Network convergence-oriented AI-driven heterogeneous cooperative system and data processing method
By integrating multi-core processors, GPUs/NPUs/DPUs, and hardware-level encryption modules through an AI-driven heterogeneous collaborative system, the bottlenecks of existing communication systems in network convergence, heterogeneous computing power collaboration, and hardware-level security have been solved, achieving high-security, low-latency data transmission and adapting to various scenario requirements.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING JIAOTONG UNIV
- Filing Date
- 2026-01-08
- Publication Date
- 2026-05-05
AI Technical Summary
Existing communication systems have bottlenecks in network convergence, heterogeneous computing power collaboration, and hardware-level security, and cannot meet the high security, low latency, and high reliability data transmission requirements of fields such as vehicle-mounted communication, rail transit, low-altitude intelligent networks, and satellite communication.
The AI-driven heterogeneous collaborative system includes routing control boards, AI computing boards, and security boards. Through multi-core heterogeneous processors, GPU/NPU/DPU computing cores, hardware-level encryption modules, and internal and external network synchronous protection modules, it achieves dynamic fusion transmission of multiple networks, intelligent routing, and end-to-end trusted transmission.
It achieves deep collaboration of heterogeneous computing resources, improves network resource utilization and security protection, adapts to dynamic needs in multiple scenarios, supports the access of new technologies and fault self-healing, and ensures the reliability and security of data transmission.
Smart Images

Figure CN121984879A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, specifically to an AI-driven heterogeneous collaborative system and data processing method for network convergence. Background Technology
[0002] As intelligent connected vehicles, rail transit (including heavy-haul transportation), low-altitude intelligent networks (such as drone swarms), and satellite communications rapidly evolve towards intelligence, unmanned operation, and high reliability, the data transmission demands in various scenarios are exhibiting a "double surge": On the one hand, the data exchange volume in vehicle-mounted environments (vehicle-road cooperative data), rail transit vehicle-to-ground systems (real-time dispatching / status monitoring / video transmission of heavy-haul trains), low-altitude intelligent networks (drone swarm control / high-definition data transmission), and satellite communications (integrated air-space-ground data interaction) is growing exponentially; on the other hand, the demand for low-latency stability, high-reliability redundancy, and security protection levels (such as data encryption, electromagnetic interference resistance, and link hijacking resistance) in data transmission has significantly increased, becoming a core bottleneck restricting the implementation of technologies in various fields.
[0003] Current mainstream communication systems and core routing equipment still suffer from the following two major technical deficiencies, making them unable to meet the above requirements:
[0004] 1. Inherent flaws in the existing network architecture: difficulty in supporting the demand for "converged transmission".
[0005] Current vehicle-mounted communication networks, railway LTE-R vehicle-to-ground systems, low-altitude local communication networks, and satellite ground access networks generally adopt a single-network architecture or a multi-network discrete deployment mode, leading to three core problems:
[0006] (1) Insufficient reliability: A single network is susceptible to scenario-based interference (such as signal attenuation in rail transit tunnels, complex low-altitude electromagnetic environment, and obstruction of vehicle-mounted mobile channels) or link interruption (such as rain attenuation of satellite links), and cannot provide fault redundancy; while when multiple networks are deployed separately, each network operates independently and resources are fragmented, making it impossible to realize link status awareness and dynamic resource allocation (such as when a heavy-load train enters a tunnel, it cannot quickly switch to other backup links after LTE-R is interrupted).
[0007] (2) Uncertainty of latency: When facing real-time services (such as vehicle-to-everything (V2X) control signals, heavy-load train dispatching instructions, and UAV real-time control data), a single network architecture is difficult to avoid sudden latency fluctuations, and a discrete architecture cannot guarantee latency stability through multi-network collaboration, resulting in the risk of delayed service response.
[0008] (3) Weak security protection: Existing solutions lack an integrated security mechanism that adapts to multiple scenarios. In vehicle scenarios, data tampering in the Internet of Vehicles is easy to be tampered with; in rail transit scenarios, signal transmission hijacking needs to be prevented; in low-altitude intelligent networks, electromagnetic interference needs to be resisted; and in satellite communications, sensitive data encryption needs to be ensured. However, the decentralized security strategy under the separate architecture cannot form a protection loop, resulting in prominent security vulnerabilities.
[0009] 2. Limitations in the computing power and functionality of existing controllers: insufficient to support the requirements of "collaborative intelligence".
[0010] As core equipment in various communication systems (such as vehicle-mounted routers, vehicle-to-ground communication controllers, and low-altitude intelligent network gateways), existing routing devices generally adopt a centralized control structure with a single CPU, which can only complete basic network protocol processing and data forwarding. This fails to meet the three key requirements of "heterogeneous computing power collaboration, AI intelligent decision-making, and hardware-level security." Specific bottlenecks are as follows:
[0011] (1) Lack of heterogeneous computing power collaboration: A single CPU cannot integrate heterogeneous computing power resources such as "general computing (CPU), AI computing (GPU / TPU, used for routing decision optimization) and dedicated encryption computing (hardware encryption chip)", resulting in two types of problems: First, the AI computing power is insufficient, and it is impossible to generate intelligent routing strategies based on real-time business needs (bandwidth, latency) and network status (link quality, load); Second, computing power resources are wasted, and general computing and dedicated computing resources cannot be dynamically allocated, resulting in insufficient computing power utilization when facing multiple services in parallel (such as heavy-load trains transmitting scheduling signals and video backhaul at the same time).
