A low-altitude logistics heterogeneous node air-ground connection collaborative control system and method

By working together with the platform's collaborative control system and multi-source sensor array, the problems of low resource utilization and difficulty in defining responsibilities in ground-to-air docking control schemes in low-altitude logistics have been solved, thereby improving stability and traceability of responsibilities, and ensuring the stability of mission execution and the efficient use of resources.

CN122450175APending Publication Date: 2026-07-24BEIJING HETENGTUZHI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING HETENGTUZHI TECH CO LTD
Filing Date
2026-04-30
Publication Date
2026-07-24

Smart Images

  • Figure CN122450175A_ABST
    Figure CN122450175A_ABST
Patent Text Reader

Abstract

The application discloses a low-altitude logistics heterogeneous node air-ground connection collaborative control system and method, and the method comprises the following steps: step one, candidate connection chain construction and shadow resource pre-synchronization; step two, global control parameter issuing; step three, multi-source observation data processing and dynamic hysteresis parameter generation; step four, double-condition cluster-driven hysteresis activation determination; step five, key node trusted sealing and continuity proof generation; step six, abnormal hierarchical fault tolerance treatment; and step seven, protected resource release and network outage recovery consistency rollback. The application improves resource utilization by constructing a candidate connection chain and pre-synchronizing shadow resources, enhances connection anti-disturbance capability by a dynamic hysteresis activation method, realizes full-process responsibility traceability by a trusted state sealing and continuity proof module, and solves the network outage state convergence problem by relying on a protected release and consistency rollback mechanism. Meanwhile, the application realizes comprehensive improvement of connection stability, resource utilization and responsibility traceability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of low-altitude logistics technology, specifically to a low-altitude logistics heterogeneous node ground-to-air connection collaborative control system and method. Background Technology

[0002] After low-altitude logistics transitions from demonstration operations to large-scale operations, the key challenge truly hindering contract fulfillment stability lies not merely in whether the aircraft can complete a single flight, but in whether stable handover can be achieved within a limited physical window between the warehouse, ground vehicles, low-altitude vehicles, and mechanical loading mechanisms. When the air-to-ground handover process is affected by complex conditions such as gusts of wind, natural battery degradation, queuing of resources within the warehouse, mechanical structural vibrations, sensor signal glitches, asynchronous multi-source sampling, and wireless link fluctuations, the traditional approach of simply equating handover issues with pure software scheduling is no longer sufficient to maintain a balance between resource efficiency, execution stability, and continuity of responsibility.

[0003] In existing technologies, ground-to-air connection control schemes are mainly divided into the following three categories: 1. Fixed reservation schemes that rigidly lock all resources such as cabins, take-off and landing positions, and robotic arms at the time of mission creation. In order to ensure the determinism of execution, this scheme will occupy physical resources exclusively for a long time, resulting in a significant decrease in the station's throughput capacity and a high resource vacancy rate; 2. Purely dynamic rescheduling schemes that recalculate and schedule uniformly by the cloud platform after an anomaly occurs. This scheme relies on a continuous and stable network connection and cloud computing power. Once the link is interrupted or the computing power is delayed, it is easy to miss the millisecond-level connection window, and frequent rescheduling will cause cascading scheduling chaos; 3. Local evidence retention schemes that only log local execution actions at a single node. This scheme cannot form a complete chain of responsibility across stations, vehicles, and stages. Once cargo damage, loss, or handover disputes occur, it is difficult to define responsibility and provide evidence. In addition, the existing technology has the following defects: First, it treats the docking window as only a time window and does not couple it with physical constraints such as vehicle remaining energy, path energy consumption, hovering waiting energy consumption, spatial envelope overlap rate, and sensor stability. Second, it directly drives resource state switching with single sampling results or instantaneous true and false quantities, completely ignoring sensor noise such as weight drift, locking jitter, contact bounce, and attitude fluctuation, which can easily lead to frequent jumps between shadow resource state and formal active state. Third, the abnormal handling mechanism is too rigid and lacks layered fault-tolerant logic from local resampling to global strong freezing. A single sensor glitch may cause the entire docking task to be interrupted. Fourth, there is no protection mechanism for resource release. The preceding resources are released immediately after the handover is completed. If the downstream node is abnormal, it will cause resource conflicts and task failure. Moreover, there is no consistency verification mechanism based on credible evidence after network recovery, which can easily lead to state chaos and cross-epoch residual actions. Summary of the Invention

[0004] The purpose of this invention is to provide a low-altitude logistics heterogeneous node ground-to-air connection collaborative control system and method to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a low-altitude logistics heterogeneous node ground-to-air connection collaborative control system, comprising a platform collaborative control system, an execution terminal, a station-end trusted node, and a multi-source sensor group. The platform collaborative control system establishes data connections with the execution terminal and the station-end trusted node, the execution terminal establishes data connections with the station-end trusted node, and the multi-source sensor group establishes data connections with the execution terminal and the station-end trusted node.

