Internet of things sensor trusted reconstruction method for complex industrial environment
By constructing observational consequence profiles and verifying multi-link data, the frozen state of IoT sensors is identified and reliably reconstructed, solving the problem of data misjudgment caused by sensor freezing and ensuring the continuity and interpretability of industrial status data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANXING TONGHENG TECH GRP CO LTD
- Filing Date
- 2026-03-20
- Publication Date
- 2026-06-16
Smart Images

Figure CN122227247A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, specifically to a reliable reconstruction method for IoT sensors in complex industrial environments. Background Technology
[0002] In complex industrial production systems, the operational status of numerous critical pieces of equipment relies on continuous monitoring using IoT sensors, such as temperature sensors, pressure sensors, flow sensors, and vibration sensors. These IoT sensors are typically deployed in complex industrial environments characterized by high temperatures, high pressures, strong electromagnetic interference, or intense mechanical vibration. They are used to collect real-time data on equipment operation and continuously output observational data streams to monitoring or control systems via industrial networks, thereby supporting functions such as equipment operation monitoring, fault early warning, and process adjustment. To ensure the hardware security of the sensors themselves, some high-reliability industrial sensors typically incorporate internal protection mechanisms. When abnormal currents, abnormal temperatures, unstable signal links, or potential damage risks to internal circuitry are detected, the sensor automatically enters a protection mode to prevent further hardware damage.
[0003] In protection mode, some industrial sensors do not immediately stop the communication link or shut down data output. Instead, they maintain the output of the most recent valid observation value, allowing external systems to still receive a seemingly continuous stream of observation data. However, the sensor's actual observation capability is lost at this stage; the output data no longer reflects the actual state changes of the measured object but remains as a frozen historical observation value. Because this frozen value is often still within a reasonable range and may closely resemble the actual operating condition trend in the short term, traditional data quality detection mechanisms often struggle to identify this type of frozen state in a timely manner. Consequently, they may easily misjudge a long-term constant frozen value as a stable operating state of the equipment. When the system fails to identify that the sensor is in a frozen state in protection mode, operational monitoring, status assessment, and process control analysis based on this frozen data will be biased, and may even mask the true changes in the equipment's state, affecting the accuracy of fault diagnosis and operational safety.
[0004] Therefore, in complex industrial environments, how to identify the observation freeze phenomenon caused by IoT sensors entering protection mode and reliably reconstruct the true state within the frozen range has become an urgent technical problem to be solved. Summary of the Invention
[0005] This application provides a reliable reconstruction method for IoT sensors in complex industrial environments, which facilitates the identification of observation freeze caused by IoT sensors entering protection mode and enables reliable reconstruction of the true state within the frozen interval.
[0006] The first aspect of this application provides a reliable reconstruction method for IoT sensors in complex industrial environments. The method includes: acquiring observation data streams, control execution streams, execution feedback streams, equipment topology state streams, energy consumption record streams, process result streams, and neighborhood disturbance streams corresponding to a target IoT sensor in a target industrial environment, and establishing an observation consequence profile around the target IoT sensor; performing observation consistency detection based on the observation data streams, and when the target IoT sensor is detected to have entered a protection mode freeze state, generating a freeze interval identifier and determining a freeze interval based on the freeze interval identifier; generating a state worldline set based on the freeze interval identifier and the freeze interval, the state worldline set consisting of multiple candidate state worldlines; performing consequence projection processing for each candidate state worldline, based on the observation data streams... The process generates an external trace oracle book corresponding to the candidate state worldline by profiling the consequences. This external trace oracle book is then compared and verified based on the control execution flow, execution feedback flow, energy consumption record flow, process result flow, and neighborhood disturbance flow to obtain the worldline residual set. The worldline residual set is then subjected to restricted area pruning based on control capability boundary indicators, device topology propagation capability indicators, actuator response capability indicators, and process stage limitation indicators. Consensus skeleton extraction is then performed on the pruned worldline residual set to obtain the trusted reconstruction skeleton corresponding to the frozen interval. After the target IoT sensor exits the protected mode frozen state and resumes observation, the recovered observation data flow is acquired. Closed-loop verification is then performed on the trusted reconstruction skeleton based on the recovered observation data flow to generate the corresponding trusted reconstruction result.
[0007] A second aspect of this application provides a trusted reconstruction device for IoT sensors in complex industrial environments. The device includes an acquisition module and a processing module. The acquisition module is used to acquire observation data streams, control execution streams, execution feedback streams, equipment topology state streams, energy consumption record streams, process result streams, and neighborhood disturbance streams corresponding to a target IoT sensor in a target industrial environment, and to establish an observation consequence profile around the target IoT sensor. The processing module is used to perform observation consistency detection based on the observation data streams. When the target IoT sensor is detected to have entered a protection mode freeze state, a freeze interval identifier is generated, and a freeze interval is determined based on the freeze interval identifier. The processing module is also used to generate a state worldline set based on the freeze interval identifier and the freeze interval, the state worldline set consisting of multiple candidate state worldlines. The processing module is further used to process each candidate state worldline... The process module performs a worldline execution consequence projection process, generating an external trace oracle book corresponding to the candidate state worldline based on the observed consequence profile. It then compares and verifies the external trace oracle book based on the control execution flow, execution feedback flow, energy consumption record flow, process result flow, and neighborhood disturbance flow to obtain the worldline residual set. The processing module further performs restricted area pruning on the worldline residual set based on control capability boundary indicators, device topology propagation capability indicators, actuator response capability indicators, and process stage limitation indicators. It then performs consensus skeleton extraction on the pruned worldline residual set to obtain a trusted reconstruction skeleton corresponding to the frozen interval. Finally, after the target IoT sensor exits the protected mode frozen state and resumes observation, the processing module acquires the recovered observation data stream and performs closed-loop verification on the trusted reconstruction skeleton based on the recovered observation data stream to generate the corresponding trusted reconstruction result.
[0008] A third aspect of this application provides an electronic device including a processor, a memory, a user interface, and a network interface. The memory is used to store instructions, and both the user interface and the network interface are used to communicate with other devices. The processor is used to execute the instructions stored in the memory to cause the electronic device to perform the method described above.
[0009] A fourth aspect of this application provides a non-transitory computer-readable storage medium storing instructions that, when executed, perform the method described above.
[0010] In summary, one or more technical solutions provided in this application have at least the following technical effects or advantages: By leveraging observational data streams and various types of industrial operational data to construct an observational consequence profile, the accuracy of identifying sensor frozen states is improved. Subsequently, multiple candidate state worldlines are constructed within the frozen interval, and verified through comparison with external trace oracles and multi-link field data, gradually filtering out a set of candidate states consistent with industrial field evidence. Further, by combining control capabilities, equipment topology propagation capabilities, actuator response capabilities, and process stage constraints, forbidden zones are pruned from candidate states, and a consensus skeleton is extracted to form a credible reconstruction skeleton. Finally, closed-loop verification of the reconstructed skeleton is performed by restoring the observational data stream to generate the final credible reconstruction result, thus maintaining the continuity, authenticity, and interpretability of industrial state data during sensor freezing. Therefore, it facilitates the identification of observational freezing phenomena caused by IoT sensors entering protection mode and enables credible reconstruction of the true state within the frozen interval. Attached Figure Description
[0011] Figure 1 A flowchart illustrating a trusted reconfiguration method for IoT sensors in complex industrial environments, provided as an embodiment of this application; Figure 2 A schematic diagram of a module for a trusted reconfiguration device for IoT sensors in complex industrial environments, provided as an embodiment of this application; Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0012] Explanation of reference numerals in the attached figures: 21. Acquisition module; 22. Processing module; 31. Processor; 32. Communication bus; 33. User interface; 34. Network interface; 35. Memory. Detailed Implementation
[0013] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0014] In the description of the embodiments of this application, the words "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design that is described as "for example" or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "for example" or "for instance" is intended to present the relevant concepts in a specific manner.
[0015] In the description of the embodiments of this application, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. In addition, the terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0016] This application provides a reliable reconstruction method for IoT sensors in complex industrial environments, referring to... Figure 1 , Figure 1 This is a flowchart illustrating a trusted reconfiguration method for IoT sensors in complex industrial environments, provided as an embodiment of this application. The method is applied to a server and includes steps S110 to S160, as follows:
[0017] S110. Acquire the observation data stream, control execution stream, execution feedback stream, equipment topology status stream, energy consumption record stream, process result stream, and neighborhood disturbance stream corresponding to the target IoT sensor in the target industrial site, and establish an observation consequence profile around the target IoT sensor.
[0018] Specifically, a server refers to a core computing node deployed in an industrial information system, responsible for tasks such as data aggregation, data processing, model calculation, and result output. Servers typically communicate with field devices, edge controllers, data acquisition terminals, and upper-level monitoring systems via industrial networks, and can continuously receive data streams from multiple IoT sensors and control systems. When a server acquires the observation data stream, control execution stream, execution feedback stream, equipment topology status stream, energy consumption record stream, process result stream, and neighborhood disturbance stream corresponding to the target IoT sensor in the target industrial site, and establishes an observation consequence profile around the target IoT sensor, it first needs to determine the sensor association domain corresponding to the target IoT sensor. The target IoT sensor refers to the core sensor that currently requires freeze identification and reliable reconstruction; the observation object refers to the state of the industrial object actually measured by the target IoT sensor, such as equipment housing temperature, pipeline pressure, medium flow rate, base vibration intensity, or internal cavity concentration; the sensor association domain refers to the association range formed by extending outward around the observation object. This range is not a simple spatial proximity range, but a multi-relationship constraint area jointly defined by the influence link, response link, and propagation link in the industrial process. In practice, the following steps are taken: first, the equipment ledger, process flow diagram, control loop configuration table, actuator mapping table, topology connectivity table, and measurement point deployment table are read. Then, taking the object observed by the target IoT sensor as the center, the equipment units, execution units, measurement point units, and process units with which there are control influence relationships, execution response relationships, topology propagation relationships, energy consumption coupling relationships, process result mapping relationships, and neighborhood disturbance propagation relationships are screened to form a sensor association domain. Control influence relationships refer to the relationships in which control commands can change the state of the observed object; execution response relationships refer to the relationships in which actuator actions can realize control effects and further propagate to the observed object; topology propagation relationships refer to the relationships in which state changes can propagate along equipment structures, medium paths, or connection topologies; energy consumption coupling relationships refer to the relationships in which changes in the state of the observed object and changes in resource consumption are accompanied by each other; process result mapping relationships refer to the relationships in which changes in the state of the observed object can leave consequences in intermediate product indicators, stage quality indicators, or final process results; and neighborhood disturbance propagation relationships refer to the relationships in which changes in the observed object can propagate to adjacent measurement points or adjacent equipment and form local disturbance responses. To make the sensor association domain computable, a relationship strength score can be established for each candidate unit, and only units with scores exceeding a threshold can be retained. The relationship strength score can be expressed as:
[0019] in, Indicates the first The overall correlation strength of each candidate unit relative to the target IoT sensor; It indicates the degree of control influence, and is determined based on whether the control command directly acts on the unit and the length of the adjustment path of the unit to the observed object. The value can be between zero and one. This indicates the degree of response, determined based on the significance of the actuator's action on the unit's state, and can take a value between zero and one. This indicates the degree of topology propagation, which is determined based on the connectivity level between the unit and the target IoT sensor, the accessibility of the medium, and whether the propagation path is available. The value can be between zero and one. This indicates the degree of energy consumption coupling, which is determined based on the correlation stability between the resource consumption of the unit and the state of the observed object, and can take a value between zero and one. This indicates the degree of mapping of the process results, and is determined based on the significance of the contribution of the unit's state change to the process results. The value can be between zero and one. This indicates the degree of disturbance propagation in the neighborhood. It is determined based on the propagability of local disturbances between the unit and the target IoT sensor and the historical response strength. The value can be between zero and one. , , , , as well as These represent the weights of the corresponding relationship terms, preset based on on-site process characteristics or adaptively calibrated based on historical data, and the sum of each weight can be set to one. This relationship strength scoring ensures that the sensor association domain is not arbitrarily expanded, but rather constrained around real industrial coupling relationships, thus providing clear boundaries for subsequent data binding.
