Method for attributing a service to a non-authenticated iot terminal based on dynamic grouping of kan and epg

CN122679413APending Publication Date: 2026-09-01NANJING INST OF MECHATRONIC TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610804825.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-05
Publication Date
2026-09-01

AI Technical Summary

Technical Problem

[0006]本发明的一个目的在于提出一种基于KAN及EPG动态分组的无认证物联终端业务归属方法,本申请要解决的核心技术问题是:如何在园区实验室、教室、机房和后勤区域中,针对缺少认证能力且无法依赖人工登记完成准入识别的物联终端,基于接入关系和业务交互关系建立与业务系统、服务对象和接入区域一致的自动业务归属机制,并将业务归属结果直接联动到EPG动态分组和业务网络接入流程,从而使能够确定归属的终端进入对应业务网络,无法确定归属的终端进入待判网络

Benefits of technology

[0076](1) This proposal presents an improved KAN-based service attribution method. Instead of classifying based solely on address features, message fingerprints, or terminal type labels on the input side, it transforms access relationships and service interaction relationships into fixed access locations, regional affiliations, control interfaces, and service chain locations, respectively, based on the actual deployment status of unauthenticated IoT terminals within the park. These are then written into a multi-branch KAN structure with dynamic packet forward-shifting constraints in the EPG, following a unified order of fixed access locations, regional affiliations, control interfaces, and service chain locations. Through unary mapping within branches, branch feature aggregation, sequential splicing of intermediate features, and fusion of KAN mappings, this invention maintains consistency in input arrangement, branch reception order, and fusion order, ensuring that access location information, regional mapping information, communication control object information, and link role information are first independently modeled and then jointly determined. This structure differs from existing recognition algorithms based on single feature splicing or black-box classification output. It can distinguish terminals with different control interfaces within the same access area and terminals with different service chain locations under the same control interface.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122679413A_ABST
    Figure CN122679413A_ABST
Patent Text Reader

Abstract

This invention discloses a method for service attribution of unauthenticated IoT terminals based on KAN and EPG dynamic grouping, aiming to solve the problem that unauthenticated IoT terminals are difficult to accurately attribute and access the corresponding service network according to service attributes. This invention collects access relationships and service interaction relationships, and establishes EPG service attribution category definitions by combining the service boundaries of access control, environmental sensing, multimedia, and management devices. It extracts fixed access locations, regional attribution relationships, control interface objects, and service chain locations to form terminal deployment service characteristics, which are then input into the KAN to generate attribution values ​​for each category. Based on consistency judgment and attribution thresholds, it determines the target service attribution category or pending label, executes EPG dynamic grouping, and connects to the corresponding service network or pending network. This invention can be used for automatic service attribution and access control of unauthenticated IoT terminals within a park, and supports isolated access for pending terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of park Internet of Things access control and service grouping, and in particular to an unauthenticated Internet of Things terminal service attribution method based on KAN and EPG dynamic grouping. Background Art

[0002] A large number of Internet of Things terminals are usually deployed in laboratories, classrooms, computer rooms and logistics areas in park networks. The Internet of Things terminals include access control devices, environment sensing devices, multimedia devices and management devices. Access control devices perform the functions of personnel access control and status collection; environment sensing devices perform the functions of reporting data such as temperature, humidity, smoke detection and energy consumption; multimedia devices perform the functions of audio and video playback control, display and linkage; management devices perform the functions of equipment operation and maintenance, asset management and service coordination. The above-mentioned Internet of Things terminals are generally online for a long time, and maintain continuous service sessions through controllers, gateways or service platforms. In order to ensure the access boundaries and regional boundaries between different service systems, park networks usually need to complete network grouping according to service attributes, and issue access control policies, communication range limitation policies and service network forwarding policies based on the grouping results. EPG dynamic grouping technology can logically classify terminals into different service groups, and then map the service groups to corresponding service networks. Multiple types of Internet of Things terminals often coexist in the same building, the same floor or even the same area in a park. Although different terminals share access facilities, their targeted service systems and access ranges are different, so it is necessary to complete finer-grained service classification in the access control stage. In actual deployment, some Internet of Things terminals have fixed positions but simplified identifiers, some Internet of Things terminals access the network through wired access ports or wireless coverage areas, and the network side can collect access relationship, communication objects, session direction and area coding information. For unauthenticated Internet of Things terminals that lack the conditions for account authentication, certificate authentication or manual registration, the park network still needs to determine the service attribution during the terminal access stage, otherwise it will easily affect the implementation of service isolation, regional management and orderly access of service systems.

[0003] In existing technologies, campus networks typically employ pre-configured mapping and identification / inference methods to assign service affiliations to IoT terminals. Pre-configured mapping methods often establish fixed network affiliations for terminals based on access switch ports, access points, wireless coverage areas, terminal address whitelists, static virtual LANs, static security groups, or preset service network entries, and maintain the mapping relationship between terminals and service networks in the network controller or access control platform. Identification / inference methods primarily collect packet characteristics, session records, communication objects, protocol fields, device fingerprints, automatic address allocation information, address characteristics, or behavior logs after the terminal goes online. They then use rule bases, network access control platforms, device identification engines, or classification models to determine the terminal category and add the terminal to the corresponding network group. Some campus solutions also incorporate information about the service system deployment area, controller, or gateway to assist in matching terminal access policies, with the network controller distributing security policies, access policies, and service network policies.

[0004] In unauthenticated IoT terminal scenarios, existing technologies often rely on static location binding, address identification, or terminal type recognition for service attribution. They lack a joint determination mechanism encompassing fixed access locations, regional affiliations, control interfaces, and business chain positions, making it difficult to establish a unified business boundary determination process based on business systems, service objects, and access areas. In mixed deployment scenarios such as laboratories, classrooms, server rooms, and logistics areas, existing technologies struggle to reliably distinguish actual service attribution between terminals with similar access locations but different control interfaces, and terminals with the same control interface but different business chain positions. Current technologies typically output only at the terminal type, access area, or device tag level, lacking a direct connection between service attribution determination and EPG dynamic grouping, and failing to simultaneously form a pending isolated access path when attribution is unclear.

[0005] Therefore, a method for attributing uncertified IoT terminal services that can overcome the shortcomings of the existing technology is a problem that needs to be solved by those skilled in the art. Summary of the Invention

[0006] One objective of this invention is to propose a service attribution method for unauthenticated IoT terminals based on KAN and EPG dynamic packetization. The core technical problem to be solved by this application is: how to establish an automatic service attribution mechanism consistent with the business system, service object, and access area based on access relationship and business interaction relationship for IoT terminals that lack authentication capabilities and cannot rely on manual registration for access identification in campus laboratories, classrooms, computer rooms, and logistics areas, and directly link the service attribution result to EPG dynamic packetization and business network access process, so that terminals that can be attributed can enter the corresponding business network, and terminals that cannot be attributed can enter the pending network.

[0007] The method for attribution of unauthenticated IoT terminal services based on KAN and EPG dynamic packetization according to embodiments of the present invention includes:

[0008] S1. Obtain the access relationship and business interaction relationship of uncertified IoT terminals in the park, and generate EPG business category definition based on business boundaries;

[0009] S2. Determine the fixed access location of the unauthenticated IoT terminal based on the access relationship, determine the control interface object of the unauthenticated IoT terminal based on the business interaction relationship, generate the area affiliation relationship based on the park area corresponding to the fixed access location and the control interface object, generate the business chain location based on the communication direction of the unauthenticated IoT terminal relative to the control interface object, and combine the fixed access location, area affiliation relationship, control interface object and business chain location to generate terminal deployment business characteristics.

[0010] S3. Write the EPG service category definition into the output category space of KAN, and input the terminal deployment service characteristics into KAN for mapping calculation to generate the category value corresponding to the EPG service category definition.

[0011] S4. Based on the EPG service category definition, determine the consistency between the category value and the terminal deployment service characteristics. When the fixed access location, regional affiliation, control interface object and service chain location all correspond to the same EPG service category definition, and the corresponding aggregation value reaches the affiliation threshold, generate the target service category. When the corresponding aggregation value does not reach the affiliation threshold, generate a pending judgment mark.

[0012] S5. Perform EPG dynamic grouping on unauthenticated IoT terminals according to the target service category, generate service network affiliation relationship, and generate network affiliation relationship to be judged according to the pending label.

[0013] S6. Connect the unauthenticated IoT terminal to the corresponding business network according to the business network affiliation, and connect the unauthenticated IoT terminal to the network to be judged according to the network affiliation to be judged.

