A protection method for dynamic measurement of an industrial control system PLC and an industrial control system PLC
By adopting the dynamic measurement protection method based on ABAC in PLC, the problem of PLC's inability to guarantee security is solved, and effective response and security improvement of internal information security threats are achieved.
Patent Information
- Application Number
- CN202010472746.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-29
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2040-05-29
AI Technical Summary
The security of PLC in the prior art cannot be guaranteed, and it is especially impossible to deal with information security issues that break out within the PLC.
The dynamic metric protection method based on the access control ABAC mechanism is adopted. In the running state of the trusted PLC, the data to be measured when any event occurs is obtained, the measurement strategy stored on the trusted hardware platform is called for measurement, and the measurement results are determined whether the event meets expectations. If it does not meet, the corresponding protection action is performed and an audit log is generated.
Through dynamic measurement and protection mechanisms, the security of the PLC is improved, and information security threats within the PLC can be effectively dealt with, and audit logs are generated for subsequent analysis.
Smart Images

Figure CN111624937B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial control technology, and in particular, to a protection method for dynamic measurement of an industrial control system PLC and an industrial control system PLC. Background Art
[0002] With the continuous development of industrial control technology towards networking and openness, industrial control technology is widely used in industrial fields such as power, transportation, energy, and finance. Currently, programmable logic controllers (PLCs) are widely used in the field of industrial control technology.
[0003] Due to computer viruses, such as Stuxnet, which can penetrate into the operating system of an industrial control system PLC and reprogram the control logic operation of the industrial control system PLC, resulting in the destruction of the industrial control system PLC, the information security problem in the industrial control field has become increasingly prominent and attracted the attention of the industry.
[0004] Currently, during the control logic operation process of an industrial control system PLC, its security mainly relies on the boundary protection devices outside the industrial control system PLC, which can effectively protect against external computer virus attacks. However, there is no way to deal with the information security problems that break out inside the PLC, resulting in the inability to guarantee the security of the PLC. Summary of the Invention
[0005] In view of this, embodiments of the present invention provide a protection method for dynamic measurement of an industrial control system PLC and an industrial control system PLC to solve the problem that the security of the PLC in the prior art cannot be guaranteed.
[0006] To achieve the above object, embodiments of the present invention provide the following technical solutions:
[0007] Embodiments of the present invention disclose a protection method for dynamic measurement of an industrial control system PLC, the method including:
[0008] In the running state of a trusted programmable logic controller (PLC), obtaining the data to be measured corresponding to any event occurring based on the access control ABAC mechanism;
[0009] Invoking the measurement strategy stored in the trusted hardware platform, and measuring the data to be measured based on the measurement strategy to obtain a measurement value;
[0010] Querying the trusted data corresponding to the event pre-stored in the trusted reference database to calculate the measurement value, and obtaining a trusted value corresponding to the determination result;
[0011] Determining whether the event meets the expectation according to the trusted value;
[0012] If it meets the expectation, continue to execute the event;
[0013] If it does not meet the expectation, perform corresponding actions according to the security and trust policy, and generate an audit log containing the unexpected results, and send it to the security management platform of the PLC.
[0014] Optionally, when the arbitrary event is an access request for a subject to access an object, in the running state of the trusted programmable logic controller (PLC), based on the access control ABAC mechanism, obtain the data to be measured corresponding to the occurrence of the arbitrary event, including:
[0015] Obtain the access request for the subject to access the object, and determine the type of the access request. The access request contains the ID of the subject;
[0016] Query the security and trust policy corresponding to the ID of the subject;
[0017] Obtain the attribute information of the subject and the object according to the security and trust policy;
[0018] Package the attribute information of the subject, the attribute information of the object, and the type of the access request as the data to be measured.
[0019] Optionally, when the arbitrary event is to measure the operating environment of the system, in the running state of the trusted programmable logic controller (PLC), based on the access control ABAC mechanism, obtain the data to be measured corresponding to the occurrence of the arbitrary event, including:
[0020] According to a set period, read the data to be measured from a specified address according to the access control ABAC mechanism. The specified address points to a code area for storing PLC service program code, kernel operating system (OS) code, and computing firmware code. The data to be measured includes the PLC service program code, kernel operating system (OS) code, and / or computing firmware code stored at the specified address in the code area.
[0021] Optionally, call the measurement policy stored in the trusted hardware platform, and measure the data to be measured based on the measurement policy to obtain a measurement value, including:
[0022] If the measurement data is the attribute information of the subject, the attribute information of the object, and the type of the access request, call the measurement policies corresponding to the attribute information of the subject, the attribute information of the object, and the type of the access request stored in the trusted hardware platform, and measure the attribute information of the subject, the attribute information of the object, and the type of the access request respectively to obtain a first measurement value;
[0023] If the measurement data is the PLC service program code, the kernel operating system (OS) code, and / or the computing firmware code, call the measurement policies stored in the trusted hardware platform corresponding to the PLC service program code, the kernel operating system (OS) code, and / or the computing firmware code, and measure the PLC service program code, the kernel operating system (OS) code, and / or the computing firmware code respectively to obtain a second measurement value.
[0024] Optionally, if the any event includes an access request for a subject to access an object and / or when measuring the operating environment of the measurement system, query the trusted data corresponding to the event pre-stored in the trusted reference database to calculate the measurement result, and obtain a trusted value corresponding to the determination result, including:
[0025] Query the first assessment item coefficient corresponding to the access request for the subject to access the object and / or the second assessment item coefficient corresponding to the operating environment of the measurement system pre-stored in the trusted reference database;
[0026] Calculate the product of the first assessment item coefficient and the first measurement value to obtain a first trusted value, and / or calculate the product of the second assessment coefficient and the second measurement value to obtain a second trusted value.
[0027] Optionally, it further includes:
[0028] In the running state of the trusted programmable logic controller (PLC), obtain the first important data file to be encrypted during the business operation process, and encrypt the first important data file to be encrypted based on the SM2 / SM4 algorithm of the national cryptography; and / or,
[0029] In the running state of the trusted programmable logic controller (PLC), obtain the encrypted important data file during the business operation process, and decrypt the encrypted file based on the SM2 / SM4 algorithm of the national cryptography to obtain a second important data file;
[0030] Compare the second important data file with the key data file of the PLC;
[0031] If it meets the expectation, continue to execute the event corresponding to the second important data file;
[0032] If they are inconsistent, determine that the event corresponding to the second important data file does not meet the expectation, perform corresponding actions according to the security and trust policy, and generate an audit log containing the non-conforming result, and send it to the security management platform of the PLC.
[0033] A second aspect of the embodiments of the present invention discloses an industrial control system PLC, where the industrial control system PLC includes: a trusted PLC, a trusted hardware platform, and a security management platform;
[0034] The trusted PLC includes a trusted firmware, a service firmware, and an access control firmware. Among them, the trusted firmware and the service firmware each independently occupy a hardware CPU, and the service firmware includes a control logic operation firmware;
[0035] The trusted firmware is used to, when the trusted PLC is in operation, obtain the data to be measured corresponding to any event based on the access control ABAC mechanism, call the measurement policy stored in the trusted hardware platform, measure the data to be measured based on the measurement policy to obtain a measurement value; query the trusted data corresponding to the event pre-stored in the trusted reference database to calculate the measurement value to obtain a trusted value corresponding to the determination result; determine whether the event meets the expectation according to the trusted value. If it meets the expectation, continue to execute the event. If it does not meet the expectation, perform corresponding actions according to the security and trust policy, and generate an audit log containing the unexpected result and send it to the security management platform of the PLC.
[0036] Optionally, the trusted firmware includes: a security and trust policy firmware and a trusted computing firmware;
[0037] The security and trust policy firmware is used to, when the arbitrary event is an access request for a subject to access an object, obtain the access request for the subject to access the object by the access control firmware based on the control logic operation firmware, and determine the type of the access request. The access request contains the ID of the subject; query the security and trust policy corresponding to the ID of the subject; obtain the attribute information of the subject and the object according to the security and trust policy; package the attribute information of the subject, the attribute information of the object, and the type of the access request as the data to be measured;
[0038] The trusted computing firmware is used to, based on the control logic operation firmware, call the measurement policy corresponding to the attribute information of the subject, the attribute information of the object, and the type of the access request stored in the trusted hardware platform, and measure the attribute information of the subject, the attribute information of the object, and the type of the access request respectively to obtain a first measurement value; query the first assessment item coefficient corresponding to the access request of the subject to access the object pre-stored in the trusted reference database; calculate the product of the first assessment item coefficient and the first measurement value to obtain a first trusted value.
