Trusted Assurance Method, System, Device and Medium for the Application of the Host Computer in the DCS Control System
The DCS control system upper computer security method verifies and monitors applications in a trusted environment, addressing security threats by allowing only trusted applications to run and detecting anomalies, enhancing system security and stability.
Patent Information
- Application Number
- CN202510228024.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-02-28
AI Technical Summary
The host computer of the DCS control system faces security threats such as malware attacks and data tampering, resulting in the risk of system crashes and data leakage.
Completeness verification is performed by combining digital signature and hash value verification, whitelist applications are established, deep neural networks are used for real-time monitoring, and abnormal behavioral alerts and response measures are taken to ensure system security.
It improves the security and stability of the DCS control system host computer, reduces the risk of system failure and data loss, reduces the work burden of system administrators, and improves management efficiency.
Smart Images

Figure CN119717749B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of industrial automation and relates to a method, system, device and medium for ensuring the trustworthiness of the host computer application in a DCS control system. Background Art
[0002] In the field of industrial automation, the distributed control system DCS (Distributed Control System) is an important device monitoring and management system. The DCS mainly consists of field controllers, communication networks, and host computers. Among them, the host computer, as the monitoring center, is responsible for monitoring the operating status of field devices and presenting these status data in a visual form to the operators.
[0003] However, in practical applications, the host computer software faces various security threats, such as malware attacks, data tampering, etc. These threats may lead to serious consequences such as system crashes and data leaks. Summary of the Invention
[0004] The present invention aims to solve the problems existing in the prior art and proposes a method, system, device and storage medium for ensuring the trustworthiness of the host computer application in a DCS control system. The method, system, device and storage medium can ensure the normal operation of software programs and guarantee the security of data.
[0005] To achieve the above objectives, the present invention discloses a method for ensuring the trustworthiness of the host computer application in a DCS control system, including:
[0006] Performing integrity verification on each application program in the host computer of the DCS control system, and taking the application programs with qualified integrity verification as whitelist applications;
[0007] Allowing the whitelist applications to run in the target environment;
[0008] Monitoring the status of the whitelist applications during the running process, and determining whether there are abnormal behaviors according to the monitored data;
[0009] When there are abnormal behaviors, an alarm is issued, and corresponding measures are taken for the abnormal behaviors.
[0010] Further, the process of performing integrity verification on each application program in the host computer of the DCS control system is as follows:
[0011] Determining the priorities of each application program in the host computer of the DCS control system;
[0012] According to the priorities of each application program, performing integrity verification on each application program by combining digital signature and hash value verification. When any application program fails the verification, an alarm signal is issued.
[0013] Further, the target environment is a trusted computing environment, which is a computer system environment with hardware, software, and data security. Among them, the computer devices in the computer system environment adopt a configuration with a security chip, and the security chip is used to protect the keys and sensitive data stored in the security chip.
[0014] Further, the measures at least include one of restricting the network access rights of abnormal applications, suspending the operation of some functions of abnormal applications, recording relevant log information of abnormal behaviors, blocking applications, deleting applications, and restarting the system.
[0015] Further, the process of determining whether there is an abnormal behavior based on the monitored data is as follows:
[0016] Input the monitored data into the trained deep neural network machine learning model to obtain the spatio-temporal feature information in the monitored data. Among them, the deep neural network machine learning model adopts an architecture that combines a convolutional neural network and a recurrent neural network;
[0017] Judge whether there is an abnormal behavior according to the spatio-temporal feature information.
[0018] The present invention discloses a trusted guarantee system for the upper computer application of a DCS control system, including:
[0019] A verification module for performing integrity verification on each application program in the upper computer of the DCS control system, and taking the application program with qualified integrity verification as a whitelist application;
[0020] An operation module for allowing the whitelist application to run in the target environment;
[0021] A monitoring module for monitoring the status of the whitelist application during the running process, and determining whether there is an abnormal behavior according to the monitored data;
[0022] An alarm module for sending an alarm when there is an abnormal behavior, and taking measures corresponding to the abnormal behavior for the abnormal behavior.
[0023] Further, the verification module includes:
[0024] A determination module for determining the priority of each application program in the upper computer of the DCS control system;
[0025] An integrity verification module for performing integrity verification on each application program by combining digital signature and hash value verification according to the priority of each application program. When any application program fails the verification, an alarm signal is sent.