[0006] The platform's collaborative control system includes a candidate connection chain construction module, a shadow resource pre-synchronization module, an activation envelope determination module, a trusted state sealing and continuity proof module, an anomaly classification and fault tolerance module, a rollback and release control module, and an audit object output interface. The candidate connection chain construction module constructs at least one candidate connection chain based on package priority, service level, site capacity, weather constraints, airspace constraints, and heterogeneous execution node availability. The shadow resource pre-synchronization module pre-synchronizes at least one shadow resource in the main chain and rollback chain. Shadow resources include at least one of the following: cabin space, takeoff and landing position, cabin door, buffer position, robotic arm working area, charging / exchange potential, and passageway. The activation envelope determination module generates dynamic hysteresis parameters. The system implements delayed activation determination based on the basic activation condition cluster and the scene additional condition cluster, and outputs shadow resource state switching instructions. The trusted state sealing and continuity proof module is used to generate and issue proxy authorization chains, receive and verify trusted state seals, and concatenate multiple trusted state seals according to the preorder digest to form a continuity proof. The anomaly classification and fault tolerance module is used to classify anomalies into weak anomalies, recoverable anomalies, and safety-critical anomalies, and output corresponding graded handling instructions. The rollback and release control module is used to verify resource release conditions and generate resource release tokens, and perform consistency verification and controlled rollback after network recovery. The audit object output interface is used to output the seal record object, freeze notification object, rollback notification object, and continuity proof to the outside world.

[0007] The execution terminal includes a trusted module and a data acquisition and processing module. The trusted module is used to generate native trusted state seals at key nodes, and the data acquisition and processing module is used to collect and preprocess its own state and physical observation data.

[0008] The trusted node at the station includes an edge observation aggregation module and a proxy signing module. The edge observation aggregation module is used to aggregate physical observation data and perform time alignment, consistency assessment and de-jitter preprocessing. The proxy signing module is used to perform proxy signing based on a valid proxy authorization chain.

[0009] The multi-source sensor group includes a weighing sensor, a locking position sensor, a contact sensor, an IMU attitude sensor, an alignment sensor, a ranging sensor, and a battery management unit. The weighing sensor measures the weight of the package and the load weight of the execution terminal, and detects whether the weight is stable and whether loading is complete. The locking position sensor detects whether the mechanical latches, doors, cargo compartments, and robotic arms are fully locked in place. The contact sensor, using either a contact pressure sensor or a contact switch, detects whether physical contact occurs between the execution terminal and the docking station, cargo, or robotic arm, and monitors the contact pressure and contact status. The IMU attitude sensor collects the pitch, roll, and yaw angles, vibration, and tilt status of the execution terminal in real time, and outputs the attitude stability. The alignment sensor, using either a binocular vision or infrared alignment module, detects the relative position and alignment deviation between the execution terminal and the target docking station, and determines whether the alignment is qualified. The ranging sensor, using either a laser ranging module or an infrared ranging module, measures the straight-line distance between the execution terminal and the docking station, obstacles, and target resources. The battery management unit collects the remaining battery power, voltage, current, health status, and remaining range, and outputs battery status data.

[0010] A collaborative control method for ground-to-air connections of heterogeneous nodes in low-altitude logistics includes the following steps: Step 1, candidate connection chain construction and shadow resource pre-synchronization; Step 2, global control parameter distribution; Step 3, multi-source observation data processing and dynamic hysteresis parameter generation; Step 4, hysteresis activation determination driven by dual-condition clusters; Step 5, trusted signature and continuity proof generation for key nodes; Step 6, anomaly classification and fault tolerance handling; Step 7, release of protected resources and consistency rollback after network outage. In step one above, the candidate connection chain construction module of the platform collaborative control system generates at least one candidate connection chain containing a main chain and a fallback chain based on package priority, service level, site capacity, weather constraints, airspace constraints and heterogeneous execution node availability. The shadow resource pre-synchronization module pre-synchronizes non-exclusive shadow resources for the target connection chain. The shadow resources only retain switching eligibility and necessary context, and do not immediately form a completely exclusive occupancy. In step two above, based on the candidate connection chain and shadow resource reserved context generated in step one, the platform collaborative control system uniformly issues the activation epoch, version number, local feasible domain, rollback order, release protection window parameters and agent signing trigger conditions to the execution terminal and trusted nodes at the station. In step three above, the multi-source sensor group continuously collects at least two types of physical observation data from locking, weight, contact, attitude, alignment, ranging, and battery status. The data acquisition and processing module and the edge observation and aggregation module perform time alignment, observation consistency assessment, and jitter preprocessing on the physical observation data. The envelope determination module is activated to generate dynamic hysteresis parameters based on the real-time disturbance status. In step four above, the activation envelope determination module performs core activation determination based on the standardized physical observation values ​​and real-time dynamic hysteresis parameters output in step three, using the basic activation condition cluster. Under specific scenarios, it superimposes scenario-additional condition cluster verification and outputs shadow resource state switching instructions. The basic activation condition cluster consists of time conditions, energy conditions, spatial conditions, and sensor stability conditions. The scenario-additional condition cluster includes epoch consistency conditions and conflict resolution conditions, which must be triggered for verification when there is version switching, resource contention, network recovery, or cross-node collaboration. In step five above, at key nodes of the entire connection process, the trusted module generates native trusted state seals. If at least one of the following occurs: trusted module failure, insufficient power, or computing power exceeding limits, the proxy seal module performs proxy seals based on the valid proxy authorization chain. The trusted state seal and continuity proof module receives all trusted state seals and concatenates them according to the pre-sequence digest to form a continuity proof. Key nodes include at least one of the following: arrival, loading, locking, handover, detachment, takeoff, landing, anomaly handling, and responsibility switching. The valid proxy authorization chain at least defines the proxy authorization token, proxy scope, proxy expiration time, gateway certificate identifier, challenge random number, and authorization proof digest. When the proxy seal module performs proxy seals, in addition to recording the proxy identifier, it also simultaneously records the original trigger source identifier, trigger time, epoch number, and authorization proof digest. The continuity proof includes the event digest, pre-sequence digest, trigger source identifier, timestamp, version number, proxy identifier, freeze level, reason code, protection identifier, and rollback sequence number, and is organized into an immutable and auditable seal record object. In step six above, the anomaly classification and fault tolerance module identifies the anomaly level and triggers the corresponding handling process to achieve layered fault tolerance. The specific rules for anomaly classification and handling are as follows: weak anomalies trigger resampling and supplementary sampling; recoverable anomalies trigger downgraded operation, proxy sealing, and backtracking switch; safety-critical anomalies trigger strong freezing and complete preservation of on-site data. In step seven above, the rollback and release control module releases resources when all release conditions are met. After network recovery, it performs consistency verification and controlled rollback based on trusted evidence, and finally outputs all auditable data through the audit object output interface. Resource release must simultaneously meet all of the following conditions: responsibility boundary closure, downstream takeover confirmation, release protection window expiration and no new conflicts, and cross-epoch residual actions. The specific process of consistency verification and controlled rollback is as follows: the rollback and release control module performs consistency verification based on the active epoch, version number, most recently valid signature, and local action sequence. The execution results after recovery are divided into a set of retained actions and a set of revoked actions. Only actions in the set of retained actions that have closed responsibility boundaries are confirmed, and the remaining actions are revoked, reassigned, or rearranged.

