Integrated intelligent monitoring system and hierarchical isolation method and device based on security domain

By integrating an intelligent monitoring system and using a hierarchical isolation method for security domains, the problems of architectural chaos and security risks in discrete manufacturing workshops have been solved, achieving the effects of data unification, functional collaboration, and security controllability.

CN121967469APending Publication Date: 2026-05-01DONGFENG MOTOR GRP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
DONGFENG MOTOR GRP
Filing Date
2026-01-29
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Currently, discrete manufacturing workshops suffer from subsystems with limited functionality, heterogeneous data formats, and isolated network deployments, resulting in chaotic architecture, blocked data flow, high network security risks, and difficulties in maintenance and expansion.

Method used

An integrated intelligent monitoring system is adopted, which achieves data unification and functional collaboration through a centralized data bus and modular functional services. Combined with a layered isolation method of security domains, a multi-NIC industrial control computer is used for network isolation and provides a unified access interface.

Benefits of technology

It achieves unified data, collaborative functions, and secure control, with a clear and easily expandable architecture, reducing integration complexity and cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967469A_ABST
    Figure CN121967469A_ABST
Patent Text Reader

Abstract

The invention discloses an integrated intelligent monitoring system and a hierarchical isolation method and equipment based on a security domain, and relates to the technical field of industrial automation system integration, the method comprises a centralized data bus, a modular function service and a service interface, the centralized data bus is used for receiving original real-time data acquired from bottom equipment; the modularized function service is used for designing each function service of the discrete manufacturing workshop into a mutually independent and pluggable module form, and each function service subscribes to required data from the centralized data bus; and the service interface is used for publishing the generated new service data back to the centralized data bus after the function service consumes the subscription data, so that other function services can subscribe and consume. According to the invention, the problems of architecture chaos, data islands and security risks in multi-subsystem integration can be effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Integrated intelligent monitoring system and security domain-based hierarchical isolation method and equipment Technical Field

[0001] This application relates to the field of industrial automation system integration technology, specifically to an integrated intelligent monitoring system and a hierarchical isolation method and device based on security domains. Background Technology

[0002] Currently, discrete manufacturing workshops have a variety of independently operating subsystems (such as SCADA for equipment monitoring, robot simulation software, MES for production management systems, and communication software). These subsystems have limited functions, heterogeneous data formats, and isolated network deployments, forming "information silos" and "functional chimneys".

[0003] In practical applications, simply piecing these subsystems together will lead to fundamental problems such as chaotic architecture, disrupted data flow, high network security risks, and difficulties in maintenance and expansion. Therefore, how to provide an innovative overall system architecture that can organically integrate the core functions of monitoring, simulation, alarm, and management in discrete manufacturing workshops, achieving data unification, functional synergy, and secure control, has become an urgent problem to be solved. Summary of the Invention

[0004] This application provides an integrated intelligent monitoring system and a hierarchical isolation method and device based on security domains, which can effectively solve the problems of chaotic architecture, data silos and security risks in the integration of multiple subsystems.

[0005] In a first aspect, embodiments of this application provide an integrated intelligent monitoring system, comprising: a centralized data bus for receiving raw real-time data collected from underlying devices; modular functional services for designing each functional service of a discrete manufacturing workshop as an independent and pluggable module, wherein each functional service subscribes to the required data from the centralized data bus; and a service interface for enabling functional services to publish new service data generated after consuming subscribed data back to the centralized data bus for other functional services to subscribe to and consume.

[0006] In conjunction with the first aspect, in one implementation, the centralized data bus is specifically used to publish raw real-time data collected from underlying devices to the centralized data bus after protocol parsing and formatting, so as to realize data distribution; the underlying devices include PLC, robot controller, and MES system.

[0007] In conjunction with the first aspect, in one implementation, the functional services include data acquisition services, equipment status monitoring services, workshop layout and production status mapping services, high-fidelity robot motion simulation services, data backup services, data aggregation services, intelligent alarm services, visualization services, notification services, and quality inspection services.

