A PLC trusted interactive communication authentication method and device
The secure core and peripheral isolation technology combining dual-core CPU and dynamic trust measurement model solves the security verification problem of peripherals in PLC control systems and realizes trusted interactive communication and security management between PLC and peripherals.
Patent Information
- Application Number
- CN202211589673.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-12
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2042-12-12
AI Technical Summary
The existing security protection measures of PLC control systems cannot effectively prevent data forgery, theft and man-in-the-middle attacks of third-party peripherals. Traditional protection methods may cause system downtime or delays and cannot achieve real-time trustworthy measurement of peripherals.
The security core of the dual-core CPU is isolated from external devices. Combined with the dynamic trust measurement model and interrupt request behavior model, the security encryption module is used to perform security judgment and encrypted transmission of peripheral communication requests, realizing trusted interactive communication between third-party peripherals and the PLC system.
It achieves physical isolation and security verification between third-party external devices and the PLC system, improves the security defense capability of the PLC control system, ensures information security and avoids system downtime, and realizes hierarchical and scientific management of peripherals.
Smart Images

Figure CN116260611B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of industrial control, and in particular relates to a PLC trusted interactive communication authentication method and device. Background Art
[0002] Programmable Logic Controllers (PLCs) bear a crucial responsibility for maintaining the safe and stable operation of equipment in national infrastructure, including power, chemical, petroleum, transportation, and manufacturing, due to their critical importance, widespread application of supporting equipment, extensive geographical distribution, diverse control scenarios, and special network connectivity requirements. PLC control systems, as nodes on the current Internet and Internet of Things, host numerous third-party devices connected to local PLC systems via Ethernet, serial ports, and CAN interfaces. These systems also harbor numerous cyberattacks and viruses, characterized by specialized, unpredictable, and devastating consequences. Cyberattacks on PLCs can paralyze critical infrastructure and even cause significant economic and social upheaval and ecological damage. Therefore, achieving trusted interactive communication between PLCs and third-party peripherals is imperative to fundamentally improve the security and defense capabilities of PLC control systems.
[0003] Currently, the primary security measures for PLC control systems are still traditional node and perimeter security. These include the use of antivirus software and system vulnerability scanning tools for node protection, and control protocol monitoring and filtering for perimeter protection. However, these security reinforcement methods require system downtime, which can lead to increased latency and system crashes. They also fail to address unsafe communication issues between PLCs and third-party communication protocol modules, such as data forgery to achieve access to the PLC or man-in-the-middle attacks, which can lead to the leakage, theft, tampering, and destruction of internal device information. Some industrial systems have also introduced trust measurement systems, most of which measure the trustworthiness of peripheral identities. However, they do not perform real-time measurement of abnormal behavior and interrupt requests from connected peripherals based on behavioral models. Consequently, some peripherals may engage in communication attacks by forging identities. Summary of the Invention
[0004] To solve the above problems, the purpose of the present invention is to provide a PLC trusted interactive communication authentication method and device, which utilizes peripheral isolation and interrupt request isolation technology, combined with behavioral modeling and abnormality identification research on peripherals, and utilizes dynamic integrity measurement technology of control behavior, interaction behavior and access behavior to achieve trusted interactive communication authentication between third-party peripherals and PLC systems.
[0005] To achieve the above-mentioned purpose, the technical solution of the present invention is: a PLC trusted interactive communication authentication method, comprising the following steps: obtaining a communication request of an external device through the security core of a dual-core CPU; performing a security judgment on the communication request through a dynamic trust measurement model pre-established in a security encryption module; and if the security judgment passes, encrypting the communication request of the external device through the security encryption module and transmitting it to the real-time core of the dual-core CPU.
[0006] In one embodiment of the present invention, the dynamic trust measurement model includes an isolation model and an interrupt request behavior model, an isolation management library is generated based on the isolation model and multiple communication requests, and an interrupt identification management library is generated based on the interrupt request behavior model and multiple communication requests.
[0007] In one embodiment of the present invention, the external device is connected to the safety core signal of the dual-core CPU via Ethernet, a serial port, a CAN bus, or an RS485 communication line.