[0039] Optionally, the trusted firmware includes: a security and trust policy firmware and a trusted computing firmware;
[0040] The secure and trustworthy policy firmware is used to, when any of the above events is to measure the system running environment, read the data to be measured from a specified address at a set period based on the control logic operation firmware according to the access control ABAC mechanism. The specified address points to a code area for storing PLC service program code, kernel operation program system OS code, and computing firmware code. The data to be measured includes the PLC service program code, kernel operation program system OS code, and / or computing firmware code stored at the specified address in the code area.
[0041] The trusted computing firmware is used to call the measurement policies corresponding to the PLC service program code, kernel operation program system OS code, and / or computing firmware code stored in the trusted hardware platform, measure the PLC service program code, kernel operation program system OS code, and / or computing firmware code respectively, and obtain a second measurement value; query the second assessment item coefficient corresponding to the measurement of the system running environment pre-stored in the trusted benchmark database; calculate the product of the second assessment coefficient and the second measurement value to obtain a second trust value.
[0042] Optionally, the trusted firmware is further used to, in the trusted PLC running state, obtain the first important data file to be encrypted during the business operation process, and encrypt the first important data file to be encrypted based on the SM2 / SM4 algorithm of the national cryptography; and / or, in the trusted PLC running state, obtain the encrypted important data file during the business operation process, and decrypt the encrypted file based on the SM2 / SM4 algorithm of the national cryptography to obtain a second important data file; compare the second important data file with the key data file of the PLC; if it meets the expectation, continue to execute the event corresponding to the second important data file; if not, determine that the event corresponding to the second important data file does not meet the expectation, perform corresponding actions according to the secure and trustworthy policy, and generate an audit log containing the unexpected result and send it to the security management platform.
[0043] Based on the protection for dynamic measurement of PLC in an industrial control system and the industrial control system PLC provided in the embodiments of the present invention, the method includes: in the running state of a trusted PLC, obtaining the to-be-measured data corresponding to any event occurrence based on the access control ABAC mechanism; invoking the measurement policy stored in the trusted hardware platform, and measuring the to-be-measured data based on the measurement policy to obtain a measurement value; querying the trusted data corresponding to the event pre-stored in the trusted reference database to calculate the measurement value to obtain a trusted value corresponding to the determination result; determining whether the event meets the expectation according to the trusted value; if it meets the expectation, continue to execute the event; if it does not meet the expectation, perform corresponding actions according to the security and trust policy, and generate an audit log containing the unexpected result and send it to the security management platform of the PLC. In the embodiments of the present invention, under the control of the security and trust policy, the PLC obtains the to-be-measured data corresponding to any event occurrence, invokes the measurement policy of the trusted hardware platform to measure the to-be-measured data, and performs corresponding protection operations according to the measurement result according to the security and trust policy, so as to ensure the security of the industrial control system PLC. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0045] Figure 1 A schematic structural diagram of an industrial control system PLC provided in an embodiment of the present invention;
[0046] Figure 2 Another schematic structural diagram of an industrial control system PLC provided in an embodiment of the present invention;
[0047] Figure 3 Another schematic structural diagram of an industrial control system PLC provided in an embodiment of the present invention;
[0048] Figure 4 A principle block diagram of the trusted computing firmware provided in an embodiment of the present invention;
[0049] Figure 5 An active measurement block diagram of a measurement system operating environment provided in an embodiment of the present invention;
[0050] Figure 6 A schematic flowchart of a protection method for dynamic measurement of an industrial control system PLC provided in an embodiment of the present invention;
[0051] Figure 7Schematic flowchart of another protection method for dynamic measurement of PLC in industrial control system provided by an embodiment of the present invention;
[0052] Figure 8 Schematic diagram of the principle of an access request for a subject to access an object provided by an embodiment of the present invention;
[0053] Figure 9 Schematic flowchart of yet another protection method for dynamic measurement of PLC in industrial control system provided by an embodiment of the present invention;
[0054] Figure 10 Schematic flowchart of still another protection method for dynamic measurement of PLC in industrial control system provided by an embodiment of the present invention;
[0055] Figure 11 Schematic flowchart of still another protection method for dynamic measurement of PLC in industrial control system provided by an embodiment of the present invention;
[0056] Figure 12 Schematic diagram of the principle of encryption and decryption of important data files provided by an embodiment of the present invention. Detailed implementation manners
[0057] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0058] In this application, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, the element defined by the statement "including one..." does not exclude the presence of additional identical elements in the process, method, article or device including the said element.
[0059] For the convenience of understanding, the terms appearing in the embodiments of the present invention are explained as follows:
[0060] Trusted computing technology: It is an active immune parallel computing architecture that combines computing and protection under the control of a secure and trusted policy. For example, it can implement functions such as identity recognition, state measurement, and encrypted storage with passwords as genes. It can be understood that it can identify the data components of "self" and "non-self", so as to destroy and exclude harmful substances entering the system, that is, to increase the immunity of the industrial control system.
[0061] Attribute-based access control (ABAC) technology: It is a key technology for industrial information security, used to determine whether different subject processes can access a certain resource, that is, a certain object file, which is calculated based on the different attributes of the subject process and the object file, so as to protect the object from illegal operations by the subject.
[0062] In the embodiment of the present invention, under the control of the security and trust policy, the PLC obtains the data to be measured corresponding to any event occurrence, and calls the measurement policy of the trusted hardware platform to measure the data to be measured, determines the corresponding trust value according to the measurement result, and executes corresponding protection operations according to the security and trust policy according to the measurement result, so as to ensure the security of the industrial control system PLC.
[0063] See Figure 1 , which shows a structural block diagram of an industrial control system PLC provided by an embodiment of the present invention. The industrial control system PLC includes: a trusted programmable logic controller (PLC) 10, a trusted hardware platform 20, and a security management platform 30.
[0064] The trusted PLC 10 is respectively communicatively connected to the trusted hardware platform 20 and the security management platform 30.
[0065] In the embodiment of the present invention, the trusted hardware platform 20 is used to call the national cryptographic SM2 / SM4 algorithm, set and store the measurement policy corresponding to the specified event according to the specified event.
[0066] It should be noted that the trusted hardware platform 20 is a (Trusted Cryptography Module, TCM) TCM security chip, which can support the trusted firmware in the trusted PLC 10 for policy management, cryptographic services, industrial control system PLC management, measurement control, etc., so as to effectively protect access to the industrial control system PLC and prevent illegal users from accessing the industrial control system PLC.
[0067] It should be noted that any event includes an access request for a subject to access an object and / or measuring the system running environment.
[0068] The security management platform 30 is used to send the security and trust policy to the trusted PLC 10, receive the audit log containing the unexpected result sent by the trusted PLC 10, and display the audit log containing the unexpected result for the user to view later.
[0069] In an embodiment of the present invention, the trusted PLC 10 refers to integrating trusted computing technology and ABAC technology into a programmable logic controller PLC. Therefore, the trusted PLC 10 can, based on cryptographic technology, construct an actively immune PLC with parallel computing and protection under the control of a secure and trusted policy, and can determine whether different subject processes can access a certain resource, that is, an object file.
[0070] It should be noted that the trusted PLC 10 is embedded in the industrial control system PLC in an embedded manner.
[0071] Based on Figure 1 the industrial control system PLC shown, the present invention also shows the specific structure of the trusted PLC 10. As Figure 2 shown, the trusted PLC 10 includes a trusted firmware 11, a service firmware 12, and an access control firmware 13.
[0072] Among them, the trusted firmware 11 and the service firmware 12 each independently occupy a hardware central processing unit (CPU).
[0073] The trusted firmware 11, the service firmware 12, and the access control firmware 13 are communicatively connected.
[0074] In an embodiment of the present invention, the service firmware 12 includes a control logic operation firmware.
