Multi-level identity authentication method based on time-frequency domain gene feature extraction and fusion portrait
By performing multi-level mathematical representation and feature extraction in the time-frequency domain, combining multidimensional Taylor networks and Mallat algorithms, a multi-level genetic portrait is constructed for identity authentication, which solves the problem of inaccurate identity authentication in existing technologies and achieves rapid and accurate attack detection and information integrity assurance for industrial cyber-physical systems.
Patent Information
- Application Number
- CN202210616600.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-01
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2042-06-01
AI Technical Summary
Existing security defense methods for industrial cyber-physical systems have difficulty achieving accurate identity authentication and attack detection in the face of diverse attacks, especially those based on data-driven, system models, watermarks, and fingerprints, which are inefficient in processing big data or easily evaded by attackers.
A multi-level identity authentication method based on time-frequency domain gene feature extraction and fusion portrait is adopted. The data is decomposed through multi-level mathematical representation and wavelet transform, combined with the self-encoding multidimensional Taylor network and Mallat algorithm to extract multi-granularity features, and multi-level comparison is performed through Euclidean distance measurement to construct a multi-scale gene portrait for identity authentication.
It achieves fast and accurate identity authentication for industrial cyber-physical systems, can detect highly concealed attack behaviors, and ensure the integrity and security of information received by the equipment.
Smart Images

Figure CN115080937B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a multi-level identity authentication method based on time-frequency domain gene feature extraction and fusion profiling. Background Art
[0002] In the industrial sector, the interaction between the physical and information layers through communication networks forms the Industrial Internet of Things (IIoT) system—the Industrial Cyber-Physical System (ICPS), which closely connects cyberspace with physical space. However, the openness and interconnectedness of networks, as well as security vulnerabilities in protocols, have led to various and multi-layered cyber attacks.
[0003] Currently, security defense approaches for industrial cyber-physical systems fall into three main categories: data-driven approaches, system model-based approaches, and approaches based on watermarks, fingerprints, and system robustness. All three approaches suffer from the following drawbacks: 1) Data-driven approaches focus on training intrusion detection systems, protecting equipment by examining the contents of each packet. However, with the increasing diversity of attack behaviors, accurately labeled datasets are difficult to obtain. 2) System model-based approaches focus on designing detectors based on system parameters and structure. Because internal attackers have complete knowledge of these parameters and structure, a variety of carefully designed attacks can be designed to disrupt system performance while evading detector detection. 3) Approaches based on watermarks, fingerprints, and system robustness. Watermarks essentially encrypt and decrypt data, which requires bandwidth for wireless transmission channels and is inefficient for processing large amounts of data. Enhancing system robustness should be used as a supplementary tool for attack detectors, not as the primary defense against attackers. Fingerprinting approaches often consider the scale of the time or frequency domain, without integrating the two. Summary of the Invention
[0004] Based on the above problems, the present invention provides the following technical solutions:
[0005] The multi-level identity authentication method based on time-frequency domain gene feature extraction and fusion profiling has the following steps:
[0006] Perform multi-level mathematical representation of the received information; in the time domain, use multi-order moments as basis functions to decompose the received data into the sum of different order moments; in the frequency domain, use the wavelet transform multi-scale analysis theory to decompose the received data into the sum of a series of wavelets;
[0007] Extract multi-granularity features based on multi-level mathematical representation; regard the importance of received data at different moments as multi-granularity features in the time domain, and regard the wavelet expansion coefficients of received data as multi-granularity features in the frequency domain;
[0008] The multi-granularity features extracted in the time domain and frequency domain are fused into a multi-level genetic profile of the received data; a multi-level comparison is performed by comparing the genetic profile of the received data with the genetic profile of the legitimate data to determine whether the data is complete; if the data is complete, the identity authentication is successful, otherwise it fails.
[0009] Preferably, a self-encoding multi-dimensional Taylor network model is used to extract multi-granularity features in the time domain, and a Mallat algorithm is used to decompose the received information to extract multi-granularity features in the frequency domain.
[0010] Preferably, when performing multi-level comparisons between gene profiles based on received data and legal gene profiles, a Euclidean distance metric is used for fine matching.
