Iot device operation management system based on dynamic topology perception

The IoT device operation management system with dynamic topology awareness uses heartbeat packets and time-domain and spatial-domain analysis modules to identify abnormal distribution characteristics of network nodes, solving the problem that existing technologies cannot effectively analyze device operation risks, and achieving efficient risk warning and operation and maintenance optimization.

CN121619213BActive Publication Date: 2026-05-19GUANGZHOU SIYUN DATA TECH CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGZHOU SIYUN DATA TECH CO LTD
Filing Date
2026-02-03
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing technologies cannot capture the distribution of network node status results in the time and spatial domains for risk analysis, resulting in the inability to effectively manage equipment operation risks.

Method used

The IoT device operation and management system based on dynamic topology perception includes an operation management platform, a device management module, a health monitoring module, a time domain analysis module, and a spatial domain analysis module. It detects the status of network nodes through heartbeat packets, generates monitoring periods and monitors health status, performs time domain and spatial domain anomaly analysis, quantifies anomaly distribution characteristics, and generates early warning signals.

Benefits of technology

It enables automatic identification and early warning of temporal anomaly risks in the topology network, optimizes system resource allocation, improves the proactive early warning capability and overall operation and maintenance efficiency of IoT device operation and management, and significantly improves the accuracy of airspace anomaly early warning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121619213B_ABST
    Figure CN121619213B_ABST
Patent Text Reader

Abstract

The application belongs to the field of Internet of Things equipment management, and relates to data analysis technology, and is used for solving the problem that the prior art cannot perform risk analysis on the distribution of state capture results of network nodes in the time domain and the space domain, and specifically relates to an Internet of Things equipment operation management system based on dynamic topology perception, which comprises an operation management platform, and the operation management platform is in communication connection with an equipment management module, a health supervision module, a time domain analysis module, a space domain analysis module and a database; the application can automatically identify the time domain abnormal risk state of the topology network, timely send early warning information to the management personnel, and avoid the spread of equipment operation risks; meanwhile, the space domain analysis is intelligently triggered when there is no time domain risk, the system resource allocation is optimized, and the active early warning capability and the overall operation and maintenance efficiency of the Internet of Things equipment operation management are improved; the application provides a structured basis for risk analysis by decomposing the topology network into independent network branches according to the data transmission path.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of Internet of Things (IoT) device management and involves data analysis technology, specifically an IoT device operation and management system based on dynamic topology sensing. Background Technology

[0002] The Internet of Things (IoT) device operation and management system is a platform that integrates sensors, communication modules, and cloud computing technologies to achieve unified access, centralized monitoring, and intelligent management of industrial equipment. Its core lies in its ability to perceive the constantly changing network connection relationships of devices in real time and make autonomous decisions and automated operation and maintenance based on this, thereby achieving a leap from "passive response" to "proactive early warning and intelligent control".

[0003] The invention patent with publication number CN113381880B discloses an IoT device management method, device, and system. This management method, through message queue telemetry transmission, can effectively adapt to the cluster requirements of IoT devices of different types and protocols. By updating the topology nodes in the configuration interface with status data, it can intuitively and efficiently display the status information of IoT devices, facilitating efficient decision-making by managers. However, this management method cannot perform risk analysis based on the distribution of network node status capture results in the time and spatial domains, resulting in the inability to effectively control the operational risks of the devices.

[0004] To address the aforementioned technical problems, this application proposes a solution. Summary of the Invention

[0005] The purpose of this invention is to provide an IoT device operation and management system based on dynamic topology awareness, which solves the problem that existing technologies cannot perform risk analysis by capturing the distribution of network node status results in the time and spatial domains.

[0006] The technical problem that this invention aims to solve is: how to provide an IoT device operation and management system based on dynamic topology awareness that can perform risk analysis based on the distribution of network node status capture results in the time and spatial domains.

[0007] The objective of this invention can be achieved through the following technical solutions:

[0008] The IoT device operation management system based on dynamic topology sensing includes an operation management platform, which is communicatively connected to a device management module, a health monitoring module, a time domain analysis module, a spatial domain analysis module, and a database.

