System security verification method, verification system and terminal device

By constructing and mapping automatons and designing state observers, verifying the opacity of information physics systems under state attacks, the problem that the existing technology cannot effectively verify system security is solved, and security guarantees are achieved in a state attack environment.

CN119513853BActive Publication Date: 2025-05-27ZHONGBEI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411687520.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-25
Publication Date
2025-05-27
Estimated Expiration
2044-11-25

AI Technical Summary

Technical Problem

The prior art is difficult to effectively verify the security of information physical systems in a state attack environment, and cannot cope with the system opacity caused by cyber attacks.

Method used

By constructing actual automata, attack automata and mapping automata, designing state observers to determine whether the state estimate only contains secret states, thereby verifying the opacity of the system under state attacks.

Benefits of technology

A method of verifying system security in a stateful attack environment is implemented to ensure that the system can maintain opacity and ensure security when facing malicious attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119513853B_ABST
    Figure CN119513853B_ABST
Patent Text Reader

Abstract

The present application provides a system security verification method, verification system and terminal device, which constructs a discrete event system model by abstracting an information-physical system at the dynamic logic level; in this model, the change of the system state is driven by the asynchronous triggering of discrete events. In the present application, a state attack refers to the ability of an external intruder to launch a state attack on the system, and to accurately determine whether the current state of the system is affected by the attack based on the information obtained after the attack; when there is no state attack, the current state of the system is reasonably estimated by analyzing the event sequence generated by the system, thereby verifying the security of the system. Therefore, the present application can use the event sequence that occurs in the system and the attack sequence that may be obtained by the external intruder to reasonably infer the current state of the system, thereby effectively verifying the security of the system when it is attacked by the state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of system security technology, and more specifically to a verification method, a verification system and a terminal device for verifying system security in a state attack environment. Background Art

[0002] With the rapid development of digitalization, networking and intelligence, as well as the in-depth research of communication and control technologies, various physical entities with embedded communication functions can be interconnected through the network in wired or wireless ways, making cyberphysical systems (CPS), such as information communication, intelligent transportation networks, high-end manufacturing, chemical production, and medical health systems, emerge and have been widely used.

[0003] In a broad sense, CPS is constructed by integrating physical entities such as sensors, actuators, storage, data transceivers, etc. into an "intelligent" feedback loop connected by numerous network adapters according to certain rules, which includes physical processes, information transmission and data calculation.

[0004] Due to the large-scale introduction of the Internet, cyber-physical systems will inevitably be subject to malicious damage or attacks by external intruders during use, so it is necessary to pay attention to the security of cyber-physical systems under state attacks. Verifying the security of cyber-physical systems is a prerequisite for ensuring that cyber-physical systems can operate normally under insecure communication conditions and when certain components with relatively vulnerable security are subjected to malicious attacks.

[0005] Therefore, there is an urgent need for a method that can characterize state attacks through models and verify the security of the system under state attacks. Summary of the invention

[0006] The present application provides a verification method, verification system and terminal device for system security in a state attack environment, which can verify opacity by judging whether the state estimation in the state observer reveals the secrets of the system in a specific state attack situation, thereby ensuring system security.

[0007] In the first aspect, the present application provides a system security verification method, including: modeling a preset information-physical system and constructing its actual automaton; designing an attack automaton and dividing the state set in the actual automaton into an attacked state set and a non-attacked state set; designing a mapping automaton and performing a natural mapping operation on the attack automaton; designing a state observer and performing a state estimation operation on the mapping automaton; based on the state observer, determining whether the state estimation only contains secret states, if all state estimates contain at least one non-secret state, the preset information-physical system satisfies the opacity under state attacks; if there is at least one state estimate that does not contain a non-secret state, the preset information-physical system does not satisfy the opacity under state attacks.

[0008] In an optional solution of the first aspect, when constructing the actual automaton, the actual automaton is formally represented as a function expression: G 1 =(X 1 ,E 1 ,f 1 ,X 0,1 ), where X 1 represents the state set of the system, E 1 Represents the event label set of the system, represents the state transfer function, X 0,1 represents the initial state set, G 1 Represents the actual automaton.

[0009] In an optional solution of the first aspect, the privacy of the preset information-physical system is modeled as a partial secret state of an actual automaton.

[0010] In an optional scheme of the first aspect, when the state set in the actual automaton is divided into an attacked state set and an unattacked state set, the method further includes: assigning a binary signal of 1 to all states belonging to the attacked state set; and assigning a binary signal of 0 to all states belonging to the unattacked state set.

[0011] In an optional solution of the first aspect, when designing the attack automaton, the attack automaton is formally represented as a function expression: G 2 =(X 2 ,X a ,E 2 ,Δ 2 ,f 2 ,λ 2 ,X 0,2 ), where X 2 represents the state set of the attack automaton, X a represents the attacked state set of the attacking automaton, E 2represents the event label set of the attack automaton, Δ 2 represents the attack pattern label set of the attack automaton, represents the state transition function of the attack automaton, λ 2 :X 2 →Δ 2 represents the attack form assignment function of the attack automaton, X 0,2 represents the initial state of the attack automaton, G 2 Denote the attack automaton.

