USV Security State Estimation Method Based on Privacy Protection under Composite Attack Constraints

By adopting anonymous dynamic identity encryption algorithm and detection and authentication mechanism in unmanned surface boats (USV) systems, the problems of USV system state estimation accuracy and data privacy security under compound attacks are solved, and higher system performance and security are achieved.

CN119652638BActive Publication Date: 2025-06-13YANTAI PILOT ELECTRONIC TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411887033.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-20
Publication Date
2025-06-13
Estimated Expiration
2044-12-20

AI Technical Summary

Technical Problem

In the context of compound attacks (such as spoofing attacks and replay attacks), it is difficult for the existing technology to effectively identify and prevent, resulting in a decrease in the accuracy of the status estimation results of unmanned surface boats (USVs) systems and the inability to guarantee data privacy.

Method used

A USV security state estimation method based on privacy protection under the constraints of composite attacks was designed, and anonymous dynamic identity encryption algorithm and detection and authentication mechanism were used to ensure data privacy and security. By correcting the information physics system model and designing an estimator under composite attacks, a state estimation error system was established to improve estimation accuracy.

Benefits of technology

Effectively identify and prevent spoofing and replay attacks, ensure the accuracy of the status estimation results of the USV system and data privacy security, improving the performance and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652638B_ABST
    Figure CN119652638B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of cyber-physical system control and network security, and specifically relates to a method for secure state estimation of USV based on privacy protection under composite attack constraints. First, a dynamic identity encryption algorithm is proposed. By transmitting anonymous identity information and revocable keys, the leakage of real identities is avoided. Then, in order to more effectively resist spoofing attacks and replay attacks, an authentication and detection mechanism is constructed based on the encryption algorithm, which can effectively identify these two types of attacks, and at the same time locate the attacked sensors to achieve comprehensive detection. Secondly, the designed distributed state estimation system is combined with the encryption algorithm and the detection mechanism, only receiving secure measurement values, eliminating potential adverse effects, and ensuring privacy security and the stability of the state estimation system. At the same time, performance indicators are given to ensure sufficient conditions for the stability of the estimation error system to guarantee the security performance of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of cyber-physical system control and network security, and particularly relates to a method for estimating the safety state of an USV (Unmanned Surface Vessel) based on privacy protection under the restriction of composite attacks. Background Art

[0002] With the rapid development of the Internet of Things, automation, and intelligent systems, the applications of cyber-physical systems (CPS) and wireless sensor networks (WSNs) in multiple fields such as transportation, energy, and healthcare have received extensive attention. As an important application of CPS, an unmanned surface vessel (USV) realizes real-time perception of the environment and intelligent decision-making by closely integrating the physical system with the information system, thereby improving the operation efficiency. WSNs provide efficient means for data acquisition and transmission, enabling the USV to quickly obtain environmental information and respond in a timely manner, so as to adapt to the dynamically changing surrounding environment. Therefore, the USV has broad application prospects in the fields of marine environmental monitoring, maritime rescue, etc., and its role in these fields is becoming increasingly important.

[0003] However, due to the wireless characteristics of wireless sensor networks and the openness of cyber-physical systems, the unmanned surface vessel faces significant security threats during sea voyages. Malicious network attacks may lead to data leakage or system misoperation, thus affecting the execution efficiency of tasks and the normal operation of the system. At the same time, the USV must ensure the stability and reliability of the system in complex and harsh environments, which requires accurate state estimation in the system. As a core component of CPS, malicious network attacks may damage the authenticity of sensor data, which has a direct impact on the performance of the state estimation system, resulting in a decrease in the accuracy of state estimation results. Therefore, studying the problem of secure state estimation of CPS under the background of network attacks has important theoretical and practical significance.

[0004] Currently, the security issues in CPS mainly focus on types such as Denial of Service (DoS) attacks, spoofing attacks, and replay attacks. A DoS attack exhausts system resources through a large number of invalid requests, causing the system, service, or network to malfunction. A spoofing attack, by forging identities or data, may lead to data leakage, identity theft, or system control; while a replay attack captures and resends valid data packets, resulting in abuse of permissions or information tampering. In contrast, if the CPS system does not adopt effective security protection measures, such as information encryption or privacy protection means, spoofing attacks and replay attacks may carefully tamper with or replay the transmission of sensor data, leading to more serious security problems. In an open data environment, spoofing attacks and replay attacks can be carried out jointly. Ordinary detectors not only have difficulty effectively identifying the existence of attacks but may also cause significant deviations in the state of the USV system. Therefore, in this context, it is particularly important to study how to ensure the security of data transmission, especially in the case of spoofing attacks and replay attacks, to ensure the accuracy of the system's real data and state estimation results.

