Multi-dimensional authentication method for intelligent cloud platform of hydropower station
By combining a three-dimensional structured light camera with an improved PBFT consensus algorithm and a multi-dimensional credit scoring system, the identity authentication security and permission management issues of the hydropower station's smart cloud platform were resolved, achieving high-precision identity verification and rapid anomaly detection, and improving the reliability and security of the authentication process.
Patent Information
- Application Number
- CN202510853678.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-09-26
AI Technical Summary
Traditional hydropower station smart cloud platforms have insufficient identity authentication security, poor flexibility in authority management, weak environmental adaptability, and low audit traceability efficiency, making it difficult to meet the power industry's high security requirements.
A 3D structured light camera is used to collect 3D facial point cloud data, combined with dynamic liveness detection and an improved PBFT consensus algorithm for permission management, to build a multi-dimensional credit scoring system. Combined with QR code-assisted authentication and operation log traceability, multimodal data fusion decision-making and anomaly detection are achieved.
Achieve high-precision identity verification in complex industrial environments, effectively resist prosthetic attacks, dynamically adjust permissions, and quickly identify abnormal behavior to meet the power industry's requirements for efficient tracing and risk prevention of security incidents.
Smart Images

Figure CN120705850A_ABST
Abstract
Description
Technical Field
[0001] The present invention provides a multi-dimensional authentication method for a hydropower station smart cloud platform. Background Art
[0002] Traditional hydropower station operations and maintenance face multi-faceted challenges in identity authentication and permissions management. Facial recognition technology is susceptible to interference from complex industrial environments (such as metal reflections and moisture), making it difficult to effectively identify prosthetic attacks (3D-printed masks, high-definition video). The RBAC permission model lacks dynamic adjustment capabilities, making it incapable of handling emergency scenarios like equipment repairs. Single-modality authentication (such as fingerprints and passwords) is prone to failure in high-humidity environments and poses the risk of information leakage. Furthermore, manual operation log tracing is inefficient, and abnormal behavior detection is delayed, making it difficult to meet the "minute-level response" requirements of the power industry's security audits. Existing technologies have significant shortcomings in multimodal decision-making, blockchain permissions management, and real-time risk assessment. An intelligent authentication system that integrates multi-dimensional security elements is urgently needed. Summary of the Invention
[0003] The purpose of the present invention is to provide a multi-dimensional authentication method for a hydropower station smart cloud platform, which is used to solve the problems of insufficient identity authentication security, poor flexibility in authority management, weak environmental adaptability and low audit traceability efficiency existing in the traditional hydropower station smart cloud platform authentication system.
[0004] In order to solve the above problems, the technical solution of the present invention is: A multi-dimensional authentication method for a hydropower station smart cloud platform includes the following steps: Step 1: Use a 3D structured light camera to collect 3D point cloud data of the user's face, synchronously obtain RGB images and depth images, and extract facial feature vectors after preprocessing; Step 2: A composite metric function combining cosine similarity and Euclidean distance is used for feature matching. When the matching degree reaches the threshold, the face recognition authentication is considered successful. Otherwise, liveness detection is triggered. Step 3: Analyze the trajectory of the user's action sequence feature points using the optical flow field estimation algorithm and perform dynamic liveness detection in combination with the Kalman filter prediction model; Step 4: Blockchain authority management is performed based on the improved PBFT consensus algorithm, and consensus weights are dynamically adjusted based on the historical operation accuracy of nodes; Step 5: Build a three-dimensional decision tree based on time, scenario, and risk to achieve dynamic adjustment of permissions; Step 6: Use the analytic hierarchy process to determine the indicator weights and build a multi-dimensional credit scoring system; Step 7: Use the feature-level adaptive weighting algorithm and the decision-level DS evidence theory to fuse multimodal data; Step 8: Enhance security through QR code-assisted authentication, and use the attribute graph model to build an operation log association graph to achieve operation chain traceability; Step 9: Use the isolation forest algorithm combined with the Bayesian network for anomaly detection and risk assessment.
[0005] Furthermore, the three-dimensional point cloud data preprocessing in step 1 includes using a statistical outlier filtering algorithm to remove noise, and using a moving least squares method to perform smooth interpolation on the sparse point cloud to improve the integrity of the point cloud.
[0006] Furthermore, in step 1, the facial feature extraction is based on the SIFT3D algorithm to detect 68 facial points, and the improved 3D-LBP algorithm is used to calculate the radial gradient histogram features in the neighborhood of each point. The three-dimensional point cloud is reduced in dimension through the KD tree space partitioning algorithm to generate a 128-dimensional feature vector.