[0009] The device management module is used to perform network management and analysis of IoT devices: the IoT devices and gateways form a topology network as network nodes, the status of network nodes in the topology network is detected by heartbeat packets, and the topology network is dynamically updated according to the status detection results;

[0010] The health monitoring module is used to perform health status monitoring and analysis on network nodes in the topology network: generating a monitoring period and dividing the monitoring period into several monitoring time periods, and marking the network nodes as healthy objects or abnormal objects at the end of the monitoring time period;

[0011] The time-domain analysis module is used to perform time-domain anomaly analysis on network nodes in the topology network: marking the monitoring period as a normal period or an abnormal period; if there are L1 consecutive monitoring periods that are all marked as abnormal periods, then time-domain risk analysis is performed.

[0012] The spatial analysis module is used to perform spatial anomaly analysis on network nodes in the topology network.

[0013] Furthermore, the specific process of marking network nodes as healthy or abnormal includes: at the end of the monitoring period, obtaining the remaining power, communication signal strength, and CPU load of the network node; obtaining the power threshold, signal strength threshold, and load threshold for the corresponding device type of the network node from the database; comparing the remaining power, communication signal strength, and CPU load of the network node with the power threshold, signal strength threshold, and load threshold respectively; if the remaining power is greater than or equal to the power threshold, the communication signal strength is greater than or equal to the signal strength threshold, and the CPU load is less than the load threshold, then the health status of the network node is determined to meet the requirements, and the corresponding network node is marked as a healthy object; otherwise, the health status of the network node is determined to not meet the requirements, and the corresponding network node is marked as an abnormal object.

[0014] Furthermore, the specific process of marking a regulatory period as a normal or abnormal period includes: marking the ratio of the number of abnormal objects marked to the total number of network nodes within the regulatory period as the abnormal coefficient of the regulatory period; obtaining the abnormal threshold through the database; and comparing the abnormal coefficient of the regulatory period with the abnormal threshold: if the abnormal coefficient is less than the abnormal threshold, the regulatory period is marked as a normal period; if the abnormal coefficient is greater than or equal to the abnormal threshold, the regulatory period is marked as an abnormal period.

[0015] Furthermore, the specific process of time-domain risk analysis includes: forming a risk set from all network nodes marked as abnormal objects within the most recent L1 regulatory period; marking network nodes in the risk set whose number of markings of abnormal objects is not less than L2 as high-frequency objects; marking the ratio of the number of high-frequency objects to the number of elements in the risk set as the time-domain distribution coefficient; and determining whether there is a time-domain abnormal risk in the topology network through the time-domain distribution coefficient.

[0016] Furthermore, the specific process for determining whether there is a temporal anomaly risk in the topology network includes: obtaining the temporal distribution threshold through the database, comparing the temporal distribution coefficient with the temporal distribution threshold; if the temporal distribution coefficient is less than the temporal distribution threshold, it is determined that there is a temporal anomaly risk in the topology network, generating a temporal warning signal and sending the temporal warning signal to the mobile terminal of the management personnel; if the temporal distribution coefficient is greater than or equal to the temporal distribution threshold, it is determined that there is no temporal anomaly risk in the topology network, generating a spatial analysis signal and sending the spatial analysis signal to the spatial analysis module.

[0017] Furthermore, the specific process of the spatial domain analysis module to perform spatial domain anomaly analysis on network nodes in the topology network includes: decomposing the topology network into several network branches according to the data transmission path; marking the ratio of the number of marked anomaly objects to the number of network nodes in the network branch as the spatial domain risk coefficient; marking the risk branches using the spatial domain risk coefficient; numbering the network nodes in the risk branches according to the unidirectional transmission direction; then calculating the variance of the serial numbers of all network nodes marked as anomaly objects in the risk branches to obtain the spatial domain distribution coefficient of the risk branches; and determining whether there are spatial domain anomalies in the risk branches using the spatial domain distribution coefficient.

[0018] Furthermore, the specific process of marking risk branches includes obtaining the airspace risk threshold from the database and comparing the airspace risk coefficient with the airspace risk threshold: if the airspace risk coefficient is less than the airspace risk threshold, the network branch is determined to have no airspace risk characteristics; if the airspace risk coefficient is less than the airspace risk threshold, the network branch is determined to have airspace risk characteristics, and the corresponding network branch is marked as a risk branch.