[0005] Currently, the research on distributed state estimation and detection problems in the context of replay attacks and spoofing attacks in CPS is still in its infancy. Current methods mostly focus on a single type of attack and do not fully consider data privacy issues. The present invention aims to propose a new security state estimation method that can detect and prevent spoofing attacks and replay attacks in real time, obtain the true values of the system through the security state estimation method, thereby ensuring the privacy security and state estimation accuracy of the system and improving the system performance and security of unmanned surface vessels. Summary of the Invention

[0006] To overcome the problems in the prior art, the present invention proposes a privacy - protected USV security state estimation method under the constraint of composite attacks.

[0007] The technical solution of the present invention to solve the above - mentioned technical problems is as follows:

[0008] The present invention provides a privacy - protected USV security state estimation method under the constraint of composite attacks, including the following steps:

[0009] Step 100: Establish a cyber - physical system model with privacy protection and a state estimation system model according to the navigation attitude of the unmanned surface vessel; and considering the ways in which an attacker obtains the information of the cyber - physical system with privacy protection through spoofing and replay attacks, as well as its impact on the performance of the estimation system, establish a composite attack model; correct the cyber - physical system model with privacy protection under the influence of the composite attack, correct the estimator under the composite attack, and establish a state estimation error system;

[0010] Step 200: Design an anonymous dynamic identity encryption algorithm and a detection and authentication mechanism; wherein, the anonymous dynamic identity encryption algorithm is used for privacy protection of the unmanned surface vehicle identity information; the detection and authentication mechanism is used to identify and prevent sensors suffering from replay attacks and spoofing attacks from sending measurement data;

[0011] Step 300: Based on the detection and authentication mechanism, rewrite the state estimation error system, construct an augmented estimation error system, analyze the stability of the state estimation error system, and solve the gain matrix.

[0012] Furthermore, in the step 100, the physical system model with privacy protection information is represented by the following state space equation:

[0013]

[0014] Wherein, represents the system state, represents x k in the n x -dimensional real number space; x k+1 represents the system state at the next moment k + 1; i represents the sensor, k represents the moment, and N represents the natural number; represents the measurement value obtained by the i-th sensor, represents y i,k in the n y -dimensional real number space; represents the disturbance suffered by the system, represents ω k in the ω-dimensional real number space; ν i,k represents the disturbance suffered by the i-th sensor; it is assumed that ω k , ν i,k ∈ l 2 [0, ∞), A k , B k , H i,k and D i,k are real-valued time-varying matrices known to the system.

[0015] Furthermore, in the step 100, in the state estimation system model, the estimator uses the following form of state estimation equation:

[0016]

[0017] Wherein, L i,k and K i,k are the parameters of the estimator to be designed; represents the estimated value of the system state x k ; represents the system state x kThe estimated value at the (k + 1)-th moment represents the state estimated value of the neighbor estimator.

[0018] Furthermore, in step 100, under the influence of the composite attack, the actual measurement output affected by the composite attack in the physical system model with privacy protection information is corrected :

[0019]

[0020] Among them, the replay attack strategy represents the previously obtained measurement values for replay; the spoofing attack model s i,k ∈l 2 [0, ∞), where l 2 represents the norm; represents the replay attack, and the random variable μ i,k obeys a white sequence with a Bernoulli distribution.

[0021] Furthermore, the estimator under the composite attack is:

[0022]

[0023] Furthermore, in step 100, a state estimation error system is established, including:

[0024] Let represent the estimation error, and the estimation error system:

[0025]

[0026] In the formula, P i,k represents the designed gain matrix; represents the system state during the period of T 2 -T 1 obtained by replay; represents the measurement noise suffered during the period of T 2 -T 1 obtained by replay; e j,k represents the neighbor estimation error, j represents the neighbor sensor; P i,k represents the designed gain matrix.

