A digital twin-based industrial internet security assessment system

CN115865408BActive Publication Date: 2026-08-14JIANGSU JINLING TECH GRP CORP +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-28
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0005]本发明旨在将复杂问题具象化、层次化,利用层次化分析法,基于数字孪生技术,对工业互联网提供更加精准、精细的安全评估系统,解决对昂贵脆弱的工业互联网的仿真模拟和低成本验证,实现了对工业互联网安全问题进行全面系统的层次化评估,并且本发明的安全评估系统也直接适用于真实工业互联网

Benefits of technology

[0034]本发明的有益效果:与现有技术相比,提供了一种基于数字孪生的工业互联网安全评估系统,评估方式上使用了层次化评估,将安全评估问题进行层次化划分,从系统性能和系统可信度两大方面对工业互联网制定了全方面、多层次的安全评估指标,运用层次化分析法计算出各层指标权重,自下而上进行安全评估,并且专家群体判断降低了主观打分对评估的影响;提出了各种针对工业互联网进行数据采集的系统,包括统计、测量、数学计算和模拟攻击等手段,获取了网络信息、工业设备信息和系统安全状态信息,作为评估的基础,并且这套数据采集方式同样适用于真实的工业互联网;本发明不仅对工业互联网中采用的常规网络安全技术进行评估,还对像可信计算这种解决工业云安全问题的新型解决方案进行评估。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865408B_ABST
    Figure CN115865408B_ABST
Patent Text Reader

Abstract

A digital twin-based industrial internet security assessment system includes: 1) a digital twin module, which uses digital twin technology to simulate cloud platforms, SDN networking, and industrial operation technologies in the industrial internet system to construct an industrial digital twin; 2) a data acquisition module, which collects data from the simulation system and the real industrial internet, and categorizes the collected data into network information, industrial equipment information, and system security status information according to different assessment indicators; 3) a data analysis module, which saves the data from the data acquisition module into a database, compares the data generated by virtual manufacturing and real manufacturing to obtain the deviation between the two, and optimizes and improves the simulation system based on the deviation to make the assessment results of the simulation system more reliable; and 4) a security assessment module, which obtains the weights of each indicator after passing a consistency check.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and more specifically to an industrial internet security assessment system based on digital twins. Background Technology

[0002] An industrial internet platform is an industrial cloud platform that addresses the digital, networked, and intelligent needs of the manufacturing industry by building a service system based on massive data collection, aggregation, and analysis, supporting ubiquitous connectivity, flexible supply, and efficient allocation of manufacturing resources.

[0003] The Industrial Internet (IIoT) is a type of cyber-physical system, a complex, expensive, and vulnerable multidimensional system encompassing computing, networking, control, and the physical environment. IIoT security is a complex, integrated security issue affecting platforms, networks, terminals, and data. Therefore, a suitable security assessment system is needed to better evaluate IIoT security. Traditional security assessment systems often employ interviews, inspections, and tests, specifically divided into four steps: personnel interviews, document review, manual verification, and tool testing. These systems often require coordination between assessors and platform technicians, resulting in low levels of intelligence. Furthermore, traditional security assessment systems often require significant investment of manpower, resources, and time during data collection, leading to high costs. The assessment results are also susceptible to the subjective opinions of the assessors, making it difficult to guarantee fairness. Currently, many new solutions to industrial cloud security issues are emerging, such as trusted computing, a hardware-software integrated technology. However, traditional IIoT security assessments often focus on evaluating conventional network security technologies, with limited evaluation of these new solutions.

[0004] Software-defined networking (SDN) is an architecture that abstracts different, distinguishable layers of a network, making it agile and flexible. SDN aims to improve network control by enabling enterprises and service providers to quickly respond to evolving business needs, and is an implementation of network virtualization. Its core technology, OpenFlow, separates the control plane from the data plane of network devices, thereby achieving flexible control of network traffic, making the network more intelligent, and providing a good platform for innovation in core networks and applications. Summary of the Invention

[0005] This invention aims to visualize and hierarchize complex problems, and by using hierarchical analysis and based on digital twin technology, it provides a more accurate and refined security assessment system for the Industrial Internet. This solves the problems of simulation and low-cost verification of the expensive and vulnerable Industrial Internet, and realizes a comprehensive and systematic hierarchical assessment of Industrial Internet security issues. Furthermore, the security assessment system of this invention is also directly applicable to real Industrial Internet.

[0006] To achieve the above objectives, this invention proposes an industrial internet security assessment system based on digital twins. This system hierarchically divides complex industrial internet security issues and generates a set of security assessment indicators, including two aspects: system performance and system credibility. System performance includes interconnectivity, network energy efficiency, and production performance; system credibility includes trusted security, cloud security, and data credibility.

[0007] The technical solution of this invention is: an industrial internet security assessment system based on digital twins. It utilizes digital twin technology to construct an industrial internet digital twin, and establishes a security assessment index system from two aspects: system performance and system trustworthiness. This system performs a hierarchical assessment of industrial internet security issues. System performance includes interconnectivity, network energy efficiency, and production performance; system trustworthiness includes trusted security, cloud security, and data trustworthiness.

[0008] The industrial internet security assessment system includes the following modules:

[0009] (1) Digital Twin Module: Based on digital twin technology, this module simulates and emulates the cloud platform, SDN networking, and industrial operation technology in the industrial internet system to construct an industrial digital twin. The cloud platform is deployed through a local server to support various application and management modules required by the industrial internet cloud platform. Global topology management is performed through an SDN controller, and data plane forwarding is performed through an SDN switch. The industrial operation technology simulation includes the simulation of industrial field networks and virtual manufacturing systems.

