Redundant control defense method, device and electronic equipment of programmable logic controller

By introducing multiple control virtual machines into the PLC, redundant control defense is achieved, and the problem of complex and costly hardware redundancy in the prior art is solved, thus realizing network security of the PLC and reducing costs.

CN119828583BActive Publication Date: 2025-05-13北京中关村实验室
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510301664.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-05-13
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

In the prior art, ensuring the network security of programmable logic controllers (PLCs) through hardware redundancy requires the deployment of multiple PLCs and supporting hardware modules, and the hardware infrastructure needs to be adjusted, which is complex and costly.

Method used

By introducing multiple control virtual machines into the PLC, the input data is obtained and processed separately, the control results are generated, and the redundant control defense is achieved through multiple control virtual machines with heterogeneous memory layout, and the target results are selected to ensure the network security of the PLC.

Benefits of technology

The network security of PLC is realized. Through redundant control of virtual machines, only some control virtual machines can be affected in a short period of time. Other control virtual machines can work normally, select normal target results, reduce costs and simplify implementation methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119828583B_ABST
    Figure CN119828583B_ABST
Patent Text Reader

Abstract

The present application provides a redundant control defense method, device and electronic device for a programmable logic controller, which is applied to the field of industrial security. The method includes: determining input data according to the acquired status data, and saving the input data to an input image table; obtaining input data in the input image table respectively through multiple control virtual machines of the programmable logic controller, and processing the input data to obtain control results; the memory layouts of the multiple control virtual machines are mutually heterogeneous; obtaining multiple control results obtained through multiple control virtual machines, and selecting a target result from the multiple control results; writing the target result into the output image table, and controlling the execution device based on the target result in the output image table. The method of the present application simplifies the implementation method of ensuring the network security of the programmable logic controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of industrial safety, and in particular to a redundant control defense method, device and electronic equipment for a programmable logic controller. Background Art

[0002] In industrial environments, programmable logic controllers are used to read the status data of input devices and control the execution of device actions based on the status data to achieve automated control of industrial processes.

[0003] In the related art, the network security of the programmable logic controller is ensured by hardware redundancy. However, this method requires the deployment of multiple programmable logic controllers and supporting hardware modules, and the adjustment of the hardware infrastructure, which makes the implementation complicated. Summary of the invention

[0004] Based on this, it is necessary to provide a redundant control defense method, device and electronic device for a programmable logic controller to address the above technical problems and simplify the implementation method.

[0005] In a first aspect, the present application provides a redundant control defense method for a programmable logic controller, comprising:

[0006] Determine input data according to the acquired status data, and save the input data to an input image table;

[0007] Through multiple control virtual machines of the programmable logic controller, input data in the input image table are obtained respectively, and the input data are processed to obtain control results; the memory layouts of the multiple control virtual machines are heterogeneous;

[0008] Acquire multiple control results obtained through multiple control virtual machines, and select a target result from the multiple control results;

[0009] The target result is written into the output image table, and the execution device is controlled based on the target result in the output image table.

[0010] In a second aspect, the present application provides a redundant control defense device for a programmable logic controller, comprising:

[0011] A data acquisition module, used for determining input data according to the acquired state data, and saving the input data to an input image table;

[0012] The control module is used to obtain input data in the input image table through multiple control virtual machines of the programmable logic controller, and process the input data to obtain a control result; the memory layouts of the multiple control virtual machines are heterogeneous;

[0013] A result processing module, used to obtain multiple control results obtained through multiple control virtual machines, and select a target result from the multiple control results;

[0014] The output module is used to write the target result into the output image table and control the execution device based on the target result in the output image table.

[0015] In a third aspect, the present application further provides an electronic device, wherein the computer comprises: a processor, and a memory communicatively connected to the processor;

[0016] Memory stores computer-executable instructions;

[0017] The above method is implemented when the processor executes the computer-executable instructions stored in the memory.

[0018] In a fourth aspect, the present application also provides a computer-readable storage medium, in which computer-executable instructions are stored, and the computer-executable instructions are used to implement the above method when executed by a processor.

[0019] In a fifth aspect, the present application also provides a computer program product, including computer execution instructions, which implement the above method when executed by a processor.