[0075] The service firmware 12 is used to provide PLC service programs and related operations.
[0076] Specifically, the control logic operation firmware performs the control logic operations of the trusted PLC and schedules tasks related to logic operations, and can communicate between the control logic firmware of the trusted PLC and other firmware of the trusted PLC 10.
[0077] Optionally, the trusted PLC is also provided with input / output files, which refer to key data files required for the operation of the trusted PLC service, such as: analog input (AI) data files, digital input (DI) data files, analog output (AO) data files, and digital output (DO) data files.
[0078] The trusted firmware 11 is used to, when the trusted PLC 10 is in an operating state, obtain the data to be measured corresponding to any event occurrence based on the ABAC mechanism, call the measurement policy stored in the trusted hardware platform 20, measure the data to be measured based on the measurement policy to obtain a measurement value; query the trusted data corresponding to the event pre-stored in the trusted reference database to calculate the measurement value to obtain a trusted value corresponding to the determination result; determine whether the event meets the expectation according to the trusted value. If it meets the expectation, continue to execute the event. If it does not meet the expectation, perform corresponding actions according to the security and trust policy, and generate an audit log containing the unexpected result and send it to the security management platform 30 of the PLC.
[0079] It should be noted that the relationship between the event and the trusted data corresponding to the event is pre-stored in the trusted reference database.
[0080] Specifically, the trusted firmware 11 is used to, when the trusted PLC 10 is in an operating state, based on the security and trust policy issued by the security management platform 30, obtain the access request of the subject accessing the object and / or the data to be measured corresponding to the occurrence of the measurement system operating environment based on the control logic operation firmware by the access control firmware 13.
[0081] In the embodiment of the present invention, the access control firmware 13 obtains the access request of the subject accessing the object and / or the data to be measured corresponding to the occurrence of the measurement system operating environment based on the ABAC technology.
[0082] According to the measurement policy pre-stored in the trusted hardware platform 20, measure the data to be measured to obtain a measurement value; query the trusted data corresponding to the event pre-stored in the trusted reference database, and calculate the trusted data and the measurement value to obtain a trusted value corresponding to the determination result; determine whether the trusted value meets the pre-set trusted value. If it meets, determine that the access request of the subject accessing the object and / or the measurement system operating environment meets the expectation and allow the control logic of the event to be executed; if it does not meet the expectation, perform a blocking or non-blocking operation according to the action of the security and trust policy, and generate an audit log containing the unexpected result, and then send the audit log containing the unexpected result to the security management platform 30 of the PLC.
[0083] It should be noted that the expectation refers to the pre-set trusted value, and the pre-set trusted value can be set through multiple experiments or set according to the experience of those skilled in the art.
[0084] The trusted reference database is used to pre-store any event and the relationship between any event and the corresponding trusted data.
[0085] Furthermore, it should be noted that the trusted data is determined according to the data corresponding to the event in the security and trust policy, and the trusted data can be 0 or 1.
[0086] Among them, the trusted data may include a first assessment item coefficient and a second assessment item coefficient. The trusted value may include a first trusted value and a second trusted value.
[0087] The trusted firmware 11 includes: a secure trusted policy firmware 111 and a trusted computing firmware 112.
[0088] In an embodiment of the present invention, under the control of the secure trusted policy, the trusted firmware obtains the data to be measured corresponding to any event occurrence. The PLC can call the corresponding measurement policy according to different events occurring, and measure the data to be measured according to the measurement policy to obtain a measurement value. Then, according to the measurement value, the corresponding trusted value is determined, and according to the trusted value, it is determined whether the event meets the expectation. If it meets the expectation, the control logic of the event is allowed to be executed. If it does not meet the expectation, corresponding protection operations are performed according to the secure trusted policy, thereby ensuring the security of the industrial control system PLC.
[0089] Combined with the above embodiments of the present invention Figure 1 shown, if the trusted firmware 11 includes a secure trusted policy firmware 111 and a trusted computing firmware 112, as Figure 3 shown.
[0090] In a specific implementation, when any event is an access request for a subject to access an object, the secure trusted policy firmware 111 is used to obtain the access request for the subject to access the object from the access control firmware 13 based on the control logic operation firmware in the service firmware 12, and determine the type of the access request; query the secure trusted policy corresponding to the ID of the subject; obtain the attribute information of the subject and the object according to the secure trusted policy; and package the attribute information of the subject, the attribute information of the object, and the type of the access request as the data to be measured.
[0091] It should be noted that the access request contains the ID of the subject.
[0092] In an embodiment of the present invention, the hook function can capture the access request for a subject to access an object before the read operation of the input class file or the write operation of the output class file.
[0093] The object refers to an object file, and the object file includes file types such as AI data files, DI data files, AO data files, and DO data files.
[0094] The types of access requests include but are not limited to read, write, execute, create, or delete, etc.
[0095] The attribute information of the subject and the object includes at least one or a combination of multiple ones such as process name, process context, stack pointer, and process priority.
[0096] Specifically, based on the control logic operation firmware, the access control firmware 13 captures the access request of the subject accessing the object through its own hook function and determines the type of the access request. According to the ID of the subject, query the security and trust policy corresponding to the subject ID in the security management platform 30; obtain at least one or more combinations such as the process name, process context, stack pointer, and process priority according to the security and trust policy. Package at least one or more combinations of the obtained process name, process context, stack pointer, and process priority and the type of the access request as the data to be measured.
[0097] Optionally, the security management platform 30 is used to pre-set the security and trust policy corresponding to the access request of the subject accessing the object according to the subject ID.
[0098] The trusted computing firmware 112 is used to, based on the control logic operation firmware, call the measurement policies stored in the trusted hardware platform 20 corresponding to the attribute information of the subject, the attribute information of the object, and the type of the access request, and measure the attribute information of the subject, the attribute information of the object, and the type of the access request respectively to obtain the first measurement value; query the first assessment item coefficient corresponding to the access request of the subject accessing the object pre-stored in the trusted benchmark database; calculate the product of the first assessment item coefficient and the first measurement value to obtain the first trust value.
[0099] It should be noted that the trusted computing firmware 112 includes: a control mechanism, a determination mechanism, a support mechanism, a trusted benchmark database, a cooperation mechanism, and a measurement mechanism, as Figure 4 shown.
[0100] Optionally, the cooperation mechanism is used to communicate with the outside, for example, to receive the security and trust policy issued by the security management platform 30.
[0101] Specifically, as Figure 4 shown, the control mechanism in the trusted computing firmware 112 receives the monitoring data, that is, the data to be measured packaged by the security and trust policy firmware 111, and transfers the data to be measured to the measurement mechanism. The measurement mechanism, according to the security and trust policy, accesses the trusted hardware platform 20 through the support mechanism and calls the measurement policies stored in the trusted hardware platform 20 corresponding to the attribute information of the subject, the attribute information of the object, and the type of the access request, measures the attribute information of the subject, the attribute information of the object, and the type of the access request to obtain the first measurement value, and then transfers the first measurement value to the determination mechanism; the determination mechanism queries the trusted benchmark database to obtain the first assessment item coefficient corresponding to the access request of the subject accessing the object, and performs trusted calculation on the first assessment coefficient and the first measurement value to obtain the first trust value.
[0102] It should be noted that the first trust value is used to indicate the boolean value of the trusted calculation result of the first measurement value corresponding to the access request of the access object.
[0103] A trusted reference database is used to pre-store the access requests of a subject to an object, as well as the corresponding relationship between the access requests of the subject to the object and the first assessment item coefficients.
[0104] The first assessment item coefficient is determined according to the data corresponding to the access request of the subject to the object in the security and trust policy, and the first assessment item coefficient can be 0 or 1.
[0105] Optionally, in practice, if a certain indicator does not need to be assessed, that is, for any event, such as the access request of a subject to an object, then the first assessment item coefficient can be set empirically.
[0106] Optionally, the trusted hardware platform 20 is used to call the national cryptographic SM2 / SM4 algorithms, and set the measurement policy corresponding to the access request of the access object according to the attribute information of the subject, the attribute information of the object, and the type of the access request.
