A power monitoring system operation and maintenance personnel authentication method based on finger vein recognition

CN122087794BActive Publication Date: 2026-08-07STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO
Filing Date
2026-04-21
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0003]鉴于上述的分析,本发明实施例旨在提供一种基于指静脉识别的电力监控系统运维人员认证方法,用以解决现有电力监控系统运维场景中身份认证与系统账号权限脱节、国产化适配浅层化以及现有指静脉采集设备物理稳定性差的技术问题

Benefits of technology

1、本发明通过SM9标识加密算法,以“人员ID+系统账号”的联合标识对指静脉特征基准模板进行加密,从密码学层面实现人员身份与系统账号的强绑定;结合Shamir秘密共享分片与三节点物理隔离存储,确保运维人员的生物特征的基准模板在存储和传输过程中不可篡改、不可窃取。登录认证时,必须同时满足指静脉活体匹配、系统账号关联校验和多维权限校验,杜绝系统账号冒用、权限滥用和操作追溯难的问题,满足电力监控系统“高安全、强管控、全链路可审计”的要求。解决了现有方法仅支持传统的账号密码登录或单一生物特征替代密码,未建立人员物理身份、系统操作账号、指静脉生物特征三者的唯一强绑定认证机制,导致权限管控松散、操作行为难以精准追溯的技术缺陷。实现“运维人员用户标识ID-系统账号-生物特征”三位一体强绑定,填补身份认证与权限管控的安全断层;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122087794B_ABST
    Figure CN122087794B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of power monitoring system based on finger vein identification operation and maintenance personnel authentication method, including the finger vein image of operation and maintenance personnel is collected to carry out living body detection, if pass, generate reference template;With the joint identification of operation and maintenance personnel, the feature ciphertext of reference template is generated by encryption, and split into multiple ciphertext fragments and store respectively;In response to the operation request of operator to system, the finger vein image of operator is collected in real time to carry out living body detection;If pass, then based on the real-time feature vector of finger vein image;From multiple storage nodes, the ciphertext fragment of the personnel identification and operation account corresponding to operator is obtained, reorganization and decryption are obtained corresponding reference template;In response to the first matching degree of real-time feature vector and corresponding reference template meets preset condition, then based on reference template and real-time feature vector, calculate fusion feature vector;Based on the second matching degree of fusion feature vector and reference template, judge whether to allow operator to operate power monitoring system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of biometric technology and computer peripheral technology, specifically to a method for authenticating maintenance personnel of a power monitoring system based on finger vein recognition. Background Technology

[0002] With increasing demands for information security, finger vein recognition, with its advantages of liveness detection, non-copyability, and high security, has been widely used in fields such as power and finance. However, existing finger vein collection methods have the following drawbacks in practical applications: ① Disconnect between identity authentication and account permissions: In the current power monitoring system operation and maintenance scenario, the traditional login authentication method that supports account login does not establish a three-in-one unique and strong binding authentication mechanism of personnel identity, system account and finger vein biometrics. It is impossible to realize the association verification of operation and maintenance personnel, system account and biometrics. The permission control is loose, and the operation behavior is difficult to trace accurately. It cannot meet the high security, strong control and full-link auditability requirements of power monitoring operation and maintenance scenario. ② Superficial adaptation to domestic use: Existing finger vein acquisition devices often only support application layer drivers and have not been optimized for the domestic operating system kernel and CPU, resulting in insufficient stability in the domestic environment and no customized adaptation for power monitoring systems. ③ Poor physical stability: Most existing finger vein scanners are small, independent peripherals with light weight. When users press their fingers to collect data, the device is very easy to slide or shift on the table, resulting in blurry vein images. Summary of the Invention

[0003] Based on the above analysis, the embodiments of the present invention aim to provide a method for authenticating operation and maintenance personnel of power monitoring systems based on finger vein recognition, in order to solve the technical problems of disconnect between identity authentication and system account permissions, superficial localization adaptation, and poor physical stability of existing finger vein acquisition devices in the operation and maintenance scenarios of existing power monitoring systems.

[0004] The objective of this invention is mainly achieved through the following technical solutions: This invention provides a method for authenticating maintenance personnel in a power monitoring system based on finger vein recognition, comprising the following steps: Collect finger vein images of maintenance personnel for liveness detection. If the liveness detection is successful, a baseline template for the maintenance personnel is generated. The baseline template is then encrypted using the joint identifier of the maintenance personnel to generate feature ciphertext, which is then split into multiple ciphertext fragments and stored separately. In response to the operator's authentication request for the power monitoring system, the finger vein image of the operator is collected in real time for liveness detection; if the liveness detection is successful, a real-time feature vector is extracted based on the finger vein image; multiple encrypted fragments corresponding to the operator's personnel identifier and operation account are obtained from multiple storage nodes, and then reassembled and decrypted to obtain the corresponding baseline template. In response to the first matching degree between the real-time feature vector and the corresponding reference template satisfying a preset condition, a fused feature vector is calculated based on the reference template and the real-time feature vector; based on the second matching degree between the fused feature vector and the reference template, it is determined whether the operator is allowed to operate the power monitoring system.

[0005] Furthermore, finger vein images of maintenance personnel are collected for liveness detection, including: Collect continuous finger vein image sequences and finger temperature data from maintenance personnel; Blood flow pulsation features are extracted by the grayscale changes of the continuous finger vein image sequence; Dynamic features are identified by the inter-frame micro-motion changes in the continuous finger vein image sequence; When the finger temperature data meets the preset finger temperature threshold, the blood flow pulsation feature is within the preset blood flow pulsation threshold range, and the dynamic feature meets the preset continuous frame grayscale fluctuation deviation, it is determined that the operation and maintenance personnel liveness detection has passed. Otherwise, the liveness detection of the maintenance personnel will be deemed unsuccessful.

[0006] Furthermore, finger vein images of maintenance personnel are collected using a finger vein acquisition device; wherein, the finger vein acquisition device has a built-in security chip; The baseline template for generating operations and maintenance personnel includes: Within the security chip, the finger vein image that has passed the liveness detection is preprocessed to obtain a preprocessed finger vein image; the image preprocessing includes image enhancement, region of interest extraction, vein pattern enhancement, and normalization processing; The preprocessed finger vein image is subjected to feature extraction within the security chip to obtain a preset feature dimension. Finger vein feature vector ; the finger vein feature vector As a benchmark template for operations and maintenance personnel .

[0007] Furthermore, using the joint identifier of the maintenance personnel, the baseline template is encrypted to generate characteristic ciphertext, including: Using a key generation center deployed in the offline security zone of the power monitoring system, an SM9 encrypted master public key is generated offline. With the master private key ; Based on the personnel identification of the maintenance personnel and their operation account in the power monitoring system, a joint identifier for the maintenance personnel is generated as the SM9 user identifier; at the same time, the user private key of the maintenance personnel is generated offline and burned into the security chip through offline burning method; Based on the master public key Using the SM9 user identifier and the SM9 identifier cryptographic algorithm, the baseline template is... Offline encryption yields the following ciphertext with the following characteristics:

[0008] in, This is a ciphertext with distinctive features; SM9 is the user identifier; SM9.Enc() is the SM9 encryption operation.

[0009] Furthermore, the ciphertext with the characteristics is split into multiple ciphertext fragments and stored separately, including: In a finite field of 256-bit large prime numbers The above converts the ciphertext into integer elements. Two random coefficients are generated using a national cryptographic true random number generator. and ; based on , and Construct the quadratic polynomial as follows:

[0010] in, For pre-generated 256-bit safe large prime numbers ; Substitute them separately , , The first ciphertext fragment was obtained. Second encrypted fragment Third encrypted fragment ; Will The encrypted storage area of ​​the security chip in the finger vein acquisition device; The encrypted storage area of ​​the private identity authentication server in the power monitoring system; The encrypted storage area is located in the power monitoring terminal workstation operated by maintenance personnel; The three storage nodes—finger vein acquisition device, private identity authentication server, and power monitoring terminal workstation—are physically isolated.

[0011] Furthermore, multiple encrypted fragments corresponding to the operator's personnel identifier and operation account are obtained from multiple storage nodes, reassembled, and decrypted to obtain the corresponding baseline template, including: The second and third encrypted fragments corresponding to the operator's personnel identifier and operation account are obtained from the encrypted storage area of ​​the private identity authentication server and the encrypted storage area of ​​the power monitoring terminal workstation, respectively. and will Transmitted to the secure chip via a trusted encrypted link; Within the security chip, the first encrypted fragment containing the personnel identifier and operation account corresponding to the operator is retrieved. Using finite fields The Shamir secret sharing algorithm uses Lagrange interpolation to... Reconstruction and decryption are performed to obtain the corresponding characteristic ciphertext. ; Based on the corresponding feature ciphertext The system uses the private key of the maintenance personnel within the security chip to perform SM9 decryption operations and obtain the corresponding baseline template. .

[0012] Further, in response to the first matching degree between the real-time feature vector and the corresponding benchmark template satisfying a preset condition, a fused feature vector is calculated based on the benchmark template and the real-time feature vector, including: The real-time feature vector is compared with the corresponding benchmark template using cosine similarity to obtain the first matching degree. ; If the first matching degree If the real-time feature vector is not less than a preset condition, then the real-time feature vector is a valid real-time feature vector. A fused feature vector is calculated based on the benchmark template and the valid real-time feature vector, as follows:

[0013] in, To fuse feature vectors, This is the base template obtained from the SM9 decryption operation. To integrate weights, This is an effective real-time feature vector.

