A control method and device for a mining vehicle

By generating permission credentials and a token verification mechanism, the problem of unreasonable permission granularity among underground coal mine equipment is solved, enabling precise permission control and secure collaboration among equipment, and adapting to the complex and ever-changing underground environment.

CN120729534BActive Publication Date: 2025-11-07HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511145237.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-15
Publication Date
2025-11-07
Estimated Expiration
2045-08-15

AI Technical Summary

Technical Problem

During the interconnection of equipment in underground coal mines, unreasonable permission granularity between devices leads to unauthorized operations and abuse of permissions, affecting system security and stability.

Method used

By generating permission credentials, which contain information about the controlling and controlled devices and device control policies, precise permission constraints are achieved, ensuring identity binding and operation mapping between devices. Combined with a token verification mechanism, this ensures the credibility of command sources and operational compliance.

Benefits of technology

It effectively prevents unauthorized operations, enhances system controllability and security, reduces malicious interference, adapts to dynamic equipment changes, and improves the accuracy and flexibility of equipment collaborative control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729534B_ABST
    Figure CN120729534B_ABST
Patent Text Reader

Abstract

The application provides a kind of mining equipment control method and equipment, it is related to industrial internet of things technical field.The method is applied to control system, control system includes control device and controlled device, method includes: control device obtains authority voucher;Wherein, authority voucher is used to indicate the control authority of control device to controlled device;Authority voucher includes the device information of control device, the device information of controlled device, the device control strategy of controlled device and voucher signature;Device control strategy includes: the mapping relationship between control instruction for controlling controlled device and the operation executed by controlled device in response to control instruction.Control device controls controlled device according to authority voucher.Precision authority constraint is realized based on authority voucher, and the problem of unreasonable authority granularity is solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of industrial Internet of Things, and in particular to a control method and device for mine equipment. BACKGROUND

[0002] With the development of intelligentization of the coal mine industry, various coal mine related devices supporting the mine standard communication protocol (may also be referred to as mine equipment) are gradually interconnected, helping to solve the problems of complex scenes in the coal mine underground. At the same time, due to the access of various devices, the data access control between devices also brings security problems.

[0003] Generally, devices can access and transmit data based on tokens. However, the two devices can arbitrarily access each other using tokens, and the situation of using excessive permissions to perform unauthorized operations may occur, and the permission granularity is unreasonable. SUMMARY

[0004] The present application provides a control method and device for mine equipment, which realizes precise permission constraint based on permission credentials and solves the problem of unreasonable permission granularity.

[0005] To achieve the above purpose, the present application adopts the following technical solutions:

[0006] In a first aspect, the present application provides a control method for mine equipment, applied to a control system, the control system comprising a control device and a controlled device, the method comprising:

[0007] The control device acquires a permission credential; wherein the permission credential is used to indicate the control permission of the control device to the controlled device; the permission credential comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device, and a credential signature; the device control strategy comprises a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction.

[0008] The control device controls the controlled device according to the permission credential.

[0009] In this way, on the one hand, the permission credential in the present application contains the device information of the control device and the device information of the controlled device, which can realize two-way identity binding. For example, the control device needs to verify whether it has the right to initiate control through its own information, and the controlled device needs to confirm whether it is the target controlled object through its own information. This prevents illegal devices from impersonating legitimate identities and reduces the interference of external malicious devices on the system.

[0010] On the other hand, the device control strategy explicitly controls the mapping relationship between the instruction and the operation of the controlled device, and the essence is to refine the permission from the overall access to the one-to-one correspondence of specific instructions and operations, which directly avoids the problem of device overstepping operation. Based on the permission credential, the precise permission constraint is realized, and the problem of unreasonable permission granularity is solved. It can be seen that, through identity verification, permission refinement, and tamper-proofing whole-link management and control, the overstepping operation risk and malicious operation can be eliminated, and the controllability of the system is further enhanced.

[0011] In an implementable manner, the control system further includes a server, and the method further includes:

[0012] The server determines the control device and the controlled device for executing the industrial task in response to the received industrial task.

[0013] The server generates the permission credential based on the device control strategy, the device information of the control device, and the device information of the controlled device.

[0014] In this way, the embodiments of the present application avoid the tediousness of manual input of device identification by the management personnel (especially in complex tasks involving multi-device cooperation), and reduce human errors such as missing devices and wrong selection areas, so that the permission configuration is more efficient and accurate, especially suitable for the complex environment of a large number of coal mine underground devices and dynamic changes of task scenes. Further, the server generates the permission credential based on the industrial task, which automatically maps the control device (such as a coal digging machine), the controlled device (such as a coal scraping plate), and the allowed operation instruction (such as starting the conveyor), to ensure that the permission granularity completely matches the production demand, realizes the binding of the permission and the industrial task, and ensures the control accuracy.

[0015] In an implementable manner, the control device acquires the permission credential, including:

[0016] The control device receives the permission credential sent by the server.

[0017] In this way, the server of the embodiments of the present application can synchronize the permission credential to the control device, so as to realize the precise permission constraint of the control device based on the permission credential, and solve the problem of unreasonable permission granularity.

[0018] In an implementable manner, the control system further includes a first terminal device, and the control device acquires the permission credential, including:

[0019] The control device receives the permission credential sent by the server through the first terminal device.

[0020] Thus, the server in the embodiment of the application can synchronize the permission credential to the control device through the first terminal device. In this way, in the case that the server fails to establish a communication connection with the control device, the first terminal device can serve as a communication medium to synchronize the permission credential to the control device. The flexibility of the scenario is improved.

[0021] In an implementable manner, the control system further includes a second terminal device, and the method further includes:

[0022] The second terminal device sends a configuration request to the server in response to a configuration operation input by a user, and the configuration request is used to request the server to configure a permission credential for the control device to control the controlled device.

[0023] The server generates the permission credential based on the device control policy of the controlled device, the device information of the control device, and the device information of the controlled device, including:

[0024] The server configures the validity period and the issuance time in response to the configuration request.

[0025] The server signs the device information of the control device, the device information of the controlled device, the device control policy, the validity period, and the issuance time through a certificate signature to generate the permission credential.

[0026] Thus, the server in the embodiment of the application configures the validity period and the issuance time to avoid long-term validity of the permission and reduce the risk of exceeding the authority. The server can also verify the authenticity and integrity of the control device, the controlled device information, and the policy through the certificate signature mechanism to ensure the security of the credential. At the same time, the core information in the permission credential is included in the signature range, which makes the permission credential clearly associated with the control device, the controlled device, and the device control policy, clearly defines the permission boundary, and facilitates subsequent precise permission constraint based on the permission credential.

[0027] In an implementable manner, the control device controls the controlled device according to the permission credential, including:

[0028] The control device sends the permission credential to the controlled device.

[0029] The controlled device generates a token based on the permission credential, and the token is used for the controlled device to verify the control instruction in the device control policy sent by the control device.

[0030] The controlled device sends the token to the control device.

[0031] The control device sends a first control instruction and the token to the controlled device based on the device control policy in the permission credential, and the first control instruction is a control instruction included in the device control policy in the permission credential.

[0032] The controlled device executes an operation corresponding to the first control instruction in response to the first control instruction in a case that the token verification succeeds.

[0033] In this way, the dual verification mechanism of the permission credential combined with the token in the embodiments of the present application ensures that the sender (the control device) of the first control instruction has permission and the control instruction source is trusted, while ensuring the security and compliance of the operation of the controlled device, and realizing trusted collaboration between industrial devices.

[0034] In an implementable manner, the method further includes:

[0035] The server determines task operation information of the industrial task in response to the received industrial task, the task operation information including a task operation flow and a task operation timing.

[0036] The server sends the task operation information to the control device, the task operation information being used to instruct the control device to execute the industrial task according to the task operation flow and the task operation timing.

[0037] In this way, the server in the embodiments of the present application can determine the task operation information and decompose the industrial task through the task operation information, so that the control instruction sending of the control device is no longer isolated but embedded in the standardized flow. Avoiding the device collision or mining quality problem caused by the chaotic operation sequence, realizing the standardized execution of the industrial task. At the same time, the timing constraints (such as step interval, execution window period) can coordinate the action rhythm of the control device and the controlled device (such as hydraulic support and coal mining machine). This double mechanism of flow guidance and permission control not only ensures the task to proceed according to the plan, but also prevents the control device from using unauthorized instructions in the process. Thus, the precision of multi-device collaboration and the permission compliance of instruction execution are enhanced.

