Resilient control method and system against denial of service attacks for cyber-physical systems

By employing an event-triggered secure transmission strategy and a flexible control method for switching observers, the problem of independent DoS attacks on sensor-to-observer and controller-to-actuator channels in cyber-physical systems was solved, thereby improving system stability and the accuracy of state estimation, and enhancing the system's resistance to attacks.

CN119520065BActive Publication Date: 2026-04-10SHANDONG NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANDONG NORMAL UNIV
Filing Date
2024-11-14
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively address independent and intermittent denial-of-service attacks on sensor-to-observer and controller-to-actuator channels in cyber-physical systems, which can lead to communication interruptions and affect system performance and stability.

Method used

Design an event-triggered secure transmission strategy and a resilient control method for switching observers. By detecting DoS attacks, event-triggered data transmission is generated. The ACK signal confirming data reception is fed back by the switching observer to update the state estimate. Finally, the controller calculates control signals to ensure system stability and optimized use of communication resources.

Benefits of technology

Under dual-channel independent DoS attacks, the system achieves state estimation and control of the network physical system, ensuring system stability and effective utilization of communication resources, enhancing the system's resistance to attacks, and guaranteeing the safe and reliable operation of critical infrastructure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520065B_ABST
    Figure CN119520065B_ABST
Patent Text Reader

Abstract

The application provides a resilient control method and system for denial of service attacks on networked physical systems, and relates to the field of security control of networked physical systems, and aims to solve the problem of non-periodic and boundaryless double-channel DOS attack. An event trigger generates an event when measurement data meets a specific trigger condition, transmits the trigger data, transmits the data under the condition of meeting the transmission rule, switches the observer to update the state estimation, and sends the estimation value to the controller; the controller sends an acknowledgement signal to the switching observer, calculates the control signal according to the estimation value, and sends the control signal to the actuator; the actuator feeds back the acknowledgement signal and executes the calculated control signal. Based on the event trigger mechanism, by designing a safe transmission strategy, a switching observer and a resilient control method, the state estimation and control of the networked physical system when suffering from double-channel independent DoS attack are realized, and the system stability is ensured and the communication resources are optimized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the field of secure control of cyber-physical systems (CPS), and particularly relates to a resilient control method and system against denial-of-service attacks for cyber-physical systems. BACKGROUND

[0002] The statements in this section merely provide background information related to the present application and do not necessarily constitute the prior art.

[0003] Cyber-physical systems (CPS) integrate computing, communication and control technologies, and are widely used in electric vehicles, smart grids, manufacturing systems, intelligent medical care, etc. However, since CPS relies on real-time network communication, it is vulnerable to denial-of-service (DoS) attacks, which can cause communication interruption and thus affect the performance and stability of the system. Therefore, it is particularly important to ensure the safe operation of CPS under potential malicious attacks.

[0004] Deception attacks and denial-of-service (DoS) attacks are two common attacks in CPSs, which have been widely studied. DOS attacks are different from deception attacks that require prior information of the system to tamper with the transmission signal. The main purpose of DoS attacks is to prevent the transmission of signals. In recent years, security problems under DoS attacks have been widely studied. Existing methods can be roughly divided into three categories: stochastic system methods, game theory methods and resilient control methods. For stochastic system methods, after modeling DoS attacks as Bernoulli processes or Markov processes, the system considered can be regarded as a stochastic system. The sufficient conditions for guaranteeing security requirements are analyzed using stochastic system theory. In the game theory method, the security control of network control systems (NCSs) with DoS attacks is achieved by using the unified game method. In previous studies, an improved Nash Q-learning algorithm is used to solve the optimal solution of the related optimality equation in the established Markov game framework. The value iteration and Q-learning methods are used to solve the hierarchical game problem of wireless NCSs, and the transmitter and DoS attacker interaction is modeled using a zero-sum Markov game method.

[0005] Researchers in the field have developed various resilient control methods to enhance the stability and performance of cyber-physical systems (CPS) when facing periodic and two-channel DoS attacks. These methods include event-triggered H ∞Control strategies to ensure the stability of vehicle suspension systems under periodic DoS attacks; observer-based controller design to ensure the exponential stability of CPS under double-channel periodic DoS attacks by analyzing enhanced discrete-time cyclic-switching systems; and resilient sliding mode controllers designed based on a general DoS attack model to achieve input-to-state practical stability and decentralized performance of CPS under DoS attacks. In addition, the researchers also proposed a robust integral sliding mode control algorithm to resist DoS attacks with time ratio and frequency constraints; achieved input-to-state stability of CPS under double-channel asynchronous DoS attacks, and derived the upper limit of attack tolerance duration and frequency; and H ∞ Filtering provides DoS attack protection for network systems with limited duration and interval time.

[0006] In addition, the researchers also designed a switching-like event-triggered communication scheme to resist single-channel DoS attacks, and developed an active security control method based on the event-triggered mechanism to achieve the asymptotic stability of CPS under asynchronous double-channel DoS attacks, which significantly improves the resilience and security of CPS when facing complex network attacks.

[0007] The inventors found that since CPS relies on real-time network communication, it is vulnerable to denial-of-service (DoS) attacks, which can cause communication interruption and affect system performance and stability. Existing methods usually consider periodic DoS attacks with boundary duration and frequency, but for non-periodic and boundaryless DoS attacks, especially independent attacks on sensor-to-observer (S-O) and controller-to-actuator (C-A) channels, existing techniques have not provided effective solutions. SUMMARY

[0008] To overcome the above-mentioned deficiencies of the prior art, the present application provides a resilient control method and system for denial-of-service attacks on cyber-physical systems, which designs a secure transmission strategy, a switching observer and a resilient control method to achieve state estimation and control of cyber-physical systems under double-channel independent DoS attacks, ensuring system stability and optimizing the use of communication resources.

