Protocol-based distributed security state estimation method in CPS under DoS attack
By designing redundant channels in CPS, introducing polling protocols, considering state saturation and using distributed recursive filtering algorithms, the data loss and state estimation accuracy problems in CPS under DoS attacks are solved, and the system's high-precision and reliable state estimation algorithm is realized in harsh environments.
Patent Information
- Application Number
- CN202510076783.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-01-17
AI Technical Summary
In CPS, DoS attacks cause data loss and communication interruption in sensor measurement data transmission, destroying the accuracy of remote state estimation, and the prior art lacks effective solutions.
Design redundant channels and introduce polling protocols, combining state saturation mechanism and distributed recursive filtering algorithms to ensure that the system performs stable and reliable state estimation algorithms in harsh communication environments.
Improve the success rate of data transmission through redundant channels, polling protocols reduce natural packet loss, state saturation mechanism increases the credibility of estimation results, and distributed recursive filtering algorithm optimizes state estimation accuracy, significantly enhancing the stability and reliability of the system.
Smart Images

Figure CN119966696A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial Internet information security, and discloses a protocol-based distributed security state estimation method in CPS (Cyber-Physical Systems) under DoS (Denial of Service) attacks. Background Art
[0002] CPS is a fusion of physical and computational processes, and is an intelligent system that integrates control, communication, and computing. CPS plays a vital role in many fields such as smart grids and aerospace, and has become one of the core technologies that promote the development of modern industry and technology. Among them, industrial control systems, as one of the typical and important CPS, combine computer monitoring equipment with industrial control components, and are responsible for real-time monitoring of the operating status of industrial systems and controlling the operation of industrial equipment. However, in CPS, the sensor measurement data of the controlled system equipment needs to be transmitted wirelessly to the remote estimator for state estimation. This transmission process usually occurs on unreliable communication channels, making the data extremely vulnerable to malicious attacks during transmission. The openness and sharing of these channels further exacerbate the risks faced during data transmission.
[0003] As the most common attack mode in CPS, DoS attacks have attracted widespread attention due to their significant destructiveness. DoS attacks prevent data from reaching its intended target by deliberately degrading the performance of the transmission channel or consuming limited channel resources, thereby causing sensor measurement data packets to be lost and communication between the control center and the remote terminal to be interrupted, thereby destroying the accuracy of remote state estimation. In recent years, research on DoS attacks has gradually increased, but secure state estimation methods under DoS attacks are still relatively scarce, and new solutions are urgently needed.
[0004] The redundant channel method is an effective means to provide additional protection for data transmission. It deploys a set of parallel channels as transmission media to provide additional data transmission channels when the main channel cannot work normally due to DoS attacks, thereby improving the success rate of data transmission and ensuring the performance of the remote estimator. As a periodic scheduling scheme, the polling protocol can alleviate the congestion problem caused by a large amount of communication data, effectively avoid data conflicts, and reduce the occurrence of natural data packet loss. Therefore, the polling protocol has been widely used in many communication systems.
[0005] However, due to the inherent physical characteristics of hardware modules, the system state is always subject to certain constraints. In order to more accurately describe the actual system, the concept of state saturation is introduced in the study. At present, there are few studies on using redundant channels to overcome the data loss caused by DoS attacks and combining polling protocols to solve the problem of natural packet loss. In addition, considering the state saturation problem increases the authenticity of the system model.
[0006] In summary, the main contributions of the present invention can be summarized as follows: (1) redundant channels are designed to transmit the sensor measurements of the tracked system, and a set of Bernoulli random variables are used to describe the exposure of each channel to DoS attacks; (2) a polling protocol is introduced to minimize data conflicts and reduce natural packet loss in non-attack situations; (3) a more realistic system description is provided by introducing state saturation; (4) a distributed recursive filtering algorithm for saturated systems is established, and the upper bound of the filtering error covariance is obtained and minimized by solving a set of difference equations similar to the Riccati equation. Summary of the invention
[0007] This paper proposes a protocol-based distributed security state estimation method in CPS under DoS attack, aiming to alleviate the impact on the security and state estimation of the system when it is subjected to DoS attack and natural data packet loss in an unreliable network environment. This method provides an effective solution by designing redundant channels, introducing polling protocols, considering state saturation effects, and combining distributed recursive filtering algorithms to ensure the stability and reliability of the system's state estimation algorithm in harsh communication environments.