[0008] In conjunction with the first aspect, in one implementation, the service interface is specifically used for a functional service to consume the subscribed data, complete internal logic processing, and then publish the output as new service data back to the centralized data bus for other functional services to subscribe to and consume; the internal logic processing includes state judgment, kinematic calculation, and report generation; the output includes device status results, alarm events, and backup reports.

[0009] Secondly, embodiments of this application provide a security domain-based hierarchical isolation method for managing the integrated intelligent monitoring system described above. The security domain-based hierarchical isolation method includes: allocating functional services to a created basic monitoring layer and advanced application layer to achieve functional layering; deploying an industrial control computer equipped with multiple network cards in the integrated intelligent monitoring system to connect to the production control network for use by the basic monitoring layer, and to connect to the information management network for use by the advanced application layer, thereby achieving network isolation.

[0010] In conjunction with the second aspect, in one implementation, the basic monitoring layer is allocated functional services with high requirements for reliability and real-time performance; the advanced application layer is allocated functional services that are computationally intensive and require interaction with external systems.

[0011] In conjunction with the second aspect, in one implementation, the deployment of an industrial control computer equipped with multiple network interface cards (NICs) in an integrated intelligent monitoring system to connect to a production control network for use by the basic monitoring layer and to connect to an information management network for use by the advanced application layer, thereby achieving network isolation, specifically includes: deploying an industrial control computer equipped with dual NICs on the integrated intelligent monitoring system, the industrial control computer including a first NIC and a second NIC; connecting the first NIC to the production control network for use by the basic monitoring layer, and connecting the second NIC to the information management network for use by the advanced application layer, thereby achieving network isolation.

[0012] In conjunction with the second aspect, in one implementation, the integrated intelligent monitoring system is also configured with firewall rules to restrict any access from the advanced application layer to the basic monitoring layer, allowing only the basic monitoring layer to push processed data to the advanced application layer.

[0013] In conjunction with the second aspect, in one implementation, the security domain-based layered isolation method further includes: encapsulating all functional services and providing a unified access interface exposed to the outside.

[0014] Thirdly, embodiments of this application provide a security domain-based hierarchical isolation device, the security domain-based hierarchical isolation device including a processor, a memory, and a security domain-based hierarchical isolation program stored in the memory and executable by the processor, wherein when the security domain-based hierarchical isolation program is executed by the processor, it implements the steps of the security domain-based hierarchical isolation method described above.

[0015] The beneficial effects of the technical solutions provided in this application include: (1) Clear architecture and easy expansion: The loosely coupled integrated intelligent monitoring system architecture makes it as simple as plugging and unplugging components to add new functional modules, which greatly improves scalability and maintainability; (2) Unified data and breaking down data silos: The centralized data bus ensures that the data source is unique and the format is unified, laying the foundation for advanced data analysis; (3) Safe and controllable and risk isolation: Through functional layering and network isolation, the security balance between the OT domain and the IT domain is achieved, and the inherent security level is high; (4) Efficient integration and reduced cost: A standardized integration framework is provided, which reduces the complexity and cost of integrating multiple heterogeneous technologies together. Attached Figure Description

[0016] Figure 1 is a schematic diagram of the integrated intelligent monitoring system of this application; Figure 2 is a flowchart of the hierarchical isolation method based on security domain of this application; Figure 3 is a schematic diagram of functional layering and network isolation strategy; Figure 4 is a schematic diagram of the hardware structure of the hierarchical isolation device based on security domain of this application. Detailed Implementation

[0017] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0018] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0019] In the first aspect, the embodiments of this application provide an integrated intelligent monitoring system, that is, an integrated intelligent monitoring system for discrete manufacturing workshops that realizes the fusion of multi-source heterogeneous data and multi-functional collaboration, that is, an overall architecture of an intelligent monitoring system based on the concept of data-driven and functional layering, which solves the problems of architectural chaos, data silos and security risks in the integration of multiple subsystems.

