Symmetrical encryption-based protocol message tamper-proofing method and system, and medium

By performing message mirroring monitoring and encryption verification in 802.1AS protocol devices, a unified set of security feature parameters is constructed to achieve real-time, quantifiable detection and closed-loop control of protocol messages. This solves the problem of message tampering in 802.1AS time synchronization networks and improves the security and stability of the system.

CN121690518APending Publication Date: 2026-03-17TRANSCEND COMM TIANJIN CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511951919.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-23
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

In existing 802.1AS time synchronization networks, protocol messages are vulnerable to tampering, forgery, and replay attacks. There is a lack of real-time monitoring and quantitative assessment of message integrity and consistency, and the impact of security mechanisms on the time synchronization process has not been effectively evaluated.

Method used

By performing message mirroring monitoring in 802.1AS protocol devices, digest data and encryption verification data are generated and parsed. Field normalization, digest consistency verification, and encryption verification format correction are performed to construct a unified set of protocol message security feature parameters. The anti-tampering consistency coefficient and encryption trust coefficient are calculated by using time window statistics and message-by-message comparison, so as to realize the hierarchical evaluation and closed-loop control of message integrity and encryption link.

Benefits of technology

It enables real-time and quantifiable detection of protocol message tampering, improves the integrity and security of time synchronization messages, eliminates the impact of device implementation differences, ensures the stability and security of the time synchronization system, and avoids the chain reaction of a single anomaly on the synchronization process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121690518A_ABST
    Figure CN121690518A_ABST
Patent Text Reader

Abstract

The invention discloses a protocol message tamper-proofing method and system based on symmetric encryption and a medium, and relates to the technical field of industrial automation Ethernet time synchronization. According to the method, mirror image monitoring is carried out on the message receiving and sending process in the protocol processing process of time synchronization equipment, a protocol message is obtained and analyzed, and the protocol message tamper-proofing effect is achieved; a message abstract and encrypted verification data thereof are generated at a sending end, and a corresponding abstract is obtained through decryption at a receiving end; consistency comparison is carried out on the sending side abstract and the receiving side abstract based on the time window, and a tamper-proof consistency coefficient is calculated to judge the integrity of the protocol message; on the basis that the integrity is qualified, performing difference analysis on an encryption verification result, and calculating an encryption credibility coefficient to evaluate the credibility state of the symmetric encryption link; and further performing coupling calculation to obtain a time synchronization security coupling coefficient, comprehensively evaluating the influence of tamper-proofing and symmetric encryption on the time synchronization operation security, and implementing a security regulation and control strategy according to the influence, thereby improving the security and stability of the time synchronization system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial automation Ethernet time synchronization technology, specifically to a method, system, and medium for preventing protocol message tampering based on symmetric encryption. Background Technology

[0002] With the rapid development of technologies such as the Industrial Internet, intelligent manufacturing, and automotive Ethernet, high-precision time synchronization technology based on Ethernet has been widely used in industrial automation control systems, distributed measurement and control systems, and real-time communication networks. The IEEE 802.1AS protocol, as the core time synchronization protocol in the Time-Sensitive Network (TSN) architecture, achieves high-precision clock synchronization between node devices by electing a master clock and periodically exchanging time information within the network. This is a crucial foundation for ensuring the collaborative operation of distributed systems.

[0003] In existing 802.1AS time synchronization networks, the synchronization accuracy of protocol messages relies primarily on the reliability of the network link and the correct implementation of the devices during transmission, while the security protection of the protocol messages themselves is relatively weak. Especially in complex industrial network environments, 802.1AS protocol messages are vulnerable to security attacks such as tampering, forgery, and replay attacks. Attackers can interfere with the alignment process of master and slave clocks by modifying key time fields in the synchronization messages, leading to a decrease in time synchronization accuracy and even causing security risks such as control logic disorder and system malfunctions.

[0004] Some existing technologies attempt to improve security by introducing encryption or verification mechanisms into time synchronization messages. However, most solutions only focus on a single security dimension, such as simple message verification or static encryption, lacking a systematic assessment of the consistency between the sender and receiver. This makes it difficult to detect in a timely manner whether messages have been tampered with or abnormally copied during transmission. Furthermore, existing technologies typically do not quantitatively assess the impact of the security mechanism itself on the time synchronization process. When security protection strategies are abnormal or misconfigured, they may actually negatively affect the stability and real-time performance of time synchronization.

[0005] Therefore, existing 802.1AS time synchronization systems generally have the following shortcomings: First, they lack real-time monitoring and quantitative evaluation methods for the integrity and consistency of protocol messages, making it difficult to identify the risk of protocol message tampering in a timely manner; second, they lack a dynamic evaluation mechanism for the credibility of symmetric encryption verification results, making it impossible to effectively distinguish between normal encryption deviations and abnormal attack behaviors; and third, they lack technical solutions for comprehensive evaluation and closed-loop control of the combined impact of multiple security mechanisms from the perspective of overall time synchronization. Summary of the Invention

[0006] To address the shortcomings of existing technologies, this invention provides a method, system, and medium for preventing protocol message tampering based on symmetric encryption, thereby solving the problems mentioned in the background art.

[0007] To achieve the above objectives, the present invention provides the following technical solution: a method for preventing tampering of protocol messages based on symmetric encryption, comprising the following steps:

[0008] Step 1: By mirroring the message sending and receiving process in the protocol processing of the 802.1AS time synchronization device, the original protocol message data packet p is obtained; it is parsed to form a complete message content data set Dp, and message digest data Hs and its corresponding encryption verification data Es are generated at the sending end. At the receiving end, the encryption verification value Er is parsed and decrypted to obtain the digest data Hr.

[0009] Step 2: By performing field normalization, digest consistency constraint, encryption verification format correction and length alignment on the collected relevant data, differences in message type, device implementation and calculation rules are eliminated, forming a set of message content feature parameters DpB, sender digest feature parameter HsB, receiver digest feature parameter HrB, sender encryption verification feature parameter EsB and receiver encryption verification feature parameter ErB after field standardization, and uniformly encapsulating and constructing a set of protocol message security feature parameters TFp;

[0010] Step 3: Based on the protocol message security feature parameter set TFp, count the number of protocol message samples N according to the time window, and perform a message-by-message consistency comparison of the digest feature parameters HsB and HrB on the sending side and the receiving side to calculate the anti-tampering consistency coefficient FYX; and compare it with the anti-tampering consistency threshold Fth to determine whether the protocol message integrity is qualified. If it is qualified, generate a consistency pass mark result; if it is not qualified, execute abnormal message discarding, event logging and alarm.

[0011] Step 4: Based on the consistency identification result, filter protocol message samples within the same time window from the protocol message security feature parameter set TFp, calculate the number M of encryption evaluation protocol message samples, and perform message-by-message difference calculation on the encryption verification feature parameters EsB and ErB of the sending and receiving sides. Further calculate the encryption trust coefficient JKX and compare it with the encryption trust threshold Jth to determine whether the symmetric encryption link trust is qualified. If it is not qualified, perform key adjustment and trust level control.

[0012] Step 5: By multiplying and coupling the anti-tampering consistency coefficient FYX and the encryption trust coefficient JKX, the time synchronization security coupling coefficient TOX is obtained and compared with the comprehensive security threshold Tth to evaluate the comprehensive impact of anti-tampering and symmetric encryption on 802.1AS time synchronization; and strategies for adjusting the synchronization period parameter, recalculating node security weights, and periodic re-evaluation are given.

[0013] Preferably, step one includes:

[0014] S11. In an industrial automation Ethernet time synchronization network, within a device running the 802.1AS protocol, a message mirroring collection point is set at the message sending and receiving interface of the protocol processing process. Through kernel-level hook interception technology of the protocol stack, the 802.1AS protocol messages entering the sending queue and completing the receiving and parsing are monitored in real time, and the binary content of the message is completely copied to form the original protocol message data packet p.

[0015] S12. Based on the original protocol message data packet p, the protocol field parsing engine parses and extracts the fields involved in the time synchronization calculation field by field according to the 802.1AS message format specification. The parsed field values ​​are then reassembled according to the message field order to form a complete message content data set Dp.