[0012] In an optional solution of the first aspect, when designing a mapping automaton, the mapping automaton is formally represented as a function expression: 3 =(X 3 ,X a ,E 3 ,Δ 3 ,f 3 ,λ 3 ,X 0,3 ), where X 3 represents the state set of the mapping automaton, X a represents the attacked state set of the mapping automaton, represents the observable event label set of the mapping automaton, Δ 3 represents the attack pattern label set of the mapping automaton, represents the state transition function of the mapping automaton, λ 3 :X 3 →Δ 3 represents the attack form assignment function of the mapping automaton, X 0,3 represents the initial state of the mapping automaton, G 3 Denotes the mapping automaton.

[0013] In an optional solution of the first aspect, the mapping operation of the mapping automaton is defined as: P:E→E o ∪{ε}, given an event e: if the event is an observable event, that is, e∈E o , then P(e)=e, where E o is a set of observable events; if the event is not an observable event, that is, e∈E\E o , then P(e)=ε, where E\E o is a set of unobservable events, E represents the set of labels of various events that can occur in the system itself; ε is a null character, indicating that the system has no event output; the mapping operation is extended from a single event to a sequence of multiple events: P:E * →(E o ∪{ε}) *, that is, given an event sequence s=s′e, the mapping operation is P(s)=P(s′)P(e).

[0014] In an optional solution of the first aspect, the state sets of the attacking automaton and the mapping automaton are the same as the state sets of the actual automaton; the event label set of the attacking automaton is the same as the event label set of the actual automaton; the attacked state set of the mapping automaton is the same as the attacked state set of the attacking automaton, and the event label set of the mapping automaton only includes observable events; the attack form label set of the mapping automaton is the same as the attack form label set of the attacking automaton, and the state transition function of the mapping automaton is obtained based on the state transition function of the attacking automaton, which is: The attack form assignment function of the mapping automaton is the same as that of the attack automaton. The initial state set of the mapping automaton is obtained based on the initial state set of the attack automaton, which is

[0015] In an optional solution of the first aspect, when designing a state observer, the state observer is formally represented as a function expression: G 4 =(X 4 ,X a ,E 4 ,Δ 4 ,f 4 ,λ 4 ,X 0,4 ),in, represents the state set of the state observer, X a represents the attacked state set of the state observer, E 4 =E 3 represents the observable event label set of the state observer, Δ 4 represents the attack form label set of the state observer, represents the state transfer function of the state observer, λ 4 :X 4 →Δ 4 represents the attack form assignment function of the state observer, X 0,4 represents the initial state of the state observer, G 4 represents the state observer.

[0016] In an optional scheme of the first aspect, when judging whether the state estimation only includes secret states, if the state estimation does not include non-secret states, the state estimation does not satisfy the opacity under state attacks; if the state estimation includes partial non-secret states, the state estimation satisfies the opacity under state attacks; if all state estimates include partial non-secret states, the preset information-physical system satisfies the opacity under state attacks; if there is at least one state estimation that does not include non-secret states, the preset information-physical system does not satisfy the opacity under state attacks.

[0017] In an optional solution of the first aspect, before verifying the opacity according to the state observer, it is determined whether the opacity of the preset cyber-physical system can be verified using a state observer that is not under state attack;

[0018] When it is determined that the preset information-physical system satisfies the opacity under no state attack, the state observer under state attack is used to verify the opacity of the preset information-physical system under state attack.

[0019] In the second aspect, the present application provides a security verification system for executing the method described in the first aspect, including: an automaton construction module, which is used to model a preset information-physical system and construct its actual automaton; an attack construction module, which is used to design an attack automaton and divide the state set in the actual automaton into an attacked state set and a non-attacked state set; a mapping construction module, which is used to design a mapping automaton and perform a natural mapping operation on the attack automaton; a state observation module, which is used to design a state observer and perform a state estimation operation on the mapping automaton; a security judgment module, which is used to judge whether the state estimation only contains secret states based on the state observer; if all state estimates contain at least one non-secret state, the preset information-physical system satisfies the opacity under state attack; if there is at least one state estimate that does not contain a non-secret state, the preset information-physical system does not satisfy the opacity under state attack.

[0020] In a third aspect, the present application provides a terminal device comprising one or more memories and a processor; the one or more memories store a computer program that can be run on the processor; and the one or more processors implement the system security verification method when executing the computer program.

[0021] It should be understood that the foregoing general description and the following detailed description are exemplary only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate one or more embodiments of the present application and, together with the description, serve to explain the principles of the present application and enable a person of ordinary skill in the relevant art to make and use the present application.

[0023] Figure 1 It is a schematic diagram of an exemplary autonomous vehicle driving on a map according to some embodiments of the present application.

[0024] Figure 2 It is a first flowchart schematic diagram of an exemplary method for constructing a state observer to perform opacity verification according to some embodiments of the present application.

[0025] Figure 3 It is a second flowchart schematic diagram of an exemplary method for constructing a state observer to perform opacity verification according to some embodiments of the present application.

[0026] Figure 4 It is a schematic structural diagram of an exemplary actual automaton according to some embodiments of the present application.

[0027] Figure 5 It is a schematic structural diagram of an exemplary attack automaton according to some embodiments of the present application.

[0028] Figure 6 It is a schematic structural diagram of an exemplary mapping automaton according to some embodiments of the present application.

[0029] Figure 7 It is a schematic structural diagram of an exemplary state observer according to some embodiments of the present application.

[0030] Figure 8 It is a schematic diagram of module connections of an exemplary security verification system according to some embodiments of the present application.

