Fire emergency wireless channel and packet sending adaptation method
Patent Information
- Application Number
- CN202611081288.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-21
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2046-07-21
AI Technical Summary
既有针对入网瞬间的有序化方法在时序上位于该难题之前,无法覆盖运行态策略切换、无法平滑网关侧的瞬时突发流量、也无法形成变更的可审计与可回滚闭环
1、通过运行状态信号到策略模式标识的映射以及在型号核准边界内的参数下发闭环,使信道、发射功率与发包行为能够在常态与应急态之间按工况差异化配置,在确警及市电切换等关键阶段能够获得更短的关键业务周期与更高的重试上限,同时避免在常态下长期维持高占空比,从而在工业无线共存场景下兼顾可靠性与空口资源利用效率。
Smart Images

Figure CN122602198B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular to an adaptive method for channel and packet transmission in fire emergency wireless communication. Background Technology
[0002] With the development of smart factories and large-scale warehousing and logistics, industrial wireless local area networks (WLANs) are commonly deployed in industrial sites for the scheduling of automated guided vehicles (AGVs) or autonomous mobile robots. These WLANs typically operate in the 2.4GHz and / or 5GHz frequency bands, leading to continuous or sudden high air interface occupancy in localized areas. Meanwhile, fire emergency lighting and evacuation guidance systems are increasingly adopting wireless networking to meet the needs of cabling flexibility and centralized monitoring. When the fire emergency wireless side uses a 2.4GHz wireless protocol, it overlaps with the spectrum of co-located industrial Wi-Fi networks, easily causing co-channel interference and air interface queuing delays.
[0003] To address the issue of orderly network entry during power switching in emergency wireless networks, a concurrent power-on logically ordered networking method has been developed. Upon detecting a main power failure and switching to backup battery power, each emergency node starts concurrently. A logical delay time is calculated based on the floor number and network role. During this logical delay time, the node maintains a silent wireless reception state. After the delay ends, network networking actions are executed sequentially to mitigate channel collisions caused by concentrated power-on. This method primarily solves the problem of orderly network entry within emergency private networks during power switching, effectively reducing the number of nodes simultaneously competing for channels.
[0004] However, the bottleneck in an industrial wireless coexistence environment is not limited to the moment of network access. Even if all nodes have completed orderly network access and are operating in a steady state, when the fire alarm level changes, mains power failure switches, or linkage triggers cause short-term centralized control and status reporting, the air interface load on the fire emergency wireless side may still increase sharply within seconds to minutes. This load overlaps with the usage of industrial Wi-Fi and other services on the same frequency band, resulting in increased latency, a surge in retransmissions, and individual nodes disconnecting from the network. If wireless parameters are not differentiated between normal and emergency states, either air interface and terminal energy will be unnecessarily consumed under normal conditions, or sufficient retry and timeliness guarantees will not be provided for key frames during critical stages such as alarm confirmation. Furthermore, adjustments to power and frequency that deviate from type approval and product compliance boundaries will bring regulatory and mutual interference risks. Meanwhile, parameters such as beacons, flow control, and access categories of industrial Wi-Fi within the factory primarily serve the energy-saving and throughput optimization of the Wi-Fi terminals themselves. Their adjustments cannot be equated to direct interference suppression of non-Wi-Fi emergency terminals such as Zigbee or Bluetooth Mesh. Therefore, a more feasible engineering approach is to reduce the overall competition intensity of the 2.4GHz band by combining emergency-side strategy shaping with gateway-side aggregation and peak shifting under the premise of compliance. This shaping process, in turn, requires the fire protection side to be able to sense the operating conditions and link status and adaptively adjust the channel, power, and packet transmission parameters accordingly.
[0005] The aforementioned contradictions thus form a core challenge that persists throughout the operational phase: on the one hand, the fire emergency gateway needs to make differentiated configurations of channels, power, and packet transmission behavior at the second or even sub-second level based on multi-source, asynchronous, and jittery operating condition signals such as alarm levels, power supply conditions, and maintenance tasks; on the other hand, every configuration change must be constrained within the compliance boundaries of model approval, within an auditable and traceable change process, and within the responsibility boundaries that do not intrude into the plant's industrial network protocol stack and scheduling logic. Existing orderly methods for the moment of network access are ahead of this challenge in terms of timing, and cannot cover operational policy switching, cannot smooth out instantaneous bursts of traffic on the gateway side, and cannot form an auditable and rollbackable closed loop for changes. Summary of the Invention
[0006] To address the need for second-level differentiated configuration of channel, power, and packet transmission behavior for fire emergency gateways in industrial wireless coexistence environments under multi-source jitter-prone signal conditions such as alarm levels, power supply status, and maintenance tasks, and to ensure that each configuration change is constrained within the type approval boundary, audit traceability, and without intruding into the responsibility boundary of the factory's industrial network, this application provides a channel and packet transmission adaptive method for fire emergency wireless.
[0007] This application provides a channel and packet transmission adaptive method for fire emergency wireless communication, which adopts the following technical solution: A channel and packet transmission adaptive method for fire emergency wireless communication includes the following steps: S1. Acquire operating status signals, which include at least one of fire alarm level signals, power supply status signals, and operation and maintenance task type signals; S2. According to the preset mapping rules, the operating status signal is mapped to the strategy mode identifier, and the corresponding strategy table entry is loaded from the non-volatile memory according to the strategy mode identifier. The strategy table entry includes at least the following fields: the working channel or channel candidate set limited within the frequency and power range allowed by the type approval certificate, the transmit power level, the polling or reporting cycle, the maximum number of retransmissions per frame, and whether downlink data aggregation is allowed. S3. Within the parameter range defined by the strategy table entries, send wireless configuration parameters to the fire emergency terminal so that the fire emergency terminal can perform transmission and retransmission according to the data packet transmission strategy. The data packet transmission strategy includes at least constraints on the polling or reporting period, the maximum number of retransmissions per frame, and the backoff parameters. S4. In response to the policy mode identifier corresponding to the emergency mode, aggregate control commands of at least two terminals within the same fire compartment, and / or distribute command queues of multiple fire compartments in a staggered manner according to the preset partition order and concurrency limit, so as to reduce the peak value of instantaneous wireless channel occupancy. S5. Record the policy table version number and the audit log for each policy switch. The audit log should include at least the switch time, the old policy mode identifier, the new policy mode identifier, and the trigger source.
[0008] By adopting the above technical solutions, the translation of fire service semantics to wireless air interface semantics is centrally carried by the policy mode identifier hub in the operational state. This allows the periodicity, power, retransmission, and aggregation policies between normal and emergency states to be switched once based on the operating condition signal within the discrete ranges permitted by the model approval. This avoids unnecessary occupation of air interface and terminal energy in normal state, and also avoids the inability to provide sufficient retry and timeliness guarantees for key frames during critical stages such as alarm confirmation. In emergency mode, the aggregation and staggered distribution on the gateway side reshape the pulsed centralized distribution into a smoother distribution on the time axis, reducing the probability of superposition and conflict with industrial Wi-Fi and other co-frequency systems in the same observation window in an industrial wireless coexistence environment. At the same time, a traceable change record is established for each policy switch using the policy table version number and audit log, enabling the operation and maintenance and information departments to locate the cause of the change and the responsible interface.
[0009] Optionally, S2 includes sub-steps S21-S23. S21. Debouncing the operating status signal: within the debouncing time window, multiple state transitions are merged into a single policy mode switching request. The length of the debouncing time window is jointly determined by the signal noise baseline and the frequency of the most recent policy switching. S22. In response to the simultaneous receipt of a fire alarm level signal and a power supply status signal, branch processing is performed according to the multi-source consistency state, and conflict events are written to the audit log when there is a multi-source conflict. S23. Based on the policy mode switching request, the mapping rules are executed, and the corresponding policy table entries are loaded. The signal noise baseline is obtained from the statistics of the operating status signal transitions, and the frequency of the most recent policy switching is obtained from the statistics of the audit log. The higher the signal noise baseline, the longer the debouncing time window; the higher the frequency of the most recent policy switching, the longer the debouncing time window. The branching process for the multi-source consistency state in S22 is as follows: In response to the fire alarm level signal and the power supply status signal being consistent for the same physical event within a preset time difference, the consistency result is used as the strategy mode switching request; in response to the fire alarm level signal and the power supply status signal conflicting for the same physical event within a preset time difference, one of the signals is used as the strategy mode switching request according to the preset source priority, and the conflict event is written to the audit log to trigger manual review; in response to the absence of one of the fire alarm level signal and the power supply status signal, the other signal independently supports the strategy mode switching request.
[0010] By adopting the above technical solutions, the de-jitter window is adaptive in both the noise baseline and the switching frequency, enabling the system to automatically extend the observation window to suppress ping-pong switching during periods of high signal spikes and periods of continuous operational instability. The three-state processing of multi-source consistency states retains the reliability of redundant observations while forcing conflict events into the audit chain, ensuring that the system behavior remains interpretable and traceable even under multi-source inconsistent boundary conditions.
[0011] Optionally, the mapping rules in S23 are constrained by the strategy mode transition state machine; in response to a strategy mode switching request pointing to a target strategy mode that does not belong to the set of reachable successor modes of the current strategy mode, an intermediate strategy mode is forcibly inserted, and the parameter change range of a single switch is limited according to the climb step size field in the strategy table entry; the strategy mode identifier corresponds to the emergency type mode, including the case where the strategy mode identifier corresponds to the alarm handling mode or the mains power abnormality mode. The strategy mode transition state machine sets the set of reachable successor modes between any two strategy modes; the intermediate strategy mode acts as a buffer for cross-level jumps, so that the switch from the current strategy mode to the target strategy mode is completed in stages through the intermediate strategy mode.
[0012] By adopting the above technical solutions, the intermediate buffer for cross-level jumps under state machine constraints and the climb step size field together make the parameter jump from normal to alarm smooth rather than step, significantly reducing the impact on the air interface caused by the instantaneous policy switching; at the same time, by explicitly establishing the inclusion relationship between emergency mode and lower-level mode, the triggering condition of the independent S4 can be correctly activated in both alarm handling mode and mains power abnormal mode.
[0013] Optionally, the loading of policy table entries in S2 adopts a double-buffered hot-switching method. Non-volatile memory simultaneously stores both the effective and candidate versions of the policy table entries. At the instruction boundary, the candidate version is atomically switched to the effective version. Within a preset observation window after the switch, the keyframe packet loss rate is collected. In response to the keyframe packet loss rate exceeding a preset rollback threshold, the system atomically switches back to the previous effective version of the policy table entry. The runtime state is not interrupted when atomically switching the candidate version to the effective version at the instruction boundary; the runtime state remains continuous when switching back to the previous effective version of the policy table entry, and the rollback event is written to the audit log.
[0014] By adopting the above technical solutions, double buffering and atomic switching of instruction boundaries ensure that policy changes do not interrupt the operation of fire emergency linkage. Using the key frame packet loss rate as the rollback observation criterion makes rollback independent of the start-stop binary state. When the new version policy deteriorates in the real air interface environment, it can be rolled back to the previous effective version in seconds, forming a closed loop of change risk control.
