Traffic analysis management system based on aviation internet autonomous controllable platform

By establishing a five-dimensional standardized dataset and a dynamic bandwidth optimization strategy, the problems of inconsistent data formats, disordered timing, and low early warning response efficiency in the autonomous and controllable aviation internet platform were solved. This enabled accurate identification of air-to-ground applications and dynamic bandwidth optimization, improving data processing efficiency and network stability.

CN122053392APending Publication Date: 2026-05-15AIRLAND INTERNET TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
AIRLAND INTERNET TECH CO LTD
Filing Date
2026-01-26
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

The traffic analysis and management system of the autonomous and controllable aviation internet platform suffers from inconsistent data formats, disordered time sequences, lack of multi-dimensional correlation analysis, inability to accurately identify air-to-ground applications, static bandwidth allocation, low data storage and query efficiency, and low early warning response efficiency, making it difficult to meet diverse operational needs.

Method used

Network traffic data is acquired through the data acquisition unit, verified and filtered by the data processing unit, and a five-dimensional standardized dataset is established. An intelligent classification mechanism for devices, flights, applications, scenarios and traffic is constructed, and a dynamic traffic map and hierarchical early warning mechanism are generated. Combined with the air-to-ground bandwidth optimization unit, traffic air-to-ground applications are identified, and multi-dimensional correlation algorithms and dynamic bandwidth optimization strategies are adopted.

Benefits of technology

It achieves the integrity and accuracy of traffic data, enables rapid retrieval and backtracking, provides precise early warnings, identifies high-traffic applications, dynamically optimizes bandwidth allocation, improves network stability and data processing efficiency, and supports multi-condition combination filtering and visualization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053392A_ABST
    Figure CN122053392A_ABST
Patent Text Reader

Abstract

The invention relates to an aviation internet autonomous controllable platform flow analysis and management system. The method comprises a data acquisition unit, a data processing unit, a flow early warning traceability unit and an air-ground bandwidth optimization unit. Presetting aviation fleet satellite network acquisition nodes, and obtaining network flow data; five-dimensional standardized data sets of equipment, flights, applications, scenes and traffic are generated through processing, and the data sets are graded through an intelligent classification mechanism and stored according to grades; constructing an equipment dynamic digital file, generating an equipment flow diagram with a time axis, extracting total flow data of target equipment through multi-condition combination screening by combining flow diagram time sequence distribution characteristics and stage flow statistical data and utilizing a dynamic flow fluctuation threshold value and a grading early warning mechanism, and obtaining an evaluation report; and combining an air space application flow fingerprint spectrum technology and the five-dimensional standardized data set to identify flow air space application, and generating a bandwidth optimization strategy. Therefore, flow analysis and management of the aviation internet are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network traffic management technology and independent and controllable information system technology, specifically relating to a traffic analysis and management system based on an independent and controllable aviation internet platform. Background Technology

[0002] Currently, the traffic analysis and management of the autonomous and controllable aviation internet platform still has the following areas for improvement: The complex satellite network environment of the aviation fleet leads to issues such as inconsistent formats and disordered time sequences in the raw traffic data. Existing systems lack targeted verification mechanisms, failing to effectively filter abnormal data. Furthermore, the lack of a multi-dimensional correlation system between equipment, flights, applications, scenarios, and traffic results in low data standardization, making it difficult to support accurate analysis. The traffic demands of aviation equipment vary significantly across different operational phases, such as takeoff, landing, and cruising. Existing systems mostly employ fixed threshold monitoring modes, unable to dynamically adjust warning standards based on flight scenarios and equipment types. Simultaneously, the root cause identification of abnormal traffic lacks cross-dimensional correlation analysis capabilities, making it difficult to quickly trace the causes of anomalies at the equipment, application, and flight levels, resulting in low warning response efficiency.

[0003] In aviation scenarios, air-to-ground applications are diverse and exhibit significant differences in traffic consumption characteristics. Existing systems lack effective application fingerprinting technology, making it difficult to accurately distinguish the attributes of various air-to-ground applications. Bandwidth allocation often employs static strategies, failing to dynamically optimize based on factors such as historical traffic trends, satellite channel capacity fluctuations, and device priorities. This results in high-traffic applications consuming excessive bandwidth, impacting the stability of critical business data transmission. Furthermore, existing systems have inadequate hierarchical storage and indexing mechanisms for traffic data, leading to low efficiency in backtracking and querying historical data within the past 31 days, and a lack of multi-level traffic ranking systems and interactive visualization features. Data export formats are limited, and the flexibility of filtering configuration is insufficient, failing to meet the diverse operational needs of administrators, data analysts, and other roles. Summary of the Invention

[0004] To address the aforementioned problems in the existing technology, this invention provides a traffic analysis and management system based on an autonomous and controllable aviation internet platform; The objective of this invention can be achieved through the following technical solutions: a data acquisition unit, a data processing unit, a traffic early warning and source tracing unit, and an air-to-ground bandwidth optimization unit; The data acquisition unit obtains network traffic data through the acquisition nodes of the preset aircraft fleet satellite network; The data processing unit verifies the network traffic data and filters abnormal network traffic data; based on the filtering results, it designs a multi-dimensional association algorithm to generate a five-dimensional standardized dataset of devices, flights, applications, scenarios and traffic; it establishes an intelligent classification mechanism to classify the five-dimensional standardized dataset; and it stores the data based on the classification results. The traffic early warning and tracing unit constructs a dynamic digital archive of the device based on the five-dimensional standardized dataset and generates a device traffic map with a time axis; it establishes a dynamic traffic fluctuation threshold and a graded early warning mechanism by combining the temporal distribution characteristics of the traffic map with the stage traffic statistics of the standardized dataset; it extracts the full traffic data of the target device using a multi-condition combination mechanism, performs correlation analysis on the early warning device information identified by the associated data, and obtains an evaluation report based on the analysis results. The air-to-ground bandwidth optimization unit verifies the air-to-ground application traffic fingerprinting technology and the five-dimensional standardized dataset based on the evaluation report to identify air-to-ground applications; it calculates the traffic difference of the air-to-ground applications on the target device through a scenario-based bandwidth allocation model and generates a bandwidth optimization strategy.