[0019] Furthermore, the specific process for determining whether there is an airspace anomaly in the risk branch includes: obtaining the airspace distribution threshold through the database, and comparing the airspace distribution coefficient with the airspace distribution threshold; if the airspace distribution coefficient is less than the airspace distribution threshold, it is determined that there is an airspace anomaly in the risk branch, an airspace warning signal is generated, and the airspace warning signal is sent to the mobile terminal of the management personnel; if the airspace distribution coefficient is greater than or equal to the airspace distribution threshold, it is determined that there is no airspace anomaly in the risk branch.

[0020] The present invention has the following beneficial effects:

[0021] 1. This application can automatically identify the time-domain abnormal risk status of the topology network and send early warning information to the management personnel in a timely manner to avoid the spread of equipment operation risks; at the same time, it can intelligently trigger spatial domain analysis when there is no time-domain risk, optimize system resource allocation, and improve the proactive early warning capability and overall operation and maintenance efficiency of IoT device operation management.

[0022] 2. The proposed solution decomposes the topology network into independent network branches based on data transmission paths, providing a structured foundation for risk analysis. Subsequently, a spatial risk coefficient is calculated to quantify the branch anomaly density, and risky branches are selected accordingly. Based on this, location coordinates are established for risky branch nodes numbered according to transmission direction. Then, the spatial distribution coefficient is obtained by calculating the variance of the anomaly node sequence number; this coefficient reflects the spatial clustering characteristics of anomalies. Finally, spatial anomalies are determined based on the spatial distribution coefficient, thus organically combining the network topology structure with anomaly distribution characteristics. This achieves a progressive analysis from anomaly density to spatial patterns, effectively solving the problem of accurately identifying spatially related risks in dynamic topology networks.

[0023] 3. The solution in this application decomposes the topology network into several network branches according to the data transmission path through the airspace analysis module, and calculates the airspace risk coefficient of each branch. Then, it obtains the airspace risk threshold from the database and compares the airspace risk coefficient with the threshold. When the airspace risk coefficient is greater than or equal to the airspace risk threshold, the network branch is determined to have airspace risk characteristics and is marked as a risk branch, thus providing reliable input for subsequent airspace anomaly determination. This process works in conjunction with the device management module, health monitoring module and database to ensure that the airspace risk analysis is based on the real-time status data of the dynamic topology network, avoiding the bias caused by subjective experience judgment.

[0024] 4. This application can make refined judgments based on the spatial distribution characteristics of abnormal nodes in risk branches, effectively distinguishing between high-risk scenarios with concentrated abnormalities and low-risk scenarios with dispersed abnormalities. This significantly improves the accuracy of airspace anomaly early warning and avoids the technical problems of misjudging low-risk branches with dispersed abnormalities as high-risk or missing high-risk branches with concentrated abnormalities. This ensures accurate allocation of operation and maintenance resources and reduces unnecessary system interference. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0026] Figure 1 This is a system block diagram of Embodiment 1 of the present invention;

[0027] Figure 2 This is a flowchart of the method in Embodiment 2 of the present invention. Detailed Implementation

[0028] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0029] In IoT device operation and management systems, existing technologies cannot perform risk analysis on the distribution characteristics of network node states in the time and spatial domains, making it difficult to effectively manage device operation risks. Specifically, the system can only display device status information through status data updates in the configuration interface, but lacks a mechanism for in-depth analysis of the continuous change patterns of status data in the time dimension and the node distribution characteristics in the spatial dimension. This makes it impossible for the system to identify potential risks caused by continuous time-related abnormal events or spatial clustering anomalies, thus affecting the accuracy of risk warnings and the timeliness of operation and maintenance decisions.

[0030] For example, in industrial equipment monitoring scenarios in large manufacturing plants, multiple IoT devices connect to the operation and management system via gateways, forming a topology network. When equipment within a production area experiences status fluctuations due to environmental interference across multiple monitoring periods, the system can only dynamically update the topology node status based on heartbeat packet detection results. However, it cannot mark the monitored periods as abnormal periods and analyze the temporal distribution characteristics of consecutive L1 abnormal periods, nor can it perform correlation analysis on the abnormal states of spatially adjacent nodes. Consequently, maintenance personnel struggle to distinguish between occasional interference and systemic risks, resulting in risk identification being limited to single-point states and failing to capture the spread of regional risks, thus affecting the effective formulation of overall operation and maintenance strategies.

