BACnet object semantic constraint based MQTT bidirectional control method
Patent Information
- Application Number
- CN202611241714.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-17
- Publication Date
- 2026-09-22
AI Technical Summary
然而,消息队列遥测传输协议(MQTT)本身仅提供消息传输通道,不具备对BACnet工业控制对象的状态合法性、写入权限、值域边界和对象间联动约束的感知与执行能力
[0027]1、本发明通过构建对象间语义控制约束图(SCCG)和维护消息队列遥测传输协议(MQTT)通信行为状态机,实现在跨协议通信过程中对楼宇自动控制网络数据通信协议(BACnet)工业控制行为的语义约束保持与安全控制。
Smart Images

Figure CN122802554A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial Internet of Things and building automation network communication technology, and in particular to a bidirectional control method for MQTT based on BACnet object semantic constraints. Background Technology
[0002] BACnet (Building Automation and Control Networks) is a core communication protocol for building automation defined by the international standard ISO 16484-5. It defines dozens of standard object types, including analog input (AI), analog output (AO), binary input (BI), binary output (BO), multi-state input (MSI), multi-state output (MSO), analog value (AV), and binary value (BV). The control behavior of BACnet objects is constrained by BACnet standard semantics, including object writability, value range, write priority (WritePriority levels 1-16), inter-object state dependencies (e.g., HVAC operating mode determines fan speed), and cross-subsystem linkage relationships (e.g., locking lighting control after a fire alarm is triggered, or forcibly increasing the priority of HVAC control).
[0003] Message Queuing Telemetry Transport Protocol (MQTT) is a lightweight publish / subscribe messaging protocol widely used in the Internet of Things (IoT) field. In smart building scenarios, MQTT is needed to send control commands from the cloud to BACnet devices. However, MQTT itself only provides a message transmission channel and lacks the ability to perceive and execute the legality of the state of BACnet industrial control objects, write permissions, value boundaries, and inter-object linkage constraints.
[0004] The existing technology has the following key shortcomings: (a) Lack of ability to maintain semantic constraints for industrial control. Existing solutions treat BACnet objects as general data nodes and do not understand the state dependencies and linkage constraints between BACnet objects. For example, the HVAC mode determines the writability of the fan, and lighting control should be locked under fire alarm status. It is impossible to maintain the semantic legitimacy of industrial control behavior during cross-protocol communication. (b) Lack of control source conflict arbitration mechanism. Message Queuing Telemetry Transport Protocol (MQTT), as an open protocol, allows multiple subscribers to issue control commands simultaneously. Existing solutions cannot distinguish the priority of different control sources such as fire linkage, manual forced control, local direct digital controller (DDC) control, and cloud remote control, and cannot perform arbitration based on semantic priority when multiple control commands conflict. (c) Lack of secure control state switching under communication anomalies. When the Message Queuing Telemetry Transport Protocol (MQTT) network experiences abnormal states such as broker congestion, persistent acknowledgment (ACK) timeouts, or excessively high retransmission rates, the existing solution will not automatically switch to a security control mode, such as freezing remote writes or retaining only the local BACnet control channel. This may lead to erroneous command issuance or command loss due to unreliable communication.
[0005] Existing BACnet-to-Message Queuing Telemetry Transport Protocol (MQTT) communication methods lack the ability to maintain the semantic constraints of BACnet industrial control objects during cross-protocol control processes. Specifically, they cannot maintain the writability constraints, value range constraints, inter-object state dependency constraints, and control source priority constraints of BACnet objects at the MQTT communication layer, and they lack a secure control state switching mechanism when the MQTT network state is abnormal.
[0006] Therefore, how to provide a bidirectional control method for MQTT based on the semantic constraints of BACnet objects is an urgent problem to be solved. Summary of the Invention
[0007] This invention provides a bidirectional control method for MQTT based on BACnet object semantic constraints to solve the aforementioned technical problems in the prior art.
[0008] According to a first aspect of the present invention, a bidirectional control method for MQTT based on BACnet object semantic constraints is provided.
[0009] In one embodiment, the MQTT bidirectional control method based on BACnet object semantic constraints includes:
[0010] Based on the object list attributes of the building automation network data communication protocol object, an object semantic descriptor is constructed, and the object semantic descriptor is updated and parameters are bound in combination with network operation layer data to obtain the associated object semantic descriptor.
[0011] The message queue telemetry transport protocol topic is constructed based on the associated object semantic descriptor, and differentiated transport behavior control strategies are generated by combining network operation status parameters.
[0012] Based on the differentiated transmission behavior control strategy and the associated object semantic descriptor, the output parameters of the semantic strategy engine are determined;
[0013] The message payload is dynamically constructed by combining the output parameters of the semantic strategy engine with the associated object semantic descriptor.
[0014] By constructing a semantic control constraint graph through differentiated transmission behavior control strategies and associated object semantic descriptors, and combining message payloads for verification, arbitration, and security control state checks, a secure two-way closed-loop control for data reporting and command issuance under the message queue telemetry transmission protocol is achieved.
[0015] According to a second aspect of the present invention, an MQTT bidirectional control system based on BACnet object semantic constraints is provided.
[0016] In one embodiment, the MQTT bidirectional control system based on BACnet object semantic constraints includes:
[0017] The object semantic descriptor construction module is used to construct object semantic descriptors based on the object list attributes of the building automation network data communication protocol object, and update and bind parameters to the object semantic descriptors in combination with network operation layer data to obtain the associated object semantic descriptors;
[0018] The transmission behavior control strategy generation module is used to construct message queue telemetry transmission protocol topics based on the associated object semantic descriptors, and generate differentiated transmission behavior control strategies in combination with network operation status parameters.
[0019] The semantic strategy engine parameter determination module is used to determine the output parameters of the semantic strategy engine based on the differentiated transmission behavior control strategy and the associated object semantic descriptor.
[0020] The message payload construction module is used to dynamically construct the message payload by combining the output parameters of the semantic strategy engine with the associated object semantic descriptor.
[0021] The bidirectional closed-loop control module is used to construct a semantic control constraint graph through differentiated transmission behavior control strategies and associated object semantic descriptors, and to perform verification, arbitration, and security control state checks in conjunction with message payloads, so as to realize secure bidirectional closed-loop control of data reporting and command issuance under the message queue telemetry transmission protocol.
[0022] According to a third aspect of the present invention, a computer device is provided.
[0023] In some embodiments, the computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the MQTT bidirectional control method based on BACnet object semantic constraints described above.
[0024] According to a fourth aspect of the present invention, a computer-readable storage medium is provided.
[0025] In one embodiment, a computer program is stored on a computer-readable storage medium, and when the computer program is executed by a processor, it implements the steps of the MQTT bidirectional control method based on BACnet object semantic constraints described above.
[0026] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:
[0027] 1. This invention achieves semantic constraint maintenance and security control of industrial control behavior of Building Automation Network Data Communication Protocol (BACnet) during cross-protocol communication by constructing an inter-object semantic control constraint graph (SCCG) and maintaining a state machine for Message Queuing Telemetry Transport Protocol (MQTT) communication behavior.
[0028] 2. This invention maintains the semantic constraints of industrial control, that is, by constructing a semantic control constraint graph (SCCG) between objects, it maintains the state dependency constraints and linkage constraints between BACnet objects during cross-protocol communication, ensuring that the remote control of Message Queue Telemetry Transport Protocol (MQTT) does not violate the semantic legality of the BACnet industrial control system.
[0029] 3. This invention switches the security control state under communication anomalies, that is, through the Message Queue Telemetry Transport Protocol (MQTT) communication behavior state machine, such as normal / congestion / safe mode / recovery, to automatically prohibit remote writing, retain only alarm reporting, and perform hierarchical recovery based on control criticality when communication is severely abnormal.
[0030] 4. This invention resolves conflicts when multiple Message Queuing Telemetry Transport Protocol (MQTT) control sources write concurrently through cross-protocol control conflict arbitration, namely, through a four-level classification of control sources and a priority-based arbitration mechanism.
[0031] 5. This invention achieves cascading propagation and dynamic activation of object constraints at runtime through the semantic control constraint graph (SCCG), that is, through state dependency edges and linkage edges in the directed graph, rather than static rule lookup.
[0032] 6. This invention uses state-condition driven Message Queuing Telemetry Transport Protocol (MQTT) behavior control, that is, the MQTT Quality of Service (QoS) level and publishing strategy are jointly determined by the current state of the communication behavior state machine and the control condition parameters of the object, rather than the result of isolated mathematical formula calculations.
[0033] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the invention. Attached Figure Description
[0034] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0035] Figure 1 This is a flowchart illustrating an MQTT bidirectional control method based on BACnet object semantic constraints, according to an exemplary embodiment.