[0009] To achieve the above-mentioned purpose, one or more embodiments of the present application provide the following technical solutions:

[0010] In a first aspect of the present application, a resilient control method for denial-of-service attacks on cyber-physical systems is provided, comprising:

[0011] Detecting network physical system state, and judging whether DoS attack occurs based on detected network physical system state, if DoS attack occurs, generating event when trigger condition is met, and triggering network physical system measurement data sending based on the event;

[0012] DoS attack is: independent and irregular DoS attack in sensor-to-observer and controller-to-actuator channel;

[0013] Based on the transmission rule, the measurement data of the network physical system is sent to the switching observer;

[0014] The switching observer feeds back ACK signal confirming data receiving, then the switching observer updates state estimation and sends to the controller;

[0015] The controller calculates control signal according to the latest state estimation and sends the calculated control signal to the actuator, the actuator feeds back ACK signal confirming control signal receiving, and executes the calculated control signal to adjust the state of the network physical system;

[0016] Check the stability of the network physical system performance index, and cycle monitoring and cycle execution until the network physical system is stable.

[0017] As a further technical solution, the network physical system, under the interference and DoS attack, the physical process formula is:

[0018]

[0019] Wherein, x(k)∈R n represents the state of the system, u(k)∈R m represents the control signal of the system, y(k)∈R p represents the measurement data of the system; w(k)∈R q and represents the process disturbance; v(k)∈R d represents the input disturbance; A, B, E, C, D are known system matrices with corresponding dimensions.

[0020] As a further technical solution, when the trigger condition is met, an event is generated, specifically:

[0021] According to the measurement data, the measurement error is calculated;

[0022] According to the measurement error, the event trigger condition is obtained;

[0023] Judge whether the event trigger condition is met, if yes, generate the event.

[0024] As a further technical solution, when transmitting, specifically:

[0025] When the measurement data meets the triggering condition, the measurement data is packaged and sent to the observer until the confirmation signal of the observer is received;

[0026] When the observer receives the packaged measurement data, the observer sends the state estimation value to the controller;

[0027] When the controller receives the state estimation value, the controller calculates the control signal and sends the calculated control signal to the actuator;

[0028] When the actuator receives the calculated control signal package, the actuator sends a confirmation signal to the controller and clears the previous control signal, and the control signal in the new data package is re-sent to the actuator in order.

[0029] As a further technical solution, the switching observer updates the state estimation, specifically:

[0030] According to the transmission rule, the switching observer is constructed, and a set of transmission successful time points is obtained;

[0031] According to the set of time points, the observer is switched to different observer states;

[0032] According to the observer state, the state estimation is updated.

[0033] As a further technical solution, the calculation formula of the control signal is:

[0034]

[0035] Wherein, K is a control gain matrix, represents the state estimation value, A represents a parameter matrix of the same dimension as the original state matrix, and B represents a parameter matrix of the same dimension as the control signal.

[0036] As a further technical solution, under the transmission rule, the measurement data and the control signal are packaged into the form of data packets for transmission.

[0037] The second aspect of the application provides a denial of service attack resilient control system for a network physical system, comprising:

[0038] The attack detection and event generation module is configured to detect the network physical system state and determine whether a DoS attack occurs based on the detected network physical system state, and if a DoS attack occurs, an event is generated when a triggering condition is met, and the event triggers the sending of network physical system measurement data;

[0039] The DoS attack is: independent and irregular DoS attacks in the sensor-to-observer and controller-to-actuator channels;

[0040] a transmission mechanism module configured to transmit the measurement data of the cyber-physical system to the switching observer based on a transmission rule;

[0041] a switching observer module configured to feed back an ACK signal of the switching observer confirming data reception, and then the switching observer updates the state estimation and transmits to the controller.

[0042] a control adjustment module configured to perform control signal calculation by the controller according to the latest state estimation and transmit the calculated control signal to the actuator, the actuator feeds back an ACK signal of the control signal confirming signal reception, and executes the control signal to adjust the state of the cyber-physical system.

[0043] a system detection module configured to check the stability of the performance index of the cyber-physical system, and perform cyclic monitoring and cyclic execution until the cyber-physical system is stable.

[0044] The third aspect of the present application provides a computer readable storage medium having a program stored thereon, which, when executed by a processor, implements the steps in the method of the first aspect of the present application.

[0045] The fourth aspect of the present application provides a computer device comprising a memory, a processor, and a program stored on the memory and executable on the processor, wherein the processor implements the steps in the method of the first aspect of the present application when executing the program.

[0046] The above one or more technical solutions have the following beneficial effects:

[0047] In the embodiment, the event-triggered remote secure state estimation and resilient control method is used in the CPS to ensure that the cyber-physical system can achieve stability and accuracy of state estimation under the predetermined performance under the double-channel independent DoS attack. By using the event-triggered secure transmission mechanism (ETSTM), the success and timely transmission of data is ensured, the designed switching observer can achieve remote secure state estimation (SSE) of the CPS within a limited predefined time, and the developed resilient control method is based on ETSTM and the switching observer, which ensures that the CPS can still meet the specified H ∞ performance criteria in the presence of process disturbance, output disturbance and DoS attack. It provides an effective solution for the safe operation of CPS in a complex network attack environment, enhances the ability of the system to resist network attacks, and ensures the safe and reliable operation of critical infrastructure.

[0048] The advantages of the additional aspects of the present application will be partially given in the following description, partially become obvious from the following description, or be learned by the practice of the present application. BRIEF DESCRIPTION OF DRAWINGS

[0049] The accompanying drawings, which form a part of this specification, are included to provide a further understanding of the application, and are incorporated by reference in their entirety.

[0050] Figure 1 A schematic diagram of a denial-of-service attack resilience control system for a cyber-physical system according to an embodiment of the present application;

[0051] Figure 2 A flowchart of a denial-of-service attack resilience control method for a cyber-physical system according to an embodiment of the present application. DETAILED DESCRIPTION

[0052] It should be noted that the following detailed description is merely exemplary and is intended to provide further description of the application. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs.