[0020] The present application provides a redundant control defense method, device, electronic device, storage medium and program product for a programmable logic controller, which decouples the functional area executing the control logic program in the programmable logic controller, executes the control logic program through a control virtual machine, isolates the function of executing the control logic program from other functions of the PLC, and thus the control logic program is not vulnerable to network attacks, and through a plurality of control virtual machines with heterogeneous memory layout and redundancy, a network attack can only affect a certain control virtual machine in a short period of time, while other control virtual machines can work normally, and then a normal target result can be selected from a plurality of control results, thereby ensuring the network security of the PLC; since the plurality of control virtual machines with heterogeneous memory layout and redundancy are implemented at the software level, there is no need to increase the number of PLCs and supporting hardware modules in hardware, and there is no need to adjust the hardware infrastructure, which effectively reduces the cost and is simple to implement. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related technologies, the drawings required for use in the embodiments or the related technical descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0022] Figure 1Schematic diagram of an application scenario of a redundant control defense method for a programmable logic controller provided in an embodiment Figure 1 ;

[0023] Figure 2 A flowchart of a redundant control defense method for a programmable logic controller provided in one embodiment Figure 1 ;

[0024] Figure 3 Schematic diagram of an application scenario of a redundant control defense method for a programmable logic controller provided in an embodiment Figure 2 ;

[0025] Figure 4 A schematic diagram of the structure of a redundant control defense device of a programmable logic controller provided in one embodiment;

[0026] Figure 5 A hardware structure diagram of an electronic device provided in one embodiment.

[0027] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0028] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0029] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.

[0030] Glossary:

[0031] Programmable Logic Controller: PLC, Programmable Logic Controller, is a digital computer for automated control systems, commonly used in industrial automation, robot control, etc.; when the PLC is running, it performs periodic cyclic scanning according to the preset control program. In each scanning cycle, in the input sampling stage, the PLC reads the status data of the input device and maps the status data to the input image table; in the program execution stage, the PLC reads the data in the input image table according to the pre-written control logic program, performs logical operations, sequential control and other processing, and finally writes the calculated control results into the output image table; in the output update stage, the PLC reads the control results in the output image table and converts them into control signals to control the actions of the execution equipment, thereby realizing automated control of the industrial process.

[0032] Input image table: used to store information collected by input devices.

[0033] Output image table: used to store information output to the execution device.

[0034] In the application environment of PLC, there are network attacks that rely on the internal host connected to the PLC, located in the industrial control system (ICS) network but accessing the Internet service at the same time as an "attack springboard" or acting as a "middleman" between the PLC and the host computer to launch a network attack on the PLC. The attacker invades the internal host of the ICS network through malicious network services and other means, and then sends the attack payload to the PLC through the network. The attack payload can obtain system permissions through a series of operations, such as through memory vulnerabilities such as buffer overflows, and then modify the control variables / logic programs in the memory, etc., and finally achieve tampering with the output image table.

[0035] In the related art, the network security of the programmable logic controller is ensured by hardware redundancy. However, this method requires the deployment of multiple programmable logic controllers and supporting hardware modules, and the adjustment of the hardware infrastructure. The implementation is complex and costly.

[0036] In the embodiment of the present application, the program execution phase of the PLC is placed separately in the control virtual machine for execution, so as to completely isolate the program execution phase of the PLC from other functional areas of the PLC and the ICS, thereby improving the security of the program execution phase of the PLC, and running the same control logic program through multiple control virtual machines with heterogeneous memory layouts, so that a network attack can only affect a certain control virtual machine in a short period of time, and other control virtual machines can work normally. Through the idea of ​​redundancy-comparison, a normal target result can be selected from multiple control results later, thereby ensuring the network security of the PLC. Since the memory layout is heterogeneous and redundant multiple control virtual machines are implemented at the software level, there is no need to increase the number of PLCs and supporting hardware modules in hardware, and there is no need to adjust the hardware infrastructure, which effectively reduces the cost and is simple to implement.

[0037] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0038] The redundant control defense method of the programmable logic controller provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, the input device 102 collects the status data of the industrial scene, the programmable logic controller 104 obtains the status data, processes the status data to obtain a control command, and sends the control command to the execution device 106 to control the execution device 106 to run.

[0039] In some embodiments, Figure 2 As shown, a redundant control defense method for a programmable logic controller is provided, and the method is applied to Figure 1 The programmable logic controller in the example is used to illustrate, including:

[0040] S201. Determine input data according to the acquired status data, and save the input data to an input image table.

[0041] Among them, the status data is the data collected by the input device, and the input device can be a sensor, a switch, etc. Correspondingly, the status data can be the data collected by the sensor, the switch status data, etc.

[0042] Specifically, in each scanning cycle, the PLC reads the status data collected by the input device in a scanning manner, converts the status data into binary data, obtains input data, and writes the input data into an input image table in the PLC memory.

[0043] S202, respectively obtaining input data in the input image table through multiple control virtual machines of the programmable logic controller, and processing the input data to obtain a control result; the memory layouts of the multiple control virtual machines are heterogeneous.

[0044] Among them, virtualization technology enables a single physical computer to run multiple operating systems by creating virtual machines. The virtual machine simulates a complete computer system, including processors, memory, IO interfaces, etc. In actual applications, virtualization technology can be used to divide multiple control virtual machines on the physical PLC.