[0036] Figure 2 This is a schematic diagram illustrating the structure of an MQTT bidirectional control system based on BACnet object semantic constraints, according to an exemplary embodiment.
[0037] Figure 3 This is a schematic diagram of the structure of a computer device according to an exemplary embodiment;
[0038] Figure 4 This is an SMG system architecture diagram illustrated according to an exemplary embodiment;
[0039] Figure 5 This is a flowchart illustrating the semantic classification process of BACnet objects according to an exemplary embodiment;
[0040] Figure 6 This is an example diagram illustrating the adaptive construction of an MQTT Topic according to an exemplary embodiment;
[0041] Figure 7 This is an example diagram illustrating the adaptive construction of an MQTT payload according to an exemplary embodiment;
[0042] Figure 8 It is a flowchart illustrating the construction of an inter-object semantic control constraint graph according to an exemplary embodiment;
[0043] Figure 9 This is a flowchart illustrating the multidimensional constraint verification process in the reverse control process according to an exemplary embodiment;
[0044] Figure 10 This is a schematic diagram illustrating the switching between the MQTT communication behavior state machine and the security control state according to an exemplary embodiment.
[0045] Figure label:
[0046] 201. Object semantic descriptor construction module; 202. Transmission behavior control strategy generation module; 203. Semantic strategy engine parameter determination module; 204. Message payload construction module; 205. Two-way closed-loop control module. Detailed Implementation
[0047] The following description and accompanying drawings fully illustrate specific embodiments described herein to enable those skilled in the art to practice them. Some portions and features of certain embodiments may be included in or replace portions and features of other embodiments. The scope of the embodiments herein includes the entire scope of the claims and all available equivalents thereof. The various embodiments described herein are presented in a progressive manner, with each embodiment focusing on its differences from other embodiments; similar or identical parts between embodiments can be referred to interchangeably.
[0048] The modules in the apparatus or system of this application can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0049] Where there is no conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.
[0050] Figure 1 An embodiment of the MQTT bidirectional control method based on BACnet object semantic constraints of the present invention is shown.
[0051] In this optional embodiment, the MQTT bidirectional control method based on BACnet object semantic constraints includes:
[0052] Step S101: Based on the object list attributes of the building automation network data communication protocol object, construct an object semantic descriptor, and update and bind parameters to the object semantic descriptor in combination with network operation layer data to obtain the associated object semantic descriptor.
[0053] In this optional embodiment, an object semantic descriptor is constructed based on the object list attributes of the building automation network data communication protocol object. This object semantic descriptor is then updated and its parameters are bound using network operation layer data, resulting in an associated object semantic descriptor including:
[0054] The semantic mapping gateway obtains the object list attributes of the target building automation network data communication protocol device by reading the multi-attribute service, and obtains the object type enumeration values of all building automation network data communication protocol objects based on the object list attributes;
[0055] Based on the object type enumeration value, the semantic mapping gateway is used to read the object's semantic attributes, and the object's semantic descriptor is constructed based on the object list attributes and the object's semantic attributes.
[0056] Based on the object semantic descriptor and the object label field, the object semantic descriptor is updated to obtain the updated object semantic descriptor.
[0057] In this optional embodiment, the object semantic descriptor is updated based on the object semantic descriptor and the object tag field, resulting in an updated object semantic descriptor including:
[0058] The semantic mapping gateway performs semantic classification on the data communication protocol objects of the building automation control network based on the object type in the object semantic descriptor, and obtains preliminary object semantic classification results.
[0059] Read the object label field in the protocol implementation consistency declaration file and statically correct the preliminary object semantic classification results to obtain the corrected classification results;
[0060] The corrected classification results are then updated to the object semantic descriptor, resulting in the updated object semantic descriptor.
[0061] Based on the protocol layer attributes in the object semantic descriptor and the network operation layer data from network status monitoring statistics, the control condition parameters of each building automation control network data communication protocol object are calculated using the semantic mapping gateway.
[0062] The control condition parameters are associated and stored in the updated object semantic descriptor to obtain the associated object semantic descriptor.
[0063] It should be further explained that the specific implementation steps for object semantic type extraction and object semantic descriptor construction in the Building Automation Network Data Communication Protocol (BACnet) include: The Semantic Mapping Gateway (SMG) reads the object list attributes of the target BACnet device through the BACnet ReadPropertyMultiple service, and obtains the object type (Object_Type) enumeration values of all BACnet objects in the device. For each BACnet object, the SMG further reads its core semantic attributes, constructs an Object Semantic Descriptor (OSD), and writes it to the OSD cache.
[0064] The OSD data structure includes the following fields: (a) Object Type: BACnet standard object type enumeration value; (b) Object Identifier: A globally unique identifier composed of a triplet of Device Instance, Object Type, and Instance Number; (c) Property Access: A set of read and write attributes of the object, extracted from the BACnet standard attribute table, and summarized into a Property Access vector; (d) Engineering Units: If the object carries an Engineering Units attribute, such as BACnet attribute ID=117, its enumeration value is extracted; (e) Value Range: A closed range of values extracted from the minimum current value (Min_Pres_Value) and maximum current value (Max_Pres_Value) of the BACnet standard attribute; (f) Event Class: If the object is an event enrollment or notification class... The `Class` type extracts the event category (`Event_Class`) and notification category (`Notification_Class`) attribute values.
[0065] like Figure 5As shown, it illustrates the classification rules and OSD generation process from the BACnet Object_Type enumeration value to four semantic categories: telemetry / control / status / alarm. The semantic classification process for BACnet device objects is as follows: The Object_Type enumeration value of the BACnet device is read; its core attributes, including writability, value range, and unit, are read; an Object Semantic Descriptor (OSD) is constructed based on the above information and written to the OSD cache; then, preliminary semantic classification is performed based on Object_Type, dividing Object_Type into four categories according to the preliminary classification rules: telemetry, control, status, and alarm; the classification result enters the judgment node, which reads the object label field of the PICS file. If the label semantics are consistent with the default classification, the update step is performed directly; otherwise, the correction process is initiated. The correction process includes: correcting the semantic category of the object based on the tag semantics, and then performing primary and secondary semantic determination for composite objects, with the priority order being: Alarm > Control > Status > Telemetry; generating the final semantic category accordingly, explicitly listing four possibilities: Telemetry / Control / Status / Alarm; and updating the OSD cache with complete information including Object_Type, core attributes, and the final semantic category. Specifically, the SMG classifies BACnet objects into the following semantic categories based on their object type (Object_Type): Telemetry = {ANALOG_INPUT, ANALOG_VALUE, MULTI_STATE_INPUT}; Control = {ANALOG_OUTPUT, BINARY_OUTPUT, MULTI_STATE_OUTPUT}; Status = {BINARY_INPUT, BINARY_VALUE}; Alarm = {EVENT_ENROLLMENT, NOTIFICATION_CLASS}. For composite objects, such as loops, programs, schedules, and trend logs, a primary-secondary semantic mechanism is used, with priority determined as alarm class > control class > status class > telemetry class.
[0066] SMG reads the object tag field from the Protocol Implementation Conformity Statement (PICS) file of the BACnet device and statically corrects the preliminary classification result based on object type (Object_Type). That is, if the tag field of an object in the PICS file marks a semantic role that is inconsistent with the default classification, for example, an analog value object is marked by the manufacturer as a critical alarm indicator, then its semantic category is adjusted according to the tag field, and the corrected classification result is updated to the OSD cache to obtain the updated object semantic descriptor.
