A protocol-based distributed security state estimation method in CPS under DoS attacks
By designing redundant channels in the CPS system, introducing a polling protocol and a state saturation mechanism, and combining it with a distributed recursive filtering algorithm, the data loss problem caused by DoS attacks is solved, and high-precision state estimation of the system is achieved in harsh environments.
Patent Information
- Application Number
- CN202510076783.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-01-17
AI Technical Summary
In CPS systems, DoS attacks lead to the loss of sensor measurement data packets, interruption of communication between the control center and remote terminals, and destruction of the accuracy of remote state estimation. Existing technologies lack effective and secure state estimation methods.
Redundant channels are designed, polling protocols and state saturation mechanisms are introduced, and distributed recursive filtering algorithms are combined to describe channel states through Bernoulli random variables to optimize data transmission and state estimation.
Under DoS attacks, the data transmission success rate is improved, natural packet loss is reduced, the accuracy and stability of system state estimation are ensured, and the reliability of the remote estimator is enhanced.
Smart Images

Figure CN119966696B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial Internet information security and discloses a protocol-based distributed security state estimation method in CPS (Cyber-Physical Systems) under DoS (Denial of Service) attacks. Background Art
[0002] CPSs are the fusion of physical and computational processes, and are intelligent systems integrating control, communication, and computing. They play a vital role in a variety of fields, including smart grids and aerospace, and have become one of the core technologies driving the development of modern industry and technology. Industrial control systems, a typical and important type of CPS, combine computer monitoring equipment with industrial control components to monitor the operating status of industrial systems in real time and control the operation of industrial equipment. However, in CPSs, sensor measurement data from controlled system devices needs to be wirelessly transmitted to a remote estimator for state estimation. This transmission process often occurs over unreliable communication channels, making the data extremely vulnerable to malicious attacks during transmission. The openness and shared nature of these channels further exacerbate the risks associated with data transmission.
[0003] Denial of Service (DoS) attacks, the most common attack mode in CPSs, have garnered widespread attention due to their significant destructive potential. DoS attacks intentionally degrade the performance of transmission channels or consume limited channel resources, preventing data from reaching its intended target. This leads to the loss of sensor measurement packets, disrupting communication between the control center and remote terminals, and ultimately undermining the accuracy of remote state estimation. While research on DoS attacks has steadily increased in recent years, secure state estimation methods under DoS attacks remain relatively scarce, necessitating the urgent need for new solutions.
[0004] Redundant channel methods are an effective means of providing additional security for data transmission. By deploying a set of parallel channels as the transmission medium, they provide additional data transmission channels when the primary channel fails due to a DoS attack, thereby improving the success rate of data transmission and guaranteeing the performance of the remote estimator. Polling protocols, as a periodic scheduling scheme, can alleviate the congestion caused by large amounts of communication data, effectively avoid data conflicts, and reduce the occurrence of natural packet loss. Therefore, polling protocols have been widely used in many communication systems.
[0005] However, due to the inherent physical properties of hardware modules, system states are always subject to certain constraints. To more accurately describe real-world systems, this research introduces the concept of state saturation. Currently, research on using redundant channels to overcome data loss caused by DoS attacks and combining polling protocols to address natural packet loss is rare. Furthermore, considering state saturation increases the realism of system models.
[0006] In summary, the main contributions of the present invention can be summarized as follows: (1) redundant channels are designed to transmit sensor measurements of the tracked system, and a set of Bernoulli random variables are used to describe the exposure of each channel to DoS attacks; (2) a polling protocol is introduced to minimize data conflicts and reduce natural packet loss in non-attack situations; (3) a more realistic system description is provided by introducing state saturation; (4) a distributed recursive filtering algorithm for saturated systems is established, and the upper bound of the filtering error covariance is obtained and minimized by solving a set of difference equations similar to the Riccati equation. Summary of the Invention
[0007] This paper proposes a protocol-based distributed secure state estimation method for CPSs under DoS attacks. This method aims to mitigate the impact of DoS attacks and natural packet loss on system security and state estimation in unreliable network environments. By designing redundant channels, introducing a polling protocol, and considering state saturation effects, this method, combined with a distributed recursive filtering algorithm, provides an effective solution to ensure the stability and reliability of the system's state estimation algorithm in harsh communication environments.
