An active Ethernet all-optical network intelligent control system for large tertiary hospitals
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-17
- Publication Date
- 2026-08-14
AI Technical Summary
该方案部署广泛、成本相对较低,但性能和可靠性已无法满足现代智慧医疗的需求
[0018]本发明由于采用了上述的技术方案,其与现有技术相比,所取得的技术进步在于:
Smart Images

Figure CN122579010A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of optical communication and medical information technology, specifically relating to an active Ethernet all-optical network intelligent control system for large tertiary hospitals. Background Technology
[0002] With the rapid development of smart healthcare, emerging services such as PACS medical imaging, remote surgery, intensive care, AI pathology diagnosis, 8K live surgery broadcasts, and medical IoT are placing unprecedentedly stringent demands on hospital network infrastructure. Large tertiary hospitals require a dedicated medical network capable of simultaneously supporting intranet, extranet, device control network, and security IoT, meeting multiple requirements including ultra-low latency, ultra-high bandwidth, strong anti-interference, physical isolation, intelligent operation and maintenance, smooth evolution, and compliance with Level 3 of the Information Security Protection System 2.0.
[0003] Currently, the mainstream network solutions for hospitals are divided into two categories: traditional Ethernet and passive optical network (PON).
[0004] Traditional Ethernet primarily uses Category 6 copper cabling, employing a networking approach of aggregation in floor-level low-voltage rooms, shared gigabit bandwidth, and RJ45 electrical port switching. While this solution is widely deployed and relatively low-cost, its performance and reliability are no longer sufficient to meet the demands of modern smart healthcare. Specifically, traditional Ethernet suffers from the following drawbacks: First, it suffers from severe performance bottlenecks. Under high load, gigabit shared bandwidth experiences latency of 10–50 ms, with significant jitter, failing to meet the latency requirements of less than 1 ms for remote robotic surgery and real-time transmission in intensive care. Second, it has poor anti-interference capabilities. In strong electromagnetic environments such as MRI, CT, linear accelerators, and operating rooms, copper cables experience packet loss rates exceeding 5%, leading to image distortion, abnormal monitoring data, and serious medical safety risks. Third, it suffers from low reliability and high maintenance costs. RJ45 connectors have a high failure rate, and copper cables are prone to aging, moisture, and rodent damage, requiring replacement every 5 years on average. Frequent construction disrupts normal medical procedures. Fourth, it lacks scalability. Expansion requires additional switches and a large amount of copper cable, resulting in long construction cycles and significant challenges, making it unable to support future business needs such as AI-assisted diagnosis, digital twin hospitals, and access to millions of medical IoT terminals.
[0005] Passive Optical Networks (PONs) employ a point-to-multipoint splitting architecture, shared 10G ports, and passive nodes that require no power supply, and are used in some newly built hospitals. However, PONs also have significant drawbacks: First, bandwidth contention is severe; with shared 10G ports, the bandwidth per user does not exceed 300Mbps when the splitting ratio reaches 1:32, leading to stuttering and large latency fluctuations during peak hours. Second, latency jitter is uncontrollable, with end-to-end latency ranging from 1 to 5ms, failing to meet the ultra-low latency requirements of remote robotic surgery. Third, fault location is difficult and repair is slow; fault location for passive splitting nodes is complex, with an average repair time of no less than 2 hours, impacting the continuity of core services. Fourth, scalability is limited; the splitting ratio is fixed, limiting expansion and hindering the long-term evolution of high-density medical IoT.
[0006] In conclusion, neither traditional Ethernet nor PON can meet the comprehensive requirements of smart healthcare development in terms of network performance, reliability, security, and scalability. Therefore, there is an urgent need for a dedicated active Ethernet all-optical network solution designed specifically for large tertiary hospitals. Summary of the Invention
[0007] The purpose of this invention is to provide an active Ethernet all-optical network intelligent management and control system for large tertiary hospitals, which can achieve ultra-low latency end-to-end, 10 Gigabit symmetrical dedicated bandwidth on a single port, physical hard isolation at the optical layer, high reliability with full-link redundancy, and AI-driven intelligent operation and maintenance, thereby improving the intelligent control level, service carrying capacity, and operational security of large tertiary hospital networks.