[0007] Furthermore, the composite metric function in step 2 is: ; Where α is the ambient light intensity adaptive coefficient, which is dynamically adjusted according to the light sensor data; S is the final similarity score; is the real-time facial feature vector to be verified; is the pre-registered template facial feature vector. Furthermore, in step 3, when the mean square error between the actual trajectory and the predicted trajectory exceeds 3 pixels, the object is determined to be non-living. Furthermore, the weight calculation formula of the improved PBFT consensus algorithm in step 4 is: ; Where ACC_i is the accuracy of the permission operation of node i, k is the adjustment coefficient, is the consensus weight of node i. Furthermore, in step 5, the time dimension uses a sliding window algorithm to analyze the frequency of permission usage, the scenario dimension triggers permission escalation rules through device failure feature vectors, and the risk dimension detects abnormal behavior based on the Gaussian mixture model of operation frequency.
[0008] Furthermore, the multi-dimensional credit scoring system in step 6 adopts the exponential smoothing method to dynamically revise the score, and the formula is: ; Where β is the forgetting factor that is dynamically adjusted according to the operation scenario. For time point t credit score, Credit score at the previous point in time; As the basic rating value.
[0009] Furthermore, the dynamic QR code in step 8 is encrypted and transmitted using the AES-256 algorithm, and contains user ID, department, and authority level information.
[0010] Furthermore, in step 9, the Bayesian network constructs three sub-networks of authentication, authority, and operation, and implements real-time update of risk levels through the conditional probability table.
[0011] The beneficial effects of the present invention are: 1. The system integrates 3D facial recognition, dynamic liveness detection, and encrypted QR code-assisted authentication, combined with a multimodal data fusion decision algorithm to achieve high-precision identity verification in complex industrial environments. It effectively protects against security threats such as prosthetic attacks and information forgery, significantly improving the reliability and security of the authentication process. 2. Based on an improved blockchain consensus algorithm and a three-dimensional decision tree model, combined with a user behavior credit scoring system, permission allocation is dynamically adjusted based on time, scenario, and risk dimensions, accurately matching operation and maintenance needs. This not only avoids security risks caused by excessive permissions, but also solves the problem of insufficient permissions in emergency scenarios, improving management efficiency and security.
[0012] 3. Through graphical tracing of operation logs, real-time risk monitoring, and Bayesian network assessment, a full-process security closed loop is established, from identity authentication and permission allocation to behavior auditing. This enables rapid identification and response to abnormal behavior, meets the power industry's requirements for efficient tracing and risk prevention of security incidents, and comprehensively ensures the stable operation of the smart cloud platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 This is the overall process architecture diagram of the multi-dimensional authentication method of the present invention; Figure 2 This is the weight calculation logic diagram of the PBFT consensus algorithm of this invention. DETAILED DESCRIPTION
[0014] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0015] like Figure 1 and 2 As shown, a multi-dimensional authentication method for a hydropower station smart cloud platform includes the following steps: The 3D structured light camera is installed 1.8 meters above the gate, with a pitch adjustment range of -15° to +15° and a horizontal rotation angle of ±30°, ensuring that the facial acquisition range covers a distance of 1.5-2.5 meters. The 3D structured light camera is connected to the edge computing unit (model: NVIDIA Jetson AGX Xavier, equipped with Ubuntu 18.04 system) via a USB3.0 Type-B interface.
[0016] Step 1: 3D facial data acquisition and preprocessing: Use a 3D structured light camera (such as Orbbec's AstraMini S) to collect 3D point cloud data and RGB images of the user's face within a distance of 1.5-2.5 meters. After statistical outlier filtering and moving least squares preprocessing, 68 facial points are located using the SIFT3D algorithm. An improved 3D-LBP algorithm is used to extract radial gradient histogram features, and a KD tree is used for dimensionality reduction to generate a 128-dimensional feature vector.