[0020] After determining the sensor association domain, it is necessary to bind the observation data stream, control execution stream, execution feedback stream, equipment topology status stream, energy consumption record stream, process result stream, and neighborhood disturbance stream within the sensor association domain, and perform unified timing correction processing to form a unified event time reference. The observation data stream refers to the sequence of measurement values, timestamps, and status markers continuously reported by the target IoT sensor itself; the control execution stream refers to the sequence of control commands issued by the controller, host computer, or edge control node to the actuator, regulator, or device; the execution feedback stream refers to the sequence of positions, opening states, speed states, hysteresis states, or abnormal states returned by the actuator or controlled component; the device topology state stream refers to the time-varying topology sequence describing the device connectivity, branch start / stop relationships, bypass opening / closing relationships, media flow direction relationships, and structural connection states; the energy consumption record stream refers to the consumption record sequence of electrical energy, steam, compressed air, gas, or other resources; the process result stream refers to the sequence of intermediate product test values, stage process achievement values, finished product quality values, or process completion results; and the neighborhood disturbance stream refers to the sequence of local disturbance responses reflected by adjacent measuring points and adjacent devices. In practice, a unit-to-stream mapping table is first established for each type of data stream based on the sensor association domain. Then, data records for the corresponding time period are extracted from the historical database, real-time message bus, and edge buffer. Subsequently, unified timing correction is performed on data from different sources, with different sampling frequencies, different timestamp accuracies, and different network delays. The goal of unified timing correction is to align all data streams to the same event time base, rather than simply unifying them to arrival time. This can be achieved by first estimating the time offset, sampling interval, and transmission delay of each data stream, and then dynamically aligning it based on the event trigger point. The timing correction can be expressed as:
[0021] in, Indicates the first The data record is the correction time under a unified event time base; This indicates the original timestamp of the data record; This indicates the local clock offset correction amount, which is determined based on the difference between the device clock and the master clock; This represents the transmission delay correction amount, which is determined based on the network link delay estimation results. This represents the event synchronization correction amount, determined based on the offset relationship between the control action trigger point, execution feedback return point, or topology switch confirmation point and the main event timeline. A unified event time base refers to a global time scale established using an event sequence that can serve as the primary reference in the industrial field, such as the controller's master clock or the station control system's event clock. After timing correction is completed, further resampling or window mapping of data streams at different frequencies is required to ensure comparability among streams within the same time slice. This approach avoids mismatches caused by clock inconsistencies, message delays, or sampling frequency differences when subsequently determining the relationship between state changes and their consequences.
[0022] After establishing a unified event time base, it is necessary to identify the target state change type based on the observed data stream. Then, based on the target state change type, control consequence extraction processing is performed on the control execution stream, execution consequence extraction processing on the execution feedback stream, topology consequence extraction processing on the device topology state stream, energy consumption consequence extraction processing on the energy consumption record stream, result consequence extraction processing on the process result stream, and disturbance consequence extraction processing on the neighborhood disturbance stream, to obtain a multi-link consequence trace set. The target state change type refers to the standardized change pattern exhibited in the time series by the object observed by the target IoT sensor, such as continuously rising state changes, continuously falling state changes, platform-stationary state changes, pulse-impact state changes, slowly decaying state changes, hysteresis-turning state changes, and disturbance superposition state changes. In specific implementation, the observed data stream can first be segmented into sliding windows, and the change direction, change amplitude, change rate, local fluctuation density, and turning point features can be extracted within each time window. Then, each window is mapped to a preset target state change type vocabulary. After identifying the target state change type, the process then traces and expands to other data streams for each type, extracting the corresponding consequence traces. Control consequence extraction focuses on identifying control command characteristics that occurred before or accompanied the state change, such as setpoint increases, valve opening increases, speed increases, or power command changes. Execution consequence extraction focuses on identifying execution fulfillment phenomena such as actuator positioning, actuator hysteresis, actuator overshoot, and actuator swingback. Topology consequence extraction focuses on identifying changes in topology propagation conditions such as branch switching, bypass closure, equipment commissioning / decommissioning, and flow direction rewriting. Energy consumption consequence extraction focuses on identifying resource consumption increases, resource consumption maintenance, resource consumption decreases, and consumption fluctuation structures. Result consequence extraction focuses on identifying process stage index deviations, quality judgment fluctuations, and intermediate result drift. Disturbance consequence extraction focuses on identifying the propagation response of thermal disturbances, pressure disturbances, vibration disturbances, and flow disturbances on adjacent measuring points or adjacent equipment. To quantify the significance of a target state change type's consequences on a specific data stream, a consequence significance function can be constructed, as follows:
[0023] in, Indicates the first The type of target state change is in the first The significance of consequences on data streams; This indicates the number of valid sampling points for the data stream within the current analysis window; Indicates the first The degree of response matching between the data stream and the target state change type at each sampling location is determined based on the temporal relationship, consistency of change direction, and similarity of change structure, and the value can be between zero and one. Indicates the first The intensity weight of the data stream response at each sampling location is calculated based on the amplitude, persistence, or significance of the consequence trace at that location, and the value can be between zero and one.
[0024] After obtaining the set of multi-link consequence traces, consequence merging processing needs to be performed on the set to unify the multi-link consequence traces from control execution flow, execution feedback flow, device topology state flow, energy consumption record flow, process result flow, and neighborhood disturbance flow according to the target state change type, thus forming an observation consequence profile. An observation consequence profile refers to a mapping structure established around the target IoT sensor between state changes and external consequences. It is not a simple data statistics table, nor a regular feature vector, but a structured profile describing what consequence traces will be left in multiple industrial links once a certain type of state change occurs in the object observed by the target IoT sensor, the temporal order in which these traces appear, and the co-occurrence patterns and constraints among the traces. In specific implementation, the set of multi-link consequence traces can first be classified and merged according to the target state change type, and then within each category, sorted according to trace source, trace appearance order, trace stability, and trace significance, forming a mapping from state change type to multi-link consequence chain. To ensure the projectability of the observed consequences profile, it is necessary to record at least the leading control trace, execution realization trace, topology propagation trace, energy consumption-related trace, result manifestation trace, and disturbance diffusion trace for each type of target state change. If it is necessary to further quantify the stability of the observed consequences profile corresponding to a certain type of target state change, a consequences merging confidence expression can be constructed:
[0025] in, Indicates the first The overall merging confidence level of the observation consequence profile corresponding to the type of target state change; Indicates the number of data stream types participating in the merging; Indicates the first The contribution weight of a data stream in the observation consequence profile is determined based on the reliability, on-site availability, and stability of that data stream, and the value can be between zero and one. The aforementioned first The type of target state change is in the first The significance of consequences on the data stream. A higher overall merging confidence level indicates a more stable, complete, and suitable representation of the consequences of the target state change type in multi-link data for subsequent consequence projection onto candidate state worldlines. After consequence merging, corresponding observation consequence profile entries can be generated for each type of target state change, and these entries can be written to the profile library. Thus, during subsequent consequence projection processing of candidate state worldlines, the system can directly read from the observation consequence profiles the expected consequence structure that a certain state change type should exhibit in the control execution flow, execution feedback flow, energy consumption record flow, process result flow, and neighborhood disturbance flow. This allows worldline verification to no longer rely on empirical judgment but instead has a unified, repeatable, and verifiable mapping basis.
[0026] S120. Perform observation consistency detection based on the observation data stream. When the target IoT sensor is detected to have entered the protection mode freeze state, generate a freeze interval identifier and determine the freeze interval based on the freeze interval identifier.
[0027] Specifically, the first step is to establish an observation behavior baseline around the target IoT sensor. The target IoT sensor refers to the core sensor that needs to be identified in the protected mode freeze state and reliably reconstructed. The observation data stream refers to the continuous data sequence composed of observation values, timestamps, and auxiliary state information output by the target IoT sensor in chronological order. The observation behavior baseline is a behavioral reference system built based on long-term operating data of the target IoT sensor under normal observation conditions, used to characterize the update behavior, fluctuation behavior, disturbance following behavior, and sampling rhythm behavior that the sensor should have under normal operating conditions. In practice, the server extracts normal operating segments of the target IoT sensor from the historical database under conditions of no protected mode, no disconnection anomalies, and no long-term cache replay. These segments are then layered and filtered according to the current process stage, equipment load range, and neighborhood disturbance level. Update activity, fine-grained natural fluctuations, external event following ability, and sampling rhythm stability are extracted from each layer of normal operating segments to form a layered observation behavior baseline. To enhance the discriminative power of the observation behavior baseline, a behavior baseline intensity field integrating multi-scale changes, local texture, and event coupling can be constructed.
[0028] in, This indicates that the operating condition label is The baseline intensity field of the observation behavior formed under the conditions; , , as well as These represent the weights of update behavior, fluctuation behavior, disturbance following behavior, and sampling rhythm behavior in the overall baseline, respectively. The weights are set according to the sensor type and process sensitivity, and the four can be normalized. This indicates the number of time scale layers involved in the modeling, used to reflect behavioral characteristics at different time scales; and They represent the first Scale weights for update behavior and fluctuation behavior at each time scale; Indicates the first Number of sampling points within a time scale; Indicates the first The first time scale Observations at each sampling point; Indicates the first Average observations over several time scales; Indicates the first The norm order of update behavior at each time scale is used to modulate sensitivity to sudden and gradual changes; Indicates the first The norm order of fluctuation behavior at each time scale is used to adjust the degree of characterization of fine-grained fluctuations and strong fluctuations. This indicates the number of external events, including control actions, changes in execution feedback, and arrival events of neighborhood disturbances. Indicates the first The event weight of each external event is determined based on the importance of the event and the coupling depth with the target IoT sensor; Indicates the first The actual delay between an external event triggering the observed response; Indicates the first The baseline response delay of an external event under normal operating conditions; Indicates the first The allowable response delay fluctuation range corresponding to each external event; This indicates the magnitude of the target IoT sensor's response within the event window; Indicates the first The magnitude of the driving force of an external event on the source link; Indicates the number of timestamps within the sampling rhythm calculation window; Indicates the time interval between two adjacent samples; This represents the average value of the sampling interval; This represents a stable term used to prevent the denominator from being zero.
[0029] The server adaptively determines the window length and window step size based on the target IoT sensor's sampling period, process change time constant, control action trigger density, and preset minimum freeze recognition time. After partitioning, four types of consistency checks need to be performed on each observation segment to be inspected. Update consistency check is used to determine whether the observation value remains effectively updated under continuous time progression; fluctuation consistency check is used to determine whether the observation segment still retains fine-grained natural fluctuations matching normal operating conditions; disturbance following consistency check is used to determine whether the target IoT sensor still gives a corresponding response when there are external events in the control execution flow, execution feedback flow, or neighborhood disturbance flow; sampling rhythm consistency check is used to determine whether the sampling rhythm and time progression remain normal even if the numerical change weakens. To enhance the detection discrimination power, a segment consistency discrimination function with coupling penalty term and temporal structure term can be constructed:
[0030] in, Indicates the first The overall consistency discriminant value of each observation segment to be inspected; , , , as well as These represent the weights of the update behavior, fluctuation behavior, perturbation following behavior, sampling rhythm behavior, and coupling penalty term, respectively. Indicates the first The number of sampling points for each observation segment to be inspected; Indicates the first The first of the observed segments to be inspected One observation value; This indicates the norm order of the update behavior calculation, which is used to enhance the ability to distinguish between small and large updates; Indicates the relationship with the first The length of a normal reference segment that matches the operating conditions of the observation segment to be inspected; Indicates the first in the normal reference segment One observation value; Indicates the first The local median of each observation segment to be examined is used to characterize the center of natural fluctuations after removing the trend term. This represents the local median value corresponding to the normal reference segment; The norm order is used to represent the calculation of fluctuation behavior. Indicates the first The number of external events covered by each observation segment to be inspected; Indicates the first The first of the observed segments to be inspected The coupling weight of an external event is determined based on the correlation strength between the event and the target IoT sensor; This indicates the actual delay between the occurrence of the event and the observed response; This represents the baseline delay for the corresponding event in the normal reference segment; Indicates the allowable delay deviation; This indicates the magnitude of the target IoT sensor's response within the event window; Indicates the driving amplitude on the event source link; Indicates the first The time interval between adjacent sampling points in a segment to be inspected; This indicates the average sampling interval within the observed segment to be inspected; This represents the coupling penalty term, used to measure the degree of a combined anomaly where observations are locked, external events exist but there is no response, and local fluctuations return to zero simultaneously.
