Edge calculation safety verification method and system for cold-chain logistics transportation terminal

By using an edge computing security verification system to detect the consistency of identity and mapping information of cold chain logistics transportation terminals and calculate the status security index, dynamic quantitative evaluation and hierarchical access management of cold chain logistics transportation terminals are achieved. This solves the problems of untrusted terminal access, delayed abnormal response and crude isolation strategy in existing technologies, and improves the security and reliability of cold chain logistics transportation.

CN121664527AInactive Publication Date: 2026-03-13FOSHAN SHANGHANG FREIGHT FORWARDING CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-03-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing security verification schemes for cold chain logistics transportation terminals lack the ability to verify the trustworthiness of terminal access and dynamically identify connection behavior. They cannot identify the gradual abnormal behavior of terminals, and the isolation strategies are crude, failing to meet the high requirements of real-time performance, security, and reliability in cold chain transportation scenarios.

Method used

An edge computing security verification system is adopted, including a connection access module, an anomaly verification module, an early warning module, and a management module. By performing correlation consistency detection on the identity data and mapping information of cold chain logistics transportation terminals, correlation status data is generated, a status security index is calculated, dynamic quantitative assessment is achieved, and hierarchical access management and isolation recovery assessment are performed based on risk level.

Benefits of technology

It enables trusted access verification of cold chain logistics transportation terminals, accurately identifies connection anomalies, ensures that the system avoids interruption while ensuring security, takes into account business continuity, reduces the delay in risk handling, and provides quantitative basis for lifting isolation, thereby improving the system's intelligence and business adaptability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121664527A_ABST
    Figure CN121664527A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of logistics transportation, and provides an edge computing safety verification system of a cold-chain logistics transportation terminal, which comprises a server, a connection access module, an abnormity verification module, an early warning module and a management module, the connection access module is used for accessing a cold chain transportation terminal, collecting identity data, configuration parameters and mapping information of the cold chain transportation terminal, and executing association consistency detection to generate association state data; the exception verification module is used for acquiring a connection state sequence in a detection period based on the associated state data, extracting statistical characteristics of the connection state sequence, calculating a state safety index and realizing dynamic quantitative evaluation on terminal connection behaviors; the early warning module triggers early warning when the state safety index is lower than a monitoring threshold value, outputs an abnormal type, and associates a terminal with a risk level; and the management module implements hierarchical access management according to the risk level, and continuously records the safety index of the isolated terminal for subsequent recovery evaluation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of logistics and transportation technology, and in particular to an edge computing security verification method and system for cold chain logistics transportation terminals. Background Technology

[0002] In cold chain logistics transportation, vehicle-mounted temperature control terminals, temperature and humidity acquisition devices, positioning units, vehicle gateways, and driver operating terminals all rely on edge nodes to maintain real-time communication with the cold chain dispatching platform to complete temperature control monitoring, trajectory tracking, and transportation process management. However, the cold chain transportation links are dispersed, vehicles are in highly mobile scenarios, and the terminal deployment environment is complex. If terminal access control is insufficient or there is a lack of dynamic recognition capabilities for changes in terminal behavior, it is highly susceptible to risks such as unauthorized device access, temperature control data forgery, communication hijacking, and tampering with mapping relationships. Most existing cold chain data acquisition systems rely on static authentication or simple heartbeat detection, making it difficult to continuously model terminal connection behavior and lacking a closed-loop security control system of "anomaly identification—early warning—isolation—recovery".

[0003] For example, Chinese patent CN110942270A discloses a cold chain logistics transportation system, which is a system for cold chain data acquisition and transmission based on edge computing nodes, capable of preprocessing and storing temperature control data on the blockchain. This solution improves the traceability of cold chain data, but its security strategy mainly focuses on data integrity protection, without addressing the consistency verification of access to cold chain logistics transportation terminals, nor performing serialization analysis of terminal connection status, and without establishing a dynamic security assessment model based on statistical characteristics. Therefore, it cannot identify gradual abnormal behavior of terminals, nor can it make real-time judgments on terminal access risks.

[0004] In addition, the following defects still exist in the existing technology:

[0005] 1. Most cold chain or IoT terminal security solutions rely solely on static identity authentication or rule comparison, lacking a consistency verification mechanism between terminal configuration parameters and mapping information, making it difficult to detect mapping anomalies caused by spoofed devices or man-in-the-middle attacks;

[0006] 2. Most common anomaly detection schemes are based on single-point threshold judgments, which cannot build a state sequence model for continuous changes in connection states, nor can they obtain a quantified "state safety index" based on statistical features, resulting in delays or high false positive rates in anomaly identification.

[0007] 3. Most existing isolation strategies are "one-size-fits-all" approaches, which do not form hierarchical access control based on the level of terminal anomaly, nor do they have the ability to continuously collect security indicators of isolated terminals for recovery assessment.

[0008] 4. There is a lack of methods to integrate the above-mentioned access consistency detection, state sequence quantitative assessment, early warning, isolation and recovery determination into a closed-loop control system for edge nodes, which cannot meet the high requirements of real-time performance, security and reliability in cold chain transportation scenarios.

[0009] This invention was developed to address common problems in the field, such as untrusted terminal access, unquantifiable connection behavior, delayed abnormal response, crude isolation strategies, and lack of recovery determination mechanisms. Summary of the Invention

[0010] The purpose of this invention is to address the shortcomings of current methods by proposing an edge computing security verification method and system for cold chain logistics transportation terminals.

[0011] To overcome the shortcomings of the prior art, the present invention adopts the following technical solution:

[0012] An edge computing security verification system for cold chain logistics transportation terminals includes a server, a connection access module, an anomaly verification module, an early warning module, and a management module. The server is connected to the connection access module, the anomaly verification module, the early warning module, and the management module. The connection access module is used for access by the cold chain logistics transportation terminals, and collects the identity data, configuration parameters, and mapping information of the cold chain logistics transportation terminals. It also performs an association consistency check on the configuration parameters and mapping information to generate association status data for subsequent security verification.

[0013] The anomaly verification module is used to obtain the connection status sequence within a preset detection period based on the associated status data, and to extract statistical features from the connection status sequence to calculate the status security index of the cold chain logistics transportation terminal, so as to realize the dynamic quantitative evaluation of the connection behavior of the cold chain logistics transportation terminal.

[0014] The early warning module is used to trigger an early warning when the status safety index is lower than the monitoring threshold, and output information including the anomaly type, associated cold chain logistics transportation terminal and risk level to the management module.

[0015] The management module is used to perform hierarchical access management on cold chain logistics transportation terminals according to the risk level output by the early warning module, and to continuously record the safety indicators of the isolated cold chain logistics transportation terminals for subsequent recovery assessment.

[0016] Optionally, the association consistency detection in the connection access module includes: performing consistency verification on the device ID, MAC address, IP address or network routing indication information between the configuration parameters of the cold chain logistics transportation terminal and its mapping information, so as to detect fake cold chain logistics transportation terminals or abnormal mapping.

[0017] Optionally, the access management includes abnormal access restrictions, port isolation, IP / MAC blocking, or resource queue removal.

[0018] Optionally, the anomaly verification module includes a data verification unit and an evaluation unit. The data verification unit is used to continuously acquire the connection behavior information of the cold chain logistics transportation terminal at the sampling frequency within a preset detection period, and organize data such as handshake delay, GPS location reporting interval, packet loss rate, connection retry count, and port reachability into a connection state sequence V={v1, v2, ..., v_m} in chronological order.

[0019] The evaluation unit is used to perform statistical feature extraction on the connected state sequence, including calculating the sequence mean, variance or standard deviation, and calculating the probability features of each state value based on a statistical model to generate a state safety index.

[0020] Optionally, the connection access module includes a consistency detection unit, an access connection management unit, and a mapping status monitoring unit. The consistency detection unit is used to compare the key fields between the configuration parameters of the cold chain logistics transportation terminal and the mapping information to determine whether the mapping relationship between the cold chain logistics transportation terminal and the terminal has been forged or tampered with. The access connection management unit is used to generate an access connection code or connection credential for the cold chain logistics transportation terminal after the consistency detection is passed. The mapping status monitoring unit is used to continuously monitor the mapping records between the cold chain logistics transportation terminal and the server and feed back any changes to the anomaly verification module.

[0021] Optionally, the early warning module determines the risk level based on the deviation of the state security index from the monitoring threshold, and uses the risk level as the input condition for hierarchical access management, so that the management module can execute differentiated security control strategies based on different degrees of deviation.

[0022] Optionally, the management module calculates a total safety score based on historical safety indicator data recorded for the isolated cold chain logistics transportation terminal, compares it with a preset recovery threshold, and releases the isolation of the cold chain logistics transportation terminal when the total safety score reaches the recovery threshold.

[0023] In addition, this application also provides an edge computing security verification method for cold chain logistics transportation terminals, the edge computing security verification method including the following steps:

[0024] S1. Obtain the identity data, configuration parameters, and mapping information of the cold chain logistics transportation terminal through the connection access module, and perform an association consistency check. If the check passes, generate an access connection credential for the cold chain logistics transportation terminal; if the check fails, directly deny access and record the reason for the exception.