[0020] In one embodiment, referring to Figure 1, which is a schematic diagram of the integrated intelligent monitoring system of this application, the integrated intelligent monitoring system includes: a centralized data bus, modular functional services, and service interfaces. That is, the integrated intelligent monitoring system of this application adopts a loosely coupled architecture model with a data bus as the core and functional services as components, to solve the problem of tight coupling and difficulty in expansion between functional modules of traditional subsystems.

[0021] In this application, a centralized data bus is used to receive raw real-time data collected from underlying devices. Specifically, the centralized data bus is used to parse and format the raw real-time data collected from the underlying devices and then publish it to the centralized data bus to facilitate data distribution. The underlying devices include PLCs (Programmable Logic Controllers), robot controllers, and MES (Manufacturing Execution System).

[0022] This involves establishing a logically centralized data distribution channel (centralized data bus). All raw, real-time data collected from underlying devices, after protocol parsing and preliminary formatting, is uniformly published onto this bus. The centralized data bus is not concerned with the specific purpose of the data; it is only responsible for distributing the data efficiently and reliably.

[0023] In this application, modular functional services are used to design the various functional services of a discrete manufacturing workshop as independent and pluggable modules, and each functional service subscribes to the required data from the centralized data bus. It should be noted that the functional services include data acquisition services, equipment status monitoring services, workshop layout and production status mapping services, high-fidelity robot motion simulation services, data backup services, data aggregation services, intelligent alarm services, visualization services, notification services, and quality inspection services.

[0024] Specifically, for each functional service in the discrete manufacturing workshop, it is designed as an independent, pluggable functional service module. Each functional service module subscribes to the specific data it needs from the centralized data bus as needed (for example, the robot high-fidelity motion simulation service only subscribes to robot joint data).

[0025] In this application, the service interface is used to enable functional services to publish new service data generated after consuming subscribed data back to the centralized data bus for other functional services to subscribe to and consume. Specifically, the service interface is used by functional services to consume subscribed data, complete internal logic processing, and then publish the output as new service data back to the centralized data bus for other functional services to subscribe to and consume; the internal logic processing includes status judgment, kinematic calculation, and report generation; the output includes device status results, alarm events, and backup reports.

[0026] Specifically, each functional service module, after consuming data and completing its internal logic, publishes its output as new service data back to the centralized data bus for consumption by other functional service modules. Through this subscription-and-publish-based communication mechanism, functional services do not communicate directly; instead, they exchange data indirectly and asynchronously through the centralized data bus, achieving loose coupling between modules. Furthermore, a new functional service module (such as a quality inspection service) can be added simply by subscribing to relevant data and publishing results, without modifying any existing modules, greatly improving the scalability and maintainability of the integrated intelligent monitoring system.

[0027] The integrated intelligent monitoring system of this application adopts a loosely coupled architecture of centralized data and distributed functions. That is, it adopts an architecture that combines a centralized data bus with modular functional services. All raw data collected from workshop equipment is uniformly aggregated into an internal centralized data bus, while each functional service, as an independent service, subscribes to the required data from the centralized data bus and provides encapsulated functions upwards. Functional services communicate loosely through the centralized data bus rather than directly calling each other.

[0028] Secondly, embodiments of this application also provide a hierarchical isolation method based on security domains for managing the integrated intelligent monitoring system described above.

[0029] In one embodiment, referring to Figure 2, which is a flowchart of the security domain-based hierarchical isolation method of this application, the security domain-based hierarchical isolation method includes: S1: allocating functional services to the created basic monitoring layer and advanced application layer to achieve functional layering; S2: deploying an industrial control computer equipped with multiple network cards in the integrated intelligent monitoring system to connect to the production control network for use by the basic monitoring layer, and to connect to the information management network for use by the advanced application layer, thereby achieving network isolation.

[0030] In order to solve the security balance problem between the OT (Operations Technology) domain and the IT (Information Technology) domain, the integrated intelligent monitoring system is logically layered and physically isolated based on the security sensitivity of its functions.