[0012] (2) Insufficient network convergence intelligence: The lack of AI-driven heterogeneous multi-network convergence algorithms makes it impossible to dynamically select the optimal transmission path based on service priorities (such as "control signals > video data" in vehicle scenarios and "cluster commands > backhaul data" in low-altitude intelligent networks). It also makes it impossible to achieve seamless switching and bandwidth aggregation of heterogeneous multi-networks (such as "cellular + short-range" in vehicle scenarios and "LTE-R + satellite backup" in rail transit), resulting in inefficient use of network resources.
[0013] (3) Lack of hardware-level security: A single CPU architecture is difficult to integrate hardware-level encryption modules (such as national cryptographic algorithm chips) and anti-interference circuits. It can only rely on software encryption to achieve basic protection, which cannot meet the stringent requirements of "hardware-level anti-tampering and link-level anti-hijacking" in high-security scenarios (such as rail transit signal transmission and satellite sensitive data interaction), resulting in insufficient security protection level.
[0014] In summary, existing technical solutions have significant bottlenecks in four dimensions: network convergence capability, heterogeneous computing power collaboration, AI intelligent routing, and hardware-level security. They cannot meet the data transmission requirements of "high security, low latency, and high reliability" in various scenarios such as vehicle-mounted communication networks, rail transit vehicle-to-ground data transmission systems, low-altitude intelligent network data transmission systems, and satellite communication networks. Summary of the Invention
[0015] This invention aims to provide an AI-driven heterogeneous collaborative system and data processing method for network convergence, which has the functions of "network converged transmission + heterogeneous controller collaboration + AI-driven intelligent routing + hardware-level security encryption" to solve the above problems.
[0016] The technical solution of this invention is: an AI-driven heterogeneous collaborative system for network convergence, which can simultaneously access at least two of the following: public network, private network, satellite communication network, and short-range communication network. Based on the decision-making of the AI computing board, it achieves dynamic multi-network converged transmission, including:
[0017] The routing control board has a built-in multi-core heterogeneous processor for performing network protocol parsing, data forwarding, multi-network link control, and QoS scheduling.
[0018] AI computing board integrates at least one computing core from GPU, NPU, and DPU, and runs business classification model, traffic prediction model, heterogeneous network collaboration model and security compliance review model to generate network resource allocation and transmission path decisions and data compliance review results;
[0019] Security boards are used to implement hardware-level encryption, decryption, authentication, and key updates, build end-to-end trusted transmission links, and perform security verification on data entering and leaving the intranet.
[0020] Internal and external network synchronization protection module: Located between the internal network and the external network, the internal network is a security domain carrying business data flows that require security protection, and the external network is a converged transmission domain that includes at least two of the following: public network, private network, satellite communication network, and short-range communication network; the internal and external network synchronization protection module is used to realize security mapping, data filtering, and policy synchronization between the internal network and the external network, ensuring that data flows entering and leaving the internal network must be verified by the security board and reviewed for security compliance by the AI computing board before being forwarded to the external network by the routing control board, or that data returned from the external network enters the internal network after reverse verification;
[0021] The software architecture adopts a multi-operating system cascade structure, with different boards running independent OSs. Cross-system communication, task synchronization, and data consistency maintenance are achieved through a middleware layer.
[0022] The high-speed interconnect bus connects routing control boards, AI computing boards, and security boards, and enables high-speed data exchange and synchronization through shared memory areas and cross-domain data buffering mechanisms.
[0023] Preferably, the multi-core heterogeneous processor built into the routing control board is a multi-core heterogeneous architecture, which runs an operating system and supports differentiated scheduling of heterogeneous multi-source data;
[0024] The AI computing board includes a multi-model fusion algorithm that can dynamically adjust decision weights based on business type, with security-related businesses having higher priority than non-security-related businesses. Security-related businesses include control signals and scheduling instructions; non-security-related businesses include video transmission and entertainment data.
[0025] The security board supports at least one of the encryption algorithms AES, RSA, SM4, and SM9, and the key update cycle can be dynamically adjusted based on network status.
[0026] High-speed interconnect buses include PCIe, SerDes, or CCIX buses.
[0027] Preferably, the internal and external network synchronous protection module is used to realize data isolation and mapping between the internal network and the external network to prevent information leakage; wherein, the internal network includes a security domain and the external network includes a transmission domain.
[0028] Preferably, the short-range communication network includes at least one of Wi-Fi, LoRa, Bluetooth, and drone self-organizing networks.
[0029] Preferably, the system is applicable to at least one of the following scenarios: vehicle-mounted communication network, rail transit vehicle-to-ground data transmission system, low-altitude intelligent network data transmission system, and satellite communication network.
[0030] Preferably, it also includes a synchronous protection mechanism for internal and external networks. This mechanism is based on a hardware architecture to build a collaborative protection system for the security domain and the transmission domain, specifically including:
[0031] The intranet is a security domain used to carry business data streams that require security protection. The flow of this business data stream must go through encryption processing by the security board, security compliance model review by the AI computing board, and then be transmitted to the routing control board after the review is passed.
