Chemical enterprise DCS system network security protection method and system
By building a dynamic process fingerprint in the DCS system of a chemical enterprise and using FPGA to cut off the virus propagation path, the problem of traditional methods being unable to identify virus tampering with data was solved, and accurate virus detection and virus blocking between controllers were achieved.
Patent Information
- Application Number
- CN202510865619.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-09-12
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional network traffic feature analysis or static whitelists cannot identify process data in chemical companies' DCS systems that has been tampered with by viruses and whose format is legal but violates physical laws, resulting in the virus spreading secretly between controllers.
By obtaining the device response delay and reaction phase change characteristic parameters, a dynamic process fingerprint is constructed, and the FPGA is used to perform a fuse operation to cut off the virus propagation path, and switch to the shadow controller to restore the normal process state.
It achieves accurate detection of viruses disguised as legitimate process data, blocks the spread of viruses between controllers, and ensures the normal operation of chemical production.
Smart Images

Figure CN120639404A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security protection method and system for a DCS system of a chemical enterprise. Background Art
[0002] In chemical production, the distributed control system (DCS) is the core control platform, responsible for real-time monitoring of key process parameters such as reactor temperature, pressure, and flow. Recently, virus attacks targeting industrial control systems have become frequent, often disguising themselves as legitimate process data and spreading within DCS networks. Chemical production process data differs fundamentally from conventional industrial data. This difference stems from the unique physical irreproducibility of chemical systems. Chemical reactions are governed by the strict laws of thermodynamics, and the irreversible increase in entropy associated with phase transitions dictates that the coupled relationships between parameters such as temperature, pressure, and viscosity cannot be forged through software.
[0003] Traditional protection methods rely on network traffic feature analysis or static whitelists, which are unable to identify process data that has been tampered with by viruses and is legal in format but violates physical laws. Therefore, there is an urgent need for a network security protection method and system for DCS systems in chemical enterprises that can detect viruses without affecting the normal operation of chemical production. Summary of the Invention
[0004] (1) Technical problems to be solved
[0005] The purpose of the present invention is to provide a network security protection method and system for the DCS system of a chemical enterprise, so as to solve the problem that traditional protection methods that rely on network traffic characteristics or protocol whitelists cannot identify process data tampered with by viruses, which is legal in format but violates physical laws, resulting in the hidden spread of viruses between controllers.
[0006] (2) Technical solution
[0007] To achieve the above objectives, the present invention provides a method for protecting network security of a DCS system in a chemical enterprise, the method comprising:
[0008] Step S1: Obtain the equipment response delay and reaction phase change characteristic parameters in the production process; analyze the fluctuation range value of the equipment response delay, and perform a historical baseline comparison on the reaction phase change characteristic parameters to obtain a verification result, and filter abnormal data according to the verification result to obtain the first production data; bind the equipment ID, the first production data and the synchronously collected timestamp to generate a dynamic process fingerprint, and construct a verification benchmark library with the equipment ID and timestamp as the index key, and the verification benchmark library stores the dynamic process fingerprint and its corresponding sensor raw data.
[0009] Step S2: Obtain the network transmission data packet and extract the device ID, declared timestamp, declared device response delay, and declared reaction phase change characteristic parameters as the second production data; according to the device ID and declared timestamp, obtain the first production data corresponding to the index key from the verification benchmark library, and obtain the device response delay deviation and the phase change characteristic comprehensive deviation by calculation; when the device response delay deviation exceeds the preset device response delay deviation threshold, or the phase change characteristic comprehensive deviation exceeds the preset phase change characteristic comprehensive deviation threshold, or a violation of the device physical limit is detected, generate a fuse instruction.
[0010] Step S3: After the fuse instruction is triggered, the corresponding hardware fuse operation is executed through the FPGA; the control right is switched to the shadow controller through the preset hardware state synchronization channel; the shadow controller loads the process state verified before the fuse, and executes the state recovery strategy corresponding to the fuse instruction level.
[0011] Furthermore, the device response delay and reaction phase change characteristic parameters in the production process are obtained; the fluctuation range of the device response delay is analyzed, and the reaction phase change characteristic parameters are compared with a historical baseline to obtain a verification result, and abnormal data is filtered out according to the verification result to obtain the first production data; the device ID, the first production data, and the synchronously collected timestamp are bound to generate a dynamic process fingerprint, and a verification reference library with the device ID and timestamp as index keys is constructed. The verification reference library stores the dynamic process fingerprint and its corresponding sensor raw data, including:
[0012] During the production process, the actuator operation is monitored in real time, and the actuator operation instruction issuance time t1 and the feedback signal stabilization time t2 are recorded to obtain the equipment response delay τ i =t2-t1; where τ i Indicates the i-th device response delay.
[0013] Get the historical device response delay average value τ0 and historical device response delay standard deviation σ; when |τ i ―τ0|>nσ is considered as signal interference and discarded, where n is the anti-interference coefficient; when the device response delay τ is three times in a row i When the ratio of the range to the mean is less than the preset percentage threshold, it is classified as the first production data.
[0014] The reactor temperature T, pressure P, solution turbidity NTU, and material viscosity μ are acquired synchronously. When the temperature change rate dT / dt or the pressure change rate dP / dt reaches the corresponding preset phase change threshold, the phase change monitoring period begins. The preset phase change threshold includes the temperature change rate threshold and the pressure change rate threshold.
[0015] During the phase change monitoring period, calculate the temperature change acceleration ε=d 2 T / dt2 Record the phase change start time t3, and record the end time t4 when the temperature change rate dT / dt or the pressure change rate dP / dt falls below the preset phase change threshold, and calculate the phase change duration Δt k =t4―t3.
[0016] During the phase change monitoring period, when the turbidity NTU> NTU th When the crystallization characteristics are analyzed, the pressure-viscosity coupling coefficient K = ΔP / μ is obtained; where NTU th is the preset turbidity threshold.
[0017] Combine the device ID, effective device response delay τ, temperature change acceleration ε, and pressure-viscosity coupling coefficient K to generate the input string S = [ID]||[τ]||[ε]||[K]||[Δt k ].
[0018] Generate dynamic process fingerprint F through SM3 hash algorithm; use phase change start time t3 as timestamp t m , the dynamic process fingerprint F and the timestamp t m And the corresponding sensor raw data packet is bound, and the key-value pairs are stored in the verification benchmark library; the index key is the device ID and the timestamp t m ; The value corresponding to the index key is the dynamic process fingerprint F and the corresponding sensor original data packet.
[0019] Furthermore, the method for obtaining the historical device response delay average value τ0 and the historical device response delay standard deviation σ includes:
[0020] The equipment response delay in the last N process control cycles is used as the sample set to calculate the historical equipment response delay average value τ0 and the historical equipment response delay standard deviation σ, where N is the number of days the equipment is in operation T. n and dynamic thresholds related to the average number of daily operations;
[0021] When the sample size does not reach the minimum statistical size N min When , the preset initial response delay parameters τ′0 and σ′ are used;
[0022] τ0 and σ are updated after completing M valid operations, where M is the baseline update trigger frequency generated based on the sample set size N and the average daily number of operations.