[0016] S13. Based on the complete message content data set Dp, the corresponding message digest value is obtained by calling the hash calculation module inside the protocol device to perform a fixed hash algorithm operation, and the digest value is recorded to form digest data Hs;

[0017] S14. Based on the digest data Hs, the symmetric encryption operation component built into the protocol device obtains the fixed length L of the encryption verification value determined by the current symmetric encryption algorithm according to the symmetric encryption algorithm type and its corresponding output length parameter pre-configured in the current communication protocol; under the constraint of the fixed length L, the digest data Hs is encrypted using the pre-configured symmetric encryption key to generate an encryption verification value of length L, and the current encryption operation result is collected to form the sending-side encryption verification data Es;

[0018] S15. In the protocol processing process at the receiving end, the TLV field of the received 802.1AS protocol message is parsed, and the encrypted verification data is extracted from the verification TLV field at the end of the protocol message to form the encrypted verification value Er on the receiving side.

[0019] S16. Based on the receiving side encryption verification value Er, perform decryption operation through the symmetric decryption operation component in the receiving device to obtain the corresponding decryption digest value, and collect the current decryption result to form decryption digest data Hr.

[0020] Preferably, step two includes:

[0021] S21. Based on the complete message content data set Dp, a field-level normalization mapping processing method is adopted. According to the fixed order and field length specification of the 802.1AS protocol fields, the field values ​​corresponding to different message lengths and different message types are uniformly scaled to eliminate the influence of message length differences and message type differences, and obtain the message content feature parameter set DpB after field standardization.

[0022] S22. Based on the digest data Hs, the hash input consistency constraint processing method is adopted to perform consistency verification and normalization processing on the input order of fields participating in hash calculation, field concatenation method and filling rules, so that the mapping relationship between the digest data Hs and the complete content data set Dp of the protocol message remains stable, and the sender digest feature parameter HsB after consistency constraint is obtained.

[0023] S23. Based on the decrypted digest data Hr, the hash result alignment processing method is adopted. The structural consistency correction is performed on the decrypted digest result according to the same field concatenation order and digest generation rules as the sending side, and the receiver digest feature parameter HrB after consistency constraint is obtained.

[0024] S24. Based on the encrypted verification data Es from the sending side, the encryption result length standardization and format correction processing method is adopted to uniformly process the bit length, encoding format and padding status of the encrypted verification value, eliminate the fluctuation of the encryption result caused by the differences in implementation of different devices, and obtain the standardized encrypted verification feature parameter EsB from the sending side.

[0025] S25. Based on the received-side encryption verification value Er obtained in step one, the encryption verification result consistency mapping processing method is used to unify the format and align the length of the encrypted verification value extracted from the received side, so that it is in the same computation space as the transmitted-side encryption verification data Es, and the normalized received-side encryption verification feature parameter ErB is obtained.

[0026] S26. The standardized message content feature parameter set DpB, the consistent sender digest feature parameter HsB, the consistent receiver digest feature parameter HrB, the standardized sender encryption verification feature parameter EsB, and the standardized receiver encryption verification feature parameter ErB are uniformly encapsulated and indexed to construct the protocol message security feature parameter set TFp.

[0027] Preferably, step three includes:

[0028] S31. Based on the protocol message security feature parameter set TFp, the time window segmentation statistical method is adopted to group the collected protocol messages according to the preset time window, count the number of protocol messages participating in the calculation in each time window, and obtain the number of protocol message samples N corresponding to the current time window.

[0029] S32. Based on the sender-side digest feature parameter HsB and the receiver-side digest feature parameter HrB after consistency constraints, a message-by-message digest consistency comparison method is used to match and determine the consistency judgment result of the protocol message corresponding to the i-th protocol message one by one, and the HsB and HrB corresponding to the i-th protocol message are obtained. .

[0030] Preferably, step three further includes:

[0031] S33. Based on the obtained number of protocol message samples N corresponding to the current time window and the consistency judgment result of the protocol messages. The anti-tampering consistency coefficient FYX is calculated and obtained by using a statistical averaging algorithm and after dimensionless processing.

[0032] S34. By setting a preset anti-tampering consistency threshold Fth, and comparing the anti-tampering consistency coefficient FYX with the anti-tampering consistency threshold Fth, the first evaluation result is obtained, including:

[0033] When the anti-tampering consistency coefficient FYX ≥ the anti-tampering consistency threshold Fth, it indicates that the current network is in an integrity qualified state, no security risk of protocol messages being tampered with is detected, a consistency pass mark result is generated, and the process proceeds to step four.

[0034] When the anti-tampering consistency coefficient FYX < the anti-tampering consistency threshold Fth, it indicates that the current network is in an integrity failure state, there is an inconsistency in the protocol message digest within the current time window, and there is a security risk of protocol message tampering. This triggers the first warning instruction and generates the first strategy: based on the consistency judgment result corresponding to the protocol message. ,right The protocol messages are discarded to prevent abnormal messages from affecting the time synchronization process. Based on the index information and time window information of the abnormal protocol messages, the protocol message tampering event log is recorded and corresponding security alarm information is generated. The protocol message security feature parameter set TFp and the anti-tampering consistency coefficient FYX in the current time window are encapsulated and saved as intermediate result data for integrity assessment. After the abnormal message is handled, the next time window is entered, the anti-tampering consistency coefficient FYX value is updated, and periodic consistency recalculation is performed until the anti-tampering consistency coefficient FYX ≥ the anti-tampering consistency threshold Fth.

[0035] Preferably, step four includes:

[0036] S41. Based on the protocol message security feature parameter set TFp corresponding to the consistency pass identification result, the time window alignment filtering method is used to extract the protocol message samples that participate in the calculation of the second encryption trust coefficient within the same time window, and the number of protocol message samples is counted to obtain the number M of encryption evaluation protocol message samples.

[0037] S42. Based on the normalized sending-side encryption verification feature parameter EsB and the normalized receiving-side encryption verification feature parameter ErB, a byte-level difference calculation method is used to perform message-by-message difference calculation on the EsB and ErB corresponding to the j-th protocol message within the same time window, and obtain the encryption verification difference value corresponding to the protocol message. .

[0038] Preferably, step four further includes:

[0039] S43. By obtaining the number M of encrypted evaluation protocol message samples and the corresponding encryption verification difference value of the protocol messages. Combining the fixed length L of the encryption verification value determined by the symmetric encryption algorithm, the normalized difference reverse mapping calculation method is used. After dimensionless processing, the encryption credibility coefficient JKX is calculated and obtained.

[0040] S44. By setting a preset encryption trust threshold Jth, and comparing the encryption trust coefficient JKX with the encryption trust threshold Jth, the second evaluation result is obtained, including:

[0041] When the encryption trust coefficient JKX ≥ the encryption trust threshold Jth, it indicates that the trust of the symmetric encryption link is qualified within the current time window, and it will be continuously monitored.

[0042] When the encryption trustworthiness coefficient JKX < the encryption trustworthiness threshold Jth, it indicates that the trustworthiness of the symmetric encryption link within the current time window is unqualified, there are abnormal differences in the encryption verification results within the current time window, and there is a risk of encryption verification forgery or replay attacks in the network. This triggers a second warning instruction and generates a second strategy: Initiate a symmetric encryption key reconfiguration or key rotation strategy to update the symmetric encryption key used in the current time synchronization link; temporarily lower the time synchronization trust level of the protocol message source node with abnormal differences, restricting its participation in master clock election; encapsulate the protocol message security feature parameter set TFp, the encryption trustworthiness coefficient JKX, and the corresponding evaluation results within the current time window into encryption trustworthiness evaluation intermediate result data and store it; after completing the key adjustment and trust level update, enter the next time window, recalculate the encryption trustworthiness coefficient JKX, and perform periodic recalculation; until the encryption trustworthiness coefficient JKX ≥ the encryption trustworthiness threshold Jth.

[0043] Preferably, step five includes:

[0044] S51. The anti-tampering consistency coefficient FYX and the encryption trust coefficient JKX obtained by calculation are used to perform joint mapping calculation on the impact of anti-tampering consistency and encryption trust by product coupling modeling algorithm. After dimensionless processing, the time synchronization security coupling coefficient TOX is calculated.

