Method of using a logic controller and apparatus
Patent Information
- Application Number
- CN202410064679.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-16
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2044-01-16
AI Technical Summary
[0004]本申请实施例提供一种逻辑控制器的使用方法及装置,主要目的在于实现一种逻辑控制器的使用方法,以解决现有的逻辑控制器的使用过程中被网络攻击篡改而导致被控设备无法正常运行的问题
[0017]This application provides a method and apparatus for using a logic controller. After receiving a control command from a control device, the application inputs the control command to both the logic controller and a shadow logic controller to perform logic controller verification. The shadow logic controller is located within the secure and trusted module, and its operational logic is identical to that of the logic controller. On one hand, when the output of the logic controller is determined to be the same as the output of the shadow logic controller, the logic controller verification is deemed successful, and control operations are executed according to the output of the logic controller. On the other hand, when the output of the logic controller is determined to be different from the output of the shadow logic controller, an anomaly is identified in the logic controller, and control operations are prohibited from being executed according to the output of the logic controller, thereby realizing the functionality of the logic controller. Compared to existing technologies, the logic controller usage method in this application is applied to a secure and trusted module, which is an independent module located between the control device and the logic controller. This ensures that even if a network attack tamperes with the logic controller's function, the shadow logic controller within the secure and trusted module will not be tampered with. Thus, the tampered logic controller and the shadow logic controller will produce different outputs when receiving the same control command. This allows for the ability to infer whether the logic controller is malfunctioning by distinguishing the output results. Therefore, if the shadow logic controller's output is normal compared to the logic controller's output, the logic controller is functioning correctly, and control operations on the industrial equipment can continue according to the output results. Conversely, if they differ, the logic controller may have been tampered with and is malfunctioning, and subsequent control operations should not be performed according to the logic controller. This solves the problem of existing technologies where, if the logic controller is tampered with through network attacks, malfunctions can be promptly identified, thus preventing the continued use of a tampered logic controller to control industrial equipment and causing operational abnormalities.
Smart Images

Figure CN118092298B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of trusted computing technology, and in particular to a method and apparatus for using a logic controller. Background Technology
[0002] With technological advancements, the application scenarios for logic controllers in industry are gradually increasing. A logic controller, also known as a programmable logic controller (PLC), is a microprocessor-based digital controller used for automation control. It can load control instructions into memory at any time to control industrial equipment to perform corresponding operations. Furthermore, with the widespread adoption of networking, more and more logic controllers can control industrial equipment remotely via network commands.
[0003] Currently, existing logic controllers typically receive control commands from control devices on the network and then execute corresponding operations on downstream industrial equipment based on these commands. However, in practical applications, if an existing logic controller is attacked from the network, its original functions can be tampered with, causing the controlled industrial equipment to malfunction. Summary of the Invention
[0004] This application provides a method and apparatus for using a logic controller. The main purpose is to implement a method for using a logic controller to solve the problem that the controlled device cannot operate normally due to network attacks and tampering during the use of existing logic controllers.
[0005] To address the aforementioned technical problems, this application provides the following technical solutions:
[0006] In a first aspect, this application provides a method for using a logic controller, applied to a secure and trusted module, wherein the secure and trusted module is disposed between a control device and the logic controller, the method comprising:
[0007] After receiving control commands from the control device, the control commands are input to the logic controller and the shadow logic controller respectively to perform logic controller verification; wherein, the shadow logic controller is set in the security and trust module, and the operation logic of the shadow logic controller is the same as that of the logic controller;
[0008] When it is determined that the output result of the logic controller is the same as the output result of the shadow logic controller, the logic controller is determined to have passed the verification, and the control operation is executed according to the output result of the logic controller.
[0009] When it is determined that the output of the logic controller is different from the output of the shadow logic controller, it is determined that there is an anomaly in the logic controller.
[0010] Secondly, this application also provides a device for using a logic controller, applied to a secure and trusted module, wherein the secure and trusted module is disposed between a control device and the logic controller, and the device includes:
[0011] The controller verification unit is used to, after obtaining control commands from the control device, input the control commands to the logic controller and the shadow logic controller respectively to perform logic controller verification; wherein, the shadow logic controller is set in the security and trust module, and the operation logic of the shadow logic controller is the same as that of the logic controller;
[0012] The first execution unit is configured to determine that the logic controller has passed the verification when it is determined that the output result of the logic controller is the same as the output result of the shadow logic controller, and to execute the control operation according to the output result of the logic controller;
[0013] The second execution unit is used to determine that the logic controller has an anomaly and prohibit the execution of control operations according to the output of the logic controller when it is determined that the output of the logic controller is different from the output of the shadow logic controller.
[0014] Thirdly, this application also provides a storage medium including a stored program, wherein the program, when running, controls the device where the storage medium is located to execute the method of using the logic controller described in the first aspect.
[0015] Fourthly, this application also provides a device for using a logic controller, the device including a storage medium; and one or more processors, the storage medium being coupled to the processors, the processors being configured to execute program instructions stored in the storage medium; the program instructions, when executed, perform the method of using the logic controller as described in any one of the first aspects.
