Method and apparatus for remote monitoring and environmental control of GSM-R system

By fusing and processing environmental sensor data from GSM-R system base stations and mining time-series patterns, threat assessment values ​​are generated, solving the problem of isolated decision-making logic for base station environmental monitoring in existing technologies, and realizing comprehensive and accurate threat assessment and collaborative response for base station environments.

CN121968128BActive Publication Date: 2026-07-17CHINA RAILWAY ELECTRIFICATION ENGINEERING GROUP CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA RAILWAY ELECTRIFICATION ENGINEERING GROUP CO LTD
Filing Date
2026-04-01
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In existing technologies, GSM-R system base station environment monitoring methods rely on a single threshold judgment, resulting in isolated and static decision-making logic, making it difficult to accurately assess the comprehensive threat level, and easily leading to false alarms, missed alarms, or one-sided response strategies.

Method used

The system collects event data and raw output signals from base station environmental sensors, processes them through optical isolation and programmable amplification, then fuses the data. It uses a time-series pattern mining algorithm to generate an abnormal pattern set, constructs an event reasoning graph, calculates threat assessment values, generates collaborative security response strategies, and coordinates environmental control through GSM-R wireless communication.

Benefits of technology

It enables comprehensive and accurate threat assessment and collaborative response to base station environments, improves the signal-to-noise ratio of risk identification and the effectiveness of decision-making basis, and enhances the system's efficiency in early detection and handling of complex risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121968128B_ABST
    Figure CN121968128B_ABST
Patent Text Reader

Abstract

This application relates to the field of railway communication monitoring technology, providing a remote monitoring and environmental control method and device for GSM-R systems, addressing the problems of low intelligence level and poor security response efficiency in railway communication base station environmental monitoring. The method includes: collecting raw signal and event data from various sensors in the base station environment; generating first pre-processed data through optical coupling isolation of digital signals and generating second pre-processed data through programmable amplification of analog signals; fusing the two types of data with event data to form a monitoring dataset; using a time-series pattern mining algorithm to mine an abnormal pattern set from the dataset; constructing an event reasoning graph based on this set, calculating a threat assessment value by analyzing event correlations, and generating a corresponding security strategy when the threshold is exceeded; encapsulating the strategy instructions into a dedicated protocol data packet and sending it to the base station environment controller to coordinate the execution of the equipment. This application improves the intelligence level and security response efficiency of railway communication base station environmental monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of railway communication monitoring technology, and in particular to a remote monitoring and environmental control method and device for a GSM-R system. Background Technology

[0002] As a key infrastructure for train control and dispatching, the stable operation of the base stations of the Global System for Mobile Communications – Railway (GSM-R) is crucial to railway safety. Therefore, remote monitoring and environmental control technologies for the base station environment of the GSM-R system have become an important research direction for ensuring the reliability of railway communication networks and have broad application prospects.

[0003] Currently, monitoring such base station environments typically relies on deploying multiple sensors, such as access control sensors for security and temperature and humidity sensors for environmental monitoring. Existing technical solutions mainly collect independent alarm data from each sensor and set fixed thresholds for judgment. When the data from a single sensor exceeds the threshold, a preset alarm or control action is triggered, such as starting a fan or sending an SMS notification. This method achieves remote perception of the base station's environmental status to a certain extent.

[0004] However, this method based on a single threshold is relatively isolated and static in its decision-making logic when dealing with complex base station environments and multiple potential risks. Because there are dynamic spatiotemporal correlations and causal influences between various physical elements within the base station environment, responding solely based on data exceeding limits at isolated points makes it difficult to accurately assess the overall threat level, easily leading to false alarms, missed alarms, or one-sided response strategies. Therefore, existing technologies suffer from insufficient comprehensive environmental situational awareness and collaborative response capabilities. Summary of the Invention

[0005] This application provides a remote monitoring and environmental control method and apparatus for a GSM-R system, which solves the problems of low intelligence level and poor security response efficiency in the existing technology for environmental monitoring of railway communication base stations.

[0006] To address the aforementioned technical problems, in a first aspect, this application provides a method for remote monitoring and environmental control of a GSM-R system, comprising: The system collects event data and raw output signals from various sensors located in the base station environment of the GSM-R system. These sensors include both digital and analog sensors. The original output signal of the digital sensor is optically isolated to generate first preprocessed data, and the original output signal of the analog sensor is amplified by programmable control to generate second preprocessed data. The first preprocessed data, the second preprocessed data, and the event data are fused together to form a monitoring dataset. Using a time-series pattern mining algorithm, pattern mining is performed on the monitoring dataset to generate an abnormal pattern set; Based on the set of abnormal patterns, an event reasoning graph is constructed. By analyzing the correlation between events in the event reasoning graph, a threat assessment value is calculated. When the threat assessment value exceeds a preset threat assessment threshold, a security response strategy corresponding to the level of the threat assessment value is generated. The environmental control instructions corresponding to the security response strategy are encapsulated into dedicated protocol data packets and transmitted to the base station environment controller via GSM-R wireless communication, so as to coordinate and adjust the operating status of the execution devices in the base station environment according to the dedicated protocol data packets.

[0007] Optionally, the step of using a time-series pattern mining algorithm to perform pattern mining on the monitoring dataset and generate an abnormal pattern set includes: Scan the time series markers in the monitoring dataset, and determine the range of each time window based on the time series markers; Within each time window, the event markers in the monitoring dataset are scanned, and the event type and event intensity value of all events within the corresponding time window are extracted based on the event markers. Using a time-series pattern mining algorithm, a target abnormal event sequence is generated based on the event type and event intensity value of all the events. Within the target abnormal event sequence, the frequency of abnormal occurrences of event combinations is counted, and abnormal event combinations with an abnormal occurrence frequency greater than a preset second frequency threshold are stored in an abnormal pattern set.

[0008] Optionally, the step of generating a target anomalous event sequence using a time-series pattern mining algorithm based on the event type and event intensity value of all events includes: Based on the event type and event intensity value of all events, a time-series pattern mining algorithm is used to count the baseline occurrence frequency of each event combination within the monitoring dataset. The combination of events whose occurrence frequency is greater than a preset first frequency threshold is defined as a normal event pattern; Events in the monitoring dataset that do not belong to the normal event pattern are identified as the initial abnormal event sequence; Based on the location of events and the temporal relationship between events in the initial abnormal event sequence, and combined with the event propagation model, the causal correlation strength between events is calculated; By utilizing an attention-enhanced sequence learning mechanism, the events in the initial abnormal event sequence are weighted based on the causal correlation strength to generate a target abnormal event sequence.

[0009] Optionally, the step of calculating the causal correlation strength between events based on the occurrence location and temporal relationship of events in the initial abnormal event sequence, combined with an event propagation model, includes: Based on the physical layout of the GSM-R system in the base station environment, the spatial distance and connection relationship between each monitoring point are determined; Based on the location of events in the initial abnormal event sequence, and combined with the spatial distance and the connection relationship, calculate the spatial influence factor between events; Based on the temporal relationship between events in the initial abnormal event sequence, the time difference between adjacent events is analyzed to calculate the time influence factor between events; Based on the spatial influence factor and the temporal influence factor, the causal correlation strength between events is calculated using an event propagation model.

[0010] Optionally, the process of optically isolating the raw output signal of the digital sensor to generate first preprocessed data, and programmatically amplifying the raw output signal of the analog sensor to generate second preprocessed data, includes: The original output signal of the digital sensor is input to the optocoupler isolation circuit, which electrically isolates the original output signal of the digital sensor and outputs the isolated digital signal. The isolated digital signal is subjected to state change identification to generate first preprocessed data; The original output signal of the analog sensor is input to a programmable gain amplifier, and the amplitude of the original output signal of the analog sensor is adjusted by the programmable gain amplifier to output an amplified analog signal. The amplified analog signal is converted into a digital signal by an analog-to-digital converter to generate second preprocessed data.

