Intelligent Redundancy Switching Control Method and System for Optoelectronic Hybrid Interface
By collecting multi-source heterogeneous data in an optoelectronic hybrid computing network to generate link state ambiguity, a dual-mode intelligent decision-making framework that prioritizes efficiency optimization and diagnosis is realized. This solves the link switching problem of the optoelectronic hybrid computing network under cognitive domain attacks and improves the network's robustness and self-healing ability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-27
- Publication Date
- 2026-03-03
AI Technical Summary
When faced with cognitive domain attacks, existing optoelectronic hybrid computing networks rely on a single network monitoring data source, which can be easily deceived, leading to incorrect link switching decisions and affecting network stability and reliability.
By collecting real-time monitoring data, historical performance data, and hardware trust anchor data from the physical layer, link status ambiguity is generated. Combined with preset weight coefficients, a dual-mode intelligent decision-making framework that prioritizes efficiency optimization and diagnosis is implemented to switch links.
It improves the network's situational awareness robustness in complex adversarial environments, ensures business continuity and network performance, and enhances self-healing capabilities and resilience.
Smart Images

Figure CN121217472B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of computing power network communication, network security and intelligent control technology, specifically to an intelligent redundancy switching control method and system for optoelectronic hybrid interfaces. Background Technology
[0002] In advanced network environments such as optoelectronic hybrid computing, intelligent redundant link switching is a core technology to ensure network performance and service stability. Control systems typically formulate optimal switching strategies based on real-time monitoring data from the physical layer, such as throughput and latency, to achieve efficient data transmission.
[0003] Existing technologies have serious flaws in the decision-making process, as they rely excessively on a single network monitoring data source. This design makes them extremely vulnerable to cognitive domain attacks, where attackers can deceive the control system by tampering with or contaminating real-time monitoring data.
[0004] Due to the lack of cross-validation and evaluation capabilities for the credibility of the data source itself, the system cannot distinguish between genuine network fluctuations and malicious false information; this can lead to the system making incorrect switching decisions based on contaminated data, causing serious consequences such as network congestion and business interruption, and seriously threatening the stability and reliability of the network.
[0005] Therefore, how to establish a system that can quantitatively assess the credibility of link state information and resist the risk of decision-making based on contaminated data, thereby improving the robustness of the network in complex adversarial environments, is a technical problem that urgently needs to be solved in this field.
[0006] The information disclosed in the background section above is only intended to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention
[0007] To address the aforementioned technical problems, this invention discloses an intelligent redundancy switching control method and system for optoelectronic hybrid interfaces. Specifically, the technical solution of this invention is as follows:
[0008] The intelligent redundancy switching control method for optoelectronic hybrid interfaces includes:
[0009] For candidate links, collect real-time physical layer monitoring data, historical performance data, and hardware trust anchor data;
[0010] Based on real-time monitoring data of the physical layer, generate a physical layer state vector;
[0011] Generate historical performance state vectors based on historical performance data;
[0012] Based on hardware trust anchor data, generate a hardware trust state vector;
[0013] The first vector deviation is determined based on the physical layer state vector and the historical performance state vector;
[0014] The second vector deviation is determined based on the physical layer state vector and the hardware trust state vector.
[0015] By combining the first vector deviation, the second vector deviation, and the preset weight coefficients, link state ambiguity is generated;
[0016] In response to the link status ambiguity being less than a preset ambiguity threshold, efficiency optimization mode is activated to perform link switching;
[0017] If the link status ambiguity is not less than a preset ambiguity threshold, enable the diagnostic priority mode to perform link switching.
[0018] Preferably, an efficiency optimization mode is enabled to perform link switching, including:
[0019] Link switching decisions are generated based on a network performance-oriented intelligent decision-making model.
[0020] Preferably, enabling diagnostic priority mode to perform link switching includes:
[0021] A predetermined proportion of critical business traffic will be forcibly switched from candidate links to the baseline trusted link.
[0022] Actively probe candidate links to generate verified link states.
[0023] Preferably, the size of the preset ratio is positively correlated with the size of the link state ambiguity.