[0014] Optionally, S1 is as follows:

[0015] Collect business deployment information of access control, environmental sensing, multimedia and management equipment in the park's laboratories, classrooms, computer rooms and logistics areas, and extract business systems, service objects and access areas from the business deployment information to form business boundary information;

[0016] Based on the business boundary information, access control, environmental sensing, multimedia and management equipment are identified as independent business categories, and these independent business categories are aligned with business systems, service objects and access areas to form the initial business category definition;

[0017] Based on the initial business category definition, the category arrangement information is determined according to the fixed order of access control, environmental perception, multimedia and management equipment, so that each independent business category is established in a one-to-one correspondence with the output category space of KAN.

[0018] Based on the initial business category definition and category arrangement information, each independent business category is bound to the EPG grouping relationship to generate the EPG business belonging category definition.

[0019] Terminology definition:

[0020] The business interaction relationship refers to the corresponding relationship formed by the establishment of a business session and continuous communication between the unauthenticated IoT terminal and the controller, gateway or business platform.

[0021] The business boundary refers to the boundary information consisting of the business system, the service object, and the access area;

[0022] The EPG service category definition refers to the category definition formed by identifying access control, environmental sensing, multimedia and management equipment as independent service categories, aligning them with the service system, service object and access area, and binding them with the EPG grouping relationship.

[0023] Optionally, S2 is as follows:

[0024] Extract access nodes from the access relationship where the association duration between unauthenticated IoT terminals and access switches, access points, or wireless coverage areas reaches the access judgment threshold, and match the access switch identifier, access point identifier, or wireless coverage area identifier with the building number, floor number, and area number to determine the fixed access location;

[0025] Extract controllers, gateways, or business platforms from the business interaction relationships where unauthenticated IoT terminals establish a business session for the first time within a preset time period and the number of business sessions reaches the session judgment threshold and the communication duration reaches the communication judgment threshold. Then, merge the object number, object type, and the business system to which they belong to determine the control interface object.

[0026] Based on the building number, floor number, and area number corresponding to the fixed access location, the area mapping is performed with the deployment area of ​​the business system to which the control interface object belongs, and the area mapping result is determined as the area affiliation relationship;

[0027] Link positioning is performed based on the data reporting direction, control sending direction, and service response direction between the uncertified IoT terminal and the control interface object, and the link positioning result is determined as the business chain position among the reporting position, execution position, service position, or aggregation position.

[0028] Based on the branch input structure of KAN, the fixed access position is aligned to the side function unit of the fixed access position branch, the control docking object is aligned to the side function unit of the control docking object branch, the regional affiliation relationship is aligned to the side function unit of the regional affiliation relationship branch, the service chain position is aligned to the side function unit of the service chain position branch, and the input arrangement relationship is formed according to the connection order of each branch before the KAN structure is integrated.

[0029] Based on the input arrangement, the fixed access location is written into the preorder field, the regional affiliation is written into the region field, the control interface object is written into the object field, the business chain location is written into the link field, and the terminal deployment business characteristics are generated by combining them in a fixed order.

[0030] Terminology definition:

[0031] The first connection and continuous communication refers to the unauthenticated IoT terminal establishing a business session for the first time within a preset time period, and the number of business sessions reaching the session determination threshold and the communication duration reaching the communication determination threshold.

[0032] The regional affiliation relationship refers to the regional mapping result between the building number, floor number, and area number corresponding to the fixed access location and the deployment area of ​​the business system to which the control interface object belongs;

[0033] The business chain position refers to the reporting position, execution position, service position, or aggregation position determined based on the data reporting direction, control sending direction, and service response direction between the uncertified IoT terminal and the control interface object.

[0034] The terminal deployment service characteristics refer to the input characteristics formed by combining fixed access location, regional affiliation, control interface object, and service chain location in a fixed order.

[0035] Optionally, S3 specifically refers to:

[0036] The EPG service attribution category definition is written into the output category space of KAN in a preset category order, and the output neurons are configured according to the number of EPG service attribution category definitions, so that each output neuron establishes a correspondence with an EPG service attribution category definition;

[0037] The terminal deployment service characteristics are input into a KAN consisting of a fixed access location branch, a regional affiliation branch, a control docking object branch, a service chain location branch, and a converged KAN structure. The fixed access location is input into the fixed access location branch, the regional affiliation branch is input into the regional affiliation branch, the control docking object is input into the control docking object branch, and the service chain location is input into the service chain location branch.

[0038] In the fixed access location branch, regional affiliation branch, control docking object branch, and business chain location branch, the corresponding inputs are split into single-dimensional inputs, and the single-dimensional inputs are respectively input into the side function units of the corresponding KAN neurons for unary mapping. Then, the summation unit aggregates the unary mapping results to form the branch features corresponding to each branch.

[0039] The branch features are concatenated in the order of fixed access location, regional affiliation, control interface object and business chain position to form intermediate features, and the intermediate features are input into the fusion KAN structure.

[0040] In the fused KAN structure, intermediate features are input into the side function units of the KAN neurons for mapping calculation, and then the summation unit aggregates the mapping calculation results. The connection relationship between the fused KAN structure and the output neurons is limited according to the EPG service affiliation category definition, so that each output neuron receives intermediate features consistent with the corresponding EPG service affiliation category definition.

[0041] Based on the mapping calculation results of the output neurons to the intermediate features, the category affiliation values ​​corresponding to the business affiliation categories of each EPG are generated respectively.

[0042] Terminology definition:

[0043] The category attribution value refers to the matching result between the terminal deployment service characteristics and the corresponding EPG service attribution category definition;

[0044] The output category space refers to the category organization space that sets up output neurons according to a preset category order and establishes a one-to-one correspondence between each output neuron and the category definition of each EPG service.

[0045] The mapping calculation according to the order of fixed access location, regional affiliation, control interface object and service chain location refers to inputting the fixed access location, regional affiliation, control interface object and service chain location into the corresponding branches respectively, and then concatenating the branch features formed by the corresponding branches in the order of fixed access location, regional affiliation, control interface object and service chain location and inputting them into the fused KAN structure for mapping calculation.

[0046] Optionally, S4 specifically refers to:

[0047] Based on the EPG business affiliation category definition, fixed access location constraints, regional affiliation constraints, control interface object constraints, and business chain location constraints are extracted to form the category determination basis;

[0048] The fixed access location, regional affiliation, control interface object, and business chain location in the terminal deployment business characteristics are matched with the category determination criteria, and the matching results are categorized by pointing to the category affiliation value defined in the same EPG business affiliation category.

[0049] The categorized category values ​​are aggregated to obtain the aggregated value corresponding to the category definition of each EPG business, and the aggregated value is compared with the category threshold.

[0050] When the fixed access location, regional affiliation, control interface object, and business chain location all correspond to the same EPG business affiliation category definition and the aggregation value reaches the affiliation threshold, a target business affiliation category is generated. When the aggregation value does not reach the affiliation threshold, a pending judgment mark is generated.

[0051] Terminology definition:

[0052] The consistency determination refers to the process of matching the fixed access location, regional affiliation, control interface object, and service chain location with the category determination criteria defined in the same EPG service affiliation category, and then aggregating and comparing the corresponding category affiliation values.

[0053] The aggregated value refers to the judgment value formed by aggregating and calculating category attribution values ​​that point to the same EPG business attribution category definition.

[0054] The target service affiliation category refers to the service affiliation category determined when the fixed access location, regional affiliation relationship, control interface object and service chain location all correspond to the same EPG service affiliation category definition and the corresponding aggregation value reaches the affiliation threshold.

[0055] The pending flag refers to the pending state flag generated when the corresponding aggregation value has not reached the attribution threshold.

[0056] Optional, S5 specifically includes:

[0057] Based on the category position of the target service category in the output category space, determine the EPG service category definition corresponding to the target service category, and extract the business system, service object and access area from the EPG service category definition to form a grouping mapping relationship.

[0058] Based on the group mapping relationship, the fixed access location is aligned with the access area, the control interface object is aligned with the business system, the business chain location is aligned with the service object, and the area affiliation relationship is associated with the alignment results of the fixed access location and the control interface object to form the group matching result;

[0059] Based on the grouping matching results, the fixed access location, regional affiliation, control interface object, and service chain location are combined as the grouping input for EPG dynamic grouping, and the category location corresponding to the target service affiliation category is used as the category input for EPG dynamic grouping to form the target grouping result;

[0060] Based on the target grouping results, the unauthenticated IoT terminal is associated with the EPG dynamic group corresponding to the target service category, and the service network corresponding to the unauthenticated IoT terminal is determined according to the mapping relationship between the EPG dynamic group and the service network, thus generating the service network affiliation relationship.

[0061] Based on the pending markers, the combination of fixed access location, regional affiliation, control interface object, and business chain location is used as the access basis for the pending network to form the pending grouping results;

[0062] Based on the results of the pending grouping, unauthenticated IoT terminals are associated with the pending network, generating the affiliation relationship of the pending network.