[0005] As a preferred technical solution of the present invention, the specific verification process includes: extracting data attributes based on the original network traffic data through feature parsing to obtain a verification feature list; establishing a format and timing compliance rule base based on the aviation internet communication protocol standard; comparing the verification feature list with the timing compliance rule base; verifying the data frame format through preset protocol specifications; and obtaining a compliance dataset and anomaly annotations. Based on the aforementioned compliance dataset, the encryption verification algorithm is invoked to decrypt and verify the integrity identifier of the data frame. Combined with the unique code of the associated device and the flight satellite network authorization list, the device from which the data originates is verified, and the secondary verification result and integrity anomaly label are obtained. Based on the secondary verification results and complete anomaly annotations, a list of verified data and an anomaly data report are generated.

[0006] Specifically, the process of filtering abnormal network traffic data includes: based on the abnormal data report and the original network traffic data, the abnormal data is classified into standard categories through anomaly classification; based on the classification results, repair and calibration are performed to obtain the repaired compliant data; based on the compliant data and the data list, standard network traffic data for filtering abnormal network traffic data is obtained.

[0007] Specifically, the multi-dimensional association algorithm is as follows: preprocessing the standard network traffic data and establishing a mapping relationship between device codes and flight scheduling records; matching the traffic dimension data to the corresponding device, flight, application, and scenario association combination according to the timestamp to obtain a preliminary association data matrix; correcting abnormal associations in the preliminary association data matrix; establishing association weight rules to prioritize the association data; generating a five-dimensional association data matrix; and converting the five-dimensional association data matrix into a structured data format to obtain the conversion result.

[0008] Specifically, the process of classifying the five-dimensional standardized dataset includes: classifying and standardizing the five-dimensional associated data matrix based on the transformation result to generate a five-dimensional standardized dataset; establishing a three-level classification system and using a federated weighted scoring algorithm, combined with the blockchain node consensus mechanism, to perform distributed weighted calculation on the priority of the corresponding dimension data of the five-dimensional standardized dataset, generating a classification verification hash value, and comparing the classification result with the verification hash value.

[0009] Specifically, the process of storing the data includes: storing the corresponding priority data in layers based on the five-dimensional standardized dataset with the hierarchical identifier, constructing a mapping relationship table using a multi-dimensional indexing mechanism, and obtaining the query link of the hierarchically stored data.

[0010] Specifically, the process of setting a dynamic traffic fluctuation threshold and triggering a tiered early warning includes: retrieving historical traffic data from the five-dimensional standardized dataset based on the mapping table, calculating the historical traffic mean and standard deviation, and obtaining an initial traffic fluctuation baseline; introducing a dynamic adjustment factor to adjust the initial traffic fluctuation baseline to generate a dynamic traffic fluctuation threshold; acquiring equipment traffic data through the acquisition nodes of the preset aviation fleet satellite network; combining the dynamic threshold of the corresponding scenario with the flight operation phase to calculate the traffic anomaly amplitude, and generating tiered early warning information based on the calculation results.

[0011] Specifically, the extraction of full traffic data of the target device includes: filtering the target device based on the hierarchical early warning information, converting the filtering result into an index query statement, locating the storage layer where the target device is located through the main index field, filtering the traffic data in the storage layer using the auxiliary index field, obtaining the data identifier of the target device, and extracting the full traffic data of the target device based on the data identifier.

[0012] Specifically, the correlation analysis of the early warning device information includes: based on the full traffic dataset of the target device and the hierarchical early warning information, performing multi-dimensional data correlation retrieval including: device dimension, flight dimension, application dimension, scenario dimension, and traffic dimension; the device dimension retrieves historical early warning records of the device and analyzes the number of device early warnings; the flight dimension retrieves the traffic data of the device and counts the number of flight early warning devices; the application dimension retrieves the characteristic data of traffic applications; the traffic dimension retrieves the traffic data of the device and analyzes traffic anomaly data; based on the multi-dimensional data and using the correlation retrieval results, an attribution analysis algorithm is used to generate an anomaly root cause location report.

[0013] Specifically, obtaining the evaluation report includes: extracting abnormal data based on the abnormal root cause location report, calculating the deviation of the abnormal data from the abnormal period traffic data and a preset threshold, calculating the abnormal impact coefficient, and generating a quantitative evaluation report using a weighted evaluation algorithm.

[0014] Specifically, the process of identifying air-to-ground applications for traffic includes: using air-to-ground application fingerprint feature enhancement extraction technology based on the five-dimensional standardized dataset to obtain the application's identification features and construct a multi-dimensional fingerprint feature library; using an adaptive calibration algorithm to match the collected traffic data features with the multi-dimensional fingerprint feature library to obtain the matching results; and introducing a scenario adaptation factor to dynamically calibrate the matching results. By using an air-to-ground application intent association reasoning model, historical application records in the target device's dynamic digital archive and application data of flight mission types are integrated to obtain the air-to-ground application attributes of traffic.

[0015] Specifically, the process of generating the bandwidth optimization strategy includes: using a three-dimensional attribution engine for air-ground applications, scenarios, and devices based on the air-ground application attributes; decomposing the influencing factors of application traffic consumption through a cross-dimensional feature decoupling algorithm; quantifying the contribution of the influencing factors using the entropy weight method; and calculating the network adaptation coefficient of air-ground applications in devices and aviation scenarios.