[0011] The present invention utilizes the aforementioned identity authentication method and employs a multi-scale metric based on genetic profiling to ensure the integrity of information received by the device. First, a multi-level mathematical representation of device data is performed using high-order moments and wavelets, respectively, to demonstrate the importance of different moments and the sophistication of different domains. Next, a Kalman-based autoencoder multidimensional Taylor network and a Mallat algorithm are used to extract multi-granular features, overcoming the inherent limitations of feature extraction. Finally, a multi-scale genetic profiling matching model is constructed, achieving rapid and accurate identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 is an overall flow chart of an embodiment of the present invention;
[0013] Figure 2 This is the industrial cyber-physical system model in the embodiment of the present invention;
[0014] Figure 3 This is the basic framework for identity authentication based on genetic profiling in the embodiments of the present invention;
[0015] Figure 4 This is the process of extracting multi-granularity features using the self-encoding multi-dimensional Taylor network model in an embodiment of the present invention;
[0016] Figure 5 This is the process of extracting multi-granularity features using the Mallat algorithm in an embodiment of the present invention;
[0017] Figure 6 A comparison chart of the gene profiles of received data and legal data in an embodiment of the present invention;
[0018] Figure 7 This is a model diagram of a four-cylinder water system in an embodiment of the present invention;
[0019] Figure 8 is a state estimation diagram of the system in Case 1 according to an embodiment of the present invention;
[0020] Figure 9 is a chi-square detector response diagram in Case 1 in an embodiment of the present invention;
[0021] Figure 10 This is a comparison diagram of the gene portraits in Case 1 in the embodiment of the present invention;
[0022] Figure 11 This is the fine metric graph in Case 1 in the embodiment of the present invention;
[0023] Figure 12 is a state estimation diagram of the system in Case 1 according to an embodiment of the present invention;
[0024] Figure 13 : is the chi-square detector response diagram in Case 2 in an embodiment of the present invention;
[0025] Figure 14 This is a comparison diagram of the gene portraits in Case 2 in the embodiment of the present invention;
[0026] Figure 15 This is the fine metric graph in Case 2 in an embodiment of the present invention;
[0027] Figure 16 is a state estimation diagram of the system in Case 3 according to an embodiment of the present invention;
[0028] Figure 17 : is the chi-square detector response diagram in Case 3 of the embodiment of the present invention;
[0029] Figure 18 This is a comparison diagram of the gene portraits in Case 3 of the embodiment of the present invention;
[0030] Figure 19 This is the fine metric graph in Case 3 in an embodiment of the present invention. DETAILED DESCRIPTION
[0031] The technical solution of the present invention is further described below with reference to the accompanying drawings and embodiments.
[0032] like Figure 1 As shown, the steps of the multi-level identity authentication method are as follows:
[0033] The received information is represented mathematically at multiple levels. In the time domain, the received data is decomposed into the sum of different order moments using multiple order moments as basis functions. In the frequency domain, the received data is decomposed into the sum of a series of wavelets using the wavelet transform multi-scale analysis theory.
[0034] Multi-granularity features are extracted based on multi-level mathematical representations. The importance of the received data at different moments is considered as multi-granularity features in the time domain, while the wavelet expansion coefficients of the received data are considered as multi-granularity features in the frequency domain. Specifically, a self-encoding multidimensional Taylor network model is used to extract multi-granularity features in the time domain, while the Mallat algorithm is used to decompose the received information to extract multi-granularity features in the frequency domain.
[0035] The multi-granularity features extracted in the time domain and frequency domain are fused into a multi-level genetic profile of the received data.
[0036] The Euclidean distance metric is used to perform multi-level fine matching and comparison between the genetic profile of the received data and the legitimate genetic profile to determine whether the data is complete; if the data is complete, the identity authentication is successful, otherwise it fails.
[0037] The above method is described in detail below with reference to specific embodiments.
[0038] 1. Industrial Cyber-Physical System Model
[0039] like Figure 2 As shown, the system is a discrete-time linear time-invariant system, and the system equations and observation equations are as follows:
[0040]
[0041] Among them: A, B, C are the state vectors of the system; A, B, C are the system transfer matrices; is the measurement vector of the sensor; and are process noise and measurement noise respectively. Assume that they are both Gaussian white noise with mean 0 and variance respectively. and as well as Independent of each other.
[0042] The remote state estimator is used as the computing unit and adopts Kalman filtering algorithm.
[0043] Based on formula (1), the state estimation and the corresponding estimation error covariance are expressed as and
[0044]
[0045]
[0046] According to the standard Kalman filter, as follows:
[0047]
[0048] 2. Multi-level mathematical representation of time series data based on high-order moments and high-spectral features
[0049] In the time domain, the multi-order moments of the data are used as basis functions to decompose the received data y(k) into the sum of the superposition of different order moments.