[0032] The external network is the transmission domain, which is a converged network consisting of at least two of the following: public network, private network, satellite communication network, and short-range communication network. It is used to receive encrypted service data streams forwarded by the routing control board.
[0033] The internal and external network synchronization protection mechanism also includes an internal and external network synchronization protection module, which is deployed between the internal and external networks and is used for:
[0034] 1) Synchronize the encryption policy of the intranet security card with the security status of the external network transmission link in real time to ensure that the encryption algorithm, key version and external network link protection requirements are matched;
[0035] 2) Perform reverse verification on feedback data returned from the external network to the internal network: First, decrypt the data through the security board, and then verify the integrity and legality of the source through the AI calculation board. Only after the verification is passed can the data be allowed to enter the internal network security domain.
[0036] 3) Intercept illegal data that fails the AI model review and encrypted data with mismatched keys, while generating anomaly logs and triggering alarms to achieve full control and traceability of data interaction between internal and external networks.
[0037] Preferably, the security compliance model review of the AI computing board specifically includes the review of the legality of the business type, the integrity of the data format, and the matching degree of the transmission priority of the business data flow. Data that fails the review will be returned to the internal network source and will not be allowed to enter the routing and forwarding process. Among them, the review of the legality of the business type of the business data flow includes whether it belongs to the preset security business list, the review of the integrity of the data format includes whether it complies with the encrypted transmission specifications, and the review of the matching degree of the transmission priority includes whether it is compatible with the bandwidth and latency indicators of the external network link.
[0038] An AI-driven heterogeneous collaborative data processing method for network fusion includes the following steps:
[0039] S1: Business data undergoes encryption and integrity verification via the security board; this step corresponds to the security board processing stage, where business data first enters the security board and undergoes encryption and integrity verification to ensure the original security of the data.
[0040] S2: Encrypted data is transmitted to the AI computing board. The AI model in the AI computing board analyzes the network status, service priority, and bandwidth information to generate the optimal transmission strategy. This step corresponds to the decision-making process of the AI computing board. The encrypted data is then transmitted to the AI computing board. Before routing, the AI model comprehensively analyzes the network status, service priority, and bandwidth information to dynamically generate the optimal transmission strategy, rather than the traditional static routing configuration.
[0041] S3: The routing control board performs multi-network scheduling and load balancing according to the transmission strategy to achieve data fusion transmission. This step corresponds to the execution stage of the routing control board, that is, the routing control board receives encrypted data and strictly follows the transmission strategy generated by the AI calculation board to perform specific multi-network scheduling and load balancing operations to achieve data fusion transmission in heterogeneous networks.
[0042] S4: The receiving end performs reverse decryption and verification through the security board to complete the data distribution. This step corresponds to the receiving end processing stage, that is, after the data is transmitted through the heterogeneous network to the receiving end, it is reverse decrypted and verified through the receiving end's security board to finally complete the secure distribution of the data.
[0043] Preferably, the AI-driven heterogeneous collaborative intelligent router system architecture for network convergence includes timing logic in three scenarios: normal data transmission, abnormal blocking, and dynamic policy adjustment;
[0044] Scenario 1 is: one-way data transmission. Data must be transmitted serially through FPGA, GPU, and CPU. If any link is disconnected or rejected, the data cannot reach the external network. It includes the following steps: sending the original sensitive data, transmitting the encrypted data stream, passing the review and then transferring it to the routing layer, and finally distributing it to the external network.
[0045] Scenario 2 is: the circuit breaker function of AI. When the GPU detects an anomaly, it not only cuts off the path to the CPU, but also sends an alarm to the management plane, including the following steps: intercepting the interrupted transmission;
[0046] Scenario 3: System intelligence. When the CPU senses a deterioration in the external network environment, the system does not passively wait, but actively triggers the Sync agent. The Sync agent then directs three boards to coordinate adjustments in parallel: the FPGA reduces the encryption load to gain speed, the AI adjusts the review strategy, and the CPU switches physical links. This includes: reporting network status data, switching to low-bandwidth-overhead encryption algorithms, adjusting review thresholds to prioritize survival, and updating routing weights to switch to satellite links.
[0047] Preferably, in step S2, the AI model can predict network traffic status in real time, adjust the transmission path in advance, and reduce data packet loss rate; in step S3, multi-network scheduling supports rapid switching of link failures and has link-level redundancy backup capability.
[0048] The beneficial effects of this invention are as follows:
[0049] (1) Deeper heterogeneous computing power collaboration solves the problem of "computing power fragmentation and efficiency bottleneck": Existing technologies either rely on a single CPU or only shallowly integrate FPGA / GPU (with loose coupling between control logic and main control), resulting in "memory walls" in data transfer and rigid scheduling. This invention achieves deep collaboration through a three-board distributed architecture of "routing control + AI computing + security" via PCIe / SerDes high-speed bus and shared memory area, integrating general computing (CPU), AI computing (GPU / NPU / DPU), and dedicated encrypted computing (FPGA) resources. With the fine-grained scheduling of unified middleware, it avoids inefficient interaction between heterogeneous computing power, reduces latency in multi-service concurrent processing, improves computing power utilization, and solves the pain point of "insufficient computing power and waste" in existing technologies.
