A multi-device joint communication method based on industrial internet of things
Patent Information
- Application Number
- CN202610217815.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-22
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2046-02-22
AI Technical Summary
一方面,中心服务器成为通信瓶颈,大量设备的数据请求导致服务器处理延迟增加,甚至出现拥塞现象;另一方面,全局通信模式下,所有数据均需经过中心服务器中转,增加了不必要的传输延迟,降低了整体通信效率;在传统通讯方法中,设备间的通信往往依赖于单一的路径
[0014]本申请中提供的一个或多个技术方案,至少具有如下技术效果或优点:通过区域划分,将全局通信局部化,减少不必要的全局传输,提高通信效率,引入主路和辅路的多路径设计,通过路径冗余和动态切换(包括分裂模式)提高通信可靠性,辅路支持平行传输、合并传输和分裂模式,可根据负载动态调整路径,提升资源利用率,通过区域化多路径通信及分裂模式的引入,优化工业物联网中多设备联合通讯的效率和可靠性,解决全局通信效率低下、单一路径可靠性不足、动态负载适应性差和局部通信优化缺失的问题;
Smart Images

Figure CN122027550B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) technology, and in particular to a multi-device joint communication method based on the Industrial Internet of Things (IIoT). Background Technology
[0002] In today's Industry 4.0 era, the Industrial Internet of Things (IIoT), as a key technology driving the transformation and upgrading of the manufacturing industry, is profoundly changing the production models and management methods of traditional industries. By tightly connecting various industrial equipment, sensors, and control systems, the IIoT enables data interaction and intelligent collaboration between devices, greatly improving production efficiency, flexibility, and reliability. However, with the deepening application of the IIoT, a series of problems exposed in the process of multi-device joint communication are gradually becoming bottlenecks restricting its further development.
[0003] In traditional Industrial Internet of Things (IIoT) multi-device collaborative communication systems, a centralized communication architecture is often adopted, with all devices directly exchanging data with a central server. This architecture is sustainable when the number of devices is small and communication demands are low, but its efficiency drops sharply when the number of devices increases significantly and the amount of communication data surges. On the one hand, the central server becomes a communication bottleneck; numerous data requests from devices lead to increased server processing latency and even congestion. On the other hand, in the global communication mode, all data must pass through the central server, increasing unnecessary transmission latency and reducing overall communication efficiency. In traditional communication methods, communication between devices often relies on a single path. Once this path is interrupted due to network failure, equipment damage, or human interference, the entire communication system faces the risk of paralysis. Especially in industrial production environments, communication interruptions can lead to serious consequences such as production line shutdowns and equipment malfunctions, causing significant economic losses to enterprises. Therefore, improving the redundancy and reliability of communication paths has become an urgent problem to be solved in IIoT multi-device collaborative communication. Summary of the Invention
[0004] This application provides a multi-device joint communication method based on the Industrial Internet of Things. By dividing the region, global communication is localized, unnecessary global transmission is reduced, and communication efficiency is improved. A multi-path design of main path and auxiliary path is introduced. Communication reliability is improved through path redundancy and dynamic switching. The auxiliary path supports parallel transmission, merged transmission and split mode. The path can be dynamically adjusted according to the load to improve resource utilization.
[0005] This application provides a multi-device joint communication method based on the Industrial Internet of Things, including: S101, Obtain industrial equipment nodes, divide the industrial equipment nodes into regions according to grouping rules, and identify the divided regions; wherein, the grouping rules include physical location and functionality; S102, based on the divided regions and industrial equipment nodes, the industrial equipment nodes within the regions are connected by directed edges to construct a device event association graph. Within the regions, the main communication line and auxiliary communication line are extracted based on the device event association graph. The main communication line is the high-frequency communication path between devices within the region, and the auxiliary communication line refers to the communication line that undertakes communication tasks when the main line is congested. The auxiliary communication line is connected to the main communication line through interactive nodes, and there are two auxiliary communication lines. S103, the main communication line and the auxiliary communication line switch interactively according to the interaction rules; the interaction rules are to calculate the device enhancement degree and trigger the interaction conditions, collect device communication logs to construct a local device event association graph in the region, and calculate the device enhancement degree based on the communication frequency in the local device event association graph; the interaction modes include parallel mode, merged interaction mode and split interaction mode. S104, construct communication paths based on parallel mode, merged interaction mode and split interaction mode, and perform joint communication based on the communication paths.
[0006] Preferably, the triggering interaction conditions include priority path mapping conditions and interaction mode triggering conditions. For priority path mapping conditions, high-priority data is required to use the main communication line, medium-priority data is transmitted via the first auxiliary communication line, and low-priority data is transmitted via the second auxiliary communication line. When the communication data delay on the main communication line exceeds a preset time threshold, the system switches to the first auxiliary communication line. When the bandwidth utilization of the main communication line exceeds a preset bandwidth threshold, the split interaction mode is triggered. When the bandwidth utilization of either the first or second auxiliary communication line exceeds a preset bandwidth threshold, the merge interaction mode is triggered. When the communication data is under normal load, the parallel mode is used.
[0007] Preferably, the joint communication method further includes: cross-regional joint communication and multi-path covert communication, wherein the cross-regional joint communication method is as follows: S201, Identify adjacent and non-adjacent areas from the divided areas, construct a cross-regional network based on the communication paths within the area, adjacent and non-adjacent areas, identify the path patterns within the current area, match the path patterns of the current area according to path matching rules, and connect the current area with adjacent or non-adjacent areas based on the matching results to form cross-regional joint communication; S202: Construct a global device event association diagram based on the device event association diagram within the region, calculate the cross-regional association weight based on the global device event association diagram, and schedule cross-regional joint communication based on the cross-regional association weight.
