A nut sorting state monitoring and diagnosis method based on edge internet of things
By generating device identifiers and matching permission levels in the edge IoT system, and dynamically adjusting permissions in combination with transmission protocols and network status, the shortcomings of edge IoT sorting systems in data security and permission management are solved, and safe and reliable monitoring and diagnosis of nut sorting status are realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-26
- Publication Date
- 2026-03-24
AI Technical Summary
Existing edge IoT sorting systems have shortcomings in data access control, data priority scheduling, and data security protection in complex network environments. They cannot achieve dynamic access control, which increases the risk of sensitive data exposure. Furthermore, they lack a continuous security management mechanism across different stages, which affects the accuracy of sorting status analysis and the reliability of diagnostic results.
Data streams are collected by edge devices, device identifiers are generated and matched with permission levels, and layered processing is performed based on transmission protocol type and data priority to dynamically adjust permissions. During the transmission stage, encryption strength and path are adjusted according to network latency and link congestion. During the storage stage, historical access logs are used to evaluate the stability of storage nodes, forming a dynamic permission management system throughout the entire lifecycle.
It enables secure and reliable management of sorting data throughout the entire process of collection, transmission and storage, improves the accuracy, security and real-time performance of nut sorting status monitoring and diagnosis, and solves the problems of insufficient dynamic permission management and weak link security adaptability.
Smart Images

Figure CN121585470B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of edge Internet of Things, and in particular to a nut sorting state monitoring and diagnosis method based on edge Internet of Things. BACKGROUND
[0002] In the modern logistics processing and agricultural product sorting industry, real-time monitoring and accurate diagnosis of the nut sorting state are key links to improve product quality and operation efficiency. With the rapid development of edge Internet of Things technology, various devices in the sorting field can realize data on-site collection, preprocessing and rapid response based on edge nodes, so that the sorting system has higher real-time and agility. However, the data collected in the nut sorting process is of various types, large in quantity and fast in change, and frequently flows between transmission links and different devices, which puts higher requirements on data security and hierarchical management capability.
[0003] Existing edge IoT sorting systems typically achieve basic data acquisition and uploading, but they still have significant shortcomings in data access control, data priority scheduling, and data security protection in complex network environments. On the one hand, the nut sorting process involves multi-dimensional data characteristics such as device identification, packet size, transmission latency, and transmission protocol type. However, existing methods often employ static or single-dimensional access control mechanisms, failing to dynamically match appropriate access levels based on the actual situation. For example, when the network environment fluctuates or the sorting equipment load changes, the system cannot automatically adjust permissions and data priorities according to the context, increasing the risk of sensitive data exposure. On the other hand, nut sorting systems generally lack cross-stage continuous security management mechanisms during the acquisition, transmission, and storage phases. Especially during data transmission, factors such as link noise, signal strength, and link congestion probability can easily lead to abnormal packet fragmentation, delays, or incorrect transmission. If dynamic density assessment and limiting strategies are not combined with real-time link status, problems such as data interception, tampering, or transmission interruption may occur, affecting the accurate analysis of sorting status. Furthermore, existing technologies also have limitations in reusing historical sorting data. Anomaly identification in nut sorting systems relies on a large amount of status data. However, conventional methods mainly rely on fixed threshold judgments or single-point data comparisons, lacking comprehensive analysis capabilities for parameters such as historical interruption nodes, anomaly frequency, and link bandwidth utilization. Therefore, the system cannot reliably infer subsequent sorting data or effectively support the construction of diagnostic models for sorting status. At the system risk assessment level, current edge IoT frameworks also fail to achieve closed-loop analysis of the data optimization transmission process. In complex interaction scenarios, without transmission path selection mechanisms, link security assessment mechanisms, and final verification mechanisms, the system struggles to guarantee the credibility and consistency of nut sorting status diagnostic results, failing to meet the high security requirements for sorting status monitoring, anomaly identification, and diagnostic output. In summary, when existing edge IoT technologies are applied to nut sorting scenarios, they lack, on the one hand, the ability to dynamically adjust permissions based on multi-dimensional information, making it impossible to achieve hierarchical control of different types of data; on the other hand, they lack data security assurance mechanisms throughout the entire lifecycle of collection, transmission, and storage, failing to address data limiting requirements under complex link conditions; and they also have shortcomings in historical data reuse, link statistics, and risk assessment, resulting in unreliable monitoring and diagnostic results for nut sorting status. Summary of the Invention
[0004] The purpose of this invention is to provide a method for monitoring and diagnosing the status of nut sorting based on edge IoT, thereby solving the problems existing in the prior art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a method for monitoring and diagnosing the nut sorting status based on edge IoT, comprising the following steps:
[0006] S1. Collect raw data streams of temperature, humidity and vibration in the nut sorting environment through edge devices. During the collection phase, generate device identifiers with MAC and serial numbers and match them with permission level parameter tables to obtain initial read, write and transmission permissions. Then, according to the transmission permission threshold, segment and normalize the data packets that exceed the limit according to the rules, and mark the data packets as allowed or delayed according to the transmission time window. Combine the device type and data importance to set the upper limit of the number of reads, storage retention time and processing priority access control tags to form a labeled collection data sequence with access constraints.
[0007] S2. Based on the collected data sequence, the data is processed in layers according to the transmission protocol type and data priority. If the data priority is detected to be lower than the preset threshold in the interactive scenario, the permission level is reduced to obtain permission adjustment data.
[0008] S3. Extract bandwidth utilization and data fragmentation strategy information from the permission adjustment data. During the transmission phase, obtain network latency and packet loss rate parameters through the network protocol. If the network latency is higher than the preset standard, adjust the data fragmentation strategy and determine the encryption strength of the transmitted data.
[0009] S4. Dynamically evaluate the encryption strength of the transmitted data by combining link congestion and signal strength. If the link congestion exceeds the safe range, optimize the transmission path selection through the error control mechanism to obtain the adjusted encrypted transmission data stream.
[0010] S5. Based on the adjusted encrypted transmission data stream, obtain historical access logs during the storage phase, analyze the stability of storage nodes by combining link interruption frequency and bandwidth availability, determine the permission policy rules for the storage location, and obtain the optimized storage data entity.
[0011] As can be seen from the above technical solution, the present invention has the following beneficial effects:
[0012] This invention achieves secure and reliable management of sorting data throughout the entire process of collection, transmission, and storage by introducing a dynamic access control and hierarchical data processing mechanism based on edge IoT into the nut sorting process.
[0013] By performing initial permission matching and restriction control based on device identification and data characteristics, data can be effectively classified at the acquisition end. Through hierarchical processing of transmission protocol type and priority, and dynamic adjustment of data fragmentation density and limiting strategies in combination with status parameters such as network latency, link noise, and signal strength, the integrity and stability of sorting data transmission can be maintained even in complex network environments. At the storage end, historical logs and node stability analysis are used to assist in the identification of anomalies, providing a reliable basis for subsequent diagnosis. Finally, a risk control system is constructed through path statistics and link security assessment, so that the diagnostic results are verified before final output.
[0014] Therefore, this invention significantly improves the accuracy, security, and real-time performance of nut sorting status monitoring and diagnosis, and solves the problems of insufficient dynamic permission management, imperfect data classification, and weak adaptability to link security in traditional technologies. Attached Figure Description
[0015] Figure 1 This is a flowchart of the nut sorting status monitoring and diagnosis method based on edge IoT of the present invention.
[0016] Figure 2 This is a structural block diagram of the local terminal of an exemplary electronic device (machine) of the present invention.
[0017] Figure 3 This is a structural block diagram of the network end of an exemplary electronic device of the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] like Figure 1 As shown, a method for monitoring and diagnosing the nut sorting status based on edge IoT includes the following steps:
[0020] S1. Collect raw data streams from the nut sorting environment through edge devices. During the collection phase, match the initial permission level according to the preset device identifier, and impose preliminary restrictions on the data packet size and transmission time window to obtain a collection data sequence marked with access constraints.
[0021] S2. Based on the collected data sequence, the data is processed in layers according to the transmission protocol type and data priority. If the data priority is detected to be lower than the preset threshold in the interactive scenario, the permission level is reduced to obtain permission adjustment data.
[0022] S3. Extract bandwidth utilization and data fragmentation strategy information from the permission adjustment data. During the transmission phase, obtain network latency and packet loss rate parameters through the network protocol. If the network latency is higher than the preset standard, adjust the data fragmentation strategy and determine the encryption strength of the transmitted data.
[0023] S4. Dynamically evaluate the encryption strength of the transmitted data by combining link congestion and signal strength. If the link congestion exceeds the safe range, optimize the transmission path selection through the error control mechanism to obtain the adjusted encrypted transmission data stream.
[0024] S5. Based on the adjusted encrypted transmission data stream, obtain historical access logs during the storage phase, analyze the stability of storage nodes by combining link interruption frequency and bandwidth availability, determine the permission policy rules for storage locations, and obtain the optimized storage data entity.
[0025] S6. Extract potential link indicators from the optimized stored data entities, combine path jump statistics and link security scores to conduct risk assessment, and if the overall status exceeds the warning line in the interaction scenario, trigger the dynamic permission adjustment mechanism to obtain enhanced permission control data.
[0026] S7. By strengthening the access control data to cover the entire lifecycle of the nut sorting environment, and conducting final verification on transmission path selection and link security assessment, a dynamic access management system is obtained to ensure the output of diagnostic results from the nut sorting status monitoring center.
[0027] This invention collects real-time data during the nut sorting process using edge devices and matches initial permission levels based on device identifiers, ensuring that data entering the system possesses basic access control attributes. Access restrictions are applied based on packet size and transmission time windows, ensuring that collected data has access constraints before entering the edge. During data processing, data is layered based on transmission protocol type and data priority. If the data priority is lower than a preset threshold, the permission level is automatically reduced, allowing the system to dynamically adjust data access rights according to real-time scenarios. During transmission, network latency and packet loss rate are continuously monitored through network protocols. When latency exceeds limits, the data fragmentation strategy is adjusted to determine encryption strength, achieving adaptive transmission control based on network conditions. The transmissibility of encrypted data streams is assessed by combining link congestion and signal strength, and an error control mechanism is used to reselect a better path when congestion is abnormal, thus ensuring the transmission stability of encrypted data streams. During storage, the stability of storage nodes is quantitatively assessed based on historical access logs, link interruption frequency, and bandwidth availability, and permission policy rules conforming to node conditions are generated accordingly. Then, potential link indicators are extracted from the optimized stored data entities, and risk assessment is achieved through path jump statistics and link security scoring. When the overall status is detected to exceed the warning line, a dynamic permission adjustment mechanism is triggered to update the permission control boundaries in real time. Ultimately, a dynamic permission management system covering the entire lifecycle from collection, transmission, storage to interaction is formed, enabling the Nuts sorting status monitoring center to output reliable diagnostic results while balancing security and performance.
[0028] Furthermore, S1 includes acquiring raw sensor data streams containing temperature, humidity, and vibration frequency from the nut sorting production line via an edge device; searching for matching device records in a permission level parameter table based on a preset device identifier composed of the device MAC address and serial number; extracting the corresponding read permission, write permission, and transmission permission values to obtain permission configuration information; detecting the byte size of each data packet in the raw sensor data stream according to the transmission permission threshold in the permission configuration information; if the number of bytes in a data packet exceeds the upper limit of the data packet size specified in the transmission permission threshold, then dividing the large data packet into multiple sub-data packets that meet the size requirements according to a preset segmentation rule to obtain standardized data transmission units; and obtaining the generation of each data packet in the standardized data transmission unit. A timestamp is generated, and the difference between the timestamp and the current processing time is calculated. If the time difference is within the preset transmission time window, an allowed transmission flag is added to the data packet. If the time difference exceeds the transmission time window, a delayed transmission flag is added to the data packet, thus determining the sequence of data packets with time constraint flags. For each data packet in the sequence of data packets with time constraint flags, three types of constraint parameters are set according to the source device type and the importance of the data content: upper limit of data read count, data storage retention time, and processing priority level. The constraint parameters are attached to the corresponding data packet as access control tags to generate a complete labeled data collection sequence for monitoring the operating status of the nut sorting equipment.
[0029] In this embodiment, the edge device is fixedly installed next to the nut sorting production line and connected to temperature, humidity, and vibration sensors via wired connections. During system deployment, process engineers measure the conveyor belt speed and nut spacing based on the time required for nuts to move from one detection position to the next on the conveyor belt. They calculate the minimum time interval during which the nut state will not change drastically in a short period. After multiple measurements, this interval is rounded down and a safety margin is added, ultimately determining the sampling period to be 500ms. Following this fixed sampling period, the edge device sequentially reads the current temperature value from the temperature sensor and the vibration sensor at each sampling moment. The system reads the current humidity percentage and the current vibration frequency from the vibration sensor. It combines these three sensor values from the same sampling moment with the corresponding device information and writes them into contiguous storage space to form a raw data packet. Each raw data packet contains a fixed-length header and variable-length data content. The header includes the source device identifier field and the time field of the current sampling moment. Multiple raw data packets are arranged in the order of sampling to form the raw sensor data stream. The media access control address of the edge device is generated by the network interface hardware during the production phase and remains unchanged. The serial number is determined sequentially by the production management system when the device enters the warehouse. When the device is first connected to the system... The installer reads the Media Access Control (MAC) address and enters the serial number one by one through the configuration interface. The system follows the order of MAC address first, then serial number, adding a pre-agreed fixed separator between the two, and concatenates the three parts in sequence to generate a unique device identifier string. This device identifier is written into the header field of the original data packet. Simultaneously, during the initialization phase, the system uses this device identifier as a search key to compare the device identifier field row by row in a pre-established permission level parameter table. This permission level parameter table is manually filled in by security policy developers during deployment, based on the responsibilities of different production lines and edge devices. Each row corresponds to one edge device, and each row contains the device identifier field and read permissions. The system includes fields for read permission, write permission, transmission permission, and transmission permission threshold. Read permission, write permission, and transmission permission are represented by integers from one to three, with higher values indicating more permissible operations. The transmission permission threshold records the maximum data packet size, in bytes, that matches the device's transmission permissions. When the system finds a row with identical device identifiers, it sequentially reads the read permission, write permission, transmission permission, and transmission permission threshold from that row, combines these four values into permission configuration information, and stores it in the edge device's memory for direct use in subsequent data processing. The maximum data packet size in the transmission permission threshold is determined through trial operation before system deployment.
[0030] Specifically, without affecting normal production, the production line is run continuously for seven days. During these seven days, data packets are not split; only the byte size of each original data packet is recorded. All recorded byte sizes are sorted from smallest to largest. Security policy makers and network maintenance personnel jointly review the sorting results. The byte size of the data packet whose sorting position is close to 95% of the total number of data packets is selected as the base threshold. Then, considering the possible increase in the number of sensors and occasional anomalies in the future, the base threshold is multiplied by a safety factor greater than 1. In this implementation, the safety factor is 1.1. The result of the multiplication is rounded up to an integer number of bytes and written as the final upper limit of the data packet size into the transmission permission threshold field of the permission level parameter table. This value is not automatically modified during system operation.
[0031] When the raw sensor data stream is sent to the access control processing stage, the edge device reads the raw data packets one by one in chronological order. For each raw data packet, it first traverses all bytes from beginning to end, counts the total number of bytes, and then compares the total number of bytes with the upper limit of the data packet size in the access control configuration information. If the total number of bytes is less than or equal to the upper limit of the data packet size, the structure of the raw data packet remains unchanged and is directly marked as a normalized data transmission unit. If the total number of bytes is greater than the upper limit of the data packet size, it is split according to the preset segmentation rules. Specifically, the system first calculates the integer multiple relationship between the total number of bytes and the upper limit of the data packet size, and then continuously adds the upper limit of the data packet size until the accumulated value does not exceed the total number of bytes. The number of times it is added is used as the required number of complete sub-data packets. If the total number of bytes after the addition is equal to the original total number of bytes, the total number of sub-data packets is equal to the number of times added. If there are any bytes remaining after the addition is completed, the system will proceed as follows: If the remaining bytes are not found, another sub-data packet is added to store them. At this point, the total number of sub-data packets is equal to the number of complete sub-data packets plus 1. Then, starting from the first byte of the original data packet, the system copies bytes of data to each sub-data packet in the original order. Data is first filled into the first sub-data packet until the number of bytes of data content in that sub-data packet reaches the upper limit of the data packet size or the remaining bytes of the original data are insufficient. Then, the system continues to fill the next sub-data packet until all bytes are allocated. Each sub-data packet generates its own header information. The header information copies the device identifier and related fixed fields of the original data packet and adds a sub-data packet sequence number field. The sequence number increments from the beginning and is used to identify the order of the sub-data packets split from the same original data packet. After the above splitting, the original data packet is replaced by multiple sub-data packets with a byte count not exceeding the upper limit of the data packet size. These sub-data packets, together with the unsplit original data packet, constitute a standardized set of data transmission units.Simultaneously with the generation of standardized data transmission units, the edge device reads its local system time as the generation timestamp. The system time is calibrated with a standard time source via a time synchronization service during device installation and then continuously increments in seconds and milliseconds. The generated timestamp fully records the year, month, day, hour, minute, second, and millisecond, and is written to the timestamp field of each standardized data transmission unit. In subsequent processing, when a standardized data transmission unit is retrieved for time constraint judgment, the system again reads the current system time as the current processing time. To calculate the time difference, the system pre-converts the year, month, day, hour, minute, second, and millisecond internally. The total number of milliseconds since a unified start time is converted as follows: first, the year, month, and day are converted into a total number of days; then, the number of days are converted into a total number of minutes; the total number of minutes is added to the current hour and minute, then converted into a total number of seconds; this is added to the current number of seconds, and finally converted into a total number of milliseconds. Adding the millisecond field results in a monotonically increasing total number of milliseconds representing a point in time. After both the generated timestamp and the current processing time are converted to total milliseconds in this way, the system subtracts the total number of milliseconds of the generated timestamp from the total number of milliseconds of the current processing time to obtain the time difference, expressed in milliseconds, between the data packet's generation and the current processing time.