[0016] Based on a multi-feature fusion bandwidth demand prediction model, a four-dimensional prediction feature set is constructed by integrating historical traffic time-series trends, flight operation phase traffic patterns, equipment type traffic thresholds, and satellite channel capacity fluctuation data. The bandwidth demand range value is obtained through a grey prediction-Markov chain combination algorithm, providing a quantitative decision basis for bandwidth allocation. A closed-loop elastic bandwidth optimization iterative framework is adopted, which adaptively corrects the scenario weight factor and equipment priority threshold of the allocation algorithm through a dynamic loop mechanism, thereby dynamically optimizing bandwidth in aviation scenarios.

[0017] The beneficial effects of this invention are as follows: This system achieves multi-dimensional value enhancement in aviation satellite network traffic management through core designs such as five-dimensional data modeling, intelligent early warning, precise identification of air-to-ground applications, and dynamic bandwidth optimization. Specific benefits include: Employing a secondary verification + anomaly repair mechanism, it filters invalid and abnormal data through protocol compliance comparison, encryption verification, and device authorization verification, ensuring the integrity and accuracy of traffic data; Innovating a five-dimensional correlation algorithm to establish standardized datasets for devices, flights, applications, scenarios, and traffic, combined with hierarchical storage and multi-dimensional indexing, enabling rapid retrieval and backtracking of historical data, improving data processing efficiency; Constructing a dynamic traffic fluctuation threshold system, adapting differentiated early warning standards to flight operation scenarios (level flight / takeoff and landing), accurately highlighting devices with sudden traffic surges, and proactively avoiding network congestion risks; Dynamic digital archives of devices and timeline traffic graphs intuitively present traffic change trends, supporting multi-condition combination filtering of target devices, and quickly locating the root cause of anomalies through attribution analysis, reducing manual investigation time.

[0018] Based on air-to-ground application fingerprinting technology, this system identifies various air-to-ground applications such as video streaming and remote control. It integrates with the AC management application library to enable custom filtering and understand the distribution of high-traffic applications. A three-dimensional attribution engine for applications, devices, and scenarios is established to quantify the traffic differences between abnormal and normal devices, providing data support for accurate bandwidth allocation and avoiding resource waste. Employing a grey prediction-Markov chain combined algorithm, it integrates multi-dimensional data such as historical traffic, flight phases, and device types to accurately predict bandwidth requirements and generate closed-loop elastic bandwidth optimization strategies. Differentiated bandwidth limiting schemes are developed for abnormal devices and high-traffic applications, such as controlling the video streaming bandwidth of abnormal devices within specified limits, balancing network stability and user needs.

[0019] It offers multi-dimensional visualization (ring charts, trend curves) and cross-level linked analysis, supports ranking configuration, and allows users to jump to historical traffic trends or related application rankings by clicking on the device IP, making operation highly efficient. It supports filtering conditions and full data export, including verification codes, warning indicators, and optimization suggestions. Data can be traced back to the original processing results, providing complete data support for operational decisions. The system's core algorithms and data processing flow are independently designed, supporting custom application libraries and bandwidth policy configurations, adapting to diverse equipment in the aviation fleet (7 categories including mobile terminals and medical equipment) and complex operating scenarios. It combines a blockchain node consensus mechanism for hierarchical data verification to ensure the security of data storage and transmission, while dynamically adjusting bandwidth to improve the satellite network's anti-interference capabilities and operational stability. Attached Figure Description

[0020] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings.

[0021] Figure 1This is a flowchart illustrating the traffic analysis and management system of the autonomous and controllable aviation internet platform of the present invention. Figure 2 This is a structural diagram of the air-to-ground bandwidth optimization strategy in this invention. Detailed Implementation

[0022] To further illustrate the technical means and effects of the present invention in achieving its intended purpose, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention, in conjunction with the accompanying drawings and preferred embodiments, is provided.

[0023] Please see Figure 1-2 A traffic analysis and management system based on an autonomous and controllable aviation internet platform includes: a data acquisition unit, a data processing unit, a traffic early warning and source tracing unit, and an air-to-ground bandwidth optimization unit. The data acquisition unit obtains network traffic data through the acquisition nodes of the preset aircraft fleet satellite network; The data processing unit verifies the network traffic data and filters abnormal network traffic data; based on the filtering results, it designs a multi-dimensional association algorithm to generate a five-dimensional standardized dataset of devices, flights, applications, scenarios and traffic; it establishes an intelligent classification mechanism to classify the five-dimensional standardized dataset; and it stores the data based on the classification results. The traffic early warning and tracing unit constructs a dynamic digital archive of the device based on the five-dimensional standardized dataset and generates a device traffic map with a time axis; it establishes a dynamic traffic fluctuation threshold and a graded early warning mechanism by combining the temporal distribution characteristics of the traffic map with the stage traffic statistics of the standardized dataset; it extracts the full traffic data of the target device using a multi-condition combination mechanism, performs correlation analysis on the early warning device information identified by the associated data, and obtains an evaluation report based on the analysis results. The air-to-ground bandwidth optimization unit verifies the air-to-ground application traffic fingerprinting technology and the five-dimensional standardized dataset based on the evaluation report to identify air-to-ground applications; it calculates the traffic difference of the air-to-ground applications on the target device through a scenario-based bandwidth allocation model and generates a bandwidth optimization strategy.

