Information physical system security protection method based on measurement output watermark coding

By adopting measurement output watermark coding technology in cyber-physical systems and encrypting the watermark signal using Huffman coding and permutation-transformation framework, the problems of replay attack and erroneous data injection attack are solved, the optimal performance and privacy protection of the control system are achieved, and the consumption of network bandwidth resources is reduced.

CN120729624AActive Publication Date: 2025-09-30NORTHEASTERN UNIV CHINA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511171326.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-21
Publication Date
2025-09-30
Estimated Expiration
2045-08-21

AI Technical Summary

Technical Problem

When existing cyber-physical systems (CPS) face replay attacks, the existing watermarking strategy leads to control performance loss and cannot effectively identify erroneous data injection attacks, and network bandwidth resources are seriously wasted.

Method used

A measurement output watermark coding method is adopted to construct a cyber-physical system model through the Kalman filter and the chi-square detector. The watermark signal is encrypted using Huffman coding and the permutation-transformation framework to achieve rapid generation and removal of watermarks, reduce the transmission signal capacity, and generate the optimal control input signal in the control system.

Benefits of technology

Effectively identify replay attacks and false data injection attacks, reduce network bandwidth resource consumption, while maintaining the optimal performance of the control system and achieving privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729624A_ABST
    Figure CN120729624A_ABST
Patent Text Reader

Abstract

The invention discloses an information physical system safety protection method based on measurement output watermark coding, and relates to the technical field of control system safety. According to the method, a chi-square detector is helped to identify replay attacks and error data injection attacks, the method is designed based on a watermark encryption technology, a watermark element set is constructed, and watermark elements are selected from the watermark element set with equal probability, so that the aim of quickly and circularly generating watermarks is fulfilled. Sensor measurement data is marked by a randomly generated watermark, and is transmitted in a network in a ciphertext form after being coded. And the data transmission quantity can be effectively reduced while the data privacy is ensured by the safe Huffman coding. Compared with a protection strategy of adding a watermark into a control input signal, the method has more excellent performance in the aspect of identifying the replay attack, and due to the fact that the introduced watermark can be completely removed, zero control performance loss can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of control system security technology, and in particular relates to a cyber-physical system security protection method based on measurement output watermark coding. Background Art

[0002] The advancement of information technology has enabled the continuous enrichment and improvement of the capabilities of cyber-physical systems (CPSs), which integrate sensing, computing, and communications. These systems have found widespread application in areas such as smart grids, intelligent transportation, and smart healthcare. However, in open network environments, the security of CPSs is facing increasingly severe challenges. In recent years, security vulnerabilities in the CPS network layer have been increasingly discovered. By tampering with sensor measurement or control signals exposed to the transmission network, attackers can cause control systems to deviate from normal operation, thereby triggering a series of security incidents.

[0003] Replay attacks, a representative type of attack, can deceive existing, widely used chi-square detectors by monitoring sensor measurement signals transmitted across the network and replaying this historical data to the control system. This attack strategy eliminates the need for attackers to design specific attack signals targeting the control system. Simply by monitoring and replaying the control system's historical sensor measurement data, attackers can achieve their attack objectives with relative ease, thereby threatening the security of cyber-physical systems. Because the attacker's replayed data is derived from real measurement signals, the statistical characteristics of the detection residual probability distribution before and after the attack are identical when the control system reaches a stable state. Consequently, existing chi-square detectors are unable to detect replay attacks.

[0004] To prevent replay attacks, the current solution is to add a perturbation signal to the CPS control input signal. This random perturbation signal, called a watermark, disrupts the static characteristics exhibited by the cyber-physical system after it reaches a stable state. Because the control watermarks added at different times are randomly generated, if the historical sensor measurement signals are replayed by an attacker, the probability distribution statistics of the detection residuals will be affected by the watermark's interference. In this case, replay attacks can be detected and verified using a chi-square detector, allowing them to be identified.

[0005] A control input watermarking strategy can assist the chi-square detector in identifying replay attacks. However, this approach comes at the expense of some system control performance. Since the watermark itself is a perturbation signal to the control system, its introduction inevitably has a negative impact on control system performance. The SCI research paper "Secure control against replay attacks" (In 2009 47th annual Allerton conference on communication, control, and computing (Allerton), pages 911-918) demonstrates the loss of system control performance caused by the introduction of watermarks. To minimize the frequency of watermarking, current improvements involve combining event-triggered technology to switch the watermark injection from continuous to intermittent. The SCI research paper "Recursive watermarking-based transient covert attack detection for the industrial CPS" (IEEE Transactions on Information Forensics and Security, 18:1709-1719, 2023) proposes an event-triggered control input watermarking strategy. This approach achieves replay attack detection while alleviating the degradation of system control performance to a certain extent.

[0006] However, the above approach cannot fundamentally address the problem of system control performance loss. Because the watermark added to the control input signal cannot be removed before attack detection is complete, system control performance loss is inevitable. In this case, the system control signal is suboptimal. Furthermore, to balance attack detection and system control performance, the watermark covariance must be kept within a certain range. Otherwise, even in the absence of an attack, the system's control performance will plummet, a level unacceptable to system administrators. Summary of the Invention

[0007] In response to the shortcomings of the existing technology, the present invention provides a cyber-physical system (CPS) security protection method based on measurement output watermark coding to meet the security requirements of cyber-physical systems, so as to solve the shortcomings of the existing CPS in detecting replay attacks, and at the same time provide the ability to identify false data injection (FDI) attacks. The watermark coding method designed by the present invention can effectively reduce the transmission signal capacity, save network bandwidth resources, and provide privacy protection for cyber-physical systems.