[0014] Further, the step of determining whether the operator is permitted to operate the power monitoring system based on the second matching degree of the fused feature vector and the benchmark template includes: Calculate the second matching degree between the fused feature vector and the baseline template; If the second matching degree is not less than the corresponding preset condition and the multi-dimensional permission verification passes, then the operator is allowed to operate the power monitoring system, and it is determined whether to dynamically update the encrypted fragment of the maintenance personnel corresponding to the operator. Otherwise, refuse the operator's request to operate the power monitoring system.

[0015] Furthermore, multi-dimensional permission verification is performed, including: When maintenance personnel register for the power monitoring system, the system pre-configures their operation time range permissions, binds their finger vein acquisition device permissions, and allows them to operate functions, thus constructing a permission map of the maintenance personnel's operation time range, finger vein acquisition device, and the power monitoring system's operable functions. Determine whether the operator's current operation time is within the pre-configured operation time range of maintenance personnel, whether the current finger vein acquisition device is in the list of bound finger vein acquisition devices, and whether the current operation request is within the functional permission map of the operable power monitoring system.

[0016] Furthermore, the system allows the operator to operate the power monitoring system and determines whether to dynamically update the encrypted fragments of the maintenance personnel corresponding to that operator, including: If the fusion weight does not exceed the weight threshold, and the maintenance personnel corresponding to the operator update the baseline template no more than once per day. Next, based on the aforementioned master public key The joint identifier of the maintenance personnel corresponding to the operator and the operation account of the maintenance personnel in the power monitoring system is used to fuse the feature vector. Perform offline encryption to obtain the corresponding characteristic ciphertext; The corresponding ciphertext with the characteristic is split into the corresponding first, second, and third ciphertext fragments; The first, second, and third ciphertext fragments are synchronously and dynamically updated to multiple physically isolated storage nodes via a trusted encrypted link.

[0017] Compared with the prior art, the present invention can achieve at least one of the following beneficial effects: 1. This invention uses the SM9 identifier encryption algorithm to encrypt the finger vein feature baseline template with a joint identifier of "personnel ID + system account," achieving a strong binding between personnel identity and system account at the cryptographic level. Combined with Shamir secret sharing sharding and three-node physical isolation storage, it ensures that the baseline template of the biometric features of maintenance personnel cannot be tampered with or stolen during storage and transmission. During login authentication, finger vein liveness matching, system account association verification, and multi-dimensional permission verification must be simultaneously satisfied, preventing system account impersonation, permission abuse, and difficulties in operation traceability, thus meeting the requirements of "high security, strong control, and full-link auditability" for power monitoring systems. It solves the technical defects of existing methods that only support traditional account password login or single biometric feature to replace password, failing to establish a unique strong binding authentication mechanism between personnel physical identity, system operation account, and finger vein biometric features, resulting in loose permission control and difficulty in accurately tracing operational behavior. It achieves a strong binding of "maintenance personnel user identifier ID - system account - biometric feature," filling the security gap between identity authentication and permission control. 2. This invention achieves full-stack domestic compatibility from the underlying hardware to the application system: The finger vein acquisition device has a built-in national cryptographic level 2 security chip, supporting national cryptographic algorithms such as SM2 / SM3 / SM4 / SM9; the driver is deeply adapted to the domestic operating system kernel, automatically recognizing it without additional driver installation; the management system of the power monitoring system can seamlessly connect to the core business platforms of the power monitoring system's control cloud and dispatch control system. This invention solves the technical defects of existing finger vein acquisition devices that only support application-layer drivers and have not been optimized for domestic CPUs and operating systems, resulting in unstable operation and poor compatibility in domestic environments. Deep domestic adaptation achieves full-stack compatibility from the underlying hardware to the application system; it is compatible with domestic databases (such as DM Database and Kingbase Database) and domestic operating systems (such as Kylin V10, UnionTech UOSV20, and NingSi 6.0.80); 3. This invention integrates a finger vein acquisition module into a finger vein keyboard. Utilizing the keyboard's own weight and anti-slip base, along with dual-positioning contact points, it physically guides the finger to press correctly, fundamentally solving the problems of device slippage, image blurring, and poor stability during acquisition, thus improving recognition success rate and user comfort. Simultaneously, it pioneers a three-dimensional liveness detection mechanism: detecting finger temperature through built-in thermal sensors on the dual-positioning contact points, extracting blood flow pulsation features through continuous image grayscale changes, and identifying dynamic features through micro-motion changes in multi-frame images. This three-dimensional logical fusion effectively prevents various forgery attacks such as silicone finger molds, 3D printing, photos, video playback, and non-living fingers, significantly improving acquisition success rate and recognition security. It addresses the technical shortcomings of existing finger vein acquisition devices, which are mostly small, independent peripherals with light weight, making them prone to slippage and image blurring when pressed by the user; and the difficulty of single-dimensional liveness detection in preventing forgery attacks such as silicone finger molds, photos, and video playback. The innovative hardware structure and liveness detection mechanism solve the problems of acquisition displacement and forgery attacks.

[0018] In this invention, the above-described technical solutions can be combined with each other to achieve more preferred combinations. Other features and advantages of this invention will be set forth in the following description, and some advantages may become apparent from the description or be learned by practicing the invention. The objects and other advantages of this invention can be realized and obtained from what is particularly pointed out in the description and drawings. Attached Figure Description

[0019] The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of the invention. Figure 1 This is a flowchart of a power monitoring system maintenance personnel authentication method based on finger vein recognition, as described in an embodiment of the present invention. Figure 2 This is an example diagram of a finger vein acquisition device in an embodiment of the present invention; Figure 3 This is an example diagram of the security partitioning architecture and corresponding encrypted fragment storage of the power monitoring system in an embodiment of the present invention. Detailed Implementation

[0020] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not intended to limit the scope of the present invention.

[0021] This method is implemented based on a four-layer logical architecture: acquisition layer, security processing layer, authentication service layer, and business control layer. Its core features include: on-chip matching authentication based on fragmented biometric features; dynamic updating method of biometric features with baseline template constraints; and multi-dimensional permission binding control and verification based on biometric authentication.

[0022] This method enables a strong, lifecycle-wide security binding and management of personnel identification, system account, and finger vein biometrics for power monitoring system operation and maintenance personnel. It can cover the identity authentication and access control needs of core businesses such as power dispatching, substation operation and maintenance, distribution automation, and power marketing.

[0023] A specific embodiment of the present invention discloses a method for authenticating maintenance personnel of a power monitoring system based on finger vein recognition, such as... Figure 1 As shown, it includes the following steps: Step S1: Collect finger vein images of maintenance personnel for liveness detection. If the liveness detection is successful, generate a baseline template for the maintenance personnel. Encrypt the baseline template with the joint identifier of the maintenance personnel to generate feature ciphertext, and split it into multiple ciphertext fragments for separate storage. Step S2: In response to the operator's authentication request for the power monitoring system, the finger vein image of the operator is collected in real time for liveness detection; if the liveness detection is successful, the real-time feature vector is extracted based on the finger vein image; multiple encrypted fragments of the personnel identifier and operation account corresponding to the operator are obtained from multiple storage nodes, and reconstructed and decrypted to obtain the corresponding baseline template. Step S3: In response to the first matching degree between the real-time feature vector and the corresponding reference template satisfying a preset condition, calculate the fused feature vector based on the reference template and the real-time feature vector; and determine whether the operator is allowed to operate the power monitoring system based on the second matching degree between the fused feature vector and the reference template.

[0024] The method of this invention is implemented based on a four-layer logical architecture, as follows: ① Acquisition Layer: The core is a finger vein acquisition device with a built-in national cryptographic level 2 security chip (civilian and commercial security chip), such as... Figure 2 As shown, the finger vein acquisition device uses dual-positioning contact sensing to acquire finger vein images and perform liveness detection for maintenance personnel, providing original and reliable acquisition data for the registration and authentication processes of maintenance personnel. For example, a finger vein acquisition device is used for... Figure 2 The keyboard integrates a national cryptographic level 2 security chip and a finger vein acquisition function.

[0025] National cryptography refers to cryptographic algorithms that conform to SM2 / SM3 / SM4 / SM9; Level 2 security chips indicate that the chips meet commercial and civilian security requirements and have core functions such as hardware encryption, anti-tampering, and key management. National cryptography Level 2 security chips are widely used in fields with high security requirements such as finance and power.

[0026] ②Security processing layer: The finger vein acquisition device has a built-in national cryptographic level 2 security chip, which is responsible for finger vein feature extraction, SM9 encryption and decryption, Shamir fragment reconstruction, and in-chip feature comparison (Match-on-Chip). Sensitive data does not leave the security chip throughout the entire process. This solution adopts a national cryptographic level 2 security chip to achieve a closed-loop system of full-stack localization from the underlying hardware (national cryptographic 64-bit chip) → operating system (Kylin V10, Tongxin UOSV20, NingSi 6.0.80) → CPU (Phytium, Loongson, Kunpeng) → database (DM, Renmin University Kingbase) → business applications (D6.0, control cloud, etc.), which meets the power industry's requirements of "independent controllability, security and reliability".