[0010] (2) Data acquisition module, used to acquire data from the simulation system and the real industrial Internet, and to divide the acquired data into network information, industrial equipment information and system security status information according to different evaluation indicators; among them, network information is acquired through statistical, measurement and mathematical calculation methods; industrial equipment information is data generated by virtual manufacturing and real manufacturing, which is acquired from the cloud platform and obtained through mathematical calculation; system security status information is obtained through configuration verification and resistance to simulated attacks;

[0011] (3) Data analysis module: Save the data in the data acquisition module to the database, compare the data generated by virtual manufacturing and real manufacturing, obtain the deviation between the two, optimize and improve the simulation system based on the deviation, so that the evaluation results of the simulation system are more credible; then use the data in the database to classify the lowest level indicators of the safety assessment system into levels, formulate scoring rules, and obtain the specific scores of the corresponding indicators according to the level.

[0012] (4) The security assessment module obtains an indicator importance judgment matrix by consulting a group of experts. After passing a consistency check, the weights of each indicator are obtained. The weight values ​​of each layer of indicators are combined with the scores of the lowest-level indicators obtained by the data analysis module, and the scores of each layer of indicators are calculated from bottom to top to obtain the overall security assessment result. Finally, a security assessment report is generated, which contains detailed information on the security assessment results and indicators. The report is then fed back to the operators to optimize the real and digital twin industrial internet. The security assessment module is used to quickly and accurately assess the security of the industrial internet based on the indicator importance judgment matrix obtained by consulting a group of experts and by adopting the above-mentioned technical means.

[0013] The system performance and system reliability indicators are hierarchically divided to obtain the lowest-level basic indicators, and the data acquisition module is used to collect data on the lowest-level basic indicators. The system performance is evaluated from three aspects: the level of system informatization, network energy efficiency, and system productivity, involving network information and industrial equipment information in the data acquisition module.

[0014] The system performance indicators include interconnectivity, network energy efficiency, and production performance; among which, interconnectivity includes the smart device network connectivity rate and information network infrastructure coverage; network energy efficiency includes effective throughput, latency, and fairness in resource acquisition; production performance includes status acquisition, system scheduling, and equipment production; the underlying basic indicators related to system performance are evaluated using network information and industrial equipment information from the data acquisition module.

[0015] The system credibility metrics include trusted security, cloud security, and data credibility; where trusted security includes trusted startup, trusted verification, virtual trust, and remote authentication; cloud security includes application security, data security, and network security; and data credibility refers to the accuracy of data in virtual manufacturing and real manufacturing. The data evaluated by the system credibility metrics is the system security status information in the data acquisition module.

[0016] Then, the data analysis module is used to analyze the network information, industrial equipment information and system security status information collected from the above-mentioned underlying basic indicators, classify the data collected from the underlying basic indicators into levels, formulate scoring rules, and obtain specific scores for the corresponding indicators according to the levels.

[0017] The acquisition of network information includes the smart device network connectivity rate, information network infrastructure coverage, effective throughput, latency, and fairness of resource acquisition. Specifically, the smart device network connectivity rate and information network infrastructure coverage are obtained statistically; network latency of each node is tested using network diagnostic tools such as ping; continuous stress testing of network connections in the industrial internet is conducted using network performance evaluation tools such as iperf to obtain the average throughput of the links, and the coefficient of variation (CoV) is used to measure the smoothness of throughput within the observation window; and the Jain Fairness Index (FI) is introduced to measure the fairness of each workshop in obtaining the available bandwidth of the links.

[0018] The industrial equipment information is collected from the cloud platform and obtained through mathematical calculations, including system status, system scheduling, and production performance. The system status examines the real-time performance and accuracy of the cloud platform in acquiring the working status of the workshop and workshop equipment. The system scheduling examines the fairness of the cloud platform in allocating tasks, and similarly, the fairness of the workshop in acquiring the available bandwidth of the link, so the Jain fairness index FI is introduced. The production performance examines the production efficiency of each workshop and the pass rate of the products produced by the workshop equipment.

[0019] The acquisition of security status information includes the implementation strength and coverage of trusted measures adopted by the Industrial Internet, as well as the success rate of the simulation system in resisting simulated attacks. Regarding trusted security, the implementation strength and coverage of trusted measures are assessed by acquiring the coverage of trusted startup devices, the scope of trusted verification, the security level and openness of virtual trusted systems, and the authentication and confidentiality of remote authentication. Regarding cloud security, the assessment is conducted from three aspects: application security, data security, and network security, evaluating whether the system's security measures are comprehensive, real-time, and reliable, and whether they have functions such as access control, security logging, and situational awareness.

[0020] The acquisition of system security status information serves two purposes. First, it assesses the effectiveness and coverage of trusted measures adopted by the Industrial Internet. In terms of trusted security, this involves evaluating the coverage of trusted startup devices, the scope of trusted verification, the security level and openness of virtual trusted systems, and the authentication and confidentiality of remote authentication. Second, in terms of cloud security, the assessment focuses on application security, data security, and network security. This evaluation assesses whether the system's security measures are comprehensive, real-time, and reliable, and whether they possess functions such as access control, security logging, and situational awareness.

[0021] The acquisition of system security status information serves two purposes: firstly, it assesses the success rate of the simulation system in resisting simulated attacks; secondly, simulated attacks targeting trusted security mainly include attacks on key aspects of trusted computing such as trusted verification and remote proof; and thirdly, simulated attacks targeting cloud security mainly include traditional attack methods such as remote vulnerability scanning, malicious traffic attacks, and database attacks.

[0022] Simulated attacks targeting trusted security include attacks on key aspects of trusted computing such as trusted verification and remote proof; simulated attacks targeting cloud security mainly include traditional attack methods such as remote vulnerability scanning, malicious traffic attacks, and database attacks.