[0008] The technical solution of the present invention is:

[0009] A cyber-physical system security protection method based on measurement output watermark coding comprises the following steps:

[0010] Assuming that the cyber-physical system is equipped with a Kalman filter and a control system, an operation model of the cyber-physical system is constructed; the Kalman filter is used to perform an unbiased estimate of the state of the control system based on the operation model of the cyber-physical system to obtain a posterior state estimate of the control system at the current moment; the control system is used to obtain an optimal control input signal based on the posterior state estimate of the control system at the current moment, thereby achieving control of the cyber-physical system;

[0011] According to the operation model of the cyber-physical system, a chi-square detector is designed to detect whether the control system is subject to replay attacks and false data injection attacks;

[0012] Constructing a basic watermark element set and selecting watermark elements from the basic watermark element set to construct a watermark, adding the watermark to the sensor measurement signal to obtain a watermark fusion signal;

[0013] According to the substitution-transformation framework, the watermark fusion signal is encrypted to obtain an encrypted watermark fusion signal;

[0014] Performing secure Huffman coding on the encrypted watermark fusion signal to obtain a measured output watermark coding signal and sending it to the control system together with a Huffman coding table for secure Huffman coding;

[0015] removing the watermark from the measurement output watermark coded signal according to the received Huffman coding table to obtain a recovered sensor measurement signal;

[0016] Input the recovered sensor measurement signal into the chi-square detector to obtain the chi-square detection value and implement error data injection attack detection and replay attack detection based on the chi-square detection value;

[0017] When no replay attack or false data injection attack is detected, the control system generates the optimal input control signal based on the recovered sensor measurement signal to control the cyber-physical system.

[0018] Furthermore, the operation model of the cyber-physical system is:

[0019] (1);

[0020] (2);

[0021] in, It is the cyber-physical system in The state vector at time t, It is the cyber-physical system in The state vector at time t, and are all integers, representing the dimension of the cyber-physical system state vector and the running time of the cyber-physical system respectively; is the control input signal, Is an integer that represents the dimension of the control input signal; yes The process noise at the moment, yes dimensional system matrix, yes dimensional control matrix; the initial state vector and process noise are assumed to be independent Gaussian random variables, and , represents a Gaussian distribution, is the initial state vector The mean of and Represent the initial state vectors and process noise The covariance matrix of the Gaussian distribution it obeys; is the sensor measurement signal, is an integer representing the dimension of the sensor measurement signal, is the measurement matrix, is the initial state vector and process noise Gaussian measurement noise that is independent of each other, is the covariance matrix of the Gaussian distribution obeyed by the Gaussian measurement noise.

[0022] Furthermore, the chi-square detector is described as:

[0023] (16);

[0024] in, is an integer representing the size of the detection window of the chi-square detector, represents the chi-square test value, is an integer variable representing the time; for The sensor measurement signal at the moment, for Prior state estimation of the control system at each moment, is the inverse covariance matrix of the detection residuals under no-attack conditions.

[0025] Furthermore, the basic watermark element set is expressed as , which includes several watermark elements, is a positive real number, is a positive integer;

[0026] The method of selecting watermark elements from the basic watermark element set to construct a watermark is specifically as follows: randomly selecting a number of watermark elements with equal probability to construct a watermark;

[0027] The watermark fusion signal is expressed as:

[0028] (18);

[0029] in, represents the watermark fusion signal, is a static template matrix, yes Always add sensor measurement signals The watermark in Indicates the first The watermark component added in dimension, The number of the dimension of the sensor's measured signal.

[0030] Furthermore, the watermark fusion signal The encryption method is as follows:

[0031] (19);

[0032] in, is the signal after binary XOR operation, is a binary coded sequence, symbol Represents a binary exclusive OR operation, represents a binary conversion function;

[0033] Next, the signal after binary XOR operation Perform the permutation operation as shown below:

[0034] (20);

[0035] Among them, the permutation function For use in permutation sequences Under the action of binary XOR operation, the signal Perform a permutation transformation, It is the encrypted watermark fusion signal.

[0036] Furthermore, the Huffman coding table is encrypted by a single table substitution method and then sent to the control system.

[0037] Furthermore, the encrypted watermark fusion signal is securely Huffman-encoded to obtain a measured output watermark coded signal, specifically:

[0038] Fusing the encrypted watermark into the signal Convert to real signal , and according to the Huffman coding table, the real signal Perform secure Huffman coding, where represents the function of converting binary numbers into decimal numbers. The final measurement output watermark encoding signal is expressed as:

[0039] (twenty one);

[0040] in, represents the secure Huffman coding function, Represents the measured output watermark encoded signal.

[0041] Furthermore, the watermark is removed from the measurement output watermark coded signal according to the received Huffman coding table to obtain the restored sensor measurement signal, specifically:

[0042] S1: Decode the measured output watermark code according to the Huffman coding table to obtain the encrypted watermark fusion signal ;

[0043] (twenty two);

[0044] in, is the encrypted watermark fusion signal obtained after decoding, express The inverse function of for The inverse function of

[0045] S2: Perform inverse permutation-transformation operation on the encrypted watermark fusion signal and obtain the signal after binary XOR operation ;

[0046] (twenty three);

[0047] in, The signal obtained by performing the inverse permutation-transformation operation after the binary XOR operation is: express The inverse function of

[0048] S3: From the signal after binary XOR operation Remove the watermark and get the restored sensor measurement signal ;

[0049] (twenty four);

[0050] in, is the sensor measurement signal obtained after removing the watermark, is the static template matrix The inverse matrix of express The inverse function of .