[0011] In step two, the local feasible domain includes one or more of the following: the set of time windows that allow switching, the set of resources, the reordering budget, the priority boundary, the freezing condition, and the threshold for returning to the platform for adjudication. The execution terminal only performs local adjustments within the local feasible domain, and adjustment requests that exceed the scope must be sent back to the platform collaborative control system for unified adjudication.

[0012] In step three, the activation envelope determination module generates dynamic hysteresis parameters based on the real-time disturbance status. Specifically, the activation envelope determination module dynamically adjusts the entry threshold, exit threshold, entry hold time, and exit hold time based on the disturbance vector composed of wind speed fluctuation amplitude, vibration noise slope, visual frame drop rate, weighing drift slope, and link jitter level. When the disturbance intensifies, it performs one or more of the following: increasing the entry threshold, extending the entry hold time, decreasing the exit threshold, and shortening the exit hold time.

[0013] In step four, the specific rules for the activation envelope determination module to determine delayed activation are as follows: when the basic activation condition cluster continuously meets the entry threshold during the entry holding time and all additional scene conditions are met, the shadow resource is switched to the formal activation state; when the basic activation condition cluster falls into the delayed interval, the current state is maintained and observation continues; when the basic activation condition cluster continuously meets the exit conditions during the exit holding time and the additional scene conditions are not met, one of the actions is executed: exiting the activation state or switching to the fallback chain.

[0014] In step four, the energy condition is based on the energy feasibility margin. To make a conservative judgment, the calculation formula is as follows: in, This represents either the risk quantile or the lower confidence bound of the difference between remaining energy and path energy consumption. Indicates the currently available remaining energy. This indicates the estimated route energy consumption to reach the candidate connection point. This indicates the energy consumption during hovering. Indicates the energy consumption during the handover process. This represents one of the following: energy consumption for safe return or emergency avoidance; spatial conditions characterize one or more of the following: Euclidean distance threshold, alignment deviation threshold, envelope overlap rate, and no third-party occupation state between the execution terminal and the target resource; sensing stability conditions are obtained by weighted fusion of at least two of the following: locking stability, weight stability, contact stability, and attitude stability, and the calculation formula is as follows: in, , , and The non-negative weighting coefficients are used to determine the sensor stabilization condition. The state switching is based on the consistency of multiple samples within the anti-shake window, not on a single sample result.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: the present invention improves resource utilization by constructing candidate connection chains and pre-synchronizing shadow resources, enhances connection anti-disturbance capability through dynamic hysteresis activation method, realizes full-process responsibility traceability through trusted state sealing and continuity proof module, and solves the problem of network outage state convergence by relying on protected release and consistency rollback mechanism; at the same time, it achieves a comprehensive improvement in connection stability, resource utilization and responsibility traceability. Attached Figure Description

[0016] Figure 1 This is a system structure block diagram of the present invention; Figure 2 This is a block diagram of the platform collaborative control system of the present invention; Figure 3 This is a block diagram of the multi-source sensor group structure of the present invention; Figure 4 This is a flowchart of the method of the present invention; Figure 5 A flowchart illustrating the process of candidate connection chain, shadow resource pre-synchronization, delayed activation, sealing and rollback release; Figure 6 A schematic diagram of the trusted state seal and continuity proof structure; Figure 7 This is a timing diagram illustrating dynamic hysteresis, releasing the protection window, and consistent rollback.