[0008] The technical solution of the present invention:
[0009] A protocol-based distributed secure state estimation method for CPSs under DoS attacks is proposed for discrete-time stochastic state saturation systems. First, redundant channels are designed between each sensor node and a remote estimator, with the number of redundant channels exceeding two. Bernoulli random variables are used to describe whether each channel is susceptible to DoS attacks. Second, a round-robin protocol scheduling mechanism is employed to schedule sensor nodes to send data to the remote estimator according to a predetermined periodic scheduling order, reducing data conflicts and natural packet loss. A state saturation mechanism is then introduced to constrain system state changes during state estimation, providing a more realistic description of the system's physical behavior. Finally, a distributed recursive filtering algorithm is employed to calculate the covariance of the filtering error at each moment. The error is minimized by adjusting the filter parameters to optimize the system's state estimation accuracy.
[0010] Furthermore, the method specifically includes the following steps:
[0011] Step 1: Redundant channel design
[0012] Multiple redundant channels are configured between the sensor node and the remote estimator. Each channel uses a Bernoulli random variable to describe whether it is available under a DoS attack, thereby ensuring the reliability of data transmission. The number of redundant channels is at least two to ensure that data can be successfully transmitted through the backup channel in the event of an attack.
[0013] Step 2: Introducing the polling protocol
[0014] A polling protocol is used to schedule sensor nodes to transmit data sequentially according to a predetermined period. By optimizing the scheduling order, the situation where data packets from sensor nodes simultaneously occupy the communication channel is alleviated, thereby reducing data conflicts and packet loss rates, ensuring efficient communication.
[0015] Step 3: State Saturation Mechanism
[0016] Introducing a state saturation mechanism: Due to the inherent physical properties of hardware modules, the state of a system is always limited. Therefore, to better reflect real-world systems, we introduce the concept of saturation, which more realistically describes system behavior and increases the credibility of state estimation results.
[0017] Step 4: Distributed recursive filtering algorithm
[0018] By solving the difference equation similar to the Riccati equation, the upper bound of the filter error covariance is calculated. According to the upper bound of the covariance, the filter parameters are adjusted to minimize the error covariance, thereby optimizing the estimation accuracy of the system state.
[0019] To evaluate the effectiveness of our method, we conducted numerical simulations to simulate the impact of attacks on system state estimation. The results show that the introduction of redundant channels and a polling protocol enables the system to maintain high state estimation accuracy despite DoS attacks and natural packet loss, while significantly enhancing the stability and reliability of the remote estimator.
[0020] Beneficial effects of the present invention: By combining these technical means, the present invention can effectively alleviate the impact of DoS attacks and communication packet loss problems, ensuring the accuracy and reliability of the system's state estimation in complex environments. Through the following innovations, optimized control of CPS is achieved:
[0021] (1) Redundant channel design: The present invention deploys multiple redundant channels between the sensor and the estimator and uses Bernoulli random variables to describe the exposure of each channel to DoS attacks, thereby improving the success rate of data transmission and the robustness of the system.
[0022] (2) Introduction of polling protocol: In order to solve the problem of natural data packet loss caused by data conflicts, the present invention introduces a polling protocol in the data transmission process to alleviate the congestion problem of the communication channel, optimize data scheduling, reduce the packet loss rate, and improve the effectiveness of data transmission.
[0023] (3) State saturation consideration: By introducing the state saturation mechanism and taking into account the constraints of the system under physical hardware and control limitations, it can more realistically reflect the dynamic changes of the actual system and further improve the accuracy of state estimation.