[0067] Based on the BACnet protocol layer attributes in the OSD and the network operation layer data statistically collected by the network status monitoring module, the SMG calculates the following control condition parameters for each object and writes them into the OSD cache: (a) Reliability condition parameters: determined jointly by the event category (Event_Class) attribute value and the event priority configuration of its associated notification category (Notification_Class). That is, if the object carries a life safety alarm event definition, it is marked as high reliability (HIGH_RELIABILITY) according to the event priority configuration associated with its notification category (Notification_Class); if the object has a retransmission rate ≥5% or an acknowledgment (ACK) timeout count ≥3 in the last 60 seconds of Message Queuing Telemetry Transport Protocol (MQTT) transmission, it is marked as improved reliability (ELEVATED_RELIABILITY). When the object has a life safety linkage edge or a critical control constraint edge in the Semantic Control Constraint Graph (SCCG), the SMG activates the high reliability transmission constraint, and the communication behavior state machine enters the high reliability transmission strategy according to the constraint, performing quality of service (QoS) enhancement and degradation restrictions on the corresponding Message Queuing Telemetry Transport Protocol (MQTT) transmission behavior. (b) Real-time condition parameters: Determined by the change increment (COV_Increment) attribute value, i.e., the SMG reads the change increment (COV_Increment) attribute of the object. The smaller the change increment threshold, the stricter the real-time condition. Based on the comparison result between the threshold and the preset level, it is marked as high real-time (HIGH_REALTIME), for example, change increment (COV_Increment) ≤ 0.5 or alarm objects, normal real-time (NORMAL_REALTIME), or low real-time (LOW_REALTIME). (c) Bandwidth condition parameters: Determined by the object change frequency statistics, i.e., the SMG counts the number of times the object's current value (Present_Value) changes within a sliding time window, for example, the default 60 seconds. When the object change frequency exceeds the preset threshold, a high-frequency change constraint is activated in the Semantic Control Constraint Graph (SCCG) cache. The communication behavior state machine adjusts the Message Queue Telemetry Transport Protocol (MQTT) publishing mode based on this constraint.(d) Control Criticality Condition Parameters: These are determined by whether the object is an AO / BO / MSO writable control object, whether it carries a WritePriority attribute and a minimum write priority value, and whether it is marked as a critical infrastructure associated object in the Semantic Control Constraint Graph (SCCG), such as fire linkage objects or security interlock objects. Specifically, if it is a control object, it is marked as a control object (CONTROL_OBJECT); if the minimum write priority is ≤5 or it is marked as a critical infrastructure associated object in the Semantic Control Constraint Graph (SCCG), it is further marked as a critical control object (CRITICAL_CONTROL). These control condition parameters are stored in the OSD cache in association with OSD fields to obtain the associated object semantic descriptor. Updates are triggered when the corresponding BACnet attribute value or network statistics value changes.
[0068] Step S102: Construct a message queue telemetry transmission protocol topic based on the associated object semantic descriptor, and generate differentiated transmission behavior control strategies in combination with network operation status parameters.
[0069] In this optional embodiment, constructing a message queue telemetry transport protocol topic based on the associated object semantic descriptor and generating differentiated transport behavior control strategies in conjunction with network operating status parameters includes:
[0070] The semantic mapping gateway constructs a policy based on the topics output by the semantic policy engine, and combines the semantic categories in the associated object semantic descriptors to construct a message queue telemetry transmission protocol topic for each building automation network data communication protocol object.
[0071] The network operating state parameters are determined based on the Message Queuing Telemetry Transport Protocol (MQTP) communication behavior state machine, and differentiated strategies are generated by combining the MQTP topics to obtain differentiated transmission behavior control strategies.
[0072] It should be added that, such as Figure 6 As shown, it uses four semantic categories as examples to illustrate the differences in the Topic hierarchy structure generated by different categories of objects. Figure 6This is an example of adaptive MQTT Topic building, divided into four main branches: Telemetry, Control, Status, and Alarm. The Telemetry branch generates attribute topics with a device / object / instance / property hierarchy. The Control branch has two branches: Control Command topics (cmd) and Control Result topics (cmd / result). The Control Command topic is device / object / instance / cmd, and the Control Result topic is device / object / instance / cmd / result. The Status branch generates attribute topics with a device / object / instance / property hierarchy. The Alarm branch generates priority prefixes with a priority / device / object / instance hierarchy. Figure 7 As shown, it illustrates the differences in the payload structure and semantic metadata embedding methods of the four types of objects. Figure 7All payloads consist of business data and semantic metadata, which provides semantic constraints and interpretability support. Telemetry metadata includes fields such as type, unit, range, reliability, and timestamp. Control metadata includes fields such as source, priority, reliability, and timestamp. Status metadata includes fields such as state_map, type, reliability, and timestamp. Alarm metadata includes fields such as event_class, priority, reliability, and timestamp. Semantic mapping relationships: Engineering_Units maps to unit; State_Text maps to state_map; Event_Class maps to priority; Value_Range maps to range. Reliability represents the data reliability level, and timestamp represents the reporting / generation time. The construction of a Message Queuing Telemetry Transport Protocol (MQTT) Topic includes the following steps: The Semantic Mapping Gateway (SMG) constructs an MQTT Topic for each BACnet object based on the Topic construction strategy output by the Semantic Processing Engine (SPE). Topics adopt a base hierarchy of {Device_ID} / {Object_Type_Name} / {Instance_Number}, with subtopics for telemetry class extended attributes, control class extended commands (cmd), and command results (cmd / result). For alarm objects, a priority identifier is embedded in the Topic prefix. Specifically, the SMG reads the Notification_Class attribute of the alarm object and the event priority configuration defined in its associated Event_Class, and determines the priority identifier level in the Topic prefix based on this event priority configuration, rather than directly using the Notification_Class enumeration value as a fixed mapping basis.
[0073] Step S103: Based on the differentiated transmission behavior control strategy and the associated object semantic descriptor, determine the output parameters of the semantic strategy engine.
[0074] In this optional embodiment, the semantic policy engine output parameters are determined based on the differentiated transmission behavior control strategy and the associated object semantic descriptor, including:
[0075] The network status monitoring data is matched with preset status switching conditions, and the current operating status identifier is determined based on the matching results.
[0076] Input the current running status identifier into the differentiated transmission behavior control strategy, and combine it with the control condition parameters and semantic attribute fields in the associated object semantic descriptor to determine the state-in-state control behavior for each state.
[0077] The semantic strategy engine comprehensively analyzes and dynamically adapts the in-state control behavior to obtain the output parameters of the semantic strategy engine.
[0078] It should be added that, such as Figure 10 As shown, it illustrates the switching conditions of four states: NORMAL, CONGESTION, SAFE_MODE, and RECOVERY, the control strategies executed within each state, and the interaction with the SCCG cache during state transitions. In NORMAL mode, bidirectional communication occurs. Congestion triggers entry into CONGESTION mode for degraded transmission; if congestion is relieved, it returns to NORMAL mode. In SAFE_MODE, severe congestion triggers entry into SAFE_MODE, where remote writes are frozen. After the SAFE_MODE error is resolved, it enters RECOVERY mode for tiered recovery. If the error recurs, it re-enters SAFE_MODE. Once recovery is complete and the network is stable (N windows), it returns to NORMAL mode. The SCCG security protection module, which triggers security protection based on mode, includes four components: traversing control nodes, setting Writable_Flag to False, pausing non-alarm topics, and keeping linked edges active. The SCCG security protection module updates the write protection status to the SCCG cache module, which stores control nodes, criticality flags, writable flags (Writable_Flag), and linked edge information. The recovery module, which triggers hierarchical recovery based on mode, includes four components: reading criticality flags, restoring Writable_Flag, restoring topics in batches, and updating the recovery status. The SCCG hierarchical recovery module and the SCCG cache perform criticality / writable flag reading and recovery status update. Figure 10 In the diagram, the red arrow indicates that the interaction with SCCG is in safe mode, where the security module actively traverses and modifies the cache to form a write-protected state; the blue arrow indicates that the interaction with SCCG is in recovery mode, where the recovery module reads and updates the cache information to achieve tiered recovery. Figure 10In the diagram, solid black arrows indicate state transitions when conditions are met; dashed black arrows indicate fallback transitions when conditions are not met; red arrows represent the interaction between safe mode and SCCG; blue arrows represent the interaction between recovery mode and SCCG. The state machine switches control strategies based on the MQTT communication operation state, triggering SCCG security protection in safe mode and SCCG hierarchical recovery in recovery mode, thus achieving protection and orderly recovery of the controlled object. The Message Queuing Telemetry Transport Protocol (MQTT) communication behavior state machine and transmission behavior control include the following: The Semantic Mapping Gateway (SMG) internally maintains the MQTT communication behavior state machine, which is the core mechanism for MQTT transmission behavior control. The state machine defines four operating states: NORMAL, CONGESTION, SAFE_MODE, and RECOVERY. The current state determines the MQTT transmission behavior strategy framework for all BACnet objects. The state transition conditions and control behaviors in each state are as follows:
[0079] Normal State: Message Queuing Telemetry Transport Protocol (MQTT) communication is running normally. Entry conditions: Broker overall load rate <70%, ACK latency <500ms, retransmission rate <5%, and packet loss rate <1%. Control behaviors within the state: (a) Quality of Service (QoS) control: The Semantic Mapping Gateway (SMG) sets the QoS level according to the determined control condition parameters. For objects with high-reliability constraint edges in the Semantic Control Constraint Graph (SCCG), the communication behavior state machine switches the MQTT transmission behavior to high-reliability transmission mode; for objects with critical control constraints, the state machine prohibits its MQTT transmission behavior from degrading. (b) Release Control: Critical control (CRITICAL_CONTROL) marked objects use a hybrid release mode of incremental change (COV) and event-driven release; high bandwidth (HIGH_BANDWIDTH) marked objects that are not critical control (CRITICAL_CONTROL) use a batch periodic reporting mode; other objects use incremental change (COV) reporting mode by default. (c) Policy Update: The Semantic Processing Engine (SPE) performs policy evaluation and parameter updates normally.