[0031] Fig. 9 It is a schematic structural diagram of an exemplary terminal device according to some embodiments of the present application. Detailed implementation manners

[0032] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application.

[0033] First, let’s take the example of a self-driving car driving on a map.

[0034] refer to Figure 1 As shown, Figure 1 A schematic diagram of an autonomous vehicle driving on a map is shown. The map is divided into five areas 1, 2, 3, 4 and 5. One-way or two-way access channels are set at specific locations of the five areas and are equipped with corresponding sensors. The autonomous vehicle can reach another area from one area via the channels. There is a channel between each area and at least one other area, and when the autonomous vehicle determines that it has reached another area through a channel from one area, the sensor can output a signal indicating that the autonomous vehicle has successfully crossed the channel; it should be noted that different channels can be equipped with the same sensor and thus can output the same signal; the same channel can also be equipped with different sensors and thus can output different signals. Different output signals represent different areas where the autonomous vehicle is heading; a channel may also not be equipped with a sensor, in which case no signal will be output.

[0035] For example, after the self-driving car passes through the channel from area 1 to area 2, 3, 4 or 5, the sensor will output signal a, which indicates that the car has reached area 2, 3, 4 or 5 from area 1; after the self-driving car passes through the channel from area 2 to area 4, the sensor will output signal b, which indicates that the car has reached area 4 from area 2; after the self-driving car passes through the channel from area 3 to area 5, the sensor will output signal b, which indicates that the car has reached area 5 from area 3; after the self-driving car passes through the channel from area 4 to area 1 or 5, the sensor will output signal c, which indicates that the car has reached area 1 or 5 from area 4; after the self-driving car passes through the channel from area 5 to area 4, the sensor will output signal c, which indicates that the car has reached area 4 from area 5; after the self-driving car passes through the channel without sensors from area 2 to area 4, or passes through the channel without sensors from area 3 to area 5, there is no signal output. This special case can be represented by signal u.

[0036] Assuming that area 5 is a secret area, and areas 2 and 4 are attacked areas, if an external intruder observes the car in area 5 together with the attacked information, the area will be destroyed, causing damage to the car, thus making the system unsafe.

[0037] The existing method of verifying system security is to build a state observer. First, it is necessary to list all event sequences that can be observed by external intruders. For a specific event sequence, the state in the state observer corresponds to the state estimate of the current system. However, the existing method of verifying system security does not involve state attacks.

[0038] Since the existing methods of constructing state observers cannot cope with cyber attacks, the opacity of the system cannot be met when it is attacked by a state, resulting in the system not being able to operate normally.

[0039] In response to the above problems, this application proposes a technical solution for a system security verification method. In this application, it is first necessary to establish a model representation of potential state attacks, and then, based on the operation of the information-physical system and the state attacks it has suffered, to build a state observer; since the state attacks have been taken into consideration in the process of building the state observer, the opacity of the system under the state attack can be verified to ensure the security of the system under the state attack.

[0040] The verification mechanism of opacity under state attack proposed in this application is to determine whether the state estimation of the state observer will reveal the secrets of the system. For example, the state observer can characterize the information of the system operation, and the operation information includes the observable events output by the system, or the operation information can also be understood as the observable events output by the system as considered by the external intruder; the state observer makes a reasonable guess about the state of the current system based on the observable events and the attack signal, and obtains the current possible state set of the system, that is, the state estimation under specific observable events and specific attack signals. In this way, the external intruder can observe the observable events output by the state observer, and can also guess the state of the system based on the event and the attack signal obtained. That is to say, for the external intruder, when estimating the state of the system, the possible state attack has been considered, thereby making up for the defect that the existing technology cannot deal with state attacks when verifying the opacity of the system.

[0041] Therefore, reference Figure 2 and Figure 3 As shown, Figure 2 A first flow chart of an exemplary system security verification method according to some embodiments of the present application is shown. Figure 3 A second flow chart of an exemplary system security verification method of some embodiments of the present application is shown. The present application relates to a system security verification method, the method comprising:

[0042] S1: First, for a given cyber-physical system, its automaton is constructed; that is, the cyber-physical system is modeled to obtain its corresponding automaton, which can be called the actual automaton of the cyber-physical system.

[0043] The information-physical system is given by the designer according to actual needs; when constructing the actual automaton, the function expression G can be used 1 =(X 1 ,E 1 ,f 1 ,X0,1 ) indicates that, where X 1 represents the state set of the system, E 1 Represents the event label set of the system. Event labels can be represented by characters. represents the state transition function, that is, the cyber-physical system will reach a certain state when a specific event occurs in a given state; X 0,1 represents the initial state set, G 1 Represents the actual automaton.

[0044] Specifically, the system's state set includes all the states experienced by the system, which include but are not limited to various physical, logical or control level situations; in the system's event label set, event labels are usually represented by characters or symbols. The event label set usually defines all events that occur in the system, which may trigger state transitions or affect the system's operating behavior; the state transition function describes the set of states that the system reaches when a specific event occurs in a given state. The definition of the state transition function reflects the system's logical rules and physical constraints, involving conditional judgments, event priorities and other system characteristics; the initial state set defines the set of states of the system at startup or initialization, which usually represents the system's safe state, default settings or other specific startup conditions, and is the starting point for system operation.

