Coal mine safety terminal mixed identification authentication system based on private block chain

By using a hybrid identifier generation and hierarchical consensus architecture based on a private blockchain, the problems of centralized vulnerability to attack, data tampering, and low authentication efficiency in traditional coal mine safety terminal authentication systems are solved. This achieves highly reliable and real-time response terminal authentication, adapting to the needs of different terminals and environments.

CN121923926APending Publication Date: 2026-04-24ANHUI UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ANHUI UNIV OF SCI & TECH
Filing Date
2026-02-02
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Traditional coal mine safety terminal authentication systems rely on a central server, which is vulnerable to attacks that could lead to paralysis. They also have a high risk of data tampering, lack a unified identification standard, have low cross-system authentication efficiency, do not differentiate between terminal security levels, and cannot meet the requirements for high reliability and real-time response.

Method used

A hybrid identifier generation module based on a private blockchain is adopted, which combines a static base layer and a dynamic environment layer, embeds real-time environment factor hash values, designs anti-interference coding, and utilizes a hierarchical consensus architecture and zero-knowledge proof to build a fog-cloud collaborative authentication module with dynamic permission adaptation, so as to realize differentiated authentication of terminal security levels and cross-regional mutual recognition.

Benefits of technology

It achieves decentralized and highly reliable authentication, reduces the risk of data tampering, improves cross-system authentication efficiency and response speed, adapts to different terminal needs, and meets the real-time secure data transmission requirements of coal mine production.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121923926A_ABST
    Figure CN121923926A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of coal mine safety authentication, and discloses a coal mine safety terminal mixed identification authentication system based on a private block chain, which uses the private block chain and a hierarchical consensus architecture, combines a PBFT and PoS mixed algorithm to distribute node differentiation weights, and gives a consensus verification negative right to a supervision node. The monitoring requirement is met while the decentralization characteristic is guaranteed, and dependence on a single central server is not needed any more; even if part of nodes break down or are attacked, the fog node self-organizing network can take over tasks quickly, authentication interruption of the whole system is avoided, and the high requirement for zero interruption of coal mine production is met. Meanwhile, a terminal full-life-cycle tracing chain is constructed by utilizing the characteristic that data on the chain cannot be tampered and a cross-chain hash synchronization technology, and a zero-knowledge proof and differential privacy algorithm is matched, so that authentication data is prevented from being tampered, sensitive information privacy can be protected, and responsibility tracing difficulty is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of coal mine safety authentication technology, specifically a coal mine safety terminal hybrid identification authentication system based on a private blockchain. Background Technology

[0002] Coal mining is a high-risk industry with a complex and unique working environment, characterized by high dust concentrations, high humidity, strong electromagnetic interference, and variable geological conditions. Coal mine production involves the collaboration of heterogeneous terminals across multiple dimensions, including personnel, equipment, and the environment. Typical terminals include personnel positioning, gas sensing, equipment monitoring, and emergency communication. Secure access and authentication of these terminals are core prerequisites for ensuring safe coal mine production. Current coal mine safety terminal authentication technologies mainly face the following technical challenges: Traditional systems rely on a central server, which can lead to the paralysis of authentication across the entire system in the event of a failure or attack, failing to meet the high reliability requirements of zero-interruption coal mine production. Furthermore, centralized storage is easily targeted by attacks, and the risk of authentication data tampering is high, making it difficult to trace responsibility.

[0003] Coal mine terminals come from diverse sources, with varying manufacturers, models, and functions. Their identification formats (hardware codes, IP addresses, device numbers, etc.) are inconsistent, and there is a lack of a unified mixed identification standard. This results in low efficiency of cross-system and cross-regional authentication and mutual recognition, making it unsuitable for human-machine-environment integrated operation scenarios.

[0004] Downhole terminals need to transmit critical safety data such as gas concentration and personnel location in real time. Traditional authentication processes are cumbersome and overly reliant on the cloud, and their latency cannot meet the millisecond-level response requirements. Furthermore, the lack of differentiation between terminal security levels and the adoption of a uniform authentication strategy result in insufficient flexibility and an inability to adapt to the needs of different terminals. Summary of the Invention

[0005] The purpose of this invention is to provide a hybrid identification and authentication system for coal mine safety terminals based on a private blockchain, so as to solve the problems mentioned in the background art.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a hybrid identification and authentication system for coal mine safety terminals based on a private blockchain, comprising: Preferably, the hybrid identifier generation module adopts a two-layer hybrid identifier generation rule consisting of a static base layer and a dynamic environment layer; The static base layer retains the inherent hardware characteristics, including the terminal chip's unique code and core module serial number, and integrates core scenario attributes such as the terminal's deployment area, device function type, and security level. It associates with a dedicated address on the private blockchain to construct a trusted on-chain identity. The original information is encrypted using the national cryptographic SM4 algorithm, and the first access timestamp and security qualification verification code are embedded. The verification code is used to verify the legality of terminal access and is generated by combining the terminal's security qualification number, blockchain address fragment, and timestamp. The dynamic environment layer adopts a real-time environmental factor hash value embedding mechanism in coal mines. It extracts the hash values ​​of real-time gas concentration, humidity, and geological stress monitoring data at the terminal's deployment location as dynamic extension fields to achieve a strong correlation between the identifier and the environment, enabling the identifier to reflect the terminal's security status. The environmental data hash value is generated using the SHA-256 algorithm. During generation, monitoring data such as gas concentration, humidity, and geological stress are first concatenated in the format of "value and collection timestamp" and then hashed to ensure that a unique hash value is generated under the same environmental conditions and that the hash result is irreversible, thus preventing the falsification of hash values ​​after the environmental data has been tampered with.