[0026] Furthermore, the monitoring module includes:
[0027] An extraction module, configured to input the monitored data into a trained deep neural network machine learning model to obtain spatio-temporal feature information in the monitored data, wherein the deep neural network machine learning model adopts an architecture combining a convolutional neural network and a recurrent neural network;
[0028] A judgment module, configured to judge whether there is an abnormal behavior according to the spatio-temporal feature information.
[0029] The present invention discloses a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the DCS control system host computer application trusted guarantee method are implemented.
[0030] The present invention discloses a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the DCS control system host computer application trusted guarantee method are implemented.
[0031] The present invention has the following advantages:
[0032] In actual operation, the trusted guarantee method for the DCS control system host computer application of the present invention performs integrity verification on each application program in the DCS control system host computer, and only enables the verified application programs to run in the target environment, thereby introducing trusted computing technology to ensure that the host computer software has a high degree of security during operation, effectively resisting various security threats, and thus improving the security of the system. In addition, the present invention ensures the stability and reliability of the host computer software through integrity verification and real-time monitoring, reduces the risk of system failures and data losses, and improves the stability of the system. At the same time, through automatic monitoring and abnormal feedback, the work burden of system administrators is reduced and the management efficiency is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] The drawings, as a part of the present invention, are used to further illustrate the present invention. The schematic embodiments and descriptions in the drawings are intended to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:
[0034] Figure 1 is the flowchart of the method for Embodiment 1;
[0035] Figure 2 is the flowchart of the method for Embodiment 2;
[0036] Figure 3 is the system structure diagram for Embodiment 3. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] In conjunction with the accompanying drawings, embodiments of the present invention will describe the technical solutions in detail. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the scope of protection of the present invention.
[0038] In the description of the present invention, the terms "include" and "comprise" indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0039] It should also be understood that the terms used in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" should include the plural forms.
[0040] It should be further understood that the term "and / or" as used in the specification of the present invention and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the present invention, the " / " character generally indicates an "or" relationship between the associated objects before and after.
[0041] It should be understood that although the terms first, second, third, etc. may be used in the embodiments of the present invention to describe preset ranges, etc., these preset ranges should not be limited to these terms. These terms are only used to distinguish different preset ranges. For example, without departing from the scope of the embodiments of the present invention, the first preset range may also be referred to as the second preset range, and similarly, the second preset range may also be referred to as the first preset range.
[0042] According to the context, as used herein, the word "if" can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, according to the context, the phrase "if determined" or "if detecting (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)".
[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Apparently, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Generally, the components in the accompanying drawings and the described embodiments of the present invention can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts fall within the scope of protection of the present invention.
[0044] The schematic diagrams of various structures according to the disclosed embodiments of the present invention are shown in the accompanying drawings. These figures are not drawn to scale, where for the purpose of clear expression, some details are enlarged and some details may be omitted. The shapes of various regions and layers shown in the figures, as well as their relative sizes and positional relationships, are merely exemplary. In practice, there may be deviations due to manufacturing tolerances or technical limitations, and those skilled in the art can design regions / layers with different shapes, sizes, and relative positions according to actual needs.
[0045] Embodiment 1
[0046] Reference Figure 1 , the trusted guarantee method for the upper computer application of the DCS control system of the present invention includes the following steps:
[0047] 1) Perform integrity verification on each application program in the upper computer of the DCS control system, and use the application programs with qualified integrity verification as whitelist applications;
[0048] 2) Allow the whitelist applications to run in the target environment;
[0049] 3) Monitor the status of the whitelist applications during operation, and determine whether there are abnormal behaviors based on the monitored data;
[0050] 4) When there are abnormal behaviors, an alarm signal is issued, and corresponding measures are taken for the abnormal behaviors. The measures include at least one of restricting the network access rights of the abnormal application, suspending the operation of some functions of the abnormal application, recording the relevant log information of the abnormal behavior, blocking the application, deleting the application, and restarting the system. Among them, when abnormal behaviors are monitored, an alarm is triggered, and response measures are started. The response measures include isolating the affected components, terminating malicious processes, and rolling back to the previous safe state, deleting the application; when the abnormality cannot be resolved, the system is restarted, and the application trusted whitelist guarantee mechanism is executed again;
[0051] 5) Update the whitelist based on the relevant log information.