[0080] Congestion State: Congestion occurs in the Message Queuing Telemetry Transport Protocol (MQTT) network. Entry Conditions: Broker overall load rate ≥ 70%, ACK latency ≥ 500ms, or retransmission rate ≥ 5%. Control Behaviors within the State: (a) Quality of Service (QoS) Control: Critical control (CRITICAL_CONTROL) marked objects maintain their original QoS; the QoS of other objects is forcibly reduced by one level, for example, QoS 2 (QoS2) is reduced to QoS 1 (QoS1), and QoS 1 (QoS1) is reduced to QoS 0 (QoS0). (b) Publication Control: Non-critical control (CRITICAL_CONTROL) objects suspend periodic reporting, only retaining the reporting of change increments (COV). Exit Conditions: All congestion conditions are lifted and this continues for N statistical windows, for example, N defaults to 3, switching to normal after each window of 10 seconds.
[0081] SAFE_MODE State: A serious anomaly occurs in Message Queuing Telemetry Transport Protocol (MQTT) communication, triggering the industrial control security protection mode. Entry conditions are triggered if any of the following conditions are met: CRITICAL_CONTROL flagged object experiences ≥5 consecutive ACK timeouts, or the broker's overall load rate is ≥90%, or the retransmission rate is ≥10%. Control behaviors within this state: (a) The Semantic Processing Engine (SPE) stops all policy updates, and the Quality of Service (QoS) and publishing mode of all objects are frozen at their current values. (b) The security control module traverses all control class nodes in the Semantic Control Constraint Graph (SCCG) cache, temporarily sets their writable flag (Writable_Flag) to False and records the original value to the security rollback record, prohibiting all MQTT remote write operations, i.e., only the local BACnet control channel is retained. (c) Traverse all non-alarm nodes in the Semantic Control Constraint Graph (SCCG) cache, suspend their MQTT Topic publication, and only retain event reporting for alarm objects. (d) Keep the linkage edges in the Semantic Control Constraint Graph (SCCG) cache active for evaluation at the BACnet local level. That is, linkage constraints triggered on the local BACnet side, such as fire alarms triggering forced HVAC adjustments, are executed directly without relying on MQTT communication. Exit condition: Switch to recovery after all SAFE_MODE entry conditions are removed and N statistical windows have been maintained.
[0082] RECOVERY State: A tiered recovery transition phase from SAFE_MODE to NORMAL state. Control behaviors within the state: (a) The Semantic Processing Engine (SPE) performs policy evaluation at a low frequency, i.e., once every 30 seconds. (b) The safe recovery module reads the original values of the critical control (CRITICAL_CONTROL) flags and writable flags for each node from the Semantic Control Constraint Graph (SCCG) cache, which are read from the safe rollback record. Message Queue Telemetry Transport Protocol (MQTT) remote write permissions and Topic publications are restored in batches according to descending control criticality: the first batch of critical control (CRITICAL_CONTROL) flagged objects are restored immediately; the second batch of control objects (CONTROL_OBJECT) flagged objects are restored after a delay of N statistical windows; the remaining objects in the third batch are restored last. (c) If any object triggers the SAFE_MODE entry condition again after recovery, the object reverts to SAFE_MODE and its recovery waiting time is doubled. Exit condition: Switch to normal after all objects are restored and the network status parameters remain stable for N statistical windows.
[0083] The input data for the Semantic Processing Engine (SPE) comes from: the associated Object Semantic Descriptor (OSD) cache, which provides control condition parameters and semantic attribute fields; and the network status cache, which provides the Broker's overall load rate, ACK latency, queue length, retransmission rate, and packet loss rate. The network status monitoring module obtains data in the following ways: (1) Broker load status: subscribe to the Broker system topic to periodically obtain the number of connections and message rate, calculate the overall load rate, and write it into the network status cache; (2) Object change frequency: calculate the object change frequency based on a sliding statistical window, count the number of changes, and write it into the associated Object Semantic Descriptor (OSD) cache; (3) ACK latency: count the Message Queue Telemetry Transport Protocol (MQTT) message ACK latency and write it into the network status cache; (4) Broker queue length: subscribe to the Broker system topic to obtain the number of messages to be processed and write it into the network status cache; (5) Retransmission rate and packet loss rate: count and write them into the network status cache within a 60-second sliding window.
[0084] The output parameters of the Semantic Processing Engine (SPE) are organized by object identifier (Object_Identifier) as the key, and are read by each step from S102 to S105.
[0085] Step S104: Combine the output parameters of the semantic strategy engine with the associated object semantic descriptor to dynamically construct the message payload.
[0086] In this optional embodiment, the dynamic construction of the message payload by combining the output parameters of the semantic policy engine with the associated object semantic descriptor includes:
[0087] The payload pattern field is obtained from the output parameters of the semantic strategy engine. The payload pattern is used as the query key to extract the semantic attribute field from the associated object semantic descriptor.
[0088] The semantic attribute fields are combined with preset mapping rules to perform field transformation and generate standardized semantic data blocks;
[0089] The message payload is obtained by taking the payload pattern field as the structured template input, taking the standardized semantic data block as the content input, and embedding the pattern version field and backward compatibility flag.
[0090] It should be noted that the Message Queuing Telemetry Transport Protocol (MQTT) payload construction includes the following steps: The payload construction module of the Semantic Mapping Gateway (SMG) reads the payload schema field from the Semantic Processing Engine (SPE) output parameter cache, and reads the semantic attribute fields from the associated Object Semantic Descriptor (OSD) cache, dynamically constructing the MQTT message payload. The mapping rules are as follows: in the associated Object Semantic Descriptor (OSD), Engineering Units are mapped to the unit field; State Text is mapped to the state map field; Event Class is mapped to the priority field; and Value Range is mapped to the range field. The payload embeds the schema version field and the backward compatible flag.
[0091] Step S105: By constructing a semantic control constraint graph through differentiated transmission behavior control strategies and associated object semantic descriptors, and combining message payloads for verification, arbitration, and security control state checks, a secure two-way closed-loop control for data reporting and command issuance under the message queue telemetry transmission protocol is realized.
[0092] In this optional embodiment, a semantic control constraint graph is constructed using differentiated transmission behavior control strategies and associated object semantic descriptors, and verification, arbitration, and security control state checks are performed in conjunction with the message payload, including:
[0093] Based on the associated object semantic descriptors, object constraint nodes are determined, and state dependency edges and linkage control edges are parsed in conjunction with differentiated transmission behavior control strategies to generate a semantic control constraint graph.
[0094] In this optional embodiment, the building automation network data communication protocol object nodes are determined based on the associated object semantic descriptors, and the state dependency edges and linkage control edges are parsed in conjunction with differentiated transmission behavior control strategies to generate a semantic control constraint graph, including:
[0095] Based on the associated object semantic descriptor, load the standard object type template library of the building automation network data communication protocol and generate object constraint nodes;
[0096] Read the associated attributes of the object to identify the state coupling relationship, establish a directed edge for each group of state coupling relationships, and combine the differentiated transmission behavior control strategy to establish a state condition expression and constraint modification rule for the directed edge to obtain the state dependent edge.
[0097] The semantic mapping gateway identifies linkage control relationships, generates linkage control edges based on these relationships, and performs runtime instantiation of the directed graph structure based on object constraint nodes, state dependency edges, and linkage control edges to obtain the semantic control constraint graph.
[0098] During reverse control, the semantic mapping gateway reads the constraint nodes and associated incoming edges of the target object from the semantic control constraint graph, and performs multi-dimensional semantic constraint verification in combination with preset verification rules and message payloads to obtain the multi-dimensional semantic constraint verification result.
[0099] In this optional embodiment, the preset verification rules include: writability verification rules, value range verification rules, and type matching verification rules.
[0100] The control source is obtained from the message payload, and cross-protocol control conflict arbitration is performed in conjunction with the semantic control constraint graph to obtain the cross-protocol control conflict arbitration result.
[0101] In this optional embodiment, the control source is obtained based on the message payload, and cross-protocol control conflict arbitration is performed in conjunction with the semantic control constraint graph to obtain the cross-protocol control conflict arbitration result, including:
[0102] The semantic mapping gateway performs a preset hierarchical classification of the control sources of the message queue telemetry transmission protocol to obtain the control source classification results.
[0103] When a downlink control command is received from the Message Queuing Telemetry Transport Protocol, the control source field is extracted from the message payload, and the current control source is identified by combining the control source classification results.