[0032] Furthermore, the upper and lower limits of the transmission time window range are determined by process engineers and monitoring personnel based on business requirements before deployment. Specifically, the maximum allowable delay from a change in the state of the nut sorting equipment to the point where monitoring and diagnosis must be performed is analyzed. During multiple trial production processes, the time from the occurrence of equipment abnormality to manual confirmation of the abnormality is recorded. In this embodiment, the maximum allowable total delay is set to 3000ms. To ensure that the monitoring results are not invalidated due to transmission delay, the total delay is divided into three parts: acquisition delay, transmission delay, and analysis delay, each part being 1000ms. Therefore, the upper limit of the transmission time window is fixed at 1000ms, and the lower limit is fixed at 0ms, which is written into the system configuration and not adjusted during operation. When judging time constraints, the system judges whether the time difference of each data packet is greater than or equal to 0ms and less than or equal to 1000ms. If the judgment is yes, the allowable transmission value is written into the time constraint identifier field of the data packet. The allowable transmission value uses integer encoding, which is coded as one in this embodiment. If the time difference is greater than 1000ms, a delayed transmission value is written into the time constraint identifier field. The delayed transmission value is encoded as two. After the time constraint identifier is written, all normalized data transmission units are arranged in chronological order of generation time, forming a data packet sequence with a time constraint identifier. The system then further attaches an access control tag to each data packet in the data packet sequence. First, by reading the device identifier in the data packet header, the system looks up the corresponding device type in the locally stored device type configuration table. The device type configuration table is filled in by the installer when the device is connected. Each record contains a device identifier and a device type field. The device type is limited to one of three types: temperature monitoring device, humidity monitoring device, or vibration monitoring device. The installer manually selects and writes the device type according to the actual type of sensor connected. Then, the system reads the temperature value, humidity value, and vibration frequency value in the data content. During the equipment commissioning phase, process engineers determine the safe range under normal production conditions through multiple fault-free operation tests.
[0033] In this embodiment, the safe upper limit for temperature is set at 60℃, the safe upper limit for humidity is set at 90%, and the safe upper limit for vibration frequency is set as the vibration frequency value measured when the equipment is running stably under full load. Based on extensive testing, in order to detect anomalies early without causing too many false alarms, lower limits for warning ranges are also determined. In this embodiment, the lower warning limit for temperature is set at 50℃, the lower warning limit for humidity is set at 80%, and the lower warning limit for vibration frequency is set at 80% of the safe upper limit. The above safe upper limit and lower warning limit are calculated by summarizing multiple sets of data measured on-site to obtain the maximum and average values of each parameter during stable operation, and a certain safety margin is then allowed. Once the full risk margin is determined, it is written into the system configuration and will not be automatically adjusted during operation. During system operation, the temperature, humidity, and vibration frequency values in each data packet are compared with their corresponding lower warning limit and upper safety limit. If any value exceeds the upper safety limit, that item is recorded as entering a high-risk state. If no item exceeds the upper safety limit but at least one value falls between the lower warning limit and the upper safety limit, the data packet is recorded as entering a warning state. If all three values are less than the lower warning limit, the data packet is recorded as being in a normal state. The system assigns a value to the importance of the data content based on these three states: high risk, warning, and normal. High risk is assigned to the first level, and the lower warning level to the first level. Alert levels are designated as Level 2, and normal levels as Level 3. These levels are fixed in the system configuration using integers 1, 2, and 3. The data read limit, data storage retention time, and processing priority level in access control are uniformly set by security policy developers during the design phase. Before setting these parameters, the needs of monitoring personnel for backtracking key historical data, the data volume that storage devices can handle, and the response speed requirements of daily monitoring tasks are comprehensively considered. In this implementation, when the data content importance is Level 1, to ensure that high-risk data can be reviewed multiple times by different personnel or different algorithms, the data read limit is set to 20 times. To ensure that high-risk data is retained for a longer period of time... The system is traceable, with a data storage retention period of 365 days and a processing priority level of one to prioritize the analysis of high-risk data. When the data content importance level is two, to balance storage resources and review needs, the maximum number of data reads is set to 10, the data storage retention period is set to 90 days, and the processing priority level is set to two. When the data content importance level is three, to reduce the consumption of storage resources, the maximum number of data reads is set to 3, the data storage retention period is set to 30 days, and the processing priority level is set to three. The above three cases and corresponding values are written into the configuration file before system deployment and remain unchanged during operation.After calculating the importance of the data content for each data packet, the system reads the corresponding data read limit, data storage retention time, and processing priority level from the configuration based on the corresponding level. These three parameters, along with a read count field initialized to zero, are written to the access control label area at the end of the data packet. Each field in the access control label is stored with a defined length and defined unit, and contains no ambiguous fields.
[0034] It should be noted that when any function in the nut sorting status monitoring process needs to read a data packet, the system first checks the read count field of the data packet and compares this field value with the data read count limit. If the read count is less than the data read count limit, the read is allowed and the read count is incremented by one. If the read count equals the data read count limit, the new read request is rejected and the data packet is logged as having reached the read limit. When a data packet is first written to the storage medium, the system records the current date and extends it by the number of days corresponding to the data storage retention period to obtain the data retention deadline. The system scans all data packets in the storage medium daily. For data packets whose current date is later than the data retention deadline, they are deleted from the online storage area or moved to a separate archive area to ensure that only data packets within their respective retention periods are retained in the online storage area. The monitoring task reads the processing priority level field in the access control tag of each data packet during scheduling. Data packets with priority level one are analyzed first, data packets with priority level two are analyzed after high-risk data, and data packets with priority level three are analyzed last. This fixed order ensures that data with higher importance participates in the operation status diagnosis of the nut sorting equipment first. After a series of defined calculation steps, including the above collection, permission lookup, data packet splitting, time difference calculation, time window judgment, time constraint identification writing, and access control tag attachment, each data packet output by the edge device carries a clear time constraint identification and access control tag. Multiple data packets are arranged in the order of generation to form a complete labeled collection data sequence, which serves as the input data for monitoring the operation status of the nut sorting equipment.
[0035] Preferably, S2 includes establishing a protocol hierarchy mapping table based on the transmission protocol type identifier in the collected data sequence, according to TCP, UDP, and HTTP protocols; obtaining the transmission priority baseline value corresponding to each protocol; if the data packet priority value is lower than a preset priority threshold, reducing the original permission level value by a preset amount to obtain the permission adjustment result after protocol layering; using the permission adjustment result to reclassify the nut appearance feature data, obtaining the red, green, and blue channel values of the nut surface, calculating the mean and variance of each color channel to obtain color distribution parameters, extracting the nut contour boundary point coordinates through an edge detection operator, and calculating the contour perimeter to area ratio to obtain shape contour parameters. A database of appearance features, including color distribution parameters and shape contour parameters, is established. Three types of status parameters are acquired within the sorting channels: conveyor belt speed, airflow pressure, and light intensity. Combined with the nut length and width dimensions recorded in the appearance feature database, the ratio of the number of nuts passing through each channel per unit time to the channel capacity is calculated. It is then determined whether the ratio exceeds the channel congestion threshold, resulting in operational status assessment data for each channel. Based on this operational status assessment data, a processing queue is established in the edge nodes according to data priority. The conveyor belt speed control value and airflow pressure control value are dynamically adjusted according to the change in nut passage frequency, generating a configuration file of key parameters for the operation control of the nut sorting equipment.
[0036] In this embodiment, each data packet is first read and identified according to the transmission protocol type identifier in the collected data sequence. Each data packet in the collected data sequence contains a field indicating the transmission protocol type. This field has been written with fixed values during the acquisition phase. In this embodiment, the value of the protocol type field is limited to one of three types: Transmission Control Protocol (TCP) for connection-oriented transmission, User Datagram Protocol (UDP) for connectionless transmission, and Hypertext Transfer Protocol (HTTP) for application-layer request-response. The system pre-establishes a protocol layer mapping table in the edge nodes. The mapping table is stored locally on the edge nodes in tabular form, where each row records a protocol type and its corresponding transmission priority baseline value. Priority baseline values are represented by integers. In this implementation, during the deployment phase, network maintenance personnel set the baseline priority of the Transmission Control Protocol (TCP) to 3, the User Datagram Protocol (UDP) to 2, and the Hypertext Transfer Protocol (HTTP) to 1 based on network link reliability and latency requirements, and then permanently save this table. When the edge node is running, for each data packet in the collected data sequence, the system first reads its protocol type identifier, searches for a row with the exact same protocol type in the protocol hierarchy mapping table, retrieves the corresponding transmission priority baseline value from that row, and simultaneously reads the priority value field already written to the data packet in the previous stage. This field is represented by an integer. The data priority is represented by a numerical value indicating its importance to the business. In this implementation, the integer value of the data priority ranges from 1 to 3, with higher values indicating greater business importance. The system pre-sets a priority threshold in the configuration, also represented by an integer. In this implementation, during the deployment phase, the integer 2 is selected as the priority threshold by statistically analyzing the data priority distribution that significantly impacts diagnostic results in historical monitoring tasks. This means that data packets with a priority value lower than 2 can have their access permissions reduced to free up resources during periods of resource scarcity or increased security. When an edge node processes each data packet, it first compares the packet's priority value with the priority threshold. If the packet's priority value is less than 2, the packet is considered to be of low priority. Priority data: At this point, the system reads the original permission level value of the data packet. This permission level value is an integer determined from the permission level parameter table based on the device identifier in the S1 stage. In this embodiment, the permission level value ranges from 1 to 5. The larger the value, the more system resources can be accessed. The system then reads the preset permission adjustment range in the configuration. In this embodiment, the permission adjustment range is set to 1, that is, it decreases by one level each time. When the priority value of the data packet is detected to be less than 2, the permission level value of the data packet is subtracted by 1. If the result after subtraction is less than 1, it is forcibly set to 1. Values less than 1 are not allowed. This yields the permission adjustment result after protocol layering, and the new permission level value is written back to the data packet for subsequent processing.If the packet priority value is greater than or equal to 2, the original permission level value remains unchanged, and this value is still used as the permission adjustment result after protocol layering for that packet. This ensures that the access permissions of high-priority data are not reduced, achieving unified coordination of protocol type, business priority, and permission level.
[0037] After completing the above protocol-based permission adjustment, the edge node uses the obtained permission adjustment results to reclassify the nut appearance feature data. The nut appearance feature data consists of image data and corresponding intermediate analysis results generated by the front end and uploaded to the collected data sequence during the nut sorting process. In this embodiment, when processing, the edge node filters out data packets with a permission level value greater than or equal to 3 and whose data type is marked as appearance feature data from the collected data sequence, classifying them as data for appearance feature analysis. Other data with lower permissions or whose data type is not appearance feature data are classified as non-appearance data to reduce unnecessary calculations. For each selected appearance feature data... According to the data, the edge node reads the color image matrix information of the nut surface from the data. This image was stored with each pixel's grayscale value encoded according to three channels: red, green, and blue. During processing, the edge node first obtains the number of rows and columns of the image, multiplying them to get the total number of pixels. Then, for the red channel, it reads the grayscale value of each pixel sequentially from the first row to the last row and from the first column to the last column, accumulating the red channel grayscale values of all pixels. After accumulating all pixels, it divides the sum by the total number of pixels to obtain the mean of the red channel and the mean of the green channel. The blue channel's mean is calculated in the exact same way. After obtaining the mean values for each channel, to calculate the variance, the edge nodes again start from the first pixel of the image, reading the grayscale value pixel by pixel for the red channel. This value is subtracted from the previously calculated red channel mean to obtain the pixel's deviation in the red channel. This deviation is multiplied by itself to obtain the squared deviation value. The squared deviation values of all pixels are accumulated, and the result is divided by the total number of pixels to obtain the variance of the red channel. The green and blue channels are calculated using the same method. In this way, each image yields six values: the mean and variance of the red, green, and blue color channels. These six values are used as color distribution parameters, serving as quantitative indicators reflecting the depth and uniformity of color on the nut surface, and stored in the data structure used later. After obtaining the color distribution parameters, the edge node performs contour extraction on the image in the same appearance feature data. Specifically, the color image is first converted into a grayscale image according to a fixed weight, and then the grayscale image is calculated pixel by pixel from the first row to the last row to calculate the degree of grayscale change in several neighborhoods around the pixel. When the degree of grayscale change is greater than the preset edge judgment threshold, the system marks the pixel as an edge point. In this embodiment, the edge judgment threshold is determined by the image processing personnel through image experiments of multiple batches of nut samples during the debugging phase.
[0038] Specifically, several sets of sample images with clear boundaries and several sets of sample images with blurred boundaries are selected respectively. The threshold is gradually adjusted to find a grayscale change value that can clearly extract the boundary between the nut and the background without introducing a large amount of noise edges. This value is recorded as the edge judgment threshold and fixed in the system configuration. When the system runs, it judges according to this threshold, records the row and column positions of the pixels marked as edge points as the coordinates of the points in the image, sorts all edge point coordinates in row and column order, and connects them to form a closed contour. Then, in order to calculate the perimeter of the contour, the system starts from the first edge point after sorting and treats each edge point as a point on the contour. The distance between two adjacent points is the difference between the coordinates of the two points. Then, the distance values between all adjacent points are accumulated, and the distance between the last point and the first point is also calculated and added to the sum to obtain the perimeter of the nut contour. In order to calculate the area of the contour, the system uses scan lines within the contour area, from the smallest row number to the largest row number. The scanning process involves finding the intersection of the contour with each row, counting the number of pixels inside the contour within the same row, summing the number of pixels inside all rows, and multiplying by the area represented by a single pixel to obtain the contour area. In this embodiment, the area of a single pixel has been converted into a specific physical area value based on camera calibration and installation distance during image acquisition and written into metadata for direct system reading and use. Subsequently, the contour perimeter value is divided by the contour area value to obtain the perimeter-to-area ratio of the nut. This ratio is used as a shape contour parameter to quantify the elongation and boundary complexity of the nut's shape. The edge nodes combine the color distribution parameters, shape contour parameters, and the nut length and width dimensions calculated during contour extraction into an appearance feature record for each nut and append it to the appearance feature database. The appearance feature database stores these records sequentially in chronological order, providing basic data on the geometric dimensions and appearance features of the nuts for subsequent channel congestion assessment.
[0039] After accumulating sufficient data in the appearance feature database, the edge node acquires three types of state parameters within the sorting channel: conveyor belt speed, airflow pressure, and light intensity. These three state parameters are written into the data acquisition sequence through the sorting equipment's own sensing units or operation records. In this embodiment, the conveyor belt speed is expressed in length per second, the airflow pressure in pressure units, and the light intensity in illuminance units. During processing, the edge node reads the latest values of these three state parameters from the data acquisition sequence based on the channel number and compares them with the nuts in the appearance feature database corresponding to the same channel. The length and width dimensions are used together to calculate the ratio of the number of nuts passing through each channel per unit time to the channel capacity. The specific calculation process is as follows: a statistical time window is set at the edge node. In this embodiment, the statistical time window length is set to 60 seconds. During the operation phase, the system maintains a sliding counter for each sorting channel. Within each statistical time window, when the channel number marked in the data record corresponding to a certain nut is detected to be the same as the current channel, the counter of that channel is incremented by 1. When the time window ends, the value of the counter is the actual number of nuts that passed through the channel during that time period. The channel capacity is determined through prior testing.