[0024] Preferably, the method further includes:
[0025] Based on active detection, the ambiguity after verification is recalculated;
[0026] If the ambiguity remains below the preset recovery threshold within a preset time window after verification, the system will switch from the diagnostic priority mode to the efficiency optimization mode.
[0027] Preferably, the method further includes:
[0028] Real-time physical layer monitoring data originates from network monitoring protocols;
[0029] Historical performance data is derived from a database that reflects the long-term baseline behavior of the link;
[0030] The hardware trust anchor data originates from the Trusted Platform module.
[0031] The intelligent redundancy switching control system for optoelectronic hybrid interfaces includes:
[0032] The status acquisition unit is used to collect real-time physical layer monitoring data, historical performance data, and hardware trust anchor data for candidate links.
[0033] The fuzzy quantification unit is used to generate link state fuzziness based on real-time physical layer monitoring data, historical performance data, and hardware trust anchor data.
[0034] The decision control unit is used to receive link status ambiguity and output efficiency optimization mode instructions or diagnostic priority mode instructions based on the comparison result with the preset ambiguity threshold.
[0035] The strategy execution unit is used to perform link switching in response to efficiency optimization mode instructions or diagnostic priority mode instructions.
[0036] Preferably, the fuzzy quantization unit includes:
[0037] The vector generation module is used to generate physical layer state vectors, historical performance state vectors, and hardware trust state vectors based on three types of data, respectively.
[0038] The deviation determination module is used to determine the first vector deviation between the physical layer state vector and the historical performance state vector, and the second vector deviation between the physical layer state vector and the hardware trust state vector.
[0039] The ambiguity generation module is used to combine the first vector deviation, the second vector deviation, and the preset weight coefficients to generate link state ambiguity.
[0040] Preferably, the strategy execution unit is used for:
[0041] In response to the diagnostic priority mode command, a preset proportion of critical business traffic is switched from candidate links to baseline trusted links, and proactive probing is initiated on candidate links.
[0042] Compared with the prior art, the present invention has the following beneficial effects:
[0043] 1. This invention constructs a quantitative evaluation model for link state ambiguity by integrating three heterogeneous data sources: real-time physical layer data, historical performance baselines, and hardware trust anchors. This model effectively addresses the shortcomings of traditional methods that rely on a single data source and are easily deceived by cross-validating the consistency between real-time state and historical / hardware states. When real-time monitoring data is contaminated by cognitive domain attacks, this multi-dimensional inconsistency increases dramatically, enabling accurate identification and quantification of information contamination risks, and significantly improving the system's situational awareness robustness in complex adversarial environments.
[0044] 2. This invention proposes a dual-mode intelligent decision-making framework that combines efficiency optimization with a diagnosis-first approach. Based on real-time calculated link state ambiguity, the system employs a performance-oriented model to maximize network efficiency when information is reliable; when information is unreliable, it switches to a diagnosis-first mode to ensure the continuity of core services while conducting proactive probing. This adaptive switching mechanism achieves a dynamic balance between network performance and security risks, avoiding the sacrifice of conventional performance due to the introduction of security mechanisms and preventing the risk of catastrophic decisions based on contaminated information.
[0045] 3. In the diagnosis-first mode, this invention designs a closed-loop self-healing mechanism that combines sacrifice and verification. By switching some critical services positively correlated with the risk level to trusted links, precise and dynamic protection of core services is achieved. Simultaneously, the true state of the link is verified through an independent active probing channel, and the system automatically recovers to high-efficiency mode based on the verified trustworthiness. This design not only ensures service continuity under threats but also achieves a complete closed loop of risk isolation, state confirmation, and automatic recovery in attack event response, significantly enhancing the network's resilience and self-healing capabilities.
[0046] 4. This invention decouples system functions into four modular units: state acquisition, fuzzy quantification, decision control, and policy execution, forming a dynamic feedback loop. This architecture not only makes the system implementation logic clear and easy to engineer and upgrade in the future, but more importantly, it streamlines the perception-cognition-decision-execution process of link state, enabling the system to continuously and autonomously adapt to changes in the network environment and potential threats, thus endowing the network with an inherent, intelligent adaptive defense and recovery capability. Attached Figure Description
[0047] The present invention will be further explained below with reference to the accompanying drawings and embodiments:
[0048] Figure 1 This is a flowchart of the method of the present invention.
