An autonomously controllable digital twin governance method and system

By using independently controllable edge computing and branch Schrödinger bridge neural networks, combined with domestically produced cryptographic algorithms and security chips, the problems of low computational efficiency and security dependence of digital twin governance platforms have been solved, realizing efficient and secure multi-path evolution characteristic expression and closed-loop governance.

CN121000724BActive Publication Date: 2026-02-17贵州中汇科技发展有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511520162.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-23
Publication Date
2026-02-17
Estimated Expiration
2045-10-23

AI Technical Summary

Technical Problem

Existing digital twin governance platforms suffer from problems such as low computational efficiency, heavy reliance on external technologies, and difficulty in expressing the dynamic divergence and evolution characteristics of the system.

Method used

Data acquisition and preprocessing are performed using domestically developed and controllable edge computing devices. A branch Schrödinger bridge neural network is constructed, and combined with domestically produced cryptographic algorithms and security chips, multi-level access control and privacy computing are achieved. Real-time sensor data is integrated for multi-modal data fusion analysis, decision suggestions are generated, and precise governance is carried out through closed-loop control.

Benefits of technology

It achieves efficient utilization of computing resources, can express the multi-path evolution characteristics of the system, improves the generalization ability of the model, ensures data security and sovereignty, and forms a complete closed-loop governance system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000724B_ABST
    Figure CN121000724B_ABST
Patent Text Reader

Abstract

The application discloses a kind of self-controllable digital twin governance method and system, comprising: based on self-controllable edge computing equipment collection physical entity data and pre-processing;Through the importance score extrapolation framework, efficient pruning is carried out on data;Branch schrodinger bridge neural network is constructed, and the evolution characteristics of system multi-path are expressed;Enhance the generalization ability of model using multi-experiment equation learning;Based on domestic cryptographic algorithm and security chip, build self-controllable security framework;Integrate real-time data and digital twin model output for analysis, realize closed-loop control.The application solves the technical problems of the existing digital twin system centralized architecture, such as low efficiency, serious external technology dependence, and difficulty in expressing system dynamic divergence evolution characteristics, realizes efficient data processing, accurate mapping of system dynamic divergence characteristics, enhanced model generalization ability and data sovereignty security guarantee, and has wide application prospect.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet of Things and artificial intelligence fusion, in particular to an autonomous controllable digital twin governance method and system. BACKGROUND

[0002] As a frontier field of deep integration of Internet of Things and artificial intelligence, digital twin technology has become an important supporting technology for today's intelligent system construction. Through the construction of high-precision digital mapping models of physical entities, the technology realizes the bidirectional interaction and real-time synchronization of the physical world and the digital world, providing a new paradigm for the whole life cycle management of complex systems.

[0003] At present, common technologies in the field of digital twins include general cloud platform-based twin modeling technology and professional simulation software-based twin analysis technology. The former builds twin models through large-scale cloud computing resources, and the latter relies on professional field knowledge for accurate simulation analysis. These technologies have been widely used in manufacturing, urban management, infrastructure monitoring and other fields.

[0004] Existing digital twin governance platforms generally adopt centralized architecture and rely heavily on commercial external computing frameworks and data processing engines. Such systems usually need to transmit full data to the central server for processing, use traditional machine learning models to analyze and predict data, and use a unified permission system for access control. When building digital twin models, the system needs a large amount of computing resources to complete model training and optimization, and the dependence on full data limits the scalability of the system.

[0005] However, this architecture has obvious technical defects: first, centralized data processing leads to low computational efficiency when dealing with large-scale data, especially when training advanced machine learning models, the computational cost is high; second, existing platforms rely heavily on external technologies, which poses a data security and sovereignty risk; in addition, traditional single model training methods are difficult to express the dynamic divergence evolution characteristics of the system and cannot accurately capture the diversity change rules of complex systems. SUMMARY

[0006] The purpose of the present application is to provide an autonomous controllable digital twin governance method and system, which aims to solve the technical problems of low efficiency of centralized data processing, heavy dependence on external technologies and difficulty in expressing the dynamic divergence evolution characteristics of the system in the prior art.

[0007] To achieve the above-mentioned purpose, the present application provides an autonomous controllable digital twin governance method, comprising the following steps:

[0008] Based on autonomous controllable edge computing devices, real-time collection of physical entity data is performed through multi-source sensors and preliminary screening and preprocessing is performed to obtain structured raw data streams;

[0009] extracting a small-scale data sample from the structured raw data stream for initial training, constructing an importance score model, performing importance score extrapolation and adaptive pruning on full-quantity data, and generating an optimized training data set;

[0010] Based on the optimized training data set, a branched Schrodinger bridge neural network is constructed and a plurality of time-dependent velocity fields are parameterized, and by jointly training shared parameters and branch-specific parameters, a branched digital twin model expressing the multi-path evolution characteristics of the system is obtained.

[0011] Based on the branched digital twin model, a multi-experiment data set is constructed and an equation discovery network is trained, the discovered mathematical laws are integrated with the branched digital twin model, and through constraint condition injection and model parameter regularization, an enhanced digital twin model with high generalization is formed.

[0012] Based on domestic cryptographic algorithms and secure chips, a data full-life-cycle protection architecture is constructed to realize multi-level permission management and privacy computing, and a self-controllable security framework is obtained.

[0013] Integrate real-time sensor data with the enhanced digital twin model with high generalization to perform multi-modal data fusion analysis, identify abnormal patterns and generate decision recommendations, and achieve precise management of physical entities through closed-loop control.

[0014] Preferably, the real-time acquisition of physical entity data by multi-source sensors and preliminary screening and preprocessing to obtain a structured raw data stream includes:

[0015] Based on the physical entity data acquisition requirements, a distributed edge computing node network of domestically developed processors and operating systems is constructed to realize local data preprocessing capabilities and obtain an edge computing network topology.

[0016] The multi-source sensors are deployed according to the key characteristics of the physical entity, and heterogeneous device standardized access is achieved through data format standardization interfaces to obtain standardized sensor access configurations.

[0017] Based on the edge computing network topology and the standardized sensor access configuration, the distributed edge computing node network uses the cache technology of edge nodes to collect data from the multi-source sensors at a preset sampling frequency, and performs local timestamp synchronization and preliminary caching to obtain time-synchronized raw data streams.

[0018] Lightweight data preprocessing algorithms are deployed on the edge nodes of the distributed edge computing node network to perform denoising, outlier filtering, and data format standardization on the time-synchronized raw data streams to obtain the structured raw data stream.

[0019] Preferably, the importance score extrapolation and adaptive pruning of the full data set generates an optimized training data set, comprising:

[0020] A small-scale data sample is selected from the structured raw data stream using a stratified random sampling method, and an initial model is trained to obtain initial model parameters and sample feature vectors;

[0021] A sample importance scoring model is constructed based on the k-nearest neighbor method and the graph neural network method, and the initial model parameters and the sample feature vectors are input to obtain the importance scoring model;

[0022] The importance scoring model is applied to the complete data set to calculate the importance score of each sample, and a weighted data sample set is obtained;

[0023] According to the system resource status, task priority and data distribution characteristics, a pruning threshold is dynamically determined, and redundant samples below the threshold are removed to generate the optimized training data set.

[0024] Preferably, the branched digital twin model expressing the multi-path evolution characteristics of the expression system comprises:

[0025] Based on the engineering parameters of the physical entity and the basic physical laws, a physical model framework is constructed to describe the basic behavior of the system, and an initial digital twin model skeleton is obtained;

[0026] Based on the initial digital twin model skeleton, a multi-head branched Schrödinger bridge neural network is designed, which includes a shared encoding layer, a multi-path decoding layer and an attention fusion mechanism, and a network structure capable of expressing the evolution of the system from a single initial state to multiple possible final states is obtained;

[0027] Based on the engineering parameters of the physical entity, the basic physical laws and the dynamic characteristics reflected by the structured raw data stream, different system change characteristics are identified, and multiple time-dependent velocity fields and growth process models are parameterized for different system change characteristics to capture dynamic evolution laws at different time scales, and a multi-time scale dynamics model is obtained.

[0028] Using the optimized training data set, the multi-head branched Schrödinger bridge neural network is trained end-to-end, and the shared parameters and branch-specific parameters are optimized to obtain the branched digital twin model.

[0029] Preferably, the formation of an enhanced digital twin model with high generalization ability comprises:

[0030] The core parameter variation range and constraint conditions of the physical entity are obtained, a multi-dimensional parameter space mapping is constructed, and a parameter space representation model is obtained.

[0031] Based on the parameter space representation model, an equation discovery network based on symbolic regression is designed, which includes three core modules of variable screening, expression generation and equation evaluation, to obtain a complete equation discovery network structure;

[0032] Based on the branching digital twin model, multiple sets of simulation experiment data are generated under different parameter configurations, a multi-experiment data set is constructed, and the equation discovery network is trained using the multi-experiment data set to obtain a mathematical equation describing the internal law;

[0033] The discovered mathematical equation describing the internal law is integrated with the branching digital twin model, and the generalization ability of the branching digital twin model in the parameter space is enhanced through constraint condition injection and model parameter regularization to obtain an enhanced digital twin model with high generalization ability.

[0034] Preferably, the autonomous controllable security framework comprises:

[0035] Based on domestic cryptographic algorithms and secure chips, a data full life cycle protection architecture is designed, which includes data encryption, access control and integrity protection measures at each link of data acquisition, transmission, storage, processing and application, to obtain a data sovereignty protection system;

[0036] Based on the data sovereignty protection system, a fine-grained permission control system based on roles and attributes is constructed, which supports three-layer permission isolation at the resource level, operation level and data level, to obtain an access control system based on the principle of least privilege;

[0037] A hardware isolated execution environment is deployed at the key nodes to ensure that the key algorithms run in a trusted environment through secure boot, remote authentication and isolated execution, to obtain a trusted execution environment;

[0038] Based on differential privacy and federated learning technology, privacy protection in data analysis process is realized, which supports model training and reasoning without exposing original data, to obtain the autonomous controllable security framework.

[0039] Preferably, the integration of real-time sensing data and the output of the enhanced digital twin model with high generalization ability is analyzed by multi-modal data fusion, to identify abnormal patterns and generate decision suggestions, and through closed-loop control, precise management of physical entities is realized, including:

[0040] Integrate real-time sensing data and the output of the enhanced digital twin model, and through time alignment and feature fusion, obtain a comprehensive view reflecting the state of physical entities;

[0041] Based on the comprehensive view reflecting the state of the physical entity and the multi-path evolution trajectory predicted by the branched digital twin model, an abnormality detection algorithm is designed to identify trends deviating from the normal operation interval, and a hierarchical early warning signal is obtained.

[0042] For the detected hierarchical early warning signal or optimization demand, multi-scenario simulation is performed using the enhanced digital twin model with high generalization, a plurality of groups of intervention measure suggestions are generated, and the effectiveness and risks of each scheme are predicted and evaluated by the enhanced digital twin model with high generalization, and an optimal decision scheme is obtained.

[0043] The optimal decision scheme is converted into specific control instructions, which are issued to the physical entity execution system through a secure channel, and execution feedback data is collected to continuously optimize the enhanced digital twin model with high generalization, thereby realizing precise management of the physical entity.

[0044] Preferably, based on the data sovereignty protection system, a fine-grained permission control system based on roles and attributes is constructed to support three-layer permission isolation at the resource, operation and data levels, and an access control system based on the principle of least privilege is obtained, including:

[0045] Based on the identity authentication requirement, a two-way identity authentication protocol based on the SM2 algorithm is implemented to ensure that the identities of both parties are real and reliable. For high-security-level scenarios, hardware-level identity authentication based on domestic security chips is supported to obtain a multi-factor identity authentication mechanism.

[0046] Resource isolation based on network segmentation and security domains is implemented for system resources, and the default denial principle is adopted, so that each resource access request is evaluated by a fine-grained strategy to obtain resource-level permission control.

[0047] Role-based access control predefines multiple roles, each role is associated with a specific set of operation permissions, and the role hierarchy and responsibility separation principle is implemented to prevent excessive concentration of permissions, thereby obtaining operation-level permission control.

[0048] Attribute-based access control is adopted to dynamically evaluate access permissions based on user attributes, data attributes and environment attributes, and three granularities of row-level, column-level and cell-level data access control are supported to obtain data-level permission control.

[0049] Based on the data-level permission control, periodic permission review and automatic recycling mechanisms are used to ensure that users only hold the necessary minimum set of permissions, and the strictness of the permission strategy is dynamically adjusted based on threat intelligence and abnormal behavior detection, thereby obtaining the access control system based on the principle of least privilege.

[0050] Preferably, the differential privacy and federated learning technology realizes privacy protection in the data analysis process, supports model training and inference without exposing original data, and obtains the autonomous controllable security framework, comprising:

[0051] Based on data sensitivity analysis, a desensitization method including static desensitization, dynamic desensitization and format reservation encryption is dynamically selected according to data sensitivity and use scenarios, intelligent desensitization based on semantic understanding is realized, and a desensitized data set is obtained;

[0052] Based on the desensitized data set, a differential privacy computing framework is constructed, including a privacy budget manager, a noise injection engine and a sensitivity analyzer, which provides privacy protection for data analysis, and obtains differential privacy computing capability;

[0053] A federated learning platform is constructed, including federated modeling service, secure aggregation protocol and model security evaluation, supporting horizontal federated learning and vertical federated learning, and obtaining multi-party collaborative learning capability;

[0054] A secure multi-party computing framework based on homomorphic encryption is realized based on domestic general-purpose cryptographic algorithm, which supports data analysis in an encrypted state, and obtains encryption computing capability;

[0055] Based on the encryption computing capability, a compliance verification mechanism based on zero-knowledge proof is realized, which allows third-party auditors to verify whether the privacy protection measures are effectively implemented, and obtains privacy protection verification capability.

[0056] The application also provides an autonomous controllable digital twin governance system, comprising:

[0057] A data perception and acquisition module is used for acquiring physical entity data in real time through multi-source sensors based on autonomous controllable edge computing equipment and performing preliminary screening and preprocessing, to obtain a structured raw data stream;

[0058] A data pruning and processing module is used for extracting small-scale data samples from the structured raw data stream for initial training, constructing an importance scoring model, performing importance score extrapolation and adaptive pruning on full-amount data, and generating an optimized training data set;

[0059] A branched digital twin model construction module is used for constructing a branched Schrodinger bridge neural network based on the optimized training data set and parameterizing a plurality of time-dependent velocity fields, sharing parameters and branch-specific parameters through joint training, and obtaining a branched digital twin model expressing system multi-path evolution characteristics;

[0060] A model enhancement and generalization module is configured to construct a multi-experiment data set based on the branched digital twin model, train an equation discovery network, integrate the discovered mathematical rules with the branched digital twin model, and form an enhanced digital twin model with high generalization through constraint condition injection and model parameter regularization.

[0061] A security framework implementation module is configured to construct a data full-life-cycle protection architecture based on domestic cryptographic algorithms and security chips, implement multi-level permission management and control and privacy calculation, and obtain a self-controllable security framework.

[0062] An intelligent decision-making and control module is configured to integrate real-time sensing data and the output of the enhanced digital twin model with high generalization for multi-modal data fusion analysis, identify abnormal patterns and generate decision-making suggestions, and realize precise management of physical entities through closed-loop control.

[0063] The present application has the following advantages:

[0064] 1. Through the importance score extrapolation framework, only a small proportion of data is initially trained to realize efficient pruning of full-quantity data, significantly reduce the demand for computing resources while maintaining model performance, and solve the problem of low computational efficiency of traditional digital twin systems when facing large-scale data.