[0007] Meanwhile, in response to the strong electromagnetic interference in the well, an anti-interference coding algorithm is used to optimize the redundancy of the hybrid identifier. Specifically, a combination of repetition coding and interleaving coding is adopted, with the number of repetitions set to 3 to adapt to the strong electromagnetic interference intensity in the well, and the interleaving depth designed to be 1.5 times the length of the transmitted data, to ensure a balance between anti-interference capability and transmission efficiency during data transmission.

[0008] The system adopts a dual-mode approach of full identification and simplified identification to adapt to the heterogeneity of terminals. The core control terminal uses full fields of static base layer and dynamic environment layer, while ordinary sensing terminals retain the inherent characteristics of hardware, blockchain address and simplified fields of core environmental factors. A dynamic identification update trigger mechanism is designed so that when the risk level of the environment where the terminal is located changes or the location is moved, the dynamic environment layer fields are automatically updated and synchronized to the blockchain.

[0009] Preferably, the consensus registration and evidence storage module achieves a balance between decentralization and regulatory adaptation through a coal mine-specific hierarchical consensus architecture. This architecture is based on an optimized design of a hybrid consensus algorithm of PBFT and PoS, and allocates differentiated consensus weights according to node type. Regulatory nodes have the right to veto consensus verification. The hybrid consensus logic consists of a two-step process: PoS node selection and PBFT consensus verification. First, 21 consensus nodes are selected based on their weight ratio using the PoS algorithm. This number balances consensus efficiency and fault tolerance, ensuring that the PBFT algorithm can quickly reach consensus. The higher the weight, the higher the probability of selection. Then, this consensus node group executes the PBFT algorithm to complete consensus verification for transactions such as identifier registration and state changes. Consensus must be confirmed by more than 2 / 3 of the nodes. The supervisory node can exercise its veto power during the verification phase. If the verification fails, the consensus process is restarted.

[0010] Regulatory nodes account for 30% of the weight, mining enterprise safety management center nodes account for 25%, equipment manufacturer nodes account for 20%, and the weight of underground edge nodes is dynamically allocated according to the number of connected terminals. The weight of a single node is capped at 10%, and the total weight of all nodes is 100%. During the consensus process, nodes participate in voting decisions according to their weight percentage.

[0011] Simultaneously, it integrates zero-knowledge proof and differential privacy algorithm to form a privacy-enhanced registration and verification mechanism. It anonymizes sensitive data, including terminal manufacturer information and security qualifications, to achieve the dual goals of compliance verification and privacy protection. At the same time, it designs a dynamic qualification verification mechanism that automatically synchronizes the terminal compliance database of the regulatory consortium blockchain during the registration process to verify the terminal's historical violation records. By pre-setting five levels of identification status (inactive, normal, warning, frozen, and deregistered) and status linkage rules through smart contracts, when environmental factors in the terminal's dynamic identification trigger a security threshold, the identification status is automatically switched to warning and high-risk operation permissions are restricted. Furthermore, the status change record is synchronized to the mining company's private chain and the regulatory alliance chain, enabling regulatory authorities to track the terminal status in real time.

[0012] After the terminal qualification is reviewed and on-chain registration is completed by the mining company's security management center, the inactive state will automatically switch to the normal state. If the terminal qualification expires, the data is tampered with, or the authentication fails three times in a row in the normal state, the frozen state will be triggered. After the frozen state is triggered, the manufacturer needs to submit a compliance certificate to unlock it. The cancellation state can only be initiated by the regulatory node or the mining company's management node. The terminal scrap certificate needs to be synchronized to the chain. After cancellation, it cannot be recovered. If the warning state is not lifted after 1 hour, it will automatically be upgraded to the frozen state.

[0013] Preferably, the fog cloud collaborative authentication module is based on the on-chain trusted identifier built by the consensus registration and evidence storage module. It realizes differentiated authentication of terminals with different security levels through the collaborative architecture of fog node self-organization and cloud deep verification. Fog nodes are deployed at the edge of the underground working face and a fog node self-organizing network mechanism is built. When a single fog node fails due to factors such as geological disasters or electromagnetic interference, the surrounding fog nodes automatically build a temporary collaborative network through short-distance communication to take over the authentication cache and response tasks of the failed node. The short-range communication adopts LoRa wireless communication technology, with a communication frequency of 433MHz to adapt to the downhole electromagnetic environment. The communication range has a coverage radius of 50 meters and a bandwidth of 125kHz. Spread spectrum modulation is used to enhance anti-interference capabilities and ensure that a temporary collaborative network can be quickly established between fog nodes.

[0014] Dedicated lightweight authentication algorithms are set for terminals with different security levels. Core monitoring terminals use full field verification of identifiers and environmental consistency verification, while ordinary sensor terminals use fast core field verification and reuse of historical authentication records. At the same time, an anti-interference check code mechanism is incorporated, and redundant check fields are added during the authentication data transmission process. The environmental consistency verification adopts a dual hash comparison method. On the one hand, it compares the hash value of the environmental data currently uploaded by the terminal with the most recent environmental hash value stored on the chain. If the deviation exceeds 5%, it is determined to be inconsistent. On the other hand, it compares the hash value of the environmental data of the terminal with the hash values ​​of the three adjacent terminals in the same area during the same period. If only the hash value of the terminal is abnormal, the anomaly monitoring process is triggered simultaneously to eliminate the problem of data distortion of a single terminal.

[0015] The core environmental factors are limited to two mandatory fields: real-time gas concentration and geological stress. The rules for reusing historical authentication records are: authentication results with no abnormal records within one hour are reused; if the environmental risk level is upgraded during this period, the results will automatically become invalid and need to be re-verified.

[0016] A dynamic adjustment mechanism for the validity period of fog node cache is adopted. The cache duration is set differently according to the terminal data transmission frequency and environmental risk level. The validity period of the authentication result cache of the core control terminal is 30 minutes, and the validity period of the cache of ordinary sensor terminal is 1 hour. The authentication response latency of the core control terminal is controlled within 8ms. The authentication result is synchronously fed back to the consensus registration and evidence storage module to complete the on-chain evidence storage.