[0107] Correspondingly, the trusted computing firmware 112 is further used to determine whether an event meets the expectation according to the first trust value. If it meets the expectation, the event is continued to be executed. If it does not meet the expectation, corresponding actions are performed according to the security and trust policy, and an audit log containing the unexpected result is generated and sent to the security management platform 30 of the PLC.
[0108] Specifically, continue to refer to Figure 4 , the determination mechanism determines whether the first trust value meets the pre-set trust value. If it meets, it is determined that the access request of the subject to the object meets the expectation, and the control logic for allowing the execution of the access request of the subject to the object is permitted; if it does not meet, it is determined that the access request of the subject to the object does not meet the expectation, and blocking or non-blocking operations are performed according to the actions in the security and trust policy received by the cooperation mechanism, and an audit log containing the unexpected result is generated, and then the audit log containing the unexpected result is sent to the security management platform 30 of the PLC.
[0109] In the invention embodiment, under the control of the security and trust policy, when any event is the access request of a subject to an object, the security and trust policy firmware obtains the data to be measured corresponding to the occurrence of the access request of the subject to the object from the access control firmware. The PLC can call the corresponding measurement policy according to the occurrence of the access request of the subject to the object, and measure the data to be measured according to the measurement policy to obtain the first measurement value. The trusted computing firmware then determines the corresponding first trust value according to the first measurement value, and determines whether the event meets the expectation according to the first trust value. If it meets, it is determined that the access request of the subject to the object meets the expectation, and the control logic for allowing the execution of the access request of the subject to the object is permitted. If it does not meet the expectation, corresponding protection operations are performed according to the security and trust policy, thereby ensuring the security of the industrial control system PLC.
[0110] Combined with the above embodiments of the present invention Figure 1 shown, if the trusted firmware 11 is the secure trusted policy firmware 111 and the trusted computing firmware 112, as Figure 3 shown.
[0111] In another specific implementation, if any event is to measure the system running environment, the secure trusted policy firmware 111 is used to read the data to be measured from a specified address based on the access control ABAC mechanism according to the control logic operation firmware at a set period.
[0112] It should be noted that the specified address points to the code area for storing the PLC service program code, the kernel operation program system OS code, and the computing firmware code, and the data to be measured includes the PLC service program code, the kernel operation program system OS code, and / or the computing firmware code stored at the specified address in the code area.
[0113] Specifically, at a set period, according to the access control ABAC mechanism, read the PLC service program code, the kernel operation program system OS code, and / or the computing firmware code stored at the specified address in the code area for storing the PLC service program code, the kernel operation program system OS code, and the computing firmware code, use the PLC service program code, the kernel operation program system OS code, and / or the computing firmware code as the measurement data, and pass the data to be measured to the trusted computing firmware 112, as Figure 5 shown.
[0114] Optionally, as Figure 5 shown, a hardware password module that provides password algorithms and service interfaces for the secure trusted policy firmware 111 and the trusted computing firmware 112 is also provided.
[0115] The trusted computing firmware 112 is used to call the measurement policies corresponding to the PLC service program code, the kernel operation program system OS code, and / or the computing firmware code stored in the trusted hardware platform, measure the PLC service program code, the kernel operation program system OS code, and / or the computing firmware code respectively to obtain a second measurement value; query the second assessment item coefficient corresponding to the measurement of the system running environment pre-stored in the trusted reference database; calculate the product of the second assessment coefficient and the second measurement value to obtain a second trusted value.
[0116] Specifically, continue to refer to Figure 4, the control mechanism in the trusted computing firmware 112 receives the monitoring data, i.e., the data to be measured packaged by the secure and trusted policy firmware 111, i.e., the packaged PLC service program code, kernel operation program system OS code, and / or computing firmware code, and passes the data to be measured to the measurement mechanism. The measurement mechanism accesses the trusted hardware platform 20 through the support mechanism according to the secure and trusted policy, and calls the measurement policies corresponding to the PLC service program code, kernel operation program system OS code, and / or computing firmware code stored in the trusted hardware platform 20 to measure the PLC service program code, kernel operation program system OS code, and / or computing firmware code respectively, obtaining the second measurement value, and then passes the second measurement value to the determination mechanism; the determination mechanism queries the second assessment item coefficient corresponding to the measurement system operating environment in the trusted benchmark database, and performs trusted calculation on the second assessment coefficient and the second measurement value to obtain the second trusted value.
[0117] It should be noted that the second trusted value is a Boolean value used to indicate the trusted calculation result of the second measurement value corresponding to the measurement system operating environment.
[0118] The trusted benchmark database is used to pre-store the correspondence between the measurement system operating environment and the second assessment item coefficient corresponding to the measurement system operating environment.
[0119] The second assessment item coefficient is determined according to the parameters corresponding to the measurement system operating environment in the secure and trusted policy, and the second assessment item coefficient can be 0 or 1.
[0120] Optionally, the trusted hardware platform 20 is used to call the national cryptography SM2 / SM4 algorithm to set the measurement policy corresponding to the measurement system operating environment according to the PLC service program code, kernel operation program system OS code, and / or computing firmware code.
[0121] Correspondingly, the trusted computing firmware 112 is further used to determine whether the event meets the expectation according to the second trusted value. If it meets the expectation, the event is continued to be executed. If it does not meet the expectation, corresponding actions are performed according to the secure and trusted policy, and an audit log containing the unexpected result is generated and sent to the security management platform 30 of the PLC.
[0122] Specifically, continue to refer to Figure 4 , the determination mechanism determines whether the second trusted value meets the pre-set trusted value. If it meets, it is determined that the measurement system operating environment meets the expectation, and the control logic of the measurement system operating environment is allowed to be executed; if it does not meet, it is determined that the measurement system operating environment does not meet the expectation, and blocking or non-blocking operations are performed according to the actions in the secure and trusted policy received by the cooperation mechanism, and an audit log containing the unexpected result is generated, and then the audit log containing the unexpected result is sent to the security management platform 30 of the PLC.
[0123] In an embodiment of the present invention, under the control of a security and trust policy, when any event is to measure the operating environment of a system, the security and trust policy firmware is used to obtain the data to be measured corresponding to the occurrence of the operating environment of the measurement system. The PLC can call the corresponding measurement policy according to the occurrence of the measurement system operating environment, and measure the data to be measured according to the measurement policy to obtain a second measurement value. The trusted computing firmware then determines the corresponding second trusted value according to the second measurement value, and determines whether the event meets the expectation according to the second trusted value. If it meets the expectation, it is determined that the operating environment of the measurement system meets the expectation, and the control logic corresponding to the operating environment of the measurement system is allowed to be executed. If it does not meet the expectation, corresponding protection operations are performed according to the security and trust policy, thereby ensuring the security of the industrial control system PLC.
[0124] Optionally, based on the industrial control system shown above Figure 1 The trusted firmware 11 is further configured to, when the trusted PLC 10 is in an operating state, obtain a first important data file to be encrypted during the operation of the service, and encrypt the first important data file to be encrypted based on the SM2 / SM4 algorithm of the national cryptography; and / or, when the trusted PLC 10 is in an operating state, obtain an encrypted important data file during the operation of the service, and decrypt the encrypted file based on the SM2 / SM4 algorithm of the national cryptography to obtain a second important data file; compare the second important data file with the key data file of the PLC; if it meets the expectation, continue to execute the event corresponding to the second important data file; if it is inconsistent, determine that the event corresponding to the second important data file does not meet the expectation, perform corresponding actions according to the security and trust policy, and generate an audit log containing the unexpected result and send it to the security management platform 30.
[0125] In an embodiment of the present invention, the first important data file to be encrypted is in plain text.
[0126] The first important data file to be encrypted may be an engineering file, a firmware file, or an important variable file that a technician wants to download, etc.
[0127] Specifically, when the trusted PLC is in an operating state, obtain an engineering file, a firmware file, or an important variable file that a technician wants to download during the operation of the service; based on the SM2 / SM4 algorithm of the national cryptography, use the SM encryption function and a preset key to encrypt the first important data file to obtain a ciphertext corresponding to the first important data file.