[0008] Preferably, the steps for identifying adjacent regions are as follows: the minimum distance is calculated by taking the distance between the nearest vertices of the two graphics as the minimum distance, the minimum distance is calculated using the Euclidean distance formula, and a distance threshold is set. If the minimum distance is less than or equal to the preset distance threshold, the two regions are determined to be adjacent regions; otherwise, they are not adjacent regions. When the two regions do not meet the minimum distance threshold, they are determined to be non-adjacent regions.
[0009] Preferably, the method for identifying the path pattern in the current area is as follows: when all traffic in the area converges to a single high-bandwidth path, it is identified as a merging pattern; when traffic in the area is distributed to multiple low-bandwidth paths, it is identified as a splitting pattern; when traffic in the area is evenly distributed to multiple equal-bandwidth paths, it is identified as a parallel pattern.
[0010] Preferably, the path matching rules are: merging mode matches splitting mode, merging mode matches parallel mode, and splitting mode matches merging mode.
[0011] Preferably, the steps of the multi-path covert communication are as follows: acquiring task metadata, classifying the task metadata by traffic, the traffic classification dividing the task metadata into hidden data and disguised data, generating fragments of hidden data based on the background traffic of the transmission path, dispersing the generated fragments to multiple auxiliary paths for transmission in a split mode, and simultaneously injecting disguised data into the main communication line.
[0012] Preferably, the hidden data refers to data with the highest requirements for the concealment of transmission, used to avoid being detected by malicious monitoring or attackers. The main function of the disguised data is to provide cover for the hidden data.
[0013] Preferably, the method for distributing the generated fragments across multiple auxiliary paths in the split mode is as follows: the fragments received on the auxiliary paths interact with the inherent background data packets on the auxiliary paths. Specifically, the sending time of the hidden data fragments is consistent with the sending interval of the background data packets. Based on the size of the background data packets, the hidden data fragments generate data packets of the same size, thereby interacting with the inherent background data packets on the auxiliary paths.
[0014] One or more technical solutions provided in this application have at least the following technical effects or advantages: by dividing the region, global communication is localized, unnecessary global transmission is reduced, and communication efficiency is improved. Multi-path design of main path and auxiliary path is introduced, and communication reliability is improved through path redundancy and dynamic switching (including split mode). The auxiliary path supports parallel transmission, merged transmission and split mode, and the path can be dynamically adjusted according to the load to improve resource utilization. By introducing regionalized multi-path communication and split mode, the efficiency and reliability of multi-device joint communication in the industrial Internet of Things are optimized, and the problems of low global communication efficiency, insufficient single path reliability, poor dynamic load adaptability and lack of local communication optimization are solved. By constructing a cross-regional network, intelligent matching and connectivity of multi-path modes in different regions are achieved, reducing communication latency between regions and effectively solving the problem of cross-regional communication efficiency. Intelligent inter-regional path coordination strategies are constructed to solve key technical challenges in multi-regional joint communication, achieving a leap from single-point optimization to full-line coordination. By generating hidden data fragments, the hidden data is highly assimilated to background traffic in both macroscopic and microscopic characteristics, significantly reducing the risk of being identified by attackers through traffic analysis. Through multi-path parallel transmission gain, a better balance between concealment and transmission efficiency is achieved, resulting in a synergistic leap in security and transmission efficiency. This provides a new generation of communication infrastructure for high-security industrial IoT, integrating high efficiency, reliability, and concealment. Attached Figure Description
[0015] Figure 1 This is a flowchart illustrating a multi-device joint communication method based on the Industrial Internet of Things according to the present invention. Figure 2 This is a schematic diagram of the cross-regional joint communication process of the present invention. Detailed Implementation
[0016] To facilitate understanding of the present invention, a more complete description of this application will be given below with reference to the accompanying drawings, which illustrate preferred embodiments of the invention. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to enable a more thorough and complete understanding of the disclosure of the present invention.
[0017] It should be noted that the terms "vertical," "horizontal," "up," "down," "left," "right," and similar expressions used in this article are for illustrative purposes only and do not represent the only possible implementation.
[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to limit the invention; the term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0019] Example 1: In the current booming development of the Industrial Internet of Things (IIoT), traditional multi-device collaborative communication systems suffer from low global communication efficiency, resulting in slow information exchange between devices and affecting the smoothness of the overall production process. The reliability of a single path is insufficient; once a path fails, communication is interrupted, leading to abnormal equipment operation. Furthermore, communication efficiency between devices in local areas is low, impacting local production efficiency. This example addresses this by dividing the entire communication network into multiple regions, reducing the complexity of global communication and improving the targeting of information transmission. The main-path-auxiliary-path topology design provides multiple path options for communication. The main path undertakes the primary communication tasks, while the auxiliary path serves as a backup. When the main path fails, it can quickly switch to the auxiliary path, ensuring communication continuity and enhancing reliability.