[0017] Preferably, the dynamic permission adaptation module constructs a ternary correlation matrix of terminal security level, environmental risk level and personnel operation permission, and uses smart contract preset permission rules to prioritize the communication and control permissions of the core monitoring terminal. Terminal security levels are divided into three levels: core, important, and ordinary; environmental risk levels are divided into four levels: low risk, medium risk, high risk, and extremely high risk; and personnel operation permissions are divided into three categories: management permissions, operation permissions, and viewing permissions. Core-level terminals are granted only management and emergency operation permissions in extremely high-risk environments, while ordinary-level terminals are granted only viewing permissions in high-risk environments, and permissions for important-level terminals are reduced progressively according to the environmental risk level.

[0018] The smart contract collects terminal operation status data and environmental monitoring data in real time. When the terminal malfunctions, it automatically triggers permission downgrade and pushes the reason for permission adjustment, related terminal information and environmental risk data to the mining enterprise's safety management platform. Terminal anomaly detection criteria are met if any of the following conditions are met: 1. Data transmission packet loss rate exceeds 5% for 3 consecutive minutes; 2. Deviates from the registered deployment area by more than 10 meters; 3. Device online stability is below 95% for 10 consecutive minutes; 4. Environmental monitoring data deviates from the historical average on the blockchain by more than 30%.

[0019] All permission adjustment operations are recorded on the blockchain, and a legality verification process is set up simultaneously. The adjustment instructions are verified through smart contracts to ensure that they comply with coal mine safety production regulations and enterprise safety management systems.

[0020] The legality verification process consists of three checks: First, it verifies whether the node initiating the adjustment instruction has the necessary authority to make the adjustment; only the mine's safety management node and regulatory node can initiate such checks. Second, it verifies whether the adjustment rules comply with the "Coal Mine Safety Regulations" and the enterprise's custom safety system (built into the smart contract's rule library). Third, it verifies whether the adjustment behavior matches the terminal's current state and environmental risk level. For example, ordinary sensor terminals cannot have their permissions frozen in a low-risk environment. If all three checks pass, the adjustment is confirmed as legal; if any one fails, the adjustment is rejected and the abnormal operation is recorded.

[0021] Preferably, the cross-chain collaboration module relies on the permission rules of the dynamic permission adaptation module and the on-chain trusted data of the consensus registration and storage module to realize the authentication collaboration between the internal system of the mining enterprise and the external regulatory system. Based on the distributed soft bus technology, a standard protocol for cross-chain authentication information interoperability for coal mines is formulated to realize the standardized sharing of authentication information of cross-regional terminals. Design a group authentication algorithm based on the safety level of the work area, and use the safety level of the work area as the priority of group authentication. The group authentication latency of high-risk work areas is controlled within 15ms. At the same time, a cross-regional authentication linkage mechanism is built. When the terminal moves from one work area to another, the fog node in the target area automatically obtains the historical authentication records and security status of the terminal from the blockchain to complete the secondary authentication. The safety levels of working faces are divided into three levels: high, medium, and low. High-risk working faces refer to tunneling faces where the current gas concentration is between 0.5% and 1.0% and the geological stress exceeds 25 MPa. Medium-risk working faces refer to mining faces where the gas concentration is between 0.1% and 0.5% and the geological stress is between 15 and 25 MPa. Low-risk working faces refer to transport roadways and auxiliary areas where the gas concentration is below 0.1% and the geological stress is below 15 MPa. The level classification is automatically updated every 24 hours based on environmental monitoring data.

[0022] By employing data anonymization and authorized access mechanisms, when sharing authentication data with the regulatory consortium blockchain, terminal business secrets are automatically masked, and only fields necessary for security supervision are retained, thus balancing data sharing and privacy protection.

[0023] Preferably, the anomaly monitoring and response module integrates the dynamic environmental data of the hybrid identifier generation module, the authentication results of the fog-cloud collaborative authentication module, and the regional linkage information of the cross-chain collaborative module. By fusing the dynamic fields of terminal identifiers, operating status data, underground environmental monitoring data, and personnel positioning data, it constructs an anomaly detection model based on deep learning to identify complex anomaly scenarios. The deep learning anomaly detection model adopts a hybrid model of CNN and LSTM. The input data is first processed by Min-Max normalization, and the feature selection adopts the mutual information entropy method with a selection threshold of 0.3. The number of model training iterations is set to 500, and the batch size is set to 32 to ensure the recognition accuracy of complex anomaly scenarios.

[0024] The CNN layer has three convolutional blocks: the first block contains 16 3×3 convolutional kernels, the second block contains 32 3×3 convolutional kernels, and the third block contains 64 3×3 convolutional kernels, which are used to extract spatial correlation features of multi-dimensional data. The LSTM layer has two hidden layers to capture the temporal variation patterns of data. The output layer uses a fully connected layer and a Softmax activation function to achieve classification mapping between anomaly type and severity level.

[0025] The model training steps are as follows: Three months of historical data from coal mines were collected, including data under normal working conditions and various abnormal scenarios. After removing invalid and missing values, the data was divided into training set, validation set and test set in a ratio of 7:2:1. Min-Max standardization was used to unify the data range. The learning rate is set to 0.001, the Adam optimizer is selected, and the cross-entropy loss function is used. The number of iterations is set to 500. The model accuracy is verified every 10 iterations. Training stops when the accuracy on the validation set shows no improvement for 15 consecutive iterations. The final model accuracy on the test set must be ≥95%. By incorporating coal mine scenario weighting factors, data from high-risk scenarios such as excessive gas concentration and illegal terminal migration are given double the weight, thereby improving the sensitivity of key anomaly identification.

