A method for optimizing metask scheduling of privacy protection computing in a metropolitan area network

By using Bayesian inference and multi-objective optimization algorithms to determine the dynamic trust value of computing nodes in real time, and combining privacy preferences and task characteristics, this approach solves the problems of static node trust assessment and the disconnect between privacy risks in metropolitan area networks. It achieves coordinated scheduling optimization of privacy and efficiency, and improves the security and flexibility of task scheduling.

CN121037119BActive Publication Date: 2026-02-03NANJING SHENYE INTELLIGENT SYST ENG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511563549.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-30
Publication Date
2026-02-03
Estimated Expiration
2045-10-30

AI Technical Summary

Technical Problem

In the current scheduling of metropolitan area network computing migration tasks, the static node trust assessment cannot reflect real-time risks, and the privacy risks are disconnected from the scheduling optimization goals, resulting in a tradeoff between privacy and efficiency. Privacy compliance audits and trust assessments are also disconnected, creating a vicious cycle.

Method used

By using Bayesian inference to determine the dynamic trust value of computing nodes in real time, and combining privacy preference parameters and task characteristics, a multi-objective optimization function is constructed. A multi-objective particle swarm optimization algorithm is used to generate a scheduling scheme, and node behavior is continuously monitored for privacy compliance auditing to correct the trust value.

Benefits of technology

It enables real-time capture of changes in computing node risks in metropolitan area networks, significantly reducing the risk of privacy leaks. The generated scheduling scheme satisfies both privacy and security requirements as well as latency and energy consumption requirements, improving the long-term reliability and flexibility of task scheduling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037119B_ABST
    Figure CN121037119B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of task scheduling, and provides a metropolitan area network privacy protection computing migration task scheduling optimization method. Through Bayesian inference, the resource state of a computing node is processed in real time to determine a dynamic trust value in real time. Compared with static trust evaluation of the prior art, the real-time risk change of the computing node can be captured in real time, and the privacy leakage risk is significantly reduced. The privacy risk evaluation, task completion delay and task execution energy consumption are jointly used as optimization objectives of a multi-objective optimization function, and constraint conditions of the multi-objective optimization function are defined, so that the generated optimization scheduling scheme not only meets the privacy security requirement, but also meets the delay and energy consumption demand. The actual behavior data of the computing node is continuously monitored and privacy compliance auditing is performed, and the privacy compliance performance is fed back to the Bayesian inference as new evidence to correct the node dynamic trust value, so that the long-term reliability and flexibility of task scheduling are significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of task scheduling, in particular to a metropolitan area network privacy protection computing migration task scheduling optimization method. BACKGROUND

[0002] With the maturity of 5G and edge computing technology, metropolitan area networks, as a key network level connecting core networks and terminal devices, have been widely used in smart factories, smart cities and remote medical scenarios, carrying massive computing migration tasks. To meet the quality of service requirements in different scenarios, existing technologies have carried out a lot of research around computing migration task scheduling.

[0003] In the scheduling optimization dimension, existing solutions mostly take time and energy consumption as the core optimization targets, and generate scheduling schemes through intelligent algorithms such as particle swarm optimization and genetic algorithm. For example, for device parameter migration tasks in smart factories, low-latency and low-energy computing nodes are preferentially selected by analyzing the transmission bandwidth and processing capacity between nodes. In the privacy protection dimension, some technologies introduce data encryption and access control means to protect the security of migration data, and at the same time, through static trust evaluation of nodes, trusted nodes are screened to avoid leakage of high-sensitive data on untrusted nodes.

[0004] Although existing technologies have made progress in efficiency optimization and basic privacy protection of metropolitan area network computing migration task scheduling, there are still deficiencies, including static node trust evaluation, which cannot reflect real-time risks and is prone to cause problems such as high-trust nodes being scheduled despite sudden risks. At the same time, privacy risks and scheduling optimization targets are separated, and there is no collaborative mechanism, resulting in the inability to balance privacy and efficiency. Privacy compliance auditing and trust evaluation are disconnected, lack of closed-loop iteration, and form a vicious cycle of repeated reuse of risk nodes.

[0005] Based on the deficiencies of the existing technologies, the technical problem to be solved by the present application is how to realize the collaborative scheduling optimization of privacy, efficiency and energy consumption in migration tasks in a complex metropolitan area network environment. SUMMARY

[0006] In view of the deficiencies of the existing technologies, the present application provides a metropolitan area network privacy protection computing migration task scheduling optimization method, which comprises: acquiring the resource state of the computing nodes in the metropolitan area network, and processing the resource state through Bayesian inference to determine the dynamic trust value of each computing node in real time;

[0007] Receiving a migration task request submitted by a user, parsing and extracting privacy preference parameters, and determining the privacy risk estimate value between the migration task and the computing node according to the dynamic trust value and the privacy preference parameters;

[0008] Based on the privacy risk estimate value, the task completion time delay and the task execution energy consumption, a multi-objective optimization function is constructed, and the constraint conditions of the multi-objective optimization function are defined.

[0009] solving a multi-objective optimization function by a multi-objective particle swarm optimization algorithm to generate a candidate scheme set, and selecting an optimized scheduling scheme from the candidate scheme set according to a strategy selected by a user to generate a scheduling instruction;

[0010] issuing the scheduling instruction to the target computing node and executing the migration task, and continuously monitoring actual behavior data of the target computing node in the whole execution process of the migration task;

[0011] performing privacy compliance auditing on the actual behavior data, and feeding privacy compliance performance as new evidence to the Bayesian inference to correct the dynamic trust value of each computing node.

[0012] As an optional implementation, the determining of the privacy risk estimate value between the migration task and the computing node comprises:

[0013] combining the dynamic trust value of the computing node and the data sensitivity degree of the migration task to determine a privacy risk base value, and dynamically adjusting a fusion weight of the dynamic trust value and the data sensitivity degree according to the type of the migration task;

[0014] correcting the privacy risk base value according to the historical privacy compliance performance of the computing node, and calibrating the corrected privacy risk base value with a leakage risk threshold as a constraint;

[0015] if the corrected privacy risk base value is less than or equal to the leakage risk threshold, taking the corrected privacy risk base value as the privacy risk estimate value;

[0016] if the corrected privacy risk base value is greater than the leakage risk threshold, judging whether to re-match the computing node based on a node trust boundary to determine the privacy risk estimate value between the migration task and the computing node.

[0017] As an optional implementation, the real-time determining of the dynamic trust value of each computing node comprises:

[0018] building an evaluation framework of the dynamic trust value with the historical privacy compliance performance, resource stability and cooperation credibility of the computing node as evaluation dimensions;

[0019] for a computing node newly accessing the metropolitan area network, determining a base trust value based on a resource state of the computing node to form a prior trust value of the Bayesian inference;

[0020] determining a likelihood function of the Bayesian inference according to the resource state and protocol adaptation degree of the computing node, and dynamically adjusting an initial weight of the likelihood function according to a runtime length of the computing node in the metropolitan area network;

[0021] The resource state of the computing node is obtained at a preset period, preprocessed and input into Bayesian inference to obtain a posterior probability, and the prior trust value of the computing node in a previous period is iteratively updated to determine the dynamic trust value of each computing node in real time.

[0022] As an optional implementation, the extracting the privacy preference parameter comprises:

[0023] The migration task request submitted by the user is received, the data type of the migration task is extracted after natural language processing, the basic sensitivity degree is determined based on the data type, and the basic sensitivity degree is adjusted based on the application scenario of the migration task to extract the data sensitivity degree;

[0024] The leakage risk description set by the user in the migration task request is analyzed, and the leakage risk threshold is extracted by calibrating the historical privacy compliance performance of the same type of migration task in the metropolitan area network;

[0025] The node trust boundary is defined based on the evaluation framework of the dynamic trust value, the node trust boundary includes an absolute trust boundary and a conditional trust boundary, the absolute trust boundary represents the dynamic trust value of processing different data sensitivity degrees, and the conditional trust boundary is an additional protection condition for the computing node close to but not reaching the absolute trust boundary.

[0026] As an optional implementation, the generating the scheduling instruction comprises:

[0027] The selected strategy of the user is converted into the screening standard of the candidate scheme set, and the strategy includes a security priority strategy, an efficiency priority strategy and a balanced optimal strategy;

[0028] The optimization scheduling scheme is selected from the candidate scheme set based on the screening standard of the candidate scheme set, and the optimization scheduling scheme includes the identification of the target computing node, the task execution order and the resource allocation ratio;

[0029] After verifying that the dynamic trust value of the target computing node meets the node trust boundary, the scheduling instruction is generated according to the selected optimization scheduling scheme.

[0030] As an optional implementation, the constructing the multi-objective optimization function comprises:

[0031] The transmission time delay of the migration task between different computing nodes is determined based on the topology structure of the metropolitan area network, the internal computing time delay of each computing node for processing the migration task is synchronously obtained, and the task completion time delay is obtained after summation;

[0032] The unit energy consumption of the migration task executed by the computing node is determined according to the resource state of the computing node, and the task execution energy consumption is obtained by combining the data volume and the execution duration of the migration task;

[0033] The privacy risk estimate, the task completion delay and the task execution energy consumption are optimization objectives, basic weight coefficients are set for each optimization objective, and the basic weight coefficients are dynamically adjusted according to the type of the migration task;

[0034] The optimization objectives are standardized, and the standardized optimization objectives and the adjusted basic weight coefficients are weighted and summed to construct a multi-objective optimization function.

[0035] As an optional implementation, the constraint condition of the multi-objective optimization function includes resource constraints, privacy constraints and task constraints, the resource constraints represent that the average of CPU occupancy and memory occupancy of the computing node is less than or equal to the upper limit of the dynamic trust value;

[0036] The privacy constraints represent that the computing node allowed to participate in the migration task scheduling meets the node trust boundary, and the privacy risk estimate of the computing node is less than or equal to the leakage risk threshold;

[0037] The task constraints refer to that the time constraints of the migration task across the metropolitan area network include transmission delay between computing nodes, internal computing delay and time cost of verifying the dynamic trust value, and the total energy consumption of all computing nodes in the same metropolitan area network for executing the migration task is not greater than the preset energy quota of the metropolitan area network.