[0050]
[0051] Where: y(k) represents the data received at time k; y i (k) represents the i-th sub-data at time k; g i (k) represents the basis function vector, i.e., the i-th order moment characteristic (including the self-multiplication term and the mutual multiplication term); θ i (k) represents the projection of the data y(k) on the i-th order moment feature, that is, the importance of the i-th order moment feature in the data y(k).
[0052] In the frequency domain, the wavelet transform multi-scale analysis theory is used to decompose the received data y(k) into the sum of a series of wavelets.
[0053]
[0054] in: It's wavelet.
[0055] In formula (6), let a = 2 m , b=n·2 m , then the binary wavelet transform of data y(k) is:
[0056]
[0057] 3. Real-time calculation and multi-granularity extraction of data time-frequency gene features based on sequential filtering
[0058] For feature extraction in the time domain, the importance of data at different moments is regarded as multi-granularity features in the time domain. To this end, a self-encoding multi-dimensional Taylor network model is used to extract multi-granularity features, such as Figure 4 shown.
[0059] Assume that the data y(k) at time k is an n×m matrix.
[0060] First, we split the data y(k) into n 1×m dimensional vectors by row.
[0061]
[0062] Among them, 1×m is the 1×m-dimensional vector in the i-th row.
[0063] Then, y i(k) is used as input and y(k) is used as output, and formula (8) is transformed according to Taylor's formula.
[0064]
[0065] Among them, f(y i (k)) is the function described by the self-encoding multidimensional Taylor network model; ω j Represents the weight of the j-th variable before the multiplication term, that is, θ in formula (5) i (k); N(n,m) represents the total number of terms in the expansion; λ i,j Indicates the y in the product term of the jth variable i The power of .
[0066] Finally, the Kalman filter algorithm is used to obtain ω j , convert formula (9) into matrix form.
[0067]
[0068]
[0069] Definition: Objective function:
[0070] J(W i )=E{W i |Y(1),Y(2),...,Y(k)}
[0071] Problem 1: Given the sequence Y(1), Y(2), ..., Y(k), find W i The optimal estimate of (k+1):
[0072]
[0073] Minimize the variance of the estimation error, that is:
[0074]
[0075] To address problem 1, a Kalman filter-based method is used to update the parameters of the self-encoding multidimensional Taylor network in real time. The state model and measurement model that conform to the Kalman filter are established as follows:
[0076] W(k+1)=AW(k)+α(k)(12)
[0077] Y L (k+1)=HW(k)+β(k)(13)
[0078] Among them, A is set to the unit matrix, H is set to the unit matrix, α(k) is the noise of the state equation, and β(k) is the noise of the measurement equation.
[0079] The Kalman filtering method is used to obtain the estimated weights. The specific process is as follows:
[0080] 1) Assume weights is the state in the Kalman filter Right now:
[0081]
[0082] Among them, W(k|k-1) represents the state value at time k, and W(k-1|k-1) represents the state value at time k-1.
[0083] 2) Predict the covariance matrix P(k|k-1) of W(k|k-1)
[0084] P(k|k-1)=AP(k-1|k-1)A T +Q (15)
[0085] Where P(k|k-1) is the covariance corresponding to W(k|k-1), P(k-1|k-1) is the covariance corresponding to W(k-1|k-1), and K(k) is the covariance matrix of the noise in the state equation.
[0086] 3) Calculate the Kalman gain matrix K(k)
[0087] K(k)=P(k|k-1)H T [HP(k|k-1)H T +R] -1 (16)
[0088] 4) Find the optimal estimate
[0089]
[0090] 5) Update The covariance P(k|k)
[0091] P(k|k)=P(k|k-1)-K(k)HP(k|k-1)(18)
[0092] The weight parameters of the autoencoder-multidimensional Taylor network estimated at time k The M-order coefficient in the received data is the M-level feature θ in the time domain M (k).
[0093] For multi-granularity feature extraction in the frequency domain. Figure 5 As shown, based on formula (7), the Mallat algorithm is used to decompose the received information y(k) as follows:
[0094]
[0095] Take H1 as the first-level feature of the received information in the frequency domain space, H2 as the second-level feature of the received information in the frequency domain space, and so on. M As the M-1 level feature of the received information in the frequency domain, L M As the M-level features of the received information in the frequency domain space.