[0031] If the above problems are not addressed, the risks to equipment operation cannot be managed in a timely and effective manner, and the system may remain in a high-risk state without being detected. Specifically, the cumulative effect of continuous abnormal events in the time domain and the spatial clustering of abnormal nodes in the spatial domain cannot be quantitatively assessed. This leads to the failure of risk warning mechanisms, a lack of data support for operational decisions, and ultimately an increased probability of equipment failure and a decline in system operational stability.

[0032] Example 1: As Figure 1 As shown, the IoT device operation management system based on dynamic topology sensing includes an operation management platform, which is communicatively connected to a device management module, a health monitoring module, a time domain analysis module, a spatial domain analysis module, and a database.

[0033] The device management module is used for network management and analysis of IoT devices: the topology network is composed of IoT devices and gateways as network nodes. The topology network is dynamically updated based on the status detection results by using heartbeat packets to detect the status of network nodes in the topology network.

[0034] Specifically, the device management module is used to perform network management and analysis of IoT devices. The status detection of network nodes in the topology network through heartbeat packets refers to the process of periodically sending probe signals to confirm the online status of nodes. This can be achieved by periodically broadcasting heartbeat request packets or by using a TCP connection keep-alive mechanism. For example, the heartbeat packet sending interval can be set to a fixed time period. If no response is received from a node within a preset timeout window, the node is determined to be offline, thereby ensuring the real-time acquisition of the topology network status.

[0035] The operation management platform can be deployed on a cloud server cluster. The device management module uses the lightweight MQTT protocol to transmit heartbeat packets, with a heartbeat packet sending interval set to 10 seconds to balance network load and status perception accuracy. The health monitoring module configures the monitoring cycle to 1 hour, divided into 6 monitoring periods of 10 minutes each, to ensure the timeliness and computational efficiency of status assessment. In the time domain analysis module, the L1 parameter is set to 5, meaning that risk analysis is initiated when 5 consecutive 10-minute monitoring periods are determined to be abnormal. This threshold setting balances the timeliness of risk response with false alarm rate control. The spatial domain analysis module performs spatial correlation analysis based on the tree structure of the network topology, identifying risk propagation paths by calculating the path dependencies between nodes.

[0036] The health monitoring module is used to monitor and analyze the health status of network nodes in the topology network. It generates a monitoring period and divides the monitoring period into several monitoring time periods. At the end of each monitoring time period, it obtains the remaining power, communication signal strength, and CPU load of the network nodes. It retrieves the power threshold, signal strength threshold, and load threshold for the corresponding device type of the network node from the database. It compares the remaining power, communication signal strength, and CPU load of the network node with the power threshold, signal strength threshold, and load threshold, respectively. If the remaining power is greater than or equal to the power threshold, the communication signal strength is greater than or equal to the signal strength threshold, and the CPU load is less than the load threshold, then the health status of the network node is determined to meet the requirements, and the corresponding network node is marked as a healthy object; otherwise, the health status of the network node is determined to not meet the requirements, and the corresponding network node is marked as an abnormal object.

[0037] Among them, remaining power refers to the battery energy reserve status of network nodes, which can be realized using a fuel gauge chip or a voltage-to-power conversion circuit, with the aim of quantitatively assessing the energy sustainability of the equipment; communication signal strength refers to the received signal quality of the wireless communication link, which can be realized using an RSSI measurement module or a signal-to-noise ratio analysis unit, with the aim of objectively reflecting the stability of the communication link; CPU load refers to the resource utilization of the central processing unit, which can be realized through the operating system performance monitoring interface or the task scheduler statistics module, with the aim of dynamically monitoring the pressure on computing resources; power threshold, signal strength threshold, and load threshold are preset health judgment benchmarks for different device types, which can be stored and retrieved through the device type configuration table in the database, with the aim of adapting to the performance characteristics differences of various IoT devices and avoiding misjudgments caused by uniform standards.