[0023] The lowest-level basic indicators are scored by combining the network information, industrial equipment information, and system security status information obtained above. The weight of each indicator is then calculated using a hierarchical analysis method to obtain the overall security assessment result. The steps include:

[0024] Step 1: Calculate the largest eigenvalue λ of the importance judgment matrix. max ;

[0025] Step 2: Determine if the largest eigenvalue is greater than the order n of the matrix. If λ max If the value is greater than n, proceed to step 3; otherwise, adjust the importance judgment matrix.

[0026] Step 3: Calculate the consistency index C I =λ max / (n-1), the average random consistency index R is obtained by looking up a table. I The consistency ratio CR = C was obtained. I / R I If CR < 0.1, the importance judgment matrix passes the consistency test; otherwise, the matrix needs to be adjusted to meet the requirements.

[0027] Step 4: Take the nth root of the product of each row of the matrix to obtain an n-dimensional vector, and then standardize the n-dimensional vector to obtain the weight vector:

[0028]

[0029] Step 5: Calculate the overall assessment result of the safety assessment indicator system, as follows:

[0030]

[0031] Where E represents the comprehensive score of the Industrial Internet Trustworthiness Assessment Index; α i β represents the weighting coefficient of the i-th primary indicator (e.g., system performance); j γ represents the weight coefficient of the j-th secondary indicator (e.g., interconnection); kThis represents the weighting coefficient of the kth tertiary indicator (e.g., smart device connectivity); W represents the weighting coefficient of the u-th fourth-level indicator (such as the network connectivity rate of production lines and process units); u This represents the score of the u-th fourth-level indicator.

[0032] Finally, using the security assessment module, experts were invited to score each level of indicators. The 1-9 scale method was used to compare each indicator in the same level pairwise to obtain the indicator importance judgment matrix for each level. The hierarchical analysis method was used to calculate the weight of each level of indicators. The indicator weights obtained from the expert scores were combined with the scores of the lowest level basic indicators to perform bottom-up calculations and obtain the overall industrial internet security assessment results.

[0033] The credibility of the aforementioned system is assessed from the perspectives of trusted security and cloud security, and involves the system security status information in the data acquisition module.

[0034] The beneficial effects of this invention are as follows: Compared with existing technologies, it provides an industrial internet security assessment system based on digital twins. The assessment method employs a hierarchical approach, dividing security assessment issues into hierarchical categories. It establishes comprehensive, multi-level security assessment indicators for the industrial internet from two main aspects: system performance and system credibility. The weights of each level of indicators are calculated using hierarchical analysis, and security assessment is conducted from the bottom up. Furthermore, expert group judgment reduces the impact of subjective scoring on the assessment. It proposes various systems for data collection from the industrial internet, including statistical, measurement, mathematical calculation, and simulated attack methods, to acquire network information, industrial equipment information, and system security status information as the basis for assessment. This data collection method is also applicable to real-world industrial internet applications. This invention not only assesses conventional network security technologies used in the industrial internet but also evaluates novel solutions for addressing industrial cloud security issues, such as trusted computing. Attached Figure Description

[0035] Figure 1 This is a structural diagram of the industrial internet security assessment system based on digital twins according to the present invention.

[0036] Figure 2 This is a diagram of the industrial internet security assessment index system based on digital twins, as presented in this invention.

[0037] Figure 3 This is a simulation scenario for the industrial internet security assessment of this invention.

[0038] Figure 4 This invention relates to a dynamic trusted verification process based on system calls.

[0039] Figure 5 This is the basic process of remote proof based on trusted computing in this invention.

[0040] Figure 6 This is a flowchart of the hierarchical analysis method of the present invention. Detailed Implementation

[0041] To better understand the technical content of this invention, the following description is in conjunction with relevant embodiments and appendices. Figure 1 ~Attached Figure 6 The specific implementation system of this invention will be described in detail.

[0042] This invention proposes an industrial internet security assessment system based on digital twins and a reconfigurable high-fidelity large-scale industrial internet simulation platform based on virtualization technology. The simulation platform comprises three parts: a logic control plane, a data plane, and a data acquisition plane.

[0043] 1) Logical control plane: This includes several local servers and databases, a main controller, a cloud platform, SDN network devices, and an industrial workshop network. Any one of the basic components of the Industrial Internet constitutes a specific Industrial Internet scenario. The target scenario is input into the logical control plane, and technicians set the parameters of the simulation scenario. The parameters are stored in the database, and the main controller issues control commands based on the target scenario parameters to configure and control the simulated network in the SDN network.

[0044] 2) Data Plane: This plane simulates the scenarios designed in the logic control plane. Digital twins of industrial production equipment are generated using digital twin technology. These are connected via virtual fieldbuses to form a field network. Several field networks are then networked using SDN technology to form a workshop. Interconnection between workshops and the cloud platform is achieved through the SDN network, thus forming a digital twin of the Industrial Internet. The SDN network switches are simulated using a combination of virtual and real switches. Virtual switches connect to virtual devices, while real switches connect to real production equipment and the cloud platform to obtain real production data. The cloud platform can be deployed on a local server according to the needs of the simulation scenario. Furthermore, software simulation of trusted modules is deployed in the digital twins of industrial equipment to simulate trusted security verification and control in the Industrial Internet. The data plane supports selecting different simulation modes for offline or real-time simulation as needed, and displays and analyzes the simulation scenarios and data in real time.

[0045] Taking into account the security characteristics of the Industrial Internet, the following security assessment indicators are selected, including system performance and system trustworthiness. System performance includes interconnectivity, network energy efficiency, and production performance; system trustworthiness includes trusted security, cloud security, and data trustworthiness.