[0024] (4) Distributed recursive filtering algorithm: This paper proposes a distributed recursive filtering algorithm that uses the observation information of each sensor and its neighboring nodes to minimize the filtering error covariance while satisfying the state saturation constraint, thereby improving the accuracy and stability of remote estimation. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 For the system structure.
[0026] Figure 2 The communication topology of the sensor network.
[0027] Figure 3 for The true and estimated values of .
[0028] Figure 4 for The true and estimated values of .
[0029] Figure 5 for The true and estimated values of .
[0030] Figure 6 for and its upper bound.
[0031] Figure 7 for and its upper bound.
[0032] Figure 8 for and its upper bound. DETAILED DESCRIPTION
[0033] The following is combined with Figure 1 , clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, other embodiments obtained by ordinary technicians in this field without making creative work are all within the scope of protection of the present invention. The specific implementation steps are as follows:
[0034] In this method, we use a sensor network consisting of N sensor nodes and utilize an N-order directed weighted graph To describe its topology, is a node set, represents the edge set, Indicates that when (i, j)∈ε, l ij The weighted adjacency matrix of the node itself plus its adjacent nodes can be expressed as express.
[0035] Step 1: Redundant channel design
[0036] In the implementation process, W (W>2) redundant channels are configured for each communication channel between the sensor node and the remote estimator. The probability of successful information transmission of each channel is regarded as an independent Bernoulli random variable The value is 0 or 1, with the following probabilities: Used to describe whether the channel is affected by DoS attack at any time, where is a known scalar. In this way, the system can dynamically select the optimal transmission path based on the working status of different channels to improve the success rate of data transmission and ensure reliable data delivery even in the environment of malicious attacks. The measurement equation of the sensor can be described as:
[0037]
[0038] in, represents the measurement output of sensor i at time k, x k is the unobservable state of the target system, V k represents the measurement noise, D i,k is a time-varying matrix with known appropriate dimensions.
[0039] Step 2: Polling protocol implementation
[0040] In order to reduce the natural loss of data packets, especially during peak data transmission periods, this invention introduces a time-based polling protocol. Each sensor node sends data to the remote estimator in sequence according to the prescribed polling protocol scheduling order. This protocol can effectively avoid data conflicts caused by multiple sensors occupying the channel at the same time, and by optimizing the scheduling mechanism, it can reduce the packet loss rate during data transmission and ensure efficient communication. represents the data received by the corresponding estimator j after transmission through the polling protocol and is defined as follows:
[0041]
[0042] Among them, n yis the vector dimension of the measurement output, t is a normal number from 0 to ny-1, y j,k-t Represents the measurement output of sensor j at time kt. When kt≤0, y j,k-t =y j,0 , δ u is the Kronecker function, exponential And η k-t satisfy
[0043] Step 3: State Saturation Mechanism
[0044] In this invention, a state saturation mechanism is introduced to account for the physical constraints of the system state. The state data of each sensor node is limited by the hardware capabilities and control strategy, so the system must model these physical constraints when performing state estimation. By introducing a state saturation model, the behavior of the system can be more realistically described, and appropriate restrictions can be placed on the state variables during the filtering process to prevent system instability caused by overestimation or overcorrection. The physical process is now modeled as a random discrete time-varying state saturation system:
[0045] x k+1 =σ(A k x k +B k u k +w k )
[0046] in, is a known control input, is a covariance Zero mean process noise. and is a matrix of known dimension, is a saturation function, which is defined as follows: When s=1,2,…,n x hour, is the saturation level, n x is the unobservable state vector dimension of the target system.