[0011] Optionally, the step of constructing an event reasoning graph based on the set of abnormal patterns, and calculating a threat assessment value by analyzing the correlation between events in the event reasoning graph, includes: Using each event type in the set of abnormal patterns as a node and the temporal causal relationship between events as an edge, an event reasoning graph is constructed. In the event reasoning graph, the relationships between events are analyzed based on the connection density and path length between nodes; The threat assessment value is calculated based on the tightness of the relationship and the event type weight of the node.

[0012] Optionally, the step of fusing the first preprocessed data, the second preprocessed data, and the event data to form a monitoring dataset includes: The event data from all sensors are synchronized at specific points in time using a unified reference time to form a synchronized event sequence. The synchronized event sequence is divided into multiple event segments according to fixed time intervals; The first preprocessed data, the second preprocessed data, and the multiple event segments are fused together to form a monitoring dataset.

[0013] Secondly, this application provides a remote monitoring and environmental control device for a GSM-R system, comprising: The acquisition module is used to acquire event data and raw output signals from various sensors installed in the base station environment of the GSM-R system. The sensors include digital sensors and analog sensors. An isolation module is used to perform optical isolation processing on the raw output signal of the digital sensor to generate first pre-processed data, and to perform programmable amplification on the raw output signal of the analog sensor to generate second pre-processed data. The fusion module is used to fuse the first preprocessed data, the second preprocessed data, and the event data to form a monitoring dataset; The generation module is used to perform pattern mining on the monitoring dataset using a time-series pattern mining algorithm to generate an abnormal pattern set. The construction module is used to construct an event reasoning graph based on the set of abnormal patterns, calculate the threat assessment value by analyzing the correlation between events in the event reasoning graph, and generate a security response strategy corresponding to the level of the threat assessment value when the threat assessment value exceeds a preset threat assessment threshold. The adjustment module is used to encapsulate the environmental control instructions corresponding to the security response strategy into dedicated protocol data packets and transmit them to the base station environment controller via GSM-R wireless communication, so as to coordinate and adjust the operating status of the execution devices in the base station environment according to the dedicated protocol data packets.

[0014] Thirdly, this application provides an electronic device, comprising: Memory, used to store computer programs; A processor, used to execute the computer program to implement the steps of the remote monitoring and environmental control method for the GSM-R system as described in the first aspect above.

[0015] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the steps of the remote monitoring and environmental control method for the GSM-R system as described in the first aspect above.

[0016] This application provides a remote monitoring and environmental control method for a GSM-R system. The method includes: collecting event data and raw output signals from various sensors installed in the base station environment of the GSM-R system, wherein each sensor includes digital sensors and analog sensors; performing optical isolation processing on the raw output signals of the digital sensors to generate first preprocessed data, and performing programmable amplification on the raw output signals of the analog sensors to generate second preprocessed data; fusing the first preprocessed data, the second preprocessed data, and the event data to form a monitoring dataset; using a time-series pattern mining algorithm to perform pattern mining on the monitoring dataset to generate an abnormal pattern set; constructing an event reasoning graph based on the abnormal pattern set; calculating a threat assessment value by analyzing the correlation between events in the event reasoning graph; when the threat assessment value exceeds a preset threat assessment threshold, generating a security response strategy corresponding to the threat assessment value's level; and encapsulating the environmental control instructions corresponding to the security response strategy into a dedicated protocol data packet and transmitting it to the base station environment controller via GSM-R wireless communication to coordinate and adjust the operating status of the execution devices within the base station environment according to the dedicated protocol data packet.

[0017] The technical solution provided in this application has the following beneficial effects: First, by simultaneously acquiring event data and raw output signals from sensors, a more comprehensive and fundamental data foundation is provided for subsequent analysis, enhancing the integrity of the information. Second, optical isolation processing of digital signals effectively avoids signal distortion caused by electrical interference, ensuring the reliability of the data source. Simultaneously, programmable amplification of analog signals ensures the clear discernibility of weak signals, improving data usability. Third, the fusion of preprocessed data from different sources with event data forms a unified monitoring dataset, creating conditions for subsequent comprehensive analysis and avoiding data silos. Subsequently, the dataset is analyzed using a time-series pattern mining algorithm, which proactively discovers anomalies hidden in the time series, changing the traditional passive waiting mode for alarms and enabling early insight into potential risks. Then, an event reasoning graph is constructed based on the anomaly patterns and threat assessment values ​​are calculated, enabling this application to comprehensively judge the overall security situation from a correlation perspective, thereby making a more accurate threat level determination. Finally, based on the judgment results, coordinated control commands are issued through the GSM-R network, realizing closed-loop automated management from perception, analysis to decision-making and execution, improving the response speed and linkage control efficiency of this application.

[0018] Furthermore, this application begins by determining time windows from the scanned monitoring dataset, and then extracts the specific type and intensity value of events within each window; next, it uses a time-series pattern mining algorithm to conduct in-depth analysis of these event data, identifying and generating sequences of abnormal events with potential risks; finally, it counts the frequency of different event combinations in the sequence, filters out those frequently occurring abnormal combinations, and stores them centrally to form the final set of abnormal patterns.

[0019] Furthermore, by focusing on the specific manifestation of events within a time window, this method can accurately pinpoint the time period and characteristics of anomalies. By using algorithms to deeply analyze the combination patterns of event types and intensities, it can more accurately capture risk patterns that are unconventional but recurring. Finally, by filtering high-frequency anomaly combinations through frequency statistics, the output set of anomaly patterns becomes more representative and targeted, providing high-quality, low-noise input for subsequent threat reasoning and improving the signal-to-noise ratio of overall risk identification and the effectiveness of decision-making basis.

[0020] These or other aspects of this application will become more apparent in the following description of the embodiments. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 A flowchart illustrating a remote monitoring and environmental control method for a GSM-R system provided in this application embodiment; Figure 2 A schematic diagram illustrating a specific implementation of a remote monitoring and environmental control method for a GSM-R system provided in this application embodiment; Figure 3This is a schematic diagram of the structure of a remote monitoring and environmental control device for a GSM-R system provided in an embodiment of this application. Detailed Implementation

[0023] In existing monitoring schemes for GSM-R systems, the system generally relies on independent alarm data reported by each sensor and makes judgments and responses based on preset fixed thresholds. This approach treats the interconnected physical environment, equipment status, and security events within the base station environment in isolation, and its decision-making logic is static and isolated. When faced with complex risks caused by the intertwining of multiple factors in time and space, such as a chain event where air conditioner condensate leakage gradually leads to abnormal temperature rise in electrical equipment and eventually triggers a smoke alarm, existing methods cannot accurately reveal the inherent connections and causal sequence between these events. As a result, the system's assessment of the overall security situation of the environment is not comprehensive enough, and the response strategy may be one-sided or delayed.

[0024] To address the aforementioned issues, this application proposes a remote monitoring and environmental control method for GSM-R systems. This method first synchronously collects raw signals and event sequences from various sensors within the base station environment, and improves data quality and reliability through optical isolation and programmable amplification. Then, it fuses the processed multi-source data to construct a unified monitoring dataset. The core of this method lies in introducing a time-series pattern mining algorithm to perform in-depth analysis of the fused dataset, proactively identifying recurring abnormal event sequence combinations, and constructing an event reasoning graph that characterizes the causal and spatiotemporal relationships between events. Based on this graph, comprehensive reasoning can calculate more accurate threat assessment values, thereby generating hierarchical and collaborative security response strategies. Finally, through a dedicated GSM-R wireless network, the strategies are translated into specific environmental control commands for execution, enabling coordinated control of ventilation, air conditioning, alarm, and other equipment. Therefore, this solution transforms the originally isolated point information from sensors into a coherent understanding and collaborative control of the overall operational status of the base station environment through data fusion, pattern mining, and correlation reasoning. This fundamentally improves the system's ability to detect complex and hidden risks early and its efficiency in comprehensive handling, effectively solving the problem of insufficient comprehensive environmental situational awareness and collaborative response capabilities in existing technologies.