[0016] By employing the above-described technical solution, the technical solution provided in this application has at least the following advantages:
[0017] This application provides a method and apparatus for using a logic controller. After receiving a control command from a control device, the application inputs the control command to both the logic controller and a shadow logic controller to perform logic controller verification. The shadow logic controller is located within the secure and trusted module, and its operational logic is identical to that of the logic controller. On one hand, when the output of the logic controller is determined to be the same as the output of the shadow logic controller, the logic controller verification is deemed successful, and control operations are executed according to the output of the logic controller. On the other hand, when the output of the logic controller is determined to be different from the output of the shadow logic controller, an anomaly is identified in the logic controller, and control operations are prohibited from being executed according to the output of the logic controller, thereby realizing the functionality of the logic controller. Compared to existing technologies, the logic controller usage method in this application is applied to a secure and trusted module, which is an independent module located between the control device and the logic controller. This ensures that even if a network attack tamperes with the logic controller's function, the shadow logic controller within the secure and trusted module will not be tampered with. Thus, the tampered logic controller and the shadow logic controller will produce different outputs when receiving the same control command. This allows for the ability to infer whether the logic controller is malfunctioning by distinguishing the output results. Therefore, if the shadow logic controller's output is normal compared to the logic controller's output, the logic controller is functioning correctly, and control operations on the industrial equipment can continue according to the output results. Conversely, if they differ, the logic controller may have been tampered with and is malfunctioning, and subsequent control operations should not be performed according to the logic controller. This solves the problem of existing technologies where, if the logic controller is tampered with through network attacks, malfunctions can be promptly identified, thus preventing the continued use of a tampered logic controller to control industrial equipment and causing operational abnormalities.
[0018] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0019] The above and other objects, features, and advantages of exemplary embodiments of this application will become readily understood by reading the following detailed description with reference to the accompanying drawings. In the drawings, several embodiments of this application are illustrated by way of example and not limitation, with the same or corresponding reference numerals denoteing the same or corresponding parts, wherein:
[0020] Figure 1 A flowchart illustrating a method of using a logic controller according to an embodiment of this application is shown.
[0021] Figure 2 This illustration shows a schematic diagram of the relationships between devices during the execution of a method for using a logic controller according to an embodiment of this application;
[0022] Figure 3 A flowchart illustrating another method of using a logic controller provided in an embodiment of this application is shown;
[0023] Figure 4 This illustration shows a block diagram of a logic controller application device according to an embodiment of this application;
[0024] Figure 5 A block diagram of an apparatus for using another logic controller provided in an embodiment of this application is shown. Detailed Implementation
[0025] Exemplary embodiments of this application will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of this application are shown in the drawings, it should be understood that this application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of this application and to fully convey the scope of this application to those skilled in the art.
[0026] It should be noted that, unless otherwise stated, the technical or scientific terms used in this application shall have the ordinary meaning as understood by one of ordinary skill in the art to which this application pertains.
[0027] This application provides a flowchart of a method for using a logic controller, such as... Figure 1 As shown, the method includes:
[0028] 101. After obtaining the control command from the control device, the control command is input to the logic controller and the shadow logic controller respectively to perform logic controller verification.
[0029] The shadow logic controller is located in the secure and trusted module, and the shadow logic controller has the same operational logic as the logic controller.
[0030] In this embodiment, the method of using the logic controller described herein is mainly applied to a secure and trusted module positioned between the control device and the logic controller. This secure and trusted module can be understood as a module independent of both the control device and the logic controller. This module includes a shadow logic controller with the same operational logic as the logic controller. That is, theoretically, the shadow logic controller and the logic controller will have the same output result when the same instruction is input. Therefore, this embodiment is based on this principle; after receiving a control instruction from the control device, the control instruction is input into both the logic controller and the shadow logic controller deployed within the secure and trusted module to obtain the subsequent output results of these two controllers.
[0031] It should be noted that in this embodiment, the logic controller, i.e., the PLC, is mainly deployed between the controlled equipment (industrial equipment) and the external network (control equipment), while the security and reliability module is located between the PLC and the control equipment. Specifically, the relationship between the various devices can be as follows: Figure 2 As shown.
[0032] Based on the above description, there are two possible scenarios after this step is executed. One scenario is that the output of the logic controller and the shadow logic controller are the same, in which case step 102 can be executed. The other scenario is that the output of the logic controller and the shadow logic controller are different, in which case step 103 can be executed.
[0033] 102. When it is determined that the output result of the logic controller is the same as the output result of the shadow logic controller, the logic controller is determined to have passed the verification, and the control operation is executed according to the output result of the logic controller.
[0034] When the output of the logic controller is determined to be the same as that of the shadow logic controller, since the shadow logic controller operates on the same logic as the original logic controller, it indicates that the current logic controller's logic has not changed. Therefore, it can be deduced that the current logic controller has not been tampered with. In this case, safe control commands can be executed on the industrial equipment through the logic controller's output. This ensures that during the use of the logic controller, the output results are compared to verify whether the logic controller has any abnormal functions, preventing the controlled industrial equipment from malfunctioning due to tampering.
[0035] 103. When it is determined that the output result of the logic controller is different from the output result of the shadow logic controller, it is determined that the logic controller is abnormal and the control operation is prohibited from being performed according to the output result of the logic controller.
