Mine data security sharing and dynamic authorization access method based on industrial internet
Patent Information
- Application Number
- CN202611041303.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-14
- Publication Date
- 2026-09-29
AI Technical Summary
[0003]为了弥补以上不足,本发明提供了基于工业互联网的矿山数据安全共享与动态授权访问方法,旨在改善现有技术中矿山多源异构数据跨系统共享困难与安全管控能力不足的问题
1.本发明中,通过办公网络与数据网络的物理隔离部署,在物理层级阻断非授权访问,同时通过安全受控的数据交换通道实现跨网数据按需流通,兼顾了安全管控与业务协同,还通过多制式无线与有线融合组网实现矿山全区域通信覆盖,使生产装备、传感装置及管理终端能够以泛在接入方式完成多源异构数据的实时采集与汇聚,为数据安全共享提供了完整的物理底座与感知基础,使系统安全性与数据采集能力得以同步提升。
Smart Images

Figure CN122845233A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of mining data security technology, and in particular to a method for secure sharing and dynamic authorized access to mining data based on the Industrial Internet. Background Technology
[0002] Against the backdrop of the rapid advancement of intelligent mining construction, mining enterprises generally face technical challenges in sharing and securely managing multi-source, heterogeneous data across systems. Currently, mining enterprises have successively deployed multiple business subsystems, such as production management systems, safety monitoring systems, equipment management systems, and operation management systems. However, the lack of unified data standards and interface specifications among these systems hinders effective data sharing, resulting in prominent information silos. Furthermore, different business systems use multiple account systems for login, leading to duplicate data uploads and increasing the cumbersomeness and complexity of business processes. In terms of security management, traditional access control mechanisms often employ static role-based authorization, making it difficult to adjust access permissions in real time based on dynamic factors such as personnel changes and business scenario shifts. In addition, mining data involves a large amount of sensitive information, including geological reserves, blasting parameters, personnel location, and slope monitoring, lacking fine-grained security control and audit traceability mechanisms during cross-system calls and sharing. Existing research indicates that industrial internet platforms in mining applications suffer from problems such as failing to fully realize data value, restricted data flow between different systems, and a lack of unified access control mechanisms for cross-system data interaction, increasing the risk of data tampering and unauthorized access. Summary of the Invention
[0003] To address the above shortcomings, this invention provides a method for secure sharing and dynamic authorized access to mine data based on the Industrial Internet, aiming to improve the problems of difficulty in sharing multi-source heterogeneous data across systems and insufficient security control capabilities in existing technologies.
[0004] To achieve the above objectives, the present invention provides the following technical solution: Methods for secure sharing and dynamic authorized access to mine data based on the Industrial Internet include: Construct a dual-network architecture with physical isolation between the office network and the data network, and achieve ubiquitous access to all elements of the mine through industrial wireless and wired access methods to support the collection and transmission of multi-source heterogeneous data; Based on the mining information standard, the multi-source heterogeneous data is cleaned and fused, and classified according to its sensitivity and importance to construct a standardized data resource library; A unified identity authentication system based on a technology middle platform is enabled. Access permissions to target resources are dynamically allocated according to the access subject's attribute information and business operation status. Based on the hierarchical classification results, corresponding security control policies are matched for data of different levels, and authorization authentication results are generated. By adopting a unified API interface specification and service bus technology, and based on the authorization and authentication results, cross-platform on-demand data access and business collaboration are realized in a service-oriented manner, generating data access results; Based on the data retrieval results, to-do tasks, monitoring and early warning, and production data are presented to different users in a personalized manner through a unified portal and visual management platform, and access behavior records are generated during the secure access process of multiple terminals. Based on the access behavior records, the system operation log and event recording mechanism are used as tracking methods to audit the data access and sharing process, thereby achieving security traceability.
[0005] Furthermore, the construction of a dual-network architecture with physical isolation between the office network and the data network specifically includes: The office network is used to support external network access, internet services, and office operations. The data network is used to support cloud platform operation and maintenance, database services, and big data business. The two networks operate independently through physical isolation, and secure and controlled data exchange channels are set up between different network areas according to the business flow.
[0006] Furthermore, the steps for achieving ubiquitous access to all elements of the mine include: The ubiquitous access uses industrial wireless base stations and wired sensing terminals deployed in mining areas, processing areas, and office areas to collect in real time the operating parameters of production equipment, environmental monitoring data from sensing devices, and location information from management terminals based on a unified communication protocol, and then connects to the industrial internet communication network.
[0007] Furthermore, the cleaning and fusion specifically includes: The three-dimensional laser scanning data of the goaf, the energy consumption monitoring data of production equipment, and the operating condition data of transport vehicles are deredundant, corrected, and converted in format. Based on the mining business logic, a correlation mapping is established between spatial data, real-time sensing data, and relational data to achieve standardized expression of heterogeneous data.
[0008] Furthermore, the step of constructing the standardized data resource repository includes: The basic library, thematic library, and model library are built according to unified standards and specifications, as well as the knowledge center generated by mining and deep processing of historical data; The knowledge center is used to support mining management, decision support, and scientific research.