[0049] Figure 2 This is a system structure diagram of the present invention. Detailed Implementation
[0050] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to specific embodiments.
[0051] Example 1:
[0052] Please see Figure 1 Intelligent redundancy switching control method for optoelectronic hybrid interfaces:
[0053] For candidate links, collect real-time physical layer monitoring data, historical performance data, and hardware trust anchor data;
[0054] Based on real-time monitoring data of the physical layer, generate a physical layer state vector;
[0055] Generate historical performance state vectors based on historical performance data;
[0056] Based on hardware trust anchor data, generate a hardware trust state vector;
[0057] The first vector deviation is determined based on the physical layer state vector and the historical performance state vector;
[0058] The second vector deviation is determined based on the physical layer state vector and the hardware trust state vector.
[0059] By combining the first vector deviation, the second vector deviation, and the preset weight coefficients, link state ambiguity is generated;
[0060] In response to the link status ambiguity being less than a preset ambiguity threshold, efficiency optimization mode is activated to perform link switching;
[0061] If the link status ambiguity is not less than a preset ambiguity threshold, enable the diagnostic priority mode to perform link switching;
[0062] To implement an intelligent redundancy handover control method for a hybrid optoelectronic interface, in a hybrid optoelectronic computing network environment, the following steps are performed for a candidate link that serves as the handover target:
[0063] For candidate links, multi-source heterogeneous state data is collected. The purpose of this step is to provide independent and cross-validable data inputs for subsequent link state reliability assessment, avoiding global misjudgments due to contamination of a single data source. Data collection is achieved through the following three dimensions:
[0064] The acquisition of physical layer real-time monitoring data refers to the acquisition of instantaneous parameters reflecting the current physical state of the link directly from network devices through standard network monitoring protocols such as SNMP or NetFlow; its function is to capture the instantaneous dynamics of the network, and the data content may include current throughput, latency, packet loss rate, and bit error rate.
[0065] Historical performance data collection refers to the extraction of data from a long-running monitoring database, which reflects the statistical behavior baseline of the link over a relatively long period of time. Its purpose is to provide a stable reference for judging whether the current state deviates from its normal performance. The data content may include the moving average, variance, or periodic fluctuation pattern of the aforementioned physical parameters.
[0066] The collection of hardware trust anchor data refers to the data obtained from hardware security modules such as Trusted Platform Module (TPM) built into network devices at both ends of the link, which is used to characterize the underlying integrity and operating status of the devices. Its function is to provide a physical security level judgment basis for the trustworthiness of the devices themselves, independent of network performance. It is an integrity measurement report of the hardware security module.
[0067] Based on the three types of heterogeneous data collected above, physical layer state vectors with uniform dimensions and mathematical comparability are generated respectively. Historical performance state vector Hardware Trust State Vector The purpose of this step is to structure and normalize raw data from different sources and in different formats, transforming them into state vectors that can be compared within the same mathematical framework. Each vector is processed into an n-dimensional normalized vector, where each dimension corresponds to a specific network state indicator, ensuring... , and The three are completely consistent in their dimension definitions and element arrangements;
[0068] To achieve this step, the following processing method can be adopted: For various performance indicators in real-time monitoring data and historical performance data of the physical layer, such as throughput, latency, and packet loss rate, the max-min normalization method is uniformly adopted to map the values to the [0,1] interval; for hardware trust anchor data, its binary integrity measurement report can be quantified: if the report verification passes, the corresponding vector dimension is assigned a value of 1, representing complete trust; if the verification fails, it is assigned a value of 0, representing complete untrustworthiness; through the above method, all data from all sources are uniformly processed into dimensionless values in the [0,1] interval, thereby constructing a state vector with completely consistent dimensions and definitions. , and ;
[0069] The process involves calculating the deviation and generating link state ambiguity. This step aims to transform the data reliability issue into a calculable and quantifiable engineering metric. Based on the physical layer state vector and historical performance state vector, a first vector deviation is determined. A second vector deviation is determined based on the physical layer state vector and hardware trust state vector. Finally, by combining the first vector deviation, the second vector deviation, and preset weighting coefficients, the link state ambiguity is generated. The formula for calculating this ambiguity is defined as follows:
[0070] ;
[0071] in, For link At any moment The state ambiguity is a dimensionless scalar, calculated by this formula; it represents a weighted comprehensive measure of the deviation between the current link monitoring data and the historical baseline and the trusted state of the hardware. The higher the value, the greater the possibility that the real-time data of the physical layer is contaminated by cognitive domain attacks.