[0027] Furthermore, in step 200, the anonymous dynamic identity encryption algorithm uses the transmission method of anonymous identity information and revocable keys to protect the privacy of the unmanned surface vehicle identity information, including:

[0028] Before performing the task, each unmanned surface vehicle submits its unique identifier to the key generation center to obtain an anonymous identity within the validity period;

[0029] After the key generation center verifies the unique identifier of each unmanned surface vessel, it generates a unique public-private key pair for the unmanned surface vessel;

[0030] If the expiration time of the anonymous identity has passed or a key leakage is detected, the key generation center immediately revokes its old key and anonymous identity, records the anonymous identity of the revoked unmanned surface vessel and the revocation time; meanwhile, the key generation center sends a new key and anonymous identity to the unmanned surface vessel.

[0031] Further, in the step 200, the detection and authentication mechanism is used to identify and prevent sensors suffering from replay attacks and spoofing attacks from sending measurement data, including:

[0032] The measured value of each sensor is marked as n i , and the received data of each estimator is marked as m i , during the sending and receiving process of the data packet, monitor the sending and receiving status of the detection data packet, and determine whether there is a replay attack by comparing whether the received data packet has been received before;

[0033] If m i >n i , the received data packet has been received before, a replay attack has occurred, and an alarm is initiated at this time; otherwise, there is no replay attack, and the validity of the verification information is verified; if the verification fails, it indicates that false data has been injected into the transmitted data, and an alarm is initiated; if the verification is successful, secure transmission is performed.

[0034] Further, in the step 300, the state estimation error system is rewritten as:

[0035]

[0036] Wherein, U i represents the set of secure neighbors of node i;

[0037] It is set that The following augmented estimation error system is established:

[0038]

[0039] Wherein,

[0040] In the above formula, represents the augmented estimation error vector at time k; represents the augmented estimation error vector at the next time k + 1; θ i,k represents the interference signal vector; E i,k , F i,k and G i,kThe system matrices representing each part respectively.

[0041] Furthermore, in the said step 300, the gain matrix:

[0042]

[0043] In the above formula, Γ i,k and X i,k represent the matrices that make the LMI hold.

[0044] Compared with the prior art, the present invention has the following technical effects:

[0045] The present invention designs a Dynamic Identity Encryption (DIE) algorithm, effectively realizing the privacy protection of USV data information, and significantly enhancing the privacy and security of USV data transmission. Compared with the existing encryption algorithms, the present invention adopts the transmission method of anonymous identity information and revocable keys, avoiding the exposure of real identities, and allowing the keys and anonymous identities to be changed at any time, thus solving the problem of data leakage.

[0046] In addition, an Authentication and Verification Mechanism (AVM) is proposed, which can efficiently identify spoofing attacks and replay attacks, ensuring data privacy security and the stability of the state estimation system. Compared with the existing attack detection methods, the detection algorithm of the present invention realizes the comprehensive detection of two common attack types without affecting the system performance, significantly enhancing the response ability of USV and the estimation system when facing security threats.

[0047] Finally, combined with the detection and authentication mechanism, an estimator under compound attacks is designed to ensure that USV uses an encryption algorithm to protect information privacy when transmitting data, and at the same time, eliminate the influence of spoofing attacks and replay attacks on the system through the detection and authentication mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0049] Figure 1 is a flowchart of a security state estimation method for a cyber-physical system with privacy protection under compound attack constraints;

[0050] Figure 2 It is the construction flow chart of the system model and the composite attack model;

[0051] Figure 3 It is the design flow chart of the anonymous dynamic identity encryption algorithm and the detection and authentication mechanism;

[0052] Figure 4 It is the flow chart for estimating the system stability analysis;

[0053] Figure 5 It is the flow chart for designing the system gain matrix estimation;

[0054] Figure 6 It is the structure diagram of the cyber-physical system under composite attacks. Specific implementation manners

[0055] In order to further elaborate on the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following, in combination with the accompanying drawings and preferred embodiments, details the specific implementation manners, structures, features and their effects of the technical solutions proposed according to the present invention. The specific features, structures or characteristics in one or more embodiments can be combined in any suitable form. Unless otherwise defined, all technical and scientific terms used in the present invention have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs.