[0036] When the output of the logic controller differs from that of the shadow logic controller, it indicates a difference in their operational logic. Theoretically, their operational logic should be identical. This means that the shadow logic controller, deployed within an independent, secure, and trusted module, cannot be tampered with. Therefore, the logic controller itself has been tampered with, confirming an anomaly. In this case, controlling the industrial equipment using this logic controller is prohibited; that is, control operations should not be performed based on the logic controller's output. This prevents the tampering of the logic controller and its continued control over the industrial equipment, thus avoiding disruption to its normal operation.
[0037] Based on this, this embodiment provides a method for using a logic controller. Compared to the prior art, the method for using a logic controller in this application is applied to a secure and trusted module, which is an independent module located between the control device and the logic controller. This ensures that even if a network attack tampers with the logic controller's function, the shadow logic controller in the secure and trusted module will not be tampered with. Thus, the output results produced by the tampered logic controller and the shadow logic controller when receiving the same control command will be different. This allows for the ability to infer whether the logic controller is abnormal by distinguishing the output results. Therefore, if the output results of the shadow logic controller and the logic controller are normal, it indicates that the logic controller is normal, and control operations on the industrial equipment can continue to be performed according to the output results. Conversely, if the two are different, it indicates that the logic controller may have been tampered with and is abnormal, and subsequent control operations will no longer be performed according to the logic controller. This solves the problem in the prior art where, if the logic controller is tampered with by network attacks or other means, abnormalities in the logic controller can be identified in a timely manner, thus avoiding the problem of continuing to use a tampered logic controller to control industrial equipment and causing malfunctions.
[0038] Furthermore, as a further description and refinement of the foregoing embodiments, this application also provides a method for using a logic controller, specifically as follows: Figure 3 As shown:
[0039] 301. After obtaining the control command from the control device, the control command is security verified by a preset decryption algorithm and a preset string.
[0040] In some cases, attackers located on the network may tamper with the control commands sent by the control device. Such tampered control commands may threaten the normal control of industrial equipment by the logic controller. Therefore, in practical applications, control commands are generally encrypted to ensure their security. Thus, the control command is an instruction encrypted based on a preset string using a preset encryption algorithm.
[0041] Therefore, in this embodiment, after obtaining the control command, its security needs to be verified. The specific verification process can be based on a preset decryption algorithm, which corresponds to the preset encryption algorithm. Both use a specific string to decrypt the command. For example, the algorithm can be the SM4-GCM algorithm, which is an encryption algorithm that combines the SM4 block cipher algorithm and the GCM mode. The SM4 block cipher algorithm is a symmetric encryption algorithm, while GCM is a powerful encryption mode that provides confidentiality, integrity, and authentication. Specifically, the encryption process of the SM4-GCM algorithm is as follows: Select a 128-bit random number as the initialization vector (IV), which is the preset string described in this embodiment. Then, encrypt the plaintext using the SM4 block cipher algorithm, and then use the CBC mode and the selected IV for initialization to obtain the ciphertext. Next, encrypt the ciphertext using the GCM mode, and transmit the result along with the ciphertext to the receiver. During the decryption process, after receiving the encrypted data, the receiver uses the same key and algorithm to decrypt the data, and uses the GCM mode for decryption and authentication to verify the integrity and authenticity of the data.
[0042] In other words, if the control command can be decrypted using the preset string and the corresponding decryption algorithm, it means that the control command has not been tampered with and is secure, thus passing the security verification. Conversely, if it cannot be decrypted successfully, it means that the control command has been tampered with during transmission, and its security is questionable, thus failing the security verification. Furthermore, it should be noted that in this embodiment, the preset algorithm can be any existing algorithm similar to the SM4-GCM algorithm. The SM4-GCM algorithm described in this embodiment is merely exemplary; any algorithm that conforms to the above encryption and decryption process is acceptable. No specific limitation is made on which algorithm is selected as the preset encryption algorithm and the corresponding preset decryption algorithm; the user can choose according to their needs. Simultaneously, the encryption and decryption process of the control command is consistent with the conventional encryption and decryption process using the SM4-GCM algorithm or similar algorithms, and will not be elaborated further here.
[0043] 302. When it is determined that the control command has been decrypted based on the preset decryption algorithm and the preset string, the control command is determined to have passed the security verification.
[0044] As described in the preceding steps, if it is determined that the control command can be decrypted based on the preset decryption algorithm and preset string, it means that the control command is not problematic. At this point, it can be determined that the control command has passed the security verification.
[0045] 303. Obtain the first code digest of the shadow logic controller and the second code digest of the logic controller respectively, and determine whether the first code digest and the second code digest are consistent.
[0046] After confirming the security of the control commands, the next step is to perform static analysis between the shadow logic controller and the logic controller, which involves code verification between them. This process essentially involves statically checking for consistency at the code level. Based on the preceding steps, the digest data is unique after being calculated. Therefore, in this embodiment, the code digest of the shadow logic controller (the first code digest) can be obtained using the method described in this step. Similarly, the code digest of the logic controller (the second code digest) can also be obtained. It should be noted that the digest algorithms used to obtain the code digests of these two controllers must be consistent to avoid affecting subsequent judgments due to differences in digest algorithms.
[0047] Furthermore, before this step, since users may sometimes store the code digests of the required logic controllers in a preset benchmark library, a judgment can be made based on this preset benchmark library before this step. Therefore, before determining whether the first code digest and the second code digest are consistent, the following steps can also be performed:
[0048] Determine whether a target code digest matching the second code digest exists in a preset benchmark library, wherein the preset benchmark library stores at least one code digest.