[0008] To achieve the above objectives, the technical solution adopted by this invention is as follows: An active Ethernet all-optical network intelligent management and control system for large tertiary hospitals includes a three-layer active Ethernet all-optical star-redundant hardware architecture, and an SDN centralized management and control platform and an AI intelligent operation and maintenance platform deployed on the hardware architecture and interacting with the hardware architecture. The hardware architecture consists of a core layer, an aggregation layer, and an access layer. The core layer and the aggregation layer, as well as the aggregation layer and the access layer, are directly connected point-to-point via 10 Gigabit single-mode optical fiber. The core layer includes a core switch, the aggregation layer includes regional aggregation switches, and the access layer includes all-optical aggregation switches deployed on each floor and scenario-specific access switches deployed at the end of each room. The all-optical aggregation switches and the scenario-specific access switches are connected via optical-electric composite cables. Furthermore, the optical fiber contains multiple independent optical wavelength channels, with different service networks occupying different wavelength channels to achieve physical hard isolation. The core layer is equipped with a dual-active core computer room and a disaster recovery core computer room. The core switch is configured with redundant main control, redundant power supply and redundant switching network board. The connection links between the core layer and the aggregation layer, and between the aggregation layer and the access layer are configured with two independent optical fiber routes, one for main and one for backup. The ports of the links are configured with link aggregation and fast switching protocols. The SDN centralized management and control platform is connected to the core switch, the regional aggregation switch, the all-optical aggregation switch and the scenario-based access switch through a control channel. It is used to collect the device operation data of each switch and transmit it to the AI intelligent operation and maintenance platform. Based on the feedback results of the AI intelligent operation and maintenance platform, it uniformly issues VLAN configuration, security policies and QoS scheduling instructions to each switch. The AI-powered intelligent operation and maintenance platform interfaces with the SDN centralized management and control platform to receive the device operation data collected by the SDN centralized management and control platform. The AI-powered intelligent operation and maintenance platform includes a time-series anomaly detection model and a fault classification neural network. The time-series anomaly detection model analyzes the device operation data based on an LSTM network to identify abnormal fluctuations. The fault classification neural network classifies abnormal features based on a CNN network to locate the fault type and location, and feeds back the identification and location results to the SDN centralized management and control platform. The SDN centralized management and control platform also includes a service identification and dynamic scheduling module. This module uses a traffic feature fingerprinting algorithm to pre-establish a dedicated traffic fingerprint database containing various medical service types. When the system is running, this module captures the network traffic in real time and compares it with the traffic fingerprint database to automatically identify the service type of the current traffic. Then, based on the weighted round-robin QoS scheduling algorithm, it assigns corresponding priority weights to different services and issues dynamic bandwidth allocation and adjustment QoS scheduling instructions to each switch accordingly.
[0009] As a limitation, the dual-active core data centers achieve real-time data synchronization via fiber optic links, and the disaster recovery core data center is connected to the dual-active core data centers via fiber optic links for asynchronous data backup. When any core data center experiences a complete failure, all network services are automatically migrated to the other core data center. Among the two independent fiber optic routes, services run on the primary route during normal operation. When the primary route experiences a link interruption, the fast failover protocol detects the link failure and triggers the backup route in the link aggregation group to take over data transmission, thereby achieving automatic service switching.
[0010] As a second limitation, the AI intelligent operation and maintenance platform adopts the following method for model training and optimization: First, it collects normal operation data of the entire hospital network and fault sample data under various known fault states. The normal operation data and fault sample data include optical power fluctuation data and medical service traffic burst data. Then, the operation and maintenance personnel label each type of fault sample with its corresponding fault type and fault location to form a labeled training dataset. After dividing the training dataset into training set, validation set and test set, the time-series anomaly detection model and the fault classification neural network are iteratively trained until the model's performance indicators on the validation set converge. After the system is officially launched, the AI intelligent operation and maintenance platform continuously collects new data in actual operation and performs incremental learning and adaptive optimization on the existing model.
[0011] As a third limitation, the operation mode of the service identification and dynamic scheduling module is as follows: Features are extracted from traffic samples of various medical services in advance to establish a dedicated traffic fingerprint database including PACS imaging services, remote surgery services, ICU monitoring services, office internet access services, and security monitoring services. During system operation, the service identification and dynamic scheduling module captures the entire network traffic in real time and performs feature comparison. Based on the comparison results, it automatically identifies the service type of the current traffic and its required service quality level and bandwidth requirements. Then, based on a weighted round-robin QoS scheduling algorithm, it assigns corresponding priority weights to various services and combines a congestion prediction algorithm to predict peak traffic periods in advance, implementing dynamic bandwidth allocation and adjustment among various services. When allocating priority weights, the remote surgery service and vital sign monitoring service are assigned the highest priority weights.
[0012] As a fourth limitation, the scenario-based access switches are divided into several types according to different deployment scenarios: ward-type access switches, which are equipped with gigabit Ethernet ports and dual 10G optical ports for connecting bedside screens, call systems, and vital sign monitors in wards; medical imaging-type access switches, which are equipped with 10G bandwidth ports for connecting CT equipment, MRI equipment, and PACS imaging terminals; operating room and ICU-type access switches, which adopt industrial-grade hardware and are equipped with dual uplink redundant links to ensure uninterrupted data transmission of critical medical equipment in operating rooms and intensive care units; and security IoT-type access switches, which are equipped with PoE power supply ports for connecting video surveillance cameras, environmental sensors, and access control controllers.