[0128] And / or, obtain the ciphertext corresponding to the encrypted engineering file, firmware file, or important variable file during the operation of the service; based on the national cipher SM2 / SM4 algorithm, use the SM decryption function corresponding to the SM encryption function and the key matching the encrypted file to decrypt the ciphertext corresponding to the engineering file, firmware file, or important variable file, and obtain the second important data file, that is, the plaintext data. Determine whether the second important data file is consistent with the key data file of the PLC. If they are consistent, determine that the event corresponding to the second important data file meets the expectation, and continue to execute the event corresponding to the second important data file; if they are inconsistent, determine that the event corresponding to the second important data file does not meet the expectation, perform a blocking or non-blocking operation according to the actions in the security and trust policy, generate an audit log containing the unexpected result, and then send the audit log containing the unexpected result to the security management platform 30 of the PLC.
[0129] It should be noted that the SM encryption function is set according to the content of the important file. For example, for the firmware file, the SM2 encryption function of the digital signature algorithm can be used.
[0130] In the embodiment of the present invention, under the control of the security and trust policy, the trusted firmware obtains the important data file during the operation of the service, and encrypts the important file based on the national cipher SM2 / SM4 algorithm to obtain the ciphertext of the important file. After the encryption process, obtain the ciphertext of the important file. Based on the national cipher SM2 / SM4 algorithm, use the SM decryption function corresponding to the SM encryption function and the key matching the encrypted file to decrypt the ciphertext of the important file. This enables the PLC to call the corresponding national cipher algorithm according to different important data files. Thus, it can prevent the important data file from being stolen and prevent the information of the important data file from being leaked.
[0131] Based on the industrial control system PLC disclosed in the above embodiment of the present invention, the embodiment of the present invention also correspondingly discloses a protection method for dynamic measurement of the industrial control system PLC.
[0132] As Figure 6 shown, it is a schematic flowchart of a protection method for dynamic measurement of an industrial control system PLC provided by an embodiment of the present invention. The method includes:
[0133] Step S601: In the trusted PLC running state, obtain the data to be measured corresponding to any event occurring based on the ABAC mechanism.
[0134] It should be noted that any event includes an access request for a subject to access an object and / or measurement of the system operating environment.
[0135] In the process of specifically implementing step S601, in the running state of the trusted PLC, based on the ABAC mechanism, obtain the access request for the subject to access the object and / or the data to be measured corresponding to the occurrence of the measurement system running environment.
[0136] Step S602: Invoke the measurement policy stored in the trusted hardware platform, and measure the data to be measured based on the measurement policy to obtain a measurement value.
[0137] In the process of specifically implementing step S602, according to the measurement policy corresponding to the access request of the subject to access the object and / or the measurement system running environment pre-stored in the trusted hardware platform, measure the access request of the subject to access the object and / or the measurement system running environment corresponding to the measurement policy respectively to obtain a measurement value.
[0138] Step S603: Query the trusted data corresponding to the event pre-stored in the trusted reference database, and calculate the measurement value to obtain the trusted value corresponding to the determination result.
[0139] In the embodiment of the present invention, the relationship between any event and the trusted data corresponding to any event is pre-stored in the trusted reference database.
[0140] In the process of specifically implementing step S603, query the trusted data corresponding to the event pre-stored in the trusted reference database, and calculate the trusted data and the measurement value to obtain the trusted value corresponding to the determination result.
[0141] It should be noted that the trusted data is determined according to the data corresponding to the event in the secure and trusted policy, and the trusted data can be 0 or 1.
[0142] The trusted data includes the first assessment item coefficient and the second assessment item coefficient. The trusted value includes the first trusted value and the second trusted value.
[0143] Step S604: Determine whether the event meets the expectation according to the trusted value. If it meets the expectation, execute step S605. If it does not meet the expectation, execute step S606.
[0144] It should be noted that the expectation refers to the pre-set trusted value, and the pre-set trusted value can be set through multiple experiments or can be set according to the experience of those skilled in the art.
[0145] In the process of specifically implementing step S604, determine whether the trusted value meets the pre-set trusted value. If it meets, determine that the access request of the subject to access the object and / or the measurement system running environment meets the expectation, and execute step S605. If it does not meet, determine that the access request of the subject to access the object and / or the measurement system running environment does not meet the expectation, and execute step S606.
[0146] Step S605: Continue to execute the event.
[0147] During the specific implementation of step S605, the control logic for executing the event is allowed.
[0148] Step S606: Execute corresponding actions according to the security and trust policy, generate an audit log containing unexpected results, and send it to the security management platform of the PLC.
[0149] During the specific implementation of step S606, perform blocking or non-blocking operations according to the actions of the security and trust policy, generate an audit log containing unexpected results, and then send the audit log containing unexpected results to the security management platform of the PLC.
[0150] It should be noted that the specific execution process of the protection method for dynamic measurement of the industrial control system PLC disclosed in the above embodiments of the present invention is the same as the specific principles and execution processes of each unit in the industrial control system PLC shown in the above embodiments of the present invention. For details, reference can be made to the corresponding parts in the industrial control system PLC disclosed in the above embodiments of the present invention, and no further elaboration will be provided here.
[0151] In the embodiments of the present invention, under the control of the security and trust policy, the trusted firmware obtains the data to be measured corresponding to any event occurrence. The PLC can call the corresponding measurement policy according to different events occurring, and measure the data to be measured according to the measurement policy to obtain a measurement value. Then, determine the corresponding trust value according to the measurement value, and determine whether the event meets the expectation according to the trust value. If it meets the expectation, the control logic for executing the event is allowed. If it does not meet the expectation, perform corresponding protection operations according to the security and trust policy, thereby ensuring the security of the industrial control system PLC.
[0152] Based on the above Figure 6 shown protection method for dynamic measurement of the industrial control system PLC, any event includes an access request for a subject to access an object and / or measurement of the system operating environment, which will be described separately below.
[0153] Optionally, if any event is an access request for a subject to access an object, in an embodiment of the present invention, as Figure 7 shown, another protection method for dynamic measurement of the industrial control system PLC provided by the embodiments of the present invention includes:
[0154] Step S701: Obtain the access request for a subject to access an object and determine the type of the access request.
[0155] In step S701, the access request contains the ID of the subject.
[0156] In the process of specifically implementing step S701, based on the control logic operation firmware, the access control firmware captures the access request of the subject accessing the object through its own hook function and determines the type of the access request.
[0157] It should be noted that the hook function can capture the access request of the subject accessing the object before the read operation of the input class file or the write operation of the output class file.
[0158] The object refers to the object file, and the object file includes file types such as AI data file, DI data file, AO data file, and DO data file.
[0159] The types of access requests include but are not limited to read, write, execute, create, or delete, etc.
[0160] Step S702: Query the security and trust policy corresponding to the ID of the subject.
[0161] In step S702, a security and trust policy corresponding to the access request of the subject accessing the object is set in advance according to the subject ID.
[0162] In the process of specifically implementing step S702, according to the ID of the subject, query the security and trust policy corresponding to the subject ID in the security and trust policy issued by the security management platform.
[0163] Step S703: Obtain the attribute information of the subject and the object according to the ABAC mechanism.
[0164] In step S703, the attribute information of the subject and the object includes at least one or a combination of multiple items such as process name, process context, stack pointer, and process priority.
[0165] In the process of specifically implementing step S703, obtain at least one or a combination of multiple items such as process name, process context, stack pointer, and process priority according to the ABAC mechanism.
[0166] Step S704: Package the attribute information of the subject, the attribute information of the object, and the type of the access request as the data to be measured.
[0167] In the process of specifically implementing step S704, package at least one or a combination of multiple items such as the obtained process name, process context, stack pointer, and process priority and the type of the access request as the data to be measured.
[0168] To better understand the specific content of determining the data to be measured shown in the above steps S701 to S704, the following is an example for illustration.
[0169] Such as Figure 8As shown in the figure, when the trusted component B initiates an access to an object file in the main process b, based on the control logic operation firmware in the service firmware, the access control firmware captures the access request of the subject accessing the object through its own hook function, and determines that the type of the access request is to read the AI data file.
[0170] According to the ID of the subject, query the security and trust policy c corresponding to the subject ID in the security and trust policy issued by the security management platform.
[0171] Obtain the subject attribute information f1 and the object attribute information f2 according to the security and trust policy.
[0172] Package the subject attribute information f1, the object attribute information f2, and the type of the access request to read the AI data file as the data to be measured.