[0038] Specifically, the solution in this application ensures the temporal consistency and objectivity of health status assessment by synchronously collecting multi-dimensional status parameters at the end of a fixed time benchmark, i.e., the end of the monitoring period, and performing parallel logical judgments in combination with thresholds dynamically matched to the device type. The system first triggers a status collection operation at the end of the monitoring period to obtain the remaining battery power, communication signal strength, and CPU load of network nodes. Then, it retrieves the corresponding threshold set from the database based on the device type of the network node. Next, it performs a synchronous comparison of multiple indicators. Only when the remaining battery power is not lower than the battery power threshold, the communication signal strength is not lower than the signal strength threshold, and the CPU load is lower than the load threshold is the node determined to be healthy; otherwise, it is determined to be abnormal. This judgment mechanism covers all health conditions through strict logical combinations, effectively preventing missed reports and providing standardized health status data input for subsequent time-domain and spatial-domain risk analysis.

[0039] The temporal analysis module performs temporal anomaly analysis on network nodes in the topology network: It defines the anomaly coefficient for a given monitoring period as the ratio of the number of marked anomalous objects to the total number of network nodes. An anomaly threshold is obtained from the database, and the anomaly coefficient is compared to this threshold. If the anomaly coefficient is less than the threshold, the monitoring period is marked as normal; if the anomaly coefficient is greater than or equal to the threshold, the monitoring period is marked as anomalous. If L1 consecutive monitoring periods are marked as anomalous, temporal risk analysis is performed: a risk set is constructed from all network nodes marked as anomalous objects within the most recent L1 monitoring periods. The anomalies within this risk set are then analyzed. Network nodes whose number of markings is not less than L2 are marked as high-frequency objects. L1 and L2 are both numerical constants, and L2 < L1. The ratio of the number of high-frequency objects to the number of elements in the risk set is marked as the temporal distribution coefficient. The temporal distribution threshold is obtained from the database, and the temporal distribution coefficient is compared with the temporal distribution threshold. If the temporal distribution coefficient is less than the temporal distribution threshold, it is determined that there is a temporal anomaly risk in the topology network, a temporal warning signal is generated, and the temporal warning signal is sent to the mobile terminal of the management personnel. If the temporal distribution coefficient is greater than or equal to the temporal distribution threshold, it is determined that there is no temporal anomaly risk in the topology network, a spatial analysis signal is generated, and the spatial analysis signal is sent to the spatial analysis module.

[0040] Among them, the anomaly coefficient of the monitoring period refers to the ratio of the number of anomaly object tags to the total number of network nodes during the monitoring period. It can be achieved by real-time data collection and ratio calculation, such as dynamically summarizing the tagging data output by the health monitoring module through the time domain analysis module of the operation management platform; the anomaly threshold refers to the critical reference value used to determine the health status of a period. It can be achieved through configurable parameters stored in the database, such as presetting multiple sets of threshold parameters according to different IoT device types or network scales; comparing the anomaly coefficient of the monitoring period with the anomaly threshold refers to performing numerical judgment and generating period tags. It can be achieved using conditional judgment logic, such as setting a threshold comparison function in the software system and outputting the tagging results.

[0041] Specifically, the proposed solution quantifies the overall anomaly ratio of network nodes to form an anomaly coefficient, which is then combined with anomaly thresholds dynamically obtained from the database for judgment, thus achieving objective operation of the monitoring period marking. The calculation of the anomaly coefficient is based on the global state distribution of network nodes, avoiding interference from single-point anomalies and truly reflecting the concentration of anomalies in the time domain. The database management mechanism for the anomaly threshold supports flexible configuration and unified maintenance of threshold parameters, enabling the system to adapt to the differentiated needs of different IoT scenarios. The comparison process between the anomaly coefficient and the anomaly threshold introduces clear numerical judgment rules. When the anomaly coefficient is below the threshold, it indicates that the overall operation of the network nodes is stable, and the abnormal fluctuations are within the range of random disturbances, and it is marked as a normal period. When the anomaly coefficient reaches or exceeds the threshold, it indicates that the abnormal phenomena exhibit systematic aggregation, reaching the risk threshold, and it is marked as an abnormal period. This quantitative judgment mechanism effectively distinguishes between random fluctuations and continuous anomalies, ensuring a high degree of consistency between the period marking results and the actual network operation status, laying a reliable foundation for subsequent time domain risk analysis to identify consecutive L1 abnormal periods.