[0045] In some implementations of the present application, the actual automaton can also be represented by a state diagram. In the state diagram, the state is represented by a circle with a number, the initial state is marked with an input arrow, and the states are connected by directed arcs marked with event numbers; the behavior of the information-physical system can be described by the language of the automaton. The actual automaton reads a string character by character, and transfers to the next state step by step according to a given state transition function. After reading the string, if the actual automaton stops at a state belonging to the system state set, then the automaton accepts the string, otherwise it rejects the string. The set of strings accepted by an actual automaton is the language it speaks, denoted by L(G). Furthermore, the privacy of the information-physical system can be modeled as a partial secret state of the actual automaton, which is expressed by express.

[0046] For example, Figure 1 The autonomous vehicle system shown can be modeled as Figure 4 The actual automaton shown in the figure, where state 1, state 2, state 3, state 4 and state 5 represent area 1, area 2, area 3, area 4 and area 5 respectively; event labels a, event labels b, event labels c and event labels u represent reaching another area from one area through a channel equipped with or without a sensor respectively, state 5 is the secret state of the system, and the initial position of the car is unknown; thus, it can be concluded that X1 ={1,2,3,4,5},E 1 ={a,b,c,u},f 1 (1,a)={2,3,4,5},f 1 (2,b)={4},f 1 (2,u)={4},f 1 (3,b)={5},f 1 (3,u)={5},f 1 (4,c)={1,5},f 1 (5,c)={4},X 0,1 ={1,2,3,4,5},X S ={5}.

[0047] S2: Divide the state set in the actual automaton into an attacked state set and a non-attacked state set, assign binary signal 1 to all states belonging to the attacked state set, and assign binary signal 0 to all states belonging to the non-attacked state set, thereby constructing an attack automaton of the information-physical system that contains state attack signals.

[0048] It can be understood that in the attack automaton, the system state sends a binary signal 1 to represent that the state belongs to the attacked area, and the system state sends a binary signal 0 to represent that the state does not belong to the attacked area.

[0049] In S2, the attacked area of ​​the cyber-physical system is modeled as certain specific states. To ensure that external intruders can determine which states are attacked and which are not attacked, first, the actual automaton representing the attacked state of all the operating conditions of the cyber-physical system can output a binary signal of 1, and the actual automaton representing the unattacked state of all the operating conditions of the cyber-physical system can output a binary signal of 0, thereby obtaining an attack automaton. Therefore, the attack automaton contains all the states of the system and the state attack information. The system corresponding to the attack automaton can also be called the attack system obtained by the external intruder based on the original cyber-physical system and state attack.

[0050] When designing the attack automaton, the function expression can be used: G 2 =(X 2 ,X a ,E 2 ,Δ 2 ,f 2 ,λ 2 ,X 0,2 ) indicates that, where X 2 represents the state set of the attack automaton, X a represents the attacked state set of the attacking automaton, E 2Denotes the set of event labels of the attack automaton, Δ 2 represents the attack pattern label set of the attack automaton, represents the state transition function of the attack automaton, λ 2 :X 2 →Δ 2 represents the attack form assignment function of the attack automaton, X 0,2 represents the initial state of the attack automaton, G 2 Represents an attack automaton.

[0051] Specifically, the state set of the attack automaton includes all states that appear in the attack automaton. Each state can describe a different attack stage or strategy, which helps to comprehensively characterize the attacker's activity path and behavior evolution. The attacked state set of the attack automaton includes all the key states that are attacked or have been attacked, which are usually used to mark the weak points or sensitive points of the system and reveal the vulnerabilities that the attacker may try to exploit. a The analysis of the attack automaton can better predict and prevent potential security threats; the event label set of the attack automaton usually marks the events or behaviors that trigger the state transition. The events can represent the specific operations of the attacker, the changes in the external environment or the system response, etc.; the attack form labels in the attack form label set of the attack automaton describe different types of attack methods, strategies or means, such as physical attacks, network attacks, social engineering attacks, etc. The attack form labels help to classify different types of attacks and compare and analyze their impacts; the state transition function of the attack automaton describes the possible state changes of the attack automaton when it is affected by an event in a given state. The definition of this function provides the possible behavior path of the attacker, which can be used to simulate and analyze the attack process and impact to improve defense measures; the attack form assignment function of the attack automaton defines the attack form corresponding to each state. The existence of this function reflects the diversity and flexibility of the attack automaton, and different attack strategies can be applied according to different situations of the current state; the initial state set of the attack automaton is the starting point or initial state of the attack, which usually represents the initial conditions or the way of entering the system when the attacker just starts to implement the attack.

[0052] For example, after assigning binary signal 1 to attacked states 2 and 4 in the actual automaton, and assigning binary signal 0 to unattacked states 1, 3, and 5 in the actual automaton, the following can be obtained: Figure 5 The attack automaton shown in Figure 2. Figure 5 As shown in Figure 2, the attack automaton contains all the states of the system and the corresponding state attack information, from which we can deduce that X 2 ={1,2,3,4,5},X a ={2,4},E 2 ={a,b,c,u},Δ 2 ={0,1},f2 (1,a)={2,3,4,5},f 2 (2,b)={4},f 2 (2,u)={4},f 2 (3,b)={5},f 2 (3,u)={5},f 2 (4,c)={1,5},f 2 (5,c)={4},λ 2 (1) = λ 2 (3) = λ 2 (5) = 0, λ 2 (2) = λ 2 (4) = 1, X 0,2 ={1,2,3,4,5},X S ={5}.