[0015] Optionally, S3 includes sub-steps S31-S33. S31. Divide the fields of the policy table entries into mandatory layer fields and optional layer fields. S32. Generate parameter delivery tasks based on the policy table entries; critical frames in the alarm handling mode enter the high-priority queue. S33. Before sending, read the terminal capability bitmap. If the fire emergency terminal does not support a field in the optional layer, downgrade the field before delivery; if the fire emergency terminal does not support any field in the mandatory layer, reject the handover. Mandatory layer fields include at least the polling or reporting cycle and the maximum number of retransmissions per frame; optional layer fields include at least the transmit power level and whether downlink data aggregation is allowed. In S32, the parameter delivery task is written to the sending queue, which includes a high-priority queue and a normal-priority queue. Non-critical status reports enter the normal-priority queue. In S33, the downgrade event is written to the audit log. When the handover is rejected, the previous valid version of the policy table entries is maintained, and a configuration incompatibility alarm is generated.
[0016] By adopting the above technical solutions, the field layering explicitly distinguishes between "the minimum guarantee that each terminal must perform" and "enhancements that can be downgraded according to capabilities" at the policy table level, so that degradation only occurs in the optional layer and does not dilute the minimum guarantee line of the solution; the combination of capability bitmap degradation closed loop and high and low priority queues enables the field to still be implemented when heterogeneous batch of lamps coexist, reducing the probability of hidden failures where configuration is successful but the terminal cannot perform.
[0017] Optionally, S4 includes sub-steps S41-S43. S41. Mark the latest delivery timestamp for each terminal control command within the same fire compartment, and divide the terminal control commands into commands to be included in the aggregation batch and commands reserved for single-frame transmission based on the latest delivery timestamp. S42. Set a maximum waiting time limit and a maximum batch size limit for each aggregation batch, and trigger the aggregation batch transmission when either limit is reached. S43. Traverse the command queues of multiple fire compartments according to a preset partitioning order and count the number of fire compartments being processed in parallel, and suspend the command queue for new fire compartments when the number of fire compartments being processed in parallel reaches the concurrency limit. In S41, terminal control instructions within the same fire compartment are first classified according to instruction type. Instructions included in the aggregation batch are terminal control instructions that allow delayed batch delivery and whose current time is greater than the preset margin of the latest delivery timestamp. Instructions reserved for single-frame transmission are terminal control instructions that require low-latency individual delivery and terminal control instructions whose current time is less than the preset margin of the latest delivery timestamp. In S42, in response to the existence of terminal control instructions within the aggregation batch whose current time is less than the preset margin of the latest delivery timestamp, the aggregation batch transmission is triggered in advance.
[0018] By adopting the above technical solution, the latest delivery timestamp is introduced as a time dimension in the batch scheduling of aggregation, enabling the aggregator to automatically balance between "batch merging to reduce frame header overhead" and "avoiding key frame timeouts". The combination of partition sequential traversal and concurrency limit transforms the pulsed centralized distribution into restricted parallel and batch transmission, which works together with the random backoff mechanism on the wireless side to reduce the probability of collision.
[0019] Optionally, S42 further includes: statistically analyzing the distribution ratio of trigger causes for aggregated batches; and, in response to the distribution ratio of trigger causes meeting preset feedback trigger conditions, feeding back to the strategy table entries in S2 and adjusting at least one of the polling or reporting cycle and the maximum waiting time limit by a single-level step adjustment. The feedback trigger conditions include: tightening the polling or reporting cycle when the proportion of the maximum batch size limit reaches a preset saturation threshold; extending the maximum waiting time limit when the proportion of the maximum waiting time limit reaches a preset idle threshold; and entering a preset feedback cooling-off period after each single-level step adjustment, during which further feedback adjustments to the strategy table entries are prohibited.
[0020] By adopting the above technical solution, using the second-order statistic of the distribution ratio of triggering causes as feedback input, the rhythm of the aggregator can affect the periodic fields at the S2 strategy table level across steps, forming a closed loop of "aggregation observation → strategy adjustment → issuance of rhythm change"; the single-level step constraint and the feedback cooling period together prevent the closed loop from entering oscillation, so that the feedback adjustment has both responsiveness and does not destroy the stability of the strategy.
[0021] Optionally, the concurrency limit in S43 is characterized by a dynamic concurrency limit parameter. This parameter is jointly calculated from the interference score, policy mode identifier, and the frequency of the most recent policy switch, and is calculated independently for each fire zone, taking values within the upper and lower bounds defined by the policy table entries. The interference score is calculated by energy sampling of a preset channel set in the 2.4GHz band. The joint calculation of the dynamic concurrency limit parameter causes it to decrease as the interference score increases and as the frequency of the most recent policy switch increases, with the upper limit being higher in the alarm handling mode than in the normal mode; calculation results exceeding the upper and lower bounds are truncated according to the upper and lower bounds.
[0022] By adopting the above technical solution, the concurrency limit is transformed from a static configuration to a dynamic quantity calculated jointly by three sources, so that the partition-level concurrency budget can simultaneously reflect external spectrum occupancy, current business mode and internal system stability. Under upper and lower bound constraints, it retains the ability to respond to sudden operating conditions without degenerating into an unbounded feedback loop.
[0023] Optionally, the steps following S3 include: Statistically analyzing link feedback indicators for each fire emergency terminal; in response to a fire emergency terminal's link feedback indicator falling below a preset individual degradation threshold and not indicating global link deterioration, issuing individual degradation parameters only to that fire emergency terminal, without triggering a global switch of the strategy mode identifier; when the preset capability renegotiation window arrives, rereading the terminal capability bitmap for fire emergency terminals in individual degradation state, and deactivating the individual degradation state when the link feedback indicator recovers to above the preset individual degradation threshold. Link feedback indicators include the confirmation success rate within the continuous observation window, which is statistically obtained from the confirmation feedback of the fire emergency terminal regarding the issued parameter issuance task; individual degradation parameters include increasing the maximum number of retransmissions per frame and reducing the transmission power level to a steady-state level; the determination of non-global link deterioration is based on comparing the link feedback indicators of other fire emergency terminals within the same fire compartment to confirm asynchronous deterioration; the arrival condition of the capability renegotiation window includes triggering the next strategy table entry switch.
[0024] By adopting the above technical solution, the global policy switching and individual link response are orthogonalized, so that the degradation of a single terminal caused by local occlusion or individual interference will not trigger parameter changes of all terminals, thus avoiding paying the price for individual anomalies at the cost of global degradation; at the same time, a recovery path is set for the degradation state through the renegotiation window to prevent the individual degradation state from being permanently frozen.
[0025] Optionally, during the execution of S3, the method further includes performing interference assessment on the 2.4GHz band and outputting the assessment results to the in-plant wireless controller or network management platform via the northbound interface. Specifically, this includes: performing energy sampling on a preset channel set. The timing of energy sampling includes passive observation periods and active scanning periods. The passive observation period is entered when the gap window for no uplink data transmission from the fire emergency terminal arrives. The active scanning period is entered to supplement energy sampling when the cumulative number of samples during the passive observation period is insufficient to meet a preset sample size threshold. The active scanning period is entered during a preset low-traffic period. The interference score is calculated based on the energy sampling and compared with the historical baseline. An interference alarm is generated when the interference score of a certain channel is continuously higher than a preset alarm threshold. Several channels with lower interference scores are arranged into a suggested channel list and output through the northbound interface according to the semantic level output by the northbound interface. The semantic level output by the northbound interface includes three levels: score and alarm level only, suggested channel list level, and suggested power adjustment level. The output of any semantic level by the northbound interface does not carry the scheduling task data of the automated guided vehicle.
[0026] By adopting the above technical solutions, the time-division multiplexing of passive observation and active scanning ensures that interference assessment does not occupy additional air interface space during most periods, avoiding the observer effect from significantly raising the self-interference baseline; the three-level semantic classification of the northbound interface physically isolates the fire-fighting side's suggestion information from the plant's industrial network's scheduling task data at the interface level, achieving collaborative governance of spectrum contention without intruding into the automated guided vehicle scheduling system's protocol stack.
[0027] Optionally, the fire emergency gateway can obtain statistical information on the channel utilization or retransmission rate of the industrial wireless access point through the Ethernet side read-only interface, and use the statistical information as an auxiliary criterion in the mapping rules; in response to the unavailability of the read-only interface, the mapping rules can still work based solely on the operating status signal and energy sampling results.
[0028] By adopting the above technical solution, the statistical information from the industrial network side is introduced as an auxiliary input for the mapping rules through read-only bypass, which enriches the decision dimensions of policy switching without issuing any control commands; the fallback path when the read-only interface is unavailable ensures the independent availability of the method.
[0029] Optionally, in response to the number of consecutive wireless link failures exceeding a preset security degradation threshold, the fire emergency gateway enters a security degradation mode, suspends the issuance of non-critical configurations, and retains only the minimum status reporting or alarm reporting; the entry and exit of the security degradation mode are both written to the audit log.
[0030] By adopting the above technical solution, non-critical transmissions can be proactively abandoned when the link has deteriorated to the point where it is no longer suitable for the transmission strategy. This avoids adding extra air interface burden to the deteriorated link and frees up resource space for the recovery of the deteriorated link.
[0031] Optionally, the operation and maintenance task type signal is used to switch the policy mode identifier to maintenance mode. In maintenance mode, the policy table entries will set the polling cycle to be relatively longer, disable or restrict downlink aggregation, and reduce the frequency of unnecessary interference scanning. After maintenance is completed, it will automatically return to normal mode or be remapped according to the fire control panel signal.
[0032] By adopting the above technical solutions, the disturbance to the production wireless environment is explicitly reduced in operation and maintenance scenarios such as annual inspection and batch parameter distribution, and the operation and maintenance operations are prevented from being misinterpreted as emergency events that trigger high duty cycle strategies.
[0033] Optionally, the internal maintenance of the fire emergency gateway includes a finite state machine encompassing normal operation status, early warning monitoring status, confirmed alarm handling status, mains power abnormality status, and maintenance mode status. The state transition condition is triggered by at least one of the following: operating status signal, manual operation and maintenance command, and local detection results. Each state transition triggers an audit log recording.
[0034] By adopting the above technical solution, the service status on the gateway side is explicitly managed as a finite state machine, so that every state transition is accompanied by the mandatory recording of audit logs, avoiding the occurrence of implicit state changes that are not recorded.
[0035] Optionally, the policy table file is digitally signed before it is published to the fire emergency gateway; the fire emergency gateway verifies the digital signature when loading the policy table file, and refuses to switch and maintains the policy table entries of the previous valid version in response to verification failure.
[0036] By adopting the above technical solution, signature verification is introduced into the policy table file as a pre-loading condition, so that policy tables that have not passed the signature cannot enter the effective slot, thus preventing unauthorized policy changes from bypassing the change control process.
[0037] Optionally, a differentiated strategy can be adopted for key frames and ordinary heartbeat frames. Key frames enter the high-priority queue and are allowed shorter retransmission intervals in the alarm handling mode. Heartbeat frames are down-frequency or merged and sent in the alarm handling mode, so that air interface resources are given to linkage and indication refresh.
[0038] By adopting the above technical solution, the critical frame and the heartbeat frame are differentiated according to the business semantics, so that the critical direction indication and control frames can obtain a faster retry rhythm in the alarm confirmation stage, while the non-business critical heartbeat frame actively gives up air interface resources for it.
[0039] Optionally, after the fire emergency terminal completes the concurrent power-on logical sequencing networking of the emergency lighting wireless system and enters the operating state, it executes S1 to S5. The concurrent power-on logical sequencing networking includes: under the condition of detecting a main power failure and switching to backup battery power, calculating the logical delay time based on the floor number and network role, maintaining a silent wireless reception state during the logical delay time, and performing network networking actions after the logical delay time ends.