[0031] In this application, the basic monitoring layer is allocated functional services with high reliability and real-time requirements. Specifically, the basic monitoring layer includes the most critical functional services requiring high reliability and real-time performance, such as data acquisition services and equipment status monitoring services. The basic monitoring layer is deployed on the production control network (equipment intranet) and interacts directly with key equipment such as workshop PLCs and robots to ensure stable production monitoring.

[0032] In this application, the advanced application layer is allocated to computationally intensive functional services that require external interaction. Specifically, the advanced application layer includes computationally intensive services that require external interaction, such as high-fidelity robot motion simulation services, intelligent alarm services, and data backup services. The advanced application layer is deployed on the information management network (management extranet).

[0033] Furthermore, in one embodiment, an industrial control computer equipped with multiple network interface cards (NICs) is deployed in an integrated intelligent monitoring system to connect to a production control network for use by the basic monitoring layer and to connect to an information management network for use by the advanced application layer, thereby achieving network isolation. Specifically, this includes: S201: Deploying an industrial control computer equipped with dual NICs on the integrated intelligent monitoring system, the industrial control computer including a first NIC and a second NIC; S202: Connecting the first NIC to the production control network for use by the basic monitoring layer and connecting the second NIC to the information management network for use by the advanced application layer, thereby achieving network isolation.

[0034] Specifically, an industrial control computer equipped with dual network cards is deployed on the integrated intelligent monitoring system. The first network card is connected to the production control network and is used exclusively by the basic monitoring layer, while the second network card is connected to the information management network and is used exclusively by the advanced application layer.

[0035] Furthermore, the integrated intelligent monitoring system is also configured with firewall rules to restrict any access from the advanced application layer to the basic monitoring layer, allowing only the basic monitoring layer to push processed data to the advanced application layer. In other words, by configuring strict operating system-level firewall rules, it ensures that no access can be initiated from the management external network (advanced application layer) to the production control network (basic monitoring layer). The data flow direction is strictly limited to one direction: only the basic monitoring layer is allowed to push processed data to the advanced application layer, thus achieving data sharing while constructing an inherently secure defense.

[0036] Furthermore, in one embodiment, the security domain-based layered isolation method of this application further includes: encapsulating all functional services and providing a unified access interface exposed externally. That is, to simplify the complexity of terminal access, the capabilities of all functional services are encapsulated, and a unified service-oriented access interface is provided.

[0037] Service encapsulation and aggregation involve encapsulating and aggregating the capabilities of various functional services. For example, functions such as "workshop status query," "robot model pose acquisition," and "alarm history retrieval" are encapsulated into a set of well-defined application programming interfaces (APIs).

[0038] Specifically, unified gateway exposure involves exposing the encapsulated APIs to the outside world through a unified API gateway. This gateway is responsible for authentication, permission verification, request routing, and protocol conversion.

[0039] Among them, for multi-terminal support, different terminals can obtain services by accessing a unified API gateway: (1) C / S client: As a "privileged" service of the integrated intelligent monitoring system, it can directly and efficiently subscribe to a large amount of real-time data on the data bus to achieve high-fidelity and high-performance local visualization; (2) B / S browser: The integrated intelligent monitoring system has a built-in lightweight web server, which obtains data by calling the unified API gateway and renders it into an HTML5 page. Users do not need to install any plugins and can access a simplified but core monitoring view through a browser; (3) Enterprise office platform: The intelligent alarm service pushes alarm information to the enterprise office platform by calling the "send message" interface provided by the API gateway.

[0040] The above design normalizes the access method, allowing services to be obtained through the same set of interfaces regardless of the terminal form, which greatly reduces the complexity of integration.

[0041] The following example will be used to illustrate this application in detail.

[0042] Deploy a high-performance industrial computer equipped with two network cards, one for connecting to the workshop equipment network and the other to the office management network.