[0013] As a fifth limitation, the SDN centralized management and control platform also includes a ZTP zero-configuration commissioning module, which works as follows: when a new scenario-based access switch first accesses the network, the ZTP zero-configuration commissioning module automatically identifies the access location and preset deployment scenario of the new access scenario-based access switch, and automatically generates and distributes corresponding VLAN division, security access policy and QoS service quality rules for the new access scenario-based access switch according to the pre-configuration policy, so that the new access scenario-based access switch can complete the configuration and enter the normal working state without manual intervention.
[0014] As a sixth limitation, the all-optical aggregation switches are deployed in the low-voltage rooms on each floor. Each all-optical aggregation switch is responsible for aggregating the uplink traffic of all scenario-specific access switches in all rooms on the same floor, and providing PoE remote power supply to each scenario-specific access switch through the optical-electric composite cable. The PoE remote power supply is uniformly provided by the upper-level all-optical aggregation switch through the power supply cable in the optical-electric composite cable, which powers the scenario-specific access switches themselves and the low-power active terminals connected to them, eliminating the need for local power adapters for network devices in the end rooms, and reducing the disturbance of high-voltage wiring construction to medical sterile environments such as operating rooms and ICUs. The core diagnostic and treatment equipment in the operating room and ICU is independently powered by the hospital's existing medical isolation power supply system.
[0015] As a seventh limitation, both the core switch and the aggregation switch support multi-rate optical interfaces. These multi-rate optical interfaces can adaptively adapt to optical modules of different rates according to the link bandwidth requirements, enabling flexible upgrades to the link rate without replacing the switching equipment.
[0016] As the eighth limitation, the system adopts a zoned power supply system, including a three-level power supply architecture: Level 1, the switching equipment in the core computer room and aggregation computer room adopts a dual-path power supply method with dual municipal mains power input plus UPS uninterruptible power supply, and the two power supplies are hot backups of each other; Level 2, the all-optical aggregation switches in the weak current rooms on each floor adopt local UPS centralized power supply; Level 3, the network power required by the scenario-based access switches at the end of each room and their downstream low-power active terminal equipment is uniformly provided by the upper-level all-optical aggregation switches through optical fiber composite cables, and the network equipment in the end rooms does not need to be separately laid with high-voltage lines and power adapters.
[0017] As a ninth limitation, it also includes a secure access and multi-service bearing platform, which integrates an access authentication module, a data encryption module, an operation and maintenance audit module, and a vulnerability scanning module; the access authentication module is used to authenticate and verify the permissions of terminal devices accessing the network; the data encryption module is used to encrypt and protect critical data transmitted over the network; the operation and maintenance audit module is used to record and trace all operation and maintenance operations; and the vulnerability scanning module is used to periodically detect security vulnerabilities in all network devices.
[0018] The present invention, by adopting the above-described technical solution, achieves the following technical advancements compared to existing technologies: (1) The system of the present invention adopts a three-layer active Ethernet all-optical star redundancy architecture of core layer-aggregation layer-access layer, with point-to-point direct connection of 10 Gigabit single-mode fiber throughout, combined with three-level redundancy mechanism of equipment level, link level and data center level, to achieve end-to-end one-way latency of less than 0.5ms and data packet loss rate of <10%. -12 With a fault switching time of less than 50ms, it fully meets the requirements for real-time transmission of vital signs data in remote robotic surgery and ICU. The annual failure rate of the system does not exceed 0.3%, significantly improving the reliability of the medical network and solving the problems of high latency jitter in traditional Ethernet and bandwidth contention and uncontrollable latency in PON. (2) The system of the present invention achieves physical hard isolation based on optical channel wavelength division technology. It divides independent optical wavelength channels inside a single optical fiber, so that the internal network, external network, equipment control network and security IoT occupy different wavelength channels respectively, eliminating unauthorized access from the bottom layer of the link. Combined with security domain division and boundary protection, it forms a dual security system, fully meets the standard requirements, effectively protects patient privacy and medical data security, and overcomes the security risk that traditional VLAN logical isolation is easily penetrated. (3) The system of the present invention adopts an AI intelligent operation and maintenance platform based on a dual-layer neural network model of LSTM+CNN. The bottom LSTM model analyzes time series data such as optical power and delay to identify minute abnormal jitters. The upper CNN model classifies abnormal features and distinguishes fault types such as optical connector failure, cable aging, equipment failure and terminal failure. It realizes second-level early warning and accurate location of hidden faults. The fault location accuracy rate is not less than 99%, and the operation and maintenance manpower cost is reduced by 45%. It solves the problems of slow fault detection and difficult fault location in traditional operation and maintenance. (4) The system of the present invention uses a service identification and dynamic scheduling module built into the SDN centralized management and control platform. It adopts a traffic feature fingerprinting algorithm to automatically identify medical service types such as PACS images, remote surgery, and ICU monitoring. Based on the weighted round-robin QoS scheduling algorithm and congestion prediction algorithm, it realizes dynamic bandwidth allocation. Each room has 10G dedicated bandwidth, and the PACS image retrieval time is reduced by 90%. It can support the concurrent operation of thousands of images and hundreds of 8K surgical live broadcasts. At the same time, it adopts ZTP zero-configuration start-up to achieve plug-and-play, which greatly improves deployment efficiency. Expansion only requires upgrading the optical module without rewiring, and reserves 15 years of service evolution space. (5) The system of the present invention uses optical fiber transmission throughout the process, without metal conductors, and the signal is zero distortion in strong electromagnetic areas such as nuclear magnetic resonance, CT, and heavy ion equipment, which completely solves the interference problem of traditional copper cables with a packet loss rate of more than 5% in strong electromagnetic environments; the optical fiber has a service life of 25 to 30 years, reduces optical transmission power consumption by 65%, reduces wiring by 70% to 90%, shortens the construction cycle by 50%, and significantly reduces the total life cycle cost; at the same time, it adopts a zoned power supply system, and the terminal equipment is remotely powered by optical fiber composite cable PoE, without the need for separate high voltage wiring, which is suitable for sterile environments such as operating rooms and ICUs.