[0040] Specifically, during the system debugging phase, a maximum reasonable conveyor belt speed that will not cause collisions or accumulation is set for each channel. Combining the typical length and width of nuts with the current channel width, the maximum number of nuts that can pass per second without overlap on the conveyor belt is calculated using a neat row-column arrangement. This is then multiplied by the length of the statistical time window to obtain the theoretical maximum number of nuts that can pass per unit time. Debugging personnel verify this calculated value through multiple on-site observations. If the calculated value is significantly higher than the actual throughput under non-congested conditions, it is adjusted downwards accordingly. The final value is used as the capacity limit for that channel and written into the local configuration of the edge node. During actual operation, at the end of each statistical time window, the edge node represents the actual number of nuts that passed within that time window using the aforementioned counter value. This value is then compared to the capacity limit of the corresponding channel. Dividing the actual number of nuts passed by the capacity limit yields a unitless ratio. The closer this ratio is to 1, the closer the channel is to full capacity; a ratio exceeding 1 indicates that it has exceeded capacity. To determine whether congestion has occurred, the system pre-sets a channel congestion threshold. In this embodiment, the channel congestion threshold is determined by process engineers based on production rhythm requirements and acceptable queue lengths for the channels. Specifically, during the testing phase, the actual load on the channels is gradually increased, and the ratio of the actual throughput to the upper limit of capacity is monitored without significant accumulation and while sorting accuracy still meets requirements. This ratio, obtained from multiple tests, is taken as a value slightly lower than the average level as the congestion threshold. In this embodiment, this threshold is typically set between 0.8 and 0.9, and a final value is selected and written into the configuration. During operation, when the ratio of a certain channel is greater than or equal to the congestion threshold, the system marks it as a congestion risk state in the operational status evaluation data of that channel. When the ratio is less than a certain range below the congestion threshold, it is marked as an idle or normal state. Thus, at the end of each statistical time window, the edge nodes can generate operational status evaluation data for each channel, including the ratio value and the congestion status mark.
[0041] Finally, for the obtained operational status assessment data of each channel, the edge node establishes a processing queue according to the data priority order. The processing queue resides entirely in the memory of the edge node without adding any other processing modules. When generating each operational status assessment data, the edge node simultaneously reads the data priority information related to that channel. In this embodiment, the data priority corresponding to the assessment data of the channel in a congestion risk state is fixed at 3, the data priority of the assessment data of the channel in a normal state but close to the congestion threshold is set to 2, and the data priority of the assessment data of the channel with low load is set to 1. The system internally establishes three queues for priority 3, priority 2, and priority 1, respectively. The priority 3 queue is placed at the front of the scheduling order, and the priority 1 queue is placed at the back. Whenever new operational status assessment data is generated, the system appends it to the tail of the corresponding queue according to its priority. In each scheduling cycle, the scheduling thread of the edge node always checks whether there is any data to be processed in the priority 3 queue first. If there is, it takes the earliest operational status assessment data that entered the queue from it for processing. Only when the priority 3 queue is empty will it switch to processing the priority 2 queue, and finally process the priority 1 queue.
[0042] When processing operational status assessment data, the edge node first calculates the change in the frequency of nut passage. To this end, the system stores the actual number of nuts that passed through each channel within the previous statistical time window, and obtains the number of nuts passed through in the current window at the end of the current window. The change is obtained by subtracting the previous window's number from the current window's number. The absolute value of the change represents the magnitude of the change. If the change is positive and the absolute value is large, and the channel congestion ratio in the current window is greater than or equal to the congestion threshold, it is determined that the channel's load is increasing and there is a risk of congestion. At this point, the system adjusts the conveyor belt speed control value and the airflow pressure control value according to preset control rules. In this embodiment... The control rule is as follows: whenever the above conditions are detected, the conveyor belt speed control value of that channel is reduced by a fixed step. The step size is determined by equipment engineers during the deployment phase based on the equipment's mechanical response capability and the stability of the nuts on the conveyor belt, for example, a 5% reduction each time. Simultaneously, the airflow pressure control value is reduced by a smaller step, for example, a 3% reduction each time, to reduce the force with which the nuts are thrown up by the airflow and reduce the risk of further congestion. When the change is negative and the absolute value is large, and the channel congestion ratio is significantly lower than the congestion threshold, it indicates that the channel load is decreasing and there is a large margin. To improve channel utilization, the system fine-tunes the conveyor belt speed and airflow pressure in the opposite direction. In this embodiment, whenever the above conditions are met... For example, the conveyor belt speed control value is increased by a fixed step, such as 3% each time, and the airflow pressure control value is increased by a smaller step, such as 2% each time, to appropriately improve the channel processing capacity while avoiding instability caused by excessively rapid increases. The light intensity value is used in the operational status assessment to ensure image acquisition quality. When the light intensity is detected to be lower than the preset lower light threshold, the system adds an insufficient light marker to the operational status assessment data. This lower light threshold is determined during the debugging phase by comparing the image recognition accuracy under multiple sets of different lighting conditions. During operation, it only serves as a reference for whether manual inspection or light source adjustment is needed and does not directly participate in the conveyor belt speed and airflow pressure values. After completing the above adjustment calculations, the edge node writes the updated conveyor belt speed control value, airflow pressure control value, corresponding channel number, adjustment ratio, and timestamp for each channel into a key parameter configuration file. This configuration file is stored in the local storage medium of the edge node in a structured text format. Each time it is updated, a configuration record is appended to the file. The sorting equipment operation control link reads the latest or most recent control parameters for each channel from the key parameter configuration file at fixed time intervals, and sends the conveyor belt speed control value and airflow pressure control value to the corresponding actuators. The actuators then adjust their operation according to the new control values.
[0043] As a preferred technical solution of the present invention, S3 includes adjusting data according to permissions, parsing the bandwidth utilization rate indicator and data fragmentation strategy configuration information therein, obtaining the network latency value and packet loss rate parameter of the current transmission link through the network protocol stack, and obtaining a network performance evaluation report; for the network latency value in the network performance evaluation report, if the latency value is detected to exceed a preset latency threshold, the data fragmentation size is reset according to the inverse relationship between the latency value and the fragmentation size, and the number of fragments is adjusted according to the bandwidth utilization rate, the queue priority sorting of data packets in the transmission buffer is modified, and the optimized transmission parameter configuration is determined; using the optimized transmission parameter configuration, according to the packet loss rate parameter... The system selects either AES or DES encryption algorithms. AES is used when the packet loss rate is below a preset threshold, and DES is used when the packet loss rate is above the threshold. A secure verification code sequence containing packet sequence numbers and checksums is generated. Using this sequence, the sorting status code and the verification code are XORed to complete the encryption encapsulation. A monitoring frequency value is set to control the transmission time interval between adjacent data packets, obtaining a data packet group containing encrypted status information. From this data packet group, the checksum of each data packet is extracted for integrity verification. The consistency between the checksum and the original data is determined, resulting in a monitoring data stream used for edge node security processing.
[0044] In this embodiment, the edge node first receives the permission adjustment data output from step S2. This data is stored as a set of records, each corresponding to a batch of data packets to be transmitted. Each record includes a bandwidth utilization index field and a data fragmentation strategy configuration information field. The bandwidth utilization index field represents the ratio of actual bandwidth usage to the maximum link bandwidth within a fixed statistical time period as a percentage. In this embodiment, after device installation, multiple cycles of bandwidth changes under full load and normal load conditions are continuously recorded. The average of these cycles is then rounded up to obtain the statistical time length, which is written to the configuration file and used consistently during operation. The data fragmentation strategy configuration information field includes two parameters: the currently used data fragmentation size and the maximum number of fragments allowed for a single service data item. The fragmentation size is in bytes, and the maximum number of fragments is a positive integer. During system deployment, network maintenance personnel and software engineers determine the maximum bandwidth usage based on the maximum link bandwidth. The average length of the transmission unit and the service message are determined after calculation. Specifically, the average length and maximum length of the service message are first counted in the debugging environment. Then, the available payload length is obtained by subtracting the protocol header and encryption overhead from the maximum transmission unit of the link. The fragment size is initially set to an integer value that does not exceed the available payload length. In this embodiment, it is initially set to 1024 bytes. At the same time, the maximum number of fragments is obtained by dividing the maximum length of the service message by the fragment size and rounding up to obtain an integer. On this basis, a certain amount of redundancy is added. In this embodiment, two fragments are added as redundancy. The maximum number of fragments is obtained and written into the configuration. During operation, the edge node reads the bandwidth utilization index and fragmentation policy configuration information from the permission adjustment data one by one and caches them in memory. Then, it obtains the network latency value and packet loss rate parameters of the current transmission link through the network protocol stack. Specifically, the edge node calls the probe function provided by the network protocol stack and sends a fixed number of probe data packets to the peer in a probe cycle.
[0045] In this implementation, the fixed number is set to 100 during the deployment phase. When sending each probe data packet, the current time is recorded as the sending time, and the system waits for an acknowledgment or confirmation from the protocol stack. Upon receiving an acknowledgment or confirmation, the current time is recorded as the receiving time. The round-trip time of the probe data packet is obtained by subtracting the sending time from the receiving time. The round-trip times of all successfully acknowledged data packets within the current probe cycle are summed, and the sum is divided by the number of successfully acknowledged data packets to obtain the average network latency value of the current transmission link, in milliseconds. Within the same probe cycle, the edge node also counts the total number of probe data packets sent and the number of data packets that did not receive an acknowledgment within a preset timeout period. The timeout period is determined during the deployment phase based on the maximum acceptable latency of the link; in this implementation, it is set to 1000 milliseconds. If a probe data packet does not receive an acknowledgment within the timeout period, it is considered a packet loss. The number of lost packets is divided by the total number of sent probe data packets and multiplied by 100 to obtain the packet loss rate parameter, which is stored as a percentage. The network latency value, packet loss rate parameter, and corresponding time period are also considered. The bandwidth utilization rate is merged into a single network performance evaluation record. Multiple records are arranged in chronological order to form a network performance evaluation report, which is stored in the memory of the edge node for subsequent retrieval. Based on the above, the edge node judges the network latency value of each record in the network performance evaluation report. The preset latency threshold is determined by process engineers and network maintenance personnel through trial operation tests during the deployment phase. Specifically, different network latency conditions are set during the debugging phase. For example, the link latency is manually controlled at multiple fixed values such as 50 milliseconds, 100 milliseconds, 200 milliseconds, 300 milliseconds, and 500 milliseconds to run the sorting monitoring system. The diagnostic result generation time, false alarm rate, and false negative rate are recorded under these latency conditions. The maximum value of the network latency value among all test results that meet the diagnostic time limit requirements and whose false alarm rate and false negative rate meet the process requirements are used as the candidate threshold. To leave a safety margin, a portion is subtracted from the candidate threshold. In this embodiment, 50 milliseconds are subtracted, and the preset latency threshold is finally determined to be 200 milliseconds and written into the configuration file. It is not changed during runtime.Edge nodes read network latency values from network performance evaluation records during operation. When the value is less than or equal to 200 milliseconds, the current link latency is considered normal, and the original data fragment size in the permission adjustment data remains unchanged. When the value is greater than 200 milliseconds, the link latency is considered too high, and the fragment size needs to be reduced to decrease the transmission time of a single fragment. The reduction process is performed in segments according to the principle that the latency value is inversely proportional to the fragment size. During the deployment phase, the maximum and minimum fragment sizes are pre-set according to the link capacity. In this embodiment, the maximum fragment size is set to 1024 bytes, and the minimum fragment size is set to 256 bytes. An intermediate fragment size of 512 bytes and a transitional fragment size of 384 bytes are set. When the network latency value is detected to be greater than 200 milliseconds and less than or equal to 400 milliseconds, the current fragment size is adjusted to 512 bytes. When the network latency value is greater than 400 milliseconds and less than or equal to 800 milliseconds, the fragment size is adjusted to 384 bytes. When the network latency value is greater than 800 milliseconds, the fragment size is directly adjusted to 256 bytes. This segmented adjustment ensures that the higher the latency, the smaller the fragment size. After adjusting the fragment size, the edge node saves the new fragment size as the current valid value.
[0046] Subsequently, the edge nodes adjust the number of shards based on bandwidth utilization. For each piece of service data, the total number of bytes of that service data recorded in the permission adjustment data is read first. This total number of bytes is divided by the current effective shard size to obtain an integer part and a possible remainder. The integer part is used as the theoretical number of shards. The remainder is compared with zero. If the remainder is greater than zero, it means that the total number of bytes is not divisible by the shard size, and an additional shard is needed to carry the remaining bytes. Therefore, the theoretical shard number is increased by 1 to obtain the base shard number. Next, the adjustment coefficient is determined based on the bandwidth utilization. The bandwidth utilization threshold is determined during the deployment phase through link stress testing experiments. The experimental method involves gradually increasing the service traffic on the actual link and recording the latency increment and packet loss changes under different bandwidth utilization rates. The range with a bandwidth utilization rate below 70% is considered the comfort zone, 70% to 90% is considered the high load warning zone, and above 90% is considered the near saturation zone. Based on this, the shard number adjustment coefficient for the comfort zone is set to 1, and the high load warning zone is set to 1. The fragment quantity adjustment factor for the load warning zone is set to 0.8, and the fragment quantity adjustment factor for the near-saturation zone is set to 0.6. These values are fixed and written into the configuration. During runtime, the edge node reads the current bandwidth utilization percentage. When the bandwidth utilization is less than 70%, the base fragment quantity is multiplied by 1 and rounded down to obtain the final fragment quantity. When the bandwidth utilization is between 70% and 90%, the base fragment quantity is multiplied by 0.8 and rounded down to obtain the final fragment quantity. When the bandwidth utilization is greater than 90%, the base fragment quantity is multiplied by 0.6 and rounded down to obtain the final fragment quantity. If the final fragment quantity is less than 1, it is forcibly set to 1 to ensure that there is at least one fragment. Then, the final fragment quantity is compared with the maximum fragment quantity allowed in the configuration. If the final fragment quantity is greater than the maximum fragment quantity, the final fragment quantity is set to the maximum fragment quantity, and the number of bytes carried by each fragment is recalculated. The last fragment is allowed to be slightly less than the number of bytes of the previous fragments to ensure that the total number of bytes of fragments is not less than the total number of bytes of business data.
[0047] Furthermore, after determining the new fragment size and number of fragments, the edge node enters the transmission buffer management phase. The transmission buffer is a ring-shaped memory block on top of the network protocol stack, used to store unsent data packets. Each data packet already contains a priority field and a generation timestamp field when stored in the buffer. The edge node prioritizes and adjusts the queue of all data packets in the buffer according to the new fragment configuration. Specifically, it first sorts them by priority field from largest to smallest. When two data packets have the same priority value, it sorts them by generation timestamp from earliest to latest. The buffer pointer is rewritten after sorting, so that data packets with higher priority and earlier generation time are placed at the front of the queue, and data packets with lower priority are placed at the back of the queue. At the same time, the edge node packages the currently effective fragment size, final fragment number, bandwidth utilization, and sorting strategy summary into an optimized transmission parameter configuration record and caches it in memory to guide the subsequent encryption and transmission process. Subsequently, the edge nodes select an encryption algorithm based on the packet loss rate parameter in the network performance evaluation report and generate a secure verification code sequence. The packet loss rate threshold is determined experimentally during the deployment phase. The experimental method involves testing the end-to-end latency, processor utilization, and retransmission processing time using AES and DES encryption algorithms in simulated network environments with different fixed packet loss rates. Scenarios with a packet loss rate of less than 1% are classified as normal links, while scenarios with a packet loss rate higher than 1% are classified as unstable links. In normal links, the processing overhead of the AES encryption algorithm is acceptable and provides higher security. However, in unstable links, the computational overhead of the AES encryption algorithm increases significantly due to frequent retransmissions. Therefore, the preset packet loss threshold is set to 1% and written into the configuration. During runtime, the edge nodes read the packet loss rate parameter. When the value is less than or equal to 1%, the AES encryption algorithm is selected for the current data batch. When the value is greater than 1%, the DES encryption algorithm is selected and recorded in the optimized transmission parameter configuration.