[0173] Step S705: Invoke the measurement policy stored in the trusted hardware platform corresponding to the subject attribute information, the object attribute information, and the type of the access request, and measure the subject attribute information, the object attribute information, and the type of the access request respectively to obtain the first measurement value.
[0174] In the process of specifically implementing step S705, according to the measurement policy stored in advance in the trusted hardware platform corresponding to the subject attribute information, the object attribute information, and the type of the access request, measure the subject attribute information, the object attribute information, and the type of the access request respectively to obtain the first measurement value.
[0175] It should be noted that the first measurement value is a boolean value, for example: it can be represented by B_LOGIC(i).
[0176] Step S706: Query the first assessment item coefficient corresponding to the access request of the subject accessing the object stored in advance in the trusted benchmark database.
[0177] In step S706, the correspondence between the access request of the subject accessing the object and the first assessment item coefficient corresponding to the access request of the subject accessing the object is stored in advance in the trusted benchmark database.
[0178] It should be noted that the first assessment item coefficient is determined according to the data corresponding to the access request of the subject accessing the object in the security and trust policy. The first assessment item coefficient can be 0 or 1, for example: it can be represented by C0.
[0179] Optionally, in practice, if a certain index does not need to be assessed, that is, for any event, such as the access request of the subject accessing the object, then the first assessment item coefficient can be set empirically.
[0180] Step S707: Calculate the product of the first assessment item coefficient and the first measurement value to obtain the first trust value.
[0181] In an embodiment of the present invention, the first trust value is used to indicate the Boolean value of the trusted computing result of the first measurement value corresponding to the main - object attribute.
[0182] In the process of specifically implementing step S707, the first assessment coefficient and the first measurement value are substituted into formula (1) for trusted computing to obtain the first trust value P1, that is, the product of the first assessment item coefficient and the first measurement value.
[0183] Formula (1):
[0184] P1 = F(C0 * B_LOGIC(i)) (1)
[0185] Wherein, F is a Boolean - value operation function for the access request of the subject to access the object, C0 is the first assessment item coefficient, and B_LOGIC(i) is the first measurement value.
[0186] Step S708: Determine whether the event meets the expectation according to the first trust value. If it meets the expectation, execute step S709; if it does not meet the expectation, execute step S710.
[0187] In the process of specifically implementing step S708, it is judged whether the first trust value meets the pre - set trust value. If it meets, it is determined that the access request of the subject to access the object meets the expectation, and step S509 is executed; if it does not meet, it is determined that the access request of the subject to access the object does not meet the expectation, and step S510 is executed.
[0188] Step S709: Continue to execute the event.
[0189] In the process of specifically implementing step S709, the control logic for allowing the access request of the subject to access the object is executed.
[0190] Step S710: Execute corresponding actions according to the security and trust policy, generate an audit log containing the unexpected result, and send it to the security management platform of the PLC.
[0191] It should be noted that the specific implementation process of step S710 is the same as that of the above - mentioned step S606 and can be referred to each other.
[0192] In an embodiment of the present invention, under the control of a security and trust policy, when any event is an access request for a subject to access an object, the security and trust policy firmware is used to obtain the data to be measured corresponding to the occurrence of the access request for the subject to access the object. The PLC can call the corresponding measurement policy according to the occurrence of the access request for the subject to access the object, and measure the data to be measured according to the measurement policy to obtain a first measurement value. The trusted computing firmware then determines the corresponding first trust value according to the first measurement value, and determines whether the event meets the expectation according to the first trust value. If it meets the expectation, it is determined that the access request for the subject to access the object meets the expectation, and the control logic for allowing the access request for the subject to access the object is executed. If it does not meet the expectation, corresponding protection operations are executed according to the security and trust policy, thereby ensuring the security of the industrial control system PLC.
[0193] Optionally, when any event is to measure the operating environment of the system, in another embodiment of the present invention, as Figure 9 shown, another protection method for dynamic measurement of the industrial control system PLC provided by the embodiment of the present invention includes:
[0194] Step S901: Read the data to be measured from a specified address according to the ABAC mechanism at a set period.
[0195] In step S901, the specified address points to a code area for storing PLC service program code, kernel operation program system OS code, and computing firmware code. The data to be measured includes the PLC service program code, kernel operation program system OS code, and / or computing firmware code stored at the specified address in the code area.
[0196] In the process of specifically implementing step S801, at a set period, according to the ABAC mechanism, the PLC service program code, kernel operation program system OS code, and computing firmware code stored at the specified address in the code area for storing PLC service program code, kernel operation program system OS code, and computing firmware code are read, and the PLC service program code, kernel operation program system OS code, and / or computing firmware code are packaged as the data to be measured.
[0197] Step S902: Call the measurement policies corresponding to the PLC service program code, kernel operation program system OS code, and / or computing firmware code stored in the trusted hardware platform, and measure the PLC service program code, kernel operation program system OS code, and / or computing firmware code respectively to obtain a second measurement value.
[0198] In the process of specifically implementing step S802, according to the measurement policies corresponding to the PLC service program code, the kernel operating system (OS) code, and / or the computing firmware code pre-stored in the trusted hardware platform, the PLC service program code, the kernel operating system (OS) code, and / or the computing firmware code are respectively measured to obtain a second measurement value.
[0199] It should be noted that the second measurement value is also a Boolean value, for example, it can be represented by B_ENV(e).
[0200] Step S903: Query the second assessment item coefficient corresponding to the measured system operating environment pre-stored in the trusted reference database.
[0201] In step S903, the correspondence between the measured system operating environment and the second assessment item coefficient corresponding to the measured system operating environment is pre-stored in the trusted reference database.
[0202] It should be noted that the second assessment item coefficient is determined according to the parameters corresponding to the measured system operating environment in the security and trust policy. The second assessment item coefficient can be 0 or 1, for example, it can be represented by C1.
[0203] Step S904: Calculate the product of the second assessment coefficient and the second measurement value to obtain a second trust value.
[0204] In the embodiment of the present invention, the second trust value is used to indicate the Boolean value of the trusted computing result of the second measurement value corresponding to the measured system operating environment.
[0205] In the process of specifically implementing step S904, the second assessment coefficient and the second measurement value are substituted into formula (2) for trusted computing to obtain a second trust value P2, that is, the product of the second assessment coefficient and the second measurement value.
[0206] Formula (2):
[0207] P2 = F(C2 * B_ENV(e)) (2)
[0208] Wherein, F is a Boolean value operation function of the measured system operating environment, C1 is the second assessment item coefficient, and B_ENV(e) is the second measurement value.
[0209] Step S905: Determine whether the event meets the expectation according to the second trust value. If it meets the expectation, execute step S906. If it does not meet the expectation, execute step S907.
[0210] In the process of specifically implementing step S905, it is determined whether the second trust value meets the pre-set trust value. If it meets, it is determined that the measurement system operating environment meets the expectation, and step S906 is executed. If it does not meet, it is determined that the measurement system operating environment does not meet the expectation, and step S907 is executed.
[0211] Step S906: Continue to execute the event.
[0212] In the process of specifically implementing step S906, the control logic of the measurement system operating environment is allowed to be executed.
[0213] Step S907: Execute corresponding actions according to the security and trust policy, generate an audit log containing the unexpected result, and send it to the security management platform of the PLC.
[0214] It should be noted that the specific implementation process of step S907 is the same as that of the above step S906 and can be referred to each other.
[0215] In the embodiment of the present invention, under the control of the security and trust policy, if any event is the measurement system operating environment, the measurement data to be measured corresponding to the occurrence of the measurement system operating environment is obtained through the security and trust policy firmware. The PLC can call the corresponding measurement policy according to the occurrence of the measurement system operating environment, and measure the data to be measured according to the measurement policy to obtain the second measurement value. The trusted computing firmware then determines the corresponding second trust value according to the second measurement value, and determines whether the event meets the expectation according to the second trust value. If it meets, it is determined that the measurement system operating environment meets the expectation, and the control logic corresponding to the measurement system operating environment is allowed to be executed. If it does not meet the expectation, corresponding protection operations are executed according to the security and trust policy, thereby ensuring the security of the industrial control system PLC.