[0024] As a preferred technical solution of the present invention, the specific verification process includes: extracting data attributes based on the original network traffic data through feature parsing to obtain a verification feature list; establishing a format and timing compliance rule base based on the aviation internet communication protocol standard; comparing the verification feature list with the timing compliance rule base; verifying the data frame format through preset protocol specifications; and obtaining a compliance dataset and anomaly annotations. Based on the aforementioned compliance dataset, the encryption verification algorithm is invoked to decrypt and verify the integrity identifier of the data frame. Combined with the unique code of the associated device and the flight satellite network authorization list, the device from which the data originates is verified, and the secondary verification result and integrity anomaly label are obtained. Based on the secondary verification results and complete anomaly annotations, a list of verified data and an anomaly data report are generated.

[0025] In this embodiment, raw network traffic data is the fundamental data source for system analysis. It contains the following key information categories, covering the entire data transmission link and related attributes: Core data frame information: complete data frame content (including transmitted payload data), data frame format (frame header, frame trailer, field structure), data frame length, and frame checksum; Communication identification information: source IP address, destination IP address, source port number, destination port number, transmission protocol type (IPv4 / IPv6, TCP / UDP, etc.), and device MAC address; Timing and transmission information: data transmission timestamp (accurate to milliseconds), data transmission duration, uplink / downlink traffic values ​​(raw byte count), and transmission rate; Device and flight association information: unique code of the data sending device (e.g., device serial number, IMEI code), device type identifier (mobile terminal / PC / medical device, etc.), and basic information of the flight (flight tail number, flight number, flight phase association identifier); Network environment auxiliary information: satellite network frequency band identifier, data transmission link identifier, signal strength related parameters, and temporary network access authorization identifier.

[0026] The collected raw network traffic data is analyzed for features, extracting key data attributes such as data frame format, timestamp, protocol type, and data length, and integrating them to form a complete verification feature list. Based on aviation internet communication protocol standards (such as ARINC and DO series specifications), a format and timing compliance rule base covering format compliance requirements and timing logic rules is constructed. The verification feature list is compared one by one with this rule base, and the format integrity and field standardization of each data frame are verified according to the preset protocol specifications. Compliant datasets that meet the protocol standards are selected, and data that does not meet the requirements, such as format errors and timing disorders, is marked with specific anomaly types and locations. For compliant datasets, an encryption verification algorithm is used to decrypt and verify the integrity identifier built into the data frame to confirm that the data has not been tampered with during transmission. At the same time, the device's unique code (such as MAC address and dedicated device number) is compared with the flight satellite network authorization list to remove data generated by devices that have not obtained network access authorization. A secondary verification result containing data integrity verification results, device authorization verification results, and anomaly data records marked with complete anomaly information are obtained. Based on the combined results of the secondary verification and complete anomaly annotations, a clear list of verified data (containing all compliant and authorized data) and a detailed anomaly report (covering anomaly identification, anomaly type, and preliminary judgment of anomaly cause) are generated.

[0027] Specifically, the process of filtering abnormal network traffic data includes: based on the abnormal data report and the original network traffic data, the abnormal data is classified into standard categories through anomaly classification; based on the classification results, repair and calibration are performed to obtain the repaired compliant data; based on the compliant data and the data list, standard network traffic data for filtering abnormal network traffic data is obtained.

[0028] In this embodiment, previously generated abnormal data reports and original network traffic data are retrieved. Abnormal data is categorized according to its nature (e.g., format errors, timing deviations, data tampering, unauthorized access, etc.) to clearly define the boundary between repairable and unrepairable anomalies. For repairable abnormal data (e.g., minor timing deviations, missing non-critical fields), targeted repair and calibration algorithms are employed. Timing deviation data is corrected based on the timing patterns of normal data from the same device within the same time period. Missing field data is supplemented by associating with historical similar data to obtain repaired compliant data. Unrepairable abnormal data (e.g., severely formatted errors, malicious attack data frames) is directly discarded. The repaired compliant data and verification data are integrated and deduplicated using a data list to obtain standard network traffic data that filters out all abnormal data, has a uniform format, and is of legitimate origin.

[0029] Specifically, the multi-dimensional association algorithm is as follows: preprocessing the standard network traffic data and establishing a mapping relationship between device codes and flight scheduling records; matching the traffic dimension data to the corresponding device, flight, application, and scenario association combination according to the timestamp to obtain a preliminary association data matrix; correcting abnormal associations in the preliminary association data matrix; establishing association weight rules to prioritize the association data; generating a five-dimensional association data matrix; and converting the five-dimensional association data matrix into a structured data format to obtain the conversion result.

[0030] In this embodiment, standard network traffic data is first preprocessed, including data cleaning, redundant field removal, and numerical format standardization to ensure data quality. The system interfaces with the flight scheduling system through a pre-defined device management module, establishing a one-to-one mapping between device codes and flight scheduling records (flight tail number, flight time, route information, etc.). Using timestamps as the core association key, traffic dimension data (uplink / downlink traffic, traffic transmission duration, etc.) are matched to corresponding device (device code, device type), flight (flight tail number, flight number), application (application type identified based on port number and protocol characteristics), and scenario (takeoff / landing / level flight scenario determined by flight scheduling records) association combinations, constructing a preliminary association data matrix. The preliminary association data matrix undergoes abnormal association correction, eliminating data combinations with mismatched timestamps or contradictory association information; association weight rules are established, prioritizing associated data based on data importance (e.g., critical business data has a higher association weight than ordinary user data), generating a five-dimensional association data matrix containing five dimensions of information: device, flight, application, scenario, and traffic. Finally, the five-dimensional association data matrix is ​​converted into a structured data format, transforming unstructured and semi-structured association information into a unified structured format, which facilitates subsequent storage and retrieval, and obtains standardized conversion results.

[0031] Specifically, the process of classifying the five-dimensional standardized dataset includes: classifying and standardizing the five-dimensional associated data matrix based on the transformation result to generate a five-dimensional standardized dataset; establishing a three-level classification system and using a federated weighted scoring algorithm, combined with the blockchain node consensus mechanism, to perform distributed weighted calculation on the priority of the corresponding dimension data of the five-dimensional standardized dataset, generating a classification verification hash value, and comparing the classification result with the verification hash value.