[0050] (2) AI-driven multi-network fusion is more intelligent and overcomes the "shortcomings of static scheduling and reliability": Existing technologies mostly use static weights or simple algorithms to achieve multi-network switching, which cannot adapt to highly dynamic scenarios. This invention integrates multiple models such as service classification, traffic prediction, and heterogeneous network collaboration to perceive the bandwidth, latency, and packet loss rate of each network in real time, dynamically calculate transmission weights and achieve millisecond-level fault switching, and supports multi-network bandwidth aggregation (such as 5G + satellite + Wi-Fi collaboration), improving link reliability and solving the problems of easy interruption of a single network and fragmentation of multi-network resources. It is especially suitable for extreme scenarios such as rail transit tunnels and complex low-altitude electromagnetic environments.
[0051] (3) A more comprehensive security protection system, achieving "hardware-level end-to-end trusted transmission": Existing technologies rely on software encryption or single hardware acceleration for security protection, lacking a complete closed-loop system. This invention integrates hardware-level encryption algorithms such as AES / SM4 / SM9 into a security board, and combines the "encryption preprocessing - AI compliance review - reverse verification" mechanism of the internal and external network security proxy zones to build an end-to-end trusted link. It also supports dynamic key updates and illegal data interception. The hardware-level anti-tampering and anti-hijacking capabilities are significantly better than software encryption schemes, meeting the high security requirements of rail transit signal transmission and satellite sensitive data interaction.
[0052] (4) Closer integration of computing and networking, adapting to "dynamic QoS and multi-scenario requirements": Existing technologies suffer from the defect of "decoupling computing and forwarding functions", resulting in decision-making lagging behind scenario changes. This invention achieves "zero-latency driving" of sensing data to the network protocol stack through heterogeneous operating system cascading and internal and external network synchronization protection modules, and dynamically allocates "computing-network" resources based on business priority (security > critical > general), supports fine-grained resource slicing, and ensures end-to-end protection of core services such as control signals and cluster commands, perfectly adapting to the heterogeneous business requirements of multiple scenarios such as vehicle-mounted, rail transit, and low-altitude intelligent networks.
[0053] (5) Enhanced scalability and redundancy, supporting "technology evolution and business continuity": Existing technologies have fixed hardware architectures, making them difficult to integrate with new technologies and lacking self-healing capabilities. This invention adopts a modular design, supporting seamless access to new networks / technologies such as 6G and quantum communication, thus improving scalability and redundancy compared to traditional architectures. Attached Figure Description
[0054] Figure 1 The hardware and software logic diagram provided for embodiments of the present invention;
[0055] Figure 2 This is a general hardware structure block diagram of the system provided in the embodiments of the present invention;
[0056] Figure 3 The overall software layer architecture diagram provided for embodiments of the present invention;
[0057] Figure 4 This is a flowchart of data flow and collaborative transmission provided in an embodiment of the present invention;
[0058] Figure 5 A diagram illustrating the network convergence and internal / external network synchronization mechanism provided in this embodiment of the invention;
[0059] Figure 6 A flowchart illustrating an AI-driven heterogeneous collaborative data processing method for network fusion, provided as an embodiment of the present invention;
[0060] Figure 7 A flowchart illustrating how data is securely transmitted from a secure intranet environment to an external network via multiple network channels after being processed by heterogeneous hardware, as provided in embodiments of the present invention.
[0061] Figure 8 The timing logic diagrams of the architecture provided in this embodiment of the invention under three scenarios: normal data transmission, abnormal blocking, and dynamic policy adjustment. Detailed Implementation
[0062] The present invention will be further described below with reference to the accompanying drawings and specific embodiments, so that those skilled in the art can better understand and implement the present invention. The embodiments of the present invention are not limited thereto.
[0063] Example 1
[0064] like Figure 1 The diagram shown is a hardware and software logic diagram of the system of this invention, illustrating the core technology and the relationship between key components of this patent.
[0065] An AI-driven heterogeneous collaborative system for network convergence, capable of simultaneously accessing at least two of the following: public networks, private networks, satellite communication networks, and short-range communication networks. Based on decisions made by AI computing boards, it achieves dynamic multi-network converged transmission, including:
[0066] The routing control board has a built-in multi-core heterogeneous processor for performing network protocol parsing, data forwarding, multi-network link control, and QoS scheduling.
[0067] AI computing board integrates at least one computing core from GPU, NPU, and DPU, and runs business classification model, traffic prediction model, heterogeneous network collaboration model and security compliance review model to generate network resource allocation and transmission path decisions and data compliance review results;
[0068] Security boards are used to implement hardware-level encryption, decryption, authentication, and key updates, build end-to-end trusted transmission links, and perform security verification on data entering and leaving the intranet.
[0069] Internal and external network synchronization protection module: Located between the internal network and the external network, the internal network is a security domain carrying business data flows that require security protection, and the external network is a converged transmission domain that includes at least two of the following: public network, private network, satellite communication network, and short-range communication network; the internal and external network synchronization protection module is used to realize security mapping, data filtering, and policy synchronization between the internal network and the external network, ensuring that data flows entering and leaving the internal network must be verified by the security board and reviewed for security compliance by the AI computing board before being forwarded to the external network by the routing control board, or that data returned from the external network enters the internal network after reverse verification;
[0070] The software architecture adopts a multi-operating system cascade structure, with different boards running independent OSs. Cross-system communication, task synchronization, and data consistency maintenance are achieved through a middleware layer.