[0009] Furthermore, the step of dynamically allocating access permissions to target resources based on the access subject's attribute information and business operation status includes: The system obtains the job functions and security level attributes of the accessing entities, and monitors the current business scenarios of the mine, including normal production scenarios, equipment maintenance scenarios, or emergency rescue scenarios. Based on the matching results between the job functions and security level attributes and the business scenario, the access weight and operation scope of the subject to the target resource are calculated and adjusted in real time.
[0010] Furthermore, when the attribute information of the access subject changes or the business operation status changes, the dynamic allocation step is re-executed to update the authorization and authentication result.
[0011] Furthermore, the security control strategy specifically includes: Based on the data classification results, differentiated security measures are matched. These security measures include encrypted storage strategies for highly sensitive data in the storage state, link encryption strategies for cross-network transmission, and access control strategies or dynamic desensitization strategies applied to the access process based on data classification.
[0012] Furthermore, the visual management and control platform specifically includes: Integrating 3D oblique photography, building information modeling, and geographic information system services to construct digital twin scenarios for mines; The real-time collected production, safety, and environmental monitoring data are overlaid and displayed in the virtual mine model to achieve transparent control and decision support for the production process.
[0013] Furthermore, the steps for auditing the data access and sharing process include: The security linkage mechanism is triggered based on the audit results. The security linkage mechanism includes at least one of the following: automatically revoking the current authorization token, restricting the access bandwidth of unauthorized access sources, and pushing security alarm notifications to the unified portal in real time.
[0014] The present invention has the following beneficial effects: 1. In this invention, by physically isolating the office network and the data network, unauthorized access is blocked at the physical level. At the same time, cross-network data can be flowed on demand through a secure and controlled data exchange channel, taking into account both security control and business collaboration. Furthermore, by integrating multi-standard wireless and wired networks, communication coverage is achieved throughout the mine area. This enables production equipment, sensing devices, and management terminals to complete the real-time collection and aggregation of multi-source heterogeneous data through ubiquitous access, providing a complete physical foundation and sensing basis for secure data sharing, and simultaneously improving system security and data acquisition capabilities.
[0015] 2. In this invention, by establishing a multi-dimensional correlation mapping between spatial data, real-time sensing data, and relational data, logical conflicts in the format and semantics of multi-source heterogeneous data are eliminated, enabling the data to possess consistency and identifiability. Combined with hierarchical classification processing based on sensitivity and importance, and the construction of a standardized data resource repository and knowledge center, raw data is transformed into knowledge assets with decision support capabilities. This provides precise hierarchical criteria for differentiated security control strategies, elevating data governance from extensive management to refined hierarchical control.
[0016] 3. In this invention, a unified identity authentication system dynamically allocates access permissions based on the access subject's attribute information and business operation status, elevating access control from static configuration to a dynamic mechanism that responds in real time to changes in job functions and production scenarios. Differentiated security strategies, such as encrypted storage, encrypted transmission, access control, or dynamic data masking, are matched according to the hierarchical classification results. Combined with the service bus's authorization verification for each call and auditing of all access behavior records, a closed-loop security management system covering the entire data lifecycle is constructed. Furthermore, a security linkage mechanism elevates security protection from passive post-event tracing to real-time blocking during events, effectively ensuring the security and compliance of mine data during cross-system sharing. Attached Figure Description
[0017] Figure 1 This is a flowchart of the mine data security sharing and dynamic authorized access method based on the Industrial Internet proposed in this invention; Figure 2 This is a schematic diagram of the mine wireless network topology proposed in this invention; Figure 3 This is a schematic diagram of the construction of a 4G network base station in a mine, as proposed in this invention. Figure 4 This is a schematic diagram of the overall architecture of the mining industrial internet proposed in this invention; Figure 5 This is a flowchart of the dynamic licensing process proposed in this invention; Figure 6 This is the audit and linkage flowchart proposed in this invention. Detailed Implementation
[0018] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] This invention provides a method for secure sharing and dynamic authorized access to mine data based on the Industrial Internet, such as... Figure 1 As shown, it includes the following steps: S100: Constructs a dual-network architecture with physical isolation between office network and data network, and realizes ubiquitous access to all elements of the mine through industrial wireless and wired access methods, supporting the collection and transmission of multi-source heterogeneous data; Furthermore, the construction of a dual-network architecture with physical isolation between the office network and the data network specifically includes: The office network is used to support external network access, internet services, and office operations. The data network is used to support cloud platform operation and maintenance, database services, and big data business. The two networks operate independently through physical isolation, and secure and controlled data exchange channels are set up between different network areas according to the business flow.
[0020] Specifically, to ensure the security of mine production data and the flexibility of office operations, this solution implements a physically isolated deployment of the office network and data network. The office network, as the main carrier for external interaction and general office work, is functionally divided into an external network access area, an internet service area, an operation and maintenance and security management area, an office service area, and a video service area. This network primarily handles external network access from the three major telecom operators, data from the group's private network, internet information retrieval, and the flow of daily office processes.