[0038] In an implementable manner, the server determines the control device and the controlled device for executing the industrial task in response to the received industrial task, including:

[0039] The server inputs the industrial task into an artificial intelligence model in response to the received industrial task, and the artificial intelligence model outputs the device identifier of the control device and the device identifier of the controlled device.

[0040] The artificial intelligence model has the ability to determine the execution device corresponding to the industrial task.

[0041] In this way, the artificial intelligence model automatically identifies the device, avoiding the tedious manual input of the device identifier by the management personnel (especially in complex tasks involving multi-device collaboration), while reducing human errors such as missing devices and wrong selection areas, making the permission configuration more efficient and accurate, especially suitable for the complex environment of a large number of devices in a coal mine and dynamic changes in task scenarios.

[0042] In an implementation, the device control strategy of the controlled device is sent by the controlled device to the server, or is preset in the server.

[0043] In this way, in the embodiments of the present application, the device control strategy is stored in the server through the storage and acquisition mode of the device control strategy, the controlled device does not need to maintain complex strategy logic locally, and the hardware design of the controlled device can be simplified (such as reducing the storage chip and reducing the performance requirement of the processor), the cost and failure risk of the device are reduced, and the stability and reliability of the system are enhanced. After the server masters the device control strategies of all devices, the linkage logic between devices can be optimized from a global perspective. Thus, the multi-device collaborative control is facilitated, the diversified device scene requirements are met, and the efficient and reliable operation of the system is ensured.

[0044] In an implementation, the control device includes a mining device, and the controlled device includes a support device and a transportation device. The mining device includes a coal mining machine and a heading machine, the support device includes a hydraulic support, and the transportation device includes a coal scraping plate and a belt conveyor.

[0045] In an implementation, in the case where the controlled device is a hydraulic support, the device control strategy in the permission credential includes one or more of the following control instructions: a first instruction, a second instruction, a third instruction, or a fourth instruction.

[0046] The execution operation corresponding to the first instruction is to control the direction of the coal mining machine by the hydraulic support.

[0047] The execution operation corresponding to the second instruction is to adjust the target pressure of the hydraulic support.

[0048] The execution operation corresponding to the third instruction is to adjust the support height of the hydraulic support.

[0049] The execution operation corresponding to the fourth instruction is to adjust the top beam pitch angle of the hydraulic support.

[0050] In this way, in the embodiments of the present application, one or more control instructions can be included in the permission credential, and the control instructions of the coal mining machine direction, the adjustment of the pressure / height / top beam angle of the hydraulic support, and other core operations are included in the strategy according to the cooperative operation characteristics of the hydraulic support and the coal mining machine, which directly corresponds to the key process of underground mining (such as the progress matching of the coal mining machine and the support strength adjustment of the support), and ensures that the control instruction is highly matched with the actual production requirement. Thus, the industrial scene requirement is accurately adapted. At the same time, through the instruction subdivision, the operation permission of the hydraulic support can be flexibly configured according to the actual requirement, the work face rhythm is prevented from being affected by the unauthorized operation or the misoperation, and the system safety is enhanced.

[0051] In an implementable manner, in the case where the controlled device is a coal scraper, the device control strategy in the permission credential includes one or more of the following control instructions: a fifth instruction, a sixth instruction, a seventh instruction, or an eighth instruction.

[0052] The execution operation corresponding to the fifth instruction is to control the left tool-approaching pre-scrapping of the coal scraper according to a first number of times of coal scraping.

[0053] The execution operation corresponding to the sixth instruction is to control the left coal scraping to the tail of the coal scraper.

[0054] The execution operation corresponding to the seventh instruction is to control the right tool-approaching pre-scrapping of the coal scraper according to a second number of times of coal scraping.

[0055] The execution operation corresponding to the eighth instruction is to control the right coal scraping to the head of the coal scraper.

[0056] In this way, one or more control instructions can be included in the permission credential in the embodiments of the present application, the instructions are designed to directly correspond to the core operation logic of the coal scraper, and specific actions such as left / right tool-approaching pre-scrapping (with number of times control), left scraping to the tail, right scraping to the head, and the like are covered, which are highly matched with the coal cleaning process of the coal mining face (such as pre-tool-approaching cleaning of floating coal, post-operation coal scraping to a designated position), and ensure that the control instruction can directly serve the production demand. Thus, the industrial scene demand is accurately adapted. Meanwhile, through instruction subdivision, the operation permission of the coal scraper can be flexibly configured according to actual demand, the system safety is enhanced by preventing overreach operation or misoperation from affecting the rhythm of the coal face.

[0057] In an implementable manner, the method further includes:

[0058] The server receives the device information of the control device sent by the control device and the device information of the controlled device sent by the controlled device.

[0059] In this way, on the one hand, the server can master the core information (such as device identifier, model, position, functional attribute, state, and the like) of the control device and the controlled device in real time by directly receiving the device information. These information are the key basis for subsequent generation of permission credentials, and provide accurate device basic data for permission configuration.

[0060] On the other hand, in the industrial scene, there can be addition, removal, repair, or position adjustment of devices (such as addition of a coal scraper conveyor in a coal mine underground, or temporary offline repair of a hydraulic support). After the device actively synchronizes the information to the server, the server can update the device in real time, and ensure that the latest device state is called when the permission is configured. Dynamic adaptation to device changes is supported, and the system flexibility is improved.

[0061] In an implementable manner, the method further includes:

[0062] The server receives, through the first terminal device, device information of the control device sent by the control device and device information of the controlled device sent by the controlled device.

[0063] In this way, on the one hand, the server indirectly acquires the device information through the first terminal device, and can master the core information (such as device identification, model, location, function attribute, state, etc.) of the control device and the controlled device in real time. These information are the key basis for subsequent generation of permission credentials, and provide accurate device basic data for permission configuration.

[0064] On the other hand, in an industrial scene, devices can be added, removed, repaired, or adjusted in position (such as adding a scraper conveyor in a coal mine underground or temporarily offline maintenance of a hydraulic support). After the devices actively synchronize information to the server, the server can update the devices in real time, ensuring that the latest device state is called when the permission is configured. Dynamic adaptation to device changes is supported, and system flexibility is improved.

[0065] In an implementable manner, the device information of the control device includes at least one of identity information, a media access control address, and serial number information of the control device.

[0066] The device information of the controlled device includes at least one of identity information, a media access control address, and serial number information of the controlled device.

[0067] In an implementable manner, the method further includes: the control device sends a second control instruction to the controlled device, and the device control strategy in the permission credential does not include the second control instruction. The controlled device does not respond to the second control instruction.

[0068] In this way, in the embodiments of the present application, it is ensured that the controlled device only responds to the operation allowed in the permission credential by verifying whether the instruction is within the authorized range, technically preventing the execution of unauthorized instructions, and strictly defining the permission boundary. At the same time, unauthorized instructions (such as illegal parameter adjustment, triggering of dangerous actions, etc.) are prevented from being executed, reducing the risk of device failure, production accidents, etc. caused by misoperation, malicious attacks, or abuse of permissions, especially for devices in industrial scenes that have extremely high requirements for operation safety. Thus, the compliance of device operation and the safety of system operation are effectively guaranteed.

[0069] In a second aspect, the embodiments of the present application also provide a control method of a mine device, applied to a server, and the method includes:

[0070] The device control strategy, device information of the control device, and device information of the controlled device are used to generate a permission credential, the permission credential is used to indicate a control permission of the control device to the controlled device, the permission credential includes the device information of the control device, the device information of the controlled device, the device control strategy of the controlled device, and a credential signature, and the device control strategy includes a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction.

[0071] The permission credential is sent to the control device.

[0072] In this way, the server in the embodiment of the application configures the permission credential, so that the permission credential is clearly associated with the control device, the controlled device, and the device control strategy, the permission boundary is clear, and subsequent accurate permission constraint based on the permission credential is facilitated.

[0073] In a third aspect, the embodiment of the application further provides a control method of a device, applied to a control device, and the method includes the following steps.