[0046] Based on the above industrial internet security assessment indicators, the industrial internet security assessment system is as follows: Figure 1 As shown, it includes the following four modules:

[0047] (1) Digital Twin Module: Based on digital twin technology, this module simulates the cloud platform, SDN networking, and industrial operation technology in the industrial internet system to construct an industrial digital twin simulation system. The cloud platform is deployed through a local server to support various application and management modules required by the industrial internet cloud platform. Global topology management is performed through an SDN controller, and data plane forwarding is performed through an SDN switch. The industrial operation technology simulation includes the simulation of industrial field networks and virtual manufacturing systems.

[0048] (2) Data acquisition module, used to acquire data from the industrial digital twin and the real industrial Internet, and to divide the acquired data into network information, industrial equipment information and system security status information according to different security assessment indicators. Among them, network information is obtained through statistics, measurement and mathematical calculation; industrial equipment information is data generated by virtual manufacturing and real manufacturing, which can be acquired from the cloud platform and obtained through mathematical calculation; system security status information is obtained through configuration verification on the one hand, indicating the strength and coverage of the credible measures taken by the industrial Internet in terms of trusted security and cloud security, and on the other hand, it is the success rate of the simulation system in resisting simulated attacks.

[0049] (3) Data analysis module: saves the data in the data acquisition module into the database, compares the data generated by virtual manufacturing and real manufacturing, obtains the deviation between the two, optimizes and improves the simulation system based on the deviation, and makes the evaluation results of the simulation system more credible; then uses the data in the database to classify the lowest level of safety assessment indicators, formulates scoring rules, and obtains the specific score of the corresponding indicator based on the level.

[0050] (4) The security assessment module obtains the indicator importance judgment matrix by consulting a group of experts, and obtains the weight of each indicator after passing the consistency test; the weight value of each indicator is combined with the lowest level indicator score obtained by the data analysis module, and the indicator score of each level is calculated from bottom to top to obtain the overall security assessment result; finally, a security assessment report is generated, which contains the security assessment results and detailed information of the indicators, and the report is fed back to the operators to optimize the real and digital twin industrial internet. Figure 2 The industrial internet security assessment index system diagram provided in this embodiment divides the system performance and system credibility indicators into hierarchical categories to obtain the lowest-level basic indicators, and uses the data acquisition module to collect data on the lowest-level basic indicators.

[0051] The system performance indicators include interconnectivity, network energy efficiency, and production performance. Interconnectivity includes the network connectivity rate of smart devices and the coverage of information network infrastructure; network energy efficiency includes effective throughput, latency, and fairness in resource acquisition; and production performance includes status data acquisition, system scheduling, and equipment production. The underlying data used to evaluate these system performance indicators are network information and industrial equipment information from the data acquisition module.

[0052] The system credibility metrics include trusted security, cloud security, and data credibility. Trusted security includes trusted startup, trusted verification, virtual trust, and remote authentication; cloud security includes application security, data security, and network security; and data credibility assesses the accuracy of data from virtual and real manufacturing processes. The data evaluated by these system credibility metrics is the system security status information from the data acquisition module.

[0053] Then, the data analysis module is used to analyze the network information, industrial equipment information and system security status information collected from the above-mentioned underlying basic indicators, classify the data collected from the underlying basic indicators into levels, formulate scoring rules, and obtain specific scores for the corresponding indicators according to the levels.

[0054] Finally, using the security assessment module, a group of experts was invited to use hierarchical analysis to calculate the weight of each indicator. The indicator weights obtained from the expert scores were combined with the scores of the underlying basic indicators to obtain the industrial internet security assessment results from the bottom up.

[0055] Based on the above introduction of the four modules of the industrial internet security assessment system, the following section uses the shipbuilding industrial internet as an example to conduct a security assessment using these four modules:

[0056] Module 1: Digital Twin Module, such as Figure 3 As shown, a digital twin is constructed using the industrial internet of shipbuilding as a simulation scenario.

[0057] First, digital twins are created for equipment in industrial operations, such as various PLCs, machining centers, and digital testing equipment. These devices are then connected via a simulated industrial fieldbus to form an industrial field network. Operators can freely add shipbuilding equipment or ship workshops through the master controller to assess the scale of different shipbuilding industrial internet systems.

[0058] Then, the cloud platform is deployed through the local server. The cloud platform needs to deploy various applications and management platforms according to the simulation scenario, such as upper-level product applications for the digital workshop and a trusted management platform for managing trusted devices.

[0059] Finally, SDN technology is used to complete the networking and build an industrial internet digital twin, which involves two aspects:

[0060] (1) Building an industrial SDN network in a single shipyard. In the simulation system, an identical SDN network is built, mimicking the actual SDN network structure of the shipbuilding industrial internet. SDN switches are deployed in the simulation system to perform actual traffic forwarding operations, and an SDN controller is deployed to manage the SDN switches within the domain. Through the industrial access gateway, industrial control protocols (ModbusTCP, OPC, DNP3, etc.) are parsed, converted, and adapted to connect the industrial field network to the SDN network.

[0061] (2) Connect the SDN network of each workshop to the locally deployed private cloud platform. In addition, in order to evaluate the trust and security of the Industrial Internet, add support for trusted modules to the data twin. Specifically, vTPM can be used as a virtual trusted module for SDN controllers, SDN switches and PLCs, so that various hosts and devices in the simulation system have the foundation of trusted computing and can simulate various trusted computing measures.

[0062] Module 2: Data Acquisition Module, used to build datasets, that is, to collect data from digital twin simulation systems and real industrial internet based on the underlying basic indicators in the industrial internet security assessment index system, including network information, industrial equipment information and system security status information.