[0038] As an optional implementation, the generating the candidate scheme set includes:

[0039] Initializing a multi-objective particle swarm optimization algorithm, each particle representing a set of optimization scheduling schemes, selecting a computing node with a dynamic trust value greater than or equal to an absolute trust boundary as an initial position of the particle, and taking the output value of the multi-objective optimization function as a particle fitness value;

[0040] In each iteration, the initial position of the particle is updated according to the individual optimal solution and the group optimal solution, and it is checked whether the updated initial position of the particle meets the constraint condition of the multi-objective optimization function, and an initial solution set that passes the check is output;

[0041] The initial solution set is subjected to secondary screening, and solutions with a privacy risk estimate greater than a leakage risk threshold are removed to generate a candidate scheme set.

[0042] As an optional implementation, the correcting the dynamic trust value of each computing node includes:

[0043] The compliance level and the violation type in the privacy compliance performance are converted into new evidence identifiable by Bayesian inference, and the identification of the target computing node is automatically matched to update the evidence pool of the target computing node;

[0044] Based on the prior trust value of the target computing node, the posterior probability of the target computing node is updated in combination with new evidence to correct the dynamic trust value and store the correction record;

[0045] The corrected dynamic trust value is compared with the absolute trust boundary to determine whether to trigger the regeneration of the candidate scheme set, and the correction record and the privacy compliance performance of the dynamic trust value of all computing nodes are periodically summarized to dynamically adjust the initial weight of the likelihood function.

[0046] As an optional implementation, the privacy compliance auditing of the actual behavior data includes:

[0047] The scheduling instruction is issued to the target computing node and the migration task is executed, and the actual behavior data of the target computing node in the whole execution process of the migration task is continuously monitored, the actual behavior data including data operation behavior, resource usage behavior and protocol compliance behavior;

[0048] An audit rule library is constructed based on the data sensitivity, leakage risk threshold and privacy constraint, the actual behavior data is matched and verified with the audit rule library to determine whether there is a violation behavior and a violation type to generate an audit intermediate result, and the audit intermediate result is associated with the task execution sequence;

[0049] The audit intermediate result is summarized according to the execution period of the migration task, and the compliance level is determined according to the number of violations and the proportion of violation types in the summary, to generate a privacy compliance performance including the compliance level, the violation type, the actual execution data and the identification of the target computing node.

[0050] Compared with the prior art, the beneficial effects of the present application are: the resource state of the computing node is processed in real time through Bayesian inference, and the dynamic trust value is determined in real time, which can capture the real-time risk change of the computing node in real time compared with the static trust evaluation of the prior art, and significantly reduce the privacy leakage risk; the privacy risk evaluation, the task completion delay and the task execution energy consumption are jointly used as the optimization target of the multi-objective optimization function, and the constraint condition of the multi-objective optimization function is defined to ensure that the generated optimization scheduling scheme meets the privacy security requirements and meets the delay and energy consumption requirements; the actual behavior data of the computing node is continuously monitored and privacy compliance auditing is performed, and the privacy compliance performance is fed back to the Bayesian inference as new evidence to correct the node dynamic trust value, which significantly improves the long-term reliability and flexibility of task scheduling. BRIEF DESCRIPTION OF DRAWINGS

[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor. Among them:

[0052] Figure 1 A flowchart illustrating a method for optimizing the scheduling of privacy-preserving computation migration tasks in a metropolitan area network, provided as an embodiment of this application;

[0053] Figure 2 This is a flowchart illustrating the logic for determining the privacy risk assessment between the migration task and the computing node, as provided in an embodiment of this application.

[0054] Figure 3 The following is a flowchart illustrating the logic for modifying the dynamic trust value of each computing node, as provided in the embodiments of this application. Detailed Implementation

[0055] To make the objectives, technical solutions, and advantages of the embodiments of this application more apparent and understandable, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.

[0056] like Figure 1 The diagram shown is a flowchart of a method for optimizing the scheduling of privacy-preserving computing migration tasks in a metropolitan area network (MAN) according to an embodiment of this application. The method includes:

[0057] The metropolitan area network (MAN) of a smart factory includes three types of computing nodes: production control area, data center area, and office area. The production control area contains equipment such as PLC controllers and industrial robots, which are responsible for processing production data such as equipment operating parameters and process formulas. The data center area deploys edge servers and core databases to store core business data of the factory. The office area contains employee terminals and office servers to process management data such as attendance records and order reports. The smart factory needs to use the MAN to realize the migration and scheduling of various types of data, while ensuring the privacy and security of core data such as process formulas, and ensuring that equipment parameters are migrated in real time to maintain production continuity.

[0058] S1. Obtain the resource status of computing nodes in the metropolitan area network, process the resource status through Bayesian inference to determine the dynamic trust value of each computing node in real time, and receive migration task requests submitted by users. Parse and extract privacy preference parameters including data sensitivity, leakage risk threshold and node trust boundary, and determine the privacy risk estimate between the migration task and the computing node based on the dynamic trust value and privacy preference parameters.

[0059] Furthermore, determining the dynamic trust value of each computing node in real time includes:

[0060] An evaluation framework for dynamic trust values ​​is established, using the historical privacy compliance performance, resource stability, and collaborative trustworthiness of computing nodes as evaluation dimensions.

[0061] For newly connected computing nodes in the metropolitan area network, a basic trust value is determined based on the resource status of the computing node, forming a prior trust value based on Bayesian inference.

[0062] The likelihood function for Bayesian inference is determined based on the resource status and protocol adaptation of the computing nodes, and the initial weight of the likelihood function is dynamically adjusted based on the runtime of the computing nodes in the metropolitan area network.

[0063] The resource status of computing nodes is acquired at preset intervals and preprocessed before being input into Bayesian inference to obtain posterior probabilities. The prior trust values ​​of computing nodes in the previous period are iteratively updated to determine the dynamic trust value of each computing node in real time.

[0064] In a smart factory, the functional positioning and potential risks of different computing nodes vary significantly. PLC controllers in the production control area are directly linked to production data transmission, the core database in the data center area stores core information such as process recipes, and terminal nodes in the office area only process ordinary office data. Using a uniform evaluation standard would prevent the accurate identification of risks unique to industrial scenarios. Therefore, this assessment uses historical privacy compliance performance, resource stability, and collaboration trustworthiness as evaluation dimensions, and refines the evaluation content of each dimension based on the industrial attributes of the smart factory. Historical privacy compliance performance involves retrieving records of past migration tasks executed by computing nodes from the factory's production management system, focusing on verifying whether there are factory-specific violations such as unauthorized access to production data, tampering with operation logs, and leakage of core parameters. For example, it checks whether unauthorized terminals read process recipes and whether equipment fault records have been manually modified. Resource stability is assessed based on the operating characteristics of industrial equipment, adding evaluation indicators such as continuous fault-free operation, data recovery integrity after power outages, and load fluctuation amplitude. For example, it counts the number of times a PLC controller operates without faults for 72 consecutive hours, and edge servers check the completeness of production data recovery after power outages. If data is missing, the resource stability assessment result is downgraded.

[0065] Collaboration trustworthiness focuses on the interaction performance between computing nodes and the factory's MES and ERP systems. It assesses whether data upload latency meets factory production requirements and whether it strictly adheres to industrial Ethernet protocols. For example, the latency of computing nodes uploading equipment operating parameters to the factory's MES system must be controlled within a set range and must be fully compatible with commonly used industrial protocols. If protocol incompatibility leads to data transmission interruption, the assessment result of collaboration trustworthiness will decrease. Based on historical security audit data, scenario-based weights are assigned to the three assessment dimensions. Considering that factory equipment failures directly affect production progress, the weight of resource stability is higher than that of ordinary scenarios, ensuring that the assessment framework can prioritize the identification of risks affecting production continuity. The assessment framework is fully adapted to the industrial scenarios of smart factories and can accurately capture the risk characteristics of different computing nodes in the production control area, data center area, and office area. It avoids missing risk points specific to industrial equipment due to the use of a general framework. At the same time, the weight allocation highlights the importance of resource stability to production, ensuring that the dynamic trust value can truly reflect the privacy protection capabilities and collaboration reliability of computing nodes in an industrial environment.

[0066] Smart factories add industrial equipment based on production needs, such as welding robots to expand production capacity. The accompanying edge computing nodes are also connected to the metropolitan area network (MAN). These new computing nodes lack historical factory operation data. If a priori trust value cannot be determined, they will be unable to participate in production task scheduling. After a new computing node is connected to the MAN, the device type is first queried to determine its type: whether it is a PLC node in the production control area, an edge server node in the data center area, or a terminal node in the office area. The resource status of different types of computing nodes is obtained. For PLC nodes in the production control area, it is checked whether they support encrypted transmission of industrial data and whether they can implement hierarchical access control, such as whether only the MES system is allowed to write production parameters to them. Simultaneously, the historical operating data of the same model of PLC nodes in the factory is compared to obtain the average trust value of that model as a base trust value. If the new computing node also has a local backup function for fault data, capable of saving critical production parameters in the event of a sudden power outage, the base trust value is appropriately increased to reflect its additional security capabilities.

[0067] For terminal nodes in the office area, it is only necessary to verify whether the factory-specified antivirus software is installed and whether the USB flash drive port control function is enabled to prevent employees from copying data via USB flash drives and causing information leakage. The basic trust value of the new terminal node is determined by referring to the average trust value of the terminal nodes already connected in the same department, so as to form the prior trust value of Bayesian inference. Thus, a differentiated prior trust value determination process is formulated for the characteristics of different types of computing nodes in the smart factory. This ensures that the prior trust value of high-risk nodes in the production control area is rigorous and reliable, while simplifying the evaluation process of low-risk nodes in the office area. It avoids excessive verification from affecting the access efficiency of computing nodes, ensures that new computing nodes can quickly participate in production task scheduling, and ensures the security of the scheduling process.