[0045] The control virtual machine is used to execute the control logic program in the PLC. The control logic program executed by multiple control virtual machines is the same; multiple control virtual machines are three or more virtual machines; it should be noted that, since the multiple control virtual machines are in different operating system environments, the multiple control virtual machines are isolated from each other, and are isolated from other functional areas of the PLC and from the ICS network of the upper layer of the PLC. Through the control virtual machine, the functional area in the PLC that executes the control logic program can be securely guaranteed.

[0046] It should also be noted that the multiple control virtual machines run the same real-time operating system, the input data input into the multiple control virtual machines are the same, and under normal operation, the control results obtained by the multiple control virtual machines are also the same.

[0047] The memory layouts of the multiple control virtual machines are heterogeneous, that is, there are no virtual machines with the same internal layout among the multiple virtual machines; the memory layout is heterogeneous, and the heterogeneous memory layout can be set by applying an address randomization strategy.

[0048] It should be noted that the memory layouts are heterogeneous, so that attacks cannot affect multiple control virtual machines in a short period of time. In the attack scenario, at least some control virtual machines can be guaranteed to work normally, thereby ensuring the output security of the PLC.

[0049] Specifically, for each control virtual machine, the control virtual machine obtains input data in the input image table, processes the input data through the control logic program, and obtains a control result corresponding to the control virtual machine.

[0050] S203: Acquire multiple control results obtained through multiple control virtual machines, and select a target result from the multiple control results.

[0051] The target result is one of multiple control results.

[0052] Optionally, the PLC obtains control results respectively output by a plurality of control virtual machines, selects a control result that accounts for the majority among the plurality of control results, and uses any one of the control results that accounts for the majority as a target result.

[0053] Exemplarily, the number of multiple control virtual machines is 3, and the 3 control virtual machines process the input data respectively to obtain 3 control results. Assuming that 2 of the 3 control results are the same, and the other one is different from the 2 control results, any one of the 2 identical control results will be taken as the target result.

[0054] It should be noted that the attacker invades the host inside the ICS network and then sends the attack payload to the PLC through the ICS network. The attack payload obtains system permissions through a series of operations, such as memory vulnerabilities such as buffer overflow, and then modifies the control logic program. The attack method can only affect a certain control virtual machine in a short period of time. The embodiment of the present application uses multiple control virtual machines with mutually heterogeneous memory layouts and the idea of ​​redundancy-comparison to ensure that the target result is obtained by the control virtual machine that has not been attacked, so that the PLC can protect against attacks on the control logic program and ensure the security of the PLC.

[0055] S204: Write the target result into the output image table, and control the execution device based on the target result in the output image table.

[0056] Specifically, the target result is written into the output image table, and the execution device is controlled based on the target result in the output image table. The input-output virtual machine may write the target result into the output image table, and generate a control command based on the target result in the output image table, and control the execution device through the control command.

[0057] In the redundant control defense method of the above-mentioned programmable logic controller, the functional area executing the control logic program in the programmable logic controller is decoupled, and the control logic program is executed by the control virtual machine, so that the function of executing the control logic program is isolated from other functions of the PLC, and thus the control logic program is not vulnerable to network attacks, and through the memory layout heterogeneous and redundant multiple control virtual machines, the network attack can only affect a certain control virtual machine in a short time, and the other control virtual machines can work normally, and then the normal target result can be selected from multiple control results, thereby ensuring the network security of the PLC; since the memory layout heterogeneous and redundant multiple control virtual machines are implemented at the software level, there is no need to increase the number of PLCs and supporting hardware modules in hardware, and there is no need to adjust the hardware infrastructure, which effectively reduces the cost and is simple to implement.

[0058] In some embodiments, determining input data based on acquired state data and saving the input data to an input image table includes: converting the acquired state data into input data through an input-output virtual machine of a programmable logic controller, and writing the input data into the input image table.

[0059] Among them, the input and output virtual machine of the PLC is constructed through virtualization technology, and the input and output virtual machine can be used to execute the input sampling part of the PLC.

[0060] Specifically, in each scanning cycle, the state data of the input device is read through the input-output virtual machine, the state data is converted into binary input data, and the input data is written into the input mapping table.

[0061] It should be noted that the input-output virtual machine provides a separate operating environment for the input sampling stage of the PLC, making the input-output virtual machine not vulnerable to network attacks; the input-output virtual machine is isolated from other functional areas of the PLC and from the ICS network above the PLC. If the control virtual machine or other functional areas of the PLC are attacked by a network attack, the input-output virtual machine will not be attacked, thus avoiding the data in the input image table from being tampered with, allowing the PLC to protect against attacks that tamper with the input image table and ensure the data security of the input image table.