[0026] The model input data is filtered according to the needs of the scenario: environmental monitoring data takes three core indicators, namely gas concentration, humidity and geological stress, and collects one data every 5 seconds; the operation status data includes four parameters, namely packet loss rate, transmission delay, online stability and data integrity; the terminal identification dynamic field extracts two key information, namely safety level and status type; and the personnel positioning data retains two features, namely area number and movement trajectory deviation. The output is a triplet of anomaly probability, anomaly type, and severity level, which directly connects to the three-level handling strategy of the anomaly monitoring and response module, achieving seamless linkage between model output and scenario handling.

[0027] Based on the severity of the anomalies, three levels of standards are set up: general anomalies, severe anomalies, and emergency anomalies. Differentiated handling strategies are matched accordingly. General anomalies are handled with retry authentication and caching as a fallback. Severe anomalies are handled with permission freezing and alarm push. Emergency anomalies are handled with permission freezing, priority transmission of alarm information through the emergency channel, and linkage of on-site equipment shutdown warning. Emergency response latency is controlled within 80ms. Common anomaly trigger thresholds include data transmission delays exceeding 50ms, one failed verification of a single authentication data entry, and fluctuations in environmental data and on-chain historical averages within the range of 10%-20%. The thresholds for triggering serious anomalies include three consecutive authentication failures, a data transmission packet loss rate exceeding 10%, fluctuations in environmental data and on-chain historical averages exceeding 20% ​​for more than 5 minutes, and terminal locations deviating from the registration area by 5-10 meters. Emergency anomaly trigger thresholds include terminal location deviation exceeding 10 meters, environmental data exceeding limits (gas concentration ≥1.0% or geological stress ≥30MPa), detection of data tampering traces, and terminal access to blacklisted devices.

[0028] The fog node authentication data local redundancy backup mechanism is designed so that when the blockchain network is temporarily interrupted, the fog node can complete basic authentication based on the local backup data. After the network is restored, the authentication records are automatically synchronized to the blockchain, and the anomaly handling records are synchronized to the traceability audit module.

[0029] The locally redundant backup data includes the terminal's core authentication information, the results of the last three authentications, and basic permission rules; the backup frequency is an incremental backup every 10 minutes, and a cyclic overwrite strategy is used to retain the backup data of the most recent 24 hours; after network outage recovery, authentication records that have not been uploaded are synchronized first in timestamp order, and then the consistency between the local backup data and the on-chain data is updated.

[0030] Preferably, the traceability audit module integrates the full lifecycle data of the consensus registration and evidence storage module, the authentication records of the fog cloud collaborative authentication module, the permission adjustment records of the dynamic permission adaptation module, and the handling records of the anomaly monitoring and response module. It adopts Merkle tree and cross-chain hash synchronization technology to synchronize and store the full data of the terminal to the mining enterprise's private chain and the regulatory consortium chain, forming an immutable cross-chain traceability chain. The Merkle tree is constructed in chronological order, with terminal single authentication records, permission adjustment records, and exception handling records as leaf nodes. The cross-chain synchronization is triggered once every 100 terminal-related records or every 30 minutes. The synchronized hash value includes the Merkle tree root hash and the hash of the core field of a single record. The synchronization process uses an encrypted transmission channel to ensure that the cross-chain data is not tampered with.

[0031] By pre-setting relevant laws and industry standards for coal mine safety production through smart contracts, the system automatically extracts on-chain authentication data and compares it with compliance standards to generate a standardized compliance audit report, and automatically marks non-compliant terminals and pushes them to regulatory nodes. The compliance audit comparison data items include six categories: terminal qualification validity (whether the explosion-proof certification and annual inspection certificate are within the validity period), authentication frequency compliance (the core control terminal authenticates at least once per hour), permission adjustment compliance (whether it complies with the ternary association matrix rules), anomaly handling timeliness (whether emergency anomalies are responded to within 80ms), data transmission integrity (whether the packet loss rate is less than 5%), and terminal access legality (whether it is an inactive or deactivated terminal access). Smart contracts are compared item by item, and items that do not meet the standards are marked as non-compliant and the basis is noted.

[0032] The traceability query interface has been optimized to support multi-dimensional retrieval of traceability data by terminal identifier, time range, region, behavior type, and risk level. An accident traceability and location function has been designed so that when a safety accident occurs, the access records, permission operations, and abnormal behaviors of all terminals in the affected area can be traced with one click using key information including the accident area and time, thereby locating the responsible party.

[0033] The multi-dimensional search rules are as follows: Terminal identifier search supports exact matching and prefix fuzzy matching, with a minimum input of 6 identifier fragments; Time range search supports interval queries accurate to the minute, with a maximum query span of 90 days; Regional search is filtered by three levels: working face, roadway, and mining area; Behavior type search includes four fixed options: access, authentication, permission adjustment, and abnormal alarm; Risk level search supports filtering by three levels: general, severe, and urgent, with search results arranged in reverse chronological order by timestamp, and supports exporting reports in Excel format.

[0034] The beneficial effects of this invention are as follows: 1. This invention utilizes a private blockchain and a hierarchical consensus architecture, combining PBFT and PoS hybrid algorithms to allocate differentiated weights to nodes and granting regulatory nodes consensus verification veto power. While ensuring decentralization, it meets regulatory requirements and no longer relies on a single central server. Even if some nodes malfunction or are attacked, the fog node self-organizing network can quickly take over tasks, avoiding system-wide authentication interruption, which meets the high requirement of zero interruption in coal mine production. At the same time, by utilizing the immutability of on-chain data and cross-chain hash synchronization technology, a terminal lifecycle traceability chain is constructed. Combined with zero-knowledge proofs and differential privacy algorithms, it not only prevents authentication data from being tampered with but also protects the privacy of sensitive information and reduces the difficulty of accountability.