[0023] Furthermore, the network transmission data packet is obtained and the device ID, the declared timestamp, the declared device response delay, and the declared reaction phase change characteristic parameter are extracted as the second production data; based on the device ID and the declared timestamp, the first production data corresponding to the index key is obtained from the verification reference library, and the device response delay deviation and the phase change characteristic comprehensive deviation are obtained by calculation, including:
[0024] Parse network transmission data packets to obtain device ID and declared timestamp t n , declared phase change duration Δt k , declared device response delay τ n , the declared phase change characteristic parameters constitute the second production data; the declared phase change characteristic parameters include temperature change acceleration ε n and the pressure-viscosity coupling coefficient K n ; According to the device ID and the declared timestamp t n , get the index key device ID and declared timestamp t in the verification benchmark library n The corresponding first production data; including the device response delay τ m , temperature change acceleration ε m and the pressure-viscosity coupling coefficient K m .
[0025] According to the second production data and the first production data, the device response delay deviation Δτ is obtained by a first deviation formula; the first deviation formula is:
[0026] Δτ=|τ n ―τ m |.
[0027] The comprehensive deviation of phase change characteristics is obtained by the second deviation formula The second deviation formula is:
[0028]
[0029] Where ε0 is the rated temperature acceleration of the equipment, and K0 is the viscosity coefficient under standard operating pressure.
[0030] Furthermore, the index key device ID and the declared timestamp t are obtained in the verification benchmark library. n The corresponding first production data method further includes:
[0031] When the verification reference library does not retrieve the device ID and the declared timestamp t n When matching index keys, based on the same device ID in the time interval Internal selection and t n The closest timestamp t m As the index key to obtain the corresponding first production data, It is the preset tolerance time threshold.
[0032] Furthermore, when the device response delay deviation exceeds a preset device response delay deviation threshold, or the phase change characteristic comprehensive deviation exceeds a preset phase change characteristic comprehensive deviation threshold, or a violation of a device physical limit is detected, the method for generating a fuse instruction includes:
[0033] When τ n >τ max The second fuse instruction is generated when τ max The maximum permissible delay is indicated on the equipment nameplate.
[0034] When Δτ>δ or A third fuse instruction is generated when , wherein δ is a preset device response delay deviation threshold, and ω is a preset phase change characteristic comprehensive deviation threshold.
[0035] When the temperature changes the acceleration ε n <ε th , determined to be the exothermic phase transition acceleration period; where ε th is the exothermic reaction acceleration threshold; if τ is detected during the exothermic phase transition acceleration period n <γτ m , generates the first fuse instruction, where γ is the threshold value of the shortening ratio of the heat release period delay.
[0036] When ε n >ε tl , determined to be the endothermic phase transition acceleration period; among them, ε tl is the endothermic reaction acceleration threshold; if τ is detected during the endothermic phase transition acceleration period n >ητ m , generate a second fuse instruction; where η is the delay growth ratio threshold of the endothermic period.
[0037] When the turbidity NTU n >NTU th When |K n ―K m |>λK m or pressure-viscosity coupling coefficient Generate the third fuse instruction; where λ is the crystal characteristic deviation coefficient, K min is the lower limit of the normal range of the pressure-viscosity coupling coefficient, K max It is the upper limit of the normal range of the pressure-viscosity coupling coefficient.
[0038] Furthermore, after the fuse instruction is triggered, the corresponding hardware fuse operation is executed through the FPGA; control is switched to the shadow controller through a preset hardware state synchronization channel; the shadow controller loads the process state that matches the fuse instruction type and has recently passed dynamic process fingerprint verification, and executes a state recovery strategy including:
[0039] When the fuse instruction is the first fuse instruction, the FPGA directly cuts off the power supply of the physical layer of the attacked port, freezes the current process state through the hardware interrupt channel of the dual-port RAM, and the shadow controller loads the most recent process state verified by the dynamic process fingerprint before the fuse moment, and the process state satisfies its dynamic process fingerprint F s Verify the device ID and t m The corresponding dynamic process fingerprint F is exactly the same.
[0040] When the fuse instruction is the second fuse instruction, the FPGA cuts off the power supply of the port physical layer and enables the backup communication link; the shadow controller loads the latest process status data packet that has passed the dynamic process fingerprint verification within three consecutive control cycles before the fuse.
[0041] When the fuse instruction is the third fuse instruction, the FPGA injects a frequency of f into the abnormal port. c The interference pulse lasts for a period of time t c If the duration is t c After the end, re-test the device response delay deviation Δτ and the comprehensive deviation of phase change characteristics When Δτ>δ1 or When the fuse is broken, it is upgraded to the second fuse instruction.
[0042] Based on the same inventive concept, on the other hand, the present invention also provides a chemical enterprise DCS system network security protection system, the system comprising:
[0043] A verification benchmark library construction module is used to obtain the equipment response delay and reaction phase change characteristic parameters in the production process; analyze the fluctuation range value of the equipment response delay, and perform historical baseline comparison on the reaction phase change characteristic parameters to obtain a verification result, and filter abnormal data based on the verification result to obtain the first production data; bind the equipment ID, the first production data and the synchronously collected timestamp to generate a dynamic process fingerprint, and construct a verification benchmark library with the equipment ID and timestamp as the index key, which stores the dynamic process fingerprint and its corresponding sensor raw data.
[0044] The anomaly detection module is used to obtain network transmission data packets and extract the device ID, declared timestamp, declared device response delay, and declared reaction phase change characteristic parameters as second production data; based on the device ID and declared timestamp, obtain the first production data corresponding to the index key from the verification benchmark library, and obtain the device response delay deviation and the phase change characteristic comprehensive deviation by calculation; when the device response delay deviation exceeds a preset device response delay deviation threshold, or the phase change characteristic comprehensive deviation exceeds a preset phase change characteristic comprehensive deviation threshold, or a violation of the device physical limit is detected, a fuse instruction is generated.
[0045] The fuse execution module is used to trigger the fuse instruction and execute the corresponding hardware fuse operation through the FPGA; switch control to the shadow controller through a preset hardware state synchronization channel; the shadow controller loads the process state that matches the fuse instruction type and has recently passed the dynamic process fingerprint verification, and executes the state recovery strategy.
[0046] Furthermore, the verification benchmark library construction module also includes:
[0047] The parameter dynamic update unit is used to calculate the historical equipment response delay average value τ0 and the historical equipment response delay standard deviation σ based on the equipment response delay in the latest N process control cycles as the sample set, where N is the number of days T that the equipment is in operation. n and dynamic thresholds related to the average number of daily operations;
[0048] When the sample size does not reach the minimum statistical size N min When , the preset initial response delay parameters τ′0 and σ′ are used;
[0049] τ0 and σ are updated after completing M valid operations, where M is the baseline update trigger frequency generated based on the sample set size N and the average daily number of operations.