[0053] It should be noted that the terms used herein are merely for the purpose of describing specific embodiments and are not intended to limit exemplary embodiments according to the present application.

[0054] In the case of no conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0055] The overall idea of the present application is as follows: for a dual-channel independent denial-of-service attack on a cyber-physical system, first, the state of the cyber-physical system is detected, the system is attacked by DoS, and the trigger condition is met at the same time, and data transmission is triggered; second, a secure transmission mechanism is built to ensure successful communication and timely data transmission, a switching observer is built to ensure that the safe state estimation of the cyber-physical system is realized within a predefined finite time; finally, based on the secure transmission mechanism and the switching observer, the controller adopts an elastic control strategy to make the CPS system stable under DoS attack and interference, and the system is detected.

[0056] Embodiment One

[0057] The present embodiment discloses a denial-of-service attack resilience control method for a cyber-physical system.

[0058] In order to more clearly illustrate the present embodiment, the implementation process of the denial-of-service attack resilience control for a cyber-physical system can be specifically described as follows:

[0059] As shown in Figure 1 , Figure 2 The present application provides a denial-of-service attack resilience control method for a cyber-physical system, comprising:

[0060] S1, detecting the network physical system state, and determining whether a DoS attack occurs based on the detected network physical system state, if a DoS attack occurs, generating an event at the same time when the trigger condition is met, and triggering the sending of the network physical system measurement data based on the event;

[0061] S2, sending the measurement data of the network physical system to the switching observer based on the transmission rule;

[0062] S3, the switching observer feeds back an ACK signal confirming data reception, and then the switching observer updates the state estimation and sends it to the controller;

[0063] S4, the controller calculates the control signal according to the latest state estimation and sends the calculated control signal to the actuator, the actuator feeds back an ACK signal confirming control signal reception, and executes the calculated control signal to adjust the network physical system state;

[0064] S5, checking the stability of the network physical system performance index, and cyclically monitoring and executing until the network physical system is stable.

[0065] As shown in Figure 1 , Figure 2 In this embodiment, in step S1, the network physical system state is detected, and whether a DoS attack occurs is determined based on the detected network physical system state, if a DoS attack occurs, an event is generated at the same time when the trigger condition is met, and the sending of the network physical system measurement data is triggered based on the event.

[0066] The network physical system is vulnerable to denial of service attacks, and in these attacks, DoS attacks occur independently and aperiodically in the sensor-to-observer (S-O) and controller-to-actuator (C-A) channels. To solve this security problem, an event-triggered remote secure state estimation and resilient control method is proposed to ensure that the network physical system can achieve stability and state estimation accuracy under the predetermined performance under double-channel independent DoS attacks.

[0067] S101, detecting that the network physical system is disturbed and attacked by DoS, the formula is:

[0068]

[0069] Where, x(k)∈R n represents the state of the system, u(k)∈R m represents the control signal of the system, y(k)∈R p represents the measurement data of the system; w(k)∈R q and represents the process disturbance; v(k)∈R drepresents the input disturbance; A, B, E, C, D are known system matrices with corresponding dimensions, A, C represent the same dimension parameter matrices of the original state matrix, B represents the same dimension parameter matrix of the control signal, and D and E represent the corresponding dimension parameter matrices of the process disturbance and output disturbance, respectively.

[0070] When the network system is attacked by DoS, the system state changes, and an x(k+1) is output through formula (1), which preliminarily detects that the network system is attacked by DoS.

[0071] In addition, in order to ensure the existence of the switching observer, according to the existence condition of the unknown input observer, the conditions that the matrix parameters E, C and D of the system satisfy are derived, and the formula is as follows:

[0072]

[0073] wherein, represents that in the case of considering output feedback and disturbance, the disturbance w(k) can still be observed in the output y(k) of the system, which projects the output y(k) into the space not affected by the direct transmission disturbance Dv(k), and this condition ensures that even in the case of output disturbance, the influence of the disturbance w(k) on the system state can still be observed; is a projection matrix, I is a unit matrix, and D is an output matrix, is the pseudo-inverse matrix of D, C is an output matrix, E is a matrix representing process disturbance, q is a positive integer, representing the rank of the disturbance matrix E, which represents the action dimension of the disturbance in the system state space, d is the rank of the output disturbance matrix D, which represents the action dimension of the output disturbance in the output space, q

[0074] In order to achieve the predefined goal, formula (2) is given, which provides necessary information for state estimation and control of the system and provides a theoretical basis for the design of the observer. It can be ensured that even in the presence of disturbance, the state of the system can still be accurately estimated and controlled.

[0075] Since the energy of the attacker is always limited, and the attacker tries to hide himself, the duration of each attack is usually bounded. At the same time, it is reasonable to allow a period of normal communication after each attack, otherwise it cannot be called energy-limited or time-limited, therefore, the duration step of each attack of S-O and C-A channels is set to be no more than b1 and b2 respectively, and the interval between adjacent attacks is greater than 1 step.

[0076] Through the above steps, it is detected that the cyber-physical system is interfered and attacked by DOS, that is, it is preliminarily judged that DOS attack is received, data support is provided for subsequent event triggering and transmission, and necessary information is provided for system state estimation and control.

[0077] S102, measurement data generates events when a certain triggering condition is met, and the events will trigger the sending of measurement data.

[0078] Specific process, S1021, according to the measurement data, the measurement error is calculated.

[0079] e y (k) = y(k) - y(k t )(3)

[0080] Wherein, e y (k) represents the measurement error, k represents the current time before the latest event triggering time, k t represents the latest event triggering time, y(k) represents the measurement data at the current time k, and y(k t ) represents the measurement data at the latest event triggering time.

[0081] According to formula (3), at each time k, the difference e y (k) between the current measurement output y(k) and the measurement output y(k t ) at the last triggering time is calculated.