[0065] 2. The branched Schrodinger bridge matching technology is adopted to design a multi-head branched neural network structure, parameterize multiple time-dependent velocity fields, so that the digital twin model can express the dynamic divergence characteristics of the system evolving from a single initial state to multiple possible final states, and overcome the limitations of traditional single models in capturing the diversity of system changes.

[0066] 3. Through the multi-experiment equation learning method, the inherent mathematical rules of the system are mined and integrated with the digital twin model, which significantly improves the generalization ability of the model in unknown parameter space and enhances the prediction ability of the system in unknown states.

[0067] 4. Based on domestic cryptographic algorithms and security chips, a self-controllable security architecture is constructed to realize multi-level permission management and control and privacy calculation, ensuring the sovereignty and safety of system data, and solving the data security and sovereignty risks caused by the serious dependence on external technologies of existing platforms.

[0068] 5. A complete closed-loop management system is formed, the enhanced digital twin model is fused with real-time data for analysis, abnormal pattern recognition, multi-scenario decision-making generation and evaluation are realized, and a complete closed loop is formed through feedback optimization to improve the management efficiency of the system. BRIEF DESCRIPTION OF DRAWINGS

[0069] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0070] Figure 1 A flowchart of the autonomous and controllable digital twin governance method provided in this embodiment of the invention;

[0071] Figure 2 A flowchart for multi-experiment equation learning enhancement generalization provided in embodiments of the present invention;

[0072] Figure 3 The diagram shows the structure of the autonomous and controllable digital twin governance system provided in this embodiment of the invention. Detailed Implementation

[0073] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments.

[0074] like Figure 1 As shown, the autonomous and controllable digital twin governance method provided in this embodiment of the invention includes the following steps:

[0075] Step S1 is based on an autonomous controllable edge computing device, which collects physical entity data in real time through multi-source sensors and performs preliminary screening and preprocessing to obtain structured raw data streams. In this step, a comprehensive data collection scheme is designed according to the characteristics and monitoring needs of the physical entity. This scheme takes into account the working principle, key parameters, potential failure modes and performance indicators of the physical entity, and determines the types of physical quantities to be monitored, sampling frequency and accuracy requirements. The system adopts a multi-level, multi-dimensional sensing strategy, deploying temperature, pressure, vibration, displacement, flow, voltage and current sensors to form a comprehensive sensing network. To ensure the autonomy and controllability of the data collection system, the system uses edge computing devices based on domestic chips and operating systems to build a distributed edge computing network. These devices are distributed around key monitoring points on the physical entity and can collect and process data on site, reducing data transmission delay and bandwidth pressure. The edge nodes are designed modularly and include data acquisition modules, preprocessing modules, storage modules and communication modules, supporting flexible configuration and functional expansion. Standardized interfaces between sensors and edge devices are implemented, supporting multiple industrial communication protocols to ensure unified access and management of heterogeneous sensing devices. During data collection, the system uses an adaptive sampling strategy based on the characteristics of different parameters to increase the sampling frequency for rapidly changing parameters and reduce the sampling frequency for slowly changing parameters, balancing data accuracy and system resource consumption. The collected raw data is preliminarily screened and preprocessed at the edge nodes, including signal conditioning, noise filtering, outlier detection and data format conversion.

[0076] Step S2 extracts small-scale data samples from the structured raw data stream for initial training, builds an importance scoring model, and performs importance scoring extrapolation and adaptive pruning on the full data to generate an optimized training data set. In this step, a key challenge is faced: the amount of data generated in the Internet of Things environment is huge, and directly using full data for model training will lead to excessive demand for computing resources, affecting system efficiency and response speed. To solve this problem, the data importance evaluation and intelligent pruning strategy are innovatively adopted, which significantly reduces the demand for computing resources while maintaining the performance of the model. The system first selects small-scale data samples (usually 5-10% of the full data) from the structured raw data stream using a hierarchical random sampling method. The sampling process considers the time distribution, spatial distribution, and feature distribution of the data to ensure that the samples are representative and cover various working conditions and boundary conditions. These small-scale samples are used for initial model training, and lightweight neural network structures such as MobileNet or EfficientNet variants are used. The training process does not pursue the final accuracy, but focuses on obtaining preliminary model parameters and sample feature vectors, which will be used for subsequent importance evaluation. Based on the initial training results, a sample importance scoring model is built, and a combination of k-nearest neighbor (KNN) and graph neural network (GNN) methods is used. The KNN method calculates the similarity of samples in the feature space and estimates the importance based on the training performance of similar samples; the GNN method constructs a sample similarity graph and learns the mutual influence between samples through a message passing mechanism to predict the contribution of each sample to model training. The constructed importance scoring model is applied to the full data to realize knowledge extrapolation from small samples to full data.

[0077] Step S3, based on the optimized training dataset, constructs a branch Schrödinger bridge neural network and parameterizes multiple time-dependent velocity fields, obtains a branched digital twin model expressing the multi-path evolution characteristics of the system through joint training of shared parameters and branch-specific parameters. In this step, the key limitation of traditional digital twin models is first addressed: most existing models can only predict a single evolution trajectory of the system, and cannot express the multiple evolution paths and bifurcation phenomena that may occur under different conditions of complex systems. To overcome this limitation, the system innovatively introduces the branch Schrödinger bridge theory and designs a new type of neural network architecture that can capture the dynamic divergence characteristics of the system. First, based on the engineering parameters and basic physical laws of the physical entity, a physical model framework is constructed to describe the basic behavior of the system. This framework combines domain expertise to identify the basic physical laws and empirical formulas applicable to the physical entity, constructs a set of differential or algebraic equations, and forms the initial digital twin model skeleton. This physics-based skeleton ensures that the model has good physical interpretability and generalization ability, avoiding the physical inconsistency problems that may occur in purely data-driven models. On this basis, the system designs a multi-head branch Schrödinger bridge neural network structure, which includes three key components: shared encoding layer, multi-path decoding layer, and attention fusion mechanism. The shared encoding layer uses a Transformer or graph convolution network structure to convert the state representation of the physical entity into a latent space representation; the multi-path decoding layer designs multiple parallel decoding branches, each corresponding to a possible evolution path and having an independent parameter set; the attention fusion mechanism establishes connections between different time steps and different branches, enabling the model to learn long-term dependencies and mutual influences between branches. The system parameterizes multiple time-dependent velocity fields and growth process models for different system variation characteristics, capturing the dynamic evolution laws of the system at different time scales. For fast-changing processes, the system uses high-order differential equations and neural ordinary differential equations; for medium time scale processes, it uses a hybrid model of recurrent neural networks and residual connections; for slow evolution processes, it uses a cumulative growth model. These multi-scale models are connected through a multi-level fusion mechanism to form a complete time-state evolution description. The system uses the optimized training dataset to perform multi-stage end-to-end training of the branch Schrödinger bridge network. The training process first fixes the physical model part and optimizes the data-driven components; then jointly optimizes the physical model and neural network parameters, introducing physical consistency constraints; finally focuses on the optimization of branch paths to maximize prediction accuracy and branch diversity. Training uses multiple regularization techniques to prevent overfitting and ensures that rare but important evolution paths have sufficient learning opportunities through sample re-weighting. The final trained branched digital twin model has core capabilities such as predicting multiple possible evolution paths, quantifying the probability of each path, identifying key bifurcation points, and maintaining physical consistency, providing a new technical paradigm for comprehensive digital mapping of complex systems.

[0078] Step S4 builds a multi-experiment dataset based on the branched digital twin model and trains an equation discovery network. The discovered mathematical laws are integrated with the branched digital twin model through constraint injection and model parameter regularization to form an enhanced digital twin model with high generalization. In this step, another key challenge faced by digital twin models is addressed: how to improve the generalization ability of the model in the parameter space, so that it can accurately predict the system behavior in the region not covered by the training data. Traditional models often perform poorly when faced with new parameter combinations or boundary conditions, limiting their practical application value. To solve this problem, the multi-experiment equation learning method is innovatively combined to significantly enhance the generalization ability of the model. The system first analyzes the core parameter variation range and constraint conditions of the physical entity, and constructs a multi-dimensional parameter space mapping. This process identifies the key parameters that affect the system behavior, analyzes the constraint relationship between parameters, and uses manifold learning methods to map the high-dimensional parameter space to a low-dimensional representation, forming a parameter space representation model. Based on the parameter space representation, a symbolic regression-based equation discovery network is designed, including three core modules: variable selection, expression generation, and equation evaluation. The variable selection module uses sparse learning principles to identify the most influential variables; the expression generation module integrates genetic programming and neural-guided search to explore possible mathematical expressions; and the equation evaluation module balances prediction accuracy, complexity, and physical reasonableness to select the optimal expression. The system generates multiple sets of simulation experiment data under different parameter configurations using the branched digital twin model, and constructs a multi-experiment dataset. The data generation uses design of experiments methodology, including orthogonal experiment design, Latin hypercube sampling, and adaptive experiment design, to ensure efficient coverage of the parameter space. Controlled random perturbations are introduced during the simulation process to enhance data diversity, and when conditions permit, physical verification experiments are used to verify the reliability of the simulation data. The system trains the equation discovery network using the constructed multi-experiment dataset to uncover the system's inherent mathematical laws. Cross-validation strategies are used to ensure that the discovered equations have generalization ability, and batch training mechanisms are used to improve efficiency. After training, a set of mathematical equations describing the system's inherent laws are obtained, which have clear physical meaning and applicable conditions. The discovered mathematical laws are deeply integrated with the branched digital twin model using multiple techniques: knowledge distillation uses equations as "teacher knowledge" to guide model learning; constraint condition injection converts equations into soft and hard constraints between network layers; model parameter regularization designs specific regularization terms based on mathematical laws; and adaptive structure optimization adjusts the network structure according to mathematical laws. Through rigorous cross-validation experiments, especially focusing on the performance of the parameter space boundary region and the sparse sampling region, the generalization ability of the enhanced model is verified. The final enhanced digital twin model can provide reliable predictions in a wider parameter space, even under conditions not covered by the training data, and maintains reasonable physical behavior, significantly improving the model's practical value and adaptability.

[0079] Step S5 builds a data full life cycle protection architecture based on domestic cryptographic algorithms and security chips, realizes multi-level permission control and privacy calculation, and obtains a self-controllable security framework. In this step, the core security challenge faced by the digital twin platform is solved: how to realize efficient utilization and value mining of data on the premise of ensuring data security and privacy protection. The traditional platform relies heavily on external security technology, which has data sovereignty hidden dangers and security risks. To solve this problem, a completely self-controllable security framework is built to cover the security protection needs of the data full life cycle. First, a data full life cycle protection architecture is designed based on domestic cryptographic algorithms and security chips. The architecture adopts a layered and domain security design concept, divides the data security protection system into physical security layer, system security layer, application security layer and management security layer, and realizes in-depth defense. In the data collection link, the system deploys a secure sensor terminal supporting national cryptographic algorithms to realize data source encryption and identity authentication; in the data transmission link, a secure communication tunnel is built using national cryptographic algorithms to realize transmission encryption and integrity protection; in the data storage link, a multi-level encryption storage architecture and a complete key management system are realized; in the data processing link, a secure computing environment is designed to support data analysis in an encrypted state; in the data application link, fine-grained access control and comprehensive audit mechanisms are realized. Based on the data sovereignty protection system, a fine-grained permission control system based on roles and attributes is built. A unified identity authentication framework is designed to support multi-factor authentication and national cryptographic algorithms; three layers of permission isolation at the resource level, operation level and data level are realized to ensure the principle of least privilege; support for permission life cycle management and dynamic permission adjustment is provided to prevent excessive accumulation and abuse of permissions. A hardware isolation execution environment is deployed at the key node to ensure that the key algorithms run in a trusted environment through secure boot, remote authentication and isolated execution. The environment is based on a domestic trusted computing platform to realize the integrity measurement chain from the boot program to the application program; a hardware isolation execution environment, a trusted container environment and a trusted blockchain environment are built to provide security for different scenarios; an algorithm protection mechanism and an exception monitoring response are realized to prevent core algorithm leakage and tampering. The system realizes privacy protection in the data analysis process based on differential privacy and federated learning technology. The system designs multi-level data desensitization strategies, selects appropriate desensitization methods according to data sensitivity and use scenarios; builds a differential privacy calculation framework to provide privacy protection for data analysis; realizes a self-controllable federated learning platform to support model training without exposing raw data; realizes secure multi-party computation based on domestic cryptographic algorithms to support data analysis in an encrypted state. Through the organic combination of these technologies, the system builds a complete self-controllable security framework, ensuring data sovereignty security while supporting efficient analysis and value mining of data, providing a solid guarantee for the safe application of digital twin systems.

[0080] Step S6 integrates real-time sensor data with the enhanced digital twin model output with high generalization to perform multi-modal data fusion analysis, identify abnormal patterns and generate decision recommendations, and achieve precise management of physical entities through closed-loop control. In this step, the final value of digital twin technology is achieved: the intelligent analysis of the digital world is closely combined with the entity control of the physical world to form a closed-loop management system. First, integrate real-time sensor data with enhanced digital twin model output, align the time sequence and fuse the features to obtain a comprehensive view of the physical entity state. The fusion process uses multi-level time alignment technology to solve the time scale difference of different data sources; multi-level feature fusion is achieved, including data level fusion, feature level fusion and decision level fusion; a data reliability evaluation mechanism is established to dynamically adjust the weight of different data sources. Based on the comprehensive view and the multi-path evolution trajectory predicted by the branched digital twin model, the system designs an anomaly detection algorithm to identify trends that deviate from the normal operating range. Define the normal operating range, including static threshold and dynamic boundary; use a multi-modal anomaly detection framework, combining rule-based methods, statistical learning and deep learning; pay special attention to trend anomalies to achieve early warning; innovatively use multi-path prediction capability to enhance anomaly detection accuracy through trajectory deviation analysis; implement anomaly correlation analysis to distinguish between independent anomalies and systemic anomalies; generate a hierarchical warning signal containing detailed anomaly information and handling suggestions. For detected warning signals or optimization needs, the system uses the enhanced digital twin model to perform multi-scenario simulation to generate multiple sets of intervention measure recommendations. The system determines the intervention urgency based on the warning type and level; generates initial schemes by combining a pre-defined measure library and historical cases; performs "hypothesis-deduction" analysis on each candidate scheme to simulate the system response after intervention; performs multi-dimensional evaluation, including effect evaluation, risk evaluation, resource evaluation and feasibility evaluation; analyzes the combined effect of the schemes to form a comprehensive intervention strategy; selects the optimal decision scheme based on the evaluation results and generates a detailed implementation plan. The system converts the optimal decision scheme into specific control instructions, which are transmitted to the physical entity execution system through a secure channel, and collects execution feedback data to continuously optimize the digital twin model. Implement instruction decomposition and scheduling to convert complex schemes into basic operation steps; transmit the instructions through a secure channel to ensure their safety; use a gradual execution strategy to reduce risks; monitor the execution process in real time and adjust abnormal responses in a timely manner; comprehensively evaluate the intervention effect to analyze effectiveness and applicable conditions; use execution data to continuously optimize the model to improve prediction accuracy and control effectiveness. Through this closed-loop control and continuous optimization mechanism, precise, efficient and safe intelligent management of physical entities is achieved, maximizing the performance and value of physical entities, and embodying the core application value of digital twin technology.