[0072] , , These are the physical layer state vector, historical performance state vector, and hardware trust state vector, respectively, which are normalized n-dimensional vectors generated by the preceding steps.
[0073] This is a vector difference metric function, and its output is a dimensionless scalar. Cosine distance and other vector distance calculation algorithms can be used to quantify the degree of inconsistency between two state vectors. In scenarios where the order of magnitude of indicators such as throughput and packet loss rate varies greatly, cosine distance is recommended because it is sensitive to changes in vector direction and can eliminate the influence of dimensions. In scenarios where the values of each indicator are relatively stable, Euclidean distance can also be used because it is more sensitive to differences in the magnitude of vector values.
[0074] , The preset dimensionless weighting coefficients satisfy... , , The calibration process for this set of parameters involves constructing a calibration dataset containing normal and simulated attack data during the offline simulation phase before system deployment, and then optimizing it using methods such as receiver operation feature ROC curve analysis. The purpose is to optimize the model's sensitivity to attack detection.
[0075] Specifically, the calibration dataset can contain at least 1000 hours of normal operation data, as well as simulated attack data; the simulated attack data should cover at least two attack types: instantaneous impact attacks, which involve tampering with real-time throughput data to less than 5% of its historical average at random time points for 1-5 seconds; and persistent contamination attacks, which involve continuously adding 10-20ms of random noise to real-time latency data; by adjusting... and For example, the step size is 0.1 to 0.9. Simulations are run to calculate the true positive rate and false positive rate under different attack scenarios. The point on the ROC curve that is closest to the top left corner, i.e., maximizing the detection rate and minimizing the false positive rate, is selected. and value;
[0076] This calculation formula establishes a cross-validation model; a healthy link, its current physical state. It should be in line with its long historical performance and its hardware trust status Maintain a high degree of consistency; when a cognitive domain attack occurs and is tampered with hour, Simultaneously with relatively stable and A significant deviation was caused, resulting in and At least one or both increase simultaneously, thus making the final The value rises sharply, forming a clear attack warning signal;
[0077] Decision mode switching based on link state ambiguity;
[0078] Response to link state ambiguity The system determines that the monitoring information for the current link is reliable, and then activates the efficiency optimization mode to perform link switching; a preset ambiguity threshold is used. It is a threshold value used to distinguish between normal network fluctuations and potential cognitive domain attacks, serving as a trigger condition for mode switching; it is determined by analyzing the system over a large number of normal operating cycles. The values are statistically analyzed, and a preset high percentage point, such as 99.9%, is selected from the probability distribution to determine the system's specificity under normal conditions.
[0079] Response to link state ambiguity If the system determines that the link information has a high risk of contamination, it will activate the diagnostic priority mode to perform link switching.
[0080] This method addresses the shortcomings of existing technologies that over-rely on a single monitoring data source and are unable to resist cognitive domain attacks by constructing a link state fuzzy quantitative evaluation system driven by multi-source heterogeneous data. It enables the system to measure the credibility of information itself in real time for the first time and establishes a dual-mode decision-making framework based on this. This allows the network control system to no longer blindly pursue short-term performance optimization, but to intelligently switch to a diagnostic mode that prioritizes restoring situational awareness when it senses the risk of information contamination. This avoids the risk of making catastrophic decisions based on erroneous information at the source and greatly enhances the survivability and stability of the entire network in advanced adversarial environments.
[0081] Example 2:
[0082] Enable efficiency optimization mode to perform link switching, including:
[0083] Based on a network performance-oriented intelligent decision-making model, link switching decisions are generated;
[0084] This embodiment is a concretization of the efficiency optimization mode based on embodiment 1; when the efficiency-optimization mode is enabled to perform link switching, its core lies in generating link switching decisions based on a network performance-oriented intelligent decision-making model.