[0068] In a smart factory, the operational status of nodes changes with the production cycle. Newly connected computing nodes are prone to data transmission anomalies due to incompatibility with the factory's existing system protocols in the initial stage. Long-running computing nodes are more likely to experience resource stability issues. For example, edge servers may experience excessive memory consumption due to prolonged high load operation. If the likelihood function and initial weights remain fixed, it is impossible to accurately quantify the risk characteristics of computing nodes at different stages. The likelihood function of Bayesian inference is determined according to the type of computing nodes in the smart factory. For PLC nodes and industrial robot nodes in the production control area, the likelihood function is divided into a resource stability branch and a protocol adaptation branch. The resource stability branch is input with industrial parameters such as equipment operating temperature, fault alarm frequency, and continuous fault-free operation time. The protocol adaptation branch is input with interaction data such as the protocol interaction success rate with the MES system and the data transmission packet loss rate. For edge server nodes in the data center area, an additional data backup integrity branch is required, which inputs indicators such as the success rate of regular production data backup and the backup data recovery time, because the production data stored on the edge server needs to be backed up regularly to cope with equipment failures.

[0069] Based on the runtime of compute nodes in the factory's metropolitan area network, the initial weights of each branch of the likelihood function are dynamically adjusted. Newly connected compute nodes have shorter runtimes, and protocol compatibility is the main risk. Therefore, the weight of the protocol compatibility branch is increased, while the weight of the resource stability branch is decreased. This ensures that the compatibility of compute nodes with the factory's existing systems is monitored first, avoiding interruptions in production data transmission due to protocol incompatibility. As the runtime of compute nodes increases, the importance of resource stability and data backup integrity gradually increases. The weight of these two branches is gradually increased, while the weight of the protocol compatibility branch is decreased. The focus is on the resource load and data security of compute nodes after long-term operation. The likelihood function can accurately capture the risk characteristics of different types of nodes. Dynamically adjusting the initial weights allows the trust assessment to adapt to the entire lifecycle of the compute node's operation, preventing new compute nodes from being misjudged as low-trust nodes due to protocol compatibility issues, and preventing the resource stability risks of long-running compute nodes from being overlooked, thus improving the accuracy of dynamic trust value assessment.

[0070] The production process in a smart factory is continuous, and the resource status and operational performance of computing nodes change in real time with the production progress. If the dynamic trust value is not updated for a long time, scheduling decisions will be made based on outdated data, which may lead to high-risk nodes participating in the migration of core data. Therefore, it is necessary to iterate and update the dynamic trust value regularly according to the factory's production rhythm. Based on the production cycle of the smart factory, a preset cycle for the dynamic trust value iteration and update is set. During the daytime, when production tasks are intensive and the resource status of computing nodes changes frequently, the update cycle is shortened to ensure timely capture of real-time risk changes of computing nodes. At night, when the production load is low and the resource status of computing nodes is relatively stable, the update cycle is appropriately extended to reduce unnecessary consumption of computing resources. Within each preset update cycle, the resource status of computing nodes is acquired, including equipment operating parameters, protocol interaction data, and data backup status. The acquired data is preprocessed using a filtering algorithm to remove abnormal data caused by instantaneous fluctuations in equipment, such as instantaneous fault alarms of PLC controllers caused by brief instability in grid voltage, to ensure that the data input for Bayesian inference is true and reliable.

[0071] The preprocessed data is input into the likelihood function in Bayesian inference, and the posterior probability is calculated by combining the weight ratio of each branch. The prior trust value of the previous period is fused with the posterior probability of the current period to obtain the dynamic trust value of the current period, which covers the historical trust value of the computing node. At the same time, information such as the time of each update, input data, and calculation process is recorded to form a trust update log, which facilitates subsequent security audits and problem tracing. The preset iteration cycle is set according to the factory production rhythm, which can ensure the real-time performance of the dynamic trust value and avoid excessive updates that consume computing resources. Data preprocessing and log recording ensure that the dynamic trust value update process is traceable and the results are reliable, so that the dynamic trust value is always synchronized with the actual operating status of the computing node. This provides a real-time and accurate trust reference for factory data migration scheduling. The iteratively updated dynamic trust value is the key input data for determining the privacy risk assessment. The real-time and accurate dynamic trust value can make the privacy risk assessment more in line with the current state of the node, avoiding the selection of high-risk nodes to participate in core data migration due to the lag of the dynamic trust value, thus ensuring the security of factory privacy data.

[0072] Furthermore, the extraction of privacy preference parameters includes:

[0073] Receive migration task requests submitted by users, extract the data type of the migration task through natural language processing, determine the basic sensitivity level based on the data type, and adjust the basic sensitivity level in combination with the application scenario of the migration task to extract the data sensitivity level;

[0074] The leakage risk description set by the user in the migration task request is analyzed and calibrated in combination with the historical privacy compliance performance of similar migration tasks in the metropolitan area network to extract the leakage risk threshold.

[0075] The node trust boundary is defined by combining the evaluation framework of dynamic trust value. The node trust boundary includes absolute trust boundary and conditional trust boundary. The absolute trust boundary represents the dynamic trust value for processing different data sensitivity levels, and the conditional trust boundary adds protection conditions to computing nodes that are close to but have not reached the absolute trust boundary.

[0076] The migration tasks for smart factories involve diverse data types, and the losses caused by different data breaches vary greatly. The leakage of core data such as process formulas can lead to the loss of the factory's technological advantages, while the leakage of ordinary office data has a smaller impact. If the sensitivity of the data cannot be accurately extracted, highly sensitive data may be assigned to computing nodes with insufficient security protection capabilities. Therefore, it is necessary to make accurate judgments based on the factory's business scenario. After receiving migration task requests submitted by users such as factory production managers and office staff, natural language processing technology is used to parse the data keywords in the migration task request description to identify the data type of the migration task. Based on the data type, the basic sensitivity of the migration task is initially determined. If the task description contains keywords such as process formulas, core equipment parameters, and employee salaries, the basic sensitivity is relatively high. If it contains keywords such as workshop temperature and humidity, public area monitoring videos, and public order reports, the basic sensitivity is relatively low.

[0077] Based on the application scenario of the migration task, the basic sensitivity level is adjusted. If the data is used in the core production process of the factory, such as process formulas used for production line parameter settings, even if the basic sensitivity level is already high, it still needs to be further improved to ensure that it receives the highest level of security protection. If the data is used in non-production scenarios, such as employee attendance records used only for internal attendance statistics with no risk of external leakage, the basic sensitivity level can be appropriately reduced to avoid over-protection affecting scheduling efficiency. The final determined data sensitivity level is recorded and stored in association with the migration task's identifier, providing a basis for subsequent privacy risk assessment and computing node matching. By combining keyword recognition and scenario adjustment, the data sensitivity level of the smart factory can be accurately distinguished, avoiding excessive or insufficient privacy protection due to misjudgment of data sensitivity. This ensures that highly sensitive data receives sufficient security protection, while ordinary data can be efficiently scheduled, balancing factory data security and production efficiency.

[0078] In a smart factory, users have varying tolerances for privacy breaches in different migration tasks. Production administrators have extremely low tolerance for breaches in process recipe migrations, while office staff have relatively high tolerance for breaches in ordinary document migrations. Setting a uniform breach risk threshold would not meet the security requirements of different migration tasks. Therefore, it is necessary to extract breach risk thresholds based on user expectations and the actual situation of the factory. The breach risk descriptions set by users in migration task requests are analyzed, and the textual descriptions are converted into initial breach risk thresholds. If a user explicitly states that data for a certain migration task must not be leaked, the initial breach risk threshold is set to an extremely low level. If a user indicates that minor breaches are acceptable, the initial breach risk threshold is appropriately relaxed.

[0079] Simultaneously, historical privacy compliance records of similar migration tasks in the factory's metropolitan area network are retrieved to statistically analyze the actual leakage situation of past migration tasks, including the number of leaks, the causes of leaks, and the losses caused. If the historical records show that similar tasks have never experienced a leak, and the factory's existing security measures can effectively prevent risks, the initial leakage risk threshold can be appropriately tightened to further reduce the possibility of leakage. If there are a small number of non-malicious leakage events in the historical records, and no serious losses have been caused, the initial leakage risk threshold can be appropriately relaxed in conjunction with the risk assessment opinions of the factory's security department. This avoids the inability to schedule tasks normally due to an excessively strict leakage risk threshold. The calibrated leakage risk threshold is then bound to the migration task as a constraint standard for subsequent privacy risk assessment, ensuring that the privacy risk assessment of the migration task does not exceed the user's acceptable range. Through user description conversion and historical data calibration, the leakage risk threshold can reflect both the user's subjective security needs and the actual security protection capabilities of the smart factory. This avoids the leakage risk threshold being too high, resulting in a lack of privacy security, or too low, affecting task scheduling efficiency, thus achieving personalized risk management.

[0080] In a smart factory, data of varying sensitivity must be processed by computing nodes with security capabilities. If node trust boundaries are unclear, highly sensitive data may be assigned to low-trust nodes, or low-sensitivity data may consume resources from high-trust nodes, leading to resource waste. Therefore, node trust boundaries must be defined based on the characteristics of factory nodes and the sensitivity of the data. Using a dynamic trust value evaluation framework, and considering factors such as the type of computing node, security measures, and historical privacy compliance performance, absolute trust boundaries and conditional trust boundaries should be defined. The absolute trust boundary sets the minimum dynamic trust value standard for the corresponding computing node based on the data sensitivity. High-sensitivity data has a higher absolute trust boundary, allowing only computing nodes with high dynamic trust values ​​and strong security capabilities to participate in scheduling. For example, core data such as process formulas can only be processed by core database nodes in the data center area and high-trust PLC nodes in the production control area. The absolute trust boundary for medium-sensitivity data is appropriately lowered, allowing it to be processed by backup servers in the data center area and encrypted terminal nodes in the office area. Low-sensitivity data has the lowest absolute trust boundary, allowing most nodes that meet basic security requirements to participate.