[0017] The statistical outlier filtering algorithm in preprocessing calculates the average distance from the point cloud to its k-neighboring points and identifies points exceeding the mean + 3 standard deviations as outliers. The k value of 20 in the statistical outlier filtering algorithm is based on facial point cloud density testing: at a distance of 1.8 meters, the average point cloud density in the facial area is 100 points / cm². A k value of 20 covers a neighborhood radius of approximately 0.5cm, effectively preserving facial details. The 0.05m search radius for moving least squares interpolation is based on the recommended value in the official Orbbec SDK. Testing has shown that this parameter results in a mean squared error (MSE) of less than 0.3mm between the interpolated point cloud and the ground truth. Step 2: Dual metric matching and liveness detection, constructing a composite metric function including the ambient light intensity adaptive coefficient α: ; Where: α is the ambient light intensity adaptation coefficient, which is dynamically adjusted based on the ambient light intensity monitored by the photosensor in real time. When the light intensity is >3000 lux, α=0.7, which increases the cosine similarity weight; when the light intensity is <500 lux, α=0.3, which increases the Euclidean distance weight. S is the final similarity score, which ranges from [0,1]. A higher score indicates a greater similarity between the feature vector to be verified and the template feature vector. To represent the real-time facial feature vector to be verified, it is extracted from the currently acquired facial image using the 3D-LBP algorithm with a dimension of 128; It is the pre-registered template facial feature vector, stored in the system database, and is also 128-dimensional; It is the dot product operation of two vectors, used to calculate the directional similarity between vectors; and Represents vectors and The L2 norm (Euclidean norm) of , used to normalize the dot product result; Cosine similarity measures the similarity of the directions of two vectors and is insensitive to changes in vector length; Represents the L2 distance (Euclidean distance) between two vectors and calculates the absolute distance in vector space; Represents the normalized Euclidean distance similarity, mapping the Euclidean distance to the interval [0,1]. The closer the distance, the higher the similarity.
[0018] Authentication is considered successful when the cosine similarity is ≥ 0.92 and the Euclidean distance similarity is ≥ 0.85. Otherwise, liveness detection using optical flow trajectory analysis and Kalman filtering is triggered. The optical flow estimation algorithm for liveness detection solves the optical flow equation using Horn-Schunck iteration, achieving a motion field estimation error of less than 1.5 pixels in the facial region.
[0019] The composite metric function combines cosine similarity and Euclidean distance because cosine similarity is insensitive to lighting changes (directional invariance), while Euclidean distance is sensitive to local feature differences (absolute distance). This combination allows for capturing subtle feature changes while maintaining robustness to lighting conditions. The dynamic α adjustment mechanism utilizes the BH1750FVI light sensor (response time <120ms), ensuring that the α value adjustment delay is less than 500ms even in the event of sudden changes in lighting (such as the sudden onset of strong light when a door is opened).
[0020] Step 3: Blockchain authority management and three-dimensional decision tree construction. After authentication, the improved PBFT consensus algorithm and the three-dimensional decision tree are combined to achieve dynamic authority allocation. Simultaneously, a multi-dimensional credit scoring system is constructed based on the hierarchical analysis method and exponential smoothing method. The improved PBFT consensus algorithm weight calculation formula is: ; in is the consensus weight of node i, ranging from [0,1], which determines the influence of the node in the block verification and voting process. The higher the weight, the greater the contribution to the final consensus result. ACC_i is the node operation accuracy, which is updated every 100 permission operations and reflects the historical reliability of the node. k is the adjustment coefficient, with a dynamic range of [1,3]. When the load is light, k=1 (the weight changes smoothly), and when the load is high, k=3 (the weight changes steeply).
[0021] The three-dimensional decision tree includes sliding window analysis in the time dimension, equipment failure feature matching in the scenario dimension, and Gaussian mixture model anomaly detection in the risk dimension.
[0022] Step 4: Multi-dimensional credit scoring and multi-modal fusion decision-making. The formula for the exponential smoothing method in the multi-dimensional credit scoring system is: ; Where β is the forgetting factor that is dynamically adjusted according to the operation scenario, with a dynamic range of [0.6, 0.95], and is automatically adjusted by the complexity of the operation scenario; For time point t The credit score range is [0,100], which comprehensively reflects the reliability of the user's historical operations and current risk status; Credit score at the previous point in time, retaining the impact of historical behavior on the current score; As the basic rating value, =70+10*authority level (authority level∈[0,3]), for example: visitor authority level is 0 (view only), general operator authority level is 1 (equipment monitoring, data query), senior engineer authority level is 2 (parameter adjustment, troubleshooting), administrator authority level is 3 (system configuration, authority allocation), = 80. Multimodal fusion decision-making adopts a two-layer architecture of feature-level adaptive weighting and decision-level DS evidence theory.
[0023] Step 5: QR code-assisted authentication and operation log graph traceability. This secure closed loop is achieved through AES-256-encrypted QR code authentication, operation log graph traceability, and Bayesian risk assessment. The dynamic QR code contains user ID, department, and permission level information and is encrypted and transmitted using the AES-256 algorithm. The operation log graph is stored using an attribute graph model, where nodes contain operation type, time, and user attributes, and edges represent predecessor-successor relationships.