[0063] Terminology definition:

[0064] The EPG dynamic grouping refers to the grouping process that forms the target grouping result based on the EPG service category definition corresponding to the target service category, as well as the fixed access location, regional affiliation, control interface object, and service chain location.

[0065] The business network attribution relationship refers to the correspondence between unauthenticated IoT terminals and business networks determined based on the target grouping results and the mapping relationship between EPG dynamic groups and business networks;

[0066] The network affiliation relationship to be judged refers to the correspondence between unauthenticated IoT terminals and networks to be judged, determined based on the judgment tag and the judgment grouping results.

[0067] Optional, S6 specifically includes:

[0068] Extract the fixed access location corresponding to the unauthenticated IoT terminal based on the business network affiliation, and map the access switch, access point or wireless coverage area associated with the fixed access location to the EPG dynamic group corresponding to the target business affiliation category;

[0069] Based on the mapping between the access switch, access point, or wireless coverage area associated with the fixed access location and the EPG dynamic group corresponding to the target service category, service network access is performed on the access switch, access point, or wireless coverage area, and unauthenticated IoT terminals are accessed to the service network corresponding to the service network affiliation relationship.

[0070] Extract the fixed access location corresponding to the unauthenticated IoT terminal based on the network affiliation relationship to be determined, and map the access switch, access point or wireless coverage area associated with the fixed access location to the network to be determined;

[0071] Based on the mapping between the access switch, access point, or wireless coverage area associated with the fixed access location and the network to be judged, access to the network to be judged is performed on the access switch, access point, or wireless coverage area, and unauthenticated IoT terminals with pending judgment tags are connected to the network to be judged.

[0072] Optionally, when multiple access switches, access points, or wireless coverage areas in the access relationship all have an association duration that reaches the access judgment threshold, the access switch, access point, or wireless coverage area with the longest association duration is determined as the fixed access location. When multiple controllers, gateways, or service platforms in the service interaction relationship all meet the requirements of establishing a service session for the first time, having a service session count that reaches the session judgment threshold, and having a communication duration that reaches the communication judgment threshold within a preset time period, the controller, gateway, or service platform with the earliest establishment of the service session is first determined as the priority object, and then the controller, gateway, or service platform with the longest communication duration among the priority objects is determined as the control docking object.

[0073] Optionally, the order of fixed access location, regional affiliation, control interface object, and service chain location in the terminal deployment service features is consistent with the input order of fixed access location (fixed access location branch), regional affiliation (regional affiliation branch), control interface object (control interface object branch), and service chain location (service chain location branch). This order is also consistent with the order in which the branch features corresponding to the fixed access location branch, regional affiliation branch, control interface object branch, and service chain location branch are concatenated to form intermediate features in the order of fixed access location, regional affiliation, control interface object, and service chain location.

[0074] Optionally, when forming group matching results based on group mapping relationships, if unauthenticated IoT terminals correspond to the same fixed access location but have different control docking objects, the different control docking objects are aligned with the business system respectively, and different group matching results and different target group results are formed to generate different business network affiliation relationships. If unauthenticated IoT terminals correspond to the same control docking object but have different business chain positions, the different business chain positions are aligned with the service objects respectively, and different group matching results and different target group results are formed to generate different business network affiliation relationships.

[0075] The beneficial effects of this invention are:

[0076] (1) This proposal presents an improved KAN-based service attribution method. Instead of classifying based solely on address features, message fingerprints, or terminal type labels on the input side, it transforms access relationships and service interaction relationships into fixed access locations, regional affiliations, control interfaces, and service chain locations, respectively, based on the actual deployment status of unauthenticated IoT terminals within the park. These are then written into a multi-branch KAN structure with dynamic packet forward-shifting constraints in the EPG, following a unified order of fixed access locations, regional affiliations, control interfaces, and service chain locations. Through unary mapping within branches, branch feature aggregation, sequential splicing of intermediate features, and fusion of KAN mappings, this invention maintains consistency in input arrangement, branch reception order, and fusion order, ensuring that access location information, regional mapping information, communication control object information, and link role information are first independently modeled and then jointly determined. This structure differs from existing recognition algorithms based on single feature splicing or black-box classification output. It can distinguish terminals with different control interfaces within the same access area and terminals with different service chain locations under the same control interface.

[0077] (2) This proposal proposes a novel category space constraint and consistency determination method. It pre-writes the business systems, service objects, access areas, and EPG grouping relationships corresponding to access control, environmental sensing, multimedia, and management equipment into the KAN output category space, establishing a fixed correspondence between the output neurons and the EPG service category definitions. During the inference phase, this invention does not directly use the maximum category attribution value as the final result. Instead, it extracts fixed access location constraints, area attribution relationship constraints, control interface object constraints, and business chain location constraints from each EPG service category definition. It then matches the terminal deployment business features field by field and aggregates and compares category attribution values ​​pointing to the same category definition. Only when all four constraints point to the same category definition and the aggregated value reaches the attribution threshold does this invention generate the target service category. If the conditions are not met, this invention generates a pending judgment mark and transfers it to the pending judgment network. This mechanism differs from existing methods that directly enter the network based on a single classification result, ensuring a consistent correspondence between business systems, service objects, and access areas, and reducing business boundary mismatches in unauthenticated scenarios.

[0078] (3) This proposal proposes a method for directly linking service attribution results to EPG dynamic grouping and network access execution. It directly maps the target service attribution category's position in the output category space to the EPG dynamic grouping category input, and combines fixed access location, regional attribution relationship, control interface object, and service chain position to form a grouping input. The campus network controller then establishes an execution mapping between the access switch, access point, or wireless coverage area and the corresponding EPG dynamic grouping and service network. This method not only directly links the service attribution determination result to the service network access process but also retains the pending network attribution relationship, allowing terminals with clear attribution to enter the corresponding service network and terminals with unclear attribution to enter the pending network. Compared to existing technologies where the identification result remains at the device tag level and still requires manual conversion to a grouping strategy, this invention forms a closed-loop process from service boundary definition, category attribution calculation, consistency verification, dynamic grouping to network access execution. It can also generate different service network attribution relationships for different control interface objects under the same fixed access location and for different service chain positions under the same control interface object, making it more suitable for the actual access control needs in mixed campus deployment scenarios. Attached Figure Description

[0079] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0080] Figure 1 The flowchart shows a method for attributing unauthenticated IoT terminal services based on dynamic grouping of KAN and EPG proposed in this invention.

[0081] Figure 2 This is a flowchart illustrating the generation of EPG service affiliation category definition for an authentication-free IoT terminal service affiliation method based on KAN and EPG dynamic grouping proposed in this invention.

[0082] Figure 3 This is a flowchart illustrating the process of generating terminal deployment service features for an authentication-free IoT terminal service attribution method based on KAN and EPG dynamic grouping proposed in this invention.

[0083] Figure 4 This is a flowchart illustrating the category attribution value generation process for a method of attributing services to unauthenticated IoT terminals based on dynamic grouping of KAN and EPG proposed in this invention.

[0084] Figure 5 This is a flowchart illustrating the consistency determination process of a service attribution method for unauthenticated IoT terminals based on dynamic grouping of KAN and EPG proposed in this invention.

[0085] Figure 6The flowchart shows the relationship between EPG dynamic packets and service network affiliation in an authentication-free IoT terminal service affiliation method based on KAN and EPG dynamic packets proposed in this invention.

[0086] Figure 7 This is a flowchart illustrating the service network access and pending network access process of an authentication-free IoT terminal service attribution method based on KAN and EPG dynamic packetization proposed in this invention. Detailed Implementation

[0087] In Example 1, reference Figures 1 to 7 A method for attributing services to unauthenticated IoT terminals based on dynamic grouping using KAN and EPG includes:

[0088] S1. Obtain the access relationship and business interaction relationship of uncertified IoT terminals in the park, and generate EPG business category definition based on business boundaries;

[0089] S2. Determine the fixed access location of the unauthenticated IoT terminal based on the access relationship, determine the control interface object of the unauthenticated IoT terminal based on the business interaction relationship, generate the area affiliation relationship based on the park area corresponding to the fixed access location and the control interface object, generate the business chain location based on the communication direction of the unauthenticated IoT terminal relative to the control interface object, and combine the fixed access location, area affiliation relationship, control interface object and business chain location to generate terminal deployment business characteristics.

[0090] S3. Write the EPG service category definition into the output category space of KAN, and input the terminal deployment service characteristics into KAN for mapping calculation to generate the category value corresponding to the EPG service category definition.

[0091] S4. Based on the EPG service category definition, determine the consistency between the category value and the terminal deployment service characteristics. When the fixed access location, regional affiliation, control interface object and service chain location all correspond to the same EPG service category definition, and the corresponding aggregation value reaches the affiliation threshold, generate the target service category. When the corresponding aggregation value does not reach the affiliation threshold, generate a pending judgment mark.