[0031] After identifying response disconnect segments, a freeze determination evidence set needs to be generated based on these segments. Freeze status determination processing is then performed according to this evidence set to determine if the target IoT sensor has entered the protection mode freeze state and to form freeze candidate segments. The freeze determination evidence set is a composite set of evidence consisting of update inactivation evidence, fluctuation missing evidence, disturbance interruption evidence, and rhythm maintenance evidence. Freeze status determination processing involves aggregating and determining this composite evidence set to identify whether the target IoT sensor has transitioned from normal observation to the protection mode freeze state. Freeze candidate segments are continuous response disconnect segments that meet the protection mode freeze characteristics. In practice, the server extracts four types of evidence strength from each response disconnect segment and assembles them into a freeze determination evidence set based on temporal continuity and evidence synergy. Evidence of update inactivation is used to characterize that observations are almost no longer updated under sampling advance conditions; evidence of missing fluctuations is used to characterize that fine-grained natural fluctuations that should exist under normal operating conditions are abnormally smoothed out; evidence of disturbance interruption is used to characterize the presence of external events but the absence of observed responses; evidence of rhythm maintenance is used to characterize that the sampling link, timestamp advancement, and message transmission still exist, thus distinguishing this phenomenon from offline or sampling stoppage states. To enhance the composite judgment capability, a freeze judgment strength function with evidence interaction enhancement terms can be constructed:
[0032] in, Indicates the first The freeze determination strength corresponding to the response detachment fragment; This indicates the strength of evidence of update inactivation, calculated based on the degree of decay of the update behavior relative to the baseline. A larger value indicates a more obvious update inactivation. This indicates the strength of evidence for missing fluctuations, calculated based on the degree of absence of fluctuation behavior relative to the baseline. A larger value indicates a more obvious absence of natural fluctuations. This indicates the strength of evidence of a disturbance interruption, calculated based on the degree to which an external event exists but there is no observed response; the larger the value, the more obvious the disturbance interruption. This indicates the strength of evidence that the rhythm is still advancing. It is calculated based on the degree to which the sampled rhythm continues to advance, and the larger the value, the more active the sampling link remains. , , as well as These represent the weights of the four individual types of evidence; , , These represent the weights of the pairwise evidence enhancement terms, used to reflect the amplification effect when update inactivation, fluctuation loss, and disturbance interruption occur simultaneously; This indicates the weight of the triple interaction enhancement item, which is used to reflect the strong judgment effect when the three types of frozen core features are simultaneously true; This indicates the weight of the penalty term when rhythm maintenance is missing.
[0033] After forming candidate frozen segments, it is necessary to perform freeze start point confirmation processing and freeze end point confirmation processing on the candidate frozen segments to determine the freeze start point and freeze end point. The freeze start point refers to the precise starting time when the target IoT sensor enters the protection mode freeze state from the normal observation state; the freeze end point refers to the precise ending time when the target IoT sensor exits the protection mode freeze state and regains its true observation expression capability. The freeze start point confirmation processing and freeze end point confirmation processing are used to locate the positions of behavioral abrupt changes and behavioral recovery near the front and rear boundaries of the candidate frozen segments, respectively. In specific implementation, the server first performs time backtracking on the leading edge of the candidate frozen segment, comparing the update behavior, fluctuation behavior, and disturbance following behavior of the adjacent windows before and after the candidate frozen segment, thereby finding the first moment when the observation behavior breaks, and confirming this moment as the freeze start point; then, it advances backward on the trailing edge of the candidate frozen segment, identifying when continuous updates, fine-grained natural fluctuations, and event response following reappear, and after continuously crossing the preset recovery stabilization time, confirming the last freeze moment before recovery as the freeze end point. To improve the accuracy of freeze boundary confirmation, a bidirectional boundary transfer function can be constructed:
[0034] in, Indicates time Boundary transition strength at the location; Indicates time The smoothed update behavior curve in the vicinity; This represents the fluctuation behavior curve after smoothing. This represents the smoothed perturbation-following behavior curve; , as well as These represent the first-order rates of change of the three types of behavioral curves, used to characterize the rate of abrupt changes in behavior; , as well as These represent the second-order rates of change of the three types of behavioral curves, used to characterize the sharpness of behavioral transitions; to These represent the weights of the corresponding items.
[0035] After the freeze start and freeze end points are confirmed, a freeze interval identifier needs to be generated based on these identifiers, and the freeze interval corresponding to the target IoT sensor needs to be determined accordingly. The freeze interval identifier is a structured identifier that uniquely represents a single protection mode freeze event, including at least the target IoT sensor identifier, freeze start point, freeze end point, freeze duration, and freeze determination evidence set. The freeze interval is a restricted observation time range jointly defined by the freeze start and freeze end points. Within this range, the original observations of the target IoT sensor are no longer considered high-confidence direct observations but are downgraded to freeze placeholder observations. In practice, after obtaining the freeze start and freeze end points, the server calculates the freeze duration and writes it along with the freeze determination evidence set into the freeze interval identifier. Simultaneously, an index record for this freeze event is created in the data warehouse. The freeze duration can be expressed as:
[0036] in, Indicates the duration of the freeze; Indicates the unified event time corresponding to the freeze start point; This indicates the unified event time corresponding to the freeze endpoint. Subsequently, the server divides the observation data stream into three time segments based on the freeze interval identifier: the normal observation interval before freezing, the frozen interval, and the recovery observation interval after freezing. Within the frozen interval, freeze markers, low-confidence markers, and reconstruction markers are added to the original observation values, enabling subsequent generation of the state worldline set and extraction of the confidence reconstruction skeleton to be carried out directly around this frozen interval. Frozen placeholder observations refer to the original frozen values that are still retained for auditing and backtracking but no longer directly involved in high-confidence state judgment.
[0037] S130. Generate a state worldline set based on the frozen interval identifier and the frozen interval. The state worldline set consists of multiple candidate state worldlines.
[0038] Specifically, the implementation process based on the frozen interval identifier and the generation of the state worldline set for the frozen interval first requires reading the frozen interval identifier and establishing a frozen constraint framework. The frozen interval identifier is a structured identifier that uniquely characterizes a single protection mode freeze event, typically including at least the target IoT sensor identifier, freeze start point, freeze end point, freeze duration, and a set of freeze determination evidence. The frozen constraint framework is a unified constraint container established around this freeze event, used to stipulate that all subsequent state deductions can only be carried out between the freeze start point and freeze end point, and must be subject to consistent constraints of the freeze duration and the evidence of the freeze event. In practice, the server first retrieves the frozen interval identifier from the event index library, parses out the freeze start point, freeze end point, and freeze duration corresponding to the target IoT sensor, and then writes this information into the time boundary field, event boundary field, and trusted boundary field of the frozen constraint framework. The time boundary field is used to limit the time range of the state worldline deduction; the event boundary field is used to bind the process stage, control context, and topology context of this freeze event; and the trusted boundary field is used to indicate that the original observations within the frozen interval have been downgraded to frozen placeholder observations and cannot be directly used as high-confidence state values in subsequent deductions. To improve the formalization of the frozen constraint framework, a frozen constraint strength function can be constructed:
[0039] in, Indicates time The corresponding freeze constraint strength; Indicates that it is defined at the freeze point. With the end of the freeze The interval indicator function between, when The value is one if it falls within the frozen interval, and zero otherwise. Indicates the unified event time corresponding to the freeze start point; Indicates the uniform event time corresponding to the freeze endpoint; This indicates the preset baseline freeze duration, used as a reference for normalizing different freeze interval lengths; This indicates the strength of the evidence group for freezing judgment corresponding to the current freezing interval, which can be obtained based on the combined strength of updated inactivation evidence, fluctuation missing evidence, disturbance interruption evidence, and rhythm maintenance evidence; Indicates the baseline strength of evidence, used to normalize the level of evidence for different freezing events; This represents a stable term to prevent the denominator from being zero. The principle behind this formula is to project the time range of the frozen interval, the duration of the frozen period, and the strength of the evidence for the frozen period into a unified constraint strength. This ensures that the deduction of the world line of subsequent candidate states is constrained by both the length of the frozen period and the credibility of the frozen event, rather than simply by the start and end times.
[0040] After the freezing constraint framework is established, state start point solidification processing needs to be performed around the freezing start point to extract the pre-freeze state transition window before the freezing start point, and to determine the end state morphology of the target IoT sensor's observed object before entering the freezing interval from the pre-freeze state transition window. State start point solidification processing refers to selecting a continuous normal observation interval before the freezing start point and using this interval as the unified starting basis for all subsequent state world lines; the pre-freeze state transition window refers to the time window immediately before the freezing start point that reflects the actual state evolution trend of the target IoT sensor's observed object before entering the freezing interval; the end state morphology refers to the direction of change, rate of change, local fluctuation texture, short-term inertial characteristics, and coupled response structure to control execution flow and execution feedback flow exhibited by the observed object in the last normal observation before freezing occurs. In specific implementation, the server first extracts a normal observation sequence that has not been determined to be frozen and has complete observation behavior before the freezing start point, and then combines the control execution flow, execution feedback flow, device topology state flow, and neighborhood disturbance flow to identify the end state trend in this sequence. To make the end state morphology computable, an end state morphology vector can be constructed:
[0041] in, This represents the end-state morphology vector corresponding to the pre-freeze state transition window. This indicates the number of sampling points within the pre-freezing state window; Indicates the first Observations at each sampling point; Indicates the first The first-order rate of change near each sampling point is used to characterize the direction and speed of change. Indicates the first The second-order rate of change near each sampling point is used to characterize curvature and inflection tendency; Indicates the norm order in the inertial strength calculation; This represents the average observation value within the window before the freeze. Indicates the norm order of the wave texture calculation; Indicates the number of external events covered by the pre-freeze state's acceptance window; Indicates the first The coupling weight of an external event; Indicates the first The actual delay from an external event to the occurrence of a response; This represents the baseline response delay under normal conditions; Indicates the allowable delay deviation; This indicates the magnitude of the target IoT sensor's response within the event window; Indicates the driving amplitude of the external event source link; This represents the stable term. The principle behind this formula is to characterize the final state of the target object before the freeze occurs from four dimensions: trend, inertia, fluctuation, and event response. This ensures that all candidate world lines must originate from this final state form and cannot be generated independently from the actual dynamics before the freeze.
[0042] After the state starting point is solidified, a state endpoint opening process needs to be performed around the frozen endpoint to read the recovered observation data stream after the frozen endpoint and form an endpoint constraint reference. This ensures that the candidate world lines in the mother set of state world lines have the ability to converge to the endpoint constraint reference at the end of the frozen interval. The state endpoint opening process does not directly define the first recovered value in the recovered observation data stream as the unique endpoint state. Instead, it abstracts the directional, amplitude, and structural information reflected in a recovered observation interval after the frozen endpoint into an endpoint constraint reference. The endpoint constraint reference refers to the constraint structure used to constrain the direction, speed, and allowable deviation of the candidate world lines at the end of the frozen interval. In practice, the server extracts a continuous recovered observation sequence after the frozen endpoint and, combined with the recovery of update behavior, fluctuation behavior, and disturbance following behavior in the sequence, identifies the main changing trend, stable interval, and re-response interval of the recovered interval. This information is then written into the endpoint constraint reference. To characterize the convergence of the candidate world lines to the endpoint constraint reference, an endpoint constraint function can be constructed:
[0043] in, Indicates time The degree of deviation from the endpoint constraint reference; Indicates the uniform event time corresponding to the freeze endpoint; This represents the endpoint convergence time constant, used to adjust the characteristic that the constraint becomes stronger as the final stage of freezing approaches the endpoint; This indicates the reference state value for restoring the initial segment of the observation interval; Indicates the candidate state worldline at time [time]. The state value; This represents the reference rate of change for the initial segment of the restored observation interval; Indicates the candidate state worldline at time [time]. The rate of change; Indicates the reference fluctuation intensity for the restored observation interval; Indicates the candidate state worldline at time [time]. The intensity of local fluctuations nearby; , as well as These represent the normalized scales for state values, rates of change, and fluctuation intensity, respectively. , as well as These represent the weights of the three constraints respectively; This represents the stable term. The principle behind this formula is that as time gradually approaches the freeze endpoint, the state value, rate of change, and fluctuation structure must gradually approach the reference characteristics of the recovery observation interval, thereby ensuring that the candidate state worldline has the ability to converge to the true recovery trend at the freeze endpoint, rather than diverging arbitrarily near the freeze endpoint.