[0040] By adopting the above technical solution, the orderly network access mechanism and the adaptive operational strategy mechanism are linked in sequence. The former solves the problem of "who connects first" during power switching, while the latter solves the problem of "how to coexist with other networks in the long term after access". When the two are deployed together, the logical boundaries are clear and they do not replace each other.
[0041] Optionally, different fire zones can be assigned different transmission power levels based on their physical distance from the industrial wireless access point or the degree of co-frequency overlap. Within the upper limit of the type approval, different fire zones can be independently configured with transmission power levels. Fire zones with closer physical distance or higher degree of co-frequency overlap can use relatively lower transmission power levels and relatively higher maximum number of retransmissions per frame.
[0042] By adopting the above technical solution, power and retransmission are spatially differentiated at the partition granularity, so that hot spot partitions reduce radiation to obtain retransmission redundancy, and cold spot partitions increase radiation to obtain fewer retries, thus making a fine-grained partition-level response to the coexistence environment within the type approval boundary.
[0043] Optionally, in an embodiment of multi-gateway collaborative deployment, adjacent fire emergency gateways exchange current policy mode identifiers, dynamic concurrency limit parameters, and interference scores through a northbound link. In response to adjacent fire emergency gateways simultaneously entering emergency mode, they coordinate to share the concurrency budget, ensuring that the sum of the number of parallel processes in adjacent partitions does not exceed the shared concurrency budget limit.
[0044] By adopting the above technical solution, the partition-level concurrent budget is extended to the super-system level, avoiding the superposition and conflict at the air interface when physically adjacent fire compartments reach their respective dynamic concurrent upper limit parameters at the same time. This is suitable for engineering scenarios where multiple fire emergency gateways are deployed in large factories according to fire compartments.
[0045] In summary, this application includes at least one of the following beneficial technical effects: 1. By mapping the operating status signal to the strategy mode identifier and the parameter distribution closed loop within the type approval boundary, the channel, transmit power and packet transmission behavior can be configured differently according to the working conditions between normal and emergency states. In critical stages such as alarm confirmation and mains power switching, a shorter critical service cycle and a higher retry limit can be obtained. At the same time, it avoids maintaining a high duty cycle for a long time under normal conditions, thus balancing reliability and air interface resource utilization efficiency in industrial wireless coexistence scenarios.
[0046] 2. By aggregating downlink data on the gateway side, distributing data in partitioned areas, and using dual-buffer hot switching in conjunction with key frame packet loss rate rollback, terminal capability bitmap downgrade, and versioned management of audit logs, the shaping, downgrading, and tracing of policy changes are closed into an auditable process, enabling the change process to have second-level rollback capability and still be implemented in the field where heterogeneous batches of lighting fixtures coexist.
[0047] 3. By superimposing mechanisms such as phased climbing under state machine constraints, joint adaptive debouncing window and switching frequency, cross-step feedback of batch trigger cause distribution ratio, dynamic concurrency limit of three sources, and individual degradation of link feedback, the system maintains policy stability and business continuity under boundary conditions such as multi-source jitter, heterogeneous terminal capability differences, and local link deterioration. Furthermore, it supports coexistence governance without intruding on the industrial network scheduling system through three-level semantic classification of the northbound interface. Attached Figure Description
[0048] Figure 1 A flowchart illustrating a channel and packet transmission adaptive method for fire emergency wireless according to an embodiment of this application is shown.
[0049] Figure 2 The following is a timing diagram illustrating S4 cross-regional peak shifting and aggregation scheduling in one embodiment of this application. Detailed Implementation
[0050] The present application will be further described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are merely illustrative of the application and are not intended to limit the scope of the application.
[0051] This application provides a channel and packet transmission adaptive method for fire emergency wireless communication, referring to... Figure 1 This includes steps S1-S5. Each step is explained in detail below.
[0052] For ease of description, the composition and terminology of the fire emergency wireless system in this application embodiment are defined as follows. The fire emergency gateway is a gateway device deployed on the industrial plant side, connecting the fire alarm control panel and the fire emergency terminal, and includes a processor, non-volatile memory, a wireless interface, a northbound interface, and an input interface. The fire emergency terminal is at least one of emergency lighting fixtures and evacuation indicator signs using a 2.4GHz frequency band wireless protocol, typically Zigbee or Bluetooth Mesh. The terminal capability bitmap is reported by the terminal during the network access phase. The policy table entries are a set of parameters that translate fire service semantics (alarm level, power supply status, maintenance tasks) into a combination of parameters executable by the wireless air interface. Fields include the working channel or channel candidate set, transmit power level, polling or reporting cycle, maximum retransmission count per frame, and whether downlink data aggregation is allowed. The strategy mode identifier is an enumeration of entries in the corresponding strategy table. Typical values include normal mode, early warning and attention mode, alarm confirmation and handling mode, mains power anomaly mode, and maintenance mode. Emergency modes are a higher-level set, which includes two lower-level modes: alarm confirmation and handling mode and mains power anomaly mode. Industrial wireless coexistence environment refers to a deployment environment in a factory where fire emergency wireless and industrial Wi-Fi access points share the same or adjacent frequencies in the 2.4GHz band.
[0053] The following uses a large electronics manufacturing plant as the baseline scenario throughout the text. The plant is divided into five fire compartments according to its architectural design, numbered Z1 to Z5. Z1 is the compartment traversed by critical evacuation routes, Z2 and Z3 are adjacent compartments on the same floor, and Z4 and Z5 are secondary compartments. Industrial wireless access points for automated guided vehicle (AGV) dispatching are deployed co-located within the plant, operating in the 2.4GHz band. Fire emergency lighting and evacuation signs use the 2.4GHz band Zigbee protocol to wirelessly access the fire emergency gateway. The baseline triggering scenario is: the fire alarm signal transitions from a warning level to a confirmed alarm level at a certain moment, simultaneously experiencing a mains power failure, and the power supply status signal switches to backup battery power. Subsequent numerical examples all follow this baseline scenario. First, S1 acquires the operating status signal as input for subsequent processes.
[0054] S1. Acquire operating status signals, which include at least one of fire alarm level signals, power supply status signals, and operation and maintenance task type signals.
[0055] The operational status signals consist of three independent sources. The fire alarm level signal originates from the service enumeration values transmitted from the fire alarm control panel via the fire protection network or fieldbus; typical values are normal, warning alert, and confirmed alarm. The power supply status signal originates from the status values of the fire emergency gateway's self-test circuit or the dry contacts of the distribution box; typical values are normal mains power, abnormal mains power - backup power supply, and low battery voltage. The maintenance task type signal originates from the maintenance terminal or manual command input; typical values are no task, annual inspection, batch parameter issuance, and single-unit maintenance.
[0056] Three types of operational status signals enter the fire emergency gateway via the input interface. Fire alarm level signals and power supply status signals arrive via push notifications, without relying on active polling on the gateway side; maintenance task type signals are triggered manually or issued by the maintenance platform. Once inside the gateway, the three types of signals are converted into a unified enumeration value for use by the S2 mapping rules.
[0057] S1 does not impose any temporal constraints on the arrival order of the three types of signals. The three types of signals can arrive in any combination, such as only the fire alarm level signal arriving, only the power supply status signal arriving, the fire alarm level signal and the power supply status signal arriving simultaneously, or the three types of signals arriving sequentially. S1 can initiate the subsequent process under any combination, without requiring all three types of signals to be present simultaneously. When only one type of signal arrives, the mapping rule in subsequent S2 is based solely on that arriving signal. When multiple types of signals arrive, the sub-step S22 of S2 performs branch processing for the multi-source consistency state.
[0058] S2. According to the preset mapping rules, the operating status signal is mapped to the strategy mode identifier, and the corresponding strategy table entry is loaded from the non-volatile memory according to the strategy mode identifier. The strategy table entry includes at least the following fields: the working channel or channel candidate set limited within the frequency and power range allowed by the type approval certificate, the transmit power level, the polling or reporting cycle, the maximum number of retransmissions per frame, and whether downlink data aggregation is allowed.
[0059] The typical values for the strategy mode identifier are: Normal Mode, Early Warning and Attention Mode, Alarm Response Mode, Mains Power Anomaly Mode, and Maintenance Mode. Each strategy mode identifier corresponds to a strategy table entry, which is pre-configured by engineers based on the fire emergency gateway's type approval certificate and burned into non-volatile memory. The range of values for the working channel or channel candidate set is limited to the frequency range allowed by the type approval certificate, and the range of values for the transmit power level is limited to the power range allowed by the type approval certificate. Field values exceeding the type approval boundaries are strictly prohibited from being issued.
[0060] The mapping rules define the correspondence between operating status signals and policy mode identifiers. Following the baseline scenario, the preset mapping rules map the policy mode identifier to the confirmed alarm handling mode when a fire alarm level signal transitions to a confirmed alarm level; simultaneously, when a power supply status signal switches to mains power anomaly-backup power supply, the policy mode identifier is mapped to the mains power anomaly mode. When two signals arrive simultaneously and point to different lower-level modes, the final policy mode switching request is determined by the multi-source consistency state branch processing of S22.
[0061] The field values of the policy table entries are configured differently depending on the policy mode identifier. For example, in normal mode, the polling or reporting cycle is 30 seconds, the maximum number of retransmissions per frame is 3, the transmit power level is P2, and the downlink data aggregation field is enabled; in alarm handling mode, the polling or reporting cycle is 2 seconds, the maximum number of retransmissions per frame is 6, the transmit power level is P3 and within the type approval limit, and the downlink data aggregation field is disabled.
[0062] In some embodiments, the fire emergency gateway internally maintains a finite state machine encompassing normal operation, early warning monitoring, alarm handling, mains power anomaly, and maintenance mode states. State transitions are triggered by at least one of the following: operating status signals, manual maintenance commands, and local detection results. Each state transition triggers an audit log recording. By maintaining the finite state machine, the fire emergency gateway can explicitly manage service states, ensuring that each state transition is accompanied by mandatory audit log recording, thus preventing unrecorded implicit state changes.
[0063] If a lookup fails during the policy table entry loading process, for example, if the policy table entry corresponding to the current policy mode identifier does not exist in the non-volatile memory, the fire emergency gateway maintains the policy table entry of the previous valid version and generates a lookup failure alarm, which is reported via the northbound interface. This fallback mechanism ensures that the mapping rules will not cause the fire emergency gateway to enter a state where no policy can be executed, even under abnormal configuration conditions. The specific sub-steps S21-S23 of S2 will be detailed later.
[0064] Specifically, S2 includes sub-steps S21-S23.
[0065] S21. Perform de-jitter processing on the running status signal, and merge multiple state transitions into one policy mode switching request within the de-jitter time window. The length of the de-jitter time window is jointly determined by the signal noise baseline and the frequency of the most recent policy switching.
[0066] The length of the dejittering time window increases with the rise in signal-to-noise baseline and the frequency of recent policy switching. The signal-to-noise baseline is obtained by statistically analyzing the transitions of the operating status signal over a statistical period, such as the number of transitions of the fire alarm level signal in the last 5 minutes; a higher number of transitions indicates a higher signal-to-noise baseline. The frequency of recent policy switching is obtained by statistically analyzing the audit logs, such as the number of policy mode switchings in the last 10 minutes; a higher number of switchings indicates a higher frequency of recent policy switching. Following the baseline scenario, if the signal is stable recently and the last policy switching occurred more than 8 minutes ago, the dejittering time window is 50ms; if the on-site noise is high and 3 switchings have occurred in the last 10 minutes, the dejittering time window is extended to 200ms. Within the dejittering time window, if the fire alarm level signal undergoes multiple transitions, only the stable state at the end of the dejittering time window is used as the basis for the policy mode switching request; intermediate transitions within the window are merged and absorbed, without triggering multiple policy mode switchings.