[0017] In the diagram: 1. Platform collaborative control system; 11. Candidate connection chain construction module; 12. Shadow resource pre-synchronization module; 13. Activation envelope determination module; 14. Trusted state sealing and continuity proof module; 15. Anomaly classification and fault tolerance module; 16. Rollback and release control module; 17. Audit object output interface; 2. Execution terminal; 21. Trusted module; 22. Data acquisition and processing module; 3. Station-side trusted node; 31. Edge observation and aggregation module; 32. Proxy sealing module; 4. Multi-source sensor group; 41. Weighing sensor; 42. Locking position sensor; 43. Contact sensor; 44. IMU attitude sensor; 45. Alignment sensor; 46. Ranging sensor; 47. Battery management unit. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] Please see the appendix Figure 1 -Appendix Figure 3This invention provides an embodiment of a low-altitude logistics heterogeneous node ground-to-air docking collaborative control system, comprising a platform collaborative control system 1, an execution terminal 2, a station-end trusted node 3, and a multi-source sensor group 4. The platform collaborative control system 1 establishes data connections with both the execution terminal 2 and the station-end trusted node 3. The execution terminal 2 establishes a data connection with the station-end trusted node 3, and the multi-source sensor group 4 establishes data connections with both the execution terminal 2 and the station-end trusted node 3. The platform collaborative control system 1 serves as the core for global scheduling and decision-making. The execution terminal 2 can be a drone, unmanned vehicle, in-station handling equipment, a robotic arm, or other spatially mobile execution node. The station-end trusted node 3 is used to respond to situations where the execution terminal 2 has insufficient power, exceeds computing power limits, or has a trusted module. When 21 fails or the sealing queue is backlogged, it undertakes proxy sealing and edge observation aggregation functions. The multi-source sensor group 4 is used to collect multi-dimensional physical observation data. The platform collaborative control system 1 includes a candidate connection chain construction module 11, a shadow resource pre-synchronization module 12, an activation envelope determination module 13, a trusted state sealing and continuity proof module 14, an anomaly classification and fault tolerance module 15, a rollback and release control module 16, and an audit object output interface 17. The candidate connection chain construction module 11 is used to construct at least one candidate connection chain based on package priority, service level, site capacity, weather constraints, airspace constraints, and heterogeneous execution node availability. The shadow resource pre-synchronization module 12 is used to pre-synchronize at least one shadow resource in the main chain and the rollback chain. Shadow resources include at least one of the following: cabin, take-off and landing position, cabin door, buffer position, robotic arm working area, charging and swapping potential, and passageway. Activation envelope determination module 13 is used to generate dynamic hysteresis parameters, perform hysteresis activation determination based on the basic activation condition cluster and the scene additional condition cluster, and output shadow resource state switching instructions. Trusted state sealing and continuity proof module 14 is used to generate and issue proxy authorization chains, receive and verify trusted state seals, and concatenate multiple trusted state seals according to the pre-sequence digest to form a continuity proof. Anomaly classification and fault tolerance module 15 is used to classify anomalies into weak anomalies, recoverable anomalies, and safety-critical anomalies, and output corresponding graded handling instructions. Rollback and release control module 16 is used to verify resource release conditions and generate... The resource release token performs consistency verification and controlled rollback after network recovery. The audit object output interface 17 is used to output the sealing record object, freeze notification object, rollback notification object, and continuity proof. The execution terminal 2 includes a trusted module 21 and a data acquisition and processing module 22. The trusted module 21 is used to generate native trusted state seals at key nodes, and the data acquisition and processing module 22 is used to collect and preprocess its own state and physical observation data. The station-side trusted node 3 includes an edge observation aggregation module 31 and a proxy sealing module 32. The edge observation aggregation module 31 is used to aggregate physical observation data and perform time alignment, consistency assessment, and debouncing preprocessing. The proxy sealing module 32 is used to perform proxy sealing based on the valid proxy authorization chain.The multi-source sensor group 4 includes a weighing sensor 41, a locking position sensor 42, a contact sensor 43, an IMU attitude sensor 44, an alignment sensor 45, a ranging sensor 46, and a battery management unit 47. The weighing sensor 41 is used to measure the weight of the package and the load weight of the execution terminal 2, and to detect whether the weight is stable and whether loading is complete. The locking position sensor 42 is used to detect whether the mechanical locks, hatches, cargo compartments, and robotic arms are fully locked in place. The contact sensor 43 adopts one of a contact pressure sensor and a contact switch to detect whether physical contact occurs between the execution terminal 2 and the docking position, cargo, and robotic arm, and to monitor the contact. The pressure and contact status are monitored by the IMU attitude sensor 44, which collects the pitch, roll, and yaw angles, vibration, and tilt status of the execution terminal 2 in real time, and outputs attitude stability. The alignment sensor 45, employing either binocular vision or an infrared alignment module, detects the relative position and alignment deviation between the execution terminal 2 and the target docking point, determining whether the alignment is qualified. The ranging sensor 46, employing either a laser ranging module or an infrared ranging module, measures the straight-line distance between the execution terminal 2 and the docking station, obstacles, or target resources. The battery management unit 47 collects the remaining battery power, voltage, current, health status, and remaining range, and outputs battery status data.