[0008] In one embodiment of the present invention, the isolation model sets the isolation priority, isolation level and isolation scope of the external device according to the security sensitivity of the external device, the host program process to which it belongs, and the trusted target characteristics.
[0009] In one embodiment of the present invention, the interrupt request behavior model sets corresponding handling measures for situations where interrupt requests meeting different conditions are received from external devices, so as to achieve reliable handling of interrupt requests.
[0010] In one embodiment of the present invention, during the access process of an external device, if it is detected that the PLC system is subject to a software monitoring flood attack, or that there is malicious operation in the communication data of the external device, the security core of the dual-core CPU immediately closes the communication handle, stops the communication thread, and stops subsequent communication between the external device and the real-time core of the dual-core CPU.
[0011] In one embodiment of the present invention, when it is detected that an external device frequently causes interruptions during communication and occupies a large amount of CPU resources, thereby causing system freezes, the communication driver IRQ corresponding to the external device is deregistered to achieve interrupt shielding and isolate the communication driver.
[0012] In one embodiment of the present invention, when it is detected that the identity of the connected external device is abnormal and the information of the external device cannot be correctly determined, or when it is found that the connected external device is faulty, the external device is directly blocked and an alarm is issued.
[0013] Based on the same concept, the present invention also provides a PLC trusted interactive communication authentication device to implement the PLC trusted interactive communication authentication method, including: a monitoring unit, used to obtain the communication request of the external device through the security core of the dual-core CPU; a security monitoring unit, used to perform security judgment on the communication request through a dynamic trust measurement model pre-established in the security encryption module; if the security judgment is passed, the communication request of the external device is encrypted by the security encryption module and then transmitted to the real-time core of the dual-core CPU.
[0014] Based on the same concept, the present invention also provides a PLC trusted interactive communication authentication device, including: a dual-core CPU module, a security encryption module and a physical peripheral interface, the dual-core CPU has a real-time core and a security core, the real-time core is connected to the PLC endogenous system signal, the security core is connected to the external device signal through the physical peripheral interface, the security encryption module is connected to the security core and the real-time core signal for performing security judgment on the external device communication request received through the security core, and if the security judgment is passed, the communication request of the external device is encrypted and transmitted to the real-time core of the dual-core CPU.
[0015] Based on the same concept, the present invention also provides a computer device, comprising: a memory, the memory being used to store a processing program; and a processor, the processor implementing any of the above-mentioned PLC trusted interactive communication authentication methods when executing the processing program.
[0016] Based on the same concept, the present invention also provides a readable storage medium, characterized in that a processing program is stored on the readable storage medium, and when the processing program is executed by a processor, any of the PLC trusted interactive communication authentication methods described above is implemented.
[0017] Due to the adoption of the above technical solution, the present invention has the following advantages and positive effects compared with the prior art:
[0018] 1. In the present invention, by setting up a dual-core CPU with a real-time core and a safety core, third-party external devices are only connected to the safety core, thereby achieving physical isolation between third-party external devices and the PLC endogenous system and protecting the endogenous security of the PLC system.
[0019] 2. Based on the physical isolation of peripherals, the present invention establishes a dynamic trust measurement model in the security encryption module. During operation, the security of the actions of the external devices is judged in real time. If the security judgment is passed, the security encryption module encrypts the request information of the peripherals and transmits it, thereby realizing security verification of third-party external devices.
[0020] 3. The isolation model in the present invention pre-sets the isolation priority, isolation level and isolation range of the external device according to the security sensitivity of the external device, the host program process to which it belongs, and the trusted target characteristics, thereby realizing hierarchical scientific management of the external device, improving the security of PLC communication while taking into account the efficiency of peripheral management. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The specific embodiments of the present invention are further described in detail below with reference to the accompanying drawings, wherein:
[0022] Figure 1 Flowchart of the PLC trusted interactive communication authentication method of the present invention;
[0023] Figure 2 This is a schematic diagram of an embodiment of the security verification processing measures of the dynamic trust measurement model of the present invention;
[0024] Figure 3 Schematic diagram of the PLC trusted interactive communication authentication device. DETAILED DESCRIPTION
[0025] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments. The advantages and features of the present invention will become more apparent from the following description and claims. It should be noted that the drawings are greatly simplified and not to exact ratios, and are intended solely to facilitate and clearly illustrate the embodiments of the present invention.