[0035] 2. This invention designs a dual-layer hybrid identifier consisting of a static base layer and a dynamic environment layer. An encryption algorithm ensures the uniqueness and legitimacy of the identifier, and embeds real-time environmental factor hash values ​​to strongly correlate the identifier with the terminal's environment. It employs a dual-mode identifier system: full identifier and simplified identifier. The core control terminal uses the full fields to ensure authentication accuracy, while ordinary sensing terminals retain the core simplified fields to reduce computational consumption, fully adapting to the heterogeneous characteristics of different types of terminals. Simultaneously, the dynamic identifier update mechanism automatically adjusts with environmental changes or location migration. Combined with the standardized interoperability protocol of the cross-chain collaboration module, it improves the low efficiency of cross-system and cross-regional authentication and mutual recognition. Through anti-interference coding optimization, it also enhances the stability of identifier transmission in complex underground environments.

[0036] 3. This invention constructs a fog-cloud collaborative authentication architecture, deploying fog nodes at the downhole edge to reduce reliance on the cloud, shorten authentication response latency, and meet the need for real-time transmission of critical security data. By differentiating terminal security levels and designing dedicated lightweight authentication algorithms, the core monitoring terminal uses full-field verification to ensure accuracy, while ordinary sensor terminals reuse historical records for rapid verification to improve efficiency, avoiding the rigidity of traditional unified authentication strategies. The dynamic permission adaptation module relies on a ternary association matrix and smart contracts to adjust permissions in real time according to terminal status and environmental risks, prioritizing the communication and control permissions of the core monitoring terminal, and automatically triggering permission downgrade and alarm when a terminal is abnormal. This improves upon the shortcomings of traditional authentication processes being cumbersome and lacking specificity, enhancing the system's adaptability and response speed to different terminals and risk scenarios. Attached Figure Description

[0037] Figure 1 This is a flowchart of the hybrid identifier generation process of the present invention; Figure 2 This is a flowchart of the fog cloud collaborative authentication process of the present invention; Figure 3 This is a flowchart of the anomaly monitoring and traceability audit process of the present invention. Detailed Implementation

[0038] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0039] like Figures 1 to 3 As shown, this embodiment of the invention provides a hybrid identifier authentication system for coal mine safety terminals based on a private blockchain, comprising: The hybrid identifier generation module adopts a two-layer hybrid identifier generation rule consisting of a static base layer and a dynamic environment layer. The static base layer retains the unique characteristics of the terminal chip, such as the serial number of the core module, to prevent hardware forgery. It integrates the core attributes of the scenario, such as the terminal deployment area, device function type, and security level, and associates them with the dedicated address of the private blockchain to build a trusted identity on the chain. It uses the national cryptographic SM4 algorithm to encrypt the original information and embeds the first access timestamp and security qualification verification code to ensure the legality and uniqueness of the identification base. The security qualification verification code is generated based on the terminal security qualification number, the last 8 bits of the private blockchain address hash, and the last 6 bits of the first access timestamp, with a fixed length of 16 bits. During verification, the qualification verification interface of the regulatory consortium blockchain is called on the blockchain to compare the consistency between the verification code and the terminal's filing information. If the verification fails, the terminal access is rejected.

[0040] The dynamic environment layer adopts a real-time environmental factor hash value embedding mechanism in coal mines. It extracts the hash values ​​of real-time gas concentration, humidity, and geological stress monitoring data at the terminal deployment location as dynamic extension fields to achieve a strong correlation between the identifier and the environment, enabling the identifier to reflect the safety status of the terminal. At the same time, in view of the strong electromagnetic interference in the mine, an anti-interference coding algorithm is used to perform redundancy optimization on the hybrid identifier to improve the anti-interference capability of identifier transmission and verification. The system adopts a dual-mode approach of full identification and simplified identification to adapt to the heterogeneity of terminals. The core control terminal uses full fields of static base layer and dynamic environment layer to ensure authentication accuracy. Ordinary sensing terminals retain the inherent characteristics of the hardware, blockchain address and simplified fields of core environmental factors to reduce computing power consumption. A dynamic identification update trigger mechanism is designed. When the risk level of the environment where the terminal is located changes (such as gas concentration exceeding the limit) or the location is moved, the dynamic environment layer fields are automatically triggered to be updated and synchronized to the blockchain to ensure that the identification matches the actual operating scenario of the terminal in real time.

[0041] The consensus registration and evidence storage module achieves a balance between decentralization and regulatory compatibility through a coal mine-specific hierarchical consensus architecture. This architecture is based on an optimized design of a hybrid consensus algorithm combining PBFT and PoS, allocating differentiated consensus weights according to node type. Regulatory nodes possess consensus verification veto power, ensuring both decentralization and meeting the regulatory authorities' control requirements for the authentication process. Consensus latency is controlled within 300ms to guarantee real-time access for underground terminals. Node types include mine safety management centers, equipment manufacturers, regulatory authorities, and underground edge nodes. Simultaneously, it integrates zero-knowledge proof and differential privacy algorithm to form a privacy-enhanced registration and verification mechanism, anonymizes sensitive data such as terminal manufacturer information and security qualifications, and achieves the dual goals of compliance verification and privacy protection, avoiding the leakage of sensitive information. At the same time, it designs a dynamic qualification verification mechanism, which automatically synchronizes the terminal compliance database of the regulatory consortium blockchain during the registration process to verify the terminal's historical violation records, thereby preventing non-compliant terminals from accessing the network from the source. The core items for dynamic qualification verification include terminal explosion-proof certification, equipment annual inspection certificate, and manufacturer production license. The verification frequency is every 72 hours, automatically synchronizing the verification results with the regulatory consortium blockchain database. If an expired or invalid qualification is found, the status of the identifier is immediately frozen and an alarm is pushed to the regulatory node. When synchronizing data, an incremental synchronization method is used, transmitting only fields related to qualification changes to improve efficiency.

[0042] By pre-setting five levels of identification status (inactive, normal, warning, frozen, and deregistered) and status linkage rules through smart contracts, when environmental factors in the terminal's dynamic identification trigger a safety threshold (such as excessive gas), the identification status is automatically switched to warning and high-risk operation permissions are restricted. Furthermore, the status change record is synchronized to the mining company's private chain and the regulatory alliance chain, enabling regulatory authorities to track the terminal status in real time.