[0020] Figure 1 This is a flowchart illustrating a multi-device joint communication method based on the Industrial Internet of Things (IIoT) according to an embodiment of the present invention, including: S101, Obtain industrial equipment nodes, divide the industrial equipment nodes into regions according to grouping rules, and identify the divided regions; wherein, the grouping rules include physical location and functionality; Specifically, in an Industrial Internet of Things (IIoT) environment, industrial device nodes refer to various industrial devices with specific functions as nodes in the network. The network is scanned using the network scanning tool Nmap. Based on the network topology and scanning purpose, the range of IP addresses to be scanned (i.e., the scan range) is determined. Scanning parameters such as scan speed, timeout time, and number of retries are set. The scan is performed based on the set scan range and parameters to obtain the scan results. The industrial device nodes are then identified based on these results. The scan results include IP address, MAC address, and device type. The IP address is the unique identifier of the device in the network, allowing for precise location of a specific device. The MAC address is the device's physical address, written into the hardware by the manufacturer during production. It is globally unique and further confirms the device's identity, avoiding misidentification due to dynamic IP address allocation. The device type identifies the device's function and purpose. Industrial equipment nodes can be identified based on their IP addresses, MAC addresses, and equipment types. The grouping rules include physical location and functionality, dividing regions according to the principle of prioritizing physical location, followed by functionality and algorithm-assisted grouping. Regions are also divided based on the physical layout of workshops, production lines, or equipment. If equipment functions are closely related, they can be grouped into the same region even if their physical locations are dispersed. Data such as physical coordinates, communication frequencies, and functional types of the equipment are collected. Physical coordinates are obtained from factory layout drawings or positioning systems; communication frequencies are obtained from monitoring data over a period of time using network scanning tools; and functional types are classified according to the equipment's manual or actual use. K-means clustering algorithm is used for region-assisted division, and the elbow method is used to determine the K value of the K-means clustering algorithm. The elbow method calculates the sum of squared clustering errors under different K values, plots a curve of the sum of squared clustering errors as a function of K, and finds the K value corresponding to the elbow in the curve. The value represents the number of clusters. The prepared input data is fed into the K-means clustering algorithm, which divides the devices into K clusters based on their similarity. Each cluster corresponds to a region. After dividing the regions by physical location, functional and algorithm-assisted divisions are performed to complete the region division. Each region contains 5-20 device nodes, improving communication efficiency within the region and reducing latency and interference from cross-regional communication. A weighted identifier allocation algorithm is used to assign region identifiers. Relevant personnel determine the weighting factors (such as device density, production process criticality, etc.) and assign weights, establishing evaluation criteria for each factor. Then, each region is scored according to the criteria, and a comprehensive score is calculated. Identifier generation rules are then developed based on the score range, and identifiers are assigned. Finally, the identifiers are verified, and the device node identifiers are updated according to the assigned region identifiers. The region identifiers are stored in the device firmware or edge gateway configuration file.
[0021] S102, based on the divided regions and industrial equipment nodes, the industrial equipment nodes within the regions are connected by directed edges to construct a device event association graph. Within the regions, the main communication line and auxiliary communication line are extracted based on the device event association graph. The main communication line is the high-frequency communication path between devices within the region, and the auxiliary communication line refers to the communication line that undertakes communication tasks when the main line is congested. The auxiliary communication line is connected to the main communication line through interactive nodes, and there are two auxiliary communication lines. Furthermore, within the divided area, after acquiring the industrial equipment nodes, event information generated by each device during operation is collected. This event information includes different types of events such as device startup, shutdown, fault alarms, and parameter changes, along with their timestamps. Using the industrial equipment nodes as nodes in the device event association graph, the associations between device nodes are identified and determined based on the order of events, causal relationships, and interactions between devices. Associated device nodes are connected by directed edges, where the direction of the directed edge indicates the direction of event transmission or influence. Edges are assigned weights based on the tightness of the association or the frequency of event occurrence. This constructs the device event association graph by combining the industrial equipment nodes and their directed edges. Based on this graph, the communication between devices within the area is analyzed. By collecting historical communication data and statistically analyzing the communication frequency between devices, high-frequency communication paths are extracted as the main communication lines. For example, within the area, device A frequently communicates with device B, and device B frequently communicates with device C. The communication frequency is significantly higher than that of other device combinations, so the main communication line is determined to be A→B→C. Two auxiliary communication lines are set up: the first auxiliary communication line and the second auxiliary communication line. The first auxiliary communication line is mainly used to prioritize the transmission of information with high latency requirements, such as control commands and real-time status data. The first auxiliary communication line is independent of the main line and is connected to the main line through an edge gateway. The edge gateway is used for data forwarding and protocol conversion to ensure that the data on the first auxiliary communication line can be transmitted with the data on the main communication line. The second auxiliary communication line is used to prioritize the transmission of big data such as sensor streams and video streams. The second auxiliary communication line partially overlaps with the main line and is connected through an independent switch (SDN). Based on the above, the interaction nodes are the edge gateway and the switch.