[0026] It should be noted that all directional indications in the embodiments of the present invention (such as up, down, left, right, front, back, etc.) are only used to explain the relative position relationship, movement status, etc. between the various components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.
[0027] Example 1
[0028] like Figure 1 As shown, the technical solution of the present invention is: a PLC trusted interactive communication authentication method, comprising the following steps:
[0029] Acquire communication requests from external devices through the security core of the dual-core CPU;
[0030] Performing security assessment on the communication request using a dynamic trust measurement model pre-established in the security encryption module;
[0031] When the security judgment is passed, the communication request of the external device is encrypted by the security encryption module and then transmitted to the real-time core of the dual-core CPU.
[0032] The present invention utilizes a dual-core CPU with a real-time core and a security core, allowing third-party external devices to connect only to the security core. This physically isolates the third-party external devices from the PLC's internal system, protecting the PLC system's inherent security. Building upon this physical isolation, a dynamic trust measurement model is established within the security encryption module. During operation, the security of the external device's actions is assessed in real time. If the assessment passes, the security encryption module encrypts the request information from the external device and transmits it, thus verifying the security of the third-party external device.
[0033] In one embodiment of the present invention, the dynamic trust measurement model includes an isolation model and an interrupt request behavior model, an isolation management library is generated based on the isolation model and multiple communication requests, and an interrupt identification management library is generated based on the interrupt request behavior model and multiple communication requests.
[0034] Based on the isolation model and interrupt request behavior model, the security of the communication request of the external device can be accurately judged, thereby realizing the secure communication between the PLC system and the external device and improving the security defense capability of the PLC control system.
[0035] See also Figure 3 In one embodiment of the present invention, the external device is connected to the safety core signal of the dual-core CPU via Ethernet or serial port or CAN bus or RS485 communication line.
[0036] In one embodiment of the present invention, the isolation model sets the isolation priority, isolation level and isolation scope of the external device according to the security sensitivity of the external device, the host program process to which it belongs, and the trusted target characteristics.
[0037] The isolation model pre-sets the isolation priority, isolation level, and isolation range of external devices based on their security sensitivity, the host program process they belong to, and the trusted target characteristics. This allows for hierarchical and scientific management of external devices, improving PLC communication security while also taking into account the efficiency of peripheral management. For example, a higher isolation level, isolation priority, and larger isolation range are set for external devices with high security sensitivity, a critical host program process, and low trusted target characteristics.
[0038] In one embodiment of the present invention, the interrupt request behavior model sets corresponding handling measures for situations where interrupt requests meeting different conditions are received from external devices, so as to achieve reliable handling of interrupt requests.
[0039] For example, see Figure 2, showing a schematic diagram of an embodiment of the security verification processing measures of the dynamic trust measurement model of the present invention. A multi-layer interrupt model technology of peripheral interrupt request isolation, interrupt request interception and interrupt trust isolation is adopted to identify whether the interrupt request is trustworthy, form an interrupt request trust identification management library, and decide whether to respond to the interrupt based on the interrupt request trust management library. The technology of intercepting untrustworthy interrupts forms an interrupt identification management library based on the interrupt model. It can accurately measure and identify abnormal behaviors and faults of peripherals, and implement functions such as shielding, isolation and alarming of abnormal peripherals according to the type of abnormal behavior, realize secure communication authentication between PLC and third-party peripherals, and fundamentally improve the security defense capability of the PLC control system.
[0040] In one embodiment of the present invention, during the access process of an external device, if it is detected that the PLC system is subject to a software monitoring flood attack, or that there is malicious operation in the communication data of the external device, the security core of the dual-core CPU immediately closes the communication handle, stops the communication thread, and stops subsequent communication between the external device and the real-time core of the dual-core CPU.
[0041] In one embodiment of the present invention, when it is detected that an external device frequently causes interruptions during communication and occupies a large amount of CPU resources, thereby causing system freezes, the communication driver IRQ corresponding to the external device is deregistered to achieve interrupt shielding and isolate the communication driver.