[0051] Furthermore, the method for detecting replay attacks and data injection attacks is specifically as follows: setting an attack detection threshold , once the chi-square test value , then the control system is judged to be under attack and an alarm is issued to the control system. If the chi-square detection value , the alarm will not be triggered.

[0052] Compared with the prior art, the present invention has the following beneficial effects:

[0053] In response to the security needs of information-physical systems, the present invention designs a security protection method for information-physical systems based on measurement output watermark coding, which can help the chi-square detector identify replay attacks and false data injection attacks. The method is designed based on watermark encryption technology. By constructing a watermark element set and selecting watermark elements with medium probability, the purpose of rapid and cyclical watermark generation is achieved. The sensor measurement data is marked with a randomly generated watermark, which is encoded and transmitted in the network in the form of ciphertext. Secure Huffman coding can effectively reduce the amount of data transmission while ensuring data privacy. Compared with the protection strategy of adding watermarks to the control input signal, the method designed by the present invention has better performance in identifying replay attacks. Since the introduced watermark can be completely removed, zero control performance loss can be achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 This is a flowchart of Huffman encoding in an embodiment of the present invention;

[0055] Figure 2 This is a flow chart of a method for measuring and outputting watermark encoding in an embodiment of the present invention;

[0056] Figure 3 1 is a comparison diagram of sensor measurement signals before and after encoding in an embodiment of the present invention;

[0057] Figure 4 1 is a comparison diagram of the number of bits of a transmission signal before and after encoding in an embodiment of the present invention;

[0058] Figure 5 Schematic diagram of the chi-square detection result of replay attack in an embodiment of the present invention. DETAILED DESCRIPTION

[0059] The present invention is described in detail below with reference to the accompanying drawings and embodiments.

[0060] The cyber-physical system security protection method designed by this invention, based on measurement output watermark coding, targets the security characteristics of the control system and utilizes watermark coding technology to achieve the goals of attack detection and privacy protection. Furthermore, the invention can effectively reduce the control system's transmission signal capacity, saving network bandwidth. Specifically, the cyber-physical system security protection method based on measurement output watermark coding includes the following steps:

[0061] Step 1: Assume that a cyber-physical system (CPS) is equipped with a Kalman filter and a control system, and an operation model of the cyber-physical system is constructed. The Kalman filter is used to perform an unbiased estimation of the state of the control system based on the operation model of the cyber-physical system, and obtain the posterior state estimate of the control system at the current moment. The control system is used to obtain the optimal control input signal based on the posterior state estimate of the control system at the current moment, thereby realizing control of the cyber-physical system. The control system includes a linear quadratic Gaussian (LQG) controller, a state estimator, an actuator, and a plant.

[0062] A cyber-physical system (CPS) uses sensors to monitor and adjust its state in real time. The operation of the cyber-physical system can be represented by the following state-space equation, that is, the operation model of the cyber-physical system is:

[0063] (1);

[0064] (2);

[0065] in, It is the cyber-physical system in The state vector at time t, It is the cyber-physical system in The state vector at time t, and are all integers, representing the dimension of the cyber-physical system state vector and the running time of the cyber-physical system respectively; is the control input signal, Is an integer that represents the dimension of the control input signal; yes The process noise at the moment, yes dimensional system matrix, yes dimensional control matrix; the initial state vector and process noise are assumed to be independent Gaussian random variables, that is, and , represents a Gaussian distribution, is the initial state vector The mean of and Represent the initial state vectors and process noise The covariance matrix of the Gaussian distribution it obeys; is the sensor measurement signal, is an integer representing the dimension of the sensor measurement signal, is the measurement matrix, is the initial state vector and process noise Gaussian measurement noise that is independent of each other, is the covariance matrix of the Gaussian distribution obeyed by the Gaussian measurement noise;

[0066] The Kalman filter is used to make an unbiased estimate of the state of the control system, specifically:

[0067] The iterative estimation process of the Kalman filter is expressed as:

[0068] (3);

[0069] (4);

[0070] (5);

[0071] (6);

[0072] (7);

[0073] in, express The posterior state estimate of the control system at each moment, and Respectively and Prior state estimation of the control system at each moment, express The error covariance of the posterior state estimate of the control system at that moment, and Respectively and The error covariance of the prior state estimate of the control system at that moment, express The Kalman filter gain at time , express dimensional identity matrix, represents the inverse of the matrix, Represents the transpose of a matrix; , , , and As defined above, without loss of generality, the initial prior state estimate of the control system is set to , under the condition that the control system can be detected, the gain of the Kalman filter will quickly converge to a stable value after a finite number of iterations. To this end, the Kalman gain that converges to the stable state is defined as:

[0074] (8);

[0075] in, represents the Kalman gain for convergence to a stable state, , in this case, the estimation of the control system state (a priori state estimation and a posteriori state estimation) is expressed as:

[0076] (9);

[0077] (10);

[0078] The optimal control input signal is obtained by using the linear squared Gaussian (LQG) controller in the control system:

[0079] Specifically, the optimization objective function of the linear squared Gaussian (LQG) controller is expressed as:

[0080] (11);

[0081] in, is the optimization objective function of the linear squared Gaussian (LQG) controller, and are all positive semidefinite matrices, is an integer representing the total number of moments, represents the expectation of a random variable;