[0019] This invention belongs to the field of optical communication and medical information technology. It can achieve ultra-low latency, ultra-high bandwidth, physical hard isolation and AI intelligent operation and maintenance for large-scale tertiary hospital networks, significantly improve the security, reliability and intelligence level of medical networks, and promote the upgrading of hospital information infrastructure towards intelligence. Attached Figure Description
[0020] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof.
[0021] In the attached diagram: Figure 1 This is a system block diagram according to an embodiment of the present invention. Detailed Implementation
[0022] The preferred embodiments of the present invention will now be described with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustrative and explanatory purposes only and are not intended to limit the scope of the invention. Example
[0023] like Figure 1 As shown, this embodiment is an active Ethernet all-optical network intelligent management and control system for a large tertiary hospital, specifically a 2000-bed tertiary general hospital. This embodiment includes a three-layer active Ethernet all-optical star-shaped redundant hardware architecture, and an SDN centralized management and control platform, an AI intelligent operation and maintenance platform, and a security access and multi-service bearing platform deployed on and interacting with the hardware architecture. The system simultaneously supports the internal network, external network, device control network, and security IoT, meeting standard compliance requirements.
[0024] In this embodiment, the tertiary-level Class A general hospital includes individual buildings such as Building A (outpatient and medical technology building), Building B (inpatient building), Building C (inpatient building), Building D (specialty center building), Building E (administrative, scientific research and training complex building), Building F (fever clinic building), the North Area basement, and the South Area basement.
[0025] Hardware architecture deployment: Core Layer Deployment: Dual-active core data centers are set up on the third floor of Building E and the first floor of Building A, each with two internal network core switches (for mutual backup); a disaster recovery core data center is set up on the second floor of Building D. The core switches use equipment with a switching capacity of no less than 1700Tbps and a packet forwarding rate of no less than 90000Mpps. Each switch is configured with no less than 48 10G optical ports, no less than 24 40G optical ports, and no less than 2 100G optical ports, and is equipped with 1+1 redundant master controllers, 1+1 redundant power supplies, and multiple sets of redundant switching network boards. The core switches serve as the central hub for data forwarding across the entire network, uniformly running VLAN, security policies, and QoS scheduling commands, connecting to the SDN controller and AI operation and maintenance platform, and collecting operational data from all network devices.
[0026] Aggregation Layer Deployment: Six regional aggregation equipment rooms are set up throughout the campus, each deploying aggregation switches. The aggregation switches utilize equipment with a switching capacity of at least 23Tbps and a packet forwarding rate of at least 720Mpps. Each switch is configured with at least 24 10G optical ports and at least 4 40G optical ports, and features dual power supply redundancy. The aggregation switches aggregate traffic from all floors of the building, execute forwarding rules and security policies issued by the core, converge upwards to the core, and distribute downwards to the floor-level all-optical aggregation. The core switch and aggregation switches are connected via a 40G dual-fiber redundant uplink. In this embodiment, the 10G / 40G / 100G optical ports configured on the core switches and the 10G / 40G optical ports configured on the aggregation switches are all multi-rate optical interfaces, which can adaptively adapt to the rate of the access optical modules, enabling flexible upgrades to link rates without replacing the switching equipment.
[0027] Access Layer Deployment: All-optical aggregation switches are deployed in the low-voltage rooms on each floor, configured with 24 or 48 10G optical ports, responsible for traffic aggregation and PoE power distribution for all access devices in each room on that floor; scenario-specific access switches are deployed at the end of each consultation room, ward, operating room, etc. All-optical aggregation switches are connected to each other via 10G dual-fiber redundant uplinks; all-optical aggregation switches are connected to scenario-specific access switches point-to-point via fiber-optic composite cables (fiber optic data transmission, cable power supply).
[0028] The scenario-based access switches are categorized by scenario: Ward access switches are equipped with gigabit Ethernet ports and dual 10G optical ports for connecting bedside screens, call systems, and vital signs monitors; Medical imaging access switches are equipped with dedicated 10G bandwidth ports for CT, MRI, and PACS equipment; Operating room / ICU access switches use industrial-grade hardware and are equipped with dual uplink redundant links to ensure critical monitoring and surgical data; Security IoT access switches are equipped with PoE++ power supply ports for connecting cameras, sensors, and access control systems.