[0042] In one embodiment of the present invention, when it is detected that the identity of the connected external device is abnormal and the information of the external device cannot be correctly determined, or when it is found that the connected external device is faulty, the external device is directly blocked and an alarm is issued.
[0043] See also Figure 2 , showing a schematic diagram of an embodiment of the security verification and processing measures for the dynamic trust measurement model of the present invention. Upon detecting abnormal behavior of an external device, corresponding measures are executed. Abnormal behavior includes, but is not limited to, login flood attacks, illegal address intrusions, malicious interrupt requests from the connected peripheral device, and malfunctions in the peripheral device itself.
[0044] Based on the same concept, the present invention also provides a PLC trusted interactive communication authentication device to implement the PLC trusted interactive communication authentication method, including: a monitoring unit, used to obtain the communication request of the external device through the security core of the dual-core CPU; a security monitoring unit, used to perform security judgment on the communication request through a dynamic trust measurement model pre-established in the security encryption module; if the security judgment is passed, the communication request of the external device is encrypted by the security encryption module and then transmitted to the real-time core of the dual-core CPU.
[0045] Example 2
[0046] Based on the same concept, the present invention also provides a PLC trusted interactive communication authentication device, including: a dual-core CPU module, a security encryption module and a physical peripheral interface, the dual-core CPU has a real-time core and a security core, the real-time core is connected to the PLC endogenous system signal, the security core is connected to the external device signal through the physical peripheral interface, the security encryption module is connected to the security core and the real-time core signal for performing security judgment on the external device communication request received through the security core, and if the security judgment is passed, the communication request of the external device is encrypted and transmitted to the real-time core of the dual-core CPU.
[0047] See also Figure 3 Physical peripheral interfaces such as Ethernet, serial port, CAN and 485 interface are only connected to the security core in the CPU, and are isolated from the PLC endogenous system. Based on the trust measurement of the security encryption module, the corresponding behavior model is established by using peripheral isolation and interrupt isolation to identify abnormal access behavior of external devices, and preset disposal is performed on peripherals judged to be abnormal, so as to realize trusted interactive communication between peripheral devices and PLC system.
[0048] Example 3
[0049] Based on the same concept, the present invention also provides a computer device, which may have relatively large differences due to different configurations or performances, and may include one or more processors (central processing units, CPU) (for example, one or more processors) and memory, one or more storage media for storing application programs or data (for example, one or more mass storage devices). Among them, the memory and storage medium can be short-term storage or persistent storage. The program stored in the storage medium may include one or more modules (not shown in the figure), each module may include a series of instruction operations in the computer device. Furthermore, the processor can be configured to communicate with the storage medium and execute a series of instruction operations in the storage medium on the computer device.
[0050] The computer device may further include one or more power supplies, one or more wired or wireless network interfaces, one or more input and output interfaces, and / or one or more operating systems, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, etc. Those skilled in the art will appreciate that the computer device structure shown above does not limit the computer device, and may include more or fewer components than shown, or combine certain components, or arrange components differently.
[0051] When the computer-readable instructions are executed by the processor, the processor implements the following steps when executing the computer-readable instructions: obtaining a communication request from an external device through the security core of the dual-core CPU; performing a security judgment on the communication request through a dynamic trust measurement model pre-established in a security encryption module; and if the security judgment passes, encrypting the communication request from the external device through the security encryption module and transmitting the encrypted data to the real-time core of the dual-core CPU.
[0052] In one embodiment, a computer-readable storage medium is provided. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the above-mentioned PLC trusted interactive communication authentication method.
[0053] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0054] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc., various media that can store program code.
[0055] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings, but the present invention is not limited to the above embodiments. Even if various changes are made to the present invention, if these changes fall within the scope of the claims of the present invention and their equivalents, they still fall within the scope of protection of the present invention.