[0050] Furthermore, the anomaly detection module includes:
[0051] Deviation calculation unit, used to parse network transmission data packets, obtain device ID, declared timestamp t n , declared phase change duration Δt k , declared device response delay τ n , the declared phase change characteristic parameters constitute the second production data; the declared phase change characteristic parameters include temperature change acceleration ε n and the pressure-viscosity coupling coefficient K n ; According to the device ID and the declared timestamp t n , get the index key device ID and declared timestamp t in the verification benchmark library n The corresponding first production data; including the device response delay τ m , temperature change acceleration ε m and the pressure-viscosity coupling coefficient K m .
[0052] According to the second production data and the first production data, the device response delay deviation Δτ is obtained by a first deviation formula; the first deviation formula is:
[0053] Δτ=|τ n ―τ m |.
[0054] The comprehensive deviation of phase change characteristics is obtained by the second deviation formula The second deviation formula is:
[0055]
[0056] Where ε0 is the rated temperature acceleration of the equipment, and K0 is the viscosity coefficient under standard operating pressure.
[0057] Multi-level fuse decision unit, used when τ n >τ max The second fuse instruction is generated when τ max The maximum permissible delay is indicated on the equipment nameplate.
[0058] When Δτ>δ or A third fuse instruction is generated when , wherein δ is a preset device response delay deviation threshold, and ω is a preset phase change characteristic comprehensive deviation threshold.
[0059] When the temperature changes the acceleration ε n <ε th , determined to be the exothermic phase transition acceleration period; where ε th is the exothermic reaction acceleration threshold; if τ is detected during the exothermic phase transition acceleration period n <γτ m , generates the first fuse instruction, where γ is the threshold value of the shortening ratio of the heat release period delay.
[0060] When ε n >ε tl , determined to be the endothermic phase transition acceleration period; among them, ε tl is the endothermic reaction acceleration threshold; if τ is detected during the endothermic phase transition acceleration period n >ητ m , generate a second fuse instruction; where η is the delay growth ratio threshold of the endothermic period.
[0061] When the turbidity NTU n >NTU th When |K n ―K m |>λK m or pressure-viscosity coupling coefficient Generate the third fuse instruction; where λ is the crystal characteristic deviation coefficient, K min is the lower limit of the normal range of the pressure-viscosity coupling coefficient, K max It is the upper limit of the normal range of the pressure-viscosity coupling coefficient.
[0062] (3) Beneficial effects
[0063] Compared with the prior art, the present invention has the following beneficial effects:
[0064] 1. This invention converts the physical laws of chemical reactions into dynamic process fingerprints to achieve accurate detection of viruses disguised as legitimate process data.
[0065] 2. A fuse mechanism that uses FGPA to directly cut off the physical layer power supply and use a shadow controller to take over control, preventing the spread of viruses between controllers without affecting production. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] Figure 1 This is a flowchart of a network security protection method for a DCS system in a chemical enterprise according to an embodiment of the present invention;
[0067] Figure 2 This is a schematic diagram of the module composition of a DCS system network security protection system for a chemical enterprise according to an embodiment of the present invention. DETAILED DESCRIPTION
[0068] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0069] Before giving examples, it is necessary to explain the application scenarios of the present invention. When viruses disguise themselves as legitimate process data, traditional detection methods that rely on network traffic feature analysis or static whitelists cannot identify them. The present invention converts the physical laws of the mechanical response delay and reaction phase change characteristics of chemical equipment into dynamic process fingerprints, constructing a verification benchmark library based on the physical unclonability of chemical data, thereby achieving accurate detection of viruses disguised as legitimate process data. This unclonability is first reflected in the strong binding relationship between the reaction phase change characteristics and the physical state of the equipment. For example, the differential characteristics of the exothermic acceleration in the reactor are determined by physical conditions such as the real-time concentration of the reactants and the activity of the catalyst. It is impossible to reproduce a completely identical acceleration sequence under the same process conditions. Secondly, the fluctuation pattern of the equipment response delay is like a mechanical fingerprint. The physical wear information it contains, such as valve stem clearance and lubrication status, forms the unique identity of each device. Most importantly, the physical coupling laws between parameters, such as the pressure-viscosity coefficient must maintain a positive gradient during crystallization. This mathematical constraint, determined by the nature of the phase change of matter, becomes a natural yardstick for verifying the authenticity of data.
[0070] Example 1: Figure 1 As shown, this embodiment provides a method for protecting network security of a DCS system in a chemical enterprise, the method comprising:
[0071] Step S1: Obtain the equipment response delay and reaction phase change characteristic parameters in the production process; analyze the fluctuation range value of the equipment response delay, and perform a historical baseline comparison on the reaction phase change characteristic parameters to obtain a verification result, and filter abnormal data according to the verification result to obtain the first production data; bind the equipment ID, the first production data and the synchronously collected timestamp to generate a dynamic process fingerprint, and construct a verification benchmark library with the equipment ID and timestamp as the index key, and the verification benchmark library stores the dynamic process fingerprint and its corresponding sensor raw data.
[0072] Step S2: Obtain the network transmission data packet and extract the device ID, declared timestamp, declared device response delay, and declared reaction phase change characteristic parameters as the second production data; according to the device ID and declared timestamp, obtain the first production data corresponding to the index key from the verification benchmark library, and obtain the device response delay deviation and the phase change characteristic comprehensive deviation by calculation; when the device response delay deviation exceeds the preset device response delay deviation threshold, or the phase change characteristic comprehensive deviation exceeds the preset phase change characteristic comprehensive deviation threshold, or a violation of the device physical limit is detected, generate a fuse instruction.
[0073] Step S3: After the fuse instruction is triggered, the corresponding hardware fuse operation is executed through the FPGA; the control right is switched to the shadow controller through the preset hardware state synchronization channel; the shadow controller loads the process state verified before the fuse, and executes the state recovery strategy corresponding to the fuse instruction level.
[0074] Furthermore, the device response delay and reaction phase change characteristic parameters in the production process are obtained; the fluctuation range of the device response delay is analyzed, and the reaction phase change characteristic parameters are compared with a historical baseline to obtain a verification result, and abnormal data is filtered out according to the verification result to obtain the first production data; the device ID, the first production data, and the synchronously collected timestamp are bound to generate a dynamic process fingerprint, and a verification reference library with the device ID and timestamp as index keys is constructed. The verification reference library stores the dynamic process fingerprint and its corresponding sensor raw data, including:
[0075] During the production process, the actuator operation is monitored in real time, and the actuator operation instruction issuance time t1 and the feedback signal stabilization time t2 are recorded to obtain the equipment response delay τ i =t2-t1; where τ i Indicates the i-th device response delay.