[0032] In this embodiment, based on the transformation result of the five-dimensional correlation data matrix, a data standardization algorithm (such as Z-score standardization) is used to uniformly process numerical data of different dimensions (such as flow values ​​and correlation weights), eliminating differences in units and numerical ranges, and generating a standardized five-dimensional dataset that can be directly used for calculation and analysis; wherein, the data standardization formula is: , Z ij X represents the standardized result of the i-th data point in the j-th dimension; ij This represents the original value of the i-th data point in the j-th dimension. The mean of all data in the j-th dimension; Let be the standard deviation of all data in the j-th dimension.

[0033] A three-tiered priority system (high priority, medium priority, and low priority) is established. High-priority data includes critical business-related data such as flight control and medical equipment communication; medium-priority data includes normal network access data for ordinary users; and low-priority data includes redundant backup data and low-value interactive data. A federated weighted scoring algorithm is adopted, with the formula as follows: , Among them, S i w represents the total priority score for the i-th data item. d V represents the weighting coefficient for the d-th dimension (device / flight / application / scenario / traffic); id Let be the original score of the i-th data point in the d-th dimension; Let be the consensus coefficient of the nth blockchain node (the sum of the consensus coefficients of all nodes is 1).

[0034] By leveraging the consensus mechanism of blockchain nodes, the priority of data in each dimension of the five-dimensional standardized dataset is calculated using a distributed weighted average. Different blockchain nodes synchronously evaluate and score the data priority, reaching a unified scoring result through the consensus mechanism. This generates a hierarchical verification hash value, ensuring the security and immutability of the hierarchical result. The hierarchical result and the hierarchical verification hash value are then stored together, providing a basis for subsequent hierarchical storage and access control.

[0035] Specifically, the process of storing the data includes: storing the corresponding priority data in layers based on the five-dimensional standardized dataset with the hierarchical identifier, constructing a mapping relationship table using a multi-dimensional indexing mechanism, and obtaining the query link of the hierarchically stored data.

[0036] In this embodiment, a tiered storage strategy is adopted based on the hierarchical identifiers (high / medium / low priority) of the five-dimensional standardized dataset: high-priority data is stored in a high-speed storage layer (such as an SSD storage array) to ensure fast querying and real-time access to critical data; medium-priority data is stored in a conventional storage layer (such as a SAS hard disk storage cluster) to balance storage performance and cost; and low-priority data is stored in an offline storage layer (such as a tape library) to meet long-term archiving and compliance retention requirements. Simultaneously, a multi-dimensional indexing mechanism is used, with device code, flight tail number, timestamp, application type, and scenario identifier as core index fields, to construct a mapping table for each level of data, clearly defining the specific location of data in different dimensions within the storage system. This mapping table optimizes the query path for tiered data storage. When a user queries specific data, the system can quickly locate the storage layer and location of the data, significantly improving data retrieval efficiency, especially the speed of backtracking queries for historical data within the past 31 days.

[0037] Specifically, the process of setting a dynamic traffic fluctuation threshold and triggering a tiered early warning includes: retrieving historical traffic data from the five-dimensional standardized dataset based on the mapping table, calculating the historical traffic mean and standard deviation, and obtaining an initial traffic fluctuation baseline; introducing a dynamic adjustment factor to adjust the initial traffic fluctuation baseline to generate a dynamic traffic fluctuation threshold; acquiring equipment traffic data through the acquisition nodes of the preset aviation fleet satellite network; combining the dynamic threshold of the corresponding scenario with the flight operation phase to calculate the traffic anomaly amplitude, and generating tiered early warning information based on the calculation results.

[0038] In this embodiment, a five-dimensional standardized dataset is retrieved from the mapping table using a multi-dimensional indexing mechanism. Historical traffic data for the target device / flight during the same historical period (e.g., the past 31 days) is extracted, and the historical traffic mean and standard deviation are calculated. Based on this, an initial traffic fluctuation baseline is determined, clarifying the normal traffic fluctuation range. A dynamic adjustment factor is introduced, taking into account the characteristics of the aviation scenario. The initial traffic fluctuation baseline is dynamically adjusted according to the flight operation phase (higher adjustment factor values ​​during takeoff and landing, and lower adjustment factor values ​​during level flight, when traffic is stable) and equipment type (lower adjustment factor values ​​for critical equipment, and higher adjustment factor values ​​for general equipment). This generates a dynamic traffic fluctuation threshold adapted to different scenarios and equipment. The formula for calculating the dynamic traffic fluctuation threshold is: , T sc This is the dynamic traffic fluctuation threshold (including upper and lower limits) for a certain scenario. This represents the historical average traffic volume for the same period. is the standard deviation of historical flow for the same period; k is the threshold coefficient (set according to the warning sensitivity). Set the scene adjustment factor (separately for takeoff and landing / level flight, etc.).

[0039] Real-time device traffic data is acquired through pre-set satellite network acquisition nodes of the aircraft fleet. The real-time traffic data is compared with dynamic thresholds for the corresponding scenario to calculate the traffic anomaly magnitude (the ratio of the deviation between the real-time traffic and the dynamic threshold). The formula for calculating the traffic anomaly magnitude is as follows: , Traffic anomaly magnitude (percentage); X real This is a real-time traffic value; This represents the median (mean) value of the dynamic threshold for the corresponding scenario.

[0040] Based on the abnormal magnitude, a tiered early warning system is generated: a yellow warning is triggered when traffic surges, and a red abnormality warning is triggered when traffic surges exceed a set threshold. The warning information is simultaneously pushed to the system management interface, and key information such as the warning device identifier, the start time of the abnormality, and the current traffic data are marked.

