Multi-domain isolation control method and system for Internet of Things platform
By identifying independent business entities within the IoT platform, adjusting their external interface status, and establishing separate connection permissions, the problems of business crosstalk and device permission abuse in IoT industrial scenarios are solved. This achieves multi-domain isolation at the data and business levels, improving the security and reliability of IoT.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUIZHIAN INFORMATION TECH CO LTD
- Filing Date
- 2025-12-23
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies have failed to effectively address issues such as crosstalk between business processes, abuse of device connection permissions, and unauthorized data access in IoT industrial scenarios, leading to insecure IoT operation and reduced business operation independence and reliability.
By identifying independent business entities within the IoT platform, adjusting their external interface status, establishing separate connection permissions, and performing isolated flow processing and access policy adjustments, multi-domain isolation at the data and business levels can be achieved.
It ensures the security and reliability of the IoT platform, avoids crosstalk between services and chaotic device operation, prevents data transmission across services, and reduces security risks.
Smart Images

Figure CN121907516A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) security, and more particularly to a multi-domain isolation control method and system for IoT platforms. Background Technology
[0002] Currently, technologies such as asymmetric encryption, certificate verification, and access control are widely used in IoT security maintenance. However, these technologies only focus on the security of the underlying IoT technology stack. Considering the widespread adoption of IoT in industrial scenarios, it needs to interface with systems in different industrial environments, making the integration of IoT into these systems highly complex. Existing technologies have not effectively addressed the business security issues arising from the application of IoT in industrial scenarios. This leads to vulnerabilities such as crosstalk between business processes, abuse of device connection permissions by different businesses, and unauthorized data access and transmission. Furthermore, the inability to implement multi-domain isolation and control of business processes within the IoT results in an insecure operational state for the entire IoT system. This reduces the independence and reliability of IoT operations and hinders timely and effective prevention of potential threats during IoT operation. Summary of the Invention
[0003] The purpose of this invention is to provide a multi-domain isolation control method and system for IoT platforms. Based on the business dynamic information of the IoT platform, it identifies independent business entities within the platform and adjusts the working status of their external interfaces based on the operational attributes of these independent business entities, preventing crosstalk caused by arbitrary communication between different independent businesses. Based on the external interfaces of the independent business entities matched with devices within the IoT platform, it constructs separate connection permissions for each independent business entity and device, managing these connection permissions separately to prevent multiple businesses from simultaneously sharing connection permissions, thus avoiding device malfunctions. Based on these separate connection permissions, it isolates and processes the device's operational data and adjusts the device's access policies for matched independent business entities, preventing data transmission across businesses. This achieves data transmission isolation at both the software and hardware levels and minimizes potential security risks caused by device access policies, implementing multi-domain isolation for the IoT platform at both the data and business levels to ensure the security and reliability of IoT operation.
[0004] This invention is achieved through the following technical solution:
[0005] Multi-domain isolation control methods for IoT platforms include:
[0006] Based on the business dynamic information of the IoT platform, identify independent business entities within the IoT platform; based on the operational attributes of the independent business entities, adjust the working status of the external interfaces of the independent business entities;
[0007] Based on the interaction requirements of the device requesting access to the IoT platform, an independent business entity matching the device is determined within the IoT platform; based on the external interface of the matched independent business entity, a separate connection permission for the matched independent business entity to the device is constructed.
[0008] Based on the individual connection permission, the operational data of the device is isolated and processed; based on the working status of the device, the access policy of the device to the matched independent business entity is adjusted.
[0009] Optionally, based on the business dynamic information of the IoT platform, independent business entities within the IoT platform are identified; based on the operational attributes of the independent business entities, the working status of their external interfaces is adjusted, including:
[0010] The system monitors the business construction end of the IoT platform to obtain dynamic information on the business construction progress of the IoT platform; based on the dynamic information on the business construction progress, it identifies all completed businesses within the IoT platform; based on the structural attributes of each completed business, it identifies independent business entities within the IoT platform; wherein, the structural attributes include the completeness of each sub-business within the completed business and the external connection status of each sub-business.
[0011] Obtain the time-domain variation information of the operating load of each sub-business under the independent business entity; determine the allowed external connection time interval of the independent business entity based on the time-domain variation information of the operating load; adjust the external interface opening time interval of the independent business entity based on the allowed external connection time interval.
[0012] Based on the aforementioned time-domain variation information of the operating load, the permitted external connection time interval for the independent business entity is determined, including:
[0013] Retrieve the operational load perspective change information of independent business entities, and use the operational load perspective change information as time series data L={L1, L2, ..., L...} n}, where n represents the total number of observation time points; L1, L2, ..., L n These represent the load field of view changes at each observation time point;
[0014] Using the time series data L={L1, L2, ..., L n Obtain the root mean square rate of change of load R;
[0015] The root mean square rate of change of load R is obtained by the following formula:
[0016]
[0017] Where R represents the root mean square rate of change of the load; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point; L x This represents the average value of load field of view variation information;
[0018] Retrieve time series data L={L1, L2, ..., L n The maximum value of load field of view change information max(L) and the minimum value of load field of view change information min(L) in};
[0019] The load peak concentration P is obtained by using the maximum value max(L) and the minimum value min(L) of the load field change information.
[0020] The load peak concentration P is obtained by the following formula:
[0021]
[0022] Where P represents the peak load concentration; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; x This represents the average value of load field of view variation information;
[0023] Using the time series data L={L1, L2, ..., L n The load trend fluctuation index T is obtained from each load field change information contained in};
[0024] The load trend fluctuation index T is obtained by the following formula:
[0025]
[0026] Where T represents the load trend fluctuation index; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point;
[0027] The load variation parameter C is obtained using the root mean square rate of change of load R, the peak load concentration P, and the load trend fluctuation index T.
[0028] The load variation parameter C is obtained by the following formula:
[0029]
[0030] Where C represents the load variation parameter; T represents the load trend fluctuation index; P represents the load peak concentration; and R represents the root mean square rate of change of load.
[0031] The load change parameter C is compared with a preset parameter threshold. When the load change parameter C exceeds the preset parameter threshold, the allowed external connection time interval needs to be adjusted.