[0047] Step 4: Distributed recursive filtering algorithm
[0048] The present invention adopts an algorithm based on distributed recursive filtering. Each sensor node not only uses its own data to estimate the state, but also shares information with its neighboring nodes to improve the accuracy of the estimation. The core of the filtering algorithm is to calculate the filtering error covariance (P) at each moment by solving a set of difference equations similar to the Riccati equation. K ), and according to the design parameters (K k) is minimized. At each moment, by calculating the upper bound of the covariance and optimizing it, an accurate estimation of the system state is finally achieved. Based on the above steps, the corresponding distributed recursive filter can be expressed as:
[0049]
[0050] In order to simplify the symbols, we define the following expression: A k 、B k are two time-varying matrices of known suitable dimensions, is n x ×n x The identity matrix of dimension is n y ×n y The identity matrix of dimension yes Expanded to N sensors, is u k Augmentation under N sensors, u k For a known control input We define the error of the i-th filter as: Let μ i (i=1,2,3,4) is a positive scalar, and the initial conditions are K k It is known that the upper bound of the filtering error covariance at each moment is It can be calculated that:
[0051]
[0052] in, is the Hadamard product It is w k Augmentation under N sensors, w k is the process noise with zero mean, It is v k Augmentation under N sensors, v k is the zero-mean measurement noise, is the augmentation of D of each sensor ki under N sensors, D 1,k-i represents the time-varying matrix with appropriate dimensions known to the first sensor at time ki, yes Augmentation with N sensors.
[0053] By solving The parameter K that minimizes the upper bound of the filtering error covariance can be obtained. k .
[0054] Step 5: Numerical simulation verification
[0055] To verify the effectiveness of the proposed method, we conducted multiple numerical simulation experiments to simulate the system state estimation process under attack. The simulation results show that by introducing redundant channels and polling protocols, the system can maintain high-precision state estimation in the face of DoS attacks and natural data loss, and significantly improve the stability and reliability of the remote estimator. A numerical example is provided, using the sensor network topology as follows: Figure 2 As shown,
[0056] Consider tracking the target system parameters as follows:
[0057]
[0058] Each sensor has W=3 redundant channels, and the sensor parameters are:
[0059]
[0060] Where q = 1, 2, 3, i = 1, 2, 3, 4. The probability that each channel of each sensor is not attacked by DoS is Correlated noise w k and v k are Gaussian white noise with variances of 0.1 and 0.01 respectively. The initial state And the nth x The mean square error (MSE) of a state estimate is defined as:
[0061]
[0062] Among them, n x ∈{1,2,3}, R is the number of Monte Carlo runs, and the specific simulation results are in Figure 3-Figure 8 Display
[0063] In this invention, the sensor network exchanges bidirectional data with the estimator via a wireless channel. When faced with a DoS attack, the system can improve the success rate of data transmission through redundant channels, thereby ensuring the continuity and accuracy of information transmission. Furthermore, the use of a polling protocol effectively mitigates the problem of natural data loss caused by packet collisions, further improving the system's robustness under high load or adverse communication conditions.
[0064] This paper introduces the concept of "state saturation" and designs a new distributed filter based on network topology. This filter comprehensively utilizes information from each sensor and its neighboring nodes to optimize the system's state estimation accuracy. Based on this, the system's estimation performance is significantly improved by calculating the upper bound of the filter error covariance at each time step and rationally adjusting the filter parameters to minimize the error.
[0065] Finally, numerical simulation is used to verify the effectiveness and feasibility of the proposed method in improving the accuracy of CPS state estimation under DoS network attack scenarios.