[0044] After determining the acceptance and opening conditions at both the freezing start and freezing end points, it is necessary to perform interval layering processing on the frozen interval, dividing it into an initial freezing segment, a middle freezing segment, and a final freezing segment. Constraints for the freezing start point, convergence at the freezing end point, control propagation constraints, execution fulfillment constraints, topology propagation constraints, energy consumption-related constraints, process result delay constraints, and neighborhood disturbance diffusion constraints are collected around these segments to form a constraint source set. Interval layering processing refers to decomposing the entire frozen interval into three segments with different dynamic meanings based on the temporal positional relationship of the frozen interval relative to the freezing start and freezing end points, and the propagation and fulfillment patterns in the industrial process. The initial freezing segment mainly accepts the inertia before freezing and the control effects that have just occurred; the middle freezing segment mainly accepts control fulfillment, topology propagation, and energy consumption-related processes; and the final freezing segment mainly accepts the convergence process towards recovery observation. The constraint source set refers to the structured constraint set extracted from multi-link industrial data that can constrain the worldline shape and boundary of candidate states. In practice, the server first adaptively segments the freezing interval based on the freezing duration and the process dynamic time constant, and then collects various constraints segment by segment. The constraints at the freezing start point originate from the aforementioned end-state morphology vector; the convergence constraints at the freezing end point originate from the end-point constraint reference; control propagation constraints originate from the direction, amplitude, and duration of control actions in the control execution flow within the freezing interval; execution fulfillment constraints originate from the actual fulfillment of actuator positioning, hysteresis, overshoot, and swivel in the execution feedback flow; topology propagation constraints originate from the connectivity, branch switching, and propagation path reachability in the equipment topology state flow; energy consumption-related constraints originate from the associated structure of resource consumption changes and state changes in the energy consumption record flow; process result delay constraints originate from the mapping of the delayed impact of certain freezing-period state changes on subsequent results in the process result flow; and neighborhood disturbance diffusion constraints originate from the propagation intensity and delay of thermal disturbances, vibration disturbances, flow disturbances, and pressure disturbances in the neighborhood disturbance flow. To quantify the constraint complexity of a certain time sub-segment, a constraint source strength function can be constructed:
[0045] in, Indicates the first Constraint source strength for each time sub-segment; This represents the projection of the constraint vector at the start of the freeze or the convergence constraint vector at the end of the freeze in that time sub-segment. This represents the control propulsion constraint vector; This represents the vector for fulfilling execution constraints; Represents the topology propagation constraint vector; Represents the energy consumption-related constraint vector; Represents the process result delay constraint vector; Represents the neighborhood perturbation diffusion constraint vector; These represent the norm form used by the corresponding vectors, which are used to characterize the strength and dispersion of different constraint types; , , , , , as well as These represent the weights of various constraints.
[0046] After forming the constraint source set, candidate state world line derivation processing needs to be performed based on the constraint source set and the preset state evolution vocabulary to generate multiple continuous state evolution trajectories in the initial, middle and final stages of freezing. Continuity correction and distinguishability sorting processing are then performed on the continuous state evolution trajectories to form the state world line mother set. The pre-defined state evolution vocabulary refers to a set of standard state segments used to uniformly describe the structure of state changes, such as continuous advancement segments, slow-release decay segments, local swing segments, platform pause segments, disturbance superposition segments, hysteresis transition segments, and boundary-following segments. Candidate state worldline derivation processing refers to generating multiple possible continuous state evolution trajectories in different segments according to the state segment combination rules allowed by the constraint source set. A continuous state evolution trajectory refers to a state path that is continuously connected from the beginning to the end of the freeze interval. Continuity correction processing refers to correcting the derived continuous state evolution trajectories for temporal continuity, amplitude continuity, and constraint continuity. Distinguishing processing refers to merging, eliminating, or identifying a large number of approximately repetitive continuous state evolution trajectories, so that the final retained candidate state worldlines can cover the true possibilities without affecting the efficiency of subsequent verification due to excessive repetition. The state worldline set is the set of all candidate state worldlines retained after the above processing. In practice, the server first generates several combinations of inheriting state segments based on the initial freezing constraints. Then, it generates several combinations of advancing state segments based on the control propagation constraints, execution fulfillment constraints, topology propagation constraints, and energy consumption-related constraints of the middle freezing segment. Finally, it generates several combinations of converging state segments based on the endpoint convergence constraints and process result delay constraints of the final freezing segment. These three types of combinations are then spliced across segments to form a continuous state evolution trajectory. To provide a comparable comprehensive score for each continuous state evolution trajectory, a state worldline derivation function can be constructed:
[0047] in, Indicates the first A comprehensive derived score for a continuous state evolution trajectory; This indicates the number of time sub-segments into which the frozen interval is divided; Indicates the first The continuous state evolution trajectory in the first The state segment matching score of each time sub-segment is used to measure whether the state segment selected for the trajectory conforms to the preset state evolution vocabulary and segment characteristics. The continuity score measures the temporal continuity, amplitude continuity, and slope continuity of the trajectory between adjacent time sub-segments. The physical constraint score is used to measure whether the trajectory satisfies control propulsion constraints, execution fulfillment constraints, topology propagation constraints, and energy consumption-related constraints. The event compatibility score measures whether the trajectory is compatible with process result delay constraints and neighborhood disturbance diffusion constraints. This represents a redundancy penalty term, used to measure the degree of structural repetition between the continuous state evolution trajectory and the generated trajectory; , , , as well as These represent the weights of each score and penalty item, respectively.
[0048] S140. Perform consequence projection processing for each candidate state worldline, generate an external trace oracle book corresponding to the candidate state worldline based on the observed consequence profile, and compare and verify the external trace oracle book based on the control execution flow, execution feedback flow, energy consumption record flow, process result flow, and neighborhood disturbance flow to obtain the worldline residual set.
[0049] Specifically, for each candidate state worldline, consequence projection processing is performed. An external trace oracle corresponding to the candidate state worldline is generated based on the observed consequence profile. The external trace oracle is then compared and verified based on control execution flow, execution feedback flow, energy consumption record flow, process result flow, and neighborhood disturbance flow to obtain the worldline residual set. The implementation process first requires reading each candidate state worldline from the state worldline mother set and establishing a worldline analytical structure. The state worldline mother set refers to the set of multiple candidate state worldlines derived within the frozen interval based on the frozen constraint framework, constraint source set, and preset state evolution vocabulary. A candidate state worldline refers to a continuous state evolution trajectory that the observed object of the target IoT sensor may experience within the frozen interval. The worldline analytical structure is an analytical carrier formed by standardizing and decomposing the internal segment structure of a candidate state worldline within the frozen interval, used to clarify which state segments constitute the candidate state worldline, the start and end positions of each state segment, and the connection relationships between each state segment. In practice, the server reads candidate world lines from the parent set of world lines one by one and performs segmentation along the frozen interval time axis, breaking them down into continuous advancement segments, gradual decay segments, local slump segments, plateau segments, disturbance superposition segments, hysteresis transition segments, and boundary-attached segments. A continuous advancement segment is a segment where the state value evolves continuously in a single direction with a consistent derivative sign; a gradual decay segment is a segment where the state value gradually declines or stabilizes after losing its primary driving factor; a local slump segment is a segment where the state value exhibits a short-term reverse shift within the overall trend; a plateau segment is a segment where the state value remains relatively stable for a certain period; a disturbance superposition segment is a segment where a local high-frequency or pulsed disturbance is superimposed on the basic trend; a hysteresis transition segment is a segment where an external drive has occurred, but the state response only completes the change in direction or speed after a delay; and a boundary-attached segment is a segment where the state value advances along a restricted physical boundary, process boundary, or control boundary. To provide a unified expression for the world line analytical structure, a state segment analytical function can be constructed:
[0050] in, Indicates the first The candidate state world line at time The corresponding state segment category; This represents the set of state segment categories in the predefined state evolution lexicon; Indicates the first The candidate state world line at time The state value; The first-order rate of change of the state value is used to characterize propulsion speed and direction; The second-order rate of change of the state value is used to characterize the intensity of the transition and curvature; This indicates the intensity of local fluctuations near that moment, used to identify the degree of superposition of disturbances; This indicates the degree of proximity to the boundary constraints at that moment, and is used to identify boundary-fitting features; , , as well as These represent the state segment categories respectively. The corresponding velocity reference, acceleration reference, fluctuation reference, and boundary proximity reference; , , as well as These represent the weights of the four types of feature terms; This represents the stable term. The principle behind this formula is to assign each moment to the most matching state segment category by analyzing the velocity, curvature, fluctuation, and boundary proximity characteristics of the candidate state worldline within a local time window. This achieves standardized analysis of the candidate state worldline, ensuring that each subsequent state segment can establish a one-to-one correspondence with the target state change type in the observed consequence profile.
[0051] After the worldline parsing structure is established, state segment mapping processing needs to be performed on the candidate state worldlines based on the worldline parsing structure to establish a correspondence between each state segment in the candidate state worldlines and the target state change type in the observation consequence profile. State segment mapping processing refers to the process of converting each state segment identified in the worldline parsing structure into a target state change type label that can call the observation consequence profile. The observation consequence profile refers to the multi-link consequence trace mapping structure formed by the target IoT sensor's observed object under different target state change types in the control execution flow, execution feedback flow, device topology state flow, energy consumption recording flow, process result flow, and neighborhood disturbance flow. The target state change type refers to the standard state category used within the observation consequence profile to uniformly identify state change patterns, such as continuously rising state changes, continuously falling state changes, platform-stationary state changes, slowly decaying state changes, hysteresis-turning state changes, and disturbance superposition state changes. In specific implementation, the server reads the category, duration, change direction, change intensity, and connection relationship between adjacent state segments in each state segment of the worldline parsing structure, and then matches it with the target state change type template in the observation consequence profile. For example, when the continuous advancement segment has a positive direction and low curvature, it is preferentially mapped to a continuously ascending state change; the gradual decay segment is preferentially mapped to a gradual decay state change; the platform pause segment is preferentially mapped to a platform pause state change; and the hysteresis transition segment is preferentially mapped to a hysteresis transition state change. To improve the accuracy of the mapping determination, a state segment mapping score function can be constructed:
[0052] in, Indicates the first The first candidate state world line The state segment and the first Mapping scores between target state change types; Indicates the first The directional feature vectors of each state segment are used to characterize the advancement direction and local trend structure of the state segment; Indicates the first Standard directional feature vectors for target state change types; Indicates the directional similarity between the two; Indicates the first The duration of each state segment; Indicates the first Standard duration center for target state change types; This indicates the permissible deviation range for the duration of the standard; Indicates the first The curvature or transition intensity characteristics of each state segment; Indicates the first Standard curvature characteristics of target state change types; Indicates the allowable range of curvature deviation; Indicates the first The local fluctuation intensity of each state segment; Indicates the first Standard fluctuation intensity of target state change type; Indicates the allowable range of fluctuation; , , as well as These represent the weights of four types of features: direction, duration, curvature, and fluctuation. Indicates a stable term.
[0053] After the state segment mapping process is completed, consequence projection processing needs to be performed based on the state segment mapping process to project the consequence mapping template corresponding to the target state change type onto the frozen interval time axis, thereby generating an external trace oracle book corresponding to the candidate state world line. Consequence projection processing refers to the process of converting the target state change type of each state segment of a candidate state world line within the frozen interval into a multi-link trace sequence that should appear in the control execution flow, execution feedback flow, energy consumption recording flow, process result flow, and neighborhood disturbance flow. The consequence mapping template refers to a multi-link consequence structure template pre-established in the observed consequence profile for a target state change type. The external trace oracle book refers to a structured oracle set formed by recording the consequence traces that should appear in each external link when a candidate state world line is established, based on the frozen interval time axis, on a time-by-time and link-by-link basis. In specific implementation, the server first reads the target state change type corresponding to each state segment in a candidate state world line, then retrieves the corresponding consequence mapping template from the observed consequence profile, and projects it according to the start and end positions of the state segment on the frozen interval time axis. The external trace oracle obtained after projection includes at least control trace oracles, execution trace oracles, energy consumption trace oracles, outcome trace oracles, and disturbance trace oracles. Control trace oracles refer to the control direction, control duration, and control switching points that should appear in the control execution flow; execution trace oracles refer to actuator positioning, actuator hysteresis, actuator overshoot, or actuator backswing that should appear in the execution feedback flow; energy consumption trace oracles refer to the resource consumption rise, resource consumption maintenance, or resource consumption fall structure that should appear in the energy consumption record flow; outcome trace oracles refer to intermediate result offsets, stage result drifts, or batch result effects that should appear in the process outcome flow; and disturbance trace oracles refer to the propagation direction, propagation delay, and propagation intensity that should appear in the neighborhood disturbance flow. To formally describe the consequence projection intensity corresponding to a candidate state worldline, an external trace oracle generator function can be constructed:
[0054] in, Indicates the first The candidate state world line at the 1st On the external link at time The intensity of the prophetic traces; Indicates the first The number of state segments contained in a candidate world line; Indicates the first The time interval indication function corresponding to each state segment, where Indicates the first The start time of each state segment Indicates the first The end time of each state segment; Indicates the number of target state change types; Indicates the first The first candidate state world line The state segment is mapped to the first... The mapping weights for target state change types can usually be obtained by normalizing the aforementioned state segment mapping scores; Indicates the first The type of target state change in the first A consequence mapping template on an external link, whose independent variable is the time offset relative to the start time of the state segment; These can represent control execution flow, execution feedback flow, energy consumption recording flow, process result flow, and neighborhood disturbance flow, respectively. The principle of this formula is to map the state segment to the target state change type, and then project the multi-link consequence templates corresponding to the target state change type onto the frozen interval time axis segment by segment, thereby generating an external trace oracle that can be directly compared with the actual multi-link data.