[0067] S22. In response to receiving both the fire alarm level signal and the power supply status signal simultaneously, perform branch processing according to the multi-source consistency state, and write the conflict event to the audit log when there is a multi-source conflict.
[0068] The branching process for multi-source consistent states is specifically divided into three cases.
[0069] Scenario 1 is consistency. In response to the fire alarm level signal and the power supply status signal being consistent for the same physical event within a preset time difference, that is, the fire alarm level signal transitions to a confirmed alarm and the power supply status signal switches to a mains power abnormality, and the arrival time difference between the two signals is less than the preset time difference of 1 second, it is determined that the two signals correspond to the same physical event, namely the confirmed alarm linkage mains power switching event. This consistency result is used as the strategy mode switching request, and the strategy mode identifier request is set to the confirmed alarm handling mode.
[0070] Scenario 2 is a conflict. In response to a conflict between the fire alarm level signal and the power supply status signal regarding the same physical event within a preset time difference—for example, if the fire alarm level signal indicates a confirmed alarm while the power supply status signal still indicates normal mains power within the same time difference—then one of the signals will be used as the strategy mode switching request according to the preset source priority. The preset source priority places the fire alarm level signal before the power supply status signal; therefore, in the event of a conflict, the confirmed alarm handling mode corresponding to the fire alarm level signal will be used as the strategy mode switching request. Simultaneously, the conflict event will be written to the audit log to trigger manual review, allowing maintenance personnel to subsequently verify whether there were false alarms or communication link failures in the sources of the two signals.
[0071] Scenario 3 is a single-path missing signal. In response to the absence of either the fire alarm level signal or the power supply status signal—for example, if only the fire alarm level signal arrives while the power supply status signal remains unchanged (mains power is normal)—the arriving signal independently supports the strategy mode switching request. This scenario corresponds to a situation where only fire alarm linkage is triggered without triggering mains power switching.
[0072] S23. Execute the mapping rules based on the policy mode switching request and load the corresponding policy table entries.
[0073] S23 takes the strategy mode switching request after S21's jitter stabilization and the strategy mode switching request after S22's multi-source fusion as input, executes the mapping rules defined in S2, obtains the target strategy mode identifier, and loads the strategy table entry corresponding to the target strategy mode identifier from non-volatile memory. Continuing with the baseline scenario, the strategy table entry loaded by S23 is the strategy table entry corresponding to the alarm handling mode, with parameter values as described above—polling or reporting period 2s, maximum retransmission times per frame 6, transmit power level P3, and whether downlink data aggregation is allowed is prohibited. This strategy table entry serves as the basis for the S3 parameter issuance task.
[0074] In some embodiments, the operation and maintenance task type signal is used to switch the policy mode identifier to maintenance mode. In maintenance mode, the policy table entries set a relatively longer polling period, disable or limit downlink aggregation, and reduce unnecessary interference scanning frequency. After maintenance, the system automatically returns to normal mode or is remapped according to the fire alarm control panel signal. The polling period of maintenance mode can be set to 60 seconds or longer to reduce disturbance to the production wireless environment in operation and maintenance scenarios. The criterion for the end of maintenance can be based on returning to a no-task state based on the operation and maintenance task type signal or by the operation and maintenance platform explicitly issuing a maintenance end command.
[0075] In S23, the mapping rules are constrained by the policy mode transition state machine. This state machine sets a set of reachable successor modes between any two policy modes. In response to a policy mode switching request pointing to a target policy mode that does not belong to the current policy mode's reachable successor mode set, an intermediate policy mode is forcibly inserted as a buffer. The maximum variation in the polling or reporting cycle, transmit power level, and maximum retransmission count per frame during a single switch is limited by the climb step size field in the policy table entry, ensuring that the switch from the current policy mode to the target policy mode is completed in stages via the intermediate policy mode. The policy mode identifier corresponds to emergency response modes, including situations where the policy mode identifier corresponds to an alarm handling mode or a mains power anomaly mode.
[0076] The strategy pattern transition state machine consists of a set of nodes and a set of directed edges. The node set includes five strategy patterns: normal mode, early warning and attention mode, confirmed alarm handling mode, mains power anomaly mode, and maintenance mode. The set of directed edges represents the set of reachable successor patterns between any two strategy patterns. For example, the reachable successor pattern set for the normal mode is early warning and attention mode and maintenance mode; the reachable successor pattern set for the early warning and attention mode is normal mode, confirmed alarm handling mode, and mains power anomaly mode; the reachable successor pattern set for the confirmed alarm handling mode is early warning and attention mode and mains power anomaly mode; the reachable successor pattern set for the mains power anomaly mode is early warning and attention mode and confirmed alarm handling mode; and the reachable successor pattern set for the maintenance mode is normal mode. A direct jump from the normal mode to the confirmed alarm handling mode does not belong to the reachable successor pattern set of the normal mode.
[0077] Following the baseline scenario, the policy mode switching request received in S22 points to the alarm handling mode, while the current policy mode is the normal mode. The target policy mode, alarm handling mode, does not belong to the set of reachable successor modes of the current policy mode, normal mode. At this time, the intermediate policy mode, early warning attention mode, is forcibly inserted as a buffer, so that the switching path is executed in two stages: normal mode → early warning attention mode → alarm handling mode.
[0078] The climb step size field limits the maximum change in key parameters during a single switch. For example, the climb step size field for the polling or reporting cycle is set to tighten by a maximum of 15 seconds per level, the climb step size field for the transmit power level is set to increase by a maximum of one level per level, and the climb step size field for the maximum number of retransmissions per frame is set to increase by a maximum of two times per level. In the first stage of the switch from normal mode to early warning and attention mode, the polling or reporting cycle is tightened from 30 seconds to 15 seconds, with a single tightening of 15 seconds reaching the upper limit of the climb step size; the transmit power level is increased from P2 to P3; and the maximum number of retransmissions per frame increases from 3 to 5. In the second stage of the switch from early warning and attention mode to confirmed alarm handling mode, the polling or reporting cycle is tightened from 15 seconds to the target value of 2 seconds for confirmed alarm handling mode, with a single tightening of 13 seconds, which is within the upper limit of the climb step size; the transmit power level remains at P3; and the maximum number of retransmissions per frame increases from 5 to the target value of 6 times for confirmed alarm handling mode. Between two adjacent phases, the policy table entries of the intermediate policy mode warning and attention mode serve as the parameter basis for the buffer period. The buffer period can be configured from 1 second to 3 seconds, allowing the terminal side time to complete the distribution and activation of the parameters from the previous phase. The intermediate mode buffer ensures a smooth transition from normal to alert parameters rather than a step jump, reducing the impact on the wireless interface caused by the policy switch.
[0079] The above example uses the transition from normal mode to alarm response mode as an example. The state machine handles transitions between other strategy modes according to the same reachable successor relationship. In another example, the current strategy mode is the early warning and attention mode, and the strategy mode switching request points to the mains power anomaly mode. Since the mains power anomaly mode belongs to the reachable successor mode set of the early warning and attention mode, this transition is a same-level reachable transition, and no intermediate strategy mode needs to be inserted. The parameter switching is directly executed according to the strategy table entry of the mains power anomaly mode. As another example, the current strategy mode is the alarm response mode, the power supply status signal indicates that the mains power has been restored and the fire alarm level signal has fallen, and the strategy mode switching request points to the early warning and attention mode. Since the early warning and attention mode belongs to the reachable successor mode set of the alarm response mode, this transition is also a same-level reachable transition and is executed directly. For any strategy mode switching request, the state machine first determines whether the target strategy mode belongs to the reachable successor mode set of the current strategy mode. If it does, the transition is direct; otherwise, an intermediate strategy mode is forcibly inserted in stages as described above to complete the transition.
[0080] In this embodiment, the emergency response mode is a higher-level set, which includes two lower-level modes: alarm handling mode and mains power anomaly mode. The condition mentioned in S4, "responding to the strategy mode identifier corresponding to the emergency response mode," is true when the strategy mode identifier corresponds to either the alarm handling mode or the mains power anomaly mode; that is, the aggregation and peak shaving actions in S4 can be triggered and activated in both the alarm handling mode and the mains power anomaly mode, and the two lower-level modes do not distinguish in terms of aggregation and peak shaving logic.
[0081] The above describes one implementation of the mapping rule constraint in S23, which is to forcibly insert an intermediate strategy mode based on the strategy mode transition state machine and limit the single change range with a climb step size field. In other embodiments, the mapping rule can adopt a direct jump combined with parameter ramping—in response to a cross-level jump between the target strategy mode and the current strategy mode pointed to by the strategy mode switching request, without inserting an intermediate strategy mode, a linear interpolation ramp is performed on the key parameters between the strategy table entries of the target strategy mode and the strategy table entries of the current strategy mode, and intermediate parameter values are sent out multiple times according to a preset ramp duration, eventually reaching the parameters of the target strategy mode. This alternative method also achieves the purpose of making the parameter jump of the cross-level jump smooth, and is also an implementation of the mapping rule in S23.
[0082] In S2, the loading of policy table entries employs a double-buffered hot-switching method. The non-volatile memory simultaneously stores both the effective version and candidate versions of the policy table entries. In response to the release of a new version of the policy table entry, the new version is loaded as a candidate version into the non-volatile memory, and at the instruction boundary, the candidate version is atomically switched to the effective version without interrupting the runtime. Within a preset observation window after the switch, the keyframe packet loss rate is collected. The keyframe packet loss rate is the proportion of packets lost in the keyframes corresponding to the policy mode identifier within the preset observation window. The length of the preset observation window is bound to the policy mode identifier; the preset observation window for the alarm handling mode is shorter than that for the normal mode. In response to the keyframe packet loss rate exceeding a preset rollback threshold, at the instruction boundary, the effective version is atomically switched back to the previous effective version of the policy table entry, maintaining runtime continuity, and the rollback event is written to the audit log.
[0083] The non-volatile memory reserves three slots for policy table entries: the effective version slot, the candidate version slot, and the previous effective version slot. The effective version is the policy table entry version currently read by the task issued by the S3 parameter; the candidate version is the policy table entry version that has just been loaded and is waiting to be switched to take effect; the previous effective version is the policy table entry version that was previously the effective version, serving as a fallback for rollback. The roles of the three slots dynamically rotate with double-buffered hot-swapping—when a new version becomes a candidate version and is switched to the effective version, the original effective version is downgraded to the previous effective version.
[0084] The instruction boundary is the time point between two adjacent parameter issuance tasks, at which no fire emergency terminal configuration frames are being transmitted. Double-buffered hot-switching occurs at the instruction boundary, ensuring that frames already issued before the switch can complete, and frames starting after the switch read the new version of the policy table entries. Frames from the two phases are not mixed, and the running state is not interrupted. Atomic switching is completed by pointer flipping at the operating system level—the effective version pointer flips from pointing to slot A to pointing to slot B. This flipping action is completed within a single instruction, without any intermediate states.
[0085] The length of the preset observation window is bound to the strategy mode identifier, with different lengths corresponding to different strategy modes. Following the baseline scenario, the preset observation window for the normal mode is 30 seconds, while the preset observation window for the alarm handling mode is 5 seconds. The difference in window length reflects the timeliness requirements of different modes for observing keyframe packet loss rates. Specifically, the normal mode, with its lower business criticality, uses a longer window to obtain statistical smoothing, while the alarm handling mode, with its high business criticality, uses a shorter window to identify degradation as early as possible.