[0025] S2. In each detection cycle, the connection behavior indicators of the cold chain logistics transportation terminal are collected through the data verification unit and organized into a connection status sequence according to the sampling time order.

[0026] S3. Extract statistical features based on the connection state sequence, calculate the sequence anomaly metric A_{med}(k), and further calculate the state safety index Safety(k) for this detection period.

[0027] S4. Compare Safety(k) with the monitoring threshold T: When Safety(k) ≥ T, it is determined that the connection behavior of the cold chain logistics transportation terminal is within the normal range, no warning is triggered, the existing access permissions are maintained, and Safety(k) is recorded for subsequent trend analysis.

[0028] When Safety(k) < T, an early warning is triggered, and the management module performs access restrictions, downgrades, or puts the cold chain logistics transportation terminal into isolation.

[0029] S5. When the cold chain logistics transportation terminal is in an isolated state, Safety(k) is calculated again in each detection cycle, and RecoverTotalSafetyScore(k) is calculated.

[0030] S6. Determine whether to lift the isolation based on RecoverTotalSafetyScore(k) and the recovery threshold.

[0031] Optionally, the edge computing security verification method further includes:

[0032] In step S3, the calculation of the state security index Safety includes analyzing the stability and volatility of the connection state sequence and generating a state security index Safety(k) to characterize the security of connection behavior in the current detection cycle, based on the abnormal characteristics of the sequence. Optionally, the edge computing security verification method further includes: in step S6, the determination of de-isolation is based on the comparison result of the total recovery security score and the recovery threshold. When the total recovery security score is greater than or equal to the preset recovery threshold in multiple consecutive detection cycles, a recovery operation is performed to avoid false recovery due to occasional improvement in individual cycles.

[0033] The beneficial effects achieved by this invention are:

[0034] 1. By performing association consistency checks on the identity data, configuration parameters, and mapping information of cold chain logistics transportation terminals through the connection access module, and cooperating with the statistical analysis of the connection behavior sequence of cold chain logistics transportation terminals by the anomaly verification module, the access credibility and behavior credibility of cold chain logistics transportation terminals can be verified simultaneously. This ensures that the system can identify spoofed access, malicious mapping, or abnormal access from the source, significantly improving the access security of cold chain logistics transportation terminals.

[0035] 2. By constructing a state security index from time-series data such as handshake delay, GPS location reporting interval, and packet loss rate through the anomaly verification module, and cooperating with the early warning module to determine the risk level based on the deviation between the security index and the monitoring threshold, the connection behavior of cold chain logistics transportation terminals no longer relies on human experience judgment, but obtains quantifiable, comparable, and trend-analyzable security assessment indicators, ensuring that the system can achieve precise identification and trend prediction of connection anomalies.

[0036] 3. By leveraging the risk levels output by the early warning module and the coordinated use of multiple strategies (soft isolation, bandwidth limiting, delay isolation, or hard isolation) selected by the management module based on these risk levels, the security control mode is no longer limited to simple hard isolation. Instead, it intelligently matches the risk level with the business scenario, ensuring that the system avoids cold chain monitoring link interruptions while maintaining security, thus balancing business continuity and the integrity of temperature control data.

[0037] 4. Through the real-time output of anomaly levels by the early warning module and the automatic execution of hierarchical access management by the management module based on risk levels, the system can immediately take differentiated security measures such as access restrictions, bandwidth control, and port isolation after detecting anomalies. This ensures that the system's anomaly response is transformed from manual to an automated closed loop, significantly reducing the delay in risk handling.

[0038] 5. The management module continuously records the safety indicators of the cold chain logistics transportation terminal during the isolation period and calculates the recovery total safety score (RecoverTotalSafetyScore(k)). This is combined with the continuous status monitoring results of the early warning module, so that the system can automatically determine the timing of the cold chain logistics transportation terminal to be unisolated based on the recovery score and trend judgment. This ensures that the unisolation has objective, quantitative and verifiable basis and avoids the uncertainty caused by manual reset in the existing technology.

[0039] 6. Through the layered collaboration of the access module, anomaly verification module, early warning module, and management module, the system can automatically complete the entire closed loop of cold chain logistics transportation terminal identity verification, behavior anomaly quantification, risk level judgment, and hierarchical access management. This transforms security verification from traditional single-point detection to a multi-dimensional, multi-stage, and automated comprehensive judgment framework, ensuring that the system exhibits a higher degree of intelligence and business adaptability in complex cold chain transportation scenarios. Attached Figure Description

[0040] The invention will be further understood from the following description taken in conjunction with the accompanying drawings. The components in the drawings are not necessarily drawn to scale, but rather the emphasis is on illustrating the principles of the embodiments. In different views, the same reference numerals designate the same parts.

[0041] Figure 1 This is a schematic diagram of the overall framework of the present invention.

[0042] Figure 2 This is a detailed flowchart of the connection access module of the present invention.

[0043] Figure 3 This is a flowchart illustrating the urgent delivery adjustment unit of the present invention.

[0044] Figure 4 This is a schematic diagram of the control block of the response execution subunit and the external linkage scheduling platform of the present invention.

[0045] Figure 5 This is a schematic diagram of the early warning module and hierarchical access management process of the present invention.

[0046] Figure 6 This is a schematic diagram of the isolation and recovery assessment process of the present invention. Detailed Implementation

[0047] The following specific embodiments illustrate the implementation of the present invention. Those skilled in the art can understand the advantages and effects of the present invention from the content disclosed in this specification. The present invention can be implemented or applied through other different specific embodiments, and various details in this specification can also be modified and changed based on different viewpoints and applications without departing from the spirit of the present invention. Furthermore, the accompanying drawings of the present invention are for simple illustrative purposes only and are not depictions of actual dimensions; this is stated beforehand. The following embodiments will further describe the relevant technical content of the present invention in detail, but the disclosed content is not intended to limit the scope of protection of the present invention.

[0048] Example 1: According to Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 ,as well as Figure 6As shown, this embodiment provides an edge computing security verification system for cold chain logistics transportation terminals, including a server, a connection access module, an anomaly verification module, an early warning module, and a management module. The server is connected to the connection access module, the anomaly verification module, the early warning module, and the management module, and stores the intermediate data and process data of the connection access module, the anomaly verification module, the early warning module, and the management module in the server's database for querying and retrieval.

[0049] The connection access module is used for access by cold chain logistics transportation terminals, and collects the identity data, configuration parameters and mapping information of the cold chain logistics transportation terminals. It also performs an association consistency check on the configuration parameters and mapping information to generate association status data for subsequent security verification.

[0050] The associated status data also includes access timestamps, session initialization parameters, and access feature summaries, which are used to provide access behavior context information for subsequent anomaly verification.

[0051] The anomaly verification module is used to obtain the connection status sequence within a preset detection period based on the associated status data, and to extract statistical features from the connection status sequence to calculate the status security index of the cold chain logistics transportation terminal, so as to realize the dynamic quantitative evaluation of the connection behavior of the cold chain logistics transportation terminal.

[0052] The early warning module is used to trigger an early warning when the status safety index is lower than the monitoring threshold, and output information including the anomaly type, associated cold chain logistics transportation terminal and risk level to the management module.

[0053] The management module is used to perform hierarchical access management on cold chain logistics transportation terminals according to the risk level output by the early warning module, and to continuously record the safety indicators of the isolated cold chain logistics transportation terminals for subsequent recovery assessment.

[0054] The edge computing security verification system of the cold chain logistics transportation terminal also includes a central processing unit and a power supply unit. The power supply unit supplies power to the central processing unit, server, connection access module, anomaly verification module, early warning module and management module. The central processing unit is connected to the connection access module, anomaly verification module, early warning module and management module respectively, and performs centralized control of the connection access module, anomaly verification module, early warning module and management module based on the central processing unit, and stores the control data in the database of the server.

[0055] The power supply device regulates, reduces, or isolates the power supply according to the model and power requirements of each hardware device. For example, it converts AC220V mains power to DC12V or DC5V to meet the low-voltage power supply requirements of sensors, communication ports, and processors. In this implementation, the power supply device can monitor the power supply status in real time, including voltage, current, temperature rise, and whether the equipment is in a power outage protection state, according to the requirements of the National Medical Products Administration, transportation companies, or third-party cold chain supervision platforms. It also reports power supply failure events to the dispatch terminal through an early warning module.

[0056] Meanwhile, the power supply device is a technology that converts mains power into a voltage range that allows various instruments to work normally. This is a technical means well known to those skilled in the art, and therefore will not be described in detail in this embodiment.

[0057] Furthermore, in this embodiment, the cold chain logistics transportation terminal is not limited to a specific carrier. It is typically an edge data acquisition and communication device deployed in a cold chain transportation scenario, and can be installed in cold chain transport vehicles, cold chain containers, aircraft cargo hold refrigerated modules, or other carriers with cold chain transportation capabilities. The cold chain logistics transportation terminal typically includes temperature, humidity, positioning, power, and door magnetic sensors, as well as a wireless communication module (such as a 4G / 5G communication module, NB-IoT module, or satellite communication module) for periodically reporting environmental data, location information, and operating status, and receiving instructions from the dispatch platform.