[0025] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are merely some embodiments of the present application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] The core of this application is to provide a remote monitoring and environmental control method for a GSM-R system, and a flowchart of one specific implementation is shown below. Figure 1 As shown, the method includes: Step 101: Collect event data and raw output signals from various sensors located in the base station environment of the GSM-R system. These sensors include digital sensors and analog sensors.

[0027] In step 101, the base station environment where the GSM-R system is located may include an outdoor integrated cabinet with communication equipment installed and an associated communication tower area. The number of cabinets may be one or more. When there are multiple cabinets, one serves as the main cabinet and the other serves as the slave cabinet. Digital sensors are detection devices that output signals that are clearly defined as high or low levels or digital pulses. Their signals directly express two states: on or off. These digital sensors include door magnetic sensors and electromagnetic lock status sensors deployed at the cabinet doors of outdoor all-in-one cabinets, as well as intrusion detection sensors deployed on communication towers. Analog sensors are detection devices that output continuously changing voltage or current values. The amplitude of the signal is proportional to the magnitude of the physical quantity being monitored. Analog sensors include smoke sensors, fire sensors, and temperature sensors deployed inside outdoor integrated cabinets, as well as video surveillance equipment deployed on communication towers. There can be multiple temperature sensors, and different temperature sensors are located in different locations to monitor different information. For example, multiple temperature sensors are used to monitor the temperature of the battery, the air temperature inside the cabinet, the air conditioner's outlet temperature, and the ambient temperature outside the cabinet. Preferably, to ensure a rapid response to fires in the equipment, the horizontal distance between the smoke sensor installed in the cabinet and the critical communication equipment it protects, such as the baseband processing unit and the DCDU-12B power module, should not exceed 1 meter; furthermore, the temperature sensor used to monitor the battery should be directly installed on the surface of the battery or on the nearby load-bearing bracket to accurately obtain the temperature of the equipment itself.

[0028] Event data refers to a record of data that is automatically generated and reported by each sensor when its monitoring status changes, containing the event type and the precise time of occurrence; raw output signal refers to the continuous or discrete electrical signal directly output by the sensing unit of various sensors, the form of which directly corresponds to the real-time change of the monitored physical quantity.

[0029] In this embodiment, all sensors deployed in the GSM-R system base station environment start working simultaneously. Digital sensors generate discrete signals representing state changes in real time, while analog sensors continuously output continuous electrical signals reflecting the magnitude of environmental physical quantities. By synchronously collecting and storing each event record reported by these sensors and the corresponding original electrical signal waveforms, the basic data required for subsequent processing can be obtained.

[0030] Step 102: Perform optical isolation processing on the original output signal of the digital sensor to generate first preprocessed data, and perform programmable amplification on the original output signal of the analog sensor to generate second preprocessed data.

[0031] In this embodiment, step 102 includes the following process: Step 1021: Input the original output signal of the digital sensor to the optocoupler isolation circuit, and electrically isolate the original output signal of the digital sensor through the optocoupler isolation circuit to output the isolated digital signal.

[0032] In step 1021, the optocoupler isolation circuit includes an optocoupler device. The optocoupler device converts the input electrical signal into an optical signal through a light-emitting element, and then recovers the optical signal into an electrical signal through a light-receiving element, thereby achieving electrical isolation between the input and output sides. The isolated digital signal refers to the electrical signal generated on the output side that is consistent with the logic state of the original output signal but is independent of each other in terms of potential.

[0033] In this embodiment, the original output signal of the digital sensor is first connected to the input side of the optocoupler isolation circuit. When the original output signal is high, the light-emitting element inside the optocoupler isolation circuit emits light, and the light-receiving element conducts after receiving the light signal, so that the output side generates a corresponding high-level signal. Conversely, when the original output signal is low, the light-emitting element does not emit light, the light-receiving element is cut off, and the output side generates a low-level signal. Through this process, the electrical isolation of the signal is completed and the isolated digital signal is output.

[0034] In practical applications, the digital sensor includes a door magnetic sensor, whose original output signal is a 12-volt DC voltage. After being connected to an optocoupler isolation circuit, the light-emitting diode inside the circuit emits light under the drive of the 12-volt voltage, which turns on the phototransistor on the other side, thereby generating a 5-volt digital signal at the output terminal that is consistent with the input logic but has an independent potential.

[0035] Step 1022: Identify state changes in the isolated digital signal to generate first preprocessed data.

[0036] In step 1022, the first preprocessed data includes the event type, the time information of the state change, and the number of times the change occurs.

[0037] In this embodiment, the digital signal output by the optocoupler isolation circuit is continuously monitored. When the voltage of the signal is detected to jump from low level to high level, the moment and event type are recorded as "high level trigger", and the number of transitions of the signal is incremented by one. When the signal is detected to jump from high level to low level, the moment and event type are recorded as "low level trigger" and the number of transitions is counted. Through this process, first preprocessed data containing event type, moment and count value is generated.

[0038] In practical applications, the 5-volt digital signal generated by the aforementioned door magnetic sensor after optical isolation is monitored. During one detection cycle, the signal is observed to jump from 0 volts to 5 volts at 10:05:03, and the event type is recorded as "door magnetic sensor open" and the count is recorded as 1. Then, at 10:07:15, the signal jumps back from 5 volts to 0 volts, and the event type is recorded as "door magnetic sensor closed" and the count is accumulated as 2. This generates the corresponding first preprocessed data.

[0039] Step 1023: Input the original output signal of the analog sensor to the programmable gain amplifier, adjust the amplitude of the original output signal of the analog sensor through the programmable gain amplifier, and output the amplified analog signal.

[0040] In step 1023, the programmable gain amplifier is an analog signal amplifier whose amplification factor can be adjusted by external commands. Its function is to receive the weak original output signal and amplify it according to the set factor to increase the signal amplitude for subsequent processing. The amplified analog signal refers to a continuous voltage or current signal whose amplitude is increased but whose signal shape remains consistent with the original output signal.

[0041] In this embodiment, the weak voltage signal output by the analog sensor is connected to the input of a programmable gain amplifier. Then, according to the preset amplification factor corresponding to the sensor type, a control command is sent to the amplifier to set a specific gain value. The amplifier linearly amplifies the original input signal according to the gain value, and finally obtains the amplified analog signal from the output.

[0042] In practical applications, the analog sensor includes a water immersion sensor, whose original output signal ranges from 0 to 1 volt. Based on its signal characteristics, the amplification factor of the programmable gain amplifier is preset to 10 times. When the original input signal is 0.5 volts, the amplified analog signal output after amplifier processing is 5 volts.

[0043] Step 1024: Convert the amplified analog signal into a digital signal using an analog-to-digital converter to generate second preprocessed data.

[0044] In step 1024, the analog-to-digital converter is an electronic device that converts continuous analog voltage signals into discrete digital codes. The conversion process includes sampling and quantization. The second preprocessed data includes the converted digital value and the time stamp corresponding to the conversion.