[0053] S3: Perform a mapping operation on the attack automaton to obtain a mapping automaton of the cyber-physical system.

[0054] Specifically, the construction of the mapping automaton is based on the structure of the attack automaton, and the mapping automaton only contains observable events. When designing the mapping automaton, the function expression can be used: G 3 =(X 3 ,X a ,E 3 ,Δ 3 ,f 3 ,λ 3 ,X 0,3 ) indicates that, where X 3 represents the state set of the mapping automaton, X a represents the attacked state set of the mapping automaton, Denotes the observable event label set of the mapping automaton, Δ 3 Represents the attack pattern label set of the mapping automaton, represents the state transition function of the mapping automaton, λ 3 :X 3 →Δ 3 represents the attack form assignment function of the mapping automaton, X 0,3 represents the initial state of the mapping automaton, G 3 Represents a mapping automaton.

[0055] Specifically, the state set of the mapping automaton includes all the states that the mapping automaton may enter under different conditions. Each state can describe the internal performance, response mode or system environment of the mapping automaton under specific conditions. By defining and dividing the state set, the different stages or steps of the mapping process can be systematically described; the attacked state set of the mapping automaton includes the system states that are attacked or have been attacked. These states are usually considered to be potential weak links and require special attention and protection in actual systems to prevent malicious use. The mapping automaton helps to simulate and evaluate attack risks by representing these states; the observable event label set of the mapping automaton is the event label set E of the attack automaton. 2 It is a subset of the mapping automaton, which shows the events that can be observed by the mapping automaton in a specific state, and is an important basis for the mapping automaton to analyze and monitor the attack state; the attack form label set of the mapping automaton describes the attack methods or strategies that exist in different states or stages. By identifying the attack form, the mapping automaton can perform specific security monitoring and protection for the system state; the state transition function of the mapping automaton defines the possible state changes under a given state and observed events. This function is used to describe the possible path of the automaton from one state to another, providing a basis for analyzing and optimizing the mapping process. The construction of the state transition function should reflect the logical rules and dynamic characteristics of the actual system operation; the attack form assignment function of the mapping automaton maps a specific state to the corresponding attack form. Through this function, the mapping automaton can select the appropriate attack form description in different states, thereby more comprehensively reflecting the behavioral characteristics and risk level of the system when it is attacked; the initial state of the mapping automaton is the starting state at the beginning of the system or process. Defining the initial state helps to set the basic conditions of the mapping automaton and provide a benchmark for subsequent mapping and state transition.

[0056] The mapping operation of the mapping automaton is defined as P:E→E o ∪{ε}, given an event e, if the event is an observable event, that is, e∈E o , then P(e)=e, where E o is an observable event; if the event is not an observable event, that is, e∈E\E o , then P(e) = ε. The mapping operation can be extended from a single event to a sequence of multiple events P:E * →(E o ∪{ε}) * , that is, given an event sequence s=s′e, the mapping operation is P(s)=P(s′)P(e).

[0057] Assume that the current state of the attack automaton is x. According to the state transition function of the attack automaton, the events that can occur in the current state are: in is an empty set, and the observed set of observable events is Therefore, we can conclude that X 3 ={1,2,3,4,5},X a ={2,4},E 3 ={a,b,c},T o (1) = {a}, T o (2) = {b, c}, T o (3) = {b, c}, T o (4) = {c}, T o (5) = {c}, Δ 3 ={0,1},f 3 (1,a)={2,3,4,5},f 3 (2,b)={4},f 3 (2,c)={1,5},f 3 (3,b)={5},f 3 (3,c)={4},f 3 (4,c)={1,5},f 3 (5,c)={4},λ 3 (1) = λ 3 (3) = λ 3 (5) = 0, λ 3 (2) = λ 3 (4) = 1, X 0,3 ={1,2,3,4,5},X S ={5}.

[0058] In this application, the state set of the attack automaton and the mapping automaton is the same as the state set of the actual automaton, that is, X 1 =X 2 =X 3 ; The attacked state set of the mapping automaton is the same as the attacked state set of the attacking automaton; The event label set of the attacking automaton is the same as the event label set of the actual automaton, and the event label set of the mapping automaton only contains observable events, that is, The attack pattern label set of the mapping automaton is the same as the attack pattern label set of the attack automaton, that is, Δ 3 =Δ 2 ; The state transfer function of the mapping automaton is obtained based on the state transfer function of the attack automaton. The principle is: The attack shape assignment function of the mapping automaton is the same as that of the attack automaton, that is, λ 3 =λ 2 ; The initial state set of the mapping automaton is obtained according to the initial state set of the attack automaton, which is

[0059] For example, according to Figure 4 The actual automaton and state attack information in Figure 5 The attack automaton in Figure 5 After the attack automaton in the mapping operation is performed, we can obtain Figure 6 The mapping automaton shown. Figure 6 In the diagram, states include 1, 2, 3, 4, and 5. In state 1, states 2, 3, 4, and 5 can be reached via observable event number a; in state 2, state 4 can be reached via observable event number b; in state 2, states 1 and 5 can be reached via observable event number c; in state 3, state 5 can be reached via observable event number b; in state 3, state 4 can be reached via observable event number c; in state 4, states 1 and 5 can be reached via observable event number c; in state 5, state 4 can be reached via observable event number c.

[0060] Since mapping automata only contain observable events, mapping automata can represent all observable event sequences.