[0086] The keyframe packet loss rate is calculated as follows: Within a preset observation window, the number of keyframes sent by the fire emergency gateway (i.e., frames entering the high-priority queue) and the number of frames that did not receive confirmation feedback from the fire emergency terminal are counted. The latter is divided by the former to obtain the keyframe packet loss rate. For example, in the 5-second preset observation window after a policy table entry switch in the alarm handling mode, if the fire emergency gateway sends 20 keyframes to the Z1 partition, and 2 of them do not receive confirmation feedback, then the keyframe packet loss rate is 2 / 20 = 10%. The preset rollback threshold is 5%. If the keyframe packet loss rate exceeds the rollback threshold by 10%, a rollback operation is triggered. During rollback, the effective version pointer is flipped from pointing to the new version's slot atom back to pointing to the previous effective version's slot. The new version is downgraded to a candidate version, and the previous effective version is upgraded to the effective version. The rollback process also occurs at the instruction boundary, and the runtime state remains continuous. Rollback events are written to the audit log, which includes fields such as the rollback time, the version number of the new version policy table that was rolled back, the version number of the previous valid version policy table that took effect after the rollback, and the packet loss rate of the key frame that triggered the rollback.
[0087] In some embodiments, the policy table file is digitally signed before being published to the fire emergency gateway. The fire emergency gateway verifies the digital signature when loading the policy table file; if verification fails, it refuses to switch and maintains the policy table entries of the previous valid version. Digital signature verification serves as a precondition for loading, preventing policy table files that fail to pass the signature test from entering the candidate version slot. The rejection action upon verification failure and the rollback action when the keyframe packet loss rate exceeds the threshold form a two-layer change control—the former intercepts unauthorized changes during the loading phase, and the latter intercepts abnormal service changes during the activation phase.
[0088] The above describes one implementation of loading S2 policy table entries, namely, double-buffered hot-switching combined with keyframe packet loss rate observation. In other embodiments, loading S2 policy table entries can adopt a single-buffered pause method—that is, pausing the S3 parameter distribution task before loading the new version, directly overwriting the effective version slot with the new version, and restarting the S3 parameter distribution task after loading is complete. This alternative method does not require maintaining candidate version slots and is applicable in implementation scenarios with limited non-volatile memory capacity, but there is a short-term runtime pause; in policy table update scenarios where pause is acceptable, such as batch updates in maintenance mode, policy table entries can still be loaded, which is also an implementation method of loading policy table entries in S2.
[0089] S3. Within the parameter range defined by the strategy table entries, send wireless configuration parameters to the fire emergency terminal so that the fire emergency terminal can perform transmission and retransmission according to the data packet transmission strategy. The data packet transmission strategy includes at least constraints on the polling or reporting period, the maximum number of retransmissions per frame, and the backoff parameters.
[0090] The input to S3 is the policy table entry loaded by S2, and the output is a set of wireless configuration parameters sent to the fire emergency terminal and the frame transmission action executed by the fire emergency terminal according to the data packet transmission policy. S3 sends parameters within the parameter range defined by the policy table entry—that is, the sent parameter values must not exceed the value range of the corresponding field in the policy table entry, thereby ensuring that any sending action is within the type approval boundary.
[0091] Specifically, S3 includes sub-steps S31-S33.
[0092] S31. Divide the fields of the policy table entries into mandatory layer fields and optional layer fields. Mandatory layer fields shall include at least the polling or reporting period and the maximum number of retransmissions per frame, while optional layer fields shall include at least the transmit power level and whether downlink data aggregation is allowed.
[0093] The mandatory layer field corresponds to the minimum guarantee items that the fire emergency terminal must perform—regardless of the terminal model, as long as the terminal is connected to this fire emergency gateway, it must be able to execute the parameter combination specified by the mandatory layer field; the polling or reporting cycle determines the frequency of terminal status reporting, and the maximum number of retransmissions per frame determines the upper limit of retransmissions for a single service frame, both of which together determine the lower limit of service reachability. The optional layer field corresponds to enhancements that can be downgraded according to terminal capabilities—different models and batches of terminals may support different sets of transmit power levels or different downlink data aggregation capabilities, and the optional layer field allows for downgrade processing when the terminal does not support them.
[0094] S32. Generate parameter distribution tasks for fire emergency terminals based on the strategy table entries, and write the parameter distribution tasks into the sending queue. The sending queue includes a high-priority queue and a normal-priority queue. Key frames in the alarm handling mode enter the high-priority queue, and non-critical status reports enter the normal-priority queue.
[0095] The parameter delivery task includes the target terminal's terminal identifier, the field names and values to be delivered, and the task priority. The high-priority queue takes precedence over the normal-priority queue in the delivery scheduling process—when delivery resources are available, the scheduler first checks if the high-priority queue is empty; if not, it retrieves the task from the head of the queue and sends it; if the high-priority queue is empty, it then retrieves the task from the normal-priority queue and sends it. Following the baseline scenario, in the alarm handling mode, critical frames, such as instructions to increase the brightness of emergency lighting fixtures or to switch evacuation directions, enter the high-priority queue, maintaining a second-level response; non-critical status reports, such as terminal heartbeat or battery level reports, enter the normal-priority queue and are sent at a lower frequency when the high-priority queue is idle.
[0096] S33. Before sending, read the terminal capability bitmap. If the fire emergency terminal does not support a certain field in the optional layer fields, downgrade the corresponding field in the policy table entry to a compatible subset supported by the fire emergency terminal before sending it, and write the downgrade event to the audit log. If the fire emergency terminal does not support any field in the mandatory layer fields, reject this switch and maintain the policy table entry of the previous valid version, and generate a configuration incompatibility alarm.
[0097] The terminal capability bitmap is reported by the terminal and stored in non-volatile memory during the terminal's network access phase. It includes fields such as the supported transmit power level set, whether downlink data aggregation is supported, the minimum supported polling period, and the maximum supported retransmission count. Following the baseline scenario, let's assume there is a terminal T1 in partition Z1. Terminal T1's capability bitmap shows that its highest supported transmit power level is P2, its minimum supported polling period is 2 seconds, its maximum supported retransmission count is 8, and it supports downlink data aggregation. When S33 sends the policy table entry for the alarm handling mode to terminal T1, it finds that the policy table entry requires the transmit power level to be P3, while terminal T1 only supports up to P2. This field is an optional layer field, so a downgrade is performed, reducing the sent transmit power level from P3 to the highest level supported by terminal T1, P2. The downgrade event is written to the audit log, which includes at least the downgrade time, the terminal identifier of terminal T1, the original field value (P3), the downgraded field value (P2), and the downgrade reason "terminal does not support the original field value". The remaining mandatory layer fields (polling or reporting cycle of 2 seconds, maximum retransmissions per frame of 6 times) are all within the capability bitmap supported by terminal T1 and are sent normally.
[0098] In contrast, if another terminal's capability bitmap shows that it supports a maximum of only 4 retransmissions, while the policy table entry requires a maximum of 6 retransmissions per frame—this field is a mandatory layer field. The current switch will be rejected, and the previous valid version of the policy table entry will be maintained as the parameter basis for the terminal. At the same time, a configuration incompatibility alarm will be generated and reported via the northbound interface. The alarm content includes at least the alarm time, terminal identifier, incompatible field name, policy table entry required value, and terminal capability bitmap supported value. This will be handled by the operations and maintenance personnel afterward—for example, by replacing it with a terminal model that supports this field or customizing a policy table entry that matches the terminal model.
[0099] In some embodiments, a differentiated strategy is adopted for key frames and normal heartbeat frames. Key frames enter a high-priority queue and are allowed shorter retransmission intervals in alarm handling mode. Heartbeat frames are sent at a lower frequency or merged in alarm handling mode, freeing up air interface resources for linkage and indication refresh. For example, the retransmission interval of key frames in alarm handling mode can be set to 100ms, while the heartbeat frames are reduced from once every 30s in normal mode to once every 60s or merged into batch heartbeats, thereby increasing the proportion of time available for key frame transmission within the same air interface period.
[0100] Following S3, the following steps are included: For each fire emergency terminal, link feedback indicators are statistically analyzed. These indicators include the confirmation success rate within a continuous observation window, obtained from the confirmation feedback statistics of the fire emergency terminal regarding the issued parameter distribution tasks. In response to a fire emergency terminal's confirmation success rate falling below a preset individual degradation threshold, and a comparison with the link feedback indicators of other fire emergency terminals within the same fire compartment confirming non-global link degradation, individual degradation parameters are issued only to that fire emergency terminal. These parameters include increasing the maximum number of retransmissions per frame and reducing the transmit power level to a steady-state level. The issuance of individual degradation parameters does not trigger a global switch of the policy mode identifier, and the individual degradation event is written to the audit log. When the next policy table entry switch is triggered or the preset capability renegotiation window arrives, the terminal capability bitmap is reread for fire emergency terminals in an individual degradation state. In response to the link feedback indicators recovering to above the preset individual degradation threshold, the individual degradation state of that fire emergency terminal is lifted. The following provides a detailed explanation of these steps.
[0101] Link feedback metrics are maintained at the terminal level on the fire emergency gateway side. For each fire emergency terminal, the fire emergency gateway counts the number of times it confirms the parameter distribution task within a continuous observation window. Confirmation feedback is a confirmation frame sent by the fire emergency terminal after receiving the parameter distribution task; a confirmation frame arriving at the fire emergency gateway is considered a successful confirmation. Within the continuous observation window, the number of successful confirmations divided by the total number of parameter distribution tasks is the confirmation success rate of that terminal within that observation window. Based on the baseline scenario, the continuous observation window length can be set to 60 seconds, and the preset individual degradation threshold can be set to 75%.
[0102] Following the previous step, Z1 partition terminal T1, after the field downgrade issued by S33, operates normally at the downgraded P2 transmission power. However, after running in alarm handling mode for a period of time, due to the gathering of emergency evacuation crowds along key evacuation routes in Z1 partition, the physical location of terminal T1 is obscured by the crowds, and its confirmation success rate within the continuous observation window (60s) drops from 95% at the initial network access stage to 60%. The confirmation success rate of 60% is lower than the preset individual downgrade threshold of 75%, triggering the individual downgrade judgment process.
[0103] The individual degradation judgment process further executes the judgment of non-global link deterioration. The fire emergency gateway compares the confirmation success rate of other fire emergency terminals in Z1 zone, such as terminals T2, T3, and T4, within the same continuous observation window. If the confirmation success rates of terminals T2, T3, and T4 are 92%, 94%, and 90% respectively, all higher than the preset individual degradation threshold of 75%, it is judged as non-global link deterioration, that is, the overall link status of Z1 zone is normal, and only terminal T1 is abnormal.
[0104] At this time, the fire emergency gateway only issues individual degradation parameters to terminal T1. These parameters include increasing the maximum number of retransmissions per frame and reducing the transmit power level to the steady-state level. The maximum number of retransmissions per frame is increased from 6 to 8, which is still within the range supported by terminal T1's capability bitmap. The steady-state level refers to the power level at which the terminal operates stably over a long period, to avoid frequent high-power transmissions that accelerate battery consumption. The steady-state level value for the baseline scenario is reduced from P2 to P1. The individual degradation parameters only apply to terminal T1 and do not affect the parameters of other terminals in zone Z1 or other zones. The overall fire emergency system's strategy mode remains in the alarm handling mode, and no global switch occurs. Individual degradation events are written to the audit log, which includes at least the following fields: degradation time, terminal identifier of terminal T1, maximum number of retransmissions per frame before degradation (6), maximum number of retransmissions per frame after degradation (8), transmit power level before degradation (P2), transmit power level after degradation (P1), and degradation reason: "confirmation success rate is lower than the individual degradation threshold and not a global link deterioration".