[0082] S1022, according to the measurement error, the event triggering condition is obtained.

[0083] The calculated measurement error e y (k) is compared with the preset threshold value, and the threshold value is determined by parameters α1, α2 and The event triggering condition is as follows:

[0084]

[0085] Wherein, 0 < α1 < 1, α2 > 0, and h is a given parameter, represents the limit of measurement noise.

[0086] S1023, it is judged whether the event triggering condition is met, if yes, an event is generated.

[0087] When the measurement data of the system meets formula (4), the state of the system has changed significantly, and the event trigger will trigger an event once. Once the event is triggered, the current measurement data y(k) is packaged and sent to the observer, and the triggering time k tFor the current time k, continue to monitor the state change of the next time step; if not satisfied, continue to monitor until the condition is met.

[0088] When the measurement data of the system satisfies formula (4), an event is generated, and the sending of the measurement data of the system is triggered.

[0089] As shown in Figure 1 , Figure 2 , in step S2, the measurement data of the network physical system is sent to the switching observer based on the transmission rule.

[0090] S201, based on the event triggering condition in formula (4), an event triggered safety transmission mechanism ETSTM is constructed, that is, the transmission rule is:

[0091] 1) When the event triggering condition in formula (4) is satisfied, the measurement data in formula (1) is packaged as Y(k), Y(k+1),..., Y(k+b1), and is sent to the observer at k∈{k t ,k t +1,...,k t +b1} respectively until the ACK signal from the observer is received. Wherein, j∈{1,2,...,b1}

[0092]

[0093] Wherein, k t in formula (4) is the time satisfying the event triggering, and τ is the designed observer parameter.

[0094] 2) When k∈S s , the observer sends the state estimation value to the controller, wherein S s ={k s ,k s,1 ,...,k s,i ,i∈N +} represents the time set when the measurement data is successfully transmitted, and k s,i represents the time of successful transmission.

[0095] 3) When the controller receives the state estimation value , the control signal [u(k s ), u(k s +1),...,u(k s +h2)] is calculated, which is packaged as U(k s,i ), U(k s,i +1),...,U(k s,i +b2), and is sent to the observer at k∈{k s,i ,k s,i +1,...,ks,i + b2} time period until an ACK signal from the actuator is received, where U(k s,i + l) = {u(k s+i + l), u(k s+i + l + 1), …, u(k s+i + h2)} and h2 = h + b1 + b2 - 1, and the controller stops sending and discarding unsent control signals, sending the latest control signal to the switching observer.

[0096] 4) When a new data packet is received, the actuator clears the previous control signal and re-sends the control signal in the new data packet to the actuator in order.

[0097] S202, verify the performance of the event-triggered security transmission mechanism ETSTM.

[0098] Since data is usually transmitted in the form of packets in the network, and the communication resources consumed in the payload of the packet are the same. Therefore, the proposed ETSTM is feasible, as long as the data transmitted each time can be packaged into a data packet, the consumption of network resources will not increase.

[0099] The specific performance analysis is as follows:

[0100] 1) Interference can cause an increase in the triggering frequency, and the upper limit of the triggering interval h can reduce the impact of interference.

[0101] 2) When k ∈ [k t , ∞), the interference can cause the event not to be triggered. The upper limit h of the triggering interval can prevent this from happening and ensure timely triggering of the event.

[0102] 3) Since the maximum duration of each attack in the S-O channel is b1, ETSTM can guarantee successful transmission of the measurement data packet at k s,i = k t + b1 at the latest, and since Δk t = k t+1 - k t ≤ h, Δk s = k s,i+1 - k s,i ≤ h1 holds, where h1 = h + b1, ensuring timely updating of the measurement data.

[0103] 4) Since the maximum duration of each attack in the C-A channel is b2, ETSTM can ensure successful transmission of the control data at k d,i = k s,i + b2, where k d,i ∈ S​​d denotes the time of successful transmission of the control packet and S d = {k d,1 , k d,2 ,..., k d,i}, i ∈ N + denotes the set of successful transmission time. Since, Δk s ≤ h1, Δk d = k d,i+1 - k d,i ≤ h2 + 1 can be established, which ensures the timely update of the control signal data. At the same time, although the DoS attack occurs independently in two channels, the remote observer can know the control signal executed by the actuator at any time through the ACK signal.

[0104] The above analysis shows that the construction of the event-triggered safe transmission mechanism (ETSTM) can save communication resources and resist independent double-channel DoS attacks, and ensure the timely update of the measurement and control signals; in addition, the designed ETSTM can ensure that the control inputs used by the observer and the actuator are the same.

[0105] S203, based on the transmission rule, the measurement data is packaged into a data packet and transmitted.

[0106] According to the transmission rule, the measurement data is first packaged and sent to the switching observer, and then the state estimation updated by the switching observer is sent to the controller according to the S-O and C-A transmission rules. The controller sends the calculated control signal to the actuator.

[0107] In this embodiment, the event-triggered safe transmission mechanism can also be applied to the remote data processing center with functional modules such as observers, controllers, etc. It can also be used as a signal transmission strategy in the factory.

[0108] As shown in Figure 1 , Figure 2 in this embodiment, in step S3, the switching observer feeds back the ACK signal for confirming the data reception, and then the switching observer updates the state estimation and sends it to the controller.

[0109] S301, the switching observer based on the transmission rule.

[0110] In this embodiment, the switching observer includes a temporary observer, an FT observer, and an RT (Real Time, RT) observer.