[0055] After the external trace oracle is generated, it needs to be aligned with the control execution flow, execution feedback flow, energy consumption record flow, process result flow, and neighborhood disturbance flow. Based on the aligned data, link consistency verification and evidence conflict identification are then performed. Evidence alignment involves mapping each oracle trace in the external trace oracle to the observation segments in the actual multi-link data flow under the same unified event time base, ensuring that oracle traces and actual traces can be directly compared time-by-time. Link consistency verification determines whether corresponding supporting evidence can be found in the actual data for each oracle trace on each link. Evidence conflict identification identifies situations where there are directional, temporal, intensity, or structural conflicts between oracle traces and actual data. In practice, the server first extracts actual evidence windows related to the frozen intervals for the control execution flow, execution feedback flow, energy consumption record flow, process result flow, and neighborhood disturbance flow based on the unified event time base. Then, it aligns the control trace oracle, execution trace oracle, energy consumption trace oracle, result trace oracle, and disturbance trace oracle in the external trace oracle with the actual evidence windows in the corresponding data flows one by one. After alignment, a consistency score and conflict intensity are calculated for each external link. For example, if a control trace oracle indicates that continuous control adjustment should exist within a certain time window, and a corresponding control record does appear in the control execution flow, the control link has a high consistency score; if an execution trace oracle indicates that an executor should be in place, but no execution is fulfilled in the execution feedback flow, the execution link has a high conflict intensity. To comprehensively characterize the degree of evidence agreement for a candidate state worldline across multiple links, a multi-link evidence consistency function can be constructed:
[0056] in, Indicates the first The total consistency score of multi-link evidence for candidate state worldlines; Indicates the number of external links participating in the verification; Indicates the first The weight of each link in the positive consistency term; Indicates the first The weight of each link in the conflict penalty term; Indicates the first The candidate state world line at the 1st The strength of the oracle trace on the link; Indicates the first The link at time The actual strength of evidence is obtained from the actual data stream through feature extraction; and These represent the start and end points of the freeze, respectively. Indicates the first The conflict sensitivity order of each link is used to enhance the ability to distinguish between strong and weak conflicts. This represents the stable term. The principle behind this formula is twofold: firstly, by normalizing the correlation term to measure the consistency between the predicted traces and the actual evidence in terms of temporal and directional structures; and secondly, by using the difference integral term to measure the degree of conflict between the two in terms of amplitude and local morphology. Together, these two factors determine whether the candidate state worldline can be supported by multi-link evidence.
[0057] After completing evidence alignment, link consistency verification, and evidence conflict identification, when there is an evidence conflict between the external trace oracle book corresponding to a candidate state worldline and the control execution flow, execution feedback flow, energy consumption record flow, process result flow, and neighborhood disturbance flow, a worldline deletion process needs to be performed on the candidate state worldline, and the candidate state worldlines that are not deleted are determined as the worldline residue set. Worldline deletion refers to removing candidate state worldlines from the state worldline parent set that, although they have a continuous state evolution structure within the frozen interval, their external trace oracle book is incompatible with the actual multi-link evidence. The worldline residue set refers to the set of candidate state worldlines that remain after evidence conflict screening; these candidate state worldlines all satisfy the condition that they have not been directly negated, at least under the current known multi-link evidence. In specific implementation, the server makes a retention or deletion decision for each candidate state worldline based on the total multi-link evidence consistency score, the intensity of local conflicts in each link, and whether there is a mandatory conflict in the critical links. Critical links typically include execution feedback flows and process result flows, because these two types of links have strong counter-evidence capabilities for real state changes. When a candidate worldline encounters serious evidence conflict on a critical link, or its overall consistency score falls below a preset retention threshold, worldline deletion is performed, removing it from the subsequent candidate set. To clarify the deletion decision rules, a worldline deletion decision function can be constructed:
[0058] in, Indicates the first The deletion decision result for each candidate state world line is: a value of 1 indicates deletion, and a value of 0 indicates retention. Indicates the first The total consistency score of multi-link evidence for candidate state worldlines; This represents the threshold for preserving overall consistency. Represents the set of critical links; Indicates the first The candidate state world line at the 1st The conflict intensity index on a critical link can be obtained by combining directional conflict, temporal conflict and structural conflict; Indicates the first The maximum allowed collision threshold for a critical link; This represents the decision indicator function, which takes a value of one when the condition is met and zero otherwise. The principle behind this formula is to treat both insufficient overall consistency and strong conflicts in critical links as deletion trigger conditions. This ensures that the candidate state worldlines in the worldline residue set are not only generally compatible with multi-link evidence, but also do not exhibit significant contradictions in the most critical counter-evidence links. After this step, all the candidate state worldlines that have not been deleted constitute the worldline residue set, which serves as the input for subsequent forbidden zone pruning and consensus skeleton extraction.
[0059] S150. Based on the control capability boundary index, equipment topology propagation capability index, actuator response capability index, and process stage limitation index, perform restricted area pruning on the worldline residual set, and perform consensus skeleton extraction on the pruned worldline residual set to obtain the trusted reconstruction skeleton corresponding to the frozen interval.
[0060] Specifically, the implementation process of performing forbidden zone pruning on the worldline residual set based on control capability boundary indicators, equipment topology propagation capability indicators, actuator response capability indicators, and process stage limitation indicators, and performing consensus skeleton extraction on the pruned worldline residual set to obtain the trusted reconstruction skeleton corresponding to the frozen interval, firstly establishes a forbidden zone discrimination benchmark and projects the forbidden zone discrimination benchmark onto the frozen interval time axis to form the forbidden zone range of the corresponding time sub-segment. Control capability boundary indicators refer to the quantitative representation of the upper limit, lower limit, duration, and direction switching capabilities of the control execution flow in actually driving the state changes observed by the target IoT sensor within the current frozen interval. Device topology propagation capability indicators refer to the quantitative representation of the farthest propagation depth, shortest propagation delay, achievable propagation direction, and propagation coverage that state changes can reach when propagating along device connection paths, media flow paths, branch paths, and bypass paths. Actuator response capability indicators refer to the quantitative representation of the action amplitude, action speed, arrival delay, maintenance capability, and fallback capability that actuators, valves, drive components, or regulating mechanisms can deliver within the current frozen interval. Process stage limitation indicators refer to the permissible boundaries for the direction, amplitude, rate, and number of state changes of the target object in the current process stage. The forbidden zone discrimination benchmark refers to the dynamic limitation benchmark formed by uniformly converting the above four types of boundary indicators onto the frozen interval time axis. It is used to explain which state changes are absolutely not allowed to occur in different time sub-segments, or which, although theoretically possible, are not feasible under current industrial conditions. In practice, the server first reads the frozen interval context corresponding to the worldline residual set, then extracts boundary information from the control execution flow, device topology state flow, execution feedback flow, and process stage records, and performs normalization and time mapping processing on the four types of boundary indicators. Subsequently, the server jointly maps the four types of boundary indicators to each time sub-segment of the frozen interval time axis, forming the forbidden zone range. A time sub-segment refers to a local time period divided on the frozen interval time axis according to the control action switching time, topology switching time, actuator response transition time, and process stage switching time; the boundary conditions within each time sub-segment are relatively stable. To express the forbidden zone discrimination criteria, a forbidden zone intensity field can be constructed:
[0061] in, Indicates time The corresponding restricted area intensity field value is used to characterize the overall intensity of the industrial boundary restriction at that moment; , , as well as These represent the weights of the control capability boundary term, the device topology propagation capability term, the actuator response capability term, and the process stage limitation term, respectively, and are set according to the sensor type, process sensitivity, and freeze interval scenario. Indicates time The maximum achievable controllable propulsion capability; Indicates time The minimum achievable controllable propulsion capability; Indicates the range of controllable capabilities; It represents the control capability normalization scale, used to unify the capability range of different controlled objects into a comparable range; Indicates time The topology propagation reachability is calculated based on device connectivity, bypass availability, medium flow direction, and propagation path reachability. A higher value indicates more sufficient propagation conditions. Indicates the topological propagation normalization scale; Indicates time The actuator's response capability is calculated based on the actuator's position, response delay, and maintenance capability. This represents the normalized scale of the actuator response; Indicates time The permissible width of a process stage is determined by comprehensively considering the allowed direction, magnitude, and number of changes in the current process stage. The higher the value, the greater the degree of freedom allowed in the process. Indicates the normalized scale of the process stage; This represents a stable term to prevent the denominator from being zero. The construction principle of the restricted area intensity field is to project four types of constraints—control, propagation, execution, and technology—onto the same time axis to form a time-varying constraint field. Any subsequent candidate state world line that touches the inaccessible area defined by this constraint field within a certain time sub-segment can be determined to have entered the restricted area.
[0062] After establishing the exclusion zone discrimination benchmark, exclusion zone comparison processing needs to be performed on each candidate state worldline in the remaining worldline set to determine whether the candidate state worldline's continuous advancement segment, slow decay segment, local swing segment, platform pause segment, disturbance superposition segment, hysteresis transition segment, and boundary-following segment within the frozen interval enters the exclusion zone range. Exclusion zone comparison processing refers to comparing the local state segments of a candidate state worldline with the exclusion zone range of its corresponding time sub-segment hourly and segment by segment to determine whether the candidate state worldline has made a state advancement at any local time position that is not permitted by current industrial conditions. In specific implementation, the server first reads the worldline parsing structure of a candidate state worldline, and then maps each state segment therein to the corresponding time sub-segment on the frozen interval time axis. Subsequently, for the continuous advancement phase, the focus is on checking whether its advancement direction and magnitude exceed the control capability boundary; for the gradual attenuation phase, the focus is on checking whether its attenuation rate and duration violate the process stage limits; for the local swing phase, the focus is on checking whether its swing direction contradicts the control execution flow or execution feedback flow; for the platform dwell phase, the focus is on checking whether its dwell position exceeds the actual maintainable state platform of the actuator; for the disturbance superposition phase, the focus is on checking whether its disturbance intensity exceeds the propagation upper limit allowed by the neighboring disturbance propagation; for the hysteresis transition phase, the focus is on checking whether its transition time is earlier than the arrival time allowed by topology propagation or execution fulfillment; for the boundary-hugging phase, the focus is on checking whether its approach to the boundary is truly supported by the boundary constraints. To quantify the degree of forbidden zone intrusion of a candidate state worldline within the frozen interval, a forbidden zone intrusion function can be constructed:
[0063] in, Indicates the first The degree to which candidate state worldlines intrude into restricted zones throughout the entire frozen interval; Indicates the starting point of the freeze; Indicates the end point of freezing; Indicates the first The candidate state world line at time The state value; Indicates at time The boundary reference value is derived from the exclusion zone discrimination criterion. This boundary reference value can be the center or boundary profile of the allowable state range. Indicates time The corresponding permissible state offset radius is used to describe the range within which the candidate state world line can deviate from the boundary reference value without constituting a restricted area intrusion within the current time sub-segment; This indicates that intrusion is only counted for the portion exceeding the allowable offset radius; This indicates the sensitivity level of a restricted area intrusion, used to amplify the impact of larger intrusions or compress the impact of smaller intrusions. This indicates the aforementioned restricted area intensity field, used to impose higher penalties on time sub-segments with stronger boundary restrictions; This represents the stable term. The calculation principle of the forbidden zone intrusion function is to accumulate the degree to which the candidate state worldline exceeds the allowed boundary within the frozen interval, and then weight it according to the boundary constraint strength at that moment, thereby obtaining a global metric for whether a candidate state worldline enters the forbidden zone. If If it is large enough, it means that the candidate state worldline has entered the forbidden zone within one or more time sub-segments.