[0082] The optimal solution of the optimization objective function of the above linear square Gaussian (LQG) controller, that is, the optimal control input signal, is expressed as:

[0083] (12);

[0084] (13);

[0085] in, Represents the optimal control input signal, the matrix To satisfy the following solution of the Riccati equation:

[0086] (14);

[0087] The optimal control input signal Under the determined conditions, the optimization objective function of the linear square Gaussian (LQG) controller is further expressed as:

[0088] (15);

[0089] in, represents the trace of the matrix, is the optimal control input signal The value of the optimization objective function of the linear squared Gaussian (LQG) controller under;

[0090] Step 2: Design a chi-square detector based on the operation model of the cyber-physical system;

[0091] In the present invention, the chi-square detector is described as:

[0092] (16);

[0093] in, is an integer representing the size of the detection window of the chi-square detector, represents the chi-square test value, is an integer variable representing the time; for The sensor measurement signal at the moment, for Prior state estimation of the control system at each moment, is the inverse covariance matrix of the detection residual under no-attack conditions; without loss of generality, the attack detection threshold is set by the control system manager ,once , then the chi-square detector will determine that the control system is under attack and send an alarm to the control system. , the alarm will not be triggered;

[0094] Replay attack strategy analysis: The type of replay attack considered in the present invention is a more concealed discontinuous replay attack. Under this attack strategy, the attacker splits the entire replay attack task into several subtasks, which are implemented by corresponding sub-attacks. Before the attack begins, the attacker will monitor the transmission network of the control system and record enough sensor measurement signals as replay signal sources. During the attack execution phase, each sub-attack is activated in turn. After each sub-attack task is completed, the replay attack is stopped immediately. A random time interval will be maintained between any two sub-attacks to conceal the attack behavior. When all subtasks are completed, the entire replay attack task is also completed. For a discontinuous replay attack, the duration of a sub-attack can be expressed as:

[0095] (17);

[0096] in, is an integer representing the duration of a sub-attack; It is an integer that represents the actual execution time of the sub-attack, which is related to the specific sub-task; is an integer random variable, used to represent the time interval between two adjacent sub-attacks;

[0097] Step 3: Construct a basic watermark element set and select watermark elements from the basic watermark element set to construct a watermark, add the watermark to the sensor measurement signal, and obtain a watermark fusion signal;

[0098] The watermark required in the embodiment of the present invention can be generated cyclically and reused. The basic watermark element set is represented as , which includes several watermark elements, is a positive real number, is a positive integer;

[0099] The method of selecting watermark elements from the basic watermark element set to construct a watermark is specifically as follows: randomly selecting a number of watermark elements with equal probability to construct a watermark;

[0100] The watermark fusion signal is expressed as:

[0101] (18);

[0102] in, represents the watermark fusion signal, is a static template matrix, which is used to further hide the real sensor measurement signal. yes Always add sensor measurement signals The watermark in Indicates the first The watermark component added in dimension, The number of the dimension of the sensor's measurement signal;

[0103] Step 4: According to the Permutation-Diffusion framework, the watermark fusion signal Encryption is performed to obtain an encrypted watermark fusion signal to effectively protect the privacy of the control system;

[0104] The watermark fusion signal The encryption method is as follows:

[0105] (19);

[0106] in, is the signal after binary XOR operation, is a binary coded sequence that is secret from the attacker, symbol Represents a binary exclusive OR operation, Represents a binary conversion function. After conversion, the watermark fusion signal Each decimal digit is represented by a set of 4-bit binary numbers. Specifically, the corresponding relationship of binary conversion is shown in the following table;

[0107] Table I Binary conversion comparison table

[0108] 0000-1001 1010 1111 1110 0-9 Distinguish between integers and decimal places ‘+’ ‘-’

[0109] Next, the signal after binary XOR operation Perform the permutation operation as shown below:

[0110] (20);

[0111] Among them, the permutation function For use in permutation sequences Under the action of binary XOR operation, the signal Perform substitution transformation, and obtain the encrypted watermark fusion signal after the above substitution-transformation operation , the real sensor measurement signal The information is therefore hidden;

[0112] Step 5: Fusion signal with encrypted watermark Perform secure Huffman coding to obtain a measured output watermark coded signal and send it to a control system together with a Huffman coding table for secure Huffman coding;

[0113] like Figure 1As shown in Figure 1, Huffman coding is an optimal coding scheme that can effectively reduce the capacity of network transmission signals. Since this coding method has the prefix-free feature, the control system (receiving end) can immediately decode the code element to obtain the unique original signal after receiving it.

[0114] In this invention, the Huffman coding table is encrypted using a single-table substitution method before being sent to the control system (receiving end). This is called secure Huffman coding. In this case, if the transmitted signal is tampered with by an attacker, decoding may become impossible, and the attacker's destructive behavior will be exposed.

[0115] like Figure 2 As shown, in the present invention, the encrypted watermark is fused into the signal Convert to real signal , and according to the Huffman coding table, the real signal Perform secure Huffman coding, where Represents a function that converts a binary number into a decimal number. For example, for the symbols and frequencies given in Table II below, the number of code elements saved after secure Huffman coding is .