[0092] S5. Perform EPG dynamic grouping on unauthenticated IoT terminals according to the target service category, generate service network affiliation relationship, and generate network affiliation relationship to be judged according to the pending label.

[0093] S6. Connect the unauthenticated IoT terminal to the corresponding business network according to the business network affiliation, and connect the unauthenticated IoT terminal to the network to be judged according to the network affiliation to be judged.

[0094] In this embodiment, step S1 specifically includes:

[0095] The deployment items of access control, environmental sensing, multimedia, and management equipment in the park's laboratories, classrooms, computer rooms, and logistics areas were collected item by item, and the data was then processed. The business deployment information record is written as follows ,in, , This indicates the total number of business deployment information records. This indicates an independent business category identifier, which is limited to one of the following: access control, environmental sensing, multimedia, and management equipment. Indicates the business system. Indicates the service recipient, This indicates the access area. For each service deployment information record, it is parsed by field to extract the three-field boundary entries. ,in This represents a business boundary information entry consisting of a business system, a service object, and an access area. The business boundary information entry directly reflects the business deployment scope and business service direction of a certain independent business category in the park. For multiple business deployment information records with the same independent business category identifier, the corresponding business boundary information entries are merged according to the collection order to maintain a stable correspondence between business systems, service objects, and access areas under the same independent business category.

[0096] Based on the business boundary information, access control, environmental sensing, multimedia, and management equipment are identified as four independent business categories. Each independent business category is then aligned with the merged business system, service object, and access area to form four initial business category definitions. The initial business category definition is written as follows ,in, , Indicates the first Each independent business category Indicates the relationship with the first The business system after aligning individual business categories Indicates the relationship with the first Service objects aligned to individual business categories Indicates the relationship with the first After aligning the access areas for each independent business category, when multiple business deployment information records correspond to the same independent business category, the business system, service object, and access area in the multiple business deployment information records are merged into the same named field in the same initial business category definition according to the collection order. This ensures that the initial business category definition fully retains the business boundary content of the independent business category in the campus laboratory, classroom, computer room, and logistics area. Through this processing, the initial business category definition is no longer a simple category name, but a category entry with constraints on business system, service object, and access area.

[0097] The four initial business category definitions are arranged in a fixed order: access control, environmental sensing, multimedia, and management equipment, forming category arrangement information. ,in, Indicates access control. Indicates environmental perception. Indicates multimedia, This indicates the location index of the managed device in the category arrangement information. The output category space corresponds one-to-one with the category positions in the KAN output category space. There are four independent business categories in the current scenario, so the output category space is set to four category positions. The four category positions correspond to access control, environmental perception, multimedia and management equipment, respectively. This fixed order directly limits the category organization method of the output category space, so that the category position is consistent with the business boundary of the park from the time of generation, thereby ensuring that the category belonging value can directly correspond to the specific EPG business belonging category definition when it is generated.

[0098] Using business systems, service objects, and access regions as binding keys, four initial business category definitions are bound to EPG grouping relationships. During binding, the complete consistency of the business system, service object, and access region is used as the criterion for determining the same EPG grouping relationship; any difference in any of these three factors is used as the criterion for determining different EPG grouping relationships. After binding is complete, the first... The EPG business category definition is written as follows: ,in, Indicates the relationship with the first EPG grouping relationships for each independent business category Indicates the first The EPG service attribution category is defined, resulting in four EPG service attribution category definitions arranged in a fixed order in the current scenario. , , , The four EPG service affiliation category definitions correspond sequentially to the four category positions in the KAN output category space. Each EPG service affiliation category definition contains five fields: independent service category, service system, service object, access area, and EPG grouping relationship. These five fields together constitute the category entry content, ensuring that the KAN output category space remains consistent with the category basis of the dynamic EPG grouping during the writing phase.

[0099] In this embodiment, step S2 specifically includes:

[0100] The access relationships of the same unauthenticated IoT terminal are sorted by time to obtain the access record sequence. , Indicates the access record sequence. Indicates the total number of access records. Indicates the first The timestamp of each access record Indicates the first Access record, Indicates the node type; for access switches, it is denoted as... The access point is recorded as The wireless coverage area is denoted as , Indicates the node number. , , These represent the building number, floor number, and area number, respectively. , These represent the start time and end time of the association, respectively. and The time difference is used as the association duration, and only association durations that reach the access judgment threshold are retained. When multiple access records meet the conditions simultaneously, the association duration is compared first, and then the time sorting position is compared. The selected access record is then written to a fixed access position. , This indicates the node type with a fixed access location. The node number indicating the fixed access location. , , These represent the building number, floor number, and area number of the fixed access location, respectively.

[0101] The service interaction relationships of the same unauthenticated IoT terminal are sorted by time to obtain the service session sequence. , Represents a business session sequence. Indicates the total number of business session records. Indicates the first The timestamp of each business session record Indicates the first One business session record, Indicates the object number. Indicates the object type, Indicates the business system to which it belongs. , These represent the start time and end time of the business session, respectively. This indicates one of the following directions: data reporting direction, control distribution direction, or service response direction. The start point of the preset time period is denoted as... The preset time period length is recorded as Record any point in time within the preset time period as ,exist Internally, business session records are merged according to object number, object type, and the business system to which they belong. For each merged object, the number of business sessions is counted based on the number of business session records, and the cumulative communication duration is calculated based on the number of business session records. and The time difference is accumulated, and the time of the first business session establishment is taken as the earliest business session start time within the merged object. Only business sessions that have reached the session determination threshold are retained. And the cumulative communication duration reaches the communication determination threshold. When multiple merged objects meet the same conditions, the merged object with the earliest initial business session establishment time is selected first. Then, among the merged objects with the same initial business session establishment time, the merged object with the longest cumulative communication duration is selected. The selected merged object is written as the control interface object. , Indicates the object number that controls the interface. Indicates the object type that controls the interface. Indicates the business system to which the control interface belongs;

[0102] Retrieving the relevant business system from the business boundary information is equivalent to... The access area record uses a structured encoding of building number, floor number, and area number. When the access area record is a character address, it is converted into building number, floor number, and area number according to the park area encoding table. The access area record is written as , , This indicates the number of access area records. The area triplet in the fixed access location is written as... ,Will With all Compare each deployment area triplet. If there are identical deployment area triplets, select the identical deployment area triplet. If there are no identical deployment area triplets but there are deployment area triplets with identical building numbers and floor numbers, select the deployment area triplet with identical building numbers and floor numbers. If only there are deployment area triplets with identical building numbers, select the deployment area triplet with identical building numbers. If multiple deployment area triplets simultaneously meet the same selection condition, select the deployment area triplet with the earliest collection order. The selected deployment area triplet is written as... And the regional affiliation relationship is written as an eight-dimensional vector. , This indicates the corresponding marker for the building and its floors. and Time to take If the building number or floor number is inconsistent, take , Indicates the region corresponding to the marker, when Time to take When the area code is inconsistent, take ;

[0103] From business session sequence Extract object number, object type, business system to which it belongs, and control interface object. Consistent business session records, sorted by time to obtain a direction sequence. , Represents a direction sequence. Indicates the number of direction records. ,when Command for data reporting direction Otherwise ,when To control the direction of the command being issued Otherwise ,when For service response direction timing Otherwise Business chain location index Determine using the following formula:

[0104] ;

[0105] in, Indicates the business chain position index. This indicates that the direction indication values ​​are accumulated according to the index range. This indicates an indicator function; the value is taken when the condition within the parentheses is true. If the condition in parentheses is not met, then take... , This indicates taking the smaller of the two cumulative values. This indicates that the position index corresponding to the maximum value among the four components is taken. In the formula, the four components correspond to the reporting position, execution position, service position, and aggregation position, respectively. , , They represent the first Each direction record corresponds to the data reporting direction indicator, control sending direction indicator, and service response direction indicator. At that time, the second component is... When the four components have the same maximum value, the business chain position is determined in the order of execution position, aggregation position, reporting position, and service position, and then the business chain position is written as a four-dimensional vector. , Corresponding reporting location, Corresponding execution location, Corresponding service location Corresponding to the convergence location, and Take the corresponding component Take the three uncorresponding components ;