[0045] S52. By setting a comprehensive security threshold Tth and comparing the time synchronization security coupling coefficient TOX with the comprehensive security threshold Tth, the third evaluation results are obtained, including:

[0046] When the time synchronization security coupling coefficient TOX ≥ the comprehensive security threshold Tth, it indicates that the combined impact of the anti-tampering mechanism and the symmetric encryption mechanism on the time synchronization process is within a controllable range, and the current 802.1AS time synchronization operation is normal and stable, and continuous monitoring is required.

[0047] When the time synchronization security coupling coefficient TOX < the comprehensive security threshold Tth, it indicates that the combined impact of the anti-tampering mechanism and the symmetric encryption mechanism on the time synchronization process is not within a controllable range. There is a risk of decreased time synchronization reliability within the current time window, triggering a third early warning instruction and generating a third strategy: Based on the changing trend of the time synchronization security coupling coefficient TOX, adaptively adjust the synchronization period parameters of the current time synchronization link, reduce the time synchronization message sending frequency and extend the synchronization period, weakening the amplified impact of abnormal security states on time synchronization stability; recalculate the security weights of the nodes participating in time synchronization, dynamically adjusting their participation weights in the time synchronization topology based on the historical time synchronization security coupling coefficient TOX evaluation results; encapsulate the time synchronization security coupling coefficient TOX, the corresponding time window identifier, and the evaluation results into time synchronization security impact evaluation result data, and write it into the time synchronization security evaluation history for trend analysis and security situation judgment; after completing the synchronization parameter adjustment and weight update, enter the next time window and recalculate the time synchronization security coupling coefficient TOX, forming a closed-loop feedback process for time synchronization security impact evaluation and control; until the time synchronization security coupling coefficient TOX ≥ the comprehensive security threshold Tth.

[0048] Preferably, a protocol message anti-tampering system based on symmetric encryption includes:

[0049] The protocol message mirroring acquisition module is used to mirror the message sending and receiving process in the protocol processing of the 802.1AS time synchronization device, acquire the original protocol message data packet p, parse it to form a complete message content data set Dp, and generate message digest data Hs and its corresponding encryption verification data Es at the sending end. At the receiving end, the encryption verification value Er is parsed and decrypted to obtain the digest data Hr.

[0050] The protocol message security feature standardization module is used to normalize the fields of the collected data, constrain the digest consistency, correct the encryption verification format and length alignment, eliminate the differences in message type, device implementation and calculation rules, and form the message content feature parameter set DpB, the sender digest feature parameter HsB, the receiver digest feature parameter HrB, the sender encryption verification feature parameter EsB and the receiver encryption verification feature parameter ErB after field standardization, and uniformly encapsulate and construct the protocol message security feature parameter set TFp;

[0051] The anti-tampering consistency assessment module is used to count the number of protocol message samples N according to the time window based on the protocol message security feature parameter set TFp, and to perform a message-by-message consistency comparison of the digest feature parameters HsB and HrB on the sending side and the receiving side, calculate the anti-tampering consistency coefficient FYX, and compare it with the anti-tampering consistency threshold Fth to determine whether the protocol message integrity is qualified. If it is qualified, a consistency pass mark result is generated; if it is unqualified, abnormal message discarding, event logging and alarm are executed.

[0052] The symmetric encryption trustworthiness assessment module is used to select protocol message samples within the same time window from the protocol message security feature parameter set TFp based on the consistency pass identification result, calculate the number M of encryption assessment protocol message samples, and perform message-by-message difference calculation on the encryption verification feature parameters EsB and ErB of the sending side and the receiving side. It further calculates the encryption trustworthiness coefficient JKX and compares it with the encryption trustworthiness threshold Jth to determine whether the symmetric encryption link trustworthiness is qualified. If it is not qualified, key adjustment and trust level control are performed.

[0053] The time synchronization security coupling assessment and control module is used to perform product coupling calculation of the anti-tampering consistency coefficient FYX and the encryption trust coefficient JKX to obtain the time synchronization security coupling coefficient TOX, and compare it with the comprehensive security threshold Tth to evaluate the comprehensive impact of anti-tampering and symmetric encryption on 802.1AS time synchronization; and to provide strategies for adjusting the synchronization period parameters, recalculating node security weights, and periodic reassessment.

[0054] Preferably, the protocol message anti-tampering medium based on symmetric encryption includes: a memory and a processor; the memory stores a computer program, and the processor is configured to run the computer program and apply it to the protocol message anti-tampering method based on symmetric encryption; the computer program is used to execute the protocol message anti-tampering system based on symmetric encryption when it is running.

[0055] This invention provides a method, system, and medium for preventing protocol message tampering based on symmetric encryption. It offers the following advantages:

[0056] (1) The protocol message anti-tampering method, system and medium based on symmetric encryption, by mirror monitoring the message sending and receiving process in the 802.1AS protocol processing process, and by comparing and analyzing the digest data and encryption verification data of the sending side and the receiving side, realizes online, real-time and quantifiable detection of whether the protocol message has been tampered with. It can accurately identify the tampering behavior of the time synchronization message during transmission without changing the original protocol interaction mechanism, and effectively improve the integrity and security guarantee capability of the 802.1AS time synchronization message.

[0057] (2) The protocol message anti-tampering method, system and medium based on symmetric encryption constructs a unified set of protocol message security feature parameters by normalizing fields, constraining digest consistency, correcting encryption verification format and length alignment, eliminating the differences caused by different message types, different device implementation methods and different calculation rules, so that the anti-tampering consistency assessment and encryption credibility assessment have cross-device and cross-implementation consistency and stability, and improve the reliability and reproducibility of the anti-tampering judgment results.

[0058] (3) The protocol message anti-tampering method, system and medium based on symmetric encryption introduces the anti-tampering consistency coefficient FYX and the encryption trust coefficient JKX respectively, and calculates them by time window statistics and message-by-message comparison, so as to realize the hierarchical evaluation and independent judgment of the integrity of the protocol message and the trust of the symmetric encryption link; when an anomaly is detected, the abnormal message can be discarded, the event is recorded, the alarm is triggered, the key is adjusted and the trust level is controlled in a targeted manner, so as to avoid the chain effect of a single anomaly on the entire time synchronization process.

[0059] (4) The protocol message anti-tampering method, system and medium based on symmetric encryption form a time synchronization security coupling coefficient TOX by multiplying and coupling the anti-tampering consistency coefficient FYX and the encryption trust coefficient JKX. Combined with the comprehensive security threshold, the overall assessment of the 802.1AS time synchronization security status is realized. When security risks occur, a closed-loop control process is constructed by adaptively adjusting the synchronization period parameters, dynamically recalculating the node security weight and periodic reassessment mechanism. This effectively suppresses the amplification effect of security anomalies on the master-slave clock synchronization accuracy and synchronization stability, and improves the overall security and operational stability of the time synchronization system. Attached Figure Description

[0060] Figure 1 This is a schematic diagram illustrating the steps of the protocol message anti-tampering method based on symmetric encryption of the present invention;

[0061] Figure 2 This is a flowchart illustrating the protocol message anti-tampering system based on symmetric encryption of the present invention. Detailed Implementation

[0062] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0063] Example 1

[0064] Please see Figure 1 This invention provides a method for preventing tampering of protocol messages based on symmetric encryption, comprising the following steps:

[0065] Step 1: By mirroring the message sending and receiving process in the protocol processing of the 802.1AS time synchronization device, the original protocol message data packet p is obtained; it is parsed to form a complete message content data set Dp, and message digest data Hs and its corresponding encryption verification data Es are generated at the sending end. At the receiving end, the encryption verification value Er is parsed and decrypted to obtain the digest data Hr.