[0063] Specifically, the network information includes the intelligent device network connectivity rate, information network infrastructure coverage, effective throughput, latency, and fairness in resource acquisition. This network information is obtained through statistical, measurement, and mathematical calculations. Specifically, the intelligent device network connectivity rate is obtained by statistically analyzing the network connectivity rates of all workshop production lines and process equipment, robots, and sensor devices. The information network infrastructure coverage rate is obtained by statistically analyzing the coverage rates of IT networks and fieldbuses. The ping tool is used to test the round-trip latency between workshop machines and the trusted cloud platform, and between workshop engineering workstations. Multiple round-trip times are performed by the workshop engineering workstations starting the machines, and the average latency and standard deviation (latency jitter) between each node are obtained to measure the system's real-time performance and stability.

[0064] The effective throughput between the trusted cloud platform and the workshop machines is measured using the iperf tool. The specific implementation is as follows: First, start the iperf server on the cloud platform, and start the iperf client on the device at the other end of the tested link, establishing a connection with the server. Then, specify the iperf test duration as 120 seconds, and count the effective throughput of the current link at 1-second intervals, calculating the average throughput of the link. The test needs to target the two main network protocols, TCP and UCP. To examine the stability of the throughput, a 1-second interval is used as the observation window. The coefficient of variation (CoV) is used to measure the smoothness of the throughput within the observation window, defined as:

[0065]

[0066] In the formula, G(t) represents the throughput within the 1s observation window mentioned above, and E t {G(t)} represents the average throughput across all observation windows, and the CoV value can be calculated for throughput from 0 to 120 seconds.

[0067] The Jain Fairness Index (FI) is introduced to measure the fairness of each workshop's acquisition of available link bandwidth. Assume there are L workshops, and each workshop has the same conditions. The index is defined as follows:

[0068]

[0069] In the formula, G l This represents the average throughput of the l-th workshop. Repeat the measurement and calculation of the fairness index FI for the available link bandwidth in each workshop, and take the average value to obtain... Similarly, the fairness of each machine's access to available bandwidth within each workshop can be calculated.

[0070] Specifically, industrial equipment information comprises data generated from both virtual and real manufacturing processes. This data can be collected from the cloud platform and obtained through mathematical calculations, including system status, system scheduling, and production performance. System status assesses the real-time performance and accuracy of the cloud platform's acquisition of workshop and equipment operating status. The real-time performance is measured by statistically analyzing the frequency of status reports from workshops and equipment, and the accuracy rate is calculated by comparing the real-time status collected by the cloud platform with that of each piece of equipment in the workshop. System scheduling assesses the fairness of the cloud platform's task allocation. The trusted cloud platform acts as the system scheduling terminal, coordinating and scheduling tasks fairly across workshops with similar conditions, allocating tasks to the operator and engineer stations in each workshop. Operators and engineers then schedule the equipment in the workshop to execute tasks. The number of operating devices in each workshop is counted, and the equipment operating ratio is calculated to obtain the fairness index of the cloud platform's task allocation.

[0071]

[0072] In the formula, ratio l This indicates the equipment operating ratio of the l-th workshop; production performance is assessed by evaluating the production efficiency of each workshop and the pass rate of products produced by the workshop equipment.

[0073] Specifically, the acquisition of system security status information serves as a measure of the effectiveness and coverage of trusted measures taken by the Industrial Internet in terms of trusted security and cloud security.

[0074] In terms of trusted security, this includes evaluating trusted boot, trusted authentication, virtual trust, and remote authentication. For trusted boot, the coverage of trusted boot devices can be assessed, such as whether SDN switches and access gateways support trusted boot. For virtual trust, the security level and openness of virtual trust can be evaluated, such as whether it supports trusted boot, trusted authentication, trusted state migration, and multiple systems.

[0075] The evaluation of trusted verification is based on the scope and accuracy of verification. The evaluation system needs to assess whether the trusted verification mechanism can detect tampering with the BIOS, operating system, critical configuration parameters, and applications based on TCM, and whether it will issue an alert when their integrity is compromised. In addition to the static verification mentioned above, it is also necessary to evaluate whether the trusted verification mechanism can perform dynamic trusted verification at critical execution stages of the application. Figure 4 This describes a system that measures and verifies system calls involved in applications, including process startup, process calls, network access, and file access, based on an application behavior whitelist. To avoid the high false positive and false negative rates caused by simply comparing system call sequences with the behavior whitelist, the dynamic trusted verification mechanism can also use call stack backtracking technology to parse system calls more finely, analyze the timing of calls, and the relationships within and between call sequences, thereby achieving more accurate dynamic trusted verification.

[0076] The evaluation of a remote verification mechanism first requires assessing the implementation of its basic functions. For example... Figure 5 As shown, the basic process of remote proof involves the following steps:

[0077] Step 1: Starting with the trusted metric root, the trusted agent measures the startup components and each dynamic executable component step by step. On the one hand, it records the measurement log (measurement object and hash value) in the OS, and on the other hand, it expands the PCR value in the TCM.

[0078] Step 2: Subsequently, TCM combines the PCR value with the Nonce to form a Quote, performs AIK signing, and transmits it to the cloud platform. Simultaneously, the trusted agent transmits the metric logs recorded by the OS to the cloud platform.

[0079] Step 3: The cloud platform verifies the legitimacy of the PCR through the signature in the Quote, recalculates the PCR through the measurement order and measurement results in the measurement log, and compares it with the PCR in the Quote to ensure that the measurement log is not tampered with.

[0080] Step 4: Finally, compare the measurement objects of each measurement object in the measurement log with the pre-stored baseline measurement values ​​to verify whether each measurement object has been tampered with.