[0029] In terms of cabling and transmission media, the trunk line uses 12-core, 24-core, or 48-core single-mode optical cables, and the cabling uses Category 6 4-pair UTP copper cables (terminal information points). All optical fibers have a repeaterless transmission distance of 80-100km, which meets the interconnection needs of multiple hospital areas and medical alliances.
[0030] This embodiment implements three levels of redundancy: device-level, link-level, and data center-level. Device-level redundancy: Both core and aggregation switches are configured with 1+1 redundant main controllers, 1+1 redundant power supplies, and multiple sets of redundant switching network boards. In the event of a single main controller or power supply failure, the backup unit automatically takes over within 50ms, ensuring the entire device remains operational. Link-level redundancy: All backbone links between the core and aggregation layers, and between the aggregation and access layers, are deployed with two independent fiber optic routes (in different cable trays and different low-voltage wells). Link ports are configured with LACP link aggregation and a fast switching protocol. After the primary link is interrupted, services automatically switch to the backup link with a switching time of less than 50ms, ensuring seamless service operation. Data center-level redundancy: The dual-active core data centers in Buildings E and A achieve real-time data synchronization via fiber optic links. The disaster recovery data center in Building D is connected to the dual-active core data centers via fiber optic links for asynchronous backup. When one core data center fails entirely, all network services automatically migrate to the other core data center. When both dual-active data centers fail, the disaster recovery data center takes over the entire network, ensuring uninterrupted core medical services.
[0031] The core and aggregation room switches are powered by dual municipal mains power and UPS uninterruptible power supply, with each power supply having an independent circuit, ensuring seamless power replenishment after one circuit fails. The floor-level all-optical aggregation switches are powered by local UPS centralized power supply. End-point access switches and low-power medical IoT terminals, such as bedside call terminals, environmental sensors, security cameras, and access control card readers, do not have separate high-voltage power lines. Instead, they are remotely powered by PoE++ fiber optic composite cables conforming to the IEEE 802.3bt standard, with unified power supply from the upper-level all-optical aggregation switches. This eliminates the need for local power adapters for network equipment, reduces disturbance from high-voltage power construction, and meets the management requirements of sterile environments such as operating rooms and ICUs. Core diagnostic and treatment equipment continues to be powered independently by the hospital's medical isolation power supply.
[0032] All-optical physical hard isolation is achieved through optical channel wavelength division multiplexing (OSM). Within a single optical fiber, four independent optical wavelength channels are divided using wavelength division multiplexing: channel 1 carries internal network services, channel 2 carries external network services, channel 3 carries device control network services, and channel 4 carries security IoT services. Signals from different wavelength channels are physically independent, and any terminal device can only transmit data within its assigned wavelength channel, unable to access other network resources across channels. Based on this, and combined with security domain division, the entire network is divided into a DMZ zone, an external interconnection zone, a security management zone, and a comprehensive service zone, with each security domain bound to a corresponding optical wavelength channel. Firewalls and intrusion prevention devices are deployed at the boundaries of the security domains, forming a dual security system of "optical-layer physical isolation plus boundary security protection," fully meeting standard requirements.
[0033] The AI-powered intelligent operation and maintenance platform includes a time-series anomaly detection model and a fault classification neural network. For data collection, it gathers the following data from the entire network: optical power, link latency, packet loss rate, port bandwidth utilization, device CPU utilization, device temperature, terminal type, and service traffic characteristics (packet length, transmission frequency, protocol type). The collection nodes cover the entire link of core, aggregation, all-optical aggregation, and access switches, with a sampling frequency of 100ms / sample.
[0034] The AI-powered intelligent operation and maintenance platform adopts a two-layer structure: a time-series anomaly detection model and a fault classification neural network. The bottom-layer time-series model is based on an LSTM (Long Short-Term Memory) network, which analyzes time-series data such as optical power and latency to identify minute anomalies and jitter. The upper-layer classification model is based on a CNN (Convolutional Neural Network) to classify anomaly features and distinguish fault types such as optical connector faults, cable aging, equipment faults, and terminal faults.
[0035] The model training process is as follows: First, normal data and various fault samples (light decay, loose connectors, cable aging, equipment failure, etc.) from this hospital area and similar tertiary hospitals are collected, with a total sample size of no less than 100,000. Then, maintenance personnel label each fault sample with its corresponding fault type and location, forming a labeled training dataset. Subsequently, the training set, validation set, and test set are divided, and the time-series anomaly detection model and fault classification neural network are iteratively trained until the model's performance indicators on the validation set converge. After the system goes live, it continuously learns the environmental characteristics of this hospital area, such as the baseline of strong electromagnetic interference from MRI and CT scans, and incrementally learns and adaptively optimizes the existing model. The trained model has a fault warning accuracy rate of no less than 98% and a fault location accuracy rate of no less than 99%.