[0062] In some embodiments, input data in the input image table are obtained respectively through multiple control virtual machines of the programmable logic controller, including: writing the input data in the input image table into multiple first message queues respectively through the input-output virtual machine; reading the input data from the multiple first message queues respectively through the multiple control virtual machines; and the multiple control virtual machines correspond one-to-one to the multiple first message queues.

[0063] Among them, the input-output virtual machine acts as the producer of the first message queue, and the control virtual machine acts as the consumer of the first message queue. The producer of the first message queue writes the input data into the first message queue, and the consumer of the first message queue reads the input data from the first message queue. The first message queue enables the input data to be shared between the input-output virtual machine and the control virtual machine, so the first message queue can be understood as an input shared memory area.

[0064] In practical applications, the first message queue can be a Kafka message queue or a lock-free ring queue. The use of a lock-free ring queue avoids the use of an interrupt-based signal mechanism to execute data exchange between virtual machines, and adopts a lock-free mechanism to make data enqueue / dequeue operations efficient.

[0065] Specifically, based on the number of multiple control virtual machines, multiple first message queues are determined so that the multiple first message queues correspond one-to-one to the multiple control virtual machines; the access rights of the first message queues are restricted by the virtualization hypervisor and can only be accessed by the input and output virtual machines and the control virtual machines, and cannot be accessed by third-party virtual machines.

[0066] For each group of corresponding first message queues and control virtual machines, the input-output virtual machine sends the input data to the first message queue, and the control virtual machine determines whether the corresponding first message queue is empty. Until the first message queue is not empty, the control virtual machine performs a data dequeue operation as a consumer, that is, takes out the input data in the first message queue and stores the input data in the virtual input image table of the control virtual machine.

[0067] In the above embodiment, data sharing between the input and output virtual machine and the control virtual machine is achieved through the first message queue, thereby improving the data transmission efficiency between the input and output virtual machine and the control virtual machine.

[0068] In some embodiments, multiple control results obtained through multiple control virtual machines are obtained, and a target result is selected from the multiple control results, including: for each control virtual machine, writing the obtained control result into a second message queue corresponding to the targeted control virtual machine through the targeted control virtual machine; obtaining control results from the second message queues corresponding to each of the multiple control virtual machines through the input and output virtual machines of the programmable logic controller, and selecting the target result from the multiple control results obtained.

[0069] Among them, the input and output virtual machine can also be used to execute the output part of the PLC.

[0070] The control virtual machine acts as the producer of the second message queue, and the input / output virtual machine acts as the consumer of the second message queue. The second message queue enables the input / output virtual machine and the control virtual machine to share control results (output data), so the second message queue can be understood as an output shared memory area.

[0071] In actual applications, the second message queue can be a Kafka message queue or a lock-free ring queue. The use of a lock-free ring queue avoids the use of an interrupt-based signal mechanism to execute data exchange between virtual machines, and uses a lock-free mechanism to make data enqueue / dequeue operations efficient.

[0072] Specifically, a corresponding second message queue is configured for each control virtual machine. For each control virtual machine, the control virtual machine writes the control result generated by itself into its corresponding second message queue, and the input-output virtual machine determines whether the second message queue is empty. When the second message queue is not empty, the input-output virtual machine obtains the control result in the second message queue. Since there are multiple control virtual machines, under normal circumstances, the input-output virtual machine can obtain multiple control results from multiple second message queues, and then select the target result from the multiple control results.

[0073] Optionally, the target result is written into the output image table, and the execution device is controlled based on the target result in the output image table. The input-output virtual machine may write the target result into the output image table, and generate a control command based on the target result in the output image table, and control the execution device through the control command.

[0074] In the above embodiment, the input-output virtual machine also provides a separate operating environment for the output stage of the PLC, so that the operation of the output stage is not easily vulnerable to network attacks. The input-output virtual machine is isolated from other functional areas of the PLC and from the ICS network of the upper layer of the PLC. If the control virtual machine or other functional areas of the PLC are attacked by a network, the input-output virtual machine will not be attacked, thereby avoiding tampering of data in the output image table, so that the PLC can protect against attacks that tamper with the output image table, and ensure the data security of the output image table; in addition, data sharing between the input-output virtual machine and the control virtual machine is realized through the second message queue, thereby improving the data transmission efficiency between the input-output virtual machine and the control virtual machine.

[0075] In some embodiments, selecting a target result from multiple control results includes: selecting a valid result belonging to the current scanning cycle from multiple control results; when the number of valid results is multiple and the multiple valid results are the same, taking any valid result as the target result; when the number of valid results is multiple and the multiple valid results are not exactly the same, dividing the multiple valid results into at least two result sets, and taking any valid result in the result set containing the largest number of valid results as the target result; the valid results belonging to the same result set are the same; when the number of valid results is multiple and the multiple valid results are different, selecting a low-risk virtual machine from multiple valid virtual machines, and taking the valid result output by the low-risk virtual machine as the target result.

