X86 industrial control mainboard identity authentication system based on multi-mode fusion
Through the multimodal fusion identity authentication system, combined with the attention mechanism, feature weighted fusion is solved, and the problem of difficult to guarantee the identity credibility of the X86 industrial control motherboard is realized, efficient detection of composite attacks and perception of advanced threats is achieved, ensuring the security and reliability of the equipment.
Patent Information
- Application Number
- CN202510669299.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-06-20
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In industrial Internet of Things and intelligent manufacturing scenarios, the identity credibility of the X86 industrial control motherboard is difficult to guarantee. Attackers may bypass traditional authentication mechanisms by tampering with hardware fingerprints, implanting malicious firmware or emulating environmental features, resulting in device out of control or data leakage.
The identity authentication system based on multimodal fusion is adopted, and the weighted fusion of static and dynamic features is achieved through the hardware feature acquisition module, firmware behavior acquisition module, environmental feature acquisition module, modal data synchronization module, forged feature simulation module, trustworthiness verification module and identity authentication response module, combined with the attention mechanism, the weighted fusion of static and dynamic features is achieved to achieve identity authentication and response.
Through multimodal correlation analysis, multi-level identity portraits are built to improve the detection ability of composite attacks, enhance the perception of advanced threats, and achieve hierarchical response based on credibility scores to ensure the security and reliability of the device.
Smart Images

Figure CN120180419A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of motherboard identity authentication, and specifically relates to an X86 industrial control motherboard identity authentication system based on multimodal fusion. Background Art
[0002] In industrial Internet of Things and intelligent manufacturing scenarios, as the core control unit, the identity credibility of the X86 industrial control motherboard is directly related to production safety. Attackers may bypass traditional authentication mechanisms by tampering with hardware fingerprints, implanting malicious firmware, or simulating environmental characteristics, resulting in equipment out of control or data leakage.
[0003] Modern attack means show dynamic and hidden characteristics. Traditional static authentication mechanisms are difficult to detect runtime anomalies, while the dynamic feature weighted fusion technology based on the attention mechanism can capture key signals such as firmware behavior offsets and network timing anomalies in real time, strengthening the response ability to advanced threats. Summary of the Invention
[0004] To solve the above technical problems, an X86 industrial control motherboard identity authentication system based on multimodal fusion is provided, and the technical solution solves the problems proposed in the above background art.
[0005] To achieve the above purposes, the technical solution adopted by the present invention is as follows: An X86 industrial control motherboard identity authentication system based on multimodal fusion, comprising: A hardware feature acquisition module, which is used to obtain a key through a trusted password module chip, generate a dynamic hardware fingerprint in combination with the cache topology and instruction latency of the X86 central processing unit, collect physical unclonable function features of power supply noise and clock jitter using a dedicated sensor on the motherboard, and generate a circuit fingerprint in combination with the difference in the resistance distribution of the printed circuit board wiring; A firmware behavior acquisition module, which is used to record the loading order, memory mapping, and interrupt vector table configuration of the firmware, generate a firmware execution track, record dynamic behaviors such as call chains and interrupt handling latencies through the hardware virtualization technology of the X86, and build a firmware runtime feature library; An environmental feature acquisition module, which is used to integrate motherboard-level environmental sensors, collect spatio-temporal features of the device deployment environment, generate an environmental fingerprint in combination with geofencing technology, capture the timing features of network data packets through the link layer monitor of the motherboard, and generate a network behavior portrait in combination with the device topology relationship; A modal data synchronization module, which is used to synchronize timestamps for the hardware fingerprint, circuit fingerprint, firmware behavior, environmental fingerprint, and network behavior, and eliminate the time offset of at least one modal data; A forgery feature simulation module, which is used to simulate fingerprint data tampering attacks through a generative adversarial network and train a robust classifier to identify forgery features; A credibility verification module, which is used to weight and fuse static features and dynamic features through an attention mechanism to highlight the impact of runtime abnormal behaviors on identity credibility. The static features include hardware fingerprints, circuit fingerprints, and environmental fingerprints, and the dynamic features include firmware behaviors and network behaviors; An identity authentication response module, which is used to trigger corresponding authentication policies based on the identity credibility score and implement irreversible response execution. The authentication policies include warnings, restricted functions, and system locks.