[0071] The high-speed interconnect bus connects routing control boards, AI computing boards, and security boards, and enables high-speed data exchange and synchronization through shared memory areas and cross-domain data buffering mechanisms.
[0072] like Figure 2 The diagram shown is a general hardware structure block diagram of the system of the present invention, which illustrates the heterogeneous controller collaborative architecture of the vehicle-mounted intelligent router, including three core modules: routing control board, AI computing board, and security board.
[0073] like Figure 3 The diagram shown is the overall software layer architecture of this invention, which describes the heterogeneous operating system cascading, middleware communication mechanism, and AI model collaborative operation structure.
[0074] like Figure 4The diagram shown is a flowchart of the data flow and collaborative transmission of the present invention, illustrating the complete flow path of business data from collection, encryption, intelligent scheduling to transmission, as well as the dynamic routing mechanism of multi-network integration.
[0075] like Figure 5 The diagram shown is a schematic of the network convergence and internal / external network synchronization mechanism of the present invention, illustrating the convergence method of public network, private network, satellite communication network, short-range communication network and UAV self-organizing network, as well as the data isolation and mapping relationship between internal and external networks realized by the security proxy zone.
[0076] like Figure 6 As shown, an AI-driven heterogeneous collaborative data processing method for network convergence is presented. The core of this method lies in utilizing specific hardware boards (security board, AI computing board, and routing control board) to work collaboratively, introducing an AI decision-making process after data encryption and before routing forwarding to achieve optimal heterogeneous network transmission. The flowchart clearly defines which hardware component performs each step and highlights the core role of the AI computing board in determining the transmission strategy.
[0077] Figure 6 It demonstrates the complete processing logic of business data from entering the system to being sent to the receiving end, highlighting the collaborative working mechanism between different functional boards.
[0078] An AI-driven heterogeneous collaborative data processing method for network fusion includes the following steps:
[0079] S1: Business data undergoes encryption and integrity verification via the security board; this step corresponds to the security board processing stage, where business data first enters the security board and undergoes encryption and integrity verification to ensure the original security of the data.
[0080] S2: Encrypted data is transmitted to the AI computing board. The AI model in the AI computing board analyzes the network status, service priority, and bandwidth information to generate the optimal transmission strategy. This step corresponds to the decision-making process of the AI computing board. The encrypted data is then transmitted to the AI computing board. Before routing, the AI model comprehensively analyzes the network status, service priority, and bandwidth information to dynamically generate the optimal transmission strategy, rather than the traditional static routing configuration.
[0081] S3: The routing control board performs multi-network scheduling and load balancing according to the transmission strategy to achieve data fusion transmission. This step corresponds to the execution stage of the routing control board, that is, the routing control board receives encrypted data and strictly follows the transmission strategy generated by the AI calculation board to perform specific multi-network scheduling and load balancing operations to achieve data fusion transmission in heterogeneous networks.
[0082] S4: The receiving end performs reverse decryption and verification through the security board to complete the data distribution. This step corresponds to the receiving end processing stage, that is, after the data is transmitted through the heterogeneous network to the receiving end, it is reverse decrypted and verified through the receiving end's security board to finally complete the secure distribution of the data.
[0083] Figure 6 It clearly defines a unique pipeline architecture of "security hardening - AI decision-making - routing execution". It intuitively demonstrates how the AI computing board intervenes between traditional security and routing, acting as an intelligent decision-making hub. This is the key innovation that distinguishes this patented method from the existing ordinary router data processing flow.
[0084] like Figure 7 As shown, this demonstrates how data is processed from a secure intranet environment through a "forced pipeline" composed of heterogeneous hardware, and finally securely sent to the external network through multiple network channels.
[0085] According to the Card_Secure ==> Card_AI ==> Card_Route path in the diagram, data processing follows a strict unidirectional serial mechanism:
[0086] Step 1: Securely Prototyping (FPGA)
[0087] Component: Card_Secure (Security Card)
[0088] Function: Utilizes the hardware features of FPGA for high-speed encryption and digital signatures.
[0089] Significance: Encapsulating data the moment it leaves the source ensures confidentiality and tamper resistance, and hardware encryption is more difficult to be attacked by side-channel attacks than software encryption.
[0090] Step 2: Intelligent Compliance Review (AI / GPU)
[0091] Component: Card_AI (AI computing board)
[0092] Function: Utilizes the computing power of GPU / NPU to perform content compliance review and policy matching on processed data streams.
[0093] Blocking mechanism: If an anomaly is detected (as shown in the figure, Reject_AI), the data will be immediately blocked and will not be able to enter the routing process.
[0094] Note: Content moderation is usually difficult after encryption. This design is intended to review traffic characteristics, metadata, or perform a final compliance check on the plaintext portion.
[0095] Step 3: Unified Router (CPU)
[0096] Component: Card_Route (Route control board)
[0097] Function: Responsible for general logical scheduling. It distributes data to 5G, satellite, or ad hoc network channels based on the current network conditions.
[0098] The Feedback Loop
[0099] The dashed section in the diagram, Sync_Logic, illustrates a dynamic adaptive control system.