[0052] In this embodiment, first determine the priority of each application, and then use a combination of digital signature and hash value verification to perform integrity verification on the application; compare the verification result with the preset standard result. If they are inconsistent, an alarm is issued to notify the administrator, and an emergency repair program is started to restore the application file from the backup storage. Send the relevant log information of this integrity verification to the system log server for storage. The relevant log information is used for auditing and troubleshooting.
[0053] In this embodiment, the target environment is a trusted computing environment, which is a computer system environment with hardware, software, and data security. Among them, the computer device in the computer system environment uses a configuration with a security chip, and the security chip is used to protect the keys and sensitive data stored in the security chip.
[0054] In this embodiment, the process of determining whether there is an abnormal behavior based on the monitored data is as follows:
[0055] Input the monitored data into the trained deep neural network machine learning model to obtain the spatio-temporal feature information in the monitored data. Among them, the deep neural network machine learning model adopts an architecture combining a convolutional neural network and a recurrent neural network;
[0056] Judge whether there is an abnormal behavior according to the spatio-temporal feature information.
[0057] Among them, in the training stage of the deep neural network machine learning model, supervised learning training is performed on the deep neural network machine learning model using historical normal operation data and labeled abnormal data samples.
[0058] In the actual operation of the present invention, by introducing the trusted computing technology, it is ensured that the host computer software has a high level of security during operation, effectively resists various security threats, thereby improving the security of the system. In addition, through integrity verification and real-time monitoring, the stability and reliability of the host computer software are ensured, the risk of system failures and data losses is reduced, and the stability of the system is improved. At the same time, through automatic monitoring and abnormal feedback, the workload of system administrators is reduced, and the management efficiency is improved.
[0059] Embodiment 2
[0060] Reference Figure 2 , the trusted guarantee method for the host computer application of the DCS control system of the present invention includes the following steps:
[0061] 1) Determine the whitelist applications;
[0062] Determine whether the application is trustworthy. If the application is trustworthy, list it as a whitelist application and allow the whitelist application to run in the target environment.
[0063] Specifically, perform an integrity check on the application, that is, check the binary code of the application to ensure that the application has not been tampered with or damaged during transmission, storage, and execution.
[0064] To implement the integrity check of the application, the present invention adopts a combination of digital signature and hash value verification. Specifically, when the developer releases the application, the application is digitally signed using the private key, and the signature is released to the user together with the application. When the user installs and runs the application, the public key is used to verify the digital signature, and the hash value of the application is calculated and compared with the hash value provided by the developer to ensure the integrity and security of the application. The application that passes the verification is listed as a whitelist application.
[0065] 2) Implement the whitelist policy:
[0066] Only allow whitelist applications to run in the target environment, and non-whitelist applications cannot run in the target environment. This can be achieved through the operating system or security policies, and the security policies support user customization.
[0067] The target environment is a trusted computing environment, which is a computer system environment with hardware, software, and data security, and can achieve the protection of data confidentiality, integrity, and availability. By introducing the trusted computing environment, the present invention provides a strong security guarantee for the upper computer application of the DCS control system.
[0068] To implement the trusted computing environment, the present invention adopts a computer device with a security chip, which can protect the keys and sensitive data stored therein to ensure the confidentiality and integrity of the data. At the same time, the present invention also adopts an operating system with a secure boot function to ensure the security during the system startup process and prevent the injection and execution of malicious code.
[0069] 3) Monitor whitelist applications;
[0070] Monitor the status of whitelist applications during operation, and judge whether there are abnormal behaviors based on the monitored data. If abnormal behaviors occur, alarms are issued according to the security hazard level of the abnormal behaviors, and corresponding measures are taken, such as blocking the application, deleting the application, or restarting the system, etc.
[0071] 4) Response and recovery;
[0072] When any abnormal behavior is detected or possible malicious activities are detected, an alarm signal is triggered and response measures are initiated. The response measures include isolating the affected components, terminating malicious processes, and rolling back to the previous secure state. When the abnormality cannot be resolved, the system is automatically restarted and the application trusted guarantee mechanism is executed again.