[0066] Step 2: By performing field normalization, digest consistency constraint, encryption verification format correction and length alignment on the collected relevant data, differences in message type, device implementation and calculation rules are eliminated, forming a set of message content feature parameters DpB, sender digest feature parameter HsB, receiver digest feature parameter HrB, sender encryption verification feature parameter EsB and receiver encryption verification feature parameter ErB after field standardization, and uniformly encapsulating and constructing a set of protocol message security feature parameters TFp;

[0067] Step 3: Based on the protocol message security feature parameter set TFp, count the number of protocol message samples N according to the time window, and perform a message-by-message consistency comparison of the digest feature parameters HsB and HrB on the sending side and the receiving side to calculate the anti-tampering consistency coefficient FYX; and compare it with the anti-tampering consistency threshold Fth to determine whether the protocol message integrity is qualified. If it is qualified, generate a consistency pass mark result; if it is not qualified, execute abnormal message discarding, event logging and alarm.

[0068] Step 4: Based on the consistency identification result, filter protocol message samples within the same time window from the protocol message security feature parameter set TFp, calculate the number M of encryption evaluation protocol message samples, and perform message-by-message difference calculation on the encryption verification feature parameters EsB and ErB of the sending and receiving sides. Further calculate the encryption trust coefficient JKX and compare it with the encryption trust threshold Jth to determine whether the symmetric encryption link trust is qualified. If it is not qualified, perform key adjustment and trust level control.

[0069] Step 5: By multiplying and coupling the anti-tampering consistency coefficient FYX and the encryption trust coefficient JKX, the time synchronization security coupling coefficient TOX is obtained and compared with the comprehensive security threshold Tth to evaluate the comprehensive impact of anti-tampering and symmetric encryption on 802.1AS time synchronization; and strategies for adjusting the synchronization period parameter, recalculating node security weights, and periodic re-evaluation are given.

[0070] In this embodiment, digest consistency verification and symmetric encryption reliability assessment are performed on the sending and receiving sides of the 802.1AS time synchronization protocol messages, respectively. Furthermore, a product coupling model of the anti-tampering consistency coefficient and the encryption reliability coefficient is introduced to achieve quantitative assessment and closed-loop control of the time synchronization security status. When a security risk is detected, the time synchronization parameters can be adaptively adjusted and the node participation weight can be dynamically controlled, thereby effectively suppressing the impact of message tampering or encryption anomalies on the master-slave clock synchronization accuracy and synchronization stability, and significantly improving the security and operational reliability of the 802.1AS time synchronization system in complex network environments.

[0071] Example 2

[0072] This embodiment is an explanation based on Embodiment 1. Please refer to it. Figure 1 Specifically, step one includes:

[0073] S11. In an industrial automation Ethernet time synchronization network, within a device running the 802.1AS protocol, a message mirroring collection point is set at the message sending and receiving interface of the protocol processing process. Through kernel-level hook interception technology of the protocol stack, the 802.1AS protocol messages entering the sending queue and completing the receiving and parsing are monitored in real time, and the binary content of the message is completely copied to form the original protocol message data packet p.

[0074] S12. Based on the original protocol message data packet p, the protocol field parsing engine parses and extracts the fields involved in the time synchronization calculation field by field according to the 802.1AS message format specification. The parsed field values ​​are then reassembled according to the message field order to form a complete message content data set Dp.

[0075] S13. Based on the complete message content data set Dp, the corresponding message digest value is obtained by calling the hash calculation module inside the protocol device to perform a fixed hash algorithm operation, and the digest value is recorded to form digest data Hs;

[0076] S14. Based on the digest data Hs, the symmetric encryption operation component built into the protocol device obtains the fixed length L of the encryption verification value determined by the current symmetric encryption algorithm according to the symmetric encryption algorithm type and its corresponding output length parameter pre-configured in the current communication protocol; under the constraint of the fixed length L, the digest data Hs is encrypted using the pre-configured symmetric encryption key to generate an encryption verification value of length L, and the current encryption operation result is collected to form the sending-side encryption verification data Es;

[0077] S15. In the protocol processing process at the receiving end, the TLV field of the received 802.1AS protocol message is parsed, and the encrypted verification data is extracted from the verification TLV field at the end of the protocol message to form the encrypted verification value Er on the receiving side.

[0078] S16. Based on the receiving side encryption verification value Er, perform decryption operation through the symmetric decryption operation component in the receiving device to obtain the corresponding decryption digest value, and collect the current decryption result to form decryption digest data Hr.

[0079] In this embodiment, by setting up a message mirroring collection point within the 802.1AS protocol processing process, the kernel-level real-time monitoring of the sending and receiving process of protocol messages is achieved. Without changing the original protocol field structure, the message content is fully parsed, digests are generated, and symmetric encryption and decryption verifications are performed. This enables the sending and receiving sides to obtain one-to-one corresponding digests and encryption verification data, thereby achieving accurate perception of the integrity and authenticity of protocol messages. This effectively prevents external eavesdropping, tampering, or replaying from being secretly propagated in the time synchronization link, improving the security, controllability, and operational reliability of the 802.1AS time synchronization process.

[0080] Example 3

[0081] This embodiment is an explanation based on Embodiment 2. Please refer to it. Figure 1 Specifically, step two includes:

[0082] S21. Based on the complete message content data set Dp, a field-level normalization mapping processing method is adopted. According to the fixed order and field length specification of the 802.1AS protocol fields, the field values ​​corresponding to different message lengths and different message types are uniformly scaled to eliminate the influence of message length differences and message type differences, and obtain the message content feature parameter set DpB after field standardization.

[0083] S22. Based on the digest data Hs, the hash input consistency constraint processing method is adopted to perform consistency verification and normalization processing on the input order of fields participating in hash calculation, field concatenation method and filling rules, so that the mapping relationship between the digest data Hs and the complete content data set Dp of the protocol message remains stable, and the sender digest feature parameter HsB after consistency constraint is obtained.

[0084] S23. Based on the decrypted digest data Hr, the hash result alignment processing method is adopted. The structural consistency correction is performed on the decrypted digest result according to the same field concatenation order and digest generation rules as the sending side, and the receiver digest feature parameter HrB after consistency constraint is obtained.

[0085] S24. Based on the encrypted verification data Es from the sending side, the encryption result length standardization and format correction processing method is adopted to uniformly process the bit length, encoding format and padding status of the encrypted verification value, eliminate the fluctuation of the encryption result caused by the differences in implementation of different devices, and obtain the standardized encrypted verification feature parameter EsB from the sending side.

[0086] S25. Based on the received-side encryption verification value Er obtained in step one, the encryption verification result consistency mapping processing method is used to unify the format and align the length of the encrypted verification value extracted from the received side, so that it is in the same computation space as the transmitted-side encryption verification data Es, and the normalized received-side encryption verification feature parameter ErB is obtained.

[0087] S26. The standardized message content feature parameter set DpB, the consistent sender digest feature parameter HsB, the consistent receiver digest feature parameter HrB, the standardized sender encryption verification feature parameter EsB, and the standardized receiver encryption verification feature parameter ErB are uniformly encapsulated and indexed to construct the protocol message security feature parameter set TFp.

[0088] In this embodiment, by performing field-level standardization, consistency constraints, and unified mapping on the protocol message content, digest results, and encryption verification data, the security-related features generated under different message types and device implementation conditions are placed in the same calculation and comparison space. This ensures that the digest and encryption verification results on the sending and receiving sides have stable comparability, thereby improving the accuracy and reliability of 802.1AS protocol message integrity and authenticity verification and reducing the risk of misjudgment caused by implementation differences.

[0089] Example 4

[0090] This embodiment is an explanation based on Embodiment 3. Please refer to it. Figure 1 Specifically, step three includes:

[0091] S31. Based on the protocol message security feature parameter set TFp, the time window segmentation statistical method is adopted to group the collected protocol messages according to the preset time window, count the number of protocol messages participating in the calculation in each time window, and obtain the number of protocol message samples N corresponding to the current time window.

[0092] S32. Based on the sender-side digest feature parameter HsB and the receiver-side digest feature parameter HrB after consistency constraints, a message-by-message digest consistency comparison method is used to match and determine the consistency judgment result of the protocol message corresponding to the i-th protocol message one by one, and the HsB and HrB corresponding to the i-th protocol message are obtained. .