[0045] In this embodiment of the application, the amplified analog signal output by the programmable gain amplifier is connected to the analog input terminal of the analog-to-digital converter. The analog-to-digital converter samples the voltage value of the analog signal at fixed time intervals, and then converts the voltage value obtained at each sampling point into a corresponding binary number. At the same time, the time point of the conversion is recorded. Through this process, second preprocessed data containing digital values ​​and time markers is generated.

[0046] In practical applications, the amplified 5V analog signal is input into a 16-bit precision analog-to-digital converter. This converter samples once every 100 milliseconds. If a 5V sampling point is converted at 10:10:00, with a reference voltage of 5V, the converted digital value is 65535. This moment is recorded to generate a corresponding second preprocessed data.

[0047] This application effectively isolates electrical interference and enhances signal amplitude by using optocoupler isolation and programmable amplification to process different types of raw signals, thus providing a high-quality and standardized preprocessed data foundation for subsequent fusion analysis.

[0048] Step 103: Merge the first preprocessed data, the second preprocessed data, and the event data to form a monitoring dataset.

[0049] In this embodiment, step 103 includes the following process: Step 1031: Synchronize the event data of all sensors using a unified reference time to form a synchronized event sequence.

[0050] In step 1031, the unified reference time refers to a clock source time that serves as the time alignment benchmark for all data; the synchronized event sequence refers to the ordered set formed by arranging all events in the corrected time order after the original timestamps of the event data reported by each sensor have been corrected or replaced with the unified reference time.

[0051] In this embodiment, a high-precision clock is first obtained as a unified reference time source. Then, the original timestamp attached to the event data reported by each sensor is read and compared with the current unified reference time for calibration. The occurrence time of each event is corrected according to the preset time offset adjustment rules so that all events are marked with their occurrence time based on the same time base. Finally, these events based on the unified time base are sorted from early to late according to the corrected time to form a synchronized event sequence arranged in chronological order.

[0052] In a practical application, a door magnetic sensor in a base station environment reported an event data with an original timestamp of 10:05:03 and a water immersion sensor reported an event data with an original timestamp of 10:05:03:200 milliseconds. Using 10:05:03:150 milliseconds provided by the network time protocol server as the current unified reference time, after calibration, the time of the door magnetic event was corrected to 10:05:03:150 milliseconds, and the time of the water immersion event was corrected to 10:05:03:200 milliseconds. Then, the events were arranged in chronological order to form a synchronized event sequence.

[0053] Step 1032: Divide the synchronized event sequence into multiple event segments according to fixed time intervals.

[0054] In step 1032, the fixed time interval refers to a preset duration used to evenly divide the time axis; the event segment refers to a subset of all events that occur within the synchronized event sequence, from a certain start time to the end time of the start time plus the fixed time interval, and each event segment has a start time marker and an end time marker.

[0055] In this embodiment of the application, a fixed time interval, such as five minutes, is used as a preset time length. Then, starting from the moment of the first event in the synchronized event sequence, the fixed time interval is used as the step size to sequentially extract time intervals on the time axis. All events falling within each time interval are grouped into a set, and the start time and end time of each set are recorded. Through this process, the entire synchronized event sequence is divided into multiple continuous and non-overlapping event segments.

[0056] In practical applications, a fixed time interval of 5 minutes is set, starting from 10:00:00. The time range of the first event segment is from 10:00:00 to 10:05:00. This time period includes the modified door magnetic event and the water immersion event mentioned above. These two events are then included in the first event segment, with the start time marked as 10:00:00 and the end time marked as 10:05:00.

[0057] Step 1033: Merge the first preprocessed data, the second preprocessed data, and the multiple event segments to form a monitoring dataset.

[0058] In step 1033, the monitoring dataset is a structured collection of data, each of which integrates information from different types of data sources within a specific time period. This information includes event information in the event segment, signal status information in the first preprocessed data, and analog quantity conversion information in the second preprocessed data, and these information are linked together by timestamps.

[0059] In this embodiment, time is used as the association key to associate each event segment with the corresponding first and second preprocessed data within its time range. For a given event segment, firstly, all first preprocessed data records within its time range are searched, i.e., information on changes in the digital sensor signal state during that time period. Then, all second preprocessed data records within its time range are searched, i.e., digital information converted from analog sensors during that time period. These first and second preprocessed data are combined with the event information contained in the event segment itself to form a complete monitoring data record. The above association and combination operations are performed on each event segment, and finally, the complete data records corresponding to all event segments are summarized together to form the final monitoring dataset.

[0060] In practical applications, for the first event segment starting at 10:00:00 and ending at 10:05:00, the first preprocessed data recorded within this time period is retrieved, such as the state change record of the door magnetic sensor at 10:05:03:150 milliseconds. Simultaneously, the second preprocessed data recorded within this time period is retrieved, such as the digital value 65535 converted from the water immersion sensor at 10:05:03:200 milliseconds. The door magnetic event information, the door magnetic state change record, and the water immersion conversion value are then associated and combined into a single data record, representing a monitoring snapshot within this 5-minute time window. The same operation is performed on all subsequent event segments, ultimately summarizing to obtain a monitoring dataset covering the entire monitoring period.

[0061] This application integrates data from different sources and in different forms into a structured dataset with a clear time dimension through time synchronization, sequence segmentation, and data association processes, providing a high-quality and highly correlated analytical foundation for subsequent pattern mining.

[0062] Step 104: Use a time-series pattern mining algorithm to perform pattern mining on the monitoring dataset and generate an abnormal pattern set.

[0063] In this embodiment, step 104 includes the following process, such as... Figure 2 As shown: Step 1041: Scan the time series markers in the monitoring dataset and determine the range of each time window based on the time series markers.

[0064] In step 1041, the time sequence marker is the time information carried by each record in the monitoring dataset to identify the time when the event occurred or the time when the data was generated. This information comes from the time synchronization and segmentation processing in step 103. The range of the time window refers to the start and end points of a continuous time segment selected when performing pattern mining.

[0065] In this embodiment, the time stamps of all records in the monitoring dataset are first traversed to find the earliest and latest time points to determine the time span of the entire dataset. Then, based on a preset analysis granularity, such as 5 minutes as a basic unit, a series of continuous, non-overlapping time periods are divided sequentially from the earliest time point with 5 minutes as a fixed length. Each time period is defined as a time window. Through this process, the start and end times of each time window are determined.

[0066] In practical applications, the earliest time stamp in the monitoring dataset is 10:00:00 and the latest is 11:00:00. If the time window length is set to 5 minutes, then the first time window range is from 10:00:00 to 10:05:00, the second time window range is from 10:05:00 to 10:10:00, and so on, until the entire time span is covered.

[0067] Step 1042: Within each time window, scan the event markers in the monitoring dataset, and extract the event type and event intensity value of all events within the corresponding time window based on the event markers.

[0068] In step 1042, the event tag is a field in the monitoring dataset used to identify the nature of a record, indicating that the record represents a sensor event; the event type refers to the type of sensor or behavior category corresponding to the event; the event intensity value refers to the quantized value associated with the event, such as the number of signal transitions or the value after analog-to-digital conversion.

[0069] In this embodiment of the application, for each time window determined in step 1041, all records in the monitoring dataset whose time sequence markers fall within the range of that window are scanned, and then entries with event markers are identified in these records. The event category information represented by these entries is read as the event type, and the quantized value associated with the event is read as the event intensity value. Through this process, a list containing the event type and the corresponding event intensity value is extracted for each time window.

[0070] In practical applications, for a time window from 10:00:00 to 10:05:00, the scan finds two records with event markers. The event type of the first record is "door magnetic sensor open" with a corresponding event intensity value of 1. The event type of the second record is "water immersion alarm" with a corresponding event intensity value of 65535. Therefore, the event type list for this window is extracted as [door magnetic sensor open, water immersion alarm], and the corresponding event intensity value list is [1, 65535].