[0041] Specifically, the extraction of full traffic data of the target device includes: filtering the target device based on the hierarchical early warning information, converting the filtering result into an index query statement, locating the storage layer where the target device is located through the main index field, filtering the traffic data in the storage layer using the auxiliary index field, obtaining the data identifier of the target device, and extracting the full traffic data of the target device based on the data identifier.

[0042] In this embodiment, target devices that trigger warnings are selected based on tiered warning information, and their core identification information (such as device code and IP address) is extracted. The selection results are converted into an index query statement that conforms to the system's storage query specifications. Using the device's core identifier as the primary index field, the storage layer (high-speed / regular / offline storage layer) where the target device resides is quickly located. In the corresponding storage layer, auxiliary index fields (such as timestamp range, application type, and flight information) are used to further filter all traffic data of the device during the warning period and related periods before and after it, including uplink / downlink traffic details, traffic transmission protocols, associated application information, and scene identifiers. By filtering, a unique data identifier (such as data storage number) for the target device is obtained. Based on this data identifier, the full traffic data of the target device is completely extracted from the storage system, covering both normal and abnormal traffic data, providing complete data support for subsequent anomaly tracing and analysis.

[0043] Specifically, the correlation analysis of the early warning device information includes: based on the full traffic dataset of the target device and the hierarchical early warning information, performing multi-dimensional data correlation retrieval including: device dimension, flight dimension, application dimension, scenario dimension, and traffic dimension; the device dimension retrieves historical early warning records of the device and analyzes the number of device early warnings; the flight dimension retrieves the traffic data of the device and counts the number of flight early warning devices; the application dimension retrieves the characteristic data of traffic applications; the traffic dimension retrieves the traffic data of the device and analyzes traffic anomaly data; based on the multi-dimensional data and using the correlation retrieval results, an attribution analysis algorithm is used to generate an anomaly root cause location report.

[0044] In this embodiment, a multi-dimensional data association retrieval is initiated based on the full traffic dataset and hierarchical early warning information of the target device. Device dimension: Historical early warning records of the target device are retrieved, and the number of historical early warnings, warning types, and past processing results are statistically analyzed to determine if the device exhibits high-frequency anomaly patterns. Flight dimension: Traffic data of all devices on the flight to which the device belongs is retrieved, and the number and distribution of early warning devices on the current flight are statistically analyzed to determine if there are flight-level batch anomalies. Application dimension: All application characteristic data (application type, port number, traffic percentage, transmission patterns, etc.) involved in the target device traffic data are retrieved to locate high-traffic applications. Scenario dimension: Combined with flight operation phase data, the specific scenario (takeoff / landing / level flight) when abnormal traffic occurs is analyzed to determine the correlation between the scenario and the anomaly. Traffic dimension: In-depth analysis of the uplink / downlink ratio, peak traffic periods, and transmission paths of abnormal traffic data is conducted to uncover the specific manifestations of traffic anomalies. Based on the multi-dimensional data association retrieval results, an attribution analysis algorithm is used to comprehensively determine the root cause of the anomaly (such as excessive bandwidth consumption by a specific application, device hardware failure, network attack, etc.) by integrating information from various dimensions, generating a detailed anomaly root cause location report.

[0045] Specifically, obtaining the evaluation report includes: extracting abnormal data based on the abnormal root cause location report, calculating the deviation of the abnormal data from the abnormal period traffic data and a preset threshold, calculating the abnormal impact coefficient, and generating a quantitative evaluation report using a weighted evaluation algorithm.

[0046] In this embodiment, key anomaly data is extracted from the anomaly root cause location report, including the scale of abnormal traffic, the duration of the anomaly, and the range of applications and devices involved. The deviation between the traffic data during the abnormal period and a preset threshold is calculated, and the anomaly impact coefficient is determined by combining the scope of the anomaly's impact (e.g., only a single device is affected, multiple devices are affected, or the entire flight network is affected) and the degree of impact (e.g., whether it affects critical services or causes network congestion). A weighted evaluation algorithm is used, with the anomaly impact coefficient, the severity of the anomaly root cause, and the historical cost of handling similar anomalies as weighting indicators for quantitative calculation. Finally, a quantitative evaluation report is generated, containing basic anomaly information, quantitative results of the anomaly impact, anomaly root cause analysis, and priority of handling suggestions, providing data support for administrators to formulate anomaly handling plans.

[0047] Specifically, the process of identifying air-to-ground applications for traffic includes: using air-to-ground application fingerprint feature enhancement extraction technology based on the five-dimensional standardized dataset to obtain the application's identification features and construct a multi-dimensional fingerprint feature library; using an adaptive calibration algorithm to match the collected traffic data features with the multi-dimensional fingerprint feature library to obtain the matching results; and introducing a scenario adaptation factor to dynamically calibrate the matching results. By using an air-to-ground application intent association reasoning model, historical application records in the target device's dynamic digital archive and application data of flight mission types are integrated to obtain the air-to-ground application attributes of traffic.

[0048] In this embodiment, based on a five-dimensional standardized dataset, an air-to-ground application fingerprint feature enhancement extraction technique is employed to extract unique identifiers for various air-to-ground applications from traffic data. These identifiers include data transmission rate, data frame length distribution, port number range, and protocol interaction mode, constructing a multi-dimensional fingerprint feature library covering multiple application types such as video streaming, remote control, file transfer, and flight control. Real-time network traffic data is collected, and its feature information is extracted. An adaptive calibration algorithm is used to perform similarity matching between these features and application features in the multi-dimensional fingerprint feature library to obtain preliminary matching results. A scenario adaptation factor (e.g., increased matching weight for video applications in level flight scenarios and increased matching weight for flight control applications in takeoff and landing scenarios) is introduced to dynamically calibrate the preliminary matching results, correcting matching deviations caused by scenario differences. Through an air-to-ground application intent association reasoning model, historical application usage records in the target device's dynamic digital archive (e.g., the device's previously commonly used application types) are integrated with application data corresponding to flight mission types (e.g., a higher proportion of remote office applications in business flights) to further verify the accuracy of the matching results and clarify the air-to-ground application attributes (application name, application type, application priority, etc.) corresponding to the traffic.