[0096] 4. Multi-level image representation of time-frequency gene fusion portraits based on multi-granularity feature extraction
[0097] The multi-granularity features extracted in the time domain The multi-granularity features F_f extracted in the frequency domain are [H1H2…H M L M ] fused into a multi-level genetic profile that receives information The details of generating gene profiles are given in Table 1. In the two-dimensional plane, xoy follows the colorful color index to draw a colorful gene portrait.
[0098] Table 1 Gene profile extraction algorithm
[0099]
[0100] 5. Multi-scale and precise identity authentication based on multi-level genetic profile similarity
[0101] Details of the multi-scale metrics are given in Table 2.
[0102] Match the level 1 gene portrait of the received data with the level 1 gene portrait of the legal data, match the level 2 gene portrait of the received data with the level 2 gene portrait of the legal data, and so on, match the level M gene portrait of the received data with the level M gene portrait of the legal data. The process is as follows: Figure 6 shown.
[0103] As shown in Table 2, the Euclidean distance metric (L1 norm) is used as the algorithm matching criterion.
[0104]
[0105] Among them: g represents the gene portrait of the gth level; G_p() represents the gene portrait of the received information, and l_G_p() represents the gene portrait of the legal data.
[0106] Table 2 Identity authentication algorithm
[0107]
[0108] Through multi-level matching, data detection is more refined, capable of detecting even subtle value changes caused by highly concealed attacks. Furthermore, color gene profile comparison can quickly determine the integrity of the currently received information by color differences, and the accuracy of the currently received information by traversing the differences in the gene profiles.
[0109] 6. Simulation Verification
[0110] The four-tank water system is used as an experimental platform to verify the effectiveness of the attack detection method. Figure 7 As shown. The system has four water tanks, and the water level in the tank is h i , i=1,2,3,4 as the system state value, that is, x=[h1,h2,h3,h4] T . Two valves V i , i=1,2 as the input value of the system, that is, u=[V1,V2] T The water levels of the first and second water tanks are used as the output of the system, i.e. y = [h1, h2] T Assume that the nonlinear system dynamics is discretized and linearized at the moment the system reaches equilibrium, and the moment the entire system reaches equilibrium is used as the initial state of the system. The system parameters are as follows:
[0111]
[0112]
[0113]
[0114] x0=[5,5,2.044,1.399] T ,
[0115] u=[0.724,1.165] T .
[0116] The threshold of the chi-square detector is β=7.013.
[0117] Without losing generality, three attack behaviors are used to verify the effectiveness of this scheme.
[0118] Case 1
[0119] This method was validated using the attack vectors designed in "State estimation under false data injection attacks: Security analysis and system protection." The measured values under attack are as follows:
[0120]
[0121] Where: σ(k+1) takes the value σ or -σ, and σ∈(0,1); λ q represents the eigenvalue of matrix A,
[0122] Assume that the attacker starts the attack when k=10 and ends the attack when k=131.
[0123] like Figure 8 As shown in , the attack behavior has a great impact on the estimated value of the system state. Figure 9 As shown in the figure, during the period when the system was attacked, the red line segment and the black line segment were not much different, resulting in the attack behavior not being able to trigger the detector alarm, and thus making it impossible for observers to discover and deal with security risks in a timely manner.
[0124] like Figure 10-11 As shown in Figure 2, a three-level gene profiling test is used. Figure 10 In the data, from time k=1 to k=9 and after time k=131, the primary, secondary, and tertiary gene portraits of the received information completely match the gene portraits of the legal information (the colors are the same); from time k=10 to k=130, the gene portraits of the received data do not match the gene portraits of the legal information (the colors are different). Figure 11 From the above, we can clearly see that the system was attacked between time k = 10 and k = 130. Note that the numerical variation range of the third-level genetic profile is greater than that of the second-level genetic profile, which is greater than that of the first-level genetic profile. Therefore, the genetic profile detection method can ensure the integrity of the received data.
[0125] Table 3 Similarity metrics between the gene profiles of received data and legal data in Case 1
[0126]
[0127] Case 2
[0128] Replay attack is used as the attack vector to test the effectiveness of our proposed method. The attacking measurement values are as follows:
[0129] y a (k) = y(k-8) (22)
[0130] Assume that the attacker starts the attack when k=10 and ends the attack when k=131.
[0131] like Figure 12-13 As shown in Figure 2, similar to Case 1, the attack behavior has a destructive effect on the system, but the chi-square detector cannot detect this type of attack because the residual transformation range when attacked is the same as the residual transformation range when not attacked.