[0071] Step 1043: Using a time-series pattern mining algorithm, generate a target abnormal event sequence based on the event type and event intensity value of all the events.

[0072] Step 1043 may specifically include the following steps: Step A1: Based on the event type and event intensity value of all events, use a time-series pattern mining algorithm to count the baseline occurrence frequency of each event combination within the monitoring dataset.

[0073] In step A1, an event combination refers to a sequence of two or more event types arranged in chronological order within a time window; the baseline occurrence frequency refers to the total number of times a specific event combination occurs in all time windows over the entire time span of the monitoring dataset.

[0074] In this embodiment of the application, for the list of event types extracted for each time window in step 1042, firstly, within each time window, these event types are arranged into an ordered sequence according to the order in which the events occur, as the complete event combination observed in that window; then, all time windows are traversed, and each complete event combination that appears is counted. Each time the combination appears in a window, its count value is increased by one. Finally, the total number of times each event combination appears in the entire monitoring dataset is obtained, which is its baseline occurrence frequency.

[0075] In practical applications, in a 24-hour monitoring dataset, there are a total of 288 5-minute time windows. The event combination "door sensor open and then water immersion alarm" appeared in 15 of these time windows, so its baseline frequency of occurrence is 15 times.

[0076] Step A2: Determine the event combination whose occurrence frequency is greater than the preset first frequency threshold as the normal event mode.

[0077] In step A2, the preset first frequency threshold is an empirical or statistical value used to distinguish the frequency of occurrence of event combinations. If the frequency is higher than this threshold, the combination is considered to be frequent and regular. This embodiment of the application does not specifically limit the value of the preset first frequency threshold; it can be set according to actual circumstances.

[0078] In this embodiment of the application, a lower frequency limit is set as a preset first frequency threshold, for example, 10 times per day; then, the baseline occurrence frequency of each event combination obtained in step A1 is compared with the preset first frequency threshold, and event combinations with a baseline occurrence frequency greater than 10 times per day are selected and these combinations are classified and marked as normal event patterns.

[0079] In practical applications, the baseline occurrence frequency of the event combination "door magnetic sensor open and then infrared trigger" is 25 times per day, which is greater than the preset first frequency threshold of 10 times per day, so it is determined to be a normal event mode; while the baseline occurrence frequency of the event combination "water immersion alarm and then smoke alarm" is 3 times per day, which is not greater than the threshold, so it is not determined to be a normal event mode.

[0080] Step A3: Identify events in the monitoring dataset that do not belong to the normal event pattern as the initial abnormal event sequence.

[0081] In step A3, the initial abnormal event sequence refers to the event sequence within the monitoring dataset whose complete event combination does not belong to the time window of the normal event pattern determined in step A2.

[0082] In this embodiment of the application, the event combination in each time window of the monitoring dataset is checked in turn, and the event combination is compared with the normal event pattern set determined in step A2. If the event combination is not in the normal event pattern set, all event records arranged in chronological order in the time window are extracted to form an initial abnormal event sequence.

[0083] In practical applications, for the time window from 10:00:00 to 10:05:00, the event combination "door magnetic sensor open and then water immersion alarm" is not in the normal event pattern set. Therefore, the door magnetic sensor open event and the water immersion alarm event in this window are extracted in chronological order to form an initial abnormal event sequence.

[0084] Step A4: Based on the occurrence location of events and the temporal relationship between events in the initial abnormal event sequence, and combined with the event propagation model, calculate the causal correlation strength between events.

[0085] Step A4 may specifically include the following steps: B1: Based on the physical layout of the GSM-R system in the base station environment, determine the spatial distance and connection relationship between each monitoring point.

[0086] In step B1, the physical layout of the GSM-R system in the base station environment refers to the actual spatial arrangement, relative position, and physical connection relationship of the core equipment of the GSM-R network and the environmental equipment that ensures its operation within the base station environment. Monitoring points refer to the physical locations where various sensors are installed within the base station environment. Spatial distance refers to the straight-line distance between two monitoring points. Connection relationship refers to whether the monitoring points are connected by physical media such as pipes, cables, or airflow channels.

[0087] In this embodiment of the application, a layout map containing the coordinates of all monitoring points is established based on the design drawings of the base station environment and the on-site survey data. Then, for any two monitoring points, the Euclidean distance between their coordinates is calculated as the spatial distance, and the map is used to determine whether there is a direct physical connection path between them. For example, it is determined whether there is an air conditioning drainage pipe connecting the water immersion sensor point and the smoke sensor point, thereby determining their connection relationship.

[0088] In practical applications, the water immersion sensor is installed at coordinates [0, 0, 0] meters, and the smoke sensor is installed at coordinates [5, 0, 0] meters. The calculated spatial distance between the two points is 5 meters, and according to the drawings, it is confirmed that there is an air conditioning condensate pipe connecting the two.

[0089] B2: Based on the location of events in the initial abnormal event sequence, and combined with the spatial distance and the connection relationship, calculate the spatial influence factor between events.

[0090] In step B2, the spatial influence factor is a numerical value used to quantify the degree of spatial correlation between the locations where two events occur. This value is influenced by both spatial distance and connectivity.

[0091] In this embodiment of the application, for any two events in the initial abnormal event sequence, the monitoring points corresponding to them are first obtained, and the spatial distance and connection relationship between the two points determined in step B1 are queried. Then, a preset calculation rule is applied, in which the larger the spatial distance, the smaller the calculated spatial influence factor. If there is a physical connection relationship, the calculated spatial influence factor will be increased. Finally, a spatial influence factor value that comprehensively represents the degree of spatial correlation is calculated.

[0092] In practical applications, for example, when there is a physical connection, the formula for calculating the spatial influence factor is Fs=K / d, where Fs is the spatial influence factor; K is the spatial influence coefficient, with a value of 1.5; and d is the spatial distance in meters. If a physical connection exists, then Fs = K / d × C, where C is a connection enhancement coefficient. For example, C can be 1.2. For water immersion event locations and smoke event locations, with a spatial distance d of 5 meters, if a connection exists, the spatial influence factor Fs = 1.5 / 5 × 1.2 = 0.36.

[0093] B3: Based on the temporal relationship between events in the initial abnormal event sequence, analyze the time difference between adjacent events to calculate the time influence factor between events.

[0094] In step B3, the time influence factor is a value used to quantify the degree of correlation between the occurrence times of two events, and this value is inversely proportional to the time interval between the two events.

[0095] In this embodiment of the application, for any two events in the initial abnormal event sequence, firstly, their precise occurrence times are obtained, and the difference between the time of the later event and the time of the earlier event is calculated to obtain the time interval; then, a preset time decay function is applied, where the larger the time interval, the smaller the calculated time influence factor, and finally a time influence factor value representing the degree of time correlation is calculated.

[0096] In practical applications, the formula for calculating the time impact factor can be Ft = 1 / Δt, where Ft is the time impact factor, in seconds to the power of negative one; Δt is the time difference between the two events, in seconds. For the water immersion event occurring at 10:05:03.200 milliseconds and the smoke event occurring at 10:05:33.200 milliseconds, with a time interval Δt of 30 seconds, the calculated time impact factor is Ft = 1 / 30 ≈ 0.0333 per second.

[0097] B4: Based on the spatial influence factor and the temporal influence factor, the causal correlation strength between events is calculated using the event propagation model.

[0098] In step B4, the causal correlation strength is a quantitative value that integrates spatial and temporal factors and is used to characterize the degree of influence of one event on the probability of another event occurring.