[0021] The data network is internally divided into a data subnet and a disaster recovery backup subnet. This network carries the operation and maintenance management of the enterprise's private cloud platform, database services, Hadoop big data analytics, and heterogeneous disaster recovery of critical data. A distributed storage cluster is deployed within the disaster recovery backup subnet, employing erasure coding or replication mechanisms to ensure data persistence. The system regularly performs incremental and full backups, and backup data is synchronized to an off-site disaster recovery center, ensuring that data recovery time in the event of a regional failure does not exceed 30 minutes, and recovery point recovery time does not exceed 1 hour.
[0022] The two networks are physically independent, but at the business logic level, necessary cross-network data flow is achieved by establishing secure and controlled data exchange channels between different network areas. Industrial isolation gateways or physical one-way optical gateways are deployed between the application front-end area of the office network and the data exchange area of the data network, performing deep packet inspection and protocol stripping based on preset security policies. Security policies include access control lists based on IP address whitelists, port numbers, and industrial protocol types, allowing only packets conforming to preset rules to pass. Deep packet inspection involves decapsulating the MAC, IP, and application layer payloads of data packets layer by layer, extracting key fields, performing pattern matching with a preset threat signature database, identifying and blocking data flows containing malicious payloads or abnormal protocol characteristics. Protocol stripping specifically involves stripping the transport and application layer headers of data packets to restore the original business data payload, performing format verification and compliance checks on the payload, and recapsulating it into an internal transport protocol format before forwarding it to the target network area.
[0023] Cloud resource configuration supports dynamic adjustment based on business concurrency. Deployed on a Kubernetes container orchestration platform, it monitors Pod processor utilization and memory usage through the HPA mechanism. When the average CPU utilization exceeds 70% or the memory usage exceeds 80%, the number of service instance replicas is automatically expanded; when the load decreases, redundant resources are automatically reclaimed. For example, the configuration to support a peak of 50 concurrent requests is shown in Table 1.
[0024] Table 1 Cloud Resource Allocation Requirements
[0025] Furthermore, the steps for achieving ubiquitous access to all elements of the mine include: The ubiquitous access uses industrial wireless base stations and wired sensing terminals deployed in mining areas, processing areas, and office areas to collect in real time the operating parameters of production equipment, environmental monitoring data from sensing devices, and location information from management terminals based on a unified communication protocol, and then connects to the industrial internet communication network.
[0026] Specifically, based on a dual-network architecture, this embodiment constructs a ubiquitous IoT system for mines through industrial-grade wireless and wired access methods, enabling real-time perception of all elements such as geology, environment, equipment, and personnel. The wireless access scheme mainly adopts a converged 4G and 5G network. The wireless network topology diagram is shown below. Figure 2 As shown. The base station standard adopts the LTE FDD 900MHz and LTE TDD 1800MHz or 3.5G NR bands to ensure signal coverage depth and penetration in complex terrains such as steep slopes and deep mining areas. Specific deployment locations are shown below. Figure 3 As shown.
[0027] The sensing terminal access covers production equipment, sensing devices, and management terminals.
[0028] Production equipment is integrated by installing smart gateways or PLC communication modules on mining, transportation, and mineral processing equipment to collect motor operating parameters in real time. The collected characteristic physical quantities include motor bearing temperature, winding temperature, vibration frequency, motor speed, outlet pressure, and real-time flow rate. For vibration signals, the sampling frequency is no less than 1kHz to capture early fault characteristic frequencies; for temperature and pressure signals, the sampling frequency is 1Hz to meet the needs of monitoring operating conditions. All collected data is encapsulated through a unified data interface specification and uploaded to the data platform.
[0029] Sensors are integrated, with slope radar or GNSS displacement monitoring points deployed on the mining slopes and environmental monitoring stations set up around the mining area perimeter. The sensors, based on a unified industrial communication protocol, aggregate data on particulate matter concentration, noise levels (decibels), atmospheric pressure, wind speed, and millimeter-level slope displacement to the access gateway. Industrial communication protocols include MQTT, Modbus, or OPC UA.
[0030] With the management terminal connected, centimeter-level high-precision positioning of personnel and transport vehicles can be achieved at the mining face using Beidou or GPS differential positioning technology; meter-level area positioning can be achieved inside the factory and office areas using UWB high-precision positioning or RFID area identification.
[0031] All collected multi-source heterogeneous data is connected to the industrial internet communication network via wired optical fiber or 4G / 5G wireless links. The wired optical fiber uses 24-core shielded cable. To ensure the transmission stability of highly sensitive data, independent QoS streams are allocated to slope radar monitoring stations and blasting vibration monitoring points on steep slopes in the mining area using 5G network slicing technology, ensuring link bandwidth of no less than 200Mbps and end-to-end latency controlled within 50ms. Through this ubiquitous access method, the system can support the efficient access and real-time processing of massive amounts of heterogeneous data, providing raw materials for subsequent data governance and business applications. A schematic diagram of the overall architecture of the mining industrial internet is shown below. Figure 4 As shown.