[0043] The fog cloud collaborative authentication module is based on the on-chain trusted identifier built by the consensus registration and evidence storage module. It realizes differentiated authentication of terminals with different security levels through the collaborative architecture of fog node self-organization and cloud deep verification. Fog nodes are deployed at the edge of the underground working face and a fog node self-organizing network mechanism is built. When a single fog node fails due to geological disasters, electromagnetic interference or other factors, the surrounding fog nodes automatically build a temporary collaborative network through short-distance communication to take over the authentication cache and response tasks of the failed node, so as to avoid authentication interruption in local areas of the underground and improve system fault tolerance. Dedicated lightweight authentication algorithms are set up for terminals with different security levels. Core monitoring terminals such as gas sensors and emergency control terminals use full-field verification of identifiers and environmental consistency verification to ensure authentication accuracy. Ordinary sensor terminals use fast verification of core fields and reuse of historical authentication records to reduce computing power consumption. At the same time, an anti-interference check code mechanism is incorporated, and redundant check fields are added during the authentication data transmission process to resist authentication data distortion caused by underground electromagnetic interference. A dynamic adjustment mechanism for the validity period of fog node cache is adopted. The cache duration is set differently according to the terminal data transmission frequency and environmental risk level. The validity period of the authentication result cache of the core control terminal is 30 minutes to adapt to high-frequency data transmission, and the validity period of the cache of ordinary sensor terminals is 1 hour. This avoids duplicate authentication and ensures the timeliness of authentication in high-risk scenarios. The authentication response latency of the core control terminal is controlled within 8ms to meet the real-time transmission requirements of key safety data such as gas concentration and personnel location. The authentication result is synchronously fed back to the consensus registration and storage module to complete the on-chain storage.

[0044] The dynamic permission adaptation module constructs a three-element correlation matrix of terminal security level, environmental risk level and personnel operation permission, and uses smart contracts to preset refined permission rules. For example, when the gas concentration in a certain area exceeds the limit (enhanced environmental risk level), it automatically restricts the data transmission frequency of ordinary sensor terminals in that area and prioritizes the communication and control permissions of core monitoring terminals. The smart contract collects terminal operation status data and environmental monitoring data in real time. When the terminal experiences anomalies such as packet loss rate exceeding the threshold or deviation from the deployment area, it automatically triggers permission downgrade and pushes the reason for permission adjustment, related terminal information, and environmental risk data to the mining enterprise's security management platform to assist managers in quick handling. Terminal operation status data includes indicators such as data transmission integrity and equipment online stability. All permission adjustment operations are recorded on the blockchain, and a legality verification process is set up simultaneously. The smart contract verifies whether the adjustment instructions comply with coal mine safety production regulations and enterprise safety management system to prevent unauthorized permission changes.

[0045] The cross-chain collaboration module relies on the permission rules of the dynamic permission adaptation module and the on-chain trusted data of the consensus registration and storage module to realize the authentication collaboration between the internal system of the mining enterprise and the external regulatory system. Based on the distributed soft bus technology, a standard protocol for cross-chain authentication information interoperability for coal mines is formulated to support the seamless connection between the private chain of the mining enterprise and the local and national coal mine safety supervision alliance chain, realize the standardized sharing of cross-regional terminal authentication information, and thus solve the problem of authentication and mutual recognition between different mining areas and different regulatory levels. The core fields of the cross-chain authentication information interoperability standard protocol include five items: terminal identifier, security level, status type, authentication timestamp, and verification code. The data transmission format adopts JSON format, the communication port is uniformly set to 8089, and the data interaction sequence follows a three-step process of request, verification, and feedback to ensure standardized sharing of data across regions.

[0046] Design a group authentication algorithm based on the safety level of the work face, and use the safety level of the work face as the priority of group authentication. The group authentication latency of high-risk work faces (such as tunneling faces) is controlled within 15ms. At the same time, a cross-regional authentication linkage mechanism is built. When the terminal moves from one work area to another, the fog node in the target area automatically obtains the historical authentication records and security status of the terminal from the blockchain, and quickly completes secondary authentication without repeating the full process verification. By employing data anonymization and authorized access mechanisms, when sharing authentication data with the regulatory consortium blockchain, terminal trade secrets, such as the manufacturer's core technical parameters, are automatically masked, and only fields necessary for security supervision, such as identifiers, access time, operating status, and anomaly records, are retained, thus balancing data sharing and privacy protection.

[0047] The data anonymization and authorized access mechanism is specifically implemented as follows: 1. Data anonymization: Field replacement and partial masking are used. The terminal manufacturer's name is replaced with a unified code, and core technical parameters are formatted as "first 3 digits + ... The format "+ last two digits" is masked, and fields containing trade secrets are directly removed. 2. Authorized Access: Regulatory nodes submit access applications through the consortium blockchain, specifying the purpose of access and the required fields. The mining company's management node reviews the application within 24 hours. Once approved, the smart contract automatically generates a temporary access token, which is valid for 2 hours. Users can use the token to obtain anonymized data, and the access record is synchronously stored on the blockchain.