[0022] S103, the main communication line and the auxiliary communication line switch interactively according to the interaction rules; the interaction rules are the conditions for calculating the device enhancement degree and triggering the interaction, collecting device communication logs to construct a local device event association graph within the region, and calculating the device enhancement degree based on the communication frequency in the local device event association graph; the interaction modes include parallel interaction, merged interaction and split interaction; Specifically, device communication logs within the region are collected. These logs contain communication pairs, communication times, and communication frequencies. High-frequency communication pairs are extracted from these logs. Based on these high-frequency communication pairs, a local device event association graph is constructed. In this graph, device nodes are used as vertices, and high-frequency communication pairs are used as directed edges (the direction of the edges indicates the direction of communication). The weight of each edge is set to its communication frequency. The device enhancement degree is calculated based on the communication frequencies of the main and auxiliary communication lines in the local device event association graph, using the following formula: Where D represents the enhancement degree of the device, used to measure the importance of the device in the network, α is the main path influence coefficient, reflecting the proportion of contribution of the main path to the central value of the device enhancement degree, and W M The main path association weight reflects the degree of association between the device and the main path, and is determined by a combination of factors such as the main path's communication frequency and bandwidth utilization. W represents the auxiliary road influence coefficient, which is the proportion of the auxiliary road path's contribution to the central value of equipment enhancement. AThe auxiliary path association weight reflects the degree of association between the device and the auxiliary path, and is determined by a combination of factors such as the communication frequency and bandwidth utilization of the main path. Triggering interaction conditions include priority and path mapping conditions, as well as interaction mode triggering conditions. An urgency threshold range is set, which includes a maximum threshold and a minimum threshold. The urgency of data is calculated using a weighted summation method. Data with an urgency level greater than the preset maximum threshold is considered high-priority data; data with an urgency level less than or equal to the maximum threshold but greater than the minimum threshold is considered medium-priority data; and data with an urgency level less than or equal to the minimum threshold is considered low-priority data. High-priority data is forced to use the main path communication line, while medium-priority data preferentially selects the first auxiliary path communication line for transmission. The first auxiliary path communication line is a low-latency line. The path can meet the real-time requirements of status update data while reducing the communication pressure on the main path. Low-priority data is transmitted through the second auxiliary communication line, which is a high-bandwidth path suitable for transmitting large amounts of historical logs, making full use of its bandwidth resources. When the communication data latency on the main path exceeds a preset time threshold, it switches to the low-latency first auxiliary communication line. When the bandwidth utilization of the main path exceeds a preset bandwidth threshold, a split interaction mode is triggered. The edge gateway calculates the remaining bandwidth of the first and second auxiliary communication lines and splits the main path communication traffic according to the ratio of the remaining bandwidth. For example, if the first auxiliary communication line has 30Mbps remaining and the second auxiliary communication line has 20Mbps remaining, the traffic is split according to a 60%:40% ratio. The main communication traffic is divided proportionally. Finally, the switch updates the routing table, initiates the split mode, and forwards data packets to the first and second auxiliary communication lines. When the bandwidth utilization of the auxiliary communication lines exceeds a preset bandwidth threshold, a merging interaction mode is triggered. The switch updates the routing table and merges the data streams originally transmitted on the first and second auxiliary communication lines into an aggregated link for transmission, thereby improving throughput and meeting high bandwidth requirements. The aggregated link is a temporary high-bandwidth channel formed by merging the two auxiliary lines at the interaction node. The parallel mode is suitable for normal load conditions. Under normal load conditions, the main communication line, the first auxiliary communication line, and the second auxiliary communication line transmit data independently. The data streams are transmitted in parallel on the main communication line, the first auxiliary communication line, and the second auxiliary communication line without interference. The switch forwards data of different priorities to the main communication line, the first auxiliary communication line, and the second auxiliary communication line for transmission according to preset routing rules.
[0023] S104, construct communication paths based on parallel mode, merged interaction mode and split interaction mode, and perform joint communication based on the communication paths.
[0024] Specifically, communication paths are formed based on the parallel mode, merged interaction mode, and split interaction mode obtained in step S103. A communication path refers to the path formed after passing through the parallel mode, merged interaction mode, or split interaction mode during the communication transmission process of multiple industrial devices. Joint communication is carried out according to the communication path. First, the data is classified according to urgency, importance, etc., and different paths are matched. High priority data takes the main communication line or aggregated link, while medium and low priority data selects the first auxiliary communication line as appropriate. Multi-path collaborative transmission is adopted, splitting large or important data and transmitting it simultaneously through different paths. The receiving end reassembles and sorts the data to improve efficiency and reliability. The path status and data transmission status are monitored in real time during communication, and indicators such as bandwidth utilization are collected. Based on this, the path and transmission strategy are dynamically adjusted. If congestion occurs, the path is switched, or the priority is adjusted due to increased delay, to ensure efficient and stable communication.
[0025] The technical solutions in the above embodiments of this application have at least the following technical effects or advantages: by dividing the region, global communication is localized, unnecessary global transmission is reduced, and communication efficiency is improved. By introducing a multi-path design of main and auxiliary paths, communication reliability is improved through path redundancy and dynamic switching (including split mode). Auxiliary paths support parallel transmission, merged transmission, and split mode. Paths can be dynamically adjusted according to the load to improve resource utilization. By introducing regionalized multi-path communication and split mode, the efficiency and reliability of multi-device joint communication in the Industrial Internet of Things are optimized, solving the problems of low global communication efficiency, insufficient reliability of single paths, poor dynamic load adaptability, and lack of local communication optimization.
[0026] Example 2: Example 1 described above is multi-path communication within a single region, lacking inter-regional communication. This example constructs inter-regional communication to achieve matching and connectivity of multi-path patterns within different regions, forming communication from a point (single region) to a line (multi-regional connection), such as... Figure 2 As shown.