[0049] Based on this, the step of determining whether the first code digest and the second code digest are consistent is specifically executed as follows: when it is determined that there is a target code digest in the preset benchmark library that matches the second code digest, it is determined whether the first code digest and the second code digest are consistent.
[0050] This preset benchmark library can be understood as a database containing code digests of all logic controllers within the current user's entire industrial system. In this embodiment, before checking whether the code digest of the current logic controller matches the code digest of the shadow logic controller in the secure and trusted module, it's possible to determine if a matching target code digest exists in the preset benchmark library. In other words, before comparing the code digests of two logic controllers, it's equivalent to first determining whether the current logic controller's code digest exists in the preset benchmark library. If it does, it indicates that the current logic controller may not have been tampered with, and therefore its code digest (i.e., the second code digest) has a corresponding target code digest in the preset benchmark library. Conversely, if it doesn't, it means the logic controller's code has been modified, indicating that the logic controller is problematic.
[0051] Based on the determined result, there are two cases: one is that the first code digest and the second code digest are the same, in which case step 305 is executed; the other is that the first code digest and the second code digest are different, in which case step 304 is executed.
[0052] 304. When the first code digest and the second code digest are inconsistent, it is determined that the logic controller does not meet the preset control parameters and an alarm message is output.
[0053] The preset control parameters are determined based on the industrial equipment control requirements specified by the user instructions.
[0054] In this embodiment, the preset control parameters can be understood as information determined by the user based on how to control the industrial equipment via instructions. That is, if the first code digest and the second code digest are inconsistent, it indicates that the code of the shadow logic controller and the code of the logic controller are inconsistent. This suggests that the logic controller's code may have been tampered with. A tampered logic controller will inevitably not conform to the user-set preset control parameters. Controlling the industrial equipment based on this logic controller will inevitably lead to its malfunction. Therefore, an alarm message can be output to prompt the user in this situation.
[0055] 305. When the first code digest and the second code digest are consistent, it is determined that the logic controller conforms to the preset control parameters, and the control instructions are respectively input to the logic controller and the shadow logic controller to perform logic controller verification.
[0056] The shadow logic controller is located in the secure and trusted module, and the shadow logic controller has the same operational logic as the logic controller.
[0057] If the first code and the second code digest are found to be consistent, it indicates that the logic controller should be trustworthy at the code level, meaning that the static code analysis is sound. However, to further ensure the security of the logic controller, it is necessary to input the control command into both logic controllers using the method described in this step. This involves having both the shadow logic controller and the logic controller execute the control command, and then verifying the logic controller based on the output results—that is, performing a dynamic-level judgment.
[0058] Since there are two possible verification results, if they match, then proceed to step 306; otherwise, proceed to step 307.
[0059] 306. When it is determined that the output result of the logic controller is the same as the output result of the shadow logic controller, the logic controller is determined to have passed the verification, and the control operation is executed according to the output result of the logic controller.
[0060] When the output of the logic controller is determined to be consistent with the output of the shadow logic controller, it indicates that the operation logic of the logic controller and the shadow logic controller is the same. Therefore, the logic controller is working properly and can be used to control industrial equipment. Thus, control operations can be performed according to the output.
[0061] 307. When it is determined that the output result of the logic controller is different from the output result of the shadow logic controller, it is determined that the logic controller is abnormal and the control operation is prohibited from being performed according to the output result of the logic controller.
[0062] When the output of the logic controller and the shadow logic controller are inconsistent, it indicates that the operational logic between the two logic controllers is different. This is why different results can be obtained after performing the same operation. In this case, it is not recommended to continue controlling the industrial equipment according to the logic controller. In other words, it is determined that the logic controller is abnormal, and it is prohibited to continue using the output of the logic controller to perform control operations.
[0063] Furthermore, in certain situations, although it is determined that the output of the logic controller and the output of the shadow logic controller are inconsistent, it may still be necessary to manage which output to use when performing subsequent control operations based on the user's needs and the operating state of the logic controller. Therefore, after verifying the result in step 305, in addition to executing steps 306 and 307, step 308 can be further executed.
[0064] 308. When it is determined that the output result of the logic controller is different from the output result of the shadow logic controller, the operating status of the logic controller is obtained.
[0065] The operating state includes a first state and a second state.
[0066] As described in the preceding steps, users can also address the issue of which output to use to control industrial equipment when the logic controller and shadow logic controller outputs differ. In this embodiment, the operating state refers to these parameters when faced with differing outputs. Specifically, it consists of a first state and a second state. Setting two states ensures that subsequent control operations can select one of the two results, thus avoiding the impact on timely control of industrial equipment if the logic controller is directly disabled when the two are inconsistent.
[0067] Based on the judgment result, if the running state is determined to be the first state, step 309 is executed; otherwise, if the running state is determined to be the second state, step 310 is executed.
[0068] 309. When the operating state is the first state, the control operation is executed according to the output result of the shadow logic controller.
[0069] In this step, when the operating state is determined to be the first state, the control operation is executed according to the output of the shadow logic controller. This means that the user needs to control the industrial equipment with a more rigorous operating logic. Since the shadow logic controller has not been tampered with, using the output of the shadow logic controller to perform the control operation can ensure that the control operation is safer and more accurate.