[0081] It is necessary to verify whether the remote certification mechanism in the evaluated industrial internet implements the above process in order to obtain the enforcement strength of the remote certification. In addition to basic functions, the evaluation system also needs to evaluate whether the remote certification mechanism implements functions such as execution sequence measurement, measurement log compression, append transmission, and report content encryption, so as to achieve a comprehensive evaluation of the comprehensiveness and efficiency of the remote certification mechanism.

[0082] In terms of cloud security, assessments are conducted on application security, data security, and network security. For application security, the assessment includes whether authentication, access authorization, security management, and auditing are supported. For data security, the assessment includes technologies and functions such as data access control, dynamic data masking, and data operation and maintenance auditing. For network security, the assessment includes functions such as real-time monitoring, real-time alerts, and security auditing.

[0083] Specifically, the acquisition of system security status information is one aspect, and the other is the success rate of the simulation system in resisting simulated attacks. Simulated attacks targeting trusted security mainly include attacks on key aspects of trusted computing such as trusted verification and remote proof; simulated attacks targeting cloud security mainly include remote vulnerability scanning, malicious traffic attacks, and database attacks.

[0084] For conventional network security technologies, the following simulated attacks can be used for verification: Use remote vulnerability scanning and attack technology, that is, through vulnerability knowledge base, discover system vulnerabilities from multiple dimensions, including: remote overflow, remote password cracking, SQL injection, etc., and use the vulnerabilities to attack the system to see if the system can respond and handle them correctly; Use DDoS attack technology, that is, generate DDoS traffic to attack the cloud platform server in the system, and see if the server can correctly detect and isolate malicious traffic.

[0085] Attacks targeting trusted computing take trusted verification and remote authentication as examples. Simulated attacks against trusted verification mainly fall into two categories. One category involves tampering with the BIOS, operating system, critical configuration parameters, and applications to check whether trusted verification can perform integrity checks based on the root of trust, detect tampering, and issue alerts for subsequent actions. The other category involves launching attacks using trusted applications, such as exploiting remote code execution vulnerabilities in browsers to execute malicious programs, and checking whether trusted verification can dynamically verify critical execution stages of the application and stop the execution of malicious programs.

[0086] Simulated attacks against remote authentication can be carried out in the following ways: Man-in-the-middle attacks can be used to tamper with the contents of the trusted status report or measurement logs to see if the trusted management platform can detect that the uploaded content has been tampered with; replay attacks can be used to steal the trusted status report through network eavesdropping or other means and send it repeatedly to the trusted management platform to see if the management platform will be deceived into believing that the device is in a trusted state.

[0087] Module 3: Data Analysis Module. This module analyzes network information, industrial equipment information, and system safety status information from the data acquisition module. The analysis has two aspects: First, it compares the data generated by virtual manufacturing and real manufacturing to obtain the deviation between the two. Based on this deviation, the simulation system is optimized and improved to make the evaluation results more reliable. Second, it scores the underlying basic indicators of the safety assessment index system based on the collected data. The lowest-level indicators related to system performance are directly scored based on the collected data, while the lowest-level indicators related to system reliability are graded based on the collected data, and scoring rules are established to obtain specific scores for the corresponding indicators according to the grade.

[0088] Specifically, regarding the lowest-level indicators related to system performance, taking the fairness of equipment access to workshop resources as an example, the fairness index collected above can be directly used... The data is converted into percentage scores for the corresponding indicators. For the lowest-level indicators related to system trustworthiness, corresponding capability levels are given. Higher levels indicate stronger capabilities, and corresponding scores are awarded based on the level. Specifically, there are four levels: L1, L2, L3, and L4, corresponding to 25, 50, 75, and 100 points respectively. Taking trusted verification as an example, the trusted verification levels are divided as follows: Trusted verification scope to BIOS, classified as L1 (25 points); Trusted verification scope to operating system, classified as L1 (50 points); Trusted verification scope to application, classified as L3 (75 points); Trusted verification scope to the critical execution environment of the application, classified as L4 (100 points). Finally, the collected data is assigned to the corresponding levels to obtain the corresponding indicator scores.

[0089] Module Four: Security Assessment Module, by Figure 6 The hierarchical analysis method shown above uses the lowest-level indicator scores obtained from the data analysis module, and then combines them with the corresponding indicator weights to perform bottom-up calculations to obtain the overall safety assessment results, which are then fed back to the operators to optimize the industrial internet. This includes the following steps:

[0090] Step 1: Invite experts in the field of industrial internet security assessment to score each layer of indicators. Use the 1-9 scale method shown in Table 1 to compare each indicator pairwise within the same layer, obtaining the indicator importance judgment matrix for each layer. Specifically, taking the three-level indicators under trusted security (trusted startup, trusted verification, virtual trust, and remote proof) as an example, as shown in Table 2, the importance judgment matrix table for the three-level trusted security indicators is obtained. It should be noted that, for simplicity, the specific scoring results and weights are not the actual results.

[0091] Step 2: Calculate the largest eigenvalue λ of the importance judgment matrix. max ;

[0092] Step 3: Determine if the largest eigenvalue is greater than the order n of the matrix. If λ max If the value is greater than n, proceed to step 4; otherwise, adjust the importance judgment matrix.

[0093] Table 1.1-9 Scale Method

[0094] 1 This indicates that the two elements are of equal importance. 3 This indicates that, compared to the previous element, the former is slightly more important. 5 This indicates that, compared to the previous element, the former is significantly more important. 7 This indicates that, compared to the other element, the former is extremely important. 9 This indicates that, compared to the latter, the former is significantly more important. 2,4,6,8 This represents the intermediate value of the above adjacent judgments. Reciprocals of 1-9 This indicates the importance of comparing the order in which the two elements are swapped.