[0104] In the semantic control constraint graph, query whether there are any unfinished control operations from higher priority sources for the target object. Compare and arbitrate the unfinished control operations from higher priority sources with the current control source to obtain the cross-protocol control conflict arbitration result.
[0105] When the communication behavior state machine enters the safe mode state, it traverses the semantic control constraint graph to perform safe control state switching and recovery management, and obtains the safe control state check results.
[0106] It should be further explained that the bidirectional control and security control state management based on the Semantic Control Constraint Graph (SCCG) specifically includes the following steps: The Semantic Mapping Gateway (SMG) executes uplink data reporting from BACnet to Message Queuing Telemetry Transport Protocol (MQTT) and writes downlink control commands from MQTT to BACnet. During the reverse control process, it performs multi-dimensional semantic constraint verification, cross-protocol control conflict arbitration, and security control state switching management based on the Semantic Control Constraint Graph (SCCG). The Semantic Control Constraint Graph (SCCG) is the core mechanism that distinguishes this invention from ordinary protocol gateways.
[0107] I. Construction of the Semantic Control Constraint Graph (SCCG), including the following steps:
[0108] The Semantic Control Constraint Graph (SCCG) is a directed graph structure with BACnet objects as nodes and semantic dependencies between objects as directed edges. The SCCG is stored in the Semantic Mapping Gateway (SMG) memory as an adjacency list, with nodes indexed by their object identifiers. Each node maintains a list of incoming and outgoing edges.
[0109] Step 1: Node Layer Construction: The Semantic Mapping Gateway (SMG) loads the BACnet standard object type template library, which is based on ISO 16484-5 and ASHRAE 135 standards, generating constraint nodes for each BACnet object. Node data structure: Data type (Value_Type), value range source attribute reference (Value_Range_Source), writable flag (Writable_Flag), type conversion rule list (Type_Casting_Rule), control criticality level (Control_Criticism_Level), and critical control (CRITICAL_CONTROL) / control object (CONTROL_OBJECT) tags in the associated object semantic descriptor (OSD) cache.
[0110] Step 2: State Dependency Edge Construction: The Semantic Mapping Gateway (SMG) reads the associated attributes of each BACnet object and identifies the state coupling relationships between objects. For each coupling relationship, a directed edge is established. The edge data structure is: {from: Object Semantic Descriptor (OSD) reference of the associated object, to: Object Semantic Descriptor (OSD) reference of the target object, condition: State condition expression, constraint modification: List of constraint modification rules}. The SMG recursively discovers multi-level cascaded dependencies along the dependency chain. That is, starting from the identified target object, it treats it as a new associated object and continues to search for its downstream objects until the chain is closed or no new downstream objects are found. For example, a three-level cascaded chain from HVAC_Mode to Fan_Speed to Damper_Position.
[0111] Step 3: Construction of Linkage Control Edges: The Semantic Mapping Gateway (SMG) identifies cross-subsystem linkage control relationships, such as fire alarm linkage and security interlocking, and establishes linkage edges. Linkage edges are built upon state dependency edges by adding a priority=HIGH field. When a linkage edge and a state dependency edge conflict in modifying the same constraint field of the same target object, the linkage edge takes precedence.
[0112] Step 4: Runtime Instantiation and Semantic Control Constraint Graph (SCCG) Caching: At runtime, the Semantic Mapping Gateway (SMG) reads the actual attribute values of the target BACnet object, instantiates and corrects the default constraints in the template library, and generates instantiated nodes and edges. The instantiated Semantic Control Constraint Graph (SCCG) is stored in the SCCG cache using the object identifier (Object_Identifier) as the key for quick lookup during verification, arbitration, and security control management. The SCCG cache is incrementally updated when the BACnet object list changes or the state of associated objects changes.
[0113] II. The specific steps of multidimensional constraint verification based on Semantic Control Constraint Graph (SCCG) include: During reverse control, the Semantic Mapping Gateway (SMG) reads the constraint nodes and associated incoming edges of the target object from the Semantic Control Constraint Graph (SCCG) cache and performs the following verification:
[0114] (a) Writability check: Look up the writable flag (Writable_Flag) of the target object from the Semantic Control Constraint Graph (SCCG) cache; traverse all incoming edges of the object, read the current value (Present_Value) of the associated object from the associated object semantic descriptor (OSD) cache, and evaluate the condition expression of each edge. If any incoming edge is active and the constraint modification (constraint_mod) contains a false writable flag (Writable_Flag → False), then reject the write operation and return a state dependency lock error.
[0115] (b) Value range verification: Read the node value range (Value_Range) from the Semantic Control Constraint Graph (SCCG) cache, check whether all active incoming edges contain range constraint modifications, and perform verification based on the modified dynamic value range.
[0116] (c) Type matching verification: Read the node data type (Value_Type) and type conversion rule list (Type_Casting_Rule) from the Semantic Control Constraint Graph (SCCG) cache. If the payload data type does not match, traverse the rule list to find the allowed conversion path.
[0117] III. Cross-protocol control conflict arbitration includes the following steps: The Semantic Mapping Gateway (SMG) classifies Message Queuing Telemetry Transport Protocol (MQTT) control sources into four levels and stores them in a global configuration cache: Source A, such as fire alarm linkage, priority level (Priority_Level) = 0, which can override all other sources; Source B, such as manual forced control, priority level (Priority_Level) = 1, which can freeze writes from source D, but cannot override the security operations of source C; Source C, such as local direct digital controller (DDC) control, priority level (Priority_Level) = 2; Source D, such as cloud remote control, priority level (Priority_Level) = 3, which is the default source.
[0118] Upon receiving a downlink control command from the Message Queuing Telemetry Transport Protocol (MQTT): The control source field is extracted from the payload to identify the source; if not marked, it is defaulted to source D. The Semantic Control Constraint Graph (SCCG) cache is checked to see if there are any incomplete control operations from higher-priority sources for the target object. If the current request has higher priority and the source is A or B, a forced overwrite is performed. For high-frequency telemetry objects marked with HIGH_BANDWIDTH and not marked with CONTROL_OBJECT, they are marked as PROTECTED in the SCCG cache, prohibiting remote forced writes.
[0119] IV. The specific execution steps for security control state switching and recovery management include: S105 and S103 linkage: When the communication behavior state machine enters the security mode (SAFE_MODE) state, the security control module traverses all control-type nodes in the semantic control constraint graph (SCCG) cache, temporarily sets their writable flag (Writable_Flag) to false, and records the original value to the security rollback record; it traverses all non-alarm-type nodes and suspends their Message Queue Telemetry Transport Protocol (MQTT) Topic publication. The linkage edges in the semantic control constraint graph (SCCG) cache remain active at the BACnet local level. When the state machine enters the recovery state, the security recovery module reads the critical control (CRITICAL_CONTROL) / control object (CONTROL_OBJECT) flags and the original values of the writable flag (Writable_Flag) from the semantic control constraint graph (SCCG) cache, and restores them in batches according to the control criticality in descending order.
[0120] V. Specific steps of reverse mapping execution: After the verification, arbitration and security control state checks are all passed, the Semantic Mapping Gateway (SMG) writes the target value (Target_Value) to the current value (Present_Value) of the target object through the BACnet WriteProperty service, and the result is published through the Message Queue Telemetry Transport Protocol Command Result (MQTT cmd / result) Topic.
[0121] Figure 2 An embodiment of the MQTT bidirectional control system based on BACnet object semantic constraints of the present invention is shown.
[0122] In this optional embodiment, the MQTT bidirectional control system based on BACnet object semantic constraints includes:
[0123] The object semantic descriptor construction module 201 is used to construct an object semantic descriptor based on the object list attributes of the building automation control network data communication protocol object, and to update and bind parameters to the object semantic descriptor in combination with network operation layer data to obtain the associated object semantic descriptor.
[0124] The transmission behavior control strategy generation module 202 is used to construct message queue telemetry transmission protocol topics based on the associated object semantic descriptors, and generate differentiated transmission behavior control strategies in combination with network operation status parameters.
[0125] The semantic strategy engine parameter determination module 203 is used to determine the output parameters of the semantic strategy engine based on the differentiated transmission behavior control strategy and the associated object semantic descriptor.
[0126] The message payload construction module 204 is used to combine the output parameters of the semantic strategy engine with the associated object semantic descriptor to dynamically construct the message payload.
[0127] The bidirectional closed-loop control module 205 is used to construct a semantic control constraint graph through differentiated transmission behavior control strategies and associated object semantic descriptors, and to perform verification, arbitration and security control state checks in conjunction with message payloads, so as to realize secure bidirectional closed-loop control of data reporting and command issuance under the message queue telemetry transmission protocol.