[0074] The permission credential is obtained, the permission credential is used to indicate a control permission of the control device to the controlled device, the permission credential includes the device information of the control device, the device information of the controlled device, the device control strategy of the controlled device, and a credential signature, and the device control strategy includes a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction.

[0075] The controlled device is controlled according to the permission credential.

[0076] In this way, the device control strategy in the embodiment of the application clearly indicates the mapping relationship between the control instruction and the operation performed by the controlled device, and the essence is to refine the permission from the overall access to the one-to-one correspondence between the specific instruction and the operation, thereby directly avoiding the problem of device overreach operation. The control device can implement accurate permission constraint based on the permission credential, and the problem of unreasonable permission granularity is solved.

[0077] In a fourth aspect, the embodiment of the application provides a control method of a device, applied to a controlled device, and the method includes the following steps.

[0078] The permission credential sent by the control device is received, the permission credential is used to indicate a control permission of the control device to the controlled device, and the permission credential includes the device information of the control device, the device information of the controlled device, the device control strategy of the controlled device, and a credential signature.

[0079] A token is generated based on the permission credential, and the token is used for the controlled device to verify a control instruction in the device control strategy sent by the control device.

[0080] The token is sent to the control device.

[0081] The first control instruction and the token are received, and the first control instruction is a control instruction included in a device control strategy in the permission credential.

[0082] In a case where the token is verified successfully, an operation corresponding to the first control instruction is performed in response to the first control instruction.

[0083] In this way, in the embodiments of the present application, the double verification mechanism of the permission credential combined with the token is used to ensure that the sender (the control device) of the first control instruction has the permission and the control instruction is from a trusted source, and the security and compliance of the operation performed by the controlled device are guaranteed, thereby realizing trusted collaboration between industrial devices.

[0084] In a fifth aspect, the embodiments of the present application provide an interaction system, which includes a control device and a controlled device.

[0085] The control device is configured to obtain a permission credential, wherein the permission credential is used to indicate a control permission of the control device to the controlled device, and the permission credential includes device information of the control device, device information of the controlled device, a device control strategy of the controlled device, and a credential signature; and the device control strategy includes a mapping relationship between a control instruction used to control the controlled device and an operation performed by the controlled device in response to the control instruction.

[0086] The control device is further configured to control the controlled device according to the permission credential.

[0087] In this way, on the one hand, the interaction system in the embodiments of the present application can perform device control based on the permission credential. The permission credential contains the device information of the control device and the device information of the controlled device, and can realize two-way identity binding. For example, the control device needs to verify whether it has the right to initiate control through its own information, and the controlled device needs to confirm whether it is the target controlled object through its own information. This can prevent illegal devices from impersonating legal identities from the source, and reduce the interference of external malicious devices on the system.

[0088] On the other hand, the device control strategy explicitly indicates the mapping relationship between the control instruction and the operation performed by the controlled device, which essentially refines the permission from a vague overall access to a one-to-one correspondence between a specific instruction and an operation, thereby directly avoiding the problem of unauthorized operation of the device. The permission credential is used to realize precise permission constraint and solve the problem of unreasonable permission granularity. It can be seen that the whole-link management and control of identity verification, permission refinement, and tamper prevention can eliminate the risk of unauthorized operation and block malicious operation, thereby further enhancing the controllability of the system.

[0089] In a sixth aspect, the embodiments of the present application provide a server, which includes a processor, a memory, and a communication interface; the memory is used to store a computer executable program; and the computer executable program, when called by the processor, causes the processor to realize the method of the second aspect through the communication interface.

[0090] In a seventh aspect, an electronic device is provided, and the electronic device includes a memory and one or more processors; the memory is coupled to the processors; and the memory has stored therein computer program codes which, when executed by the processors, cause the electronic device to perform the method according to the third aspect or the fourth aspect.

[0091] In an eighth aspect, a computer-readable storage medium is provided, and the computer-readable storage medium has stored therein instructions which, when executed on an electronic device, cause the electronic device to perform the method according to the third aspect or the fourth aspect. BRIEF DESCRIPTION OF DRAWINGS

[0092] Figure 1 A structural schematic diagram of an interactive system provided by an embodiment of the present application;

[0093] Figure 2 A system architecture schematic diagram provided by an embodiment of the present application;

[0094] Figure 3 A flowchart of a control method of a mining device provided by an embodiment of the present application;

[0095] Figure 4 An interface schematic diagram of a configuration platform interface provided by an embodiment of the present application;

[0096] Figure 5 A schematic diagram of determining task operation information provided by an embodiment of the present application;

[0097] Figure 6 An interactive schematic diagram of a control device and a controlled device provided by an embodiment of the present application Figure 1 ;

[0098] Figure 7 An interactive schematic diagram of a control device and a controlled device provided by an embodiment of the present application Figure 2 ;

[0099] Figure 8 A structural schematic diagram of a control device or a controlled device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0100] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application. In the description of the present application, unless otherwise specified, " / " represents an "or" relationship between the objects before and after the " / ", for example, A / B can represent A or B; in the present application, "and / or" is only a description of the relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent three cases: A alone, A and B together, and B alone, where A and B can be singular or plural. In the description of the present application, unless otherwise specified, "multiple" means two or more than two. "At least one of the following" or similar expressions means any combination of the items, including any combination of single item or multiple items. For example, at least one of a, b, or c can represent a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple. In addition, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, "first", "second", and the like are used to distinguish the same items or similar items with basically the same function and role.

[0101] Those skilled in the art can understand that the "first", "second", and the like do not limit the quantity and execution order, and the "first", "second", and the like do not necessarily mean different. At the same time, in some embodiments of the present application, the words "exemplary" or "for example" are used to represent an example, illustration or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the use of "exemplary" or "for example" is intended to present the relevant concept in a specific manner, for ease of understanding.

[0102] In addition, the device architecture and business scenarios described in the embodiments of the present application are used to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that as the evolution of device architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0103] With the development of intelligentization of the coal mining industry, various coal mine related devices supporting the mine standard communication protocol (also referred to as mine devices) are gradually interconnected, helping to solve the problems of complex scenes in the coal mine underground. At the same time, due to the access of various devices, the data access control between devices also brings security problems.

[0104] Generally, devices can access and transmit data based on tokens. However, the two devices can access each other at will by using the token, and the over-privileged operation may occur, and the granularity of the privilege is unreasonable. Meanwhile, the token can only verify the identity and does not limit the operation range. That is, based on the token-based access control, if only the legality of the device identity is verified and the operations that can be performed by the device are not limited, malicious modification or deletion operations will not be controlled, thereby causing the system to be unstable and lacking precise access control.

[0105] To solve the above problems, the embodiments of the present application provide a control method of a mining device, applied to a control system, the control system comprising a control device and a controlled device, the method comprising: the control device obtaining a privilege credential; wherein the privilege credential is used to indicate the control right of the control device to the controlled device; the privilege credential comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device, and a credential signature; the device control strategy comprises a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction. The control device controls the controlled device according to the privilege credential.

[0106] In this way, on the one hand, the privilege credential in the embodiments of the present application contains the device information of the control device and the device information of the controlled device, and can realize two-way identity binding. For example, the control device needs to verify whether it has the right to initiate control through its own information, and the controlled device needs to confirm whether it is the target controlled object through its own information. This eliminates the problem of illegal devices impersonating legal identities from the source and reduces the interference of external malicious devices on the system.

[0107] On the other hand, the device control strategy explicitly defines the mapping relationship between the control instruction and the operation performed by the controlled device, which essentially refines the privilege from the vague overall access to the one-to-one correspondence of specific instructions and operations, directly avoiding the problem of device over-privileged operation. Based on the privilege credential, precise privilege constraints are realized, and the problem of unreasonable privilege granularity is solved. It can be seen that, through identity verification, privilege refinement, and tamper-proofing whole-link control, the embodiments of the present application can eliminate the risk of over-privileged operation and block malicious operations, further enhancing the controllability of the system.

[0108] The present application also provides an interactive system, as shown in Figure 1 The interactive system comprises a server 101, a control device 102, a controlled device 103, a first terminal device 104, and a second terminal device 105.