[0116] Table II: Example of secure Huffman coding

[0117] symbol 0 1 2 3 4 5 6 7 8 9 frequency 3 2 0 8 2 1 5 2 4 6 coding 1001 0000 100000 11 10001 100001 101 0001 001 01

[0118] Based on the above security operation process, the final measurement output watermark encoding signal is expressed as:

[0119] (twenty one);

[0120] in, represents the secure Huffman coding function, It represents the measured output watermark coded signal. From Table II, it can be noted that the data obtained after secure Huffman coding is a digital signal composed of 0-1. This digital signal is transmitted through the network layer and is decrypted after reaching the control system (receiving end);

[0121] Step 6: Remove the watermark from the measured output watermark coded signal according to the received Huffman coding table to obtain the recovered sensor measurement signal;

[0122] Step 6.1: Decode the measured output watermark code according to the Huffman coding table to obtain the encrypted watermark fusion signal ;

[0123] (twenty two);

[0124] in, is the encrypted watermark fusion signal obtained after decoding, express The inverse function of for The inverse function of

[0125] Step 6.2: Perform inverse permutation-transformation operation on the encrypted watermark fusion signal and obtain the signal after binary XOR operation ;

[0126] (twenty three);

[0127] in, The signal obtained by performing the inverse permutation-transformation operation after the binary XOR operation is: express The inverse function of

[0128] Step 6.3: From the signal after binary XOR operation Remove the watermark and get the restored sensor measurement signal ;

[0129] Specifically, the control system performs the following operations to eliminate the interference of the watermark on the sensor measurement signal:

[0130] (twenty four);

[0131] in, is the sensor measurement signal obtained after removing the watermark, is the static template matrix The inverse matrix of express The inverse function of

[0132] It can be seen that if there is no attack, the control performance of the control system will not be lost, and the control input signal will always be the optimal control input signal. ;

[0133] Step 7: Input the recovered sensor measurement signal into the chi-square detector to obtain the chi-square detection value and implement replay attack detection based on the chi-square detection value;

[0134] Analysis of watermark statistical characteristics: For replay attacks, set The measurement output watermark coded signal at the moment quilt The measurement output of the watermark coded signal at the time history replaced by and are all integers. In this case, the decoding result of the control system is expressed as:

[0135] (25);

[0136] in, Indicates a replay attack Decoded measurement signal at the moment, represents the secure Huffman coding function, express The inverse function of express Watermark of the moment;

[0137] Since the sensor measurement signals at different times are marked with different watermarks, when a replay attack occurs, the decoded measurement signals at the receiving end Decoded measurement signal with real There will be a deviation between express Moment and The difference of the watermark added at the moment, express The watermark at the moment, since the watermark is selected from the basic watermark element set with equal probability, Moment and The probability of the watermark component selected at the moment can be expressed as:

[0138] (26);

[0139] in, express Always select watermark component The probability of express The watermark component of the moment, express Always select watermark component probability;

[0140] In this case, Moment and The difference of the watermark added at the moment The expectation is:

[0141] (27);

[0142] in, express expectations, express expectations, express expectations;

[0143] According to formula (26), the watermark component , The variance of is expressed as:

[0144] (28);

[0145] in, express The variance of express expectations, express The square of the expectation, Represents an integer variable;

[0146] because , is the component of the historical watermark being replayed, so its variance ; Note the weight of the watermark , , and Any two of them are independent of each other, where , and represent two different integers, so, Moment and The difference of the watermark added at the moment The covariance of is:

[0147] (29);

[0148] in, represents the covariance of the random variables, express dimensional identity matrix; the above formula (29) reveals the statistical characteristics of the difference between the watermarks added at different times. Using this statistical characteristic, the replay attack will be able to be identified by the chi-square detector;

[0149] For the convenience of expression, define the following two variables and .in, represents the error introduced by the output watermark coded signal due to the error decoding measurement, express Moment and The moment sensor measures the difference between the signals;

[0150] Set replay attack from When the replay attack is not started, the output watermarked signal is measured can be correctly decoded, and the control system is now The state estimate at time t is expressed as:

[0151] (30);

[0152] Set the attacker to select A historical sensor measurement signal starting at time t is used as the replay signal source. Once the replay attack The moment is started, due to the measurement output watermark coded signal Marked by the watermark, the measurement output watermark encoded signal replayed by the attacker will deviate from the true decrypted signal after decryption. Without loss of generality, define the variable , therefore, the control system state estimation under replay attack is expressed as:

[0153] (31);

[0154] in, Indicates the impact of replay attacks Prior state estimation of the control system at each moment, Indicates the impact of replay attacks The posterior state estimate of the control system at each moment, Indicates the impact of replay attacks Prior state estimation of the control system at each moment, Indicates the impact of replay attacks Control input signal at each moment;

[0155] The state estimates expressed in equations (30) and (31) above can be further iterated to derive The control system state estimate before time;

[0156] Considering that the replay attack is from The state starts at time , so the state estimate and The difference between them is expressed as:

[0157] (32);

[0158] in, is an integer variable, Indicates the impact of replay attacks Prior state estimation of the control system at each moment, express The a priori state estimation of the control system at the moment; the above formula (32) reveals the impact of the replay attack on the state estimation of the control system. When the control system reaches a stable state, the added watermark will have a decisive impact on the state estimation performance. Based on formula (32), the control system state estimation and The difference between them is further expressed as:

[0159] (33);

[0160] in, is an integer variable, Indicates the impact of replay attacks Prior state estimation of the control system at each moment, express The a priori state estimate of the control system at that moment; note that due to the error decoding is from The moment begins, so Established, that is to say, The control system state estimate before time will not be disturbed by the replay attack. In this case, the detection residual of the chi-square detector is expressed as:

[0161] (34);

[0162] Under the influence of replay attacks, the probability distribution of the above detection residuals will be disturbed, so The chi-square test value at the moment is expressed as:

[0163] (35);