[0061] S4: construct a state observation automaton, which includes all observable event sequences and attack sequences; in the embodiment of the present application, the state observation automaton may also be referred to as a state observer.

[0062] Specifically, the construction of the state observer is based on the structure of the mapping automaton; a state in the state observer corresponds to the current state of all possible systems under an observable event sequence occurring in the mapping automaton and an attack sequence obtained by an external intruder. This state is called the state estimate of the system under a specific observable event sequence and a specific attack sequence. By listing all possible observable event sequences and attack sequences and finding the corresponding state estimate, the corresponding state observer can be obtained.

[0063] When designing a state observer, you can use the function expression: G 4 =(X 4 ,X a ,E 4 ,Δ 4 ,f 4 ,λ 4 ,X 0,4 ) indicates that, represents the state set of the state observer, X a represents the attacked state set of the state observer, E 4 =E 3 represents the observable event label set of the state observer, Δ 4 represents the attack pattern label set of the state observer, represents the state transition function of the state observer, λ4 :X 4 →Δ 4 represents the attack form assignment function of the state observer, X 0,4 represents the initial state of the state observer, G 4 represents the state observer.

[0064] Specifically, the state set of the state observer is usually the state set X of the mapping automaton. 3 It is a power set of the state observer, which contains the system state information that the observer can capture or infer at a specific time point. By designing the state observer state set, the system operation can be monitored and necessary analysis and feedback can be performed; the attacked state set of the state observer is a subset of the attacked or potentially attacked states that the state observer pays attention to, so that the state observer can focus on monitoring key states or vulnerabilities so that appropriate response measures can be taken when the system state approaches or enters the attacked state; the observable event label set of the state observer is consistent with the event label set of the mapping automaton. These event labels are used to represent events that can be observed in a specific state. The state observer can infer or verify the state change of the system by analyzing these events; the attack form label set of the state observer describes the attack forms detected by the state observer in different states. These labels can describe different types of attacks or threats, thereby helping the state observer to more accurately identify and classify threats; the state transition function of the state observer defines how the state observer transfers to another state under a specific state and observed event conditions. The state transition function defines the state observer's response to system changes and the rules for state transitions, thereby supporting continuous monitoring and analysis of the system state; the attack form assignment function of the state observer assigns a corresponding attack form to each state of the state observer. The attack form assignment function ensures that when the state observer detects state changes, it can classify or mark them according to the attack characteristics to provide a more accurate security situation assessment; the initial state of the state observer is the state of the state observer when it is started or initialized. Defining the initial state helps to set the working benchmark of the state observer, thereby providing basic conditions for subsequent state observation and transfer.

[0065] refer to Figure 7As shown, in some examples of the present application, when the external intruder does not observe any observable events, the initial states of the state observer are {1, 3, 5} and {2, 4} according to whether the current state of the information-physical system belongs to the attacked state set, where the attack form corresponding to {1, 3, 5} is 0, and the attack form corresponding to {2, 4} is 1. Taking the state {1, 3, 5} in the state observer as an example, the actual state of the information-physical system may be 1, 3 or 5. When the information-physical system is in state 1, event a may be observed; when the information-physical system is in state 3, events b and c may both be observed; when the information-physical system is in state 5, event b is observed; therefore, in state {1, 3, 5}, events a, b and c may all be observed. When event a is observed, the information-physical system may reach states 2, 3, 4 and 5 from state 1, and the attack form obtained by the external intruder is 0 or 1. When the acquired attack form is 1, the current state of the cyber-physical system should be 2 and 4; when the acquired attack form is 0, the current state of the cyber-physical system should be 3 and 4. Therefore, when the state of the state observer is {1, 3, 5}, when the external intruder observes event a and acquires attack signal 0, the state of the state observer becomes {3, 5}; when the external intruder observes event a and acquires attack signal 1, the state of the state observer becomes {2, 4}; similarly, the states of all state observers can be obtained according to the observed event sequence and attack signal sequence.

[0066] S5: According to the state observer, determine whether the state estimation only contains secret states. If all state estimates contain at least one non-secret state, execute step S50: preset the information-physical system to satisfy the opacity under state attacks; if there is at least one state estimation that does not contain a non-secret state, execute step S51: preset the information-physical system to not satisfy the opacity under state attacks.

[0067] Specifically, when judging whether the state estimation only contains secret states, if the state estimation does not contain non-secret states, the state estimation does not satisfy the opacity under state attacks; if the state estimation contains partial non-secret states, the state estimation satisfies the opacity under state attacks; if all state estimates contain partial non-secret states, the preset information-physical system satisfies the opacity under state attacks; if there is at least one state estimation that does not contain non-secret states, the preset information-physical system does not satisfy the opacity under state attacks.

[0068] In this application, the state in the state observer is composed of the current possible real state of the system. If there is a state in the state observer that only contains the secret state of the system, then when the observable event sequence and attack sequence corresponding to the state occur, the privacy of the system will be revealed, and thus the system does not meet the opacity under state attacks.

[0069] In this application, all possible current system states obtained according to the structure of the mapping automaton, the event sequence and attack sequence observed by the external intruder, that is, the state estimation of the mapping automaton, can be called a state observation automaton.