[0076] Get the historical device response delay average value τ0 and historical device response delay standard deviation σ; when |τ i ―τ0|>nσ is considered as signal interference and discarded, where n is the anti-interference coefficient; when the device response delay τ is three times in a row iWhen the ratio of the range to the mean is less than the preset percentage threshold, it is classified as the first production data.
[0077] The reactor temperature T, pressure P, solution turbidity NTU, and material viscosity μ are acquired synchronously. When the temperature change rate dT / dt or the pressure change rate dP / dt reaches the corresponding preset phase change threshold, the phase change monitoring period begins. The preset phase change threshold includes the temperature change rate threshold and the pressure change rate threshold.
[0078] During the phase change monitoring period, calculate the temperature change acceleration ε=d 2 T / dt 2 Record the phase change start time t3, and record the end time t4 when the temperature change rate dT / dt or the pressure change rate dP / dt falls below the preset phase change threshold, and calculate the phase change duration Δt k =t4―t3.
[0079] During the phase change monitoring period, when the turbidity NTU> NTU th When the crystallization characteristics are analyzed, the pressure-viscosity coupling coefficient K = ΔP / μ is obtained; where NTU th is the preset turbidity threshold.
[0080] Combine the device ID, effective device response delay τ, temperature change acceleration ε, and pressure-viscosity coupling coefficient K to generate the input string S = [ID]||[τ]||[ε]||[K]||[Δt k ].
[0081] Generate dynamic process fingerprint F through SM3 hash algorithm; use phase change start time t3 as timestamp t m , the dynamic process fingerprint F and the timestamp t m And the corresponding sensor raw data packet is bound, and the key-value pairs are stored in the verification benchmark library; the index key is the device ID and the timestamp t m ; The value corresponding to the index key is the dynamic process fingerprint F and the corresponding sensor original data packet.
[0082] For example, take the electrolytic cell of a chlor-alkali plant (ID: E-205) as an example:
[0083] When a new device is put into use for the first time, the initial response delay parameters τ′0=1.6s and σ′=0.05s provided by the manufacturer are loaded and the full N min = Dynamic update is enabled after 30 times.
[0084] Real-time monitoring of the cathode liquid level valve, the command is issued at t1 = 09:30:15.230, the feedback is stable at t1 = 09:30:16.850, and the device response delay τ is obtained i=1.62s. Historical baseline τ0 = 1.58, standard deviation σ = 0.04s, n = 3. Since |1.62-1.58| = 0.04 < 3σ = 0.12, the data is retained.
[0085] Perform three consecutive delay validations: Get the latest three operation delay data:
[0086] τ i―2 =1.59s(t=09:29:45.110), τ i―1 =1.61s(t=09:30:00.780), τ i =1.62s(t=09:30:16.850).
[0087] Calculate the mean:
[0088] Calculate the range: R = max(1.59,1.61,1.62) - min(1.59,1.61,1.62) = 0.03s.
[0089] Range to mean ratio: The preset percentage threshold is 5% (valve equipment). Since 1.87% is less than 5%, it is determined to be a valid data group.
[0090] Synchronous data collection: T = 89.3 °C, P = 1.25 MPa, NTU = 45.6, μ = 0.21 Pa · s, temperature change rate dT / dt=1.2℃ / min>ε th =0.8℃ / min, triggering exothermic phase change monitoring. Temperature acceleration ε=d 2 T / dt 2 =-0.015℃ / min 2 , record the start time t3 = 09:30:16.850; end when dT / dt = 0.5℃ / min, t4 = 09:32:05.110, phase change duration Δt k =t4―t3=108.26s.
[0091] Because turbidity NTU=45.6>NTU th =40, calculate the pressure-viscosity coupling coefficient, where the pressure change ΔP = 0.15 MPa, and obtain K = ΔP / μ ≈ 0.714 MPa / (Pa·s).
[0092] Combine and generate the input string S = [E-205]||[1.62]||[-0.015]||[0.714]||[108.26], and use the SM3 hash algorithm to obtain the dynamic process fingerprint F = 9c2a...a3b6. Bind the device IDE-205 and the timestamp tm =09:30:16.850 stored in the verification benchmark library.
[0093] Furthermore, the method for obtaining the historical device response delay average value τ0 and the historical device response delay standard deviation σ includes:
[0094] The equipment response delay in the last N process control cycles is used as the sample set to calculate the historical equipment response delay average value τ0 and the historical equipment response delay standard deviation σ, where N is the number of days the equipment is in operation T. n and dynamic thresholds related to the average number of daily operations;
[0095] When the sample size does not reach the minimum statistical size N min When , the preset initial response delay parameters τ′0 and σ′ are used;
[0096] τ0 and σ are updated after completing M valid operations, where M is the baseline update trigger frequency generated based on the sample set size N and the average daily number of operations.
[0097] For example, the device E-205 operates T n = 180 days, operation number c = 5 times / day, calculation sample number N = min(1000, T n c) = min(1000, 900). Take the latest 900 delay data: τ j ∈[1.52s,1.65s], we get τ0 = 1.58s, σ = 0.04s. The baseline update trigger frequency M = max(50,0.1×N) = 90, and the baseline is recalculated after every 90 operations.
[0098] When the minimum sample size N is not reached min =30, the initial response delay parameters τ′0=1.6s and σ′=0.05s preset by the manufacturer are loaded.
[0099] Furthermore, the network transmission data packet is obtained and the device ID, the declared timestamp, the declared device response delay, and the declared reaction phase change characteristic parameter are extracted as the second production data; based on the device ID and the declared timestamp, the first production data corresponding to the index key is obtained from the verification reference library, and the device response delay deviation and the phase change characteristic comprehensive deviation are obtained by calculation, including:
[0100] Parse network transmission data packets to obtain device ID and declared timestamp t n , declared phase change duration Δt k , declared device response delay τ n , the declared phase change characteristic parameters constitute the second production data; the declared phase change characteristic parameters include temperature change acceleration ε n and the pressure-viscosity coupling coefficient Kn ; According to the device ID and the declared timestamp t n , get the index key device ID and declared timestamp t in the verification benchmark library n The corresponding first production data; including the device response delay τ m , temperature change acceleration ε m and the pressure-viscosity coupling coefficient K m .
[0101] According to the second production data and the first production data, the device response delay deviation Δτ is obtained by a first deviation formula; the first deviation formula is:
[0102] Δτ=|τ n ―τ m |.
[0103] The comprehensive deviation of phase change characteristics is obtained by the second deviation formula The second deviation formula is:
[0104]
[0105] Where ε0 is the rated temperature acceleration of the equipment, and K0 is the viscosity coefficient under standard operating pressure.