[0085] Network performance-oriented intelligent decision-making models refer to a class of decision-making algorithms that optimize traditional network performance metrics such as maximizing network throughput and minimizing latency. Their role is to perform the most efficient link resource scheduling, provided that the monitoring data is reliable. This model can be a decision agent based on deep reinforcement learning (DRL) or the classic Q-Learning algorithm.
[0086] In this embodiment, when the system confirms When the link information is highly reliable, it will fully rely on the real-time monitoring data of the physical layer provided by the state acquisition unit. This data will be used as input to a pre-trained deep reinforcement learning model. The objective function of the model is set to maximize the overall transmission performance of the key services. The model will output an optimal link switching action based on the current input state, which will then be executed by the policy execution unit.
[0087] This specific solution clarifies the compatibility and integration of the present invention with existing technologies under a trusted information state; by adopting a mainstream, performance-oriented intelligent decision-making model in the efficiency optimization mode, it ensures that the present invention can still maintain industry-leading network resource utilization efficiency and business performance in normal operating scenarios without attacks, avoiding unnecessary sacrifice of normal performance due to the introduction of security mechanisms; it enables security and efficiency to be intelligently switched and balanced within a unified framework.
[0088] Example 3:
[0089] Enable diagnostic priority mode to perform link switching, including:
[0090] A predetermined proportion of critical business traffic will be forcibly switched from candidate links to the baseline trusted link.
[0091] Actively probe candidate links to generate verified link states;
[0092] The magnitude of the preset ratio is positively correlated with the magnitude of link state ambiguity.
[0093] The method also includes:
[0094] Based on active detection, the ambiguity after verification is recalculated;
[0095] If the ambiguity remains below the preset recovery threshold within a preset time window after verification, the system will switch from the diagnostic priority mode to the efficiency optimization mode.
[0096] This embodiment, based on Embodiment 1, provides a detailed description of the complete process and internal logic of the diagnostic priority mode; when When this happens, the system enters this mode and executes a sequence of operations that include sacrifice and verification in parallel;
[0097] The system performs a sacrifice operation, which means that a preset proportion of critical business traffic is forcibly switched from the candidate links that are currently judged to be highly ambiguous to the baseline trusted links;
[0098] A benchmark trusted link refers to one or more pre-selected links in a network whose state ambiguity has been proven over a long period of time. The link is maintained at an extremely low level; its function is to provide a reliable backup for carrying services when the information of the main link is unreliable, ensuring the continuity of core services. It can be specified in advance by the network administrator based on the network's historical operating data and topological importance.
[0099] Preset ratio in this operation Size and link state ambiguity The magnitudes are positively correlated; this correlation can be expressed by a function. To express; for example, design a piecewise linear function: when In When the interval is, From a minimum sacrifice ratio Linear growth to maximum proportion ; This refers to the upper limit of ambiguity that the system can tolerate; the technical motivation behind this design is to achieve adaptive adjustment of defense strength: attack signals The higher the value, the greater the proportion of traffic sacrificed by the system. The larger the capacity, the more robust the core business can be, while also providing greater scope for verification operations.
[0100] Among them, the minimum sacrifice ratio The maximum percentage can be set based on the bandwidth requirements of the most critical services in the network that must ensure absolute continuity, for example, 5%; It can be set to 100% to deal with extreme threats; ambiguity limit It can be set to a preset fuzziness threshold. A multiple of, for example Thus, when In When the interval is, From a linear increase of 5% to 100%;
[0101] In parallel with the sacrifice operation, the system performs a verification operation, which involves actively probing candidate links to generate verified link states.
[0102] Active probing is a technique that bypasses conventional monitoring data paths to obtain state information that is closer to the physical reality of the link. Its role is to provide an independent and reliable source of verification information when conventional monitoring data is suspected of being contaminated. This can be an encrypted signature probe packet sent through an out-of-band management channel or raw data obtained using other physical layer measurement techniques.