[0027] ③ Authentication Service Layer: A private identity authentication server deployed in Security Zone III of the power monitoring system is responsible for managing user information of maintenance personnel, storing feature-encrypted fragments, configuring permission rules, and managing audit logs; the Key Generation Center (KGC) function provides backend service support for the authentication process of maintenance personnel; such as... Figure 3 As shown.

[0028] KGC is a functional component of the private identity authentication server; the two have a relationship of inclusion and being included.

[0029] The private identity authentication server is deployed in the security zone III of the power monitoring system. In addition to core functions such as managing user information of operation and maintenance personnel, storing feature-encrypted fragments, configuring permission rules, and managing audit logs, it also integrates KGC functionality.

[0030] As a key module of the server, KGC is mainly responsible for core cryptographic tasks such as generating the master public key and master private key of the SM9 encryption algorithm offline and generating user private keys based on the joint identifier of operation and maintenance personnel, providing key support for the entire authentication process.

[0031] In summary, a private identity authentication server is a comprehensive service node that includes KGC functionality, with KGC serving as the underlying cryptographic support module for achieving secure identity authentication.

[0032] ④ Business Control Layer: Corresponds to the various business power monitoring terminal workstations / operator stations and core business platforms of the power monitoring system. It is responsible for receiving the authentication results of maintenance personnel, executing permission linkage, and triggering business operations, so as to achieve deep adaptation between maintenance personnel identity authentication and power monitoring operation business.

[0033] Before executing step S1 of the method, it is necessary to initialize the management system of the power monitoring system and the finger vein acquisition device, and establish a trusted encrypted link between the finger vein acquisition device and the power monitoring system.

[0034] The initialization of the management system of the power monitoring system, and the trusted connection process between the power monitoring system and the finger vein acquisition device, corresponding to the initialization of the acquisition layer and the security processing layer.

[0035] This section completes the deployment of the management system corresponding to the power monitoring system, the hardware initialization of the finger vein acquisition equipment, and the establishment of a trusted encrypted link, providing a basic operating environment for subsequent authentication processes, including: A management system for deploying power monitoring systems adapted to domestic operating systems; Hardware initialization is performed on the finger vein acquisition device with a built-in national cryptographic level 2 security chip, and liveness detection parameters are preset in the security chip; wherein, the security chip is a national cryptographic level 2 security chip; the liveness detection parameters include temperature detection threshold, blood flow pulsation detection threshold, and multi-frame image dynamic change threshold; The finger vein acquisition device is connected to the power monitoring terminal via a USB interface to complete the national cryptographic SM4-CBC link encryption negotiation between the finger vein acquisition device and the management system. A session key is generated based on the national cryptographic true random number generator. The session key is then bidirectionally bound to the hardware serial number of the finger vein acquisition device and the unique identifier of the power monitoring terminal hardware to obtain a trusted encrypted link between the finger vein acquisition device and the power monitoring system. The session key is automatically rotated at a preset time period and becomes invalid immediately after the USB bus connection is disconnected.

[0036] ① Deployment of the management system for the power monitoring system: Download the installation package of the management system. For example, the installation package is a domestic operating system installation package such as Kylin V10, Tongxin UOSV20, or NingSi 6.0.80. Double-click to run the installer and follow the prompts to complete the installation. The installation path can be customized and the disk space occupied is ≤50MB. The system automatically adapts to the operating system kernel during the installation process, without the need for additional configuration of domestic drivers. It is compatible with the existing operating environment of the power monitoring terminal workstation / operator station and does not require updating the operating system of the power monitoring terminal workstation / operator station.

[0037] ② Hardware-level trusted link negotiation: The finger vein acquisition device with a built-in national cryptographic level 2 security chip is connected to the power monitoring terminal workstation via a USB interface for encrypted data transmission and communication. The finger vein acquisition device and the management system complete the national cryptographic SM4-CBC link encryption negotiation: based on the hardware serial number of the finger vein acquisition device and the unique hardware identifier of the power monitoring terminal workstation / operator station, a session key is generated using a national cryptographic true random number generator.

[0038] For example, the session key is automatically rotated every 24 hours, and the session key becomes invalid immediately after a single USB connection is disconnected; all subsequent data transmission of finger vein images, finger vein features, and encrypted fragments is transmitted through a trusted encrypted link, and plaintext data does not enter the USB bus. At the same time, each transmitted encrypted data packet carries a millisecond-level timestamp and a 16-bit random number, which can prevent the USB bus from being hijacked and replay attacks.

[0039] A replay attack is a type of network attack in which an attacker intercepts and resends previously transmitted legitimate data packets in order to trick the system into performing unauthorized operations.

[0040] ③ Connection confirmation of finger vein acquisition device: After the encryption negotiation is completed, the power monitoring terminal workstation / operator station identifies the finger vein acquisition device. After the management system is started, a trusted encrypted connection is established. The connection light of the finger vein acquisition device changes from flashing to solid light, indicating that the finger vein acquisition device, the power monitoring terminal workstation / operator station and the management system are successfully connected. If the connection does not occur automatically, you can click "Manual Connection" on the "Device Management" page of the power monitoring system's management system, select the corresponding finger vein acquisition device number, and complete the connection between the finger vein acquisition device and the power monitoring system workstation / operator station.

[0041] ④ Preset liveness detection parameters: The operation and maintenance administrator operates the management system and, after auditing by the security auditor, preset liveness detection parameters in the security chip of the finger vein acquisition device, including: finger temperature threshold, blood flow pulsation threshold, and continuous frame grayscale fluctuation deviation, which are used for liveness detection in subsequent processes to prevent forgery attacks such as silicone finger molds, 3D printing, infrared photos, and video playback. For example, the finger temperature threshold is preset to 32℃-36℃, which is the normal human finger temperature range; the blood flow pulsation threshold range is preset to 60-100 times / minute, which is the normal human pulse range; and the continuous frame grayscale fluctuation deviation is preset to ≤5%.

[0042] This section completes the deployment of the management system for the power monitoring system, the initialization of the finger vein acquisition equipment, the establishment of a trusted encrypted link, and the initialization of liveness detection parameters, providing a basic operating environment for subsequent registration and authentication processes for maintenance personnel.

[0043] Step S1 includes steps S11-S12.

[0044] Step S1 is the registration process for operations and maintenance personnel.

[0045] Step S11: Enter the basic information of the operation and maintenance personnel's identity information, and use the finger vein acquisition device to collect the finger vein images of the operation and maintenance personnel for liveness detection.

[0046] This step involves entering the identity information of operations and maintenance personnel, as well as the modeling process based on the collected finger vein images of these personnel, corresponding to the user registration of operations and maintenance personnel at the authentication service layer.

[0047] The operation and maintenance administrator of the power monitoring system logs into the management system of the power monitoring system. The management system and the power monitoring system are a unified identity management platform with shared accounts, and are compatible with dual-role administrator access control. The dual-role administrator refers to both the operation and maintenance administrator and the security auditor. The operations and maintenance administrator enters the "User Management" page, clicks "Add User," and utilizes the hierarchical organizational structure of the power grid company, including provincial, regional, county, and substation operations and maintenance teams, to complete the following operations: (1) Basic information entry for maintenance personnel: ① Enter application information: including application name, application ID, and application key, which can be used to interface with core business systems such as power monitoring system control cloud and dispatch control system; ② Enter user information for maintenance personnel: name, department, position, and permission level. For example, it includes two categories: ordinary maintenance personnel and maintenance administrators. It can correspond to roles such as power system dispatcher, maintenance manager, repair personnel, and visitor, and the associated application name. You can choose to set a password for users to log in to the management system. If the user information for this maintenance personnel already exists in the organizational structure, it can be reused directly without re-entering. The management system supports interface integration with the personnel identity management system of the power monitoring system (such as a unified identity authentication platform or human resources management system), automatically synchronizing basic information such as the name, department, and employee number of maintenance personnel to avoid duplicate entry and ensure information consistency. After the entry is completed, a second verification is required by the security auditor in the "user review" stage. The maintenance personnel's account is only activated after the review and verification are passed.

[0048] All entered basic information is encrypted and stored using the national cryptographic SM4 algorithm. The setting of permission levels strictly follows the "principle of least privilege" in the power industry. For example, ordinary maintenance personnel are only assigned the permissions to view equipment status and perform routine operations, while the operation and maintenance manager can obtain the permissions to modify system configuration and handle anomalies. The permission allocation results need to generate audit logs for future reference.

[0049] (2) Finger vein image acquisition and liveness detection: When the administrator clicks "Collect finger vein", the system prompts "Please place your finger on the upper right corner of the keyboard and press the two touch points at the same time"; after the user follows the prompt, the LED light of the collection area of ​​the finger vein acquisition device lights up, and a continuous finger vein image sequence of 0.8 seconds is collected, and liveness detection is performed simultaneously.

[0050] Collect finger vein images of maintenance personnel for liveness detection, including: Collect continuous finger vein image sequences and finger temperature data from maintenance personnel; Blood flow pulsation features are extracted by the grayscale changes of the continuous finger vein image sequence; Dynamic features are identified by the inter-frame micro-motion changes in the continuous finger vein image sequence; When the finger temperature data meets the finger temperature threshold, the blood flow pulsation feature is within the preset blood flow pulsation threshold range, and the dynamic feature meets the preset continuous frame grayscale fluctuation deviation, it is determined that the operation and maintenance personnel liveness detection has passed. Otherwise, the liveness detection of the maintenance personnel will be deemed unsuccessful.