[0073] In addition, it should be noted that the present invention also supports remote monitoring and anomaly detection. Through remote access to the control system, the administrator can view the running status of the system in real time, receive warning messages, view anomaly reports, etc., which provides great convenience for the administrator, enabling the administrator to discover and handle abnormal situations in a timely manner, and ensuring the stability and reliability of the DCS control system.
[0074] Through the present invention, application trusted guarantee ensures that only verified and trusted application programs run in the system, thus greatly reducing the risk of attacks on the system caused by insecure application programs. At the same time, the continuous monitoring and response mechanism can also detect and respond to potential security threats in a timely manner, ensuring the stability and security of the system.
[0075] Embodiment III
[0076] Reference Figure 3 , the DCS control system host computer application trusted guarantee system of the present invention includes:
[0077] A verification module for performing integrity verification on each application program in the DCS control system host computer, and taking the application programs with qualified integrity verification as whitelist applications;
[0078] An operation module for allowing whitelist applications to run in the target environment;
[0079] A monitoring module for monitoring the status of whitelist applications during operation and determining whether there is any abnormal behavior based on the monitored data;
[0080] An alarm module for issuing an alarm when there is abnormal behavior and taking measures corresponding to the abnormal behavior for the abnormal behavior.
[0081] In this embodiment, the verification module includes:
[0082] A determination module for determining the priority of each application program in the DCS control system host computer;
[0083] An integrity verification module for performing integrity verification on each application program by combining digital signature and hash value verification according to the priority of each application program, and issuing an alarm signal when any application program fails the verification.
[0084] In this embodiment, the monitoring module includes:
[0085] An extraction module, configured to input the monitored data into a trained deep neural network machine learning model to obtain spatio-temporal feature information in the monitored data, wherein the deep neural network machine learning model adopts an architecture combining a convolutional neural network and a recurrent neural network;
[0086] A judgment module, configured to judge whether there is an abnormal behavior according to the spatio-temporal feature information.
[0087] The division of modules in the embodiments of the present application is illustrative, merely a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present application, each functional module may be integrated in a processor, may also exist physically alone, or two or more modules may be integrated in one module. The above integrated modules may be implemented in the form of hardware or in the form of software function modules.
[0088] Embodiment 4
[0089] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the DCS control system host computer application trusted guarantee method are implemented. For example, it includes: performing integrity verification on each application program in the DCS control system host computer, and using the application program with qualified integrity verification as a whitelist application; allowing the whitelist application to run in the target environment; monitoring the state of the whitelist application during operation, and determining whether there is an abnormal behavior according to the monitored data; when there is an abnormal behavior, an alarm is issued, and corresponding measures are taken for the abnormal behavior. Wherein, the memory may include internal memory, such as high-speed random access memory, and may also include non-volatile memory, such as at least one disk memory, etc.; the processor, network interface, and memory are interconnected through an internal bus, and this internal bus may be an Industry Standard Architecture bus, a Peripheral Component Interconnect standard bus, an Extended Industry Standard Architecture bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory is used to store programs. Specifically, the program may include program code, and the program code includes computer operation instructions. The memory may include internal memory and non-volatile memory, and provide instructions and data to the processor.
[0090] Embodiment 5
[0091] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the DCS control system host computer application trusted guarantee method are implemented. For example, it includes: performing integrity verification on each application program in the DCS control system host computer, and using the application program with qualified integrity verification as a whitelist application; allowing the whitelist application to run in the target environment; monitoring the status of the whitelist application during the running process, and determining whether there is an abnormal behavior based on the monitored data; when there is an abnormal behavior, an alarm is issued, and corresponding measures are taken for the abnormal behavior. Specifically, the computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. The volatile memory may include random access memory and / or cache memory, etc. The non-volatile memory may include read-only memory, hard disk, flash memory, optical disc, magnetic disk, etc.
[0092] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) containing computer-usable program code.
[0093] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0094] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0095] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the functions specified in one process or a plurality of processes and / or blocks Figure 1 in one block or a plurality of blocks Figure 1 of the steps.