[0103] After obtaining more reliable link state data returned by proactive probing, the system will replace the original data based on the results of the proactive probing. The vector is recalculated to obtain a verified ambiguity. ;
[0104] This method also includes an automatic recovery mechanism; the system will continuously monitor this. The value of the ambiguity after verification; Within the preset time window The value remains below the preset recovery threshold. ,in ,For example The system will determine that the credibility of the knowledge of this link has been successfully reconstructed; this time window The value should be greater than the sum of the maximum cycles of network status detection and policy issuance to avoid misjudgment due to system response delay. A typical value can be set to 30 seconds. At this time, the system will automatically switch from the diagnosis priority mode to the efficiency optimization mode and gradually restore the traffic that was switched away to the original link, completing the closed-loop control of the entire defense and recovery.
[0105] A robust and intelligent closed-loop self-healing system was built; the sacrifice operation ensured uninterrupted core business operations during diagnosis by switching a portion of traffic to a baseline trusted link; the switching ratio... With ambiguity A positive correlation ensures that the investment of defense resources is precisely matched with the threat level, avoiding an overly simplistic "one-size-fits-all" approach to defense and achieving a dynamic balance between performance sacrifice and security assurance. Verification operations, through proactive detection, provide the system with a path to restore true visibility amidst the fog of information. Based on... The mode switching mechanism enables the system to automatically return to the most efficient operating mode after the threat is resolved, thus automating the entire event response process.
[0106] Example 4:
[0107] Real-time physical layer monitoring data originates from network monitoring protocols;
[0108] Historical performance data is derived from a database that reflects the long-term baseline behavior of the link;
[0109] Hardware trust anchor data originates from the trusted platform module;
[0110] Based on Example 1, this embodiment further defines the specific technical sources of the three data sources, ensuring the feasibility of the technical solution.
[0111] The physical layer real-time monitoring data is network monitoring protocol, which means that the present invention can directly utilize standardized monitoring facilities that are already widely deployed in the existing network, such as Simple Network Management Protocol (SNMP), NetFlow, or sFlow. These protocols can obtain low-level data such as port traffic, error packet count, and round-trip time from the Management Information Base (MIB) of network devices in real time. This limitation makes the present invention have good real-world deployment compatibility.
[0112] Historical performance data is a database that reflects the long-term behavior baseline of the link. This means that the system needs to be integrated with a backend database system that can store and analyze time-series data, such as Prometheus or InfluxDB. By performing statistical analysis on the long-term data accumulated in these databases, a stable and reliable profile of normal behavior can be established for each link. To ensure the long-term credibility of historical performance data, the backend database system storing this data should have anti-tampering log functions and regularly perform offline audits of the effectiveness of the historical baseline model to prevent long-term pollution attacks on historical data.
[0113] The hardware trust anchor data is the Trusted Platform Module (TPM), which means that this invention utilizes device-level hardware security features. The TPM is a standardized secure cryptographic chip that provides secure key generation, storage, and platform integrity measurement functions. Through mechanisms such as remote authentication, the control system can securely obtain data reported by the TPM regarding the device startup process and whether critical software modules have been tampered with. This limitation introduces a robust physical security dimension to the data trustworthiness assessment that is difficult to bypass by software-level attacks.
[0114] This solution reveals the design of the invention by clarifying the specific technical sources of the three types of data. It constructs a three-dimensional, in-depth defense system by integrating information from three different layers: the network management layer, the data analysis layer, and the hardware security layer. This cross-layer data fusion design makes it difficult for any single-layer attack to simultaneously deceive all three information channels, thereby greatly improving the sensitivity and robustness of the link state ambiguity index in detecting attacks.
[0115] Example 5:
[0116] Please see Figure 2 The status acquisition unit is used to collect real-time physical layer monitoring data, historical performance data, and hardware trust anchor data for candidate links.
[0117] The fuzzy quantification unit is used to generate link state fuzziness based on real-time physical layer monitoring data, historical performance data, and hardware trust anchor data.
[0118] The decision control unit is used to receive link status ambiguity and output efficiency optimization mode instructions or diagnostic priority mode instructions based on the comparison result with the preset ambiguity threshold.
[0119] The strategy execution unit is used to execute link switching in response to efficiency optimization mode instructions or diagnostic priority mode instructions;
[0120] This embodiment provides an intelligent redundancy switching control system for implementing the above method; the system is a logical or physical entity that can be deployed on a centralized controller or distributed control node of a network; the system consists of the following units that work closely together to form a closed-loop adaptive control system.