[0032] Optionally, based on the interaction requirements of the device requesting access to the IoT platform, an independent business entity matching the device within the IoT platform is determined; based on the external interface of the matched independent business entity, a separate connection permission for the matched independent business entity to the device is constructed, including:
[0033] The connection request initiated by the device requesting access to the IoT platform is parsed and processed to obtain the interaction requirements of the task to be processed by the device; wherein, the interaction requirements include the data type and data volume of the task to be processed that need to be processed by the IoT platform.
[0034] Based on the interaction requirements and the data processing efficiency between each independent business entity within the IoT platform, the independent business entity matching the device within the IoT platform is determined.
[0035] Based on the open time range of the external interface of the matched independent business entity and the hardware identity information of the device, a time-restricted exclusive connection permission for the matched independent business entity to the device is constructed.
[0036] Optionally, based on the individual connection permission, the operational data of the device is isolated and processed; based on the working status of the device, the access policy of the device to the matched independent business entity is adjusted, including:
[0037] Based on the effective duration range of the individual connection permission, the operational data uploaded by the device is identified, and it is determined whether the operational data can be uploaded within the effective duration range; if not, the part of the operational data that has not been uploaded is isolated and intercepted.
[0038] The device's work logs are analyzed to determine whether any security anomalies occur during operation. Based on the predicted occurrence time of the security anomalies, the device's access data range and the amount of data allowed to be accessed at one time are adjusted within the matched independent business entity.
[0039] A multi-domain isolation control system for IoT platforms includes:
[0040] The independent business entity identification module is used to identify independent business entities within the Internet of Things (IoT) platform based on the business dynamic information of the IoT platform.
[0041] The external interface status adjustment module is used to adjust the working status of the external interface of the independent business entity based on the running attributes of the independent business entity.
[0042] The independent business entity matching module is used to determine the independent business entity within the IoT platform that matches the device based on the interaction requirements of the device requesting access to the IoT platform.
[0043] The connection permission construction module is used to construct the individual connection permissions of the matched independent business entity to the device based on the external interface of the matched independent business entity.
[0044] The data isolation and transfer module is used to isolate and transfer the operational data of the device based on the individual connection permission.
[0045] The access policy adjustment module is used to adjust the access policy of the device for the matched independent business entity based on the working status of the device.
[0046] Optionally, the independent business entity identification module is used to identify independent business entities within the IoT platform based on the business dynamic information of the IoT platform, including:
[0047] The system monitors the business construction end of the IoT platform to obtain dynamic information on the business construction progress of the IoT platform; based on the dynamic information on the business construction progress, it identifies all completed businesses within the IoT platform; based on the structural attributes of each completed business, it identifies independent business entities within the IoT platform; wherein, the structural attributes include the completeness of each sub-business within the completed business and the external connection status of each sub-business.
[0048] The external interface status adjustment module is used to adjust the working status of the external interface of the independent business entity based on the operating attributes of the independent business entity, including:
[0049] Obtain the time-domain variation information of the operating load of each sub-business under the independent business entity; determine the allowed external connection time interval of the independent business entity based on the time-domain variation information of the operating load; adjust the external interface opening time interval of the independent business entity based on the allowed external connection time interval.
[0050] Based on the aforementioned time-domain variation information of the operating load, the permitted external connection time interval for the independent business entity is determined, including:
[0051] Retrieve the operational load perspective change information of independent business entities, and use the operational load perspective change information as time series data L={L1, L2, ..., L...} n}, where n represents the total number of observation time points; L1, L2, ..., L n These represent the load field of view changes at each observation time point;
[0052] Using the time series data L={L1, L2, ..., L n Obtain the root mean square rate of change of load R;
[0053] The root mean square rate of change of load R is obtained by the following formula:
[0054]
[0055] Where R represents the root mean square rate of change of the load; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point; L x This represents the average value of load field of view variation information;
[0056] Retrieve time series data L={L1, L2, ..., L n The maximum value of load field of view change information max(L) and the minimum value of load field of view change information min(L) in};
[0057] The load peak concentration P is obtained by using the maximum value max(L) and the minimum value min(L) of the load field change information.
[0058] The load peak concentration P is obtained by the following formula:
[0059]
[0060] Where P represents the peak load concentration; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; x This represents the average value of load field of view variation information;
[0061] Using the time series data L={L1, L2, ..., L n The load trend fluctuation index T is obtained from each load field change information contained in};
[0062] The load trend fluctuation index T is obtained by the following formula:
[0063]
[0064] Where T represents the load trend fluctuation index; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point;
[0065] The load variation parameter C is obtained using the root mean square rate of change of load R, the peak load concentration P, and the load trend fluctuation index T.
[0066] The load variation parameter C is obtained by the following formula:
[0067]
[0068] Where C represents the load variation parameter; T represents the load trend fluctuation index; P represents the load peak concentration; and R represents the root mean square rate of change of load.
[0069] The load change parameter C is compared with a preset parameter threshold. When the load change parameter C exceeds the preset parameter threshold, the allowed external connection time interval needs to be adjusted.
[0070] Optionally, the independent business entity matching module is used to determine, based on the interaction requirements of a device requesting access to the IoT platform, an independent business entity within the IoT platform that matches the device, including:
[0071] The connection request initiated by the device requesting access to the IoT platform is parsed and processed to obtain the interaction requirements of the task to be processed by the device; wherein, the interaction requirements include the data type and data volume of the task to be processed that need to be processed by the IoT platform.
[0072] Based on the interaction requirements and the data processing efficiency between each independent business entity within the IoT platform, the independent business entity matching the device within the IoT platform is determined.
[0073] The connection permission construction module is used to construct individual connection permissions for the matching independent business entity to the device based on the external interface of the matching independent business entity, including:
[0074] Based on the open time range of the external interface of the matched independent business entity and the hardware identity information of the device, a time-restricted exclusive connection permission for the matched independent business entity to the device is constructed.
[0075] Optionally, the data isolation and transfer module is used to perform isolated transfer processing on the operational data of the device based on the separate connection permission, including:
[0076] Based on the effective duration range of the individual connection permission, the operational data uploaded by the device is identified, and it is determined whether the operational data can be uploaded within the effective duration range; if not, the part of the operational data that has not been uploaded is isolated and intercepted.
[0077] The access policy adjustment module is used to adjust the access policy of the device for the matched independent business entity based on the working status of the device, including:
[0078] The device's work logs are analyzed to determine whether any security anomalies occur during operation. Based on the predicted occurrence time of the security anomalies, the device's access data range and the amount of data allowed to be accessed at one time are adjusted within the matched independent business entity.