[0020] Please see Figure 4 -Appendix Figure 7 This invention provides an embodiment of a low-altitude logistics heterogeneous node ground-to-air connection collaborative control method, comprising: Step 1, candidate connection chain construction and shadow resource pre-synchronization; Step 2, global control parameter distribution; Step 3, multi-source observation data processing and dynamic hysteresis parameter generation; Step 4, hysteresis activation determination driven by dual-condition clusters; Step 5, key node trusted signature and continuity proof generation; Step 6, anomaly hierarchical fault tolerance handling; Step 7, protected resource release and network outage recovery consistency rollback. In step one above, the candidate connection chain construction module 11 of the platform collaborative control system 1 generates at least one candidate connection chain containing a main chain and a fallback chain based on package priority, service level, site capacity, weather constraints, airspace constraints and heterogeneous execution node availability. The shadow resource pre-synchronization module 12 pre-synchronizes non-exclusive shadow resources for the target connection chain. The shadow resources only retain switching qualifications and necessary context, and do not immediately form a completely exclusive occupancy. In step two above, based on the candidate connection chain and shadow resource reservation context generated in step one, the platform collaborative control system 1 uniformly issues the activation epoch, version number, local feasible domain, rollback order, release protection window parameters, and proxy signing trigger conditions to the execution terminal 2 and the station trusted node 3. The local feasible domain includes one or more of the following: allowed switching time window set, resource set, reorder budget, priority boundary, freeze condition, and return to platform adjudication threshold. The execution terminal 2 only performs local adjustments within the local feasible domain. Adjustment requests outside the scope must be sent back to the platform collaborative control system 1 for unified adjudication. In step three above, the multi-source sensor group 4 continuously collects at least two types of physical observation data from locking, weight, contact, attitude, alignment, ranging, and battery status. The data acquisition and processing module 22 and the edge observation and aggregation module 31 perform time alignment, observation consistency assessment, and jitter preprocessing on the physical observation data. The envelope determination module 13 is activated to dynamically adjust the entry threshold, exit threshold, entry holding time, and exit holding time based on the disturbance vector composed of wind speed fluctuation amplitude, vibration noise slope, visual frame drop rate, weighing drift slope, and link jitter level. When the disturbance increases, one or more of the following are executed: increasing the entry threshold, extending the entry holding time, decreasing the exit threshold, and shortening the exit holding time. In step four above, the activation envelope determination module 13, based on the standardized physical observation values ​​and real-time dynamic hysteresis parameters output in step three, performs core activation determination using the basic activation condition cluster, and superimposes scenario-additional condition cluster verification under specific scenarios, outputting a shadow resource state switching instruction. The basic activation condition cluster consists of time conditions, energy conditions, spatial conditions, and sensor stability conditions. The scenario-additional condition cluster includes epoch consistency conditions and conflict resolution conditions, which must be triggered during version switching, resource contention, network recovery, and cross-node collaboration. The specific rules for hysteresis activation determination by the activation envelope determination module 13 are as follows: when the basic activation condition cluster continuously meets the entry threshold during the entry holding time, and all scenario-additional conditions are met, the shadow resource is switched to the formal activation state; when the basic activation condition cluster falls into the hysteresis interval, the current state is maintained and observation continues; when the basic activation condition cluster continuously meets the exit conditions during the exit holding time, and the scenario-additional conditions are not met, one action is executed: exiting the activation state or switching to the fallback chain. The energy condition is based on the energy feasibility margin. To make a conservative judgment, the calculation formula is as follows: in, This represents either the risk quantile or the lower confidence bound of the difference between remaining energy and path energy consumption. Indicates the currently available remaining energy. This indicates the estimated route energy consumption to reach the candidate connection point. This indicates the energy consumption during hovering. Indicates the energy consumption during the handover process. This represents one of the following: energy consumption for safe return or emergency avoidance; spatial conditions characterize one or more of the following: Euclidean distance threshold, alignment deviation threshold, envelope overlap rate, and no third-party occupation state between the execution terminal 2 and the target resource; sensing stability conditions are obtained by fusing at least two of the following weighted conditions: locking stability, weight stability, contact stability, and attitude stability, and the calculation formula is as follows: in, , , and The non-negative weighting coefficients are used to determine the state switching based on the consistency of multiple samplings within the anti-shake window, rather than the single sampling result. In step five above, at key nodes of the entire connection process, the trusted module 21 generates native trusted state seals. If at least one of the following occurs: trusted module 21 malfunctions, insufficient power, or computing power exceeds limits, the proxy seal module 32 performs proxy seals based on the valid proxy authorization chain. The trusted state seal and continuity proof module 14 receives all trusted state seals and concatenates them according to the pre-sequence digest to form a continuity proof. Key nodes include at least one of the following: arrival, loading, locking, handover, detachment, takeoff, landing, anomaly handling, and responsibility switching. The valid proxy authorization chain at least limits the proxy authorization token, proxy scope, proxy expiration time, gateway certificate identifier, challenge random number, and authorization proof digest. When the proxy seal module 32 performs proxy seals, in addition to recording the proxy identifier, it also simultaneously records the original trigger source identifier, trigger time, epoch number, and authorization proof digest. The continuity proof includes the event digest, pre-sequence digest, trigger source identifier, timestamp, version number, proxy identifier, freeze level, reason code, protection identifier, and rollback sequence number, and is organized into an immutable and auditable seal record object. In step six above, the anomaly classification and fault tolerance module 15 identifies the anomaly level and triggers the corresponding handling process to achieve layered fault tolerance. The specific rules for anomaly classification and handling are as follows: weak anomalies trigger resampling and supplementary sampling; recoverable anomalies trigger downgraded operation, proxy sealing, and backtracking switch; safety-critical anomalies trigger strong freezing and complete preservation of on-site data. In step seven above, the rollback and release control module 16 releases resources when all release conditions are met. After network recovery, it performs consistency verification and controlled rollback based on trusted evidence, and finally outputs all auditable data through the audit object output interface 17. Resource release must simultaneously meet all of the following conditions: responsibility boundary closure, downstream takeover confirmation, release protection window expiration and no new conflicts, and cross-epoch residual actions. The specific process of consistency verification and controlled rollback is as follows: the rollback and release control module 16 performs consistency verification based on the active epoch, version number, most recently valid signature, and local action sequence. The execution results after recovery are divided into a set of retained actions and a set of revoked actions. Only actions in the set of retained actions that have closed responsibility boundaries are confirmed, and the remaining actions are revoked, reassigned, or rearranged.