[0042] Specifically, the risk set refers to the collection of all network nodes marked as anomalous objects within the most recent L1 regulatory period. It can be implemented using dynamic arrays or hash table data structures to support efficient data storage and real-time updates. Its purpose is to focus on recent consecutive anomalous events, avoid interference from historical data, and ensure that risk analysis is based on dynamically changing network topology. High-frequency objects refer to network nodes in the risk set whose anomalous object marking frequency is not less than L2. The cumulative counting of marking frequency can be achieved using a counter mechanism or database logs. Its purpose is to identify recurring anomalous nodes, effectively filter random noise, and highlight persistently faulty nodes. The temporal distribution coefficient is the ratio of the number of high-frequency objects to the number of elements in the risk set. It can be quantified using floating-point ratio calculations or normalization. Its purpose is to objectively reflect the concentration of anomalous nodes and provide a quantifiable basis for risk assessment. Risk assessment using the temporal distribution coefficient can be automated using threshold comparison logic or rule engines. Its purpose is to replace subjective judgment and improve the accuracy and timeliness of risk warnings.

[0043] The spatial domain analysis module performs spatial domain anomaly analysis on network nodes in the topology network. It decomposes the topology network into several network branches according to data transmission paths. The ratio of the number of marked anomaly objects in a network branch to the number of network nodes is labeled as the spatial domain risk coefficient. A spatial domain risk threshold is obtained from a database, and the spatial domain risk coefficient is compared with the threshold. If the spatial domain risk coefficient is less than the threshold, the network branch is determined to have no spatial domain risk characteristics; otherwise, the corresponding network branch is marked as risky. Branch lines; network nodes in the risk branch line are numbered according to the unidirectional transmission direction. Then, the variance of the serial numbers of all network nodes marked as abnormal objects in the risk branch line is calculated to obtain the spatial distribution coefficient of the risk branch line. The spatial distribution threshold is obtained from the database, and the spatial distribution coefficient is compared with the spatial distribution threshold: if the spatial distribution coefficient is less than the spatial distribution threshold, it is determined that there is a spatial anomaly in the risk branch line, an spatial warning signal is generated, and the spatial warning signal is sent to the mobile terminal of the management personnel; if the spatial distribution coefficient is greater than or equal to the spatial distribution threshold, it is determined that there is no spatial anomaly in the risk branch line.

[0044] Decomposing the topology into several network branches according to the data transmission path refers to constructing logical transmission units based on the actual communication flow. This can be achieved using depth-first search or breadth-first search algorithms in graph theory. The purpose is to isolate independent data flow paths and avoid ambiguity in the overall network analysis.

[0045] Marking the ratio of the number of marked anomalous objects in a network branch to the number of network nodes as the spatial risk coefficient is an indicator for quantifying the density of anomalous objects. It can be implemented by using a proportional calculation method. The purpose is to associate the anomalous state with the network size and prevent a small number of anomalous objects in sparsely populated branches from being underestimated.

[0046] Marking risk branches using airspace risk coefficients refers to screening high-risk areas based on risk levels. This can be achieved based on preset risk level thresholds or classification rules, with the aim of concentrating analysis resources on critical paths and improving initial screening efficiency.

[0047] Numbering network nodes in the risk branch according to the unidirectional transmission direction means establishing the node order based on the data flow direction. This can be achieved using topology sorting algorithms or data packet transmission sequences, with the aim of capturing the actual physical or logical location relationships of the network topology.

[0048] The spatial distribution coefficient of the risk branch is obtained by calculating the variance of the index of all network nodes marked as anomalous objects in the risk branch. This refers to the spatial clustering degree of anomalies quantified by statistical variance. It can be calculated using the variance formula. The purpose is to distinguish the distribution pattern of anomalies. For example, low variance indicates local faults while high variance reflects systemic problems.