[0106] To enable the direct input layer of the KAN network with EPG dynamic packet forwarding constraints to include fixed access locations, control interfaces, regional affiliations, and service chain locations, integer numbering and fixed-length encoding are used to quantify node numbers, object numbers, and affiliated service system numbers. The campus network resource table stores integer numbers for access switches, access points, and wireless coverage areas; the service object resource table stores integer object numbers for controllers, gateways, and service platforms; and the service system resource table stores service system numbers. The campus network resource table assigns five-digit integer numbers to access switches, four-digit integer numbers to access points, and three-digit integer numbers to wireless coverage areas. The service object resource table assigns six-digit integer object numbers to controllers, gateways, and service platforms, and the service system resource table assigns four-digit integer system numbers to service systems. When the original identifier is a character type, it is mapped to an integer number of corresponding digits according to the registration order. The fixed access location is written as a sixteen-dimensional vector. , , to Write the five-digit access switch number in the order of ten thousand, thousand, hundred, tens, and units. If the node type is not an access switch, write the entire number. , to Write the four-digit access point number in the thousands, hundreds, tens, and units place values. If the node type is not an access point, write all digits. , to Write the three-digit wireless coverage area number in hundreds, tens, and units digits. If the node type is not a wireless coverage area, write the entire number. , , , Write the control docking object as a twelve-dimensional vector. , to Write the six-digit object number according to the place value of 100,000, 1 ... , Write the two-digit object type code, and write the controller as... The gateway is written as The business platform is written as , to Enter the four-digit business system ID for each digit (thousands, hundreds, tens, and units). Regional affiliation is directly represented by an eight-dimensional vector. ;

[0107] The KAN network with EPG dynamic packet forwarding constraint takes terminal deployment service characteristics as input and outputs a four-dimensional category attribution value. The input layer adopts a four-branch structure: the fixed access location branch is... The regional affiliation branch is Control the branch of the interface object as The business chain position branch is The final output dimensions of the fixed access location branch, regional affiliation branch, control interface object branch, and business chain location branch are respectively , , , The outputs of the four branches are concatenated in a fixed connection order to form a twelve-dimensional intermediate feature, which is then fed into a fused KAN structure with eight KAN neurons. The sixteen components are sequentially aligned to the side function units corresponding to the sixteen input neurons of the first layer of the fixed access position branch. The eight components are aligned dimension-wise to the side function units corresponding to the eight input neurons of the first layer of the region affiliation branch. The twelve components are sequentially aligned to the side function units corresponding to the twelve input neurons of the first layer of the control docking object branch. The four components are sequentially aligned to the side function units corresponding to the four input neurons of the first layer of the business chain position branch. The connection order of the four branches before fusion with the KAN structure is fixed as fixed access position branch, regional affiliation branch, control docking object branch, and business chain position branch. The forty-dimensional terminal deployment business features are obtained by splicing them together according to the fixed connection order. , The Wei Zhi Di Dimension is a fixed access location field, the first Wei Zhi Di Dimension is a region field, the first Wei Zhi Di Dimension is an object field, the first Wei Zhi Di The dimension is the link field.

[0108] In this embodiment, step S3 specifically includes:

[0109] The four EPG service categories corresponding to access control, environmental sensing, multimedia, and management equipment are defined as follows: , , , According to the preset category order of access control, environmental sensing, multimedia, and management equipment, , , , Write to output category space , Represents the output category space. , , , This represents four output neurons, which will and Establish a corresponding relationship, and and Establish a corresponding relationship, and and Establish a corresponding relationship, and and Establish a correspondence and configure the number of output neurons synchronously with the number of EPG service category definitions. Under the four service configurations of access control, environmental perception, multimedia, and management equipment, the number of output neurons is configured to be four, so that the category position in the output category space and the EPG service category definition are maintained in a one-to-one correspondence.

[0110] The characteristics of terminal deployment services are written as a 40-dimensional vector. , Indicates the characteristics of terminal deployment services, the first Wei Zhi Di Dimensions constitute the input vector of the fixed access location ,in, Indicates the node type code. to A fixed-length code representing the access switch number. to A fixed-length code representing the access point number. to A fixed-length code representing the wireless coverage area number. , , These represent the building number, floor number, and area number, respectively. Wei Zhi Di Dimensional constitutive region affiliation input vector ,in, , , These represent the building number, floor number, and area number of the fixed access location, respectively. , , These represent the building number, floor number, and area number, respectively, of the business system deployment area to which the control interface object belongs. This indicates the corresponding markers for building floors. Indicates the region corresponding to the marker, the first Wei Zhi Di Dimensional composition of the input vector of the control docking object ,in, to A fixed-length code representing the object number. , Indicates the object type code, to A fixed-length code representing the business system number to which it belongs, the first... Wei Zhi Di Dimensional structure constitutes the business chain position input vector ,in, Corresponding reporting location, Corresponding execution location, Corresponding service location Corresponding to the aggregation location, the input vectors for fixed access location, regional affiliation, control interface object, and service chain location are: The order of arrangement in the data is consistent with the path formed by the affiliation of business within the park.

[0111] Will The input dimension of the KAN network constrained by EPG dynamic packet forward shift is forty-dimensional, and the output dimension is four-dimensional. The network structure adopts a concatenated form of fixed access location branch, regional affiliation branch, control interface object branch, service chain location branch, and fused KAN structure. The fixed access location branch adopts... The structure consists of eight KAN neurons in the first layer, each receiving... The first layer has sixteen one-dimensional inputs, and the second layer has four KAN neurons that receive the outputs of the first layer and generate four-dimensional fixed access position branch features. The regional affiliation relationship branch adopts Structure, generating two-dimensional region attribution branch features Controlling the branch of the interface object Structure, generating four-dimensional control docking object branch features Business chain position branches adopt Structure, generating two-dimensional business chain position branch features Each KAN neuron consists of a side function unit and a summation unit. The side function unit receives a single-dimensional input and completes a univariate mapping. The summation unit aggregates the mapping results of all side function units within the same KAN neuron to obtain the output of the KAN neuron. The fixed access position input vector only enters the fixed access position branch, the region affiliation relationship input vector only enters the region affiliation relationship branch, the control docking object input vector only enters the control docking object branch, and the business chain position input vector only enters the business chain position branch. No cross-branch input is performed.

[0112] Will , , , By concatenating the data in the order of fixed access location, regional affiliation, control interface object, and business chain position, a twelve-dimensional intermediate feature is obtained. , Indicate intermediate features, The input is a fused KAN structure, which consists of eight KAN neurons. Each KAN neuron has twelve side function units and one summing unit, which receive inputs from the input KAN. The twelve components are used to generate an eight-dimensional fusion feature after univariate mapping and aggregation. , Indicates fusion characteristics, to These represent the output values ​​of the eight fused KAN neurons. The connection between the fused KAN structure and the output neurons is defined according to their class positions in the output class space: the class position is the... The output neuron receives the bit. and The category position is the first The output neuron receives the bit. and The category position is the first The output neuron receives the bit. and The category position is the first The output neuron receives the bit. and Therefore, the mapping calculation results received by the output neuron are consistent with the corresponding EPG service category definition.

[0113] The first The category position of each EPG service's classification in the output category space is denoted as . , will the The category classification value corresponding to each EPG business category definition is denoted as follows: The category affiliation value is generated using the following formula:

[0114] ;

[0115] In the formula, Indicates the first Each EPG service category defines a corresponding category classification value. This represents the category index defined by the EPG business category definition. Indicates the first Each EPG business category is defined by its category location index in the output category space. The component index represents the fused feature. Indicates fusion features The One portion, Indicates to to Summing all candidate fusion feature components. This indicates an indicator function that takes the value when the condition within the parentheses is true. The value is taken as follows when the condition inside the parentheses is not true. , Indicates the location relative to the category The corresponding starting index of the fusion feature, Indicates the location relative to the category The corresponding fusion feature end index, under the four types of service configurations: access control, environmental perception, multimedia, and management equipment. , , , ,therefore Depend on and generate, Depend on and generate, Depend on and generate, Depend on and The generation process directly extracts the corresponding components from the fused features according to the category position in the output category space and generates the category attribution value without introducing an intermediate conversion layer from device type to business attribution category;

[0116] Arrange the four class attribution values ​​according to the class order in the output class space to obtain a four-dimensional class attribution value vector. , Represents a vector of category affiliation values. , , , These correspond to the four EPG service categories defined respectively: access control, environmental sensing, multimedia, and management equipment. During model inference, service features are deployed for each terminal. A fixed forward prediction path is executed independently. The fixed forward prediction path consists of input splitting, branch mapping, branch feature generation, intermediate feature concatenation, fusion KAN mapping, and category attribution value generation. The input layer receives 40-dimensional terminal deployment business features, and the output layer generates a 4-dimensional category attribution value vector. The order of fixed access location, regional attribution relationship, control docking object, and business chain position is consistent with the order of receiving each branch and the order of concatenating intermediate features.