[0095] Table 2 Judgment Matrix of Trustworthy Security Level 3 Indicators

[0096] Trusted Boot 1 1 / 2 1 / 2 1 Trusted verification 1 / 2 1 1 2 Virtual Trust 1 / 2 1 1 2 Remote Proof 1 2 2 1

[0097] Table 3 Consistency Index R I

[0098] <![CDATA[R I ]]> 0 0 0.58 0.90 1.12 1.24 1.32

[0099] Step 4: Calculate the consistency index C I =λ max / (n-1), by querying the consistency index R in Table 3 I Obtain the average random consistency index R I The consistency ratio CR = C was obtained. I / R I If CR < 0.1, the importance judgment matrix passes the consistency test; otherwise, the matrix needs to be adjusted to meet the requirements.

[0100] Step 5: Take the nth root of the product of each row of the matrix to obtain an n-dimensional vector, and then standardize the n-dimensional vector to obtain the weight vector:

[0101]

[0102] Furthermore, the overall evaluation results of the aforementioned safety assessment indicator system are as follows:

[0103]

[0104] Where E represents the comprehensive score of the Industrial Internet Trustworthiness Assessment Index; α i β represents the weighting coefficient of the i-th primary indicator (e.g., system performance); j γ represents the weight coefficient of the j-th secondary indicator (e.g., interconnection); k This represents the weighting coefficient of the kth tertiary indicator (e.g., smart device connectivity); W represents the weighting coefficient of the u-th fourth-level indicator (such as the network connectivity rate of production lines and process units); u This represents the score of the u-th fourth-level indicator.

[0105] Finally, the comprehensive score of the industrial internet security assessment index system and the detailed content of each level of index are used to generate a security assessment report, which is then fed back to the operators. This report serves as the basis for optimizing the real and digital twin industrial internet.

Claims

1. An industrial internet security assessment system based on digital twins, characterized in that, By utilizing digital twin technology to construct an industrial internet digital twin, a security assessment index system is established from two aspects: system performance and system trustworthiness. This system enables a hierarchical assessment of industrial internet security issues. System performance includes interconnectivity, network energy efficiency, and production performance; system trustworthiness includes trusted security, cloud security, and data trustworthiness. The industrial internet security assessment system includes the following modules: (1) Digital twin module: Based on digital twin technology, it simulates the cloud platform, SDN networking and industrial operation technology in the industrial Internet system to construct an industrial digital twin; among them, the cloud platform is deployed through a local server to support the application and management modules required by the industrial Internet cloud platform; global topology management is performed through the SDN controller and the SDN switch performs data plane forwarding; the industrial operation technology simulation includes the simulation of industrial field network and virtual manufacturing system; (2) Data acquisition module, used to acquire data from the simulation system and the real industrial Internet, and to divide the acquired data into network information, industrial equipment information and system security status information according to different evaluation indicators; among them, network information is acquired through statistics, measurement and mathematical calculation; industrial equipment information is data generated by virtual manufacturing and real manufacturing, which is acquired from the cloud platform and obtained through mathematical calculation; system security status information is obtained through configuration verification and resistance to simulated attacks; (3) Data analysis module: save the data in the data acquisition module to the database, compare the data generated by virtual manufacturing and real manufacturing, obtain the deviation between the two, optimize and improve the simulation system according to the deviation, so that the evaluation results of the simulation system are more credible; then use the data in the database to classify the lowest level indicators of the safety assessment system into levels, formulate scoring rules, and obtain the specific scores of the corresponding indicators according to the level. (4) Safety assessment module: By consulting a group of experts, an indicator importance judgment matrix is ​​obtained. After passing the consistency test, the weight of each indicator is obtained. The weight value of each indicator is combined with the lowest level indicator score obtained by the data analysis module. The indicator score of each level is calculated from bottom to top to obtain the overall safety assessment result. Finally, a safety assessment report is generated. The report contains the safety assessment results and detailed information of the indicators. The report is fed back to the operators to optimize the real and digital twin industrial internet. The system performance and system reliability indicators are hierarchically divided to obtain the lowest-level basic indicators, and the data acquisition module is used to collect data on the lowest-level basic indicators. The system performance is evaluated from three aspects: the level of system informatization, network energy efficiency, and system productivity, involving network information and industrial equipment information in the data acquisition module. The system performance indicators include interconnectivity, network energy efficiency, and production performance; among which, interconnectivity includes the smart device network connectivity rate and information network infrastructure coverage; network energy efficiency includes effective throughput, latency, and fairness in resource acquisition; production performance includes status acquisition, system scheduling, and equipment production; the underlying basic indicators related to system performance are evaluated using network information and industrial equipment information from the data acquisition module. The system credibility indicators include trusted security, cloud security, and data credibility; where trusted security includes trusted startup, trusted verification, virtual trust, and remote authentication; cloud security includes application security, data security, and network security; data credibility is the accuracy of data in virtual manufacturing and real manufacturing; the data evaluated by the system credibility indicators is the system security status information in the data acquisition module. Then, the data analysis module is used to analyze the network information, industrial equipment information and system security status information collected from the above-mentioned underlying basic indicators, classify the data collected from the underlying basic indicators into levels, formulate scoring rules, and obtain specific scores for the corresponding indicators according to the levels.

2. The industrial internet security assessment system according to claim 1, characterized in that, The acquisition of network information includes the smart device network connectivity rate, information network infrastructure coverage, effective throughput, latency, and fairness of resource acquisition. Specifically, the smart device network connectivity rate and information network infrastructure coverage are obtained statistically; the network latency of each node is tested using a network diagnostic tool (ping); continuous stress testing of network connections in the industrial internet is conducted using the network performance evaluation tool (iperf) to obtain the average throughput of the links, and the coefficient of variation (CoV) is used to measure the smoothness of throughput within the observation window; and the Jain fairness index (FI) is introduced to measure the fairness of each workshop in obtaining the available bandwidth of the links.