[0093] In this embodiment, by segmenting and statistically analyzing protocol messages within a preset time window and comparing the message-by-message consistency of the digest feature parameters between the sending and receiving sides, the protocol message digest matching status can be accurately characterized while ensuring time correlation. This enables refined identification of digest tampering, replay, or timing anomalies, thereby improving the real-time performance and accuracy of protocol message security consistency detection.

[0094] Example 5

[0095] This embodiment is an explanation based on Embodiment 4. Please refer to it. Figure 1 Specifically, step three also includes:

[0096] S33. Based on the obtained number of protocol message samples N corresponding to the current time window and the consistency judgment result of the protocol messages. The tamper-proof consistency coefficient FYX is calculated using a statistical averaging algorithm and after dimensionless processing, as shown in the following formula:

[0097]

[0098] In the formula, For consistency determination function, when When the condition is met, the value is 1; otherwise, the value is 0.

[0099] S34. By setting a preset anti-tampering consistency threshold Fth, and comparing the anti-tampering consistency coefficient FYX with the anti-tampering consistency threshold Fth, the first evaluation result is obtained, including:

[0100] When the anti-tampering consistency coefficient FYX ≥ the anti-tampering consistency threshold Fth, it indicates that the current network is in an integrity qualified state, no security risk of protocol messages being tampered with is detected, a consistency pass mark result is generated, and the process proceeds to step four.

[0101] When the anti-tampering consistency coefficient FYX < the anti-tampering consistency threshold Fth, it indicates that the current network is in an integrity failure state, there is an inconsistency in the protocol message digest within the current time window, and there is a security risk of protocol message tampering. This triggers the first warning instruction and generates the first strategy: based on the consistency judgment result corresponding to the protocol message. ,right The protocol messages are discarded to prevent abnormal messages from affecting the time synchronization process. Based on the index information and time window information of the abnormal protocol messages, the protocol message tampering event log is recorded and corresponding security alarm information is generated. The protocol message security feature parameter set TFp and the anti-tampering consistency coefficient FYX in the current time window are encapsulated and saved as intermediate result data for integrity assessment. After the abnormal message is handled, the next time window is entered, the anti-tampering consistency coefficient FYX value is updated, and periodic consistency recalculation is performed until the anti-tampering consistency coefficient FYX ≥ the anti-tampering consistency threshold Fth.

[0102] The method for obtaining the anti-tampering consistency threshold Fth is as follows: By statistically analyzing a large amount of historical protocol message data from 802.1AS time synchronization networks under normal operating conditions and under conditions with the risk of message tampering, the distribution range of the message digest consistency coefficient between the sending and receiving sides under different security conditions is extracted. Combined with the experience judgment of time synchronization network security operation and maintenance personnel, a reasonable threshold range for distinguishing between message integrity qualified and unqualified states is determined. At the same time, referring to the time synchronization protocol security hardening specifications, industrial Ethernet security design guidelines, and the integrity verification recommended indicators given by equipment manufacturers, the anti-tampering consistency threshold Fth is finally determined to determine whether there is a security risk of protocol messages being tampered with.

[0103] In this embodiment, by statistically quantifying the consistency of protocol message digests within a time window, an anti-tampering consistency coefficient is constructed and compared with a preset threshold. This enables automatic judgment and graded handling of protocol message tampering behavior. When an inconsistency anomaly is detected, abnormal messages are promptly discarded and security events are recorded, preventing tampered messages from participating in time synchronization calculations. This reduces the impact of tampering attacks on time synchronization accuracy and stability, and improves the overall security and reliability of the network time synchronization process.

[0104] Example 6

[0105] This embodiment is an explanation based on Embodiment 5. Please refer to it. Figure 1 Specifically, step four includes:

[0106] S41. Based on the protocol message security feature parameter set TFp corresponding to the consistency pass identification result, the time window alignment filtering method is used to extract the protocol message samples that participate in the calculation of the second encryption trust coefficient within the same time window, and the number of protocol message samples is counted to obtain the number M of encryption evaluation protocol message samples.

[0107] S42. Based on the normalized sending-side encryption verification feature parameter EsB and the normalized receiving-side encryption verification feature parameter ErB, a byte-level difference calculation method is used to perform message-by-message difference calculation on the EsB and ErB corresponding to the j-th protocol message within the same time window, and obtain the encryption verification difference value corresponding to the protocol message. .

[0108] In this embodiment, by filtering only protocol messages that pass consistency within the same time window and performing message-by-message and byte-level difference calculations on the encryption verification feature parameters of the sending and receiving sides, the interference of abnormal messages and cross-window data on encryption evaluation can be effectively eliminated. This accurately depicts the deviation of symmetric encryption verification results during transmission and processing, providing a reliable sample basis for subsequent encryption trust quantification evaluation and improving the accuracy and stability of encryption mechanism security status determination.

[0109] Example 7

[0110] This embodiment is an explanation based on Embodiment 6. Please refer to it. Figure 1 Specifically, step four also includes:

[0111] S43. By obtaining the number M of encrypted evaluation protocol message samples and the corresponding encryption verification difference value of the protocol messages. Combining the fixed length L of the encryption check value determined by the symmetric encryption algorithm, the normalized difference reverse mapping calculation method is used. After dimensionless processing, the encryption reliability coefficient JKX is calculated and obtained, as shown in the following formula:

[0112]

[0113] In the formula, This represents a function for calculating byte-level differences.

[0114] S44. By setting a preset encryption trust threshold Jth, and comparing the encryption trust coefficient JKX with the encryption trust threshold Jth, the second evaluation result is obtained, including:

[0115] When the encryption trust coefficient JKX ≥ the encryption trust threshold Jth, it indicates that the trust of the symmetric encryption link is qualified within the current time window, and it will be continuously monitored.

[0116] When the encryption trustworthiness coefficient JKX < the encryption trustworthiness threshold Jth, it indicates that the trustworthiness of the symmetric encryption link within the current time window is unqualified, there are abnormal differences in the encryption verification results within the current time window, and there is a risk of encryption verification forgery or replay attacks in the network. This triggers a second warning instruction and generates a second strategy: Initiate a symmetric encryption key reconfiguration or key rotation strategy to update the symmetric encryption key used in the current time synchronization link; temporarily lower the time synchronization trust level of the protocol message source node with abnormal differences, restricting its participation in master clock election; encapsulate the protocol message security feature parameter set TFp, the encryption trustworthiness coefficient JKX, and the corresponding evaluation results within the current time window into encryption trustworthiness evaluation intermediate result data and store it; after completing the key adjustment and trust level update, enter the next time window, recalculate the encryption trustworthiness coefficient JKX, and perform periodic recalculation; until the encryption trustworthiness coefficient JKX ≥ the encryption trustworthiness threshold Jth.

[0117] The encryption trust threshold Jth is obtained by long-term collection and statistical analysis of encryption verification result differences of symmetric encryption mechanisms under normal communication conditions, abnormal key conditions, and replay or forgery attack simulation scenarios. The range of changes in the encryption trust coefficient under trusted and untrusted states is extracted. Combined with the engineering experience of cryptographic security technicians, the encryption stability under different network loads and device implementation conditions is comprehensively evaluated. The encryption trust threshold Jth is determined by referring to the symmetric encryption application specifications in industrial communication, cryptographic algorithm implementation guidelines, and encryption performance and security recommendations provided by equipment manufacturers. This threshold is used to distinguish between trusted and untrusted states of symmetric encryption links.

[0118] In this embodiment, by normalizing and reverse mapping the encryption verification differences within the time window and introducing the encryption trust coefficient JKX and threshold determination mechanism, the overall trust level of the symmetric encryption link can be quantitatively evaluated. When an anomaly is detected, key updates and node trust level adjustments are automatically triggered, effectively suppressing the impact of encryption verification forgery and replay attacks on the time synchronization process, and improving the security, continuity and operational reliability of industrial automation Ethernet time synchronization communication.