[0081] In one embodiment of the present application, in step S1, the real-time physical entity data is collected by multi-source sensors and preliminarily screened and pre-processed to obtain structured raw data streams, including:

[0082] Step S1.1, based on physical entity data acquisition requirements, constructs a distributed edge computing node network of domestically developed processors and operating systems, realizes local data preprocessing capabilities, and obtains an edge computing network topology. This step first analyzes the physical entity comprehensively to determine the key points of data acquisition and the frequency requirements. The system designs the optimal edge node deployment scheme according to the spatial distribution of the physical entity, the data size, and the real-time requirements. In terms of hardware selection, domestically developed processor chips such as Loongson, Feiteng, or Kunpeng series processors are used to ensure the controllability of the computing core. On the operating system level, a customized operating system based on the domestic Linux kernel is used, such as Galaxy Kirin, UOS, or Zhongbiao Kirin, and performance optimization is carried out for the edge computing scene, especially in real-time response, low-power operation, and security protection. The system also realizes the self-organizing network capability of the edge node, supports dynamic joining and exiting of the node, automatically adjusts the network topology structure, and ensures the high availability and elastic expansion capability of the network. Each edge node is equipped with local storage and computing resources, can work independently for a period of time in the case of network disconnection, and automatically synchronizes data after network recovery. Through distributed collaborative algorithms, task allocation and load balancing between edge nodes are realized, and work allocation is dynamically adjusted according to the computing capacity, network status, and battery capacity of each node. Finally, the system forms a complete edge computing network topology structure, including node location, connection relationship, computing capacity distribution, and data flow direction, etc. information, providing infrastructure support for subsequent data acquisition and processing.

[0083] Step S1.2 deploys the multi-source sensors for the key characteristics of the physical entity, realizes standardized access of heterogeneous devices through a data format standardization interface, and obtains a standardized sensor access configuration. In this step, first, based on the engineering characteristics and monitoring requirements of the physical entity, the type and quantity of sensors to be deployed are determined. These sensors usually include temperature, pressure, vibration, displacement, flow, voltage and current physical quantity sensors, as well as multimedia sensors such as cameras and microphones. The system adopts a multi-level sensing strategy, divides the sensors into core layer, extension layer and auxiliary layer according to importance and sampling frequency requirements, and forms a stereoscopic perception network. To solve the access problem of heterogeneous sensing devices, a unified data format standardization interface is designed to support multiple industrial communication protocols such as Modbus, Profibus, OPC UA, etc., and also support common Internet of Things protocols such as MQTT, CoAP, etc. A protocol conversion gateway is implemented, which can convert sensing data of different protocols into a unified internal data format, ensuring data consistency and processability. For intelligent sensors, the system supports plug-and-play function on the edge side, automatically identifies sensor type and parameters through device self-description technology, and reduces manual configuration work. A sensor metadata database is also established to record the location, model, accuracy, calibration information and maintenance records of each sensor, etc., to facilitate subsequent data quality evaluation and exception troubleshooting. Through these measures, the system finally forms a standardized sensor access configuration, realizes the unified management and data acquisition of heterogeneous sensing devices, and lays a foundation for obtaining high-quality raw data.

[0084] Step S1.3 collects data of the multi-source sensors according to a preset sampling frequency by using cache technology of edge nodes in the distributed edge computing node network based on the edge computing network topology and the standardized sensor access configuration, and performs local timestamp synchronization and preliminary caching to obtain time-synchronized raw data streams. In this step, optimal sampling frequencies are set for different types of sensors according to dynamic characteristics of physical entities and monitoring requirements. For rapidly changing parameters (such as vibration and current), higher sampling frequencies are used, and for slowly changing parameters (such as temperature and humidity), lower sampling frequencies are used to balance data accuracy and system resource consumption. The system realizes an efficient data collection and scheduling mechanism on the edge node, which can accurately control the sampling time interval and ensure the time consistency of data. To solve the time synchronization problem in the distributed system, an improved network time protocol (NTP) and precise time protocol (PTP) are combined to achieve microsecond-level time synchronization accuracy. Each collected data point is attached with a high-precision timestamp to record the exact time of data generation. A hierarchical cache architecture is configured on the edge node, including high-speed memory cache and persistent storage cache, which can temporarily store a large amount of data locally in case of network interruption or upper system failure. The cache management adopts a priority strategy to ensure that critical data is saved and transmitted first. The system also realizes a data compression mechanism that automatically selects suitable compression algorithms according to data types, such as differential encoding for time series data and special compression algorithms for image data, significantly reducing storage and transmission overhead. For periodic data, the system supports variable sampling rate technology to increase the sampling frequency when data changes dramatically and reduce the sampling frequency when data is stable, further optimizing resource utilization. Through these technologies, the system finally outputs time-synchronized raw data streams, providing a high-quality data foundation for subsequent data preprocessing and analysis.

[0085] Step S1.4 deploys lightweight data preprocessing algorithms on the edge nodes of the distributed edge computing node network to process the time-synchronized raw data streams for denoising, outlier filtering and data format standardization to obtain the structured raw data streams. In this step, a series of lightweight but efficient data preprocessing algorithms are deployed on the edge nodes to realize data quality improvement and preliminary structuring. First, special denoising algorithms are designed for different types of sensor data, such as wavelet transform denoising for continuous signals and median filter for discrete signals, effectively removing measurement noise and environmental interference. For sudden noise, the system uses an adaptive threshold detection method to identify and correct abnormal spikes. A multi-level outlier detection mechanism is implemented, including statistical-based methods (such as The detected outliers are processed according to different situations, slight abnormalities are corrected, serious abnormalities are marked or removed, and the abnormal situation is recorded for subsequent analysis. Data format standardization processing includes unit conversion, range normalization and time alignment operations to ensure that data from different sources can be uniformly processed and compared. Data completion function is also implemented, for missing or removed data points, reasonable filling is carried out through interpolation or prediction method to maintain the continuity of data. In view of the characteristics of limited edge computing resources, these algorithms are specially optimized, and incremental calculation, approximate calculation and other technologies are used to reduce the computational complexity, to ensure efficient operation in resource-limited environment. The preprocessed data is organized according to the predefined structured mode, including time series, feature vector, state matrix and other forms, which is convenient for subsequent analysis and processing. The system also adds quality labels to each data, records the reliability and processing history of the data, and provides data quality reference for subsequent analysis. Through these preprocessing steps, the original data that may contain noise and abnormalities are converted into high-quality structured data stream, laying a solid foundation for subsequent data analysis and model training.

[0086] In an embodiment of the present application, in step S2, the importance scoring and adaptive pruning of the full data set are carried out to generate an optimized training data set, including:

[0087] Step S2.1: A small-scale data sample is selected from the structured raw data stream using a hierarchical random sampling method, and an initial model training is carried out to obtain initial model parameters and sample feature vectors.

[0088] Step S2.2: A sample importance scoring model is constructed based on the k-nearest neighbor method and the graph neural network method, and the initial model parameters and the sample feature vectors are input to obtain the importance scoring model.

[0089] Step S2.3: The importance scoring model is applied to the complete data set to calculate the importance score of each sample, and a weighted data sample set is obtained.

[0090] Step S2.4: The pruning threshold is dynamically determined according to the system resource status, task priority and data distribution characteristics, and the redundant samples below the threshold are removed to generate the optimized training data set.

[0091] In the traditional machine learning process, the full data set usually needs to be trained, which requires a large amount of computing resources for large-scale Internet of Things data. Step S2.1 innovatively adopts a small sample training strategy, which randomly selects a small proportion (about 5%-10%) of data samples from the preprocessed structured data stream for initial training, greatly reducing the computing resource demand.

[0092] In implementation, first, a representative small-scale dataset is selected from the pre-processed structured data stream output in step S1.4 using a hierarchical random sampling method. The sampling process takes into account the temporal distribution, spatial distribution, and feature distribution of the data to ensure that the small sample can well reflect the overall data characteristics. For example, for sensor data of an industrial production line, it is ensured that the sampled data covers normal operation state, abnormal state, and various transition states.

[0093] Subsequently, a lightweight neural network model (such as MobileNet or EfficientNet variants) is used to perform initial training on these samples. During training, the final accuracy of the model is not pursued, but the preliminary model parameters and sample feature vectors are focused on. The sample feature vector here refers to the low-dimensional feature representation after model encoding, usually from the penultimate layer or a specific feature extraction layer of the neural network.

[0094] After training, two key results are output: initial model parameters and sample feature vectors. The initial model parameters reflect the model's preliminary understanding of data distribution, while the sample feature vectors contain the position information of each training sample in the feature space. These two outputs will serve as key inputs for the subsequent importance scoring model.

[0095] Step S2.2 builds a sample importance scoring model based on the initial model parameters and sample feature vectors obtained in step S2.1. This scoring model can predict the contribution of each data sample to model training, thereby identifying which samples are redundant and which are critical.

[0096] Two technical paths are provided to implement the importance scoring model: k-nearest neighbor (KNN) method and graph neural network (GNN) method.

[0097] The implementation principle of the k-nearest neighbor method is as follows: for each sample, calculate its distance to other samples in the feature space, and find the k most similar samples. Then, based on the performance of these similar samples in initial training (such as loss value reduction contribution, gradient size, etc.), estimate the importance of the current sample. For example, if the neighbors of a sample mostly have high gradient values, it indicates that this type of sample contributes significantly to model optimization, and should be assigned a higher importance score.

[0098] The graph neural network method is more complex and accurate: first, construct a similarity graph from all sample feature vectors, where nodes are samples and edge weights represent the similarity between samples. Then, design a graph neural network whose input includes node features (sample feature vectors), model behavior data in initial training (such as loss value, gradient, etc.), and graph structure information. GNN learns the mutual influence between samples through multi-layer message passing, thereby predicting the importance score of each sample.

[0099] The combination of the two methods can evaluate the importance of the sample from different angles and form a final importance score model through weighted fusion. This model can generalize the knowledge obtained in step S2.1 to unseen samples, laying the foundation for the next step of full data evaluation.

[0100] Step S2.3 applies the importance score model constructed in step S2.2 to the full data set, realizing the extrapolation of knowledge from small samples to full data, which is one of the core innovations of the present scheme.

[0101] In specific implementation, the pre-processed full structured data stream is first passed through the feature extraction layer of the initial model to obtain the representation vector of each sample. This process can be batched and does not require a complete model training process, resulting in high computational efficiency.

[0102] Then, these representation vectors are input into the importance score model. For the KNN method, the system calculates the distance between each new sample and the known importance score sample, and performs weighted averaging based on the importance scores of the k nearest neighbors. For the GNN method, the system adds the new sample to the constructed sample similarity graph, and then performs forward propagation through the trained GNN model to directly predict the importance score of the new sample.

[0103] To improve computational efficiency, this process can use approximate nearest neighbor algorithms (such as locality-sensitive hashing or KD trees) and sparse graph structures to effectively handle large-scale data sets. At the same time, a distributed computing architecture is implemented to distribute the extrapolation task to multiple edge nodes for parallel processing, further improving processing speed.

[0104] After scoring, each sample is associated with its importance score to form a weighted data sample set. This set not only contains all the features of the original data, but also adds an importance score representing its value for model training, providing a scientific basis for subsequent data pruning.

[0105] Step S2.4 is based on the weighted data sample set generated in step S2.3 to achieve intelligent data pruning to maximize the reduction of computational resource requirements while maintaining model performance.

[0106] The core of adaptive data pruning is to dynamically determine the pruning threshold. Instead of using a fixed percentage or absolute threshold, the system determines the pruning criteria based on the following factors:

[0107] System resource status: including available computing power, storage space, and network bandwidth, etc. When resources are tight, the system will increase the pruning threshold to retain fewer but more critical samples.

[0108] Task priority: Different precision requirements are set for different business scenarios. For high-priority tasks, the system reduces the pruning threshold to retain more samples to ensure model accuracy.

[0109] Data distribution characteristics: By calculating the distribution statistics of importance scores (such as mean, variance, quantile, etc.), identify the natural dividing point of importance scores as a reference for pruning thresholds.

[0110] Validation set performance: By evaluating the model performance changes under different pruning thresholds on a small-scale validation set, find the balance point.

[0111] In the actual pruning process, first sort the samples by importance score, then remove samples below the determined threshold. To prevent data distribution bias, the system also retains a small number of randomly selected low-score samples and implements a stratified pruning strategy to ensure that samples of each class are retained in proportion.

[0112] After pruning, an optimized training dataset is generated, which is significantly smaller than the original dataset (usually reduced by 30%-70%) but contains the most valuable samples for model training. This optimized dataset will be used as input for the branched digital twin model construction in step S3, significantly improving modeling efficiency without compromising model accuracy.

[0113] In one embodiment of the present application, in step S3, the branched digital twin model expressing the multi-path evolution characteristics of the system comprises:

[0114] Step S3.1: Based on the engineering parameters of the physical entity and the basic physical laws, a physical model framework is constructed to describe the basic behavior of the system, and an initial digital twin model skeleton is obtained;

[0115] Step S3.2: Based on the initial digital twin model skeleton, a multi-head branched Schrödinger bridge neural network is designed, which includes shared encoding layers, multi-path decoding layers and attention fusion mechanisms, to obtain a network structure that can express the evolution of the system from a single initial state to multiple possible final states;

[0116] Step S3.3: Based on the engineering parameters of the physical entity, the basic physical laws, and the dynamic characteristics reflected by the structured raw data stream, different system change characteristics are identified. For different system change characteristics, parameterize multiple time-dependent velocity fields and growth process models to capture dynamic evolution laws at different time scales, and obtain a multi-time scale dynamics model;

[0117] Step S3.4: Use the optimized training dataset to train the multi-head branched Schrödinger bridge neural network end-to-end, while optimizing shared parameters and branch-specific parameters, to obtain the branched digital twin model.

[0118] Step S3.1 builds a physical model framework describing the basic behavior of the system by combining the engineering parameters of the physical entity and the fundamental physical laws, serving as the basic skeleton of the digital twin model. This process ensures that the digital twin model has a physical interpretation, rather than just being a data-driven black box model.

[0119] First, analyze the core engineering parameters of the physical entity, including basic characteristics such as geometric dimensions, material properties, and working conditions. For example, for industrial equipment, this may include equipment size, power parameters, and working temperature range; for infrastructure, it may include structural parameters, load capacity, and design service life.

[0120] Then, based on domain expertise, identify the basic physical laws applicable to this physical entity. These laws may include classical mechanics laws (such as Newton's laws of motion), thermodynamic laws, electromagnetism laws, etc., and may also include empirical formulas and design specifications specific to the field. For example, for bridge structures, structural mechanics equations are applied; for power systems, circuit theory and power system stability theory are applied.

[0121] Based on these parameters and laws, a set of differential or algebraic equations is constructed to describe the basic behavior of the physical entity. These equations are organized into a structured computational graph, representing the causal relationships and computational dependencies between parameters. The system uses a combination of symbolic computation and numerical solution methods to effectively solve the equations.

[0122] The final output of the initial digital twin model skeleton is a parameterized mathematical model that can predict the basic physical response of the system under given input conditions. Although this model does not yet include complex dynamic characteristics and uncertainties, it provides a basic framework based on physical principles, ensuring that subsequent data-driven enhancements always maintain physical consistency and avoid predictions that violate physical laws.

[0123] Step S3.2 designs a multi-head branch Schrödinger bridge neural network structure, which is the core innovation for modeling the dynamic divergence characteristics of the system. This network can express the evolution of a physical system from a single initial state to multiple possible final states, overcoming the limitations of traditional single trajectory prediction models.

[0124] The Schrödinger bridge is an important concept in probability flow theory, describing how a stochastic process smoothly transitions from an initial distribution to a final state distribution. This scheme innovatively extends it to a branch structure to capture the bifurcation phenomenon that may occur during the evolution of the system.

[0125] The specific network structure design includes three main parts:

[0126] Shared encoding layer: A multi-layer transformer or graph convolution network structure is used to convert the state representation of physical entities into latent space. This shared layer ensures that all possible evolution paths are based on the same initial state understanding, improving the consistency and stability of the model. The input to the encoding layer includes physical parameters, environmental conditions, and historical state data.