[0070] 310. When the operating state is the second state, the control operation is executed according to the output result of the logic controller.
[0071] When the operating state is determined to be the second state, control operations are performed based on the output of the logic controller. This ensures that in some cases, the user may not need a more sophisticated operating logic for control, or the logic controller itself may have been modified by the user. In such cases, since the shadow logic controller has not been modified, if control is performed in the manner described in steps 308 or 309 above, it will affect the normal operation of the industrial equipment. Therefore, based on the method in this step, the process of modifying the operation logic of the shadow logic controller in the security and trust module can be eliminated. Only by setting the logic controller to the second state can the overall efficiency of the logic controller be improved.
[0072] Furthermore, since the shadow logic controller also has an operating state in some cases, the operating state of the shadow logic controller also needs to be considered when performing subsequent control operations. Therefore, after obtaining the operating state of the logic controller, the method further includes:
[0073] The system acquires the operating status of the shadow logic controller and outputs an alarm when it determines that the operating status of the shadow logic controller is inconsistent with that of the logic controller, so that the user can adjust the operating status of the shadow logic controller to be consistent with that of the logic controller based on the alarm.
[0074] In this way, when the operating state of the shadow logic controller is inconsistent with that of the logic controller, an alarm is output to prompt the user to adjust the two to be consistent. This ensures that subsequent control operations are not affected by the inconsistency between the two operating states, thus laying the foundation for the normal use of the logic controller.
[0075] Furthermore, since users may have set an indication policy in some cases to determine which operating state to use to manage subsequent control operations when the operating states of the shadow logic controller and the logic controller are inconsistent, the method further includes the following before outputting the alarm prompt:
[0076] Detect the existence of a running status indication strategy, wherein the running status indication strategy is used to select one of the running statuses of the shadow logic controller and the logic controller as the target running status when they are inconsistent;
[0077] When it is determined that the operation status indication strategy exists, one of the operation statuses of the shadow logic controller and the logic controller is selected as the target operation status according to the operation status indication strategy.
[0078] Based on this, the output alarm message mentioned in this step is specifically executed as follows:
[0079] When it is determined that the running status indication policy does not exist, the alarm prompt is output.
[0080] In some cases, as described above, if the shadow logic controller and the logic controller's operating states are inconsistent, alarm prompts will be issued. If a large number of logic controllers and safety-reliable modules are used in the entire industrial equipment control system, this will generate a large number of alarm prompts. To avoid this situation, an indication strategy can be set for each safety-reliable module to solve this problem, namely, an operating state indication strategy. When it is determined that the operating state of the shadow logic controller and the logic controller are different, it first checks whether the user has set an operating state indication strategy. If such a strategy exists, then one of the two operating states can be selected as the target operating state based on this strategy. That is, when determining which output result should be used to control the industrial equipment in the aforementioned steps, the target operating state is used as the standard. This achieves the function of automatically selecting one when the two operating states are inconsistent, avoiding user selection and adjustment, and reducing the number of alarm prompts. When it is determined that there is no operating state indication strategy, it means that the current logic controller's control function is relatively important and cannot be arbitrarily selected by the strategy. Instead, manual intervention is required. Therefore, issuing an alarm prompt in this case can effectively remind the user that the control function of a certain important logic controller requires human intervention.
[0081] Furthermore, as a response to the above Figure 1 and Figure 2 In addition to the implementation of the method shown, another embodiment of this application also provides a device for using a logic controller. This device embodiment corresponds to the foregoing method embodiment. For ease of reading, this device embodiment will not repeat the details of the foregoing method embodiment, but it should be understood that the device in this embodiment can implement all the contents of the foregoing method embodiment. This device is used to implement a method for using a logic controller, applied to a secure and trusted module, which is disposed between the control device and the logic controller, specifically as follows... Figure 4 As shown, the device includes:
[0082] The controller verification unit 41 can be used to obtain control instructions from the control device and input the control instructions to the logic controller and the shadow logic controller respectively to perform logic controller verification; wherein, the shadow logic controller is set in the security and trust module, and the operation logic of the shadow logic controller is the same as that of the logic controller;
[0083] The first execution unit 42 can be used to determine that the logic controller has passed the verification when the controller verification unit 41 determines that the output result of the logic controller is the same as the output result of the shadow logic controller, and to execute the control operation according to the output result of the logic controller.
[0084] The second execution unit 43 can be used to determine that the logic controller has an abnormality and prohibit the execution of control operations according to the output result of the logic controller when the controller verification unit 41 determines that the output result of the logic controller is different from the output result of the shadow logic controller.
[0085] Furthermore, such as Figure 4 As shown, the device further includes:
[0086] The instruction verification unit 44 can be used to perform security verification on the control instruction using a preset decryption algorithm and a preset string.
[0087] The first determining unit 45 can be used to determine that the control instruction has passed the security verification when the instruction verification unit 44 determines that the control instruction has been decrypted based on the preset decryption algorithm and the preset string, so that the controller verification unit 41 can perform subsequent operations.