[0119] Example 8

[0120] This embodiment is an explanation based on Embodiment 7. Please refer to it. Figure 1 Specifically, step five includes:

[0121] S51. Using the calculated anti-tampering consistency coefficient FYX and encryption trustworthiness coefficient JKX, a product coupling modeling algorithm is employed to jointly map the impact of anti-tampering consistency and encryption trustworthiness. After dimensionless processing, the time synchronization security coupling coefficient TOX is calculated, as shown in the following formula:

[0122]

[0123] In the formula, the product coupling modeling algorithm is used to characterize the superimposed amplification effect of anti-tampering consistency degradation and encryption trust degradation on time synchronization security, so that a decrease in any single security index will have an inhibitory effect on the overall time synchronization security.

[0124] S52. By setting a comprehensive security threshold Tth and comparing the time synchronization security coupling coefficient TOX with the comprehensive security threshold Tth, the third evaluation results are obtained, including:

[0125] When the time synchronization security coupling coefficient TOX ≥ the comprehensive security threshold Tth, it indicates that the combined impact of the anti-tampering mechanism and the symmetric encryption mechanism on the time synchronization process is within a controllable range, and the current 802.1AS time synchronization operation is normal and stable, and continuous monitoring is required.

[0126] When the time synchronization security coupling coefficient TOX < the comprehensive security threshold Tth, it indicates that the combined impact of the anti-tampering mechanism and the symmetric encryption mechanism on the time synchronization process is not within a controllable range. There is a risk of decreased time synchronization reliability within the current time window, triggering a third early warning instruction and generating a third strategy: Based on the changing trend of the time synchronization security coupling coefficient TOX, adaptively adjust the synchronization period parameters of the current time synchronization link, reduce the time synchronization message sending frequency and extend the synchronization period, weakening the amplified impact of abnormal security states on time synchronization stability; recalculate the security weights of the nodes participating in time synchronization, dynamically adjusting their participation weights in the time synchronization topology based on the historical time synchronization security coupling coefficient TOX evaluation results; encapsulate the time synchronization security coupling coefficient TOX, the corresponding time window identifier, and the evaluation results into time synchronization security impact evaluation result data, and write it into the time synchronization security evaluation history for trend analysis and security situation judgment; after completing the synchronization parameter adjustment and weight update, enter the next time window and recalculate the time synchronization security coupling coefficient TOX, forming a closed-loop feedback process for time synchronization security impact evaluation and control; until the time synchronization security coupling coefficient TOX ≥ the comprehensive security threshold Tth.

[0127] The comprehensive security threshold Tth is obtained by statistically modeling and analyzing the joint changes of the anti-tampering consistency coefficient and the encryption trust coefficient under various time synchronization operation scenarios. This extracts the distribution characteristics of the time synchronization security coupling coefficient under both secure and stable operation and security degradation states. Combining the overall reliability design requirements of the time synchronization system with the experience and judgment of security operation and maintenance personnel, the comprehensive security threshold range is determined. Furthermore, referencing the security operation specifications of industrial time synchronization systems, network security level protection requirements, and system-level security assessment recommendations provided by equipment manufacturers, the comprehensive security threshold Tth is finally determined. This threshold is used to assess the combined impact of the anti-tampering mechanism and the symmetric encryption mechanism on the security of 802.1AS time synchronization.

[0128] In this embodiment, a time synchronization security coupling coefficient TOX is constructed by product coupling modeling the anti-tampering consistency coefficient FYX and the encryption trust coefficient JKX. This coefficient can comprehensively characterize the superimposed impact of the anti-tampering mechanism and the symmetric encryption mechanism on the security of 802.1AS time synchronization under a unified dimension. When the overall security level decreases, the synchronization cycle adaptive adjustment and node security weight reconstruction can be automatically triggered according to the TOX change trend. This suppresses the amplification effect of abnormal security status on time synchronization stability, realizes quantifiable evaluation, dynamic control and closed-loop optimization of time synchronization security status, and improves the overall reliability and risk resistance of the time synchronization system in complex network environments.

[0129] Example 9

[0130] For a protocol message anti-tampering system based on symmetric encryption, please refer to... Figure 2 Specifically, including:

[0131] The protocol message mirroring acquisition module is used to mirror the message sending and receiving process in the protocol processing of the 802.1AS time synchronization device, acquire the original protocol message data packet p, parse it to form a complete message content data set Dp, and generate message digest data Hs and its corresponding encryption verification data Es at the sending end. At the receiving end, the encryption verification value Er is parsed and decrypted to obtain the digest data Hr.

[0132] The protocol message security feature standardization module is used to normalize the fields of the collected data, constrain the digest consistency, correct the encryption verification format and length alignment, eliminate the differences in message type, device implementation and calculation rules, and form the message content feature parameter set DpB, the sender digest feature parameter HsB, the receiver digest feature parameter HrB, the sender encryption verification feature parameter EsB and the receiver encryption verification feature parameter ErB after field standardization, and uniformly encapsulate and construct the protocol message security feature parameter set TFp;

[0133] The anti-tampering consistency assessment module is used to count the number of protocol message samples N according to the time window based on the protocol message security feature parameter set TFp, and to perform a message-by-message consistency comparison of the digest feature parameters HsB and HrB on the sending side and the receiving side, calculate the anti-tampering consistency coefficient FYX, and compare it with the anti-tampering consistency threshold Fth to determine whether the protocol message integrity is qualified. If it is qualified, a consistency pass mark result is generated; if it is unqualified, abnormal message discarding, event logging and alarm are executed.

[0134] The symmetric encryption trustworthiness assessment module is used to select protocol message samples within the same time window from the protocol message security feature parameter set TFp based on the consistency pass identification result, calculate the number M of encryption assessment protocol message samples, and perform message-by-message difference calculation on the encryption verification feature parameters EsB and ErB of the sending side and the receiving side. It further calculates the encryption trustworthiness coefficient JKX and compares it with the encryption trustworthiness threshold Jth to determine whether the symmetric encryption link trustworthiness is qualified. If it is not qualified, key adjustment and trust level control are performed.

[0135] The time synchronization security coupling assessment and control module is used to perform product coupling calculation of the anti-tampering consistency coefficient FYX and the encryption trust coefficient JKX to obtain the time synchronization security coupling coefficient TOX, and compare it with the comprehensive security threshold Tth to evaluate the comprehensive impact of anti-tampering and symmetric encryption on 802.1AS time synchronization; and to provide strategies for adjusting the synchronization period parameters, recalculating node security weights, and periodic reassessment.

[0136] In this embodiment, by modularizing and coordinating the functions of protocol message mirroring acquisition, message security feature standardization, anti-tampering consistency assessment, symmetric encryption trustworthiness assessment, and time synchronization security coupling assessment and control, each security assessment function operates independently and is decoupled from the others on a unified protocol message security feature parameter set TFp. This avoids cross-interference between different security judgment logics and supports hierarchical, itemized, and comprehensive assessments by time window, thereby improving the structural clarity, scalability, and response efficiency to abnormal states of the 802.1AS time synchronization security monitoring system.

[0137] Example 10

[0138] The protocol message anti-tampering medium based on symmetric encryption specifically includes a memory and a processor, characterized in that: the memory stores a computer program, and the processor is configured to run the computer program and apply it to the protocol message anti-tampering method based on symmetric encryption; the computer program is used to execute the protocol message anti-tampering system based on symmetric encryption when it is running.

[0139] In this embodiment, by storing the symmetric encryption-based protocol message anti-tampering method and the corresponding anti-tampering system in the medium as computer programs, and having them executed by the processor as needed, the anti-tampering logic can be flexibly deployed in software on different 802.1AS time synchronization devices. This achieves consistent anti-tampering and encryption trustworthiness assessment functions without relying on a fixed hardware structure, thereby improving the portability, reusability, and rapid integration capability of the solution into existing time synchronization networks.

[0140] The threshold is set to facilitate comparison. The size of the threshold depends on the amount of sample data and the number of bases set by those skilled in the art for each set of sample data; as long as it does not affect the ratio between the parameter and the quantized value, it is acceptable.

[0141] The above formulas are all derived from software simulation using a large amount of data and are selected to be close to the actual values. The coefficients in the formulas are set by those skilled in the art according to the actual situation. The above description is only a preferred embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any equivalent substitutions or changes made by those skilled in the art within the technical scope disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the protection scope of the present invention.

