Layered network access control system for remote operation and maintenance of coal mine equipment

By introducing a hierarchical network access control system into coal mine equipment, combined with blockchain and edge computing technologies, dynamic monitoring and secure linkage of equipment operation status were achieved. This solved the problems of insufficient static permission management and linkage response capabilities of existing systems, and improved network security and equipment operation efficiency.

CN121531360APending Publication Date: 2026-02-13HUOLINHE OPENCUT COAL IND CORP LTD OF INNER MOGOLIA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511695272.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-19
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

The existing network access control system for coal mine equipment cannot adapt to the dynamic changes in equipment operating status and environmental parameters, lacks linkage response capabilities, resulting in frequent safety incidents, and static permission management leads to accidental misoperation.

Method used

A hierarchical network access control system for remote operation and maintenance of coal mine equipment is adopted. It combines intrinsically safe explosion-proof sensors, blockchain edge computing gateways, dual-band 5G and edge computing to build a linkage response mechanism of perception layer, network layer and application layer. It adopts ABAC dynamic access control and multi-factor authentication to realize equipment identity authentication, dynamic permission management and real-time security monitoring.

Benefits of technology

It achieves low latency and high reliability in remote control, dynamically adjusts permissions, identifies and blocks abnormal traffic, improves network security and equipment operating efficiency, and reduces the risk of misoperation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121531360A_ABST
    Figure CN121531360A_ABST
Patent Text Reader

Abstract

The invention discloses a layered network access control system for remote operation and maintenance of coal mine equipment, which belongs to the technical field of layered network access control systems, and is characterized in that a sensing layer deploys intrinsic safety type explosion-proof sensor and block chain edge computing gateway fusion equipment, and sensor equipment generates a unique digital identity label by adopting an SM2 algorithm; equipment attributes and operation state data are stored in a block chain in a Hash value form, an equipment identity block chain is constructed, a network transmission layer adopts a dual-frequency 5G, edge computing and block chain fusion architecture, an intrinsic safety type wireless base station is deployed underground to realize 700MHz and 2.6 GHz dual-frequency 5G networking, a core network supports separation of a control plane and a user plane, a platform layer constructs a trusted data middle platform, and the trusted data middle platform is connected with the equipment identity block chain. The application layer adopts a zero-trust architecture to design an operation and maintenance portal and integrates a multi-factor authentication mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a hierarchical network access control system, and more particularly to a hierarchical network access control system for remote operation and maintenance of coal mine equipment, belonging to the technical field of hierarchical network access control systems. Background Technology

[0002] Existing systems mostly employ role-based access control (RBAC) models, which cannot adapt to the dynamic changes in the operating status of coal mine equipment and environmental parameters. For example, when the underground gas concentration exceeds 0.75%, traditional systems cannot automatically elevate the control authority of ventilation equipment, still requiring manual approval at each level. During equipment maintenance periods, the allocation of temporary permissions lacks timely management, leading to operational errors due to the failure to promptly reclaim permissions after maintenance. The National Energy Administration's 2023 coal mine safety accident report shows that 32% of cybersecurity incidents originated from vulnerabilities in static access control.

[0003] The existing system's security measures at the perception layer, network layer, and application layer are deployed independently, lacking coordinated response capabilities. For example, when a camera at the perception layer detects personnel illegally entering a dangerous area, manual intervention is required to simultaneously disable equipment control, with an average response time of 120 seconds. The network layer firewall cannot identify attack traffic based on industrial protocols (such as Modbus). In 2024, a mine's PLC controller was maliciously tampered with, causing the conveyor belt to run at excessive speed for 15 minutes before it was detected. Summary of the Invention

[0004] The main objective of this invention is to provide a hierarchical network access control system for remote operation and maintenance of coal mine equipment.

[0005] The objective of this invention can be achieved by adopting the following technical solution:

[0006] A hierarchical network access control system for remote operation and maintenance of coal mine equipment includes a sensing layer that integrates intrinsically safe explosion-proof sensors with a blockchain edge computing gateway. The sensor devices use the SM2 algorithm to generate unique digital identities and store equipment attribute and operating status data in the form of hash values ​​on the blockchain to build an equipment identity blockchain.

[0007] The network transmission layer adopts a dual-band 5G, edge computing and blockchain integrated architecture. Intrinsically safe wireless base stations are deployed underground to achieve 700MHz and 2.6GHz dual-band 5G networking. The core network supports the separation of control plane and user plane. The platform layer builds a trusted data middleware platform. The application layer adopts a zero-trust architecture to design the operation and maintenance portal and integrates a multi-factor authentication mechanism.