[0109] A communication connection is established between the server 101, the control device 102, the controlled device 103, the first terminal device 104, and the second terminal device 105. The server 101 is configured to perform the authority credential generation process in the embodiments of the present application. The server 101 can be a server cluster composed of multiple servers or can be a single server.

[0110] In some embodiments, the communication connection established between the server 101, the control device 102, the controlled device 103, the first terminal device 104, and the second terminal device 105 can include a wireless communication connection.

[0111] In some embodiments, the wireless communication technology for establishing the wireless communication connection includes, but is not limited to, at least one of the following: a wireless local area network (WLAN) (such as a wireless fidelity (Wi-Fi) network), Bluetooth (BT) (for example, traditional Bluetooth or Bluetooth low energy (BLE)), near field communication (NFC), Zigbee, frequency modulation (FM), infrared (IR), and the like.

[0112] In some embodiments, the first terminal device 104 and the second terminal device 105 can include at least one of a notebook computer, a desktop computer, a mobile phone, a foldable electronic device, a tablet computer, a desktop computer, a laptop computer, a handheld computer, an Ultra-Mobile Personal Computer (UMPC), a netbook, a cellular phone, a Personal Digital Assistant (PDA), an Augmented Reality (AR) device, a Virtual Reality (VR) device, an Artificial Intelligence (AI) device, a wearable device, an in-vehicle device, a smart home device, or a smart city device. The embodiments of the present application do not specially limit the specific types of the first terminal device 104 and the second terminal device 105.

[0113] The control device 102 and the controlled device 103 can be mine terminal devices, which refer to various mine-related devices loaded with a mine operating system. The mine operating system is a new generation of industrial Internet of Things operating system for mine terminals, which interconnects devices from different manufacturers through "soft bus" technology and the like, and helps coal mining enterprises to realize intelligentization.

[0114] The mine terminal devices can include mine electro-hydraulic control system devices, mine intelligent coal flow transportation devices, mine intelligent drainage devices, mine intelligent power supply management system devices, mine individual equipment, and mine industrial control screens and industrial control mainboards.

[0115] For example, the control device includes mining equipment, and the controlled device includes supporting equipment and transportation equipment.

[0116] The mining equipment includes a coal mining machine and a heading machine, the supporting equipment includes a hydraulic support, and the transportation equipment includes a coal scraping plate and a belt conveyor.

[0117] In some embodiments, the first terminal device 104 can act as an interaction medium between the server 101 and the control device 102 and the controlled device 103, and the first terminal device 104 can forward the permission credentials generated by the server 101 to the control device 102 and the controlled device 103. The manager can trigger the server 101 to generate the permission credentials through the second terminal device 105, that is, the second terminal device 105 is used by the manager to configure the permission credentials of the control device.

[0118] The operating systems installed on the control device 102, the controlled device 103, the first terminal device 104, and the second terminal device 105 include but are not limited to iOS ® , Android ® , OpenHarmony ® , HarmonyOS ® , Windows ® , Linux ® or other operating systems. The present application does not limit the specific types of the above-mentioned devices, whether or not an operating system is installed, and the type of the operating system when an operating system is installed.

[0119] Of course, the interaction system provided by the embodiments of the present application can also include other electronic devices in addition to the server 101, the control device 102, the controlled device 103, the first terminal device 104, and the second terminal device 105. The interaction system provided by the embodiments of the present application includes but is not limited to information interaction between two devices, and can also be information interaction between one device and multiple devices. Those skilled in the art can determine the type and number of electronic devices according to actual needs, and these designs do not exceed the protection scope of the embodiments of the present application.

[0120] Figure 2 A system architecture diagram is provided for an embodiment of the present application.

[0121] Referring to Figure 2 The system architecture of the embodiment of the present application includes a server side and an end side, the server side is one or more servers 101, and the end side is a control device 102, a controlled device 103, a first terminal device 104, and a second terminal device 105. The controlled device 103 can be a coal mining machine, and the controlled device 103 can be a hydraulic support, a coal scraping plate, a belt conveyor, and other coal mine related devices. The first terminal device 104 is a handheld mine terminal. The second terminal device 105 is a notebook computer of a manager. The end side devices all support data interaction of a mine standard communication protocol. That is, the mine standard communication protocol is a data communication protocol between the server side and the end side devices and between the end side devices. Both the end side devices and the server side need to support the protocol and transmit data through the protocol.

[0122] The embodiment of the present application can be applied to a coal mine underground production scene. For example, the server 101 and the second terminal device 105 are aboveground devices, and the control device 102, the controlled device 103, and the first terminal device 104 are underground devices.

[0123] Among them, the management platform is deployed on a cloud side server on the surface of the well, and stores basic information (such as device information) of devices such as coal mining machines, hydraulic supports, coal scraping plates, and belt conveyors. That is, the server can interconnect with underground devices through an industrial network, collect and receive data information of the underground devices, generate permission credentials, and distribute them to the underground devices (such as coal mining machines). Control devices such as coal mining machines and handheld mine terminals can control other mine devices to work, receive and send data and operation instructions through the mine standard communication protocol. The controlled devices such as coal scraping plates and hydraulic supports are controlled by other mine devices to work, receive and send data and execute operation instructions through the mine standard communication protocol.

[0124] Specifically, continuing to refer to Figure 2 Taking a coal mining machine controlling a hydraulic support as an example, the coal mining machine and the hydraulic support need to send their own device information to the server through the first terminal device. The manager can control the server to execute a device permission configuration process through the notebook computer, the server generates permission credentials, and distributes them to the coal mining machine through the first terminal device. The coal mining machine can send control instructions to the hydraulic support according to the permission credentials to control the hydraulic support to execute corresponding operations.

[0125] In other words, this application's embodiment is a solution for access control of machine / human-machine access in underground mining equipment. The implementation of this solution relies on various coal mine-related equipment within the aforementioned interactive system. It is applied to production processes such as integrated mining and transportation. For example, in an integrated mining scenario: during coal mining, the hydraulic supports and scraper blades verify the access credentials provided by the coal mining machine. Only when the access credentials are valid and state that the coal mining machine is allowed to control the hydraulic supports and scraper blades can the hydraulic supports and scraper blades respond to the coal mining machine's control.

[0126] It should be noted that the hardware and software architecture of the control device, the controlled device, and the terminal device in the embodiments of this application can adopt the hardware and software architecture commonly used in related technologies, and the embodiments of this application do not limit this.

[0127] The control method for the mining equipment provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0128] Figure 3 This is a schematic flowchart illustrating a control method for mining equipment according to an embodiment of this application, as shown below. Figure 3 As shown, the method may include the following steps S301-S305.

[0129] S301. The second terminal device responds to the configuration operation input by the user and sends a configuration request to the server.

[0130] The configuration request is used to request the server to configure the control device with the permission credentials for controlling the controlled device.

[0131] In some examples, administrators can use a second terminal device (such as a laptop) to configure permission credentials for controlling the device. See, for an example... Figure 4 The laptop can display a configuration platform interface, which includes input boxes and confirmation controls. The input boxes are used to input industrial tasks. Administrators can perform configuration operations by entering the industrial tasks into the input boxes and then clicking the confirmation control to configure the permissions of the controlled devices. Specifically, the second terminal device responds to the configuration operation input by the user (administrator) by sending a configuration request to the server. The configuration request includes the industrial tasks, which are the industrial tasks that the controlled and controlled devices need to perform.

[0132] Thus, on the one hand, the above process is a humanized process of the permission credential configuration link, and the user can convert the industrial task demand into the device permission rule through the visual configuration of the second terminal device (such as a notebook computer) and the subsequent generation of the permission credential by the server. The configuration request directly triggers the server to automatically generate the permission credential, reduces the manual intervention link, and avoids the permission errors (such as the omission of the control permission of a certain device) caused by manual configuration omissions. At the same time, the management personnel can adjust the configuration (such as re-inputting the industrial task when switching tasks) at any time through the second terminal, the server quickly generates new permission credentials, and the dynamic update of the permission is realized. The dynamic production scene is adapted, and the flexibility of the system is enhanced.