[0105] If the comparison results show that the confirmation success rate of multiple terminals within partition Z1 is simultaneously below 75%—for example, the confirmation success rates of terminals T2, T3, and T4 are 65%, 68%, and 62%, respectively—then it is determined to be a global link degradation rather than an individual degradation situation. Global link degradation is not handled through individual degradation paths, but rather through subsequent S42 aggregation feedback or S43 dynamic concurrency limit parameters for global adjustment, avoiding the need to repeatedly send individual degradation parameters to each terminal and increase additional air interface overhead.
[0106] A preset capability renegotiation window is used to determine the recovery status of terminals in an individual degradation state. The arrival conditions for the capability renegotiation window include being triggered by the next policy table entry switch or arriving at a preset period, such as every 5 minutes. When the capability renegotiation window arrives, the fire emergency gateway rereads the confirmation success rate of terminal T1 in its most recent continuous observation window. For example, after the crowd evacuation is completed and the physical obstruction of terminal T1 is removed, if its confirmation success rate in the most recent 60-second continuous observation window recovers to 88%, which is higher than the preset individual degradation threshold of 75%, then the individual degradation state of terminal T1 is lifted, and its maximum number of retransmissions per frame and transmit power level are restored to the values limited by the policy table entry in the currently effective version (i.e., 6 times and P2 level). The event of lifting the individual degradation state is also written to the audit log.
[0107] In some embodiments, in response to the number of consecutive wireless link failures exceeding a preset security degradation threshold, the fire emergency gateway enters a security degradation mode, suspending the issuance of non-critical configurations and retaining only minimal status reporting or alarm reporting; both entry and exit from the security degradation mode are recorded in the audit log. The security degradation mode is activated when the link has deteriorated to the point where it is no longer suitable to issue complete policies, avoiding additional air interface burden on the deteriorated link and freeing up resource space for the recovery of the deteriorated link.
[0108] S4. In response to the policy mode identifier corresponding to the emergency mode, aggregate control commands for at least two terminals within the same fire compartment, and / or distribute command queues for multiple fire compartments in a staggered manner according to a preset partition order and concurrency limit, so as to reduce the peak value of instantaneous wireless channel occupancy.
[0109] The trigger condition for S4 is that the policy mode identifier corresponds to the emergency mode, that is, the policy mode identifier is the alarm handling mode or the mains power anomaly mode. Continuing with the baseline scenario, the policy table entry loaded by S2 corresponds to the alarm handling mode, and S4 is activated. S4 introduces two-dimensional shaping actions: in the time dimension, it performs intra-zone instruction aggregation, and in the spatial dimension, it performs cross-zone peak-shifting distribution. The two dimensions are executed in parallel or in combination to jointly reduce the instantaneous peak wireless channel occupancy.
[0110] Specifically, refer to Figure 2 S4 includes sub-steps S41-S43.
[0111] S41. Classify terminal control instructions within the same fire compartment according to instruction type, and mark the latest delivery timestamp for each terminal control instruction. Allow delayed batch delivery of terminal control instructions and the current time is greater than the preset margin of the latest delivery timestamp into aggregate batches. Reserve terminal control instructions that require low latency and individual delivery, as well as terminal control instructions that the current time is less than the preset margin of the latest delivery timestamp, as single-frame transmissions.
[0112] Terminal control commands are categorized into two types based on command type. Commands that allow for delayed batch delivery include those for adjusting lighting brightness, switching evacuation indicator colors, and querying heartbeats. The business semantics of these commands allow for delays of several hundred milliseconds without affecting fire emergency functions. Terminal control commands requiring low-latency, individual delivery include those for changing emergency evacuation directions, instantly turning on lighting, and resetting terminals. The business semantics of these commands require delivery to the terminal within seconds; delays may affect evacuation guidance effectiveness.
[0113] The latest delivery timestamp is overlaid by the business timeliness requirements at the time the instruction is generated. For example, the typical latest delivery timestamp for terminal control instructions that allow delayed batch delivery is the current time plus 500ms; the typical latest delivery timestamp for terminal control instructions that require low-latency individual delivery is the current time plus 100ms. The preset margin is typically 50ms, serving as a safety margin for batch aggregation triggering decisions.
[0114] Following the baseline scenario, the following are examples of terminal control commands generated within a single second in the Z1 partition: Command I1 (light brightness adjustment, latest delivery timestamp t+500ms), Command I2 (evacuation indicator color switching, latest delivery timestamp t+500ms), Command I3 (emergency evacuation direction switching, latest delivery timestamp t+100ms), Command I4 (heartbeat query, latest delivery timestamp t+500ms), and Command I5 (instant light activation, latest delivery timestamp t+100ms). Commands I1, I2, and I4 are batch-delivered commands that allow for delay; their latest delivery timestamps are all 500ms away (greater than the preset margin of 50ms), and they are grouped into the aggregated batch. Commands I3 and I5 are individual commands requiring low latency and are retained for single-frame transmission.
[0115] S42. Set a maximum waiting time limit and a maximum batch size limit for each aggregated batch. In response to the arrival of either the maximum waiting time limit or the maximum batch size limit, trigger the aggregated batch to be sent. In response to a terminal control command within the aggregated batch where the current time is less than the preset margin of the latest delivery timestamp, trigger the aggregated batch to be sent in advance.
[0116] The maximum waiting time limit and the maximum batch size limit are two hard constraints for each aggregation batch. For aggregation batch B1 (containing instructions I1, I2, and I4) following the aforementioned Z1 partition, the maximum waiting time limit is set to 300ms, and the maximum batch size limit is set to 8 instructions. Aggregation batch B1 begins aggregation at time t. If no other instructions are added within 300ms and the number of instructions in aggregation batch B1 remains at 3, then aggregation batch transmission is triggered at t+300ms (maximum waiting time limit reached). If instructions I6, I7… arrive consecutively in aggregation batch B1 at t+200ms, bringing the number of instructions to 8, then aggregation batch transmission is immediately triggered at that moment (maximum batch size limit reached).
[0117] The early trigger condition serves as a fallback constraint. If the latest delivery timestamp of a command within aggregate batch B1 falls below a preset margin of 50ms from the current time—for example, if the latest delivery timestamp of a command within aggregate batch B1 is t+500ms and the current time is t+450ms, the remaining 50ms has reached the threshold—then the aggregate batch is immediately triggered for transmission, without waiting for the maximum waiting time limit or the maximum batch size limit to be reached. The early trigger mechanism prioritizes ensuring that service frames do not time out when the aggregate batch approaches the hard boundary of timeliness, sacrificing the benefits of batch aggregation in exchange for the timeliness of critical frames.
[0118] S43. Traverse the instruction queues of multiple fire compartments in the preset partition order and count the number of fire compartments to be processed in parallel. In response to the number of fire compartments to be processed in parallel reaching the concurrency limit, suspend the instruction queue of the newly added fire compartment until a free parallel slot becomes available.
[0119] The preset partitioning order is a loop traversal sequence, cycling through Z1→Z2→Z3→Z4→Z5→Z1. The fire emergency gateway internally maintains a parallel processing slot counter to record the number of partitions currently executing commands. Based on the baseline scenario, the concurrency limit is set to 2—meaning a maximum of two fire compartments can process command issuances concurrently at any given time.
[0120] The scheduling process is illustrated below. Initially, partition Z1 enters the parallel processing slot first, with one firewall partition being processed in parallel. Subsequently, partition Z2 enters the parallel processing slot, with two firewall partitions being processed in parallel, reaching the concurrency limit. If partition Z3 has a new aggregation batch to send, its instruction queue is suspended, and it does not enter the parallel processing slot, waiting for an idle parallel slot to be released. When partition Z1 finishes sending its aggregation batch, partition Z1 exits the parallel processing slot, and the number of firewall partitions being processed in parallel drops to one. At this point, the suspended queue of partition Z3 is activated and enters the parallel processing slot, and the number of firewall partitions being processed in parallel rises back to two. This cycle repeats, ensuring that the number of firewall partitions being processed in parallel at any given time does not exceed the concurrency limit of two. The result of this staggered delivery is that the instruction delivery from multiple partitions presents staggered pulses on the timeline, rather than overlapping pulses at the same time, reducing the peak instantaneous wireless channel occupancy.
[0121] In some embodiments, different fire zones are assigned different transmit power levels based on their physical distance from the industrial wireless access point or the degree of co-frequency overlap. Within the type approval limit, transmit power levels are independently configured for different fire zones. Fire zones with closer physical distances or higher co-frequency overlap use relatively lower transmit power levels and relatively higher maximum retransmissions per frame. Continuing with the baseline scenario, zone Z1 is only 10m away from the industrial wireless access point and has a high degree of co-frequency overlap; therefore, zone Z1 is configured with a transmit power level of P2 and a maximum retransmission of 8 times per frame. Zone Z4 is 50m away from the industrial wireless access point and has a low degree of co-frequency overlap; therefore, zone Z4 is configured with a transmit power level of P3 and a maximum retransmission of 4 times per frame. This differentiated configuration allows hotspot zones to reduce radiation to gain retransmission redundancy, while coldspot zones can reduce radiation to gain fewer retries, providing a zone-level spatially differentiated response to the coexistence environment within the type approval boundary.
[0122] The above describes one implementation of S4 for intra-partition aggregation and cross-partition peak shifting, which is accomplished by a combination of aggregation batches, partition sequential traversal, and concurrency limit scheduling. In other embodiments, S4 aggregation and peak shifting can also adopt a single-path approach of aggregation without peak shifting or peak shifting without aggregation—that is, aggregation is only performed on instructions within the same partition while cross-partition concurrent transmission continues, or peak shifting is only performed on cross-partitions while instructions within the same partition are transmitted as single frames. This alternative approach can also reduce the instantaneous peak wireless channel occupancy in low instruction density scenarios where aggregation benefits are not significant or in small-scale partition scenarios with low concurrency pressure, and it also belongs to the implementation of S4.
[0123] Furthermore, S42 also includes: statistically analyzing the distribution ratio of triggering causes for aggregated batches within the most recent preset batch number for each fire compartment. Triggering causes include reaching the maximum waiting time limit and reaching the maximum batch size limit. In response to the proportion reaching the maximum batch size limit continuously exceeding a preset saturation threshold, feedback is sent to the strategy table entry in S2, tightening the polling or reporting cycle by one step within the adjustable range defined by the strategy table entry. In response to the proportion reaching the maximum waiting time limit continuously exceeding a preset idle threshold, feedback is sent to the strategy table entry in S2, extending the maximum waiting time limit by one step within the adjustable range defined by the strategy table entry. After each step adjustment, a preset feedback cooling-off period is entered, during which further feedback adjustments to the strategy table entry are prohibited.
[0124] The trigger cause distribution ratio is a second-order statistic, reflecting the trigger rhythm characteristics of aggregated batches over a recent period. Each time an aggregated batch is sent, the fire emergency gateway records the trigger cause for that batch (maximum waiting time limit reached or maximum batch size limit reached), and maintains the trigger cause history for the most recent preset number of batches by fire compartment. Following the baseline scenario, the preset number of batches is set to 20—that is, for each fire compartment, the trigger cause history for the most recent 20 aggregated batches is maintained. The saturation threshold is set to 70%, and the idle threshold is set to 70%.