[0164] in, express Chi-square test value at time; is an integer variable, the set , represents the set of moments of the entire detection, Indicates the impact of replay attacks A priori state estimation of the moment-to-moment control system;

[0165] According to formula (34), based on the variable Definition of , detection residual Further expressed as:

[0166] (36);

[0167] Combining the above formulas (35) and (36), the chi-square detection value under the influence of replay attack is:

[0168] (37);

[0169] in, is a vector, specifically, , , , is an integer variable; the parameter in formula (37) ;

[0170] Comparison of replay attack detection performance with control input watermark strategy: To compare the measurement output watermark encoding method designed by the present invention with the existing control input watermark strategy, a virtual system is introduced. This virtual system can be regarded as the time delay of the real control system, which is expressed as:

[0171] (38);

[0172] (39);

[0173] (40);

[0174] (41);

[0175] (42);

[0176] in, , and denote the state vector of the virtual system, the control input signal and the sensor measurement signal, respectively. express The posterior state estimate of the virtual system at time t, and Respectively and The prior state estimate of the virtual system at time t, and denote the process noise and measurement noise of the virtual system respectively; the initial state of the virtual system is assumed to be and ,in Indicates the initial state of the virtual system at time 0, represents the initial priori state estimate of the virtual system at time 0. Prior state estimate at time Expressed as:

[0177] (43);

[0178] For virtual systems, when replay attacks are launched from Lasts until At time , the disturbed virtual system state estimate is expressed as:

[0179] (44);

[0180] Among them, integer variables , express The prior state estimate of the virtual system that is constantly perturbed by the replay attack, express The prior state estimate of the virtual system that is disturbed by the replay attack at any moment; therefore, for a discrete linear time-invariant system, based on the iterative equations given by Equations (43) and (44), the virtual system state estimate is and The difference between them is expressed as:

[0181] (45);

[0182] in, express The prior state estimate of the virtual system at time t, express A priori state estimation of a virtual system that is constantly perturbed by replay attacks;

[0183] For the sake of simplicity, let , then the detection residual of the chi-square detector is Expressed as:

[0184] (46);

[0185] Due to replay attacks from Starts immediately and continues until At this moment, Equation (46) can be further rewritten as:

[0186] (47);

[0187] Considering that the virtual system can be regarded as the time delay of the real control system, therefore:

[0188] (48);

[0189] From the definition of the virtual system and based on formula (48), we can further deduce:

[0190] (49);

[0191] make , based on the probability statistical characteristics of watermark, . Note that the residual is independent of Yes, therefore The covariance of is expressed as:

[0192] (50);

[0193] Given the watermark component added to the sensor measurement signal and are independent of each other, , and represent two different integers, so The covariance of is expressed as:

[0194] (51);

[0195] For the convenience of expression, the following variables are defined:

[0196] (52);

[0197] in, is an integer variable, ;

[0198] Substituting equations (51) and (52) into equation (50), we obtain: (53);

[0199] It can be seen from formula (53) that for replay attacks, the measurement output watermark encoding method designed by the present invention has better attack detection performance than the control input watermark strategy. Because the watermark introduced by the present invention can be completely removed, the watermark added to the measurement signal will not destroy the control performance of the system. In this case, by adjusting the watermark parameter , the replay attack will be accurately identified by the chi-square detector;

[0200] Step 8: Input the recovered sensor measurement signal into the chi-square detector to obtain the chi-square detection value and implement the error data injection attack detection based on the chi-square detection value;

[0201] FDI attack detection performance analysis: The method designed by the present invention also has good attack detection performance for false data injection (FDI) attacks. , , , and Without being leaked, the FDI attack on the measured output watermarked signal is expressed as:

[0202] (54);

[0203] in, represents the measurement output watermark coded signal injected by FDI attack, Indicates FDI attack injection. In order to evade the chi-square detector, the attacker needs to ensure the chi-square detection index Does not exceed the detection threshold :

[0204] (55);

[0205] in, is an integer variable, represents the chi-square detection index under FDI attack, The sensor measurement signal decoded under FDI attack, Control systems under FDI attack Prior state estimate at time t;

[0206] Based on the watermark encoding method designed by the present invention, the FDI attack process shown in formula (54) is further expressed as:

[0207] (56);

[0208] However, due to the secret parameter , , , and Unknown, FDI attack will be detected by Chi-square detector. This is due to the following reasons: First, the attacker outputs the watermark coded signal to the measurement Attack signal injected into It will destroy the Huffman coding rules and may cause decoding confusion. Once the decoding is confused and wrong, the FDI attack will be easily identified. Secondly, even if the signal after the FDI attack can be decoded, due to the secret parameters , , , and Unknown, injection attack under the substitution-transformation protection framework designed by this invention The disturbance to the control system state estimate cannot be predicted, so it is difficult for the attacker to conceal the attack and sabotage behavior; in this case, the FDI attack will be captured by the chi-square detector;

[0209] Analysis of the interference of FDI attack on control performance when secret parameters are leaked: Assume that the attacker obtains the secret parameters through some method , , , and If the attacker can only tamper with the sensor measurement signal, the control performance of the control system will be weakened. For the attacker, a feasible attack strategy is to disguise the FDI attack as measurement noise. Then, when the secret parameters are leaked, the injection attack is expressed as:

[0210] (57);

[0211] in, represents the injected sensor measurement signal, Indicates an injection attack, , express In this case, the control performance of the control system will decrease. For the convenience of description, define Considering the impact of FDI attacks, The control system state at time t is expressed as:

[0212] (58);