[0133] On the other hand, the core of the permission credential is to make the device permission serve the specific production demand, rather than the static and fixed permission allocation. The industrial task contained in the configuration request is essentially clear: which devices need to cooperate and what the cooperation boundary is in the current production scene. When the server generates the permission credential based on the industrial task subsequently, the control device (such as a coal mining machine), the controlled device (such as a coal scraping plate), and the allowed operation instruction (such as starting the conveying) are automatically mapped out, ensuring that the permission granularity and the production demand are completely matched, realizing the binding of the permission and the industrial task, and ensuring the control accuracy.

[0134] S302, the server determines the control device and the controlled device for executing the industrial task in response to the received industrial task.

[0135] In some embodiments of the present application, referring to Figure 5 , the server inputs the industrial task into an artificial intelligence model in response to the received industrial task, and the artificial intelligence model outputs the device identifier of the control device and the device identifier of the controlled device. The artificial intelligence model has the ability to determine the execution device corresponding to the industrial task.

[0136] It should be noted that the artificial intelligence model can be implemented by using a neural network model, and the specific implementation manner is not limited in the present application.

[0137] That is, the above process is to realize the automatic mapping of the industrial task to the device identifier by using the artificial intelligence model, and the purpose is to learn the historical configuration logic through the model, and automatically identify which devices need to be used as the control side and which devices need to be used as the controlled side for a certain industrial task.

[0138] Thus, the devices are automatically identified by the artificial intelligence model, which avoids the tedious manual input of the device identifier by the management personnel (especially in the complex task involving the cooperation of multiple devices), reduces the human errors such as the omission of the device and the wrong selection of the area, makes the permission configuration more efficient and accurate, and is especially suitable for the complex environment of the coal mine underground with a large number of devices and dynamic changes of the task scene.

[0139] S303, the server generates a permission credential based on the device control policy, the device information of the control device, and the device information of the controlled device.

[0140] The permission credential is used to indicate the control permission of the control device to the controlled device. The permission credential includes the device information of the control device, the device information of the controlled device, the device control policy of the controlled device, and a credential signature. The device control policy includes a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction.

[0141] In some embodiments of the present application, the control device and the controlled device can synchronize their device information to the server, so as to facilitate the server to perform the permission configuration process based on the device information of the devices subsequently.

[0142] In an implementable manner, the server receives the device information of the control device sent by the control device and the device information of the controlled device sent by the controlled device.

[0143] In another implementable manner, the server receives the device information of the control device sent by the control device and the device information of the controlled device sent by the controlled device through the first terminal device.

[0144] In this way, on the one hand, the server can master the core information (such as device identifier, model, location, function attribute, state, etc.) of the control device and the controlled device in real time through direct reception of the device information or indirect acquisition through the first terminal device. These information are the key basis for subsequent generation of the permission credential, and provide accurate device basic data for permission configuration.

[0145] On the other hand, in the industrial scene, there can be addition, removal, maintenance, or location adjustment of devices (such as addition of a scraper conveyor in a coal mine underground, or temporary offline maintenance of a hydraulic support). After the devices actively synchronize the information to the server, the server can update the devices in real time, so as to ensure that the latest device state is called when the permission configuration is performed. Dynamic adaptation to device changes is supported, and the flexibility of the system is improved.

[0146] In some embodiments of the present application, the device information of the control device includes at least one of identity information, a media access control address, and serial number information of the control device. The device information of the controlled device includes at least one of identity information, a media access control address, and serial number information of the controlled device.

[0147] It can be understood that the device information is unique and tamper-proof information, and is used to prove the identity thereof.

[0148] For example, the control device is a coal mining machine, and the device information of the coal mining machine at least includes one or more of the following: identity information (CMC-301-2023, where "CMC" is an abbreviation of the coal mining machine, "301" represents the number of the fully mechanized coal mining face, and "2023" is the device number), a media access control address (MAC: 00:1B:44:11:3A:B7), and serial number information (serial number: SNCJC20200518007).

[0149] In some embodiments of the present application, the server stores the device control strategy of the controlled device.

[0150] The device control strategy of the controlled device is sent to the server by the controlled device, or is preset in the server.

[0151] For example, the device control strategy of the hydraulic support is shown in Table 1.

[0152] Table 1

[0153]

[0154] For another example, the device control strategy of the coal scraping plate is shown in Table 2.

[0155] Table 2

[0156]

[0157] It should be noted that the controlled device can actively update the strategy and synchronize it to the server according to its own state (such as changes in hardware parameters, adjustment of the running environment) or user demand.

[0158] In this way, in the embodiments of the present application, the control strategy is stored in the server through the storage and acquisition mode of the device control strategy, the controlled device does not need to maintain complex strategy logic locally, and the hardware design of the controlled device can be simplified (such as reducing the storage chip and reducing the performance requirement of the processor), thereby reducing the cost and failure risk of the device and enhancing the stability and reliability of the system. After the server masters the device control strategies of all devices, the linkage logic between devices can be optimized from a global perspective. Thus, it is convenient for multi-device collaborative control, which meets the needs of diversified device scenarios and guarantees the efficient and reliable operation of the system.

[0159] In some embodiments of the present application, in the process of generating the permission credential by the server, the server can configure the validity period and the issuance time in response to the configuration request. The server signs the device information of the control device, the device information of the controlled device, the device control strategy, the validity period, and the issuance time through certificate signing to generate the permission credential.

[0160] It can be understood that when the server receives the configuration request, it will first set the validity period (i.e. the time range in which the credential can be used) and the issuance time (the time point at which the credential is generated) of the permission credential. The server integrates the following key information and digitally signs it with its own certificate private key:

[0161] Device information of the control device (such as device ID, model, etc.);

[0162] Device information of the controlled device (such as device ID, model, etc.);

[0163] Device control policy content of the controlled device;

[0164] Configured validity period and issuance time.

[0165] The complete data packet digitally signed by the server is the permission credential, which proves the operation permission of the control device to the controlled device and the basis, limits the effective range of the permission through the time parameter, and ensures that the information has not been tampered with and the source is trustworthy through certificate signature.

[0166] For example, the permission credential is shown in Table 3:

[0167] Table 3

[0168]

[0169] Among them, the authorized subject: clearly the object to which the permission is granted is the coal mining machine device (control device). The authorized object: specifies the objects that the authorized subject can control, including hydraulic supports, and clearly defines the range of controlled devices on which the permission acts. The authorization content: defines the specific operations that can be performed through control instruction IDs (such as 0x1001, 0x1002, etc.), such as device control instructions that may correspond to "start", "stop", "adjust pressure", etc., limiting the specific operation range of the permission. Validity period and issuance time: respectively mark the expiration time (2026 / 6 / 9) and generation time (2025 / 6 / 9) of the permission credential, constrain the effective period of the permission through the time dimension, and avoid the security risks brought by long-term validity of the permission. Signature: as a security guarantee for the credential, generated by the issuer (such as the server) through the certificate private key, used to verify the authenticity, integrity and source legality of the credential, to prevent information from being tampered with or forged.

[0170] Thus, in the embodiments of the present application, the server avoids long-term validity of the authority by configuring the validity period and the issuing time, and reduces the risk of exceeding authority. The server can also verify the authenticity and integrity of the control device, the controlled device information and the policy through the certificate signing mechanism, to ensure the security of the credential. At the same time, the core information in the authority credential is included in the signing range, so that the authority credential is clearly associated with the control device, the controlled device and the device control policy, the authority boundary is clear, and the subsequent precise authority constraint based on the authority credential is facilitated.

[0171] In some embodiments of the present application, in the case of the controlled device being a hydraulic support, the device control policy in the authority credential includes one or more of the following control instructions: a first instruction, a second instruction, a third instruction, or a fourth instruction.

[0172] The execution operation corresponding to the first instruction is to control the direction of the coal mining machine by the hydraulic support.

[0173] The execution operation corresponding to the second instruction is to adjust the target pressure of the hydraulic support.

[0174] The execution operation corresponding to the third instruction is to adjust the support height of the hydraulic support.

[0175] The execution operation corresponding to the fourth instruction is to adjust the top beam pitch angle of the hydraulic support.