[0008] The technical solution of the present invention:
[0009] A protocol-based distributed secure state estimation method in CPS under DoS attack is used for discrete-time random state saturation systems. Firstly, redundant channels are designed between each sensor node and the remote estimator. The number of redundant channels is greater than 2. Bernoulli random variables are used to describe whether each channel is affected by DoS attacks. Secondly, a polling protocol scheduling mechanism is adopted to schedule sensor nodes to send data to the remote estimator according to a predetermined periodic scheduling order to reduce data conflicts and natural data packet losses. Then, a state saturation mechanism is introduced to limit the change of system state during the state estimation process, which more realistically describes the physical behavior of the system. Finally, a distributed recursive filtering algorithm is used to calculate the covariance of the filtering error at each moment, and the error is minimized by adjusting the filter parameters to optimize the state estimation accuracy of the system.
[0010] Furthermore, the method specifically includes the following steps:
[0011] Step 1: Redundant channel design
[0012] Multiple redundant channels are configured between the sensor node and the remote estimator, and each channel is described by a Bernoulli random variable as to whether it is available under a DoS attack, thereby ensuring the reliability of data transmission. The number of the redundant channels is at least two to ensure that data can be successfully transmitted through the backup channel when an attack occurs.
[0013] Step 2: Introducing the polling protocol
[0014] The polling protocol is used to schedule sensor nodes to transmit data in a predetermined cycle. By optimizing the scheduling order, the situation where data packets in sensor nodes occupy the communication channel at the same time is alleviated, thereby reducing data conflicts and packet loss rates, ensuring efficient communication.
[0015] Step 3: State Saturation Mechanism
[0016] Introducing the state saturation mechanism, due to the inherent physical characteristics of the hardware module, the state of the system is always limited. Therefore, in order to better reflect the real-world system, we introduce the concept of saturation, which can more realistically describe the system behavior and increase the credibility of the state estimation results.
[0017] Step 4: Distributed recursive filtering algorithm
[0018] By solving the difference equation similar to the Riccati equation, the upper bound of the filter error covariance is calculated. According to the upper bound of the covariance, the filter parameters are adjusted to minimize the error covariance, thereby optimizing the estimation accuracy of the system state.
[0019] In order to evaluate the actual effect of the method of the present invention, we carried out numerical simulation experiments to simulate the impact of attacks on system state estimation. The experimental results show that the introduction of redundant channels and polling protocol methods enables the system to maintain high accuracy of state estimation under DoS attacks and natural packet loss, while significantly enhancing the stability and reliability of the remote estimator.
[0020] Beneficial effects of the present invention: Through the combination of these technical means, the present invention can effectively alleviate the impact of DoS attacks and communication packet loss problems, and ensure the accuracy and reliability of the system's state estimation in complex environments. Through the following innovations, the optimized control of CPS is achieved:
[0021] (1) Redundant channel design: The present invention deploys multiple redundant channels between the sensor and the estimator and uses Bernoulli random variables to describe the exposure of each channel under DoS attacks, thereby improving the success rate of data transmission and the robustness of the system.
[0022] (2) Introduction of polling protocol: In order to solve the problem of natural data packet loss caused by data conflict, the present invention introduces a polling protocol in the data transmission process to alleviate the congestion problem of the communication channel, optimize data scheduling, reduce the packet loss rate, and improve the effectiveness of data transmission.
[0023] (3) State saturation consideration: By introducing the state saturation mechanism and taking into account the constraints of the system under physical hardware and control limitations, it can more realistically reflect the dynamic changes of the actual system and further improve the accuracy of state estimation.
[0024] (4) Distributed recursive filtering algorithm: The present invention proposes a distributed recursive filtering algorithm that utilizes the observation information of each sensor and its neighboring nodes to minimize the filtering error covariance while satisfying the state saturation constraint, thereby improving the accuracy and stability of remote estimation. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 For the system structure.