[0081] Conditional trust boundaries target computing nodes whose dynamic trust values ​​are close to but not yet at the absolute trust boundary, and impose specific security protection conditions to enable them to process more sensitive data. For edge server nodes approaching the absolute trust boundary for highly sensitive data, additional protection conditions such as real-time behavior auditing, double data encryption, and secondary verification of access permissions are added to ensure effective prevention of privacy leakage risks when processing core data. For office terminal nodes approaching the absolute trust boundary for moderately sensitive data, additional conditions such as encrypted data transmission and prohibition of external storage devices are added to enhance their security protection level. The defined node trust boundaries are then stored and associated with the classification of data sensitivity, including high, medium, and low sensitive data, providing clear boundary standards for subsequent privacy risk assessment and node matching. Thus, through the dual design of absolute trust boundaries and conditional trust boundaries, the smart factory's computing node resources can be used judiciously. This ensures that highly sensitive data is processed only by high-trust nodes, while the additional conditions expand the application scenarios of medium and low-trust nodes, preventing high-trust node resources from being occupied by low-sensitivity data, thereby improving overall scheduling efficiency and security.

[0082] Specifically, such as Figure 2 As shown, determining the privacy risk assessment between the migration task and the computing node includes:

[0083] By combining the dynamic trust value of computing nodes and the data sensitivity of migration tasks, a basic value for privacy risk is determined, and the fusion weight of dynamic trust value and data sensitivity is dynamically adjusted according to the type of migration task.

[0084] The baseline privacy risk value is adjusted based on the historical privacy compliance performance of the computing nodes, and the adjusted baseline privacy risk value is calibrated with the leakage risk threshold as a constraint.

[0085] If the revised baseline value of privacy risk is less than or equal to the disclosure risk threshold, then the revised baseline value of privacy risk will be used as the privacy risk estimate.

[0086] If the revised baseline privacy risk value is greater than the leakage risk threshold, then a decision is made based on the node trust boundary to determine whether to rematch the computing node in order to determine the privacy risk estimate between the migration task and the computing node.

[0087] Different migration tasks in a smart factory have different core requirements. Some migration tasks prioritize privacy and security, while others prioritize scheduling efficiency. If a uniform basic value for privacy risk is used, it will not reflect the core requirements of the migration tasks, which may lead to an underestimation of the risk of security-priority tasks or a reduction in the scheduling flexibility of efficiency-priority tasks. Therefore, it is necessary to dynamically adjust the value based on the task type. The current dynamic trust value of the computing node and the data sensitivity of the migration task are obtained, and the two are weighted and fused to obtain the basic value for privacy risk. According to the type of migration task in the smart factory, privacy-priority, efficiency-priority, and balanced tasks are distinguished, and a fusion weight of dynamic trust value and data sensitivity is set for different types of migration tasks.

[0088] Firstly, privacy-priority migration tasks, such as process formula migration and core production parameter upload tasks, prioritize data privacy and security. These tasks increase the weight of data sensitivity in the fusion computing process while decreasing the weight of dynamic trust values, ensuring data sensitivity plays a dominant role in risk assessment. Computing nodes that meet the security requirements of highly sensitive data are prioritized. Secondly, efficiency-priority tasks focus on rapidly completing data migration and ensuring production continuity, such as real-time uploading of workshop temperature and humidity data and sharing of ordinary office files. These tasks increase the weight of dynamic trust values ​​while decreasing the weight of data sensitivity. While ensuring basic privacy and security, computing nodes with sufficient resources and fast response times are prioritized. Finally, balanced tasks have equal requirements for privacy and security and scheduling efficiency, such as employee attendance record migration and non-core order data transmission tasks. These tasks set the weight of dynamic trust values ​​and data sensitivity equally, comprehensively assessing the impact of the trust level and data sensitivity of computing nodes on risk.

[0089] According to the set fusion weights, the dynamic trust value and data sensitivity are fused and calculated to obtain the basic privacy risk value that matches the migration task with the calculation node. The higher the basic privacy risk value, the lower the risk, and the lower the basic privacy risk value, the higher the risk. In this way, the fusion weights are set differently according to the core needs of the smart factory migration task, so that the basic privacy risk value can accurately reflect the security requirements of the migration task. This avoids the core needs of the migration task not being met due to uniform weights. At the same time, it provides a benchmark value that conforms to the characteristics of the task for subsequent risk correction, and improves the pertinence of privacy risk assessment.

[0090] In smart factories, the historical privacy compliance performance of computing nodes exhibits unique characteristics. If a computing node has previously committed a violation involving unauthorized access to core data such as process recipes, the risk impact on subsequent process recipe migration tasks is far greater than that on temperature and humidity data migration tasks. Simply adjusting the basic privacy risk value according to general rules could lead to an underestimation of the risk for core tasks or an overestimation of the risk for ordinary tasks. Therefore, targeted adjustments are necessary, taking into account the type of violation and the characteristics of the task data, while ensuring that the calibration meets the constraints of the leakage risk threshold. First, retrieve the historical privacy compliance of the computing node within the factory's metropolitan area network, distinguishing the violation type and the associated data attributes. If the computing node has previously experienced core data leakage or unauthorized access, and the current migration task has a high level of data sensitivity, then the basic privacy risk value should be further lowered to amplify the risk impact of historical violations on core tasks, ensuring that past security vulnerabilities of the computing node are fully considered during core data migration. If the computing node has previously experienced ordinary data leakage, and the current task involves low-sensitivity data migration, then only the basic value should be slightly lowered to avoid over-amplifying the impact of ordinary violations.

[0091] If a compute node has no violations for multiple consecutive production cycles and passes the factory's monthly security audit, the base privacy risk value will be slightly increased based on the audit results. This reflects the security advantages of the node's long-term compliant operation and encourages the compute node to maintain a compliant status. After the base privacy risk value is corrected, calibration will be performed using the leakage risk threshold as a constraint. If the corrected base privacy risk value is less than or equal to the leakage risk threshold, the corrected base privacy risk value will be retained as the privacy risk estimate. If the corrected base privacy risk value is greater than the leakage risk threshold, it will first be checked whether the compute node has additional security protection capabilities that can be enabled. After enabling them, the risk will be reassessed. If the risk drops to within the leakage risk threshold, calibration will be completed. If the threshold requirements still cannot be met after enabling additional measures, the compute node will be marked as temporarily unsuitable for the current migration task.

[0092] Smart factories have extremely high requirements for production continuity. If the corrected basic privacy risk value is greater than the leakage risk threshold, directly excluding computing nodes will lead to insufficient available nodes and interrupt production tasks. Therefore, it is necessary to flexibly judge based on node trust boundaries, prioritize the reuse of computing nodes by adding conditions, and only report errors and rematch when reuse is not possible, balancing security and production continuity. If the corrected basic privacy risk value is greater than the leakage risk threshold, first check whether the computing node is within the previously defined conditional trust boundary. If it is within the conditional trust boundary, add factory-specific protection conditions based on the data sensitivity of the current migration task. For example, add real-time behavior auditing and double encryption for data transmission for core data migration, and add conditions such as full retention of data access logs and prohibition of data writing during non-production periods for medium-sensitive data migration. After the additional conditions are enabled, recalculate the basic privacy risk value. If the risk drops to within the leakage risk threshold, the recalculated result is used as the final privacy risk estimate, and the enabled status of the additional conditions is recorded.

[0093] If a computing node is not within the conditional trust boundary, or if the risk still exceeds the leakage risk threshold after adding conditions, the computing node is deemed unsuitable for the current migration task and excluded from the candidate nodes. Simultaneously, a re-matching of computing nodes is triggered, and other computing nodes are selected to recalculate the privacy risk estimate until a computing node that meets the leakage risk threshold requirement is found. This ensures that the migration task can proceed normally under the premise of security and avoids production interruption due to the failure of a single computing node. The final determined privacy risk estimate is directly used as one of the core input parameters for constructing the multi-objective optimization function. It participates in the optimization calculation together with the task completion latency and task execution energy consumption, ensuring that the privacy and security bottom line is not breached while pursuing scheduling efficiency and energy consumption optimization.

[0094] It should be explained that the privacy risk valuation data is a continuous numerical value, using a dimensionless relative value form. Essentially, it is a comprehensive risk assessment indicator formed by integrating multiple dimensions such as the dynamic trust value of computing nodes, data sensitivity, and historical privacy compliance performance. This indicator is used to quantify the level of privacy security risk when a migration task is matched with a computing node. This value has clear comparative significance; its magnitude can directly determine the level of privacy risk for the same migration task from different computing nodes, or the difference in privacy risk for different migration tasks from the same computing node. This provides calculable and comparable quantitative input for subsequent multi-objective optimization functions. Different privacy risk valuation values ​​correspond to different risk levels.

[0095] S2. Construct a multi-objective optimization function based on privacy risk assessment, task completion latency, and task execution energy consumption. Define the constraints of the multi-objective optimization function and solve the multi-objective optimization function using a multi-objective particle swarm optimization algorithm to generate a candidate scheme set. At the same time, select an optimized scheduling scheme from the candidate scheme set according to the user's selected strategy to generate scheduling instructions.

[0096] Furthermore, constructing a multi-objective optimization function includes:

[0097] Based on the topology of the metropolitan area network, the transmission latency of the migration task between different computing nodes is determined, the internal computing latency of each computing node in processing the migration task is obtained synchronously, and the task completion latency is obtained by summing them.

[0098] The unit energy consumption of the migration task is determined based on the resource status of the computing nodes, and the task execution energy consumption is obtained by combining the data volume and execution time of the migration task.

[0099] With privacy risk assessment, task completion latency, and task execution energy consumption as optimization objectives, a basic weight coefficient is set for each optimization objective, and the basic weight coefficient is dynamically adjusted according to the type of migration task;

[0100] The optimization objective is standardized, and the standardized optimization objective is weighted and summed with the adjusted basic weight coefficients to construct a multi-objective optimization function.

[0101] Different migration tasks have significantly different time sensitivities. Real-time equipment parameter migration needs to be completed immediately to ensure dynamic control of the production line. Process recipe migration can tolerate a certain delay but must ensure stable transmission. Attendance record migration has the lowest time requirement. If the task completion delay is calculated only based on the transmission path length, key factors such as the processing time of forwarding devices and the data parsing process in the industrial network will be ignored, leading to the failure of real-time control tasks. The topology of the metropolitan area network is retrieved to clarify the physical location and connection path of the original computing node and the target computing node of the migration task. Various forwarding devices included in the connection path are identified, and relevant parameters of each connection path are obtained, including the signal transmission time corresponding to the physical distance of the connection path, the single processing time of each forwarding device, and the impact of the current load status of the connection path on the transmission efficiency. The transmission delay between different computing nodes is calculated by combining these factors.