[0127] Multi-path decoding layer: Multiple parallel decoding branches are designed, each corresponding to a possible evolution path. Each branch contains independent parameter sets but shares similar network structures. For example, an industrial device may have "normal aging," "accelerated degradation," and "sudden failure" evolution branches. The system uses a soft routing mechanism to dynamically allocate weights to different branches based on the current state.

[0128] Attention fusion mechanism: An attention mechanism is introduced between different time steps and different branches, allowing the model to learn long-term dependencies and mutual influences between branches. This mechanism allows different branches to borrow information from each other under certain conditions, improving overall prediction accuracy.

[0129] Network training uses a multi-task learning framework to optimize both branch prediction accuracy and the rationality of branch probability distribution. The loss function includes a prediction error term, a path diversity regularization term, and a physical consistency constraint term, ensuring that the generated multi-path predictions conform to data rules and meet physical constraints.

[0130] Step S3.3 parameterizes multiple time-dependent velocity fields and growth process models for different system variation characteristics to capture the dynamic evolution laws of the system at different time scales. This technique enables the digital twin model to handle both rapid transient changes (such as sudden events) and slow cumulative changes (such as aging processes).

[0131] The velocity field is mathematically represented as a vector field in the state space, describing the motion trend and rate of the system at each point. The system innovatively designs a multi-scale, time-varying velocity field parameterization method:

[0132] First, based on physical knowledge and data analysis, multiple characteristic time scales of the physical entity are identified. For example, for a power generation device, there may be millisecond-level electrical transients, hour-level thermodynamic changes, and monthly-level wear processes. The system designs a special parameterization model for each time scale.

[0133] For rapid change processes, a combination of high-order differential equations and neural ordinary differential equations (Neural ODE) is used to accurately capture transient dynamic characteristics. The model uses adaptive time steps, using finer time resolution in areas of rapid change.

[0134] For medium time-scale processes, a hybrid model combining recurrent neural networks with residual connections is designed to balance short-term memory and long-term dependencies.

[0135] For slow evolution processes, cumulative growth models are used to simulate long-term trends by integrating small incremental changes. These models focus on slow but continuous changes such as material aging and performance degradation.

[0136] Each time-scale model is connected through a multi-level fusion mechanism to form a complete time-state evolution description. The system also implements an adaptive attention mechanism that can dynamically adjust the attention to different time scales based on the current state and prediction requirements.

[0137] Finally, these parameterized velocity fields and growth process models together form the core dynamics system of the branching Schrödinger bridge, providing a mathematical foundation for the joint training of branching models in step S3.4.

[0138] Step S3.4 uses the optimized training dataset output by step S2.4 to perform end-to-end training on the previously designed branching Schrödinger bridge network, optimizing both shared parameters and branch-specific parameters. Finally, it outputs a branching digital twin model that can express the system's multi-path evolution characteristics.

[0139] Joint training uses a multi-stage strategy to ensure model stability and accuracy:

[0140] In the first stage, the basic physical model part is fixed, and only the data-driven neural network components are trained. This stage uses supervised learning methods to minimize the error between predicted values and actual observations. Training uses small batch gradient descent and the Adam optimizer, and uses a learning rate scheduler to dynamically adjust the learning rate.

[0141] In the second stage, the physical model parameters and neural network parameters are jointly optimized. This stage introduces physical consistency constraints to ensure that the model's predictions comply with basic physical laws. For example, for energy systems, energy conservation constraints are introduced; for mechanical systems, force balance constraints are introduced. These constraints are added to the loss function in the form of soft constraints.

[0142] In the third stage, the optimization focuses on branching paths. The training objectives include:

[0143] Maximizing the prediction accuracy of different branching paths;

[0144] Maximizing branching diversity to ensure that different paths capture different evolution patterns;

[0145] Optimizing branch probability distribution to reflect the occurrence probability of various scenarios in the real world;

[0146] To prevent overfitting, the system employs various regularization techniques, including Dropout, weight decay, and early stopping. Simultaneously, the system implements multiple rounds of cross-validation to ensure consistent model performance across different subsets of data.

[0147] During training, the system dynamically balances the allocation of training resources across branches to ensure that rare but important evolutionary paths (such as failure paths) receive sufficient learning opportunities. This is achieved through sample reweighting and focus loss.

[0148] The final trained branched digital twin model has the following core capabilities:

[0149] Predict multiple possible evolution paths of the system based on the current state;

[0150] Quantify the probability of occurrence of each evolutionary path;

[0151] Identify the key factors and time points that lead to path forks;

[0152] Achieve high-precision predictions while maintaining physical consistency.

[0153] This model serves as the input for step S4, providing a foundation for learning multi-experiment equations and further enhancing the model's generalization ability.

[0154] The training process employs specific hyperparameter settings, including an initial learning rate of 0.001, the use of the Adam optimizer (β1=0.9, β2=0.999), and batch size dynamically adjusted between 32 and 128 based on the data size. The number of training epochs is typically controlled between 50 and 200, and an early stopping strategy (patience=10) is used to avoid overfitting. A cosine annealing strategy is used for learning rate scheduling, gradually reducing the learning rate during training. For models of different sizes, the network depth is typically set to 4-8 layers, with the number of neurons per layer determined by the input feature dimension, usually 1-4 times the input dimension. Supervised learning methods are used in this stage to minimize the error between predicted and observed values.

[0155] like Figure 2 As shown, in one embodiment of the present invention, step S4, forming an enhanced digital twin model with high generalization capabilities, includes:

[0156] Step S4.1: Obtain the range of variation of the core parameters and constraints of the physical entity, construct a multi-dimensional parameter space mapping, and obtain the parameter space representation model;

[0157] Step S4.2: Based on the parameter space representation model, design an equation discovery network based on symbolic regression, which includes three core modules: variable selection, expression generation, and equation evaluation, to obtain the complete equation discovery network structure;

[0158] Step S4.3: Based on the branched digital twin model, generate multiple sets of simulation experiment data under different parameter configurations, construct a multi-experiment data set, and use the multi-experiment data set to train the equation discovery network to obtain a mathematical equation describing the internal law;

[0159] Step S4.4: Integrate the discovered mathematical equation describing the internal law with the branched digital twin model, enhance the generalization ability of the branched digital twin model in the parameter space through constraint condition injection and model parameter regularization, and obtain the enhanced digital twin model with high generalization ability.

[0160] Step S4.1: By analyzing the core parameter variation range and constraint conditions of the physical entity, a multi-dimensional parameter space mapping is constructed, forming a parameter space representation model. This step lays the foundation for subsequent equation learning, enabling the system to understand the internal relationship and constraints between parameters.

[0161] First, based on domain knowledge and historical data analysis, a set of core parameters that affect the behavior of the physical entity is identified. These parameters usually include physical property parameters (such as material properties, geometric dimensions), operating parameters (such as temperature, pressure, flow), and environmental parameters (such as humidity, vibration intensity), etc. The system uses principal component analysis (PCA) and autoencoder technology to extract the most influential key parameters from high-dimensional parameter space.

[0162] Then, each core parameter is quantitatively analyzed to determine its effective variation range, distribution characteristics and physical constraints. For example, some parameters may have physical upper and lower limit constraints (such as pressure cannot be negative), and some parameters may have functional relationship constraints (such as the relationship between power and voltage, current). The system establishes a parameter constraint library, including equality constraints, inequality constraints and implicit constraints.

[0163] Next, a mathematical representation of the multi-dimensional parameter space is constructed. Since the parameter space usually has high dimensionality and non-uniformity, the system uses manifold learning methods (such as t-SNE, UMAP, etc.) to map high-dimensional parameter space to low-dimensional manifold, identifying natural structures and clusters in the parameter space. At the same time, the system constructs a parameter sensitivity matrix to quantify the influence and interaction of each parameter on system behavior.

[0164] Finally, using symbolic regression and Gaussian process methods, an interpolation model and approximation function in the parameter space are constructed to realize continuous representation of the parameter space. These models can predict the behavior of the system under any parameter combination and identify special regions in the parameter space (such as stable region, critical region and unstable region).

[0165] After completion, the output parameter space representation model is characterized, which contains parameter constraint relationships, sensitivity information, and spatial structure characteristics, providing a structured search space and constraint conditions for subsequent equation discovery. This model enables the system to infer the behavior of the entire parameter space based on limited experimental data.

[0166] Step S4.2 designs a symbolic regression-based multi-experiment equation learning network aimed at discovering mathematical equations that describe the inherent laws of the system. This network includes three core modules: variable screening, expression generation, and equation evaluation, enabling the extraction of physically meaningful mathematical expressions from data rather than just black-box prediction models.

[0167] The variable screening module is designed using sparse learning principles, identifying key variables that have a significant impact on system behavior from a large number of candidate variables through L1 regularization and random feature selection techniques. The module implements an adaptive variable importance evaluation mechanism that can dynamically adjust variable weights according to different operating conditions. The system also designs a variable transformation engine that automatically attempts various mathematical transformations (such as logarithm, exponential, trigonometric functions, etc.), creating a more rich feature space and improving the expression ability of equation discovery.

[0168] The expression generation module combines genetic programming and neural-guided search techniques. The system designs a tree structure representation method to encode mathematical expressions into operable syntax trees. Based on this representation, the system implements three expression generation strategies:

[0169] Rule-based construction: Utilize domain knowledge to pre-set possible equation templates, such as dynamic equations, heat transfer equations, etc.

[0170] Evolutionary search: Continuously evolve expression trees through crossover, mutation, and other operations to explore the expression space.

[0171] Neural-guided generation: Train a neural network to predict the combination probability of expression components, guiding the search in the right direction.

[0172] The equation evaluation module designs a multi-criteria evaluation system to balance the prediction accuracy, complexity, and physical reasonableness of the equation. Evaluation indicators include fitting error (MSE, , complexity penalty (based on expression length and operation number), and physical consistency score (based on dimensional analysis and known physical laws). The system also designs an equation simplification engine that can automatically perform mathematical equivalent transformations on discovered expressions to obtain the simplest form.

[0173] The entire network adopts an end-to-end training architecture, integrating variable screening, expression generation, and evaluation processes into a unified optimization framework. Training uses a reinforcement learning paradigm, using equation scores as reward signals to guide the system to continuously improve expression generation strategies. To improve training efficiency, a distributed computing architecture is implemented to support parallel evaluation of multiple candidate expressions.

[0174] Finally, the equation discovery network can output a set of candidate mathematical equations, each with detailed evaluation metrics and applicable conditions, providing a theoretical basis for subsequent multi-experiment data training.

[0175] Step S4.3 generates multiple sets of simulated experimental data under different parameter configurations based on the branched digital twin model output in step S3.4, constructs a multi-experiment data set, and trains the equation discovery network using this data set to mine the internal mathematical laws of the system.

[0176] The multi-experiment data set construction uses the Design of Experiment (DOE) methodology to ensure efficient coverage of the parameter space. The system implements three experimental design strategies:

[0177] Orthogonal experimental design: Arrange parameter combinations through orthogonal tables to investigate the effects of multiple factors with the least number of experiments;

[0178] Latin hypercube sampling: Uniformly distribute sampling points in the parameter space to avoid sample clustering;

[0179] Adaptive experimental design: Dynamically adjust subsequent experimental parameters based on existing experimental results, focusing on exploring areas with high uncertainty.

[0180] Based on the branched digital twin model in step S3.4, perform simulated experiments for each set of parameter configurations. To enhance data diversity, introduce controlled random perturbations during simulation to simulate noise and fluctuations in the real world. For each set of parameter configurations, the system records the complete state evolution trajectory, including steady-state response, transient process, and key performance indicators.

[0181] To verify the reliability of the simulation data, if conditions permit, select some parameter configurations for entity verification experiments, and compare the differences between simulation results and experimental results. Based on the difference analysis, the system adjusts the relevant parameters of the branched digital twin model to improve simulation accuracy.

[0182] The constructed multi-experiment data set has the following characteristics:

[0183] Comprehensive parameter coverage: Includes normal operating intervals and boundary conditions;

[0184] Multiple time scales: Contains both short-term dynamic response and long-term evolution trend;

[0185] Multiple branch representation: record multiple possible evolution paths and their probabilities for each set of parameter configurations;

[0186] Standardized format: adopt unified data structure and metadata annotation to facilitate equation learning.

[0187] Subsequently, the equation discovery network designed in step S4.2 is trained using the constructed multi-experiment dataset. The training process adopts a cross-validation strategy, dividing the dataset into training, validation, and test sets to ensure that the discovered equations have generalization ability. A batch training mechanism is also implemented, first quickly screening candidate equations on small-scale data, and then finely evaluating them on full-scale data.

[0188] After training is complete, a set of mathematical equations describing the internal laws of the system are output, and these equations have clear physical meaning and applicable conditions. For example, for a heat exchange system, a power law relationship between heat transfer coefficient and flow rate may be discovered; for a structural system, a nonlinear equation between deformation and load may be discovered. These equations will be integrated with the digital twin model in the next step to enhance the model's generalization ability.

[0189] Step S4.4 deeply integrates the mathematical laws discovered in step S4.3 with the branched digital twin model output in step S3.4, significantly enhancing the model's generalization ability in the parameter space through constraint injection and model parameter regularization, forming an enhanced digital twin model with high generalization ability.

[0190] The integration process first uses knowledge distillation technology, using the discovered mathematical equations as "teacher knowledge" to guide the digital twin model to learn the laws contained therein. In specific implementation, the system designs a double-layer loss function: one layer based on the supervised loss of the original data, and the other layer based on the consistency loss of equation prediction, both of which guide model optimization together.

[0191] Then, through constraint injection technology, the mathematical equations are converted into soft or hard constraints between neural network layers. For laws with high certainty (such as physical conservation laws), the system implements them as hard constraint layers, forcing the model output to satisfy these constraints; for statistical laws, they are implemented as soft constraint layers, guiding the model to learn these patterns through penalty terms. This constraint injection allows the model to maintain reasonable physical behavior when facing unknown regions in the parameter space.

[0192] Next, model parameter regularization is implemented, and specific regularization terms are designed based on the discovered mathematical laws. For example, if the system is found to have a linear response to a certain parameter, a linear constraint is imposed on the corresponding network connection; if a periodic law is discovered, a Fourier constraint is introduced. These special regularization terms significantly improve the model's accuracy in parameter interpolation and extrapolation.

[0193] An adaptive structure optimization mechanism is also implemented, which dynamically adjusts the structure of the neural network according to the discovered mathematical laws. For example, for equations found to contain high-order derivatives, the system will enhance the corresponding time series modeling capability; for laws found to contain piecewise functions, the system will introduce conditional calculation branches. This structure optimization makes the model architecture better match the internal structure of the problem.

[0194] To verify the enhancement effect, a strict cross-validation experiment is designed, with special attention to the performance of the model in the boundary region of the parameter space and the sparse sampling region. The verification experiment includes parameter interpolation test (prediction between known parameter points), parameter extrapolation test (prediction outside the boundary of the parameter range), and sparse region test (prediction in the region with sparse data).

[0195] The final output of the enhanced digital twin model has significantly improved generalization ability, and can provide reliable prediction in a wider parameter space, even under conditions not covered by the training data, while maintaining reasonable physical behavior. This model will serve as the core computing engine of the autonomous controllable safety framework in step S5, and provide reliable support for intelligent decision-making in step S6.