[0036] A typical fault handling process is as follows: data acquisition - AI analysis - anomaly warning - fault location - work order dispatch - on-site handling - status verification - closed-loop archiving. Specifically, when the optical power of the access switch experiences slight fluctuations, all-link acquisition nodes upload data to the AI platform in real time; the LSTM model identifies deviations in time-series data from the normal baseline, and the CNN classification determines it as a loose or contaminated optical connector; the system pops up an audible and visual warning, distinguishing between general and high-risk hazards; combined with topology data, it automatically locates the building, floor, low-voltage room, and specific port or optical connector, marking its physical location; the platform automatically generates a maintenance work order and pushes it to the corresponding maintenance personnel's mobile device, along with the fault cause, location, and handling instructions; the maintenance personnel clean or replace the LC optical connector according to the instructions; after repair, the optical power returns to normal, and the AI automatically retests to confirm the hazard has been eliminated; the work order is automatically completed, and the fault data is stored in the sample library for continuous model optimization.
[0037] The SDN centralized management and control platform connects to core switches, regional aggregation switches, all-optical aggregation switches, and scenario-specific access switches via control channels. It collects operational data from each switch and, based on feedback from the AI-powered intelligent operation and maintenance platform, uniformly distributes VLAN configuration, security policies, and QoS scheduling commands to each switch. Specifically, when the AI platform identifies an anomaly on a link or a surge in traffic for a certain type of service, it feeds back the identification and location results to the SDN platform, which then makes decisions and triggers policy adjustments accordingly.
[0038] The SDN centralized management and control platform also includes a service identification and dynamic scheduling module. It employs a traffic feature fingerprinting algorithm to pre-establish dedicated traffic fingerprint databases for PACS imaging, remote surgery, ICU monitoring, office internet access, and security monitoring. This database compares network-wide traffic characteristics in real time to automatically identify service types, priorities, and bandwidth requirements. Dynamic bandwidth allocation is then performed based on a weighted round-robin QoS scheduling algorithm and a congestion prediction algorithm. For priority weighting, remote surgery and vital sign data have the highest weight and are allocated a fixed 10G dedicated bandwidth first. Lower-priority traffic is automatically evicted when bandwidth resources are preempted. For congestion prediction, AI predicts peak traffic periods such as morning peaks, outpatient peaks, and nighttime consultations based on historical traffic curves, reserving bandwidth in advance for PACS and remote surgery. For link optimization, in multi-redundant link scenarios, the algorithm calculates link latency and packet loss rate in real time and automatically selects the optimal transmission path.
[0039] The secure access and multi-service platform integrates MAC address and IP binding, 802.1X authentication, AES-128 encryption, bastion host, log auditing, and vulnerability scanning. It supports a full range of services including data, voice, video, IoT, and ward calls, seamlessly connecting to medical information systems such as HIS, LIS, EMR, and PACS. The ZTP zero-configuration deployment module automatically distributes corresponding VLANs, security policies, and QoS rules to the SDN centralized management platform after terminal access, achieving plug-and-play functionality without manual configuration. When a new scenario-based access switch connects to the network for the first time, the ZTP zero-configuration deployment module automatically identifies the access location and preset deployment scenario of the new access switch, and automatically generates and distributes corresponding VLAN partitioning, security access policies, and QoS service quality rules according to the pre-configured policies.
[0040] Taking the PACS service in the radiology department of Building A outpatient medical technology building as an example, the complete deployment and service launch process is as follows: In the initial planning phase, a dedicated PACS VLAN (VLAN 100) is planned, configured with 10G dedicated bandwidth and the highest QoS priority, and assigned to the medical technology security domain. In the core equipment room configuration phase, VLAN 100 is created on the dual-core device of the core switch on the first floor of Building A, QoS priority and bandwidth reservation rules are configured, and security access policies are bound to prohibit unauthorized terminals from accessing the PACS server. In the aggregation layer configuration phase, the core distributes VLAN 100 and the policy to the outpatient aggregation switch in Building A, and the aggregation device completes port access and link bandwidth mapping. In the floor-level all-optical aggregation configuration phase, the floor-level all-optical aggregation switch receives the policy, allocates reserved bandwidth for the corresponding ports in the radiology department, and enables PoE power supply. In the end-user access configuration phase, the clinic access switch automatically synchronizes the upper-layer configuration; after the CT or MRI equipment in the clinic is connected to the power port, ZTP zero-configuration takes effect. In the service launch phase, after the terminal is powered on, it automatically connects to the network. AI identifies PACS service traffic, dynamically optimizes the transmission path, and enables high-speed uploading or retrieval of image data, and the service officially begins operation. During the operation and monitoring phase, the AI operation and maintenance platform monitors the optical power, latency, and bandwidth of the link in real time and automatically issues warnings for anomalies.