[0125] Following the previous Z1 partition aggregated batches, after running in alarm handling mode for a period of time, the triggering reasons for the most recent 20 aggregated batches in Z1 partition are distributed as follows: 15 batches reached the maximum batch size limit, and 5 batches reached the maximum waiting time limit. The proportion of batches reaching the maximum batch size limit is 15 / 20 = 75%, which is higher than the saturation threshold of 70%. This result indicates that the instruction generation rhythm of Z1 partition is faster than the aggregated batch processing rhythm—aggregated batches are repeatedly sent ahead of schedule due to the batch size being full, and the air interface utilization is close to saturation. To avoid further air interface congestion, a feedback mechanism is triggered, feeding back to the policy table entry in S2: within the adjustable range of the polling or reporting cycle defined by the policy table entry, the polling or reporting cycle is tightened by one step in a single increment, where the adjustable range is, for example, from 1s to 10s. For example, if the current polling or reporting cycle is 2s and the single step length is 0.5s, then the tightened polling or reporting cycle becomes 1.5s. Tightening the polling or reporting cycle slows down the terminal reporting pace, thereby reducing the number of instructions entering the aggregation batch per unit time and alleviating the batch size saturation pressure of the aggregation batch.
[0126] Example of the reverse scenario. If the triggering reasons for the most recent 20 aggregation batches in partition Z1 are distributed as follows: 16 batches reached the maximum waiting time limit, and 4 batches reached the maximum batch size limit. The proportion of batches reaching the maximum waiting time limit is 16 / 20 = 80%, which is higher than the idle threshold of 70%. This result indicates that the instruction generation rhythm of partition Z1 is slower than the aggregation batch processing rhythm—aggregation batches are frequently sent due to waiting timeouts, with fewer instructions per batch and lower air interface utilization. A feedback mechanism is triggered, feeding back to the policy table entry in S2: within the adjustable range of the maximum waiting time limit defined by the policy table entry, the maximum waiting time limit is extended by one step in a single increment, where the adjustable range is, for example, from 100ms to 1000ms. For example, if the current maximum waiting time limit is 300ms and the single step length is 100ms, then the extended maximum waiting time limit becomes 400ms. Extending the maximum waiting time limit allows each aggregation batch to accumulate more instructions before transmission, improving the load efficiency of a single air interface frame.
[0127] Single-step constraints ensure that feedback adjustments are made in small increments, preventing feedback oscillations caused by excessively large single parameter changes. A feedback cooldown period serves as a second layer of anti-oscillation mechanism. After each single-step adjustment, the fire emergency gateway enters a preset feedback cooldown period, for example, set to 2 minutes. During the cooldown period, even if the trigger cause distribution ratio still exceeds the threshold, no further feedback adjustments are performed on the strategy table entries. After the cooldown period ends, the fire emergency gateway re-collects the trigger cause distribution ratios of the most recent 20 batches and evaluates whether further adjustments are necessary. The single-step constraints and feedback cooldown period together prevent the closed-loop feedback from entering an oscillating state, ensuring that feedback adjustments can adapt to changes in operating conditions without compromising strategy stability.
[0128] In S43, the concurrency limit is characterized by a dynamic concurrency limit parameter. This parameter is calculated jointly by the interference score, policy mode identifier, and the frequency of the most recent policy handover. The dynamic concurrency limit parameter decreases as the interference score and the frequency of the most recent policy handover increase, with a higher upper limit under alarm handling mode than under normal mode. The dynamic concurrency limit parameter is calculated independently for each fire compartment and takes values within the upper and lower bounds defined by the policy table entries. Calculation results exceeding these bounds are truncated. The interference score is calculated by sampling the energy of a preset set of channels in the 2.4 GHz band.
[0129] The dynamic concurrency limit parameter is denoted as , where the subscript p indicates parallel processing. Calculated independently for each fire compartment, Z1 partition has its own corresponding Z1 partition. The value, the Z2 partition has a corresponding Z2 partition. Values for each partition They do not affect each other. An example of the joint calculation formula is as follows: ; in, This is a dynamic concurrency limit parameter. The baseline concurrency limit parameter value for strategy table entries. Assign a mode gain coefficient to the strategy mode identifier (under alarm handling mode). Take 1, in normal mode Take 0). To interfere with the scoring, The frequency of recent strategy switching. , , These are the preset non-negative weighting coefficients. The formula structure makes... Scoring with interference Increase and decrease ( Item), frequency of switching with the most recent strategy Increase and decrease ( Item), under the confirmed alarm handling mode ( Compared to the normal mode ( (Higher than) .
[0130] Building upon the baseline scenario, computation is performed for the Z1 partition. .set up , , , The current strategy mode for partition Z1 is identified as the alarm handling mode. Interference score for Z1 partition For moderate interference, the frequency of recent policy switching This indicates that 5 switches occurred within the last 10 minutes. Substituting this into the formula, the Z1 partition... The calculation is 2 + 3×1 - 0.5×4 - 0.2×5 = 2 + 3 - 2 - 1 = 2. This calculation means: at the baseline concurrency limit... Based on 2, the mode gain brought by the confirmed alarm handling mode is superimposed. Take 3, deducting the interference score introduced by the score. Take 2, then subtract the amount introduced by the frequency of recent policy switching. Setting it to 1, the final dynamic concurrency limit parameter for partition Z1 is set to 2. This is limited by the strategy table entries. The lower bound is 1 and the upper bound is 5. Calculation result 2 falls within these bounds, so truncation is not triggered. This represents the current concurrency limit for partition Z1. The value is 2, meaning that the Z1 partition can be processed together with at most another partition that is also in a parallel state.
[0131] Comparison scenario. If the Z1 partition executes the same formula in normal mode, Let the current (Low interference) (Recently, there have been fewer changes), substituting the values yields the following results. =2 + 0 - 0.5 × 2 - 0.2 × 1 = 2 - 1 - 0.2 = 0.8. The calculated result of 0.8 is lower than the lower bound of 1, so it is truncated according to the lower bound. This is the concurrency limit for the Z1 partition in normal mode. Taking 1 means that in normal mode, the Z1 partition is treated as a separate partition. Upper and lower bound truncation makes... The value of is always within the executable range defined by the strategy table entry, avoiding abnormally low calculation results (e.g., 0 or negative values, meaning that scheduling is not possible) or abnormally high results (e.g., exceeding the number of concurrent connections that the hardware can handle at the same time).
[0132] In some embodiments, in scenarios involving multi-gateway collaborative deployment, adjacent fire emergency gateways exchange current policy mode identifiers, dynamic concurrency limit parameters, and interference scores via a northbound link. In response to adjacent fire emergency gateways simultaneously entering emergency mode, they coordinate and share the concurrency budget, ensuring that the sum of parallel processing volumes in adjacent zones does not exceed the shared concurrency budget limit. For example, after the factory area expands, the original Z1-Z5 zones are managed by two adjacent fire emergency gateways. When both gateways simultaneously enter alarm handling mode, their respective parallel slots are allocated according to the shared concurrency budget limit, with the allocation ratio determined through negotiation based on the service urgency of the two gateways. This alternative method extends the zone-level concurrency budget to the super-system level, similarly achieving the goal of reducing instantaneous wireless channel occupancy peaks, and is also an implementation method of the S43 concurrency limit.
[0133] S5. Record the policy table version number and the audit log for each policy switch. The audit log should include at least the switch time, the old policy mode identifier, the new policy mode identifier, and the trigger source.
[0134] S5 is executed each time a policy switch occurs. Switching events include policy mode switching in S23, version switching in double-buffered hot switching in S2, field degradation issuance in S33, feedback adjustment in S42, and individual degradation after S4. Each time an event occurs, the fire emergency gateway records the event in the audit log, which is stored in non-volatile memory and supports historical backtracking.
[0135] Each audit log entry contains at least the following four fields: switchover time (accurate to milliseconds), old strategy mode identifier (strategy mode before switchover), new strategy mode identifier (strategy mode after switchover), and trigger source (the running status signal or internal event that triggered this switchover). Following the baseline scenario, when S23 completes the two-stage switchover from normal mode to early warning monitoring mode to confirmed alarm handling mode, two audit log entries are generated: The first entry's fields are: switchover time T1, old strategy mode identifier is normal mode, new strategy mode identifier is early warning monitoring mode, and trigger source is the combined triggering of the fire alarm level signal transitioning to confirmed alarm and the power supply status signal switching to mains power anomaly; the second entry's fields are: switchover time T2, old strategy mode identifier is early warning monitoring mode, new strategy mode identifier is confirmed alarm handling mode, and trigger source is the completion of the state machine buffer phase. The strategy table version number, as an additional field for each audit log entry, identifies the version of the strategy table entry that took effect when the switchover event occurred, supporting tracing the change history by version number.
[0136] During the execution of S3, the method also includes performing interference assessment on the 2.4GHz band and outputting the assessment results to the plant's wireless controller or network management platform via the northbound interface. Energy sampling is performed on a preset channel set. The timing of energy sampling includes passive observation periods and active scanning periods. Passive observation periods are initiated when there is a gap window for uplink data transmission from the fire emergency terminal. Active scanning periods are initiated to supplement energy sampling when the cumulative number of samples during passive observation periods is insufficient to meet a preset sample size threshold. Active scanning periods are initiated during preset low-traffic periods. Interference scores are calculated based on energy sampling and compared with historical baselines. Interference alarm information is generated when the interference score of a certain channel is consistently higher than a preset alarm threshold. Several channels with lower interference scores are arranged into a suggested channel list and output through the northbound interface according to the semantic level output. The semantic levels output by the northbound interface include three levels: score and alarm level only, level including suggested channel list, and level including suggested power adjustment. The output of any semantic level by the northbound interface does not carry scheduling task data for the automated guided vehicle. The following provides a detailed explanation of each of the above steps.
[0137] The preset channel set consists of 2.4GHz channel candidates allowed by the type approval certificate. Based on the baseline scenario, the preset channel set consists of three candidates: channel 11, channel 16, and channel 22.
[0138] The passive observation period refers to the window of opportunity when the fire emergency terminal has no uplink data transmission. During this period, the fire emergency gateway performs energy sampling using idle wireless interfaces without occupying additional fire service time. Following the baseline scenario, in the alarm handling mode, the reporting cycle of the Z1 partition terminal is 2 seconds, with a gap window of approximately 1.8 seconds between two reports. Within this gap window, the fire emergency gateway performs energy sampling on a preset set of channels. The energy sampling result is the energy value of each channel, recorded in time sequence.
[0139] Active scanning serves as a supplement when passive observation samples are insufficient. If the cumulative number of samples collected during passive observation is less than a preset sample size threshold (e.g., the threshold of at least 100 sampling points per channel is not met), active scanning is initiated to supplement energy sampling. Active scanning occurs during preset low-traffic periods, such as 2:00 AM to 4:00 AM or the early morning off-peak traffic period. During active scanning, the fire emergency gateway briefly suspends routine parameter distribution tasks and focuses on scanning a preset set of channels.
[0140] Interference scores are calculated based on energy sampling. The interference score is the average or median of the energy sampling values over a statistical period, reflecting the average occupancy intensity of the channel. The interference score is compared to a historical baseline, which is the average interference score of the channel over the past 24 hours. Continuing with the baseline scenario, a certain evaluation result shows channel 11 with an interference score of 3, channel 16 with an interference score of 7, and channel 22 with an interference score of 2. Channels 11 and 22 are considered low-interference, while channel 16 is considered high-interference. Channel 16's interference score of 7 consistently exceeds the preset alarm threshold of 5, generating an interference alarm. The alarm information includes at least the fields of alarm time, alarm channel, interference score, and duration. Channels 11 and 22, with lower interference scores, are listed as suggested channels, sorted in ascending order of interference score. The sorting result is channel 22 first with a score of 2, followed by channel 11 with a score of 3.