[0100] Perception: The CardRoute board monitors the network status of the external network in real time (congestion, packet loss, interference, etc.).
[0101] Decision: The Sync Logic agent receives feedback.
[0102] Adjustment:
[0103] Update the blocking rules to the AI board (e.g., if a malicious attack is detected from a certain IP, block it immediately).
[0104] Dynamically adjust encryption strategies for security boards (e.g., switch to a lower-overhead but tolerable encryption algorithm or enhance anti-interference coding when the network environment deteriorates).
[0105] like Figure 8 As shown, the timing logic of the architecture is illustrated in three scenarios: normal data transmission, abnormal blocking, and dynamic policy adjustment.
[0106] One-way data "passing" (steps 1-4)
[0107] In the green area (Scenario 1), data must pass through the FPGA, GPU, and CPU sequentially. If any link is disconnected or rejected, the data cannot reach the external network. This verifies the security of "forced serialization".
[0108] AI's "Fuse" Role (Step 5)
[0109] In the red area (Scenario 2), when the GPU detects an anomaly, it not only cuts off the path to the CPU (--x), but also sends an alert to the management plane (Sync).
[0110] The system's "vitality" (steps 6-7)
[0111] The yellow area (Scenario 3) showcases the most intelligent part of the architecture.
[0112] When the CPU senses a deterioration in the external network environment (such as weak 5G signal or high latency), it does not passively wait, but actively triggers the Sync agent.
[0113] The Sync agent then directs the three boards to adjust in parallel: the FPGA reduces the encryption load in exchange for speed, the AI adjusts the review strategy, and the CPU switches physical links.
[0114] Explanation of the internal and external network synchronization protection module
[0115] The internal and external network synchronization protection module is the key hub connecting the "security domain (internal network)" and the "transmission domain (external network)" in this invention. This module is not just a simple firewall or gateway, but a set of mandatory logical control and state synchronization mechanisms based on a heterogeneous hardware architecture. The core logic of this module lies in "isolation" and "synchronization," which forcibly defines the only legal path for data flow, breaking the traditional router's "CPU direct forwarding" mode.
[0116] (1) Location
[0117] Internal network (security domain): This carries core business operations (such as train control commands and drone swarm coordination commands). This data is in plaintext or internal format and must never be directly exposed to the public network.
[0118] External network (transmission domain): A highly complex and untrusted converged network environment (including public network, satellite, Wi-Fi, etc.).
[0119] Synchronization Protection Module (Agent Zone): Deployed between the two, like an "airlock". It cuts off the direct physical / logical connection between the internal network and the external network.
[0120] (2) Execution logic
[0121] This module enforces the following process; any data packet that skips the following steps will be discarded:
[0122] Encryption preprocessing (hardware level): Before data leaves the intranet, it must first be "armored" (encrypted and signed) on the security board.
[0123] Compliance Review (AI Level): After encryption, data cannot be sent directly; it must be sent to the AI computing board. The AI not only checks the routing but also performs a "security compliance model review" (e.g., does this control command conform to the current business logic? Is it a forged replay attack?).
[0124] Policy synchronization and forwarding: Only after passing the dual checks of hardware and AI will the module allow the routing control board to send data to the external network.
[0125] This invention establishes a physical and logical sequential dependency chain of "security board -> AI board -> routing board". An AI computing board is introduced as a mandatory node (Gatekeeper) for security review. Even encrypted data will be intercepted if the AI model determines that its business characteristics are abnormal (e.g., issuing a high-speed driving command while not in a driving state). This architecture uses AI inference as a precondition for data packet forwarding.
[0126] The "synchronization" of this invention is not just data synchronization, but dynamic synchronization of security policies, which solves the security pain points of existing technologies in multi-network convergence scenarios.
[0127] Example 2
[0128] Hardware replacement solutions for security boards
[0129] Alternative components: Replace the "FPGA security board" in the original solution with a "security coprocessor chip (such as TPM 2.0+ national cryptographic chip)" or a "reconfigurable AI security chip (such as Huawei Ascend 310B with hardware encryption engine)".
[0130] Feasibility Explanation: The TPM 2.0 chip can achieve hardware-level identity authentication and key storage. When paired with a dedicated national cryptographic chip (such as Huada HC32L136), it can complete AES / SM4 encryption. Although its computing power is weaker than that of FPGA, it has lower cost and lower power consumption, making it suitable for low-power automotive scenarios. The reconfigurable AI security chip integrates AI inference and encryption functions, which can simplify data interaction between boards and still build a full-link security protection of "encryption-compliance review-reverse verification" without affecting the achievement of security objectives.
[0131] Example 3
[0132] Alternatives to high-speed interconnect buses
[0133] Alternative components: Replace the original "PCIe / SerDes bus" with either "NVLink bus" or "CCIX (Cache Coherence Interconnect) bus";
[0134] Feasibility Explanation: The NVLink bus (NVIDIA dedicated) is suitable for high-speed interconnection between the GPU and routing / security boards within AI computing boards, with a bandwidth of up to 600GB / s, which is higher than PCIe 4.0, and can improve the speed of AI decision result delivery; the CCIX bus supports cache consistency of heterogeneous chips (such as CPU, NPU, FPGA), reducing cross-board data transfer latency. Both can meet the "high bandwidth, low latency" collaboration requirements between the three boards, ensuring high-speed data exchange.