[0056] The purpose of the present invention is to solve the problem of secure state estimation of an unmanned surface vehicle (USV) with privacy protection under spoofing attacks and replay attacks. The present invention adopts a dynamic identity encryption (DIE) algorithm to ensure data security. First, the key generation center (KGC) uses forged identity information and revocable keys to resist attacks and ensure the authenticity of USV information transmission. Then, at the authentication and detection center, replay attacks and spoofing attacks are identified through a detection algorithm. Finally, a distributed state estimation system combined with the detection and authentication mechanism is designed to ensure that the estimation system only receives secure measurement data, thereby guaranteeing the reliability and stability of the estimation system and accurately estimating the true state of the USV.

[0057] To achieve the above object, the present invention adopts the following technical solutions:

[0058] Referring to Figure 1 , the present invention relates to a method for secure state estimation of a USV based on privacy protection under composite attack constraints, including the following steps:

[0059] Step 100: Establish a cyber-physical system model with privacy protection and a state estimation system model based on the navigation attitude of the unmanned surface vehicle; and consider the ways in which an attacker obtains the information of the cyber-physical system with privacy protection through spoofing and replay attacks, as well as its impact on the performance of the estimation system, to establish a composite attack model; correct the cyber-physical system model with privacy protection under the influence of the composite attack, design an estimator under the composite attack, and establish a state estimation error system.

[0060] Step 200: Design an anonymous dynamic identity encryption algorithm and a detection and authentication mechanism; wherein, the anonymous dynamic identity encryption algorithm is used for privacy protection of the identity information of the unmanned surface vehicle; the detection and authentication mechanism is used to identify and block sensors suffering from replay attacks and spoofing attacks from sending measurement data.

[0061] Step 300: Based on the detection and authentication mechanism, rewrite the state estimation error system, construct an augmented estimation error system, analyze the stability of the state estimation error system, and solve the gain matrix.

[0062] The following is a detailed expansion of each of the above steps:

[0063] Step 100: Establish a cyber-physical system model with privacy protection and a state estimation system model based on the navigation attitude of the unmanned surface vehicle; and consider the ways in which an attacker obtains the information of the cyber-physical system with privacy protection through spoofing and replay attacks, as well as its impact on the performance of the estimation system, to establish a composite attack model; correct the cyber-physical system model with privacy protection under the influence of the composite attack, design an estimator under the composite attack, and establish a state estimation error system.

[0064] As an example, referring to Figure 2 , this step may include the following steps:

[0065] Step 110: Construct a cyber-physical system model with privacy protection and a state estimation system model.

[0066] According to the navigation attitude of the unmanned surface vehicle USV, construct a cyber-physical system model with privacy protection, and design a state estimation system model.

[0067] The cyber-physical system model with privacy protection can be expressed as the following state space equation:

[0068]

[0069] wherein, represents the system state, represents x k in the n x dimensional real space; x k+1Denote the system state at the next moment \(k + 1\); \(i\) represents the sensor, \(k\) represents the moment, and \(N\) represents the natural number; Denote the measurement value obtained by the \(i\)-th sensor, Denote \(y\) i,k Belonging to the \(n\) y -dimensional real number space; Denote the interference received by the system, Denote \(\omega\) k Belonging to the \(\omega\)-dimensional real number space; \(\nu\) i,k Denote the interference received by the \(i\)-th sensor; Assume \(\omega\) k , \(\nu\) i,k \(\in l\) 2 [0, \(\infty\)), \(A\) k , \(B\) k , \(H\) i,k And \(D\) i,k Are real-valued time-varying matrices known to the system.

[0070] In the state estimation system model, the estimator uses a state estimation equation in the following form:

[0071]

[0072] Where, \(L\) i,k And \(K\) i,k Are the parameters of the estimator to be designed; Denote the estimated value of the system state \(x\) k ; Denote the estimated value of the system state \(x\) k At the \(k + 1\) moment, Denote the estimated value of the neighbor estimator at the \(k\) moment.

[0073] Step 120: Construct a composite attack model, which includes a replay attack strategy and a spoofing attack model.

[0074] Considering the ways for the attacker to obtain system information through spoofing attacks and replay attacks, and the potential impact on the performance of the estimation system, establish a replay attack strategy And a spoofing attack model \(s\) i,k \(\in l\) 2 [0, \(\infty\)).

[0075] Replay attack strategy:

[0076] (1) The attacker records the sensor measurement values within the time interval \([T\) 1 , \(T\) 2 during the entire time \(k\), where \(T\) 2 - \(T\) 1It is the effective time for the attacker to replay the measurement value for a long time in the future.