[0117] In this embodiment, step S4 specifically includes:

[0118] Category Attribution Value Vector Together with the four types of judgment fields in the terminal deployment service characteristics, they serve as inputs for consistency judgment. , , , These represent the category attribution values ​​corresponding to the four EPG service categories: access control, environmental sensing, multimedia, and management equipment. The fixed access location determination sub-vector is read from the terminal deployment service characteristics. ,in, , , These represent the building number, floor number, and area number in the fixed access location, respectively, and the area affiliation vector is read. The first three components represent the fixed access location area code, and the middle three components represent the deployment area code of the business system to which the control interface object belongs. This indicates the corresponding markers for building floors. Indicates the region corresponding to the marker, and reads the control docking object vector. , among which, the Wei Zhi Di Dimension represents the object number encoding, the first... Wei Zhi Di The dimension represents the object type code, the first... Wei Zhi Di The dimension represents the business system number code, and the business chain position vector is read. The four components correspond to the reporting location, execution location, service location, and aggregation location, respectively.

[0119] Define the business category for each EPG. Construction category determination criteria ,in, , Indicates fixed access location constraints, The bound access area is obtained by splitting it into building number, floor number, and area number according to the park area code table. This indicates a region affiliation constraint, where, , , Depend on The deployment region code corresponding to the field in the business system is obtained. The deployment region code adopts... The alignment result between the business system and the access area established during generation. exist and When written as Otherwise, write as , exist When written as Otherwise, write as , This indicates the constraints of the control interface object. Press and The same twelve-dimensional encoding method will Write in the bound service object number, service object type, and business system number. Indicates business chain position constraints. Adopted and Using the same four-dimensional encoding method, the access control is written as Environmental perception is written as Multimedia is written as Management equipment is written as ;

[0120] Will and A fixed access location matching flag is generated when all three fields are identical, based on a field-by-field comparison. A fixed access location matching tag is generated when any field is inconsistent. ,Will and A field-by-field comparison is performed; a region affiliation matching flag is generated when all eight fields match. If any field is inconsistent, a region affiliation matching flag is generated. ,Will and A field-by-field comparison is performed; a matching flag for the control interface object is generated when all twelve fields are identical. If any field is inconsistent, a control interface object matching flag is generated. ,Will and A field-by-field comparison is performed; a business chain position matching flag is generated when all four fields match. If any field is inconsistent, a business chain position matching flag is generated. ;

[0121] Definition of business category around the same EPG Establish a classification sequence , Matching results for corresponding fixed access locations Matching results for corresponding regional affiliation. The corresponding control over the matching results of the docking objects The corresponding business chain position matching result, when When Write ,when When Write ,when When Write ,when When Write ,when When Write ,when When Write ,when When Write ,when When Write ,Will , , , Add and then divide ,get Corresponding aggregate value ,Will and the attribution threshold In comparison, when , , , and At that time, This is denoted as a candidate target business category. When multiple candidate target business categories exist simultaneously, the candidate with the largest aggregation value is selected as the target business category. When multiple target business category candidates have the same aggregate value, the target business category candidate with the highest category position in the output category space is selected as the target business category. If no candidate category for the target business exists, a pending judgment marker is generated. There is a target business category. At that time, generate a flag to be judged. .

[0122] In this embodiment, step S5 specifically includes:

[0123] Record the uncertified IoT terminal identifier as , The target service category is obtained directly from the terminal identifier field in the access relationship. Mark the pending judgment as ,when At that time, With output category space EPG business category definition corresponding to the four category positions , , , Compare item by item, when When, write the category position as ,in, This indicates the category position of the target business in the output category space. Each EPG business category definition Read the business system Service recipients Access Area and EPG dynamic group identifier ,in, Indicates the first Each EPG business category defines the business system number it is bound to. Indicates the first Each EPG business category defines the service object it is bound to. Indicates the first Each EPG service category defines the access area code bound to it. Indicates the first Each EPG service category defines a corresponding integer-coded EPG dynamic group identifier. , , Composition of grouping mapping relationship ;

[0124] Will Based on the park area coding table, it is divided into access area triplets. The three components represent the building number, floor number, and area number, respectively. Write the four-dimensional business system code according to the business system numbering and coding rules. ,from The system reads the service object type field and generates a four-dimensional service object location code based on the fixed correspondence between the service object type and the business chain position. Access control correspondence Environmental perception corresponds Multimedia correspondence Management equipment corresponding Then read from the business system deployment table and The corresponding deployment region code is then broken down into deployment region triples. Generate a region affiliation constraint vector according to the field order of the region affiliation vector. , among which, the Wei Zhi Di Taken from , No. Wei Zhi Di Taken from , No. Wei Zai and When written as Otherwise, write as , No. Wei Zai When written as Otherwise, write as ;

[0125] From fixed access location vector Extract the building number, floor number, and area number to form a fixed access location triplet. From the control docking object vector Extract the relevant business system number code to form the control interface object business system code. The region affiliation vector is written as Write the business chain position vector as By category position Based on the corresponding grouping mapping relationship, and A field-by-field comparison is performed; if all three fields are identical, the result is written to a fixed access position for alignment. Write when there are inconsistent fields ,Will and A field-by-field comparison is performed; if all four fields are identical, the alignment result is written to the control interface object. Write when there are inconsistent fields ,Will and A field-by-field comparison is performed; if all four fields are identical, the business chain alignment result is written. Write when inconsistent fields exist ,Will and A field-by-field comparison showed that all eight fields were identical. and Write the region attribution alignment result Otherwise, write ,Will , , , Composition of group matching results ;

[0126] when and At that time, the EPG dynamic grouping identifier is determined jointly based on the category position of the target business category in the output category space and the grouping matching result. :

[0127] ;

[0128] In the formula, This indicates the EPG dynamic grouping identifier used in the target grouping results. Indicates the first Each EPG service category defines a corresponding integer-coded EPG dynamic group identifier. Indicates category index, This indicates the category position of the target business in the output category space. This indicates an indicator function; the value is set to true when the condition within the parentheses is true. The value is taken when the condition in parentheses is not met. , This indicates a series of multiplication operations. This indicates that the category index with the largest matching value within the parentheses is selected. This indicates the index of the fixed access location field. Represents a fixed access location triplet The One portion, Indicates the first Access area triplet The One portion, This indicates the index of the code field in the business system of the control interface object. Indicates the code of the business system controlling the interface. The One portion, Indicates the first Individual business system codes The One portion, This indicates the index of the business chain position field. Represents the business chain position vector The One portion, Indicates the first Location code of each service recipient The One portion, Index of the field representing the region affiliation relationship. Represents the vector of regional affiliation. The One portion, Indicates the first Region affiliation constraint vector The One component;

[0129] Fixed access location vector Regional affiliation vector Control docking object vector Business chain position vector The input is grouped into forty dimensions in a fixed order. Among them, the fixed access location vector is sixteen-dimensional, the regional affiliation vector is eight-dimensional, the control interface object vector is twelve-dimensional, and the business chain location vector is four-dimensional, thus classifying the location... As a one-dimensional category input, EPG dynamic grouping only accepts forty-dimensional grouping input. and one-dimensional category input ,Will , , , , , , Combined into target group results Then, the mapping table between EPG dynamic packets and the service network is written as follows: ,in, Indicates and The corresponding service network identifier, based on exist The business network identifier was obtained by searching in the middle. ,Will Associated with To form a business network ownership relationship ;

[0130] when At that time, do not proceed Calculate, , , , The direct combination is used as the access criterion for the network to be judged, and the pre-configured dynamic packet identifier of the EPG to be judged is recorded as... , will with The one-to-one corresponding network identifier to be judged is denoted as ,Will , , , , , The combination is the result of the group to be judged. Then Associated with This forms the network affiliation relationship to be determined. ;

[0131] The grouped inputs formed by the same unauthenticated IoT terminal in multiple decision windows are written as follows: ,in, Indicates the number of grouped inputs. When there is make and At that time, and Extract the business system codes of the control interface objects respectively, and perform fixed access location alignment, control interface object alignment, business chain location alignment, and regional affiliation relationship alignment respectively. The calculations generate different grouping matching results, different target grouping results, and different business network affiliations. and At that time, and Alignment is performed with the location code of the service object, resulting in different group matching results, different target group results, and different business network affiliation relationships.