[0041] Tests have verified that the system in this embodiment achieves an end-to-end one-way latency of less than 0.5ms and a packet loss rate of less than 10%. -12 Each port boasts a dedicated 10Gbps symmetrical bandwidth. In equipment-level redundancy verification, simulating a core switch main control board failure, the backup main control board automatically takes over within 42ms. In link-level redundancy verification, simulating a primary fiber optic link interruption from the core to the aggregation point, services switch to the backup fiber optic link within 38ms. In data center-level redundancy verification, simulating a complete power outage in Building E's core data center, the dual-active core data center in Building A takes over all services in real time, with uninterrupted service during the switchover process. PACS image retrieval time is reduced by 90%, radiology image reading efficiency is improved by 40%, and the system's annual failure rate does not exceed 0.3%.
[0042] In summary, this embodiment can achieve end-to-end ultra-low latency, single-port 10 Gigabit symmetrical dedicated bandwidth, optical layer physical hard isolation, full-link redundancy and high reliability, and AI-driven intelligent operation and maintenance for large-scale tertiary hospital networks, significantly improving the security, reliability and intelligence level of medical networks.
Claims
1. An active Ethernet all-optical network intelligent control system for large tertiary hospitals, characterized in that: It includes a three-layer active Ethernet all-optical star-topology redundant hardware architecture, as well as an SDN centralized management and control platform and an AI intelligent operation and maintenance platform deployed on the hardware architecture and interacting with the hardware architecture. The hardware architecture consists of a core layer, an aggregation layer, and an access layer. The core layer and the aggregation layer, as well as the aggregation layer and the access layer, are directly connected point-to-point via 10 Gigabit single-mode optical fiber. The core layer includes a core switch, the aggregation layer includes regional aggregation switches, and the access layer includes all-optical aggregation switches deployed on each floor and scenario-specific access switches deployed at the end of each room. The all-optical aggregation switches and the scenario-specific access switches are connected via optical-electric composite cables. Furthermore, the optical fiber contains multiple independent optical wavelength channels, with different service networks occupying different wavelength channels to achieve physical hard isolation. The core layer is equipped with a dual-active core computer room and a disaster recovery core computer room. The core switch is configured with redundant main control, redundant power supply and redundant switching network board. The connection links between the core layer and the aggregation layer, and between the aggregation layer and the access layer are configured with two independent optical fiber routes, one for main and one for backup. The ports of the links are configured with link aggregation and fast switching protocols. The SDN centralized management and control platform is connected to the core switch, the regional aggregation switch, the all-optical aggregation switch and the scenario-based access switch through a control channel. It is used to collect the device operation data of each switch and transmit it to the AI intelligent operation and maintenance platform. Based on the feedback results of the AI intelligent operation and maintenance platform, it uniformly issues VLAN configuration, security policies and QoS scheduling instructions to each switch. The AI-powered intelligent operation and maintenance platform interfaces with the SDN centralized management and control platform to receive the device operation data collected by the SDN centralized management and control platform. The AI-powered intelligent operation and maintenance platform includes a time-series anomaly detection model and a fault classification neural network. The time-series anomaly detection model analyzes the device operation data based on an LSTM network to identify abnormal fluctuations. The fault classification neural network classifies abnormal features based on a CNN network to locate the fault type and location, and feeds back the identification and location results to the SDN centralized management and control platform. The SDN centralized management and control platform also includes a service identification and dynamic scheduling module. This module uses a traffic feature fingerprinting algorithm to pre-establish a dedicated traffic fingerprint database containing various medical service types. When the system is running, this module captures the network traffic in real time and compares it with the traffic fingerprint database to automatically identify the service type of the current traffic. Then, based on the weighted round-robin QoS scheduling algorithm, it assigns corresponding priority weights to different services and issues dynamic bandwidth allocation and adjustment QoS scheduling instructions to each switch accordingly.
2. The active Ethernet all-optical network intelligent control system for large tertiary hospitals according to claim 1, characterized in that, The dual-active core data centers achieve real-time data synchronization via fiber optic links, and the disaster recovery core data center is connected to the dual-active core data centers via fiber optic links for asynchronous data backup. When any core data center experiences a complete failure, all network services are automatically migrated to the other core data center. Among the two independent fiber optic routes, services run on the primary route during normal operation. When the primary route experiences a link interruption, the fast failover protocol detects the link failure and triggers the backup route in the link aggregation group to take over data transmission, thereby achieving automatic service switching.
3. The active Ethernet all-optical network intelligent control system for large tertiary hospitals according to claim 1 or 2, characterized in that, The AI intelligent operation and maintenance platform uses the following method for model training and optimization: First, it collects normal operation data of the entire hospital network and fault sample data under various known fault states. The normal operation data and fault sample data include optical power fluctuation data and medical service traffic burst data. Then, the operation and maintenance personnel label each type of fault sample with its corresponding fault type and fault location, forming a labeled training dataset. After dividing the training dataset into a training set, a validation set, and a test set, the time-series anomaly detection model and the fault classification neural network are iteratively trained until the model's performance indicators on the validation set converge. After the system is officially launched, the AI intelligent operation and maintenance platform continuously collects new data from actual operation and performs incremental learning and adaptive optimization on the existing model.