[0032] Physical isolation between office and data networks prevents unauthorized access, ensuring the secure operation of production data and core business processes. Secure and controlled data exchange channels support on-demand cross-network data flow, balancing security and collaboration. Multi-standard wireless and wired converged networking provides communication coverage in complex terrain environments, including mining areas, processing zones, and office areas, ensuring link continuity and stability. Production equipment, sensors, and management terminals utilize ubiquitous access to achieve real-time collection and aggregation of multi-source heterogeneous data, laying the physical foundation and sensing basis for secure data sharing, thus simultaneously enhancing system security and data acquisition capabilities.
[0033] S200: Based on the mining information standard, the multi-source heterogeneous data is cleaned and fused, and classified according to its sensitivity and importance to construct a standardized data resource library; Furthermore, the cleaning and fusion specifically includes: The three-dimensional laser scanning data of the goaf, the energy consumption monitoring data of production equipment, and the operating condition data of transport vehicles are deredundant, corrected, and converted in format. Based on the mining business logic, a correlation mapping is established between spatial data, real-time sensing data, and relational data to achieve standardized expression of heterogeneous data.
[0034] Specifically, after acquiring all elements of the mine data, the heterogeneous data is preprocessed based on mine information standards. The cleaning and fusion process is implemented using building information modeling tools, aiming to eliminate data redundancy, correct outliers, and achieve correlation of multi-dimensional data.
[0035] For the 3D laser scanning data of the goaf, redundancy removal is performed. Due to the massive amount of point cloud data generated by 3D laser scanning and the existence of overlapping areas, the system adopts a spatial grid filtering algorithm to remove duplicate coordinate points while preserving the morphological characteristics of the ore body.
[0036] For energy consumption monitoring data from production equipment, error correction and format conversion are performed. Preset threshold ranges are used to logically validate the collected voltage, current, and power data. For example, when the collected transformer load rate data exceeds 120% of the rated power, or when negative energy consumption records appear, the system marks it as abnormal data and triggers retesting or value compensation logic. The cleaned data is then uniformly converted into standardized JSON or relational database report formats.
[0037] For the operational data of transport vehicles, the collected vehicle speed, fuel consumption, load capacity, and location coordinates are corrected in real time. A Kalman filter algorithm is used to correct positioning jumps caused by occlusion, ensuring the continuity of the trajectory.
[0038] During the data fusion phase, a mapping relationship is established between spatial data, real-time sensing data, and relational data based on the mine's business logic. Spatial data is based on a 3D oblique photogrammetry model or BIM model, real-time sensing data is indexed by IoT sensor IDs, and relational data is linked using equipment ledgers or production plan numbers. Through mapping, the real-time sensor values are accurately located in the 3D spatial model; for example, the real-time deformation data of slope displacement gauges can be dynamically mapped to the corresponding geographic coordinates on the 3D model of the mining area.
[0039] The system classifies the cleaned data according to its sensitivity and importance.
[0040] The first level consists of core data, including mineral resource reserves, blasting design parameters, three-dimensional models of underground goaf areas, and major safety early warning information.
[0041] The second level consists of important data, including production plan execution progress, real-time equipment operating parameters, and real-time personnel location.
[0042] The third level consists of general data, including office administration information and general environmental monitoring data.
[0043] Furthermore, the step of constructing the standardized data resource repository includes: The basic library, thematic library, and model library are built according to unified standards and specifications, as well as the knowledge center generated by mining and deep processing of historical data; The knowledge center is used to support mining management, decision support, and scientific research.
[0044] Specifically, a standardized data resource repository is constructed according to unified standards and specifications, consisting of a basic repository, a thematic repository, a model repository, and a knowledge center. The basic repository stores raw and pre-cleaned basic mine information, including mine area geographic information, company overview, and equipment ledgers. The thematic repositories are logically divided according to business areas, into a safety monitoring thematic repository, a production control thematic repository, and an operations management thematic repository. The safety monitoring thematic repository stores slope monitoring data, blasting vibration data, and environmental monitoring data; the production control thematic repository stores energy consumption data, production data, and vehicle dispatch records; and the operations management thematic repository stores business data related to operations. The model repository stores various algorithm models used to support business analysis, including bearing fault diagnosis models, open-pit mining boundary optimization models, and slope stability assessment models.
[0045] The Knowledge Center generates knowledge through the mining and in-depth processing of historical data. Utilizing machine learning techniques, it analyzes the correlation between historical production data and energy consumption and output, transforming fragmented historical data into systematic production knowledge. The Knowledge Center provides support for mining management, decision support, and scientific research. For example, by analyzing historical mining data from the past three years, optimal blasting charge parameters for different rock hardnesses can be extracted to guide current blasting designs. Table 2 shows the predicted annual growth rate and total data volume for different data types.
[0046] Table 2. Estimated Growth of Mine Data Volume
[0047] By cleaning and fusing multi-source heterogeneous data, logical conflicts at the format and semantic levels are eliminated, and a multi-dimensional correlation mapping is established between spatial data, real-time sensing data, and relational data, ensuring data consistency and identifiability. Data is categorized and classified according to sensitivity and importance, and differentiated storage and access strategies are matched to different levels of data to achieve secure data governance and compliance management. The construction of a standardized data resource repository and knowledge center transforms raw data into knowledge assets with decision support capabilities, providing support for mining management, decision support, and scientific research enhancement.