[0213] Without loss of generality, The cost function of the control system at time is defined as:

[0214] (59);

[0215] in, represents the control system cost function at time, represents an integer, represents an integer variable. In this case, the optimization objective function of the LQG controller is , for a certain moment , define the following variables ,and ;

[0216] (60);

[0217] in, represents the sensor measurement signal available to the control system, represents an integer variable; therefore, It represents the system control cost index obtained under the condition of the received sensor measurement signal, which is represented by The definition of , the following recursive expression holds:

[0218] (61);

[0219] Next, we will first prove that the optimal control input signal Next Satisfies the following recursive equation:

[0220] (62);

[0221] Among them, the matrix It is represented by the following recursive expression:

[0222] (63);

[0223] With the matrix Similarly, the matrix It is represented by the following recursive expression:

[0224] (64);

[0225] in, and , express The error covariance of the posterior state estimate of the control system at the moment, the matrix ,when When , the recursive expression (62) holds, set Satisfying formula (62), we now need to prove Based on the above assumptions, we can deduce that:

[0226] (65);

[0227] because and are independent of each other, so The expectation is expressed as:

[0228] (66);

[0229] According to formula (58), we can deduce: (67);

[0230] Substituting equations (66) and (67) into equation (65) above yields:

[0231] (68);

[0232] From the above formula (68), it can be seen that the optimal control input signal of the control system is determined by the last term in formula (68), so the optimal control input signal Expressed as:

[0233] (69);

[0234] Substituting (69) into (65) we obtain: (70);

[0235] because For any positive semidefinite matrix All of them hold true, so we can deduce that: (71);

[0236] in, Indicates that FDI attacks are affecting The covariance of the posterior system state estimation error at time t;

[0237] Then according to The recursive expression (63) is derived as follows:

[0238] (72);

[0239] therefore, Expressed as: (73);

[0240] because , through iteration The recursive expression of derives:

[0241] (74);

[0242] Therefore, the optimization objective function of the LQG controller is expressed as:

[0243] (75);

[0244] The above derivation results show that when secret parameters are leaked, an attacker launching an FDI attack disguised as noise will disrupt the system's control performance. However, because a large-scale FDI attack not only damages the system's control performance but also exposes the attacker's own attack behavior, the security of the control system can still be guaranteed under the protection of the detection mechanism designed by this invention.

[0245] Step 9: When no replay attack or error data injection attack is detected, the control system generates the optimal input control signal based on the recovered sensor measurement signal to control the cyber-physical system.

[0246] To verify the safety performance of the present invention, a simulation test was conducted using MATLAB as the test platform, employing a classic four-cylinder water tank control system as the simulation object. The control system state was the water level in the four-cylinder water tank, and the control signal input was the pressure in the water pump. In the experiment, the present invention set the sampling interval of the sensor measurement signal to 1 second. Specifically, the parameters of the four-cylinder water tank system were quantified as follows:

[0247] (76);

[0248] (77);

[0249] (78);

[0250] The covariance matrices of process noise and measurement noise are , The LQG controller parameters are

[0251] (79);

[0252] The state equilibrium point of the four-cylinder water tank system is:

[0253] (80);

[0254] Figure 3 The changes in the sensor measurement signal before and after encoding are shown. It can be seen that the encoded measurement signal has a strong randomness. Since the watermark is dynamically and randomly selected from the watermark element set with equal probability, the real sensor measurement signal is hidden under the protection of the encoding mechanism. In this case, it will be difficult for an attacker to intercept the watermark encoded signal. The real information of the control system can be inferred from the data, so the privacy of the system can be protected.

[0255] The method designed in the present invention can save the channel bandwidth occupied by the transmission signal. Figure 4 This demonstrates the performance of the present invention in terms of coding efficiency. It can be seen that using the method designed by the present invention, encoding sensor measurement signals can save approximately 20% of information bits. Given the prefix-free nature of Huffman coding, received symbols can be decoded immediately, effectively reducing decoding time. It is worth noting that coding efficiency further improves as the dimensionality of the sensor measurement signal increases.

[0256] In order to verify the detection effect of the measurement output watermark encoding method on replay attack, in the simulation, the attacker is simulated from The historical sensor measurement signals are replayed starting at the moment to fool the chi-square detector. Figure 5 The results of the chi-square detector's detection of replay attacks under the protection of the watermark strategy designed by the present invention are shown. In the simulation, the detection window is set It can be seen that as the watermark parameter As the value of increases, the chi-square detection value will also be improved. In this case, the replay attack will not be able to escape the chi-square detector. It should be noted that since the proposed scheme will not cause the system control performance to degrade, the watermark parameter Can be large enough so that replay attacks will be more easily caught by detectors.

Claims

1. A cyber-physical system security protection method based on measurement output watermark coding, characterized in that: The following steps are involved: Assuming that the cyber-physical system is equipped with a Kalman filter and a control system, an operation model of the cyber-physical system is constructed; the Kalman filter is used to perform an unbiased estimate of the state of the control system based on the operation model of the cyber-physical system to obtain a posterior state estimate of the control system at the current moment; the control system is used to obtain an optimal control input signal based on the posterior state estimate of the control system at the current moment, thereby achieving control of the cyber-physical system; According to the operation model of the cyber-physical system, a chi-square detector is designed to detect whether the control system is subject to replay attacks and false data injection attacks; Constructing a basic watermark element set and selecting watermark elements from the basic watermark element set to construct a watermark, adding the watermark to the sensor measurement signal to obtain a watermark fusion signal; According to the substitution-transformation framework, the watermark fusion signal is encrypted to obtain an encrypted watermark fusion signal; Performing secure Huffman coding on the encrypted watermark fusion signal to obtain a measured output watermark coding signal and sending it to the control system together with a Huffman coding table for secure Huffman coding; removing the watermark from the measurement output watermark coded signal according to the received Huffman coding table to obtain a recovered sensor measurement signal; Input the recovered sensor measurement signal into the chi-square detector to obtain the chi-square detection value and implement error data injection attack detection and replay attack detection based on the chi-square detection value; When no replay attack or false data injection attack is detected, the control system generates the optimal input control signal based on the recovered sensor measurement signal to control the cyber-physical system.