[0058] Optionally, the association consistency detection in the connection access module includes: performing consistency verification on the device ID, MAC address, IP address or network routing indication information between the configuration parameters of the cold chain logistics transportation terminal and its mapping information, so as to detect fake cold chain logistics transportation terminals or abnormal mapping.

[0059] Furthermore, by calculating the difference measure or consistency score between key fields, field change trend analysis can be achieved to identify potential man-in-the-middle attacks or session forgery signs in advance. Optionally, the connection access module includes a consistency detection unit, an access connection management unit, and a mapping status monitoring unit. The consistency detection unit is used to compare the consistency of key fields between the configuration parameters and mapping information of cold chain logistics transportation terminals to determine whether the mapping relationship between the cold chain logistics transportation terminal and itself has been forged or tampered with. The consistency detection unit can also analyze the frequency of changes in key fields, the direction of field drift, and the magnitude of offset to generate field drift features as supplementary input to the anomaly verification module.

[0060] The access connection management unit is used to generate an access connection code or connection credential for the cold chain logistics transportation terminal after the consistency check passes; the access connection code can carry a timestamp, session sequence number and encrypted digest to enhance subsequent session continuity detection and prevent replay attacks.

[0061] The mapping status monitoring unit is used to continuously monitor the mapping records between the cold chain logistics transportation terminal and the server, and feed back the changes to the anomaly verification module. The mapping status monitoring unit can maintain a sliding window of the mapping fields, extract the field change patterns (drift amplitude, direction, abrupt change points), and mark the mapping behavior as a potential abnormal feature when it deviates from the normal pattern, and input it as a supplementary dimension of the connection state sequence into the anomaly verification module.

[0062] In this embodiment, the key fields include device ID, MAC address, IP address, or network routing information.

[0063] In addition, the consistency detection unit is used to determine the consistency between the configuration parameters reported by the cold chain logistics transportation terminal and the mapping information obtained from the system side, in order to identify spoofed cold chain logistics transportation terminals, tampering behavior, or abnormal mapping relationships. Specifically, the consistency detection unit extracts key fields from the data collected from the cold chain logistics transportation terminal and the system side, including device ID, MAC address, IP address, and network routing indication information (including gateway identifier and carrier segment information), and performs unified formatting on the above fields, converting IP addresses to integers; unifying MAC addresses to uppercase and removing separators; and extracting key fields from the routing indication information into a fixed structure.

[0064] The fixed mechanism includes the following processing: IP addresses are uniformly converted to dotted decimal or integer; MAC addresses are uniformly cased and delimited; RouteInfo extracts key routing segments according to preset rules.

[0065] Using field matching functions: Define a Boolean consistency flag for each field: Eq_DeviceID = 1 (same) or 0 (different); Eq_MAC = 1 or 0; Eq_IP = 1 or 0; Eq_Route = 1 or 0;

[0066] A value of 1 indicates that the fields are consistent; a value of 0 indicates that the fields are inconsistent.

[0067] In addition, in this embodiment, a weighted summation scoring method is used to comprehensively quantify consistency, so as to obtain the consistency score ConsScore:

[0068] ;

[0069] in, ~ The preset weights can be adjusted according to the importance of the fields; a higher ConsScore value indicates that the access from the cold chain logistics transportation terminal is more reliable.

[0070] In this embodiment, the weights required for the ConsScore are... ~ The immutability level of each field is determined, with DeviceID, MAC, IP, and Route set to 5, 4, 3, and 2 respectively, and calculated after normalization. =0.36 =0.29 =0.21, =0.14.

[0071] In another application scenario, such as high-security cold chain transportation of vaccines and blood products, the immutability level can be adjusted to 6, 5, 2, 1, thereby obtaining... =0.43 =0.36 =0.14 =0.07, to enhance the ability to identify disguised cold chain logistics transportation terminals; while in scenarios with large network environment fluctuations, such as cross-border transportation, immutability levels 5, 4, 2, and 1 can be used to reduce the probability of false alarms caused by IP or route hopping. Through the above methods, the determination of weights can be ensured to be reproducible and consistent with business operations, and the consistency calculation results can be guaranteed to be more in line with actual operating scenarios.

[0072] like Figure 2 As shown, based on the comparison between ConsScore and the consistency threshold Cons_Threshold, a consensus conclusion of pass / fail is output.

[0073] Specifically, when ConsScore is greater than or equal to Cons_Threshold, the output is "consistency passed"; when ConsScore is less than Cons_Threshold, the output is "consistency failed".

[0074] When the detection result is that the consistency is passed, the consistency detection unit marks the corresponding cold chain logistics transportation terminal as the currently trusted cold chain logistics transportation terminal and triggers the access connection management unit to generate an access connection code and session sequence number for the cold chain logistics transportation terminal. At the same time, it writes the associated state data, including the consistency score and drift characteristics, into the associated state buffer, which is used as the basic input for the anomaly verification module to build the connection state sequence in subsequent detection cycles. The management module keeps the cold chain logistics transportation terminal in the normal access list, allowing it to continue to interact with the server for business data.

[0075] When the detection conclusion is that consistency fails, the consistency detection unit returns a rejection flag to the access connection management unit. The access connection management unit does not assign an access connection code and session sequence number to the cold chain logistics transportation terminal, and can record this access event as an abnormal access attempt. The management module updates the access status of the cold chain logistics transportation terminal according to the rejection flag, adds the cold chain logistics transportation terminal to the restricted access list or blacklist, and optionally increases the abnormal access count of the cold chain logistics transportation terminal for subsequent statistical analysis of historical security indicators. At the same time, the result of consistency failure can be written as a high-risk feature into the associated status data, and the anomaly verification module assigns a higher risk weight to the cold chain logistics transportation terminal when calculating the status security index, thereby realizing rapid interception and continuous monitoring of disguised cold chain logistics transportation terminals or mapped abnormal cold chain logistics transportation terminals.

[0076] Additionally, for the same cold chain logistics transportation terminal, a record of field changes over a period of time can be maintained, such as the most recent N accesses:

[0077] The DeviceID sequence (which should not change in theory), MAC sequence (which should not change frequently), and IP / RouteInfo sequence (which are allowed to change, but the frequency and pattern of change have a normal range) are used to calculate the change data of the above indicators, including: ChangeCount_X: the number of times a certain field has changed in the last N times;

[0078] NormalRange_X: The upper limit of normal variation obtained from experience or statistics;

[0079] If DeviceID or MAC changes multiple times within a short period of time, it is a clear anomaly.

[0080] If the frequency of IP / RouteInfo changes is much higher than normal, it is suspicious (there may be an attack or reuse).

[0081] In this embodiment, the system maintains a mapping history window of length N for each cold chain logistics transportation terminal. Each record in the window includes at least a timestamp, device ID, MAC address, IP address, and routing information. When a new mapping record is added, it is added to the window, and the oldest record is deleted when the window length exceeds N. N is set to 10, 20, 50, or a value set or limited by the system / administrator.

[0082] For the device ID and MAC address fields, the drift feature uses a Boolean quantization method to indicate whether a change has occurred. When at least one field value change is detected within the window, the corresponding drift feature is set to 1; otherwise, it is set to 0, to reflect that a change in this type of field is highly suspicious.

[0083] In the drift analysis of IP address and routing indication information fields, on the one hand, the number of field changes between two adjacent records within a window is counted, and the rate of change is calculated accordingly; on the other hand, the network segment prefix of the IP address is compared with the routing path, and when a sudden jump from one network segment to a distant network segment or carrier segment is detected, this type of sudden change is marked as Abrupt_change.

[0084] Based on the aforementioned rate of change and mutation markers, ΔIP and ΔRoute are calculated respectively to characterize whether the mapping behavior of cold chain logistics transportation terminals at the network layer is stable.

[0085] The frequency of the above-mentioned changes is represented as the field drift feature ΔFeature, which is expressed as a vector, including the drift amount of each field: This data is appended to the associated status data and considered by the anomaly verification module.

[0086] For each cold chain logistics transportation terminal, maintain a mapping history window of length N. Each record in the window includes at least a timestamp, device ID, MAC address, IP address, and routing information. When a new mapping record is added, it is added to the window, and the oldest record is deleted when the window length exceeds N.

[0087] For the device ID and MAC address fields, the consistency detection unit counts the changes in the fields within the window. When the device ID or MAC address is detected to have changed at least once within the window, the corresponding drift feature ΔDevID or ΔMAC is set to 1, indicating that an abnormal change has occurred in this type of field. Otherwise, it is set to 0 to reflect the high sensitivity of this type of field.

[0088] For the IP address and routing indication information fields, the mapping status monitoring unit counts the number of field changes between adjacent records within the statistical window, calculates IP_change_rate and Route_change_rate, and compares the network segment prefix and routing path of the IP address. When a jump from the local network segment to a distant network segment or a cross-carrier segment is detected, the behavior is marked as Abrupt_change. Based on the above change rate and abrupt change flag, ΔIP and ΔRoute are calculated respectively to characterize whether the mapping behavior of the cold chain logistics transportation terminal at the network layer is stable.