[0021] Based on the above, the advantages of this invention are as follows: When this invention is used, the platform collaborative control system 1, through the candidate connection chain construction module 11, generates a set of candidate connection chains including the main chain and at least one fallback chain based on package priority, service level, station capacity, weather and airspace constraints, and heterogeneous node availability. Combined with the shadow resource pre-synchronization module 12, it achieves non-exclusive resource reservation, retaining only resource switching eligibility and control context, without forming complete exclusive occupation, replacing the traditional rigid locking method, and avoiding resource idleness while ensuring execution redundancy; the platform collaborative control system 1 uniformly issues the activation epoch, version number, local feasible domain, release protection window, and agent signing trigger condition to the execution terminal 2 and the station trusted node 3 to complete the global parameter initialization; during the connection execution phase, the weighing sensor 41 in the multi-source sensor group 4 collects the weight of the package and the load of the execution terminal 2, the locking position sensor 42 detects the mechanical lock in place, the contact sensor 43 monitors the physical contact state, the IMU attitude sensor 44 collects the pitch, roll, and yaw attitude of the execution terminal 2, and the alignment sensor 45 detects the execution... The relative position and alignment deviation between the execution terminal 2 and the target docking point are measured to determine whether the alignment is qualified. The ranging sensor 46 measures the straight-line distance between the execution terminal 2 and the docking station, obstacles, and target resources. The battery management unit 47 collects the remaining battery power, voltage, current, health status, and remaining range, and outputs battery status data. After the above data is processed by the data acquisition and processing module 22 of the execution terminal 2 and the edge observation and aggregation module 31 of the station-end trusted node 3 to complete time alignment, consistency assessment, and jitter preprocessing, standardized observation values ​​are generated and activated by the envelope. The judgment module 13 performs dual-condition judgment of the basic activation condition cluster and the scene additional condition cluster, and dynamically adjusts the hysteresis parameter according to the real-time disturbance to effectively suppress false state switching and frequent jumps. For example, under normal working conditions, the entry threshold can be set to 0.72, the exit threshold to 0.58, the entry holding time to 400ms, and the exit holding time to 200ms. When the wind speed standard deviation is greater than 1.5m / s and the visual frame drop rate is greater than 8%, the entry threshold can be increased to 0.78 and the entry holding time can be extended to 650ms, while the exit threshold can be decreased to 0.54; The native trusted signature is generated by the trusted module 21 of the execution terminal 2. When the execution terminal 2 malfunctions, the proxy signature module 32 of the trusted node 3 at the station end completes the proxy signature based on the authorization chain. Then, the trusted state signature and continuity proof module 14 are concatenated according to the pre-sequence summary to form a full-process continuity proof, connecting the boundaries of cross-entity responsibility. The system status is monitored in real time throughout the entire process by the anomaly classification and fault tolerance module 15, realizing layered fault tolerance with weak anomaly resampling, recoverable anomaly degradation operation, and strong freezing of safety-critical anomalies. When the connection is completed or anomaly terminated, the protected resource is released and the consistency rollback after network disconnection is implemented by the rollback and release control module 16. Finally, the standardized auditable data is output by the audit object output interface 17, comprehensively improving the feasibility of the system engineering. The execution terminal 2 can be a drone, unmanned vehicle, in-station handling equipment, robotic arm, or other spatially mobile execution nodes. The trusted node 3 at the station end is used to undertake proxy signature and edge observation aggregation functions when the execution terminal 2 has insufficient power, exceeds computing power limits, the trusted module 21 malfunctions, or the signature queue is backlogged.

[0022] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A low-altitude logistics heterogeneous node ground-to-air connection collaborative control system, comprising a platform collaborative control system (1), an execution terminal (2), a station-end trusted node (3), and a multi-source sensor group (4), characterized in that: The platform collaborative control system (1) establishes data connections with the execution terminal (2) and the station trusted node (3) respectively. The execution terminal (2) establishes data connections with the station trusted node (3) respectively. The multi-source sensor group (4) establishes data connections with the execution terminal (2) and the station trusted node (3) respectively.