[0132] In this embodiment, step S6 specifically includes:

[0133] Uncertified IoT terminal identifiers in the business network attribution relationship EPG dynamic group identifier Business network identifier Fixed access location vector corresponding to the same unauthenticated IoT terminal As input for business network access execution This indicates the EPG dynamic grouping identifier corresponding to the target business category. The fixed access location vector represents the service network identifier corresponding to the service network affiliation. The dimension Indicates the access object type code, number 1 Wei Zhi Di Dimension represents a fixed-length code for the access switch number, the dimensional Wei Zhi Di Dimension represents a fixed-length code for the access point number, the first dimension... Wei Zhi Di Dimension represents a fixed-length code for the wireless coverage area number, the dimensional... Wei Zhi Di Wei represents the building number, floor number, and area number. Written as , Indicates the type of access object associated with a fixed access location, when Read in the order of ten thousand, thousand, hundred, tens, and units. to Concatenate to generate a five-digit access switch number ,when Read in the order of thousands, hundreds, tens, and units. to Concatenate to generate a four-digit access number ,when Read in the order of hundreds, tens, and units. to Concatenate to generate a three-digit wireless coverage area number ,Will , , , , Composition of service access mapping , This represents the mapping record between the access switch, access point, or wireless coverage area associated with the fixed access location and the EPG dynamic packets and service networks corresponding to the target service category;

[0134] Will The service access policy table of the park network controller is written. When the park network controller receives an access report from an unauthenticated IoT terminal, it generates a current access execution record. ,in, Indicates the type of the currently accessed object. This indicates the current access object number. The current access execution record is directly generated from the port access events reported by the access switch, the link access events reported by the access point management module, and the associated events reported by the wireless controller. The campus network controller will... and Perform field-by-field comparison, when Consistent and At that time, it is determined that the current access object is consistent with the fixed access location mapping, and then... Write the EPG dynamic packet policy field to the corresponding access switch, access point, or wireless coverage area, and simultaneously... When writing to the corresponding business network forwarding table entry, if the access object type is an access switch, in the entry numbered... Write in the access switch policy entries and When the access object type is an access point, in the number of Write in the access policy entry and When the access object type is wireless coverage area, in the numbered Write in the wireless coverage area policy entry and After the park network controller completes the policy writing, it will associate the unauthenticated IoT terminal with... The corresponding EPG dynamic grouping will be used to connect uncertified IoT terminals. The corresponding business network;

[0135] Uncertified IoT terminal identifiers in the network attribution relationship to be determined EPG dynamic group identifier to be judged Network identifier to be judged Fixed access location vector corresponding to the same unauthenticated IoT terminal As input for the network access execution to be judged This indicates the EPG dynamic packet identifier corresponding to the network to be judged. The network identifier to be judged will still be... Written as and in accordance with The corresponding number fields are concatenated in order to generate ,Will , , , , Composition of access mapping to be determined , This represents a mapping record between the access switch, access point, or wireless coverage area associated with a fixed access location and the network to be judged.

[0136] Will The pending access policy table is written to the campus network controller. When the campus network controller receives an access report from an unauthenticated IoT terminal with a pending flag, it generates a current access execution record. and will and Perform field-by-field comparison, when Consistent and At that time, it is determined that the current access object is consistent with the network mapping to be judged, and then... Write the pending packet policy field to the corresponding access switch, access point, or wireless coverage area, and simultaneously... When writing to the network forwarding table entry to be judged, if the access object type is an access switch, in the entry numbered... Write in the access switch policy entries and When the access object type is an access point, in the number of Write in the access policy entry and When the access object type is wireless coverage area, in the numbered Write in the wireless coverage area policy entry and After the park network controller completes the policy writing, it associates the unauthenticated IoT terminals with the pending judgment tag with [the relevant authority / system]. The corresponding dynamic grouping of the EPG to be judged will be used to connect unauthenticated IoT terminals with the pending judgment tag. The corresponding network to be judged;

[0137] When the same unauthenticated IoT terminal generates multiple mapping records at different access locations, the park network controller will follow the instructions. Store the service access mapping separately for the index. Or pending access mapping The policy entries corresponding to different access switch numbers, different access point numbers, and different wireless coverage area numbers take effect independently, and the service network access and the network access to be judged are executed separately according to the hit mapping record.

[0138] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

[0139] This invention directly addresses the issue of business attribution for unauthenticated IoT terminals in campus laboratories, classrooms, computer rooms, and logistics areas through a closed-loop technical path encompassing business boundary definition, terminal deployment business feature construction, category attribution value generation, consistency determination, EPG dynamic grouping, and network access execution. It addresses scenarios where terminals lack account authentication, certificate authentication, and manual registration, and where unclear business attribution, difficulty in shifting business boundaries, and easy terminal mis-entry into business networks arise due to near-simultaneous fixed access locations, cross-deployment of controllers, gateways, or business platforms, and different business session directions. Under the condition of only readily available information such as access relationships, business interaction relationships, business deployment information, campus area codes, and business system deployment areas, this invention first addresses the issue through access control, environmental perception, and multi-channel... The service boundaries of media and management equipment generate EPG service attribution category definitions. Then, the fixed access location, regional attribution relationship, control interface object, and service chain location form terminal deployment service characteristics. The fixed access location branch, regional attribution relationship branch, control interface object branch, service chain location branch, and fused KAN structure are input to generate category attribution values ​​that correspond one-to-one with the output category space. Through the service boundary pre-positioning and joint feature modeling, this invention consolidates the service attribution criteria scattered in access nodes, deployment areas, communication objects, and communication directions into calculable, comparable, and aggregateable intermediate judgment quantities. This enables the category attribution values ​​to be stably generated around the same EPG service attribution category definition, providing a direct basis for subsequent service attribution confirmation.

[0140] Compared to common solutions that directly admit users to the network based solely on terminal address, access point, wireless coverage area, static entries, or single classification results, this invention does not directly use the KAN output as the final result. Instead, it extracts fixed access location constraints, regional affiliation constraints, control interface object constraints, and service chain location constraints from the EPG service affiliation category definition. It then matches the terminal deployment service characteristics field by field and aggregates the category affiliation values ​​pointing to the same EPG service affiliation category definition. The aggregated value is then compared with an affiliation threshold to determine consistency. The target service affiliation category is only confirmed when the fixed access location, regional affiliation, control interface object, and service chain location all correspond to the same EPG service affiliation category definition and the aggregated value reaches the affiliation threshold. If the aggregated value does not reach the threshold, the target service affiliation category is determined. When the affiliation threshold is reached, a pending label is generated, and a pending network affiliation relationship is further formed. Since the category position in the output category space, the EPG service affiliation category definition, the EPG dynamic grouping, and the service network affiliation relationship maintain a continuous correspondence, this invention can directly link the target service affiliation category to the network access execution process of the access switch, access point, or wireless coverage area. At the same time, it can import unauthenticated IoT terminals with unknown affiliation into the pending network, thereby forming a closed loop from service boundary definition to network-side execution. Furthermore, it can distinguish unauthenticated IoT terminals with different control docking objects under the same fixed access location, and it can also distinguish unauthenticated IoT terminals with different service chain positions under the same control docking object. This is more suitable for the service isolation and access control requirements in mixed deployment scenarios in parks.

Claims

1. A method for attributing services to unauthenticated IoT terminals based on dynamic grouping using KAN and EPG, characterized in that, include: S1. Obtain the access relationship and business interaction relationship of uncertified IoT terminals in the park, and generate EPG business category definition based on business boundaries; S2. Determine the fixed access location of the unauthenticated IoT terminal based on the access relationship, determine the control interface object of the unauthenticated IoT terminal based on the business interaction relationship, generate the area affiliation relationship based on the park area corresponding to the fixed access location and the control interface object, generate the business chain location based on the communication direction of the unauthenticated IoT terminal relative to the control interface object, and combine the fixed access location, area affiliation relationship, control interface object and business chain location to generate terminal deployment business characteristics. S3. Write the EPG service category definition into the output category space of KAN, and input the terminal deployment service characteristics into KAN for mapping calculation to generate the category value corresponding to the EPG service category definition. S4. Based on the EPG service category definition, determine the consistency between the category value and the terminal deployment service characteristics. When the fixed access location, regional affiliation, control interface object and service chain location all correspond to the same EPG service category definition, and the corresponding aggregation value reaches the affiliation threshold, generate the target service category. When the corresponding aggregation value does not reach the affiliation threshold, generate a pending judgment mark. S5. Perform EPG dynamic grouping on unauthenticated IoT terminals according to the target service category, generate service network affiliation relationship, and generate network affiliation relationship to be judged according to the pending label. S6. Connect the unauthenticated IoT terminal to the corresponding business network according to the business network affiliation, and connect the unauthenticated IoT terminal to the network to be judged according to the network affiliation to be judged.

2. The method for attribution of unauthenticated IoT terminal services based on dynamic KAN and EPG grouping according to claim 1, characterized in that, S1 specifically refers to: Collect business deployment information of access control, environmental sensing, multimedia and management equipment in the park's laboratories, classrooms, computer rooms and logistics areas, and extract business systems, service objects and access areas from the business deployment information to form business boundary information; Based on the business boundary information, access control, environmental sensing, multimedia and management equipment are identified as independent business categories, and these independent business categories are aligned with business systems, service objects and access areas to form the initial business category definition; Based on the initial business category definition, the category arrangement information is determined according to the fixed order of access control, environmental perception, multimedia and management equipment, so that each independent business category is established in a one-to-one correspondence with the output category space of KAN. Based on the initial business category definition and category arrangement information, each independent business category is bound to the EPG grouping relationship to generate the EPG business belonging category definition.