Claims
1. A PLC trusted interactive communication authentication method, characterized in that: The following steps are involved: Acquire communication requests from external devices through the security core of the dual-core CPU; Performing security assessment on the communication request using a dynamic trust measurement model pre-established in the security encryption module; The dynamic trust measurement model includes an isolation model and an interrupt request behavior model, an isolation management library is generated based on the isolation model and multiple communication requests, and an interrupt identification management library is generated based on the interrupt request behavior model and multiple communication requests; The isolation model sets the isolation priority, isolation level, and isolation scope of the external device according to the security sensitivity of the external device, the host program process to which it belongs, and the trusted target characteristics; the interrupt request behavior model sets corresponding handling measures for the situations where interrupt requests meeting different conditions are received from the external device, so as to achieve trusted handling of the interrupt request; When the security judgment is passed, the communication request of the external device is encrypted by the security encryption module and then transmitted to the real-time core of the dual-core CPU.
2. The PLC trusted interactive communication authentication method according to claim 1, characterized in that: The external device is connected to the safety core signal of the dual-core CPU via Ethernet, serial port, CAN bus or RS485 communication line.
3. The PLC trusted interactive communication authentication method according to claim 1, characterized in that: During the process of external device access, if it is detected that the PLC system is subject to a software monitoring flood attack, or that there is malicious operation in the communication data of the external device, the security core of the dual-core CPU immediately closes the communication handle, stops the communication thread and stops subsequent communication between the external device and the real-time core of the dual-core CPU.
4. The PLC trusted interactive communication authentication method according to claim 1, characterized in that: When it is detected that an external device frequently causes interrupts during communication, occupies a large amount of CPU resources, and thus causes system freezes, the communication driver IRQ corresponding to the external device will be deregistered to achieve interrupt shielding and isolate the communication driver.
5. The PLC trusted interactive communication authentication method according to claim 1, characterized in that: If it is detected that the identity of the connected external device is abnormal and the information of the external device cannot be correctly judged, or if it is found that the connected external device has a fault, the external device will be directly blocked and an alarm will be issued.
6. A PLC trusted interactive communication authentication device, characterized in that: Implementing the PLC trusted interactive communication authentication method according to any one of claims 1 to 5, comprising: A monitoring unit is used to obtain communication requests from external devices through the security core of the dual-core CPU; A security monitoring unit is configured to perform a security assessment on the communication request using a dynamic trust measurement model pre-established within a security encryption module; the dynamic trust measurement model includes an isolation model and an interrupt request behavior model, an isolation management library is generated based on the isolation model and multiple communication requests, and an interrupt identification management library is generated based on the interrupt request behavior model and multiple communication requests; the isolation model sets the isolation priority, isolation level, and isolation range of the external device based on the security sensitivity of the external device, the host program process to which it belongs, and the trusted target characteristics; the interrupt request behavior model sets corresponding handling measures for interrupt requests received from external devices that meet different conditions, so as to achieve trusted handling of the interrupt request; and if the security assessment passes, the communication request of the external device is encrypted by the security encryption module and transmitted to the real-time core of the dual-core CPU.
7. A PLC trusted interactive communication authentication device, characterized in that: include: A dual-core CPU module, a security encryption module, and a physical peripheral interface, wherein the dual-core CPU has a real-time core and a security core, the real-time core is connected to the PLC's endogenous system signal, the security core is connected to the external device signal via the physical peripheral interface, the security encryption module is connected to the security core and the real-time core signal for performing a security assessment on the external device communication request received via the security core, the security assessment being performed on the communication request using a dynamic trust measurement model pre-established within the security encryption module. If the security assessment passes, the communication request from the external device is encrypted and transmitted to the real-time core of the dual-core CPU; The dynamic trust measurement model includes an isolation model and an interrupt request behavior model, an isolation management library is generated based on the isolation model and multiple communication requests, and an interrupt identification management library is generated based on the interrupt request behavior model and multiple communication requests; The isolation model sets the isolation priority, isolation level and isolation scope of the external device according to the security sensitivity of the external device, the host program process to which it belongs, and the trusted target characteristics; the interrupt request behavior model sets corresponding handling measures for the situations in which interrupt requests that meet different conditions are received from the external device, so as to achieve trusted handling of the interrupt request.
Citation Information
Patent Citations
PAC (programmable automatic controller) real-time control system based on dual-core processor
CN103744342A
Trusted PLC control system
CN112948086A