[0070] For example, the initial position of the car in the automatic driving system is unknown, that is, the initial state set of the automaton is {1, 2, 3, 4, 5}, the attacked state set known to the external intruder is {2, 4}, and area 5 is a secret area, that is, the secret state set is {5}. When the external intruder first observes the operation of the system, he can only judge the initial state of the system based on the attack signal. When the attack signal is 1, the initial state set of the system is {2, 4}; when the attack signal is 0, the initial state set of the system is {1, 3, 5}. After the external intruder obtains the attack signal 1, he observes the event b and the attack signal 1. Then, based on the current state estimate {2, 4}, the observable event b and the attack signal 1, the external intruder infers that the current state estimate of the system is {4}; because the external intruder cannot accurately infer the secret state of the system based on the state attack signal, the opacity of the system under the state attack is verified, that is, the security of the system under the state attack is verified.

[0071] By analogy, based on the operation of the cyber-physical system and the attack signals of external intruders, the state observer can estimate the state of the cyber-physical system in real time. By judging whether the state estimation of the cyber-physical system will necessarily reveal the system secrets, the purpose of verifying the opacity under state attacks can be achieved, thereby verifying the security of the system.

[0072] In some embodiments of the present application, before verifying the opacity of the system's automaton according to the state observer, it can be determined whether the existing state observer construction mechanism can be used to verify the opacity of the system. When it is determined that the system meets the opacity when it is not subjected to a state attack, the state observer construction mechanism under the state attack is used to verify the opacity of the system under the state attack. For example, after mapping the actual automaton, a state observer is constructed, and all state estimates in the state observer contain at least one non-secret state, it can be determined that the information-physical system can use the state observer to verify the opacity of the system when it is not subjected to a state attack.

[0073] The method for verifying the security of a system under a state attack in an embodiment of the present application is performed by constructing a state observer under a state attack. The state observer is closely connected to a given information-physical system. In one implementation, the state observer can be deployed inside the information-physical system; of course, the state observer can also be deployed outside the information-physical system and be able to communicate with the information-physical system.

[0074] The state observer can receive any event sent by the information-physical system and send out observable events that can be perceived by the outside world. The information of the information-physical system and the information of the state attack can be electrical signals, digital signals or signals sent by sensors. The specific form of the information of the information-physical system mainly depends on what kind of system the information-physical system is, and the state attack information mainly depends on the attack behavior launched by the information-physical system and the external intruder. In this application, the information of the information-physical system can be abstracted as the state of the information-physical system at that time and the behavior of the system represented by the event number. The state attack information can be abstracted as a binary signal sent by the state of the information-physical system at that time, representing whether it is attacked.

[0075] In some embodiments, reference Figure 8 As shown, Figure 8 Schematic diagram of module connection of a security verification system for implementing an embodiment of the present application. Therefore, the present application also relates to a security verification system for executing a system security verification method, including:

[0076] The automaton construction module 101 is used to model the preset cyber-physical system and construct its actual automaton.

[0077] The attack construction module 102 is used to design an attack automaton and divide the state set in the actual automaton into an attacked state set and a non-attacked state set.

[0078] The mapping construction module 103 is used to design a mapping automaton and perform a natural mapping operation on the attack automaton.

[0079] The state observation module 104 is used to design a state observer and perform state estimation operations on the mapping automaton.

[0080] The security judgment module 105 is used to judge whether the state estimation only contains secret states based on the state observer. If all state estimates contain at least one non-secret state, the preset information-physical system satisfies the opacity under state attacks; if there is at least one state estimation that does not contain a non-secret state, the preset information-physical system does not satisfy the opacity under state attacks.

[0081] In some embodiments, reference Fig. 9 As shown, Fig. 9 The block diagram of the terminal device used to implement the embodiment of the present application. The terminal device includes: a memory 201 and a processor 202, and the memory 201 stores a computer program that can be run on the processor 202. When the processor 202 executes the computer program, the method in the above embodiment is implemented. The number of the memory 201 and the processor 202 can be one or more.

[0082] The terminal device also includes:

[0083] The communication interface 203 is used to communicate with external devices and perform data exchange transmission.

[0084] If the memory 201, the processor 202 and the communication interface 203 are implemented independently, the memory 201, the processor 202 and the communication interface 203 can be connected to each other through a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig. 9 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0085] Optionally, in a specific implementation, if the memory 201, the processor 202 and the communication interface 203 are integrated on a chip, the memory 201, the processor 202 and the communication interface 203 can communicate with each other through an internal interface.

[0086] The embodiment of the present application provides a computer-readable storage medium storing a computer program, which implements the method provided in the embodiment of the present application when the program is executed by the processor 202.

[0087] The embodiment of the present application also provides a chip, which includes a processor 202, which is used to call and execute instructions stored in the memory 201 from the memory 201, so that a communication device equipped with the chip executes the method provided by the embodiment of the present application.

[0088] The embodiment of the present application also provides a chip, including: an input interface, an output interface, a processor 202 and a memory 201. The input interface, the output interface, the processor 202 and the memory 201 are connected through an internal connection path. The processor 202 is used to execute the code in the memory 201. When the code is executed, the processor 202 is used to execute the method provided in the embodiment of the application.

[0089] It should be understood that the processor 202 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor 202 may be a processor 202 that supports the Advanced RISC Machines (ARM) architecture.

[0090] Further, the above-mentioned memory 201 may include a read-only memory and a random access memory, and may also include a non-volatile random access memory. The memory 201 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may include a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may include a random access memory (RAM), which is used as an external cache. By way of exemplary but not limiting description, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM) and direct memory bus random access memory (DR RAM).