[0128] To facilitate understanding of the above technical solutions of the present invention, the following further explains the above technical solutions of the present invention from the perspective of architecture and principle, as follows:
[0129] It should be further explained that steps S101 to S105 above constitute an industrial control constraint system with Semantic Control Constraint Graph (SCCG) constraint propagation and communication behavior state machine as its dual cores. The SCCG constructs runtime constraint propagation links through state-dependent edges and linkage edges. When the state of associated objects changes, constraint activation and cascading propagation are triggered, enabling the Message Queuing Telemetry Transport Protocol (MQTT) communication behavior state machine to dynamically adjust MQTT transmission behavior and security control strategies based on the propagated constraint states. The communication behavior state machine switches between NORMAL, CONGESTION, SAFE_MODE, and RECOVERY modes based on the network operating status. In SAFE_MODE, it triggers traversal-based secure write protection of the SCCG; in RECOVERY, it performs hierarchical recovery based on the constraint edge control criticality. Topic construction and payload construction, as execution steps of the semantic processing engine (SPE) output parameters, are jointly controlled by the current state of the state machine and the constraint propagation results of the semantic control constraint graph (SCCG).
[0130] The core of this invention lies in: propagating the constraint relationships between BACnet objects at runtime through a Semantic Control Constraint Graph (SCCG), and dynamically switching communication behaviors and security control strategies based on the propagated constraint states using a Message Queuing Telemetry Transport Protocol (MQTT) communication behavior state machine, thereby maintaining the semantic legitimacy and security of industrial control behaviors during cross-protocol communication.
[0131] It should be noted that this invention is further illustrated using a scenario of bidirectional control deployment of BACnet and Message Queuing Telemetry Transport Protocol (MQTT) in a large commercial complex as an example.
[0132] A large commercial complex has deployed an Ethernet-based BACnet (BACnet / IP) building automation system, which includes subsystems such as HVAC, lighting control, fire alarm, and energy consumption monitoring, with a total of 50 BACnet controllers and approximately 10,000 BACnet objects in the network.
[0133] Semantic Mapping Gateway (SMG) Hardware Deployment: The Semantic Mapping Gateway (SMG) is deployed as a software module in the edge gateway device. It communicates with the BACnet network via the Ethernet-based BACnet (BACnet / IP) protocol and with the cloud-based Message Queuing Telemetry Transport Protocol (MQTT) broker server (MQTT Broker) via the Message Queuing Telemetry Transport Protocol (MQTT).
[0134] Example of control condition parameter calculation: (a) Temperature sensor object (telemetry class): Object type = analog input (Object_Type=ANALOG_INPUT(0)), change value increment = 0.5 (COV_Increment=0.5), changes 12 times within 60 seconds. Control condition parameters: Reliability condition = normal reliability (NORMAL_RELIABILITY), i.e., no alarm events; Real-time condition = normal real-time (NORMAL_REALTIME); Bandwidth condition = high bandwidth (HIGH_BANDWIDTH), i.e., 12 times / minute ≥ 10; Control criticality = non-control (NON_CONTROL). Write to the object semantic descriptor (OSD) cache. (b) Lighting relay object (control class): Object type = binary output (Object_Type=BINARY_OUTPUT(4)), write priority minimum priority = 8 (WritePriority=8). Control condition parameters: Reliability condition = Normal reliability (NORMAL_RELIABILITY); Control criticality = Controlled object (CONTROL_OBJECT), i.e., Write Priority = 8>5 (WritePriority=8>5), which does not meet the critical control (CRITICAL_CONTROL) condition. Write to the object semantic descriptor (OSD) cache. (c) Fire alarm object (alarm class): Object type = Event registration (Object_Type=EVENT_ENROLLMENT(9)), and the event priority associated with the notification category (Notification_Class) is configured as the life safety class. Control condition parameters: Reliability condition = High reliability (HIGH_RELIABILITY), which is determined to be the life safety class according to the event priority configuration; Real-time condition = High real-time (HIGH_REALTIME), i.e., alarm class; Control criticality = Critical control (CRITICAL_CONTROL), i.e., the object marked as a critical infrastructure associated with fire linkage in the semantic control constraint diagram (SCCG). Write to the object semantic descriptor (OSD) cache.
[0135] Example of Semantic Control Constraint Graph (SCCG) Construction and Application: The Semantic Mapping Gateway (SMG) initialization phase constructs the Semantic Control Constraint Graph (SCCG). The node layer generates constraint nodes for objects. State-dependent edges: The state coupling between HVAC mode (HVAC_Mode) and fan speed (Fan_Speed) is identified, establishing a directed edge {HVAC_Mode→Fan_Speed, condition:Present_Value=OFF, constraint_mod:[Writable_Flag→False]}. Linked edges: Two linked edges (priority=HIGH) are established: {Fire_Alarm→HVAC control object, constraint_mod:[Write_Priority→Force_High]} and {Fire_Alarm→Lighting_Control, constraint_mod:[Writable_Flag→False]}. The Semantic Control Constraint Graph (SCCG) is stored in the Semantic Control Constraint Graph (SCCG) cache in the form of an adjacency list.
[0136] Multidimensional constraint verification: (a) Normal state: Fan speed = 50% (Fan_Speed = 50%) write command. The Semantic Mapping Gateway (SMG) reads the writable flag of the Fan speed (Fan_Speed) node from the Semantic Control Constraint Graph (SCCG) cache = True (Writable_Flag = True); it traverses the incoming edge {HVAC_Mode → Fan_Speed}, reads HVAC_Mode.Present_Value = ON from the associated Object Semantic Descriptor (OSD) cache, and passes if the condition (Present_Value = OFF) is not met. (b) HVAC off state, same command. If the condition is met, the edge is activated, and if constraint_mod contains Writable_Flag → False, then write is rejected, and a state dependency lock (STATE_DEPENDENT_LOCKED) is returned.
[0137] Example of security control state transition: The broker server (Broker) load is 93%, and the ACK timeout occurs for 8 consecutive times for 3 critical control (CRITICAL_CONTROL) objects (e.g., ≥5). The state machine transitions from NORMAL to SAFE_MODE. The security control module traverses the Semantic Control Constraint Graph (SCCG) and caches control class nodes: temporarily sets the writable flag (False) of Fan_Speed, Lighting_Control, and HVAC related objects to False and records the original value to the security rollback record; it suspends the publication of non-alarm object topics. The SCCG linkage edges remain active locally on BACnet. After 90 seconds, the network recovers, stabilizes for 3 consecutive windows, and the state machine transitions from SAFE_MODE to RECOVERY. The security recovery module reads the original values of critical control (CRITICAL_CONTROL) flags and writable flags from the Semantic Control Constraint Graph (SCCG) cache and restores them in batches: the first batch of fire alarm critical controls (CRITICAL_CONTROL) and HVAC control objects (CONTROL_OBJECT) are restored immediately; the second batch is restored after a 30-second delay; and the third batch is restored last. Once restoration is complete, the system enters normal mode.