2. The low-altitude logistics heterogeneous node ground-to-air connection collaborative control system according to claim 1, characterized in that: The platform collaborative control system (1) includes a candidate connection chain construction module (11), a shadow resource pre-synchronization module (12), an activation envelope determination module (13), a trusted state sealing and continuity proof module (14), an anomaly classification and fault tolerance module (15), a rollback and release control module (16), and an audit object output interface (17). The candidate connection chain construction module (11) is used to construct at least one candidate connection chain based on package priority, service level, site capacity, weather constraints, airspace constraints, and heterogeneous execution node availability. The shadow resource pre-synchronization module (12) is used to pre-synchronize at least one shadow resource in the main chain and rollback chain. The shadow resource includes at least one of the following: cabin, take-off and landing position, cabin door, buffer position, robotic arm working area, charging and swapping potential, and passageway. The activation envelope determination module (13) 13) Used to generate dynamic hysteresis parameters, implement hysteresis activation judgment based on basic activation condition cluster and scene additional condition cluster, and output shadow resource state switching instructions. Trusted state sealing and continuity proof module (14) is used to generate and issue agent authorization chain, receive and verify trusted state sealing, and connect multiple trusted state sealing according to the pre-sequence digest to form continuity proof. Anomaly classification and fault tolerance module (15) is used to classify anomalies into weak anomalies, recoverable anomalies and safety critical anomalies, and output corresponding graded handling instructions. Rollback and release control module (16) is used to verify resource release conditions and generate resource release tokens, and perform consistency verification and controlled rollback after network recovery. Audit object output interface (17) is used to output sealing record object, freeze notification object, rollback notification object and continuity proof to the outside world.

3. The low-altitude logistics heterogeneous node ground-to-air connection collaborative control system according to claim 1, characterized in that: The execution terminal (2) includes a trusted module (21) and a data acquisition and processing module (22). The trusted module (21) is used to generate native trusted state seals at key nodes, and the data acquisition and processing module (22) is used to collect and preprocess its own state and physical observation data.

4. The low-altitude logistics heterogeneous node ground-to-air connection collaborative control system according to claim 1, characterized in that: The trusted node (3) at the station includes an edge observation aggregation module (31) and a proxy signing module (32). The edge observation aggregation module (31) is used to aggregate physical observation data and perform time alignment, consistency assessment and jitter removal preprocessing. The proxy signing module (32) is used to perform proxy signing based on a valid proxy authorization chain.

5. The low-altitude logistics heterogeneous node ground-to-air connection collaborative control system according to claim 1, characterized in that: The multi-source sensor group (4) includes a weighing sensor (41), a locking position sensor (42), a contact sensor (43), an IMU attitude sensor (44), an alignment sensor (45), a ranging sensor (46), and a battery management unit (47). The weighing sensor (41) is used to measure the weight of the package and the load weight of the execution terminal (2), and to detect whether the weight is stable and whether the loading is complete. The locking position sensor (42) is used to detect whether the mechanical lock, hatch, cargo compartment, and robotic arm are fully locked in place. The contact sensor (43) is one of a contact pressure sensor and a contact switch, used to detect whether there is a physical contact between the execution terminal (2) and the docking position, the cargo, and the robotic arm. Contact, monitor contact pressure and contact status, IMU attitude sensor (44) collects pitch, roll, yaw angle and vibration, tilt status of execution terminal (2) in real time, output attitude stability, alignment sensor (45) adopts one of binocular vision and infrared alignment module to detect the relative position and alignment deviation between execution terminal (2) and target docking position, and judge whether the alignment is qualified, distance sensor (46) adopts one of laser distance module and infrared distance module to measure the straight distance between execution terminal (2) and docking station, obstacle and target resource, and battery management unit (47) collects battery remaining power, voltage, current, health status and remaining range, and outputs battery status data.