[0079] Compared with the prior art, the present invention has the following beneficial effects:
[0080] The multi-domain isolation control method and system for IoT platforms provided in this application identify independent business entities within the IoT platform based on the platform's dynamic business information. Based on the operational attributes of these independent business entities, the system adjusts their external interface working status to prevent crosstalk caused by arbitrary communication between different independent businesses. Based on the external interfaces of the independent business entities matched with devices within the IoT platform, the system constructs separate connection permissions between the independent business entities and the devices, managing these permissions separately to prevent multiple businesses from simultaneously sharing connection permissions and causing operational chaos. Based on these separate connection permissions, the system isolates and processes the device's operational data and adjusts the device's access policies for matched independent business entities to prevent cross-business data transmission. This achieves data transmission isolation at both the software and hardware levels and minimizes potential security risks caused by device access policies. The system implements multi-domain isolation for the IoT platform at both the data and business levels, ensuring the security and reliability of IoT operations. Attached Figure Description
[0081] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:
[0082] Figure 1This is a flowchart illustrating the multi-domain isolation control method for IoT platforms provided by the present invention.
[0083] Figure 2 This is a schematic diagram of the structure of the multi-domain isolation control system for the Internet of Things platform provided by the present invention. Detailed Implementation
[0084] To make the above-mentioned objectives, features, and advantages of this application more apparent and understandable, the specific embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, it should be noted that, for ease of description, only the parts relevant to this application are shown in the accompanying drawings, not the entire structure. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of this application.
[0085] The terms “comprising” and “having”, and any variations thereof, used in this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.
[0086] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0087] Please see Figure 1 As shown, an embodiment of this application provides a multi-domain isolation control method for an Internet of Things (IoT) platform. This multi-domain isolation control method for an IoT platform includes:
[0088] Based on the business dynamic information of the IoT platform, identify independent business entities within the IoT platform; based on the operational attributes of independent business entities, adjust the working status of their external interfaces.
[0089] Based on the interaction requirements of devices requesting access to the IoT platform, identify independent business entities within the IoT platform that match the devices; based on the external interfaces of the matched independent business entities, construct separate connection permissions for the matched independent business entities to the devices.
[0090] Based on individual connection permissions, the operational data of the device is processed in an isolated manner; based on the working status of the device, the access policy of the device to the matching independent business entities is adjusted.
[0091] The beneficial effects of the above embodiments are as follows: This multi-domain isolation control method for IoT platforms identifies independent business entities within the IoT platform based on the platform's dynamic business information, and adjusts the working status of their external interfaces based on the operational attributes of these independent business entities, thus avoiding crosstalk caused by arbitrary communication between different independent businesses. Based on the external interfaces of the independent business entities matched with the devices within the IoT platform, it constructs separate connection permissions matching the independent business entities and the devices, and manages these connection permissions separately, preventing multiple businesses from simultaneously sharing connection permissions and causing device malfunctions. Based on these separate connection permissions, it isolates and processes the device's operational data and adjusts the device's access policies for the matched independent business entities, preventing data transmission across businesses. This achieves data transmission isolation at both the software and hardware levels, minimizes potential security risks caused by device access policies, and implements multi-domain isolation for the IoT platform at both the data and business levels, ensuring the security and reliability of IoT operation.
[0092] In another embodiment, based on the business dynamic information of the IoT platform, independent business entities within the IoT platform are identified; based on the operational attributes of the independent business entities, the working status of their external interfaces is adjusted, including:
[0093] The system monitors the business construction end of the IoT platform to obtain dynamic information on the business construction progress. Based on this dynamic information, it identifies all completed businesses within the IoT platform. Based on the structural attributes of each completed business, it identifies independent business entities within the IoT platform. The structural attributes include the completeness of each sub-business within a completed business and the external connection status of each sub-business.
[0094] Obtain the time-domain change information of the operating load of each sub-business under the independent business entity; based on the time-domain change information of the operating load, determine the allowed external connection time interval of the independent business entity; based on the allowed external connection time interval, adjust the opening time interval of the external interface of the independent business entity.
[0095] The beneficial effects of the above embodiments are that the IoT platform (i.e., the IoT operating system platform) can execute corresponding business operations in different industrial scenarios, thereby achieving good integration with industrial scenarios. The IoT platform can integrate or build multiple businesses simultaneously according to its actual operational needs, that is, integrate and associate multiple sub-businesses to form a complete business, or correct multiple sub-businesses and then build a complete business. The IoT platform uses an internal computer terminal as the business building end for business construction. However, the construction progress of different businesses varies on the business building end. Considering that the IoT platform needs to be in a complete state before calling and executing the corresponding business, in order to ensure the reliability of the IoT platform's business operation, it is necessary to monitor the business building end to obtain dynamic progress information during the business building process, thereby comprehensively grasping the completion progress of the business building end. Based on the dynamic information of business building progress, all completed businesses within the IoT platform are periodically selected. Next, business structure identification is performed on all completed services to obtain the completeness and external connectivity status of all sub-services within each completed service. The completeness of a sub-service refers to whether it fully includes all the necessary plugins for its operation, and the external connectivity status refers to whether the sub-task block needs to communicate and interact with the outside world during operation. If all sub-services within a completed service fully include all the necessary plugins for its operation and none of the sub-services need to communicate and interact with the outside world during operation, then the completed service is identified as an independent business entity; otherwise, it is not identified as an independent business entity. Furthermore, the time-domain variation information of the operating load of each sub-service under the independent business entity is obtained, i.e., the change in the operating load of each sub-service over time during operation. Based on the time-domain variation information of the operating load of each sub-service, the change in the overall operating load of the independent business entity over time during operation is determined. If the overall operating load value of the independent business entity during a certain time interval is less than a preset load threshold, then the aforementioned time interval is determined as the allowed external connectivity time interval for the independent business entity. Then, the time interval with the longest duration among all the allowed external connection time intervals of the independent business entity is used as the external interface opening time interval of the independent business entity. This allows the independent business entity to open an appropriate number of external interfaces, avoiding the independent business entity from frequently making external connections and affecting its normal operation.