[0089] In one implementation, the drift feature ΔFeature is represented as a vector:

[0090] ;

[0091] It also serves as an additional dimension input to the anomaly verification module for the connection state sequence, and is used to comprehensively consider the change patterns of the cold chain logistics transportation terminal identity field and the network mapping field during the calculation of the state security index.

[0092] In another implementation, the drift characteristics of the above fields can be combined into a total drift score, DriftScore, according to a preset weight. This score is used to quantify the overall stability of the mapping behavior of cold chain logistics transportation terminals. When the DriftScore exceeds the normal range, the cold chain logistics transportation terminal is marked as having abnormal mapping characteristics, and the state security index corresponding to the cold chain logistics transportation terminal is further reduced, thereby achieving early identification of mapping anomalies.

[0093] In this embodiment, the access connection management unit generates an access connection code Token for each access that passes the consistency check, which contains:

[0094] The unique identifier of the cold chain logistics transportation terminal (such as DeviceID or its hash), the session sequence number SessionID (incrementing or random), the timestamp Ts (such as millisecond time), the summary or rating label of the consistency score ConsScore, and a signature / summary Sign for a complete field;

[0095] For example: For a string to be signed: ;

[0096] In the formula, "||" indicates string concatenation or byte concatenation in a fixed order;

[0097] The following is obtained by using the HMAC-SHA256 cryptographic digest algorithm:

[0098] ;

[0099] The key K is stored in a protected storage area of ​​the access connection management unit, and is not stored on the cold chain logistics transportation terminal side, nor is it transmitted over the network, to ensure that the signature cannot be forged.

[0100] The access connection management unit encapsulates the calculated Sign_token along with DeviceID, SessionID, Ts, and ConsLevel to form the final access connection code Token:

[0101] ;

[0102] The token is returned to the cold chain logistics transportation terminal for integrity and legality verification of subsequent access operations.

[0103] The access connection management unit calls the same digest algorithm and key used when generating the access connection code to recalculate the signature of the RawString. In this embodiment, the HMAC-SHA256 algorithm is used:

[0104] ;

[0105] Where K is a symmetric key stored only on the server side or inside the access connection management unit, and Sign_{calc} is the signature value recalculated on the server side this time.

[0106] The access connection management unit compares the recalculated signature value Sign_calc with the original signature value Sign_token carried in the access connection code. If the two are strictly equal, it is determined that the access connection code has not been tampered with during transmission and is indeed legally generated. If the two are not equal, it is determined that the access connection code may have been forged or tampered with, and thus the access request is rejected.

[0107] In a preferred embodiment, to avoid time-side channel risks introduced by improper string comparison implementation, the access connection management unit adopts a fixed-time byte-level comparison strategy, comparing each byte of Sign_calc and Sign_token bit by bit before giving the final result of whether they are consistent.

[0108] The generation of the Sign_token relies on a key K stored only on the server side, and the concatenation order of the RawString is fixed. Cold chain logistics transportation terminals cannot know the internal key of the signature algorithm, thus preventing them from forging or modifying the signature field in the access connection code. Simultaneously, the access connection management unit verifies the token's integrity each time an access occurs by reconstructing the RawString and calculating Sign_calc, thereby detecting whether the token has been tampered with or replayed, achieving highly reliable protection of the access credentials.

[0109] Assuming the signature verification passes, the access connection management unit can further verify the rationality of the session sequence number (SessionID) and timestamp (Ts), including but not limited to: determining whether the SessionID belongs to the valid session range registered in the session table for the cold chain logistics transportation terminal, whether the SessionID has been marked as invalid or revoked, and whether the timestamp (Ts) falls within the allowed time offset window. Only when the signature verification passes and both SessionID and Ts meet the preset rules will the access request be deemed legitimate, and the corresponding access record will be written into the session table and associated state data for subsequent connection state sequence construction and state security index calculation. Conversely, if the signature verification fails or the SessionID and Ts verification fails, the access connection management unit will reject the access and record the event in the abnormal access statistics, allowing the management module and the abnormal verification module to increase the risk weight of the cold chain logistics transportation terminal in subsequent security assessments.

[0110] The access connection management unit maintains a session table, which records the most recent valid SessionID, validity period, and whether it has been frozen or revoked for each cold chain logistics transportation terminal.

[0111] Subsequent accesses to the cold chain logistics transportation terminal require a token. The access connection management unit verifies the summary Sign and SessionID to prevent session replay attacks.

[0112] When the management module or the anomaly verification module determines that a cold chain logistics transportation terminal has a high risk, the access connection management unit can: freeze its SessionID, reject new token generation requests, and synchronize the freeze record to the server and the management module.

[0113] The mapping status monitoring unit is used to continuously monitor the network mapping behavior of cold chain logistics transportation terminals in a sliding window manner and identify abnormal mapping change patterns.

[0114] The mapping status monitoring unit maintains a mapping record sequence with a window length of N for each cold chain logistics transportation terminal. Each record contains: timestamp, IP address, routing indication information, network information such as operator; as a new record is added, the oldest record is removed.

[0115] Simultaneously, the mapping status monitoring unit calculates the mapping fields within the sliding window:

[0116] ;

[0117] In the formula, IP change rate, that is, the frequency of IP address changes within a sliding window (the most recent N records). The route change rate is the frequency with which the route indication fields (such as carrier ASN, gateway prefix, and path identifier) ​​change within the window; N is the length of the window, which can be set by the administrator according to actual needs, and can be any value such as 10, 20, or 50.

[0118] Several cold chain logistics terminals confirmed by the business side to be operating normally (e.g., terminals in stable operation, without spoofing, and without abnormal mapping records) are selected. Within M consecutive detection cycles (e.g., M=100~500), the IP_change_rate and Route_change_rate of these terminals in each cycle are collected. These change rates are calculated according to the aforementioned definition using the mapping records of the cold chain logistics terminals within a sliding window length N.

[0119] For the normal sample set IP_change_rate(i) included in the statistics, its sample mean is with sample standard deviation Calculate as follows:

[0120] ;

[0121] Where K is the number of normal samples that are included in the statistics after screening;

[0122] Sample mean of route change rate with standard deviation Calculate in the same way:

[0123] ;

[0124] During the online assessment phase, for the cold chain logistics transportation terminal to be evaluated, the mapping status monitoring unit calculates the IP_change_rate and Route_change_rate within the current monitoring cycle in the aforementioned manner, and further calculates their deviation from the normal distribution:

[0125] ;

[0126] Specifically, when the current rate of change is lower than the normal average, the corresponding deviation will be truncated to 0 to avoid misjudging normal fluctuations as abnormal.

[0127] In addition, the mapping status monitoring unit compares the IP address network segments of adjacent records with the routing indication information. When a cross-network segment jump or cross-carrier segment change is detected, the Abrupt_change flag is set to 1; otherwise, it is set to 0.

[0128] MapVar, the intensity of mapping behavior change, is defined as a distance superposition mutation penalty term in two-dimensional space between the abnormal feature points formed by IP change deviation and routing change deviation.

[0129] ;

[0130] In the formula, δ is a constant used to amplify the impact of mutation behavior; in this embodiment, δ = 1. When MapVar is close to 0, it indicates that the mapping behavior of the current cold chain logistics transportation terminal is highly consistent with the normal distribution.

[0131] If an abnormal mapping behavior is detected, the mapping status monitoring unit generates an abnormal mapping feature (MapAbnormal flag) and an abnormal mapping score (MapScore). The monitoring unit then appends these features to the associated status data to improve the accuracy of the status safety index calculated by the anomaly verification module. If the behavior exceeds the set normal range, the cold chain logistics transportation terminal is determined to have an abnormal mapping trend.

[0132] The consistency detection unit uses weighted scoring and field drift analysis to initially quantify the trustworthiness of cold chain logistics transportation terminals; the access connection management unit uses session sequence numbers and encrypted digest mechanisms to ensure that access is unforgeable and traceable; and the mapping status monitoring unit uses a sliding window algorithm to identify mapping behavior patterns and extract change features.

[0133] Optionally, the anomaly verification module includes a data verification unit and an evaluation unit. The data verification unit is used to continuously acquire the connection behavior information of the cold chain logistics transportation terminal at the sampling frequency within a preset detection period, and organize data such as handshake delay, GPS location reporting interval, packet loss rate, connection retry count, and port reachability into a connection state sequence V={v1, v2, ..., v_m} in chronological order.

[0134] Specifically, within each detection cycle, the connection status between the cold chain logistics transportation terminal and the server is collected at a preset sampling interval Δt (e.g., 1s to 5s). Each collection yields a connection status vector vⱼ, which includes: handshake delay T_handshake(j), GPS location reporting interval T_report(j), packet loss rate Loss(j), connection retry count Retry(j), and port reachability Port_reachable(j).

[0135] During the data acquisition process, the data verification unit performs preliminary filtering of missing or outlier values. For example, if a certain indicator fails to be acquired, the sample is discarded, or the previous valid sample is used for interpolation. If the acquired indicator significantly exceeds the physical upper or lower limit (e.g., the handshake delay is negative), the sample is marked as invalid and removed. The m valid connection state vectors after filtering are arranged in order of sampling time to form the connection state sequence corresponding to the current detection period: V={v1, v2, ..., v_m}. This connection state sequence V and its length m are provided as input to the evaluation unit.