3. The industrial internet security assessment system according to claim 1, characterized in that, The industrial equipment information is collected from the cloud platform and obtained through mathematical calculations, including system status, system scheduling, and production performance. The system status examines the real-time performance and accuracy of the cloud platform in acquiring the working status of the workshop and workshop equipment. The system scheduling examines the fairness of the cloud platform in allocating tasks, and similarly, the fairness of the workshop in acquiring the available bandwidth of the link, so the Jain fairness index FI is introduced. The production performance examines the production efficiency of each workshop and the pass rate of the products produced by the workshop equipment.

4. The industrial internet security assessment system according to claim 1, characterized in that, The acquisition of the security status information includes the implementation strength and coverage of the trusted measures taken by the Industrial Internet, as well as the success rate of the simulation system in resisting simulated attacks; the implementation strength and coverage of the trusted measures, in terms of trusted security, are assessed by acquiring the coverage of trusted startup devices, the scope of trusted verification, the security level and openness of virtual trusted systems, and the authentication and confidentiality of remote proofs. In terms of cloud security, the assessment is conducted from three aspects: application security, data security, and network security. The assessment evaluates whether the system's security measures are comprehensive, real-time, and reliable, and whether it has functions such as access control, security logging, and situational awareness.

5. The industrial internet security assessment system according to claim 1, characterized in that, The acquisition of the system security status information serves two purposes: firstly, to assess the strength and coverage of trusted measures adopted by the Industrial Internet; secondly, in terms of trusted security, it involves evaluating trusted security by acquiring the coverage of trusted startup devices, the scope of trusted verification, the security level and openness of virtual trusted systems, and the authentication and confidentiality of remote proofs. In terms of cloud security: the evaluation will be conducted from three aspects: application security, data security, and network security. The evaluation will assess whether the system's security measures are comprehensive, real-time, and reliable, and whether it has functions such as access control, security logging, and situational awareness. The acquisition of system security status information serves two purposes: firstly, it assesses the success rate of the simulation system in resisting simulated attacks; secondly, simulated attacks targeting trusted security include attacks on trusted verification and remote proof; and thirdly, simulated attacks targeting cloud security include remote vulnerability scanning, malicious traffic attacks, and database attacks.

6. The industrial internet security assessment system according to claim 1, characterized in that, The lowest-level basic indicators are scored by combining the network information, industrial equipment information, and system security status information obtained above. The weight of each indicator is then calculated using a hierarchical analysis method to obtain the overall security assessment result. The steps include: Step 1: Calculate the largest eigenvalue λ of the importance judgment matrix. max ; Step 2: Determine if the largest eigenvalue is greater than the order n of the matrix. If λ max If the value is greater than n, proceed to step 3; otherwise, adjust the importance judgment matrix. Step 3: Calculate the consistency index C I The average random consistency index R is obtained by looking up a table. I The consistency ratio CR=C was obtained. I / R I If CR < 0.1, the importance judgment matrix passes the consistency test; otherwise, the matrix needs to be adjusted to meet the requirements. Step 4: Take the nth root of the product of each row of the matrix to obtain an n-dimensional vector, and then standardize the n-dimensional vector to obtain the weight vector: Where E represents the comprehensive score of the Industrial Internet Trustworthiness Assessment Index; α i β represents the weight coefficient of the i-th primary indicator; j γ represents the weight coefficient of the j-th secondary indicator; k φ represents the weight coefficient of the k-th tertiary indicator. u W represents the weight coefficient of the u-th fourth-level indicator. u This represents the score of the u-th fourth-level indicator.

7. The industrial internet security assessment system according to claim 1, characterized in that, Finally, using the security assessment module, experts were invited to score each level of indicators. The 1-9 scale method was used to compare each indicator in the same level pairwise to obtain the indicator importance judgment matrix for each level. The hierarchical analysis method was used to calculate the weight of each level of indicators. The indicator weights obtained from the expert scores were combined with the scores of the lowest level basic indicators to perform bottom-up calculations and obtain the overall industrial internet security assessment results.

8. The industrial internet security assessment system according to claim 1, characterized in that, The credibility of the aforementioned system is assessed from the perspectives of trusted security and cloud security, and involves the system security status information in the data acquisition module.

9. The industrial internet security assessment system according to claim 1, characterized in that, The effective throughput between the trusted cloud platform and the workshop machines is measured using the iperf tool. First, the iperf server is started on the cloud platform, and the iperf client is started on the device at the other end of the tested link, establishing a connection with the server. Then, the iperf test duration is specified as 120 seconds, and the effective throughput of the current link is counted at 1-second intervals, and the average throughput of the link is calculated. The test needs to be performed on both TCP and UCP network protocols. The observation window is 1-second intervals, and the coefficient of variation is used to measure the smoothness of the throughput within the observation window, defined as: In the formula, G(t) represents the throughput within the 1s observation window mentioned above, and E t {G(t)} represents the average throughput across all observation windows, and the CoV value is calculated for throughput from 0 to 120 seconds. The Jain Fairness Index (FI) is introduced to measure the fairness of each workshop's acquisition of available link bandwidth. Assume there are L workshops, and each workshop has the same conditions. The index is defined as follows: In the formula, G l This represents the average throughput of the l-th workshop; the fairness index FI of the bandwidth used to acquire the link is repeatedly measured and calculated for each workshop, and the average value is obtained. Similarly, the fairness of each machine's access to available bandwidth within each workshop can be calculated.

Citation Information

Patent Citations

  • Security evaluation system and method for industrial internet

    CN113489728A

  • Trusted evaluation method and system for equipment digital twinning evolution process

    CN114418414A