[0196] In an embodiment of the present application, in step S5, the autonomous controllable safety framework is obtained, comprising:

[0197] Step S5.1, based on domestic cryptographic algorithms and security chips, designs a data full-life-cycle protection architecture, including data collection, transmission, storage, processing and application of each link of data encryption, access control and integrity protection measures, to obtain a data sovereignty protection system. In this step, a hierarchical and regional data security architecture is first designed, which divides the data security protection system into physical security layer, system security layer, application security layer and management security layer, and realizes in-depth defense. According to the data sensitivity level (public, internal, secret, confidential, etc.) and data flow scenario, the system defines different security domains and data flow control strategies to form a comprehensive security partition management system. In the data collection link, the system deploys a secure sensor terminal supporting national cryptographic algorithms to realize data source encryption. Each sensor terminal is equipped with an independent security chip (such as domestic SM series security chip) to provide a trusted root and key storage environment. The raw data collected by the sensor is encrypted in real time locally and attached with a digital signature and timestamp to ensure data authenticity and non-repudiation. The system implements a sensor identity authentication mechanism to prevent fake devices from accessing and data injection attacks. In the data transmission link, national cryptographic algorithms (such as SM4 symmetric encryption and SM2 asymmetric encryption) are used to build a secure communication tunnel to realize transmission encryption. The system implements a lightweight secure transmission protocol suitable for resource-constrained edge devices, while supporting national SSL / TLS protocols to ensure compatibility with existing security infrastructure. The system also deploys a traffic monitoring and anomaly detection mechanism to identify possible data theft or tampering attempts in real time, and realizes dynamic selection of transmission paths to automatically switch security channels when network anomalies are detected. In the data storage link, a multi-level encryption storage architecture is implemented. For structured data, column-level encryption technology is used to selectively encrypt key fields according to data sensitivity; for unstructured data, object-level encryption and transparent encryption technology are used to ensure data security during storage. The system also implements a secure key management system, including the complete life cycle of key generation, distribution, rotation and destruction, using national SM2 algorithm and key fragmentation technology to avoid single-point leakage risk. The system supports data classification and hierarchical storage, using different strength protection measures for different sensitivity levels of data, and implements data life cycle management, including automatic archiving and secure destruction mechanisms. In the data processing link, the system designs a secure computing environment that supports data analysis in an encrypted state. A secure computing framework based on homomorphic encryption is implemented to allow certain operations on encrypted data without decryption; at the same time, it also supports secure processing in a trusted execution environment (TEE), using CPU security areas for sensitive data calculation. For complex analysis requiring multi-party participation, a secure multi-party computation protocol based on national cryptographic algorithms is implemented to ensure data security during the calculation process. In the data application link, a fine-grained data access control and use audit mechanism is designed. Each data access is recorded with detailed operation logs, including access identity, access content, access time and operation type, etc.The system also implements data watermarking and traceability technology, which can track the source of the leak when data leakage occurs. The entire data sovereignty protection architecture is built on a domestically independent and controllable technology stack, eliminating the need for external security components and providing a foundation for security assurance for the next step of multi-level permission management.

[0198] In this step, the system uses domestic cryptographic algorithms, including the SM2 elliptic curve public key cryptography algorithm, the SM3 cryptographic hash algorithm, and the SM4 block cipher algorithm, among other national cryptographic standards, to ensure the independence and controllability of data encryption and authentication. At the same time, the system selects a variety of domestic security chips as the hardware security foundation, such as the Puhua Foundation hardware and software security chip, the Loongson secure trusted computing module, and the Huada Jiutian security unit. These chips provide core functions such as key storage, encryption operations, and secure boot.

[0199] Step S5.2. Based on the data sovereignty protection system, a role and attribute-based fine-grained permission control system is constructed, supporting three-layer permission isolation at the resource level, operation level, and data level, to obtain the access control system of the principle of least privilege. In this step, a unified identity authentication framework is first designed to support multi-factor authentication and national encryption algorithms. The authentication mechanism includes three elements: known information (such as password), held information (such as digital certificate), and possessed characteristics (such as biometric characteristics). The system implements a two-way identity authentication protocol based on the national SM2 algorithm to ensure that both parties in the communication are authentic and trustworthy. For high-security level scenarios, the system also supports hardware-level identity authentication based on domestic security chips, providing higher security protection. A centralized identity management combined with distributed authentication architecture is adopted to achieve unified management of identity information and high availability of authentication services. The system supports flexible combination of multiple authentication methods, dynamically adjusts the authentication strength according to the resource sensitivity and access scenario, and balances security and ease of use. Based on authentication, a three-layer permission control system is constructed: resource level, operation level, and data level. Resource-level permission control is for access control of system resources (such as servers, storage devices, network devices, etc.), which realizes resource isolation based on network segmentation and security domains, adopts the "default deny" principle, and only allows explicitly authorized resource access. A dynamic evaluation mechanism for resource access is implemented, and each resource access request is evaluated by a fine-grained policy, considering multiple factors such as request source, target resource sensitivity, and network path security. Operation-level permission control is for access control of system functions and operations, based on the RBAC (Role-Based Access Control) model, multiple roles (such as system administrator, data analyst, and operation personnel) are predefined, and each role is associated with a specific set of operation permissions. The role hierarchy and responsibility separation principle is implemented to prevent excessive concentration of permissions. To enhance flexibility, temporary permission elevation and emergency authorization mechanisms are supported, but with strict approval processes and operation log recording. Data-level permission control is the most fine-grained control level, which controls access to specific data objects and content. The system uses the ABAC (Attribute-Based Access Control) model to dynamically evaluate access permissions based on multiple attributes (user attributes, data attributes, environment attributes, etc.). The system supports three granularities of data access control: row-level, column-level, and cell-level, which can implement complex policies such as "only allow viewing summary data and not detailed records." Data-level permission control is tightly integrated with the data classification and grading system, and sensitive data automatically applies stricter access strategies. The system implements permission management life cycle automation, including the complete process of permission application, approval, allocation, use, recovery, and audit. In particular, the system strengthens the principle of least privilege, through regular permission review and automatic recovery mechanisms, to ensure that users only hold the necessary minimum set of permissions.To cope with dynamic security requirements, an adaptive permission control mechanism is designed, which can dynamically adjust the strictness of permission policies according to threat intelligence, abnormal behavior detection and system load status. For example, when suspicious activities are detected, the system will automatically increase the permission granting threshold and enhance monitoring. The multi-level permission management system is deeply integrated with the data sovereignty protection architecture of step S5.1, and together forms a unified security protection system, providing identity authentication and permission control basis for the secure and trusted execution environment of step S5.3.

[0200] Step S5.3 deploys a hardware isolated execution environment at the key node, ensures that the key algorithm runs in a trusted environment through secure boot, remote authentication and isolated execution, and obtains a trusted execution environment. In this step, a hardware root of trust architecture based on domestic trusted computing platform is first designed. Domestic security chips (such as trusted platform module TPM or secure element SE) are deployed on key servers and edge nodes to provide hardware-level key protection and measurement verification capabilities. The integrity measurement chain from the boot program to the operating system and then to the application is implemented to ensure that each software component in the system startup process is verified to prevent malicious code execution. The system uses a secure boot mechanism to verify the firmware signature immediately after the device is powered on, then verifies the boot loader, kernel and key system components level by level to form a trust chain. Any component verification failure will trigger a preset security response, such as refusing to start or entering recovery mode. On the basis of secure boot, the system builds a multi-level trusted execution environment. First, the hardware isolated execution environment uses CPU security extensions (such as the secure virtualization technology of domestic Loongson processor) to create a physically isolated execution area. Sensitive algorithms and data are processed in this environment, which is protected at the hardware level to prevent access by the main operating system or other applications. The system implements memory encryption and integrity protection to ensure that even if the physical memory is directly accessed, the plaintext data cannot be obtained. Second, the trusted container environment is based on domestic container technology to build a lightweight isolated execution environment. The system extends the security functions of the container, implements runtime integrity protection, memory isolation and secure resource management. Each container is verified for integrity before starting to ensure that the container image has not been tampered with. The system also supports secure communication and resource isolation between containers to prevent horizontal attacks. Third, the trusted blockchain environment is built for scenarios that require multi-party collaboration based on a domestic blockchain framework. Through the consensus mechanism and smart contract, multi-party trust and operation integrity are achieved, which is particularly suitable for data sharing and joint analysis scenarios. A complete remote authentication mechanism is designed to allow remote verification of the authenticity and integrity of the execution environment. The authentication process uses national encryption algorithms to verify the trusted state of the execution environment through a challenge-response protocol. After successful authentication, a secure channel is established to ensure the safe transmission of sensitive data to the trusted environment for processing. The dynamic proof mechanism is supported to allow continuous verification of the trusted state of the environment during runtime to detect possible security state changes in a timely manner. To protect key algorithms, an algorithm protection mechanism is implemented. Core algorithms are encrypted in containers and decrypted and executed only in trusted execution environments. The system also supports code obfuscation and white-box cryptography to increase the difficulty of algorithm reverse analysis. For particularly sensitive algorithms, the system implements a segmented execution strategy to distribute the algorithm across multiple secure nodes for execution, and a single node cannot obtain the complete algorithm. The system also designs an exception monitoring and response mechanism to monitor the integrity and behavior characteristics of the execution environment in real time.Once a possible tampering attempt or abnormal access pattern is detected, a pre-set security response is triggered, such as isolating the affected components, switching to a backup environment, or securely destroying sensitive data. The secure trusted execution environment is tightly integrated with the aforementioned data protection and permission management, providing a trusted infrastructure support for data desensitization and privacy computation in step S5.4.

[0201] Step S5.4 is based on differential privacy and federated learning technology to realize privacy protection in data analysis process, support model training and inference without exposing original data, and obtain the autonomous controllable security framework. In this step, a multi-level data desensitization strategy is designed first, and appropriate desensitization methods are dynamically selected according to data sensitivity and use scenarios. Various technologies such as static desensitization, dynamic desensitization and format-preserving encryption are implemented. Static desensitization is applied to persistent storage data, and technologies such as field replacement, masking and truncation are used for permanent processing before data is stored in the database; dynamic desensitization is applied to query results and interface returns, and desensitization rules are applied in real time to protect sensitive information from being viewed by unauthorized users; format-preserving encryption preserves data format and features while implementing encryption, such as encryption methods that preserve phone number formats, protecting original data while maintaining application compatibility. An intelligent desensitization engine based on semantic understanding is innovatively implemented, which can identify sensitive information (such as personal identification information and location information) in text and automatically apply corresponding desensitization strategies. The engine uses domestic natural language processing models to support accurate identification and desensitization of Chinese text, significantly improving the privacy protection capabilities of unstructured data. Based on desensitization, a differential privacy computing framework is constructed to provide privacy protection for data analysis. A privacy budget manager is implemented to control overall privacy loss, dynamically allocate privacy budgets, and ensure that the cumulative privacy loss of multiple queries does not exceed the pre-set threshold. The noise injection engine adds precisely calibrated random noise to query results based on the Laplace mechanism and Gaussian mechanism to protect individual data from being inferred. The sensitivity analyzer automatically calculates the sensitivity of the query to optimize the amount of noise added, maximizing data availability while ensuring privacy protection. The application of differential privacy in time series data analysis is particularly optimized, and a time series publishing mechanism that meets privacy protection requirements is implemented to support trend analysis and anomaly detection for key businesses. For scenarios that require multi-party data collaboration, an autonomous and controllable federated learning platform is constructed, including federated modeling services, secure aggregation protocols, and model security evaluation modules. The federated modeling service supports horizontal federated learning (same features, different samples) and vertical federated learning (different features, same sample ID), adapting to different data distribution scenarios. The secure aggregation protocol is based on the model parameter secure aggregation implemented by the national cryptographic algorithm, ensuring that participants cannot access the original gradient of other parties and can only obtain the aggregated result. The model security evaluation detects whether the federated model has privacy leakage risks, such as member inference attack protection, to ensure that the model training process does not indirectly leak original data information. A secure multi-party computation framework based on homomorphic encryption is also implemented to support data analysis in an encrypted state. The framework uses domestic lattice cryptography algorithms and is specially optimized to reduce computational overhead. It provides secure implementations of common data analysis operations such as secure connection, secure aggregation and secure statistical analysis, enabling analysts to complete analysis tasks without accessing original data.To improve practicality, a privacy computing development kit is designed to allow developers to use APIs similar to conventional data processing, which is automatically converted to privacy protection implementation. At the same time, a privacy risk assessment tool is provided to help administrators balance the balance point between data utility and privacy protection, and adjust the protection strength according to business needs. A compliance verification mechanism based on zero-knowledge proof is also implemented, which allows third-party auditors to verify whether the privacy protection measures are effectively implemented without accessing the sensitive data itself, solving the contradiction between privacy protection and compliance audit. Data desensitization and privacy computing technology together with the foregoing security measures constitute a complete self-controllable security framework, providing privacy protection capability for intelligent decision-making and closed-loop control in step S6, ensuring the protection of data sovereignty while realizing the value of data.

[0202] In an embodiment of the present application, in step S5.2, based on the data sovereignty protection system, a role and attribute-based fine-grained permission control system is constructed to support three-layer permission isolation of resource level, operation level and data level, and an access control system of the least privilege principle is obtained, including:

[0203] Step S5.2.1. Based on identity authentication requirements, implement a two-way identity authentication protocol of the national SM2 algorithm, ensure that the identities of both parties are real and trustworthy, support hardware-level identity authentication based on domestic security chips for high-security-level scenarios, and obtain a multi-factor identity authentication mechanism. In this step, first, analyze the identity authentication requirements of different scenarios, design a layered authentication strategy according to factors such as resource sensitivity, access frequency, and use environment. For ordinary resource access, a basic authentication method is used; for sensitive operations and high-value resources, a more stringent multi-factor authentication is required. A two-way identity authentication protocol is implemented based on the national SM2 elliptic curve algorithm, which not only verifies the user's identity, but also verifies the service side's identity to prevent phishing attacks and man-in-the-middle attacks. The authentication process uses a challenge-response mechanism, the service side sends a random challenge value to the user, the user returns after signing with a private key, and the service side verifies the signature to confirm the user's identity; at the same time, the user also sends a challenge to the service side to verify the service side's identity. A digital certificate system based on the national SM2 algorithm is implemented, including complete life cycle management of certificate application, issuance, verification, update, and revocation. The certificate uses the national SM3 algorithm to calculate the digest to ensure the integrity of the certificate. Support for the Online Certificate Status Protocol (OCSP) and Certificate Revocation List (CRL) to verify the validity of the certificate in real time. For high-security-level scenarios, support hardware-level identity authentication based on domestic security chips. The user's private key is stored in the security chip and cannot be exported, and all cryptographic operations are completed in the chip, effectively preventing private key leakage and cloning attacks. Support for a variety of domestic security chips, such as financial IC cards, smart password keys, and secure smart cards, to meet the needs of different application scenarios. A multi-factor authentication framework is implemented, supporting flexible combinations of knowledge factors (such as passwords, PIN codes), possession factors (such as digital certificates, hardware tokens), and biological factors (such as fingerprints, faces). The authentication strength can be dynamically adjusted according to the risk assessment results, and high-risk operations automatically trigger stricter authentication requirements. Context-aware authentication is also supported, considering environmental factors such as access time, location, device characteristics, and imposing additional authentication requirements on abnormal access patterns. To improve user experience, a single sign-on (SSO) mechanism is implemented, allowing users to access multiple authorized resources with a single authentication, reducing the hassle of repeated authentication. At the same time, adaptive authentication is supported, based on user behavior patterns and risk scores, requiring additional authentication only when necessary, balancing security and convenience. An authentication failure handling mechanism is also designed, including account locking, step-by-step delay, and abnormal alarm measures, effectively preventing brute force cracking and dictionary attacks. Through these technologies, a powerful and flexible multi-factor identity authentication mechanism is constructed, providing a reliable identity basis for subsequent permission control.