[0099] In this embodiment, the event propagation model employs a linear weighted fusion formula. This model multiplies the spatial influence factor calculated in step B2 and the temporal influence factor calculated in step B3 by a preset weight coefficient, and then adds them together. The final summation result is the causal association strength, calculated as S = α × Fs + β × Ft, where S is the causal association strength; Fs is the spatial influence factor; Ft is the temporal influence factor, in negative first power of seconds; α and β are the spatial weight coefficient and the temporal weight coefficient, respectively, and α + β = 1.

[0100] In practical applications, the spatial weight coefficient α is set to 0.7 and the time weight coefficient β is set to 0.3. Substituting the spatial influence factor Fs=0.36 and the time influence factor Ft=0.0333 per second obtained above into the formula, the causal relationship strength S=0.7×0.36+0.3×0.0333≈0.262 is calculated.

[0101] Step A5: Using an attention-enhanced sequence learning mechanism, weight each event in the initial abnormal event sequence based on the causal association strength to generate the target abnormal event sequence.

[0102] In step A5, the attention-enhanced sequence learning mechanism is a data processing rule that assigns appropriate weights to each event based on its causal importance in the sequence. The target anomalous event sequence is a sequence that highlights key events after weight information is added to each event in the initial anomalous event sequence. This embodiment does not limit the specific implementation process of this mechanism and can be set accordingly based on the actual situation.

[0103] In this embodiment of the application, for an initial abnormal event sequence, based on the causal correlation strength between each event in the sequence and other events calculated in step B4, the average causal correlation strength of each event is calculated, and the average value is normalized. The normalized value is used as the weight coefficient of the event. Then, the original feature vector of each event in the initial abnormal event sequence is multiplied by its corresponding weight coefficient to generate a new feature representation with weights. The weighted feature representations of all events are arranged in the original order to form the target abnormal event sequence.

[0104] In practical applications, the initial abnormal event sequence contains two events: a water immersion alarm event E1 and a smoke alarm event E2. The calculated causal correlation strength of E1 to E2 is 0.262, and the correlation of E2 to E1 is 0. Therefore, the average causal correlation strength of E1 is (0.262+0) / 2=0.131, and the average causal correlation strength of E2 is (0+0.262) / 2=0.131. After normalization, the weight coefficients of both are 1. The event intensity value of each event is multiplied by the weight coefficient 1 to obtain the weighted event intensity value. The target abnormal event sequence generated in this way does not change the intensity value, but it already contains the weighting process. In practice, if there are multiple events, the weight coefficients of different events will be different, thereby highlighting the key events.

[0105] Step 1044: Within the target abnormal event sequence, count the frequency of abnormal occurrences of event combinations, and store the abnormal event combinations whose frequency of occurrence is greater than a preset second frequency threshold into an abnormal pattern set.

[0106] In step 1044, the anomaly occurrence frequency refers to the total number of times a specific event combination occurs within the set of all target anomaly event sequences; the preset second frequency threshold is a threshold value used to determine whether the anomaly pattern is statistically significant. This embodiment does not specifically limit the value of the preset second frequency threshold; it can be set according to actual circumstances.

[0107] In this embodiment of the application, firstly, all target abnormal event sequences generated by step A5 are summarized. In these sequences, the number of times each event combination occurs is counted to obtain its abnormal occurrence frequency. Then, a threshold value for filtering abnormal patterns is set as a preset second frequency threshold. Event combinations with abnormal occurrence frequencies greater than the threshold are filtered out and stored in a special set, which is the final generated abnormal pattern set.

[0108] In practical applications, a total of 50 target abnormal event sequences were generated in the monitoring data over a period of one week. The event combination "water immersion alarm followed by smoke alarm" appeared 8 times in these sequences, with an abnormal occurrence frequency of 8. The preset second frequency threshold is 5 times per week. Since 8 is greater than 5, the event combination "water immersion alarm followed by smoke alarm" is stored in the abnormal pattern set.

[0109] This application utilizes a process of time-series pattern mining, causal correlation analysis, and attention weighting to automatically identify and extract statistically significant and causally related abnormal event combination patterns from monitoring data, thereby achieving accurate capture and structured representation of complex hidden risks.

[0110] Step 105: Based on the set of abnormal patterns, construct an event reasoning graph. By analyzing the correlation between events in the event reasoning graph, calculate the threat assessment value. When the threat assessment value exceeds a preset threat assessment threshold, generate a security response strategy corresponding to the level of the threat assessment value.

[0111] In step 105, the preset threat assessment threshold is a pre-set threshold value used to trigger different levels of response. In this embodiment, the size of the threshold is not specifically limited. The level to which the threat assessment value belongs refers to the range of intervals divided according to the size of the threat assessment value. Each interval corresponds to a preset response level. The security response strategy is a set of specific control instructions formulated for a specific threat level, including which devices to adjust and what operations to perform. In this embodiment, the content of the strategy is not specifically limited.

[0112] In this embodiment, step 105 includes the following process: Step 1051: Construct an event reasoning graph using each event type in the set of abnormal patterns as a node and the temporal causal relationship between events as an edge.

[0113] In step 1051, a node is a basic unit in a graph structure, which in this application is used to represent a specific type of event; the temporal causal relationship between events refers to the temporal sequence between the occurrence of one event type and the occurrence of another event type, and this relationship comes from the fixed order reflected in the set of abnormal patterns mined in step 104; An edge is a directed line segment connecting two nodes in a graph, used to represent the temporal causal relationship between the event types represented by the nodes; an event reasoning graph is a network structure composed of nodes and directed edges, used to intuitively represent the potential impact paths between different abnormal event types.

[0114] In this embodiment, firstly, the abnormal pattern set is traversed to extract all the different event types contained therein, and a corresponding node is created for each event type. Then, for each event combination in the abnormal pattern set, the occurrence order of the event types is analyzed. For two consecutive event types, a directed edge is established between their corresponding two nodes. The direction of the directed edge is from the node of the previous event type to the node of the next event type, and a weight value is assigned to the edge, which comes from the causal relationship strength calculated in step 104. By traversing all abnormal patterns and establishing directed edges for each pair of consecutive event types, an event reasoning graph with event types as nodes, temporal causal relationships as directed edges, and weighted edges is finally constructed.

[0115] In practical applications, if the abnormal pattern set contains an event combination "water immersion alarm followed by smoke alarm", then two event types, "water immersion alarm" and "smoke alarm", are extracted, and nodes N1 and N2 are created for these two types respectively. According to the order of the combination, a directed edge from N1 to N2 is established between nodes N1 and N2, and the causal correlation strength of 0.262 between the two events calculated in step 104 is used as the weight of the edge.

[0116] Step 1052: In the event reasoning graph, analyze the correlation between events based on the connection density and path length between nodes.

[0117] In step 1052, the connection density refers to the number of edges directly connected to a node in a graph, which reflects the extent of the direct connections between that node and other nodes; the path length refers to the minimum number of edges required to reach another node from one node along a directed edge in a graph, which reflects the tightness of the indirect connections between two nodes.

[0118] In this embodiment of the application, a topological analysis is performed on the event reasoning graph constructed in step 1051. For each node in the graph, the total number of directed edges starting from or ending at that node is counted, and this total number is the connection density of that node. Then, for any two nodes in the graph, a graph traversal algorithm is used to find whether there is a path composed of directed edges between the starting node and the target node. If there is, the number of directed edges traversed on this path is calculated, and this number is the path length between the two nodes. If there is no reachable path, the path length is considered to be infinite. By calculating the connection density and path length of all important node pairs in the graph, the direct and indirect associations between different event types are quantitatively analyzed.