[0111] In order to ensure that the event-triggered remote safe state estimation SSE is within a known bounded range within a predefined finite time, based on the event-triggered safe transmission mechanism ETSTM, a switching observer is constructed, and the formula is as follows:

[0112]

[0113] where, and denote the successful transmission time set when k ∈ [0, τ-1] and k ∈ [τ, +∞), respectively; is the state estimation at time k, is the initial state estimation; F1 k and F τ is the dynamic matrix of the observer; and is the control signal matrix based on the observer dynamics; U s1 (k) and U s2 (k) is the control signal; and is the output disturbance matrix based on the observer dynamics; Y s1 (k) and Y s2 (k) is the measurement data; M is a matrix used to switch the observer dynamics when k ∈ S s2 ; N is a parameter matrix used to define the switching logic of the observer; τ is the time interval of the observer switching; the specific expressions are as follows:

[0114] when k ∈ S s1 , Y s1 (k) = [y T (k) y T (k-1) … y T (0)] T ,

[0115]

[0116] T = I - GQC,

[0117] U s1 (k) = [u T (k-1) u T (k-2) … u T (0)] T ,

[0118]

[0119] when k ∈ S s1 , Y s1 (k) = [y T (k) y T (k-1) … y T (0)] T and

[0120]

[0121] M = [I n 0 n ][N F τ N] -1 ,

[0122]

[0123] L1 and L2 are gain matrices when k ∈ S s2 .

[0124] The following is the existence condition and effectiveness proof of the SSE method.

[0125] If the eigenvalues of F satisfy

[0126] 0 < |λ 1,min | < |λ 1,max | < |λ 2,min | < |λ 2,max | < 1 (6)

[0127] where, l λ = 1, 2, there is a positive integer τ such that

[0128] det([N F τ N]) ≠ 0 (7)

[0129] ;

[0130] At the same time, formula (2) is satisfied, and is observable, then the designed switching observer is existent based on the designed ETSTM, and when k ≥ k s2,1 , the designed switching observer can guarantee that the state estimation error of the CPS under DoS attack is within a certain bounded range.

[0131] And substitute the parameter matrices A, B, C, E and D in formula (1) into formula (3), and solve all parameter matrices F1, F2, Q and G by MATLAB calculation.

[0132] According to the ETSTM, when k ∈ S s1 and k ∈ S s2 , Y s1 (k) and Y s2 (k) are available, and the control signal used by the system at each time can also be determined by the ACK signal. When the eigenvalues of F satisfy formula (6), M exists. Since when When the system is observable, the eigenvalues of F can be chosen arbitrarily, so we can design F1 and F2 to satisfy (6) to ensure the existence of M. At the same time, when formula (2) is satisfied, Q and G also exist.

[0133] According to the structure of the switching observer and the above proof process, when the given conditions are satisfied, it can be known that the designed switching observer exists.

[0134] S302, the switching observer updates the state estimation.

[0135] The observer updates the state estimation by formula (5). According to the time set of successful communication between the sensor and the observer, we divide the switching observer into three observation states, namely: temporary observer state, FT (finite time) observer state, and RT (Real Time, RT) observer.

[0136] The following process is a specific analysis process of state estimation for CPS safety at different time sets.

[0137] First, it re-expresses the state of the system by introducing the matrix and processing the disturbance matrix T = (I-GQC), The introduction of these matrices is to convert the system model into a form that is easier to analyze, and the formula is:

[0138]

[0139] From formula (2) and the known Q, G, we get the following:

[0140]

[0141] Then the state x(k) can be expressed as formula:

[0142]

[0143] According to the switching observer and formula (10), the state estimation error is obtained, which is divided into several stages according to the communication time set, and the state estimation error of each stage will tend to be stable, so the state estimation update is effective.

[0144] When k < k s1,1 , that is, when the time set is in other time, the observer is in the RT observer state, and the time set between the sensor and the observer will not be successfully communicated. At this time, according to the switching observer formula (5), the observer expression is: Then the state estimation error The state estimation error of the time period selected by the switching observer to satisfy the state estimation update is as follows:

[0145]

[0146] E e1 = [E AE…A k-1 E] and w e1 (k) = [w T (k-1) w T (k-2)…w T (0)] T , which

[0147] is the initial state estimation error.

[0148] When k < k s2,1 and k ∈ S s1 , the observer is in the temporary observer state, at which time the set of time instants at which the sensor and the observer can successfully communicate.

[0149] The temporary observer expression is given by the observer formula (5) as follows:

[0150] The state estimation error is updated by the switching observer as follows:

[0151]

[0152] When k < k s2,1 and , the observer is in the RT observer state, at which time the set of time instants at which the sensor and the observer cannot successfully communicate. At this time, the observer expression is given by the switching observer (5) as follows: The state estimation error is updated by the switching observer as follows:

[0153]

[0154] where

[0155]

[0156] When k ∈ S s2 , define z(k) ∈ R 2n×1 , the observer is in the FT observer state, at which time the set of time instants at which the sensor and the observer can successfully communicate. At this time, the observer expression is given by the switching observer (5) as follows: The state estimation error is updated by the switching observer as follows: z(k) = Fz(k-1) + B s ​u(k - 1) + NGQy(k) + L s Qy(k - 1), where z(k) is the state estimation at this time. z(k) combined with (10) will derive this expression as follows:

[0157]

[0158] The process of iterating τ times is derived as follows:

[0159]

[0160] The derivation of formulas (14) and (15) is to ensure that when the network physical system is subjected to DoS attacks, the proposed switching observer can accurately estimate the system state, thereby providing support for the stable control and safe operation of the system.