[0076] The current scanning cycle is the scanning cycle in which the state data is located; and the valid result is at least a part of the control result.

[0077] Specifically, the period information of each of the multiple control results is obtained, and the valid result of the current scanning period is selected from the multiple control results according to the period information. If the number of valid results is 1, the valid result is used as the target result.

[0078] If there are multiple valid results, when the multiple valid results are exactly the same, any valid result will be used as the target result.

[0079] When multiple valid results are not exactly the same, the multiple valid results are divided into at least two result sets, so that the same valid results belong to the same result set, and the valid results belonging to different result sets are different. The result set containing the largest number of valid results in each result set is taken as the target result set, and any valid result in the target result set is taken as the target result, that is, the majority of valid results are taken as the target result.

[0080] When multiple valid results are not exactly the same, but it is impossible to select the target result set containing the largest number of valid results, for example, each valid result contains the same number of valid results; obtain the number of exceptions of each control virtual machine, take the control virtual machine with the least number of exceptions as a low-risk virtual machine, and take the valid results output by the low-risk virtual machine as the target result.

[0081] Optionally, when there are multiple valid results, and the multiple valid results are not completely the same, the multiple valid results are divided into at least two result sets, and the target result set containing the largest number of valid results is selected from the at least two result sets. For other target result sets other than the target result set, the control virtual machines corresponding to the valid results contained in the other target result sets are used as abnormal control virtual machines, and the abnormal number of the abnormal control virtual machine is increased by 1. In other words, if the valid result output by the control virtual machine does not belong to the target result set, the result output by the control virtual machine is different from the results output by most control virtual machines, and the control virtual machine may have suffered a network attack. The abnormal number can reflect the number of times the control virtual machine may have suffered a network attack.

[0082] Exemplarily, taking the case where the multiple control virtual machines are three control virtual machines, assuming that the control results output by the three control virtual machines are all valid results, there are several situations as shown in Table 1.

[0083] Table 1

[0084]

[0085] In the above embodiment, a target result is selected from multiple control results. Even if a certain control virtual machine is attacked by a network, it can be ensured that the target result is output by a control virtual machine that has not been attacked by the network, thereby ensuring the network security of the PLC.

[0086] In some embodiments, selecting a valid result belonging to the current scanning cycle from multiple control results includes: obtaining a cycle tag contained in the multiple control results; for each control result, when the cycle tag of the targeted control result is consistent with the scanning cycle corresponding to the status data, the targeted control result is taken as a valid result.

[0087] The control result includes a period tag. Specifically, the period tag may be at the end of the control result.

[0088] It should be noted that the input-output virtual machine maintains a counter for a scan cycle. When the input data corresponding to the status data of the current scan cycle is input into the first message queue, the cycle tag corresponding to the current scan cycle is determined by the counter, and the cycle tag is attached to the end of the input data, so that the cycle tag enters the first message queue together with the input data; when the control virtual machine obtains input data from the first message queue as a consumer, it can obtain the input data and the cycle tag. When the control virtual machine determines the control result corresponding to the input data through the control logic program, the cycle tag is added to the control result, and the control result with the cycle tag is saved to its own virtual output image table, and then the control result with the cycle tag in the virtual output image table is written into the second message queue. The input-output virtual machine obtains the control result with the cycle tag from the second message queue, and selects the valid result belonging to the current scan cycle from the control results output by each control virtual machine through the cycle tag.

[0089] In actual applications, in the cyclic dequeue process (the process of cyclically obtaining control results from each second message queue), if the control result obtained in a second message queue is a valid result, the second message queue will be skipped in the subsequent cyclic dequeue process until valid results are obtained from all second message queues; optionally, in the cyclic dequeue process of the current scanning cycle, if the waiting time for dequeueing exceeds the preset time, the cyclic dequeue process is terminated.

[0090] In the above embodiment, the periodic label is used to ensure that the subsequent valid results participating in the output decision-making all belong to the current scanning cycle, thereby avoiding the difference in valid results participating in the output decision-making due to inconsistent scanning cycles, which may be mistaken for the difference caused by network attacks, avoiding misjudgment and improving the reliability of PLC security protection.

[0091] Optionally, the redundant control defense method of the programmable logic controller further includes: in response to the update operation, updating the control logic program of multiple control virtual machines one by one in a preset order. It is understandable that in the process of updating the control logic program one by one, the control result output by the control virtual machine in the update process may be different from the control result output by other control virtual machines, or the control result output by the updated control virtual machine may be different from the control result output by the unupdated control virtual machine. However, by selecting a target result from multiple control results and controlling the execution device through the target result, the normal operation of the PLC during the update process can be guaranteed.