[0051] The finger vein acquisition device uses a dual-positioning contact built-in thermal sensor to collect finger temperature data, extracts blood flow pulsation features through grayscale changes in continuous image sequences, and identifies dynamic features through micro-motion changes in multiple frames of images. Only when all three detections meet the thresholds for blood flow pulsation detection, temperature detection, and dynamic changes in multiple frames of images, is the liveness detection considered successful and the subsequent feature extraction process can proceed. If the liveness detection fails, the acquisition process is terminated directly, and the message "Non-liveness feature, acquisition failed" is displayed.

[0052] Dual positioning contacts, such as Figure 2 The contact points 1 and 2 are shown in the diagram.

[0053] Step S12: Liveness detection passed, generating a baseline template for maintenance personnel.

[0054] A finger vein acquisition device is used to collect finger vein images of maintenance personnel; wherein, the finger vein acquisition device has a built-in security chip; The baseline template for generating operations and maintenance personnel includes: Within the security chip, the finger vein image that has passed the liveness detection is preprocessed to obtain a preprocessed finger vein image; the image preprocessing includes image enhancement, region of interest extraction, vein pattern enhancement, and normalization processing. The preprocessed finger vein image is subjected to feature extraction within the security chip to obtain a preset feature dimension. Finger vein feature vector ; the finger vein feature vector As a benchmark template for operations and maintenance personnel .

[0055] After the liveness detection is passed in step S11, the original finger vein images of the maintenance personnel are acquired using a finger vein acquisition device; the original finger vein images are a sequence of multiple consecutive images. Image preprocessing is performed within the national cryptographic security chip built into the finger vein acquisition device: image enhancement (such as contrast stretching and noise reduction), region of interest extraction (ROI, region of interest, finger placement area), vein pattern enhancement (Gabor filtering, Gaussian filtering), and normalization processing (size and height standardization).

[0056] The raw finger vein image may contain identifiable secret information about the vein patterns. Processing it within the secure chip can prevent the plaintext image from being exposed to the external bus. The secure chip has a built-in image processing acceleration unit that can efficiently complete the preprocessing operations of the finger vein image.

[0057] Based on the preprocessed finger vein image, finger vein feature extraction is performed within the security chip, extracting discriminative and stable feature vectors from the preprocessed image: ① Extract vein structure features using skeleton extraction and topology analysis. Extracted features include bifurcation points, endpoints, intersections, length, and curvature, reflecting the unique vein topology of the maintenance personnel; this yields a vein structure feature vector; for example, the vector is... , dimension ; ② Extract HOG (Histogram of Oriented Gradients) features. The extraction method is histogram of oriented gradients. The extracted content includes the local gradient magnitude and orientation distribution, which is not sensitive to changes in lighting. It describes the edge structure of the fingers collected by maintenance personnel; thus, the HOG feature vector is obtained. For example, the vector is... , dimension ; ③ Extract LBP (Local Binary Pattern) features. The extraction method is local binary pattern, and the extracted content is local texture; thus, an LBP feature vector is obtained. For example, the vector is... , dimension .

[0058] The vein structure feature vector, HOG feature vector, and LBP feature vector are concatenated as follows: Formula (1) in, The concatenated feature vector has a total dimension of . .

[0059] Perform PCA (principal components analysis) dimensionality reduction to reduce the dimensionality to Normalization is performed to map the eigenvalues ​​to [0,1].

[0060] The final dimension is The original finger vein feature vector .

[0061] For example, 256-dimensional or 512-dimensional options are available to ensure that all feature vectors have the same dimensions.

[0062] ①256-dimensional: Suitable for scenarios with limited storage space and high authentication speed requirements. The feature vector is shorter and the matching speed is faster. ②512-dimensional: Suitable for scenarios with high security requirements and a large user base, offering rich feature information and higher recognition accuracy. The appropriate dimension should be selected based on specific needs in practical applications.

[0063] The dimensions must be consistent because the subsequent cosine similarity calculation requires the two vectors to have the same dimension, and the encryption, sharding, and storage processes require a fixed-length data format.

[0064] The security chip will encrypt the original finger vein feature vector. The data is transmitted to the management system via a trusted encrypted link, and the system displays "Data collection successful". The maintenance personnel can then choose to "re-collect" or "confirm and save".

[0065] After confirmation and saving, the management system will collect the original finger vein feature vector. Defined as a baseline template for individual operations and maintenance personnel. It is permanently stored and cannot be tampered with.

[0066] Based on the baseline template of operation and maintenance personnel, the system achieves full lifecycle security protection for the finger vein biometrics of operation and maintenance personnel through the logical process of "SM9 national cryptographic encryption → Shamir (3,3) secret sharing sharding → physical isolation storage of three storage nodes → full process matching within the security chip".

[0067] Using the joint identifier of the maintenance personnel, the baseline template is encrypted to generate characteristic ciphertext, including: Using a key generation center deployed in the offline security zone of the power monitoring system, an SM9 encrypted master public key is generated offline. With the master private key ; Based on the personnel identification of the maintenance personnel and their operation account in the power monitoring system, a joint identifier for the maintenance personnel is generated as the SM9 user identifier; at the same time, the user private key of the maintenance personnel is generated offline and burned into the security chip through offline burning method; Based on the master public key Using the SM9 user identifier and the SM9 identifier cryptographic algorithm, the baseline template is... Offline encryption yields the following ciphertext with the following characteristics: Formula (2) in, This is a ciphertext with distinctive features; SM9 is the user identifier; SM9.Enc() is the SM9 encryption operation.

[0068] KGC generates the master public key for the SM9 encryption system offline. With the master private key Master private key KGC securely stores the encryption in an offline cryptographic machine, ensuring it is never connected to the business network of the power monitoring system or transmitted to any power monitoring terminal workstation or server.

[0069] After the maintenance personnel complete the finger vein feature collection, KGC uses the combined identifier of the power monitoring system maintenance personnel's personnel ID and system account as the SM9 user identifier, and generates the maintenance personnel's SM9 encrypted private key offline. The private key is encrypted by writing the national cryptographic security chip built into the finger vein acquisition device through an offline secure programming method. The entire process is unreadable, unexportable, and uncopyable; it can only be accessed within the chip, ensuring that "the private key never leaves the chip."

[0070] The user private key backup and recovery mechanism uses the master private key to back up and restore the user private keys generated by the operations and maintenance personnel. Encryption is performed to generate a user private key backup ciphertext, which is stored in an offline cryptographic machine. A dual primary key management mechanism is adopted, with the decryption key component held separately by the operations administrator and the security auditor, respectively, to establish a compliant private key recovery process. ① When the original finger vein keyboard device is damaged and the maintenance personnel replace it with a new finger vein keyboard device, the maintenance personnel shall submit a device replacement and private key recovery application. The recovery process can only be started after the maintenance administrator and the security auditor have signed and approved it. Device damage includes, but is not limited to: physical damage to the finger vein keyboard, security chip failure, irreversible damage to the internal data of the security chip, device loss, and other situations that prevent the original device from continuing to perform authentication operations.

[0071] ② The operations and maintenance administrator and the security auditor each enter their respective key components, and together they decrypt the user's private key backup ciphertext in the offline cryptographic machine, and then burn the user's private key offline securely. The private key is written into the security chip of the finger vein acquisition device, and the private key is never transmitted in plaintext and never leaves the security chip of the offline cryptographic machine and the finger vein acquisition device. ③ After the burning process is completed, the encrypted feature fragmentation and permission rules of the operation and maintenance personnel are migrated simultaneously, restoring all authentication functions of the operation and maintenance personnel and resolving the problem of data loss of operation and maintenance personnel caused by hardware failure.

[0072] SM9 offline encryption (Chinese national standard): In the security chip, the user's initial reference template Offline encryption is performed using the SM9 national cryptographic algorithm, and the encryption process is based on the public key published by the Key Generation Center (KGC). A shared identifier with operations and maintenance personnel, and the SM9 master public key. Without requiring user private keys, a baseline template can be obtained from operations and maintenance personnel. .

[0073] The personnel identification of operation and maintenance personnel is the unique identity identifier of the operation and maintenance system in the power monitoring system, and is bound to their real physical identity (or role); For example, the personnel identifier is ZG2023006 (an employee number of a provincial dispatch center); the system account of the operation and maintenance personnel is the operation account of the operation and maintenance personnel in the target power monitoring system. For example, the system account is: sgcc_operator_zhang; Personnel ID = Personnel ID || Separator || System Account Or use hash combination Personnel ID = hash(personnel ID || system account) In this context, || represents string concatenation or data splicing.

[0074] SM9 is an identity-based cryptography (IBC) algorithm, whose core features are: A user's public key is calculated directly from their identity identifier, without the need for binding through a digital certificate; The encrypting party only needs to know the identity identifier and the system's master public key to encrypt.

[0075] Feature Ciphertext It is uniquely bound to a specific operations and maintenance personnel. The characteristic ciphertext of the SM9 encrypted output. It is approximately 400-800 bytes in length.