[0027] S201, Identify adjacent and non-adjacent areas from the divided areas, construct a cross-regional network based on the communication paths within the area, adjacent and non-adjacent areas, identify the path patterns within the current area, match the path patterns of the current area according to path matching rules, and connect the current area with adjacent or non-adjacent areas based on the matching results. Specifically, the boundary coordinates of the region and the location coordinates of industrial equipment nodes are acquired. These coordinates are preprocessed to unify the coordinate system and remove redundant points. Adjacent regions are identified by calculating the minimum distance between any two geometric shapes. Specifically, the distance between the nearest vertices of the two shapes is calculated as the minimum distance using the Euclidean distance formula. A distance threshold is set; if the minimum distance is less than or equal to the preset threshold, the two regions are considered adjacent. For complex shapes (concave polygons), spatial indexing is used to identify adjacent regions. An R-tree index is constructed for the region to quickly filter sub-regions that are close to another region. If two regions do not meet the minimum distance threshold, they are determined to be non-adjacent regions. ICMP is sent to the boundary gateway of adjacent regions. Ping checks the physical connection status of adjacent areas. If the response time is less than or equal to a preset time threshold and the packet loss rate is less than the threshold, it is marked as connectable. For non-adjacent areas, the degree center value (number of directly connected devices) and clustering coefficient (actual number of connections between neighbors / possible number of connections) of each border gateway are calculated. The nodes are sorted in descending order of degree center value, and the top 20% of nodes are selected as candidate core nodes. From the candidate nodes, nodes with a clustering coefficient ≥ 0.7 are selected as the final core nodes. The physical connection status between core nodes is checked. If the link is valid, the core node is marked as connectable. The core node that passes the verification is the cross-region connection point.
[0028] For adjacent areas, high-speed wireless links are deployed between the boundary gateways of adjacent areas, with bandwidth set to twice the intra-area demand. For non-adjacent areas, connections are established between non-adjacent areas through core nodes. A cross-area network is constructed based on multi-path communication within the area, direct connections between adjacent areas, and node connections between non-adjacent areas. Real-time bandwidth utilization and traffic direction data for each path within the area are collected through the traffic monitoring module of the edge gateway. Based on the collected data, the path pattern within the current area is identified: when all traffic within the area converges to a single high-bandwidth path, it is identified as a merging mode; when traffic within the area is dispersed across multiple low-bandwidth paths, it is identified as a splitting mode; when traffic within the area... The data is evenly distributed across multiple equal-bandwidth paths in parallel mode. When there is a data transmission request between regions, the system identifies the current path mode of both regions according to the above steps and sets path matching rules: merge mode matches split mode, merge mode matches parallel mode, and split mode matches merge mode. Based on the path matching rules, the system matches the current path modes between regions. The steps are as follows: For the match between merge mode and split mode, when the sender (merge mode) transmits to the receiver (split mode), the sender aggregates multiple low-bandwidth sub-paths (5 100Mbps paths) into one high-bandwidth path (500Mbps) and carries the sub-path identification information in the aggregated traffic. After receiving the 500Mbps aggregated traffic, the receiving end deaggregates the traffic based on the sub-path identifier information, splitting it into five independent 100Mbps sub-paths. Each sub-path is then mapped to its corresponding local low-bandwidth path, completing the connection and achieving matching between the merge and split modes. For matching between the merge and parallel modes, when the sender (merge mode) transmits to the receiver (parallel mode), the sender aggregates multiple low-bandwidth sub-paths (six 100Mbps paths) into a single 600Mbps path. The 600Mbps aggregated traffic is then split according to the number of paths in the parallel mode (six paths), with each sub-path transmitting 100Mbps of traffic independently, and there is no overlap between paths. Interoperability is achieved by the receiver directly receiving six 100Mbps traffic streams without aggregation or splitting, thus matching the merged and parallel modes. For matching the split and merged modes, the sender splits a single high-bandwidth path (320Mbps) into multiple low-bandwidth sub-paths (four 80Mbps paths) and transmits them through different links. The receiver (in merged mode) receives the traffic from the four 80Mbps sub-paths and merges them into a single 320Mbps path, thus matching the split and merged modes. Based on the matching results, the path mode of the current region is connected with the path modes of the corresponding adjacent or non-adjacent regions to achieve cross-regional joint communication.
[0029] S202, construct a global device event association diagram based on the device event association diagram within the region, calculate the cross-regional association weight based on the global device event association diagram, and schedule inter-regional joint communication based on the cross-regional association weight.
[0030] Further, according to step S102, the device event association graph of each region is extracted, the device nodes and their associated events in the region are identified, and the association weights in the region are obtained. The association weights in the region are obtained by statistically analyzing the frequency, data volume, and dependency strength of events between devices in the region, combined with edge weight calculation methods in graph theory (normalized event counts or weighted average delay). The path characteristics (bandwidth, delay, path pattern) in the region are recorded. Cross-regional association edges are expanded according to the physical connections between regions and cross-regional connection points. For devices A and B associated in the region, a new cross-regional edge (A,B) is added to the global graph. If cross-regional communication requires intermediate nodes (such as gateways or routers), the intermediate nodes are added to the global graph, and a complete path (A→gateway→B) is constructed. Each edge is labeled with its region pair, for example: region X-region Y. All regional association graphs and cross-regional edges are merged to form a global device event association graph. The cross-regional association weights are calculated according to the regional association weights, using the following formula: ,in, Cross-region association weights quantify the cross-regional association strength between two devices (or nodes), used to evaluate the priority of cross-regional communication or as a basis for path selection. Regional correlation refers to the strength of the correlation between devices within the same region, reflecting the frequency or dependence of communication between devices within the region. The path bandwidth matching degree is obtained by dividing the actual bandwidth by the required bandwidth. It reflects the degree of matching between the actual bandwidth and the required bandwidth of the current path, indicating whether the bandwidth resources meet the communication requirements. Inter-region delay refers to the transmission delay of data packets along a cross-region path, typically expressed as round-trip time (RTT) or one-way delay. This is a weighting coefficient for the degree of correlation within a region, used to adjust the proportion of influence of the degree of correlation within a region on the weight of correlation across regions. This is a weighting coefficient for a comprehensive indicator of bandwidth matching and latency, used to adjust the proportion of influence of the comprehensive indicator of bandwidth matching and latency on the cross-regional correlation weight.