[0106] For example, parsing the data packet from controller #7 states: the device rated temperature acceleration ε0 is 0.1°C / min 2 The standard working pressure viscosity coefficient K0 is 0.5MPa / (P a ·s), device E-205, timestamp t n =09:30:16.850, declare device response delay τ n =0.75s, declare the temperature change acceleration ε n =0.02℃ / min 2 (Declare heat release), declare pressure-viscosity coupling coefficient K n =0.8MPa / (P a ·s).
[0107] Get the corresponding benchmark library data based on the device ID and timestamp: τ m =1.62s, ε m =-0.015℃ / min 2 , K m =0.714MPa / (P a ·s).
[0108] Δτ=|τ n ―τ m |=0.87s.
[0109]
[0110] Furthermore, the index key device ID and the declared timestamp t are obtained in the verification benchmark library. n The corresponding first production data method further includes:
[0111] When the verification reference library does not retrieve the device ID and the declared timestamp t n When matching index keys, based on the same device ID in the time interval Internal selection and t n The closest timestamp t m As the index key to obtain the corresponding first production data, It is the preset tolerance time threshold.
[0112] For example, when parsing controller #8 data packet stating timestamp t n =09:30:17.150, search the verification benchmark library:
[0113] Device control cycle ΔT = 100ms, preset tolerance time threshold Calculate the time window:
[0114]
[0115] Search within the index key range for device ID = E-205:
[0116] Key3 = E-205@09:30:17.150 (reference library does not exist), Key1 = E-205@09:30:16.950 (reference library exists),
[0117] Key2 = E-205@09:30:17.250 (benchmark inventory exists).
[0118] Candidate timestamp within the window: t m1 =09:30:16.950, 200ms difference; t m2 =09:30:17.250, difference of 100ms.
[0119] Select the closest timestamp: t m2 =09:30:17.250, use the key value Key=E-205@09:30:17.250 corresponding to τ m , ε m , K m As the first production data.
[0120] Furthermore, when the device response delay deviation exceeds a preset device response delay deviation threshold, or the phase change characteristic comprehensive deviation exceeds a preset phase change characteristic comprehensive deviation threshold, or a violation of a device physical limit is detected, the method for generating a fuse instruction includes:
[0121] When τ n >τ max The second fuse instruction is generated when τ max The maximum allowable delay marked on the equipment nameplate;
[0122] When Δτ>δ or When , a third fuse instruction is generated, wherein δ is a preset device response delay deviation threshold, and ω is a preset phase change characteristic comprehensive deviation threshold;
[0123] When the temperature changes the acceleration ε n <ε th , determined to be the exothermic phase transition acceleration period; where ε th is the exothermic reaction acceleration threshold; if τ is detected during the exothermic phase transition acceleration period n <γτ m , generating the first fuse instruction, where γ is the threshold value of the shortening ratio of the heat release period delay;
[0124] When ε n >ε tl , determined to be the endothermic phase transition acceleration period; among them, ε tl is the endothermic reaction acceleration threshold; if τ is detected during the endothermic phase transition acceleration period n >ητ m , generating a second fuse instruction; wherein η is the threshold value of the delay growth ratio of the endothermic period;
[0125] When the turbidity NTU n >NTU th When |K n ―K m |>λK m or pressure-viscosity coupling coefficient Generate the third fuse instruction; where λ is the crystal characteristic deviation coefficient, K min is the lower limit of the normal range of the pressure-viscosity coupling coefficient, K max It is the upper limit of the normal range of the pressure-viscosity coupling coefficient.
[0126] For example, the value of γ is determined based on 1,326 exothermic phase change experiments on 12 types of chemical equipment. When the delay is shortened by more than 40%, the probability of temperature runaway reaches 87%, while when the delay is shortened by more than 60%, the risk of mechanical damage to the equipment increases. Therefore, γ is limited to [0.4, 0.6], with γ = 0.5 being used for electrolytic cells in chlor-alkali plants.
[0127] Taking η = 1.15, the upper limit of normal fluctuation of the delay of the endothermic process equipment is 15%. Exceeding this value may cause overcooling due to the injection of false loads by viruses.
[0128] When λ=0.3, a sudden change of the pressure-viscosity coupling coefficient exceeding 30% during the crystallization process will cause blockage of the crystallizer.
[0129] Equipment operating time T n = 180 days, δ = α1 × β, ω = α2 × β; where α1 is the basic delay tolerance and α2 is the phase change characteristic tolerance. For valves, α1 is 0.6s, and for reactors, α2 is 0.05s; β is calculated based on the number of days the equipment is in operation, T. n Dynamic calculation: β=1―(T n / θ) k , verified by Weibull distribution, is consistent with the mechanical wear curve of chemical equipment, where θ = 3650 days is the design life of the equipment and k = 1.2 is the accelerated failure parameter of chemical equipment.
[0130] β=1―(180 / 3650) 1.2 ≈0.97, δ=α1×β=0.58s, ω=α2×β=0.0485.
[0131] If the declared device delay τ n =3.0s>τ max =2.5s, directly triggering the second fuse instruction.
[0132] Because ε n =0.05℃ / min 2 >ε tl =0.01℃ / min 2 Entering the endothermic phase transition acceleration period; detecting τ n =1.92s>ητ m =1.15×1.62≈1.86s, triggering the second fuse instruction.
[0133] Supplement to the first circuit breaker scenario: If the declaration ε n =-0.85℃ / min 2 <ε th =-0.8℃ / min 2 (Exothermic acceleration period) and τ n =0.3s<γτ m =0.5×1.62=0.81s, triggering the first fuse instruction.
[0134] Supplement to the third circuit breaker scenario: If NTU is declared n =45.6>NTU th =40,K n =1.2MPa / (Pa·s)>Km =0.714MPa / (Pa·s), and |1.2―0.714|=0.486>λK m =0.3×0.714≈0.214 triggers the third fuse instruction.
[0135] Or another scenario: declare data: τ n =0.75s, ε n =0.02℃ / min 2 , K n =0.8MPa / (Pa·s); Benchmark data: τ m =1.62s, ε m =-0.015℃ / min 2 , K m =0.714MPa / (Pa·s).
[0136] Calculation deviation: Δτ=0.87s, Detected Δτ=0.87s>δ=0.58s or Trigger the third fuse instruction.
[0137] In particular, when multiple fuse instructions are triggered, the fuse instructions are executed according to priority, with the first fuse instruction > the second fuse instruction > the third fuse instruction.
[0138] Furthermore, after the fuse instruction is triggered, the corresponding hardware fuse operation is executed through the FPGA; control is switched to the shadow controller through a preset hardware state synchronization channel; the shadow controller loads the process state that matches the fuse instruction type and has recently passed dynamic process fingerprint verification, and executes a state recovery strategy including:
[0139] When the fuse instruction is the first fuse instruction, the FPGA directly cuts off the power supply of the physical layer of the attacked port, freezes the current process state through the hardware interrupt channel of the dual-port RAM, and the shadow controller loads the most recent process state verified by the dynamic process fingerprint before the fuse moment, and the process state satisfies its dynamic process fingerprint F s Verify the device ID and t m The corresponding dynamic process fingerprint F is exactly the same.