[0132] like Figure 14-15 As shown in Table 4, using the three-level gene portrait detection, it can be clearly seen that the information transmitted is incomplete within k = 10 to k = 130. Figure 15 The same conclusion as in Case 1 was reached: the tertiary gene profile was generally more effective at detecting aggressive behavior than the secondary gene profile, which was also more effective than the primary gene profile. Therefore, the effectiveness of the gene profile detection method was verified.
[0133] Table 4 Similarity measurement between the gene profile of the received information and the gene profile of the legitimate information in Case 2
[0134]
[0135] Case 3
[0136] In this example, we use the attack vector from "Blended Active Detection Strategy for False Data Injection Attacks in Cyber-Physical Systems" to verify the effectiveness of our proposed method. Furthermore, we compare the attack detection rate of our proposed method with that of the paper. The initial state of the system is x0 = [5.1, 5.2, 2.344, 1.799] T The attack vector is as follows:
[0137]
[0138] Assume that the attacker starts the attack at k=300 and ends the attack at k=350.
[0139] For attack behaviors, the performance of the detector is shown below:
[0140]
[0141] Table 5 records the experimental results of more than 1000 experiments. As can be seen from the table, the detection rate of the method proposed in this paper is higher than the method proposed in the paper "Blended Active Detection Strategy for False Data Injection Attacks in Cyber-Physical Systems". Due to the limited space of the article, we only show the attack vector u a (k) = [-0.03, -0.03] T A single simulation.
[0142] like Figure 16-17As shown in , the residual caused by this attack behavior is within the tolerance range of the chi-square detector, which is the same as Case 1 and Case 2. Figure 18 It is difficult to detect whether the information received from the color gene portrait match is complete. However, through Table 6 and Figure 19 We can clearly see that the information received from time k = 300 to time k = 350 is incomplete. Furthermore, the third-level genetic profiles show the greatest degree of discrepancy. This demonstrates the accuracy of the genetic profile detection method and further validates the effectiveness of the multi-level genetic profile-based identity authentication method.
[0143] Table 5 Detection rates of different attack vectors
[0144]
[0145] Table 6 Similarity measurement between the gene profile of the received information and the gene profile of the legitimate information in Case 3
[0146]
[0147] The above are specific embodiments of the present invention, but the scope of protection of the present invention should not be limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed by the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection defined in the claims.
Claims
1. A multi-level identity authentication method based on time-frequency domain gene feature extraction and fusion portrait, characterized by: Perform multi-level mathematical representation of received information; In the time domain, the received data is decomposed into the sum of different order moments using multi-order moments as basis functions; in the frequency domain, the received data is decomposed into the sum of a series of wavelets using the wavelet transform multi-scale analysis theory; Multi-granularity features are extracted based on multi-level mathematical representations; the importance of received data at different moments is regarded as multi-granularity features in the time domain, as follows: ; Where, express Data received at all times; represents the basis function vector, that is moment characteristics; Representation data exist The projection on the moment feature, that is The moment feature in the data The importance of The wavelet expansion coefficients of the received data are regarded as multi-granularity features in the frequency domain; In the time domain, the weight parameters of the self-encoding multi-dimensional Taylor network model are solved to obtain multi-granularity features in the time domain. In the frequency domain, the Mallat algorithm is used to decompose the received data into a series of wavelet sums to obtain multi-granularity features in the frequency domain. The multi-granularity features extracted in the time domain and frequency domain are integrated into a multi-level genetic profile of the received data. The genetic profile of the received data is compared with the genetic profile of the legitimate data to determine whether the data is complete. If the data is complete, the identity authentication succeeds; otherwise, it fails. The multi-level comparison is to match the level 1 gene portrait of the received data with the level 1 gene portrait of the legal data, the level 2 gene portrait of the received data with the level 2 gene portrait of the legal data, and so on, to match the level M gene portrait of the received data with the level M gene portrait of the legal data.
2. The multi-level identity authentication method according to claim 1, characterized in that: When performing multi-level comparisons between the gene profiles of the received data and the legal gene profiles, the Euclidean distance metric is used for fine matching.
Citation Information
Patent Citations
Rolling bearing fault diagnosis method based on time-frequency domain multidimensional vibration feature fusion
CN104655423A
Continuous identity authentication method based on mouse behavior time-frequency conjoint analysis
CN112949690A