[0121] The status acquisition unit, as described in the aforementioned embodiment, collects real-time physical layer monitoring data, historical performance data, and hardware trust anchor data for candidate links. It has a built-in interface module for communicating with external entities such as SNMP agents, historical databases, and TPM verification servers, and is responsible for continuously providing the system with the raw data required for decision-making.
[0122] The fuzzy quantization unit is the system's cognitive processing module. Its function is to receive data from the state acquisition unit and, based on this data, perform a series of operations such as vectorization and deviation calculation to ultimately generate the link state fuzziness. ;
[0123] The decision control unit is the system's decision module, and its function is to receive the results calculated by the fuzzy quantization unit. and compare it with a preset ambiguity threshold. It makes comparisons; based on the comparison results, it makes strategic decisions on mode switching and outputs efficiency optimization mode instructions or diagnostic priority mode instructions.
[0124] The policy execution unit is the system's execution module. Its function is to respond to mode commands issued by the decision control unit and execute specific link switching operations. It interacts with the control plane interface of network devices to issue flow table rules or routing policies, thereby achieving precise scheduling of network traffic.
[0125] The interaction of these four units forms a dynamic feedback loop: the policy execution unit's scheduling of network traffic changes the real-time state of the network, and this new state is captured by the state acquisition unit, entering the next round of perception-cognition-decision-execution cycle, enabling the entire system to continuously and adaptively respond to changes in the network environment and potential threats. By decoupling complex functional logic into four mutually cooperating modular units, the engineering implementation of this invention becomes goal-oriented and structurally clear, endowing the network with an adaptive defense and recovery mechanism.
[0126] Example 6:
[0127] Fuzzy quantization units include:
[0128] The vector generation module is used to generate physical layer state vectors, historical performance state vectors, and hardware trust state vectors based on three types of data, respectively.
[0129] The deviation determination module is used to determine the first vector deviation between the physical layer state vector and the historical performance state vector, and the second vector deviation between the physical layer state vector and the hardware trust state vector.
[0130] The ambiguity generation module is used to combine the first vector deviation, the second vector deviation, and the preset weight coefficients to generate link status ambiguity.
[0131] This embodiment further refines the internal functional structure of the fuzzy quantification unit based on embodiment 5; to achieve the overall function of generating link state fuzziness, this unit is internally divided into three logical sub-modules:
[0132] The vector generation module is responsible for data preprocessing. Its function is to receive three types of heterogeneous raw data from the state acquisition unit and generate physical layer state vectors with uniform specifications. Historical performance state vector Hardware Trust State Vector ;
[0133] The deviation determination module is responsible for calculating the inconsistencies between data. Its function is to receive three state vectors and apply a preset vector difference metric function to determine the first vector deviation between the physical layer state vector and the historical performance state vector. And the second vector deviation between the physical layer state vector and the hardware trust state vector. ;
[0134] The ambiguity generation module is responsible for synthesizing the final index; its function is to obtain two deviation values and combine them with preset weighting coefficients. and ,according to The formula generates the final link state ambiguity;
[0135] This embodiment further decomposes the function of the fuzzy quantization unit into three serially processed sub-modules, making the implementation logic of the core algorithm part of the system clearer and more streamlined. This internal structure design not only makes each sub-module functionally singular, easy to implement and test, but also provides convenience for future algorithm upgrades.
[0136] Example 7:
[0137] The strategy execution unit is used for:
[0138] In response to the diagnostic priority mode command, a preset proportion of critical business traffic is switched from candidate links to baseline trusted links, and proactive probing is initiated on candidate links;
[0139] This embodiment, based on embodiment 5, provides a more detailed description of the strategy execution unit's function in a specific mode. When the decision control unit issues a diagnostic priority mode command, the strategy execution unit activates a specific set of operating procedures. Its function is precisely defined as two parallel tasks:
[0140] This unit performs traffic switching, redirecting a preset proportion of critical service traffic from attacked candidate links to baseline trusted links. It does this by invoking southbound interface protocols, such as OpenFlow, to issue commands to relevant network switches, modifying the forwarding rules that match the critical service flows. The switching proportion... The value is determined by the decision control unit based on the current... The calculated value is then transmitted to this unit.