[0006] Preferably, the hardware feature acquisition module specifically includes: The trusted password module generates a root key based on the unique hardware identifier built into the chip, calculates a session key through a hash algorithm, and generates a dynamic key by combining the current timestamp and a random number; Perform an exclusive OR operation on the dynamic key and the cache sharing topology feature of the central processing unit to generate a key bound to the hardware architecture; In the processor core, execute a specific instruction sequence in a loop, read the processor information and timestamp, measure the number of time cycles required for instruction execution, record its fluctuation range, and dynamically adjust the delay measurement value in combination with the processor temperature change, and perform linear weighted correction on the delay value; By forcibly refreshing the cache and measuring the delay difference between at least two cores accessing the same memory area, obtain the cores sharing the same cache block, construct a cache sharing topology structure diagram, convert the topology structure into a binary code, and generate a fixed-length feature code through a hash algorithm; In the idle state of the processor, repeatedly execute basic arithmetic instructions and count the average delay time of instruction execution. The basic arithmetic instructions include addition and exclusive OR instructions; Combine the processor load rate and temperature data to perform non-linear correction on the reference delay and generate delay features adapted to each operating state; Use the voltage monitoring chip on the motherboard to collect voltage fluctuation data of the power supply line, record the instantaneous voltage value, perform spectral analysis on the voltage fluctuation data, and calculate the complexity of its frequency distribution as the uniqueness feature of the power supply noise; By capturing the clock signal of the processor, measure the time interval between adjacent clock rising edges, count its fluctuation range and distribution law, convert the clock jitter data into standard deviation and skewness statistics, and extract high-frequency jitter components in combination with Fourier transform to generate a multi-dimensional jitter feature vector; Inject a constant current at both ends of the memory bus signal path of the circuit board, measure the voltage drop on the path, calculate the actual resistance value, compare the measured resistance value with the theoretical design value, calculate the resistance deviation rate of each path, and generate a feature vector reflecting the manufacturing process differences of the circuit board; Map the resistance deviation rate to the two-dimensional coordinate system of the circuit board to form a heat map of the resistance value distribution, and perform a discrete cosine transform on the heat map as the unique fingerprint feature of the circuit board.
[0007] Preferably, the firmware behavior acquisition module specifically includes: When the computer starts up, after the power supply is stably powered, the main board control chipset removes the reset signal, and the central processing unit starts to execute instructions from the fixed address of the system basic input / output system; Perform a power-on self-test, sequentially detect the core hardware of the memory and the graphics card, and test the conventional memory area during the memory detection; Generate a memory mapping table according to the hardware configuration, and allocate physical memory, video memory, and input / output port resources to at least two address spaces; Record the start address, end address, and type of the physical memory in the memory mapping table, and analyze whether the memory block allocation strategy is continuous allocation or discontinuous allocation; The interrupt vector table is located at the memory start address 0, stores the segment address and offset address of the interrupt service routine. After entering the protected mode, the interrupt vector table is replaced by the interrupt descriptor table and can be stored at any memory location; Traverse the interrupt vector table and the interrupt descriptor table, record the entry addresses of the service routines corresponding to each interrupt, and analyze the interrupt processing flow; Decompose the interrupt processing delay into the interrupt response time, the execution time of the interrupt service routine, and the context switch time. The interrupt response time is from the interrupt trigger to the processor starting to execute the first instruction of the interrupt service routine, and the context switch time is recorded as the register save and restore overhead time; Save the return address and the stack frame pointer when a function is called, construct a function call chain, analyze the depth and width of the call chain, and identify the core functions called and potential recursive calls; Associate the instruction execution trace, the call chain, and the context snapshot to form a complete execution trace, and compress the trace data using differential coding and hash algorithms; In a virtualized environment, through dynamic instrumentation technology, insert hook functions when a function is called and returns, record the real-time changes of the call chain, analyze the branch probability, loop count, and call frequency of the call chain, and identify hot functions and abnormal call paths; Fuse the firmware loading order, memory mapping, interrupt vector table configuration, execution trace, call chain, interrupt processing delay, and hardware virtualization dynamic behavior characteristics, and use the feature vector splicing or graph structure representation method to construct a firmware runtime feature library.