[0077] (2) From time T 2 +1 to time k, the adversary modifies the measurement value to k ∈ [rT 2 +1, (r + 1)T 2 -T 1 +1], where r = 1, 2,... represents the number of replay attacks; denotes the replayed measurement value of the replay attack.

[0078] Spoofing attack model: Define s i,k ∈ l 2 [0, ∞) as the spoofing attack vector, where l 2 represents the norm. The attacker randomly launches a spoofing attack in the k time period and injects some spoofing attack signals into the measurement value during data transmission, thereby affecting the estimation performance of the estimation system.

[0079] Step 130: Under the influence of the composite attack, correct the sensor measurement value in the physical system model with privacy protection information.

[0080] The actual measurement output under the composite attack is given by the following formula (3):

[0081]

[0082] where represents the replay attack, and the random variable μ i,k obeys a white sequence with a Bernoulli distribution, taking values 0 or 1, and the probabilities are as follows:

[0083]

[0084] where is a known constant, and the given value represents the success rate of the attack; if then the spoofing attack can arbitrarily manipulate the system to inject false data.

[0085] Step 140: Design an estimator under the composite attack and establish a state estimation error system.

[0086] In an open network environment, the designed estimator under the composite attack can be written as:

[0087]

[0088] Let represent the estimation error, and the estimation error system is represented by Equation (6):

[0089]

[0090] In the formula, P i,k represents the designed gain matrix; represents the obtained T during replay 2 -T 1 system state during; represents the replay of T 2 -T 1 measurement noise suffered during; e j,k represents the neighbor estimation error, and j represents the neighbor sensor.

[0091] Step 200: Design an anonymous dynamic identity encryption algorithm and a detection and authentication mechanism; wherein, the anonymous dynamic identity encryption algorithm is used to protect the privacy of the unmanned surface vehicle identity information; the detection and authentication mechanism is used to identify and block sensors suffering from replay attacks and spoofing attacks from sending measurement data.

[0092] As an example, referring to Figure 3 , this step may include the following steps:

[0093] Step 210: Before executing a task, each unmanned surface vehicle submits its unique identifier to the key generation center to obtain an anonymous identity within a validity period; and in each task, each unmanned surface vehicle updates this identity and sends it to the state estimation system.

[0094] Referring to Table 1, generate an anonymous identity AID (Anonymous Identity) for each unmanned surface vehicle USV. Before executing a task, each unmanned surface vehicle USV (US j ) needs to submit its unique identifier to the Key Generation Center (KGC) to obtain the anonymous identity where T j is the valid time of the anonymous identity. Each unmanned surface vehicle USV will obtain a new anonymous identity each time it executes a task and send it to the state estimation system ES k for storage.

[0095] Table 1 Anonymous Identity Generation Algorithm

[0096]

[0097] Step 220: After verifying the unique identifier of each unmanned surface vehicle, the key generation center will generate a unique public-private key pair for it to ensure the security of communication and the privacy of data.

[0098] Referring to Table 2, interact with the key generation center through a secure channel to generate and verify the public-private key pair for the unmanned surface vehicle to ensure communication security.

[0099] The unmanned surface vehicle selects a random number as the secret value and uses this secret value to calculate the public key Send the public key and the selected false identity to the key generation center to obtain the key;

[0100] The key generation center will generate a partial private key and send it to the unmanned surface vehicle US j , where, represents the partial private key, represents the partial public key; if the unmanned surface vehicle US j receives the above partial private key message, it calculates the hash value and verifies the hash value to confirm the validity of the received information, where, H 0 represents the hash function; the validity and integrity of the partial private key are confirmed by comparing the results of the verification process. If then the verification passes, confirming that the partial private key is valid, where, k pub represents the system public key, represents the hash value;

[0101] The key generation center sends another part of the public-private key to the unmanned surface vehicle US j , where, represents the partial private key, represents the partial public key, and t is the system initialization time; if the unmanned surface vehicle US j receives the message the unmanned surface vehicle US j calculates the hash value If then the verification passes, confirming that the partial private key is valid; return and and represent the public-private key.

[0102] Table 2 Key Generation Algorithm

[0103]

[0104]

[0105] Step 230: If the expiration time of the anonymous identity has passed or a key leakage is detected, the key generation center revokes its old key and anonymous identity information. The key generation center will record the identity information and revocation time of the unmanned surface vessel whose key has been revoked. Meanwhile, the key generation center sends a new key and anonymous identity information to the unmanned surface vessel to ensure the security of its subsequent communications.