[0138] like Figure 4As shown, it illustrates the deployment location of SMG between the BACnet / IP network and the MQTT Broker, as well as the internal functional module structure of SMG, such as the semantic extraction module, semantic policy engine module, communication behavior state machine module, SCCG constraint management module, conflict arbitration module, security control module, and the cached data flow relationships between modules. Specifically, the core function of the SMG (BACnet-MQTT Semantic Mapping Gateway) architecture is to realize semantic-level data interaction and control between the BACnet / IP network and the MQTT Broker. The BACnet / IP network interacts with SMG through read / subscribe and write / response; the MQTT Broker communicates with SMG through publish / subscribe and ACK / response, and receives status feedback from SMG. SMG is internally composed of five major functional modules: Semantic Extraction Module (STE), responsible for object discovery and extraction, semantic attribute extraction, and object classification and correction, outputting OSD (Object Semantic Description) and generating object semantics to write to the cache layer; Semantic Policy Engine Module (SPE), which executes policy generation and evaluation, parameter calculation and update, Topic and Payload policies, and outputs policies to write to the cache layer; Communication Behavior State Machine Module (MQTT-FSM), which implements state monitoring and switching, transmission behavior control, anomaly detection and recovery, and publishes / subscribes to messages to the MQTT Broker while receiving state feedback; SCCG Constraint Management Module (SCCGM), responsible for constraint graph construction and maintenance, constraint propagation and update, writability / value range verification, and supports constraint read and write; Conflict Arbitration Module (CAM), which completes control source priority determination, conflict detection and arbitration, and execution permission decision-making, and supports arbitration read and write; and Security Control Module (SCM), which implements security state switching, write freeze and rollback, and hierarchical recovery control, and supports security record read and write. The above-mentioned SCCGM, CAM, and SCM are interconnected through read and write or interaction. The underlying layer implements data storage through a caching layer, including OSD caching object semantics, SCCG caching constraint graphs, policy caching QoS / publishing policies, arbitration record caching control sources / priorities, security record caching freeze / rollback records, and network metric caching load / latency / retransmission. Each cache is read and written by its corresponding module, forming a closed loop. In summary, this invention specifically relates to an MQTT communication behavior control method based on inter-object semantic control constraint graphs for BACnet / IP networks. It is applicable to large-scale smart buildings, industrial parks, and data centers where BACnet building automation systems need to be securely and controllably connected to IoT cloud platforms. This invention is deployed on the BACnet-MQTT Semantic Mapping Gateway (SMG). The SMG, as a software module, is integrated into the edge gateway device of the building automation system, located on the data forwarding path between the BACnet / IP network and the MQTT Broker.Specifically, this includes: extracting the semantic types of BACnet objects; constructing object semantic descriptors (OSDs) containing standard attributes of BACnet objects; determining control condition parameters for each object based on BACnet protocol layer attributes and network operation statistics, including semantic constraint parameters related to object constraint propagation and Message Queuing Telemetry Transport Protocol (MQTT) communication behavior control; maintaining an MQTT communication behavior state machine, which includes at least a normal state, a congestion state, a safe mode state, and a recovery state, automatically switching between these four states based on network operation status parameters, and employing differentiated MQTT transmission behavior control strategies in different states; and constructing an inter-object semantic control constraint graph (SCCG), with BACnet objects as nodes and the state dependencies and linkage control relationships between objects as directed graphs. Each edge carries a state condition expression and a list of constraint modification rules. The Semantic Control Constraint Graph (SCCG) is instantiated at runtime and stored in the SCCG cache. During the reverse control process from Message Queuing Telemetry Transport Protocol (MQTT) to BACnet, the constraint nodes and associated incoming edges of the target object are read from the SCCG cache, and writability checks, value range checks, and type matching checks are performed. The control source identifier field is extracted from the MQTT message to perform cross-protocol control conflict arbitration. When the communication behavior state machine switches to the safe mode (SAFE_MODE) state, all control-class nodes in the SCCG cache are traversed to prohibit MQTT remote write operations and the original writable state is recorded to the safe rollback record. When entering the recovery state, MQTT remote write permissions are restored in batches according to the control criticality in descending order.
[0139] Among the control condition parameters: the reliability condition is jointly determined by the event category attribute value and the notification category attribute value; that is, if the object carries a life safety alarm event definition, it is marked as high reliability (HIGH_RELIABILITY), and if the retransmission rate or the number of acknowledgment timeouts in the Message Queuing Telemetry Transport Protocol (MQTT) transmission exceeds a preset threshold, it is marked as improved reliability (ELEVATED_RELIABILITY); the control criticality condition is jointly determined by whether the object is a writable control object, whether it carries a write priority attribute and its lowest write priority value, and whether it is marked as a critical infrastructure associated object in the Semantic Control Constraint Graph (SCCG); that is, those that meet the corresponding conditions are marked as control objects (CONTROL_OBJECT) and critical controls (CRITICAL_CONTROL) in turn.
[0140] The Message Queuing Telemetry Transport Protocol (MQTT) transmission behavior control policies under different states include: In the normal state, objects marked with high reliability are forced to have a quality of service (QoS) of 2, and objects marked with critical control are forced to have a QoS of 2 and are prohibited from degradation; in the congestion state, objects marked with non-critical control are forced to have their QoS reduced by one level and periodic reporting is suspended; in the safe mode state, the semantic processing engine (SPE) stops all policy updates, and the QoS and publishing mode of all objects are frozen at their current values.
[0141] like Figure 8 As shown, it illustrates the node and edge structure of SCCG, the state dependency discovery process, and the cascading dependency recursive discovery process. The specific process involves loading a standard object template to generate object constraint nodes; discovering state dependencies based on these object constraint nodes, i.e., identifying state couplings and establishing dependent edges, for example, a unidirectional dependency where HVAC_Mode points to Fan_Speed; recursively searching downstream objects to form cascading links to achieve recursive dependency discovery, for example, recursively discovering a chain link where HVAC_Mode points to Fan_Speed, and Fan_Speed then points to Damper_Position; further identifying linkage relationships and establishing linkage edges to achieve linkage control relationship discovery, for example, Fire_Alarm pointing to HVAC_Control and Lighting_Control respectively; and instantiating the SCCG cache by storing nodes, dependent edges, and linkage edges in the cache. And as shown... Figure 9As shown, the reverse control process includes writability verification, value range verification, type matching verification, and conflict arbitration. It receives downlink control commands and payloads to obtain MQTT control commands, locates the target object node in the SCCG, verifies whether the target object is writable (writability verification), performs value range verification by checking if the control value is within the allowed range, and verifies if the control value type matches the object type (type matching verification). Then, considering priority, it determines if there are higher-priority unresolved control conflicts (conflict arbitration). In safe mode, it restricts or blocks writes (safety control state check). After successful verification, it executes the BACnet WriteProperty service to issue commands and execute WriteProperty. The construction of the Semantic Control Constraint Graph (SCCG) between objects includes: node layer construction, which generates constraint nodes for each BACnet object, containing data type, value domain source, writable flag, type conversion rules, and control criticality level; state dependency edge construction, which identifies state coupling relationships between objects and establishes directed edges, and recursively discovers multi-level cascading dependencies along the dependency links; and linkage control edge construction, which identifies fire linkage and safety interlocking relationships across subsystems and establishes linkage edges, with linkage edges having higher priority than state dependency edges.
[0142] Cross-protocol control conflict arbitration includes: control sources are divided into at least four priority levels: fire alarm linkage, manual forced control, local direct digital controller (DDC) control, and cloud remote control; when multiple sources issue conflicting commands to the same BACnet object, forced overriding is performed according to priority, and fire alarm linkage can overridden all other sources; for high-frequency telemetry objects marked with high bandwidth (HIGH_BANDWIDTH) and not marked as controlled objects (CONTROL_OBJECT), they are marked as protected (PROTECTED) in the semantic control constraint graph (SCCG) cache and remote forced writes are prohibited.
[0143] The conditions for entering the SAFE_MODE state include: any critical control (CRITICAL_CONTROL) marked object has a consecutive acknowledgment response timeout count of ≥5, or the overall load rate of the Message Queuing Telemetry Transport Protocol (MQTP) proxy server is ≥90%, or the MQTP message retransmission rate is ≥10%. Tiered recovery is performed in batches in the following order: critical control (CRITICAL_CONTROL) marked objects first, control objects (CONTROL_OBJECT) marked objects second, and the remaining objects last.
[0144] Writability verification includes: traversing all incoming edges of the target object in the Semantic Control Constraint Graph (SCCG) cache, reading the current value of the associated object from the associated Object Semantic Descriptor (OSD) cache, evaluating the state condition expression of each edge, and rejecting the write operation if any incoming edge is active and its constraint modification rule list contains a writeable flag that is false (Writable_Flag→False); the value range verification is based on the dynamic value range modified by the currently active incoming edge.
[0145] When an object is added or deleted in the BACnet network, the nodes and edges in the Semantic Control Constraint Graph (SCCG) cache are updated incrementally; when the state of an associated object changes, the activation state of all outgoing edges originating from that object is re-evaluated.
[0146] This invention employs a semantic extraction module, which reads the semantic attributes of BACnet objects through the BACnet batch attribute reading service, generates object semantic descriptors (OSDs) and control condition parameters, and writes them into the object semantic descriptor (OSD) cache; a communication behavior state machine module, which switches between normal, congestion, safe mode, and recovery states based on parameters in the network state cache, writing differentiated service quality levels and release mode control values to the policy output parameter cache in different states; and a semantic control constraint graph management module, which constructs a semantic control constraint graph (SCCG) with BACnet objects as nodes and state dependencies and linkage control relationships as directed edges, and stores it in the semantic control constraint graph (SCCG) cache. During the reverse control process, constraints are read from the semantic control constraint graph (SCCG) cache. The system performs writability checks, value range checks, and type matching checks on nodes and incoming edges. The conflict arbitration module extracts the control source identifier field from Message Queuing Telemetry Transport Protocol (MQTT) messages, reads the control source priority mapping table from the global configuration cache, and performs priority-based forced overwrite arbitration when multiple source instructions conflict. The security control module receives the security mode trigger signal from the communication behavior state machine module, traverses all control class nodes in the Semantic Control Constraint Graph (SCCG) cache, temporarily sets their writability flags to false, and records the original values to the security rollback record. Upon receiving the recovery trigger signal, it reads the control criticality flags from the SCCG cache and restores the writability flags in descending order. The modules communicate via data read / write operations between the associated Object Semantic Descriptor (OSD) cache, network state cache, policy output parameter cache, SCCG cache, and global configuration cache.