[0102] Historical data on the processing of similar tasks by each computing node is acquired synchronously. The protocol parsing time after receiving historical data and the processing time for data storage or computation are analyzed and accumulated to obtain the internal computation latency of the computing node in processing migration tasks. The transmission latency is added to the internal computation latency to obtain the complete task completion latency. For time-sensitive tasks such as real-time parameter migration of equipment, the latency of multiple alternative connection paths is calculated. The latency of the connection path with lower load and stable transmission is selected as the final reference to avoid the impact of sudden congestion on the main connection path on task timeliness. This comprehensively covers the transmission and processing links unique to industrial networks, ensuring that the latency calculation conforms to the actual operation scenario of smart factories, avoiding delays in critical production tasks due to time estimation errors, and improving latency reliability through alternative connection paths.

[0103] In smart factories, the energy consumption per unit of computing nodes accounts for a significant proportion of total energy consumption. The energy requirements of different types of migration tasks vary considerably; large-scale data tasks consume far more energy than small-scale data tasks. Furthermore, the resource load status of computing nodes directly affects energy consumption levels; higher loads result in higher energy consumption. Estimating energy consumption solely based on the type of computing node would lead to overall factory energy consumption exceeding controllable limits. Therefore, obtaining real-time resource status for each computing node, including processor load, memory usage, and storage device read / write frequency, is crucial to determining the current energy consumption per unit of computing node. Extracting the data size and estimated execution time from migration tasks, and combining this with the energy consumption per unit of computing node, is also essential. The energy consumption calculation for task execution is adjusted based on data compression processing for large-scale data tasks, while for small-scale data tasks, the startup energy consumption from standby to operation is additionally considered to avoid underestimating energy consumption. During periods of tight energy control in the factory, the energy efficiency of each computing node is considered, and the computing node with better energy efficiency is selected for energy consumption calculation to balance task requirements and energy control objectives. The determination of task execution energy consumption avoids excessive factory energy consumption due to general estimation. By combining data processing characteristics and equipment status adjustments, the assessment of task execution energy consumption is made more in line with the actual production scenario, while supporting green production through energy efficiency references.

[0104] The core objectives of different types of migration tasks differ significantly. Process formula migration must prioritize privacy and security, equipment real-time parameter migration must prioritize meeting time requirements, and attendance record migration needs to balance various needs. Using a fixed weight allocation method would fail to adequately guarantee the core objectives of each task. Therefore, it is necessary to dynamically adjust the basic weight coefficients of each optimization objective based on the task type. In the production scheduling system, a basic weight coefficient is set for each optimization objective, ensuring that the weight coefficient for privacy risk assessment is relatively the highest, reflecting the principle of security priority. The type of migration task is identified from the migration task requests, and the weights are adjusted accordingly. For privacy-priority tasks, the basic weight coefficient for privacy risk assessment is increased, while the basic weight coefficients for task completion latency and task execution energy consumption are decreased to ensure optimal performance. The optimization process prioritizes privacy and security. For efficiency-oriented tasks, the base weight coefficient for task completion delay is increased, while the base weight coefficients for the other two items are appropriately reduced. However, the privacy risk assessment weight is kept above the preset base security threshold. For balanced tasks, the base weight coefficients of each item are fine-tuned to maintain a relative balance among the three. After the weight adjustment, the base weight coefficient of each optimization objective is verified to ensure that the base weight coefficient for privacy risk assessment is not below the preset base security threshold. If the adjustment result exceeds the base security threshold, it is automatically corrected, and a manual confirmation process is triggered if necessary. Dynamic weight adjustment ensures that the optimization objective is accurately matched with the core requirements of the task, avoiding the imbalance of task objectives caused by fixed weights. At the same time, security verification ensures that the privacy bottom line is not breached, which meets the security management requirements of smart factories.

[0105] The assessment dimensions and representations of privacy risk valuation, task completion latency, and task execution energy consumption differ significantly. Directly integrating these dimensions can lead to unbalanced assessment results, with one indicator dominating due to its dimensional characteristics, failing to accurately reflect the overall optimization level of the scheduling scheme. Therefore, standardization is necessary before constructing a multi-objective optimization function using basic weighting coefficients to ensure fair participation of each optimization objective in the evaluation. The three optimization objectives are processed separately using an extreme value standardization method. The value range for each objective is determined based on statistical data of similar tasks in the factory's history. For privacy risk valuation, the risk level is mapped to a standardized value, with lower risk corresponding to higher values. For task completion latency, the relative duration is mapped to a standardized value, with shorter durations corresponding to higher values. For task execution energy consumption... Energy consumption is mapped to a standardized value based on relative energy consumption, with lower energy consumption corresponding to higher values. The standardized values ​​of each optimization objective are multiplied by the adjusted basic weight coefficients and then summed to obtain the output value of the multi-objective optimization function. The higher the output value, the better the overall optimization effect of the scheduling scheme. Then, the output result of the multi-objective optimization function is validated. If the output value is less than a preset threshold, the standardization process and the setting of the basic weight coefficients are checked back. If necessary, manual intervention is triggered to investigate anomalies, ensuring that the output of the multi-objective optimization function can truly reflect the quality of the scheme. The standardization process eliminates the dimensional differences between different optimization objectives, enabling each optimization objective to participate in the evaluation fairly. The validity verification mechanism ensures the reliability of the multi-objective optimization function output, providing a scientific and reasonable evaluation basis for subsequent multi-objective particle swarm optimization algorithm solutions.

[0106] Furthermore, the constraints of the multi-objective optimization function include resource constraints, privacy constraints, and task constraints. Resource constraints characterize that the average CPU utilization and memory utilization of the computing node are less than or equal to the upper limit of the dynamic trust value.

[0107] Privacy constraint representation allows computing nodes whose dynamic trust values ​​meet the node trust boundary to participate in migration task scheduling, and the privacy risk estimate of the computing node is less than or equal to the leakage risk threshold.

[0108] Task constraints refer to the time constraints of cross-metropolitan area network migration tasks, including the transmission latency between computing nodes, the internal computing latency, and the time cost of verifying dynamic trust values. In addition, the total energy consumption of all computing nodes in the same metropolitan area network performing migration tasks shall not exceed the preset energy quota of the metropolitan area network.

[0109] Overloading compute node resources can trigger a series of production problems, leading to production line shutdowns or data processing anomalies. Furthermore, nodes with different trust levels exhibit varying hardware capabilities and capacity; high-trust nodes typically possess stronger resource capacity. Without properly limiting resource usage using dynamic trust values, high-trust nodes may become overloaded while low-trust nodes waste resources, impacting overall system stability. Therefore, it's necessary to define resource constraints in conjunction with dynamic trust values. This involves obtaining the dynamic trust value of each compute node, classifying them into different levels based on their dynamic trust value, and setting differentiated resource usage limits for each level: higher limits for high-trust nodes, medium limits for medium-trust nodes, and lower limits for low-trust nodes. Continuous monitoring and optimization are required. The system retrieves the resource usage status of computing nodes, calculates the average CPU utilization and memory utilization, and records it as the resource utilization rate. When the resource utilization rate exceeds the resource utilization limit of the corresponding computing node, the computing node is marked as temporarily unavailable and removed from the candidate nodes. When the resource utilization rate approaches the limit, an early warning notification is issued to remind maintenance personnel to pay attention. At the same time, additional resource priorities are set for critical equipment in the production control area to ensure that core production-related tasks receive priority resource support. When resources are scarce, priority is given to ensuring the resource needs of core tasks. Based on the differentiated resource constraints of dynamic trust values, the system achieves refined management of computing node resources, avoids production problems caused by resource overload, and ensures the resource needs of core production tasks through a priority mechanism, thereby improving the overall stability of the smart factory.

[0110] The leakage of core data in a smart factory can cause serious losses, necessitating strict risk control from the scheduling source. Allowing computing nodes that do not meet trust requirements or exceed risk thresholds to participate in core data migration directly threatens data security. This approach involves retrieving the leakage risk threshold and node trust boundaries of the current migration task and setting dual constraint rules. The first layer is an admission constraint based on the node trust boundary, allowing only two types of computing nodes to participate in scheduling: those with dynamic trust values ​​reaching the absolute trust boundary and those with dynamic trust values ​​at the conditional trust boundary and all additional protection measures enabled, directly excluding low-trust nodes. The second layer is a control constraint based on the leakage risk threshold. For computing nodes that pass the node trust boundary admission, their corresponding privacy risk estimates are further verified. Only computing nodes with privacy risk estimates not exceeding the leakage risk threshold are allowed to participate in the final scheduling, and the verification process and results are recorded. This dual privacy constraint constructs a security defense line from both node qualifications and risk levels, completely blocking the possibility of insecure nodes participating in core data migration and providing comprehensive protection for core data security.

[0111] Migration tasks across metropolitan area networks (MANs) involve unique trust verification steps, increasing task time. Ignoring this time cost can lead to timeouts. Furthermore, the factory has overall energy consumption control requirements for each MAN; without limiting total MAN energy consumption, the preset energy quota will be exceeded. Therefore, task constraints need to be specifically defined to cover the characteristics of cross-MAN tasks and energy consumption control needs. For cross-MAN migration tasks, the time cost of dynamic trust value verification should be additionally included in the time constraints, encompassing the entire process of verification request transmission, verification processing, and result feedback, ensuring the completeness and accuracy of the time constraints. For migration tasks within the same region… All computing nodes within the network monitor the total energy consumption of all migration tasks within the same metropolitan area network and compare it with the preset energy quota. When the total energy consumption approaches the preset energy quota, the scheduling of new high-energy-consuming tasks is restricted to ensure that the overall energy control requirements are not exceeded. For tasks that involve both cross-metropolitan area network and high-energy-consuming scheduling, time and energy constraints are comprehensively applied, and computing nodes and connection paths that can meet both time requirements and energy consumption standards are prioritized. The task constraints fully cover the special time costs of cross-metropolitan area network tasks and the energy control requirements within the same metropolitan area network, avoiding task timeouts or energy consumption exceeding standards due to lack of constraints, and ensuring the controllability of the overall scheduling of the smart factory.