[0076] The ciphertext with features is split into multiple ciphertext fragments and stored separately, including: In a finite field of 256-bit large prime numbers The above converts the ciphertext into integer elements. Two random coefficients are generated using a national cryptographic true random number generator. and ; based on , and Construct the quadratic polynomial as follows: Formula (3) in, For pre-generated 256-bit safe large prime numbers ; Substitute them separately , , The first ciphertext fragment was obtained. Second encrypted fragment Third encrypted fragment ; Will The encrypted storage area of ​​the security chip in the finger vein acquisition device; The encrypted storage area of ​​the private identity authentication server in the power monitoring system; The encrypted storage area is located in the power monitoring terminal workstation operated by maintenance personnel; The three storage nodes—finger vein acquisition device, private identity authentication server, and power monitoring terminal workstation—are physically isolated.

[0077] Using finite field The Shamir(3,3) secret sharing slice, where all operations are performed in a finite field of 256-bit large prime numbers. Onwards, For a pre-generated 256-bit safe large prime number, satisfying ,and It is a prime number. Include A set of integers, within which all operations are performed.

[0078] To avoid floating-point arithmetic errors and ensure cryptographic security, the specific steps are as follows: Convert the ciphertext into integer elements. ,include: Obtain the ciphertext by feature byte length ; like Not greater than The element length is then determined by obtaining an integer element based on the ciphertext features. ; Otherwise, it will be in accordance with Element length to feature ciphertext Grouping, resulting in Each block The last block is insufficient The element length is then padded; where, for Element length; Based on each block Perform the conversion to obtain the corresponding integer element. .

[0079] ① Encrypt the features to be protected Convert to integer elements ,like Length exceeding The element length is determined using a block encryption method.

[0080] If len(C) ≤ 32 bytes / / If the ciphertext is a feature No more than 32 bytes =int(C) mod p / / Directly convert to an integer else Grouped in 32-byte blocks:

[0081] in, These are the first, second, and nth blocks of the ciphertext C, each consisting of 32-byte blocks; the last block may be less than 32 bytes.

[0082] For each group Execute subsequent processes independently.

[0083] ② and ③ are characteristic ciphertexts When the number of bytes is less than or equal to 32, the process of obtaining the first, second, and third ciphertext fragments is as follows.

[0084] ② Using the national cryptographic true random number generator Two coefficients are randomly generated above. , , , , , Randomly generated each time registration occurs, ensuring that encrypted fragmentation is unpredictable; Construct the quadratic polynomial in formula (3), The variable is a polynomial with values ​​of 1, 2, and 3, used to generate slices.

[0085] ③ Substitute them in separately All of them Non-zero elements on, The above calculation yields three independent ciphertext fragments, as shown below: Formula (4) Formula (5) Formula (6) in, These are the first, second, and third ciphertext fragments, respectively.

[0086] If the ciphertext features For ciphertext fragments larger than 32 bytes, the following process is used to obtain the first, second, and third ciphertext fragments. .

[0087] For example, suppose the feature ciphertext It is 96 bytes long and is processed in groups of 32 bytes each, as shown below: Formula (7) For groups Independent sharding is performed as follows: Group ,structure: Formula (8) Group ,structure: Formula (9) Group ,structure: Formula (10) Finally, the fragments are concatenated to obtain the first, second, and third ciphertext fragments, as follows: Formula (11) Encrypted fragmented directed physical isolation storage: The first, second, and third ciphertexts are fragmented and stored on three physically isolated storage nodes that meet power security partitioning requirements, specifically as follows: ① First ciphertext fragment The data is directly stored in the encrypted storage area inside the national cryptographic security chip built into the finger vein keyboard. It is uniquely bound to the hardware of the finger vein acquisition device and can only be accessed within the security chip; it cannot be read externally. ② Second ciphertext fragmentation The system transmits data via a trusted, encrypted link between the finger vein acquisition device and the power monitoring equipment. The data is stored on a privately deployed identity authentication server within the power monitoring system's Security Zone III. Security Zone III is physically isolated from Security Zones I and II of the power monitoring system. Figure 3 As shown, it conforms to the general principles of power security protection: "security zoning, dedicated network, horizontal isolation, and vertical authentication." ③ Third ciphertext fragmentation : Stored in the local encrypted storage area of ​​the power monitoring terminal workstation or operator station operated by the corresponding user, and uniquely bound to the power monitoring terminal equipment.

[0088] After the first, second, and third encrypted fragment storage is completed, the personnel identification, operation account, and finger vein characteristics of the operation and maintenance personnel are uniquely associated and bound.

[0089] Step S1 is the process of inputting the identity information of operation and maintenance personnel and modeling finger vein features. Through basic information input, liveness detection and feature extraction and generation of benchmark templates, as well as the generation of encrypted features, the encrypted features are physically isolated and stored independently to complete the registration of operation and maintenance personnel in the authentication service layer.

[0090] Step S2, specifically.

[0091] This step corresponds to the authentication and login verification process for maintenance personnel before operating the power control system.

[0092] To address the full-scenario identity verification needs of power monitoring systems, covering the entire process of operating system login, business system login, and two strong verifications for critical operations, a Match-on-Chip security chip on-chip full-process verification architecture is adopted. Decryption, template restoration, and feature comparison are all completed inside the security chip, and the power monitoring terminal workstation / operator station receives the final verification result.

[0093] For regular users, there is no need to log in to the management system. The power monitoring system is set to start automatically upon system power-on, adapting to the 24-hour operation requirements of the power monitoring terminal workstation / operator station. The finger vein acquisition device automatically enters standby mode after power-on. When maintenance personnel perform actions requiring identity verification, such as logging into the power monitoring system, initiating remote control / remote adjustment commands, modifying settings, and executing operation tickets, they place their registered finger on the finger vein acquisition area in the upper right corner of the finger vein acquisition keyboard. After the dual positioning contacts (contact point 1 and contact point 2) sense the finger pressure, the sensor detects and starts finger vein image acquisition, and a voice announcement simultaneously broadcasts "Acquiring, please keep your finger stable." After the finger vein acquisition device acquires the finger vein image sequence, authentication is completed according to the following process: (1) Liveness detection, corresponding to the acquisition layer and the security processing layer.

[0094] The finger vein acquisition device acquires a 0.8-second continuous finger vein image sequence of the maintenance personnel to be certified, and performs liveness detection simultaneously. It determines whether the features are live by detecting finger temperature data, blood flow pulsation features, and multi-frame dynamic features. If the liveness detection fails, the verification light (red) will flash 3 times, and a voice announcement will be made saying "Non-liveness feature, verification failed" and an exception log will be recorded simultaneously. If the liveness detection passes, image preprocessing and feature extraction are performed within the security chip to obtain a real-time feature vector corresponding to that of the maintenance personnel. Dimensions and benchmark templates The dimensions are consistent, all of which are .

[0095] (2) Encryption fragment acquisition and chip ciphertext reassembly, corresponding to the security processing layer and authentication service layer.

[0096] Multiple encrypted fragments corresponding to the operator's personnel identifier and operation account are obtained from multiple storage nodes, reassembled, and decrypted to obtain the corresponding baseline template, including: The second and third encrypted fragments corresponding to the operator's personnel identifier and operation account are obtained from the encrypted storage area of ​​the private identity authentication server and the encrypted storage area of ​​the power monitoring terminal workstation, respectively. and will Transmitted to the secure chip via a trusted encrypted link; Within the security chip, the first encrypted fragment containing the personnel identifier and operation account corresponding to the operator is retrieved. Using finite fields The Shamir secret sharing algorithm uses Lagrange interpolation to... Reconstruction and decryption are performed to obtain the corresponding characteristic ciphertext. ; Based on the corresponding feature ciphertext The system uses the private key of the maintenance personnel within the security chip to perform SM9 decryption operations and obtain the corresponding baseline template. .

[0097] After receiving the authentication verification request, the management system checks whether the number of the currently connected finger vein acquisition device is in the user's bound device list. If the verification is successful, it sends an encrypted fragmentation request to the private identity authentication server in Security Zone III of the power monitoring system. The private identity authentication server then fragments the data via an SM4 trusted encrypted link. Transmitted to the power monitoring terminal workstation; The power monitoring terminal workstation reads the locally encrypted storage fragments. ,Will , Transmitted to the security chip of the finger vein keyboard via a pre-negotiated SM4 trusted encrypted link; the chip has already stored the fragments. Complete the full acquisition of 3 encrypted fragments; Inside the security chip, based on finite field The Shamir secret sharing algorithm on the platform uses Lagrange interpolation to restore the complete ciphertext with features. The Lagrange interpolation formula is: Formula (12) in, Let j be the i-th ciphertext fragment; i is the index of the current ciphertext fragment, which can be 1, 2, or 3; j is the index of other ciphertext fragments, which can be any value among 1, 2, or 3 that is not equal to i; all division operations are... Multiplicative inverse operation on the top, the restored characteristic ciphertext It exists only inside the chip and is not transmitted externally.

[0098] get That is, the integer representation of the ciphertext C.

[0099] Will Convert to a fixed-length byte string, and if there are groups, concatenate all the blocks to obtain the corresponding C.

[0100] Accessing the stored user SM9 private key inside the security chip The encrypted text is decrypted inside the security chip, restoring the fixed-dimensional text. The corresponding benchmark template As shown below: Formula (13) in, The SM9 private key for operations and maintenance personnel is burned offline to the security chip during registration. Decrypted The plaintext exists only in the chip's internal computing area and is completely unreadable and unexportable. (3) Feature comparison within the security chip, Match-on-Chip on-chip matching and authentication, corresponding to the security processing layer.