[0008] Preferably, the environmental feature acquisition module specifically includes: Deploy six types of environmental sensors including temperature, humidity, air pressure, light, acceleration, and magnetic field on the main board, and the sensors communicate with the main board management controller; The sensors generate a data frame at each same interval, and the data frame includes the current values of each sensor and the time stamp; The three-axis data of the acceleration sensor is used to calculate the device attitude angle through vector synthesis, and the air pressure data is combined to estimate the altitude change of the device; Obtain the longitude and latitude coordinates of the device, delimit a polygonal fence area on the electronic map, and use the ray casting method to determine whether the device is located within the fence. When the coordinates are outside the fence for 3 consecutive times, an out-of-bounds alarm is triggered; Statistically calculate the mean and variance of the environmental data of the device within at least one time period within the fence to generate an environmental baseline model; Deploy a link layer monitor between the network card chips on the main board, copy all incoming and outgoing data packets through the mirror port, and capture the five-tuple, time stamp, data packet length, and frame check sequence error flag of the data packet. The five-tuple includes the source IP, destination IP, source port, destination port, and protocol type; Calculate the periodicity of the data packet arrival rate through the autocorrelation function to identify periodic scanning behaviors, statistically calculate the delay distribution of retransmitted packets, calculate the average delay, maximum delay, and delay variance, and generate a delay jitter feature vector; Collect the mapping relationship between the MAC address and IP address of active devices in the local area network to generate an initial topology map; Listen to the link layer discovery protocol packets in the network, extract the device model, port identifier, and management IP address, and improve the device attribute information of the topology map; Draw a device topology map, where the size of the node represents the importance of the device, and the thickness of the edge represents the size of the communication traffic.
[0009] Compared with the prior art, the beneficial effects of the present invention are as follows: Through the cross-modal correlation analysis of hardware fingerprints, circuit fingerprints, firmware behaviors, environmental fingerprints, and network behaviors, a multi-level identity portrait is constructed to improve the detection ability of composite attacks. Based on the X86 hardware virtualization technology, the firmware call chain and interrupt latency are recorded, combined with the timing characteristics of network data packets, runtime anomalies are captured in real time, the perception ability of advanced threats is enhanced, and the weights of static features and dynamic features are dynamically adjusted through the attention mechanism to highlight the impact of runtime abnormal behaviors, realizing hierarchical response based on credibility scoring. Description of the Drawings
[0010] Figure 1 It is the flowchart of the X86 industrial control main board identity authentication system based on multi-modal fusion of the present invention; Figure 2It is the system flowchart of the hardware feature acquisition module of the present invention; Figure 3 It is the system flowchart of the firmware behavior acquisition module of the present invention; Figure 4 It is the system flowchart of the environmental feature acquisition module of the present invention; Figure 5 It is the system flowchart of the modal data synchronization module of the present invention; Figure 6 It is the system flowchart of the forgery feature simulation module of the present invention; Figure 7 It is the system flowchart of the credibility verification module of the present invention. Specific implementation manners
[0011] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variations.