[0096] In another embodiment, determining the allowed external connection time interval for the independent business entity based on the operational load time-domain variation information includes:
[0097] Retrieve the operational load perspective change information of independent business entities, and use the operational load perspective change information as time series data L={L1, L2, ..., L...} n}, where n represents the total number of observation time points; L1, L2, ..., L n These represent the load field of view changes at each observation time point;
[0098] Using the time series data L={L1, L2, ..., L n Obtain the root mean square rate of change of load R;
[0099] The root mean square rate of change of load R is obtained by the following formula:
[0100]
[0101] Where R represents the root mean square rate of change of the load; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point; L x This represents the average value of load field of view variation information;
[0102] Retrieve time series data L={L1, L2, ..., L n The maximum value of load field of view change information max(L) and the minimum value of load field of view change information min(L) in};
[0103] The load peak concentration P is obtained by using the maximum value max(L) and the minimum value min(L) of the load field change information.
[0104] The load peak concentration P is obtained by the following formula:
[0105]
[0106] Where P represents the peak load concentration; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; x This represents the average value of load field of view variation information;
[0107] Using the time series data L={L1, L2, ..., L n The load trend fluctuation index T is obtained from each load field change information contained in};
[0108] The load trend fluctuation index T is obtained by the following formula:
[0109]
[0110] Where T represents the load trend fluctuation index; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point;
[0111] The load variation parameter C is obtained using the root mean square rate of change of load R, the peak load concentration P, and the load trend fluctuation index T.
[0112] The load variation parameter C is obtained by the following formula:
[0113]
[0114] Where C represents the load variation parameter; T represents the load trend fluctuation index; P represents the load peak concentration; and R represents the root mean square rate of change of load.
[0115] The load change parameter C is compared with a preset parameter threshold. When the load change parameter C exceeds the preset parameter threshold, the allowed external connection time interval needs to be adjusted.
[0116] The beneficial effects of the above embodiments are that they achieve accurate quantitative assessment of the degree of load change. By constructing three-dimensional parameters—the root mean square rate of change of load (R), the peak load concentration (P), and the load trend fluctuation index (T)—these parameters characterize the time-domain characteristics of load change from three core dimensions: "the severity of load fluctuations," "peak clustering characteristics," and "trend stability." Compared with single-dimensional assessment indicators, this approach can comprehensively capture the complex patterns of load changes. Furthermore, through root mean square calculation, mean normalization, and the introduction of a zero constant ε, the interference from load magnitude differences, extreme data, and zero values is effectively avoided, improving the objectivity and accuracy of the quantitative results. The root mean square rate of change of load (R) focuses on the fluctuation amplitude of load at adjacent time points, accurately reflecting the severity of short-term load fluctuations. The peak load concentration (P) is calculated by correlating the maximum, minimum, and mean values, highlighting the clustering effect of load peaks and the degree of deviation from the norm. The load trend fluctuation index (T) emphasizes the continuous trend of load changes, capturing long-term fluctuation patterns. These three parameters work together to cover all dimensions of short-term fluctuations, peak characteristics, and long-term trends, ensuring a complete characterization of the time-domain load change state and providing comprehensive data support for time interval adjustments. To enhance the scientific rigor and reliability of external connectivity time interval adjustments, a comprehensive load change parameter C is derived by integrating three-dimensional parameters. This avoids the limitations of single-parameter assessments and ensures that the evaluation of the impact of load changes on external connectivity better aligns with actual business operation logic. Adjustment decisions are based on a comparison of parameter C with preset thresholds, establishing standardized and quantifiable judgment criteria to replace subjective experience-based judgments, reduce human error, ensure the accuracy of adjustment timing, and guarantee dynamic adaptation between external connectivity and business load. By accurately characterizing load changes over time and dynamically adjusting external connectivity time intervals, resource conflicts caused by external connectivity during periods of high load fluctuations and peak concentration can be effectively avoided, reducing operational pressure. Simultaneously, it ensures the normal operation of external connectivity during periods of low load fluctuations, improving resource utilization and achieving a balance between operational stability and external connectivity efficiency.
[0117] In another embodiment, based on the interaction requirements of the device requesting access to the IoT platform, an independent business entity matching the device within the IoT platform is determined; based on the external interface of the matching independent business entity, a separate connection permission for the matching independent business entity to the device is constructed, including:
[0118] The connection request initiated by the device requesting access to the IoT platform is parsed and processed to obtain the interaction requirements of the device's pending task; among which, the interaction requirements include the data type and data volume of the task to be processed by the IoT platform.
[0119] Based on the interaction requirements and the data processing efficiency between each independent business entity within the IoT platform, the independent business entities that match the devices within the IoT platform are determined.
[0120] Based on the open time range of the external interfaces of the matched independent business entities and the hardware identity information of the devices, a time-restricted individual connection permission for the matched independent business entities to the devices is constructed.
[0121] The beneficial effects of the above embodiments are that when an IoT platform is applied to different industrial scenarios, it needs to interact with corresponding devices within those scenarios to achieve device control. Typically, the IoT platform processes task data from the devices through its own internal independent business entities to achieve this interaction. Different devices perform different tasks, leading to varying interaction requirements between them and the IoT platform. To ensure matched interaction for each device, the connection requests initiated by devices requesting access to the IoT platform are first parsed to obtain the data type and volume of the task to be processed. The data processing performance of all independent business entities within the IoT platform varies. This difference is mainly reflected in the different data types that different independent business entities can process, and the different data volume processing caps for different independent business entities. This results in different processing times required for different independent business entities to process task data of the same type and volume. To enable the IoT platform to efficiently process task data from devices by calling appropriate independent business entities, the processing time of all independent business entities within the IoT platform is determined based on the data type and volume of the tasks to be processed by the device and the IoT platform. This timeframe serves as the data processing efficiency between the interaction requirements and each independent business entity within the IoT platform. The independent business entity with the shortest processing time is then selected as the matching independent business entity for the device. Furthermore, based on the open time range of the matching independent business entity's external interface and the device's hardware identity information, a time-restricted exclusive connection permission is established for the matching independent business entity to access the device. This ensures that the matching independent business entity enjoys exclusive connection permission to the device within a predetermined time range, preventing other independent business entities from connecting to the device during this time range. This avoids the sharing of connection permission for the same device among different businesses. The predetermined time range is at least a portion of the open time range of the matching independent business entity's external interface.
[0122] In another embodiment, based on individual connection permissions, the operational data of the device is processed in an isolated manner; based on the device's operating status, the access policy of the device to matching independent business entities is adjusted, including:
[0123] Based on the effective duration range of individual connection permissions, the operational data uploaded by the device is identified to determine whether the operational data can be uploaded within the effective duration range; if not, the part of the operational data that has not been uploaded is isolated and intercepted.