[0176] Thus, in the embodiments of the present application, the authority credential can include one or more control instructions, and the control instructions of controlling the direction of the coal mining machine, adjusting the pressure / height / top beam angle of the hydraulic support, etc. are included in the policy according to the characteristics of the collaborative work of the hydraulic support and the coal mining machine, which directly corresponds to the key processes of underground mining (such as coal mining machine marching cooperation, support strength adjustment, etc.), to ensure that the control instructions are highly matched with the actual production demand. Thus, the industrial scene demand is precisely adapted. At the same time, by subdividing the instructions, the operation authority of the hydraulic support can be flexibly configured according to the actual demand, to prevent the work face rhythm from being affected by exceeding authority operation or misoperation, and to enhance the system safety.

[0177] In some embodiments of the present application, in the case of the controlled device being a coal scraping plate, the device control policy in the authority credential includes one or more of the following control instructions: a fifth instruction, a sixth instruction, a seventh instruction, or an eighth instruction.

[0178] The execution operation corresponding to the fifth instruction is to control the left forward sweep of the coal scraping plate according to a first coal sweeping frequency.

[0179] The execution operation corresponding to the sixth instruction is to control the left coal sweeping of the coal scraping plate to the tail of the machine.

[0180] The execution operation corresponding to the seventh instruction is to control the right forward sweep of the coal scraping plate according to a second coal sweeping frequency.

[0181] The eighth instruction corresponds to an execution operation of controlling the coal scraper to sweep coal to the right to the machine head.

[0182] Thus, in the embodiments of the present application, one or more control instructions can be included in the permission credential. The instructions are designed to directly correspond to the core operation logic of the coal scraper, covering specific actions such as left / right sweeping coal before cutting (with number control), left sweeping to the tail, right sweeping to the head, and highly matching the coal cleaning process of the coal mining face (such as cleaning floating coal before cutting and sweeping coal to the designated position after operation). The control instructions can directly serve the production needs. Thus, the industrial scene needs are precisely adapted. At the same time, through instruction subdivision, the operation permissions of the coal scraper can be flexibly configured according to actual needs to prevent unauthorized operation or misoperation from affecting the rhythm of the working face and enhance the safety of the system.

[0183] S304, the control device acquires the permission credential.

[0184] In some embodiments of the present application, the server can synchronize the permission credential to the control device.

[0185] In an implementable manner, the server can directly synchronize the permission credential to the control device. For example, the control device receives the permission credential sent by the server.

[0186] In another implementable manner, the server can synchronize the permission credential to the control device through the first terminal device. For another example, the control device receives the permission credential sent by the server through the first terminal device.

[0187] In some embodiments, the control device can also encrypt and store the permission credential locally.

[0188] Thus, in the embodiments of the present application, the server can synchronize the permission credential to the control device through the first terminal device. In this way, in the case that the server fails to establish a communication connection with the mining device, the first terminal device can serve as a communication medium to synchronize the permission credential to the control device. The flexibility of the scene is improved.

[0189] S305, the control device controls the controlled device according to the permission credential.

[0190] In some embodiments of the present application, in the process of controlling the controlled device according to the permission credential, see Figure 6, the control device sends the permission credential to the controlled device (S601). The controlled device generates a token based on the permission credential (S602), which is used by the controlled device to verify the control instruction in the device control policy sent by the control device. The controlled device sends the token to the control device (S603). The control device sends the first control instruction and the token to the controlled device based on the device control policy in the permission credential (S604), and the first control instruction is the control instruction included in the device control policy in the permission credential. The controlled device executes the operation corresponding to the first control instruction in response to the first control instruction if the token is verified successfully (S605).

[0191] That is, the controlled device verifies the signature in the permission credential based on the permission credential to verify the integrity of the credential, while verifying the validity period, consistency of the authorized subject and the control device identifier, and matching of the authorized object containing the identifier of the device itself. After the above verifications are passed, the controlled device extracts the authorized content (such as operation attribute code) and validity period information in the permission credential, generates a token containing a simplified permission identifier, a token expiration time (not exceeding the credential validity period), and the identifier of the device itself, which is used for real-time permission verification when the control device sends a control instruction to the controlled device. In this way, the control device can carry the token in the process of sending a control instruction to the controlled device to facilitate the controlled device to verify and perform the corresponding operation.

[0192] For example, referring to Figure 7 Taking the first control instruction as the above first instruction (controlling the direction of the coal mining machine by the hydraulic support) as an example, the interaction process between the control device (coal mining machine) and the controlled device (hydraulic support) is as follows:

[0193] The coal mining machine sends the permission credential containing the first instruction to the hydraulic support. After verifying the authenticity (by signature verification) and validity (checking the validity period, etc.) of the permission credential, the hydraulic support generates a token and sends it to the coal mining machine. The coal mining machine sends the first instruction including the control of the direction of the coal mining machine to the hydraulic support based on the first instruction in the permission credential, and attaches the token received before. The hydraulic support verifies the validity of the token (such as whether it matches, whether it is within the validity period), and after verification, responds to the first instruction and executes the operation of controlling the direction of the coal mining machine (for example, adjusting the direction of the coal mining machine to match the mining rhythm).

[0194] In this way, the dual verification mechanism of the permission credential combined with the token in the embodiments of the present application ensures that the sender of the first control instruction (the control device) has the permission and the control instruction is from a trusted source, while ensuring the safety and compliance of the controlled device executing the operation, and realizing the trusted collaboration between industrial devices.

[0195] In some embodiments of the present application, the server determines, in response to the received industrial task, task operation information of the industrial task, the task operation information including a task operation flow and a task operation timing. The server sends the task operation information to the control device, the task operation information being used to instruct the control device to execute the industrial task according to the task operation flow and the task operation timing.

[0196] With continued reference to Figure 5 The artificial intelligence model can also output the task operation information.

[0197] That is, after the server receives an industrial task (such as adjusting the advancing direction of a coal cutter along the strike of a coal seam and completing a cutting operation), the server analyzes the task operation information:

[0198] The task operation flow: clear step logic (for example, first adjust the angle of the top beam by the hydraulic support, and then send the first control instruction (adjust the direction of the coal cutter) by the hydraulic support).

[0199] The task operation timing: specifies the time sequence and interval of step execution (for example, within 3 seconds after the hydraulic support completes the adjustment of the angle of the top beam, the first control instruction is sent).

[0200] In some examples, the server sends the above task operation information to the control device, and the control device can send the first control instruction and the token to the controlled device according to the task operation information and the device control strategy in the permission credential.

[0201] For example, the control device plans an execution flow according to the task operation information: at a node that meets the timing requirements, the first control instruction (authorized hydraulic support control coal cutter direction operation) is called from the permission credential, and the instruction and the token are sent to the hydraulic support (controlled device) according to the flow, and finally the industrial task is completed.

[0202] In this way, the server of the embodiments of the present application disassembles the industrial task through the task operation information, so that the sending of the control instruction of the control device is no longer isolated but embedded in the standardized flow. Avoiding the problem of device collision or mining quality caused by chaotic operation sequence, the standardized execution of the industrial task is realized. At the same time, the timing constraints (such as step interval and execution window period) can coordinate the action rhythm of the control device and the controlled device (such as the hydraulic support and the coal cutter). This double mechanism of flow guidance and permission control not only ensures the task to proceed according to the plan, but also prevents the control device from using unauthorized instructions in the flow. Therefore, the precision of multi-device cooperation and the permission compliance of instruction execution are enhanced.

[0203] In some embodiments of the present application, the control device sends a second control instruction to the controlled device, and the device control strategy in the permission credential does not include the second control instruction. The controlled device does not respond to the second control instruction.

[0204] That is, when the control device sends a second control instruction to the controlled device, if the instruction is not included in the device control policy of the permission credential, the controlled device will check the instruction (according to the range of control instructions authorized in the permission credential), confirm that it is an unauthorized operation, and then refuse to respond to the instruction, that is, do not perform any operation related to the second control instruction.

[0205] In this way, by checking whether the instruction is within the authorized range in the embodiments of the application, it is ensured that the controlled device only responds to the operations explicitly allowed in the permission credential, the execution of unauthorized instructions is prevented from a technical level, and the permission boundary is strictly defined. At the same time, unauthorized instructions (such as illegal parameter adjustment, triggering of dangerous actions, etc.) are prevented from being executed, reducing the risk of device failure, production accidents, etc. caused by misoperation, malicious attacks or abuse of authority, especially for devices with extremely high requirements for operation safety in industrial scenarios. Thus, the compliance of device operation and the safety of system operation are effectively guaranteed.