[0064] After completing the restricted area comparison process, when a candidate state worldline enters the restricted area at any time sub-segment of the frozen interval, a restricted area deletion process needs to be performed on the candidate state worldline, and an edge contraction process needs to be performed on candidate state worldlines that have not entered the restricted area but are locally close to the restricted area, to form a pruned worldline residual set. Restricted area deletion refers to directly removing candidate state worldlines that have substantially entered the restricted area and are incompatible with the industrial boundary from the worldline residual set; edge contraction refers to locally compressing the state amplitude, delaying the turning point, reducing the disturbance intensity, or shortening the duration of candidate state worldlines that have not truly entered the restricted area but are too close to the restricted area boundary in a local time sub-segment, so that they retreat from the vicinity of the boundary to a safer and more reasonable activity corridor. The pruned worldline residual set refers to the set of candidate state worldlines that remain after the restricted area deletion and edge contraction processes. In specific implementation, the server first determines whether a candidate state worldline should be deleted based on the value of the restricted area intrusion function. Candidate state world lines exceeding the deletion threshold are directly subject to forbidden zone deletion. For candidate world lines that do not exceed the deletion threshold but exhibit significant edge-grabbing in local segments, their edge proximity is calculated, and edge shrinkage processing is performed. To quantify edge proximity, an edge proximity function can be constructed:
[0065] in, Indicates the first The degree of proximity of the edges of the world lines of the candidate states; Indicates the allowable state offset radius; Indicates the candidate state worldline at time [time]. Deviation from the boundary reference value; This indicates a scale close to the spread of punishment, used to control the rate of punishment increase when approaching the boundary of a restricted area; The conditional indicator function is activated only when the candidate state worldline has not yet crossed the boundary but is inside the allowed boundary; This represents a stable term. The calculation principle of the edge proximity function is to identify fragile candidate world lines that are prone to becoming illogical trajectories after slight perturbations by applying an exponential enhancement penalty to segments that, while not crossing the boundary, are consistently close to it. For such candidate world lines, the server can perform edge contraction processing by applying operations such as amplitude reduction, slope smoothing, or shifting the turning point to a later time to their local state segments. After the forbidden zone removal and edge contraction processing, all remaining candidate world lines constitute the pruned world line residue set. The advantage of this processing is that it eliminates obviously illogical candidate world lines while retaining and refining candidate world lines that still have interpretable value but have overly aggressive edges, making the input for subsequent consensus skeleton extraction more stable.
[0066] After forming the trimmed worldline residue set, a consensus skeleton extraction preparation process needs to be performed on it to map the trimmed worldline residue set to a unified frozen interval time axis and a unified state segment index structure. The consensus skeleton extraction preparation process refers to reprojecting each candidate state worldline onto the same coordinate system before actually identifying the common parts of different candidate state worldlines, ensuring fairness and consistency in subsequent comparisons. The unified frozen interval time axis means projecting all trimmed candidate state worldlines onto a common time axis with the same standard time sampling granularity and the same time reference. The unified state segment index structure means establishing unified numbering, unified category labels, and unified segment boundary rules for state segments in all candidate state worldlines, enabling direct one-to-one comparison of state segments at the same time position in different candidate state worldlines. In specific implementation, the server first resamples the trimmed candidate state worldlines to ensure they have the same time discrete points on the same frozen interval time axis. Subsequently, the server re-labels the state segment categories of each candidate worldline at each time sampling point based on a preset state evolution vocabulary, and aggregates sampling points of consecutive same categories into a unified state segment index. Through this process, different candidate worldlines are no longer incomparable due to differences in sampling density, slight offsets in segment boundaries, or differences in local expression. To quantify the structural fidelity of a candidate worldline after remapping to a unified structure, a structural alignment function can be constructed:
[0067] in, Indicates the first The structural alignment of candidate state worldlines after consensus skeleton extraction and preparation; This indicates the number of sampling points on the time axis of the unified freeze interval; Indicates the first The candidate state world line at the 1st The original state segment category of each sampling point; Indicates the state segment category of the sample point after remapping; This represents a category consistency indicator function; and These represent the original state value and the remapped state value, respectively. and These represent the original rate of change and the rate of change after remapping, respectively; and These represent the permissible deviation ranges for the state value and the rate of change, respectively. , as well as These represent the weights for category consistency, state value consistency, and rate of change consistency, respectively. This represents a stable term. The principle of the structure alignment function is to ensure that the core structure of each candidate state worldline is not destroyed after mapping through a unified time axis and a unified state segment index structure, thereby providing reliable input for subsequent direction consensus recognition processing, structure consensus recognition processing, and transition consensus recognition processing.
[0068] After completing the consensus skeleton extraction preparation process, it is necessary to perform direction consensus identification processing, structure consensus identification processing, and transition consensus identification processing on the pruned world line residual set based on a unified frozen interval time axis and a unified state segment index structure. Based on the identification results, skeleton merging processing is then performed to obtain the reliable reconstructed skeleton corresponding to the frozen interval. Directional consensus identification processing refers to identifying the state progression direction commonly supported by most candidate state worldlines within the same time sub-segment, such as ascending, descending, or stationary. Structural consensus identification processing refers to identifying the combination of state segment categories and their distribution patterns commonly supported by most candidate state worldlines, such as belonging to a continuous advancement segment or a platform stationary segment within a certain time period. Transitional consensus identification processing refers to identifying the location and type of transitions commonly supported by most candidate state worldlines, such as transitioning from a continuous advancement segment to a platform stationary segment, or from a gradual decay segment to a local swing segment. Skeleton merging processing refers to combining the above three types of consensus identification results to form a unified skeleton structure spanning the entire frozen interval. Trustworthy reconstruction skeleton refers to the core state evolution structure that is commonly recognized by most candidate state worldlines in the remaining set of the pruned worldlines, while also satisfying industrial constraints and evidence consistency. In specific implementation, the server first statistically analyzes the directional distribution of each candidate state worldline at each unified time sampling point, then statistically analyzes the distribution of each state segment category, and subsequently identifies the locations where the direction and segment type commonly recognized by most candidate state worldlines appear. In the consensus identification process for turning points, the server statistically analyzes the changes in state segment categories between adjacent time sampling points and filters out the turning points with the highest common frequency and the most stable temporal position. To quantify the consensus strength at a given time sampling point, a consensus strength function can be constructed:
[0069] in, Indicates the first The overall consensus strength across all sampling points at a unified time; This represents a set of direction categories, including directions such as ascending, descending, and stationary. Indicates the first Each sampling point supports directional categories The number of candidate world lines; Represents the set of state segment categories; Indicates the first Each sampling point supports state segment categories The number of candidate world lines; Represents a set of transition categories; Indicates the first Each sampling point supports transition categories. The number of candidate world lines; Indicates the first The total number of candidate state world lines that are still included in the statistics at each sampling point; , as well as These represent the weights of the directional consensus term, the structural consensus term, and the turning point consensus term, respectively. The principle of the consensus strength function is to weight and fuse the majority proportions of the three dimensions (direction, structure, and turning point) at the same time point, thereby identifying which time points exhibit stable consensus and which exhibit disagreement. The server is based on... The distribution of the data is analyzed, and a skeleton merging process is performed on continuous high-consensus segments. This process sequentially assembles the main direction, main segment category, and main turning point of these segments to form a credible reconstruction skeleton. The skeleton merging process does not simply average the values of all candidate state worldlines. Instead, it prioritizes consensus strength, turning point stability, and structural continuity, extracting the common backbone of multiple candidate state worldlines and removing marginal segments and occasional turning points supported only by a few candidate state worldlines. The resulting credible reconstruction skeleton retains the main evolutionary trends commonly acknowledged by multiple candidate state worldlines within the frozen interval, while avoiding the inclusion of a few extreme but not completely deleted local forms in the final reconstruction skeleton. This provides a stable foundation for subsequent closed-loop verification and the generation of the final credible reconstruction result.
[0070] S160. After the target IoT sensor exits the protection mode freeze state and resumes observation, acquire the restored observation data stream, and perform closed-loop verification processing on the trusted reconstruction skeleton based on the restored observation data stream to generate the corresponding trusted reconstruction result.
[0071] Specifically, after the target IoT sensor exits the protection mode freeze state and resumes observation, the process of acquiring the recovered observation data stream and performing closed-loop verification processing on the trusted reconstruction skeleton based on the recovered observation data stream to generate the corresponding trusted reconstruction result first involves performing a recovery confirmation process on the recovered observation data stream. The recovered observation data stream refers to the sequence of observation values, the sequence of additional state information, and the sequence of link rhythm information that the target IoT sensor resumes outputting after the freeze endpoint and has a continuous timestamp progression relationship. The recovery confirmation process is the identification process for determining whether the target IoT sensor has truly exited the protection mode freeze state and regained normal observation capabilities. The recovery observation stage refers to the stage in which the target IoT sensor has resumed its update behavior, fluctuation behavior, disturbance following behavior, and sampling rhythm behavior, and this recovery state continues to span a preset recovery stabilization time. Update behavior refers to the ability of observed values to reappear with valid changes over time; fluctuation behavior refers to the ability of the target IoT sensor to exhibit fine-grained natural fluctuations under real-world operating conditions; disturbance following behavior refers to the ability of the target IoT sensor to generate detectable responses to external events in the control execution flow, execution feedback flow, and neighborhood disturbance flow; sampling rhythm behavior refers to the ability of sampling timestamp progression, message arrival rhythm, and sampling interval stability to return to normal. In practice, the server first extracts candidate recovery intervals from the observation records after the frozen endpoint and uses a sliding window to check whether the update behavior, fluctuation behavior, disturbance following behavior, and sampling rhythm behavior within each candidate recovery interval have returned to the baseline requirements for observation behavior. When the update behavior, fluctuation behavior, and disturbance following behavior have all recovered, and this recovery continuously spans a preset recovery stability time, the target IoT sensor is confirmed to have entered the recovery observation phase. To quantify the degree of recovery validity of a candidate recovery interval, a recovery confirmation function can be constructed:
[0072] in, Indicates the first The strength of recovery confirmation for each candidate recovery interval; Indicates the first The update behavior measure in each candidate recovery interval is calculated based on the effective change activity of the re-emergence of adjacent observations; Indicates the first The fluctuation behavior measure in each candidate recovery interval is calculated based on the intensity of local fine-grained natural fluctuations. Indicates the first The disturbance following behavior measure in each candidate recovery interval is calculated based on the response of the target IoT sensor after an external event occurs. Indicates the first The sampling rhythm behavior measure in each candidate recovery interval is calculated based on the continuity of timestamps and the stability of sampling intervals. , , as well as These represent the corresponding baseline values in the normal observation behavior baseline; , , as well as These represent the weights of the four types of behavioral items; This represents the interaction enhancement weights when update behavior, fluctuation behavior, and perturbation-following behavior are simultaneously restored, emphasizing the importance of the three core behaviors being held together when observation capabilities are truly restored. Indicates the first The degree of abnormal residual in each candidate recovery interval is calculated based on whether frozen locked textures still remain, whether the recovery values show pseudo jitter, and whether local duplicate samples still exist significantly. Indicates the normalized scale of abnormal residues; Indicates the weight of the penalty term for abnormal residues; This represents a stable term to prevent the denominator from being zero. The principle behind this formula is to establish the validity of the recovery observation phase on the basis of joint recovery of multiple behaviors and a significant reduction in anomalous residues, thereby avoiding misjudging short-term pseudo-recovery, slow self-calibration recovery, or buffer replay recovery as the true recovery observation phase.
[0073] After confirming the recovery observation phase, it is necessary to extract continuously advancing recovery observation segments from the recovery observation data stream based on the recovery observation phase, and perform timeline unification processing on the recovery observation segments to align the time series of the recovery observation segments with the timeline of the frozen interval and the unified timeline corresponding to the trusted reconstruction skeleton. A recovery observation segment refers to a subsequence of observations selected from the recovery observation phase that is continuously advancing in time, has not experienced refreezing, has not shown obvious abnormal jumps, and can represent the true recovery trend. Timeline unification processing refers to transforming the time base of the recovery observation segments to a unified event time base that is completely consistent with the frozen interval and the trusted reconstruction skeleton, allowing them to be directly compared in the same time coordinate system. In specific implementation, the server first extracts the effective recovery interval from the recovery observation data stream based on the freeze endpoint and the recovery stabilization duration, and then performs link latency correction, cache jitter correction, and time base correction between edge nodes and the server on the timestamps in this interval, thereby obtaining the recovery observation segments under the unified event time. Subsequently, the server maps the recovery observation segments onto the unified timeline extension window after the frozen interval, enabling the segments to form a continuous time relationship with the end of the trusted reconstruction skeleton. To quantify the alignment quality after timeline unification, a time alignment function can be constructed:
[0074] in, This indicates the alignment quality between the restored observation segment and the unified timeline; This indicates the number of valid sampling points in the recovered observation segment; Indicates the first Correction time of each restored observation sampling point under a unified event time reference; Indicates the relationship with the first The time axis position of the reliable reconstructed skeleton corresponding to each recovery observation sampling point; This represents the average sampling interval in the recovered observation segment; This represents the average residual offset of the entire recovered observation segment relative to a uniform time axis; This represents the expected remaining offset, which is usually zero or a small offset preset by the system synchronization mechanism. Indicates the allowable range of time offset fluctuations; This indicates the stability term. The principle behind this formula is to simultaneously evaluate the degree of fit of the recovered observation segment on a unified time axis from both the perspectives of point time deviation and overall offset, thereby ensuring that subsequent skeleton alignment processing is not performed on a misaligned time reference.