[0136] The evaluation unit is used to perform statistical feature extraction on the connected state sequence, including calculating the sequence mean, variance or standard deviation, and calculating the probability features of each state value based on a statistical model to generate a state safety index.

[0137] During the deployment phase or initial operation, several normally benign cold chain logistics transportation terminals were selected as samples. The distribution characteristics of indicators such as handshake delay, GPS location reporting interval, packet loss rate, connection retries, and port reachability were statistically analyzed over multiple detection cycles. The sample mean and sample standard deviation of each indicator were calculated.

[0138] μT_handshake, σT_handshake, μT_report(j), σT_report(j), μLoss, σLoss, μRetry, σRetry, μPort, σPort, and the above parameters are stored in the evaluation unit as statistical benchmarks for normal behavior, and are used for probabilistic feature calculation in the subsequent online detection stage.

[0139] During the online detection phase, the evaluation unit first calculates the sequence statistical characteristics of each index in the connection state sequence V. For example, for the handshake delay sequence {T_handshake(1), …, T_handshake(m)}, its sequence mean μ_seq_handshake and sequence standard deviation σ_seq_handshake can be calculated by the following formula:

[0140] ;

[0141] The GPS location reporting interval, packet loss rate, connection retry count, and port reachability are similarly calculated to obtain the corresponding sequence mean and standard deviation μT_report(j), σT_report(j), μLoss, σLoss, μRetry, σRetry, μPort, and σPort.

[0142] Among them, the aforementioned sequence-level statistical features are used to describe the overall stability and fluctuation of the connection behavior of the cold chain logistics transportation terminal within the current detection period.

[0143] To characterize the "rarity" of the state vector at each time point in the connected state sequence, the evaluation unit calculates the standardized deviation and probability characteristics of each connected state vector vⱼ based on pre-obtained normal behavior baseline parameters.

[0144] For the handshake delay T_handshake(j), first calculate its standardized deviation relative to the normal mean:

[0145] ;

[0146] Similarly, based on the formula above, the standardized deviations of GPS location reporting interval, packet loss rate, number of retries, and port reachability, Z_report(j), Z_Loss(j), Z_Retry(j), and Z_Port(j), can be calculated.

[0147] Furthermore, the evaluation unit approximates the standardized deviations of the above-mentioned parameters to follow a standard normal distribution N(0,1), and calculates the tail probability of the current value of each indicator accordingly. For the handshake delay, the following can be calculated:

[0148] ;

[0149] Where Φ(·) is the cumulative distribution function of the standard normal distribution. The smaller the tail probability, the more likely the current handshake delay is to be an outlier. The probability values ​​p_report(j), p_Loss(j), p_Retry(j), and p_Port(j) of GPS location reporting interval, packet loss rate, connection retries, and port reachability are calculated in the same way.

[0150] Meanwhile, to avoid numerical underflow due to extremely low probability, a lower limit ε can be set for each probability value in actual calculations (set as: ε=10⁻). 6 When p is less than ε, ε is used instead.

[0151] After obtaining the tail probabilities of each indicator at each time point, the evaluation unit transforms these probabilities into single-point anomaly metrics. For the j-th connection state vector, its log-likelihood value L(j) and anomaly score A(j) can be defined as follows:

[0152]

[0153] Where L(j) represents the joint log-likelihood of the connected state vector under the premise that each indicator is independent and follows the corresponding statistical distribution; A(j) is its corresponding anomaly score, the larger the value, the less the state conforms to the normal behavior distribution, that is, the more abnormal.

[0154] In order to extract an indicator that can represent the overall security level of the detection cycle from the entire connection state sequence, the evaluation unit aggregates the anomaly scores {A(1), A(2), …, A(m)} at all time points.

[0155] The evaluation unit first sorts the set of abnormal scores {A(j)} from largest to smallest, and then obtains...

[0156] ;

[0157] The purpose of sorting is that when there are a few sudden and large-amplitude anomalies within the detection period, directly using the average value will be diluted by a large number of normal values, which is not conducive to exposing abnormal behavior. By sorting, the time points with the "most significant anomalies" can be extracted for focused analysis.

[0158] The evaluation unit selects the largest set of anomalies from the top q% (in this embodiment, it is set to 20% of the anomaly score set) after sorting. Calculate the median value A_med of this subset as a representative anomaly measure at the sequence level:

[0159] ,in, In the formula, The value of q is the rounding symbol, ranging from 10% to 30%, preferably 20%.

[0160] In this embodiment, by extracting the top q% of anomalies, highly abnormal behaviors that occur within a short period of time can be effectively captured, while avoiding the weakening of anomalies caused by simple averaging over the entire period.

[0161] Evaluation unit Take the median as a sequence-level representative anomaly measure: A_med = median( );

[0162] The larger the sequence anomaly metric A_{med}, the more anomalous the connection behavior during that detection cycle. For ease of use by subsequent modules, the evaluation unit maps A_{med} to a state safety index between 0 and 1: Safety.

[0163] ;

[0164] In the formula, The normalized scaling factor is obtained by statistical analysis of multiple detection cycles of historical normal cold chain logistics transportation terminals during the system deployment phase; specifically, A_med is calculated in each of the N normal cycles; the median or 75th percentile of these A_med values ​​is taken as S0.

[0165] By performing consistency checks on the identity data, configuration parameters, and mapping information of cold chain logistics transportation terminals through the connection access module, and cooperating with the anomaly verification module to perform statistical analysis on the connection behavior sequence of cold chain logistics transportation terminals, the access credibility and behavioral credibility of cold chain logistics transportation terminals can be verified simultaneously. This ensures that the system can identify spoofed access, malicious mapping, or abnormal access from the source, significantly improving the access security of cold chain logistics transportation terminals.

[0166] Optionally, the early warning module determines the risk level based on the deviation of the state security index from the monitoring threshold, and uses the risk level as the input condition for hierarchical access management, so that the management module can execute differentiated security control strategies based on different degrees of deviation.

[0167] Optionally, the access management includes abnormal access restrictions, port isolation, IP / MAC blocking, or resource queue removal.

[0168] In this embodiment, after obtaining the safety index, the early warning module first calculates the deviation Δ between Safety and the monitoring threshold T: ;

[0169] The monitoring threshold T is used to characterize the minimum safety level of a cold chain transportation terminal under normal operating conditions. Since terminal connection behavior is somewhat volatile, this invention statistically analyzes the safety index (Safety(k)) of multiple normal terminals within a continuous detection period to obtain the mean μ' and standard deviation σ'. Based on statistical stability, the monitoring threshold T = μ' − β'·σ' is set, where β' is the safety sensitivity coefficient. The value of β' can range from 0.5 to 1.2, reflecting the sensitivity requirements for abnormal triggering in different transportation scenarios. When β' is larger, the system is more sensitive to slight fluctuations; when β' is smaller, it is more tolerant of slight fluctuations. For example, in a typical cold chain transportation scenario, the mean safety index of a normal terminal is μ' = 0.82, and the standard deviation σ' = 0.06. Setting β' = 1 yields a monitoring threshold T = 0.82 − 0.06 = 0.76. Based on this, an early warning is triggered when Safety(k) < 0.76.

[0170] The early warning module determines the corresponding risk level based on the magnitude of Δ. The larger the deviation, the more significant the difference between the current detection cycle's safety status and the expected normal status, and the higher the risk level. In one feasible implementation, the risk level can be determined according to the following interval relationship:

[0171] When △≤0, the risk level is Level0 (no risk).

[0172] When 0 < △ ≤ α, the risk level is Level 1 (low risk).

[0173] When α < △ ≤ β, the risk level is Level 2 (medium risk).

[0174] When 0 > β, the risk level is Level 3 (high risk).

[0175] Wherein, α and β are deviation thresholds preset by the system based on historical data statistics or business requirements. In this embodiment, they are set as: α = 0.05, β = 0.15. Through the above division method, continuously changing security deviations can be mapped to discrete risk levels, making subsequent hierarchical access management feasible and controllable.

[0176] like Figure 5 As shown, after the early warning module determines the risk level, it transmits the risk level as input to the management module, enabling the management module to execute differentiated access control policies based on different risk levels.

[0177] When at Level 0 (Safety ≥ T, no risk), normal access is maintained and no restrictions are enforced.

[0178] When at Level 1 (low risk), lightweight access restrictions are implemented, such as reducing connection speed, restricting unnecessary port access, or adding to a low-priority resource queue.

[0179] When at Level 2 (medium risk), moderate-intensity restrictions are implemented, such as port isolation, bandwidth limiting, MAC blocking, or limiting the number of TCP / UDP interactions.

[0180] When the risk level is Level 3 (high risk), high-intensity security strategies such as isolation of cold chain logistics transportation terminals, communication cut-off, or forced re-authentication are directly implemented.

[0181] By classifying risks based on the magnitude of deviation, a graded response from mild to severe anomalies can be achieved, thereby improving the safety protection capabilities of cold chain logistics transportation terminals in edge scenarios.