[0008] Preferably, the edge computing gateway has built-in AI visual analysis algorithms and local AI models to preprocess the collected temperature, gas concentration and equipment vibration data to realize the detection and early warning of abnormal equipment behavior;

[0009] The MEC edge computing platform is deployed at the mining face to achieve low-latency remote control; the national cryptographic algorithms SM2, SM4, and SM3 are used to build an end-to-end encrypted tunnel, and a blockchain traffic fingerprint mechanism is introduced to dynamically analyze network traffic through smart contracts to achieve secure transmission and automatic handling of abnormal traffic; a cross-layer redundancy strategy is designed, including dual-core network, ring networking, and data caching and network interruption resumption mechanism, to ensure network reliability.

[0010] Preferably, based on industrial blockchain, an ABAC dynamic access control model is adopted to collect multi-dimensional data on equipment attributes, environmental parameters, and user roles, forming dynamic permission decision factors and establishing a three-dimensional permission matrix of equipment importance, risk level, and access timeliness to achieve dynamic permission management; by combining blockchain with privacy computing, trusted data circulation is achieved, a security posture twin engine is developed, and a three-dimensional security posture model is constructed by integrating multi-source data to achieve early warning of equipment anomalies; an intrusion detection module is constructed using machine learning algorithms to analyze abnormal network traffic and coordinate with the network layer to adjust access policies.

[0011] Preferably, an operational audit is implemented using a dual-track mechanism of behavioral baseline and anomaly detection to monitor and block violations of the operational behavior of maintenance personnel in real time; data from the edge layer and platform layer are integrated to build an intelligent decision-making module to provide auxiliary decision-making for maintenance personnel; a quantum resistance interface is reserved, and a key management system supporting the national cryptographic SM9 identifier cryptographic algorithm is adopted to realize quantum preparatory design.

[0012] Preferably, in the sensing layer, the intrinsically safe explosion-proof sensor and the blockchain edge computing gateway fusion device adopts a dual protection design of explosion-proof and increased safety, and has passed IP68 dustproof and waterproof certification, and can operate stably in environments from -40℃ to 85℃.

[0013] Preferably, in the network transmission layer, a dual-band 5G network deploys intrinsically safe wireless base stations every 280m underground, and the MEC edge computing platform makes the end-to-end latency of remote control less than 10ms;

[0014] At the platform layer, the ABAC dynamic access control model calculates trust scores in real time based on device importance level, environmental hazard parameters, and user operation history through machine learning algorithms, and dynamically adjusts access permissions accordingly.

[0015] Preferably, in the application layer, the multi-factor authentication mechanism includes username and password, digital certificate authentication based on the SM2 algorithm, and biometric identification;

[0016] The edge computing gateway of the perception layer adopts the Chengdu Zongheng Intelligent Control EG8200Mini industrial-grade hardware platform, which integrates an ARM Cortex-A55 processor and an independent NPU, providing 1.0 TOPSAI computing power support.

[0017] Preferably, in the network transmission layer, the blockchain traffic fingerprinting mechanism analyzes network traffic characteristics through smart contracts, and automatically triggers transmission strategy adjustments, such as switching encryption algorithms or enabling backup communication links, when abnormal traffic patterns are detected.

[0018] Preferably, the intelligent decision-making module at the application layer integrates real-time data from the edge layer with historical analysis results from the platform layer to generate maintenance work orders and recommend spare parts replacement plans. In the event of an emergency downhole, it combines UWB positioning data and video monitoring to provide evacuation route suggestions.

[0019] Beneficial technical effects of the present invention:

[0020] This invention provides a hierarchical network access control system for remote operation and maintenance of coal mine equipment. The dual-band 5G and MEC-based architecture stabilizes the end-to-end latency of remote control at 8-10ms, meeting the real-time requirements for emergency shutdown of conveyor belts, representing a 5-12 times improvement over traditional industrial Ethernet (50-100ms). In one mine, the control latency of an unmanned electric locomotive was reduced from 80ms to 9ms, increasing operating efficiency by 25%. The combination of national cryptographic algorithms and blockchain traffic fingerprinting achieves a 1.2Gbps encrypted throughput, supporting concurrent transmission of eight channels of 1080P video and control commands. The blockchain traffic fingerprinting mechanism can identify abnormal traffic patterns within 200ms, automatically switching encryption algorithms or activating backup links. In a mine test, it successfully intercepted ransomware attacks disguised as Modbus protocols. The dual-core network and ring network design achieve 99.99% network availability. The edge gateway's outage recovery mechanism ensures no data loss for 72 hours during network interruptions. In another mine, a conveyor belt system successfully resumed transmitting 23GB of historical data after a network failure. Attached Figure Description