[0031] Inter-regional joint communication is scheduled based on the calculated cross-regional association weights. Before communication, devices in region X and region Y exchange path information to obtain the optimal path combination. A priority queue is set up, with control commands marked as the highest priority and logs marked as low priority. The priority queue is managed, and when high-priority data arrives, the system immediately interrupts the currently transmitting low-priority data and processes it first to avoid low-priority data consuming bandwidth and causing excessive latency for critical data. The high-priority queue is always processed first, and the low-priority queue is only processed when the high-priority queue is empty. The latency of high-priority data is measured in real time. If it approaches the threshold, its priority is increased or an early warning is triggered. If the cross-regional association weight decreases, inter-regional joint communication is scheduled, triggering a re-exchange of information before communication to obtain the optimal path combination. Traffic is distributed to multiple paths with similar weights to avoid single-point congestion. If a path is interrupted, it quickly switches to the second-best path, i.e., the second-highest cross-regional association weight.
[0032] The technical solutions in the above embodiments of this application have at least the following technical effects or advantages: by constructing a cross-regional network, intelligent matching and connection of multi-path modes in different regions are realized, the communication latency between regions is reduced, the cross-regional communication efficiency problem is effectively solved, an intelligent inter-regional path collaboration strategy is constructed, the key technical problems in multi-regional joint communication are solved, and the leap from single-point optimization to full-line collaboration is realized.
[0033] Example 3: Examples 1 and 2 above respectively solved the problems of communication optimization within the region and cross-regional path coordination. However, the intermediate data of the computing task is easily exposed during the transmission process, which poses a risk of being identified and intercepted by attackers. This solution innovatively deeply couples the computing task flow scheduling with multi-path covert communication, and uses the natural characteristics of multi-path communication to achieve the covertness of data transmission and ensure the security of IoT data.
[0034] Obtain task metadata and classify it into traffic categories. The traffic classification divides the task metadata into hidden data and disguised data. Hidden data is fragmented based on the background traffic of the transmission path. The split mode distributes the generated fragments to multiple auxiliary lines for transmission. At the same time, disguised data is injected into the main communication line.
[0035] Furthermore, the task awareness module of the regional gateway monitors the computation task metadata in real time, acquiring task metadata information, including task type, level, data size, deadline, and security tags. This acquired task metadata is then categorized into traffic types. Traffic categorization refers to distinguishing and classifying data flows in the network according to rules, grouping data flows with similar attributes, uses, or security requirements into different categories. Task metadata is divided into hidden data and disguised data. Hidden data refers to data with extremely high requirements for concealment during transmission, aiming to avoid detection by malicious monitoring or attackers, ensuring the security and confidentiality of data during transmission. Disguised data primarily serves to cover hidden data, increasing the difficulty for attackers to monitor and analyze it. Disguised data includes device regular status heartbeats, non-real-time logs, software update fragments, etc. Background traffic refers to normal, continuously flowing network data traffic other than hidden and disguised data, based on the transmission path. To construct a background traffic feature model, the following steps are taken: Background traffic parameters are collected, including packet size and packet transmission interval. A network packet capture tool (Wireshark) is used to acquire these parameters, recording the size of each packet and the transmission time difference between adjacent packets. The acquired data is preprocessed to remove noise and outliers. The frequency of packet occurrence within different size intervals is statistically analyzed, and the proportion of packets in each interval to the total number of packets is calculated. A Poisson-exponential background traffic model is used as the background traffic feature model. This model is trained using background traffic data. Based on the constructed background traffic feature model, the hidden data is decomposed into a series of fragments. The size of these fragments is randomly distributed among the main packet sizes of the background traffic, and the transmission interval of the fragments also conforms to the corresponding pattern presented by the background traffic interval. This ensures that the generated fragments are highly similar to the background traffic in terms of features, thereby reducing the risk of being monitored and identified.
[0036] Based on the split interaction mode in step S104, and based on the several auxiliary paths formed by the split, the generated fragments are distributed to several auxiliary paths for transmission, increasing the difficulty for attackers to track and intercept. The fragments received on the auxiliary paths interact with the background data packets inherent on the auxiliary paths. Specifically, the sending time of the hidden data fragments is consistent with the sending interval of the background data packets. Based on the size of the background data packets obtained above, the hidden data fragments generate data packets of the corresponding size, thereby interacting the received fragments with the background data packets inherent on the auxiliary paths.
[0037] The system enables non-critical devices to inject spoofed data into the main communication line during specific time periods. These non-critical devices refer to those that have a relatively small impact on the overall network operation and can adjust their data transmission behavior within a certain range. By injecting spoofed data, the system can actively shape the traffic pattern of the main line, creating a spoofed environment for cross-regional hidden data. This makes it difficult for attackers to detect the transmission of critical data from changes in the main line's traffic, thereby improving the security and reliability of critical data transmission.