[0206] In some embodiments of the application, the controlled device can also include various sensor devices.

[0207] The sensor device can include a gas sensor, a carbon monoxide sensor, an oxygen sensor, a dust sensor, a pressure sensor, a temperature sensor, a vibration sensor, a displacement sensor, an inclination sensor, etc.

[0208] In some embodiments, the sensor device actively uploads the collected sensor data to a data processing center or a target device with data receiving authority, such as a detection host, an intelligent gateway, a disease control center, etc. However, the sensor device will not send sensor data to an unauthorized device. The target device can also be a device with the authority to read sensor data, such as a detection system, an automatic control system, etc. When the detection system receives the data of the gas sensor that the gas concentration exceeds the standard, it can timely issue an alarm and link to the ventilation equipment for ventilation processing. It should be noted that the target device of the embodiments of the application is not specifically limited. The target device can perform a subscription operation on the sensor device to achieve the process of receiving and reading sensor data.

[0209] In some embodiments, the sensor device can perform a certain degree of control operation on other devices according to the sensor data. For example, when the temperature sensor detects that the temperature of the motor is too high, it has the authority to send an instruction to the motor control system to reduce the power of the motor or start the cooling device.

[0210] That is, the sensor device can also be the control device described above, and the motor control system is the controlled device. The specific interaction process and the permission credential generation process are described above and will not be described here.

[0211] In some embodiments, the sensor device needs to communicate with other devices to achieve data transmission and cooperation. The communication link between different types of sensor devices and other devices can also be authenticated. For example, the communication between the carbon monoxide sensor and the intelligent gateway is authenticated and encrypted, and only when the identity of both parties is verified and has the corresponding communication permission, a secure and reliable communication connection can be established to ensure the security and stability of data transmission and prevent data from being stolen or forged. That is, the sensor device can also be the controlled device described above, and the intelligent gateway is the control device. The specific interaction process and permission credential generation process are described above and will not be repeated here.

[0212] In some schemes, multiple embodiments of the present application can be combined and implemented. Optionally, some operations in the flow of each method embodiment are optionally combined, and / or the order of some operations is optionally changed. In addition, the execution order between the steps of each flow is only exemplary and does not constitute a limitation on the execution order between the steps, and other execution orders between the steps can also be used. The execution order is not intended to indicate the only execution order in which these operations can be performed.

[0213] A person of ordinary skill in the art can think of various ways to reorder the operations described in the embodiments of the present application. In addition, it should be pointed out that the process details involved in some embodiments of the present application are also applicable in a similar manner to other embodiments, or different embodiments can be combined for use.

[0214] In addition, some steps in the method embodiments can be equivalently replaced by other possible steps. Alternatively, some steps in the method embodiments can be optional and can be deleted in some use scenarios. Alternatively, other possible steps can be added to the method embodiments.

[0215] In addition, each method embodiment can be implemented individually or in combination.

[0216] The embodiments of the present application also provide an electronic device, which can be the control device or the controlled device described above, such as Figure 8 As shown in the figure, the control device or the controlled device can include one or more processors 810, a memory 820, and a communication interface 830.

[0217] The memory 820, the communication interface 830, and the processor 810 are coupled. For example, the memory 820, the communication interface 830, and the processor 810 can be coupled together through a bus 840.

[0218] The communication interface 830 is configured to perform data transmission with other devices. The memory 820 stores computer program code. The computer program code includes computer instructions, which, when executed by the processor 810, cause the electronic device to perform the related method steps in the embodiments of the present application.

[0219] The processor 810 can be a processor or a controller, for example, can be a central processing unit (CPU), a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a transistor logic device, a hardware component or any combination thereof. It can implement or execute various exemplary logical blocks, modules and circuits described in combination with the present disclosure. The processor can also be a combination that implements computing functions, such as one or more microprocessor combinations, combinations of DSP and microprocessor, etc.

[0220] The bus 840 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus 840 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 Only one thick line is used in the figure, but it does not mean that there is only one bus or only one type of bus.

[0221] The embodiments of the present application also provide an electronic device, which includes a memory and one or more processors; the memory is coupled with the processor; wherein the memory stores computer program code, and the computer program code includes computer instructions, which, when executed by the processor, cause the electronic device to perform the related method steps in the above method embodiments.

[0222] The embodiment of the present application also provides a control method of a mine device, which is applied to a server, and the method comprises the following steps: the server generates a permission voucher based on a device control strategy, device information of a control device and device information of a controlled device; the permission voucher is used for indicating control permission of the control device to the controlled device; the permission voucher comprises the device information of the control device, the device information of the controlled device, the device control strategy of the controlled device and a voucher signature; the device control strategy comprises a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction; and the server sends the permission voucher to the control device.

[0223] The embodiment of the present application also provides a control method of a mine device, which is applied to a control device, and the method comprises the following steps: the control device acquires a permission voucher; the permission voucher is used for indicating control permission of the control device to a controlled device; the permission voucher comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device and a voucher signature; the device control strategy comprises a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction; and the control device controls the controlled device according to the permission voucher.

[0224] The embodiment of the present application also provides a control method of a mine device, which is applied to a controlled device, and the method comprises the following steps: the controlled device receives a permission voucher sent by a control device, the permission voucher is used for indicating control permission of the control device to the controlled device; the permission voucher comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device and a voucher signature; the controlled device generates a token based on the permission voucher, the token is used for verifying a control instruction in the device control strategy sent by the control device; the controlled device sends the token to the control device and receives a first control instruction and the token sent by the control device, the first control instruction is a control instruction included in the device control strategy in the permission voucher; and the controlled device executes an operation corresponding to the first control instruction in response to the first control instruction in a case that the token is verified successfully.

[0225] The embodiment of the present application also provides an interactive system, which comprises a control device and a controlled device.

[0226] The control device is configured to acquire a permission voucher; the permission voucher is used for indicating control permission of the control device to a controlled device; the permission voucher comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device and a voucher signature; the device control strategy comprises a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction.

[0227] The control device is further configured to control the controlled device according to the permission voucher.

[0228] The embodiment of the present application further provides a server, which comprises a processor, a memory and a communication interface; the memory is used for storing a computer executable program; the computer executable program, when invoked by the processor, causes the processor to execute the related method steps in the above method embodiments through the communication interface.

[0229] The embodiment of the present application further provides a communication device, which comprises a memory and one or more processors; the memory is coupled with the processors; wherein the memory stores computer program codes, the computer program codes comprise computer instructions, when the computer instructions are executed by the processors, the communication device executes the related method steps in the above method embodiments.

[0230] The embodiment of the present application further provides a computer readable storage medium, which stores computer program codes, when the above processor executes the computer program codes, the electronic device executes the related method steps in the above method embodiments.

[0231] The embodiment of the present application further provides a computer program product, which contains instructions, when the instructions run on the computer or the processor, the computer or the processor executes the related method steps in the above method embodiments.

[0232] The embodiment of the present application further provides a chip system, which comprises a processor and a memory; the memory is used for storing programs or instructions, when the programs or instructions are executed by the processor, the chip system realizes the method in any of the above method embodiments.

[0233] Optionally, the processor in the chip system can be one or more. The processor can be realized by hardware or software. When realized by hardware, the processor can be a logic circuit, an integrated circuit, etc. When realized by software, the processor can be a general-purpose processor, which realizes by reading the software codes stored in the memory.

[0234] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or set separately from the processor, and the embodiment of the present application does not make a specific limitation. Exemplarily, the memory can be a non-transient processor, for example, a read-only memory (ROM), which can be integrated with the processor on the same chip or set on different chips, and the embodiment of the present application does not make a specific limitation on the type of the memory and the setting mode of the memory and the processor.

[0235] For example, the chip system can be a field programmable gate array (FPGA), can be an application specific integrated circuit (ASIC), can also be a system on chip (SoC), can also be a central processing unit (CPU), can also be a network processor (NP), can also be a digital signal processor (DSP), can also be a micro controller unit (MCU), can also be a programmable logic device (PLD) or other integrated chip.