[0141] The northbound interface output semantic level is divided into three levels. Level 1 is the scoring and alarm-only level, outputting only the interference score and interference alarm information for each channel. Level 2 includes a suggested channel list, adding a suggested channel list (e.g., channel 22, channel 11) to Level 1. Level 3 includes suggested power adjustment, adding a suggested power adjustment direction (e.g., suggesting that industrial wireless access points reduce to a specific power level to mitigate co-channel interference) to Level 2. The northbound interface output semantic level is configured by the fire emergency gateway and can be selected according to the required level of collaboration at the deployment site. Based on the baseline scenario, the northbound interface output semantic level is configured as Level 2. The fire emergency gateway outputs the following content to the plant's wireless controller or network management platform via the northbound interface: Channel 11 interference score 3, Channel 16 interference score 7 with alarm, Channel 22 interference score 2, and a suggested channel list of channels 22 and 11. After receiving this output, the plant's wireless controller or network management platform allows industrial network maintenance personnel to decide whether to adjust the channel selection of the industrial wireless access points. The output at the semantic level of any northbound interface does not carry the scheduling task data of the automated guided vehicles. That is, the northbound interface only carries the suggestion information from the fire protection side and does not intervene in the protocol stack and scheduling logic of the automated guided vehicle scheduling system in the plant. At the interface level, the suggestions from the fire protection side and the scheduling data of the industrial network are physically isolated.
[0142] In some embodiments, the fire emergency gateway obtains statistical information on the channel utilization or retransmission rate of the industrial wireless access point through the Ethernet-side read-only interface, and uses this statistical information as an auxiliary criterion in the mapping rules. In the event that the read-only interface is unavailable, the mapping rules can still operate solely based on the operating status signals and energy sampling results. The read-only interface only reads data from the publicly available management information database of the plant's industrial network and does not issue any control commands. The channel utilization or retransmission rate obtained by the read-only interface is used as an auxiliary input to the mapping rules, adding a one-dimensional decision-making basis in addition to the operating status signals and energy sampling. The fallback path in the event that the read-only interface is unavailable ensures the independent availability of this method.
[0143] The fire emergency system described in this embodiment consists of a fire alarm control panel, a fire emergency gateway, and a fire emergency terminal. The fire alarm control panel and the fire emergency gateway are connected via a fire protection network or fieldbus, and the fire emergency gateway and the fire emergency terminal are connected wirelessly. The fire emergency gateway includes a processor, non-volatile memory, a wireless interface, a northbound interface, and an input interface.
[0144] The processor is used to execute steps S1 to S5 and their sub-steps in the above method embodiments. The processor is typically implemented as an embedded microcontroller or system-on-a-chip, possessing computational capabilities for functions such as loading policy table entries, debouncing, multi-source fusion, state machine transitions, double-buffered hot-switching, aggregated batch scheduling, dynamic concurrency limit parameter calculation, and audit log writing. Non-volatile memory is used to store the policy table file, policy table version number, terminal capability bitmap, and audit logs; its typical implementation is flash memory or ferroelectric memory. The non-volatile memory reserves three slots for the policy table entries: a slot for the effective version, a slot for the candidate version, and a slot for the previous effective version. The wireless interface is used for data frame interaction with the fire emergency terminal; its typical implementation is a 2.4GHz Zigbee or Bluetooth Mesh RF module. The frequency and power range of the wireless interface are limited by the type approval certificate of the fire emergency gateway. The northbound interface is used to interact with the plant's wireless controller or network management platform via a northbound link when needed. A typical implementation is an Ethernet interface using a manufacturer-defined lightweight communication protocol. The northbound interface only carries suggestion information from the fire protection side and does not carry industrial network scheduling task data. The input interface is used to receive at least one of the following: fire alarm level signal, power supply status signal, and maintenance task type signal. Typical implementations include fire network bus interface, dry contact input terminal, and human-machine interface panel.
[0145] The fire emergency terminal includes at least one of the following: emergency lighting fixtures, evacuation signs, and an information acquisition module. Emergency lighting fixtures provide illumination in case of alarm activation or mains power failure; evacuation signs indicate the direction of evacuation; and the information acquisition module is a sensor module that collects environmental parameters such as temperature or smoke concentration. All fire emergency terminals connect to the wireless interface of the fire emergency gateway via a 2.4GHz frequency band wireless protocol.
[0146] After completing the concurrent power-on logical sequencing and networking of the emergency lighting wireless system and entering the operational state, the fire emergency terminal executes steps S1 to S5. Concurrent power-on logical sequencing and networking occurs during the network entry phase of the fire emergency terminal. Specifically, under the trigger condition of detecting a main power failure and switching to backup battery power, each emergency node concurrently starts up and reads the floor number and network role. Based on the floor number and network role, it calculates the logical delay time, maintains a silent wireless reception state during the logical delay time, and executes the network networking action corresponding to its network role after the logical delay time ends. For example, the lighting node with floor number 1 in zone Z1 calculates a logical delay time of 100ms, and the lighting node with floor number 2 in zone Z2 calculates a logical delay time of 300ms. The lighting nodes in both zones execute the network entry action after their respective logical delay times, avoiding simultaneous channel contention among all nodes at the moment of power switching.
[0147] After completing the above network access process and entering the operational state, S1 to S5 superimpose strategy switching in the operational state, so that the orderly network access and the adaptive air interface strategy in the operational state form a sequential connection and complementary objectives.
[0148] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0149] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A channel and packet transmission adaptive method for fire emergency wireless communication, characterized in that, Includes the following steps: S1. Acquire operating status signals, wherein the operating status signals include at least one of fire alarm level signals, power supply status signals, and operation and maintenance task type signals; S2. According to the preset mapping rules, the operating status signal is mapped to a strategy mode identifier, and the corresponding strategy table entry is loaded from the non-volatile memory according to the strategy mode identifier. The strategy table entry includes at least the following fields: working channel or channel candidate set limited within the frequency and power range allowed by the type approval certificate, transmit power level, polling or reporting cycle, maximum number of retransmissions per frame, and whether downlink data aggregation is allowed. S3. Within the parameter range defined by the strategy table entries, wireless configuration parameters are sent to the fire emergency terminal, so that the fire emergency terminal performs transmission and retransmission according to the data packet transmission strategy. The data packet transmission strategy includes at least constraints on the polling or reporting period, the maximum number of retransmissions per frame, and the backoff parameters. S4. In response to the strategy mode identifier corresponding to the emergency mode, aggregate control commands of at least two terminals within the same fire compartment, and / or distribute command queues of multiple fire compartments in a staggered manner according to a preset partition order and concurrency limit, so as to reduce the peak value of instantaneous wireless channel occupancy. S5. Record the policy table version number and the audit log for each policy switch. The audit log shall include at least the switch time, the old policy mode identifier, the new policy mode identifier, and the trigger source. S4 includes the following sub-steps: S41. Mark the latest delivery timestamp for each terminal control instruction within the same fire compartment, and divide the terminal control instructions into instructions that are included in the aggregate batch and instructions that are retained for single frame transmission based on the latest delivery timestamp; S42. Set a maximum waiting time limit and a maximum batch size limit for each aggregated batch, and trigger the sending of the aggregated batch in response to either limit being reached; S43. Traverse the instruction queues of the multiple fire compartments in a preset partition order and count the number of fire compartments processed in parallel. In response to the number of fire compartments processed in parallel reaching the concurrency limit, suspend the instruction queue for adding a new fire compartment. S42 further includes: statistically analyzing the distribution ratio of triggering causes of the aggregated batch; in response to the distribution ratio of triggering causes satisfying a preset feedback triggering condition, feeding back to the strategy table entry in S2 and adjusting at least one of the polling or reporting cycle and the maximum waiting time limit by a single step. The concurrency limit in S43 is characterized by a dynamic concurrency limit parameter, which is jointly calculated by the interference score, the policy mode identifier, and the frequency of the most recent policy switching, and is calculated independently by fire zone and takes values within the upper and lower bounds defined by the policy table entries; the interference score is calculated by energy sampling of a preset channel set in the 2.4GHz band.
2. The adaptive channel and packet transmission method for fire emergency wireless communication according to claim 1, characterized in that, S2 includes the following sub-steps: S21. Perform de-jitter processing on the running status signal, and merge multiple state transitions into one strategy mode switching request within the de-jitter time window. The length of the de-jitter time window is jointly determined by the signal noise baseline and the frequency of the most recent strategy switching. S22. In response to receiving the fire alarm level signal and the power supply status signal simultaneously, perform branch processing according to the multi-source consistency state, and write the conflict event into the audit log when there is a multi-source conflict. S23. Execute the mapping rule based on the policy mode switching request and load the corresponding policy table entry.
3. The adaptive channel and packet transmission method for fire emergency wireless communication according to claim 2, characterized in that, The mapping rule in S23 is constrained by the strategy mode transition state machine; in response to the strategy mode of the target being requested by the strategy mode switching request not belonging to the set of reachable successor modes of the current strategy mode, an intermediate strategy mode is forcibly inserted, and the parameter change range of a single switch is limited according to the climb step size field in the strategy table entry; the strategy mode identifier corresponds to the emergency type mode, including the case where the strategy mode identifier corresponds to the alarm handling mode or the mains power abnormality mode.
4. The adaptive channel and packet transmission method for fire emergency wireless communication according to claim 3, characterized in that, The loading of the strategy table entries in S2 adopts a double-buffered hot-switching method. The non-volatile memory simultaneously stores the effective version and the candidate version of the strategy table entries, and atomically switches the candidate version to the effective version at the instruction boundary. After the switch is completed, the key frame packet loss rate is collected in the preset observation window. In response to the key frame packet loss rate exceeding the preset rollback threshold, the strategy table entry is atomically switched back to the previous valid version.
5. The adaptive channel and packet transmission method for fire emergency wireless communication according to claim 4, characterized in that, S3 includes the following sub-steps: S31. Divide the fields of the strategy table entries into mandatory layer fields and optional layer fields; S32. Generate parameters and issue tasks according to the strategy table entries, and the key frames in the alarm handling mode enter the high-priority queue; S33. Before sending, read the terminal capability bitmap; if the fire emergency terminal does not support a certain field in the optional layer fields, downgrade the field and send it; if the fire emergency terminal does not support any field in the mandatory layer fields, reject this switch.
6. The adaptive channel and packet transmission method for fire emergency wireless communication according to claim 5, characterized in that, The following steps are included after S3: For each of the aforementioned fire emergency terminals, statistical link feedback indicators are collected; In response to a link feedback indicator of a certain fire emergency terminal being lower than a preset individual degradation threshold and not a global link deterioration, an individual degradation parameter is issued only to the certain fire emergency terminal. The issuance of the individual degradation parameter does not trigger a global switch of the strategy mode identifier. When the preset capability renegotiation window is reached, the terminal capability bitmap of the fire emergency terminal in the individual downgrade state is reread, and the individual downgrade state is lifted in response to the link feedback index recovering to above the preset individual downgrade threshold.
Citation Information
Patent Citations
Service quality scheduling method and system, electronic equipment and computer storage medium
CN121865411A
Hospital ward emergency lighting method and equipment based on power management and medium
CN122028259A