[0091] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium.

[0092] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A system security verification method, characterized in that: The method comprises: Model the pre-set cyber-physical system and construct its actual automaton; Designing an attack automaton and dividing a state set in the actual automaton into an attacked state set and a non-attacked state set; Designing a mapping automaton and performing a natural mapping operation on the attack automaton; Designing a state observer and performing state estimation operations on the mapping automaton; According to the state observer, it is determined whether the state estimation only includes secret states. If all state estimations include at least one non-secret state, the preset information-physical system satisfies the opacity under state attacks; if there is at least one state estimation that does not include a non-secret state, the preset information-physical system does not satisfy the opacity under state attacks; When designing an attack automaton, the attack automaton is formally represented as a function expression: ,in, represents the state set of the attack automaton, represents the attacked state set of the attacking automaton, represents the set of event labels of the attack automaton, represents the attack pattern label set of the attack automaton, represents the state transition function of the attack automaton, represents the attack form assignment function of the attack automaton, represents the initial state of the attack automaton, Denote the attack automaton.

2. The method according to claim 1, characterized in that When constructing an actual automaton, the actual automaton is formally represented as a function expression: ,in, represents the state set of the system, Represents the event label set of the system, represents the state transition function, represents the initial state set, represents the actual automaton.

3. The method according to claim 2, characterized in that The privacy of the preset cyber-physical system is modeled as a partial secret state of the actual automaton.

4. The method according to claim 1 or 3, characterized in that: When the state set in the actual automaton is divided into an attacked state set and a non-attacked state set, the method further comprises: Assigning a binary signal 1 to all states belonging to the attacked state set; All states belonging to the unattacked state set are assigned a binary signal 0.

5. The method according to claim 1, characterized in that When designing a mapping automaton, the mapping automaton is formally represented as a function expression: ,in, represents the state set of the mapping automaton, represents the attacked state set of the mapping automaton, represents the set of observable event labels of the mapping automaton, represents the attack pattern label set of the mapping automaton, represents the state transition function of the mapping automaton, represents the attack form assignment function of the mapping automaton, represents the initial state of the mapping automaton, Denotes the mapping automaton.

6. The method according to claim 5, characterized in that in, The mapping operation of the mapping automaton is defined as: , given an event : If the event is an observable event, ,but , where is the set of observable events; If the event is not a significant event, ,but ,in is the set of unobservable events, A set of labels representing various events that can occur in the system itself; A null character indicates that the system does not have any event output; The mapping operation is expanded from a single event to a sequence of multiple events: , that is, given a sequence of events , whose mapping operation is .

7. The method according to claim 5, characterized in that in, The state set of the attack automaton and the mapping automaton is the same as the state set of the actual automaton; The event label set of the attack automaton is the same as the event label set of the actual automaton; The attacked state set of the mapping automaton is the same as the attacked state set of the attacking automaton, and the event label set of the mapping automaton only contains observable events; The attack form label set of the mapping automaton is the same as the attack form label set of the attack automaton. The state transition function of the mapping automaton is obtained based on the state transition function of the attack automaton, which is: ,in is the current state of the attack automaton; The attack form assignment function of the mapping automaton is the same as that of the attack automaton. The initial state set of the mapping automaton is obtained based on the initial state set of the attack automaton, which is .

8. The method according to claim 1 or 7, characterized in that: When designing a state observer, the state observer is formally represented as a function expression: ,in, represents the state set of the state observer, represents the attacked state set of the state observer, represents the set of observable event labels of the state observer, represents the attack form label set of the state observer, represents the state transfer function of the state observer, represents the attack form assignment function of the state observer, represents the initial state of the state observer, represents the state observer.

9. The method according to claim 8, characterized in that When judging whether the state estimation only includes secret states, if the state estimation does not include non-secret states, the preset information-physical system does not satisfy the opacity under state attacks; if the state estimation includes partial non-secret states, the preset information-physical system satisfies the opacity under state attacks; if all state estimates include partial non-secret states, the preset information-physical system satisfies the opacity under state attacks; if there is at least one state estimation that does not include non-secret states, the preset information-physical system does not satisfy the opacity under state attacks.

10. The method according to claim 1, characterized in that Before verifying the opacity according to the state observer, determining whether the opacity of the preset cyber-physical system can be verified using a state observer that is not under state attack; When it is determined that the preset information-physical system satisfies the opacity under no state attack, the state observer under state attack is used to verify the opacity of the preset information-physical system under state attack.

11. A security verification system for executing the method according to any one of claims 1 to 10, characterized in that: include: The automaton building module is used to model the preset cyber-physical system and build its actual automaton; An attack construction module, used for designing an attack automaton and dividing a state set in the actual automaton into an attacked state set and a non-attacked state set; A mapping construction module, used for designing a mapping automaton and performing a natural mapping operation on the attack automaton; A state observation module, used for designing a state observer and performing state estimation operations on the mapping automaton; A security judgment module is used to judge whether the state estimation only contains secret states based on the state observer. If all state estimates contain at least one non-secret state, the preset information-physical system satisfies the opacity under state attacks; if there is at least one state estimation that does not contain a non-secret state, the preset information-physical system does not satisfy the opacity under state attacks.

12. A terminal device, characterized in that: comprising one or more memories and processors; One or more memories storing a computer program executable on the processor; When one or more processors execute the computer program, the method according to any one of claims 1 to 10 is implemented.