[0124] Analyze the device's work logs to determine if any security anomalies occurred during operation; based on the predicted occurrence time of security anomalies, adjust the device's access data range and the amount of data allowed to be accessed at a time in matching independent business entities.
[0125] The beneficial effect of the above embodiments is that, during the period when the matched independent business entity has exclusive connection rights to the device (i.e., the effective duration of the exclusive connection rights), the operational data uploaded by the device is identified. By combining the total amount of operational data that the device expects to upload and the device's operational data upload rate, the time taken for the device to upload the operational data is estimated, thereby determining whether the operational data can be uploaded within the effective duration. If so, the uploaded operational data continues to be processed within the IoT platform. If not, the unuploaded portion of the operational data is isolated and intercepted, that is, the data portion of the operational data that has not been uploaded to the IoT platform is marked, and the unuploaded data portion continues to be uploaded in the next effective duration, thus avoiding the upload of the unuploaded data portion to other independent business entities and causing cross-business data transmission. Furthermore, the device's operational logs are analyzed to determine whether any security anomalies, such as unauthorized intrusion or hijacking, have occurred during operation. Based on the predicted occurrence time of these security anomalies, the scope of data access and the amount of data allowed to be accessed by the device in matching independent business entities are adjusted. This reduces the scope of data access and the amount of data allowed to be accessed by the device in matching independent business entities during the predicted occurrence time, thus preventing the device's own security risks from being transferred to the IoT platform.
[0126] Please see Figure 2 As shown in one embodiment of this application, a multi-domain isolation control system for an Internet of Things (IoT) platform is provided. This multi-domain isolation control system for an IoT platform includes:
[0127] The independent business entity identification module is used to identify independent business entities within the IoT platform based on business dynamic information from the IoT platform.
[0128] The external interface status adjustment module is used to adjust the working status of the external interface of an independent business entity based on its running attributes.
[0129] The independent business entity matching module is used to determine the independent business entities within the IoT platform that match the devices based on the interaction requirements of the devices requesting access to the IoT platform.
[0130] The connection permission building module is used to build individual connection permissions for a device for a matching independent business entity based on the external interface of the matching independent business entity.
[0131] The data isolation and transfer module is used to isolate and process the operational data of the device based on individual connection permissions;
[0132] The access policy adjustment module is used to adjust the access policy of the device for matching independent business entities based on the device's working status.
[0133] The beneficial effects of the above embodiments are as follows: This multi-domain isolation control system for IoT platforms identifies independent business entities within the IoT platform based on the platform's dynamic business information, and adjusts the working status of their external interfaces based on the operational attributes of these independent business entities, avoiding crosstalk caused by arbitrary communication between different independent businesses; based on the external interfaces of the independent business entities matched with the devices within the IoT platform, it constructs separate connection permissions matching the independent business entities and the devices, and manages these connection permissions separately, preventing multiple businesses from simultaneously sharing connection permissions to the devices, which could lead to device malfunctions; based on these separate connection permissions, it isolates and processes the device's operational data and adjusts the device's access policies for the matched independent business entities, preventing data transmission across businesses, achieving data transmission isolation at both the software and hardware levels, and minimizing potential security risks caused by device access policies. This implements multi-domain isolation for the IoT platform at both the data and business levels, ensuring the security and reliability of IoT operation.
[0134] In another embodiment, the independent business entity identification module is used to identify independent business entities within the IoT platform based on the platform's dynamic business information, including:
[0135] The system monitors the business construction end of the IoT platform to obtain dynamic information on the business construction progress. Based on this dynamic information, it identifies all completed businesses within the IoT platform. Based on the structural attributes of each completed business, it identifies independent business entities within the IoT platform. The structural attributes include the completeness of each sub-business within a completed business and the external connection status of each sub-business.
[0136] The external interface status adjustment module is used to adjust the working status of the external interfaces of independent business entities based on their operational attributes, including:
[0137] Obtain the time-domain change information of the operating load of each sub-business under the independent business entity; based on the time-domain change information of the operating load, determine the allowed external connection time interval of the independent business entity; based on the allowed external connection time interval, adjust the opening time interval of the external interface of the independent business entity.
[0138] The beneficial effects of the above embodiments are that the IoT platform (i.e., the IoT operating system platform) can execute corresponding business operations in different industrial scenarios, thereby achieving good integration with industrial scenarios. The IoT platform can integrate or build multiple businesses simultaneously according to its actual operational needs, that is, integrate and associate multiple sub-businesses to form a complete business, or correct multiple sub-businesses and then build a complete business. The IoT platform uses an internal computer terminal as the business building end for business construction. However, the construction progress of different businesses varies on the business building end. Considering that the IoT platform needs to be in a complete state before calling and executing the corresponding business, in order to ensure the reliability of the IoT platform's business operation, it is necessary to monitor the business building end to obtain dynamic progress information during the business building process, thereby comprehensively grasping the completion progress of the business building end. Based on the dynamic information of business building progress, all completed businesses within the IoT platform are periodically selected. Next, business structure identification is performed on all completed services to obtain the completeness and external connectivity status of all sub-services within each completed service. The completeness of a sub-service refers to whether it fully includes all the necessary plugins for its operation, and the external connectivity status refers to whether the sub-task block needs to communicate and interact with the outside world during operation. If all sub-services within a completed service fully include all the necessary plugins for its operation and none of the sub-services need to communicate and interact with the outside world during operation, then the completed service is identified as an independent business entity; otherwise, it is not identified as an independent business entity. Furthermore, the time-domain variation information of the operating load of each sub-service under the independent business entity is obtained, i.e., the change in the operating load of each sub-service over time during operation. Based on the time-domain variation information of the operating load of each sub-service, the change in the overall operating load of the independent business entity over time during operation is determined. If the overall operating load value of the independent business entity during a certain time interval is less than a preset load threshold, then the aforementioned time interval is determined as the allowed external connectivity time interval for the independent business entity. Then, the time interval with the longest duration among all the allowed external connection time intervals of the independent business entity is used as the external interface opening time interval of the independent business entity. This allows the independent business entity to open an appropriate number of external interfaces, avoiding the independent business entity from frequently making external connections and affecting its normal operation.