[0075] After the timeline is uniformly processed, skeleton alignment processing needs to be performed on the credible reconstruction skeleton based on the timeline uniform processing. This is to project the frozen end convergence skeleton in the credible reconstruction skeleton onto the time window covered by the recovered observation segment and form the skeleton end prediction structure. The credible reconstruction skeleton refers to the core state evolution structure of the frozen interval obtained by processing the pruned worldline residue set through direction consensus recognition, structure consensus recognition, and transition consensus recognition. The frozen end convergence skeleton refers to the skeleton structure located at the end of the frozen interval in the credible reconstruction skeleton, used to describe the trend of the state approaching the recovered observation. Skeleton alignment processing refers to extending the frozen end convergence skeleton and projecting it into the time window of the recovered observation segment, so that it forms a prediction structure that can be directly compared with the recovered observation segment. The skeleton end prediction structure refers to the predicted expression of the state direction, change amplitude, local fluctuations, and convergence rhythm that should continue to appear after the frozen end, under the premise that the credible reconstruction skeleton is valid. In practice, the server first reads the direction, slope, curvature, and fluctuation information of the frozen terminal convergence skeleton near the freezing endpoint. Then, based on the coverage duration of the recovered observation segment, it projects the frozen terminal convergence skeleton into the corresponding time window, forming the skeleton's terminal prediction structure. This structure is not a simple linear extrapolation but maintains the original convergence mode and boundary constraints of the frozen terminal convergence skeleton. To quantify the consistency between the skeleton's terminal prediction structure and the frozen terminal convergence skeleton, a skeleton projection function can be constructed:
[0076] in, Indicates at time Predicted structural state values at the ends of the skeleton; This represents the end state value of the trusted reconstructed skeleton at the frozen endpoint; Indicates the uniform event time corresponding to the freeze endpoint; This represents the rate of change at the end of the credible reconstructed skeleton at the frozen endpoint; This represents the end-effector acceleration or curvature driver of the credible reconstructed skeleton near the freezing endpoint; This represents the time constant of the rate of change decay, used to describe the speed at which the convergence trend gradually slows down; This represents the acceleration decay time constant, used to describe the rate at which the effects of the transition gradually diminish. This indicates the intensity of the terminal fluctuations of the credible reconstructed skeleton at the end of the freeze. This represents the fluctuation decay time constant, used to describe the process of local fluctuations gradually weakening in the early stage of the recovery observation phase; This represents a zero-mean constrained random perturbation function used to preserve the local natural fluctuation texture in the predicted structure at the skeleton ends; and Indicates intermediate integration variables; Indicates a stable term.
[0077] After forming the predicted structure at the end of the skeleton, a skeleton consistency check is required based on the predicted structure and the recovered observation segment to compare the consistency between the direction of change in the initial stage of recovery, the amplitude of change in the initial stage of recovery, and the fluctuation structure in the middle stage of recovery and the credible reconstructed skeleton. The skeleton consistency check is the process of determining whether the actual recovered observation and the predicted structure at the end of the skeleton are compatible in terms of direction, amplitude, and fluctuation. The direction of change in the initial stage of recovery refers to the dominant direction of change at the beginning of the recovered observation segment; the amplitude of change in the initial stage of recovery refers to the magnitude of change in the beginning of the recovered observation segment relative to the state near the frozen endpoint; the fluctuation structure in the middle stage of recovery refers to the intensity, frequency, and local perturbation superposition pattern of the natural fluctuations in the middle of the recovered observation segment. In practice, the server first extracts the direction feature vector, amplitude feature vector, and fluctuation feature vector from the recovered observation segment, then extracts the corresponding feature vectors of the predicted structure at the end of the skeleton within the same time window, and then compares the consistency of the two items one by one. If the direction of change in the initial stage of recovery is the same as the predicted direction at the end of the skeleton, the amplitude of change in the initial stage of recovery falls within the allowed convergence amplitude band of the skeleton, and the fluctuation structure in the middle stage of recovery is compatible with the fluctuation attenuation law in the predicted structure at the end of the skeleton, then it can be considered that there is no structural conflict between the two. To quantify this consistency relationship, a skeleton consistency check function can be constructed:
[0078] in, This represents the skeleton consistency score between the credible reconstructed skeleton and the recovered observation fragment; This represents the feature vector indicating the direction of change in the initial stage. This represents the feature vector indicating the direction of change corresponding to the predicted structure at the end of the skeleton. This represents the dot product of two vectors; and Let these represent the magnitudes of the two vectors respectively; Indicates the magnitude of change in the initial recovery phase; This represents the center value of the change amplitude corresponding to the predicted structure at the end of the skeleton. Indicates the allowable amplitude deviation range of the skeleton; This indicates the recovery of the mid-segment wave structure strength; This indicates the intensity of the wave structure corresponding to the predicted structure at the end of the skeleton. Indicates the allowable fluctuation range of the skeleton; This indicates a structural conflict term, used to characterize whether a sudden reverse turn, anomalous spike, or wave-like fracture occurs in the recovered observation segment that is not allowed by the predicted structure at the end of the skeleton. , , as well as These represent the weights of the direction consistency term, amplitude consistency term, fluctuation consistency term, and conflict penalty term, respectively. This represents the stability term. The principle of this formula is to use directional similarity, amplitude similarity, and wave structure similarity as positive support terms, while using structural conflict as a penalty term, thus forming a comprehensive consistency test result. Only when the three types of positive terms are sufficiently high and the conflict term is sufficiently low can it be considered that there is no structural conflict between the credible reconstructed skeleton and the recovered observation segment.
[0079] After the skeleton consistency check is completed, when the skeleton consistency check determines that there is no structural conflict between the credible reconstructed skeleton and the recovered observation segment, it is necessary to perform reconstruction trajectory expansion processing on the credible reconstructed skeleton to form a reconstruction trajectory covering the frozen interval, and then perform reconstruction result solidification processing on the reconstruction trajectory to generate the credible reconstruction result corresponding to the frozen interval. Reconstruction trajectory expansion processing refers to restoring the credible reconstructed skeleton from a skeletonized structural expression to a continuous sequence of state values covering each time sampling point in the frozen interval; the reconstruction trajectory refers to the continuous state recovery result of the target IoT sensor's observed object within the frozen interval; reconstruction result solidification processing refers to the process of writing the final obtained reconstruction trajectory as the formal credible reconstruction result of the frozen interval into the system data record, and attaching source explanation, credibility explanation, and frozen replacement explanation; the credible reconstruction result refers to the frozen interval state result that, after being confirmed by closed-loop verification, can be used to replace frozen placeholder observations in subsequent analysis, monitoring, and control auxiliary judgment. In specific implementation, the server first performs state value completion on each time sampling point in the frozen interval based on the direction, turning point, and amplitude boundary of each skeleton segment in the credible reconstructed skeleton to form a complete reconstruction trajectory. If some time sampling points are located in the strong consensus segment of the skeleton, the main skeleton value is used first; if some time sampling points are located in the consensus segment of the skeleton, smooth interpolation and boundary constraint interpolation are performed in combination with the local skeleton range. Subsequently, the server writes the entire reconstructed trajectory back to the frozen interval record position in the observation database, retains the original frozen observation values as a bypass audit field, and adds a reconstruction identifier and a closed-loop verification pass identifier to the newly generated trusted reconstruction result. To quantify the segmental trustworthiness of the reconstructed trajectory, a reconstruction trustworthiness function can also be constructed:
[0080] in, Indicates the time interval of the freeze interval The corresponding reconstruction credibility; This indicates that the trusted reconfiguration skeleton is at time [time]. The consensus strength is obtained based on the number and stability of candidate state worldlines that participate in supporting the skeleton position; This represents the normalized scale of consensus strength; This indicates the aforementioned skeleton consistency score; This represents the normalization scale for consistency scores. This indicates that the final reconstructed trajectory is at time [time]. The state value; This indicates that the trusted reconfiguration skeleton is at time [time]. The center value of the skeleton; Indicates the allowable range of state deviations for the skeleton; , as well as These represent the weights of the skeleton consensus term, the closed-loop consistency term, and the trajectory skeleton attachment term, respectively. This represents the stable term. The principle behind this formula is to integrate the degree of consensus within the skeleton, the degree of closed-loop verification of the recovered observations, and the degree of fit between the final reconstructed trajectory and the skeleton's central value, thereby providing a time-by-time reliability characterization for the final reliable reconstruction result. Through this process, not only can a reliable reconstruction result covering the entire frozen interval be obtained, but it can also provide subsequent users with a description of the reliability at each time point.
[0081] This application also provides a trusted reconfiguration device for IoT sensors in complex industrial environments, referring to... Figure 2 , Figure 2 This application provides a schematic diagram of a trusted reconfiguration device for IoT sensors in complex industrial environments. The device is a server, comprising an acquisition module 21 and a processing module 22. The acquisition module 21 acquires the observation data stream, control execution stream, execution feedback stream, equipment topology state stream, energy consumption record stream, process result stream, and neighborhood disturbance stream corresponding to the target IoT sensor in the target industrial environment, and establishes an observation consequence profile around the target IoT sensor. The processing module 22 performs observation consistency detection based on the observation data stream. When the target IoT sensor is detected to have entered a protection mode freeze state, it generates a freeze interval identifier and determines the freeze interval based on the freeze interval identifier. The processing module 22 also generates a state worldline set based on the freeze interval identifier and the freeze interval, the state worldline set consisting of multiple candidate state worldlines. The processing module 22 is used to perform consequence projection processing for each candidate state worldline, generate an external trace oracle book corresponding to the candidate state worldline based on the observed consequence profile, and compare and verify the external trace oracle book based on the control execution flow, execution feedback flow, energy consumption record flow, process result flow, and neighborhood disturbance flow to obtain the worldline residual set; the processing module 22 is also used to perform restricted area pruning processing on the worldline residual set based on the control capability boundary index, device topology propagation capability index, actuator response capability index, and process stage limitation index, and perform consensus skeleton extraction processing on the pruned worldline residual set to obtain the trusted reconstruction skeleton corresponding to the frozen interval; the processing module 22 is also used to obtain the restored observation data flow after the target IoT sensor exits the protection mode frozen state and resumes observation, and perform closed-loop verification processing on the trusted reconstruction skeleton based on the restored observation data flow to generate the corresponding trusted reconstruction result.
[0082] This application also provides an electronic device, with reference to... Figure 3 , Figure 3This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. The electronic device may include: at least one processor 31, at least one network interface 34, a user interface 33, a memory 35, and at least one communication bus 32.
[0083] The communication bus 32 is used to enable communication between these components.
[0084] The user interface 33 may include a display screen and a camera. Optionally, the user interface 33 may also include a standard wired interface and a wireless interface.
[0085] The network interface 34 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0086] The processor 31 may include one or more processing cores. The processor 31 connects to various parts of the server via various interfaces and lines, executing instructions, programs, code sets, or instruction sets stored in the memory 35, and calling data stored in the memory 35 to perform various server functions and process data. Optionally, the processor 31 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 31 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content to be displayed on the screen; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 31 and may be implemented as a separate chip.
[0087] The memory 35 may include random access memory (RAM) or read-only memory. Optionally, the memory 35 may include a non-transitory computer-readable storage medium. The memory 35 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 35 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 35 may also be at least one storage device located remotely from the aforementioned processor 31. Figure 3 As shown, the memory 35, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an application program for a trusted reconfiguration method for IoT sensors in complex industrial environments.
[0088] exist Figure 3 In the electronic device shown, the user interface 33 is mainly used to provide an input interface for the user and obtain the user input data; while the processor 31 can be used to call the application stored in the memory 35, which is a trusted reconfiguration method for IoT sensors in complex industrial environments. When executed by one or more processors, the electronic device executes one or more methods as described in the above embodiments.
[0089] This application also provides a non-transitory computer-readable storage medium storing instructions. When executed by one or more processors, these instructions cause an electronic device to perform one or more of the methods described in the above embodiments.
[0090] The foregoing description is merely an exemplary embodiment of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Those skilled in the art will readily conceive of other embodiments of this disclosure upon considering the specification and the disclosure of practical truth. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described in this disclosure. The specification and embodiments are considered exemplary only, and the scope and spirit of this disclosure are defined by the claims.
Claims
1. A reliable reconfiguration method for IoT sensors in complex industrial environments, characterized in that, The method includes: Acquire the observation data stream, control execution stream, execution feedback stream, equipment topology status stream, energy consumption record stream, process result stream, and neighborhood disturbance stream corresponding to the target IoT sensor in the target industrial site, and establish an observation consequence profile around the target IoT sensor; Based on the observed data stream, an observation consistency check is performed. When the target IoT sensor is detected to have entered the protection mode freeze state, a freeze interval identifier is generated, and the freeze interval is determined based on the freeze interval identifier. Based on the frozen interval identifier and the frozen interval, a state world line set is generated, which is composed of multiple candidate state world lines. For each candidate state worldline, a consequence projection process is performed. An external trace oracle book corresponding to the candidate state worldline is generated based on the observed consequence profile. The external trace oracle book is then compared and verified based on the control execution flow, the execution feedback flow, the energy consumption record flow, the process result flow, and the neighborhood perturbation flow to obtain the worldline residual set. Based on the control capability boundary index, equipment topology propagation capability index, actuator response capability index, and process stage limitation index, the worldline residual set is subjected to restricted area pruning, and the pruned worldline residual set is subjected to consensus skeleton extraction to obtain the trusted reconstruction skeleton corresponding to the frozen interval. After the target IoT sensor exits the protection mode freeze state and resumes observation, the recovered observation data stream is acquired, and closed-loop verification processing is performed on the trusted reconstruction skeleton based on the recovered observation data stream to generate the corresponding trusted reconstruction result.