[0021] Figure 1 This is a system diagram of a preferred embodiment of a hierarchical network access control system for remote operation and maintenance of coal mine equipment according to the present invention. Detailed Implementation

[0022] To enable those skilled in the art to understand the technical solution of the present invention more clearly, the present invention will be further described in detail below with reference to the embodiments and accompanying drawings, but the embodiments of the present invention are not limited thereto.

[0023] Intrinsically safe explosion-proof sensors, including belt speed sensors, belt misalignment sensors, temperature sensors, and vibration sensors, are installed at key locations in the belt conveyor system. A blockchain edge computing gateway is also deployed. Each sensor device uses the SM2 algorithm to generate a unique digital identity, uploading attributes such as device model, installation location, and safety label information, along with real-time operational data, to the blockchain in hash form to complete device authentication. The edge computing gateway incorporates AI visual analysis algorithms to monitor the belt's operating status in real time, detecting anomalies such as belt misalignment and obstruction. It also uses a local AI model to analyze the temperature and vibration data collected by the sensors to determine if there are potential equipment malfunctions. When an anomaly is detected, an early warning signal is immediately generated.

[0024] A dual-band 5G, edge computing, and blockchain converged network was constructed underground in the coal mine. Intrinsically safe 700MHz and 2.6GHz dual-band wireless base stations were deployed every 280m, and an MEC edge computing platform was set up near the belt conveyor system. During data transmission, the SM2 algorithm was used for key negotiation, the SM4 algorithm for data encryption, and the SM3 algorithm for digest verification, constructing an end-to-end encrypted tunnel. Simultaneously, a blockchain traffic fingerprinting mechanism was used to analyze network traffic in real time. When abnormal traffic was detected, smart contracts automatically triggered adjustments to the transmission strategy, such as switching to backup communication links. Furthermore, the data caching function of the dual-core network, ring network topology, and edge computing gateway ensured the reliability of network transmission. Even in the event of a network failure, critical data was ensured not to be lost, and transmission automatically resumed after network recovery.

[0025] A trusted data platform is built, employing an ABAC dynamic access control model based on industrial blockchain. It collects multi-dimensional data on belt conveyor system equipment attributes (such as equipment importance level, manufacturer, and service life), environmental parameters (underground gas concentration, temperature, and humidity), and maintenance personnel roles. Based on this data, access permissions are dynamically adjusted through a three-dimensional permission matrix. For example, when underground gas concentration increases, access permissions for ventilation equipment are automatically increased, while unnecessary operations on the belt conveyor system are restricted. Utilizing blockchain and privacy computing technologies, the data is reliably stored and analyzed. A security posture twin engine is developed, integrating belt operation data, AI visual analysis results, and network traffic data to construct a three-dimensional security posture model. This model displays the real-time operating status and security risks of the belt conveyor system and provides early warnings of potential equipment failures. The intrusion detection module analyzes network traffic using machine learning algorithms. When abnormal traffic patterns are detected, it immediately triggers the network transport layer to adjust access policies and block unauthorized access.

[0026] The operations and maintenance portal is designed with a zero-trust architecture. Operations and maintenance personnel must use multi-factor authentication, including username and password, digital certificate authentication based on the SM2 algorithm, and biometric recognition (such as fingerprint recognition), to log in. During operation, a dual-track mechanism of behavioral baseline and anomaly detection monitors the operational behavior of operations and maintenance personnel in real time. The system pre-sets operating procedures for the belt conveyor system equipment, such as belt start-up and shutdown sequences and speed adjustment ranges. When a violation is detected, an audible and visual alarm is immediately issued, and the operation command is blocked. The intelligent decision-making module integrates real-time data from the edge layer and historical analysis results from the platform layer to provide auxiliary decision-making for operations and maintenance personnel. For example, when the belt motor temperature is detected to be too high, a maintenance work order is automatically generated, and appropriate repair solutions and spare parts replacement suggestions are recommended based on inventory. Simultaneously, the operations and maintenance portal reserves a quantum resistance interface and adopts a key management system supporting the national cryptographic SM9 identifier cryptography algorithm, preparing for the future application of quantum communication technology.