[0139] In another embodiment, determining the allowed external connection time interval for the independent business entity based on the operational load time-domain variation information includes:
[0140] Retrieve the operational load perspective change information of independent business entities, and use the operational load perspective change information as time series data L={L1, L2, ..., L...} n}, where n represents the total number of observation time points; L1, L2, ..., L n These represent the load field of view changes at each observation time point;
[0141] Using the time series data L={L1, L2, ..., L n Obtain the root mean square rate of change of load R;
[0142] The root mean square rate of change of load R is obtained by the following formula:
[0143]
[0144] Where R represents the root mean square rate of change of the load; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point; L x This represents the average value of load field of view variation information;
[0145] Retrieve time series data L={L1, L2, ..., L n The maximum value of load field of view change information max(L) and the minimum value of load field of view change information min(L) in};
[0146] The load peak concentration P is obtained by using the maximum value max(L) and the minimum value min(L) of the load field change information.
[0147] The load peak concentration P is obtained by the following formula:
[0148]
[0149] Where P represents the peak load concentration; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; x This represents the average value of load field of view variation information;
[0150] Using the time series data L={L1, L2, ..., L n The load trend fluctuation index T is obtained from each load field change information contained in};
[0151] The load trend fluctuation index T is obtained by the following formula:
[0152]
[0153] Where T represents the load trend fluctuation index; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point;
[0154] The load variation parameter C is obtained using the root mean square rate of change of load R, the peak load concentration P, and the load trend fluctuation index T.
[0155] The load variation parameter C is obtained by the following formula:
[0156]
[0157] Where C represents the load variation parameter; T represents the load trend fluctuation index; P represents the load peak concentration; and R represents the root mean square rate of change of load.
[0158] The load change parameter C is compared with a preset parameter threshold. When the load change parameter C exceeds the preset parameter threshold, the allowed external connection time interval needs to be adjusted.
[0159] The beneficial effects of the above embodiments are that they achieve accurate quantitative assessment of the degree of load change. By constructing three-dimensional parameters—the root mean square rate of change of load (R), the peak load concentration (P), and the load trend fluctuation index (T)—these parameters characterize the time-domain characteristics of load change from three core dimensions: "the severity of load fluctuations," "peak clustering characteristics," and "trend stability." Compared with single-dimensional assessment indicators, this approach can comprehensively capture the complex patterns of load changes. Furthermore, through root mean square calculation, mean normalization, and the introduction of a zero constant ε, the interference from load magnitude differences, extreme data, and zero values is effectively avoided, improving the objectivity and accuracy of the quantitative results. The root mean square rate of change of load (R) focuses on the fluctuation amplitude of load at adjacent time points, accurately reflecting the severity of short-term load fluctuations. The peak load concentration (P) is calculated by correlating the maximum, minimum, and mean values, highlighting the clustering effect of load peaks and the degree of deviation from the norm. The load trend fluctuation index (T) emphasizes the continuous trend of load changes, capturing long-term fluctuation patterns. These three parameters work together to cover all dimensions of short-term fluctuations, peak characteristics, and long-term trends, ensuring a complete characterization of the time-domain load change state and providing comprehensive data support for time interval adjustments. To enhance the scientific rigor and reliability of external connectivity time interval adjustments, a comprehensive load change parameter C is derived by integrating three-dimensional parameters. This avoids the limitations of single-parameter assessments and ensures that the evaluation of the impact of load changes on external connectivity better aligns with actual business operation logic. Adjustment decisions are based on a comparison of parameter C with preset thresholds, establishing standardized and quantifiable judgment criteria to replace subjective experience-based judgments, reduce human error, ensure the accuracy of adjustment timing, and guarantee dynamic adaptation between external connectivity and business load. By accurately characterizing load changes over time and dynamically adjusting external connectivity time intervals, resource conflicts caused by external connectivity during periods of high load fluctuations and peak concentration can be effectively avoided, reducing operational pressure. Simultaneously, it ensures the normal operation of external connectivity during periods of low load fluctuations, improving resource utilization and achieving a balance between operational stability and external connectivity efficiency.
[0160] In another embodiment, the independent business entity matching module is used to determine the independent business entities within the IoT platform that match the devices based on the interaction requirements of the devices requesting access to the IoT platform, including:
[0161] The connection request initiated by the device requesting access to the IoT platform is parsed and processed to obtain the interaction requirements of the device's pending task; among which, the interaction requirements include the data type and data volume of the task to be processed by the IoT platform.
[0162] Based on the interaction requirements and the data processing efficiency between each independent business entity within the IoT platform, the independent business entities that match the devices within the IoT platform are determined.
[0163] The connection permission construction module is used to construct individual connection permissions for a device for a matching independent business entity based on its external interface, including:
[0164] Based on the open time range of the external interfaces of the matched independent business entities and the hardware identity information of the devices, a time-restricted individual connection permission for the matched independent business entities to the devices is constructed.
[0165] The beneficial effects of the above embodiments are that when an IoT platform is applied to different industrial scenarios, it needs to interact with corresponding devices within those scenarios to achieve device control. Typically, the IoT platform processes task data from the devices through its own internal independent business entities to achieve this interaction. Different devices perform different tasks, leading to varying interaction requirements between them and the IoT platform. To ensure matched interaction for each device, the connection requests initiated by devices requesting access to the IoT platform are first parsed to obtain the data type and volume of the task to be processed. The data processing performance of all independent business entities within the IoT platform varies. This difference is mainly reflected in the different data types that different independent business entities can process, and the different data volume processing caps for different independent business entities. This results in different processing times required for different independent business entities to process task data of the same type and volume. To enable the IoT platform to efficiently process task data from devices by calling appropriate independent business entities, the processing time of all independent business entities within the IoT platform is determined based on the data type and volume of the tasks to be processed by the device and the IoT platform. This timeframe serves as the data processing efficiency between the interaction requirements and each independent business entity within the IoT platform. The independent business entity with the shortest processing time is then selected as the matching independent business entity for the device. Furthermore, based on the open time range of the matching independent business entity's external interface and the device's hardware identity information, a time-restricted exclusive connection permission is established for the matching independent business entity to access the device. This ensures that the matching independent business entity enjoys exclusive connection permission to the device within a predetermined time range, preventing other independent business entities from connecting to the device during this time range. This avoids the sharing of connection permission for the same device among different businesses. The predetermined time range is at least a portion of the open time range of the matching independent business entity's external interface.