[0026] Figure 2 The communication topology of the sensor network.
[0027] Figure 3 for The true and estimated values of .
[0028] Figure 4 for The true and estimated values of .
[0029] Figure 5 for The true and estimated values of .
[0030] Figure 6 for and its upper bound.
[0031] Figure 7 for and its upper bound.
[0032] Figure 8 for and its upper bound. DETAILED DESCRIPTION
[0033] The following is combined with Figure 1 , the technical solutions in the embodiments of the present invention are clearly and completely described. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, other embodiments obtained by ordinary technicians in this field without creative work are all within the scope of protection of the present invention. The specific implementation steps are as follows:
[0034] In this method, we use a sensor network consisting of N sensor nodes and utilize an N-order directed weighted graph To describe its topological structure, is a node set, represents the edge set, It means that when (i,j)∈ε, l ij > 0. The node itself plus its adjacent node set can be expressed as express.
[0035] Step 1: Redundant channel design
[0036] In the implementation, W (W>2) redundant channels are configured for each communication channel between the sensor node and the remote estimator. The probability of successful information transmission on each channel is considered as an independent Bernoulli random variable The value is 0 or 1, with the following probabilities: Used to describe whether the channel is affected by DoS attack at any time. is a known scalar. In this way, the system can dynamically select the best transmission path according to the working status of different channels to improve the success rate of data transmission and ensure reliable data delivery even in the environment of malicious attacks. The measurement equation of the sensor can be described as:
[0037]
[0038] in, represents the measured output of sensor i at time k, x k is the unobservable state of the target system, V k represents the measurement noise, D i,k is a time-varying matrix with known appropriate dimensions.
[0039] Step 2: Polling protocol implementation
[0040] In order to reduce the natural loss of data packets, especially during the peak period of data transmission, the present invention introduces a time-based polling protocol. Each sensor node sends data to the remote estimator in turn according to the prescribed polling protocol scheduling order. This protocol can effectively avoid the data conflict problem caused by multiple sensors occupying the channel at the same time, and by optimizing the scheduling mechanism, it can reduce the packet loss rate during data transmission and ensure the efficiency of communication. represents the data received by the corresponding estimator j after transmission through the polling protocol, and is defined as follows:
[0041]
[0042] Among them, n yis the vector dimension of the measurement output, t is a normal number from 0 to ny-1, y j,k-t represents the measured output of sensor j at time kt. When kt≤0, y j,k-t =y j,0 , δ u is the Kronecker function, exponential And η k-t satisfy
[0043] Step 3: State Saturation Mechanism
[0044] In this invention, a state saturation mechanism is introduced to consider the physical constraints of the system state. The state data of each sensor node is limited by the hardware capabilities and control strategies, so the system must model these physical constraints when performing state estimation. By introducing the state saturation model, the behavior of the system can be described more realistically, and the state variables can be properly restricted during the filtering process to prevent the system from being unstable due to overestimation or overcorrection. The physical process is now modeled as a random discrete time-varying state saturation system:
[0045] x k+1 =σ(A k x k +B k u k +w k )
[0046] in, is a known control input, is a covariance Zero mean process noise. and is a matrix of known dimension, is a saturation function, which is defined as follows: When s=1,2,…,n x hour, is the saturation level, n x is the unobservable state vector dimension of the target system.