Claims
1. A protocol-based distributed security state estimation method for CPS under DoS attack, for discrete-time random state saturation system; characterized by: In the first step, redundant channels are designed between each sensor node and the remote estimator. The number of redundant channels is greater than 2, and Bernoulli random variables are used to describe whether each channel is affected by the DoS attack. In the second step, a polling protocol scheduling mechanism is used to schedule sensor nodes to send data to the remote estimator according to a predetermined periodic scheduling order to reduce data conflicts and natural data packet loss. In the third step, a state saturation mechanism is introduced to limit the changes in the system state during the state estimation process, more realistically describing the physical behavior of the system. In the fourth step, a distributed recursive filtering algorithm is used to calculate the covariance of the filtering error at each moment, and the error is minimized by adjusting the filter parameters to optimize the state estimation accuracy of the system. The step 1 is specifically as follows: configure W redundant channels for each communication channel between the sensor node and the remote estimator; the probability of successful information transmission of each channel is regarded as an independent Bernoulli random variable The value is 0 or 1, with the following probabilities: Used to describe whether the channel is affected by DoS attack at any time, where is a known scalar. In this way, the system can dynamically select the optimal transmission path based on the working status of different channels to improve the success rate of data transmission and ensure reliable data delivery even in the environment of malicious attacks. The measurement equation of the sensor can be described as: in, represents the measurement output of sensor i at time k, x k is the unobservable state of the target system, ν k represents the measurement noise, D i,k is a time-varying matrix with known appropriate dimensions; The step 2 is specifically as follows: A time-based polling protocol is introduced; each sensor node sends data to the remote estimator in sequence according to the prescribed polling protocol scheduling order; this protocol can avoid data conflicts caused by multiple sensors occupying the channel at the same time, and by optimizing the scheduling mechanism, it can reduce the packet loss rate during data transmission and ensure the efficiency of communication; represents the data received by the corresponding estimator j after transmission through the polling protocol and is defined as follows: Among them, n y Is the vector dimension of the measurement output, t is a number from 0 to n y -1 ordinary number, y j,k-t Represents the measurement output of sensor j at time kt. When kt≤0, y j,k-t =y j,0 , δ u is the Kronecker function, exponential And η k-t satisfy The step three is specifically as follows: A state saturation mechanism is introduced to account for the physical constraints of the system state. The state data of each sensor node is limited by hardware capabilities and control strategies. Therefore, when the system performs state estimation, these physical constraints must be modeled. By introducing a state saturation model, the system behavior is realistically described, and state variables are restricted during the filtering process to prevent system instability caused by overestimation or overcorrection. The physical process is now modeled as a random discrete time-varying state saturation system: x k+1 =σ(A k x k +B k u k +w k ) in, is a known control input, is a covariance Zero-mean process noise; and is a matrix of known dimension, is a saturation function, which is defined as follows: When s=1,2,…,n x hour, is the saturation level; n x is the unobservable state vector dimension of the target system; The step four is specifically as follows: Each sensor node not only uses its own data to estimate the state, but also shares information with its neighboring nodes to improve the accuracy of the estimation. The filtering algorithm calculates the filtering error covariance P at each moment by solving the difference equation. K , and according to the design parameter K k Minimize it; at each moment, by calculating the upper bound of the covariance and optimizing it, the accurate estimation of the system state is finally achieved; based on the above steps, the corresponding distributed recursive filter can be expressed as: In order to simplify the symbols, the following expressions are defined: A k 、B k are two time-varying matrices of known suitable dimensions, is n x ×n x The identity matrix of dimension is n y ×n y The identity matrix of dimension yes Expanded to N sensors, is u k Augmentation under N sensors, u k is a known control input; The error of the i-th filter is defined as: Let μ i (i=1,2,3,4) is a positive scalar, and the initial conditions are K k It is known that the upper bound of the filtering error covariance at each moment is It can be calculated that: in, is the Hadamard product, It is w k Augmentation under N sensors, w k is the process noise with zero mean, It is v k Augmentation under N sensors, v k is the zero-mean measurement noise, is the augmentation of D of each sensor ki under N sensors, D 1,k-i represents the time-varying matrix with appropriate dimensions known to the first sensor at time ki, yes Augmentation under N sensors; By solving The parameter K that minimizes the upper bound of the filtering error covariance can be obtained. k .
2. The method for estimating the protocol-based distributed security status in a CPS under a DoS attack according to claim 1, characterized in that: A sensor network consisting of N sensor nodes is used, and an N-order directed weighted graph is used To describe its topology, is a node set, represents the edge set, Indicates that when (i, j)∈ε, l ij >0 weighted adjacency matrix; the node itself plus its adjacent node set can be used express.