[0112] Furthermore, generating a set of candidate solutions includes:

[0113] Initialize the multi-objective particle swarm optimization algorithm. Each particle represents a set of optimization scheduling schemes. Select the computing node whose dynamic trust value is greater than or equal to the absolute trust boundary as the initial position of the particle, and use the output value of the multi-objective optimization function as the particle fitness value.

[0114] In each iteration, the initial position of the particle is updated based on the individual optimal solution and the group optimal solution, and it is verified whether the updated initial position of the particle satisfies the constraints of the multi-objective optimization function. The set of initial solutions that pass the verification is output.

[0115] The initial solution set is then subjected to a second screening process to remove solutions whose privacy risk estimates exceed the leakage risk threshold, in order to generate a candidate solution set.

[0116] The initialization quality of the multi-objective particle swarm optimization (MPS) algorithm directly affects the efficiency and quality of subsequent solutions. Randomly selecting computational nodes as initial particle positions leads to the rapid elimination of many particles due to non-compliance with privacy constraints, wasting computational resources. Inappropriate fitness evaluation can cause deviations in the convergence direction of the MPS algorithm. By selecting nodes that meet the absolute trust boundary from the computational nodes and using these nodes as the possible initial particle positions, we avoid the direct elimination of initial particles due to privacy constraints. Each particle represents a complete optimization scheduling scheme, including elements such as the selection of target computational nodes, task execution paths, and resource allocation. Based on the optimization scheduling scheme corresponding to the particle, the fitness value is calculated using the multi-objective optimization function, reflecting the comprehensive optimization level of the optimization scheduling scheme. This initial screening of the particle swarm retains particles with high fitness while ensuring that particles cover different types of target computational nodes, avoiding a homogenized solution space and laying the foundation for subsequent iterative optimization. Therefore, initial particle selection based on the absolute trust boundary improves particle effectiveness and reduces invalid computation. Reasonable fitness evaluation and particle screening ensure the quality of the initial population, and diverse node coverage prevents the MPS algorithm from getting trapped in local optima.

[0117] Multi-objective particle swarm optimization (PSO) algorithms need to gradually approach the optimal solution through an iterative process. A single update strategy can lead to slow convergence or getting trapped in local optima. Without real-time constraint verification, a large number of infeasible solutions will be generated. Therefore, scientific iterative updates are necessary, dynamically adjusting particle positions based on constraints. In each iteration, the individual historical optimal solution and the swarm optimal solution for each particle are recorded. This information is used to adjust the particle's search direction and step size, while introducing appropriate random perturbations to prevent the PSO algorithm from getting trapped in local optima. After updating particle positions, the new optimization scheduling scheme is immediately checked to ensure it meets resource constraints, privacy constraints, and task constraints. For optimal scheduling schemes that satisfy all constraints, the current particle position is retained. For optimal scheduling schemes that do not satisfy the constraints, the particle position is reverted to the nearest feasible position, and the subsequent search strategy is adjusted to reduce the possibility of violating the rules again. After each iteration, all schemes that satisfy the constraints are collected to form an initial solution set, and reasonable iteration termination conditions are set to achieve a balance between convergence and computational efficiency in the multi-objective particle swarm optimization algorithm. Dynamic iterative updates combined with constraint verification ensure that the multi-objective particle swarm optimization algorithm converges efficiently to the feasible solution space. The random perturbation strategy increases the probability of finding the global optimum. The formation of the initial solution set provides a rich foundation for subsequent scheme selection.

[0118] The initial solution set contains some optimized scheduling schemes with privacy risks slightly exceeding the leakage risk threshold. Directly including these in the candidate set would pose security risks. Therefore, a secondary screening is required to ensure that the final candidate scheme set satisfies all constraints and possesses sufficient diversity to provide users with a wide range of choices. The secondary screening of the initial solution set focuses on verifying whether the privacy risk estimate of each optimized scheduling scheme is strictly less than or equal to the leakage risk threshold, eliminating all schemes that do not meet privacy requirements. For schemes that pass the privacy screening, their performance in terms of task completion latency and task execution energy consumption is further evaluated, retaining schemes with advantages in different dimensions to ensure that the candidate scheme set covers multiple optimization directions. For example, some schemes focus on the balance between privacy and time, while others focus on low energy consumption. The final candidate scheme set must contain a certain number of differentiated schemes to provide users with sufficient possibilities to choose according to their actual needs. The secondary screening ensures the security baseline of the candidate scheme set, and the retention of diverse optimized scheduling schemes provides users with flexible choices to meet scheduling needs in different scenarios. A high-quality candidate scheme set is the foundation for generating final scheduling instructions, providing a reliable basis for user strategy selection and scheduling instruction generation.

[0119] Specifically, generating scheduling instructions includes:

[0120] The user-selected strategy is transformed into a selection criterion for a set of candidate solutions. The strategies include security-first strategy, efficiency-first strategy, and balanced optimal strategy.

[0121] The optimal scheduling scheme is selected from the candidate scheme set based on the screening criteria. The optimal scheduling scheme includes the identification of the target computing node, the order of task execution, and the resource allocation ratio.

[0122] After verifying that the dynamic trust value of the target computing node meets the node trust boundary, a scheduling instruction is generated based on the selected optimized scheduling scheme.

[0123] Users select different scheduling strategies based on actual production needs. These strategies need to be translated into specific screening criteria to select the optimal scheduling solution that best meets the requirements from the candidate pool. Inaccurate translation will result in the selected optimal scheduling solution not matching the user's expectations. A mapping mechanism between strategies and screening criteria is established to transform the user's selected strategies into quantifiable screening conditions. For the security-first strategy, privacy risk assessment is set as the primary screening indicator, prioritizing the optimal scheduling solution with the lowest privacy risk assessment, while considering task completion latency and task execution energy consumption when privacy is comparable. For the efficiency-first strategy, task completion latency is the primary indicator, prioritizing the optimal scheduling solution with the shortest task completion latency, while ensuring that the privacy risk assessment does not exceed the limit. For the balanced optimal strategy, three indicators are comprehensively considered, selecting the optimal scheduling solution with relatively balanced performance across all indicators. The translated screening criteria are stored to ensure that the screening process strictly follows the user's strategy intent. Accurate strategy translation ensures that the selected optimal scheduling solution highly matches the user's needs, and the differentiated screening criteria under different strategies meet diverse production scheduling requirements.

[0124] The candidate solution set includes multiple optimized scheduling schemes that meet the constraints. The optimal optimized scheduling scheme must be selected based on the transformed screening criteria. Furthermore, the optimized scheduling scheme must include specific execution elements to guide the actual migration task execution. The candidate solution set is evaluated and ranked according to the transformed screening criteria, and the scheme with the best overall performance is selected as the optimized scheduling scheme. The optimized scheduling scheme must clearly include specific execution elements such as: the identifier of the target computing node, the task execution order of the migration task among the target computing nodes, and the resource allocation ratio of each target computing node. The selected optimized scheduling scheme undergoes a feasibility review to confirm whether the current resource status of the target computing nodes still meets the execution conditions, whether the resource allocation ratio is reasonable, and whether the task execution order conforms to the production process requirements. A scientific scheme selection process ensures the optimality and feasibility of the final optimized scheduling scheme. Clearly defined execution elements provide specific guidance for task implementation, avoiding ambiguity during the execution process.

[0125] Optimized scheduling schemes need to be translated into machine-executable scheduling instructions before being sent to target computing nodes for execution. These instructions must include all necessary execution parameters and ensure the target computing node still has the necessary execution capabilities to prevent them from becoming invalid due to changes in the node's resource status. The optimized scheduling scheme is then converted into standardized scheduling instructions, containing detailed information such as the target computing node's identifier, task data transmission path, resource allocation ratio, execution time requirements, and privacy protection activation instructions. Before generating instructions, the dynamic trust value of the target computing node is re-verified to ensure it still meets the node's trust boundary requirements and that its resource status still allows task execution. If the target computing node's resource status still meets the requirements, the scheduling instructions are generated and sent. If the target computing node's resource status no longer meets the requirements, an alternative optimized scheduling scheme is selected from the candidate set, and a new scheduling instruction is generated. The scheduling instructions are transmitted to the target computing node using encryption to ensure the security of the transmission process and prevent tampering or interception. Standardized scheduling instructions ensure that the target computing node can accurately understand and execute the task requirements. Pre-delivery status verification prevents scheduling instructions from becoming invalid, and encrypted transmission ensures the security of the scheduling instructions, comprehensively ensuring that the migration task is executed as planned.

[0126] S3. Issue scheduling instructions to the target computing node and execute the migration task. Continuously monitor the actual behavior data of the target computing node throughout the entire migration task execution process, conduct privacy compliance audits on the actual behavior data, and feed the privacy compliance performance as new evidence to Bayesian inference to correct the dynamic trust value of each computing node.

[0127] Furthermore, conducting privacy compliance audits on actual behavioral data includes:

[0128] The scheduling instructions are sent to the target computing node and the migration task is executed. The actual behavior data of the target computing node is continuously monitored throughout the entire process of the migration task. The actual behavior data includes data operation behavior, resource usage behavior and protocol compliance behavior.

[0129] An audit rule base is built based on data sensitivity, leakage risk threshold and privacy constraints. Actual behavioral data is matched and verified with the audit rule base to determine whether there are violations and the types of violations, so as to generate audit intermediate results and associate the audit intermediate results with the task execution order.

[0130] The audit intermediate results are summarized according to the execution cycle of the migration task, and the compliance level is determined based on the summarized number of violations and the proportion of violation types, so as to generate a privacy compliance performance including compliance level, violation type, actual execution data and target computing node identifiers.