[0043] For the initialization and data flow of the integrated intelligent monitoring system: The data acquisition service (basic monitoring layer) collects data (such as production line status words, robot joint angles, motor currents) from 14 PLCs and 97 robot controllers on-site via device network cards using protocols such as EtherNet / IP and OPC UA, and publishes it to the centralized data bus; the equipment status monitoring service (advanced application layer) subscribes to the production line status words on the centralized data bus, determines the production line status based on the status words (0-abnormal, 1-automatic, 2-teach, 3-standby), and publishes the results (such as "main line of the vehicle body - running - green") back to the centralized data bus; the visualization service (as a C / S client) subscribes to data from the equipment status monitoring service and the robot high-fidelity motion simulation service on the centralized data bus, and renders the workshop layout diagram and robot 3D model in the WPF interface to achieve digital twin visualization.

[0044] For the security and access mechanisms of the integrated intelligent monitoring system, see Figure 3. The system firewall rules are configured to prohibit any connection requests from the management network (second network card) to the device network (first network card), ensuring the security of the production network. The provided unified Web API allows authenticated access. Production managers can open a browser on their office computers and enter the system address (such as http: / / [system IP]:5000) to access a Web monitoring page. This page retrieves key workshop status and alarm lists by calling the API, realizing remote monitoring in a B / S mode.

[0045] The security domain-based layered isolation method of this application adopts a security-oriented functional and network collaborative partitioning, dividing each functional service into a basic monitoring layer and an advanced application layer according to its requirements for real-time performance and security. The basic monitoring layer focuses on high-reliability data acquisition and equipment status monitoring, and is deployed in the production control network; the advanced application layer focuses on data analysis and human-computer interaction, and is deployed in the information management network. The two layers exchange secure data through a unidirectional data gateway to ensure that risks in the management network do not penetrate into the control network.

[0046] Meanwhile, a unified service access interface is adopted to provide a unified service access interface (such as HTTP, Webhook, etc.) to the outside world, encapsulating the complex internal Togo functional services into standardized services; whether it is a local client, a remote browser or a mobile application, they all interact with the system through this unified interface, realizing the normalization and simplification of access methods.

[0047] Thirdly, embodiments of this application provide a hierarchical isolation device based on a security domain. The hierarchical isolation device based on a security domain can be a personal computer (PC), a laptop computer, a server, or other devices with data processing capabilities.

[0048] Referring to Figure 4, which is a schematic diagram of the hardware structure of a security domain-based hierarchical isolation device involved in the embodiments of this application, the security domain-based hierarchical isolation device may include a processor, a memory, a communication interface, and a communication bus in the embodiments of this application.

[0049] The communication bus can be of any type and is used to interconnect the processor, memory, and communication interface.

[0050] Communication interfaces include input / output (I / O) interfaces, physical interfaces, and logical interfaces used for interconnecting devices within a security domain-based hierarchical isolation device, as well as interfaces used for interconnecting the security domain-based hierarchical isolation device with other devices (such as other computing devices or user equipment). Physical interfaces can be Ethernet interfaces, fiber optic interfaces, ATM interfaces, etc.; user equipment can be displays, keyboards, etc.

[0051] Memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.

[0052] The processor can be a general-purpose processor, which can call a security domain-based hierarchical isolation program stored in memory and execute the security domain-based hierarchical isolation method provided in the embodiments of this application. For example, the general-purpose processor can be a central processing unit (CPU). The method executed when the security domain-based hierarchical isolation program is called can be referred to in the various embodiments of the security domain-based hierarchical isolation method of this application, and will not be repeated here.

[0053] Those skilled in the art will understand that the hardware structure shown in Figure 4 does not constitute a limitation of this application, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0054] The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus. The terms "first," "second," and "third," etc., are used to distinguish different objects, etc., and do not indicate a sequence, nor do they limit "first," "second," and "third" to different types.

[0055] In the description of the embodiments of this application, terms such as "exemplary," "for example," or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplary," "for example," or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary," "for example," or "for instance" is intended to present the relevant concepts in a concrete manner.

[0056] In the description of the embodiments of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. The "and / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this application, "multiple" means two or more.