[0048] Furthermore, when generating the security verification code sequence, the edge node assigns a unique sequence number to each data packet to be sent. The sequence numbers start from 1 and increment sequentially. For each data packet generated, the sequence number is incremented by 1 and written to the data packet sequence number field in the packet header. Based on this, a checksum is calculated for each data packet. The calculation method for the checksum is determined and fixed during the deployment phase. Specifically, the edge node reads all bytes in the header and data payload sequentially, starting from the first byte of the data packet header. The values of each byte are summed to obtain a total. This total is then divided by a fixed integer 1000, and the remainder is used as the checksum value. This value varies between 0 and 999 and is written to the checksum field in the data packet header. Simultaneously, the edge node maintains a security verification code list in memory, recording the sequence number and corresponding checksum of each data packet sequentially in the list. This list constitutes the security verification code sequence. Afterwards, the edge node uses the security verification code sequence... The edge node performs an XOR operation on the sorting status code to complete the encryption and encapsulation. The sorting status code is a status code generated by the upstream monitoring process based on the nut detection results. Each sorting status code consists of several bits, and each bit represents a specific sorting status indicator, such as qualified, unqualified, damaged, etc. When the edge node performs encryption, it first converts the check code into a binary bit sequence of the same length as the sorting status code. This conversion process involves decomposing the check code value into a binary representation and padding it with zeros until the number of bits is equal to the number of bits in the sorting status code. Then, the binary bit sequence of the sorting status code and the binary bit sequence of the check code are matched bit by bit, and an XOR logical operation is performed bit by bit. For each bit, if the two input bits are the same, the output bit is 0; if the two input bits are different, the output bit is 1. After all bits are processed, a new binary bit sequence is obtained. This sequence is the encrypted sorting status information. The edge node uses this encrypted sorting status information to overwrite the original sorting status code field, thereby completing the encryption and encapsulation of the status code.
[0049] In this invention, to control the transmission interval between adjacent data packets, the edge node sets a monitoring frequency value during the deployment phase based on the timescale of changes in the sorting equipment status and network transmission capacity. Specifically, process engineers record the shortest time interval from a change in equipment status to the need to send monitoring data through on-site testing, and calculate the acceptable number of data packets per second based on network bandwidth. In this embodiment, the monitoring frequency value is set to send 10 data packets per second, corresponding to a transmission interval of 100ms between adjacent data packets. This value is fixed after being written into the system configuration. During operation, the edge node uses a timer in the sending thread. Every 100ms accumulated by the timer, the next encrypted and encapsulated data packet is retrieved from the head of the transmission buffer queue and handed over to the network protocol stack for transmission. Multiple sets of encrypted data packets continuously sent according to the monitoring frequency value constitute a data packet group. During the receiving or readback phase, the edge node extracts the checksum and data content from each data packet in the data packet group to ensure integrity. Verification specifically involves reading all bytes in the header and payload of each data packet in the same order as during the transmission phase. The byte values are summed, and the sum is divided by 1000 with the remainder to obtain a new checksum value. This new checksum is compared one by one with the checksum originally stored in the header of the data packet. If the two values are completely consistent, it is determined that the data packet has not been erroneous or tampered with during transmission, and the encryption status information and other monitoring fields can be extracted. If the two values are inconsistent, the data packet is considered to have an error. In this embodiment, the time and sequence number of the data packet verification failure are recorded in the internal log of the edge node, and the data packet is not included in the subsequent monitoring data stream. After all data packets in the data packet group have completed integrity verification, the edge node arranges all the data packets that have passed verification in ascending order of data packet sequence number. The encryption status information, data packet sequence number, timestamp, and channel-related information in each data packet are extracted and sequentially concatenated to form a monitoring data stream.
[0050] Preferably, S4 includes acquiring real-time congestion parameters and signal strength measurements of the current network link; collecting link bandwidth utilization, buffer occupancy, and signal attenuation coefficient through network probe packets; classifying congestion into three levels (mild, moderate, and severe) based on the congestion value range; establishing a three-dimensional evaluation parameter table corresponding to the signal strength range; recording the RSA key bit configuration under different congestion levels and signal strength combinations; using the key bit configuration in the evaluation parameter table, if the link congestion exceeds a preset security range, generating a path probe data packet containing the source and destination addresses; measuring the round-trip time and available bandwidth of alternative transmission paths by sending probe data packets; calculating the path comprehensive score by adding the delay and bandwidth values according to a weighted ratio; and initiating Hamming code error correction processing to generate a verification value based on the path comprehensive score. The bit sequence method divides the original data packet into data bit groups of fixed length. A parity bit is calculated for each data bit group and appended to the end of the data bit group to form an encoded data block. An error detection flag is obtained by XORing the parity bit and the data bits in the encoded data block. Using the error detection flag, the transmission path with the highest score is selected as the primary transmission path, and the path with the second highest score is selected as the backup transmission path. A path control instruction set containing primary and backup path address information and switching trigger conditions is generated. Using the path control instruction set, the encoded data block processed by RSA is forwarded according to the primary transmission path. A sorting code for identifying the data packet type and a status flag for detecting transmission anomalies are added to the header of the data block to obtain an encrypted data stream with path switching capability for sorting anomaly diagnosis and processing.
[0051] In this implementation, after the preceding steps have obtained encrypted data blocks with a packet structure, the edge nodes periodically acquire the real-time congestion parameters and signal strength measurements of the current network link. The statistical period is determined to be 60 seconds during the deployment phase by network maintenance personnel through multiple measurements of the link jitter cycle. Specifically, after equipment installation, the link is allowed to run continuously for several hours under typical industry loads, and the bandwidth utilization curve is recorded. The length of a complete fluctuation cycle of bandwidth utilization from low to high and then back down is calculated. The average of multiple cycles is taken and rounded up to 60 seconds, and this 60-second period is written to the configuration file as a fixed statistical period. Within each statistical period, the edge node calls the statistical interface provided by the network protocol stack. The interface returns the cumulative number of bytes sent in the uplink direction and the downlink direction within that 60-second period. The cumulative number of received bytes and the maximum number of bytes that can be sent per second corresponding to the maximum bandwidth of the link are used to calculate the average actual number of bytes transmitted per second by the edge node by dividing the total number of bytes in the uplink and downlink directions by the length of the statistical period. Then, the average actual number of bytes transmitted per second is divided by the maximum number of bytes that can be sent per second and multiplied by 100 to obtain the bandwidth utilization percentage. At the same time, the statistics interface also returns the average number of bytes occupied in the send buffer, the total capacity of the send buffer, the average number of bytes occupied in the receive buffer, and the total capacity of the receive buffer within the statistical period. The edge node divides the average number of bytes occupied in the send buffer by the total capacity of the send buffer and multiplies by 100 to obtain the send buffer utilization percentage, and divides the average number of bytes occupied in the receive buffer by the total capacity of the receive buffer and multiplies by 100 to obtain the receive buffer utilization percentage.
[0052] Specifically, to integrate the three indicators into a single congestion parameter, during the deployment phase, network maintenance personnel and system designers determine the weighting coefficients based on performance data collected over long-term operation. In this implementation, the weight of bandwidth utilization is set to 50%, the weight of transmit buffer occupancy is set to 25%, and the weight of receive buffer occupancy is set to 25%. The method for determining these weights is to perform regression analysis on link performance under multiple different loads. It was found that the impact of bandwidth utilization on latency and packet loss is approximately half of the total impact, and the impacts of transmit and receive buffer occupancy are roughly equivalent. Therefore, the above weights are given and written into the configuration. In the process, edge nodes obtain the congestion parameter percentage by the following steps: first, multiply the bandwidth utilization percentage by 50, then multiply the transmit buffer occupancy percentage by 25, then multiply the receive buffer occupancy percentage by 25, add the three results together and divide by 100 to obtain a value between 0 and 100. This value is used as the congestion parameter percentage at the current moment. The signal strength measurement value is reported by the network interface physical layer every second through the driver, and the unit is a fixed power level negative value. During the deployment phase, when the equipment is installed and debugged, the average signal strength over a period of time is recorded as the reference signal strength in an environment with minimal interference.
[0053] In this implementation, the baseline signal strength is obtained by averaging the signal strength data sampled continuously for 300 seconds during the initial installation. During operation, the current average signal strength is obtained by averaging all signal strength samples reported by the physical layer within each 60-second statistical period. The absolute value of the difference between the baseline signal strength and the current average signal strength is then used to obtain the signal attenuation coefficient. The larger the signal attenuation coefficient, the more severe the signal attenuation. At the same time, the edge node sends network probe packets periodically within the statistical period, sending one every second. The probe packet header contains a fixed probe identifier, and the payload length is very small. After being sent, it is immediately returned by the peer as is. The edge node records the time difference between sending and receiving each probe packet, as well as the instantaneous bandwidth utilization and buffer occupancy rate at the time of sending the probe packet. However, these instantaneous values are mainly used to assist in the analysis of short-term link fluctuations, and the congestion parameter is still based on the weighted percentage obtained from the 60-second period.
[0054] After the congestion parameters are prepared, the deployment phase divides the congestion value range according to a standardized method. Specifically, under the stress test environment, the service traffic is gradually increased, and the congestion parameters and corresponding average latency and packet loss are recorded under different combinations of bandwidth utilization and buffer occupancy. The latency and packet loss when the congestion parameter is below 40% are marked as areas with less impact on the service. Therefore, the congestion percentage in the range of 0 to 40 is defined as mild congestion. The test results corresponding to the congestion percentage in the range of 40 to 70, where the latency starts to rise significantly but is still within an acceptable range, are defined as moderate congestion. The area corresponding to the congestion percentage of 70 and above, where the latency and packet loss increase significantly, is defined as severe congestion. The boundaries of these three intervals, 40 and 70, are written into the configuration as fixed values. During operation, the current congestion level is determined based on the relationship between the congestion percentage and these two boundaries.
[0055] For signal strength, signal strength and bit error rate are measured at the equipment site under three environments: no significant interference, moderate interference, and strong interference. The average signal strength under no significant interference is calculated, and values slightly below this average are used as the lower threshold for strong signals. The average signal strength under significant interference is used as the upper threshold for weak signals, and values slightly above this average are used as the upper threshold for weak signals. Thus, a signal strength above the lower threshold is considered a strong signal range, a signal strength below the upper threshold is considered a weak signal range, and the range in between is considered a medium signal range. These two thresholds are written into the configuration. Based on the two dimensions of congestion level and signal strength level, and the third dimension of a preset RSA key bit combination, a three-dimensional evaluation parameter table is finally formed in memory. Each row in the table corresponds to a combination of a congestion level (mild, moderate, severe) and a signal strength level (strong, medium, weak), and the RSA key bit number to be used is written for this combination. In this embodiment, the security policy makers determine the key bit configuration as follows: First, under conditions of no congestion and strong signal, different bit lengths of RSA encryption are tested. Regarding the impact on CPU time and transmission latency, it was found that 2048 bits can meet the real-time requirements under current hardware conditions, while also offering a high level of security. Therefore, 2048 bits are chosen when the congestion level is mild and the signal is strong or medium, while 1536 bits are chosen to slightly reduce computational overhead when the signal is weak. When the congestion level is moderate, 1536 bits are chosen when the signal is strong or medium, while 1024 bits are chosen when the signal is weak. When the congestion level is severe, to prioritize availability, 1024 bits are used uniformly for all strong, medium, and weak signal conditions. All these combinations and their corresponding key bit lengths are statically configured in a table. At runtime, the RSA key bit length is obtained by looking up the table based on the current real-time congestion level and signal strength measurement. In addition, to determine whether path optimization is needed, a preset safety range was determined by process engineers and network maintenance personnel during the deployment phase. That is, the congestion level is acceptable as long as it does not exceed the upper limit of medium. By analyzing historical records and comprehensively considering the acceptable latency of the service, a congestion percentage of 70% was selected as the upper limit of the safety range. When the congestion percentage is greater than 70%, the current link congestion level is considered to be outside the safety range.
[0056] In actual operation, when the congestion level is within a safe range, the system only adjusts the RSA key length based on the three-dimensional evaluation parameter table without performing path reselection. When the congestion level is detected to be greater than 70, the system enters the path detection and optimization process. First, path detection packets are generated based on the list of alternative transmission paths in the network configuration. The header of each path detection packet contains source address and destination address fields. The source address is the network address of the current edge node, and the destination address is the address of the peer node corresponding to each alternative path. A fixed-length detection sequence number is written into the payload to distinguish different detection rounds. The size of the detection packet is set to be much smaller than the maximum transmission unit of the link during the deployment phase. The fixed number of bytes is 64 bytes in this embodiment to reduce additional overhead. Edge nodes select candidate paths one by one, sending path probe data packets to the target address via a specified next-hop sequence. The sending time is recorded for each probe packet sent, and the receiving time is recorded when a response packet is received from the peer. Ten probe packets are sent consecutively on each path, and the round-trip time for each packet is calculated. The ten round-trip times are then added together and divided by 10 to obtain the average round-trip latency for that path, in milliseconds. In the response packet, the peer also writes the available bandwidth value based on the monitored current path bandwidth. The calculation method is... The remaining bandwidth, obtained by subtracting the current instantaneous actual bandwidth usage from the physical maximum bandwidth of the path, is then encoded in bytes per second. In this implementation, the available bandwidth is directly taken as the statistical value of the unused bandwidth within the current second. Edge nodes pair and store the average round-trip latency and available bandwidth of each path, and establish a correspondence between path numbers and these values. To convert round-trip latency and available bandwidth of different dimensions into comparable path scores, a scoring algorithm is defined during the deployment phase, with latency scoring weighted at 60% and bandwidth scoring weighted at 40%. The determination process involves plotting the test results of multiple paths into a scatter plot and comparing latency-prioritized and bandwidth-prioritized paths. The impact of each width-first approach on diagnostic real-time performance and data integrity is considered to have a greater impact on monitoring real-time performance, and therefore it is given a higher weight. In the specific scoring process, for all candidate paths, edge nodes first find the maximum and minimum round-trip delay values. For a certain path, if its round-trip delay is equal to the minimum value, the delay score of the path is set to 100. If it is equal to the maximum value, it is set to 0. If it is in the middle, the delay score of the path is calculated as the difference between the round-trip delay of the path and the maximum value, divided by the difference between the maximum and minimum values, and then multiplied by 100. In words, the closer to the minimum delay, the closer the score is to 100, and the closer to the maximum delay, the closer the score is to 0.Similarly, for available bandwidth, identify the maximum and minimum available bandwidth values across all paths. Assign a bandwidth score of 100 to the path with the highest available bandwidth and 0 to the path with the lowest available bandwidth. Linearly interpolate the bandwidth scores of the remaining paths within the range of 0 to 100, based on their available bandwidth positions between the maximum and minimum values, ensuring that higher available bandwidth results in higher bandwidth scores. Then, for each path, multiply its latency score by 60 and its bandwidth score by 40, add the two together, and divide by 100 to obtain the path's overall score, which is between 0 and 100. A higher score indicates a better path. Edge nodes write the comprehensive score of each path, along with the path number and next-hop address list, into the path evaluation table. After obtaining the comprehensive path score, the system initiates Hamming code error correction processing to generate a check bit sequence. In this embodiment, the service payload in the original data packet has already been encrypted and encapsulated in stage S3. Here, in the link selection stage, the encrypted payload is still extended with check bits in units of bits. Specifically, the encrypted payload of each data packet is expanded into a bit sequence by bytes, and then divided into several data bit groups of fixed length starting from the first bit. Each group contains 64 bits. If the last bit is... If the remaining data bits are less than 64 bits, 0s are padded at the end until the number of bits reaches 64. The overall length of the Hamming code is determined during the deployment phase based on the target bit error rate and coding overhead. In this implementation, each coded data block is designed to contain 64 data bits and 7 parity bits, with a total length of 71 bits. The positions of the 7 parity bits and the set of data bit numbers that each parity bit is responsible for checking are pre-calculated by the coding designers and made into a coverage table, which is written into the program to ensure that each data bit is covered by at least one parity bit, and each parity bit also covers multiple data bits to form the classic single-bit error correction capability. In specific calculations, edge nodes... For each 64-bit data group, for each parity bit, the indices of all data bits to be checked corresponding to that parity bit are read from the coverage table. Then, the bit values at those positions are retrieved one by one from the data group according to the index. These bit values are treated as 0s and 1s added together to obtain an integer sum. If the integer sum is even, the parity bit is written as 0; if the integer sum is odd, the parity bit is written as 1. After calculating all 7 parity bits, the 7 parity bits are appended to the 64-bit data group in a predetermined order to form a 71-bit encoded data block. These encoded data blocks are then concatenated in their original order to form the encoded data stream.
[0057] During the error detection phase, before each encoded data block is sent, the edge node performs a check recalculation for each encoded data block, similar to the method used during encoding, except that it now includes check bits and data bits. The system again sums all the data bits covered by each check bit according to the coverage table to calculate the parity result. If the calculated parity is the same as the original check bit value in the encoded data block, the error detection flag for that check bit is set to 0; otherwise, it is set to 1. Each of the seven check bits corresponds to seven error detection flags. The edge node sequentially combines these seven bits to form an error detection flag sequence. If this sequence is all 0, it indicates that no single-bit error was detected after encoding the encoded data block. If at least one error detection flag is 1, it indicates that the encoded data block had an error before transmission or was corrupted in the buffer. Based on this, the system increases its suspicion of the current path in subsequent path control decisions.