[0135] Example 4
[0136] AI computing board computing unit replacement solution
[0137] Alternative components: Replace the original solution's heterogeneous computing power of "GPU+NPU+DPU" with "edge AISoC (such as Rockchip RK3588S and RISC-V embedded AI units, etc.) + independent hardware traffic offloading chip (such as Mellanox ConnectX-5)";
[0138] Feasibility Explanation: The RK3588S integrates a quad-core A76+NPU (6TOPS), which can run lightweight business classification and traffic prediction models to meet the needs of small and medium-sized AI inference. It is paired with an independent traffic offloading chip to handle data forwarding optimization. Although its computing power is smaller than the original solution, it is low-cost and small in size, making it suitable for miniaturized scenarios such as low-altitude drones, and can still achieve the purpose of AI-driven network scheduling.
[0139] Example 5
[0140] Software operating system alternatives
[0141] Alternative components: Replace the original solution of "heterogeneous OS cascading (VxWorks + Ubuntu RTX + FreeRTOS)" with "containerized real-time operating system (such as Kubernetes Edge + RT-Thread)";
[0142] Feasibility study: Kubernetes Edge can isolate routing control, AI computing, and security protection tasks on a single Linux kernel through containers. Combined with RT-Thread's real-time scheduling function (task latency <1ms), it can simplify cross-OS data interaction. Through containerized deployment, it can also flexibly load AI models for different scenarios, still achieve "heterogeneous task synchronization + resource scheduling", and reduce software maintenance complexity.
[0143] Example 6
[0144] Link type alternatives for network convergence modules
[0145] Replacement components: Replace the original "5G+LTE-R + satellite + Wi-Fi" link with "5G-A+LoRaWAN+millimeter wave communication + low-Earth orbit satellite" and other emerging communication technologies;
[0146] Feasibility Explanation: 5G-A improves bandwidth and reduces latency (<1ms), making it suitable for L4 autonomous driving in vehicles; LoRaWAN is suitable for low-power wide-area scenarios (such as rail transit monitoring in remote areas); millimeter-wave communication (28GHz) provides high bandwidth (>10Gbps), meeting the needs of high-definition image backhaul for low-altitude intelligent networks; low-orbit satellites enhance global coverage and can still achieve "dynamic fusion of multiple networks + fault switching", expanding the scope of scenario adaptation (such as ocean satellite communication).
[0147] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. An AI-driven heterogeneous collaborative system for network convergence, wherein the system can simultaneously access at least two of the following: public network, private network, satellite communication network, and short-range communication network, and achieves dynamic converged transmission across multiple networks based on the decision-making of AI computing boards, characterized in that... include: The routing control board has a built-in multi-core heterogeneous processor for performing network protocol parsing, data forwarding, multi-network link control, and QoS scheduling. AI computing board integrates at least one computing core from GPU, NPU, and DPU, and runs business classification model, traffic prediction model, heterogeneous network collaboration model and security compliance review model to generate network resource allocation and transmission path decisions and data compliance review results; Security boards are used to implement hardware-level encryption, decryption, authentication, and key updates, build end-to-end trusted transmission links, and perform security verification on data entering and leaving the intranet. Internal and external network synchronization protection module: Located between the internal network and the external network, the internal network is a security domain carrying business data flows that require security protection, and the external network is a converged transmission domain that includes at least two of the following: public network, private network, satellite communication network, and short-range communication network; the internal and external network synchronization protection module is used to realize security mapping, data filtering, and policy synchronization between the internal network and the external network, ensuring that data flows entering and leaving the internal network must be verified by the security board and reviewed for security compliance by the AI computing board before being forwarded to the external network by the routing control board, or that data returned from the external network enters the internal network after reverse verification; The software architecture adopts a multi-operating system cascade structure, with different boards running independent OSs. Cross-system communication, task synchronization, and data consistency maintenance are achieved through a middleware layer. The high-speed interconnect bus connects routing control boards, AI computing boards, and security boards, and enables high-speed data exchange and synchronization through shared memory areas and cross-domain data buffering mechanisms.
2. The AI-driven heterogeneous collaborative system for network fusion as described in claim 1, characterized in that, The routing control board has a built-in multi-core heterogeneous processor with a multi-core heterogeneous architecture. It runs an operating system and supports differentiated scheduling of heterogeneous multi-source data. The AI computing board includes a multi-model fusion algorithm that can dynamically adjust decision weights based on business type, with security-related businesses having higher priority than non-security-related businesses. Security-related businesses include control signals and scheduling instructions; non-security-related businesses include video transmission and entertainment data. The security board supports at least one of the encryption algorithms AES, RSA, SM4, and SM9, and the key update cycle can be dynamically adjusted based on network status. High-speed interconnect buses include PCIe, SerDes, or CCIX buses.
3. The AI-driven heterogeneous collaborative system for network fusion according to claim 1, characterized in that, The internal and external network synchronization protection module is used to achieve data isolation and mapping between the internal and external networks to prevent information leakage; the internal network includes a security domain, and the external network includes a transmission domain.
4. The AI-driven heterogeneous collaborative system for network fusion as described in claim 1, characterized in that, Short-range communication networks include at least one of Wi-Fi, LoRa, Bluetooth, and drone self-organizing networks.