[0024] Step 6: Anomaly Detection and Risk Assessment. Risk assessment is based on a Bayesian network, building three sub-networks for authentication, permissions, and operations. The risk level is updated in real time using a conditional probability table. Anomaly detection uses the Isolation Forest algorithm, with 100 decision trees. When abnormal behavior is detected, the Bayesian network automatically updates the risk level. Furthermore, the three-dimensional structured light camera in step 1 is installed 1.8 meters above the entrance gate of the hydropower station, and is equipped with an automatic cleaning device to cope with humid environments. It collects 30 frames of depth images and RGB images per second and transmits them to the edge computing unit through the USB3.0 interface. Furthermore, the ambient light intensity adaptive coefficient α in step 2 is dynamically adjusted based on real-time data from the photosensor. When the light intensity is >3000 lux, α is set to 0.7, and when the light intensity is <500 lux, α is set to 0.3. The photosensor monitors the ambient light intensity in real time and dynamically adjusts the ambient light intensity adaptive coefficient α in the composite metric function when the light intensity is too strong or too weak. This optimizes the feature matching strategy by increasing the weight of Euclidean distance in strong light environments and cosine similarity in weak light environments, improving authentication accuracy under different lighting conditions.
[0025] Furthermore, the adjustment coefficient k in step 3 is dynamically adjusted based on node load, with k=2 under normal load and k=3 under high load. The node operation accuracy ACC_i is updated every 1,000 operations. The node load monitoring module collects real-time statistics on the processing delay and throughput of each node in the blockchain network. When high load is detected, the adjustment coefficient k is automatically increased, reducing the exponential sensitivity in the weight calculation. This allows low-accuracy nodes to still participate in consensus, but with reduced influence, ensuring system stability under high concurrency.
[0026] Furthermore, in step 3, the time dimension sliding window is set to 8 hours, 12 device failure feature vectors are preset in the scenario dimension, and the parameters of the Gaussian mixture model in the risk dimension are automatically updated every 24 hours. The time dimension sliding window analyzes historical user operation habits, the scenario dimension matches preset failure feature vectors with device sensor data, and the risk dimension uses a Gaussian mixture model to establish a normal behavior distribution. When any of these three dimensions triggers a threshold, the three-dimensional decision tree automatically adjusts the permission level, achieving dynamic permission allocation.
[0027] Furthermore, in step 4, β is set to 0.8 for routine inspection scenarios and 0.6 for equipment repair scenarios. When the credit score falls below 60, the system automatically triggers the dual authentication process. The forgetting factor β is dynamically adjusted based on the complexity of the operation scenario. A higher β value is used for routine inspections to retain more historical records, while a lower β value is used for equipment repair scenarios to quickly reflect the current operation quality. When the credit score falls below the threshold, the system automatically triggers the dual authentication process, enhancing security by adding an authentication dimension.
[0028] Furthermore, in the feature-level fusion in step 4, the facial feature vector is weighted 0.5, the device state vector is weighted 0.3, and the environmental parameter vector is weighted 0.2. The facial feature vector, device state vector, and environmental parameter vector are each generated through a feature extraction network, and weights are dynamically assigned based on the importance of different scenarios. For example, the device state vector is weighted more heavily in device operation scenarios, while the facial feature vector is weighted more heavily in personnel entry and exit scenarios. This weighted fusion improves decision accuracy.
[0029] Furthermore, in step 5, the mobile app uses the AES-256 algorithm to generate a dynamic QR code every 30 seconds. After the scanner reads the code, it is cross-validated with the facial recognition result, with verification time less than 500ms. The mobile app generates a dynamic QR code based on the timestamp and the user's private key. After the scanner reads the code, it compares the QR code information with the locally stored public key and compares the extracted feature vector with the database template. The two comparison results are cross-validated using a logical AND operation, keeping verification time within 500ms, ensuring authentication efficiency and security.
[0030] Furthermore, the operation log graph in step 5 is synchronized to the blockchain every 10 minutes to ensure data immutability. The operation log is stored as an attribute graph, with each operation node containing attributes such as timestamp, operation type, and device ID. Edges represent the temporal relationships between operations. The graph is synchronized to the blockchain network every 10 minutes using the PBFT consensus algorithm, leveraging the blockchain's immutable nature to ensure log integrity and support fast graph queries for operation tracing.
[0031] Furthermore, in step 6, the Bayesian network uses a conditional probability table to update the risk level in real time. When the risk level exceeds a threshold, the system automatically triggers an early warning mechanism. The Bayesian network pre-builds three sub-networks: authentication, permission, and operation. The conditional probability table is trained using historical data. During real-time monitoring, when the anomaly detection module detects that operational behavior deviates from the normal distribution, the Bayesian network updates the posterior probability of each node based on the current evidence. When the risk level exceeds the threshold, the early warning mechanism is triggered.