[0058] Specifically, during the primary / backup path selection process, edge nodes first sort all available paths from highest to lowest based on their comprehensive path score. The path with the highest score is selected as the primary transmission path, and the path with the second highest score is selected as the backup transmission path. When scores are the same, the average round-trip time of the paths is compared, and the path with the lower latency is selected as the priority path, serving as either the primary or backup path. Paths with lower scores or higher latency are only kept in the path evaluation table as candidates but do not participate in the current round of primary / backup selection. Then, the edge nodes generate a path control instruction set, which is stored in structured record form. This set includes the path number of the primary transmission path and the next-hop address column for each hop from the source node to the target node. The table lists the path numbers and next-hop addresses of the backup transmission paths, and includes specific thresholds for path switching trigger conditions. These trigger conditions are determined by security policy developers during the deployment phase, taking into account bit error rate requirements and path stability test results. This implementation uses two types of trigger rules: a threshold for the number of consecutive erroneous data blocks and a threshold for a decrease in the overall score. The method for determining the threshold for the number of consecutive erroneous data blocks is as follows: different degrees of link failure are simulated in a test environment. After observing the impact of transient and persistent errors on the sorting and diagnostic results, five consecutive detections of erroneous encoded data blocks are used as the dividing line between transient bit errors and serious link quality problems. Therefore, five times is written as a fixed threshold into the configuration. Secondly, the method for determining the threshold for the overall score decrease is to perform statistical analysis on the historical path score sequence. When the overall path score is lower than the backup path score for three consecutive statistical periods and the difference exceeds 10 points, a significant increase in diagnostic delay is observed. Therefore, the score decrease threshold is set to 10 points, the number of consecutive periods is 3, and this is written into the configuration. During operation, the logic in the path control instruction set is executed. When the error detection flag sequence of 5 consecutive coded data blocks detected on a certain main transmission path contains at least one 1, that is, 5 consecutive data blocks have errors, or when the overall score of the main path is lower than the backup path overall score every time in the last 3 statistical periods and the difference is not less than 10 points each time, the edge node will... The forwarding path of the encoded data block is switched from the primary path to the backup path, and the path switching event is recorded in the status flag. After the path control instruction set and the primary and backup paths are determined, the edge node calls the security module in the edge node to generate the corresponding RSA key pair according to the RSA key bit configuration given in the three-dimensional evaluation parameter table. The public key is used to encrypt the encoded data block at this node, and the private key is stored at the authorized decryption end for decryption. In the actual encryption process, the edge node converts each 71-bit encoded data block into an integer plaintext block according to the RSA algorithm requirements, and then uses the public key with the currently selected bit number to perform an exponentiation operation to obtain the ciphertext block. The ciphertext block is used as the new payload to replace the data bit part of the original encoded data block.When generating the final data structure to be sent, the edge nodes add a fixed-format data block header to the beginning of each encrypted block. The header contains a sorting code field and a status flag field. The length of the sorting code field is determined by process engineers during the deployment phase based on the number of different business types.
[0059] In this implementation, the sorting code is specified as an 8-bit binary code, where each specific code represents a distinct sorting service type, such as normal operation monitoring, suspected anomaly warning, and confirmed fault report. These codes are all statically written into the system configuration in tabular form. During runtime, the corresponding code is written to the sorting code field according to the service type when constructing the data block header. The status flag field is determined to be 8 bits long during the deployment phase. It contains information indicating whether the data block is being sent for the first time, whether it is a retransmission block, whether it is currently being transmitted on the primary path or the backup path, whether the most recent error detection result passed, and whether a path switch has just occurred. The meaning of each status is... The specific value correspondences are explicitly listed in the configuration. For example, the first-transmission flag is 1 for the first transmission and 0 for a retransmission; the path flag is 1 for the primary path and 0 for the backup path; the error detection pass flag is 1 for a pass and 0 for a fail; and the path switching flag is 1 for a recent switch and 0 for no switch. The edge node concatenates the sorting code and status flag in the header with the subsequent RSA encrypted ciphertext block to form a complete data packet. Then, it forwards the data packet according to the next-hop address link of the primary transmission path in the path control instruction set. When the switching condition is detected, the subsequent data packets are forwarded according to the next-hop address link of the backup path.
[0060] As a preferred technical solution of the present invention, S5 includes obtaining historical access log records of storage nodes, extracting access timestamps, data read and write frequencies, node response delays and access failures, calculating the access success rate and average response time of each storage node in different time periods, and combining node identifiers with corresponding access performance indicators to form an access pattern dataset.
[0061] Using access success rate and response time data from the access pattern dataset, combined with link outage frequency and real-time bandwidth availability values obtained from network monitoring, a Bayesian classifier is used to classify the stability of each storage node. The access success rate is used as the prior probability and the link outage frequency is used as the conditional probability for calculation. If the node outage frequency exceeds a preset threshold, the node is classified as low stability level, resulting in a node evaluation matrix containing stability level identifier and reliability score.
[0062] Based on the stability level identifier in the node evaluation matrix, storage access policy rules corresponding to different permission levels are formulated. The first stability node is assigned read and write permissions, the second stability node is assigned read-only permissions, and the third stability node is set as a backup node. A mapping relationship is established between permission levels and node identifiers to form a permission allocation table.
[0063] By using the permission level mapping relationship in the permission allocation table, a storage location is selected from the first stability node. The encrypted transmission data stream is classified and stored according to data type and importance. A primary and backup dual-node storage mode is adopted for key diagnostic data. An integrity verification code based on cyclic redundancy check is added to the end of the data block to generate an optimized storage data entity containing storage address mapping and data integrity verification code. Using the storage address mapping information in the optimized storage data entity, the changing trend of sorting equipment operating parameters and the nut appearance quality inspection results are extracted. By comparing historical normal operation data, the threshold range of abnormal equipment status is established. The appearance defect image features of different types of nuts are collected to establish a quality defect feature library, forming a sorting anomaly diagnosis basis based on storage data correlation analysis.
[0064] In this embodiment, after the data stream has been generated through encrypted transmission and path selection in the preceding steps, the storage management function in the edge node periodically retrieves historical access log records from each storage node. The historical access logs are stored locally on each storage node in an append-only manner. Each record in the log contains at least an access timestamp, an access type flag, an access result flag, an access response latency value, and an access failure reason code. In this embodiment, the access timestamp is accurate to milliseconds, the access type flag distinguishes between read and write operations, the access result flag uses integers 0 to indicate failure and 1 to indicate success, the node response latency records the time difference from sending a request to receiving a response in milliseconds, and the access failure reason code uses integers to encode different failure reasons. The edge node scans the logs of each storage node within a fixed statistical period. The statistical period is determined by the system designers during the deployment phase through multiple rounds of actual testing, taking into account the business access rhythm and storage node load fluctuations.
[0065] In this implementation, the statistical period is set to 60 minutes, meaning statistics are performed every 60 minutes. Within this period, for a specific storage node and edge node, the total number of access records is counted. The number of records with an access result flag of 1 is recorded as the number of successful accesses within that period, and the number of records with an access result flag of 0 is recorded as the number of failed accesses. The total number of accesses is obtained by adding the number of successful accesses to the number of failed accesses. Then, the percentage of successful accesses is obtained by dividing the number of successful accesses by the total number of accesses and multiplying by 100. Simultaneously, the response latency values of all successful access records within this period are accumulated and used... Dividing the accumulated value by the number of successful accesses yields the node's average response time within that period, in milliseconds. Data read / write frequency is obtained by counting the number of read and write operation records separately. Node response latency has been calculated as above. The number of access failures is directly derived from the number of failed records. Access timestamps are used to divide log records into different statistical periods. During the initialization phase, the system assigns a unique node identifier to each storage node. This identifier is registered by maintenance personnel and written to the configuration file during device deployment. During the statistical process, edge nodes use the node identifier as an index to calculate the access success rate percentage and average response time. The system combines metrics such as read / write frequency and access failure count to form the access performance metric record of the node within a statistical period. The records from all periods are then arranged chronologically to form the access performance time series of each node. The system merges the access performance time series of all nodes to form an access pattern dataset. Each record in the access pattern dataset consists of a node identifier field, a statistical period time range field, an access success rate field, an average response time field, a read operation frequency field, a write operation frequency field, and an access failure count field. Furthermore, the edge node obtains the interruption frequency and real-time bandwidth availability values for each storage node link from the network monitoring function. During operation, the network monitoring function continuously monitors the link connection status between the storage node and the edge node. Whenever a connection is detected to transition from a normal state to an interrupted state, an interruption event is recorded, along with the timestamp of the interruption and the timestamp of recovery. In this embodiment, the link interruption frequency is expressed as the number of interruptions per hour. Specifically, the calculation involves counting the number of link interruption events for the node within the statistical period, converting the statistical period length into hours. In this embodiment, the statistical period is 60 minutes, therefore the number of hours is 1. The link interruption frequency value is obtained by dividing the number of interruptions by the number of hours.Real-time bandwidth availability is obtained by evaluating the average available bandwidth of the node's link within the statistical period. Specifically, the available bandwidth of the node's link is recorded by network monitoring every 10 seconds within the period. This is calculated by subtracting the current bandwidth occupied from the maximum physical bandwidth of the link to obtain the remaining bandwidth. The remaining bandwidth values from all 10-second sampling points are summed and divided by the number of sampling points to obtain the average available bandwidth of the node within the statistical period. This average available bandwidth is then divided by the maximum physical bandwidth of the link and multiplied by 100 to obtain the real-time bandwidth availability percentage of the node within that period. Access success rate percentage, average response time, link outage frequency, and real-time bandwidth availability together constitute the input features of the Bayesian classifier. The system uses the Bayesian classifier to classify the stability of each storage node. Specifically, during the deployment phase, the system selects a batch of manually confirmed storage nodes from a long period of historical data as training samples. Some nodes experience almost no interruptions and maintain high access success rates and bandwidth availability over a long period; these nodes are marked as stable nodes by maintenance personnel. Other nodes frequently experience interruptions and access failures during operation; these nodes are marked as unstable nodes. The access success rate, average response time, link outage frequency, and real-time bandwidth availability of the training samples are discretized and bucketed according to numerical intervals. For example, the access success rate is divided into multiple intervals in 1% increments, the average response time is divided into multiple intervals in fixed millisecond segments, the link outage frequency is divided into several intervals based on 0, 1, 2, or more times per hour, and the real-time bandwidth availability is divided into multiple intervals in 20% segments. Then, for each interval combination, the proportion of records falling into that combination in the stable node samples is counted out of the total number of stable samples. This proportion is recorded as the number of records of that feature combination observed under the stable node assumption. The system calculates the probability value of each feature combination, then calculates the proportion of records in unstable node samples that fall into the same feature combination out of the total number of unstable samples. This proportion is recorded as the conditional probability value of observing that feature combination under the unstable node assumption. During the same training process, the system also calculates the long-term average access success rate of each node and considers this long-term average access success rate as the prior probability that the node belongs to a stable state. The access failure rate, obtained by subtracting the access success rate from 1, is considered as the prior probability that the node belongs to an unstable state. This process ultimately forms a Bayesian classification model containing a feature combination conditional probability table and a prior probability table.
[0066] In actual operation, for a certain node within a certain statistical period, the system first reads the access success rate and average response time of the node within that period from the access pattern dataset, and then obtains the link interruption frequency and real-time bandwidth availability of the node within the same period from network monitoring. It then determines which predefined success rate interval the access success rate belongs to, which response time interval the average response time belongs to, which interruption frequency interval the link interruption frequency belongs to, and which bandwidth availability interval the real-time bandwidth availability belongs to. The combination of these four intervals is located in the conditional probability table of the Bayesian model to find the corresponding conditional probability value. One set of conditional probability values corresponds to the stable node hypothesis, and the other set of conditional probability values corresponds to the unstable node hypothesis.
[0067] The system then uses the access success rate of the node in the current statistical period as the prior probability of the stable node hypothesis and the access failure rate in the current statistical period as the prior probability of the unstable node hypothesis. The prior probability of the stable node is multiplied by the corresponding conditional probability value to obtain the non-normalized score of the node belonging to the stable node in the current statistical period. The prior probability of the unstable node is multiplied by the corresponding conditional probability value to obtain the non-normalized score of the node belonging to the unstable node. The two non-normalized scores are then added together to obtain a normalization coefficient. The non-normalized score of the stable node is divided by the normalization coefficient to obtain the posterior probability of the node being a stable node in the current period. This posterior probability is between 0 and 1.
[0068] In this implementation, the posterior probability is defined as the reliability score of the node in the current period. To prevent nodes with extremely high link outage frequency but still high access success rate from being incorrectly classified as stable nodes, a mandatory link outage frequency threshold is introduced based on the Bayesian classification results. During the deployment phase, when analyzing historical outage statistics, maintenance personnel calculate the maximum number of link outages per hour for all nodes that have been manually identified as stable for a long time. Then, a certain safety margin is added to this maximum value. In this implementation, the margin is set to 1. The sum of the above maximum value and the margin is used as the preset outage frequency threshold. In this implementation, the preset outage frequency threshold is 2 times per hour. During operation, if a node has a high number of outages within the current statistical period... If the link interruption frequency exceeds twice per hour, the system will directly classify the node as low stability regardless of the reliability score calculated by Bayesian classification, and force the reliability score to be set to a low fixed value, which is 0.3 in this embodiment. Otherwise, when the interruption frequency does not exceed the threshold, the reliability score output by Bayesian classification will be used as the basis for stability judgment. After obtaining the reliability score of each node, the system will classify the nodes into three levels by setting a stability level division threshold. During the deployment phase, the system will calculate the distribution of reliability scores for all stable nodes in the training samples, sort these reliability scores from largest to smallest, and select the reliability score at the 5th percentile position in the sort as the lower limit of the first stability level.
[0069] In this embodiment, the lower limit is approximately 0.98. Using 0.98 as a fixed value, nodes with a reliability score greater than or equal to 0.98 and not triggering the forced degradation condition due to interruption frequency are classified as first-stability nodes. Nodes in the training samples that are neither first-stability nor significantly unstable are then classified as moderately stable samples. Their reliability scores are sorted from largest to smallest, and the reliability score at the 10th percentile is selected as the second stability lower limit. In this embodiment, this lower limit is approximately 0.95. Nodes with a reliability score greater than or equal to 0.95 and less than 0.98 are classified as second-stability nodes. The remaining nodes are classified as third-stability nodes if they have not been forcibly degraded. If a node has already been forcibly degraded due to interruption frequency exceeding the threshold, it is directly... The system categorizes each node into the third stability level. It records the node identifier, access success rate, average response time, link interruption frequency, real-time bandwidth availability, stability level identifier, and reliability score for each node in a row-by-row format, forming a node evaluation matrix. Each row in the matrix corresponds to a storage node, and each column corresponds to one of the aforementioned indicators. A stability level identifier value of 1 indicates a first-level stable node, 2 indicates a second-level stable node, and 3 indicates a third-level stable node. Based on this, the system formulates storage access policy rules corresponding to different permission levels according to the stability level identifiers in the node evaluation matrix. These rules are determined by security policy developers during the deployment phase based on the business's data availability requirements.
[0070] In this implementation, nodes with a stability level of 1 are granted read and write permissions, allowing them to store new data and update and read existing data. Nodes with a stability level of 2, due to their slightly lower reliability, are granted only read-only permissions, allowing data to be read from the node but not allowing new data to be written to the node or existing data to be modified. Nodes with a stability level of 3 serve as backup nodes, only providing backup storage when the primary node fails or long-term archiving is required, and do not provide regular read and write services under normal circumstances. During system operation, the node evaluation matrix is read to generate a permission level identifier for each node. Read and write permissions correspond to a permission level value of 3, read-only permissions correspond to a permission level value of 2, and backup permissions correspond to a permission level value of 1. A one-to-one mapping relationship is established between node identifiers and permission level values to form a permission allocation table. The permission allocation table is stored in the memory of the edge nodes and is refreshed periodically according to the new node evaluation matrix.