[0057] In some processes described in the embodiments of this application, multiple operations or steps are included in a specific order. However, it should be understood that these operations or steps may not be executed in the order they appear in the embodiments of this application, or they may be executed in parallel. The sequence number of the operation is only used to distinguish different operations, and the sequence number itself does not represent any execution order. In addition, these processes may include more or fewer operations, and these operations or steps may be executed sequentially or in parallel, and these operations or steps may be combined.

[0058] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device to execute the methods described in the various embodiments of this application.

[0059] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. An integrated intelligent monitoring system, characterized in that, The integrated intelligent monitoring system includes: a centralized data bus for receiving raw real-time data collected from underlying devices; modular functional services for designing each functional service in the discrete manufacturing workshop as an independent and pluggable module, with each functional service subscribing to the required data from the centralized data bus; and a service interface for enabling functional services to publish new service data generated after consuming subscribed data back to the centralized data bus for other functional services to subscribe to and consume.

2. The integrated intelligent monitoring system as described in claim 1, characterized in that: The centralized data bus is specifically used to publish raw real-time data collected from underlying devices to the centralized data bus after protocol parsing and formatting, so as to realize data distribution; the underlying devices include PLC, robot controller, and MES system.

3. The integrated intelligent monitoring system as described in claim 1, characterized in that, The functional services include data acquisition services, equipment status monitoring services, workshop layout and production status mapping services, high-fidelity robot motion simulation services, data backup services, data aggregation services, intelligent alarm services, visualization services, notification services, and quality inspection services.

4. The integrated intelligent monitoring system as described in claim 1, characterized in that: The service interface is specifically used for functional services to consume subscribed data, complete internal logic processing, and then publish the output as new service data back to the centralized data bus for other functional services to subscribe to and consume; the internal logic processing includes status judgment, kinematic calculation, and report generation; the output includes device status results, alarm events, and backup reports.

5. A hierarchical isolation method based on security domains, used to manage the integrated intelligent monitoring system described in any one of claims 1 to 4, characterized in that, The security domain-based hierarchical isolation method includes: allocating functional services to the created basic monitoring layer and advanced application layer to achieve functional layering; deploying industrial control computers equipped with multiple network cards in the integrated intelligent monitoring system to connect to the production control network for use by the basic monitoring layer, and to connect to the information management network for use by the advanced application layer, thereby achieving network isolation.

6. The hierarchical isolation method based on security domains as described in claim 5, characterized in that: The basic monitoring layer is allocated to functional services with high requirements for reliability and real-time performance; the advanced application layer is allocated to functional services that are computationally intensive and require interaction with external systems.

7. The hierarchical isolation method based on security domains as described in claim 6, characterized in that, The deployment of an industrial control computer equipped with multiple network interface cards (NICs) in an integrated intelligent monitoring system to connect to the production control network for use by the basic monitoring layer and to connect to the information management network for use by the advanced application layer, thereby achieving network isolation, specifically includes: deploying an industrial control computer equipped with dual NICs on the integrated intelligent monitoring system, the industrial control computer including a first NIC and a second NIC; connecting the first NIC to the production control network for use by the basic monitoring layer, and connecting the second NIC to the information management network for use by the advanced application layer, thereby achieving network isolation.

8. The hierarchical isolation method based on security domains as described in claim 7, characterized in that: The integrated intelligent monitoring system is also configured with firewall rules to restrict any access from the advanced application layer to the basic monitoring layer, allowing only the basic monitoring layer to push processed data to the advanced application layer.

9. The hierarchical isolation method based on security domains as described in claim 5, characterized in that, The security domain-based layered isolation method further includes: encapsulating all functional services and providing a unified access interface exposed to the outside.

10. A hierarchical isolation device based on security domains, characterized in that, The security domain-based hierarchical isolation device includes a processor, a memory, and a security domain-based hierarchical isolation program stored in the memory and executable by the processor, wherein when the security domain-based hierarchical isolation program is executed by the processor, it implements the steps of the security domain-based hierarchical isolation method as described in any one of claims 5 to 9.