[0092] In a specific scenario, the real-time control task of the PLC regularly performs input sampling, control logic program execution, and output update in three stages according to the scanning cycle. The embodiment of the present application decouples the three stages. Figure 3 , through static allocation of virtualization hypervisor, real-time virtual machine 0, real-time virtual machine 1, real-time virtual machine 2 and real-time virtual machine 3 are allocated. The static allocation virtualization hypervisor can be Jailhouse (Linux-based partition virtual machine hypervisor), RTS (static allocation virtualization hypervisor supporting all x86 platforms), Bao (lightweight static partition virtual machine hypervisor), etc.; the static allocation virtualization hypervisor can allocate exclusive CPU cores, I / O devices and other hardware resources to real-time virtual machines to achieve non-interference in resource usage scheduling between virtual machines, thereby ensuring the real-time performance of PLC industrial control; real-time virtual machines 0~3 all run real-time operating systems and are isolated from each other.

[0093] Among them, real-time virtual machine 0 is an input and output virtual machine, which processes the physical input / output process of PLC and is completely isolated from the upper network space of the host such as PLC host computer. Therefore, it can completely avoid the attack payload from the upper network space from invading its virtual machine to tamper with the input / output image table; real-time virtual machine 1, real-time virtual machine 2 and real-time virtual machine 3 are control virtual machines. At the same time, the memory layout of real-time virtual machines 1~3 is heterogeneous, and they have the same input data in each scanning cycle and execute the same control logic program.

[0094] When the PLC is used in actual business, when the attack payload of the upper network space invades a control virtual machine and finally tamperes with the output data of the current virtual machine through a series of memory destruction operations (such as buffer overflow) (that is, it can tamper with the virtual output image table of the current control program virtual machine), however, the embodiment of the present application uses multiple control virtual machines with mutually heterogeneous memory layouts, so that the attack can only affect a certain control virtual machine in a short period of time. At the same time, by comparing the control results output by the three control virtual machines, the attacked control virtual machine can be identified, and the majority of the control results can be used as the target results to ensure the output security of the PLC.

[0095] Specifically, the following processes are included:

[0096] (1) At the beginning of each scan cycle, the input-output virtual machine (real-time virtual machine 0) reads the status data of the input device, maps the status data into input data, and saves it in the input image table.

[0097] (2) The input-output virtual machine (real-time virtual machine 0) reads the input data in the input image table, and as a producer, sequentially inputs the input data into the first message queues of the input shared memory areas (1-3) corresponding to the three control virtual machines (real-time virtual machines 1-3). The input shared memory areas (1-3) include three first message queues; the first message queues may be lock-free circular queues.

[0098] The input and output virtual machine (real-time virtual machine 0) also maintains a cycle tag, which is incremented by 1 in each scan cycle. When executing the input data enqueue operation, the cycle tag is attached to the end of the input data and enqueued uniformly. The cycle tag is used in subsequent processes to match the input and output in the same cycle.

[0099] (3) In the virtual input sampling phase, the three control virtual machines continuously determine whether the first message queue in their respective input shared memory areas (1-3) is empty. When the first message queue is not empty, they perform a dequeue operation as queue consumers, take out the input data and cycle tags in the corresponding first message queue, and store them in the virtual input image table of the local PLC during operation.

[0100] (4) During the execution phase of their respective control logic programs, the three control virtual machines perform conditional judgment, logical operations, and sequential control based on the input data in the virtual input image table during PLC runtime, and write the calculated control results into their respective virtual output image tables. In addition, the control virtual machine also copies the cycle label to the end of the control result in the virtual output image table.

[0101] (5) The control virtual machine (real-time virtual machine 1-3) acts as a producer and inputs the control results in its respective virtual output image table into the second message queue of its corresponding output shared memory area. The second message queue can be a lock-free circular queue. The control virtual machine executes (3)-(5) in a loop.

[0102] (6) After executing (2), the input-output virtual machine continuously and cyclically determines whether the second message queue of each output shared memory area is empty. When a second message queue is not empty, it performs a dequeue operation on it to retrieve the control result and cycle label, and determines whether the control result is a valid result through the label of the current scan cycle stored locally, and then selects the valid result belonging to the current scan cycle.

[0103] The input-output virtual machine executes output decisions for valid results to select a target result from the valid results and write the target result into an output impact table; the process of selecting the target result may be: for example, when there are multiple valid results and the multiple valid results are the same, any valid result is used as the target result; when there are multiple valid results and the multiple valid results are not completely the same, the multiple valid results are divided into at least two result sets, and the target result set containing the largest number of valid results is selected from the at least two result sets, and any valid result in the target result set is used as the target result; the valid results belonging to the same result set are the same; when there are multiple valid results and the multiple valid results are not completely the same, the multiple valid results are divided into at least two result sets. If the target result set cannot be selected, a low-risk virtual machine is selected from multiple control virtual machines, and the valid result output by the low-risk virtual machine is used as the target result.