[0147] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 3As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage medium. The database stores static and dynamic information data. The network interface communicates with external terminals via a network connection. When the computer program is executed by the processor, it implements the steps in the above embodiment of the MQTT bidirectional control method based on BACnet object semantic constraints.
[0148] Those skilled in the art will understand that Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present invention and does not constitute a limitation on the computer device to which the present invention is applied. A specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0149] Furthermore, the present invention also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described embodiments of the MQTT bidirectional control method based on BACnet object semantic constraints.
[0150] In addition, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the above-described embodiments of the MQTT bidirectional control method based on BACnet object semantic constraints.
[0151] Those skilled in the art will understand that implementing all or part of the processes in the MQTT bidirectional control method based on BACnet object semantic constraints in the above embodiments can be accomplished by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the MQTT bidirectional control method based on BACnet object semantic constraints described above. Any references to memory, storage, databases, or other media used in the embodiments provided by this invention can include at least non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical storage, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0152] This invention is not limited to the structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this invention is limited only by the appended claims.
Claims
1. A bidirectional control method for MQTT based on BACnet object semantic constraints, characterized in that, include: Based on the object list attributes of the building automation network data communication protocol object, an object semantic descriptor is constructed, and the object semantic descriptor is updated and parameters are bound in combination with network operation layer data to obtain the associated object semantic descriptor. The message queue telemetry transport protocol topic is constructed based on the associated object semantic descriptor, and differentiated transport behavior control strategies are generated by combining network operation status parameters. Based on the differentiated transmission behavior control strategy and the associated object semantic descriptor, the output parameters of the semantic strategy engine are determined; The message payload is dynamically constructed by combining the output parameters of the semantic strategy engine with the associated object semantic descriptor. By constructing a semantic control constraint graph through differentiated transmission behavior control strategies and associated object semantic descriptors, and combining message payloads for verification, arbitration, and security control state checks, a secure two-way closed-loop control for data reporting and command issuance under the message queue telemetry transmission protocol is achieved.
2. The MQTT bidirectional control method based on BACnet object semantic constraints according to claim 1, characterized in that, The object list attributes based on the building automation network data communication protocol object are used to construct an object semantic descriptor. This descriptor is then updated and its parameters are bound using network operation layer data. The resulting associated object semantic descriptor includes: The semantic mapping gateway obtains the object list attributes of the target building automation network data communication protocol device by reading the multi-attribute service, and obtains the object type enumeration values of all building automation network data communication protocol objects based on the object list attributes; Based on the object type enumeration value, the semantic mapping gateway is used to read the object's semantic properties, and the object's semantic descriptor is constructed based on the object list properties and the object's semantic properties. Based on the object semantic descriptor and the object label field, the object semantic descriptor is updated to obtain the updated object semantic descriptor; Based on the protocol layer attributes in the object semantic descriptor and the network operation layer data from network status monitoring statistics, the control condition parameters of each building automation control network data communication protocol object are calculated using the semantic mapping gateway. The control condition parameters are associated and stored in the updated object semantic descriptor to obtain the associated object semantic descriptor.
3. The MQTT bidirectional control method based on BACnet object semantic constraints according to claim 2, characterized in that, The updated object semantic descriptor, based on the object semantic descriptor and object tag field, includes: The semantic mapping gateway performs semantic classification on the data communication protocol objects of the building automation control network based on the object type in the object semantic descriptor, and obtains preliminary object semantic classification results. Read the object label field in the protocol implementation consistency declaration file and statically correct the preliminary object semantic classification results to obtain the corrected classification results; The corrected classification results are then updated to the object semantic descriptor, resulting in the updated object semantic descriptor.
4. The MQTT bidirectional control method based on BACnet object semantic constraints according to claim 1, characterized in that, The step of constructing message queue telemetry transport protocol topics based on the associated object semantic descriptors and generating differentiated transport behavior control strategies in conjunction with network operating status parameters includes: The semantic mapping gateway constructs a policy based on the topics output by the semantic policy engine, and combines the semantic categories in the associated object semantic descriptors to construct a message queue telemetry transmission protocol topic for each building automation network data communication protocol object. The network operating state parameters are determined based on the Message Queuing Telemetry Transport Protocol (MQTP) communication behavior state machine, and differentiated strategies are generated by combining the MQTP topics to obtain differentiated transmission behavior control strategies.
5. The MQTT bidirectional control method based on BACnet object semantic constraints according to claim 1, characterized in that, The semantic policy engine output parameters, determined by the differentiated transmission behavior control strategy and the associated object semantic descriptor, include: The network status monitoring data is matched with preset status switching conditions, and the current operating status identifier is determined based on the matching results. Input the current running status identifier into the differentiated transmission behavior control strategy, and combine it with the control condition parameters and semantic attribute fields in the associated object semantic descriptor to determine the state-in-state control behavior for each state. The semantic strategy engine comprehensively analyzes and dynamically adapts the in-state control behavior to obtain the output parameters of the semantic strategy engine.
6. The MQTT bidirectional control method based on BACnet object semantic constraints according to claim 1, characterized in that, The step of combining the output parameters of the semantic strategy engine with the associated object semantic descriptor to dynamically construct the message payload includes: The payload pattern field is obtained from the output parameters of the semantic strategy engine. The payload pattern is used as the query key to extract the semantic attribute field from the associated object semantic descriptor. The semantic attribute fields are combined with preset mapping rules to perform field transformation and generate standardized semantic data blocks; The message payload is obtained by taking the payload pattern field as the structured template input, taking the standardized semantic data block as the content input, and embedding the pattern version field and backward compatibility flag.
7. The MQTT bidirectional control method based on BACnet object semantic constraints according to claim 1, characterized in that, The process of constructing a semantic control constraint graph through differentiated transmission behavior control strategies and associated object semantic descriptors, and combining it with message payload for verification, arbitration, and security control state checks includes: Based on the associated object semantic descriptors, object constraint nodes are determined, and state dependency edges and linkage control edges are parsed in combination with differentiated transmission behavior control strategies to generate a semantic control constraint graph. During reverse control, the semantic mapping gateway reads the constraint nodes and associated incoming edges of the target object from the semantic control constraint graph, and performs multi-dimensional semantic constraint verification in combination with preset verification rules and message payload to obtain the multi-dimensional semantic constraint verification result. The control source is obtained based on the message payload, and cross-protocol control conflict arbitration is performed in conjunction with the semantic control constraint graph to obtain the cross-protocol control conflict arbitration result. When the communication behavior state machine enters the safe mode state, it traverses the semantic control constraint graph to perform safe control state switching and recovery management, and obtains the safe control state check results.
8. The MQTT bidirectional control method based on BACnet object semantic constraints according to claim 7, characterized in that, The step of determining the building automation network data communication protocol object nodes based on the associated object semantic descriptors, and generating a semantic control constraint graph by parsing state dependency edges and linkage control edges in conjunction with differentiated transmission behavior control strategies, includes: Based on the associated object semantic descriptor, load the standard object type template library of the building automation network data communication protocol and generate object constraint nodes; Read the associated attributes of the object to identify the state coupling relationship, establish a directed edge for each group of state coupling relationships, and combine the differentiated transmission behavior control strategy to establish a state condition expression and constraint modification rule for the directed edge to obtain the state dependent edge. The semantic mapping gateway identifies linkage control relationships, generates linkage control edges based on these relationships, and performs runtime instantiation of the directed graph structure based on object constraint nodes, state dependency edges, and linkage control edges to obtain the semantic control constraint graph.
9. The MQTT bidirectional control method based on BACnet object semantic constraints according to claim 7, characterized in that, The preset verification rules include: writability verification rules, value range verification rules, and type matching verification rules.
10. The MQTT bidirectional control method based on BACnet object semantic constraints according to claim 7, characterized in that, The step of obtaining the control source based on the message payload and performing cross-protocol control conflict arbitration in conjunction with the semantic control constraint graph to obtain the cross-protocol control conflict arbitration result includes: The semantic mapping gateway performs a preset hierarchical classification of the control sources of the message queue telemetry transmission protocol to obtain the control source classification results. When a downlink control command is received from the Message Queuing Telemetry Transport Protocol, the control source field is extracted from the message payload, and the current control source is identified by combining the control source classification results. In the semantic control constraint graph, query whether there are any unfinished control operations from higher priority sources for the target object. Compare and arbitrate the unfinished control operations from higher priority sources with the current control source to obtain the cross-protocol control conflict arbitration result.