[0048] S300: Enables a unified identity authentication system based on a technology middle platform, dynamically allocates access permissions to target resources according to the access subject's attribute information and business operation status, and matches corresponding security control policies to data of different levels according to the hierarchical classification results to generate authorization authentication results; Furthermore, such as Figure 5 As shown, the step of dynamically allocating access permissions to target resources based on the access subject's attribute information and business operation status includes: The system obtains the job functions and security level attributes of the accessing entities, and monitors the current business scenarios of the mine, including normal production scenarios, equipment maintenance scenarios, or emergency rescue scenarios. Based on the matching results between the job functions and security level attributes and the business scenario, the access weight and operation scope of the subject to the target resource are calculated and adjusted in real time.
[0049] Specifically, the system utilizes a unified identity authentication system based on a technology platform. Through a lightweight integration framework and a robust security management mechanism, it enables dynamic authorization of mining resources. During the permission allocation process, the system acquires the attribute information of the access subject. This attribute information includes job function and security level. Job functions cover roles such as production scheduler, safety administrator, equipment maintenance worker, and external visitor. Security levels are assigned different scores based on the employee's background, access history, and job importance. Simultaneously, the system monitors the mine's operational status in real time to identify the current business scenario. The business scenario is determined through real-time feedback from the production process control system and the slope and blasting monitoring systems.
[0050] In normal production scenarios, all monitoring indicators in the mining area are within the threshold range, and the production, transportation, and ore beneficiation processes operate as planned. In equipment maintenance scenarios, when the equipment management system issues a maintenance work order or the monitoring system identifies abnormal motor temperature or excessive vibration, the maintenance mode for a specific area or equipment is triggered. In emergency rescue scenarios, when the slope displacement monitoring system or blasting vibration monitoring system triggers a red alert, or when an emergency response is manually triggered, the system switches to emergency command mode.
[0051] Access permissions are dynamically assigned based on the matching results of job functions, security level attributes, and business scenarios. In normal production scenarios, regular authorization is executed according to established permission policies. In equipment maintenance scenarios, access permissions for equipment data are automatically elevated for maintenance personnel. In emergency rescue scenarios, access permissions for emergency resources are automatically elevated for safety command personnel; for example, all high-definition surveillance footage of the accident area is automatically displayed to the safety administrator.
[0052] Furthermore, when the attribute information of the access subject changes or the business operation status changes, the dynamic allocation step is re-executed to update the authorization and authentication result.
[0053] Specifically, when the attribute information of the access subject changes or the business operation status changes, the system will trigger the re-authorization logic in real time.
[0054] When an employee's job is changed or their security certificate expires, causing their security level to drop, the unified identity authentication system immediately recalculates their access weight and revokes their original access permissions for highly sensitive data.
[0055] When a mine switches from a normal production scenario to an emergency rescue scenario, a command is sent to all on-the-go terminals via the service bus to force an update of the authorization and authentication results. For example, during blasting operations, the system increases the access weight of sensors around the blasting area while restricting unauthorized personnel from entering the digital twin real-time monitoring layer of that area.
[0056] Furthermore, the security control strategy specifically includes: Based on the data classification results, differentiated security measures are matched. These security measures include encrypted storage strategies for highly sensitive data in the storage state, link encryption strategies for cross-network transmission, and access control strategies or dynamic desensitization strategies applied to the access process based on data classification.
[0057] Specifically, based on the data classification and categorization results, authorization and authentication results are generated, and differentiated security control strategies are matched. For highly sensitive data in storage, such as core data like mineral resource reserves and goaf models, encrypted storage strategies are implemented. The system uses national cryptographic algorithms or AES-256 algorithms to encrypt key fields in the database, ensuring that data is unreadable in the event of storage media loss or unauthorized database access.
[0058] For data transmitted across networks, a link encryption strategy is implemented. During controlled data exchange between the office network and the data network, the system establishes a secure transmission tunnel using SSL or TLS protocols to encrypt video surveillance streams and monitoring and early warning commands in real time, preventing data interception during wireless base station or wired transmission.
[0059] Differentiated access control and dynamic data masking strategies are applied to different access levels. For Level 1 core data, multi-factor authentication is implemented, requiring users to enter their username and password, along with a dynamic mobile verification code or biometric authentication. The dynamic data masking strategy automatically masks sensitive information when a Level 3 user accesses a report or layer containing sensitive information. For example, in a capacity management system, precise vehicle load values or financial settlement details are hidden from general management personnel, displaying only vehicle shift statistics, thus protecting critical business assets while meeting business collaboration needs.
[0060] The dynamic authorization mechanism of the technology platform achieves deep decoupling and real-time correlation between permissions and the business environment. The design of dynamically adjusting access weights based on scenario coefficients ensures that, in critical moments such as equipment maintenance and emergency rescue, relevant personnel can quickly obtain the necessary resources by overcoming conventional permission restrictions, thus improving response efficiency.