[0049] Determining whether there are airspace anomalies in risk branches by using airspace distribution coefficients refers to identifying real risks based on distribution characteristics. This can be achieved by combining preset judgment criteria, with the aim of avoiding the one-sidedness of relying solely on the number of anomalies and ensuring the reliability of risk judgment.

[0050] Specifically, the proposed solution decomposes the topology network into independent network branches based on data transmission paths, providing a structured foundation for risk analysis. Subsequently, a spatial risk coefficient is calculated to quantify the anomaly density of the branches, and risky branches are selected accordingly. Based on this, location coordinates are established for risky branch nodes numbered according to transmission direction. Then, the spatial distribution coefficient is obtained by calculating the variance of the anomaly node sequence number; this coefficient reflects the spatial clustering characteristics of anomalies. Finally, spatial anomalies are determined based on the spatial distribution coefficient, thus organically combining the network topology structure with anomaly distribution characteristics. This achieves a progressive analysis from anomaly density to spatial patterns, effectively solving the problem of accurately identifying spatially related risks in dynamic topology networks.

[0051] Example 2: Figure 2 As shown, the IoT device operation management method based on dynamic topology awareness includes the following steps:

[0052] Step 1: Perform network management analysis on IoT devices: The topology network consists of IoT devices and gateways as network nodes;

[0053] Step 2: Perform health status monitoring and analysis on network nodes in the topology network: Generate a monitoring period and divide the monitoring period into several monitoring time periods. At the end of each monitoring time period, determine the health status of the network nodes.

[0054] Step 3: Perform time-domain anomaly analysis on network nodes in the topology network: mark abnormal time periods. If there are L1 consecutive monitoring time periods that are all marked as abnormal time periods, then perform time-domain risk analysis.

[0055] Step 4: Perform spatial anomaly analysis on network nodes in the topology network: Decompose the topology network into several network branches according to the data transmission path, screen for risky branches and determine whether there are spatial anomalies in the risky branches.

[0056] The IoT device operation management system based on dynamic topology awareness works as follows: During operation, the device management module constructs a topology network using IoT devices and gateways as network nodes. It uses heartbeat packets to periodically probe the status of these network nodes and updates the topology network structure in real time based on the probe results. This ensures the network topology accurately reflects the dynamic changes in device connection status, providing reliable basic data support for subsequent analysis. The health monitoring module generates a fixed-length monitoring period and evenly divides it into multiple equal-length monitoring time periods. At the end of each monitoring time period, it marks the network nodes as healthy or abnormal based on comprehensive status data. This complete data evaluation mechanism based on the end point of each time period effectively avoids interference from instantaneous status fluctuations in health judgment and achieves stable capture of node health trends. The time-domain analysis module classifies the monitoring time periods, marking each period as normal or abnormal. When L1 consecutive monitoring time periods are marked as abnormal, a time-domain risk analysis process is automatically triggered. This mechanism identifies persistent risks through the temporal distribution characteristics of continuous abnormal events, avoiding misjudgments caused by single anomalies. The spatial analysis module performs spatial anomaly analysis on the topology network. By analyzing the spatial distribution characteristics of network nodes, it identifies potential risk areas and enables the spatial location of abnormal nodes.

[0057] The above description is merely an example and illustration of the structure of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the structure of the invention or exceed the scope defined in the claims, all of which should fall within the protection scope of the present invention.