[0204] Step S5.2.2 implements resource isolation based on network segmentation and security domains, adopts the default rejection principle, and each resource access request is subjected to fine-grained policy evaluation to obtain resource-level permission control. In this step, first, all resources are comprehensively sorted and classified, including computing resources (such as servers, virtual machines), storage resources (such as databases, files), network resources (such as routers, switches), and application resources (such as APIs, services), etc. According to the sensitivity, importance and functional correlation of the resources, the resources are divided into multiple security domains, such as core production domain, management domain, development and test domain, and external access domain, etc. Network segmentation-based resource isolation technology is implemented, which adopts a combination of physical isolation and logical isolation. Physical isolation is implemented through independent network equipment and communication links, which is suitable for core resources with high security requirements; logical isolation is implemented through VLAN, VPN and software-defined network (SDN) technologies, providing flexible resource segmentation capabilities. A multi-level network boundary protection is designed, including firewall, intrusion detection, web application firewall and other security devices, which strictly controls cross-domain communication. Communication between each security domain must pass through a clearly defined security gateway and be subject to access control policies. The "default rejection" security principle is adopted, that is, unless explicitly allowed, all resource access is prohibited. Although this approach requires a large amount of initial configuration, it effectively prevents unauthorized access and significantly reduces security risks. A policy-based resource access control engine is implemented, and each resource access request is subjected to fine-grained policy evaluation. The evaluation process considers multiple factors, including request source (such as user identity, source IP address), target resource characteristics (such as sensitivity level, domain to which it belongs), access time, access method and current state, etc. Complex condition combinations and policy expressions are supported, enabling fine-grained control requirements such as "only allow users from a specific department to access certain resources through the intranet during working hours". To improve management efficiency, a policy template and inheritance mechanism is implemented, allowing administrators to define generic policy templates and then make individual adjustments based on specific resource characteristics. A policy conflict detection and resolution mechanism is also supported, which automatically identifies and handles potential policy conflicts to ensure the consistency of access control rules. An emergency response mechanism for resource access control is designed, which can quickly adjust access policies when security threats are detected, such as temporarily blocking specific resources or limiting access scope. At the same time, version control and rollback functions are supported for policies, facilitating the restoration of normal access rules after an emergency is resolved. Comprehensive resource access audit logs are also implemented, recording all resource access requests and policy evaluation results, providing detailed evidence for security analysis and compliance auditing. Through these technologies, a strict and flexible resource-level permission control system is built, effectively ensuring the secure access of resources.

[0205] Step S5.2.3. Role-based access control predefines multiple roles, each associated with a specific set of operation permissions, implements role hierarchy and separation of duties principles, prevents excessive concentration of permissions, and achieves operation-level permission control. In this step, first, typical user roles in the system are identified through business process analysis and user access demand research. These roles are usually defined based on organizational structure (such as department manager, ordinary employee), functional responsibilities (such as administrator, security auditor), or business processes (such as data entry clerk, approval personnel), etc. A set of basic roles is predefined, covering common use scenarios, while providing a role customization mechanism to allow the creation of new roles according to specific needs. Each role is associated with a specific set of operation permissions, clearly defining the types of operations that the role can perform. The operation permission granularity is accurate to specific functions, such as "view report", "modify configuration", "approve application", etc. The "least privilege" principle is adopted, each role is only granted the minimum set of permissions necessary to complete its duties, avoiding excessive allocation of permissions. A role hierarchy structure is implemented, supporting inheritance relationships between roles. Senior roles can inherit all the permissions of lower-level roles and have additional privileged operations, simplifying the complexity of permission management. Multiple role hierarchy models are supported, including tree hierarchy (strict superior-inferior relationship) and lattice hierarchy (allowing multiple inheritance), adapting to the management needs of different organizations. The separation of duties principle is strictly enforced to ensure that sensitive operations require the cooperation of multiple different roles, preventing a single role from abusing its powers. Static separation of duties (prohibiting the same user from simultaneously possessing conflicting roles) and dynamic separation of duties (prohibiting the same user from playing multiple conflicting roles in the same business process) are supported, comprehensively preventing the risk of abuse of power. A role-based operation authorization mechanism is implemented, users indirectly obtain operation permissions through assigned roles. A user can be assigned multiple roles, and their maximum permissions are the union of all role permissions. Temporary role assignment and time limits are supported, allowing users to temporarily obtain certain role permissions within a specific time period, meeting temporary work needs while avoiding long-term over-privilege. A workflow for role management is designed, including role creation, permission configuration, role assignment, regular review, and role recovery, etc. In particular, for high-privilege roles, a more stringent allocation approval process and regular review mechanism is implemented to ensure the rationality of permission allocation. Role usage monitoring and analysis functions are also implemented, which can identify long-term unused roles and permissions, support optimization of role design based on actual usage. Role conflict detection is supported, automatically identifying role combinations that may violate the separation of duties principle, and providing warnings and suggestions to administrators. Through these technologies, a complete operation-level permission control system is built, which not only guarantees the security of operations, but also provides flexible and efficient permission management capabilities.

[0206] Step S5.2.4 adopts attribute-based access control, dynamically evaluates access permissions based on user attributes, data attributes, and environmental attributes, supports data access control at row level, column level, and cell level, and obtains data-level permission control. In this step, a comprehensive attribute model is first designed, including user attributes (such as identity, position, department, and security level), data attributes (such as sensitivity, owner, and classification label), and environmental attributes (such as time, location, device type, and network security status). Static attributes (such as user department) and dynamic attributes (such as current time and load) are supported for combined use, enabling context-aware access control. An attribute management framework is implemented, including attribute definition, attribute acquisition, attribute verification, and attribute caching functions. Attributes can come from multiple sources, such as identity management, organizational structure database, resource metadata database, and environmental perception components. Real-time attribute querying and periodic synchronization are supported to ensure that the latest attribute values are used for decision-making. An attribute-based policy language is designed, supporting complex conditional expressions and rule combinations. Policies can express fine-grained access rules such as "allow doctors in the medical department to view non-sensitive medical records of their responsible patients during working hours." Modular organization and reuse of policies are supported to simplify policy management in complex scenarios. A high-performance policy evaluation engine is implemented, capable of handling a large number of access requests in real time. The evaluation engine uses optimized algorithm structures such as decision trees and rule indexes to speed up the policy matching process. Policy evaluation result caching is also supported to further improve response speed in frequent access patterns. In terms of data access control, three levels of granularity are supported: row-level control limits the range of data records that users can access, such as "only view customer data in the department"; column-level control limits the data fields that users can access, such as "view basic information but not salary information"; and cell-level control is the most fine-grained control, limiting data access at specific row-column intersections, such as "only view budget data for projects you are responsible for." A data filtering and conversion mechanism is implemented to automatically apply access control rules before query results are returned, removing or sanitizing unauthorized data content. This mechanism seamlessly integrates with databases and applications, transparent to users and developers. Dynamic adjustment of data access control is supported, automatically updating data access policies based on data lifecycle, business process status, and risk assessment results. For example, after a data breach occurs, the protection level of related data can be automatically increased to limit access. A data access delegation and transfer mechanism is also designed, allowing data owners to temporarily authorize other users to access their data while maintaining the auditability of access activities. Comprehensive data access audit logs are implemented, recording all data access requests, policy evaluation processes, and access results, supporting post-auditing and compliance checking. Through these technologies, a fine, flexible, and high-performance data-level permission control system is built, effectively protecting sensitive data security while meeting the access needs of complex business scenarios.

[0207] Step S5.2.5. Based on the data-level permission control, through periodic permission review and automatic recycling mechanism, ensure that users only hold the necessary minimum set of permissions, dynamically adjust the strictness of the permission policy according to threat intelligence and abnormal behavior detection, and obtain the access control system of the principle of minimum permission. In this step, first, a comprehensive permission life cycle management framework is designed, covering the complete process of permission application, approval, allocation, use, review and recycling. A workflow-based permission application and approval mechanism is implemented, users need to specify the purpose and duration of the permission, and the approval process may require multi-level review according to the sensitivity of the permission. Support for automatic expiration of permissions, temporary permissions automatically expire after a predetermined time without the need for manual recycling, reducing the risk of long-term permission accumulation. A periodic permission review system is established to regularly check whether the permissions held by users are still necessary. The review process takes into account various factors, including permission usage frequency, user role changes, and business demand changes. Provide permission usage analysis tools to automatically identify long-term unused permissions and generate recycling suggestions to assist administrators in optimizing permissions. An automatic recycling mechanism for permissions is implemented to automatically remove permissions that are no longer needed according to preset rules. Conditions for triggering recycling include user role changes, organizational structure adjustments, project completion, or long-term non-use. Before recycling permissions, impact analysis is performed to assess the impact of recycling on user work, and if necessary, provide a transition period or alternative solution. A dynamic permission adjustment mechanism based on risk is designed to dynamically adjust the strictness of the permission policy according to the real-time security situation. Integrate threat intelligence sources to obtain the latest security threat information, and automatically increase the access control strength of related resources when detecting specific types of threats. Implement user behavior analysis and anomaly detection functions to establish a baseline model of user access behavior and identify abnormal activities that deviate from the normal pattern. When detecting suspicious behavior, you can temporarily restrict user permissions, require additional verification, or trigger a security review process. Support for environment-aware permission adjustment, dynamically adjust the permission scope according to the security status of the access environment. For example, limit sensitive operations when accessing from an insecure network, and reduce data access levels when using unauthenticated devices. An emergency response mode is also implemented that can quickly activate a preset restrictive permission policy when a serious security event is detected, such as retaining only core business functions, suspending non-critical access, until the threat is resolved. Provide a comprehensive permission management dashboard to display permission allocation status, usage, and risk assessment results, helping administrators have a comprehensive understanding of permission status and timely identify potential problems. Also support permission compliance checks to automatically verify whether permission allocation complies with organizational policies and external regulatory requirements, generate compliance reports to assist audit work. Through these technologies, a dynamic access control system is built that follows the principle of minimum permission, ensuring security while minimizing the operational burden of permission management, improving overall security and usability.

[0208] In an embodiment of the present application, in step S5.4, the differential privacy and federated learning technology is used to realize privacy protection in the data analysis process, support model training and inference without exposing the original data, and obtain the autonomous controllable security framework, including:

[0209] Step S5.4.1 Based on data sensitivity analysis, dynamically select desensitization methods including static desensitization, dynamic desensitization, and format-preserving encryption according to data sensitivity and usage scenarios, realize intelligent desensitization based on semantic understanding, and obtain the desensitized data set. In this step, a comprehensive data classification and grading system is established, and each type of data in the system is evaluated and classified for sensitivity. The evaluation process considers multiple factors, including data content types (such as personal identification information, business secrets, operating parameters, etc.), the impact of data leakage, applicable legal and regulatory requirements (such as GDPR, data security law, etc.), and the organization's internal data protection policies. A multi-dimensional classification method is adopted to divide the data into different sensitivity levels such as public, internal, confidential, and secret, and define corresponding protection requirements and processing rules for each level. Based on the results of data sensitivity analysis, multiple desensitization technologies are implemented, and the most suitable method is dynamically selected according to the data characteristics and usage scenarios. For sensitive data that needs to be stored for a long time, static desensitization technology is adopted to permanently process the data before it is stored in the database. Static desensitization methods include data masking (such as replacing the middle digits of a credit card number with asterisks), data generalization (such as replacing the exact age with an age range), pseudonymization (replacing real identity information with unique identifiers), and randomization (adding random noise while maintaining statistical properties). These methods protect sensitive information while preserving the analytical value of the data as much as possible. For query results and interface returned data, dynamic desensitization technology is adopted to apply desensitization rules in real time before the data is displayed or transmitted. Dynamic desensitization adjusts the desensitization level according to user permissions and access context, achieving fine-grained data protection. For example, ordinary users viewing customer information can only see part of the desensitized phone number, while customer service supervisors can view the complete information. Context-aware dynamic desensitization is also supported, which dynamically adjusts the desensitization strategy based on access environment (such as internal network or external network), device security status, and risk assessment results. For scenarios that require privacy protection while maintaining data format and functional characteristics, format-preserving encryption technology is implemented. This technology encrypts sensitive data while preserving the format characteristics of the original data, such as data type, length, and part of the structure, ensuring that the encrypted data remains compatible with existing applications. For example, format-preserving encryption of social security numbers generates seemingly valid but actually invalid numbers, maintaining the original format while completely protecting the real information. An innovative intelligent desensitization engine based on semantic understanding is implemented, which can automatically identify sensitive information in unstructured text. The engine uses domestic natural language processing models to accurately identify personal identification information, location information, financial information, and other sensitive content in the text through named entity recognition, relationship extraction, and semantic analysis, and automatically applies the corresponding desensitization strategy. It supports deep semantic understanding of Chinese text and can handle complex language expressions and context relationships, greatly improving the accuracy and efficiency of unstructured data desensitization.The desensitization effect evaluation and audit mechanism is also implemented, which verifies the security of the desensitized data through simulation attacks and privacy risk assessment; at the same time, through data utility testing, the influence of desensitization on data analysis value is evaluated, and the best balance point between privacy protection and data availability is found. Through these technologies, a desensitized data set that protects sensitive information and maintains analysis value is generated, laying the foundation for subsequent secure data analysis.

[0210] Step S5.4.2. Based on the desensitized data set, a differential privacy computing framework is constructed, including a privacy budget manager, a noise injection engine and a sensitivity analyzer, to provide privacy protection for data analysis and obtain differential privacy computing capability. In this step, the theoretical framework of differential privacy is first implemented, which is a strict mathematical privacy protection mechanism that can provide provable privacy protection during data analysis. The core idea of differential privacy is to add precisely calibrated random noise to the query result, making it impossible to determine whether any specific individual is included in the data set, thereby protecting individual privacy. A complete differential privacy computing framework is designed, including three core components: a privacy budget manager, a noise injection engine and a sensitivity analyzer. The privacy budget manager is responsible for controlling the overall privacy loss, and implements the allocation and tracking of the privacy budget. A global privacy budget model is adopted to set the overall privacy budget for the entire setting The manager dynamically allocates budgets based on query type, importance, and frequency. It tracks budget consumption in real-time and automatically increases query limits or noise levels when accumulated privacy loss approaches a preset threshold, ensuring overall privacy protection. It also supports differentiated budget allocation based on user roles and data sensitivity, providing flexible privacy protection strategies for different types of queries and analysis tasks. The noise injection engine, responsible for adding random noise to query results, is a core component of differential privacy. It implements various noise mechanisms, including Laplace (for numerical results), exponential (for non-numerical selections), and Gaussian (for multiple queries). The noise injection process precisely controls noise distribution and scale, ensuring sufficient noise for privacy protection while minimizing impact on data analysis accuracy. The noise injection algorithm is optimized with adaptive noise adjustment, dynamically optimizing noise parameters based on query complexity and data characteristics to improve the usability of query results. The sensitivity analyzer calculates query sensitivity—the maximum impact a change in a single record might have on the query results—a key parameter for determining noise levels. It implements automatic sensitivity analysis technology, capable of analyzing the sensitivity of SQL queries, statistical functions, and machine learning algorithms. For complex queries, query decomposition and sensitivity combination techniques are employed to break down complex queries into basic operations, calculate the sensitivity of each operation, and then combine them appropriately. Smoothing sensitivity calculations are also supported to reduce excessive noise addition in extreme cases, improving the usability of query results. The application of differential privacy in time-series data analysis, a key data type in digital twins, has been specifically optimized. Event-level and user-level differential privacy protection is implemented, supporting privacy protection under continuous observation, overcoming the limitations of traditional differential privacy in time-series data. A sliding window mechanism and correlation analysis are used to preserve the trend characteristics of time-series data while protecting privacy, supporting key business operations such as trend analysis, anomaly detection, and predictive modeling. Confidence interval estimation of differential privacy query results is also implemented, providing analysts with quantitative indicators of result reliability to assist in the decision-making process. Through these technologies, a powerful differential privacy computing capability is built, providing strict privacy protection while maximizing the accuracy and effectiveness of data analysis.