[0216] Optionally, based on the above Figure 7 and Figure 9 shown protection method for dynamic measurement of the industrial control system PLC, if the any event includes an access request for a subject to access an object and a measurement system operating environment. The following steps are further included:
[0217] Step S11: Calculate the product of the first trust value and the second trust value to obtain the third trust value.
[0218] In the process of specifically implementing step S11, based on the above Figure 7 first trust value calculated in step S707 and Figure 9 second trust value calculated in step S905 are substituted into formula (3) for logical AND / OR operation to obtain the third trust value P3.
[0219] P3 = F(C0 * B_LOGIC(i), C2 * B_ENV(e)) (3)
[0220] Wherein, F is a Boolean value operation function for the operation environment of the measurement system and / or the access request of the subject to access the object, C0 is the coefficient of the first assessment item, B_LOGIC(i) is the first measurement value, C1 is the coefficient of the second assessment item, and B_ENV(e) is the second measurement value.
[0221] Step S12: Determine whether the event meets the expectation according to the third trust value. If it meets the expectation, continue to execute the event. If it does not meet the expectation, execute step S13.
[0222] In the process of specifically implementing step S12, it is judged whether the third trust value meets the pre-set trust value. If it meets, it is determined that both the access request of the subject to access the object and the operation environment of the measurement system meet the expectation, and step S13 is executed. If at least one of the access request of the subject to access the object and the operation environment of the measurement system does not meet the expectation, step S14 is executed.
[0223] Step S13: Continue to execute the event.
[0224] In the process of specifically implementing step S13, the control logic of the access request of the subject to access the object and the operation environment of the measurement system is allowed to be executed.
[0225] Step S14: Execute corresponding actions according to the security and trust policy, generate an audit log containing the unexpected result, and send it to the security management platform of the PLC.
[0226] It should be noted that the specific implementation processes of step S14 and step S606 are the same and can be referred to each other.
[0227] In the embodiment of the present invention, under the control of the security and trust policy, the trusted firmware obtains the data to be measured corresponding to any event occurrence. The PLC can call the corresponding measurement policy according to different events occurring, and measure the data to be measured according to the measurement policy to obtain the measurement value. Then, the corresponding trust value is determined according to the measurement value, and it is determined whether the event meets the expectation according to the trust value. If it meets, the control logic of the event is allowed to be executed. If it does not meet the expectation, corresponding protection operations are executed according to the security and trust policy, so as to ensure the security of the industrial control system PLC.
[0228] Based on the above Figure 6 shown protection method for dynamic measurement of the PLC, as Figure 10 shown, another protection method for dynamic measurement of the industrial control system PLC provided by the embodiment of the present invention, this method further includes:
[0229] Step S1001: In the trusted PLC running state, obtain the first important data file to be encrypted during the business operation process.
[0230] It should be noted that the first important data file to be encrypted is in plaintext.
[0231] The first important data file to be encrypted can be an engineering file, a firmware file, or an important variable file that a technician wants to download, etc.
[0232] In the process of specifically implementing step S1001, in the running state of the trusted PLC, obtain the plaintext corresponding to the engineering file, firmware file, or important variable file that a technician wants to download during the business operation.
[0233] Step S1002: Encrypt the first important data file to be encrypted based on the SM2 / SM4 algorithm of the national cryptography.
[0234] In the process of specifically implementing step S1002, based on the SM2 / SM4 algorithm of the national cryptography, use the SM encryption function and a preset key to encrypt the first important data file to obtain the ciphertext corresponding to the first important data file, that is, the engineering file, firmware file, or important variable file that wants to be downloaded.
[0235] In the embodiment of the present invention, under the control of the secure and trusted policy, the trusted firmware obtains the important data file during the business operation and encrypts the important file based on the SM2 / SM4 algorithm of the national cryptography, so that the PLC can call the corresponding national cryptography algorithm according to different important data files. Thus, it can prevent the important data file from being stolen and prevent the information of the important data file from being leaked.
[0236] Based on the above Figure 10 shown protection method for dynamic measurement of the industrial control system PLC, combined with Figure 10 , such as Figure 11 shown, another protection method for dynamic measurement of the industrial control system PLC provided by the embodiment of the present invention, this method further includes:
[0237] Step S1003: In the running state of the PLC, obtain the encrypted important data file during the business operation.
[0238] In the process of specifically implementing step S1003, in the running state of the PLC, obtain the ciphertext corresponding to the encrypted engineering file, firmware file, or important variable file during the business operation.
[0239] Step S1004: Decrypt the encrypted file based on the SM2 / SM4 algorithm of the national cryptography to obtain the second important data file.
[0240] In the process of specifically implementing step S1004, based on the national cryptography SM2 / SM4 algorithm, through the SM decryption function corresponding to the SM encryption function and the key matching the encrypted file, the ciphertext corresponding to the engineering file, firmware file or important variable file is decrypted to obtain the second important data file, that is, the plaintext.
[0241] Step S1005: Compare the second important data file with the key data file of the PLC. If it meets the expectation, determine that the event corresponding to the second important data file meets the expectation, and execute step S1006. If it does not meet the expectation, determine that the event corresponding to the second important data file does not meet the expectation, and execute step S1007.
[0242] In the process of specifically implementing step S1005, determine whether the second important data file is consistent with the key data file of the PLC. If they are consistent, determine that the event corresponding to the second important data file meets the expectation, and execute step S1006. If they are not consistent, determine that the event corresponding to the second important data file does not meet the expectation, and execute step S1007.
[0243] It should be noted that the key data file of the PLC is obtained in advance.
[0244] Step S1006: Continue to execute the event corresponding to the second important data file.
[0245] Step S1007: Execute corresponding actions according to the security and trust policy, and generate an audit log containing the unexpected result, and send it to the security management platform of the PLC.
[0246] It should be noted that the specific implementation process of step S1007 is the same as that of the above step S606 and can be referred to each other.
[0247] In the embodiment of the present invention, under the control of the security and trust policy, the trusted firmware obtains the important data files during the operation of the service, and encrypts the important files based on the national cryptography SM2 / SM4 algorithm to obtain the ciphertext of the important files. After the encryption process, the ciphertext of the important files is obtained. Based on the national cryptography SM2 / SM4 algorithm, through the SM decryption function corresponding to the SM encryption function and the key matching the encrypted file, the ciphertext of the important files is decrypted. So that the PLC can call the corresponding national cryptography algorithm according to different important data files. Thus, it can prevent the important data files from being stolen and prevent the information of the important data files from being leaked.
[0248] For a better understanding of the above Figure 10 and Figure 11 the content shown below, an example is given for illustration.
[0249] Such as Figure 12As shown, when the trusted PLC is in the running state, obtain the plaintext P corresponding to the engineering file a that the technician wants to download during the business operation.
[0250] Based on the national cryptography SM2 / SM4 algorithm, use the encryption functions of SM2 / SM4 and the preset key K to encrypt the plaintext P corresponding to the engineering file a that the technician wants to download, and obtain the ciphertext C corresponding to the engineering file a.
[0251] Obtain the ciphertext C corresponding to the encrypted engineering file a during the business operation; based on the national cryptography SM2 / SM4 algorithm, by using the encryption functions of SM2 / SM4 and the key K matching the encrypted file, decrypt the ciphertext C corresponding to the engineering file a, and obtain the plaintext P corresponding to the engineering file a with successful decryption, that is, the second important data file.
[0252] Determine that the event corresponding to the second important data file meets the expectation, and continue to execute the engineering file a corresponding to the second important data file.
[0253] In the embodiment of the present invention, under the control of the secure and trusted policy, the trusted firmware obtains the important data files during the business operation, and performs encryption processing on the important files based on the national cryptography SM2 / SM4 algorithm to obtain the ciphertexts of the important files. After the encryption processing, obtain the ciphertexts of the important files. Based on the national cryptography SM2 / SM4 algorithm, decrypt the ciphertexts of the important files through the SM decryption function corresponding to the SM encryption function and the key matching the encrypted file. Enable the PLC to call the corresponding national cryptography algorithm according to different important data files. Thereby, it can prevent the important data files from being stolen and prevent the information of the important data files from being leaked.