[0119] In practical applications, in the event reasoning graph, if the node "water immersion alarm" is connected to a directed edge pointing to "smoke alarm", then its connection density is 1; if the node "smoke alarm" is connected to a directed edge from "water immersion alarm", then its connection density is also 1; there is a direct directed edge from the node "water immersion alarm" to the node "smoke alarm", so the path length between them is 1.

[0120] Step 1053: Calculate the threat assessment value based on the tightness of the relationship and the event type weight of the node.

[0121] In step 1053, the tightness of the association is a comprehensive measure, which is calculated based on the node connection density and path length obtained from step 1052. The higher the connection density and the shorter the path length, the tighter the association. The event type weight of the node is a priority parameter that is set in advance for each event type based on experience or security importance. The threat assessment value is a quantitative value that combines the tightness of the association and the event type weight, and is used to characterize the overall threat level reflected by the current set of abnormal patterns.

[0122] In this embodiment of the application, for each node in the event reasoning graph, its corresponding local threat contribution value is calculated. Specifically, for any node, its local threat contribution value can be the ratio of the product of the preset weight of the event type corresponding to the node and the connection density of the node in the event reasoning graph to a factor. The factor is a path length factor that characterizes the degree of centrality of the node in the graph, and the path length factor is defined as the average shortest path length from the node to all other reachable nodes in the graph. Next, after obtaining the local threat contribution values ​​of all nodes in the graph, these local threat contribution values ​​are summed up by accumulating them. The sum can be used as the final threat assessment value of the entire graph; or the local threat contribution value with the largest value among all nodes can be selected as the final threat assessment value of the entire graph.

[0123] In practical applications, the event type weight W1 of the "water immersion alarm" node is set to 0.3, and the event type weight W2 of the "smoke alarm" node is set to 0.8. The local threat contribution values ​​of the two nodes are calculated. The connection density D1 of the "water immersion alarm" node is 1, and its path length L1 to the most relevant node in the graph, such as the smoke alarm node, is 1. Its local threat contribution value T1 is calculated using the formula T1=(W1×D1) / L1, which gives T1=(0.3×1) / 1=0.3. The connection density D2 of the "smoke alarm" node is 1, and its path length L2 is defined as the length from itself to itself, denoted as 1. Its local threat contribution value T2=(W2×D2) / L2=(0.8×1) / 1=0.8. The final threat assessment value is the largest local threat contribution value among all nodes, i.e., V=max(T1,T2)=0.8.

[0124] This application transforms fragmented anomaly patterns into a quantitative assessment of the overall security situation by constructing an event reasoning graph and calculating a comprehensive threat assessment value. Based on this assessment, it enables graded and precise automated security responses, thereby improving the pertinence and timeliness of risk response.

[0125] Step 106: Encapsulate the environmental control instructions corresponding to the security response strategy into a dedicated protocol data packet and transmit it to the base station environment controller via GSM-R wireless communication, so as to coordinate and adjust the operating status of the execution devices in the base station environment according to the dedicated protocol data packet.

[0126] In step 106, GSM-R wireless communication refers to a communication method that uses the dedicated wireless network of the Global Railway Mobile Communication System for data transmission; the environmental control command corresponding to the security response strategy refers to the set of commands generated based on the threat level calculated in the aforementioned steps, used to operate equipment such as ventilation, air conditioning, and alarms within the base station environment. A dedicated protocol data packet refers to a complete data unit that can be transmitted on the GSM-R network, which is assembled from the aforementioned control commands and necessary address, check and other information according to the specific data format and communication rules agreed upon between the GSM-R network and the equipment. The base station environment controller can be a controller used to coordinate and regulate the operating status of the devices within the base station environment. This embodiment does not limit the structure or type of the controller. The equipment within the base station environment refers to the physical devices that are remotely controlled and used to regulate the base station environment. These physical devices include ventilation equipment, air conditioning systems, security alarm devices, etc., such as the air conditioning thermostat and air conditioner built into the cabinet.

[0127] In this embodiment, specific environmental control instructions are first generated based on the content of the security response strategy. Then, these instructions, along with the identification information of the target base station environment, are assembled and encapsulated according to the dedicated protocol format specified by the GSM-R network to form a dedicated protocol data packet that can be transmitted in the wireless network. Next, the dedicated protocol data packet is sent to the target base station environment through the base station and wireless link of the GSM-R network. After receiving the data packet, the receiving device in the base station environment parses it, extracts the environmental control instructions, and coordinates the ventilation equipment to adjust the wind speed, controls the air conditioning system to change the operating mode and temperature setting, and activates the corresponding audible and visual alarm devices according to the instructions, thereby realizing remote automated environmental control and security response.

[0128] Figure 3 A schematic diagram of a remote monitoring and environmental control device for a GSM-R system provided in this application embodiment is shown below. Figure 3 As shown, the detailed implementation section describes: The acquisition module 31 is used to acquire event data and raw output signals of various sensors set in the base station environment of the GSM-R system. The sensors include digital sensors and analog sensors.

[0129] The isolation module 32 is used to perform optical isolation processing on the original output signal of the digital sensor to generate first pre-processed data, and to perform programmable amplification on the original output signal of the analog sensor to generate second pre-processed data.

[0130] The fusion module 33 is used to fuse the first preprocessed data, the second preprocessed data, and the event data to form a monitoring dataset.

[0131] The generation module 34 is used to perform pattern mining on the monitoring dataset using a time-series pattern mining algorithm to generate an abnormal pattern set.

[0132] The construction module 35 is used to construct an event reasoning graph based on the set of abnormal patterns, calculate a threat assessment value by analyzing the correlation between events in the event reasoning graph, and generate a security response strategy corresponding to the level of the threat assessment value when the threat assessment value exceeds a preset threat assessment threshold.

[0133] The adjustment module 36 is used to encapsulate the environmental control instructions corresponding to the security response strategy into a dedicated protocol data packet and transmit it to the base station environment controller via GSM-R wireless communication, so as to coordinate and adjust the operating status of the execution equipment in the base station environment according to the dedicated protocol data packet.

[0134] The remote monitoring and environmental control device for the GSM-R system in this application is used to implement the aforementioned remote monitoring and environmental control method for the GSM-R system. Therefore, the specific implementation of the remote monitoring and environmental control device for the GSM-R system can be found in the embodiment section of the remote monitoring and environmental control method for the GSM-R system above. The specific implementation can be referred to the description of the corresponding embodiments, which will not be repeated here.

[0135] This application also provides an electronic device, comprising: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of the remote monitoring and environmental control method of any of the above-described GSM-R systems.

[0136] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the remote monitoring and environmental control method for any of the GSM-R systems described above.

[0137] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB flash drives, read-only memory, random access memory, portable hard drives, magnetic disks, or optical disks.

[0138] The embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the embodiments of the remote monitoring and environmental control method for the GSM-R system described above.

[0139] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0140] The foregoing has provided a detailed description of a remote monitoring and environmental control method and apparatus for a GSM-R system. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are merely for the purpose of helping to understand the method and its core ideas. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from its principles, and these improvements and modifications also fall within the protection scope of this application.