[0061] S400: Adopting a unified API interface specification and service bus technology, based on the authorization and authentication results, it realizes cross-platform on-demand data access and business collaboration in a service-oriented manner, and generates data access results; Specifically, to address the information silo problem between various business systems, the system has developed and implemented a unified API interface specification. This specification defines standard request headers, communication protocols, data exchange formats, and error code systems.
[0062] Each subsystem encapsulates its core business capabilities according to this specification. The digital mining platform provides resource service interfaces containing data such as ore body morphology, grade distribution, and mining / stripping plans; the production process control system provides IoT interfaces containing real-time streaming data such as motor speed, energy consumption data, and equipment status; and the intelligent application platform provides safety monitoring interfaces including video stream addresses, slope displacement warning values, and vehicle positioning coordinates. All interfaces are uniformly registered in the service directory.
[0063] The system constructs a service bus based on a technology middleware platform, serving as the central hub for cross-platform collaboration. The service bus integrates API gateway functionality, responsible for request routing, protocol conversion, load balancing, and circuit breaker protection. When an application layer initiates a data request, the request message first enters the service bus. The bus verifies whether the access conforms to the authorization authentication result by parsing the authorization credentials carried in the request. After successful verification, the service bus distributes the request to the corresponding data source or business system according to service orchestration logic.
[0064] For scenarios with high real-time requirements, the system is configured with high-performance transmission parameters to ensure real-time updates of the monitoring interface. The concurrent throughput supported by the service bus is dynamically adjusted based on cloud resource configuration, and the system distributes traffic to different application service containers through a load balancing algorithm.
[0065] Through the service bus, the system achieves closed-loop collaboration across various aspects of mine operations, including geology, surveying, mining, mineral processing, and safety management, generating data retrieval results to support business decisions. When the slope displacement monitoring system issues a red alert via API, the service bus automatically triggers a collaboration mechanism, pushing the alert data to the mine's intelligent truck dispatching system. Based on the acquired coordinate information, the dispatching system automatically adjusts vehicle routes within the affected area, achieving real-time linkage between safety risks and production scheduling. Blasting design parameters generated by the digital mining platform are transmitted to the blasting vibration monitoring system via the service bus. The system estimates the vibration impact range based on the designed charge quantity and provides feedback on the actual monitored particle vibration velocity.
[0066] In 4G or 5G private network environments, the end-to-end data latency is controlled within 500ms through the performance optimization mechanism of the service bus to ensure the real-time performance and accuracy of collaborative operations.
[0067] To handle complex data interactions between heterogeneous systems, the service bus employs a service discovery and retry mechanism. When a subsystem interface experiences a transient failure, the bus attempts to retry according to a preset retry policy. If the failure persists, circuit breaker logic is executed, and an alarm is sent to the system operation and maintenance monitoring module.
[0068] By adopting a unified API interface specification and service bus technology, the system enables cross-platform on-demand invocation, making the heterogeneity of underlying data transparent to upper-layer applications. During the invocation process, the service bus performs authorization verification on each request, ensuring that data access is executed within an authorized framework; through real-time business linkage logic, isolated monitoring data is transformed into collaborative instructions with business significance.
[0069] S500: Based on the data call results, to-do tasks, monitoring and early warning and production data are presented to different users in a personalized manner through a unified portal and visual management and control platform, and access behavior records are generated during the secure access process of multiple terminals; Furthermore, the visual management and control platform specifically includes: Integrating 3D oblique photography, building information modeling, and geographic information system services to construct digital twin scenarios for mines; The real-time collected production, safety, and environmental monitoring data are overlaid and displayed in the virtual mine model to achieve transparent control and decision support for the production process.
[0070] Specifically, based on the data retrieval results returned by the service bus, a unified portal is used to build personalized workspaces for users at different levels. The unified portal adopts a component-based design architecture, supporting customized display interfaces according to user roles and responsibilities, including mine managers, safety officers, dispatchers, and technicians. In terms of content distribution, the portal system executes information-to-person logic based on authorization and authentication results. The to-do task component retrieves task flows such as equipment maintenance approvals and safety inspection rectification orders from the production management system in real time by calling the unified messaging service of the technology platform. The monitoring and early warning component aggregates and displays real-time alarm information from slope, blasting, environmental protection, and production equipment. The production data component displays the current mining and stripping progress, energy consumption curves, and production capacity achievement rate in the form of charts and reports. The system supports personalized column configuration, allowing users to independently adjust the layout order and display weight of various functional components.
[0071] The visualization and management platform integrates 3D oblique photogrammetry, building information modeling (BIM), and geographic information system (GIS) services to construct a digital twin scene synchronized with the physical mine. Using drones to collect full oblique photogrammetry data of the mining area, a high-precision 3D model with detailed textures and geometric topological relationships is generated to recreate the stope slopes, industrial area, and spoil heap. Secondly, BIM models of important buildings and structures, including the crushing workshop, substation, and office building, are integrated to achieve a refined representation of their internal structures. Finally, the above models are uniformly mapped to the CGCS2000 coordinate system through environmental GIS services.
[0072] Real-time collected production, safety, and environmental monitoring data are overlaid on the virtual model using dynamic tags or color blocks. For example, on the 3D model of the mining area, the system maps the monitoring points to their geographical coordinates and ensures that the refresh frequency of the monitoring values in the 3D scene is no less than 0.5Hz through periodic polling of the service bus, thereby achieving transparent control of the production process.