4. The active Ethernet all-optical network intelligent control system for large tertiary hospitals according to claim 1, characterized in that, The operation mode of the service identification and dynamic scheduling module is as follows: Features are extracted from traffic samples of various medical services in advance to establish a dedicated traffic fingerprint database including PACS imaging services, remote surgery services, ICU monitoring services, office internet access services, and security monitoring services. During system operation, the service identification and dynamic scheduling module captures the entire network traffic in real time and performs feature comparison. Based on the comparison results, it automatically identifies the service type of the current traffic and its required service quality level and bandwidth requirements. Then, based on a weighted round-robin QoS scheduling algorithm, it assigns corresponding priority weights to various services and combines a congestion prediction algorithm to predict peak traffic periods in advance, implementing dynamic bandwidth allocation and adjustment among various services. When allocating priority weights, the remote surgery service and vital sign monitoring service are assigned the highest priority weights.
5. The active Ethernet all-optical network intelligent control system for large tertiary hospitals according to claim 1, characterized in that, The scenario-based access switches are divided into several types according to different deployment scenarios: ward access switches, which are equipped with gigabit Ethernet ports and dual 10G optical ports for connecting bedside screens, call systems, and vital sign monitors in wards; medical imaging access switches, which are equipped with 10G bandwidth ports for connecting CT equipment, MRI equipment, and PACS imaging terminals; operating room and ICU access switches, which use industrial-grade hardware and are equipped with dual uplink redundant links to ensure uninterrupted data transmission of critical medical equipment in operating rooms and intensive care units; and security IoT access switches, which are equipped with PoE power supply ports for connecting video surveillance cameras, environmental sensors, and access control controllers.
6. The active Ethernet all-optical network intelligent control system for large tertiary hospitals according to claim 1, characterized in that, The SDN centralized management and control platform also includes a ZTP zero-configuration commissioning module, which works as follows: when a new scenario-based access switch connects to the network for the first time, the ZTP zero-configuration commissioning module automatically identifies the access location and preset deployment scenario of the new access scenario-based access switch, and automatically generates and distributes corresponding VLAN division, security access policy and QoS service quality rules for the new access scenario-based access switch according to the pre-configuration policy, so that the new access scenario-based access switch can complete the configuration and enter the normal working state without manual intervention.
7. The active Ethernet all-optical network intelligent control system for large tertiary hospitals according to claim 1, characterized in that, The all-optical aggregation switches are deployed in the low-voltage rooms on each floor. Each all-optical aggregation switch is responsible for aggregating the uplink traffic of all scenario-specific access switches in all rooms on its floor and providing PoE remote power supply to each scenario-specific access switch through an optical-electrical composite cable. The PoE remote power supply is provided uniformly by the upper-level all-optical aggregation switch through the power supply cable in the optical-electrical composite cable, powering the scenario-specific access switches themselves and the low-power active terminals connected to them, eliminating the need for local power adapters for network devices in the end rooms, and reducing the disturbance of high-voltage wiring construction to the sterile medical environment such as operating rooms and ICUs. The core diagnostic and treatment equipment in the operating rooms and ICUs are independently powered by the hospital's existing medical isolation power supply system.
8. The active Ethernet all-optical network intelligent control system for large tertiary hospitals according to claim 1, characterized in that, Both the core switch and the aggregation switch support multi-rate optical interfaces. These multi-rate optical interfaces can adaptively adapt to optical modules of different rates according to the link bandwidth requirements, enabling flexible upgrades to the link rate without replacing the switching equipment.
9. The active Ethernet all-optical network intelligent control system for large tertiary hospitals according to claim 1, characterized in that, The system adopts a zoned power supply system, including a three-level power supply architecture: Level 1, the switching equipment in the core computer room and aggregation computer room adopts a dual-path power supply method with dual municipal mains power input plus UPS uninterruptible power supply, and the two power supplies are hot backups of each other; Level 2, the all-optical aggregation switches in the weak current rooms on each floor adopt local UPS centralized power supply; Level 3, the scenario-based access switches at the end of each room and their downstream low-power active terminal equipment are all provided with the required network power by the upper-level all-optical aggregation switches through optical fiber composite cables, and the network equipment in the end rooms does not need to be separately laid with high-voltage power lines and power adapters.
10. The active Ethernet all-optical network intelligent control system for large tertiary hospitals according to claim 1, characterized in that, It also includes a security access and multi-service bearing platform, which integrates an access authentication module, a data encryption module, an operation and maintenance audit module, and a vulnerability scanning module. The access authentication module is used to authenticate and verify the permissions of terminal devices accessing the network. The data encryption module is used to encrypt and protect critical data transmitted over the network. The operation and maintenance audit module is used to record and trace all operation and maintenance operations. The vulnerability scanning module is used to periodically detect security vulnerabilities in all network devices.