[0166] In another embodiment, the data isolation and transfer module is used to perform isolated transfer processing of the device's operational data based on individual connection permissions, including:
[0167] Based on the effective duration range of individual connection permissions, the operational data uploaded by the device is identified to determine whether the operational data can be uploaded within the effective duration range; if not, the part of the operational data that has not been uploaded is isolated and intercepted.
[0168] The access policy adjustment module is used to adjust the access policy of the device for matching independent business entities based on the device's operating status, including:
[0169] Analyze the device's work logs to determine if any security anomalies occurred during operation; based on the predicted occurrence time of security anomalies, adjust the device's access data range and the amount of data allowed to be accessed at a time in matching independent business entities.
[0170] The beneficial effect of the above embodiments is that, during the period when the matched independent business entity has exclusive connection rights to the device (i.e., the effective duration of the exclusive connection rights), the operational data uploaded by the device is identified. By combining the total amount of operational data that the device expects to upload and the device's operational data upload rate, the time taken for the device to upload the operational data is estimated, thereby determining whether the operational data can be uploaded within the effective duration. If so, the uploaded operational data continues to be processed within the IoT platform. If not, the unuploaded portion of the operational data is isolated and intercepted, that is, the data portion of the operational data that has not been uploaded to the IoT platform is marked, and the unuploaded data portion continues to be uploaded in the next effective duration, thus avoiding the upload of the unuploaded data portion to other independent business entities and causing cross-business data transmission. Furthermore, the device's operational logs are analyzed to determine whether any security anomalies, such as unauthorized intrusion or hijacking, have occurred during operation. Based on the predicted occurrence time of these security anomalies, the scope of data access and the amount of data allowed to be accessed by the device in matching independent business entities are adjusted. This reduces the scope of data access and the amount of data allowed to be accessed by the device in matching independent business entities during the predicted occurrence time, thus preventing the device's own security risks from being transferred to the IoT platform.
[0171] In summary, this multi-domain isolation control method and system for IoT platforms identifies independent business entities within the platform based on the platform's dynamic business information. It adjusts the operational status of these entities' external interfaces based on their operational attributes to prevent crosstalk caused by arbitrary communication between different independent businesses. Furthermore, it constructs separate connection permissions between the independent business entities and devices within the IoT platform, based on their external interfaces, and manages these permissions separately to prevent multiple businesses from sharing connection permissions and causing operational chaos. Based on these separate connection permissions, it isolates and processes the device's operational data and adjusts the device's access policies for the matched independent business entities, preventing cross-business data transmission. This achieves data transmission isolation at both the software and hardware levels and minimizes potential security risks caused by device access policies. By implementing multi-domain isolation at both the data and business levels, it ensures the security and reliability of IoT operations.
[0172] The above is only one specific embodiment of the present invention, and any improvements made based on the concept of the present invention shall be considered within the scope of protection of the present invention.
Claims
1. A multi-domain isolation control method for IoT platforms, characterized in that, include: Based on the business dynamic information of the IoT platform, identify independent business entities within the IoT platform; based on the operational attributes of the independent business entities, adjust the working status of the external interfaces of the independent business entities; Based on the interaction requirements of the device requesting access to the IoT platform, an independent business entity matching the device is determined within the IoT platform; based on the external interface of the matched independent business entity, a separate connection permission for the matched independent business entity to the device is constructed. Based on the aforementioned separate connection permission, the operational data of the device is processed in an isolated manner. Based on the operating status of the device, adjust the device's access policy for the matched independent business entity.
2. The multi-domain isolation control method for IoT platforms as described in claim 1, characterized in that: Based on the business dynamic information of the IoT platform, identify independent business entities within the IoT platform; based on the operational attributes of the independent business entities, adjust the working status of the external interfaces of the independent business entities, including: The system monitors the business construction end of the IoT platform to obtain dynamic information on the business construction progress of the IoT platform; based on the dynamic information on the business construction progress, it identifies all completed businesses within the IoT platform; based on the structural attributes of each completed business, it identifies independent business entities within the IoT platform; wherein, the structural attributes include the completeness of each sub-business within the completed business and the external connection status of each sub-business. Obtain the time-domain variation information of the operating load of each sub-business under the independent business entity; determine the allowed external connection time interval of the independent business entity based on the time-domain variation information of the operating load; adjust the external interface opening time interval of the independent business entity based on the allowed external connection time interval.
3. The multi-domain isolation control method for IoT platforms as described in claim 2, characterized in that: Based on the aforementioned time-domain variation information of the operating load, the permitted external connection time interval for the independent business entity is determined, including: Retrieve the operational load perspective change information of independent business entities, and use the operational load perspective change information as time series data L={L1, L2, ..., L...} n }, where n represents the total number of observation time points; L1, L2, ..., L n These represent the load field of view changes at each observation time point; Using the time series data L={L1, L2, ..., L n Obtain the root mean square rate of change of load R; The root mean square rate of change of load R is obtained by the following formula: Where R represents the root mean square rate of change of the load; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point; L x This represents the average value of load field of view variation information; Retrieve time series data L={L1, L2, ..., L n The maximum value of load field of view change information max(L) and the minimum value of load field of view change information min(L) in}; The load peak concentration P is obtained by using the maximum value max(L) and the minimum value min(L) of the load field change information. The load peak concentration P is obtained by the following formula: Where P represents the peak load concentration; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; x This represents the average value of load field of view variation information; Using the time series data L={L1, L2, ..., L n The load trend fluctuation index T is obtained from each load field change information contained in}; The load trend fluctuation index T is obtained by the following formula: Where T represents the load trend fluctuation index; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point; The load variation parameter C is obtained using the root mean square rate of change of load R, the peak load concentration P, and the load trend fluctuation index T. The load variation parameter C is obtained by the following formula: Where C represents the load variation parameter; T represents the load trend fluctuation index; P represents the load peak concentration; and R represents the root mean square rate of change of load. The load change parameter C is compared with a preset parameter threshold. When the load change parameter C exceeds the preset parameter threshold, the allowed external connection time interval needs to be adjusted.