[0071] When a new encrypted data stream arrives at the storage stage, the system first classifies the data according to the data type and importance tags carried in the data packets. The data type tags were already marked in previous steps according to categories such as operating parameter data, appearance inspection result data, system operation log data, and diagnostic conclusion data. The importance tags use integers 1, 2, and 3 to distinguish between critical diagnostic data, important operating data, and general operating data. In this embodiment, integer 1 represents critical diagnostic data, integer 2 represents important operating data, and integer 3 represents general operating data. Edge nodes select a specific storage location from nodes with stability level 1 and permission level 3 according to the permission allocation table. In this embodiment, to achieve load balancing, all first-stability nodes are sorted by node identifier to form a node list. Whenever a new encrypted data stream needs to be stored, the system uses the global sequence number of that data stream. The system modulo the length of the node list to obtain an index value, and uses the node corresponding to this index value as the primary storage node for the data stream. For critical diagnostic data with an importance label of 1, the system adopts a primary-backup dual-node storage mode. After selecting the primary storage node, a backup node is selected from the third stability nodes in descending order of reliability score. The same critical diagnostic data is written to both the primary and backup nodes simultaneously, and the storage address mapping of the two nodes is recorded in the optimized storage data entity. For operational data with an importance label of 2, the system only writes the data to a first stability node, but reserves a backup opportunity for this node in the permission allocation table. During subsequent batch archiving, a background process migrates some data to the third stability node. For general operational data with an importance label of 3, the system prioritizes writing to the first stability node, and only writes to the third stability backup node when space is insufficient.Before writing data blocks to storage nodes, the system generates an integrity verification code based on cyclic redundancy check (CRBC) at the end of each data block. The verification length is determined by security policy makers and software developers during the deployment phase based on error risk and additional storage overhead. In this implementation, a 32-bit CRBC is used. The specific calculation process is as follows: during initialization, the system clears a 32-bit check register, selects a fixed generator polynomial, and encodes its coefficients as a constant binary value. This constant is stored in the program as a bit table. When performing CRBC on a data block, the system starts from the first byte of the data block and reads 8 bits of each byte in byte order. Each bit is extracted sequentially from the most significant bit to the least significant bit, and the most significant bit of the check register is XORed with the current data bit. The OR operation is performed, and the result is used as the plural signal bit for the current step. The entire check register is then shifted left by one bit, and the current data is shifted into the least significant bit of the register. If the plural signal bit is 1, the current content of the check register is XORed with the constant corresponding to the generator polynomial; otherwise, no XOR operation is performed. After processing all bits of the entire data block, the 32-bit content in the check register is the cyclic redundancy check value for that data block. The system appends this 32-bit check value to the end of the data block as a fixed-length field; this field is the integrity verification code. During write to storage, the system simultaneously generates storage address mapping information for each data block. The storage address mapping includes at least the node identifier, physical storage path or logical volume identifier, file offset or block sequence number, and data block length.
[0072] In this implementation, this information, along with the cyclic redundancy check value, is organized into a whole with the data block content, called the optimized storage data entity. This entity is written into a specific storage node, and the storage address mapping of the optimized storage data entity is recorded in the metadata index table maintained by the edge node. During the sorting anomaly diagnosis stage, the system uses the storage address mapping information in the optimized storage data entity to read historical storage data in batches from the first stability node and the third stability backup node, extracting the changing trends of sorting equipment operating parameters and the nut appearance quality inspection results. The operating parameters include the time sequence of the conveyor belt running speed, airflow pressure value, and light intensity value in the aforementioned sorting channel. The appearance quality inspection results include color distribution parameters, shape contour parameters, nut length and width dimensions, and appearance defect markers identified in the previous steps. To establish the equipment status anomaly threshold range, the system filters historical data marked as normal operating status from the optimized storage data entity. This data is divided according to the monitored equipment and channel, and a normal sample set is constructed for each type of operating parameter. The average level and fluctuation amplitude of each operating parameter are calculated in this set, specifically by summing all normal sample values of a certain parameter. Dividing by the sample size yields the normal average. Then, the absolute value of the difference between each record and the average is calculated. These absolute values are summed and divided by the sample size to obtain the average deviation value of the parameter. In this embodiment, the average deviation value is multiplied by 3 to obtain the abnormal alarm range span. The normal average value plus the abnormal alarm range span is used as the upper threshold, and the normal average value minus the abnormal alarm range span is used as the lower threshold, forming the equipment status abnormal threshold range for this parameter. These thresholds are written into the equipment status threshold library. For the nut appearance quality inspection results, the system filters out the sorting results marked as non-compliant from the optimized stored data entities. Sample data of different defect types such as graininess, breakage, mold, and uneven color are collected and grouped according to nut type and defect type. For each group, the characteristic values of color distribution parameters (mean and variance of red, green, and blue channels), shape and contour parameters (perimeter to area ratio), length and width are statistically analyzed. The typical range of each feature in the group is calculated. Specifically, the average value and average deviation value of the feature in the group are calculated. The average value is added to and subtracted from the average deviation to obtain the feature interval of the defect type. These intervals, along with the corresponding nut type and defect type labels, are written into the quality defect feature database.
[0073] During actual diagnosis, the system optimizes the storage address mapping provided by the storage data entity to associate the operating parameter data, appearance inspection data and diagnostic output data within the same time window. It compares the currently collected operating parameters with the abnormal threshold range of the equipment status item by item to determine whether they exceed the normal range. It matches the currently collected nut appearance features with the feature range in the quality defect feature library. If the operating parameters exceed the limit or the appearance features fall into a certain defect type feature range, the corresponding abnormal type, the triggered parameter item and the associated historical data are output as the basis for sorting abnormal diagnosis.
[0074] Furthermore, S6 includes parsing network connection records and data packet transmission trajectories from the optimized stored data entities, extracting link performance indicators including transmission latency, packet loss rate, bandwidth utilization, and connection stability, statistically analyzing the number of network node hops and path switching frequency on each data transmission path, recording path change timestamps and change reason identifiers, and generating a path hop statistics table containing path identifiers and hop frequencies. Based on the hop frequency data in the path hop statistics table, combined with the security authentication level and historical attack records of each node in the network topology, each transmission link is assigned different weight values according to the node security level. Nodes with security levels higher than a preset threshold are assigned positive weights, while nodes with security vulnerabilities or abnormal access behavior are assigned negative weights. The security trustworthiness value of each transmission link is calculated by accumulating the weight values of each node, forming a link security assessment matrix containing link identifiers and security scores. Based on the security score values in the link security assessment matrix, links with security scores below the negative range are classified as high-risk, and links with security scores near zero are classified as medium-risk. Links with security scores above the positive range are considered low-risk. The proportion of high-risk links is calculated; if this proportion exceeds a preset warning threshold, an access control level escalation command is triggered, generating a risk assessment report containing risk level identifiers and adjustment instructions. Using the adjustment instructions from the risk assessment report, the authentication requirement in the current access allocation strategy is upgraded from single-factor authentication to multi-factor authentication, the access validity period is shortened from the original time to a preset duration, and the access log recording frequency is adjusted from hourly to minutely. A new mapping relationship is established between the adjusted verification method, validity parameters, and recording frequency and the user identifier, resulting in access control data containing enhanced verification rules and access restrictions. Through the enhanced verification rules in the access control data, strict access control and transmission encryption are implemented for the operational monitoring data and quality inspection diagnostic data generated by the nut sorting equipment. The identity credentials and access permission level of the data requester are verified, and detailed log information for all data access operations is recorded, ensuring the security and reliability of the sorting process monitoring and diagnostic data during transmission and storage.
[0075] In this embodiment, after completing step S5, an optimized storage data entity is obtained. Besides containing nut sorting-related business data, the optimized storage data entity also includes network connection record fields and data packet transmission trajectory fields generated during data generation and transmission. The network connection record field records the timestamp, source address, destination address, transmission path identifier used, and connection status code for each connection establishment and release. The data packet transmission trajectory field records the sequence of nodes each data packet traverses in the network, the arrival and departure times of each hop, whether retransmission occurs at each hop, the number of retransmissions, and the final status flag of the data packet throughout the entire transmission process. When the edge node executes step S6, it first parses the optimized storage data entity line by line, grouping data packets belonging to the same transmission path into the same group according to the path identifier. Then, within each group, it statistically analyzes the transmission time of all data packets. For a specific data packet on a certain path, the system uses that data packet... The end-to-end transmission delay value of the data packet, recorded in the transmission trajectory field, is obtained by subtracting the departure time of the last node from the arrival time of the first node, in milliseconds. The average transmission delay value of the path is obtained by summing the end-to-end transmission delay values of all data packets on the same path and dividing by the number of data packets. The packet loss rate is calculated by counting the total number of data packets that should have been sent within a certain statistical period on the same path and the number of data packets whose final status is marked as failed or timed out. The packet loss rate percentage of the path within that time period is obtained by dividing the number of failed or timed-out data packets by the total number of data packets and multiplying by 100. The bandwidth utilization rate is obtained by counting the total number of service bytes actually transmitted on the path within a certain time window and dividing by the length of the time window to obtain the average number of bytes per second. Then, the average number of bytes per second is divided by the maximum number of bytes per second corresponding to the physical bandwidth of the path and multiplied by 100 to obtain the bandwidth utilization rate percentage of the path. Connection stability is quantified by analyzing the available time and interruption time of the same path over a longer statistical period.
[0076] In this implementation, the statistical period is determined by network maintenance personnel during the deployment phase by analyzing path interruption data from multiple days of operation logs, and is set to 24 hours. Within each period, the system calculates the cumulative duration of normal connection and the cumulative duration of interruption for that path. The normal connection duration is divided by the total duration of the statistical period and multiplied by 100 to obtain the connection stability percentage of that path. After the above link performance indicators are calculated, the system counts the number of network node hops on each data transmission path based on the node sequence recorded in the data packet transmission trajectory. Specifically, for a specific transmission on a certain path, the length of the node sequence in that transmission path is subtracted by one to obtain the number of hops for that transmission. The average number of hops for the same path is obtained by averaging the number of hops for all transmissions within the statistical period. The statistical method for path switching frequency is to read the path identifier in multiple consecutive data packets of the same service session or the same data stream. When the path identifier of the current data packet is different from the path identifier of the previous data packet, it is recorded as a path switching event. The system counts the total number of path switching events for each service data stream within the statistical period, and divides the total number by the duration of the statistical period (in hours) to obtain the path switching frequency of the data stream. Then, the path switching frequencies of all data streams belonging to the same path are averaged according to the path identifier to obtain the average path switching frequency of the path. Simultaneously, upon each path switching event, the system reads the corresponding path change timestamp field from the stored data entity to record the specific time of the switch, and reads the change reason identifier field. This field, written in the preceding steps, indicates whether the switch is due to excessive link latency, excessive packet loss rate, node failure, or manual maintenance operations. The system organizes and archives the path change timestamps and change reason identifiers corresponding to each path according to the path identifier, ultimately generating a path jump statistics table. Each row in the path jump statistics table corresponds to one path and includes fields such as path identifier, average number of jumps, average path switching frequency, most recent change timestamp, and the cumulative number of various change reasons. This information is used for subsequent risk assessment. After obtaining the path hop statistics table, the system combines the security authentication level of each node in the network topology and historical attack records to perform a security rating on each transmission link. The network topology is entered by the network administrator during the deployment phase according to the actual network devices and connection relationships. It includes the unique identifier of each network node, the region to which the node belongs, the node type, and the security authentication level obtained by the node after security assessment. The security authentication level uses integers from one to five to represent the security strength. The larger the value, the more stringent the security authentication. Historical attack records are provided by the security audit system, which records the number of attack events that have occurred to each node, the event type, and whether there are any unpatched security vulnerabilities.
[0077] In this implementation, during the deployment phase, security policy makers determine preset security level thresholds based on enterprise security specifications. Nodes with a security authentication level of four or higher and zero historical attack counts are classified as high-security nodes. Nodes with a security authentication level between two and three, or with fewer historical attack counts and patched vulnerabilities, are classified as medium-security nodes. Nodes with a security authentication level of one, unpatched vulnerabilities, or more than a preset number of historical attack counts are classified as low-security nodes. The preset number of historical attack counts is the median of the attack counts of the most frequently attacked nodes when analyzing attack event statistics over the past year. In this implementation, the median is three, so three is used as the boundary. The system assigns a weight value to each node based on the above classification.
[0078] In this implementation, the weight of high-security-level nodes is set to 2, the weight of medium-security-level nodes is set to positive 1, and the weight of low-security-level nodes is set to -2. If a node still experiences an attack within the past month, its weight is reduced by one to make it more negative. For a specific transmission link, the system reads the weight value of each node from the starting point to the ending point according to the path node sequence recorded in the network topology, and adds these weight values one by one to obtain the security and trustworthiness value of the transmission link. This value can be positive or negative. The larger the absolute value, the more obvious the security attribute. A positive value indicates high trustworthiness, and a negative value indicates low trustworthiness. The system stores the path identifier, node sequence, security and trustworthiness value, and the previously calculated number of hops and path switching frequency of each transmission link into the link security evaluation matrix. The link security evaluation matrix represents the link in rows and the link identifier, security and trustworthiness value, average number of hops, average path switching frequency, etc., in columns.
[0079] After obtaining the link security assessment matrix, it is necessary to segment the security scores and classify risk levels. To this end, during the deployment phase, statistical analysis is performed on the security reliability values calculated for all transmission links over a relatively long historical period. These values are sorted from smallest to largest, and their distribution range is observed. In this implementation, analysis revealed that the security reliability values for most links are concentrated between -10 and 10. Based on this distribution, the security team defined the interval with a security reliability less than -2 as the negative value interval, the interval with a security reliability between -2 and 2 as the interval near zero, and the interval with a security reliability greater than 2 as the positive value interval. The boundary values of -2 and 2 are written into the system configuration as fixed thresholds. During runtime, the system traverses the link security assessment matrix and... Each link reads its security and trustworthiness value. When the value is less than -2, the link is marked as high-risk; when the value is ≥ -2 and ≤ 2, the link is marked as medium-risk; and when the value is greater than 2, the link is marked as low-risk. A risk status field is added to the link security assessment matrix to record this result. Subsequently, the system counts the number of links currently in a high-risk state, divides the number of high-risk links by the total number of links, and multiplies by 100 to obtain the percentage of high-risk links in the total number of links. The preset warning threshold is determined by security policy makers during the deployment phase, taking into account the enterprise's risk tolerance and historical event statistics. Specifically, it is the typical range of the proportion of high-risk links before major security incidents in the past year.
[0080] In this implementation, it was found that the system is in a clearly insecure state when the proportion of high-risk links is around 20%. Therefore, the warning threshold is fixed at 20%. When the proportion of high-risk links calculated during runtime is greater than 20%, the system triggers an access control level upgrade instruction and generates a risk assessment report. The risk assessment report records the number of high-risk links, the total number of links, the high-risk ratio, the warning threshold used in the calculation, and the overall risk level identifier given by the system in the current statistical period.
[0081] In this implementation, when the high-risk ratio is greater than 20% and less than or equal to 40%, the overall risk level is set to medium risk; when the high-risk ratio is greater than 40%, the overall risk level is set to high risk, and a corresponding permission adjustment instruction is issued. This instruction explicitly requires upgrading the authentication requirement in the current permission allocation strategy from single-factor authentication to multi-factor authentication, while also shortening the permission validity period and increasing the frequency of access log recording. After receiving the adjustment instruction from the risk assessment report, the system adjusts the specific parameters of the current permission allocation strategy. Firstly, regarding the authentication method, in this implementation, single-factor authentication uses only username and password, while multi-factor authentication uses both username and password. After successful verification, a separate dynamic credential is verified again. The dynamic credential is a second factor pre-bound during the user registration phase, such as a one-time verification code or a code value generated by a hardware token. When no risk is triggered, the system only requires the user to provide a username and password. After the risk assessment report triggers the escalation instruction, the system switches the authentication method of all users participating in nut sorting monitoring and diagnostic data access from single-factor to multi-factor, adds a second-factor verification step to the authentication process, and records the currently enabled verification method for each user identifier in the access control data structure. The adjustment of the permission validity period parameter is preset by the system during the deployment phase, including the original validity period and the shortened validity period under risk conditions.
[0082] In this implementation, the original validity period is 8 hours, meaning that after authentication, users can access authorized data within 8 hours without re-login. After a risk assessment report is triggered, the validity period is shortened to 2 hours. This 2-hour value was determined after analyzing the statistical results of continuous user operation time in typical use cases. The statistical results show that the continuous operation time of most monitoring personnel does not exceed 2 hours. Therefore, 2 hours is used as the fixed validity period under risk conditions. After the system triggers the adjustment command, it immediately compares the remaining validity period of all active sessions with 2 hours, reduces the remaining time of sessions exceeding 2 hours to 2 hours, and sets the validity period of subsequent newly created sessions to 2 hours. The access log recording frequency parameter is recorded hourly when the risk is not triggered, meaning that the system summarizes all access events within that hour and writes them to the access log at the end of each natural hour. When the risk assessment report triggers the privilege escalation command, the system adjusts the recording frequency to minute-based recording, meaning that the access events within that minute are written to the log at the end of each minute. The change in log recording granularity can reflect access behavior more precisely. During the deployment phase, this minute granularity was determined to be acceptable after evaluating log storage space and auditing requirements.