[0032] The contents described in the embodiments of this specification are merely an enumeration of the implementation forms of the inventive concept. The scope of protection of the present invention should not be regarded as limited to the specific forms described in the embodiments. The scope of protection of the present invention also extends to equivalent technical means that can be conceived by those skilled in the art based on the inventive concept.
Claims
1. A multi-dimensional authentication method for a hydropower station smart cloud platform, characterized in that: The following steps are involved: Step 1: Use a 3D structured light camera to collect 3D point cloud data of the user's face, synchronously obtain RGB images and depth images, and extract facial feature vectors after preprocessing; Step 2: A composite metric function combining cosine similarity and Euclidean distance is used for feature matching. When the matching degree reaches the threshold, the face recognition authentication is considered successful. Otherwise, liveness detection is triggered. Step 3: Analyze the trajectory of the user's action sequence feature points using the optical flow field estimation algorithm and perform dynamic liveness detection in combination with the Kalman filter prediction model; Step 4: Blockchain authority management is performed based on the PBFT consensus algorithm, and consensus weights are dynamically adjusted based on the historical operation accuracy of the nodes; Step 5: Build a three-dimensional decision tree based on time, scenario, and risk to achieve dynamic adjustment of permissions; Step 6: Use the analytic hierarchy process to determine the indicator weights and build a multi-dimensional credit scoring system; Step 7: Use the feature-level adaptive weighting algorithm and the decision-level DS evidence theory to fuse multimodal data; Step 8: Enhance security through QR code-assisted authentication, and use the attribute graph model to build an operation log association graph to achieve operation chain traceability; Step 9: Use the isolation forest algorithm combined with the Bayesian network for anomaly detection and risk assessment.
2. A multi-dimensional authentication method for a hydropower station smart cloud platform according to claim 1, characterized in that: The 3D point cloud data preprocessing in step 1 includes removing noise using a statistical outlier filtering algorithm and performing smooth interpolation on the sparse point cloud using the moving least squares method.
3. The multi-dimensional authentication method of a hydropower station smart cloud platform according to claim 1, characterized in that: In step 1, facial feature extraction is performed based on the SIFT3D algorithm to detect 68 facial points. The 3D-LBP algorithm is used to calculate the radial gradient histogram features in the neighborhood of each point. The KD tree space partitioning algorithm is used to reduce the dimensionality of the three-dimensional point cloud to generate a 128-dimensional feature vector.
4. The multi-dimensional authentication method of a hydropower station smart cloud platform according to claim 1, characterized in that: The composite metric function in step 2 is: ; Where α is the ambient light intensity adaptive coefficient, which is dynamically adjusted according to the light sensor data; S is the final similarity score; is the real-time facial feature vector to be verified; is the pre-registered template facial feature vector.
5. The multi-dimensional authentication method of a hydropower station smart cloud platform according to claim 1, characterized in that: In step 3, when the mean square error between the actual trajectory and the predicted trajectory exceeds 3 pixels, it is judged as non-living.
6. A multi-dimensional authentication method for a hydropower station smart cloud platform according to claim 1, characterized in that: The PBFT consensus algorithm weight calculation formula in step 4 is: ; Where ACC_i is the accuracy of the permission operation of node i, k is the adjustment coefficient, is the consensus weight of node i.
7. The multi-dimensional authentication method of a hydropower station smart cloud platform according to claim 1, characterized in that: In step 5, the time dimension uses a sliding window algorithm to analyze the frequency of permission usage. The scenario dimension triggers permission escalation rules through the device failure feature vector. The risk dimension detects abnormal behavior based on the Gaussian mixture model of operation frequency.
8. The multi-dimensional authentication method of a hydropower station smart cloud platform according to claim 1, characterized in that: In step 6, the multi-dimensional credit scoring system uses the exponential smoothing method to dynamically adjust the score. The formula is: ; Where β is the forgetting factor that is dynamically adjusted according to the operation scenario. For time point t credit score, Credit score at the previous point in time; As the basic rating value.
9. The multi-dimensional authentication method of a hydropower station smart cloud platform according to claim 1, characterized in that: In step 8, the dynamic QR code is encrypted and transmitted using the AES-256 algorithm.
10. The multi-dimensional authentication method of a hydropower station smart cloud platform according to claim 1, characterized in that: In step 9, the Bayesian network constructs three sub-networks of authentication, permission, and operation, and updates the risk level in real time through the conditional probability table.