[0058] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0059] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. An IoT device operation management system based on dynamic topology sensing, characterized in that, It includes an operation management platform, which is communicatively connected to a device management module, a health monitoring module, a time domain analysis module, a spatial domain analysis module, and a database; The device management module is used to perform network management and analysis of IoT devices: the IoT devices and gateways form a topology network as network nodes, the status of network nodes in the topology network is detected by heartbeat packets, and the topology network is dynamically updated according to the status detection results; The health monitoring module is used to perform health status monitoring and analysis on network nodes in the topology network: generating a monitoring period and dividing the monitoring period into several monitoring time periods, and marking the network nodes as healthy objects or abnormal objects at the end of the monitoring time period; The time-domain analysis module is used to perform time-domain anomaly analysis on network nodes in the topology network: marking the monitoring period as a normal period or an abnormal period; if there are L1 consecutive monitoring periods that are all marked as abnormal periods, then time-domain risk analysis is performed. The spatial domain analysis module is used to perform spatial domain anomaly analysis on network nodes in the topology network. The specific process of time-domain risk analysis includes: forming a risk set by all network nodes marked as abnormal objects in the most recent L1 regulatory period; marking network nodes in the risk set whose number of markings of abnormal objects is not less than L2 as high-frequency objects; marking the ratio of the number of high-frequency objects to the number of elements in the risk set as the time-domain distribution coefficient; and determining whether there is a time-domain anomaly risk in the topology network by using the time-domain distribution coefficient. The specific process for determining whether there is a temporal anomaly risk in the topology network includes: obtaining the temporal distribution threshold from the database, comparing the temporal distribution coefficient with the temporal distribution threshold; if the temporal distribution coefficient is less than the temporal distribution threshold, it is determined that there is a temporal anomaly risk in the topology network, a temporal warning signal is generated and sent to the mobile terminal of the management personnel; if the temporal distribution coefficient is greater than or equal to the temporal distribution threshold, it is determined that there is no temporal anomaly risk in the topology network, a spatial analysis signal is generated and sent to the spatial analysis module. The specific process of the spatial domain analysis module in performing spatial domain anomaly analysis on network nodes in the topology network includes: decomposing the topology network into several network branches according to the data transmission path; marking the ratio of the number of marked anomaly objects to the number of network nodes in the network branch as the spatial domain risk coefficient; marking risky branches using the spatial domain risk coefficient; numbering the network nodes in the risky branches according to the unidirectional transmission direction; then calculating the variance of the serial numbers of all network nodes marked as anomaly objects in the risky branches to obtain the spatial domain distribution coefficient of the risky branches; and determining whether there are spatial domain anomalies in the risky branches using the spatial domain distribution coefficient. The specific process of marking risk branches includes obtaining the airspace risk threshold from the database and comparing the airspace risk coefficient with the airspace risk threshold: if the airspace risk coefficient is less than the airspace risk threshold, the network branch is determined to have no airspace risk characteristics; if the airspace risk coefficient is less than the airspace risk threshold, the network branch is determined to have airspace risk characteristics, and the corresponding network branch is marked as a risk branch.

2. The IoT device operation management system based on dynamic topology awareness according to claim 1, characterized in that, The specific process of marking network nodes as healthy or abnormal includes: at the end of the monitoring period, obtaining the remaining power, communication signal strength, and CPU load of the network node; obtaining the power threshold, signal strength threshold, and load threshold for the corresponding device type of the network node from the database; comparing the remaining power, communication signal strength, and CPU load of the network node with the power threshold, signal strength threshold, and load threshold respectively; if the remaining power is greater than or equal to the power threshold, the communication signal strength is greater than or equal to the signal strength threshold, and the CPU load is less than the load threshold, then the health status of the network node is determined to meet the requirements, and the corresponding network node is marked as a healthy object; otherwise, the health status of the network node is determined to not meet the requirements, and the corresponding network node is marked as an abnormal object.

3. The IoT device operation management system based on dynamic topology awareness according to claim 2, characterized in that, The specific process of marking a regulatory period as a normal or abnormal period includes: marking the ratio of the number of abnormal objects marked to the total number of network nodes within the regulatory period as the abnormal coefficient of the regulatory period; obtaining the abnormal threshold through the database; and comparing the abnormal coefficient of the regulatory period with the abnormal threshold: if the abnormal coefficient is less than the abnormal threshold, the regulatory period is marked as a normal period; if the abnormal coefficient is greater than or equal to the abnormal threshold, the regulatory period is marked as an abnormal period.

4. The IoT device operation management system based on dynamic topology awareness according to claim 3, characterized in that, The specific process for determining whether there is an airspace anomaly in a risk branch includes: obtaining the airspace distribution threshold from the database, comparing the airspace distribution coefficient with the airspace distribution threshold; if the airspace distribution coefficient is less than the airspace distribution threshold, it is determined that there is an airspace anomaly in the risk branch, an airspace warning signal is generated and sent to the mobile terminal of the management personnel; if the airspace distribution coefficient is greater than or equal to the airspace distribution threshold, it is determined that there is no airspace anomaly in the risk branch.