[0140] When the fuse instruction is the second fuse instruction, the FPGA cuts off the power supply of the port physical layer and enables the backup communication link; the shadow controller loads the latest process status data packet that has passed the dynamic process fingerprint verification within three consecutive control cycles before the fuse.
[0141] When the fuse instruction is the third fuse instruction, the FPGA injects a frequency of f into the abnormal port. cThe interference pulse lasts for a period of time t c If the duration is t c After the end, re-test the device response delay deviation Δτ and the comprehensive deviation of phase change characteristics When Δτ>δ1 or When the fuse is broken, it is upgraded to the second fuse instruction.
[0142] For example, when the first fuse instruction is executed, the FPGA cuts off the PHY layer power supply of the attacked port Eth3 within 10μs, freezes the electrolytic cell state through the dual-port RAM hardware interrupt, and the shadow controller loads the state that has been verified by the dynamic process fingerprint most recently before the fuse moment. The dynamic process fingerprint F s Exactly matches F in the benchmark library.
[0143] Second fuse instruction example: FPGA cuts off the physical layer power supply of the port, enables the backup optical fiber communication link, and the shadow controller retrieves the fuse before
[0144] The third fuse instruction upgrade example, FPGA injects a frequency of f into port Eth7 c =25MHz interference pulse, duration t c =max(10ms, 3ΔT)=90ms. After the interference is completed, Δτ>δ1 is still detected, and the second fuse instruction is upgraded; the power supply of Eth7 is cut off, the backup optical fiber communication link is enabled, and the shadow controller retrieves the verification records of three consecutive control cycles ΔT=30ms before the fuse is blown, and loads the latest verified status.
[0145] where f c Selected from the industrial equipment immunity test frequency band, based on IEC 61000-4-4 standard 4.3.2; in the embodiment, the electrolytic cell is selected according to the second level risk f c =25MHz.
[0146] Example 2: Based on the same inventive concept, Figure 2 As shown, this embodiment also provides a chemical enterprise DCS system network security protection system, the system comprising:
[0147] A verification benchmark library construction module is used to obtain the equipment response delay and reaction phase change characteristic parameters in the production process; analyze the fluctuation range value of the equipment response delay, and perform a historical baseline comparison on the reaction phase change characteristic parameters to obtain a verification result, and filter abnormal data based on the verification result to obtain the first production data; bind the equipment ID, the first production data and the synchronously collected timestamp to generate a dynamic process fingerprint, and construct a verification benchmark library with the equipment ID and timestamp as the index key, which stores the dynamic process fingerprint and its corresponding sensor raw data.
[0148] The anomaly detection module is used to obtain network transmission data packets and extract the device ID, declared timestamp, declared device response delay, and declared reaction phase change characteristic parameters as second production data; based on the device ID and declared timestamp, obtain the first production data corresponding to the index key from the verification benchmark library, and obtain the device response delay deviation and the phase change characteristic comprehensive deviation by calculation; when the device response delay deviation exceeds a preset device response delay deviation threshold, or the phase change characteristic comprehensive deviation exceeds a preset phase change characteristic comprehensive deviation threshold, or a violation of the device physical limit is detected, a fuse instruction is generated.
[0149] The fuse execution module is used to trigger the fuse instruction and execute the corresponding hardware fuse operation through the FPGA; switch control to the shadow controller through a preset hardware state synchronization channel; the shadow controller loads the process state that matches the fuse instruction type and has recently passed the dynamic process fingerprint verification, and executes the state recovery strategy.
[0150] Furthermore, the verification benchmark library construction module also includes:
[0151] The parameter dynamic update unit is used to calculate the historical equipment response delay average value τ0 and the historical equipment response delay standard deviation σ based on the equipment response delay in the latest N process control cycles as the sample set, where N is the number of days T that the equipment is in operation. n and dynamic thresholds related to the average number of daily operations;
[0152] When the sample size does not reach the minimum statistical size N min When , the preset initial response delay parameters τ′0 and σ′ are used;
[0153] τ0 and σ are updated after completing M valid operations, where M is the baseline update trigger frequency generated based on the sample set size N and the average daily number of operations.
[0154] Furthermore, the anomaly detection module includes:
[0155] Deviation calculation unit, used to parse network transmission data packets, obtain device ID, declared timestamp t n , declared phase change duration Δt k , declared device response delay τ n , the declared phase change characteristic parameters constitute the second production data; the declared phase change characteristic parameters include temperature change acceleration ε n and the pressure-viscosity coupling coefficient K n ; According to the device ID and the declared timestamp t n , get the index key device ID and declared timestamp t in the verification benchmark library n The corresponding first production data; including the device response delay τ m, temperature change acceleration ε m and the pressure-viscosity coupling coefficient K m .
[0156] According to the second production data and the first production data, the device response delay deviation Δτ is obtained by a first deviation formula; the first deviation formula is:
[0157] Δτ=|τ n ―τ m |;
[0158] The comprehensive deviation of phase change characteristics is obtained by the second deviation formula The second deviation formula is:
[0159]
[0160] Where ε0 is the rated temperature acceleration of the equipment, and K0 is the viscosity coefficient under standard operating pressure.
[0161] Multi-level fuse decision unit, used when τ n >τ max The second fuse instruction is generated when τ max The maximum permissible delay is indicated on the equipment nameplate.
[0162] When Δτ>δ or A third fuse instruction is generated when , wherein δ is a preset device response delay deviation threshold, and ω is a preset phase change characteristic comprehensive deviation threshold.
[0163] When the temperature changes the acceleration ε n <ε th , determined to be the exothermic phase transition acceleration period; where ε th is the exothermic reaction acceleration threshold; if τ is detected during the exothermic phase transition acceleration period n <γτ m , generates the first fuse instruction, where γ is the threshold value of the shortening ratio of the heat release period delay.
[0164] When ε n >ε tl , determined to be the endothermic phase transition acceleration period; among them, ε tl is the endothermic reaction acceleration threshold; if τ is detected during the endothermic phase transition acceleration period n >ητ m , generate a second fuse instruction; where η is the delay growth ratio threshold of the endothermic period.
[0165] When the turbidity NTU n >NTU th When |K n ―K m |>λKm or pressure-viscosity coupling coefficient Generate the third fuse instruction; where λ is the crystal characteristic deviation coefficient, K min is the lower limit of the normal range of the pressure-viscosity coupling coefficient, K max It is the upper limit of the normal range of the pressure-viscosity coupling coefficient.
[0166] It should be noted that, regarding the system in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated on here.