[0182] In addition, in this embodiment, the interval thresholds α and β of Δ are not fixed values. They can be automatically determined according to the normal behavior distribution of different cold chain transportation scenarios, so that the risk classification is not based on simple hard-coded rules, but on statistical deviation distribution, thus having adaptability in different network environments.

[0183] In this embodiment, an anomaly verification module constructs a state security index based on time-series data such as handshake delay, GPS location reporting interval, and packet loss rate. This index works in conjunction with a warning module to determine the risk level based on the deviation between the security index and the monitoring threshold. This allows the connection behavior of cold chain logistics transportation terminals to no longer rely on human experience judgment, but instead obtain quantifiable, comparable, and trend-analyzable security assessment indicators, ensuring that the system can achieve precise identification and trend prediction of connection anomalies.

[0184] Optionally, the management module calculates a total safety score based on historical safety indicator data recorded for the isolated cold chain logistics transportation terminal, compares it with a preset recovery threshold, and releases the isolation of the cold chain logistics transportation terminal when the total safety score reaches the recovery threshold.

[0185] In this embodiment, the management module continuously records the Safety index of the cold chain logistics transportation terminal in the isolated state for each detection cycle, and calculates the total safety score RecoverTotalSafetyScore for the recovery phase.

[0186] In this embodiment, in order to determine whether the connection behavior of the isolated cold chain logistics transportation terminal has been continuously restored to an acceptable safety level, the management module introduces a recovery total safety score (RecoverTotalSafetyScore) to dynamically evaluate the state safety index over multiple detection cycles.

[0187] By leveraging the risk levels output by the early warning module and the coordinated efforts of the management module to select multiple levels of strategies such as soft isolation, bandwidth limiting, delay isolation, or hard isolation based on the risk level, the security control mode is no longer limited to a single hard isolation. Instead, it is intelligently matched according to the degree of risk and the business scenario, ensuring that the system avoids the interruption of the cold chain monitoring link while ensuring security, and taking into account both business continuity and the integrity of temperature control data.

[0188] like Figure 6 As shown, after each detection cycle is completed, the evaluation unit first calculates the state safety index Safety(k) for that cycle (the k-th cycle), that is:

[0189] ;

[0190] in, For the sequence anomaly measure of the k-th period, The normalized scaling factor is obtained by statistical analysis of multiple detection cycles of cold chain logistics terminals during the system deployment phase. Specifically, A_med is calculated in each of the N normal cycles, and the median or 75th percentile of these A_med values ​​is taken as S0.

[0191] Subsequently, the management module updates the recovery total safety score (RecoverTotalSafetyScore(k)) based on Safety(k):

[0192] ;

[0193] Where γ is a smoothing coefficient of 0.1 to 0.5, and RecoverTotalSafetyScore(0) is initialized to Safety(0) of the last period before isolation, so that the recovery trend is consistent with the risk status at the time of isolation.

[0194] In this embodiment, the specific value of the smoothing coefficient is determined according to the following formula: γ=2 / (L+1), where L is the selected smoothing period. For example, if the target smoothing period L is set to 9, then γ=0.2.

[0195] In another application scenario, cold chain logistics transportation terminals are mainly used for the urban or regional distribution of general cold chain goods such as fresh produce and fruits and vegetables in supermarkets. This type of business has certain security requirements, but also aims to lift quarantine measures as soon as possible after the cold chain logistics transportation terminal's behavior stabilizes and recovers, in order to minimize the impact on transportation efficiency. In this scenario, the target smoothing period L can be set to 5, meaning that the cumulative recovery score is expected to reflect the recovery trend over a timescale of approximately 5 detection periods.

[0196] When RecoverTotalSafetyScore(k) is greater than or equal to the preset recovery threshold RecoverThreshold, and this condition is met for N consecutive cycles (e.g., N = 2 to 4), the management module determines that the cold chain logistics transportation terminal has been restored to a stable and safe state and executes the unisolation operation; if RecoverTotalSafetyScore(k) does not reach the recovery threshold RecoverThreshold, the isolation continues and the status collection and scoring update process of the next cycle begins.

[0197] Specifically, when RecoverTotalSafetyScore(k) is greater than or equal to RecoverThreshold, and this condition is met for N consecutive cycles (N can be 2 to 4), the management module considers the terminal state to have stabilized and performs the release from isolation operation; otherwise, it continues to maintain isolation and enters the next detection cycle.

[0198] In this invention, the recovery threshold (RecoverThreshold) is used to characterize the minimum level of safety and stability of the terminal during the isolation recovery phase. This threshold is obtained by statistical analysis of data from a large number of normal cold chain logistics transportation terminals during the system's deployment or initial operation. Specifically, the state safety index (Safety(k)) is calculated within a continuous detection cycle of multiple normal terminals, and its mean μ and standard deviation σ are statistically analyzed. Based on this, RecoverThreshold is set as μ −τ·σ, where τ is a stability coefficient of 0.5 to 1.5 (its value is set according to different types of cold chain transportation scenarios (such as long-distance inter-provincial transportation, delivery of highly sensitive temperature-controlled medicines, and short-distance intra-city delivery)).

[0199] In this embodiment, a value example is provided:

[0200] 1) If the mean μ=0.85 and the standard deviation σ=0.05 of the normal safety index are statistically obtained, and τ=1 is set, then RecoverThreshold = 0.85 − 1×0.05 = 0.80. That is, the normal safety index level is relatively high, so setting the recovery threshold at 0.80 is more reasonable.

[0201] 2) If the system statistics show μ=0.75 and σ=0.10, and τ=0.8 is set, then RecoverThreshold = 0.75 −0.8×0.10 = 0.67, which means that the transportation link is complex and the signal fluctuation is large, so the recovery threshold is low.

[0202] 3) If μ=0.90, σ=0.03, and τ=1.5, then RecoverThreshold = 0.90 − 1.5×0.03≈ 0.855, which is equivalent to a higher recovery standard required for highly sensitive goods.

[0203] In summary, the recovery threshold RecoverThreshold needs to be determined based on the specific application scenario and statistical analysis. This is a well-known technical method among those skilled in the art, and therefore will not be elaborated upon in this embodiment.

[0204] By coordinating the real-time output of anomaly levels by the early warning module and the automatic execution of tiered access management based on risk levels by the management module, the system can immediately take differentiated security measures such as access restrictions, bandwidth control, and port isolation after detecting anomalies. This ensures that the system's anomaly response is transformed from manual to an automated closed loop, significantly reducing the delay in risk handling.

[0205] In addition, this application also provides an edge computing security verification method for cold chain logistics transportation terminals, the edge computing security verification method including the following steps:

[0206] S1: Obtain the identity data, configuration parameters, and mapping information of the cold chain logistics transportation terminal through the connection access module, and perform an association consistency check. If the check passes, an access connection credential is generated for the cold chain logistics transportation terminal; if the check fails, access is directly denied and the reason for the abnormality is recorded.

[0207] S2: In each detection cycle, the connection behavior indicators of the cold chain logistics transportation terminal are collected through the data verification unit and organized into a connection status sequence according to the sampling time order;

[0208] S3: Extract statistical features based on the connection state sequence, calculate the sequence anomaly metric A_{med}(k), and further calculate the state safety index Safety(k) for this detection period.

[0209] S4: Compare Safety(k) with the monitoring threshold T: When Safety(k) ≥ T, it is determined that the connection behavior of the cold chain logistics transportation terminal is within the normal range, no warning is triggered, the existing access permissions are maintained, and Safety(k) is recorded for subsequent trend analysis;

[0210] When Safety(k) < T, an early warning is triggered, and the management module performs access restrictions, downgrades, or puts the cold chain logistics transportation terminal into isolation.

[0211] S5: When the cold chain logistics transportation terminal is in an isolated state, continue to calculate Safety(k) and RecoverTotalSafetyScore(k) in each detection cycle.

[0212] S6: Determine whether to lift the isolation based on RecoverTotalSafetyScore(k) and the recovery threshold.

[0213] The management module continuously records the safety indicators of the cold chain logistics transportation terminal during the isolation period and calculates the recovery total safety score (RecoverTotalSafetyScore(k)). This, combined with the continuous status monitoring results of the early warning module, enables the system to automatically determine the timing of the de-isolation of the cold chain logistics transportation terminal based on the recovery score and trend judgment. This ensures that the de-isolation has objective, quantitative, and verifiable basis, avoiding the uncertainty caused by manual reset in existing technologies.

[0214] Optionally, the edge computing security verification method further includes:

[0215] In step S3, the calculation of the state safety index Safety includes analyzing the stability and volatility of the connection state sequence, and generating a state safety index Safety(k) to characterize the safety of the connection behavior in the current detection period by combining the abnormal characteristics of the sequence.

[0216] Optionally, the edge computing security verification method further includes: in step S6, the determination of de-isolation is based on the comparison result of the total recovery security score and the recovery threshold. When the total recovery security score is greater than or equal to the preset recovery threshold in multiple consecutive detection cycles, the recovery operation is performed to avoid false recovery due to occasional improvement in individual cycles.