[0254] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A protection method for dynamic measurement of PLC in an industrial control system, characterized in that The method includes: When the trusted programmable logic controller (PLC) is in an operating state, obtaining the data to be measured corresponding to any event based on the access control ABAC mechanism; Invoking the measurement policy stored in the trusted hardware platform, and measuring the data to be measured based on the measurement policy to obtain a measurement value; Querying the trusted data corresponding to the event pre-stored in the trusted reference database to calculate the measurement value, and obtaining the trusted value corresponding to the determination result; Determining whether the event meets the expectation according to the trusted value; If it meets the expectation, continue to execute the event; If it does not meet the expectation, perform corresponding actions according to the security and trust policy, generate an audit log containing the unexpected result, and send it to the security management platform of the PLC; Wherein, when the arbitrary event is an access request for a subject to access an object, the step of obtaining the data to be measured corresponding to any event based on the access control ABAC mechanism when the trusted programmable logic controller (PLC) is in an operating state includes: Obtaining the access request for the subject to access the object, and determining the type of the access request, where the access request contains the ID of the subject; Querying the security and trust policy corresponding to the ID of the subject; Obtaining the attribute information of the subject and the object according to the security and trust policy; Packing the attribute information of the subject, the attribute information of the object, and the type of the access request as the data to be measured; The step of invoking the measurement policy stored in the trusted hardware platform, and measuring the data to be measured based on the measurement policy to obtain a measurement value includes: If the measurement data is the attribute information of the subject, the attribute information of the object, and the type of the access request, invoking the measurement policy corresponding to the attribute information of the subject, the attribute information of the object, and the type of the access request stored in the trusted hardware platform, and respectively measuring the attribute information of the subject, the attribute information of the object, and the type of the access request to obtain a first measurement value; When the arbitrary event includes an access request for a subject to access an object, the step of querying the trusted data corresponding to the event pre-stored in the trusted reference database to calculate the measurement value and obtaining the trusted value corresponding to the determination result includes: Querying the first assessment item coefficient corresponding to the access request for the subject to access the object pre-stored in the trusted reference database; Calculating the product of the first assessment item coefficient and the first measurement value to obtain a first trusted value.
2. The method according to claim 1, characterized in that, When the arbitrary event is to measure the operating environment of the system, the step of obtaining the data to be measured corresponding to any event based on the access control ABAC mechanism when the trusted programmable logic controller (PLC) is in an operating state includes: According to a set period, reading the data to be measured from a specified address based on the access control ABAC mechanism, where the specified address points to a code area for storing PLC service program code, kernel operating program system (OS) code, and computing firmware code, and the data to be measured includes the PLC service program code, kernel operating program system (OS) code, and / or computing firmware code stored at the specified address in the code area.
3. The method according to claim 2, wherein Invoking the measurement policy stored in the trusted hardware platform, and measuring the data to be measured based on the measurement policy to obtain a measurement value, including: If the measurement data is the PLC service program code, the kernel operation program system OS code, and / or the computing firmware code, invoke the measurement policies corresponding to the PLC service program code, the kernel operation program system OS code, and / or the computing firmware code stored in the trusted hardware platform, and measure the PLC service program code, the kernel operation program system OS code, and / or the computing firmware code respectively to obtain a second measurement value.
4. The method according to claim 3, characterized in that If any event includes measuring the operating environment of the system, query the trusted data corresponding to the event pre-stored in the trusted reference database to calculate the measurement value to obtain a trusted value corresponding to the determination result, including: Query the second assessment item coefficient corresponding to the measurement system operating environment pre-stored in the trusted reference database; Calculate the product of the second assessment item coefficient and the second measurement value to obtain a second trusted value.
5. The method according to claim 1, wherein It further includes: When the industrial control system PLC is in the running state, obtain the first important data file to be encrypted during the business operation, and encrypt the first important data file to be encrypted based on the SM2 / SM4 algorithm of the national cryptography; and / or When the industrial control system PLC is in the running state, obtain the encrypted important data file during the business operation, and decrypt the encrypted important data file based on the SM2 / SM4 algorithm of the national cryptography to obtain a second important data file; Compare the second important data file with the key data file of the PLC; If it meets the expectation, continue to execute the event corresponding to the second important data file; If they are inconsistent, determine that the event corresponding to the second important data file does not meet the expectation, execute corresponding actions according to the security and trust policy, and generate an audit log containing the non-conforming result, and send it to the security management platform of the PLC.
6. An industrial control system PLC, characterized in that, The industrial control system PLC includes: a trusted PLC, a trusted hardware platform, and a security management platform; The trusted PLC includes a trusted firmware, a service firmware, and an access control firmware. Among them, the trusted firmware and the service firmware respectively independently occupy a hardware CPU, and the service firmware includes a control logic operation firmware; The trusted firmware is used to, when the trusted PLC is in the running state, obtain the data to be measured corresponding to any event occurring based on the access control ABAC mechanism, invoke the measurement policy stored in the trusted hardware platform, measure the data to be measured based on the measurement policy to obtain a measurement value; query the trusted data corresponding to the event pre-stored in the trusted reference database to calculate the measurement value to obtain a trusted value corresponding to the determination result; determine whether the event meets the expectation according to the trusted value. If it meets the expectation, continue to execute the event. If it does not meet the expectation, execute corresponding actions according to the security and trust policy, and generate an audit log containing the non-conforming result, and send it to the security management platform of the PLC; Among them, the trusted firmware includes: a secure trusted policy firmware and a trusted computing firmware; The secure trusted policy firmware is used to, when the arbitrary event is an access request for a subject to access an object, obtain the access request for the subject to access the object by the access control firmware based on the control logic operation firmware, and determine the type of the access request, where the access request includes the ID of the subject; query the secure trusted policy corresponding to the ID of the subject; obtain the attribute information of the subject and the object according to the secure trusted policy; and package the attribute information of the subject, the attribute information of the object, and the type of the access request as the data to be measured; The trusted computing firmware is used to, based on the control logic operation firmware, call the measurement policies corresponding to the attribute information of the subject, the attribute information of the object, and the type of the access request stored in the trusted hardware platform, measure the attribute information of the subject, the attribute information of the object, and the type of the access request respectively, to obtain a first measurement value; query the first assessment item coefficient corresponding to the access request for the subject to access the object pre-stored in the trusted benchmark database; and calculate the product of the first assessment item coefficient and the first measurement value to obtain a first trust value.
7. The industrial control system PLC according to claim 6, wherein The secure trusted policy firmware is further used to, when the arbitrary event is to measure the system running environment, at a set period, based on the control logic operation firmware, read the data to be measured from a specified address according to the access control ABAC mechanism, where the specified address points to a code area for storing PLC service program code, kernel operation program system OS code, and computing firmware code, and the data to be measured includes the PLC service program code, kernel operation program system OS code, and / or computing firmware code stored at the specified address in the code area; The trusted computing firmware is further used to call the measurement policies corresponding to the PLC service program code, kernel operation program system OS code, and / or computing firmware code stored in the trusted hardware platform, measure the PLC service program code, kernel operation program system OS code, and / or computing firmware code respectively, to obtain a second measurement value; Query the second assessment item coefficient corresponding to the measurement of the system running environment pre-stored in the trusted benchmark database; Calculate the product of the second assessment item coefficient and the second measurement value to obtain a second trust value.
8. The PLC of the industrial control system according to claim 6, wherein The trusted firmware is further used to, in the trusted PLC running state, obtain the first important data file to be encrypted during the business operation process, and encrypt the first important data file to be encrypted based on the SM2 / SM4 algorithm of the national cipher; And / or, in the trusted PLC running state, obtain the encrypted important data file during the business operation process, and decrypt the encrypted important data file based on the SM2 / SM4 algorithm of the national cipher to obtain a second important data file; Compare the second important data file with the key data file of the PLC; if it meets the expectation, continue to execute the event corresponding to the second important data file; If they are inconsistent, determine that the event corresponding to the second most important data file does not meet expectations, perform corresponding actions according to the security and trust policy, generate an audit log containing the unexpected results, and send it to the security management platform.
Citation Information
Patent Citations
Operation system trusted guide method based on real mode technology
CN104751063A
PLC dynamic measurement method, device and system, storage medium and electronic device
CN110826075A