[0047] Step 4: Distributed recursive filtering algorithm
[0048] The present invention adopts an algorithm based on distributed recursive filtering. Each sensor node not only uses its own data to estimate the state, but also shares information with its neighboring nodes to improve the accuracy of the estimation. The core of the filtering algorithm is to calculate the filtering error covariance (P) at each moment by solving a set of difference equations similar to the Riccati equation. K ), and according to the design parameters (K k) is minimized. At each moment, by calculating the upper bound of the covariance and optimizing it, an accurate estimation of the system state is finally achieved. Based on the above steps, the corresponding distributed recursive filter can be expressed as:
[0049]
[0050] In order to simplify the notation, we define the following expression: A k , B k are two time-varying matrices of known suitable dimensions, Yes x ×n x The identity matrix of dimension Yes y ×n y The identity matrix of dimension yes Expanded to N sensors, is u k The augmentation under N sensors, u k For a known control input We define the error of the i-th filter as: Let μ i (i=1,2,3,4) is a positive scalar, and the initial condition is K k It is known that the upper bound of the filtering error covariance at each moment is It can be calculated that:
[0051]
[0052] in, is the Hadamard product Yes k Augmentation under N sensors, w k is the process noise with zero mean, Yes k Augmentation under N sensors, v k is the zero-mean measurement noise, is the augmentation of D at each sensor ki under N sensors, D 1,k-i represents the time-varying matrix with appropriate dimension known to the first sensor at time ki, yes Augmentation with N sensors.
[0053] By solving The parameter K that minimizes the upper bound of the filtering error covariance can be obtained. k .
[0054] Step 5: Numerical simulation verification
[0055] In order to verify the effectiveness of the proposed method, we conducted multiple numerical simulation experiments to simulate the system state estimation process under attack. The simulation results show that when redundant channels and polling protocols are introduced, the system can maintain high-precision state estimation in the face of DoS attacks and natural data loss, and significantly improve the stability and reliability of the remote estimator. A numerical example is now provided, using a sensor network topology such as Figure 2 As shown,
[0056] Consider tracking the target system parameters:
[0057]
[0058] Each sensor has W = 3 redundant channels, and the sensor parameters are:
[0059]
[0060] Where q = 1, 2, 3, i = 1, 2, 3, 4. The probability that each channel of each sensor is not attacked by DoS is Correlated noise w k and v k are Gaussian white noise with variances of 0.1 and 0.01 respectively. The initial state And the nth x The mean square error (MSE) of a state estimate is defined as:
[0061]
[0062] Among them, n x ∈{1,2,3}, R is the number of Monte Carlo runs, and the specific simulation results are Figure 3-Figure 8 Display
[0063] In the present invention, the sensor network performs bidirectional data exchange with the estimator through a wireless channel. When facing a DoS attack, the system can improve the success rate of data transmission through redundant channels, thereby ensuring the continuity and accuracy of information transmission. At the same time, the use of a polling protocol effectively alleviates the problem of natural data loss caused by data packet collisions, which can further improve the robustness of the system under high load or poor communication conditions.
[0064] This paper introduces the concept of "state saturation" and designs a new distributed filter based on the network topology. The filter can comprehensively utilize the information of each sensor and its neighboring nodes to optimize the state estimation accuracy of the system. Based on this, the upper bound of the filter error covariance at each time step is calculated and the filter parameters are reasonably adjusted to minimize the error, thereby significantly improving the estimation performance of the system.
[0065] Finally, numerical simulation is used to verify the effectiveness and feasibility of the proposed method in improving the accuracy of CPS state estimation under DoS network attack scenarios.
Claims
1. A protocol-based distributed security state estimation method in CPS under DoS attack, for discrete-time random state saturation system; characterized by: First, redundant channels are designed between each sensor node and the remote estimator. The number of redundant channels is greater than 2, and a Bernoulli random variable is used to describe whether each channel is affected by the DoS attack. Secondly, a polling protocol scheduling mechanism is adopted to schedule sensor nodes to send data to the remote estimator according to a predetermined periodic scheduling order to reduce data conflicts and natural data packet losses; Then, a state saturation mechanism is introduced to limit the change of system state during the state estimation process and describe the physical behavior of the system more realistically. Finally, a distributed recursive filtering algorithm is used to calculate the filtering error covariance at each moment, and minimize the error by adjusting the filter parameters to optimize the state estimation accuracy of the system.
2. According to claim 1, a distributed security state estimation method based on protocol in CPS under DoS attack is characterized by: A sensor network consisting of N sensor nodes is used, and an N-order directed weighted graph is used To describe its topological structure, is a node set, represents the edge set, It means that when (i,j)∈ε, l ij >0 weighted adjacency matrix; the node itself plus its adjacent node set can be used express.