[0073] The system supports secure access from various terminals, including PCs, mobile phones, iPads, and large screens. Mobile devices utilize an app or WeChat mini-program to provide environmental monitoring dashboards, key pollution source warnings, and severe weather push notifications. During terminal access, the system generates a complete log of all access activities. Record elements include the access subject identifier, access timestamp, device MAC address, terminal geolocation, accessed API interface identifier, and operation type. Operation types include query, export, and modification. These records are written to the system's runtime log database in real time, serving as the foundational data for security auditing and risk tracing.
[0074] To support decision-making, the visualization platform employs a multi-level early warning display strategy. Taking slope displacement monitoring as an example, when the displacement rate... Furthermore, when the cumulative displacement is within the stable range, the model points are displayed in green; when the displacement rate... When a yellow alert is triggered, the system highlights the alarm icon at the corresponding location in the 3D model; when the displacement rate... When a red alert is triggered, the visualization platform automatically links to the high-definition eagle eye monitoring system, displays the image in a pop-up window on the enterprise command center's large screen, and locks the accident simulation layer to conduct emergency simulations.
[0075] In terms of production monitoring, an 80% warning threshold is set for transformer load rate. When the actual load exceeds this threshold, the production data component will automatically change color and generate an energy consumption anomaly analysis report.
[0076] Through the collaboration of a unified portal and a 3D visualization platform, the system overlays and displays real-time production, safety, and environmental monitoring data within a digital twin scenario, enabling managers to perceive the operational status of the physical mine in a virtual space. Users with different roles and functions receive differentiated information presentations based on authorization and authentication results, facilitating information-to-person matching. Combined with full access behavior recording and multi-level early warning threshold management during secure multi-terminal access, the system provides data support and visualization for production scheduling, safety assessment, and emergency response.
[0077] S600: Based on the access behavior records, the system operation log and event recording mechanism are used as tracking methods to audit the data access and sharing process, thereby achieving security traceability.
[0078] Furthermore, such as Figure 6 As shown, the steps for auditing the data access and sharing process include: The security linkage mechanism is triggered based on the audit results. The security linkage mechanism includes at least one of the following: automatically revoking the current authorization token, restricting the access bandwidth of unauthorized access sources, and pushing security alarm notifications to the unified portal in real time.
[0079] Specifically, using access behavior records as raw material, in-depth auditing is conducted through the daily operation management module in the security operation and maintenance mechanism. The auditing system subscribes to the log streams of the service bus and the unified identity authentication system in real time, and uses an event logging mechanism to track the entire lifecycle of each data request.
[0080] Audit elements are integrated through correlation analysis logic to form a complete audit trail. The audit trail includes: entity attribute verification records, target resource hierarchical identification, authorization determination criteria, and the final operation result. The system serializes logs to ensure that stored audit data has tamper-proof characteristics, providing reliable evidence for security tracing. In the event of data leakage risks or system anomalies, the audit system can accurately locate the source of the fault or the point of unauthorized operation by tracing back the timeline.
[0081] Based on the audit results, a preset security linkage mechanism is automatically triggered to achieve proactive defense of the mine network environment. The linkage logic is executed by the security management engine and mainly covers the following three methods: The system automatically revokes the current authorization token. When the auditing system detects abnormal behavior of an active token, such as accessing multiple geographical locations within a very short period or attempting unauthorized access to core data, the system immediately sends a revocation command to the unified identity authentication system. The access permissions corresponding to the token are revoked in real time, the entity is forced offline, and is required to re-enter multi-factor authentication.
[0082] To limit the access bandwidth of unauthorized access sources, targeting those exhibiting malicious scanning or large-scale data crawling characteristics (identified by IP or MAC address), a rate-limiting policy is implemented at the core switch or firewall level in conjunction with the security detection zone of the office network or data network. The access bandwidth of these unauthorized sources is restricted to an extremely low level to prevent their continuous acquisition of sensitive mining data.
[0083] Security alerts are pushed to the unified portal in real time, and identified risk events are sent to security administrators via the messaging service of the technology platform. Alerts are displayed in a highlighted section of the unified portal and simultaneously sent to operations and maintenance personnel via a mobile app.
[0084] To accurately identify abnormal behavior, abnormal access patterns are identified through behavior deviation analysis. When a user repeatedly attempts to access primary core data beyond their authorized scope within a preset time window, a token revocation is triggered. When the system identifies high-frequency abnormal requests to secondary important data interfaces, rate limiting policies are automatically implemented.
[0085] The auditing system regularly generates safety and compliance reports, summarizing the frequency and security distribution of mine data sharing across different departments and application platforms. The traceability module supports retrieving all historical access records using keywords such as specific ore body numbers or blasting command IDs. Through a visualized traceability map, managers can intuitively view the entire process of highly sensitive data, from collection, cleaning, and storage to which user and on which terminal it is ultimately viewed.