[0217] Optionally, the edge computing security verification method further includes: in step S4, comparing the state security index Safety(k) with the monitoring threshold to obtain the deviation range, and classifying the security status of the current detection period into different risk levels based on the deviation range; the early warning module generates corresponding early warning information according to the risk level, and the management module performs hierarchical access management based on the risk level, including maintaining normal access, implementing abnormal access restrictions, implementing port isolation, IP / MAC blocking, or completely isolating the cold chain logistics transportation terminal.

[0218] Optionally, the edge computing security verification method further includes: in step S6, after the isolation is lifted, an observation period is entered. During the observation period, the detection frequency of the cold chain logistics transportation terminal is increased or the monitoring threshold is appropriately increased. When the state security index Safety(k) of multiple consecutive detection cycles is less than the monitoring threshold again during the observation period, the management module re-triggers the isolation process to prevent the cold chain logistics transportation terminal from repeatedly experiencing abnormalities in a short period of time.

[0219] Optionally, the edge computing security verification method further includes: within any detection period, when an alert is triggered, access restrictions are implemented, or isolation is lifted, the system writes the corresponding state security index Safety(k), total recovery security score, risk level, control action type, and timestamp into the server's security audit log to support subsequent anomaly tracing analysis and policy optimization.

[0220] Furthermore, the edge computing security verification method also includes: during the long-term operation of the system, periodically selecting cold chain logistics transportation terminals that have been in a normal state for a preset period of time as samples, and updating the normalized scaling factor, monitoring threshold and recovery threshold based on their state security index Safety(k) and sequence anomaly characteristics for the most recent multiple detection cycles, so as to make the security verification strategy adapt to the long-term changes in network environment and business characteristics.

[0221] Optionally, the edge computing security verification method further includes: after the cumulative recovery score reaches the recovery threshold and the isolation is lifted, if the same cold chain logistics transportation terminal triggers isolation again within a preset number of times, the management module increases the recovery threshold corresponding to the cold chain logistics transportation terminal and / or increases the number of continuous detection cycles required to lift the isolation, so as to implement a more stringent recovery strategy for frequently abnormal cold chain logistics transportation terminals.

[0222] In this embodiment, through the layered collaboration of the access module, anomaly verification module, early warning module, and management module, the system can automatically complete the entire closed loop of cold chain logistics transportation terminal identity verification, behavior anomaly quantification, risk level judgment, and hierarchical access management. This transforms security verification from traditional single-point detection to a multi-dimensional, multi-stage, and automated comprehensive judgment framework, ensuring that the system exhibits a higher degree of intelligence and business adaptability in complex cold chain transportation scenarios.

[0223] Example 2: This example should be understood as including all the features of any of the foregoing examples, and further improving upon them, according to... Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 ,as well as Figure 6 As shown, the management module also includes an urgent delivery adjustment unit. When the early warning module outputs that a cold chain logistics transportation terminal has an abnormal risk and the management module is preparing to implement access restrictions or isolation on the cold chain logistics transportation terminal, the urgent delivery adjustment unit is used to dynamically adjust the security control strategy and delivery execution strategy by comprehensively considering the business attributes of the current cold chain transportation task, so as to ensure that the cold chain delivery task is completed on time as much as possible under the premise that the security risk is controllable.

[0224] Optional, such as Figure 3 As shown, the urgent delivery adjustment unit includes a task attribute acquisition subunit, a strategy matching subunit, and a response execution subunit. The task attribute acquisition subunit is used to acquire transportation task attribute information bound to the current cold chain logistics transportation terminal from the cold chain task management system or scheduling platform. The task attribute information includes at least: task urgency level (ordinary delivery, expedited delivery, near-expiry delivery, etc.), cargo sensitivity level (regular fresh produce, high-value fresh produce, medicines, vaccines, blood products, etc.), customer personalized requirements (e.g., whether interrupted monitoring is allowed, whether seamless temperature control data is required throughout the process, tolerance range for arrival time deviation), current transportation stage (outbound loading stage, in-transit operation stage, arrival and delivery stage), and current temperature control risk status (e.g., whether the temperature deviation is close to the warning threshold, whether one or more temperature control warnings have been triggered).

[0225] The task attribute acquisition subunit organizes the above information into a task risk feature vector, and inputs it into the strategy matching subunit along with the risk level output by the early warning module.

[0226] The task attribute acquisition subunit maps different types of task attributes to discrete risk level values ​​according to preset encoding rules, and organizes them in a fixed order to form a task risk feature vector. For example, task urgency, cargo sensitivity level, customer personalized requirements, transportation stage, and temperature control risk can be denoted as R_urg, R_sens, R_cust, R_phase, and R_temp, respectively, and the above five dimensions are organized into a task risk feature vector in the form R_task=(R_urg, R_sens, R_cust, R_phase, R_temp).

[0227] Wherein: R_urg takes values ​​from 0 to 2, representing regular delivery, expedited delivery, and near-expiry / emergency delivery respectively; its values ​​correspond to regular delivery (estimated arrival time ≥ 120 minutes remaining before delivery deadline), expedited delivery (30-120 minutes remaining), and near-expiry / emergency delivery (< 30 minutes remaining); R_sens takes values ​​from 0 to 3, representing general fresh produce, high-value fresh produce, pharmaceuticals, and highly sensitive goods such as vaccines / blood products respectively; R_cust takes values ​​from 0 to 2, representing no strong monitoring constraints, continuous process monitoring required, and uninterrupted monitoring required throughout the entire process respectively; R_phase takes values ​​from 0 to 2, corresponding to the outbound loading stage (vehicle not yet dispatched or located in the warehouse area), the en route stage (task status is in transit), and the arrival and delivery stage (vehicle enters the station area or task status is pending signature); R_temp takes values ​​from 0 to 2, corresponding to the temperature being within the target range for the most recent three monitoring cycles, temperature fluctuations approaching the warning threshold in at least one cycle, and a recent temperature over-limit warning being triggered respectively.

[0228] The task attribute acquisition subunit encodes business attributes from different sources into a structured task risk feature vector R_{task}, and inputs it along with the security risk level output by the early warning module into the strategy matching subunit for subsequent matching decisions between security control modes and delivery adjustment strategies.

[0229] For example, in a cold chain task, the transported goods are highly sensitive vaccines, the task is marked as expedited delivery, the customer requires uninterrupted temperature control monitoring throughout the entire process, the task is currently in transit, and the temperature has repeatedly approached the warning threshold in recent monitoring cycles. The task attribute acquisition subunit can encode this task as: R_{urg} = 1 (expedited delivery), R_{sens} = 3 (vaccines / blood products), R_{cust} = 2 (uninterrupted monitoring throughout the entire process), R_{phase} = 1 (in transit), R_{temp} = 1 (approaching the warning threshold), thus obtaining the task risk feature vector R_{task} = (1, 3, 2, 1, 1). Upon receiving this vector and the high-risk level label, the strategy matching subunit can prioritize soft isolation or bandwidth limiting modes, avoiding hard isolation strategies that would cause monitoring interruptions.

[0230] The strategy matching subunit is used to determine the applicable security control mode and delivery adjustment strategy based on the combination of security risk level and task attributes.

[0231] When the risk level is high, and the goods are highly sensitive goods such as vaccines and blood products, and the current temperature control is fluctuating greatly, the strategy matching subunit can choose to increase the security verification strength, shorten the testing cycle, and implement hard isolation or mandatory recertification when necessary.

[0232] When the risk level is high but the task is nearing delivery, and the customer requires that monitoring should not be interrupted, the strategy matching subunit can choose soft isolation or bandwidth limitation mode. That is, it prohibits the cold chain logistics transportation terminal from initiating high-risk operations such as configuration changes and control commands, but still retains the reporting channels for core monitoring data such as temperature, humidity, and location to ensure that the delivery task is not interrupted.

[0233] When the risk level is medium risk and the task urgency is expedited delivery, and the goods type is general fresh produce, the delayed isolation mode can be selected. This means that monitoring and alarms are strengthened within a limited grace period. If the Safety(k) status index returns to the normal range within the grace period, isolation will not be implemented; otherwise, isolation will be implemented after the grace period ends, and the backup delivery strategy will be triggered in advance.

[0234] The strategy matching subunit pre-sets multiple sets of risk level-task attribute-control mode mapping rules, enabling the system to automatically select appropriate security verification and delivery collaboration strategies when facing different business scenarios.

[0235] The strategy matching subunit not only determines the corresponding safety control mode based on the task risk feature vector R_task and the safety risk level, but also generates a delivery decision tag DeliveryTag to indicate whether the dispatching system needs to perform collaborative delivery operations.

[0236] The DeliveryTag is used to indicate whether adjustments to the delivery strategy are needed. The DeliveryTag is a discrete field, and its values ​​include: no adjustment required, delayed isolation and enhanced monitoring required, advance reassignment of backup vehicles required, adjustment of delivery time window required, and triggering service reminders to customers required.