3. According to the protocol-based distributed security state estimation method in a CPS under DoS attack in claim 2, the step 1 is specifically: configuring W redundant channels for the communication channel between each sensor node and the remote estimator; the probability of successful information transmission of each channel is regarded as an independent Bernoulli random variable The value is 0 or 1, with the following probabilities: Used to describe whether the channel is affected by DoS attack at any time. is a known scalar; in this way, the system can dynamically select the best transmission path according to the working status of different channels to improve the success rate of data transmission and ensure reliable data delivery even in the environment of malicious attacks; the measurement equation of the sensor can be described as: in, represents the measured output of sensor i at time k, x k is the unobservable state of the target system, v k represents the measurement noise, D i,k is a time-varying matrix with known appropriate dimensions.
4. According to the protocol-based distributed security state estimation method in CPS under DoS attack according to claim 3, the step 2 is specifically: A time-based polling protocol is introduced; each sensor node sends data to the remote estimator in turn according to the prescribed polling protocol scheduling order; this protocol can avoid data conflicts caused by multiple sensors occupying the channel at the same time, and reduce the packet loss rate during data transmission by optimizing the scheduling mechanism to ensure efficient communication; represents the data received by the corresponding estimator j after transmission through the polling protocol, and is defined as follows: in, n y is the vector dimension of the measurement output, t is a normal number from 0 to ny-1, y j,k-t represents the measured output of sensor j at time kt. When kt≤0, y j,k-t =y j,0 , δ u is the Kronecker function, exponential And η k-t satisfy 5. According to the protocol-based distributed security state estimation method in CPS under DoS attack according to claim 4, the step three is specifically: The state saturation mechanism is introduced to consider the physical constraints of the system state. The state data of each sensor node is limited by the hardware capabilities and control strategies. Therefore, when the system performs state estimation, these physical constraints must be modeled. By introducing the state saturation model, the behavior of the system is truly described, and the state variables are restricted during the filtering process to prevent the system from being unstable due to over-estimation or over-correction. The physical process is now modeled as a random discrete time-varying state saturation system: x k+1 =σ(A k x k +B k u k +w k ) in, is a known control input, is a covariance Zero mean process noise; and is a matrix of known dimension, is a saturation function, which is defined as follows: When s=1,2,...,n x hour, is the saturation level; n x is the unobservable state vector dimension of the target system.
6. According to the protocol-based distributed security state estimation method in CPS under DoS attack according to claim 5, the step 4 is specifically: Each sensor node not only uses its own data for state estimation, but also shares information with its neighboring nodes to improve the accuracy of the estimation; The filtering algorithm is to solve the difference equation and calculate the filtering error covariance P at each moment. K , and according to the design parameter K k Minimize it; At each moment, by calculating the upper bound of the covariance and optimizing it, an accurate estimation of the system state is finally achieved; based on the above steps, the corresponding distributed recursive filter can be expressed as: In order to simplify the symbols, the following expressions are defined: A k , B k are two time-varying matrices of known suitable dimensions, Yes x ×n x The identity matrix of dimension Yes y ×n y The identity matrix of dimension yes Expanded to N sensors, is u k Augmentation under N sensors, u k For a known control input The error of the i-th filter is defined as: (i=1,2,…,N), let μ i (i=1,2,3,4) is a positive scalar, and the initial condition is K k It is known that the upper bound of the filtering error covariance at each moment is It can be calculated that: in, is the Hadamard product Yes k Augmentation under N sensors, w k is the process noise with zero mean, Yes k Augmentation under N sensors, v k is the zero-mean measurement noise, is the augmentation of D at each sensor ki under N sensors, D 1,k-i represents the time-varying matrix with appropriate dimension known to the first sensor at time ki, yes Augmentation under N sensors; By solving The parameter K that minimizes the upper bound of the filtering error covariance can be obtained. k .
Citation Information
Patent Citations
CPS-based random event trigger security state estimation method and related device
CN116150759A
Remote state estimation method based on polling protocol
CN116527515A
Method for evaluating state estimation performance based on polling communication protocol under DoS attack
CN118827237A
Detection and protection against mode switching attacks in cyber-physical systems
US20200125978A1