[0211] Step S5.4.3 builds a federated learning platform, including federated modeling service, secure aggregation protocol and model security evaluation, supporting horizontal federated learning and vertical federated learning, and obtaining multi-party collaborative learning capability. In this step, the federated learning technology is implemented, which is an innovative method for multi-party data collaboration modeling under the premise of protecting data privacy. The core idea of federated learning is "data does not move, model moves", and each participant keeps the data locally stored and only exchanges model parameters or gradient information, so as to realize collaborative learning without sharing original data. A complete federated learning platform is built, including three core components: federated modeling service, secure aggregation protocol and model security evaluation. The federated modeling service is the core functional module of the platform, which supports multiple federated learning modes. Horizontal federated learning is implemented, which is suitable for the scenario where participants have the same features but different samples, such as different hospitals having similar patient data structures. At the same time, vertical federated learning is also supported, which is suitable for the scenario where participants have the same sample ID but different features, such as banks and e-commerce platforms having different dimension information of the same batch of users. A flexible federated learning framework is designed, which supports the federated implementation of multiple machine learning algorithms, including linear models, decision trees, neural networks and deep learning models, etc. The framework adopts modular design, which decomposes the model training process into basic operations that can be federated, realizing flexible combination and extension of algorithms. The communication efficiency of federated learning is also optimized, adopting gradient compression, sparse update and asynchronous aggregation technologies to reduce communication overhead and adapt to the needs of different network environments. The secure aggregation protocol is a key component to ensure the security of the federated learning process. Based on the SM2 algorithm of the national cryptography standard of China, the secure aggregation protocol is designed to protect the privacy of model parameters and gradient information during transmission, ensuring the security of the federated learning process. The algorithm implements a secure model parameter aggregation mechanism to ensure that any participant cannot obtain the original gradient or parameter of other parties during the aggregation process. By combining secret sharing and homomorphic encryption, an efficient and secure parameter aggregation is achieved. Secret sharing technology divides each participant's model update into multiple shares and distributes them to other participants. Only enough shares can restore the complete information. Homomorphic encryption allows direct parameter aggregation calculation in encrypted state, further enhancing security. A secure multi-party computation protocol is also implemented, which supports complex joint calculations such as secure feature selection, secure model evaluation, and secure prediction while protecting privacy. Model security evaluation is an important component to prevent potential privacy risks in federated learning. A comprehensive federated model security evaluation mechanism is implemented to detect whether the model has privacy leakage risks. It supports member inference attack protection to prevent attackers from determining whether a specific sample participated in training through model output. It also implements model reverse attack protection to prevent extracting training data information from model parameters. It also supports attribute inference protection to prevent inferring sensitive attribute information. By using differential privacy, gradient clipping, and knowledge distillation, the privacy protection capability of the federated model is enhanced, effectively resisting various privacy attacks while maintaining model performance. A fair incentive mechanism for federated learning is also designed, which reasonably allocates model rights based on the data quality, computing contribution, and model improvement effect of participants, promoting active participation and contribution of high-quality data. Through these technologies, a secure and efficient federated learning platform is built, achieving the goal of fully leveraging the value of multi-party data collaboration while protecting data privacy and ownership.

[0212] Step S5.4.4 is based on the domestic lattice cryptography algorithm to realize the secure multi-party computation framework of homomorphic encryption, which supports data analysis in an encrypted state and obtains encrypted computing capabilities. In this step, homomorphic encryption technology is realized, which is a revolutionary cryptography technology that allows direct computation on encrypted data without decryption first. The core advantage of homomorphic encryption is to protect data privacy while performing data analysis and computation, solving the contradiction between data use and data protection. Based on the domestic lattice cryptography algorithm, a self-controllable homomorphic encryption framework is constructed. Lattice cryptography is a cryptographic system based on lattice theory in mathematics, which has the potential to resist quantum computing attacks and is an important candidate for post-quantum cryptography. A lattice-based fully homomorphic encryption (FHE) scheme is implemented, which supports arbitrary computation in an encrypted state. At the same time, a partial homomorphic encryption (PHE) scheme is also implemented, such as Paillier encryption supporting addition and ElGamal encryption supporting multiplication, which provides a more efficient solution in specific scenarios. The domestic lattice cryptography algorithm is deeply optimized to improve encryption and computing efficiency. Optimization measures include key generation optimization, parameter selection optimization, polynomial multiplication acceleration, and parallel computing techniques, which significantly reduce the performance overhead of homomorphic computation. An automatic parameter selection mechanism is also implemented, which automatically selects the most suitable encryption parameters according to security requirements and performance requirements, balancing security and efficiency. Based on the optimized homomorphic encryption algorithm, a complete secure multi-party computation framework is constructed, which supports various data analysis operations in an encrypted state. Basic operations of encrypted data are implemented, including addition, subtraction, multiplication, and comparison operations. On this basis, more complex secure computing functions are constructed, such as secure join query, secure aggregation statistics, secure set operation, and secure sorting. The application of homomorphic encryption in machine learning is particularly optimized, implementing linear regression, logistic regression, and simplified neural network algorithms in an encrypted state, supporting model training and prediction while protecting data privacy. A hybrid computing strategy is designed, combining homomorphic encryption with other privacy protection technologies (such as secure multi-party computation and federated learning), selecting the most suitable technology in different computing stages to optimize overall performance and security. For example, federated learning is used in data preprocessing, homomorphic encryption is used in model training, and zero-knowledge proof is used in result verification, forming a complementary privacy protection system. Key management and access control mechanisms are implemented to ensure the secure use of homomorphic encryption. Key management includes the complete life cycle of key generation, distribution, storage, and revocation; access control ensures that only authorized users can obtain decryption results, preventing abuse of authority. A threshold decryption mechanism is also supported, requiring multiple key holders to authorize decryption results, further enhancing security. A development-friendly encryption computing interface is provided, allowing developers to use encrypted data as ordinary data.The encrypted query interface of the SQL syntax is implemented, and the execution of the standard SQL query statement on the encrypted data is supported. Meanwhile, the programming API is provided, and the encrypted calculation function is directly called in the application code. The performance monitoring and optimization suggestion function is also implemented, and the performance characteristics of the encrypted calculation are understood and optimized by the developer. Through these technologies, the powerful encrypted calculation capability is constructed, the goal of efficient data analysis under the premise of protecting the data privacy is achieved, and the innovative solution is provided for the safe use of the sensitive data.

[0213] Step S5.4.5, based on the encryption computing capability, implements a compliance verification mechanism based on zero-knowledge proof, allowing third-party auditors to verify whether privacy protection measures are effectively implemented, obtaining privacy protection verification capability. In this step, zero-knowledge proof technology is implemented, which is an advanced cryptography technology that allows one party (prover) to prove to another party (verifier) that a certain statement is true without revealing any information other than the truth of the statement. The unique value of zero-knowledge proof is to be able to verify compliance without revealing sensitive information, solving the contradiction between privacy protection and compliance audit. Based on zero-knowledge proof technology, a comprehensive privacy protection verification framework is constructed. This framework supports multiple types of compliance verification requirements, including data processing compliance (verifying that data processing complies with pre-defined rules and policies), algorithm execution compliance (verifying that algorithms are executed as declared), and result correctness (verifying the accuracy of the calculation result). Multiple zero-knowledge proof protocols are implemented, including interactive zero-knowledge proof and non-interactive zero-knowledge proof. Interactive protocols are suitable for real-time verification scenarios, with the prover and verifier completing verification through multiple rounds of interaction; non-interactive protocols generate one-time proofs, suitable for offline audit scenarios, where the verifier can independently verify the validity of the proof at any time. The zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) technology is particularly optimized, enabling efficient and compact proof generation and verification. A modular proof generation framework is designed to support the conversion of complex compliance requirements into provable computation circuits. A circuit compiler is implemented to automatically convert high-level language descriptions of compliance rules into arithmetic or Boolean circuits, significantly simplifying the application difficulty of zero-knowledge proof. Multiple types of compliance verification scenarios are supported. In data desensitization verification, it can be proved that the desensitization process is correctly executed and meets the pre-defined desensitization rules without revealing the original sensitive data; in differential privacy verification, it can be proved that the noise addition meets the differential privacy requirements, and the noise amount and distribution meet the privacy budget constraints; in federated learning verification, it can be proved that the model aggregation process is correct and the participants comply with the protocol specified computation steps; in encryption calculation verification, it can be proved that the calculation performed on encrypted data is consistent with the declared operation and the result is accurate. A hierarchical verification mechanism is implemented to support different levels of compliance verification. Basic-level verification ensures that basic data processing rules are followed; intermediate-level verification adds verification of algorithm execution process; high-level verification includes comprehensive data flow and computation logic verification, providing the most stringent compliance guarantee. Different verification levels correspond to different computational complexity and proof generation costs, and users can choose appropriate verification levels according to actual needs. An audit-friendly verification interface is designed to allow third-party auditors to verify the effective implementation of privacy protection measures without accessing sensitive data.The verification interface provides intuitive verification result display, including verification status, coverage range and possible problem warnings; at the same time, a detailed verification report is generated, recording the verification process and results, meeting the compliance document requirements. It also supports public release and verification of verification results, allowing the public or regulatory authorities to independently verify compliance, enhancing credibility and transparency. Through these technologies, a strong privacy protection verification capability is built, achieving the goal of meeting compliance audit requirements while protecting data privacy, providing an innovative solution for data privacy protection and compliance supervision.

[0214] In an embodiment of the present application, in step S6, the integrated real-time sensor data and the enhanced digital twin model output with high generalization are analyzed by multi-modal data fusion, abnormal patterns are identified and decision suggestions are generated, and precise management of physical entities is realized through closed-loop control, including:

[0215] Step S6.1 integrates real-time sensor data and the enhanced digital twin model output, and obtains a comprehensive view of the state of the physical entity through time alignment and feature fusion. In this step, first, the mapping relationship between real-time sensor data and digital twin model output is established to ensure the consistency of the two data sources in terms of semantics and structure. Multi-level time alignment technology is used to solve the differences in time scale and sampling frequency between real-time data and model output. For high-frequency sampled sensor data, sliding window aggregation or downsampling processing is used to match the time granularity of the model output; for low-frequency sampled sensor data, model interpolation or state estimation methods are used to supplement the time points. An adaptive time window mechanism is implemented, which dynamically adjusts the alignment window size according to the data change rate, using a small window to retain details during rapid changes and a large window to reduce redundancy during stable periods. Feature fusion uses a multi-level strategy, including data-level fusion, feature-level fusion and decision-level fusion. Data-level fusion directly combines the original measurement values and model predictions to obtain more accurate state estimates through weighted averaging or Kalman filtering; feature-level fusion extracts key features from sensor data and model output, combining them through feature splicing, feature transformation or attention mechanisms to form enhanced feature representations; decision-level fusion is based on independent state judgments from different data sources, using voting, Bayesian inference or fuzzy logic to reach a comprehensive conclusion. A data reliability evaluation mechanism is also implemented, which dynamically adjusts the weights of different data sources, increasing the weight of sensor data when its quality is high, and increasing the weight of model output when sensor data is abnormal or missing. During the fusion process, the uncertainty information of the original data is preserved, generating state estimates with confidence intervals to provide risk assessment for subsequent decision-making. Finally, a comprehensive view of the state of the physical entity is generated, including current state parameters, state trends, abnormal indicators and state predictions, providing a comprehensive data foundation for anomaly detection and decision support.

[0216] Step S6.2. Based on the comprehensive view reflecting the state of the physical entity and the multi-path evolution trajectory predicted by the branched digital twin model, design an anomaly detection algorithm to identify trends deviating from the normal operation interval, and obtain a hierarchical early warning signal. In this step, first, based on historical data and expert knowledge, define the normal operation interval for each key parameter of the physical entity, including static thresholds and dynamic boundaries. Static thresholds are set based on equipment specifications and safety standards, while dynamic boundaries take into account operating conditions, load states, and environmental factors, and can automatically adjust with operating conditions. Adopt a multi-modal anomaly detection framework, combining rule-based methods, statistical learning methods, and deep learning methods to identify abnormal patterns from different perspectives. Rule-based methods apply domain expert knowledge to detect specifically defined abnormal states; statistical learning methods such as one-class SVM and isolation forest detect abnormal points in data distribution; deep learning methods such as autoencoders and generative adversarial networks can capture complex nonlinear abnormal patterns. Pay special attention to trend anomalies, identify situations where parameters have not yet exceeded thresholds but show abnormal trends through time series analysis and trend prediction techniques, and achieve early warning. Innovatively use the multi-path prediction capability of the branched digital twin model to calculate the deviation of the actual observation trajectory from each predicted path, and trigger an anomaly alert when the observation trajectory deviates from all expected paths or deviates towards undesirable paths. Realize anomaly correlation analysis, which can identify abnormal correlation patterns between multiple parameters, distinguish between independent and dependent anomalies, and improve the accuracy and interpretability of anomaly detection. Based on the detected anomaly type, severity, and development speed, generate a hierarchical early warning signal, usually divided into five levels: prompt, slight, moderate, severe, and urgent. Each early warning signal contains detailed information such as anomaly description, possible causes, impact range, and recommended measures, providing sufficient basis for subsequent decision-making. Also realize early warning priority management, when multiple anomalies occur simultaneously, determine the processing order according to the risk assessment results to ensure that the most critical issues are given priority. Through this comprehensive anomaly detection and early warning mechanism, the abnormal state and potential risks of the physical entity can be discovered in a timely manner, providing decision support for proactive intervention and fault prevention.

[0217] Step S6.3. For the detected hierarchical early warning signals or optimization needs, multi-scenario simulation is performed using the enhanced digital twin model with high generalization capability, multiple sets of intervention measures are generated, and the effectiveness and risks of each scheme are predicted and evaluated by the enhanced digital twin model with high generalization capability, and the optimal decision scheme is obtained. In this step, first, according to the type and level of the early warning signal, the emergency degree and range of intervention are determined. For high-level early warning, the emergency response process is immediately started; for low-level early warning, the regular decision-making process is entered. Based on the pre-defined intervention measure library and historical successful cases, combined with the current specific situation, an initial set of intervention schemes is generated. These schemes include parameter adjustment schemes (such as adjusting temperature, pressure, and other control parameters), operation adjustment schemes (such as changing working mode, adjusting load, etc.), and maintenance intervention schemes (such as starting specific maintenance programs, replacing components, etc.). Using the simulation capability of the enhanced digital twin model, "hypothesis-deduction" analysis is performed on each candidate scheme to simulate the response and evolution process after the implementation of the intervention measures. The simulation process considers various uncertain factors such as parameter fluctuations, environmental changes, and operation errors, etc. Through Monte Carlo method or scenario tree analysis technology, the prediction results containing uncertainties are generated. The simulation results are evaluated in multiple dimensions, including effect evaluation (problem solving degree), risk evaluation (potential negative impact), resource evaluation (required time and cost), and feasibility evaluation (implementation difficulty and success rate). The evaluation adopts multi-criteria decision analysis method, considering various factors, and generates a comprehensive score for each scheme. The combination effect between schemes is also analyzed to identify possible synergistic schemes, and a more optimal comprehensive scheme is formed by combining multiple basic intervention measures. Based on the evaluation results and decision preference settings (such as risk aversion degree, cost sensitivity, etc.), the optimal decision scheme is selected, and a detailed implementation plan is generated, including operation steps, time schedule, resource requirements, and risk control measures, etc. For complex situations, a human-machine collaborative decision-making mode is supported, providing decision-making suggestions and basis, and the final decision is made by human experts. Through this model-based decision support process, scientific and reliable intervention schemes can be quickly generated when facing various abnormal situations and optimization needs, improving the quality and efficiency of decision-making.