[0096] After considering the specification and the disclosure of the invention, those skilled in the art will readily conceive of other embodiments of the invention. This application is intended to cover any variations, uses, or adaptations of the invention, which follow the general principles of the invention and include known common knowledge or conventional technical means in the technical field not disclosed by the invention. The specification and examples are only regarded as exemplary, and the true scope and spirit of the invention are pointed out by the following claims.
[0097] It should be understood that the invention is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is only limited by the appended claims.
[0098] The above are only the preferred embodiments of the invention, and do not limit the invention in any way. Any simple modifications, changes, and equivalent structural changes made to the above embodiments according to the technical essence of the invention still fall within the protection scope of the technical solution of the invention.
Claims
1. A method for ensuring the trustworthiness of the upper computer application in a DCS control system, characterized in that, Including: Performing integrity verification on each application program in the upper computer of the DCS control system, and taking the application programs with qualified integrity verification as whitelist applications; Allowing the whitelist applications to run in the target environment; Monitoring the status of the whitelist applications during operation, and determining whether there are abnormal behaviors according to the monitored data; When there are abnormal behaviors, an alarm is issued, and corresponding measures are taken for the abnormal behaviors; The target environment is a trusted computing environment, which is a computer system environment with hardware, software, and data security. Among them, the computer devices in the computer system environment adopt a configuration with a security chip, and the security chip is used to protect the keys and sensitive data stored in the security chip.
2. The method for ensuring the trustworthiness of the upper computer application in the DCS control system according to claim 1, wherein The process of performing integrity verification on each application program in the upper computer of the DCS control system is as follows: Determining the priorities of each application program in the upper computer of the DCS control system; According to the priorities of each application program, performing integrity verification on each application program by combining digital signature and hash value verification. When any application program fails the verification, an alarm signal is issued.
3. The method for ensuring the credibility of the upper computer application of the DCS control system according to claim 1, characterized in that, The measures include at least one of restricting the network access rights of abnormal applications, suspending the operation of some functions of abnormal applications, recording relevant log information of abnormal behaviors, blocking applications, deleting applications, and restarting the system.
4. The method for ensuring the trustworthiness of the upper computer application in the DCS control system according to claim 1, wherein The process of determining whether there are abnormal behaviors according to the monitored data is as follows: Inputting the monitored data into the trained deep neural network machine learning model to obtain the spatio-temporal feature information in the monitored data. Among them, the deep neural network machine learning model adopts an architecture combining a convolutional neural network and a recurrent neural network; Judging whether there are abnormal behaviors according to the spatio-temporal feature information.
5. A trustworthy guarantee system for the upper computer application of a DCS control system, characterized in that, Including: A verification module for performing integrity verification on each application program in the upper computer of the DCS control system, and taking the application programs with qualified integrity verification as whitelist applications; An operation module for allowing the whitelist applications to run in the target environment; A monitoring module for monitoring the status of the whitelist applications during operation, and determining whether there are abnormal behaviors according to the monitored data; An alarm module for issuing an alarm when there are abnormal behaviors, and taking corresponding measures for the abnormal behaviors; The target environment is a trusted computing environment, which is a computer system environment with hardware, software, and data security. Among them, the computer devices in the computer system environment adopt a configuration with a security chip, and the security chip is used to protect the keys and sensitive data stored in the security chip.
6. The DCS control system host computer application trusted guarantee system according to claim 5, characterized in that, The verification module includes: A determination module for determining the priorities of each application program in the upper computer of the DCS control system; An integrity verification module for performing integrity verification on each application program by combining digital signature and hash value verification according to the priorities of each application program. When any application program fails the verification, an alarm signal is issued.
7. The DCS control system upper computer application trusted guarantee system according to claim 5, characterized in that The monitoring module includes: An extraction module, configured to input the monitored data into a trained deep neural network machine learning model to obtain spatio-temporal feature information in the monitored data, wherein the deep neural network machine learning model adopts an architecture combining a convolutional neural network and a recurrent neural network; A judgment module, configured to judge whether there is an abnormal behavior according to the spatio-temporal feature information.
8. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the DCS control system host computer application trusted guarantee method according to any one of claims 1-4.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the DCS control system host computer application trusted guarantee method according to any one of claims 1-4.
Citation Information
Patent Citations
White list network management and control system and method based on trusted chip
CN106936768A
DCS (Distributed Control System) upper computer startup credibility guarantee method and related device
CN119397547A