[0161] By designing The state estimation update result at this time can be obtained, and the formula is:

[0162]

[0163] When k > k s2,1 and , the observer is in the RT observer state, and at this time the set of time points at which the sensor cannot successfully communicate with the observer, based on the state estimation update (16), e(k) satisfies

[0164]

[0165] where

[0166]

[0167] and

[0168] According to the analysis of the performance of the ETSTM, it can be known that k - k s,i ≤ h1-1, k s1,1 ≤ b1 and k s2,1 ≤ h3, where h3 = τ + b1 + h-1. At the same time, according to formula (11), when k < k s1,1 , where and e(k) satisfies the following formula:

[0169]

[0170] When k < k s2,1 , e(k) satisfies

[0171]

[0172] Among them

[0173] According to formula (18), when k ∈ S s2

[0174] e(k) = 0 (20)

[0175] According to formula (19), when k > k s2 , when

[0176]

[0177] In the worst case, when k < h3

[0178]

[0179] and when k ≥ h3

[0180]

[0181] In summary, the SSE method developed based on the designed ETSCM exists and can achieve the SSE of CPS within a pre-determined finite time. In addition, when w(k) = 0, it can be achieved when k ≥ h3

[0182] After the above steps, the switching observer designed based on ETSTM can achieve the security state estimation of the cyber-physical system within a pre-determined finite time. After receiving the data, the switching observer updates the state estimation by combining the new measurement data according to the system model and the previous estimated state, that is, the iterative process according to the formula. When suffering from a denial-of-service attack, the switching observer can ensure the completion of state estimation within a pre-determined finite time according to the event-triggered mechanism, ensuring that the system state can be accurately estimated even when the communication is interfered. In addition, the switching observer uses the transmitted acknowledgment (ACK) signal to ensure the consistency of the control signal, thereby ensuring that the actuator and the observer use the same control input; finally, based on the latest state estimation and the designed control gain matrix, the control signal is calculated and sent to the actuator to achieve the robust control of the cyber-physical system.

[0183] As Figure 1 , Figure 2 shown, in this embodiment, in step S4, the controller calculates the control signal according to the latest state estimation and sends the calculated control signal to the actuator. The actuator feeds back the ACK signal for acknowledging the receipt of the control signal and executes the calculated control signal to adjust the state of the cyber-physical system.

[0184] S401, the controller receives the data packet, and calculates the control signal in the data packet according to the state estimation value of the switching observer in the data packet.

[0185] The controller sends an acknowledgement signal to the switching observer after the data is successfully received, confirming that the data packet has successfully arrived at the destination.

[0186] S4011, according to the received state estimation value, calculate the control signal.

[0187] Then, the controller receives the state estimation value from the switching observer According to the state estimation value Calculate the control signal at the current and future time, the formula is:

[0188]

[0189] Where K is obtained by design based on formula (25), the formula is as follows:

[0190]

[0191] Where A represents the same dimension parameter matrix of the original state matrix, B represents the same dimension parameter matrix of the control signal, is the estimated state at time k, is the estimated state at the last time, u(k-1) is the control signal at the last time, u(k) is the control signal calculated at time k, K is the control gain matrix, the first formula is the state prediction; the second formula is the control rate.

[0192] Based on ETSTM, when k∈(k d,i ,k d,i+1 ), the system will be controlled by the calculated control signal in the data packet.

[0193] After the above steps, the mathematical relationship between the state update and the control signal of the network physical system (CPS) can be established, formula (25) is a basic component in the design of the control system, which can combine the current state estimation and the control input of the system to realize closed-loop control. The first formula is the state prediction, which is used to predict the state estimation at the next time step; the second formula is the control rate, which provides the basis for designing the control strategy, so that the control gain matrix K can be selected according to the required system performance.

[0194] S4012, according to the control signal obtained after calculation, set the H ∞ performance index of the control system as γ and the stability of the closed-loop system to meet the conditions.

[0195] According to the designed controller, the control rate formula in formula (25) is substituted into formula (1), and the closed-loop system formula is obtained as:

[0196]

[0197] Wherein, A, B, E, C, D are known system matrices with corresponding dimensions; A, C represent the same dimension parameter matrix of the original state matrix, B represents the same dimension parameter matrix of the control signal, k is the control gain matrix, D and E represent the corresponding dimension parameter matrix of the process disturbance and output disturbance respectively; x(k) represents the state of the original system, y(k) represents the measurement data of the system; w(k) represents the process disturbance of the system; v(k) represents the input disturbance of the system; is the estimated state at time k, x(k+1) is the updated state of the system at the next time. u(k) is designed based on .

[0198] According to The system formula (26) is written as:

[0199]

[0200] Wherein, e(k) is the state estimation error, is the state estimation based on the observer; A s =A+BK, A s is the system matrix, which represents the state transition of the system without external input and attack; A is the original system matrix, B is the input matrix, K is the control gain matrix, D and E represent the corresponding dimension parameter matrix of the process disturbance and output disturbance respectively; x(k) represents the state of the original system at time k, y(k) represents the measurement data of the system.

[0201] In formula (27), when the following conditions are met, the controller can control the H ∞ performance index of the closed-loop system is γ and the stability of the closed-loop system.

[0202] (1) When w(k) = 0, the closed-loop system (27) is asymptotically stable;

[0203] (2) Under zero initial condition, for any initial state x(0), the system state x(k) satisfies and the prescribed γ>0 can obtain Wherein, ||x(k)|| is the Euclidean norm of x(k), is the maximum norm of the process noise, γ is the H ∞ performance index. represents the total sum of the system state norm from time k = 0 to infinity, which can be regarded as the cumulative energy of the system state; is the performance index γ and the upper bound of the process noise the infinite sum of the product of the.

[0204] The following analysis process is given when there is interference and denial of service attack, closed-loop system H ∞ The necessary condition for performance index γ stable, that is, the linear matrix inequality is established.

[0205] For CPS with process disturbance, output disturbance and double-channel independent denial of service attack, if for given γ1>0, there exists α3>0, matrix P1>0, Φ>0, X, such that the following linear matrix inequality (LMI) is established:

[0206] The designed elastic control method can ensure the H -1 performance index γ stable of the closed-loop system (27) by designing K=XP1 ∞ The control gain matrix K is obtained by solving the linear matrix inequality (LMI) of formula (28) and (29), and finding the matrix P1, Φ and X that satisfy the inequality.

[0207] Based on the basic state space model of the system and the control strategy, by introducing state estimation and control gain matrix, it is solved by LMI matrix (28) K value, that is, K=XP1 -1 .