[0038] A specific example is as follows: A large enterprise has multiple branches located in different regions. These branches exchange data with headquarters via the enterprise wide area network (WAN). The finance department needs to aggregate the financial statement data from each branch to headquarters monthly for financial analysis and decision-making. This financial statement data is highly sensitive information, requiring extremely high levels of confidentiality during transmission. Leakage could cause significant economic losses and reputational damage to the enterprise. Therefore, the enterprise decided to adopt a transmission method combining hidden and disguised data to ensure the secure transmission of financial statement data.
[0039] A task awareness module is deployed at the regional gateway of each branch office. This module monitors the metadata of computing tasks in the network in real time. When the finance department initiates a financial statement data transmission task, the task awareness module obtains the task metadata information, including task type (financial statement data transmission), level (high security level), data size (assumed to be 500MB), deadline (before 24:00 on the last day of the month), and security label (highly sensitive). The task metadata is categorized into traffic types based on preset rules. Because financial statement data requires extremely high confidentiality during transmission, it is classified as hidden data. Simultaneously, to provide cover for the hidden data, device status heartbeats, non-real-time logs, and software update fragments are selected as disguised data. The network packet capture tool Wireshark is used to collect background traffic parameters along the transmission path (WAN link from branch office to headquarters). Packet capture is continuously performed for a period of time (e.g., one week), recording the size of each data packet and the time difference between adjacent data packets. The collected data is preprocessed to remove noise and outliers. For example, remove packets that are significantly too large or too small (which may be abnormal data caused by network errors or attacks), and records with significantly different sending times (which may be abnormal situations caused by network congestion or equipment failure). Statistically analyze the frequency of packets within different size ranges and calculate the proportion of packets in each range to the total number of packets. Assume the statistics show that 60% of background traffic packets are between 100 and 500 bytes, 30% are between 500 and 1000 bytes, and 10% are greater than 1000 bytes. Use the Poisson-exponential background traffic model as the background traffic feature model, train the model using preprocessed background traffic data, and determine the parameters in the model, such as the arrival rate λ of the Poisson process and the parameters of the exponential distribution (which are the same as λ).
[0040] Based on the established background traffic characteristic model, 500MB of hidden financial statement data is broken down into a series of fragments. The size of the fragments is randomly distributed between the main background traffic packet size (100-1000 bytes). For example, the generated fragment sizes might be 120 bytes, 350 bytes, 780 bytes, etc., and the sending interval of the fragments also conforms to the pattern shown by the background traffic interval. The sending time difference between adjacent fragments is determined according to a trained Poisson-exponential model. For example, if the model predicts that a background data packet is sent on average every 200 milliseconds, then the sending interval of the fragments will also fluctuate randomly around this average value, possibly being 180 milliseconds, 220 milliseconds, etc. Based on the split interaction pattern, multiple auxiliary paths (such as internal backup network links or shared network bandwidth with other partners) are selected to transmit the generated fragments. Distributing different fragments across these auxiliary paths increases the difficulty for attackers to track and intercept them. For example, fragment 1 is transmitted via auxiliary route A, fragment 2 via auxiliary route B, and so on. On each auxiliary route, the received hidden data fragments interact with the inherent background data packets on that route. Specifically, the transmission time of the hidden data fragments follows the same pattern as the transmission interval of the background data packets, and hidden data fragment packets of corresponding sizes are generated based on the size of the background data packets. For example, if most background data packets on the auxiliary routes are 300-600 bytes, then the hidden data fragments will also generate packets within this size range for transmission, making the fragments highly similar in characteristics to the background traffic, thus reducing the risk of being detected and identified.
[0041] Identify non-critical devices within the enterprise network, such as printers and surveillance cameras in office areas. These devices have a relatively small impact on the overall network operation, and their data transmission behavior can be adjusted within a certain range. During specific periods of financial statement data transmission (such as the first few hours after transmission begins), software can be used to control these non-critical devices to inject spoofed data into the main communication line. For example, printers can be instructed to send regular device status heartbeat data at intervals, and surveillance cameras can upload non-real-time log data. By injecting this spoofed data, the traffic pattern of the main line can be actively shaped, making the main line traffic appear normal. This makes it difficult for attackers to detect the transmission of critical data (financial statement data) from changes in the main line traffic, thereby improving the security and reliability of critical data transmission.
[0042] The technical solutions in the above-described embodiments of this application have at least the following technical effects or advantages: by generating hidden data fragments, the hidden data is highly assimilated with the background traffic in both macroscopic and microscopic characteristics, which greatly reduces the risk of being identified by attackers through traffic analysis. Through multi-path parallel transmission gain, a better balance between concealment and transmission efficiency is achieved, realizing a synergistic leap in security and transmission efficiency, and building a new generation of communication base that integrates high efficiency, reliability and concealment for high-security industrial Internet of Things.