[0012] Referring to Figure 1 As shown, an X86 industrial control motherboard identity authentication system based on multi-modal fusion includes: A hardware feature acquisition module, which is used to obtain a key through a trusted password module chip, generate a dynamic hardware fingerprint by combining the cache topology and instruction latency of the X86 central processing unit, collect physical unclonable function features of power supply noise and clock jitter using a dedicated sensor on the motherboard, and generate a circuit fingerprint by combining the difference in the resistance distribution of the printed circuit board wiring; A firmware behavior acquisition module, which is used to record the loading sequence, memory mapping, and interrupt vector table configuration of the firmware, generate a firmware execution track, record the dynamic behaviors of the call chain and interrupt handling latency through the hardware virtualization technology of X86, and build a firmware runtime feature library; An environmental feature acquisition module, which is used to integrate motherboard-level environmental sensors, collect the spatio-temporal features of the device deployment environment, generate an environmental fingerprint by combining geofencing technology, capture the timing features of network packets through the link layer monitor of the motherboard, and generate a network behavior portrait by combining the device topology relationship; A modal data synchronization module, which is used to synchronize the timestamps of the hardware fingerprint, circuit fingerprint, firmware behavior, environmental fingerprint, and network behavior, and eliminate the time offset of at least one modal data; A forgery feature simulation module, which is used to simulate fingerprint data tampering attacks through a generative adversarial network and train a robust classifier to identify forgery features; A credibility verification module, which is used to perform weighted fusion of static features and dynamic features through an attention mechanism to highlight the impact of abnormal runtime behaviors on identity credibility. The static features include hardware fingerprints, circuit fingerprints, and environmental fingerprints, and the dynamic features include firmware behaviors and network behaviors; An identity authentication response module, which is used to trigger corresponding authentication policies based on the identity credibility score and implement irreversible response execution. The authentication policies include warnings, restricted functions, and system locks.
[0013] Refer to Figure 2 As shown, the hardware feature acquisition module specifically includes: The trusted password module generates a root key based on the unique hardware identifier built into the chip, calculates the session key through a hashing algorithm, and generates a dynamic key by combining the current timestamp and a random number; Perform an exclusive OR operation on the dynamic key and the cache sharing topology feature of the central processing unit to generate a key bound to the hardware architecture; Execute a specific instruction sequence in the processor core loop, read the processor information and timestamp, measure the number of time cycles required for instruction execution, record its fluctuation range, dynamically adjust the delay measurement value in combination with the processor temperature change, and perform linear weighted correction on the delay value; By forcibly refreshing the cache and measuring the delay difference between at least two cores accessing the same memory area, obtain the cores sharing the same cache block, construct a cache sharing topology structure diagram, convert the topology structure into binary encoding, and generate a fixed-length feature code through a hashing algorithm; In the idle state of the processor, repeatedly execute basic arithmetic instructions and count the average delay time of instruction execution. The basic arithmetic instructions include addition and exclusive OR instructions; Combine the processor load rate and temperature data to perform non-linear correction on the reference delay and generate delay features adapted to each operating state; Use the voltage monitoring chip on the motherboard to collect voltage fluctuation data of the power supply line, record the instantaneous voltage value, perform spectral analysis on the voltage fluctuation data, and calculate the complexity of its frequency distribution as the uniqueness feature of the power supply noise; By capturing the clock signal of the processor, measuring the time interval between adjacent clock rising edges, counting its fluctuation range and distribution law, converting the clock jitter data into standard deviation and skewness statistics, and extracting high-frequency jitter components in combination with Fourier transform to generate a multi-dimensional jitter feature vector; Inject a constant current at both ends of the memory bus signal path on the circuit board, measure the voltage drop on the path, calculate the actual resistance value, compare the measured resistance value with the theoretical design value, calculate the resistance deviation rate of each path, and generate a feature vector reflecting the manufacturing process differences of the circuit board; Map the resistance deviation rate to the two-dimensional coordinate system of the circuit board to form a heat map of the resistance value distribution, and perform a discrete cosine transform on the heat map as the unique fingerprint feature of the circuit board.
[0014] The hash algorithm is to transform any length of input through a hashing algorithm into a fixed-length output, and this output is the hash value. This transformation is a compression mapping, that is, the space of the hash value is usually much smaller than the space of the input. Different inputs may be hashed into the same output, and it is impossible to uniquely determine the input value from the hash value, that is, a function that compresses a message of any length into a message digest of a certain fixed length.