[0086] Through a closed-loop auditing mechanism based on operational logs, the system enables monitoring and auditing of data flow across platforms and multiple business scenarios. The introduction of a security linkage mechanism elevates traditional post-event tracing to real-time blocking during the event, effectively preventing the leakage of core mine assets caused by internal misoperations and external malicious attacks, and ensuring the inherent security of the intelligent mine construction system.
[0087] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for secure sharing and dynamic authorized access to mine data based on the Industrial Internet, characterized in that, include: Construct a dual-network architecture with physical isolation between the office network and the data network, and achieve ubiquitous access to all elements of the mine through industrial wireless and wired access methods to support the collection and transmission of multi-source heterogeneous data; Based on the mining information standard, the multi-source heterogeneous data is cleaned and fused, and classified according to its sensitivity and importance to construct a standardized data resource library; A unified identity authentication system based on a technology middle platform is enabled. Access permissions to target resources are dynamically allocated according to the access subject's attribute information and business operation status. Based on the hierarchical classification results, corresponding security control policies are matched for data of different levels, and authorization authentication results are generated. By adopting a unified API interface specification and service bus technology, and based on the authorization and authentication results, cross-platform on-demand data access and business collaboration are realized in a service-oriented manner, generating data access results; Based on the data retrieval results, to-do tasks, monitoring and early warning, and production data are presented to different users in a personalized manner through a unified portal and visual management platform, and access behavior records are generated during the secure access process of multiple terminals. Based on the access behavior records, the system operation log and event recording mechanism are used as tracking methods to audit the data access and sharing process, thereby achieving security traceability.
2. The method for secure sharing and dynamic authorized access of mine data based on the Industrial Internet according to claim 1, characterized in that, The construction of a dual-network architecture with physical isolation between the office network and the data network specifically includes: The office network is used to support external network access, internet services, and office operations. The data network is used to support cloud platform operation and maintenance, database services, and big data business. The two networks operate independently through physical isolation, and secure and controlled data exchange channels are set up between different network areas according to the business flow.
3. The method for secure sharing and dynamic authorized access to mine data based on the Industrial Internet according to claim 1, characterized in that, The steps to achieve ubiquitous access to all elements of the mine include: The ubiquitous access uses industrial wireless base stations and wired sensing terminals deployed in mining areas, processing areas, and office areas to collect in real time the operating parameters of production equipment, environmental monitoring data from sensing devices, and location information from management terminals based on a unified communication protocol, and then connects to the industrial internet communication network.
4. The method for secure sharing and dynamic authorized access to mine data based on the Industrial Internet according to claim 1, characterized in that, The cleaning and fusion process specifically includes: The three-dimensional laser scanning data of the goaf, the energy consumption monitoring data of production equipment, and the operating condition data of transport vehicles are deredundant, corrected, and converted in format. Based on the mining business logic, a correlation mapping is established between spatial data, real-time sensing data, and relational data to achieve standardized expression of heterogeneous data.
5. The method for secure sharing and dynamic authorized access to mine data based on the Industrial Internet according to claim 1, characterized in that, The steps for constructing a standardized data resource repository include: The basic library, thematic library, and model library are built according to unified standards and specifications, as well as the knowledge center generated by mining and deep processing of historical data; The knowledge center is used to support mining management, decision support, and scientific research.
6. The method for secure sharing and dynamic authorized access to mine data based on the Industrial Internet according to claim 1, characterized in that, The step of dynamically allocating access permissions to target resources based on the access subject's attribute information and business operation status includes: The system obtains the job functions and security level attributes of the accessing entities, and monitors the current business scenarios of the mine, including normal production scenarios, equipment maintenance scenarios, or emergency rescue scenarios. Based on the matching results between the job functions and security level attributes and the business scenario, the access weight and operation scope of the subject to the target resource are calculated and adjusted in real time.
7. The method for secure sharing and dynamic authorized access of mine data based on the Industrial Internet according to claim 6, characterized in that, When the attribute information of the access subject changes or the business operation status changes, the dynamic allocation step is re-executed to update the authorization and authentication result.
8. The method for secure sharing and dynamic authorized access of mine data based on the Industrial Internet according to claim 1, characterized in that, The security control strategy specifically includes: Based on the data classification results, differentiated security measures are matched. These security measures include encrypted storage strategies for highly sensitive data in the storage state, link encryption strategies for cross-network transmission, and access control strategies or dynamic desensitization strategies applied to the access process based on data classification.
9. The method for secure sharing and dynamic authorized access to mine data based on the Industrial Internet according to claim 1, characterized in that, The visual management and control platform specifically includes: Integrating 3D oblique photography, building information modeling, and geographic information system services to construct digital twin scenarios for mines; The real-time collected production, safety, and environmental monitoring data are overlaid and displayed in the virtual mine model to achieve transparent control and decision support for the production process.
10. The method for secure sharing and dynamic authorized access of mine data based on the Industrial Internet according to claim 1, characterized in that, The steps for auditing the data access and sharing process include: The security linkage mechanism is triggered based on the audit results. The security linkage mechanism includes at least one of the following: automatically revoking the current authorization token, restricting the access bandwidth of unauthorized access sources, and pushing security alarm notifications to the unified portal in real time.