6. A collaborative control method for ground-to-air connections of heterogeneous nodes in low-altitude logistics, comprising: Step 1, candidate connection chain construction and shadow resource pre-synchronization; Step 2, global control parameter distribution; Step 3, multi-source observation data processing and dynamic hysteresis parameter generation; Step 4, hysteresis activation determination driven by dual-condition clusters; Step 5, generation of trusted signatures and continuity proofs for key nodes; Step 6, anomaly hierarchical fault-tolerant handling; Step 7, release of protected resources and consistency rollback after network outage; characterized in that: In step one above, the candidate connection chain construction module (11) of the platform collaborative control system (1) generates at least one candidate connection chain containing the main chain and the fallback chain based on the package priority, service level, site capacity, weather constraints, airspace constraints and heterogeneous execution node availability. The shadow resource pre-synchronization module (12) pre-synchronizes non-exclusive shadow resources for the target connection chain. The shadow resources only retain the switching qualification and necessary context, and do not immediately form a completely exclusive occupancy. In step two above, based on the candidate connection chain and shadow resource reserved context generated in step one, the platform collaborative control system (1) uniformly issues the activation epoch, version number, local feasible domain, rollback order, release protection window parameters and agent signing trigger conditions to the execution terminal (2) and station trusted node (3). In step three above, the multi-source sensor group (4) continuously collects at least two types of physical observation data from locking, weight, contact, attitude, alignment, ranging and battery status. The data acquisition and processing module (22) and the edge observation convergence module (31) perform time alignment, observation consistency evaluation and jitter removal preprocessing on the physical observation data. The envelope determination module (13) is activated to generate dynamic hysteresis parameters based on the real-time disturbance status. In step four above, the activation envelope determination module (13) performs core activation determination based on the standardized physical observation values ​​and real-time dynamic hysteresis parameters output in step three, and superimposes scene additional condition cluster verification in specific scenarios, and outputs shadow resource state switching instructions; wherein, the basic activation condition cluster consists of time conditions, energy conditions, spatial conditions and sensing stability conditions, and the scene additional condition cluster includes epoch consistency conditions and conflict resolution conditions, which must be triggered for verification when there is version switching, resource competition, network recovery, or cross-node collaboration; In step five above, at key nodes of the entire connection process, the trusted module (21) generates native trusted state seals. If at least one of the following occurs: trusted module (21) malfunctions, insufficient power, or computing power exceeds limits, the proxy seal module (32) performs proxy seals based on the valid proxy authorization chain. The trusted state seal and continuity proof module (14) receives all trusted state seals and concatenates them according to the preceding digest to form a continuity proof. Key nodes include arrival, loading, locking, handover, detachment, takeoff, landing, anomaly handling, and responsibility switching. At least one of the following; the effective proxy authorization chain at least limits the proxy authorization token, proxy scope, proxy expiration time, gateway certificate identifier, challenge random number and authorization proof digest; when the proxy sealing module (32) performs proxy sealing, in addition to recording the proxy identifier, it also records the original trigger source identifier, trigger time, epoch number and authorization proof digest simultaneously; the continuity proof includes event digest, prequel digest, trigger source identifier, timestamp, version number, proxy identifier, freeze level, reason code, protection identifier and rollback sequence number, and is organized into an unalterable auditable sealing record object; In step six above, the anomaly classification and fault tolerance module (15) identifies the anomaly level and triggers the corresponding handling process to achieve layered fault tolerance; the specific rules for anomaly classification and handling are as follows: weak anomalies trigger resampling and supplementary sampling; recoverable anomalies trigger downgraded operation, proxy sealing, and backtracking switch; safety-critical anomalies trigger strong freezing and complete preservation of on-site data. In step seven above, the rollback and release control module (16) releases resources when all release conditions are met. After network recovery, it performs consistency verification and controlled rollback based on trusted evidence, and finally outputs all auditable data through the audit object output interface (17). Resource release must meet all of the following conditions at the same time: responsibility boundary closed, downstream takeover confirmed, release protection window expired and there are no new conflicts, and cross-epoch residual actions. The specific process of consistency verification and controlled rollback is as follows: the rollback and release control module (16) performs consistency verification based on the activation epoch, version number, most recently valid signature and local action sequence, divides the execution results after recovery into a set of retained actions and a set of revoked actions, only confirms the actions in the set of retained actions that have closed the responsibility boundary, and revokes, reassigns and rearranges the remaining actions.

7. A low-altitude logistics heterogeneous node ground-to-air connection collaborative control method according to claim 6, characterized in that: In step two, the local feasible domain includes one or more of the following: the set of time windows that allow switching, the set of resources, the reorder budget, the priority boundary, the freeze condition, and the threshold for returning to the platform for adjudication; the execution terminal (2) only performs local adjustments within the local feasible domain, and adjustment requests that exceed the scope must be sent back to the platform collaborative control system (1) to wait for unified adjudication.

8. A method for coordinated control of ground-to-air connections between heterogeneous nodes in low-altitude logistics according to claim 6, characterized in that: In step three, the activation of the envelope determination module (13) to generate dynamic hysteresis parameters based on the real-time disturbance status is specifically as follows: The activation of the envelope determination module (13) dynamically adjusts the entry threshold, exit threshold, entry hold time, and exit hold time based on the disturbance vector composed of wind speed fluctuation amplitude, vibration noise slope, visual frame loss rate, weighing drift slope, and link jitter level. When the disturbance is enhanced, one or more of the following are executed: increase the entry threshold, extend the entry hold time, decrease the exit threshold, and shorten the exit hold time.

9. A method for coordinated control of ground-to-air connections between heterogeneous nodes in low-altitude logistics according to claim 6, characterized in that: In step four, the specific rules for the activation envelope determination module (13) to perform hysteresis activation determination are as follows: when the basic activation condition cluster continuously meets the entry threshold during the entry holding time and all additional scene conditions are met, the shadow resource is switched to the formal activation state; when the basic activation condition cluster falls into the hysteresis interval, the current state is maintained and observation continues; when the basic activation condition cluster continuously meets the exit conditions during the exit holding time and the additional scene conditions are not met, one of the actions of exiting the activation state or switching to the fallback chain is executed.

10. A method for coordinated control of ground-to-air connections between heterogeneous nodes in low-altitude logistics according to claim 6, characterized in that: In step four, the energy condition is based on the energy feasibility margin. To make a conservative judgment, the calculation formula is as follows: in, This represents either the risk quantile or the lower confidence bound of the difference between remaining energy and path energy consumption. Indicates the currently available remaining energy. Indicates the estimated route energy consumption to reach the candidate connection point. This indicates the energy consumption during hovering. Indicates the energy consumption during the handover process. This represents one of the following: energy consumption for safe return or emergency avoidance; spatial conditions characterize one or more of the following: Euclidean distance threshold, alignment deviation threshold, envelope overlap rate, and no third-party occupation state between the execution terminal (2) and the target resource; sensing stability conditions are obtained by weighted fusion of at least two of the following: locking stability, weight stability, contact stability, and attitude stability, and the calculation formula is as follows: in, , , and The non-negative weighting coefficients are used to determine the sensor stabilization condition. The state switching is based on the consistency of multiple samples within the anti-shake window, not on a single sample result.