[0088] Furthermore, such as Figure 4 As shown, the device further includes:
[0089] The digest acquisition unit 46 can be used to acquire the first code digest of the shadow logic controller and the second code digest of the logic controller respectively, and determine whether the first code digest and the second code digest are consistent;
[0090] The second determining unit 47 can be used to determine that the logic controller does not meet the preset control parameters and output alarm information when the digest acquisition unit 46 determines that the first code digest and the second code digest are inconsistent. The preset control parameters are determined based on the industrial equipment control requirements determined by the user instructions.
[0091] The controller verification unit 41 can be used to determine that the logic controller conforms to preset control parameters when the digest acquisition unit 46 determines that the first code digest and the second code digest are consistent, and to input the control instructions to the logic controller and the shadow logic controller respectively to perform logic controller verification.
[0092] Furthermore, such as Figure 4 As shown, the device further includes:
[0093] The third determining unit 48 can be used to determine whether there is a target code digest that matches the second code digest in a preset benchmark library, wherein the preset benchmark library stores at least one code digest;
[0094] The summary acquisition unit 46 can be used to determine whether the first code summary and the second code summary are consistent when the third determination unit 48 determines that there is a target code summary in the preset benchmark library that matches the second code summary.
[0095] Furthermore, such as Figure 4 As shown, the device further includes:
[0096] The acquisition unit 49 can be used to acquire the operating state of the logic controller when the controller verification unit 41 determines that the output result of the logic controller is different from the output result of the shadow logic controller; the operating state includes a first state and a second state;
[0097] The third execution unit 50 can be used to perform control operations according to the output result of the shadow logic controller when the operating state acquired by the acquisition unit 49 is the first state;
[0098] The fourth execution unit 51 can be used to perform control operations according to the output result of the logic controller when the operating state obtained by the acquisition unit 49 is the second state.
[0099] Furthermore, such as Figure 4 As shown, the device further includes:
[0100] The output unit 52 can be used to acquire the operating status of the shadow logic controller, and when it is determined that the operating status of the shadow logic controller is inconsistent with the operating status of the logic controller acquired by the acquisition unit 49, it outputs an alarm prompt so that the user can adjust the operating status of the shadow logic controller to be consistent with the operating status of the logic controller based on the alarm prompt.
[0101] Furthermore, such as Figure 4 As shown, the device further includes:
[0102] The detection unit 53 can be used to detect whether there is a running status indication strategy, wherein the running status indication strategy can be used to select one of the running statuses of the shadow logic controller and the logic controller as the target running status when they are inconsistent.
[0103] The selection unit 54 can be used to select one of the running states of the shadow logic controller and the running states of the logic controller as the target running state when the detection unit 53 determines that the running state indication strategy exists.
[0104] Specifically, the output unit 52 can be used to output the alarm prompt when the detection unit 53 determines that the running status indication strategy does not exist.
[0105] To achieve the above objectives, according to another aspect of this application, an embodiment of this application also provides a storage medium, the storage medium including a stored program, wherein, when the program is executed, it controls the device where the storage medium is located to perform the above-described method of using the logic controller.
[0106] To achieve the above objectives, according to another aspect of this application, an embodiment of this application also provides an apparatus for using a logic controller, the apparatus including a storage medium; and one or more processors, the storage medium being coupled to the processors, the processors being configured to execute program instructions stored in the storage medium; the program instructions, when executed, perform the above-described method for using the logic controller.
[0107] This application provides a method and apparatus for using a logic controller. After receiving a control command from a control device, the application inputs the control command to both the logic controller and a shadow logic controller to perform logic controller verification. The shadow logic controller is located within the secure and trusted module, and its operational logic is identical to that of the logic controller. On one hand, when the output of the logic controller is determined to be the same as the output of the shadow logic controller, the logic controller verification is deemed successful, and control operations are performed according to the output of the logic controller. On the other hand, when the output of the logic controller is determined to be different from the output of the shadow logic controller, an anomaly is identified in the logic controller, and control operations are prohibited from being performed according to the output of the logic controller, thereby realizing the functionality of the logic controller. Compared to existing technologies, the logic controller usage method in this application is applied to a secure and trusted module, which is an independent module located between the control device and the logic controller. This ensures that even if a network attack tamperes with the logic controller's function, the shadow logic controller within the secure and trusted module will not be tampered with. Thus, the tampered logic controller and the shadow logic controller will produce different outputs when receiving the same control command. This allows for the ability to infer whether the logic controller is malfunctioning by distinguishing the output results. Therefore, if the shadow logic controller's output is normal compared to the logic controller's output, the logic controller is functioning correctly, and control operations on the industrial equipment can continue according to the output results. Conversely, if they differ, the logic controller may have been tampered with and is malfunctioning, and subsequent control operations should not be performed according to the logic controller. This solves the problem of existing technologies where, if the logic controller is tampered with through network attacks, malfunctions can be promptly identified, thus preventing the continued use of a tampered logic controller to control industrial equipment and causing operational abnormalities.
[0108] The device for using the logic controller includes a processor and a memory. The controller verification unit, the first execution unit, the second execution unit, etc., are all stored in the memory as program units. The processor executes the program units stored in the memory to realize the corresponding functions.
[0109] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and by adjusting kernel parameters, a specific method of using the logic controller can be implemented to address the problem of controlled devices malfunctioning due to network attacks and tampering with existing logic controllers.
[0110] This application provides a device for using a logic controller, the device including a storage medium and one or more processors, the storage medium being coupled to the processors, the processors being configured to execute program instructions stored in the storage medium; the program instructions, when executed, perform the method for using the logic controller as described in any of the preceding claims.