[0218] Step S6.4 transforms the optimal decision scheme into specific control instructions, transmits them to the physical entity through the secure channel for execution, and collects execution feedback data to continuously optimize the enhanced digital twin model with high generalization ability, and realizes precise management of the physical entity. In this step, the abstract decision scheme is first transformed into a specific control instruction sequence, including device control instructions, parameter adjustment instructions, and operation guidance instructions, etc. The transformation process considers the control interface characteristics and operation constraints of the physical entity to ensure that the instructions are executable and safe. The instruction decomposition and scheduling mechanism is implemented to decompose the complex intervention scheme into ordered basic operation steps and schedule them according to the dependency relationship and priority to form the optimal execution path. The control instructions are transmitted through the secure channel constructed in step S5, encrypted and digitally signed using the national encryption algorithm to ensure the confidentiality, integrity and non-repudiation of the instructions. A multi-level authorization mechanism is supported, and high-risk operations require multi-party authorization to execute to prevent misoperation and malicious attacks. The instruction execution adopts a gradual strategy, first executes the operation with less impact and observes the response, and then executes the key operation after confirming the safety to minimize the risk. Real-time monitoring and feedback collection mechanisms are implemented to closely track the instruction execution process and the physical entity response, including execution status, parameter changes and abnormal events, etc. When execution deviation or abnormal response is detected, subsequent instructions can be quickly adjusted or emergency plans can be started to ensure the safety and controllability of the intervention process. After execution is completed, a comprehensive effect evaluation is performed to compare the differences between the actual results and the expected targets, analyze the effectiveness and applicable conditions of the intervention measures. All data collected during the intervention, including initial state, intervention measures, response and final results, etc., are used for continuous optimization of the enhanced digital twin model. The optimization process uses online learning methods to update model parameters and knowledge bases in real time, continuously improving the prediction accuracy and generalization ability of the model. An intervention case library is also maintained to record detailed information and lessons learned from each intervention to provide a reference for future similar situations. Through this closed-loop control and continuous optimization mechanism, the governance capability of the physical entity can be continuously improved to achieve precise, efficient and safe intelligent control, maximizing the performance and value of the physical entity.

[0219] As shown in Figure 3 The present application also provides an autonomous controllable digital twin management system, comprising:

[0220] A data perception and collection module 100 is used to collect physical entity data in real time through multi-source sensors based on autonomous controllable edge computing devices and perform preliminary screening and preprocessing to obtain structured raw data streams.

[0221] A data pruning and processing module 200 is used to extract small-scale data samples from the structured raw data streams for initial training, build an importance scoring model, perform importance scoring extrapolation and adaptive pruning on the full data, and generate an optimized training data set.

[0222] The branching digital twin model construction module 300 is used for constructing a branching Schrodinger bridge neural network and parameterizing a plurality of time-dependent velocity fields based on the optimized training data set, obtaining a branching digital twin model expressing system multi-path evolution characteristics by jointly training shared parameters and branching-specific parameters.

[0223] The model enhancement and generalization module 400 is used for constructing a multi-experiment data set based on the branching digital twin model and training an equation discovery network, integrating the discovered mathematical law with the branching digital twin model, and forming an enhanced digital twin model with high generalization by constraint condition injection and model parameter regularization.

[0224] The security framework implementation module 500 is used for constructing a data full-life-cycle protection architecture based on domestic cryptographic algorithms and security chips, realizing multi-level permission management and control and privacy computing, and obtaining a self-controllable security framework.

[0225] The intelligent decision and control module 600 is used for integrating real-time sensing data and the enhanced digital twin model output with high generalization for multi-modal data fusion analysis, identifying abnormal patterns and generating decision suggestions, and realizing precise management of physical entities through closed-loop control.

[0226] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An autonomously controllable digital twin governance method, characterized in that, The method comprises the following steps: Based on the autonomous controllable edge computing device, real-time collection of physical entity data by multi-source sensors and preliminary screening and preprocessing are performed to obtain a structured raw data stream; From the structured raw data stream, a small-scale data sample is extracted for initial training, an importance scoring model is constructed, the importance scoring of full-quantity data is extrapolated and adaptively pruned, and an optimized training data set is generated; Based on the optimized training data set, a branched Schrodinger bridge neural network is constructed and a plurality of time-dependent velocity fields are parameterized, joint training of shared parameters and branch-specific parameters is performed, and a branched digital twin model expressing the multi-path evolution characteristics of the system is obtained; Based on the branched digital twin model, a multi-experiment data set is constructed and an equation discovery network is trained, the discovered mathematical law is integrated with the branched digital twin model, and through constraint condition injection and model parameter regularization, an enhanced digital twin model with high generalization is formed; wherein the formation of the enhanced digital twin model with high generalization includes: obtaining the core parameter variation range and constraint conditions of the physical entity, constructing a multi-dimensional parameter space mapping, and obtaining a parameter space representation model; based on the parameter space representation model, designing a symbolic regression-based equation discovery network containing three core modules of variable selection, expression generation and equation evaluation, to obtain the complete equation discovery network structure; based on the branched digital twin model, a plurality of groups of simulation experiment data are generated under different parameter configurations, a multi-experiment data set is constructed, and the equation discovery network is trained using the multi-experiment data set to obtain a mathematical equation describing the internal law; the discovered mathematical equation describing the internal law is integrated with the branched digital twin model, and through constraint condition injection and model parameter regularization, the generalization ability of the branched digital twin model in the parameter space is enhanced, to obtain the enhanced digital twin model with high generalization; Based on domestic cryptographic algorithms and secure chips, a data full-life-cycle protection architecture is constructed to realize multi-level permission management and control and privacy computing, and an autonomous controllable security framework is obtained; Integrating real-time sensor data with the output of the enhanced digital twin model with high generalization for multi-modal data fusion analysis, identifying abnormal patterns and generating decision recommendations, and through closed-loop control, precise management of the physical entity is realized.

2. The method of claim 1, wherein, The real-time collection of physical entity data by multi-source sensors and the preliminary screening and preprocessing to obtain a structured raw data stream comprise: Based on the physical entity data collection requirements, a distributed edge computing node network of domestically developed processors and operating systems is constructed to realize local data preprocessing capabilities and obtain an edge computing network topology structure; The multi-source sensors are deployed according to the key characteristics of the physical entity, and standardized access of heterogeneous devices is realized through a data format standardization interface to obtain a standardized sensor access configuration; Based on the edge computing network topology and the standardized sensor access configuration, data of the multi-source sensors are collected at a preset sampling frequency by using a cache technology of edge nodes in the distributed edge computing node network, and local timestamp synchronization and preliminary caching are performed to obtain a time-synchronized raw data stream; A lightweight data preprocessing algorithm is deployed on the edge nodes of the distributed edge computing node network to perform denoising, outlier filtering and data format standardization processing on the time-synchronized raw data stream to obtain the structured raw data stream.

3. The method of claim 1, wherein, The importance score extrapolation and adaptive pruning of the full data to generate the optimized training data set include: Small-scale data samples are selected from the structured raw data stream by using a hierarchical random sampling method, and an initial model is trained to obtain initial model parameters and sample representation vectors; A sample importance scoring model is constructed based on a k-nearest neighbor method and a graph neural network method, and the initial model parameters and the sample representation vectors are input to obtain an importance scoring model; The importance scoring model is applied to the complete data set to calculate the importance score of each sample to obtain a weighted data sample set; A pruning threshold is dynamically determined according to the system resource status, task priority and data distribution characteristics, and redundant samples below the threshold are removed to generate the optimized training data set.

4. The method of claim 1, wherein, The branched digital twin model expressing the multi-path evolution characteristics of the system includes: Based on the engineering parameters of the physical entity and the basic physical laws, a physical model framework describing the basic behavior of the system is constructed to obtain an initial digital twin model skeleton; Based on the initial digital twin model skeleton, a multi-head branched Schrodinger bridge neural network is designed, which includes a shared encoding layer, a multi-path decoding layer and an attention fusion mechanism to obtain a network structure capable of expressing the evolution of the system from a single initial state to multiple possible final states; Based on the engineering parameters of the physical entity, the basic physical laws and the dynamic characteristics reflected by the structured raw data stream, different system change characteristics are identified, and multiple time-dependent velocity fields and growth process models are parameterized for different system change characteristics to capture dynamic evolution laws at different time scales to obtain a multi-time scale dynamics model; The multi-head branched Schrodinger bridge neural network is trained end-to-end using the optimized training data set to optimize shared parameters and branch-specific parameters to obtain the branched digital twin model.

5. The method of claim 1, wherein, The autonomous controllable security framework includes: Based on domestic cryptographic algorithms and secure chips, a data full life cycle protection architecture is designed, which includes data encryption, access control and integrity protection measures at each link of data acquisition, transmission, storage, processing and application to obtain a data sovereignty protection system; Based on the data sovereignty protection system, a fine-grained permission control system based on roles and attributes is constructed to support three-layer permission isolation at the resource level, operation level and data level to obtain an access control system based on the principle of least privilege. Deploy a hardware isolated execution environment at key nodes, ensure that critical algorithms run in a trusted environment through secure boot, remote authentication and isolated execution, and obtain a trusted execution environment; Based on differential privacy and federated learning technology, privacy protection is realized in data analysis process, model training and inference are supported without exposing original data, and the autonomous controllable security framework is obtained.

6. The method of claim 1, wherein, The integrated real-time sensor data and the enhanced digital twin model output with high generalization are analyzed for multi-modal data fusion, abnormal patterns are identified and decision suggestions are generated, and precise management of physical entities is realized through closed-loop control, including: Integrate real-time sensor data and enhanced digital twin model output, and obtain a comprehensive view of the state of physical entities through time alignment and feature fusion; Based on the comprehensive view of the state of physical entities and the multi-path evolution trajectory predicted by the branched digital twin model, an anomaly detection algorithm is designed to identify trends that deviate from the normal operating range, and a graded warning signal is obtained; For the detected graded warning signal or optimization demand, multi-scenario simulation is performed using the enhanced digital twin model with high generalization, multiple sets of intervention measure suggestions are generated, and the effectiveness and risk of each scheme are predicted and evaluated using the enhanced digital twin model with high generalization, and the optimal decision scheme is obtained; The optimal decision scheme is converted into specific control instructions, which are issued to the physical entity execution system through a secure channel, and execution feedback data is collected to continuously optimize the enhanced digital twin model with high generalization, and precise management of physical entities is realized.

7. The method of claim 5, wherein, Based on the data sovereignty protection system, a fine-grained permission control system based on roles and attributes is constructed, supporting three-layer permission isolation at resource, operation and data levels, obtaining an access control system based on the principle of least privilege, including: Based on identity authentication requirements, a two-way identity authentication protocol based on the SM2 algorithm is implemented to ensure that both parties in communication are authentic and trusted, and for high security level scenarios, hardware-level identity authentication based on domestic security chips is supported, obtaining a multi-factor identity authentication mechanism; Resource isolation based on network segmentation and security domains is implemented for system resources, and the default denial principle is adopted, with each resource access request being evaluated by fine-grained policies, resulting in resource-level permission control; Role-based access control predefines multiple roles, each associated with a specific set of operation permissions, implementing the role hierarchy and responsibility separation principle to prevent excessive concentration of permissions, resulting in operation-level permission control; Attribute-based access control dynamically evaluates access permissions based on user attributes, data attributes and environmental attributes, supporting three granularities of data access control: row, column and cell, resulting in data-level permission control; Based on the data-level permission control, periodic permission review and automatic recycling mechanisms are used to ensure that users only hold the necessary minimum set of permissions, and the strictness of the permission policy is dynamically adjusted based on threat intelligence and abnormal behavior detection, resulting in an access control system based on the principle of least privilege.

8. The method of claim 5, wherein, The differential privacy and federated learning technology realizes privacy protection in the data analysis process, supports model training and inference without exposing original data, and obtains the self-controllable security framework, which includes: Based on data sensitivity analysis, according to data sensitivity and use scene, dynamically select desensitization methods including static desensitization, dynamic desensitization and format reservation encryption, realize intelligent desensitization based on semantic understanding, and obtain the desensitized data set; Based on the desensitized data set, a differential privacy computing framework is constructed, including a privacy budget manager, a noise injection engine and a sensitivity analyzer, which provides privacy protection for data analysis, and obtains differential privacy computing capability; A federated learning platform is constructed, including federated modeling service, security aggregation protocol and model security evaluation, supporting horizontal federated learning and vertical federated learning, and obtaining multi-party collaborative learning capability; Based on the encryption computing capability, a homomorphic encryption security multi-party computing framework is realized based on domestic general-purpose cryptographic algorithm, which supports data analysis in encrypted state, and obtains encryption computing capability; Based on the encryption computing capability, a compliance verification mechanism based on zero-knowledge proof is realized, which allows third-party auditors to verify whether the privacy protection measures are effectively implemented, and obtains privacy protection verification capability.

9. An autonomously controllable digital twin governance system, characterized in that, It includes: Data perception and acquisition module, for acquiring physical entity data in real time through multi-source sensors and performing preliminary screening and preprocessing based on self-controllable edge computing equipment, to obtain structured raw data stream; Data pruning and processing module, for extracting small-scale data samples from the structured raw data stream for initial training, constructing importance scoring model, and performing importance scoring extrapolation and adaptive pruning on full data to generate optimized training data set; Branching digital twin model construction module, for constructing branching Schrodinger bridge neural network and parameterizing multiple time-dependent velocity fields based on the optimized training data set, sharing parameters and branching specific parameters through joint training, and obtaining branching digital twin model expressing system multi-path evolution characteristics; The model enhancement and generalization module is configured to construct a multi-experiment data set based on the branched digital twin model, train an equation discovery network, integrate the discovered mathematical law with the branched digital twin model, inject constraint conditions and perform model parameter regularization, and form an enhanced digital twin model with high generalization; wherein the formation of the enhanced digital twin model with high generalization includes: obtaining the core parameter variation range and constraint conditions of the physical entity, constructing a multi-dimensional parameter space mapping, and obtaining a parameter space representation model; based on the parameter space representation model, designing an equation discovery network based on symbolic regression, including three core modules of variable selection, expression generation and equation evaluation, and obtaining a complete equation discovery network structure; generating multiple sets of simulation experiment data under different parameter configurations based on the branched digital twin model, constructing a multi-experiment data set, training the equation discovery network using the multi-experiment data set, and obtaining a mathematical equation describing the internal law; integrating the discovered mathematical equation describing the internal law with the branched digital twin model, injecting constraint conditions and performing model parameter regularization, enhancing the generalization ability of the branched digital twin model in the parameter space, and obtaining the enhanced digital twin model with high generalization; The security framework implementation module is configured to construct a data full-life-cycle protection architecture based on domestic cryptographic algorithms and security chips, implement multi-level permission management and control and privacy computing, and obtain a self-controllable security framework; The intelligent decision and control module is configured to integrate real-time sensing data and output of the enhanced digital twin model with high generalization for multi-modal data fusion analysis, identify abnormal patterns and generate decision suggestions, and realize precise management of the physical entity through closed-loop control.

Citation Information

Patent Citations

  • Multi-modal remote sensing data change detection method and system based on twin U-Net neural network

    CN117372885A

  • Tunnel boring machine performance prediction and monitoring system based on digital twinning and machine learning

    CN120633403A