[0106] Referring to Table 3, if T j = 0 or US j the key has leaked, the key generation center KGC revokes the j key of US and records the anonymous identity information and revocation time of the revoked US j ; the key generation center KGC and the unmanned surface vessel US j interact with each other to exchange a new key through a secure channel. Among them, if the detection and authentication mechanism detects an alarm due to an FDI attack during the transmission process, it is assumed that the key has leaked.

[0107] Table 3 Key Dynamic Update Algorithm

[0108]

[0109] Step 240: Design and implement a detection and authentication mechanism that identifies and prevents sensors suffering from replay attacks and spoofing attacks from sending measurement data to the state estimation system ES k . Through this mechanism, it can be ensured that the data received by the state estimation system ES k is reliable and secure.

[0110] To prevent sensors suffering from replay attacks and spoofing attacks from sending measurement data to the state estimation system ES k , a detection and authentication mechanism is designed to identify sensors under attack. Referring to Table 4, first initialize the alarm factor η = 0, two counters n i and m i , the loop factor k, and the termination time T end and other parameters. In the loop execution stage, the measured value of each sensor is marked as n i , the received data of each estimator is marked as m i . During the sending and receiving process of data packets, monitor the sending and receiving status of the detection data packets, and determine whether there is a replay attack by comparing whether the received data packet has been received before. If m i > n i , the received data packet has been received before, and a replay attack has occurred, and an alarm is issued at this time; otherwise, there is no replay attack, and ES kVerify the validity of the information by mutual authentication of identities and judging the integrity of the message. If the session key sk is negotiated, the verification is successful; otherwise, it fails. A verification failure indicates that false data has been injected into the transmitted information, and an alarm is initiated. If the verification is successful, the information has not been attacked and can be transmitted securely. The entire algorithm aims to ensure the security and integrity of data during transmission and effectively resist composite attacks such as replay attacks and spoofing attacks.

[0111] Table 4 Detection and Authentication Mechanism Algorithm Based on Composite Attacks

[0112]

[0113]

[0114] Step 300: Based on the detection and authentication mechanism, rewrite the state estimation error system, construct an augmented estimation error system, analyze the stability of the state estimation system, and solve the gain matrix.

[0115] As an example, referring to Figure 4 - Figure 5 , this step may include the following steps:

[0116] Step 310: Construct an augmented estimation error system.

[0117] The distributed security estimation system (i.e., the state estimation system) only receives the measurement data of authenticated secure sensors. By rewriting the state estimation error system, an augmented estimation error system is constructed. Among them, the augmented estimation error system is established to ensure the stability of the distributed security estimation system and to analyze the stability and solve the estimator gain matrix.

[0118] The state estimation error system can be rewritten as:

[0119]

[0120] where U i represents the set of secure neighbors of node i.

[0121] Then, set Combining equations (1)-(7), the following augmented estimation error system is established:

[0122]

[0123] where

[0124] In the above formula, represents the augmented estimation error vector at time k; represents the augmented estimation error vector at the next time k + 1; θ i,k represents the interference signal vector; Ei,k , F i,k and G i,k respectively represent the system matrices of each part.

[0125] Step 320: Performance analysis and cost function design.

[0126] To ensure that the state estimation system meets the specified H ∞ performance, a cost function is introduced, and the cost function represents the inconsistency between adjacent estimators caused by the interference signal vector θ i,k

[0127]

[0128] In the above formula, C represents the cost function; N represents a natural number; represents the state estimation value of the neighbor estimator; e j,k represents the neighbor state estimation error; represents the neighbor augmented estimation error vector.

[0129] Step 330: Stability analysis and proof of the distributed secure estimation system (state estimation system).

[0130] Use the Lyapunov function to analyze the stability of the system under the composite attack. Theorem 1 is introduced and it is proved that when the system is not under the composite attack and θ i,k ≡ 0, the state estimation error system is stable. Through the dynamic anonymous identity encryption algorithm and the detection and authentication mechanism, the state estimation error system can still maintain θ i,k ≡ 0 under the action of the composite attack, thus ensuring the stability of the system.