[0237] When a DeliveryTag indicates a need to adjust the delivery strategy, the response execution subunit sends a coordination instruction to the cold chain dispatch system based on the tag, enabling the synchronized execution of safety and delivery strategies. For example, when the risk level is high and the goods are highly sensitive items such as vaccines or blood products, and temperature control limits are exceeded, the response execution subunit sends a backup vehicle pick-up instruction to the dispatch system. When the risk level is high and the transportation task is nearing delivery, and the customer requires uninterrupted monitoring throughout the process, the response execution subunit implements soft isolation for the cold chain logistics transportation terminal, prohibiting configuration changes but allowing monitoring data to continue to be reported. When the risk level is medium risk and the task is expedited delivery, the response execution subunit initiates delay isolation logic and strengthens monitoring during the grace period. In near-delay tasks, the response execution subunit can send an expected delay reminder to the dispatch system to adjust the delivery time window.

[0238] The system achieves coordinated operation of security control and delivery business through the strategy matching subunit and response execution subunit, enabling the system to ensure the timely fulfillment of cold chain tasks under the premise of controllable security risks.

[0239] The response execution subunit is used to issue specific execution instructions to the external scheduling system connected to the management module based on the output of the strategy matching subunit.

[0240] When the soft isolation mode is selected, the response execution subunit control management module restricts write operations and configuration change operations on the cold chain logistics transportation terminal, while maintaining read-only reception of monitoring data.

[0241] When selecting the bandwidth limiting mode, control the data reporting frequency and bandwidth usage of cold chain logistics transportation terminals to reduce the potential attack surface while ensuring that the security status is observable.

[0242] like Figure 4 As shown, when the delivery plan needs to be adjusted, the response execution subunit sends the current risk status, task urgency and estimated arrival time of the cold chain logistics transportation terminal to the dispatch system, which then decides whether to dispatch a backup vehicle, adjust the delivery time window or send a service reminder to the customer.

[0243] The response execution subunit enables the linkage between safety control strategies and delivery execution strategies.

[0244] In addition, the response execution subunit does not only enforce access restrictions within the security system, but can also synchronously send business parameters such as security risk level, task urgency, cargo sensitivity, and estimated arrival time to the external dispatch system, so that the dispatch system can execute vehicle reassignment, delivery time adjustment, or customer notification delivery strategies accordingly.

[0245] By employing tiered isolation strategies such as soft isolation, bandwidth limiting, and delay isolation, the temperature control monitoring link can be maintained uninterrupted even in the event of anomalies in cold chain logistics transportation terminals. This resolves the structural contradiction in existing technologies where isolation leads to delivery task interruptions in cold chain transportation scenarios, thus forming a collaborative control mechanism that balances security and business continuity. This mechanism and its linkage strategies are unprecedented in this field and possess significant non-obviousness.

[0246] The task attribute acquisition subunit provides multi-dimensional task feature input, which is combined with the multi-strategy mapping rules preset in the strategy matching subunit for different combination scenarios. Then, the response execution subunit implements specific restriction strategies or task adjustment actions. The collaborative work of the three enables the system to execute differentiated safety strategies for different cargo types, different customer requirements and different transportation stages, ensuring that the system has stronger adaptability and fine-grained risk control capabilities in highly diverse cold chain transportation scenarios.

[0247] The content disclosed above is only a preferred and feasible embodiment of the present invention, and is not intended to limit the scope of protection of the present invention. Therefore, all equivalent technical changes made based on the content of the present invention specification and drawings are included within the scope of protection of the present invention. Furthermore, the elements therein can be updated as technology develops.

Claims

1. An edge computing security verification system for cold chain logistics transportation terminals, characterized in that, It includes a server, a connection access module, an anomaly verification module, an early warning module, and a management module, wherein the server is connected to the connection access module, the anomaly verification module, the early warning module, and the management module respectively; The connection access module is used for access by cold chain logistics transportation terminals, and collects the identity data, configuration parameters and mapping information of the cold chain logistics transportation terminals. It also performs an association consistency check on the configuration parameters and mapping information to generate association status data for subsequent security verification. The anomaly verification module is used to obtain the connection status sequence within a preset detection period based on the associated status data, and to extract statistical features from the connection status sequence to calculate the status security index of the cold chain logistics transportation terminal, so as to realize the dynamic quantitative evaluation of the connection behavior of the cold chain logistics transportation terminal. The early warning module is used to trigger an early warning when the status safety index is lower than the monitoring threshold, and output information including the anomaly type, associated cold chain logistics transportation terminal and risk level to the management module. The management module is used to perform hierarchical access management on cold chain logistics transportation terminals according to the risk level output by the early warning module, and to continuously record the safety indicators of the isolated cold chain logistics transportation terminals for subsequent recovery assessment.

2. The edge computing security verification system for cold chain logistics transportation terminals according to claim 1, characterized in that, The association consistency detection in the connection access module includes: verifying the consistency of device ID, MAC address, IP address or network routing indication information between the configuration parameters of the cold chain logistics transportation terminal and its mapping information, so as to detect fake cold chain logistics transportation terminals or abnormal mapping.

3. The edge computing security verification system for cold chain logistics transportation terminals according to claim 2, characterized in that, The access management includes abnormal access restrictions, port isolation, IP / MAC blocking, or resource queue removal.

4. The edge computing security verification system for cold chain logistics transportation terminals according to claim 3, characterized in that, The anomaly verification module includes a data verification unit and an evaluation unit. The data verification unit is used to continuously acquire the connection behavior information of the cold chain logistics transportation terminal according to the sampling frequency within a preset detection period, and organize data such as handshake delay, GPS location reporting interval, packet loss rate, connection retry count, and port reachability into a connection state sequence V={v1, v2, ..., v_m} in chronological order. The evaluation unit is used to perform statistical feature extraction on the connected state sequence, including calculating the sequence mean, variance or standard deviation, and calculating the probability features of each state value based on a statistical model to generate a state safety index.

5. The edge computing security verification system for cold chain logistics transportation terminals according to claim 4, characterized in that, The connection access module includes a consistency detection unit, an access connection management unit, and a mapping status monitoring unit. The consistency detection unit is used to compare the key fields between the configuration parameters of the cold chain logistics transportation terminal and the mapping information to determine whether the mapping relationship between the cold chain logistics transportation terminal and the terminal has been forged or tampered with. The access connection management unit is used to generate an access connection code or connection credential for the cold chain logistics transportation terminal after the consistency detection is passed. The mapping status monitoring unit is used to continuously monitor the mapping records between the cold chain logistics transportation terminal and the server and feed back any changes to the anomaly verification module.

6. The edge computing security verification system for cold chain logistics transportation terminals according to claim 4 or 5, characterized in that, The early warning module determines the risk level based on the deviation of the state security index from the monitoring threshold, and uses the risk level as the input condition for hierarchical access management, enabling the management module to execute differentiated security control strategies based on different degrees of deviation.

7. The edge computing security verification system for cold chain logistics transportation terminals according to claim 6, characterized in that, The management module calculates a total safety score based on historical safety indicator data recorded for the isolated cold chain logistics transportation terminal, compares it with a preset recovery threshold, and releases the isolation of the cold chain logistics transportation terminal when the total safety score reaches the recovery threshold.

8. An edge computing security verification method for a cold chain logistics transportation terminal, applied to the edge computing security verification system for the cold chain logistics transportation terminal as described in claim 7, characterized in that, The edge computing security verification method includes the following steps: S1. Obtain the identity data, configuration parameters, and mapping information of the cold chain logistics transportation terminal through the connection access module, and perform an association consistency check. If the check passes, generate an access connection credential for the cold chain logistics transportation terminal; if the check fails, directly deny access and record the reason for the exception. S2. In each detection cycle, the connection behavior indicators of the cold chain logistics transportation terminal are collected through the data verification unit and organized into a connection status sequence according to the sampling time order. S3. Extract statistical features based on the connection state sequence, calculate the sequence anomaly metric A_{med}(k), and further calculate the state safety index Safety(k) for this detection period. S4. Compare Safety(k) with the monitoring threshold T: When Safety(k) ≥ T, it is determined that the connection behavior of the cold chain logistics transportation terminal is within the normal range, no warning is triggered, the existing access permissions are maintained, and Safety(k) is recorded for subsequent trend analysis. When Safety(k) < T, an early warning is triggered, and the management module performs access restrictions, downgrades, or puts the cold chain logistics transportation terminal into isolation. S5. When the cold chain logistics transportation terminal is in an isolated state, Safety(k) is calculated again in each detection cycle, and RecoverTotalSafetyScore(k) is calculated. S6. Determine whether to lift the isolation based on RecoverTotalSafetyScore(k) and the recovery threshold.

9. The edge computing security verification method for cold chain logistics transportation terminals according to claim 8, characterized in that, The edge computing security verification method further includes: In step S3, the calculation of the state safety index Safety includes analyzing the stability and volatility of the connection state sequence, and generating a state safety index Safety(k) to characterize the safety of the connection behavior in the current detection period by combining the abnormal characteristics of the sequence.

10. The edge computing security verification method for cold chain logistics transportation terminals according to claim 9, characterized in that, The edge computing security verification method further includes: in step S6, the determination of de-isolation is based on the comparison result of the total recovery security score and the recovery threshold. When the total recovery security score is greater than or equal to the preset recovery threshold in multiple consecutive detection cycles, the recovery operation is performed to avoid false recovery due to occasional improvement in individual cycles.

Citation Information

Patent Citations

  • Cold-chain logistics transportation system

    CN110942270A