[0027] Deploy an intrinsically safe explosion-proof sensor and blockchain edge computing gateway integrated device. The sensor device uses the SM2 algorithm to generate a unique digital identity, and stores the device attribute and operating status data in the form of hash values ​​on the blockchain to build a device identity blockchain; deploy a multi-protocol conversion gateway to realize real-time conversion of industrial protocols such as Modbus, Profibus, and EtherCAT; the edge computing gateway has built-in AI visual analysis algorithms and local AI models to preprocess the collected data such as temperature, gas concentration, and equipment vibration to realize abnormal equipment behavior detection and early warning.

[0028] The system adopts a dual-band 5G architecture that integrates edge computing and blockchain. Intrinsically safe wireless base stations are deployed underground to achieve dual-band 5G networking at 700MHz and 2.6GHz, with the core network supporting separation of the control plane and user plane. An MEC edge computing platform is deployed at the mining face to achieve low-latency remote control. End-to-end encrypted tunnels are constructed using national cryptographic algorithms SM2, SM4, and SM3, and a blockchain traffic fingerprint mechanism is introduced. Smart contracts dynamically analyze network traffic to achieve secure transmission and automatic handling of abnormal traffic. A cross-layer redundancy strategy is designed, including a dual-core network, ring networking, and a data caching mechanism for resuming transmission after network outages, ensuring network reliability.

[0029] A trusted data platform is constructed based on industrial blockchain and employs the ABAC dynamic access control model. Multi-dimensional data, including device attributes, environmental parameters, and user roles, are collected to form dynamic permission decision factors. A three-dimensional permission matrix of device importance, risk level, and access timeliness is established to achieve dynamic permission management. Trusted data flow is achieved through the combination of blockchain and privacy computing. A security posture twin engine is developed, integrating multi-source data to construct a three-dimensional security posture model, enabling early warning of device anomalies. An intrusion detection module is built using machine learning algorithms to analyze abnormal network traffic and adjust access policies in conjunction with the network layer.

[0030] The operation and maintenance portal is designed with a zero-trust architecture and integrates a multi-factor authentication mechanism; a dual-track mechanism of behavioral baseline and anomaly detection is used to implement operation auditing, which monitors the operation behavior of operation and maintenance personnel in real time and blocks violations; data from the edge layer and platform layer are integrated to build an intelligent decision-making module to provide auxiliary decision-making for operation and maintenance personnel; a quantum resistance interface is reserved, and a key management system that supports the national cryptographic SM9 identifier cryptographic algorithm is adopted to realize quantum preparatory design.

[0031] The hierarchical network access control method for remote operation and maintenance of coal mine equipment based on the above system comprises the following steps:

[0032] When sensor devices in the perception layer access the network, they generate digital identity identifiers using the SM2 algorithm. The edge computing gateway then uploads the device information to the blockchain in the form of hash values ​​to complete device identity authentication.

[0033] Sensors collect equipment operation data and environmental data. The edge computing gateway uses AI visual analysis algorithms and local AI models to preprocess the data, detect abnormal equipment behavior, and generate early warning signals.

[0034] The preprocessed data is transmitted through a dual-band 5G network at the network transport layer, encrypted using national cryptographic algorithms, and protected by a blockchain traffic fingerprint mechanism. In the event of network failure, a redundancy strategy is employed to ensure that no data is lost.

[0035] Based on the collected multidimensional data, the platform layer calculates dynamic permissions through the ABAC dynamic access control model, performs trusted data storage and analysis, and utilizes a security situation twin engine and intrusion detection module to achieve device anomaly early warning and network security protection.

[0036] The application layer provides an operation interface for operations and maintenance personnel through a zero-trust operations and maintenance portal, uses multi-factor authentication to ensure the authenticity of user identities, monitors operational behavior through an operation audit module, and provides auxiliary decision-making for operations and maintenance personnel based on platform layer data.

[0037] The above are merely further embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope disclosed in the present invention, based on the technical solution and concept of the present invention, shall fall within the scope of protection of the present invention.

Claims

1. A hierarchical network access control system for remote operation and maintenance of coal mine equipment, characterized in that: This includes a device that integrates intrinsically safe explosion-proof sensors with a blockchain edge computing gateway at the perception layer. The sensor device uses the SM2 algorithm to generate a unique digital identity, and stores the device attributes and operating status data in the form of hash values ​​on the blockchain to build a device identity blockchain. The network transmission layer adopts a dual-band 5G, edge computing and blockchain integrated architecture. Intrinsically safe wireless base stations are deployed underground to achieve 700MHz and 2.6GHz dual-band 5G networking. The core network supports the separation of control plane and user plane. The platform layer builds a trusted data middleware platform. The application layer adopts a zero-trust architecture to design the operation and maintenance portal and integrates a multi-factor authentication mechanism.