Claims

1. A tamper-proofing method of protocol messages based on symmetric encryption, characterized in that, Comprise the following steps: Step one, by mirroring monitoring the message transceiving process in the protocol processing process of the 802.1AS time synchronization device, obtaining the original protocol message data packet p; forming the message complete content data set Dp by analyzing, and respectively generating the message digest data Hs and its corresponding encryption check data Es at the sending end, and obtaining the encryption check value Er and decrypting to obtain the digest data Hr at the receiving end; Step two, by field normalization, digest consistency constraint, encryption check format correction and length alignment processing on the collected related data, eliminating the differences of message type, device implementation and calculation rules, forming the field standardized message content feature parameter set DpB, the sending side digest feature parameter HsB, the receiving side digest feature parameter HrB, the sending side encryption check feature parameter EsB and the receiving side encryption check feature parameter ErB, and uniformly packaging and building the protocol message security feature parameter set TFp; Step three, based on the protocol message security feature parameter set TFp, the protocol message sample number N is counted according to the time window, and the sending side and receiving side digest feature parameters HsB and HrB are compared for message consistency, and the tamper-proof consistency coefficient FYX is calculated; and compared with the tamper-proof consistency threshold Fth, to determine whether the protocol message integrity is qualified, if qualified, a consistency passing identification result is generated, if not qualified, an abnormal message is discarded, event record and alarm are executed; Step four, through the consistency passing identification result, the protocol message samples in the same time window are selected from the protocol message security feature parameter set TFp, the encryption evaluation protocol message sample number M is calculated, and the sending side and receiving side encryption check feature parameters EsB and ErB are calculated for each message difference, and the encryption confidence coefficient JKX is further calculated, and compared with the encryption confidence threshold Jth, to determine whether the symmetric encryption link confidence is qualified, if not qualified, the key adjustment and trust level control are executed; Step five, by multiplying the tamper-proof consistency coefficient FYX and the encryption confidence coefficient JKX, the time synchronization security coupling coefficient TOX is obtained, and compared with the comprehensive security threshold Tth, to evaluate the comprehensive influence of tamper-proof and symmetric encryption on 802.1AS time synchronization; give adjustment synchronization period parameter, recalculate node security weight and periodic reevaluation strategy.

2. The protocol message tamper-proofing method based on symmetric encryption according to claim 1, characterized in that, The step one comprises: S11, in the industrial automation Ethernet time synchronization network, in the device running the 802.1AS protocol, a message mirror collection point is set at the message transceiving interface of the protocol processing process, the 802.1AS protocol message entering the sending queue and completing the receiving analysis is monitored in real time through the protocol stack kernel level hook interception technology, and the binary content of the message is completely copied to form the original protocol message data packet p; S12, based on the original protocol packet data p, through the protocol field analysis engine according to the 802.1AS message format specification, the field participating in the time synchronization calculation is parsed and extracted field by field, the field value obtained by parsing is reorganized according to the message field order to form a message complete content data set Dp; S13, based on the message complete content data set Dp, through the internal call of the hash calculation module in the protocol device to execute the fixed hash algorithm operation, the corresponding message digest value is obtained, and the digest value is recorded to form the digest data Hs; S14, based on the digest data Hs, through the symmetric encryption operation component built-in in the protocol device, according to the symmetric encryption algorithm type and the corresponding output length parameter pre-configured in the current communication protocol, the encryption check value fixed length L determined by the current symmetric encryption algorithm is obtained; under the constraint of fixed length L, the pre-configured symmetric encryption key is used to execute the encryption operation on the digest data Hs, and the encryption check value with length L is generated, and the current encryption operation result is collected to form the sending side encryption check data Es; S15, in the receiving end protocol processing process, the received 802.1AS protocol packet is parsed, the encryption check data is extracted from the check TLV field at the tail of the protocol packet, and the receiving side encryption check value Er is formed; S16, based on the receiving side encryption check value Er, through the symmetric decryption operation component in the receiving end device to execute the decryption operation, the corresponding decryption digest value is obtained, and the current decryption result is collected to form the decryption digest data Hr.

3. The method of claim 2, wherein the symmetric encryption-based protocol message tamper-proofing method is characterized by, The step two includes: S21, based on the message complete content data set Dp, using the field level normalization mapping processing method, according to the fixed order and field length specification of the 802.1AS protocol field, the field value corresponding to different message length and different message type is uniformly converted, the influence of message length difference and message type difference is eliminated, and the field standardized message content feature parameter set DpB is obtained; S22, based on the digest data Hs, using the hash input consistency constraint processing method, the field input order, field splicing mode and filling rule participating in the hash calculation are checked and standardized, so that the mapping relationship between the digest data Hs and the protocol message complete content data set Dp is kept stable, and the consistency constrained sending side digest feature parameter HsB is obtained; S23, based on the decryption digest data Hr, using the hash result alignment processing method, according to the same field splicing order and digest generation rule as the sending side, the structure consistency of the decrypted digest result is corrected, and the consistency constrained receiving side digest feature parameter HrB is obtained; S24, based on the sending side encryption check data Es, using the encryption result length specification and format correction processing method, the bit length, encoding format and filling state of the encryption check value are uniformly processed, the encryption result fluctuation caused by the implementation difference of different devices is eliminated, and the standardized sending side encryption check feature parameter EsB is obtained; S25, based on the received side encryption check value Er obtained in step one, using encryption check result consistency mapping processing method, the encryption check value extracted from the receiving side is processed in format uniformity and length alignment, and is in the same calculation space with the sending side encryption check data Es, to obtain the normalized receiving side encryption check feature parameter ErB; S26, the field standardized message content feature parameter set DpB, the consistency constrained sending side digest feature parameter HsB, the consistency constrained receiving side digest feature parameter HrB, the normalized sending side encryption check feature parameter EsB and the normalized receiving side encryption check feature parameter ErB are uniformly packaged and indexed, and the protocol message security feature parameter set TFp is constructed.

4. The method of claim 3, wherein the symmetric encryption-based protocol message tamper-proofing method is characterized by, The third step comprises: S31, based on the protocol message security feature parameter set TFp, using time window segmentation statistical method, the collected protocol messages are grouped according to the preset time window, the number of protocol messages participating in the calculation in each time window is counted, and the number of protocol message samples corresponding to the current time window N is obtained; S32, based on the consistency constraint after the sending side summary feature parameter HsB and the consistency constraint after the receiving side summary feature parameter HrB, using the message-by-message summary consistency comparison method, matching and judging HsB and HrB corresponding to the i th protocol message in the same time window one by one, and obtaining the consistency judgment result corresponding to the protocol message .

5. The method of claim 4, wherein the symmetric encryption-based protocol message tamper-proofing method is characterized by, The third step further comprises: S33, obtaining the number N of protocol message samples corresponding to the current time window and the consistency determination result corresponding to the protocol message through the obtained current time window , using a statistical average algorithm, after dimensionless processing, calculating and obtaining the tamper-proof consistency coefficient FYX; S34, by comparing the tamper-proof consistency coefficient FYX with the tamper-proof consistency threshold Fth, the first evaluation result is obtained, including: When the tamper-proof consistency coefficient FYX is greater than or equal to the tamper-proof consistency threshold Fth, it indicates that the current network is in the integrity qualified state, and no security risk of protocol message tampering is detected, a consistency passing identification result is generated, and step four is entered; When the anti-tampering consistency coefficient FYX < the anti-tampering consistency threshold Fth, it indicates that the current network is in an integrity unqualified state, there is a protocol message digest inconsistency in the current time window, there is a security risk that the protocol message is tampered, a first early warning instruction is triggered, and a first strategy is generated: according to the consistency judgment result corresponding to the protocol message , the protocol message is executed Discarding processing, blocking the influence of abnormal messages on the time synchronization process; based on the index information and time window information of the abnormal protocol message, recording the protocol message tampering event log and generating the corresponding security alarm information; the protocol message security feature parameter set TFp and the anti-tampering consistency coefficient FYX in the current time window are encapsulated and saved as the integrity evaluation intermediate result data; after the abnormal message is disposed, the next time window is entered, the anti-tampering consistency coefficient FYX value is updated, and periodic consistency recalculation is performed; until the anti-tampering consistency coefficient FYX ≥ the anti-tampering consistency threshold Fth.