[0167] Finally, it should be noted that although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments, or make equivalent substitutions for some of the technical features therein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A chemical enterprise DCS system network security protection method, characterized in that: The method comprises: Obtaining equipment response delay and reaction phase change characteristic parameters during the production process; analyzing the fluctuation range of the equipment response delay, and performing a historical baseline comparison on the reaction phase change characteristic parameters to obtain a verification result, filtering abnormal data based on the verification result to obtain first production data; binding the equipment ID, the first production data, and a synchronously collected timestamp to generate a dynamic process fingerprint, and constructing a verification reference library with the equipment ID and timestamp as index keys, wherein the verification reference library stores the dynamic process fingerprint and its corresponding sensor raw data; Obtaining a network transmission data packet and extracting a device ID, a declared timestamp, a declared device response delay, and a declared reaction phase change characteristic parameter as second production data; obtaining first production data corresponding to an index key from a verification reference library based on the device ID and the declared timestamp, and calculating a device response delay deviation and a phase change characteristic comprehensive deviation; generating a fuse instruction when the device response delay deviation exceeds a preset device response delay deviation threshold, or the phase change characteristic comprehensive deviation exceeds a preset phase change characteristic comprehensive deviation threshold, or a violation of a device physical limit is detected; After the fuse instruction is triggered, the corresponding hardware fuse operation is executed through the FPGA; the control is switched to the shadow controller through the preset hardware state synchronization channel; the shadow controller loads the process state that matches the fuse instruction type and has recently passed the dynamic process fingerprint verification, and executes the state recovery strategy.
2. A chemical enterprise DCS system network security protection method according to claim 1, characterized in that: The method includes obtaining a device response delay and a reaction phase change characteristic parameter during a production process; analyzing a fluctuation range of the device response delay, and performing a historical baseline comparison on the reaction phase change characteristic parameter to obtain a verification result, filtering abnormal data according to the verification result to obtain first production data; binding the device ID, the first production data, and a synchronously collected timestamp to generate a dynamic process fingerprint, and constructing a verification reference library with the device ID and timestamp as index keys. The verification reference library stores the dynamic process fingerprint and its corresponding sensor raw data, including: During the production process, the actuator operation is monitored in real time, and the actuator operation instruction issuance time t1 and the feedback signal stabilization time t2 are recorded to obtain the equipment response delay τ i =t2-t1; where τ i represents the response delay of the i-th device; Get the historical device response delay average value τ0 and historical device response delay standard deviation σ; when |τ i ―τ0|>nσ is considered as signal interference and discarded, where n is the anti-interference coefficient; when the device response delay τ is three times in a row i When the ratio of the range to the mean is less than a preset percentage threshold, it is classified into the first production data; The reactor temperature T, pressure P, solution turbidity NTU, and material viscosity μ are acquired simultaneously; when the temperature change rate dT / dt or the pressure change rate dP / dt reaches the corresponding preset phase change threshold, the phase change monitoring period begins; the preset phase change threshold includes the temperature change rate threshold and the pressure change rate threshold; During the phase change monitoring period, calculate the temperature change acceleration ε=d 2 T / dt 2 Record the phase change start time t3, and record the end time t4 when the temperature change rate dT / dt or the pressure change rate dP / dt falls below the preset phase change threshold, and calculate the phase change duration Δt k =t4-t3; During the phase change monitoring period, when the turbidity NTU> NTU th When the crystallization characteristics are analyzed, the pressure-viscosity coupling coefficient K = ΔP / μ is obtained; where NTU th is the preset turbidity threshold; Combine the device ID, effective device response delay τ, temperature change acceleration ε, and pressure-viscosity coupling coefficient K to generate the input string S = [ID]||[τ]||[ε]||[K]||[Δt k ]; Generate dynamic process fingerprint F through SM3 hash algorithm; use phase change start time t3 as timestamp t m , the dynamic process fingerprint F and the timestamp t m And the corresponding sensor raw data packet is bound, and the key-value pairs are stored in the verification benchmark library; the index key is the device ID and the timestamp t m ; The value corresponding to the index key is the dynamic process fingerprint F and the corresponding sensor original data packet.
3. A chemical enterprise DCS system network security protection method according to claim 2, characterized in that: The method for obtaining the historical device response delay average value τ0 and the historical device response delay standard deviation σ includes: The equipment response delay in the last N process control cycles is used as the sample set to calculate the historical equipment response delay average value τ0 and the historical equipment response delay standard deviation σ, where N is the number of days the equipment is in operation T. n and dynamic thresholds related to the average number of daily operations; When the sample size does not reach the minimum statistical size N min When , the preset initial response delay parameters τ′0 and σ′ are used; τ0 and σ are updated after completing M valid operations, where M is the baseline update trigger frequency generated based on the sample set size N and the average daily number of operations.
4. A chemical enterprise DCS system network security protection method according to claim 3, characterized in that: The method of obtaining a network transmission data packet and extracting a device ID, a declared timestamp, a declared device response delay, and a declared reaction phase change characteristic parameter as the second production data; obtaining the first production data corresponding to the index key from the verification reference library based on the device ID and the declared timestamp, and calculating the device response delay deviation and the phase change characteristic comprehensive deviation includes: Parse network transmission data packets to obtain device ID and declared timestamp t n , declared phase change duration Δt k , declared device response delay τ n , the declared phase change characteristic parameters constitute the second production data; the declared phase change characteristic parameters include temperature change acceleration ε n and the pressure-viscosity coupling coefficient K n ; According to the device ID and the declared timestamp t n , get the index key device ID and declared timestamp t in the verification benchmark library n The corresponding first production data; including the device response delay τ m , temperature change acceleration ε m and the pressure-viscosity coupling coefficient K m ; According to the second production data and the first production data, the device response delay deviation Δτ is obtained by a first deviation formula; the first deviation formula is: Δτ=|τ n ―t m |; The comprehensive deviation Δθ of the phase change characteristic is obtained by the second deviation formula; the second deviation formula is: Where ε0 is the rated temperature acceleration of the equipment, and K0 is the viscosity coefficient under standard operating pressure.
5. A chemical enterprise DCS system network security protection method according to claim 4, characterized in that: The index key device ID and the declared timestamp t are obtained in the verification benchmark library. n The corresponding first production data method further includes: When the verification reference library does not retrieve the device ID and the declared timestamp t n When matching index keys, based on the same device ID in the time interval Internal selection and t n The closest timestamp t m As the index key to obtain the corresponding first production data, It is the preset tolerance time threshold.