[0101] Real-time feature vectors within the security chip With standard feature template Perform cosine similarity comparison and calculate the first matching degree. The calculation is as follows: Formula (14) in, The dot product of two N-dimensional eigenvectors. These are the feature vector magnitude and the matching score, respectively. The range of values ​​is .

[0102] It exists only in the internal computing area of ​​the chip, is used for cosine similarity comparison and is immediately cleared afterward, and is not output externally.

[0103] The security chip will be the first match 1. The verification result (pass / fail) is transmitted to the management system via an encrypted link, with no sensitive data output externally.

[0104] Step S2 completes real-time verification of the identity of maintenance personnel through on-chip liveness detection, encrypted fragment acquisition and in-chip reconstructing and decryption, and feature comparison, and outputs the matching score and authentication result, realizing the security authentication of sensitive data without leaving the chip throughout the process.

[0105] Step S3, specifically.

[0106] In response to the first matching degree between the real-time feature vector and the corresponding benchmark template satisfying a preset condition, a fused feature vector is calculated based on the benchmark template and the real-time feature vector, including: The real-time feature vector is compared with the corresponding benchmark template using cosine similarity to obtain the first matching degree. ; If the first matching degree If the real-time feature vector is not less than a preset condition, then the real-time feature vector is a valid real-time feature vector. A fused feature vector is calculated based on the benchmark template and the valid real-time feature vector, as follows: Formula (15) in, To fuse feature vectors, This is the base template obtained from the SM9 decryption operation. To integrate weights, This is an effective real-time feature vector.

[0107] If the first matching degree is greater than or equal to the preset condition, no fused feature vector will be generated.

[0108] For example, the preset condition is set to 0.8, when At 0.8, the fused feature vector is calculated based on the benchmark template and the effective real-time feature vector.

[0109] For real-time feature vectors The validity check is performed, and the selection rule is: the security chip returns the highest matching degree. Confirm if the value is greater than or equal to the preset threshold. For effective real-time feature vectors.

[0110] Meanwhile, the management system uses preset update weights to update the standard feature templates. Perform incremental updates to obtain the fused feature vector. For example, fusion weights The default value is 15%, and administrators can adjust it within the range of 0-30%.

[0111] For the preset conditions of the first matching degree, an adaptive threshold is used for adaptive updating.

[0112] If the first matching degree does not meet the corresponding preset condition. The time frame is within the specified range, and the operator has no history of violations, the user has bound a device to the user, the threshold adjustment has not been triggered within the configured valid time range and the single user login process; First matching degree The corresponding preset adaptive thresholds are shown below: Formula (16) in, First matching degree The corresponding preset threshold is 0.8 by default, and adaptive threshold adjustment is performed. The adjustment factor is fixed at 0.5 and cannot be modified.

[0113] First matching degree The corresponding preset threshold constraint is: the adjusted first matching degree. Corresponding preset condition threshold The minimum value should not be lower than 0.75, and the safety threshold must not be exceeded.

[0114] Only for the first matching degree Verification failed, and In such scenarios, an adaptive threshold control algorithm is adopted to adjust the preset condition threshold only within the preset rules, thereby avoiding the compliance risks of automatically lowering the security threshold.

[0115] If the first matching degree is If the operator still fails to verify after adjusting the corresponding preset threshold, the user account will be locked for 10 minutes immediately, and an unalterable abnormal audit log will be recorded simultaneously, including information such as the threshold before and after the adjustment, the triggering reason, and the operation time. Preferably, in actual deployment, the first matching degree can be targeted. The corresponding preset threshold adjustment function is set up with a dual-approval mechanism. The threshold adjustment function can only be enabled within a specified time window after approval by both the operations and maintenance administrator and the security auditor.

[0116] The determination of whether the operator is permitted to operate the power monitoring system based on the second matching degree of the fused feature vector and the benchmark template includes: Calculate the second matching degree between the fused feature vector and the baseline template; If the second matching degree is not less than the corresponding preset condition and the multi-dimensional permission verification is passed, then the operator is allowed to operate the power monitoring system, and it is determined whether to dynamically update the encrypted fragment of the maintenance personnel corresponding to the operator. Otherwise, refuse the operator's request to operate the power monitoring system.

[0117] Second matching degree ,for With reference template The cosine similarity is calculated as follows: Formula (17) For example, the preset threshold for the second matching degree is 0.9; ; When the second matching degree meets the corresponding preset conditions, and the weights are merged... When the percentage is less than 30%, update the encrypted fragments of the corresponding operations and maintenance personnel to prevent the risk of gradual template drift and infection.

[0118] Perform multi-dimensional permission verification, including: When maintenance personnel register for the power monitoring system, the system pre-configures their operation time range permissions, binds their finger vein acquisition device permissions, and allows them to operate functions, thus constructing a permission map of the maintenance personnel's operation time range, finger vein acquisition device, and the power monitoring system's operable functions. Determine whether the operator's current operation time is within the pre-configured operation time range of maintenance personnel, whether the current finger vein acquisition device is in the list of bound finger vein acquisition devices, and whether the current operation request is within the functional permission map of the operable power monitoring system.

[0119] Multidimensional permission verification based on biometric authentication corresponds to the authentication service layer and the business control layer.

[0120] Based on the zero-trust concept and the principle of least privilege, a multi-dimensional permission binding control mechanism is constructed, which includes "biometric features - operation time - finger vein acquisition device - power monitoring system operation".

[0121] Pre-configuration of multi-dimensional permission rules: During the initialization phase before step S1, the administrator constructs a full-dimensional permission map for each operations and maintenance personnel's system account on the user management page of the management system, covering "Operations and Maintenance Personnel - Power Monitoring System Operation Business - Finger Vein Acquisition Device," and configures the following refined rules for multi-dimensional permissions, including: (1) Time range permissions: Configure the valid time range during which users are allowed to perform operations, such as 9:00-18:00 on weekdays, monthly maintenance window, and valid operation period for operation ticket approval, etc.; (2) Bind device permissions: Configure the finger vein collection device number that the user can only use, that is, only 1-3 finger vein keyboards can complete the user's identity verification and permission authorization; (3) Operable function permissions: Based on the business scenarios of the power monitoring system, the operation permissions are accurately granted and granted. Specifically, the permissions of operable host equipment and remote control / remote adjustment instruction set, accessible business system modules, operable database tables and corresponding CRUD operations, and DDL operation permissions are implemented. It can be linked with the operation ticket and work ticket system of the power monitoring system.

[0122] Multi-dimensional permission verification: After receiving the verification result from the security chip indicating that the second matching degree is not less than the corresponding preset condition, the management system simultaneously completes three verifications: (1) Verify whether the current system time operated by the operator is within the configured valid time range; (2) Verify whether the finger vein keyboard device number currently accessed is in the user's bound device list; (3) Verify whether the login / operation request initiated by the operator is within the scope of the configured operable function permissions.

[0123] Only when all three of the above checks pass, and the security chip returns a finger vein feature matching score... The entire verification process can only be considered successful when the threshold value is greater than or equal to the preset threshold. If any verification fails, the verification will be deemed a failure, and the operation request will be rejected.

[0124] For example, the first matching degree preset matching degree threshold is 0.8.

[0125] If a user's operation request exceeds the scope of the multi-dimensional permission binding, the system will automatically block the operation execution, synchronously record an unalterable violation log, including the time, device number, username, violation content, and triggered permission rule, and send a warning message to the security administrator and the corresponding department head in real time through the internal alarm channel of the power monitoring system.

[0126] When the operator is allowed to operate the power monitoring system, it is determined whether to dynamically update the encrypted fragments of the corresponding maintenance personnel, including: If the fusion weight does not exceed the weight threshold, and the maintenance personnel corresponding to the operator update the baseline template no more than once per day. Next, based on the aforementioned master public key The joint identifier of the maintenance personnel corresponding to the operator and the operation account of the maintenance personnel in the power monitoring system is used to fuse the feature vector. Perform offline encryption to obtain the corresponding characteristic ciphertext; The corresponding ciphertext with the characteristic is split into the corresponding first, second, and third ciphertext fragments; The first, second, and third ciphertext fragments are synchronously and dynamically updated to multiple physically isolated storage nodes via a trusted encrypted link.

[0127] For example, The value is 2, meaning that each operator can update the template no more than twice per day per user.

[0128] Based on fusion template The SM9 encryption and Shamir fragment storage process on GF(p) in step S1 is re-executed to generate new ciphertext fragments. These fragments are then synchronously updated to the three storage nodes: the security chip in the finger vein acquisition device, the private identity authentication private server, and the power monitoring terminal workstation, completing the full-node synchronous update of the ciphertext fragments.

[0129] Step S3 generates a new template by weighted fusion of the authenticated real-time features and the baseline template, and simultaneously updates the encrypted fragments of the three nodes, thereby achieving dynamic optimization of the biometric template and secure synchronization of all nodes.