5. The AI-driven heterogeneous collaborative system for network fusion according to claim 1, characterized in that, The system is applicable to at least one of the following scenarios: vehicle-mounted communication network, rail transit vehicle-to-ground data transmission system, low-altitude intelligent network data transmission system, and satellite communication network.
6. The AI-driven heterogeneous collaborative system for network fusion according to claim 1, characterized in that, It also includes a synchronous protection mechanism for internal and external networks. This mechanism is based on a hardware architecture to build a collaborative protection system for the security domain and the transmission domain, specifically including: The intranet is a security domain used to carry business data streams that require security protection. The flow of this business data stream must go through encryption processing by the security board, security compliance model review by the AI computing board, and then be transmitted to the routing control board after the review is passed. The external network is the transmission domain, which is a converged network consisting of at least two of the following: public network, private network, satellite communication network, and short-range communication network. It is used to receive encrypted service data streams forwarded by the routing control board. The internal and external network synchronization protection mechanism also includes an internal and external network synchronization protection module, which is deployed between the internal and external networks and is used for: 1) Synchronize the encryption policy of the intranet security card with the security status of the external network transmission link in real time to ensure that the encryption algorithm, key version and external network link protection requirements are matched; 2) Perform reverse verification on feedback data returned from the external network to the internal network: First, decrypt the data through the security board, then use the AI calculation board to verify the integrity and legality of the data source. Only after the verification is passed can the data be allowed to enter the internal network security domain. 3) Intercept illegal data that fails the AI model review and encrypted data with mismatched keys, while generating anomaly logs and triggering alarms to achieve full control and traceability of data interaction between internal and external networks.
7. The AI-driven heterogeneous collaborative system for network fusion according to claim 6, characterized in that, The security compliance model review of AI computing boards specifically includes the review of the legality of business types, the integrity of data formats, and the matching degree of transmission priorities for business data flows. Data that fails the review will be returned to the internal network source and will not be allowed to enter the routing and forwarding process. Among them, the review of the legality of business types of business data flows includes whether they belong to the preset security business list; the review of data format integrity includes whether they comply with the encrypted transmission specifications; and the review of transmission priority matching degree includes whether they are compatible with the bandwidth and latency indicators of the external network link.
8. An AI-driven heterogeneous collaborative data processing method for network fusion, characterized in that, Includes the following steps: S1: Business data undergoes encryption and integrity verification via a security board; This step corresponds to the security board processing stage, where business data first enters the security board and undergoes encryption and integrity verification to ensure the original security of the data. S2: Encrypted data is transmitted to the AI computing board. The AI model in the AI computing board analyzes the network status, service priority, and bandwidth information to generate the optimal transmission strategy. This step corresponds to the decision-making process of the AI computing board. The encrypted data is then transmitted to the AI computing board. Before routing, the AI model comprehensively analyzes the network status, service priority, and bandwidth information to dynamically generate the optimal transmission strategy, rather than the traditional static routing configuration. S3: The routing control board performs multi-network scheduling and load balancing according to the transmission strategy to achieve data fusion transmission. This step corresponds to the execution stage of the routing control board, that is, the routing control board receives encrypted data and strictly follows the transmission strategy generated by the AI calculation board to perform specific multi-network scheduling and load balancing operations to achieve data fusion transmission in heterogeneous networks. S4: The receiving end performs reverse decryption and verification through the security board to complete the data distribution. This step corresponds to the receiving end processing stage, that is, after the data is transmitted through the heterogeneous network to the receiving end, it is reverse decrypted and verified through the receiving end's security board to finally complete the secure distribution of the data.
9. The AI-driven heterogeneous collaborative data processing method for network fusion according to claim 8, characterized in that, The AI-driven heterogeneous collaborative intelligent router system architecture for network convergence includes timing logic in three scenarios: normal data transmission, abnormal blocking, and dynamic policy adjustment. Scenario 1 is: one-way data transmission. Data must be transmitted serially through FPGA, GPU, and CPU. If any link is disconnected or rejected, the data cannot reach the external network. It includes the following steps: sending the original sensitive data, transmitting the encrypted data stream, passing the review and then transferring it to the routing layer, and finally distributing it to the external network. Scenario 2 is: the circuit breaker function of AI. When the GPU detects an anomaly, it not only cuts off the path to the CPU, but also sends an alarm to the management plane, including the following steps: intercepting the interrupted transmission; Scenario 3: System intelligence. When the CPU senses a deterioration in the external network environment, the system does not passively wait, but actively triggers the Sync agent. The Sync agent then directs three boards to coordinate adjustments in parallel: the FPGA reduces the encryption load to gain speed, the AI adjusts the review strategy, and the CPU switches physical links. This includes: reporting network status data, switching to low-bandwidth-overhead encryption algorithms, adjusting review thresholds to prioritize survival, and updating routing weights to switch to satellite links.
10. The AI-driven heterogeneous collaborative data processing method for network fusion according to claim 8, characterized in that, In step S2, the AI model can predict network traffic status in real time, adjust the transmission path in advance, and reduce data packet loss rate; in step S3, multi-network scheduling supports rapid switching of link failures and has link-level redundancy backup capabilities.