6. A chemical enterprise DCS system network security protection method according to claim 5, characterized in that: The method of generating a fuse instruction when the device response delay deviation exceeds a preset device response delay deviation threshold, or the phase change characteristic comprehensive deviation exceeds a preset phase change characteristic comprehensive deviation threshold, or a violation of a device physical limit is detected includes: When τ n >τ max The second fuse instruction is generated when τ max The maximum allowable delay marked on the equipment nameplate; When Δτ>δ or Δθ>ω, a third fuse instruction is generated, where δ is a preset device response delay deviation threshold, and ω is a preset phase change characteristic comprehensive deviation threshold; When the temperature changes the acceleration ε n <ε th , determined to be the exothermic phase transition acceleration period; where ε th is the exothermic reaction acceleration threshold; if τ is detected during the exothermic phase transition acceleration period n <γτ m , generating the first fuse instruction, where γ is the threshold value of the shortening ratio of the heat release period delay; When ε n >ε tl , determined to be the endothermic phase transition acceleration period; among them, ε tl is the endothermic reaction acceleration threshold; if τ is detected during the endothermic phase transition acceleration period n >ητ m , generating a second fuse instruction; wherein η is the threshold value of the delay growth ratio of the endothermic period; When the turbidity NTU n >NTU th When |K n ―K m |>λK m or pressure-viscosity coupling coefficient Generate the third fuse instruction; where λ is the crystal characteristic deviation coefficient, K min is the lower limit of the normal range of the pressure-viscosity coupling coefficient, K max It is the upper limit of the normal range of the pressure-viscosity coupling coefficient.
7. A chemical enterprise DCS system network security protection method according to claim 6, characterized in that: After the fuse instruction is triggered, the corresponding hardware fuse operation is executed through the FPGA; control is switched to the shadow controller through a preset hardware state synchronization channel; the shadow controller loads the process state that matches the fuse instruction type and has recently passed dynamic process fingerprint verification, and executes the state recovery strategy including: When the fuse instruction is the first fuse instruction, the FPGA directly cuts off the power supply of the physical layer of the attacked port, freezes the current process state through the hardware interrupt channel of the dual-port RAM, and the shadow controller loads the most recent process state verified by the dynamic process fingerprint before the fuse moment, and the process state satisfies its dynamic process fingerprint F s Verify the device ID and t m The corresponding dynamic process fingerprint F is exactly the same; When the fuse instruction is the second fuse instruction, the FPGA cuts off the power supply to the physical layer of the port and enables the backup communication link; the shadow controller loads the latest process status data packet that has passed the dynamic process fingerprint verification within three consecutive control cycles before the fuse is blown; When the fuse instruction is the third fuse instruction, the FPGA injects a frequency of f into the abnormal port. c The interference pulse lasts for a period of time t c If the duration is t c After completion, the device response delay deviation Δτ and the phase change characteristic comprehensive deviation Δθ are re-tested. When Δτ>δ1 or Δθ>δ2 is still satisfied, it is upgraded to the second fuse instruction.
8. A chemical enterprise DCS system network security protection system, characterized by: The system comprises: A verification benchmark library construction module is used to obtain equipment response delay and reaction phase change characteristic parameters during the production process; analyze the fluctuation range of the equipment response delay, and simultaneously perform a historical baseline comparison on the reaction phase change characteristic parameters to obtain a verification result, and filter abnormal data based on the verification result to obtain the first production data; bind the equipment ID, the first production data, and the synchronously collected timestamp to generate a dynamic process fingerprint, and construct a verification benchmark library with the equipment ID and timestamp as index keys, wherein the verification benchmark library stores the dynamic process fingerprint and its corresponding sensor raw data; an anomaly detection module, configured to obtain a network transmission data packet and extract a device ID, a declared timestamp, a declared device response delay, and a declared reaction phase change characteristic parameter as second production data; obtain, based on the device ID and the declared timestamp, the first production data corresponding to the index key from a verification reference library, and calculate a device response delay deviation and a phase change characteristic comprehensive deviation; and generate a fuse instruction when the device response delay deviation exceeds a preset device response delay deviation threshold, or the phase change characteristic comprehensive deviation exceeds a preset phase change characteristic comprehensive deviation threshold, or a violation of a device physical limit is detected; The fuse execution module is used to trigger the fuse instruction and execute the corresponding hardware fuse operation through the FPGA; switch control to the shadow controller through a preset hardware state synchronization channel; the shadow controller loads the process state that matches the fuse instruction type and has recently passed the dynamic process fingerprint verification, and executes the state recovery strategy.
9. A chemical enterprise DCS system network security protection system according to claim 8, characterized in that: The verification benchmark library building module also includes: The parameter dynamic update unit is used to calculate the historical equipment response delay average value τ0 and the historical equipment response delay standard deviation σ based on the equipment response delay in the latest N process control cycles as the sample set, where N is the number of days T that the equipment is in operation. n and dynamic thresholds related to the average number of daily operations; When the sample size does not reach the minimum statistical size N min When the preset initial response delay parameter τ is used ′ 0 and σ ′ ; τ0 and σ are updated after completing M valid operations, where M is the baseline update trigger frequency generated based on the sample set size N and the average daily number of operations.
10. A chemical enterprise DCS system network security protection system according to claim 9, characterized in that: The anomaly detection module includes: Deviation calculation unit, used to parse network transmission data packets, obtain device ID, declared timestamp t n , declared phase change duration Δt k , declared device response delay τ n , the declared phase change characteristic parameters constitute the second production data; the declared phase change characteristic parameters include temperature change acceleration ε n and the pressure-viscosity coupling coefficient K n ; According to the device ID and the declared timestamp t n , get the index key device ID and declared timestamp t in the verification benchmark library n The corresponding first production data; including the device response delay τ m , temperature change acceleration ε m and the pressure-viscosity coupling coefficient K m ; According to the second production data and the first production data, the device response delay deviation Δτ is obtained by a first deviation formula; the first deviation formula is: Δτ=|τ n ―t m |; The comprehensive deviation Δθ of the phase change characteristic is obtained by the second deviation formula; the second deviation formula is: Wherein, ε0 is the rated temperature acceleration of the equipment, K0 is the viscosity coefficient under standard working conditions; Multi-level fuse decision unit, used when τ n >τ max The second fuse instruction is generated when τ max The maximum allowable delay marked on the equipment nameplate; When Δτ>δ or Δθ>ω, a third fuse instruction is generated, where δ is a preset device response delay deviation threshold, and ω is a preset phase change characteristic comprehensive deviation threshold; When the temperature changes the acceleration ε n <ε th , determined to be the exothermic phase transition acceleration period; where ε th is the exothermic reaction acceleration threshold; if τ is detected during the exothermic phase transition acceleration period n <γτ m , generating the first fuse instruction, where γ is the threshold value of the shortening ratio of the heat release period delay; When ε n >ε tl , determined to be the endothermic phase transition acceleration period; among them, ε tl is the endothermic reaction acceleration threshold; if τ is detected during the endothermic phase transition acceleration period n >ητ m , generating a second fuse instruction; wherein η is the threshold value of the delay growth ratio of the endothermic period; When the turbidity NTU n >NTU th When |K n ―K m |>λK m or pressure-viscosity coupling coefficient Generate the third fuse instruction; where λ is the crystal characteristic deviation coefficient, K min is the lower limit of the normal range of the pressure-viscosity coupling coefficient, K max It is the upper limit of the normal range of the pressure-viscosity coupling coefficient.