[0083] After modifying the verification method, validity period, and recording frequency parameters, the system re-establishes a mapping relationship between these parameters and specific user identifiers, saving an access control record for each user. This record includes the user identifier, the currently enabled authentication method parameters, the current session validity period parameters, and the current access log recording frequency, thus forming access control data containing enhanced verification rules and access restrictions. Finally, the system uses this access control data to implement strict access control and transmission encryption for the operational monitoring data and quality inspection diagnostic data generated by the nut sorting equipment. Upon each data access request, the system first searches the access control data for the user's corresponding verification method and validity period based on the user identifier carried in the request. If the current session has exceeded the record's validity period, the user is forced to re-complete multi-factor authentication, during which the correct authentication method must be provided. The system requires the user's username, password, and the dynamic credentials bound to the user to be verified before a session identifier is regenerated and its validity period is refreshed; otherwise, access is denied. Access to operational monitoring data and quality inspection diagnostic data is only permitted after verification and confirmation that the user's current access permission level meets the requested data type requirements. The system encrypts the data to be sent according to the encryption transmission parameters configured in steps S3 and S4 to ensure secure data transmission over the link. Simultaneously, after the minute-based recording granularity takes effect, the system generates a complete log entry for each data access operation. Each log entry records the access timestamp, user identifier, accessed data type, accessed node identifier, access result (success or failure), and, if failure, the failure reason code. These log entries are then summarized and written to the access log file or log database on a minute-by-minute basis.
[0084] Preferably, S7 includes: establishing a lifecycle permission coverage table based on the operational stages of the nut sorting equipment, comprising five stages: equipment startup, sorting execution, quality inspection, data transmission, and equipment shutdown; setting different access levels and time window limits for each stage; recording the identity of the permission holder and the boundaries of the operating scope for each stage; associating stage identifiers with corresponding access levels to generate a full-cycle permission allocation list containing the correspondence between stage identifiers and permission levels; using the permission level correspondence in the full-cycle permission allocation list, and based on the differences in data transmission security requirements for different permission levels, performing path planning for data transmission needs generated during nut sorting; filtering candidate transmission paths that meet the security requirements of the current permission level by detecting the connectivity status and bandwidth availability between network nodes; recording the node sequence and jump delay parameters of each candidate path to form a candidate set of transmission paths containing path numbers and node connection information; obtaining the security authentication status and historical access records of each network node through the node connection information in the candidate set of transmission paths; statistically analyzing the number of abnormal connections and data packet loss rate of each node within a preset time period; if the number of abnormal connections of a node exceeds a preset threshold, the node is marked as unsafe. In the context of trust status, a weighted summation method is used to calculate the security weight value of paths containing trusted nodes, where the weight of trusted nodes is positive and the weight of untrusted nodes is negative. This yields a link security verification result containing the path identifier and security weight value. Based on the security weight value in the link security verification result, a mapping table is established to correspond to the numerical range of permission levels and security weights. Paths with security weights higher than the preset upper limit are assigned to administrator-level permissions, paths with security weights in the preset middle range are assigned to operator-level permissions, and paths with security weights lower than the preset lower limit are assigned to visitor-level permissions. The timestamp and triggering conditions of permission level changes are recorded, generating a dynamic permission allocation record containing the user identifier and the current permission level. Using the user identifier and current permission level information in the dynamic permission allocation record, authentication and permission matching are performed on access requests for diagnostic results from the nut sorting status monitoring center. By verifying the consistency between the digital certificate provided by the requester and the pre-stored certificate information, and checking whether the access time is within the permission validity period, access operation logs and data flow trajectories for all diagnostic results are recorded. The verified permission verification rules and access control conditions are integrated to construct a dynamic permission management system that includes an identity authentication mechanism and access control policies.
[0085] In this embodiment, based on the complete operation flow of the nut sorting equipment, the operation process is strictly divided into five distinct stages: equipment startup, sorting execution, quality inspection, data transmission, and equipment shutdown. Each stage is assigned a unique stage identifier, represented by integers 1, 2, 3, 4, and 5 respectively. Simultaneously, process engineers and maintenance personnel define the start and end conditions for each stage based on the on-site operation flow. For example, the equipment startup stage starts at the time the equipment is powered on and the main control program begins running, and ends at the time the key sensors complete their self-checks and output stable data. The sorting execution stage starts at the time the first batch of nuts enters the sorting channel and ends at the time the last batch of nuts is sorted. The quality inspection stage starts at the time the first batch of sorted results are sent to the quality inspection logic and ends at the time the current... The batch sorting task's corresponding inspection completion timestamp serves as the endpoint; the data transmission phase starts from the timestamp when the quality inspection results are first submitted to the monitoring center and ends at the timestamp when all batch data is written to the storage node or reported to the upper-level system; the equipment shutdown phase starts from the timestamp when the control command to stop receiving new nuts is issued and ends at the timestamp when all actuators of the equipment stop, the power is turned off, and safety confirmation is completed; the system records the actual duration of each phase during multiple rounds of trial operation, calculates the maximum and average durations of each phase, and adds a certain safety margin to the average to obtain the recommended time window length for that phase. In this embodiment, the safety margin is fixed at 50% of the average. For example, the equipment startup phase takes an average of 4 minutes. After adding a 50% margin, the upper limit of the time window is set to 6 minutes and written into the lifecycle permission coverage table as the time window limit parameter for that phase.
[0086] For different stages, the system predefines three fixed access levels: administrator level, operator level, and guest level. During the deployment phase, a minimum permission level is determined for each stage. In this implementation, the integer 3 represents the administrator level, the integer 2 represents the operator level, and the integer 1 represents the guest level. For example, during the device startup phase, only administrator and operator levels are allowed to participate in configuration and startup operations; therefore, the minimum permission level for this phase is set to 2. During the sorting execution and quality inspection phase, administrator and operator levels are allowed access, while guest levels are restricted to viewing only partial statistical information. During the data transmission phase, to protect diagnostic results and historical data security, the minimum permission level is set to 2. During the device shutdown phase, only administrator level access is required; therefore, the minimum permission level is set to 3. In user management, the system assigns a unique user identifier to each person or process with operational permissions. The configuration file specifies the permission level for each user identifier, records the set of user identifiers allowed to operate in each stage, and the data categories and operation scope boundaries that these users are allowed to access within that stage. For example, in the sorting execution stage, an operator can read real-time sorting monitoring data but cannot delete historical diagnostic results, and an administrator can modify sorting parameters. All this information is written into the lifecycle permission overlay table in the form of stage identifier, stage time window, allowed permission level, allowed data type, and allowed operation type within the stage. During system initialization, the lifecycle permission overlay table is imported into memory, and a full-cycle permission allocation list is generated. Each line in the full-cycle permission allocation list records the mapping relationship between a stage identifier and its corresponding permission access level, along with the stage time window and allowed operation scope, for subsequent quick determination of the permission policy to be enabled at the current time and under the current device status.
[0087] The present invention also discloses a machine-executable program that can be automatically executed by a machine to realize the nut sorting status monitoring and diagnosis method based on edge IoT as described above.
[0088] The machine (electronic device) mentioned above is, for example, a microcontroller, a single-board computer, a desktop computer, a laptop computer, a server, a programmable controller, or a field-programmable gate array.
[0089] Figure 2 This is a structural block diagram of the local terminal of an exemplary electronic device (machine) of the present invention; as shown... Figure 2 As shown, the electronic device of the present invention includes a processor 31, a memory 32 and a storage space 33 for storing a machine-executable program 34, the machine-executable program 34 being used to execute the above-described control logic.
[0090] Figure 3 This is a structural block diagram of the network end of an exemplary electronic device of the present invention; as shown below.Figure 3 As shown, the present invention also provides an electronic device (machine), which may include at least one processor 410, at least one memory 430 communicatively connected to the processor, and a communication bus 440 connecting different system components (including memory 430 and processor 410); wherein, memory 430 stores a machine executable program that can be executed by the processor, and processor 410 can execute the above-mentioned control logic by calling the machine executable program.
[0091] Communication bus 440 represents one or more of several bus architectures, including a memory bus or memory controller, peripheral bus, graphics acceleration port, processor, or local bus using any of the various bus architectures. Examples of these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnection (PCI) bus.
[0092] Electronic devices typically include a variety of computer system readable media, which can be any available media that can be accessed by the electronic device, including volatile and non-volatile media, and removable and non-removable media.
[0093] Memory 430 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory. The electronic device may further include other removable / non-removable, volatile / non-volatile computer system storage media. Memory 430 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the control logic described above.
[0094] A program / utility having a set (at least one) of program modules can be stored in memory 430. Such program modules include, but are not limited to, an operating system, one or more applications, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.
[0095] Machine-executable programs for performing this invention can be written in one or more programming languages or a combination thereof. These programming languages include object-oriented programming languages such as Java, C++, and Python, and may also include specialized engineering languages such as R. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0096] The present invention also discloses a storage medium on which a machine-executable program as described above is stored.
[0097] The aforementioned storage medium may be any combination of one or more computer-readable media. Computer-readable media may be, for example, computer-readable signal media or computer-readable storage media. Computer-readable storage media include, but are not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or flash memory, optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this invention, a computer-readable storage medium may be, for example, any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0098] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.
[0099] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0100] During system operation, whenever a nut sorting device generates a new data transmission request, the system determines the corresponding stage identifier based on the current timestamp and device operating status. It then retrieves the corresponding permission level requirements and time window limits from the full-cycle permission allocation list. Next, it reads the permission level corresponding to the user identifier initiating the request and compares it with the minimum permission level required for that stage. If the user's permission level is less than or equal to the minimum permission level required for that stage, the data transmission request is rejected. If the user's permission level is greater than or equal to the minimum permission level required for that stage, the system proceeds to the path planning process. During path planning, the system first lists all pre-defined paths from the current edge node to the target storage node or monitoring center node based on network topology information. The configured feasible transmission paths and network topology information are entered by the network administrator during the deployment phase, including the identifiers of each network node, the physical connections between nodes, and the bandwidth limit of each physical link. The system confirms the real-time availability of these paths through periodic connectivity checks. The specific process of connectivity checks involves sending probe packets to the next-hop node on the path at fixed time intervals. If a response is received within a preset timeout period, the hop is considered available; otherwise, it is marked as unavailable. In this embodiment, the detection interval is set to 30 seconds, and the timeout period is set to 1 second. For data transmission requests with higher privilege levels, such as administrator-level data access, the system requires... The selected path must not only have normal connectivity throughout, but also sufficient real-time bandwidth availability. During deployment, the minimum acceptable bandwidth availability for different permission levels is determined as a percentage based on the business's real-time transmission requirements. In this implementation, the path bandwidth availability requirement is no less than 50% for administrator-level data transmission, no less than 30% for operator-level, and no less than 20% for visitor-level. Bandwidth availability is calculated by averaging the available bandwidth collected by the system every 10 seconds over the past 60 seconds and dividing the average by the maximum link bandwidth. During path planning, the system first filters out paths with failed connectivity checks or bandwidth availability lower than the current permission level requirement. For the remaining path, the node sequence and hop delay parameters are calculated. The node sequence is a list of network node identifiers that are passed sequentially from the source node to the target node on the path. The hop delay parameter is in milliseconds and is specifically the time difference between the source node sending a probe message and the next hop node returning a response message, as recorded by the system in the most recent connectivity test. For the entire path, the delay values of all hops are summed to obtain the estimated end-to-end delay. At the same time, the delay values of each hop can be recorded in the path description, and finally a transmission path candidate set is formed. Each record in the set includes the path number, node sequence, delay values of each hop, and estimated end-to-end delay of the path, which are used for subsequent security assessment.
[0101] After obtaining the candidate set of transmission paths, the system uses the node connection information recorded in the set to further obtain the security authentication status and historical access records of each network node. During the deployment phase, the security authentication status is assigned a specific level by the security administrator based on factors such as whether the node has passed security audit, whether hardware encryption is enabled, and whether the latest security patches have been deployed. In this embodiment, the security authentication status is divided into two types: authenticated and unauthenticated. At the same time, the historical access record is maintained for each node in the log system. The historical access record includes the total number of connections, the number of authentication failures, the number of abnormal connections, and data packet loss statistics within a preset time period. In this embodiment, the preset time period is 24 hours, that is, the system performs a statistical analysis on the data of the previous 24 hours every 24 hours. The abnormal connection count is defined as the sum of connection attempts from unauthorized addresses, incorrect passwords, and connection rejections due to invalid certificates. The packet loss rate is defined as the percentage of the difference between the number of incoming packets and the number of successfully forwarded packets during forwarding, relative to the total number of incoming packets. The system calculates this percentage by comparing the receive and send counts from the network interface and combining them with the send count records of the upstream nodes. During the deployment phase, a preset threshold for the abnormal connection count is set based on historical operational data. Specifically, records of manually confirmed secure nodes are selected from logs over the past few months, and the maximum abnormal connection count for these nodes within any 24-hour period is calculated. This maximum value is then incremented by 1 to serve as the preset threshold. The maximum value in the formula is 4 times, so the preset threshold is set to 5 times. During operation, if a node has more than 5 abnormal connections in the current 24-hour statistical period, the node is marked as untrusted. Otherwise, it is determined as trusted or untrusted based on its security authentication status and data packet loss rate. In this implementation, for the sake of simplicity, nodes that have passed security authentication, have no more than 5 abnormal connections, and have a data packet loss rate of less than 5% are marked as trusted nodes, while nodes that have not passed security authentication, have more than 5 abnormal connections, or have a data packet loss rate of 5% or higher are marked as untrusted nodes. Then, the system uses a weighted summation method to calculate the security weight value of each candidate path. The specific value of the node weight is determined by the security policy makers during the deployment phase. Based on the assessment of node reliability, this implementation assigns a weight of +1 to each trusted node and a weight of -1 to each untrusted node. If a node has been recorded as a security incident point in the past week and the incident has not yet been rectified, the weight of that node is reduced by 1, making its weight -2 to reflect a higher risk. When calculating the security weight for a path, the system takes the weight of each node in the path's node sequence in order and adds them up. The sum of all node weights gives the security weight value of the path, which may range from a number of negative integers to a number of positive integers. For example, the security weight of a path consisting of 5 trusted nodes is 5, and the security weight of a path consisting of 3 trusted nodes and 2 untrusted nodes is 1.The system combines the path number, node sequence, and corresponding security weight value into a single link security verification record, and merges the records of all candidate paths to form a set of link security verification results.
[0102] To associate path security weights with permission levels, the system establishes a mapping table corresponding to the numerical ranges of permission levels and security weights based on the security weight distribution in the link security verification results. During the deployment phase, the system statistically analyzes the set of security weight values calculated for all paths over a relatively long period, observing the maximum, minimum, and concentrated ranges. In this implementation, after multiple simulations and field tests, it was found that the security weights of most normal paths are concentrated in the range of -5 to 5. Based on the enterprise's security requirements for different permission levels, the security team selected -2 and 2 as the segment boundaries for security weights. Paths with security weights greater than 2 are considered high-security paths, paths with security weights between -2 and 2 are considered medium-security paths, and paths with security weights less than -2 are considered low-security paths. The mapping table specifies that administrator-level permissions only use paths with security weights greater than 2, operator-level permissions use paths with security weights between -2 and 2, and visitor-level permissions only use paths with security weights less than or equal to 2 but greater than a preset lower limit. This implementation prevents the use of excessively low-security paths. The system sets the lower limit of the security weight for visitor-level available paths to -5, meaning paths with a security weight less than -5 are not used. All path weight ranges and their corresponding permission levels are written into the configuration in a table and loaded into memory. When the link security verification result is updated, the system iterates through each candidate path, looks up the corresponding permission level in the mapping table based on its security weight value, and marks the path as available only to administrators, operators, or visitors. It also records the timestamp and triggering conditions for each change in the permission level of a path. These triggering conditions include specific events such as security weight crossing a boundary value, a node status changing from trusted to untrusted or vice versa, and the number of abnormal connections exceeding a threshold. The system associates the user identifier, the current path set, and the current permission level to generate a dynamic permission allocation record. This record contains the user identifier, a list of path numbers currently allowed for the user, the current permission level, and the timestamp and triggering reason for the most recent permission level change. All records form a dynamic permission allocation record set, which serves as the basis for subsequent access control based on diagnostic results.