[0131] In smart factories, different types of computing nodes face varying privacy risks during task execution. PLC controllers may leak process recipes due to operational errors, edge servers may be illegally accessed due to protocol compatibility issues, and office terminals may copy attendance data through external storage devices. If only a unified monitoring method is used, it is easy to miss behavioral anomalies specific to industrial scenarios, such as PLC ladder diagram program tampering and illegal data transmission through server ports. After the scheduling command is issued to the target computing node through the factory's industrial Ethernet and the migration task is initiated, the actual behavioral data is acquired according to the type of the target computing node based on the factory's equipment monitoring system. For PLC controllers in the production control area, the internal register data is read in real time through the OPCUA protocol to record the read and write addresses of process recipes, the source of modification instructions, and the data CRC check value. At the same time, the real-time changes in CPU load rate and memory usage rate are also acquired.

[0132] For edge servers in the data center area, system logs and custom audit scripts are used to track changes in access permissions for production video files, transmission target ports, and disk I / O read / write frequencies, monitoring for unauthorized account operations or external IP access. For terminal devices in the office area, the opening, copying, and deleting of attendance data are recorded, verifying whether the terminal access network type is the factory-designated VPN and whether there is any writing of data to non-factory domain storage devices. All acquired actual behavior data is stored using a combination of local caching and cloud synchronization to avoid data loss due to network interruptions, ensuring full coverage and no omissions in the monitoring process. By designing monitoring schemes according to the type of target computing nodes, the unique risk points of different devices in industrial scenarios are accurately captured, avoiding risk omissions caused by general monitoring methods. The storage mechanism of local caching and cloud synchronization ensures the integrity and traceability of actual behavior data, providing a reliable data foundation for subsequent compliance audits.

[0133] The original actual behavior data consists only of scattered operation records, making it impossible to directly determine whether it meets privacy and security requirements. Therefore, it is necessary to combine the privacy preference parameters of the migration task with the privacy constraints of the multi-objective optimization function to construct targeted audit rules. Through rule matching, the scattered data is transformed into structured audit judgment results. Simultaneously, the task execution sequence is correlated to clarify the specific stages where violations occurred, providing a clear basis for subsequent compliance level assessments. Based on data sensitivity, leakage risk thresholds, and privacy constraints, an audit rule base covering data operations, resource usage, and protocol compliance is constructed. For highly sensitive data, i.e., process recipes, rules are set to prohibit transmission to nodes with non-absolute trust boundaries, require authorization verification for reading and writing, and require double encryption for transmission. For moderately sensitive data, i.e., attendance records, rules are set to prohibit transmission to external terminals and require basic encryption for transmission. For low-sensitivity data, i.e., workshop temperature and humidity, only the transmission recipient needs to be recorded.

[0134] The acquired behavioral data is compared against the audit rule base item by item. If the PLC controller transmits process recipes to an unknown IP terminal, it is judged as a data operation violation; if the edge server's memory usage continuously exceeds the quota allocated by the scheduling instruction, it is judged as a resource usage violation; if the office terminal does not access the network through the factory VPN, it is judged as a protocol compliance violation. When generating each violation judgment result, the corresponding stage in the task execution sequence is synchronously associated, such as the data transmission stage, data storage stage, or task completion stage, forming an audit intermediate result containing the violation type, violation stage, associated behavioral data, and the identifier of the target computing node. This result is stored in the factory audit rule base in a unified format. The audit rule base stores the corresponding data operation, resource usage, and protocol compliance requirements in a structured form based on a unified format, and stores audit results and corresponding instances, including the storage of historical data and the iterative updates of real-time data. By constructing the audit rule base, accurate matching between privacy preference parameters and behavioral data is achieved, avoiding misjudgments or omissions caused by general rules. Associating the task execution sequence makes the audit results more targeted, facilitating subsequent analysis of risk characteristics at different stages and providing direction for optimizing privacy protection strategies.

[0135] Intermediate audit results are individual violation records, which need to be summarized and analyzed according to the task execution cycle. Combining the severity and frequency of violations, the overall compliance level of the target computing node is comprehensively judged. At the same time, the actual execution data and the identifier of the target computing node are integrated to form a complete privacy compliance performance, providing a comprehensive and accurate basis for subsequent dynamic trust value correction. According to the execution cycle of the migration task, all intermediate audit results within the corresponding execution cycle are extracted and classified and statistically analyzed according to the severity of violations. Violations of highly sensitive data and multiple general violations are classified as serious violations, violations of medium and low sensitive data and single resource exceedances are classified as general violations, and brief protocol handshake failures and slight resource fluctuations are classified as minor violations.

[0136] The system analyzes the frequency and percentage of various violations within the execution cycle to identify core risk points, such as an excessively high proportion of unauthorized transmissions in serious violations and a concentrated concentration of resource overruns in general violations. Based on the statistical results and in conjunction with smart factory security management regulations, compliance levels are determined: excellent (no serious violations, no more than two general violations, and no more than three minor violations); qualified (no serious violations, no more than three general violations, and no more than four minor violations); and unqualified (serious violations or more than three general violations). The system integrates compliance levels, violation types, actual execution data, and target computing node identifiers to form a complete privacy compliance performance. By summarizing and classifying violations by execution cycle, the system transforms individual violation records into overall compliance levels, avoiding assessment bias caused by viewing violations in isolation. Integrating multi-dimensional information on privacy compliance performance provides a comprehensive basis for subsequent dynamic trust value adjustments, ensuring the accuracy and reliability of the correction process.

[0137] Specifically, such as Figure 3 As shown, correcting the dynamic trust value of each compute node includes:

[0138] The compliance level and violation type in privacy compliance performance are transformed into new evidence that can be identified by Bayesian inference, and the identifier of the target computing node is automatically matched to update the evidence pool of the target computing node.

[0139] Based on the prior trust value of the target computing node, the posterior probability of the target computing node is updated by combining new evidence to correct the dynamic trust value and store the correction record.

[0140] The corrected dynamic trust value is compared with the absolute trust boundary to determine whether the candidate solution set is regenerated. The correction records of the dynamic trust values ​​of all computing nodes and their privacy compliance performance are summarized periodically to dynamically adjust the initial weight of the likelihood function.

[0141] Bayesian inference relies on structured evidence to update dynamic trust values. Information such as compliance level and violation type in privacy compliance performance needs to be transformed into evidence formats recognizable by Bayesian inference. Simultaneously, it must be precisely correlated with the target computing node to avoid evidence mismatch leading to deviations in dynamic trust value correction. This ensures that Bayesian inference can iteratively optimize trust assessment results based on the latest compliance performance of the target computing node. Cases with an excellent compliance level and no core risk violations are transformed into strong positive evidence, correlated with historical privacy compliance performance in the dynamic trust value assessment framework. Cases with a satisfactory compliance level and minor violations are transformed into weak positive evidence, also correlated with historical privacy compliance performance. Cases with an unsatisfactory compliance level and serious violations are transformed into strong negative evidence based on the violation type. For violations involving highly sensitive data, historical privacy compliance performance and protocol compatibility are correlated; for violations involving resource usage, resource stability is correlated.

[0142] The transformed structured evidence is then bound to the identifiers of the target computing node, including the device number of the PLC controller and the IP address of the edge server, to ensure that the new evidence accurately corresponds to the target computing node. The bound new evidence is then written into the target computing node's dedicated evidence pool, stored in order of evidence generation time, and expired evidence is periodically cleaned up while recent valid evidence is retained, ensuring that the evidence pool reflects the latest compliance status of the target computing node. Through the effective transformation of privacy compliance performance into structured evidence, the problem that Bayesian inference cannot directly recognize natural language descriptions is solved. The node identifier binding and evidence pool management ensure that the new evidence accurately matches the node and reflects the latest status, providing reliable input for Bayesian inference.

[0143] The dynamic trust value of a computing node needs to be adjusted in real time based on the latest compliance performance. Relying solely on historical trust values ​​can lead to trust assessments lagging behind the actual resource status of the computing node. For example, a node may have frequent violations recently, but its trust value remains high, potentially triggering subsequent scheduling risks. Furthermore, the entire process of correcting the dynamic trust value must be recorded to facilitate subsequent security audits and issue tracing, ensuring the traceability and reliability of the entire trust assessment system. The system retrieves the target computing node's prior trust value from the previous period and combines it with the latest structured evidence in the evidence pool to initiate Bayesian inference. If strong positive evidence is input, Bayesian inference increases the posterior probability of the corresponding assessment dimension, thereby increasing the target computing node's dynamic trust value. If strong negative evidence is input, Bayesian inference decreases the posterior probability of the corresponding assessment dimension, causing the target computing node's dynamic trust value to drop. If weak positive evidence is input, Bayesian inference only slightly adjusts the posterior probability of the corresponding assessment dimension, keeping the dynamic trust value relatively stable.

[0144] Based on the posterior probability output by Bayesian inference and combined with the dimensional weights of the evaluation framework, the dynamic trust value of the node in the current period is calculated, overriding and storing the dynamic trust value of the previous period. Simultaneously, during the recording of dynamic trust value correction, key information is recorded in detail, including the target computing node's identifier, correction time, dynamic trust value before correction, dynamic trust value after correction, type of evidence used, source of evidence, and changes in the posterior probability of each evaluation dimension, ensuring the correction process is traceable and verifiable. By correcting the dynamic trust value through Bayesian inference combined with new evidence, the trust assessment can reflect the actual compliance level of the target computing node in real time, avoiding scheduling risks caused by lag in dynamic trust values. Recording the entire correction process meets the needs of security auditing and issue tracing, enhancing the reliability and credibility of the trust assessment system.

[0145] If the corrected dynamic trust value is less than the absolute trust boundary, the target computing node no longer meets the privacy and security requirements of the current or subsequent migration tasks. Therefore, the candidate solution set needs to be regenerated promptly, and a suitable target computing node needs to be replaced to prevent the expansion of privacy risks. Furthermore, long-term dynamic trust value correction records and privacy compliance performance can reflect the risk characteristics of the target computing node. The corrected dynamic trust value is compared with the absolute trust boundary. If the dynamic trust value is less than the absolute trust boundary and the target computing node is currently performing a migration task, a candidate solution set regeneration signal is immediately sent. A backup computing node with a suitable dynamic trust value is selected from the existing candidate solution set to replace the current target computing node and continue performing the migration task, ensuring privacy and security during the migration process.