[0049] Specifically, the process of generating the bandwidth optimization strategy includes: using a three-dimensional attribution engine for air-ground applications, scenarios, and devices based on the air-ground application attributes; decomposing the influencing factors of application traffic consumption through a cross-dimensional feature decoupling algorithm; quantifying the contribution of the influencing factors using the entropy weight method; and calculating the network adaptation coefficient of air-ground applications in devices and aviation scenarios.

[0050] Based on a multi-feature fusion bandwidth demand prediction model, a four-dimensional prediction feature set is constructed by integrating historical traffic time-series trends, flight operation phase traffic patterns, equipment type traffic thresholds, and satellite channel capacity fluctuation data. The bandwidth demand range value is obtained through a grey prediction-Markov chain combination algorithm, providing a quantitative decision basis for bandwidth allocation. A closed-loop elastic bandwidth optimization iterative framework is adopted, which adaptively corrects the scenario weight factor and equipment priority threshold of the allocation algorithm through a dynamic loop mechanism, thereby dynamically optimizing bandwidth in aviation scenarios.

[0051] In this embodiment, based on the identified air-to-ground application attributes, a three-dimensional attribution engine for air-to-ground applications, scenarios, and devices is activated. Through a cross-dimensional feature decoupling algorithm, the influencing factors of application traffic consumption are broken down into three categories: application characteristics (e.g., video applications inherently consume high amounts of traffic), device priority (e.g., critical equipment applications have higher priority), and scenario requirements (e.g., level flight scenarios have higher bandwidth requirements for entertainment applications than takeoff and landing scenarios). The contribution of each influencing factor is quantified using the entropy weight method to determine the weight of different factors on traffic consumption, thereby calculating the network compatibility coefficients of various air-to-ground applications under different devices and aviation scenarios (e.g., assessing the degree of matching between the application and the current network environment). Based on a multi-feature fusion bandwidth demand prediction model, historical traffic time-series trends (e.g., traffic change patterns under similar scenarios for the same flight), flight operation phase traffic patterns (e.g., low traffic during takeoff and landing, high traffic during level flight), device type traffic thresholds (e.g., maximum allowable bandwidth for medical devices), and satellite channel capacity fluctuation data (e.g., changes in satellite signal strength across different routes) are integrated to construct a four-dimensional prediction feature set. The bandwidth demand over a future period is predicted using a grey prediction-Markov chain combination algorithm to obtain a bandwidth demand range, which serves as the basis for quantitative decision-making regarding bandwidth allocation. The formula is: Grey GM(1,1) predicts the base value: , Markov chain correction: , The cumulative generated value for gray prediction; The first term of the original sequence; a and b are the parameters of the grey prediction model; The state transition correction coefficients for the Markov chain are set based on the historical error distribution; the final bandwidth requirement range is the corrected prediction value ± the error fluctuation range.

[0052] A closed-loop elastic bandwidth optimization iterative framework is adopted. Through a dynamic loop mechanism, the bandwidth usage and application running status are monitored in real time. Based on the actual running data, the scenario weight factor and device priority threshold of the allocation algorithm are adaptively adjusted to continuously optimize the bandwidth allocation scheme. This enables dynamic optimization of bandwidth resources in aviation scenarios, ensuring sufficient bandwidth for critical business applications while avoiding excessive bandwidth consumption by non-critical applications.

[0053] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.

Claims

1. A traffic analysis and management system based on an autonomous and controllable aviation internet platform, characterized in that, include: Data acquisition unit, data processing unit, traffic early warning and source tracing unit, air-to-ground bandwidth optimization unit; The data acquisition unit obtains network traffic data through the acquisition nodes of the preset aircraft fleet satellite network; The data processing unit verifies the network traffic data and filters out abnormal network traffic data. Based on the filtering results, a multi-dimensional association algorithm is designed to generate a five-dimensional standardized dataset of devices, flights, applications, scenarios, and traffic. An intelligent classification mechanism is established to classify the five-dimensional standardized dataset, and the data is stored based on the classification results. The traffic early warning and tracing unit constructs a dynamic digital archive of the equipment based on the five-dimensional standardized dataset and generates a equipment traffic map with a time axis; through the time-series distribution characteristics of the traffic map and the stage traffic statistics of the standardized dataset, a dynamic traffic fluctuation threshold and a hierarchical early warning mechanism are established. The full traffic data of the target device is extracted using a multi-condition combination mechanism. The warning device information identified by the associated data is analyzed, and an evaluation report is obtained based on the analysis results. The air-to-ground bandwidth optimization unit verifies the air-to-ground application traffic fingerprinting technology and the five-dimensional standardized dataset based on the evaluation report to identify air-to-ground applications; The traffic difference between the target device and the application of the traffic space is calculated using a scenario-based bandwidth allocation model, and a bandwidth optimization strategy is generated.

2. The method according to claim 1, characterized in that, The specific verification process includes: extracting data attributes based on the original network traffic data through feature parsing to obtain a verification feature list; establishing a format and timing compliance rule base based on the aviation internet communication protocol standard; comparing the verification feature list with the timing compliance rule base; verifying the data frame format through preset protocol specifications; and obtaining a compliance dataset and anomaly annotations. Based on the aforementioned compliance dataset, the encryption verification algorithm is invoked to decrypt and verify the integrity identifier of the data frame. Combined with the unique code of the associated device and the flight satellite network authorization list, the device from which the data originates is verified, and the secondary verification result and integrity anomaly label are obtained. Based on the secondary verification results and complete anomaly annotations, a list of verified data and an anomaly data report are generated.