[0208] S402, send the calculated control signal to the actuator, and the actuator feedback ACK signal to confirm the reception of the control signal, and execute the calculated control signal to adjust the network physical system state.

[0209] The data containing the calculated control signal is packaged into b2+1 data packets, and these data packets are sent to the actuator according to ETSTM.

[0210] When the actuator receives the calculated control signal, it feedbacks ACK signal to confirm the reception of the data, adjusts the network physical state according to the calculated control signal, and controls the performance index and system stability of the system through the control gain matrix K according to step S401.

[0211] As shown in Figure 1 , Figure 2 In this embodiment, step S5 checks the stability of the network physical system performance index, and the loop monitoring and loop execution are performed until the network physical system is stable.

[0212] The following formula constitutes a theoretical framework for analyzing and proving the stability and H ∞Performance. By solving these inequalities, a control strategy that satisfies the performance requirement can be derived to ensure the robustness and stability of the system under various attacks and uncertainties.

[0213] First, the Lyapunov function is introduced as

[0214] V(k) = x T (k)P2x(k) (30)

[0215] where V(k) denotes the Lyapunov function, P2 is a positive definite matrix, x(k) is the state matrix of the original system, and x T (k) is the transpose matrix of the original system state.

[0216] First, according to the Schur complement lemma, it is ensured that the closed-loop system is stable in the H ∞ norm sense, and LMI (28) is equivalent to the formula:

[0217]

[0218] where A s1 = AP1+B s1 , B s1 = BX.A s1 denotes the state transition matrix of the closed-loop system, B s1 is the control signal matrix, A is the state transition matrix of the original system, B is the input matrix of the original system, and X is a design parameter matrix used to calculate the control gain K. A s1 is the system matrix, is the transpose of the system matrix; is the transpose of the control signal matrix, E T is the transpose matrix of the disturbance matrix; P1 is a positive definite matrix, is the inverse matrix of the positive definite matrix, used for Lyapunov stability analysis; Φ2 is a positive definite matrix, used to represent the weight of system performance; γ1I q denotes the performance limit of the system when subjected to disturbance, and γ1I q is a preset performance index used to ensure the stability and performance of the closed-loop system when subjected to bounded disturbance.

[0219] Multiplying the left and right sides of inequality (31) by matrices respectively, the following inequality can be obtained:

[0220]

[0221] where A d = A+B d and B d = BXP1 -1 , Φ2 = P1-1 ΦP1 -1 Let P2 = P1 -1 , according to K = XP1 -1 , inequality (32) is equivalent to the formula:

[0222]

[0223] According to the closed-loop system formula (27), we can get:

[0224]

[0225]

[0226] Based on (33) and (34), we can get:

[0227] ΔV(k) + x T (k) Φ2x(k) - γ1e T (k) Φ2e(k) - γ1w T (k) w(k) < 0 (35)

[0228] Under the initial condition of zero, we can get:

[0229]

[0230] where,

[0231] Φ3 = diag(Φ2, I q ),

[0232] w s (k) = [e T (k) w T (k)] T ,

[0233] λ min (Φ2) = min{λ(Φ2)}, u(k) = 0;

[0234] When k < k s1 , u(k) = 0 is equivalent to Since the system is controlled by the control signal designed based on , when k ∈ [k d,i , k d,i+1 ] and k d,i+1 - k d,i ≤ h2 + 1, then where Therefore,

[0235] Therefore, the designed resilient control method can guarantee H ∞ the stability of performance index γ.

[0236] After the above steps, the stability and H ∞ performance of the networked physical system under DoS attack and disturbance are analyzed and proved.

[0237] In this embodiment, the maximum duration step of the double-channel denial-of-service attack that the method can tolerate is related to the estimation effect of the capacity of the data packet and the performance of the CPS is related to the event-triggered interval and the maximum duration step of each attack. This is because when there is no measurement signal transmission, the disturbance can reduce the estimation and control performance. The designed method can guarantee accurate state estimation of the CPS within a given finite time, and the closed-loop system is stable when w(k) = 0.

[0238] In this embodiment, the problem is solved by MATLAB, and the main parameters and matrices related to system stability and control performance are solved. The control gain matrix K, the observer gain matrix L1 and L2, the observer parameters τ, F1 and F2, and the event-triggered parameters α1, α2, h are solved by LMI. These solved elements are crucial for designing event-triggered remote secure state estimation (SSE) and resilient control strategy.

[0239] In the embodiment, the design of the control gain matrix K, the observer gain matrix L1 and L2, the observer parameters and the event-triggered parameters plays a crucial role in updating the state estimation and implementing resilient control.

[0240] Currently, there is no similar scheme for the security control system of linear discrete systems based on considering the total duration and frequency-limited aperiodic DoS attack, while the present invention discusses the design strategy of remote secure state estimation (SSE) and resilient control system for networked physical systems (CPSs) with process disturbance, output disturbance and denial-of-service (DoS) attack. The considered DoS attack occurs independently and aperiodically in the sensor-to-observer (S-O) and controller-to-actuator (C-A) channels. In order to achieve successful transmission of signals and save communication resources, an event-triggered secure transmission mechanism (ETSTM) system is designed, and the transmission strategy, state estimation and control method that can resist aperiodic independent DoS attack are developed in this study, and the attack strength that the method can tolerate is explained.

[0241] Embodiment two

[0242] The embodiment provides a resilience control system for denial of service attack of a networked physical system, comprising:

[0243] An attack detection and event generation module is configured to detect a networked physical system state, and determine whether a DoS attack occurs based on the detected networked physical system state, and if the DoS attack occurs, generate an event when a trigger condition is met, and trigger sending of networked physical system measurement data based on the event;

[0244] The DoS attack is an independent and irregular DoS attack in a sensor-to-observer and controller-to-actuator channel.

[0245] A transmission mechanism module is configured to send the measurement data of the networked physical system to the switching observer based on a transmission rule.