[0048] The anomaly monitoring and response module integrates the dynamic environmental data from the hybrid identifier generation module, the authentication results from the fog-cloud collaborative authentication module, and the regional linkage information from the cross-chain collaborative module. By fusing dynamic fields of terminal identifiers, operating status data, underground environmental monitoring data (gas, humidity, geological stress), and personnel positioning data, it constructs an anomaly detection model based on deep learning, enhances the system's robustness, and solves the problems of low anomaly detection accuracy and delayed emergency response in complex underground environments. It identifies complex anomaly scenarios such as the terminal location not matching the identifier registration area, unauthorized access to environmentally restricted areas, and abnormal data transmission frequency. Based on the severity of the anomalies, three levels of standards are set: general anomalies, severe anomalies, and emergency anomalies. Differentiated handling strategies are matched accordingly. For example, for general anomalies such as temporary network fluctuations, retry authentication and caching are implemented as a fallback. For severe anomalies such as terminal data tampering, permissions are frozen and alarms are pushed. For emergency anomalies such as illegal access by terminals in areas with excessive gas levels, permissions are frozen, alarm information is prioritized for transmission through emergency channels, and on-site equipment shutdown warnings are triggered. Emergency response latency is controlled within 80ms. The fog node authentication data local redundancy backup mechanism is designed so that when the blockchain network is temporarily interrupted, the fog node can complete basic authentication based on the local backup data to ensure that the core security data transmission is uninterrupted. After the network is restored, the authentication records are automatically synchronized to the blockchain to ensure data integrity, and the abnormal handling records are synchronized to the traceability and auditing module.

[0049] The traceability audit module integrates the full lifecycle data of the consensus registration and evidence storage module, the authentication records of the fog cloud collaborative authentication module, the permission adjustment records of the dynamic permission adaptation module, and the handling records of the anomaly monitoring and response module. It adopts Merkle tree and cross-chain hash synchronization technology to synchronize and store all relevant data, such as terminal identifier registration records, each authentication request / response data, permission adjustment records, and abnormal behavior alarm and handling records, to the mining company's private chain and the regulatory consortium chain, forming an immutable cross-chain traceability chain. This ensures that regulatory authorities can directly verify the traceability data to reduce audit costs. By pre-setting relevant laws and industry standards for coal mine safety production through smart contracts, the system automatically extracts on-chain authentication data and compares it with compliance standards to generate standardized compliance audit reports. It also automatically marks non-compliant terminals, such as those that have not been inspected on time or whose authentication records have expired, and pushes them to regulatory nodes. The traceability query interface has been optimized to support multi-dimensional data retrieval by terminal identifier, time range, region, behavior type, risk level, etc. An accident traceability and location function has been designed. When a safety accident occurs, the access records, permission operations and abnormal behaviors of all terminals in the area can be traced with one click through key information such as accident area and time, thereby locating the responsible party and completing the closed-loop management of the entire authentication system.

[0050] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0051] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A hybrid identification and authentication system for coal mine safety terminals based on a private blockchain, characterized in that, include: Hybrid Identifier Generation Module: It adopts a two-layer hybrid identifier generation rule with a static base layer and a dynamic environment layer. The static base layer integrates the inherent characteristics of terminal hardware, core attributes of the scene and blockchain dedicated address and encrypts them. The dynamic environment layer embeds the hash value of real-time environmental factors in the well. At the same time, it optimizes the anti-interference encoding of the hybrid identifier. It adapts to heterogeneous terminals through full identifier and simplified identifier dual mode and designs a dynamic update mechanism triggered by changes in environmental risk level and location migration. Consensus registration and evidence storage module: It transforms standardized identifiers into a trusted authentication basis, achieves a balance between decentralization and regulatory adaptation through a coal mine-specific hierarchical consensus architecture, and allocates differentiated weights to nodes based on a hybrid consensus algorithm; The system integrates privacy enhancement technologies to achieve registration verification, presets five levels of identification status and linkage rules, and synchronizes status changes to the mining company's private chain and the regulatory alliance chain. Fog-Cloud Collaborative Authentication Module: Based on on-chain trusted identifiers, it achieves differentiated authentication through a collaborative architecture of fog node self-organization and cloud-based deep verification; it deploys a fog node self-organizing network to improve fault tolerance, configures lightweight authentication algorithms for terminals with different security levels and incorporates anti-interference verification mechanisms; it dynamically adjusts the fog node cache duration and synchronizes authentication results to the chain for evidence storage. Dynamic permission adaptation module: Based on smart contracts, a multi-dimensional dynamic permission adjustment system is built. Permission rules are preset through a ternary correlation matrix of terminal security level, environmental risk level and personnel operation permissions. When the terminal is abnormal, permission downgrade and alarm are triggered, and the legality of permission adjustment is verified and recorded on the chain. Cross-chain collaboration module: Based on permission rules and on-chain data, a cross-chain authentication and interoperability protocol is set up to enable collaboration between mining companies and regulatory systems; a working face group authentication and cross-regional linkage mechanism is designed, and data anonymization and authorized access mechanisms are adopted to ensure data security; Anomaly monitoring and response module: Integrates relevant data from multiple modules to build an anomaly detection model based on deep learning, classifies anomalies into three levels and matches them with differentiated handling strategies; designs a local redundant backup mechanism for fog nodes to ensure basic authentication during network outages and synchronizes handling records to the traceability and auditing module; Traceability and Audit Module: The traceability chain is constructed using Merkle trees and cross-chain hash synchronization technology; compliance audits are completed and results are pushed through smart contracts, and multi-dimensional search and incident location functions are optimized.

2. The hybrid identification and authentication system for coal mine safety terminals based on a private blockchain as described in claim 1, characterized in that, The static base layer of the hybrid identifier generation module retains the inherent hardware features, including the terminal chip's unique code and the core module's serial number, integrates the core attributes of the scenario, including the terminal's deployment area, device function type, and security level, associates the blockchain private chain's dedicated address to construct a trusted on-chain identity, and uses national cryptographic algorithms to encrypt the original information and embed the first access timestamp and security qualification verification code. The dynamic environment layer extracts the hash value of monitoring data, including real-time gas concentration, humidity, and geological stress at the terminal deployment location, as a dynamic extended field. The anti-interference coding algorithm is designed with a redundancy optimization scheme for strong electromagnetic interference scenarios in the well. The adaptation rules for full and simplified identifiers are as follows: core control terminals use full fields of static base layer and dynamic environment layer, while ordinary sensing terminals retain the inherent hardware characteristics, blockchain address and simplified fields of core environmental factors; the dynamic update triggering mechanism is that when the risk level of the environment in which the terminal is located changes or the location is moved, the dynamic environment layer fields are automatically triggered to be updated and synchronized to the blockchain.