2. The trusted reconfiguration method for IoT sensors in complex industrial environments according to claim 1, characterized in that, The process involves acquiring the observation data stream, control execution stream, execution feedback stream, equipment topology status stream, energy consumption record stream, process result stream, and neighborhood disturbance stream corresponding to the target IoT sensor in the target industrial site, and establishing an observation consequence profile around the target IoT sensor, specifically including: Determine the sensor association domain corresponding to the target IoT sensor. The sensor association domain is used to define the device unit, execution unit, measurement point unit and process unit that have control influence relationship, execution response relationship, topology propagation relationship, energy consumption coupling relationship, process result mapping relationship and neighborhood disturbance propagation relationship with the object observed by the target IoT sensor. Within the sensor association domain, observation data stream, control execution stream, execution feedback stream, device topology status stream, energy consumption record stream, process result stream, and neighborhood disturbance stream are respectively bound, and unified timing correction processing is performed on the observation data stream, the control execution stream, the execution feedback stream, the device topology status stream, the energy consumption record stream, the process result stream, and the neighborhood disturbance stream to form a unified event time reference; Based on the observed data stream, the target state change type is identified, and control consequence extraction processing is performed on the control execution stream, execution consequence extraction processing on the execution feedback stream, topology consequence extraction processing on the equipment topology state stream, energy consumption consequence extraction processing on the energy consumption record stream, result consequence extraction processing on the process result stream, and disturbance consequence extraction processing on the neighborhood disturbance stream, in order to obtain a multi-link consequence trace set. The multi-link consequence trace set is subjected to consequence merging processing so that the multi-link consequence traces from the control execution flow, the execution feedback flow, the device topology state flow, the energy consumption record flow, the process result flow, and the neighborhood disturbance flow are uniformly organized according to the target state change type to form the observation consequence profile.
3. The trusted reconfiguration method for IoT sensors in complex industrial environments according to claim 1, characterized in that, The observation consistency detection is performed based on the observed data stream. When the target IoT sensor is detected to have entered a protection mode freeze state, a freeze interval identifier is generated, and the freeze interval is determined based on the freeze interval identifier. Specifically, this includes: An observation behavior baseline is established around the target IoT sensor. The observation behavior baseline is used to characterize the update behavior, fluctuation behavior, disturbance following behavior, and sampling rhythm behavior of the target IoT sensor under normal observation conditions. The observed data stream is divided into observation segments to form multiple observation segments to be inspected. Update consistency detection, fluctuation consistency detection, disturbance following consistency detection and sampling rhythm consistency detection are performed on each observation segment to be inspected to identify response detachment segments that simultaneously satisfy update behavior inactivation, fluctuation behavior missing and disturbance following behavior interruption while sampling rhythm behavior continues to advance. Based on the response detachment fragment, a freeze determination evidence group is generated, and a freeze state determination process is performed according to the freeze determination evidence group to determine that the target IoT sensor has entered the protection mode freeze state and form a freeze candidate fragment. The freeze candidate segments are subjected to freeze start point confirmation processing and freeze end point confirmation processing to determine the freeze start point and freeze end point; A freeze interval identifier is generated based on the freeze start point and the freeze end point, and the freeze interval corresponding to the target IoT sensor is determined based on the freeze interval identifier.
4. The trusted reconfiguration method for IoT sensors in complex industrial environments according to claim 1, characterized in that, The process of generating a world line set based on the frozen interval identifier and the frozen interval specifically includes: Read the frozen interval identifier and establish a frozen constraint framework, which is used to limit the freezing start point, freezing end point and freezing duration of the target IoT sensor. A state start point solidification process is performed around the freezing start point to extract the pre-freezing state acceptance window before the freezing start point, and the end state form of the object observed by the target IoT sensor before entering the freezing interval is determined from the pre-freezing state acceptance window. State endpoint opening processing is performed around the frozen endpoint to read the recovered observation data stream after the frozen endpoint and form an endpoint constraint reference, so that the candidate state world lines in the state world line mother set have the ability to converge to the endpoint constraint reference at the end of the frozen interval. The frozen interval is divided into an initial frozen section, a middle frozen section, and a final frozen section. Constraints such as the freezing start point, freezing end point convergence, control propagation, execution fulfillment, topology propagation, energy consumption associated, process result delay, and neighborhood disturbance diffusion are collected around the initial frozen section, the middle frozen section, and the final frozen section to form a constraint source set. Based on the constraint source set and the preset state evolution vocabulary, candidate state world line derivation processing is performed to generate multiple continuous state evolution trajectories in the initial frozen stage, the middle frozen stage, and the final frozen stage. Continuity correction processing and distinguishability sorting processing are then performed on the continuous state evolution trajectories to form the state world line set.
5. The trusted reconfiguration method for IoT sensors in complex industrial environments according to claim 1, characterized in that, The process of performing consequence projection processing on each candidate worldline generates an external trace oracle book corresponding to the candidate worldline based on the observed consequence profile. The external trace oracle book is then compared and verified based on the control execution flow, the execution feedback flow, the energy consumption record flow, the process result flow, and the neighborhood perturbation flow to obtain the worldline remainder set. Specifically, this includes: Read each candidate state worldline in the state worldline set and establish a worldline analysis structure to analyze the continuous advancement segment, slow-release attenuation segment, local swing segment, platform pause segment, disturbance superposition segment, hysteresis transition segment and boundary-following segment of the candidate state worldline in the frozen interval. Based on the worldline analysis structure, state segment mapping processing is performed on the candidate state worldline so that each state segment in the candidate state worldline corresponds to the target state change type in the observation consequence profile. Based on the state segment mapping process, the consequence projection process is performed to project the consequence mapping template corresponding to the target state change type onto the frozen interval time axis to generate an external trace oracle book corresponding to the candidate state world line. The external trace oracle book includes control trace oracle, execution trace oracle, energy consumption trace oracle, result trace oracle and disturbance trace oracle. The external trace oracle book is aligned with the control execution flow, the execution feedback flow, the energy consumption record flow, the process result flow, and the neighborhood disturbance flow. Based on the aligned data, link consistency verification and evidence conflict identification are performed. When there is an evidence conflict between the external trace oracle book corresponding to the candidate state worldline and the control execution flow, the execution feedback flow, the energy consumption record flow, the process result flow, and the neighborhood disturbance flow, the candidate state worldline is deleted, and the candidate state worldlines that are not deleted are determined as the worldline residue set.
6. The trusted reconfiguration method for IoT sensors in complex industrial environments according to claim 1, characterized in that, The process involves performing restricted area pruning on the worldline residual set based on control capability boundary indicators, equipment topology propagation capability indicators, actuator response capability indicators, and process stage constraint indicators. Then, consensus skeleton extraction is performed on the pruned worldline residual set to obtain the trusted reconstruction skeleton corresponding to the frozen interval. Specifically, this includes: Based on the control capability boundary index, the equipment topology propagation capability index, the actuator response capability index, and the process stage limitation index, a restricted area discrimination benchmark is established, and the restricted area discrimination benchmark is projected onto the frozen interval time axis to form the restricted area range of the corresponding time sub-segment; For each candidate state worldline in the remaining set of worldlines, a restricted area comparison process is performed to determine whether the candidate state worldline enters the restricted area range in the following segments within the frozen interval: continuous advancement segment, slow-release attenuation segment, local swing segment, platform pause segment, disturbance superposition segment, hysteresis turning segment, and boundary-following segment. When the candidate world line enters the restricted area at any time sub-segment of the frozen interval, the candidate world line is subject to restricted area deletion processing, and the candidate world line that has not entered the restricted area but is locally close to the restricted area is subject to edge shrinkage processing to form a cropped world line residual set; A consensus skeleton extraction preparation process is performed on the pruned worldline residual set to map the pruned worldline residual set to a unified frozen interval time axis and a unified state segment index structure. Based on the unified frozen interval time axis and the unified state segment index structure, the pruned world line residual set is subjected to direction consensus identification processing, structure consensus identification processing, and transition consensus identification processing. Based on the identification results, skeleton merging processing is performed to obtain the reliable reconstructed skeleton corresponding to the frozen interval.
7. The trusted reconfiguration method for IoT sensors in complex industrial environments according to claim 1, characterized in that, After the target IoT sensor exits the protected mode freeze state and resumes observation, the recovered observation data stream is acquired, and closed-loop verification processing is performed on the trusted reconstruction skeleton based on the recovered observation data stream to generate the corresponding trusted reconstruction result, specifically including: A recovery confirmation process is performed on the recovered observation data stream to detect update behavior, fluctuation behavior, disturbance following behavior, and sampling rhythm behavior in the recovered observation data stream. When the update behavior, fluctuation behavior, and disturbance following behavior are all recovered and a preset recovery stabilization time is exceeded, the target IoT sensor is confirmed to have entered the recovery observation stage. Based on the recovery observation phase, continuously advancing recovery observation segments are extracted from the recovery observation data stream, and time axis unification processing is performed on the recovery observation segments to align the time series of the recovery observation segments with the frozen interval time axis and the unified time axis corresponding to the trusted reconstruction skeleton. Based on the unified processing of the time axis, skeleton alignment processing is performed on the trusted reconstruction skeleton to project the frozen end convergence skeleton in the trusted reconstruction skeleton to the time window covered by the recovered observation segment and form the skeleton end prediction structure. Based on the predicted structure at the end of the skeleton and the recovered observation segment, a skeleton consistency check is performed to compare the consistency relationship between the change direction of the initial recovery segment, the change amplitude of the initial recovery segment, and the fluctuation structure of the middle recovery segment and the reliable reconstructed skeleton. When the skeleton consistency check process determines that there is no structural conflict between the credible reconstruction skeleton and the recovered observation segment, the credible reconstruction skeleton is subjected to reconstruction trajectory unfolding process to form a reconstruction trajectory covering the frozen interval, and the reconstruction trajectory is subjected to reconstruction result solidification process to generate the credible reconstruction result corresponding to the frozen interval.
8. A trusted reconfiguration device for IoT sensors in complex industrial environments, characterized in that, The apparatus is used to execute the trusted reconstruction method for IoT sensors in complex industrial environments as described in any one of claims 1 to 7, the apparatus comprising an acquisition module and a processing module, wherein... The acquisition module is used to acquire the observation data stream, control execution stream, execution feedback stream, equipment topology status stream, energy consumption record stream, process result stream, and neighborhood disturbance stream corresponding to the target IoT sensor in the target industrial site, and to establish an observation consequence profile around the target IoT sensor. The processing module is used to perform observation consistency detection based on the observation data stream. When the target IoT sensor is detected to have entered the protection mode freeze state, a freeze interval identifier is generated and the freeze interval is determined based on the freeze interval identifier. The processing module is also used to generate a state world line set based on the frozen interval identifier and the frozen interval, wherein the state world line set is composed of multiple candidate state world lines. The processing module is further configured to perform consequence projection processing for each candidate state worldline, generate an external trace oracle book corresponding to the candidate state worldline based on the observed consequence profile, and compare and verify the external trace oracle book based on the control execution flow, the execution feedback flow, the energy consumption record flow, the process result flow, and the neighborhood disturbance flow to obtain the worldline residual set. The processing module is also used to perform restricted area pruning on the worldline residual set based on control capability boundary indicators, equipment topology propagation capability indicators, actuator response capability indicators and process stage limitation indicators, and to perform consensus skeleton extraction on the pruned worldline residual set to obtain the trusted reconstruction skeleton corresponding to the frozen interval. The processing module is further configured to acquire the recovery observation data stream after the target IoT sensor exits the protection mode freeze state and resumes observation, and perform closed-loop verification processing on the trusted reconstruction skeleton based on the recovery observation data stream to generate the corresponding trusted reconstruction result.
9. An electronic device, characterized in that, The electronic device includes a processor, a memory, a user interface, and a network interface. The memory is used to store instructions. The user interface and the network interface are both used to communicate with other devices. The processor is used to execute the instructions stored in the memory to cause the electronic device to perform the method as described in any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores instructions that, when executed, perform the method as described in any one of claims 1 to 7.