4. The multi-domain isolation control method for IoT platforms as described in claim 1, characterized in that: Based on the interaction requirements of devices requesting access to the IoT platform, an independent business entity matching the device within the IoT platform is identified; based on the external interface of the matched independent business entity, a separate connection permission for the matched independent business entity to the device is constructed, including: The connection request initiated by the device requesting access to the IoT platform is parsed and processed to obtain the interaction requirements of the task to be processed by the device; wherein, the interaction requirements include the data type and data volume of the task to be processed that need to be processed by the IoT platform. Based on the interaction requirements and the data processing efficiency between each independent business entity within the IoT platform, the independent business entity matching the device within the IoT platform is determined. Based on the open time range of the external interface of the matched independent business entity and the hardware identity information of the device, a time-restricted exclusive connection permission for the matched independent business entity to the device is constructed.
5. The multi-domain isolation control method for IoT platforms as described in claim 1, characterized in that: Based on the aforementioned separate connection permission, the operational data of the device is processed in an isolated manner. Based on the operating status of the device, adjust the access policy of the device for the matched independent business entity, including: Based on the effective duration range of the individual connection permission, the operational data uploaded by the device is identified, and it is determined whether the operational data can be uploaded within the effective duration range; if not, the part of the operational data that has not been uploaded is isolated and intercepted. The device's work logs are analyzed to determine whether any security anomalies occur during operation. Based on the predicted occurrence time of the security anomalies, the device's access data range and the amount of data allowed to be accessed at one time are adjusted within the matched independent business entity.
6. A multi-domain isolation control system for an Internet of Things (IoT) platform, characterized in that, include: The independent business entity identification module is used to identify independent business entities within the Internet of Things (IoT) platform based on the business dynamic information of the IoT platform. The external interface status adjustment module is used to adjust the working status of the external interface of the independent business entity based on the running attributes of the independent business entity. The independent business entity matching module is used to determine the independent business entity within the IoT platform that matches the device based on the interaction requirements of the device requesting access to the IoT platform. The connection permission construction module is used to construct the individual connection permissions of the matched independent business entity to the device based on the external interface of the matched independent business entity. The data isolation and transfer module is used to isolate and transfer the operational data of the device based on the individual connection permission. The access policy adjustment module is used to adjust the access policy of the device for the matched independent business entity based on the working status of the device.
7. The multi-domain isolation control system for IoT platforms as described in claim 6, characterized in that: The independent business entity identification module is used to identify independent business entities within the IoT platform based on the platform's dynamic business information, including: The system monitors the business construction end of the IoT platform to obtain dynamic information on the business construction progress of the IoT platform; based on the dynamic information on the business construction progress, it identifies all completed businesses within the IoT platform; based on the structural attributes of each completed business, it identifies independent business entities within the IoT platform; wherein, the structural attributes include the completeness of each sub-business within the completed business and the external connection status of each sub-business. The external interface status adjustment module is used to adjust the working status of the external interface of the independent business entity based on the operating attributes of the independent business entity, including: Obtain the time-domain variation information of the operating load of each sub-business under the independent business entity; determine the allowed external connection time interval of the independent business entity based on the time-domain variation information of the operating load; adjust the external interface opening time interval of the independent business entity based on the allowed external connection time interval.
8. The multi-domain isolation control system for IoT platforms as described in claim 7, characterized in that: Based on the aforementioned time-domain variation information of the operating load, the permitted external connection time interval for the independent business entity is determined, including: Retrieve the operational load perspective change information of independent business entities, and use the operational load perspective change information as time series data L={L1, L2, ..., L...} n }, where n represents the total number of observation time points; L1, L2, ..., L n These represent the load field of view changes at each observation time point; Using the time series data L={L1, L2, ..., L n Obtain the root mean square rate of change of load R; The root mean square rate of change of load R is obtained by the following formula: Where R represents the root mean square rate of change of the load; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point; L x This represents the average value of load field of view variation information; Retrieve time series data L={L1, L2, ..., L n The maximum value of load field of view change information max(L) and the minimum value of load field of view change information min(L) in}; The load peak concentration P is obtained by using the maximum value max(L) and the minimum value min(L) of the load field change information. The load peak concentration P is obtained by the following formula: Where P represents the peak load concentration; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; x This represents the average value of load field of view variation information; Using the time series data L={L1, L2, ..., L n The load trend fluctuation index T is obtained from each load field change information contained in}; The load trend fluctuation index T is obtained by the following formula: Where T represents the load trend fluctuation index; ε represents the zero-prevention constant; n represents the total number of observation time points; L t L represents the load field of view change information corresponding to the t-th observation time point; t-1 This represents the load field of view change information corresponding to the (t-1)th observation time point; The load variation parameter C is obtained using the root mean square rate of change of load R, the peak load concentration P, and the load trend fluctuation index T. The load variation parameter C is obtained by the following formula: Where C represents the load variation parameter; T represents the load trend fluctuation index; P represents the load peak concentration; and R represents the root mean square rate of change of load. The load change parameter C is compared with a preset parameter threshold. When the load change parameter C exceeds the preset parameter threshold, the allowed external connection time interval needs to be adjusted.
9. The multi-domain isolation control system for an IoT platform as described in claim 6, characterized in that: The independent business entity matching module is used to determine the independent business entities within the IoT platform that match the device based on the interaction requirements of the device requesting access to the IoT platform, including: The connection request initiated by the device requesting access to the IoT platform is parsed and processed to obtain the interaction requirements of the task to be processed by the device; wherein, the interaction requirements include the data type and data volume of the task to be processed that need to be processed by the IoT platform. Based on the interaction requirements and the data processing efficiency between each independent business entity within the IoT platform, the independent business entity matching the device within the IoT platform is determined. The connection permission construction module is used to construct individual connection permissions for the matching independent business entity to the device based on the external interface of the matching independent business entity, including: Based on the open time range of the external interface of the matched independent business entity and the hardware identity information of the device, a time-restricted exclusive connection permission for the matched independent business entity to the device is constructed.
10. The multi-domain isolation control system for an IoT platform as described in claim 6, characterized in that: The data isolation and transfer module is used to perform isolated transfer processing on the device's operational data based on the separate connection permission, including: Based on the effective duration range of the individual connection permission, the operational data uploaded by the device is identified, and it is determined whether the operational data can be uploaded within the effective duration range; if not, the part of the operational data that has not been uploaded is isolated and intercepted. The access policy adjustment module is used to adjust the access policy of the device for the matched independent business entity based on the working status of the device, including: The device's work logs are analyzed to determine whether any security anomalies occur during operation. Based on the predicted occurrence time of the security anomalies, the device's access data range and the amount of data allowed to be accessed at one time are adjusted within the matched independent business entity.