[0131] Problem 1: How to design the state estimation system gain matrices P i,k and L i,k such that the state estimation error system (7) satisfies:

[0132] (1) When the system is not under the composite attack and θ i,k ≡ 0, the state estimation error system (7) is stable. Relying on the encryption algorithm and the detection and authentication mechanism, the state estimation error system can also maintain θ i,k ≡ 0 under the action of the composite attack.

[0133] (2) For a given scalar γ > 0 and Q > 0, the state estimation system meets the specified H ∞ performance:

[0134]

[0135] Where,

[0136] ​Theorem 1: For a given scalar \(0 < \sigma\) i < 1, \(0 < \lambda\) i <((1 - \sigma i ) / q i ) and the state - estimation system gain matrices \(P\) i,k and \(L\) i,k , if there exist matrices \(Q\) i > 0, \(i = 1,2,\cdots,N\) such that the inequality (11) holds, then for the estimation - error system (7), Problem 1 is effectively solved.

[0137]

[0138] where \(\Delta V\) i (k)=V i (k + 1)-\sigma i V i (k); \(\Delta V\) i (k) represents the change; \(V\) i (k + 1) represents the Lyapunov function at time \(k + 1\); \(\gamma\) represents a given constant, scalar.

[0139] Step 340: Solve the LMI conditions.

[0140] By using the Kronecker operator and the neighbor information of each observer, introduce Theorem 2, and transform the condition for Theorem 1 to hold into a solvable linear - matrix - inequality (LMI) condition, thus providing an operable mathematical basis for system design.

[0141] Theorem 2: For a given scalar \(0 < \sigma\) i < 1, \(0 < \lambda\) i <((1 - \sigma i ) / q i ), \(\gamma>0\) and the state - estimation system gain matrices \(P\) i,k and \(L\) i,k , if there exist matrices \(Q\) i > 0, \(M\) i , \(K\) i , \(R\) i , \(i = 1,2,\cdots,N\) such that the following LMI holds

[0142]

[0143] In the above formula, \(\Xi\) i,k represents the matrix that satisfies the LMI; represents the matrix related to the augmented estimation - error vector; and represent arbitrary compatible matrices; represents a \(1\times p\) i unit vector; \(I\) represents the identity matrix.

[0144] Step 350: The designed gain matrix P i,k and L i,k are coupled with any compatible matrix M i , K i , R i to introduce Theorem 3, providing a decoupling scheme for the design of the state estimation system gain matrix.

[0145] Theorem 3: For a given constant if there exist matrices Q i > 0, M i , |M i | ≠ 0, Γ i,k , X i,k such that the following LMI holds:

[0146]

[0147] where Ψ i,k represents the matrix satisfying the decoupling scheme; each part in Ψ i,k represents the relevant matrix for the augmented estimation error vector to satisfy the LMI under the decoupling scheme;

[0148] then the gain matrix of the state estimation system is obtained by Equation (14):

[0149]

[0150] In the above formula, Γ i,k and X i,k represent the matrices that make the LMI hold.

[0151] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A privacy-preserving USV security state estimation method under composite attack constraints, characterized in that: The following steps are involved: Step 100: Establish a privacy-protected cyber-physical system model and a state estimation system model according to the navigation posture of the unmanned surface vessel; and consider the way in which the attacker obtains the information of the privacy-protected cyber-physical system through deception and replay attacks, and its impact on the performance of the estimation system, and establish a composite attack model; modify the privacy-protected cyber-physical system model under the influence of the composite attack, modify the estimator under the composite attack, and establish a state estimation error system; Step 200: Design an anonymous dynamic identity encryption algorithm and a detection and authentication mechanism; wherein the anonymous dynamic identity encryption algorithm is used to protect the privacy of the identity information of the unmanned surface vessel; and the detection and authentication mechanism is used to identify and prevent sensors that are subject to replay attacks and spoofing attacks from sending measurement data; Step 300: Based on the detection and authentication mechanism, rewrite the state estimation error system, construct an augmented estimation error system, analyze the stability of the state estimation error system, and solve the gain matrix.

2. According to claim 1, a privacy-preserving USV security state estimation method under composite attack constraints is characterized in that: In step 100, the privacy-preserving cyber-physical system model is represented by the following state-space equation: in, Indicates the system status. Represents x k Where n x dimensional real number space; x k+1 represents the system state at the next time k+1; i represents the sensor, k represents the time, and N represents a natural number; represents the measurement value obtained by the i-th sensor, Represents y i,k Where n y dimensional real number space; Indicates the interference to the system. Represents ω k The ω-dimensional real number space where it is located; ν i,k represents the interference to the i-th sensor; assuming ω k ,ν i,k ∈l2[0,∞),A k ,B k ,H i,k and D i,k is a real-valued time-varying matrix known to the system.