[0111] This application provides a storage medium that includes a stored program, wherein the program, when running, controls the device where the storage medium is located to execute the above-described method for using a logic controller.
[0112] Storage media may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0113] This application provides a device including a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs the following steps: after obtaining a control instruction from the control device, it inputs the control instruction to the logic controller and a shadow logic controller respectively to perform logic controller verification; wherein, the shadow logic controller is located in the secure and trusted module, and the shadow logic controller has the same operational logic as the logic controller; when it is determined that the output result of the logic controller is the same as the output result of the shadow logic controller, it is determined that the logic controller verification is successful, and control operations are executed according to the output result of the logic controller; when it is determined that the output result of the logic controller is different from the output result of the shadow logic controller, it is determined that the logic controller has an anomaly, and control operations are prohibited from being executed according to the output result of the logic controller.
[0114] Furthermore, the control command is an instruction encrypted based on a preset string using a preset encryption algorithm;
[0115] Before inputting the control commands to the logic controller and the shadow logic controller respectively to perform logic controller verification, the method further includes:
[0116] The control commands are security verified using a preset decryption algorithm and a preset string.
[0117] When it is determined that the control command has been decrypted based on the preset decryption algorithm and the preset string, the control command is determined to have passed the security check.
[0118] Furthermore, before inputting the control commands to the logic controller and the shadow logic controller respectively to perform logic controller verification, the method further includes:
[0119] Obtain the first code digest of the shadow logic controller and the second code digest of the logic controller respectively, and determine whether the first code digest and the second code digest are consistent;
[0120] When the first code digest and the second code digest are inconsistent, it is determined that the logic controller does not meet the preset control parameters and an alarm message is output. The preset control parameters are determined based on the industrial equipment control requirements determined by user instructions.
[0121] The step of inputting the control commands to the logic controller and the shadow logic controller respectively to perform logic controller verification includes:
[0122] When the first code digest and the second code digest are consistent, it is determined that the logic controller conforms to the preset control parameters, and the control instructions are respectively input to the logic controller and the shadow logic controller to perform logic controller verification.
[0123] Furthermore, before determining whether the first code digest and the second code digest are consistent, the method further includes:
[0124] Determine whether a target code digest matching the second code digest exists in a preset benchmark library, wherein the preset benchmark library stores at least one code digest;
[0125] Determining whether the first code digest and the second code digest are consistent includes:
[0126] When it is determined that a target code digest matching the second code digest exists in the preset benchmark library, it is determined whether the first code digest and the second code digest are consistent.
[0127] Furthermore, the method also includes:
[0128] When it is determined that the output of the logic controller is different from the output of the shadow logic controller, the operating state of the logic controller is obtained; the operating state includes a first state and a second state.
[0129] When the operating state is the first state, the control operation is executed according to the output result of the shadow logic controller;
[0130] When the operating state is the second state, the control operation is performed according to the output result of the logic controller.
[0131] Furthermore, after obtaining the operating state of the logic controller, the method further includes:
[0132] The system acquires the operating status of the shadow logic controller and outputs an alarm when it determines that the operating status of the shadow logic controller is inconsistent with that of the logic controller, so that the user can adjust the operating status of the shadow logic controller to be consistent with that of the logic controller based on the alarm.
[0133] Furthermore, before outputting the alarm notification, the method further includes:
[0134] Detect the existence of a running status indication strategy, wherein the running status indication strategy is used to select one of the running statuses of the shadow logic controller and the logic controller as the target running status when they are inconsistent;
[0135] When it is determined that the operation status indication strategy exists, one of the operation statuses of the shadow logic controller and the logic controller is selected as the target operation status according to the operation status indication strategy.
[0136] The output alarm prompts include:
[0137] When it is determined that the running status indication policy does not exist, the alarm prompt is output.
[0138] This application also provides a computer program product capable of performing corresponding functions, including: after obtaining control instructions from the control device, inputting the control instructions to the logic controller and the shadow logic controller respectively to perform logic controller verification; wherein, the shadow logic controller is set in the secure and trusted module, and the shadow logic controller has the same operational logic as the logic controller; when it is determined that the output result of the logic controller is the same as the output result of the shadow logic controller, it is determined that the logic controller verification is successful, and the control operation is performed according to the output result of the logic controller; when it is determined that the output result of the logic controller is different from the output result of the shadow logic controller, it is determined that the logic controller has an anomaly and the execution of the control operation according to the output result of the logic controller is prohibited.