[0043] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. For those skilled in the art, the present invention can have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A multi-device joint communication method based on the Industrial Internet of Things, characterized in that, include: S101, Obtain industrial equipment nodes, divide the industrial equipment nodes into regions according to grouping rules, and identify the divided regions; wherein, the grouping rules include physical location and functionality; S102, based on the divided regions and industrial equipment nodes, the industrial equipment nodes within the regions are connected by directed edges to construct a device event association graph. Within the regions, the main communication line and auxiliary communication line are extracted based on the device event association graph. The main communication line is the high-frequency communication path between devices within the region, and the auxiliary communication line refers to the communication line that undertakes communication tasks when the main line is congested. The auxiliary communication line is connected to the main communication line through interactive nodes, and there are two auxiliary communication lines. S103, the main communication line and the auxiliary communication line switch interactively according to the interaction rules; the interaction rules are to calculate the device enhancement degree and trigger the interaction conditions, collect device communication logs to construct a local device event association diagram in the region, and calculate the device enhancement degree based on the communication frequency in the local device event association diagram; the interaction modes include parallel mode, merged interaction mode and split interaction mode. S104, construct a communication path based on parallel mode, merged interaction mode and split interaction mode, and perform joint communication based on the communication path; The joint communication method further includes: cross-regional joint communication and multi-path covert communication, wherein the cross-regional joint communication method is as follows: S201, Identify adjacent and non-adjacent areas from the divided areas, construct a cross-regional network based on the communication paths within the area, adjacent and non-adjacent areas, identify the path patterns within the current area, match the path patterns of the current area according to path matching rules, and connect the current area with adjacent or non-adjacent areas based on the matching results to form cross-regional joint communication; S202, construct a global device event association diagram based on the device event association diagram within the region, calculate the cross-regional association weight based on the global device event association diagram, and schedule cross-regional joint communication based on the cross-regional association weight; The steps of the multi-path covert communication are as follows: acquire task metadata, classify the task metadata by traffic, the traffic classification divides the task metadata into hidden data and disguised data, the hidden data generates fragments based on the background traffic of the transmission path, the split mode disperses the generated fragments to multiple auxiliary lines for transmission, and at the same time, disguised data is injected into the main communication line.
2. The multi-device joint communication method based on the Industrial Internet of Things as described in claim 1, characterized in that, The triggering conditions for interaction include priority path mapping conditions and interaction mode triggering conditions. For priority path mapping conditions, high-priority data is required to use the main communication line, medium-priority data is transmitted using the first auxiliary communication line, and low-priority data is transmitted using the second auxiliary communication line. When the communication data delay on the main communication line exceeds a preset time threshold, the system switches to the first auxiliary communication line. When the bandwidth utilization of the main communication line exceeds the preset bandwidth threshold, the split interaction mode is triggered; when the bandwidth utilization of the first auxiliary communication line or the second auxiliary communication line exceeds the preset bandwidth threshold, the merge interaction mode is triggered; when the communication data is under normal load, the parallel mode is used.
3. The multi-device joint communication method based on the Industrial Internet of Things as described in claim 1, characterized in that, The steps for identifying adjacent regions are as follows: calculate the minimum distance by taking the distance between the nearest vertices of two graphics as the minimum distance, use the Euclidean distance formula to calculate the minimum distance, set a distance threshold, and if the minimum distance is less than or equal to the preset distance threshold, then the two regions are determined to be adjacent regions; otherwise, they are not adjacent regions. When two regions do not meet the minimum distance threshold, they are determined to be non-adjacent regions.
4. The multi-device joint communication method based on the Industrial Internet of Things as described in claim 1, characterized in that, The method for identifying the path pattern in the current area is as follows: when all traffic in the area converges to a single high-bandwidth path, it is identified as a merging pattern; when traffic in the area is distributed across multiple low-bandwidth paths, it is identified as a splitting pattern; when traffic in the area is evenly distributed across multiple paths of equal bandwidth, it is identified as a parallel pattern.
5. The multi-device joint communication method based on the Industrial Internet of Things as described in claim 1, characterized in that, The path matching rules are: merge pattern matches split pattern, merge pattern matches parallel pattern, and split pattern matches merge pattern.
6. The multi-device joint communication method based on the Industrial Internet of Things as described in claim 1, characterized in that, The formula for calculating cross-regional association weights is: ,in, This is a cross-regional association weight, used to evaluate the priority or path selection criteria for cross-regional communication. The degree of correlation within a region refers to the strength of the correlation between devices within the same region. For path bandwidth matching degree, For inter-regional delay, This is a weighting coefficient for the degree of correlation within a region, used to adjust the proportion of influence of the degree of correlation within a region on the weight of correlation across regions. This is a weighting coefficient for a comprehensive indicator of bandwidth matching and latency, used to adjust the proportion of influence of the comprehensive indicator of bandwidth matching and latency on the cross-regional correlation weight.
7. The multi-device joint communication method based on the Industrial Internet of Things as described in claim 1, characterized in that, The hidden data refers to data with the highest requirements for the concealment of transmission, used to avoid being detected by malicious monitoring or attackers. The main function of the disguised data is to provide cover for the hidden data.
8. The multi-device joint communication method based on the Industrial Internet of Things as described in claim 7, characterized in that, The method by which the generated fragments are distributed across multiple auxiliary paths for transmission in the split mode is as follows: the fragments received on the auxiliary paths interact with the background data packets inherent on the auxiliary paths. Specifically, the sending time of the hidden data fragments is consistent with the sending interval of the background data packets. Based on the size of the background data packets, the hidden data fragments generate data packets of the same size, thereby interacting with the background data packets inherent on the auxiliary paths.
Citation Information
Patent Citations
Multi-link switching method and apparatus
CN105848236A
Multi-device joint communication system, method and device based on industrial Internet of Things
CN116827808A