[0104] (7) The input-output virtual machine generates control commands based on the target results in the output image table and outputs the control commands to the execution device to control the action of the execution device.

[0105] It should be noted that when the PLC host computer needs to update the PLC control logic program, the operator can synchronize the control logic programs of all control virtual machines by updating the programs of the redundant control virtual machines in sequence; it can be understood that under the idea of ​​redundancy-comparison, the present application can ensure that the PLC physical output is not disturbed by updating the control program of the control virtual machines one by one, thereby eliminating the need to stop the normal industrial production process.

[0106] In an embodiment of the present application, embedded virtualization technology is used to establish a control virtual machine with heterogeneous redundant memory layout for the PLC, and heterogeneous redundant security defense is performed. Abnormal control program virtual machines are identified by output result comparison and the destructive effects of various unknown network attacks on the PLC are eliminated; embedded virtualization technology is used to establish an input and output virtual machine for the PLC that is completely isolated from the upper network space, thereby avoiding direct damage to the physical input and output stages of the PLC by the network attack payload, and providing integrity protection for the input and output stages of the PLC; embedded virtualization technology is used to establish a redundant control program virtual machine for the PLC, providing availability guarantee without stopping the industrial production process during the control program update.

[0107] It should be understood that, although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0108] Based on the same inventive concept, Figure 4 A schematic diagram of the structure of the redundant control defense device of the programmable logic controller provided in this application, such as Figure 4 As shown, the redundant control defense device 40 of the programmable logic controller provided in this embodiment includes:

[0109] The data acquisition module 401 is used to determine the input data according to the acquired state data, and save the input data to the input image table;

[0110] The control module 402 is used to obtain input data in the input image table through multiple control virtual machines of the programmable logic controller, and process the input data to obtain a control result; the memory layouts of the multiple control virtual machines are heterogeneous;

[0111] A result processing module 403 is used to obtain multiple control results obtained through multiple control virtual machines and select a target result from the multiple control results;

[0112] The output module 404 is used to write the target result into the output image table and control the execution device based on the target result in the output image table.

[0113] In some embodiments, the data acquisition module 401 is further used to convert the acquired state data into input data through the input-output virtual machine of the programmable logic controller, and write the input data into the input image table.

[0114] In some embodiments, the control module 402 is also used to write the input data in the input image table into multiple first message queues through the input and output virtual machines; read the input data from the multiple first message queues through multiple control virtual machines; and the multiple control virtual machines correspond one-to-one to the multiple first message queues.

[0115] In some embodiments, the result processing module 403 is also used to write the obtained control result into the second message queue corresponding to the targeted control virtual machine through the targeted control virtual machine for each control virtual machine; obtain the control result from the second message queues corresponding to the multiple control virtual machines respectively through the input and output virtual machines of the programmable logic controller, and select the target result from the multiple control results obtained.

[0116] In some embodiments, the result processing module 403 is also used to select valid results belonging to the current scanning cycle from multiple control results; when the number of valid results is multiple and the multiple valid results are the same, any valid result is used as the target result; when the number of valid results is multiple and the multiple valid results are not completely the same, the multiple valid results are divided into at least two result sets, and the target result set containing the largest number of valid results is selected from the at least two result sets, and any valid result in the target result set is used as the target result; the valid results belonging to the same result set are the same; when the number of valid results is multiple and the multiple valid results are not completely the same, the multiple valid results are divided into at least two result sets, and if the target result set cannot be selected, a low-risk virtual machine is selected from multiple control virtual machines, and the valid results output by the low-risk virtual machine are used as the target result.

[0117] In some embodiments, the result processing module 403 is further used to obtain the cycle tags contained in the multiple control results; for each control result, when the cycle tag of the control result is consistent with the scanning cycle corresponding to the state data, the control result is taken as a valid result.

[0118] The redundant control defense device of the programmable logic controller provided in this embodiment can execute the method provided in the above method embodiment, and its implementation principle and technical effect are similar. Therefore, the specific limitations in the redundant control defense device embodiment of the programmable logic controller provided above can be found in the above limitations on the redundant control defense method of the programmable logic controller, which will not be repeated here.

[0119] Each module in the redundant control defense device of the programmable logic controller can be implemented in whole or in part by software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in an electronic device in the form of hardware, or can be stored in a memory in the electronic device in the form of software, so that the processor can call and execute operations corresponding to each module.

[0120] Figure 5 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 5As shown, the electronic device 50 provided in this embodiment includes: at least one processor 501 and a memory 502. Optionally, the device 50 also includes a communication component 503. The processor 501, the memory 502 and the communication component 503 are connected via a bus.

[0121] In a specific implementation process, at least one processor 501 executes the computer-executable instructions stored in the memory 502, so that at least one processor 501 executes the above method.