6. The method of claim 5, wherein the symmetric encryption-based protocol message tamper-proofing method is characterized by, The fourth step comprises: S41, based on the protocol message security feature parameter set TFp corresponding to the consistency passing identification result, using time window alignment filtering method, the protocol message samples participating in the second encryption trust coefficient calculation in the same time window are extracted, and the number of protocol message samples is counted, to obtain the number of encryption evaluation protocol message samples M; S42, based on the normalized sending side encryption verification feature parameter EsB and the normalized receiving side encryption verification feature parameter ErB, using a byte-level difference calculation method, performing message-by-message difference calculation on EsB and ErB corresponding to the jth protocol message in the same time window to obtain an encryption verification difference value corresponding to the protocol message .

7. The method of claim 6, wherein the symmetric encryption-based protocol message tamper-proofing method is characterized by, The fourth step further comprises: S43, through the encrypted evaluation protocol message sample quantity M and the encrypted check difference value corresponding to the protocol message obtained by acquisition , combined with the fixed length L of the encrypted check value determined by the symmetric encryption algorithm, the normalized difference reverse mapping calculation method is adopted, and after non-dimensional processing, the encrypted confidence coefficient JKX is calculated and obtained; S44, by comparing the encryption trust coefficient JKX with the preset encryption trust threshold Jth, the second evaluation result is obtained, including: When the encryption trust coefficient JKX is greater than or equal to the encryption trust threshold Jth, it indicates that the trustworthiness of the symmetric encryption link in the current time window is qualified, and the monitoring is continued. When the encryption credibility coefficient JKX < the encryption credibility threshold Jth, it indicates that the credibility of the symmetric encryption link in the current time window is unqualified, there is an abnormal difference in the encryption verification result in the current time window, there is a risk of encryption verification forgery or replay attack in the network, a second early warning instruction is triggered, and a second strategy is generated: the symmetric encryption key reconfiguration or key rotation strategy is started, the symmetric encryption key used in the current time synchronization link is updated; the time synchronization trust level of the protocol message source node of the abnormal difference is temporarily reduced, and participation in the master clock election is limited; the protocol message security feature parameter set TFp in the current time window, the encryption credibility coefficient JKX and the corresponding evaluation result are packaged as encryption credibility evaluation intermediate result data and stored; after the key adjustment and trust level update are completed, the next time window is entered, the encryption credibility coefficient JKX is recalculated, and periodic recalculation is performed; until the encryption credibility coefficient JKX ≥ the encryption credibility threshold Jth.

8. The method of claim 7, wherein the symmetric encryption-based protocol message tamper-proofing method is characterized by, The step five comprises: S51, by calculating the obtained tamper-proof consistency coefficient FYX and the encryption credibility coefficient JKX, the product coupling modeling algorithm is adopted to jointly map and calculate the tamper-proof consistency influence and the encryption credibility influence, and after non-dimensional processing, a time synchronization security coupling coefficient TOX is calculated; S52, by presetting a comprehensive security threshold Tth, and comparing and analyzing the time synchronization security coupling coefficient TOX with the comprehensive security threshold Tth, a third evaluation result is obtained, comprising: When the time synchronization security coupling coefficient TOX ≥ the comprehensive security threshold Tth, it indicates that the comprehensive influence of the tamper-proof mechanism and the symmetric encryption mechanism on the time synchronization process is in a controllable range, the current 802.1AS time synchronization running state is normal and stable, and continuous monitoring is performed; When the time synchronization security coupling coefficient TOX < the comprehensive security threshold Tth, it indicates that the comprehensive influence of the tamper-proof mechanism and the symmetric encryption mechanism on the time synchronization process is not in a controllable range, there is a risk of time synchronization reliability decline in the current time window, a third early warning instruction is triggered, and a third strategy is generated: based on the change trend of the time synchronization security coupling coefficient TOX, the synchronization period parameter of the current time synchronization link is adaptively adjusted, the time synchronization message sending frequency is reduced and the synchronization period is prolonged, the amplification influence of the abnormal security state on the time synchronization stability is weakened; the node set participating in the time synchronization is executed security weight recalculation, the participation weight of each node in the time synchronization topology is dynamically adjusted according to the historical time synchronization security coupling coefficient TOX evaluation result of the node; the time synchronization security coupling coefficient TOX, the corresponding time window identifier and the evaluation result are packaged as time synchronization security influence evaluation result data, and are written into the time synchronization security evaluation history record, the trend analysis and security situation discrimination are performed; after the synchronization parameter adjustment and weight update are completed, the next time window is entered, the time synchronization security coupling coefficient TOX is recalculated, the closed-loop feedback process of the time synchronization security influence evaluation and control is formed; until the time synchronization security coupling coefficient TOX ≥ the comprehensive security threshold Tth.

9. The tamper-proof system of protocol messages based on symmetric encryption, applied to the tamper-proof method of protocol messages based on symmetric encryption according to any one of claims 1 to 8, characterized in that, Comprise: The protocol message mirror acquisition module is configured to mirror monitor the message transceiving process in the protocol processing process of the 802.1AS time synchronization device, to obtain original protocol message data packets p; to analyze and form a complete content data set Dp, and to generate a message digest data Hs and its corresponding encrypted check data Es at the sending end, and to analyze and obtain the encrypted check value Er and decrypt the digest data Hr at the receiving end; The protocol message security feature standardization module is configured to perform field normalization, digest consistency constraint, encrypted check format correction and length alignment processing on the collected related data, eliminate differences in message types, device implementation and calculation rules, form a field-standardized message content feature parameter set DpB, a sending-side digest feature parameter HsB, a receiving-side digest feature parameter HrB, a sending-side encrypted check feature parameter EsB and a receiving-side encrypted check feature parameter ErB, and uniformly package and build a protocol message security feature parameter set TFp; The tamper-proofing consistency evaluation module is configured to count the number of protocol message samples N based on the protocol message security feature parameter set TFp according to a time window, and compare the sending-side and receiving-side digest feature parameters HsB and HrB for each message for consistency, calculate a tamper-proofing consistency coefficient FYX, and compare the tamper-proofing consistency coefficient FYX with a tamper-proofing consistency threshold Fth to determine whether the protocol message integrity is qualified, and if qualified, generate a consistency passing identification result, and if not qualified, execute abnormal message discarding, event recording and alarming; The symmetric encryption trustworthiness evaluation module is configured to filter protocol message samples in the same time window from the protocol message security feature parameter set TFp through the consistency passing identification result, calculate the number of encrypted evaluation protocol message samples M, and calculate the difference between the sending-side and receiving-side encrypted check feature parameters EsB and ErB for each message, further calculate an encryption trustworthiness coefficient JKX, and compare the encryption trustworthiness coefficient JKX with an encryption trustworthiness threshold Jth to determine whether the symmetric encryption link trustworthiness is qualified, and if not qualified, execute key adjustment and trust level control; The time synchronization security coupling evaluation and control module is configured to multiply and couple the tamper-proofing consistency coefficient FYX and the encryption trustworthiness coefficient JKX to obtain a time synchronization security coupling coefficient TOX, and compare the time synchronization security coupling coefficient TOX with a comprehensive security threshold Tth to evaluate the comprehensive influence of tamper-proofing and symmetric encryption on the 802.1AS time synchronization, and to adjust the synchronization period parameter, recalculate the security weight of the node and the periodic reevaluation strategy.

10. Protocol message tamper-evident medium based on symmetric encryption, comprising a memory and a processor, characterized in that: The memory stores a computer program, and the processor is configured to run the computer program, which is applied to the protocol message tamper-proofing method based on symmetric encryption in any one of claims 1-8; and the computer program is used to execute the protocol message tamper-proofing system based on symmetric encryption in claim 9 when running.

Citation Information

Cited By

  • An end-to-end encrypted data collection method and system for industrial control scenarios

    CN122394969A