[0103] When the nut sorting status monitoring center performs access control on diagnostic results, the system uses the user identifier and current permission level information in the dynamic permission allocation record to authenticate and match permissions for each diagnostic result access request. Specifically, when the monitoring center receives a user's access request for a diagnostic result, the request message contains the user identifier, the user's digital certificate, the data type of the request, and the target diagnostic result identifier. The system first searches for the corresponding record in the dynamic permission allocation record based on the user identifier to obtain the user's current permission level, the set of allowed access paths, and the permission validity period parameter. In this implementation, the system... The validity period parameter has been set to a specific number of hours based on the risk assessment results in the preceding steps. For example, it is 8 hours under normal circumstances and shortened to 2 hours under high-risk conditions. The system reads the timestamp of the user's most recent authentication and subtracts the timestamp from the current time to obtain the duration of the current session. If the duration is longer than the recorded permission validity period, the user is required to re-authenticate. During the authentication process, the system first reads the pre-stored digital certificate information corresponding to the user identifier from the local certificate storage, including the certificate issuer, certificate serial number, public key digest, and certificate validity period. The system then verifies the digital certificate field by field in the request. The system compares the digital certificate with a pre-stored certificate. If the issuer, serial number, or public key digest does not match, or if the certificate's current time is outside its validity period, the digital certificate is deemed invalid, the access request is rejected, and the reason for rejection is recorded in the access log. If the digital certificate matches and is within its validity period, the system continues to determine whether the user has the right to access the requested data type based on their current permission level registered in the dynamic permission allocation record. For example, administrators can access all diagnostic results, including raw monitoring data, intermediate analysis results, and final diagnostic reports; operators can only access diagnostic reports related to the current production task and some real-time monitoring data; and visitors... Access is only permitted to anonymized statistical diagnostic information. The system matches the data type in the request with the allowed range of the user's permission level. If the data type is outside the allowed range, access is denied. If the data type is matched, the system selects a path with the required security weight from the set of paths that match the user's permission level. The system also confirms whether the current device operation phase allows such access and whether it is within the time window of the current phase based on the aforementioned full-cycle permission allocation list. Only when the device phase, permission level, path security weight, and digital certificate all meet the requirements will the system generate a decision to allow access.During the actual execution of data access, the system encrypts the diagnostic result data to be sent according to the encryption transmission parameters set in steps S3 and S4, and transmits it through a path that meets the security requirements of the permission level. Simultaneously, following the current log recording frequency set to minute-by-minute recording, a complete access log entry is generated for each access operation. The log entry records the access timestamp, user identifier, transmission path number used, data type accessed, access result, and, if access fails, the reason for failure and the triggered security policy entry number. Furthermore, to meet the needs of data flow tracking, the system records data flow trajectory information separately from the access log. The data flow trajectory marks the path sequence of the diagnostic results from the monitoring center to each requester, the node identifiers where data is cached or copied, and the timestamp of each transmission, for post-event auditing and anomaly tracing. Finally, the system integrates the above-mentioned identity authentication mechanism, access control policies based on security weights and permission levels, time window restrictions divided by stage, and detailed access logs and data flow records, outputting a dynamic permission management system in the form of configuration files and real-time control rules. This system serves as the basis for permission decisions in the nut sorting status monitoring center.
[0104] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for monitoring and diagnosing the nut sorting status based on edge IoT, characterized in that, Includes the following steps: S1. Collect raw data streams of temperature, humidity and vibration in the nut sorting environment through edge devices. During the collection phase, generate device identifiers with MAC and serial numbers and match them with permission level parameter tables to obtain initial read, write and transmission permissions. Then, according to the transmission permission threshold, segment and normalize the data packets that exceed the limit according to the rules, and mark the data packets as allowed or delayed according to the transmission time window. Combine the device type and data importance to set the upper limit of the number of reads, storage retention time and processing priority access control tags to form a labeled collection data sequence with access constraints. S2. Based on the collected data sequence, the data is processed in layers according to the transmission protocol type and data priority. If the data priority is detected to be lower than the preset threshold in the interactive scenario, the permission level is reduced to obtain permission adjustment data. S3. Extract bandwidth utilization and data fragmentation strategy information from the permission adjustment data. During the transmission phase, obtain network latency and packet loss rate parameters through the network protocol. If the network latency is higher than the preset standard, adjust the data fragmentation strategy and determine the encryption strength of the transmitted data. S4. Dynamically evaluate the encryption strength of the transmitted data by combining link congestion and signal strength. If the link congestion exceeds the safe range, optimize the transmission path selection through the error control mechanism to obtain the adjusted encrypted transmission data stream. S5. Based on the adjusted encrypted transmission data stream, obtain historical access logs during the storage phase, analyze the stability of storage nodes by combining link interruption frequency and bandwidth availability, determine the permission policy rules for the storage location, and obtain the optimized storage data entity.
2. The method for monitoring and diagnosing nut sorting status based on edge IoT according to claim 1, characterized in that: S1 includes: The edge device acquires raw sensor data streams containing temperature, humidity, and vibration frequency from the nut sorting production line. Based on the device identifier composed of the preset device MAC address and serial number, the device records are searched in the permission level parameter table to extract the corresponding read permission, write permission, and transmission permission values, thereby obtaining permission configuration information. Based on the transmission permission threshold in the permission configuration information, the size of each data packet in the original sensor data stream is detected. If the number of bytes in the data packet exceeds the upper limit of the data packet size specified in the transmission permission threshold, the large data packet is divided into multiple sub-data packets that meet the size requirements according to the preset segmentation rules to obtain a standardized data transmission unit. Obtain the generation timestamp of each data packet in the standardized data transmission unit, calculate the difference between the timestamp and the current processing time, and add an allowed transmission flag to the data packet if the time difference is within the preset transmission time window; otherwise, add a delayed transmission flag to the data packet to determine the sequence of data packets with time constraint flags. For each data packet in the data packet sequence with time constraint identifiers, three types of constraint parameters are set according to the source device type and data content importance of each data packet in the data packet sequence with time constraint identifiers: upper limit of data reading times, data storage retention time, and processing priority level. The constraint parameters are attached to the corresponding data packets as access control tags to generate a complete labeled data collection sequence for monitoring the operating status of nut sorting equipment.
3. The method for monitoring and diagnosing nut sorting status based on edge IoT according to claim 1, characterized in that: S2 includes: Based on the transmission protocol type identifier in the collected data sequence, a protocol layer mapping table is established according to the three types of TCP, UDP and HTTP protocols. The transmission priority baseline value corresponding to each protocol is obtained. If the priority value of the data packet is lower than the preset priority threshold, the original permission level value is reduced by a preset amount to obtain the permission adjustment result after protocol layering. The nut appearance feature data is reclassified using the permission adjustment results. The red, green and blue channel values of the nut surface are obtained. The mean and variance of each color channel are calculated to obtain the color distribution parameters. The coordinates of the nut outline boundary points are extracted by the edge detection operator. The ratio of the outline perimeter to the area is calculated to obtain the shape outline parameters. An appearance feature database containing color distribution parameters and shape outline parameters is established. The system acquires three types of status parameters in the sorting channel: conveyor belt speed, air pressure, and light intensity. Combined with the nut length and width dimensions recorded in the appearance feature database, it calculates the ratio of the number of nuts passing through each channel per unit time to the channel capacity, determines whether the ratio exceeds the channel congestion threshold, and obtains the operating status evaluation data of each channel. Based on the operational status assessment data, a processing queue is established in the edge nodes according to the data priority order. The conveyor belt speed control value and airflow pressure control value are dynamically adjusted according to the change in the frequency of nut passage, and a key parameter configuration file for the operation control of the nut sorting equipment is generated.
4. The method for monitoring and diagnosing nut sorting status based on edge IoT according to claim 1, characterized in that: S3 includes: Based on the permission adjustment data, the bandwidth utilization rate and data fragmentation strategy configuration information are parsed, and the network latency value and packet loss rate parameters of the current transmission link are obtained through the network protocol stack to obtain a network performance evaluation report. If the network latency value in the network performance evaluation report exceeds the preset latency threshold, the data fragment size is reset according to the inverse relationship between the latency value and the fragment size. At the same time, the number of fragments is adjusted according to the bandwidth utilization rate, the queue priority sorting of data packets in the transmission buffer is modified, and the optimized transmission parameter configuration is determined. The system uses optimized transmission parameter configuration and selects either AES or DES encryption algorithm based on the packet loss rate parameter range. When the packet loss rate is lower than the preset packet loss threshold, the AES encryption algorithm is selected, and when the packet loss rate is higher than the preset packet loss threshold, the DES encryption algorithm is selected to generate a secure verification code sequence containing the data packet sequence number and the checksum. By performing an XOR operation on the sorting status code and the verification code using a security verification code sequence, encryption and encapsulation are completed. The monitoring frequency value is set to control the time interval between the transmission of adjacent data packets, and a group of data packets containing encrypted status information is obtained. From the data packet group, the checksum of each data packet is extracted for integrity verification. The consistency between the checksum and the original data is determined to obtain the monitoring data stream used for edge node security processing.
5. The method for monitoring and diagnosing nut sorting status based on edge IoT according to claim 1, characterized in that: S4 includes: The system obtains real-time congestion parameters and signal strength measurements of the current network link. It collects link bandwidth utilization, buffer occupancy, and signal attenuation coefficient through network probe packets. The system divides the congestion into three levels: mild, moderate, and severe, based on the range of congestion values. A three-dimensional evaluation parameter table is established for the corresponding signal strength range. The evaluation parameter table records the RSA key bit configuration under different congestion levels and signal strength combinations. Using the key bit length configuration in the evaluation parameter table, if the link congestion exceeds the preset security range, a path probe data packet containing the source address and destination address is generated. By sending the probe data packet, the round-trip delay and available bandwidth of the alternative transmission path are measured. The delay value and bandwidth value are added according to the weight ratio to calculate the comprehensive path score. Based on the path comprehensive score, Hamming code error correction processing is initiated to generate a check bit sequence. The original data packet is divided into data bit groups of fixed length. Parity check bits are calculated for each data bit group and appended to the end of the data bit group to form an encoded data block. Error detection flag bits are obtained by performing an XOR operation between the check bits and data bits in the encoded data block. By using the error detection flag, the transmission path with the highest score is selected as the primary transmission path from the comprehensive path score values, and the path with the second highest score is selected as the backup transmission path. A path control instruction set containing primary and backup path address information and switching trigger conditions is generated. Using a path control instruction set, the RSA-encrypted encoded data blocks are forwarded along the main transmission path. A sorting code to identify the data packet type and a status flag to detect transmission anomalies are added to the header of the data block, resulting in an encrypted data stream with path switching capability for sorting anomaly diagnosis and processing.
6. The method for monitoring and diagnosing nut sorting status based on edge IoT according to claim 1, characterized in that: S5 includes: Obtain historical access logs of storage nodes, extract access timestamps, data read / write frequency, node response latency and access failure count, and calculate the access success rate and average response time of each storage node in different time periods. Combine node identifiers with corresponding access performance metrics to form an access pattern dataset. Using access success rate and response time data from the access pattern dataset, combined with link outage frequency and real-time bandwidth availability values obtained from network monitoring, a Bayesian classifier is used to classify the stability of each storage node. The access success rate is used as the prior probability and the link outage frequency is used as the conditional probability for calculation. If the node outage frequency exceeds a preset threshold, the node is classified as low stability level, resulting in a node evaluation matrix containing stability level identifier and reliability score. Based on the stability level identifier in the node evaluation matrix, storage access policy rules corresponding to different permission levels are formulated. The first stability node is assigned read and write permissions, the second stability node is assigned read-only permissions, and the third stability node is set as a backup node. A mapping relationship is established between permission levels and node identifiers to form a permission allocation table. By using the permission level mapping relationship in the permission allocation table, the storage location is selected from the first stability node. The encrypted transmission data stream is classified and stored according to data type and importance. The key diagnostic data adopts a primary and backup dual-node storage mode. An integrity verification code based on cyclic redundancy check is added to the end of the data block to generate an optimized storage data entity containing storage address mapping and data integrity verification code. By optimizing the storage address mapping information in the stored data entity, the changing trend of the sorting equipment operating parameters and the nut appearance quality detection results are extracted. By comparing the historical normal operation data, the abnormal equipment status threshold range is established. The appearance defect image features of different types of nuts are collected to establish a quality defect feature library, forming a sorting anomaly diagnosis basis based on storage data correlation analysis.
7. The method for monitoring and diagnosing nut sorting status based on edge IoT according to claim 1, characterized in that, This also includes S6, which extracts potential link indicators from optimized stored data entities, combines path hop statistics and link security scores for risk assessment, and triggers a dynamic permission adjustment mechanism if the overall status exceeds the warning threshold in interactive scenarios, resulting in enhanced permission control data, specifically including: The network connection records and data packet transmission trajectories are parsed from the optimized storage data entities. Link performance indicators, including transmission delay, packet loss rate, bandwidth utilization, and connection stability, are extracted. The number of network node hops and path switching frequency on each data transmission path are counted. The path change timestamp and change reason identifier are recorded. A path hop statistics table containing path identifiers and hop frequency is generated. Based on the hop frequency data in the path hop statistics table, combined with the security authentication level and historical attack records of each node in the network topology, each transmission link is assigned a different weight value according to the node's security level. Nodes with a security level higher than a preset threshold are assigned a positive weight, while nodes with security vulnerabilities or abnormal access behavior are assigned a negative weight. The security trustworthiness value of each transmission link is calculated by accumulating the weight values of each node, forming a link security assessment matrix that includes link identifiers and security scores.
8. The method for monitoring and diagnosing nut sorting status based on edge IoT according to claim 7, characterized in that: S6 further includes: Based on the security score values in the link security assessment matrix, links with security scores below the negative range are classified as high-risk, links with security scores near zero are classified as medium-risk, and links with security scores above the positive range are classified as low-risk. The proportion of links in the high-risk state to the total number of links is counted. If this proportion exceeds the preset warning threshold, an access control level upgrade instruction is triggered, and a risk assessment report containing risk level identification and adjustment instructions is generated. Using the adjustment instructions in the risk assessment report, the authentication requirements in the current permission allocation strategy are upgraded from single-factor authentication to multi-factor authentication, the validity period of permissions is shortened from the original time to the preset time, the access log recording frequency is adjusted from hourly recording to minutely recording, and a new mapping relationship is established between the adjusted verification method, validity period parameters and recording frequency and user identifiers to obtain permission control data containing enhanced verification rules and access restrictions. By strengthening the verification rules in the access control data, strict access control and transmission encryption are implemented for the operation monitoring data and quality inspection and diagnostic data generated by the nut sorting equipment. The identity credentials and access permission level of the data requester are verified, and detailed log information of all data access operations is recorded to ensure the security and reliability of the monitoring data and diagnostic data in the sorting process during transmission and storage.
9. The method for monitoring and diagnosing nut sorting status based on edge IoT according to claim 7, characterized in that, It also includes S7, which, through enhanced access control data coverage of the entire lifecycle of the nut sorting environment, performs final verification on transmission path selection and link security assessment, resulting in a dynamic access management system output that ensures the diagnostic results output by the nut sorting status monitoring center. Specifically, this includes: Based on the operational phases of the nut sorting equipment, a lifecycle permission coverage table is established, which includes five phases: equipment startup, sorting execution, quality inspection, data transmission, and equipment shutdown. Different permission access levels and time window limits are set for each phase. The identity of the permission holder and the boundaries of the operation scope are recorded for each phase. The phase identifier is associated with the corresponding permission access level, and a full-cycle permission allocation list containing the correspondence between phase identifiers and permission levels is generated. By adopting the permission level correspondence in the full-cycle permission allocation list, and based on the different requirements of data transmission security for different permission levels, path planning is performed for the data transmission needs generated during the nut sorting process. By detecting the connectivity status and bandwidth availability between network nodes, candidate transmission paths that meet the security requirements of the current permission level are selected. The node sequence and jump delay parameters of each candidate path are recorded to form a candidate set of transmission paths containing path numbers and node connection information.
10. The method for monitoring and diagnosing nut sorting status based on edge IoT according to claim 9, characterized in that: The S7 also includes: By using the node connection information in the candidate set of transmission paths, the security authentication status and historical access records of each network node are obtained. The number of abnormal connections and data packet loss rate of each node within a preset time period are counted. If the number of abnormal connections of a node exceeds a preset threshold, the node is marked as untrusted. The path security weight value containing trusted nodes is calculated by weighted summation, where the weight of trusted nodes is positive and the weight of untrusted nodes is negative. The link security verification result containing path identifier and security weight value is obtained. Based on the security weight values in the link security verification results, establish a mapping table that corresponds the value range of the permission level and the security weight. Assign the path with the security weight higher than the preset upper limit to the administrator level permission, assign the path with the security weight in the preset middle range to the operator level permission, and assign the path with the security weight lower than the preset lower limit to the visitor level permission. Record the timestamp and triggering conditions of the permission level change, and generate a dynamic permission allocation record containing the user identifier and the current permission level. By using the user identifier and current permission level information in the dynamic permission allocation record, the system authenticates and matches the access requests for diagnostic results from the nut sorting status monitoring center. It verifies the consistency between the digital certificate provided by the requester and the pre-stored certificate information, checks whether the access time is within the validity period of the permission, records the access operation logs and data flow trajectory of all diagnostic results, integrates the verified permission verification rules and access control conditions, and constructs a dynamic permission management system that includes identity authentication mechanisms and access control policies.
Citation Information
Patent Citations
Intelligent ERP financial system data security management and authentication method
CN121167793A
Network mapping behavior anomaly detection method and system based on machine learning
US20250358316A1