[0130] In this method, for high-risk operation scenarios such as remote control, setting modification, and switching operations in power monitoring systems, the "dual-person dual-monitoring" requirement can also be adopted. This method sets up a dual-person finger vein collaborative authentication mechanism, as follows: (1) High-risk operation pre-configuration: On the permission configuration page, the operation and maintenance administrator configures the dual-person collaborative authentication rules for key operations such as remote control command issuance, setting value modification, and circuit breaker opening and closing, specifying the binding relationship between the operator and the monitor. Only when both have completed identity verification can the operation of the power monitoring system be executed; the registration of the operator and the monitor is as follows: step S2; (2) Collaborative certification process for operators and supervisors: ① After the operator completes the verification in step S3, the system generates a unique authentication token A for the operator. Token A is bound to the operator's identity, operation content, and timestamp, and the monitoring personnel are prompted to verify the identity. ② After the guardian completes the verification in step S2 on the same finger vein collection device or the designated bound finger vein collection device, the system generates a unique authentication token B for the guardian. The token B is bound to the guardian's identity, operation content, and timestamp. ③ The management system performs hash combination verification on tokenA and tokenB. After confirming that the identities of the two people are consistent with the pre-configured operator-guardian binding relationship and that the operation content matches the timestamp, a dual-signature authorization certificate is generated, and the corresponding high-risk operation permissions are granted. If the combination verification fails, the operation request is directly rejected, and a high-level security alarm is triggered simultaneously.

[0131] (3) Audit traceability: The entire process of dual-person collaborative authentication, including the identity information of the operator and the supervisor, the verification time, the operation content, and the authorization result, is recorded in an unalterable audit log, which complies with the "two tickets and three systems" management requirements of the power industry.

[0132] (4) Verification result feedback and implementation If both individual and collaborative verification by the operator pass, the operator is permitted to operate the power monitoring system.

[0133] Otherwise, if the verification fails three times in a row, the finger vein collection device will pause collection for one minute, and the management system will record the abnormal event log. The administrator can view the cause of the abnormality and the entire process record.

[0134] The auditing function of this invention complies with the security protection of power monitoring systems, and realizes the manageable, controllable, and traceable process of identity authentication of the operation personnel corresponding to the maintenance personnel. The specific operation is as follows: Administrators can access the "Verification Settings" page of the management system and drag the slider to adjust the preset threshold for the first matching degree. The selectable range is 0.75-0.9. A higher threshold provides higher security but may increase the false rejection rate. Dynamic template updates and fusion weights can also be configured. The selectable range is 0-30%; dual-person collaborative authentication rules for high-risk operations can be configured.

[0135] Administrators can access the "Device Monitoring" page of the management system to view the connection status, security chip status, firmware version, and encrypted link status of all connected finger vein acquisition devices in real time. It supports remote device disabling, firmware security upgrades, and unbinding of binding relationships, and can adapt to the large-scale equipment operation and maintenance management needs of power systems.

[0136] Administrators can access the "Log Management" page of the management system to view the entire process of unalterable audit logs, including user registration, feature collection and template updates, verification records, threshold adjustment operations, two-person collaborative authentication records, permission changes, equipment status changes, and violation operation events. The logs contain full-dimensional information such as time, equipment number, username, operation type, operation content, result, trigger rules, and approver. They support filtering by time range, username, operation type, and equipment number, and support encrypted and fixed storage. They also support synchronization to structured databases such as DM and Kingbase, and can be connected to the power industry safety audit platform and regulatory system.

[0137] Administrators can access the "Permission Settings" page of the management system to configure granular permission rules for each user account based on a multi-dimensional permission binding mechanism, and batch import / export permission configuration tables. They can assign tiered management permissions to ordinary users, such as "Allow verification only," "Allow viewing personal logs," and "Prohibit modification of personal information," strictly separating the dual permissions of operations administrators and security auditors to prevent unauthorized operations. Simultaneously, they can configure permission violation warning rules and recipients to achieve real-time alerts for violations.

[0138] The method in this invention is designed for the identity authentication scenario of power monitoring system operation and maintenance personnel. It follows the security protection policy of "security zoning, dedicated network, horizontal isolation, and vertical authentication" of power monitoring system and can be adapted and integrated with core business systems in the power monitoring field.

[0139] (1) Adaptation of all business systems like Figure 3 As shown, this invention can be adapted to the core business systems of various security zones in a power monitoring system, covering: ① Security Zone I (Real-time Control Zone): The new generation power grid dispatch control system D6.0, substation monitoring system SCADA, distribution automation master station system, unit monitoring system and other real-time control systems adopt a Match-on-Chip on-chip verification architecture for key operations such as remote control, remote adjustment, circuit breaker opening and closing, and setting modification. This enables strong identity verification before operation and ensures that no sensitive data leaves the security chip throughout the process, which meets the hardware security control requirements of Security Zone I. ②Safety Zone II (Non-Controlled Production Zone): Dispatch planning management system, power metering system, relay protection and fault information management system, operation and maintenance management system, etc., to realize full-process identity authentication for system login and business operation; ③ Security Zone III (Production Management Zone): Control cloud platform, production management system (PMS), power marketing management system, collaborative office system, etc., to achieve strong identity authentication and access control for personnel accessing across regions.

[0140] (2) Integration of Binding Identity Verification It can connect to the core business system of the power monitoring system to build a unique and strongly bound verification mechanism that integrates personnel identity, system account, and finger vein biometrics.

[0141] ① Pre-binding of personnel identity and system account: The user management system of this invention is connected with the unified identity management platform of the power monitoring system to achieve two-way synchronization of personnel organizational structure and account information, and ensure the unique binding of personnel identity with internal accounts of the power system; ② Login verification process linkage: When personnel log in to the target power monitoring system, the system first completes the matching of basic account information, and synchronously calls the standardized interface of the finger vein management system of this invention to trigger the finger vein feature verification process uniquely bound to the account; ③ Closed-loop feedback of verification results: Only when the finger vein feature image is matched and all multi-dimensional permission verifications are passed, the verification result is encrypted and fed back to the business system in real time, and the system login or operation authorization can be completed; if the verification fails, access is directly denied. There is no plaintext feature transmission throughout the process, which meets the security protection requirements of the power system.

[0142] (3) Standardized interface adaptation It provides standard SDK / API interfaces, is compatible with the remote communication interface specifications of power monitoring systems and the data transmission protocol of the power industry, supports encrypted transmission using national cryptographic algorithms, and can quickly complete the integration of core systems such as the control cloud platform, D6.0 dispatch control system, and PMS production management system with this solution. It enables batch binding of user accounts and finger vein features, and real-time encrypted interaction of verification results without the need for large-scale modification of the target system, reducing integration and deployment costs. It can adapt to the large-scale deployment needs of power grid enterprises at the provincial, prefecture, and county levels.

[0143] (4) Interlocking and controlling the permission system The identity verification results and multi-dimensional permission binding rules of this invention can be synchronized to the power monitoring system in real time, and deeply linked with the system's built-in RBAC (Role-Based Access Control) permission system to achieve fine-grained and dynamic management of permissions. The system only grants operation permissions to the corresponding roles to legitimate individuals who have completed the "account-finger vein" strong binding verification and passed the multi-dimensional permission verification. Following the principle of least privilege, critical operations such as issuing scheduling instructions and adjusting equipment parameters can only be performed when the personnel's identity completely matches the bound system account and finger vein characteristics, and within the specified time, specified device, and specified operation range. For high-risk operations in the power system, it supports dual-person finger vein collaborative authentication, which is linked with the operation ticket and work ticket system to achieve precise control and security reinforcement of the operation permissions of the power monitoring system from the source of identity, and can prevent the power grid operation safety risks caused by unauthorized operations.

[0144] In summary, the power monitoring system maintenance personnel authentication method based on finger vein recognition according to the embodiments of the present invention has the following beneficial effects: 1. This invention uses the SM9 identifier encryption algorithm to encrypt the finger vein feature baseline template with a joint identifier of "personnel ID + system account," achieving a strong binding between personnel identity and system account at the cryptographic level. Combined with Shamir secret sharing sharding and three-node physical isolation storage, it ensures that the baseline template of the biometric features of maintenance personnel cannot be tampered with or stolen during storage and transmission. During login authentication, finger vein liveness matching, system account association verification, and multi-dimensional permission verification must be simultaneously satisfied, preventing system account impersonation, permission abuse, and difficulties in operation traceability, thus meeting the requirements of "high security, strong control, and full-link auditability" for power monitoring systems. It solves the technical defects of existing methods that only support traditional account password login or single biometric feature to replace password, failing to establish a unique strong binding authentication mechanism between personnel physical identity, system operation account, and finger vein biometric features, resulting in loose permission control and difficulty in accurately tracing operational behavior. It achieves a strong binding of "maintenance personnel user identifier ID - system account - biometric feature," filling the security gap between identity authentication and permission control. 2. This invention achieves full-stack domestic compatibility from the underlying hardware to the application system: The finger vein acquisition device has a built-in national cryptographic level 2 security chip, supporting national cryptographic algorithms such as SM2 / SM3 / SM4 / SM9; the driver is deeply adapted to the domestic operating system kernel, automatically recognizing it without additional driver installation; the management system of the power monitoring system can seamlessly connect to the core business platforms of the power monitoring system's control cloud and dispatch control system. This invention solves the technical defects of existing finger vein acquisition devices that only support application-layer drivers and have not been optimized for domestic CPUs and operating systems, resulting in unstable operation and poor compatibility in domestic environments. Deep domestic adaptation achieves full-stack compatibility from the underlying hardware to the application system; it is compatible with domestic databases (such as DM Database and Kingbase Database) and domestic operating systems (such as Kylin V10, UnionTech UOSV20, and NingSi 6.0.80); 3. This invention integrates a finger vein acquisition module into a finger vein keyboard. Utilizing the keyboard's own weight and anti-slip base, along with dual-positioning contact points, it physically guides the finger to press correctly, fundamentally solving the problems of device slippage, image blurring, and poor stability during acquisition, thus improving recognition success rate and user comfort. Simultaneously, it pioneers a three-dimensional liveness detection mechanism: detecting finger temperature through built-in thermal sensors on the dual-positioning contact points, extracting blood flow pulsation features through continuous image grayscale changes, and identifying dynamic features through micro-motion changes in multi-frame images. This three-dimensional logical fusion effectively prevents various forgery attacks such as silicone finger molds, 3D printing, photos, video playback, and non-living fingers, significantly improving acquisition success rate and recognition security. It addresses the technical shortcomings of existing finger vein acquisition devices, which are mostly small, independent peripherals with light weight, making them prone to slippage and image blurring when pressed by the user; and the difficulty of single-dimensional liveness detection in preventing forgery attacks such as silicone finger molds, photos, and video playback. The innovative hardware structure and liveness detection mechanism solve the problems of acquisition displacement and forgery attacks.