[0139] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0140] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0141] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0142] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0143] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0144] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0145] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0146] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0147] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0148] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method of using a logic controller, characterized in that, The method, applied to a secure and trusted module disposed between a control device and a logic controller, includes: After receiving control commands from the control device, the control commands are input to the logic controller and the shadow logic controller respectively to perform logic controller verification; wherein, the shadow logic controller is set in the security and trust module, and the operation logic of the shadow logic controller is the same as that of the logic controller; When it is determined that the output result of the logic controller is the same as the output result of the shadow logic controller, the logic controller is determined to have passed the verification, and the control operation is executed according to the output result of the logic controller. When it is determined that the output of the logic controller is different from the output of the shadow logic controller, it is determined that the logic controller is abnormal and control operations are prohibited from being performed according to the output of the logic controller. When it is determined that the output of the logic controller is different from the output of the shadow logic controller, the operating state of the logic controller is obtained; the operating state includes a first state and a second state. When the operating state is the first state, the control operation is executed according to the output result of the shadow logic controller; When the operating state is the second state, the control operation is executed according to the output result of the logic controller; After obtaining the operating state of the logic controller, the method further includes: The system acquires the operating status of the shadow logic controller and outputs an alarm when it determines that the operating status of the shadow logic controller is inconsistent with the operating status of the logic controller, so that the user can adjust the operating status of the shadow logic controller to be consistent with the operating status of the logic controller based on the alarm. Before the output alarm notification, the method further includes: Detect the existence of a running status indication strategy, wherein the running status indication strategy is used to select one of the running statuses of the shadow logic controller and the logic controller as the target running status when they are inconsistent; When it is determined that the operation status indication strategy exists, one of the operation statuses of the shadow logic controller and the logic controller is selected as the target operation status according to the operation status indication strategy. The output alarm prompts include: When it is determined that the running status indication policy does not exist, the alarm prompt is output.
2. The method according to claim 1, characterized in that, The control command is an instruction encrypted based on a preset string using a preset encryption algorithm; Before inputting the control commands to the logic controller and the shadow logic controller respectively to perform logic controller verification, the method further includes: The control commands are security verified using a preset decryption algorithm and a preset string. When it is determined that the control command has been decrypted based on the preset decryption algorithm and the preset string, the control command is determined to have passed the security check.
3. The method according to claim 1, characterized in that, Before inputting the control commands to the logic controller and the shadow logic controller respectively to perform logic controller verification, the method further includes: Obtain the first code digest of the shadow logic controller and the second code digest of the logic controller respectively, and determine whether the first code digest and the second code digest are consistent; When the first code digest and the second code digest are inconsistent, it is determined that the logic controller does not meet the preset control parameters and an alarm message is output. The preset control parameters are determined based on the industrial equipment control requirements determined by user instructions. The step of inputting the control commands to the logic controller and the shadow logic controller respectively to perform logic controller verification includes: When the first code digest and the second code digest are consistent, it is determined that the logic controller conforms to the preset control parameters, and the control instructions are respectively input to the logic controller and the shadow logic controller to perform logic controller verification.
4. The method according to claim 3, characterized in that, Before determining whether the first code digest and the second code digest are consistent, the method further includes: Determine whether a target code digest matching the second code digest exists in a preset benchmark library, wherein the preset benchmark library stores at least one code digest; Determining whether the first code digest and the second code digest are consistent includes: When it is determined that a target code digest matching the second code digest exists in the preset benchmark library, it is determined whether the first code digest and the second code digest are consistent.
5. A device for using a logic controller, characterized in that, An apparatus for use in a secure and trusted module, wherein the secure and trusted module is disposed between a control device and a logic controller, and is used to execute the method of using the logic controller as described in any one of claims 1-4, the apparatus comprising: The controller verification unit is used to, after obtaining control commands from the control device, input the control commands to the logic controller and the shadow logic controller respectively to perform logic controller verification; wherein, the shadow logic controller is set in the security and trust module, and the operation logic of the shadow logic controller is the same as that of the logic controller; The first execution unit is configured to determine that the logic controller has passed the verification when it is determined that the output result of the logic controller is the same as the output result of the shadow logic controller, and to execute the control operation according to the output result of the logic controller; The second execution unit is used to determine that the logic controller is abnormal and prohibit the execution of control operations according to the output of the logic controller when it is determined that the output of the logic controller is different from the output of the shadow logic controller. The acquisition unit is used to acquire the operating state of the logic controller when it is determined that the output result of the logic controller is different from the output result of the shadow logic controller; the operating state includes a first state and a second state. The third execution unit is used to perform control operations according to the output result of the shadow logic controller when the running state is the first state. The fourth execution unit is used to perform control operations according to the output result of the logic controller when the operating state is the second state; The output unit is used to acquire the operating status of the shadow logic controller, and when it is determined that the operating status of the shadow logic controller is inconsistent with the operating status of the logic controller, it outputs an alarm prompt so that the user can adjust the operating status of the shadow logic controller to be consistent with the operating status of the logic controller based on the alarm prompt. A detection unit is used to detect whether a running status indication strategy exists, wherein the running status indication strategy is used to select one of the running statuses of the shadow logic controller and the logic controller as the target running status when they are inconsistent. The selection unit is used to select one of the running states of the shadow logic controller and the running states of the logic controller as the target running state when it is determined that the running state indication strategy exists. The output unit is specifically used to output the alarm prompt when it is determined that the running status indication strategy does not exist.
6. A storage medium, characterized in that, The storage medium includes a stored program, wherein, when the program is executed, the device containing the storage medium is controlled to perform the method of using the logic controller as described in any one of claims 1-4.
7. A device for using a logic controller, characterized in that, The device includes a storage medium; and one or more processors, the storage medium being coupled to the processors, the processors being configured to execute program instructions stored in the storage medium; the program instructions, when executed, perform the method of using the logic controller according to any one of claims 1-4.
Citation Information
Patent Citations
Systems and methods for securing controllers
US20130291094A1
Redundant control circuit for an exercise device
US20230149762A1