[0236] The electronic device, computer storage medium or computer program product provided in the application are used to execute the corresponding method provided above, and thus the beneficial effects achieved thereby can refer to the beneficial effects of the corresponding method provided above, which will not be described herein again.

[0237] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional modules is taken as an example for illustration, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0238] In several embodiments provided in the application, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division, and actual implementation can have another division manner. For example, a plurality of units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0239] The units described as separate components can or can not be physically separate, and the components shown as units can be one physical unit or multiple physical units, which can be located in one place or distributed in multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0240] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.

[0241] If the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application essentially or say the parts that make contributions or the whole or part of the technical solutions can be embodied in the form of a software product. The software product is stored in a storage medium and includes a plurality of instructions for causing an apparatus (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the method of each embodiment of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0242] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A control method of a mining equipment, characterized by, The method is applied to a control system, the control system comprising a control device and a controlled device, and the method comprises: The control device acquires a permission credential; wherein the permission credential is used to indicate a control permission of the control device to the controlled device; the permission credential comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device, and a credential signature; the device control strategy comprises a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction; The control device controls the controlled device according to the permission credential.

2. The method of claim 1, wherein, The control system further comprises a server, and the method further comprises: The server determines the control device and the controlled device for executing an industrial task in response to the received industrial task; The server generates the permission credential based on the device control strategy, the device information of the control device, and the device information of the controlled device.

3. The method of claim 2, wherein, The control device acquires the permission credential, comprising: The control device receives the permission credential sent by the server.

4. The method of claim 2, wherein, The control system further comprises a first terminal device, and the control device acquires the permission credential, comprising: The control device receives the permission credential sent by the server through the first terminal device.

5. The method according to any one of claims 2-4, characterized in that, The control system further comprises a second terminal device, and the method further comprises: The second terminal device sends a configuration request to the server in response to a configuration operation input by a user, the configuration request being used to request the server to configure a permission credential for the control device to control the controlled device; The server generates the permission credential based on the device control strategy of the controlled device, the device information of the control device, and the device information of the controlled device, comprising: The server configures a validity period and an issuance time in response to the configuration request; The server signs the device information of the control device, the device information of the controlled device, the device control strategy, the validity period, and the issuance time through a certificate signature to generate the permission credential.

6. The method of claim 1, wherein, The control device controls the controlled device according to the permission credential, comprising: The control device sends the permission credential to the controlled device; The controlled device generates a token based on the permission credential, the token being used for the controlled device to verify a control instruction in the device control strategy sent by the control device; The controlled device sends the token to the control device; The control device sends a first control instruction and the token to the controlled device based on the device control strategy in the permission credential, the first control instruction being a control instruction included in the device control strategy in the permission credential; The controlled device performs an operation corresponding to the first control instruction in response to the first control instruction in a case that the token is verified successfully.

7. The method of claim 2, wherein, The method further comprises: The server determines task operation information of the industrial task in response to the received industrial task, the task operation information comprising a task operation flow and a task operation timing; The server sends the task operation information to the control device, and the task operation information is used to instruct the control device to execute the industrial task according to the task operation flow and the task operation timing.

8. The method of claim 2, wherein, The server determines the control device and the controlled device for executing the industrial task in response to the received industrial task, and the determination includes: The server inputs the industrial task into an artificial intelligence model in response to the received industrial task, and the artificial intelligence model outputs the device identification of the control device and the device identification of the controlled device. The artificial intelligence model has the capability of determining the execution device corresponding to the industrial task.

9. The method of claim 2, wherein, The device control strategy of the controlled device is sent to the server by the controlled device, or is pre-stored in the server.

10. The method of claim 9, wherein, The control device includes a mining device, and the controlled device includes a supporting device and a transportation device. The mining device includes a coal mining machine and a heading machine, the supporting device includes a hydraulic support, and the transportation device includes a coal scraping plate and a belt conveyor.

11. The method of claim 10, wherein, In the case where the controlled device is the hydraulic support, the device control strategy in the permission credential includes one or more of the following control instructions: a first instruction, a second instruction, a third instruction, or a fourth instruction. The execution operation corresponding to the first instruction is that the hydraulic support controls the direction of the coal mining machine. The execution operation corresponding to the second instruction is to adjust the target pressure of the hydraulic support. The execution operation corresponding to the third instruction is to adjust the support height of the hydraulic support. The execution operation corresponding to the fourth instruction is to adjust the top beam pitch angle of the hydraulic support.

12. The method according to claim 10 or 11, characterized in that, In the case where the controlled device is the coal scraping plate, the device control strategy in the permission credential includes one or more of the following control instructions: a fifth instruction, a sixth instruction, a seventh instruction, or an eighth instruction. The execution operation corresponding to the fifth instruction is to control the left tool before coal scraping of the coal scraping plate according to a first coal scraping frequency. The execution operation corresponding to the sixth instruction is to control the left coal scraping of the coal scraping plate to the tail of the machine. The execution operation corresponding to the seventh instruction is to control the right tool before coal scraping of the coal scraping plate according to a second coal scraping frequency. The execution operation corresponding to the eighth instruction is to control the right coal scraping of the coal scraping plate to the head of the machine.

13. The method of claim 2 or 3, wherein, The method further includes: The server receives the device information of the control device sent by the control device and the device information of the controlled device sent by the controlled device.

14. The method of claim 4, wherein, The method further includes: The server receives the device information of the control device sent by the control device and the device information of the controlled device sent by the controlled device through the first terminal device.

15. The method of claim 1, wherein: The device information of the control device includes at least one of identity information, a media access control address, and serial number information of the control device. The device information of the controlled device includes at least one of identity information, a media access control address, and serial number information of the controlled device.

16. The method of claim 1, wherein, The method further includes: The control device sends a second control instruction to the controlled device, and the device control strategy in the permission credential does not include the second control instruction; The controlled device does not respond to the second control instruction.

17. A control method of a mining vehicle, characterized by The method applied to a server comprises: generating a permission credential based on a device control strategy, device information of a control device, and device information of a controlled device; the permission credential is used to indicate a control permission of the control device to the controlled device; the permission credential comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device, and a credential signature; the device control strategy comprises a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction; sending the permission credential to the control device.

18. A control method of a mining equipment, characterized by, The method applied to a control device comprises: obtaining a permission credential; the permission credential is used to indicate a control permission of the control device to a controlled device; the permission credential comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device, and a credential signature; the device control strategy comprises a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction; controlling the controlled device according to the permission credential.

19. A control method of a mining vehicle, characterized by The method applied to a controlled device comprises: receiving a permission credential sent by a control device; the permission credential is used to indicate a control permission of the control device to the controlled device; the permission credential comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device, and a credential signature; generating a token based on the permission credential; the token is used for the controlled device to verify a control instruction in the device control strategy sent by the control device; sending the token to the control device; receiving a first control instruction and the token sent by the control device; the first control instruction is a control instruction included in the device control strategy in the permission credential; in a case where the token is verified successfully, performing an operation corresponding to the first control instruction in response to the first control instruction.

20. An interactive system, characterized by The interaction system comprises a control device and a controlled device, the control device is configured to obtain a permission credential; the permission credential is used to indicate a control permission of the control device to the controlled device; the permission credential comprises device information of the control device, device information of the controlled device, a device control strategy of the controlled device, and a credential signature; the device control strategy comprises a mapping relationship between a control instruction for controlling the controlled device and an operation performed by the controlled device in response to the control instruction; the control device is further configured to control the controlled device according to the permission credential.

21. A server, comprising: The server comprises a processor, a memory and a communication interface; the memory is used for storing a computer executable program; the computer executable program, when invoked by the processor, causes the processor to realize the method of claim 17 through the communication interface.

22. An electronic device, comprising: The electronic device comprises a memory and one or more processors; the memory is coupled with the processors; wherein the memory has computer program codes stored therein, the computer program codes comprise computer instructions, when the computer instructions are executed by the processors, cause the electronic device to execute the method of claim 18 or 19.

23. A computer-readable storage medium, characterized in that, The computer readable storage medium has instructions stored therein, when the instructions are run on an electronic device, cause the electronic device to execute the method of claim 18 or 19.

Citation Information

Patent Citations

  • Industrial control equipment control method, device and system based on block chain

    CN114298711A

  • Control method based on Hong mine configuration system

    CN118535212A