2. The cyber-physical system security protection method based on measurement output watermark coding according to claim 1 is characterized in that: The operation model of the cyber-physical system is: (1); (2); in, It is the cyber-physical system in The state vector at time t, It is the cyber-physical system in The state vector at time t, and are all integers, representing the dimension of the cyber-physical system state vector and the running time of the cyber-physical system respectively; is the control input signal, Is an integer that represents the dimension of the control input signal; yes The process noise at the moment, yes dimensional system matrix, yes dimensional control matrix; the initial state vector and process noise are assumed to be independent Gaussian random variables, and , represents a Gaussian distribution, is the initial state vector The mean of and Represent the initial state vectors and process noise The covariance matrix of the Gaussian distribution it obeys; is the sensor measurement signal, is an integer representing the dimension of the sensor measurement signal, is the measurement matrix, is the initial state vector and process noise Gaussian measurement noise that is independent of each other, is the covariance matrix of the Gaussian distribution obeyed by the Gaussian measurement noise.

3. The cyber-physical system security protection method based on measurement output watermark coding according to claim 1 is characterized in that: The chi-square detector is described as: (16); in, is an integer representing the size of the detection window of the chi-square detector, represents the chi-square test value, is an integer variable representing the time; for The sensor measurement signal at the moment, for Prior state estimation of the control system at each moment, is the inverse covariance matrix of the detection residuals under no-attack conditions.

4. The cyber-physical system security protection method based on measurement output watermark coding according to claim 1 is characterized in that: The basic watermark element set is expressed as , which includes several watermark elements, is a positive real number, is a positive integer; The method of selecting watermark elements from the basic watermark element set to construct a watermark is specifically as follows: randomly selecting a number of watermark elements with equal probability to construct a watermark; The watermark fusion signal is expressed as: (18); in, represents the watermark fusion signal, is a static template matrix, yes Always add sensor measurement signal The watermark in Indicates the first The watermark component added in dimension, The number of the dimension of the sensor's measured signal.

5. The cyber-physical system security protection method based on measurement output watermark coding according to claim 1 is characterized in that: The watermark fusion signal The encryption method is as follows: (19); in, is the signal after binary XOR operation, is a binary coded sequence, symbol Represents a binary exclusive OR operation, represents a binary conversion function; Next, the signal after binary XOR operation Perform the permutation operation as shown below: (20); Among them, the permutation function For use in permutation sequences Under the action of binary XOR operation, the signal Perform a permutation transformation, It is the encrypted watermark fusion signal.

6. The cyber-physical system security protection method based on measurement output watermark coding according to claim 1 is characterized in that: The Huffman coding table is encrypted by a single table substitution method and then sent to the control system.

7. The cyber-physical system security protection method based on measurement output watermark coding according to claim 1 is characterized in that: The secure Huffman encoding is performed on the encrypted watermark fusion signal to obtain the measured output watermark coded signal, specifically: Fusing the encrypted watermark into the signal Convert to real signal , and according to the Huffman coding table, the real signal Perform secure Huffman coding, where represents the function of converting binary numbers into decimal numbers. The final measurement output watermark encoding signal is expressed as: (21); in, represents the secure Huffman coding function, Represents the measured output watermark encoded signal.

8. The cyber-physical system security protection method based on measurement output watermark coding according to claim 1 is characterized in that: The watermark is removed from the measurement output watermark coded signal according to the received Huffman coding table to obtain the restored sensor measurement signal, specifically: S1: Decode the measured output watermark code according to the Huffman coding table to obtain the encrypted watermark fusion signal ; (22); in, is the encrypted watermark fusion signal obtained after decoding, express The inverse function of for The inverse function of S2: Perform inverse permutation-transformation operation on the encrypted watermark fusion signal and obtain the signal after binary XOR operation ; (23); in, The signal obtained by performing the inverse permutation-transformation operation after the binary XOR operation is: express The inverse function of S3: From the signal after binary XOR operation Remove the watermark and get the restored sensor measurement signal ; (24); in, is the sensor measurement signal obtained after removing the watermark, is the static template matrix The inverse matrix of express The inverse function of .

9. The cyber-physical system security protection method based on measurement output watermark coding according to claim 1 is characterized in that: The method for replay attack detection and data injection attack detection is specifically as follows: setting the attack detection threshold , once the chi-square test value , then the control system is judged to be under attack and an alarm is issued to the control system. If the chi-square detection value , the alarm will not be triggered.

Citation Information

Patent Citations

  • Physical watermark detection method for replay attack of industrial control system

    CN114563996A

  • Industrial control system dual-channel false data injection attack detection method

    CN117081780A

  • Watermark Detection Method with Highly ImprovedAbility of Resistance to Sensitivity Attack and TheSystem

    KR1020030077868A

  • System and method for detecting the watermark using decision fusion

    US20120300975A1