[0141] Initiating active probing: In parallel, this unit triggers a probing task to actively probe candidate links. It constructs special probe data packets and injects them into the candidate links through an independent control channel. Simultaneously, it starts a listening program to receive and parse the probe results, and feeds the results back to the fuzzy quantization unit for computation. ;
[0142] This solution details how the strategy execution unit translates the "diagnosis priority" instruction into specific, executable network operations. It ensures that the two core actions of sacrifice and verification can be executed precisely and synchronously. This design makes the response behavior of the entire system deterministic and efficient after entering an emergency state, thereby ensuring that the diagnosis priority mode can be truly implemented and play its due role, that is, while protecting core business, quickly initiating the cognitive reconstruction process of network status.
[0143] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. An intelligent redundancy switching control method for optoelectronic hybrid interfaces, characterized in that, include: For candidate links, collect real-time physical layer monitoring data, historical performance data, and hardware trust anchor data; Based on real-time monitoring data of the physical layer, generate a physical layer state vector; Generate historical performance state vectors based on historical performance data; Based on hardware trust anchor data, generate a hardware trust state vector; The first vector deviation is determined based on the physical layer state vector and the historical performance state vector; The second vector deviation is determined based on the physical layer state vector and the hardware trust state vector. By combining the first vector deviation, the second vector deviation, and the preset weight coefficients, link state ambiguity is generated; In response to the link status ambiguity being less than a preset ambiguity threshold, efficiency optimization mode is activated to perform link switching; If the link status ambiguity is not less than a preset ambiguity threshold, enable the diagnostic priority mode to perform link switching; Enable efficiency optimization mode to perform link switching, including: Based on a network performance-oriented intelligent decision-making model, link switching decisions are generated; Enable diagnostic priority mode to perform link switching, including: A predetermined proportion of critical business traffic will be forcibly switched from candidate links to the baseline trusted link. Actively probe candidate links to generate verified link states; The magnitude of the preset ratio is positively correlated with the magnitude of link state ambiguity. The method also includes: Based on active detection, the ambiguity after verification is recalculated; If the ambiguity remains below the preset recovery threshold within a preset time window after verification, the system will switch from the diagnostic priority mode to the efficiency optimization mode.
2. The intelligent redundancy switching control method for the optoelectronic hybrid interface according to claim 1, characterized in that, Real-time physical layer monitoring data originates from network monitoring protocols; Historical performance data is derived from a database that reflects the long-term baseline behavior of the link; The hardware trust anchor data originates from the Trusted Platform module.
3. An intelligent redundancy switching control system for a photoelectric hybrid interface, based on the intelligent redundancy switching control method for a photoelectric hybrid interface as described in any one of claims 1-2, characterized in that, include: The status acquisition unit is used to collect real-time physical layer monitoring data, historical performance data, and hardware trust anchor data for candidate links. The fuzzy quantification unit is used to generate link state fuzziness based on real-time physical layer monitoring data, historical performance data, and hardware trust anchor data. The decision control unit is used to receive link status ambiguity and output efficiency optimization mode instructions or diagnostic priority mode instructions based on the comparison result with the preset ambiguity threshold. The strategy execution unit is used to perform link switching in response to efficiency optimization mode instructions or diagnostic priority mode instructions.
4. The intelligent redundancy switching control system for the optoelectronic hybrid interface according to claim 3, characterized in that, Fuzzy quantization units include: The vector generation module is used to generate physical layer state vectors, historical performance state vectors, and hardware trust state vectors based on three types of data, respectively. The deviation determination module is used to determine the first vector deviation between the physical layer state vector and the historical performance state vector, and the second vector deviation between the physical layer state vector and the hardware trust state vector. The ambiguity generation module is used to combine the first vector deviation, the second vector deviation, and the preset weight coefficients to generate link state ambiguity.
5. The intelligent redundancy switching control system for the optoelectronic hybrid interface according to claim 3, characterized in that, The strategy execution unit is used for: In response to the diagnostic priority mode command, a preset proportion of critical business traffic is switched from candidate links to baseline trusted links, and proactive probing is initiated on candidate links.
Citation Information
Patent Citations
Intelligent redundancy control system and method based on functional safety
CN120540032A
Concentrator network switching decision-making system and method based on communication quality evaluation
CN120786360A