3. According to claim 2, a USV security state estimation method based on privacy protection under composite attack constraints is characterized in that: In step 100, in the state estimation system model, the estimator uses the state estimation equation in the following form: in, L i,k and K i,k is the parameter of the estimator to be designed, i.e., the solution gain matrix; Represents the system state x k An estimated value of Represents the system state x k The k+1 moment estimated value of represents the state estimate of the neighbor estimator, indicates that j is An element of a collection.

4. According to claim 3, a privacy-preserving USV security state estimation method under composite attack constraints is characterized in that: In step 100, the actual measured output of the privacy-preserving cyber-physical system model that is subjected to the composite attack is corrected under the influence of the composite attack. Among them, the replay attack strategy Represents the previous measurement value obtained by replaying; deception attack model s i,k ∈l2[0,∞), l2 represents the norm; represents a replay attack, and the random variable μ i,k White sequence following Bernoulli distribution.

5. According to claim 4, a privacy-preserving USV security state estimation method under composite attack constraints is characterized in that: The estimator under the composite attack is:

6. The method for estimating the safety status of a USV based on privacy protection under the constraints of a composite attack according to claim 5 is characterized in that: In step 100, a state estimation error system is established, including: make Represents the estimation error, the estimation error system: In the formula, Indicates the system status during T2-T1 obtained by replay; represents the measurement noise suffered during playback T2-T1; e j,k represents the neighbor estimation error; P i,k represents the gain matrix of the design.

7. The method for estimating the safety status of a USV based on privacy protection under the constraints of a composite attack according to claim 1 is characterized in that: In step 200, the anonymous dynamic identity encryption algorithm uses anonymous identity information and revocable key transmission to protect the privacy of the unmanned surface vessel identity information, including: Before carrying out a mission, each unmanned surface vessel submits its unique identification to the key generation center to obtain an anonymous identity within a valid period; After the key generation center verifies the unique identification of each unmanned surface vessel, it generates a unique public-private key pair for the unmanned surface vessel; If the validity period of the anonymous identity expires or the key is found to be leaked, the key generation center immediately revokes its old key and anonymous identity, and records the anonymous identity and revocation time of the revoked unmanned surface vessel; at the same time, the key generation center sends a new key and anonymous identity to the unmanned surface vessel.

8. The method for estimating the safety status of a USV based on privacy protection under the constraints of a composite attack according to claim 7 is characterized in that: In step 200, the detection and authentication mechanism is used to identify and prevent sensors that are subject to replay attacks and spoofing attacks from sending measurement data, including: The measurement value of each sensor is marked as n i , the received data of each estimator is labeled m i ,During the process of sending and receiving data packets, the sending and receiving status of the data packets is monitored and detected, and whether there is a replay attack is determined by comparing whether the received data packets have been received before; If m i >n i , the received data packet has been received before, a replay attack has occurred, and an alarm is triggered; otherwise, there is no replay attack, and the validity of the information is verified; if the verification fails, it means that false data has been injected into the transmitted data, and an alarm is triggered; if the verification succeeds, secure transmission is performed.

9. The method for estimating the safety status of a USV based on privacy protection under the constraints of a composite attack according to claim 6 is characterized in that: In step 300, the state estimation error system is rewritten as: in, U i represents the safe neighbor set of node i; set up θ i,k =[ω k ,ν i,k ] T , establish the following augmented estimation error system: in, In the above formula, represents the augmented estimation error vector at time k; represents the augmented estimation error vector at the next moment k+1; θ i,k represents the interference signal vector; E i,k 、F i,k and G i,k Represent the system matrix of each part respectively.

10. The method for estimating the safety status of a USV based on privacy protection under the constraints of a composite attack according to claim 9 is characterized in that: In step 300, the gain matrix: In the above formula, Γ i,k and X i,k represents the matrix that makes LMI hold.

Citation Information

Patent Citations

  • Leader-free consistency control method for nonlinear multi-agent system based on attack compensation

    CN112558476A

  • Federal learning task trusted unloading system and method in end-edge collaborative environment

    CN115633062A