3. The method for attribution of unauthenticated IoT terminal services based on dynamic packetization using KAN and EPG according to claim 1, characterized in that, S2 specifically refers to: Extract access nodes from the access relationship where the association duration between unauthenticated IoT terminals and access switches, access points, or wireless coverage areas reaches the access judgment threshold, and match the access switch identifier, access point identifier, or wireless coverage area identifier with the building number, floor number, and area number to determine the fixed access location; Extract controllers, gateways, or business platforms from the business interaction relationships where unauthenticated IoT terminals establish a business session for the first time within a preset time period and the number of business sessions reaches the session judgment threshold and the communication duration reaches the communication judgment threshold. Then, merge the object number, object type, and the business system to which they belong to determine the control interface object. Based on the building number, floor number, and area number corresponding to the fixed access location, the area mapping is performed with the deployment area of ​​the business system to which the control interface object belongs, and the area mapping result is determined as the area affiliation relationship; Link positioning is performed based on the data reporting direction, control sending direction, and service response direction between the uncertified IoT terminal and the control interface object, and the link positioning result is determined as the business chain position among the reporting position, execution position, service position, or aggregation position. Based on the branch input structure of KAN, the fixed access position is aligned to the side function unit of the fixed access position branch, the control docking object is aligned to the side function unit of the control docking object branch, the regional affiliation relationship is aligned to the side function unit of the regional affiliation relationship branch, the service chain position is aligned to the side function unit of the service chain position branch, and the input arrangement relationship is formed according to the connection order of each branch before the KAN structure is integrated. Based on the input arrangement, the fixed access location is written into the preorder field, the regional affiliation is written into the region field, the control interface object is written into the object field, the business chain location is written into the link field, and the terminal deployment business characteristics are generated by combining them in a fixed order.

4. The method for attribution of unauthenticated IoT terminal services based on dynamic packetization using KAN and EPG as described in claim 1, characterized in that, S3 specifically refers to: The EPG service attribution category definition is written into the output category space of KAN in a preset category order, and the output neurons are configured according to the number of EPG service attribution category definitions, so that each output neuron establishes a correspondence with an EPG service attribution category definition; The terminal deployment service characteristics are input into a KAN consisting of a fixed access location branch, a regional affiliation branch, a control docking object branch, a service chain location branch, and a converged KAN structure. The fixed access location is input into the fixed access location branch, the regional affiliation branch is input into the regional affiliation branch, the control docking object is input into the control docking object branch, and the service chain location is input into the service chain location branch. In the fixed access location branch, regional affiliation branch, control docking object branch, and business chain location branch, the corresponding inputs are split into single-dimensional inputs, and the single-dimensional inputs are respectively input into the side function units of the corresponding KAN neurons for unary mapping. Then, the summation unit aggregates the unary mapping results to form the branch features corresponding to each branch. The branch features are concatenated in the order of fixed access location, regional affiliation, control interface object and business chain position to form intermediate features, and the intermediate features are input into the fusion KAN structure; In the fused KAN structure, intermediate features are input into the side function units of the KAN neurons for mapping calculation, and then the summation unit aggregates the mapping calculation results. The connection relationship between the fused KAN structure and the output neurons is limited according to the EPG service affiliation category definition, so that each output neuron receives intermediate features consistent with the corresponding EPG service affiliation category definition. Based on the mapping calculation results of the output neurons to the intermediate features, the category affiliation values ​​corresponding to the business affiliation categories of each EPG are generated respectively.

5. The method for attribution of unauthenticated IoT terminal services based on dynamic KAN and EPG grouping according to claim 1, characterized in that, S4 specifically refers to: Based on the EPG business affiliation category definition, fixed access location constraints, regional affiliation constraints, control interface object constraints, and business chain location constraints are extracted to form the category determination basis; The fixed access location, regional affiliation, control interface object, and business chain location in the terminal deployment business characteristics are matched with the category determination criteria, and the matching results are categorized by pointing to the category affiliation value defined in the same EPG business affiliation category. The categorized category values ​​are aggregated to obtain the aggregated value corresponding to the category definition of each EPG business, and the aggregated value is compared with the category threshold. When the fixed access location, regional affiliation, control interface object, and business chain location all correspond to the same EPG business affiliation category definition and the aggregation value reaches the affiliation threshold, a target business affiliation category is generated. When the aggregation value does not reach the affiliation threshold, a pending judgment mark is generated.

6. The method for attribution of unauthenticated IoT terminal services based on dynamic KAN and EPG grouping according to claim 1, characterized in that, S5 specifically refers to: Based on the category position of the target service category in the output category space, determine the EPG service category definition corresponding to the target service category, and extract the business system, service object and access area from the EPG service category definition to form a grouping mapping relationship. Based on the group mapping relationship, the fixed access location is aligned with the access area, the control interface object is aligned with the business system, the business chain location is aligned with the service object, and the area affiliation relationship is associated with the alignment results of the fixed access location and the control interface object to form the group matching result; Based on the grouping matching results, the fixed access location, regional affiliation, control interface object, and service chain location are combined as the grouping input for EPG dynamic grouping, and the category location corresponding to the target service affiliation category is used as the category input for EPG dynamic grouping to form the target grouping result; Based on the target grouping results, the unauthenticated IoT terminal is associated with the EPG dynamic group corresponding to the target service category, and the service network corresponding to the unauthenticated IoT terminal is determined according to the mapping relationship between the EPG dynamic group and the service network, thus generating the service network affiliation relationship. Based on the pending markers, the combination of fixed access location, regional affiliation, control interface object, and business chain location is used as the access basis for the pending network to form the pending grouping results; Based on the results of the pending grouping, unauthenticated IoT terminals are associated with the pending network, generating the affiliation relationship of the pending network.

7. The method for attribution of unauthenticated IoT terminal services based on dynamic KAN and EPG grouping according to claim 1, characterized in that, S6 specifically refers to: Extract the fixed access location corresponding to the unauthenticated IoT terminal based on the business network affiliation, and map the access switch, access point or wireless coverage area associated with the fixed access location to the EPG dynamic group corresponding to the target business affiliation category; Based on the mapping between the access switch, access point, or wireless coverage area associated with the fixed access location and the EPG dynamic group corresponding to the target service category, service network access is performed on the access switch, access point, or wireless coverage area, and unauthenticated IoT terminals are accessed to the service network corresponding to the service network affiliation relationship. Extract the fixed access location corresponding to the unauthenticated IoT terminal based on the network affiliation relationship to be determined, and map the access switch, access point or wireless coverage area associated with the fixed access location to the network to be determined; Based on the mapping between the access switch, access point, or wireless coverage area associated with the fixed access location and the network to be judged, access to the network to be judged is performed on the access switch, access point, or wireless coverage area, and unauthenticated IoT terminals with pending judgment tags are connected to the network to be judged.

8. The method for attribution of unauthenticated IoT terminal services based on dynamic packetization using KAN and EPG according to claim 3, characterized in that, When multiple access switches, access points, or wireless coverage areas in the access relationship all reach the access judgment threshold in terms of association duration, the access switch, access point, or wireless coverage area with the longest association duration is determined as the fixed access location. When multiple controllers, gateways, or service platforms in the service interaction relationship all meet the requirements of establishing a service session for the first time, having a service session count that meets the session judgment threshold, and having a communication duration that meets the communication judgment threshold within a preset time period, the controller, gateway, or service platform with the earliest establishment of the service session is first determined as the priority object, and then the controller, gateway, or service platform with the longest communication duration among the priority objects is determined as the control docking object.

9. The method for attribution of unauthenticated IoT terminal services based on dynamic KAN and EPG grouping according to claim 4, characterized in that, The order of fixed access location, regional affiliation, control interface object, and service chain location in the terminal deployment service features is consistent with the input order of the fixed access location branch, regional affiliation branch, control interface object branch, and service chain location branch. It is also consistent with the order in which the branch features corresponding to the fixed access location branch, regional affiliation branch, control interface object branch, and service chain location branch are spliced ​​together to form intermediate features in the order of fixed access location, regional affiliation, control interface object, and service chain location.

10. The method for attribution of unauthenticated IoT terminal services based on KAN and EPG dynamic grouping according to claim 6, characterized in that, When generating group matching results based on group mapping relationships, if unauthenticated IoT terminals correspond to the same fixed access location but have different control docking objects, the different control docking objects are aligned with the business system respectively, resulting in different group matching results and different target group results, thereby generating different business network affiliation relationships. If unauthenticated IoT terminals correspond to the same control docking object but have different business chain positions, the different business chain positions are aligned with the service objects respectively, resulting in different group matching results and different target group results, thereby generating different business network affiliation relationships.