2. The hierarchical network access control system for remote operation and maintenance of coal mine equipment according to claim 1, characterized in that: The edge computing gateway has built-in AI visual analysis algorithms and local AI models to preprocess the collected temperature, gas concentration and equipment vibration data to realize the detection and early warning of abnormal equipment behavior; The MEC edge computing platform is deployed at the mining face to achieve low-latency remote control; the national cryptographic algorithms SM2, SM4 and SM3 are used to build an end-to-end encrypted tunnel, and a blockchain traffic fingerprint mechanism is introduced to dynamically analyze network traffic through smart contracts to achieve secure transmission and automatic handling of abnormal traffic. The design incorporates cross-layer redundancy strategies, including dual-core networks, ring networking, and data caching mechanisms for resuming data transmission after network outages, to ensure network reliability.

3. The hierarchical network access control system for remote operation and maintenance of coal mine equipment according to claim 1, characterized in that: Based on industrial blockchain and employing the ABAC dynamic access control model, it collects multi-dimensional data on equipment attributes, environmental parameters, and user roles to form dynamic permission decision factors. It establishes a three-dimensional permission matrix of equipment importance, risk level, and access timeliness to achieve dynamic permission management. By combining blockchain with privacy computing, it achieves trusted data circulation, develops a security posture twin engine, integrates multi-source data to construct a three-dimensional security posture model, and realizes early warning of equipment anomalies. It uses machine learning algorithms to build an intrusion detection module, analyzes abnormal network traffic, and coordinates with the network layer to adjust access policies.

4. The hierarchical network access control system for remote operation and maintenance of coal mine equipment according to claim 1, characterized in that: Operational auditing is achieved through a dual-track mechanism of behavioral baseline and anomaly detection, enabling real-time monitoring and blocking of operational personnel's actions; edge layer and platform layer data are integrated to build an intelligent decision-making module, providing auxiliary decision-making for operational personnel; a quantum-resistant interface is reserved, and a key management system supporting the national cryptographic SM9 identifier cryptographic algorithm is adopted to realize quantum preparatory design.

5. The hierarchical network access control system for remote operation and maintenance of coal mine equipment according to claim 1, characterized in that: In the perception layer, the intrinsically safe explosion-proof sensor and blockchain edge computing gateway fusion device adopts a dual protection design of explosion-proof and increased safety, and has passed IP68 dustproof and waterproof certification, and can operate stably in environments ranging from -40℃ to 85℃.

6. The hierarchical network access control system for remote operation and maintenance of coal mine equipment according to claim 1, characterized in that: In the network transmission layer, dual-band 5G networks deploy intrinsically safe wireless base stations every 280m underground, and the MEC edge computing platform enables remote control end-to-end latency of less than 10ms; At the platform layer, the ABAC dynamic access control model calculates trust scores in real time based on device importance level, environmental hazard parameters, and user operation history through machine learning algorithms, and dynamically adjusts access permissions accordingly.

7. The hierarchical network access control system for remote operation and maintenance of coal mine equipment according to claim 1, characterized in that: In the application layer, multi-factor authentication mechanisms include username and password, digital certificate authentication based on the SM2 algorithm, and biometric identification; The edge computing gateway of the perception layer adopts the Chengdu Zongheng Intelligent Control EG8200Mini industrial-grade hardware platform, which integrates an ARM Cortex-A55 processor and an independent NPU, providing 1.0 TOPSAI computing power support.

8. The hierarchical network access control system for remote operation and maintenance of coal mine equipment according to claim 1, characterized in that: In the network transport layer, the blockchain traffic fingerprinting mechanism analyzes network traffic characteristics through smart contracts. When abnormal traffic patterns are detected, it automatically triggers transmission strategy adjustments, such as switching encryption algorithms or activating backup communication links.

9. The hierarchical network access control system for remote operation and maintenance of coal mine equipment according to claim 1, characterized in that: The intelligent decision-making module at the application layer integrates real-time data from the edge layer with historical analysis results from the platform layer to generate maintenance work orders and recommend spare parts replacement plans. In the event of an emergency downhole, it combines UWB positioning data and video monitoring to provide evacuation route suggestions.