[0122] The specific implementation process of the processor 501 can be found in the above method embodiment, and its implementation principle and technical effect are similar, so this embodiment will not be repeated here.

[0123] In the above embodiments, it should be understood that the processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the invention can be directly implemented as a hardware processor, or can be implemented by a combination of hardware and software modules in the processor.

[0124] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk storage.

[0125] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of this application is not limited to only one bus or one type of bus.

[0126] The embodiment of the present application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, each step of the method in the above embodiment is implemented.

[0127] The embodiment of the present application also provides a computer program product, including computer executable instructions, which implement the various steps of the method in the above embodiment when executed by a processor.

[0128] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0129] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general or special-purpose computer.

[0130] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (Application Specific Integrated Circuits, referred to as: ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.

[0131] The division of units is only a logical function division, and there may be other divisions in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0132] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0133] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0134] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0135] Those skilled in the art can understand that all or part of the steps of implementing the above-mentioned method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk and other media that can store program codes.

[0136] Finally, it should be noted that those skilled in the art will readily conceive of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses or adaptations of the present invention, which follow the general principles of the present invention and include common knowledge or customary technical means in the art not disclosed by the present invention, are not limited to the precise structure described above and shown in the drawings, and may be modified and changed in various ways without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

Claims

1. A redundant control defense method for a programmable logic controller, characterized in that: include: Determine input data according to the acquired status data, and save the input data to an input image table; The input data in the input image table are respectively obtained through multiple control virtual machines of the programmable logic controller, and the input data are processed to obtain a control result; the memory layouts of the multiple control virtual machines are heterogeneous; Acquire multiple control results obtained through the multiple control virtual machines, and select a target result from the multiple control results; The target result is written into an output image table, and an execution device is controlled based on the target result in the output image table.

2. The method according to claim 1, characterized in that The step of determining input data according to the acquired state data and storing the input data in an input image table comprises: The acquired state data is converted into input data through the input-output virtual machine of the programmable logic controller, and the input data is written into the input image table.

3. The method according to claim 2, characterized in that The step of respectively obtaining the input data in the input image table through the multiple control virtual machines of the programmable logic controller includes: Writing the input data in the input image table into a plurality of first message queues respectively through the input-output virtual machine; The input data is read from the multiple first message queues respectively through the multiple control virtual machines; the multiple control virtual machines correspond to the multiple first message queues one by one.

4. The method according to claim 1, characterized in that: The acquiring a plurality of control results obtained by the plurality of control virtual machines and selecting a target result from the plurality of control results includes: For each control virtual machine, writing the obtained control result into a second message queue corresponding to the targeted control virtual machine through the targeted control virtual machine; The control results are obtained from the second message queues corresponding to the multiple control virtual machines respectively through the input and output virtual machines of the programmable logic controller, and the target result is selected from the multiple control results obtained.

5. The method according to any one of claims 1 to 4, characterized in that The selecting a target result from the multiple control results comprises: Selecting a valid result belonging to the current scanning cycle from the multiple control results; When there are multiple valid results, and the multiple valid results are the same, any valid result is used as the target result; When there are multiple valid results, and the multiple valid results are not completely the same, the multiple valid results are divided into at least two result sets, and a target result set containing the largest number of valid results is selected from the at least two result sets, and any valid result in the target result set is used as the target result; valid results belonging to the same result set are the same; When there are multiple valid results and they are not exactly the same, the multiple valid results are divided into at least two result sets. If the target result set cannot be selected, a low-risk virtual machine is selected from the multiple control virtual machines, and the valid results output by the low-risk virtual machine are used as the target results.

6. The method according to claim 5, characterized in that The selecting a valid result belonging to the current scanning cycle from the multiple control results includes: Acquire period labels included in the multiple control results; For each control result, when the period tag of the control result is consistent with the scanning period corresponding to the status data, the control result is taken as a valid result.

7. A redundant control defense device for a programmable logic controller, characterized in that: The device comprises: A data acquisition module, used for determining input data according to the acquired state data, and saving the input data to an input image table; A control module, used for respectively acquiring the input data in the input image table through a plurality of control virtual machines of a programmable logic controller, and processing the input data to obtain a control result; the memory layouts of the plurality of control virtual machines are mutually heterogeneous; A result processing module, used for acquiring a plurality of control results obtained through the plurality of control virtual machines, and selecting a target result from the plurality of control results; The output module is used to write the target result into an output image table and control the execution device based on the target result in the output image table.

8. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 6 when executed by a processor.

10. A computer program product, characterized in that The method comprises computer-executable instructions, which implement the method according to any one of claims 1 to 6 when executed by a processor.

Citation Information

Patent Citations

  • Virtual machine switching system and method

    CN104484231A

  • Available system, and method and program-recording medium thereof

    CN110874261A