[0146] If the target compute node does not perform a migration task, only the node's trust status is updated, without triggering a regeneration process. The dynamic trust value correction records and privacy compliance performance of all compute nodes are periodically summarized. The high incidence of violations across different evaluation dimensions is analyzed. If the violation rate of a certain dimension, such as protocol compatibility, increases significantly, it indicates that the initial weight of that dimension in the current likelihood function is too low and needs to be appropriately increased to make subsequent trust evaluations focus more on that dimension. If the violation rate of a certain dimension continues to decrease, its initial weight is appropriately decreased to avoid over-evaluation. The adjusted initial weight of the likelihood function is synchronized to Bayesian inference for use in the next cycle's dynamic trust value calculation. The system continuously optimizes the performance of Bayesian inference; by triggering the regeneration of the candidate solution set, it promptly replaces computing nodes with substandard dynamic trust values, effectively avoiding privacy risks and ensuring the secure execution of migration tasks. It dynamically adjusts the initial weights of the likelihood function, enabling trust assessment to adapt to changes in node risk characteristics, improving long-term assessment accuracy, and perfecting the entire trust assessment system. The regeneration of the candidate solution set directly ensures the continuous secure execution of the current migration task, while the adjusted initial weights of the likelihood function provide optimized Bayesian inference parameters for subsequent dynamic trust value calculations, ensuring that the entire scheduling optimization method forms a closed-loop iteration and continuously improves privacy protection and scheduling efficiency.

Claims

1. A method for optimizing the scheduling of privacy-preserving computing migration tasks in a metropolitan area network, characterized in that, include: Obtain the resource status of computing nodes in the metropolitan area network, and process the resource status through Bayesian inference to determine the dynamic trust value of each computing node in real time; Receive migration task requests submitted by users, parse and extract privacy preference parameters, and determine the privacy risk estimate between the migration task and the computing node based on the dynamic trust value and privacy preference parameters; A multi-objective optimization function is constructed based on privacy risk assessment, task completion latency, and task execution energy consumption, and constraints on the multi-objective optimization function are defined. The construction of the multi-objective optimization function includes: Based on the topology of the metropolitan area network, the transmission latency of the migration task between different computing nodes is determined, the internal computing latency of each computing node in processing the migration task is obtained synchronously, and the task completion latency is obtained by summing them. The unit energy consumption of the migration task is determined based on the resource status of the computing nodes, and the task execution energy consumption is obtained by combining the data volume and execution time of the migration task. With privacy risk assessment, task completion latency, and task execution energy consumption as optimization objectives, a basic weight coefficient is set for each optimization objective, and the basic weight coefficient is dynamically adjusted according to the type of migration task; The optimization objective is standardized, and the standardized optimization objective is weighted and summed with the adjusted basic weight coefficients to construct a multi-objective optimization function. The constraints of the multi-objective optimization function include resource constraints, privacy constraints, and task constraints. The resource constraint indicates that the average CPU utilization and memory utilization of the computing node are less than or equal to the upper limit of the dynamic trust value. Privacy constraint representation allows computing nodes whose dynamic trust values ​​meet the node trust boundary to participate in migration task scheduling, and the privacy risk estimate of the computing node is less than or equal to the leakage risk threshold. Task constraints refer to the time constraints of cross-metropolitan area network migration tasks, including the transmission latency between computing nodes, the internal computing latency, and the time cost of verifying dynamic trust values. In addition, the total energy consumption of all computing nodes in the same metropolitan area network performing migration tasks shall not exceed the preset energy quota of the metropolitan area network. A multi-objective optimization function is solved by a multi-objective particle swarm optimization algorithm to generate a candidate scheme set. At the same time, an optimized scheduling scheme is selected from the candidate scheme set according to the strategy selected by the user to generate a scheduling instruction. The scheduling instructions are issued to the target computing node and the migration task is executed. The actual behavior data of the target computing node is continuously monitored throughout the entire process of the migration task. Perform privacy compliance audits on actual behavioral data and use the privacy compliance performance as new evidence to feed back into Bayesian inference to correct the dynamic trust value of each computing node.

2. The method for optimizing the scheduling of privacy-preserving computation migration tasks in a metropolitan area network as described in claim 1, characterized in that, The determination of privacy risk assessment between the migration task and the computing node includes: By combining the dynamic trust value of computing nodes and the data sensitivity of migration tasks, a basic value for privacy risk is determined, and the fusion weight of dynamic trust value and data sensitivity is dynamically adjusted according to the type of migration task. The baseline privacy risk value is adjusted based on the historical privacy compliance performance of the computing nodes, and the adjusted baseline privacy risk value is calibrated with the leakage risk threshold as a constraint. If the revised baseline value of privacy risk is less than or equal to the disclosure risk threshold, then the revised baseline value of privacy risk will be used as the privacy risk estimate. If the revised baseline privacy risk value is greater than the leakage risk threshold, then a decision is made based on the node trust boundary to determine whether to rematch the computing node in order to determine the privacy risk estimate between the migration task and the computing node.

3. The method for optimizing the scheduling of privacy-preserving computation migration tasks in a metropolitan area network as described in claim 2, characterized in that, The real-time determination of the dynamic trust value of each computing node includes: An evaluation framework for dynamic trust values ​​is established, using the historical privacy compliance performance, resource stability, and collaborative trustworthiness of computing nodes as evaluation dimensions. For newly connected computing nodes in the metropolitan area network, a basic trust value is determined based on the resource status of the computing node, forming a prior trust value based on Bayesian inference. The likelihood function for Bayesian inference is determined based on the resource status and protocol adaptation of the computing nodes, and the initial weight of the likelihood function is dynamically adjusted based on the runtime of the computing nodes in the metropolitan area network. The resource status of computing nodes is acquired at preset intervals and preprocessed before being input into Bayesian inference to obtain posterior probabilities. The prior trust values ​​of computing nodes in the previous period are iteratively updated to determine the dynamic trust value of each computing node in real time.

4. The method for optimizing the scheduling of privacy-preserving computation migration tasks in a metropolitan area network as described in claim 3, characterized in that, The extraction of privacy preference parameters includes: Receive migration task requests submitted by users, extract the data type of the migration task through natural language processing, determine the basic sensitivity level based on the data type, and adjust the basic sensitivity level in combination with the application scenario of the migration task to extract the data sensitivity level; The leakage risk description set by the user in the migration task request is analyzed and calibrated in combination with the historical privacy compliance performance of similar migration tasks in the metropolitan area network to extract the leakage risk threshold. The node trust boundary is defined by combining the evaluation framework of dynamic trust value. The node trust boundary includes absolute trust boundary and conditional trust boundary. The absolute trust boundary represents the dynamic trust value for processing different data sensitivity levels, and the conditional trust boundary adds protection conditions to computing nodes that are close to but have not reached the absolute trust boundary.

5. The method for optimizing the scheduling of privacy-preserving computation migration tasks in a metropolitan area network as described in claim 4, characterized in that, The generated scheduling instructions include: The user-selected strategy is transformed into a selection criterion for a set of candidate solutions. The strategies include security-first strategy, efficiency-first strategy, and balanced optimal strategy. The optimal scheduling scheme is selected from the candidate scheme set based on the screening criteria. The optimal scheduling scheme includes the identification of the target computing node, the order of task execution, and the resource allocation ratio. After verifying that the dynamic trust value of the target computing node meets the node trust boundary, a scheduling instruction is generated based on the selected optimized scheduling scheme.

6. The method for optimizing the scheduling of privacy-preserving computation migration tasks in a metropolitan area network as described in claim 5, characterized in that, The generated candidate solution set includes: Initialize the multi-objective particle swarm optimization algorithm. Each particle represents a set of optimization scheduling schemes. Select the computing node whose dynamic trust value is greater than or equal to the absolute trust boundary as the initial position of the particle, and use the output value of the multi-objective optimization function as the particle fitness value. In each iteration, the initial position of the particle is updated based on the individual optimal solution and the group optimal solution, and it is verified whether the updated initial position of the particle satisfies the constraints of the multi-objective optimization function. The set of initial solutions that pass the verification is output. The initial solution set is then subjected to a second screening process to remove solutions whose privacy risk estimates exceed the leakage risk threshold, in order to generate a candidate solution set.

7. The method for optimizing the scheduling of privacy-preserving computation migration tasks in a metropolitan area network as described in claim 6, characterized in that, The process of correcting the dynamic trust value of each computing node includes: The compliance level and violation type in privacy compliance performance are transformed into new evidence that can be identified by Bayesian inference, and the identifier of the target computing node is automatically matched to update the evidence pool of the target computing node. Based on the prior trust value of the target computing node, the posterior probability of the target computing node is updated by combining new evidence to correct the dynamic trust value and store the correction record. The corrected dynamic trust value is compared with the absolute trust boundary to determine whether the candidate solution set is regenerated. The correction records of the dynamic trust values ​​of all computing nodes and their privacy compliance performance are summarized periodically to dynamically adjust the initial weight of the likelihood function.

8. The method for optimizing the scheduling of privacy-preserving computation migration tasks in a metropolitan area network as described in claim 7, characterized in that, The aforementioned privacy compliance audit of actual behavioral data includes: The scheduling instructions are sent to the target computing node and the migration task is executed. The actual behavior data of the target computing node is continuously monitored throughout the entire process of the migration task. The actual behavior data includes data operation behavior, resource usage behavior and protocol compliance behavior. An audit rule base is built based on data sensitivity, leakage risk threshold and privacy constraints. Actual behavioral data is matched and verified with the audit rule base to determine whether there are violations and the types of violations, so as to generate audit intermediate results and associate the audit intermediate results with the task execution order. The audit intermediate results are summarized according to the execution cycle of the migration task, and the compliance level is determined based on the summarized number of violations and the proportion of violation types, so as to generate a privacy compliance performance including compliance level, violation type, actual execution data and target computing node identifiers.

Citation Information

Patent Citations

  • Calculation migration method considering privacy protection in wireless metropolitan area network environment

    CN110753117A

  • Market supervision data asset management method and system based on compliance and privacy protection

    CN120296788A