Claims

1. A method for remote monitoring and environmental control of a GSM-R system, characterized in that, include: The system collects event data and raw output signals from various sensors located in the base station environment of the GSM-R system. These sensors include both digital and analog sensors. The original output signal of the digital sensor is optically isolated to generate first preprocessed data, and the original output signal of the analog sensor is amplified by programmable control to generate second preprocessed data. The first preprocessed data, the second preprocessed data, and the event data are fused together to form a monitoring dataset. Using a time-series pattern mining algorithm, pattern mining is performed on the monitoring dataset to generate an abnormal pattern set; Based on the set of abnormal patterns, an event reasoning graph is constructed. By analyzing the correlation between events in the event reasoning graph, a threat assessment value is calculated. When the threat assessment value exceeds a preset threat assessment threshold, a security response strategy corresponding to the level of the threat assessment value is generated. The environmental control instructions corresponding to the security response strategy are encapsulated into dedicated protocol data packets and transmitted to the base station environment controller via GSM-R wireless communication, so as to coordinate and adjust the operating status of the execution devices in the base station environment according to the dedicated protocol data packets. The step of using a time-series pattern mining algorithm to perform pattern mining on the monitoring dataset and generate an abnormal pattern set includes: Scan the time series markers in the monitoring dataset, and determine the range of each time window based on the time series markers; Within each time window, the event markers in the monitoring dataset are scanned, and the event type and event intensity value of all events within the corresponding time window are extracted based on the event markers. Using a time-series pattern mining algorithm, a target abnormal event sequence is generated based on the event type and event intensity value of all the events. Within the target abnormal event sequence, the frequency of abnormal occurrences of event combinations is counted, and abnormal event combinations whose abnormal occurrence frequency is greater than a preset second frequency threshold are stored in an abnormal pattern set. The time-series pattern mining algorithm generates a target anomalous event sequence based on the event type and event intensity value of all events, including: Based on the event type and event intensity value of all events, a time-series pattern mining algorithm is used to count the baseline occurrence frequency of each event combination within the monitoring dataset. The combination of events whose occurrence frequency is greater than a preset first frequency threshold is defined as a normal event pattern; Events in the monitoring dataset that do not belong to the normal event pattern are identified as the initial abnormal event sequence; Based on the location of events and the temporal relationship between events in the initial abnormal event sequence, and combined with the event propagation model, the causal correlation strength between events is calculated; By utilizing an attention-enhanced sequence learning mechanism, the events in the initial abnormal event sequence are weighted based on the causal association strength to generate a target abnormal event sequence. The step of calculating the causal correlation strength between events based on the occurrence location and temporal relationship of events in the initial abnormal event sequence, combined with the event propagation model, includes: Based on the physical layout of the GSM-R system in the base station environment, the spatial distance and connection relationship between each monitoring point are determined; Based on the location of events in the initial abnormal event sequence, and combined with the spatial distance and the connection relationship, the spatial influence factor between events is calculated; Based on the temporal relationship between events in the initial abnormal event sequence, the time difference between adjacent events is analyzed to calculate the time influence factor between events; Based on the spatial influence factor and the temporal influence factor, the causal correlation strength between events is calculated using an event propagation model.

2. The remote monitoring and environmental control method for the GSM-R system according to claim 1, characterized in that, The process of optically isolating the raw output signal of the digital sensor to generate first preprocessed data, and then programmatically amplifying the raw output signal of the analog sensor to generate second preprocessed data, includes: The original output signal of the digital sensor is input to the optocoupler isolation circuit, which electrically isolates the original output signal of the digital sensor and outputs the isolated digital signal. The isolated digital signal is subjected to state change identification to generate first preprocessed data; The original output signal of the analog sensor is input to a programmable gain amplifier, and the amplitude of the original output signal of the analog sensor is adjusted by the programmable gain amplifier to output an amplified analog signal. The amplified analog signal is converted into a digital signal by an analog-to-digital converter to generate the second preprocessed data.

3. The remote monitoring and environmental control method for the GSM-R system according to claim 1, characterized in that, The step of constructing an event reasoning graph based on the set of abnormal patterns, and calculating a threat assessment value by analyzing the correlation between events in the event reasoning graph, includes: Using each event type in the set of abnormal patterns as a node and the temporal causal relationship between events as an edge, an event reasoning graph is constructed. In the event reasoning graph, the relationships between events are analyzed based on the connection density and path length between nodes; The threat assessment value is calculated based on the tightness of the relationship and the event type weight of the node.

4. The remote monitoring and environmental control method for the GSM-R system according to claim 1, characterized in that, The step of fusing the first preprocessed data, the second preprocessed data, and the event data to form a monitoring dataset includes: The event data from all sensors are synchronized at specific points in time using a unified reference time to form a synchronized event sequence. The synchronized event sequence is divided into multiple event segments according to fixed time intervals; The first preprocessed data, the second preprocessed data, and the multiple event segments are fused together to form a monitoring dataset.

5. A remote monitoring and environmental control device for a GSM-R system, characterized in that, include: The acquisition module is used to acquire event data and raw output signals from various sensors installed in the base station environment of the GSM-R system. The sensors include digital sensors and analog sensors. An isolation module is used to perform optical isolation processing on the raw output signal of the digital sensor to generate first pre-processed data, and to perform programmable amplification on the raw output signal of the analog sensor to generate second pre-processed data. The fusion module is used to fuse the first preprocessed data, the second preprocessed data, and the event data to form a monitoring dataset; The generation module is used to perform pattern mining on the monitoring dataset using a time-series pattern mining algorithm to generate an abnormal pattern set. The construction module is used to construct an event reasoning graph based on the set of abnormal patterns, calculate the threat assessment value by analyzing the correlation between events in the event reasoning graph, and generate a security response strategy corresponding to the level of the threat assessment value when the threat assessment value exceeds a preset threat assessment threshold. The adjustment module is used to encapsulate the environmental control instructions corresponding to the security response strategy into dedicated protocol data packets and transmit them to the base station environment controller via GSM-R wireless communication, so as to coordinate and adjust the operating status of the execution devices in the base station environment according to the dedicated protocol data packets; The step of using a time-series pattern mining algorithm to perform pattern mining on the monitoring dataset and generate an abnormal pattern set includes: Scan the time series markers in the monitoring dataset, and determine the range of each time window based on the time series markers; Within each time window, the event markers in the monitoring dataset are scanned, and the event type and event intensity value of all events within the corresponding time window are extracted based on the event markers. Using a time-series pattern mining algorithm, a target abnormal event sequence is generated based on the event type and event intensity value of all the events. Within the target abnormal event sequence, the frequency of abnormal occurrences of event combinations is counted, and abnormal event combinations whose abnormal occurrence frequency is greater than a preset second frequency threshold are stored in an abnormal pattern set. The time-series pattern mining algorithm generates a target anomalous event sequence based on the event type and event intensity value of all events, including: Based on the event type and event intensity value of all events, a time-series pattern mining algorithm is used to count the baseline occurrence frequency of each event combination within the monitoring dataset. The combination of events whose occurrence frequency is greater than a preset first frequency threshold is defined as a normal event pattern; Events in the monitoring dataset that do not belong to the normal event pattern are identified as the initial abnormal event sequence; Based on the location of events and the temporal relationship between events in the initial abnormal event sequence, and combined with the event propagation model, the causal correlation strength between events is calculated; By utilizing an attention-enhanced sequence learning mechanism, the events in the initial abnormal event sequence are weighted based on the causal association strength to generate a target abnormal event sequence. The step of calculating the causal correlation strength between events based on the occurrence location and temporal relationship of events in the initial abnormal event sequence, combined with the event propagation model, includes: Based on the physical layout of the GSM-R system in the base station environment, the spatial distance and connection relationship between each monitoring point are determined; Based on the location of events in the initial abnormal event sequence, and combined with the spatial distance and the connection relationship, the spatial influence factor between events is calculated; Based on the temporal relationship between events in the initial abnormal event sequence, the time difference between adjacent events is analyzed to calculate the time influence factor between events; Based on the spatial influence factor and the temporal influence factor, the causal correlation strength between events is calculated using an event propagation model.

6. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the steps of the remote monitoring and environmental control method for the GSM-R system as described in any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, enables the remote monitoring and environmental control method for the GSM-R system as described in any one of claims 1 to 4.