3. The hybrid identification and authentication system for coal mine safety terminals based on a private blockchain as described in claim 2, characterized in that, The consensus registration and storage module's coal mine-specific hierarchical consensus architecture is based on an optimized design of a hybrid consensus algorithm combining PBFT and PoS, and allocates differentiated consensus weights according to node type, with regulatory nodes having the right to veto consensus verification. The privacy enhancement technology is a fusion of zero-knowledge proof and differential privacy algorithm. It anonymizes sensitive data, including terminal manufacturer information and security qualifications, and designs a dynamic qualification verification mechanism. During the registration process, it simultaneously monitors the terminal compliance database of the consortium blockchain and verifies historical violation records. The five-level identification status is inactive, normal, warning, frozen, and deregistered. The status linkage rules are preset by the smart contract. The core rules include: when the environmental factors in the terminal's dynamic identification trigger the security threshold, it automatically switches to the warning status and restricts high-risk operation permissions. Other status transitions are executed according to preset logic, and status change records are synchronized to the mining company's private chain and the regulatory consortium chain.

4. The hybrid identification and authentication system for coal mine safety terminals based on a private blockchain as described in claim 3, characterized in that, The fog node self-organizing network of the fog cloud collaborative authentication module is deployed at the edge of the downhole working face. When a single fog node fails, the surrounding fog nodes build a temporary collaborative network through short-range communication to take over the authentication cache and response tasks of the failed node. The lightweight authentication algorithms for terminals with different security levels are configured differently: core monitoring terminals use full-field verification of the identifier and environmental consistency verification, while ordinary sensor terminals use fast core field verification and reuse of historical authentication records. The anti-interference verification mechanism is implemented by adding redundant verification fields during the authentication data transmission process. The dynamic adjustment rule for the validity period of fog node cache is as follows: it is set differently according to the terminal data transmission frequency and environmental risk level. The validity period of the authentication result cache of the core control terminal is 30 minutes, the validity period of the cache of ordinary sensor terminal is 1 hour, and the authentication response latency of the core control terminal is controlled within 8ms.

5. The hybrid identification and authentication system for coal mine safety terminals based on a private blockchain according to claim 4, characterized in that, In the preset permission rules of the ternary association matrix of the dynamic permission adaptation module, priority is given to ensuring the communication and control permissions of the core monitoring terminal. The smart contract collects terminal operation status data and environmental monitoring data in real time. When the terminal is abnormal, it triggers permission downgrade and pushes the reason for permission adjustment, related terminal information and environmental risk data to the mining enterprise's safety management platform. The permission adjustment legality verification process verifies the legality of the adjustment instruction through a smart contract, and all permission adjustment operations are fully recorded on the blockchain.

6. The coal mine safety terminal hybrid identification and authentication system based on a private blockchain according to claim 5, characterized in that, The cross-chain collaboration module is based on distributed soft bus technology to formulate a standard protocol for cross-chain authentication information interoperability for coal mines, so as to realize the standardized sharing of cross-regional terminal authentication information. The working face group authentication algorithm uses the safety level of the working face as the priority of group authentication, and the authentication latency of high-risk working face groups is controlled within 15ms. The cross-regional authentication linkage mechanism enables the target region's fog node to automatically obtain the terminal's historical authentication records and security status from the blockchain and complete secondary authentication when the terminal moves across regions. The data anonymization and authorized access mechanism is as follows: when sharing authentication data with the regulatory consortium blockchain, terminal business secrets are automatically masked, and only fields necessary for security supervision are retained. Specific anonymization rules and access permissions are preset by the smart contract.

7. The coal mine safety terminal hybrid identification and authentication system based on private blockchain according to claim 6, characterized in that, The anomaly monitoring and response module integrates multi-module data including dynamic environmental data from the hybrid identifier generation module, authentication results from the fog-cloud collaborative authentication module, and regional linkage information from the cross-chain collaborative module. It constructs a deep learning anomaly detection model by fusing dynamic fields of terminal identifiers, operational status data, downhole environmental monitoring data, and personnel positioning data. The three-level anomaly standards are general anomaly, severe anomaly, and emergency anomaly. The corresponding differentiated handling strategies are as follows: for general anomalies, retry authentication and cache fallback are implemented; for severe anomalies, permission freezing and alarm push are implemented; for emergency anomalies, permission freezing is implemented, alarm information is prioritized for transmission through the emergency channel, and on-site equipment shutdown warning is linked. The emergency response latency is controlled within 80ms. The fog node local redundancy backup mechanism ensures basic authentication when the blockchain network is temporarily interrupted, and automatically synchronizes authentication records to the blockchain after the network is restored.

8. The coal mine safety terminal hybrid identification and authentication system based on a private blockchain according to claim 7, characterized in that, The data integrated by the traceability audit module includes the full lifecycle data of the consensus registration and evidence storage module, the authentication records of the fog cloud collaborative authentication module, the permission adjustment records of the dynamic permission adaptation module, and the handling records of the anomaly monitoring and response module. Through Merkle tree and cross-chain hash synchronization technology, the full amount of terminal data is synchronized and stored to the mining enterprise's private chain and the regulatory consortium chain to form an immutable cross-chain traceability chain. The compliance audit automatically compares on-chain authentication data with compliance standards by using smart contracts to pre-set coal mine safety production regulations and industry standards, generates a standardized compliance audit report, and marks non-compliant terminals to be pushed to regulatory nodes. Multi-dimensional retrieval supports querying and tracing data based on conditions including terminal identifier, time range, region, behavior type, and risk level; the accident tracing and location function can use key information including accident area and time to trace the access records, permission operations, and abnormal behaviors of all terminals in the area with one click to locate the responsible party.