3. The method according to claim 1, characterized in that, The specific process of filtering abnormal network traffic data includes: based on the abnormal data report and the original network traffic data, the abnormal data is classified into standard categories through anomaly classification; based on the classification results, repair and calibration are performed to obtain the repaired compliant data; based on the compliant data and the data list, standard network traffic data for filtering abnormal network traffic data is obtained.

4. The method according to claim 1, characterized in that, The multi-dimensional association algorithm is as follows: preprocess the standard network traffic data, establish a mapping relationship between device codes and flight scheduling records, match the traffic dimension data to the corresponding device, flight, application and scenario association combination according to the timestamp, and obtain a preliminary association data matrix; The preliminary association data matrix is ​​corrected for abnormal associations, association weight rules are established to prioritize the association data, a five-dimensional association data matrix is ​​generated, and the five-dimensional association data matrix is ​​converted into a structured data format to obtain the conversion result.

5. The method according to claim 1, characterized in that, The specific process of classifying the five-dimensional standardized dataset includes: classifying and standardizing the five-dimensional associated data matrix based on the transformation result to generate a five-dimensional standardized dataset; establishing a three-level classification system and using a federated weighted scoring algorithm, combined with the blockchain node consensus mechanism, to perform distributed weighted calculation on the priority of the corresponding dimension data of the five-dimensional standardized dataset, generating a classification verification hash value, and comparing the classification result with the verification hash value.

6. The method according to claim 1, characterized in that, The specific process of storing the data includes: storing the corresponding priority data in layers based on the five-dimensional standardized dataset with the hierarchical identifier, constructing a mapping relationship table using a multi-dimensional indexing mechanism, and obtaining the query link of the hierarchically stored data.

7. The method according to claim 1, characterized in that, The specific process of setting a dynamic traffic fluctuation threshold and triggering a tiered early warning includes: retrieving historical traffic data from the five-dimensional standardized dataset based on the mapping table, calculating the historical traffic mean and standard deviation, and obtaining an initial traffic fluctuation baseline; introducing a dynamic adjustment factor to adjust the initial traffic fluctuation baseline to generate a dynamic traffic fluctuation threshold; acquiring equipment traffic data through the acquisition nodes of the preset aircraft fleet satellite network; combining the dynamic threshold of the corresponding scenario with the flight operation phase to calculate the traffic anomaly amplitude, and generating tiered early warning information based on the calculation results.

8. The method according to claim 1, characterized in that, The extraction of full traffic data of the target device includes: filtering the target device based on the hierarchical early warning information, converting the filtering result into an index query statement, locating the storage layer where the target device is located through the main index field, filtering the traffic data in the storage layer using the auxiliary index field, obtaining the data identifier of the target device, and extracting the full traffic data of the target device based on the data identifier.

9. The method according to claim 1, characterized in that, The correlation analysis of the early warning device information includes: based on the full traffic dataset of the target device and the hierarchical early warning information, performing multi-dimensional data correlation retrieval including: device dimension, flight dimension, application dimension, scenario dimension, and traffic dimension; the device dimension retrieves historical early warning records of the device and analyzes the number of early warnings; the flight dimension retrieves the traffic data of the device and counts the number of flight early warning devices; the application dimension retrieves the characteristic data of traffic applications; the traffic dimension retrieves the traffic data of the device and analyzes abnormal traffic data; based on the multi-dimensional data and using the correlation retrieval results, an attribution analysis algorithm is used to generate an anomaly root cause location report.

10. The method according to claim 1, characterized in that, The process of obtaining the evaluation report includes: extracting abnormal data based on the anomaly root cause location report, calculating the deviation of the abnormal data from the traffic data during the abnormal period and a preset threshold, calculating the anomaly impact coefficient, and generating a quantitative evaluation report using a weighted evaluation algorithm.

11. The method according to claim 1, characterized in that, The specific process for identifying air-to-ground applications in traffic includes: using air-to-ground application fingerprint feature enhancement extraction technology based on the five-dimensional standardized dataset to obtain the application's identification features and construct a multi-dimensional fingerprint feature library; using an adaptive calibration algorithm to match the collected traffic data features with the multi-dimensional fingerprint feature library to obtain the matching results; and introducing a scenario adaptation factor to dynamically calibrate the matching results. By using an air-to-ground application intent association reasoning model, historical application records in the target device's dynamic digital archive and application data of flight mission types are integrated to obtain the air-to-ground application attributes of traffic.

12. The method according to claim 1, characterized in that, The specific process of generating the bandwidth optimization strategy includes: based on the air-ground application attributes, adopting a three-dimensional attribution engine for air-ground applications, scenarios and devices, splitting the influencing factors of application traffic consumption through a cross-dimensional feature decoupling algorithm, quantifying the contribution of the influencing factors by combining the entropy weight method, and calculating the network adaptation coefficient of air-ground applications in devices and aviation scenarios. Based on a multi-feature fusion bandwidth demand prediction model, a four-dimensional prediction feature set is constructed by integrating historical traffic time-series trends, flight operation phase traffic patterns, equipment type traffic thresholds, and satellite channel capacity fluctuation data. The bandwidth demand range value is obtained through a grey prediction-Markov chain combination algorithm, providing a quantitative decision basis for bandwidth allocation. A closed-loop elastic bandwidth optimization iterative framework is adopted, which adaptively corrects the scenario weight factor and equipment priority threshold of the allocation algorithm through a dynamic loop mechanism, thereby dynamically optimizing bandwidth in aviation scenarios.