[0145] Those skilled in the art will understand that all or part of the processes of the methods described in the above embodiments can be implemented by a computer program instructing related hardware, and the program can be stored in a computer-readable storage medium. The computer-readable storage medium may be a disk, optical disk, read-only memory, or random access memory, etc.

[0146] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for authenticating maintenance personnel in a power monitoring system based on finger vein recognition, characterized in that, include: Collect finger vein images of maintenance personnel for liveness detection. If the liveness detection is successful, a baseline template for the maintenance personnel is generated. A finger vein acquisition device is used to collect finger vein images of maintenance personnel; wherein, the finger vein acquisition device has a built-in security chip; The baseline template for generating operations and maintenance personnel includes: Within the security chip, the finger vein image that has passed the liveness detection is preprocessed to obtain a preprocessed finger vein image; the image preprocessing includes image enhancement, region of interest extraction, vein pattern enhancement, and normalization processing; The preprocessed finger vein image is subjected to feature extraction within the security chip to obtain a preset feature dimension. Finger vein feature vector ; the finger vein feature vector As a benchmark template for operations and maintenance personnel ; Using the joint identifier of the maintenance personnel, the baseline template is encrypted to generate feature ciphertext, which is then split into multiple ciphertext fragments and stored separately. Using the joint identifier of the maintenance personnel, the baseline template is encrypted to generate characteristic ciphertext, including: Using a key generation center deployed in the offline security zone of the power monitoring system, an SM9 encrypted master public key is generated offline. With the master private key ; Based on the personnel identification of the maintenance personnel and their operation account in the power monitoring system, a joint identifier for the maintenance personnel is generated as the SM9 user identifier; at the same time, the user private key of the maintenance personnel is generated offline and burned into the security chip through offline burning method; Based on the master public key Using the SM9 user identifier and the SM9 identifier cryptographic algorithm, the baseline template is... Offline encryption yields the following ciphertext with the following characteristics: in, This is a ciphertext with distinctive features; SM9 user identifier; SM9.Enc() is the SM9 encryption operation; In response to the operator's authentication request for the power monitoring system, the finger vein image of the operator is collected in real time for liveness detection; if the liveness detection is successful, a real-time feature vector is extracted based on the finger vein image; multiple encrypted fragments corresponding to the operator's personnel identifier and operation account are obtained from multiple storage nodes, and then reassembled and decrypted to obtain the corresponding baseline template. In response to the first matching degree between the real-time feature vector and the corresponding reference template satisfying a preset condition, a fused feature vector is calculated based on the reference template and the real-time feature vector; based on the second matching degree between the fused feature vector and the reference template, it is determined whether the operator is allowed to operate the power monitoring system.

2. The method for authenticating maintenance personnel of a power monitoring system based on finger vein recognition according to claim 1, characterized in that, Collect finger vein images of maintenance personnel for liveness detection, including: Collect continuous finger vein image sequences and finger temperature data from maintenance personnel; Blood flow pulsation features are extracted by the grayscale changes of the continuous finger vein image sequence; Dynamic features are identified by the inter-frame micro-motion changes in the continuous finger vein image sequence; When the finger temperature data meets the preset finger temperature threshold, the blood flow pulsation feature is within the preset blood flow pulsation threshold range, and the dynamic feature meets the preset continuous frame grayscale fluctuation deviation, it is determined that the operation and maintenance personnel liveness detection has passed. Otherwise, the liveness detection of the maintenance personnel will be deemed unsuccessful.

3. The method for authenticating maintenance personnel of a power monitoring system based on finger vein recognition according to claim 1, characterized in that, The ciphertext with features is split into multiple ciphertext fragments and stored separately, including: In a finite field of 256-bit large prime numbers The above converts the ciphertext into integer elements. Two random coefficients are generated using a national cryptographic true random number generator. and ; based on , and Construct the quadratic polynomial as follows: in, For pre-generated 256-bit safe large prime numbers ; Substitute them separately , , The first ciphertext fragment was obtained. Second encrypted fragment Third encrypted fragment ; Will The encrypted storage area of ​​the security chip in the finger vein acquisition device; The encrypted storage area of ​​the private identity authentication server in the power monitoring system; The encrypted storage area is located in the power monitoring terminal workstation operated by maintenance personnel; The three storage nodes—finger vein acquisition device, private identity authentication server, and power monitoring terminal workstation—are physically isolated.

4. The method for authenticating maintenance personnel of a power monitoring system based on finger vein recognition according to claim 3, characterized in that, Multiple encrypted fragments corresponding to the operator's personnel identifier and operation account are obtained from multiple storage nodes, reassembled, and decrypted to obtain the corresponding baseline template, including: The second and third ciphertext fragments corresponding to the operator's personnel identifier and operation account are obtained from the encrypted storage area of ​​the private identity authentication server and the encrypted storage area of ​​the power monitoring terminal workstation, respectively. and will Transmitted to the secure chip via a trusted encrypted link; Within the security chip, the first encrypted fragment containing the personnel identifier and operation account corresponding to the operator is retrieved. Using finite fields The Shamir secret sharing algorithm uses Lagrange interpolation to... Reconstruction and decryption are performed to obtain the corresponding characteristic ciphertext. ; Based on the corresponding feature ciphertext The system uses the private key of the maintenance personnel within the security chip to perform SM9 decryption operations and obtain the corresponding baseline template. .

5. The method for authenticating maintenance personnel of a power monitoring system based on finger vein recognition according to claim 4, characterized in that, In response to the first matching degree between the real-time feature vector and the corresponding benchmark template satisfying a preset condition, a fused feature vector is calculated based on the benchmark template and the real-time feature vector, including: The real-time feature vector is compared with the corresponding benchmark template using cosine similarity to obtain the first matching degree. ; If the first matching degree If the real-time feature vector is not less than a preset condition, then the real-time feature vector is a valid real-time feature vector. A fused feature vector is calculated based on the benchmark template and the valid real-time feature vector, as follows: in, To fuse feature vectors, This is the base template obtained from the SM9 decryption operation. To integrate weights, This is an effective real-time feature vector.

6. The method for authenticating maintenance personnel of a power monitoring system based on finger vein recognition according to claim 4, characterized in that, The determination of whether the operator is permitted to operate the power monitoring system based on the second matching degree of the fused feature vector and the benchmark template includes: Calculate the second matching degree between the fused feature vector and the baseline template; If the second matching degree is not less than the corresponding preset condition and the multi-dimensional permission verification passes, then the operator is allowed to operate the power monitoring system, and it is determined whether to dynamically update the encrypted fragment of the maintenance personnel corresponding to the operator. Otherwise, refuse the operator's request to operate the power monitoring system.

7. The method for authenticating maintenance personnel of a power monitoring system based on finger vein recognition according to claim 4, characterized in that, Perform multi-dimensional permission verification, including: When maintenance personnel register for the power monitoring system, the system pre-configures their operation time range permissions, binds their finger vein acquisition device permissions, and allows them to operate functions, thus constructing a permission map of the maintenance personnel's operation time range, finger vein acquisition device, and the power monitoring system's operable functions. Determine whether the operator's current operation time is within the pre-configured operation time range of maintenance personnel, whether the current finger vein acquisition device is in the list of bound finger vein acquisition devices, and whether the current operation request is within the functional permission map of the operable power monitoring system.

8. The method for authenticating maintenance personnel of a power monitoring system based on finger vein recognition according to claim 6, characterized in that, Allowing the operator to operate the power monitoring system and determining whether to dynamically update the encrypted fragments of the maintenance personnel corresponding to the operator, including: If the fusion weight does not exceed the weight threshold, and the maintenance personnel corresponding to the operator update the baseline template no more than once per day. Next, based on the aforementioned master public key The joint identifier of the maintenance personnel corresponding to the operator and the operation account of the maintenance personnel in the power monitoring system is used to fuse the feature vector. Perform offline encryption to obtain the corresponding ciphertext with distinctive features; The corresponding ciphertext with the characteristic is split into the corresponding first, second, and third ciphertext fragments; The first, second, and third ciphertext fragments are synchronously and dynamically updated to multiple physically isolated storage nodes via a trusted encrypted link.

Citation Information

Patent Citations

  • Mobile SSD based on fingerprint and finger vein recognition

    CN115017488A

  • MES system login authentication method based on face recognition technology

    CN121239479A