[0246] A switching observer module is configured to switch an observer to feed back an ACK signal of data reception, and then the switching observer updates state estimation and sends to a controller.

[0247] A control adjustment module is configured to control a controller to perform control signal calculation based on the latest state estimation and send the calculated control signal to an actuator, the actuator feeds back an ACK signal of control signal reception, and executes the calculated control signal to adjust the networked physical system state.

[0248] A system detection module is configured to check the stability of a networked physical system performance index, and perform cyclic monitoring and cyclic execution until the networked physical system is stable.

[0249] Embodiment three

[0250] The embodiment aims to provide a computer readable storage medium, which stores a program, and the program is executed by a processor to implement the method steps of the embodiment one.

[0251] Embodiment four

[0252] The embodiment aims to provide an electronic device, which comprises a memory, a processor, and a program stored in the memory and executable on the processor, and the processor implements the method steps of the embodiment one when executing the program.

[0253] The steps involved in the device of the above embodiment correspond to the method embodiment one, and the specific embodiments can be referred to the related description part of the embodiment one. The term "computer readable storage medium" should be understood as including a single medium or multiple media of one or more instruction sets; and should also be understood as including any medium capable of storing, encoding or carrying instruction sets for execution by a processor and causing the processor to perform any method in the present application.

[0254] Those skilled in the art should understand that the modules or steps of the present application described above can be realized by general computer devices, or alternatively, they can be realized by program codes executable by the computer devices, so that they can be stored in the storage devices and executed by the computer devices, or they can be respectively manufactured into individual integrated circuit modules, or a plurality of modules or steps among them can be manufactured into a single integrated circuit module. The present application is not limited to any specific combination of hardware and software.

[0255] The specific embodiments of the present application described above in conjunction with the accompanying drawings are not intended to limit the protection scope of the present application. Those skilled in the art should understand that various modifications or changes made on the basis of the technical solutions of the present application without creative labor are still within the protection scope of the present application.

Claims

1. A resilient control method against denial-of-service attacks for cyber-physical systems, characterized in that, The method comprises the following steps: detecting the state of the networked physical system, and determining whether a DoS attack occurs based on the detected state of the networked physical system, and if a DoS attack occurs, generating an event when a triggering condition is met, and triggering the sending of measurement data of the networked physical system based on the event; the DoS attack is an independent and irregular DoS attack in the sensor-to-switching observer channel and the controller-to-actuator channel; sending the measurement data of the networked physical system to the switching observer based on a transmission rule; when the measurement data meets the triggering condition during transmission based on the transmission rule, the measurement data is packaged and sent to the switching observer until an acknowledgement signal of the switching observer is received; when the switching observer receives the packaged measurement data, the switching observer sends a state estimation value and a packaged control signal to the controller; when the controller receives the state estimation value, the controller calculates a control signal, and the calculated control signal is packaged and sent to the actuator; when the actuator receives the calculated control signal package, the actuator sends an acknowledgement signal to the controller, and clears the previous control signal, and re-sends the control signal in the new data package to the actuator in sequence; the switching observer feeds back an ACK signal for confirming the data reception, and then the switching observer updates a state estimation and sends it to the controller; the switching observer updates the state estimation, specifically: constructing a switching observer according to a transmission rule, and obtaining a time set of successful transmission; according to the time set, the switching observer is switched to different switching observer states; the switching observer comprises a temporary observer, a finite-time observer and a real-time observer, and the state estimation is updated according to the switching observer state; the controller calculates a control signal according to the latest state estimation and sends the calculated control signal to the actuator, and the actuator feeds back an ACK signal for confirming the control signal reception and executes the calculated control signal to adjust the state of the networked physical system; checking the stability of the performance index of the networked physical system, and performing the monitoring and execution cyclically until the networked physical system is stable.

2. The resilience control method against denial-of-service attacks for networked physical systems of claim 1, wherein, The networked physical system under the interference and denial of service attack is formulaed as: ; wherein represents a state of the system, represents a control signal of the system, represents a measurement data of the system; and represents a process disturbance; represents an input disturbance; is a known system matrix of corresponding dimension.

3. The method of claim 1, wherein, generating an event when a triggering condition is met, specifically: calculating a measurement error according to the measurement data; obtaining an event triggering condition according to the measurement error; determining whether the event triggering condition is met, and if yes, generating an event.

4. The method of claim 1, wherein, The formula for calculating the control signal is: ; wherein is a control gain matrix, denotes a state estimate, represents a parameter matrix of the same dimension as the original state matrix, represents a parameter matrix of the same dimension as the control signal.

5. The method of claim 1, wherein, under the transmission rule, the measurement data and the control signal are packaged into a data package form for transmission.

6. A resilient control system against denial-of-service attacks for cyber-physical systems for implementing a resilient control method against denial-of-service attacks for cyber-physical systems according to any one of claims 1 to 5, characterized in that, The method comprises the following steps: an attack detection and event generation module configured to detect the state of the networked physical system, and determine whether a DoS attack occurs based on the detected state of the networked physical system, and if a DoS attack occurs, generate an event when a triggering condition is met, and trigger the sending of measurement data of the networked physical system based on the event; the DoS attack is an independent and irregular DoS attack in the sensor-to-switching observer channel and the controller-to-actuator channel; a transmission mechanism module configured to send the measurement data of the networked physical system to the switching observer based on a transmission rule; The switching observer module is configured to switch the ACK signal of the observer feedback confirmation data reception, and then the switching observer updates the state estimation and sends it to the controller; The control adjustment module is configured to control the controller to calculate the control signal according to the latest state estimation and send the calculated control signal to the actuator, the actuator feeds back the ACK signal of the control signal reception, and executes the calculated control signal to adjust the state of the network physical system; The system detection module is configured to check the stability of the performance index of the network physical system, and circulates monitoring and executing until the network physical system is stable.

7. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to realize the steps of the method of any one of claims 1-5.

8. A computer-readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to perform the steps of the method of any one of claims 1-5.