[0015] Refer to Figure 3 As shown, the firmware behavior acquisition module specifically includes: When the computer starts up, after the power supply is stably powered, the motherboard control chipset removes the reset signal, and the central processing unit starts to execute instructions from the fixed address of the system basic input / output system; Perform a power-on self-test, sequentially detect the core hardware of the memory and the graphics card, and test the conventional memory area during the memory detection; Generate a memory mapping table according to the hardware configuration, and allocate physical memory, video memory, and input / output port resources to at least two address spaces; Record the start address, end address, and type of the physical memory in the memory mapping table, and analyze whether the memory block allocation strategy is continuous allocation or discontinuous allocation; The interrupt vector table is located at the memory start address 0, stores the segment address and offset address of the interrupt service routine. After entering the protected mode, the interrupt vector table is replaced by the interrupt descriptor table and can be stored at any memory location; Traverse the interrupt vector table and the interrupt descriptor table, record the entry address of the service routine corresponding to each interrupt, and analyze the interrupt processing flow; Decompose the interrupt processing delay into the interrupt response time, the execution time of the interrupt service routine, and the context switch time. The interrupt response time is from the interrupt trigger to the processor starting to execute the first instruction of the interrupt service routine, and the context switch time is recorded as the register save and restore overhead time; Save the return address and the stack frame pointer when a function is called, construct a function call chain, analyze the depth and width of the call chain, and identify the core functions called and potential recursive calls; Associate the instruction execution trace, the call chain, and the context snapshot to form a complete execution trace, and compress the trace data using differential coding and the hash algorithm; In a virtualized environment, through dynamic instrumentation technology, insert hook functions when a function is called and returns, record the real-time changes of the call chain, analyze the branch probability, loop count, and call frequency of the call chain, and identify hot functions and abnormal call paths; Fuse the firmware loading sequence, memory mapping, interrupt vector table configuration, execution trace, call chain, interrupt handling latency, and dynamic behavior characteristics of hardware virtualization. Adopt the method of feature vector splicing or graph structure representation to construct a firmware runtime feature library.
[0016] Call chain tracing saves the return address and stack frame pointer at the function entry, records the call target address after the instruction through dynamic binary instrumentation, constructs a call chain graph, where the nodes are function addresses, the edges are call relationships, the call chain depth is the maximum call path length from the main function to the current function, the width is the number of functions called at the same level, and if a repeated function address appears in the call chain, it is marked as a recursive call.
[0017] Refer to Figure 4 As shown, the environmental feature acquisition module specifically includes: Deploy six types of environmental sensors, namely temperature, humidity, air pressure, light, acceleration, and magnetic field, on the motherboard, and the sensors communicate with the motherboard management controller; The sensors generate a data frame at the same interval, and the data frame includes the current values of each sensor and a timestamp; The three-axis data of the acceleration sensor calculates the device attitude angle through vector synthesis, and estimates the device altitude change in combination with the air pressure data; Obtain the device's longitude and latitude coordinates, delimit a polygon fence area on the electronic map, and use the ray casting method to determine whether the device is located within the fence. When the coordinates are outside the fence for 3 consecutive times, an out-of-bounds alarm is triggered; Statistically calculate the mean and variance of the environmental data of the device within at least one time period within the fence to generate an environmental baseline model; Deploy a link layer monitor between the motherboard network card chips, copy all incoming and outgoing data packets through the mirror port, and capture the five-tuple, timestamp, data packet length, and frame check sequence error flag of the data packet. The five-tuple includes the source IP, destination IP, source port, destination port, and protocol type; Calculate the periodicity of the data packet arrival rate through the autocorrelation function to identify periodic scanning behavior, statistically calculate the delay distribution of retransmitted packets, calculate the average delay, maximum delay, and delay variance, and generate a delay jitter feature vector; Collect the mapping relationship between the MAC address and IP address of active devices in the local area network to generate an initial topology map; Listen to the link layer discovery protocol packets in the network, extract the device model, port identifier, and management IP address, and improve the device attribute information of the topology map; Draw a device topology map, where the size of the node represents the importance of the device, and the thickness of the edge represents the size of the communication traffic.
[0018] The steps to determine whether a device is inside a fence using ray casting are as follows: emit a ray from the current coordinates of the device in the due east direction, count the number of intersections of the ray with the fence edges. If the number is odd, it is determined that the device is inside the fence; if it is even, it is determined that the device is outside the fence.
[0019] Refer to Figure 5 As shown, the modal data synchronization module specifically includes: For hardware fingerprints, each time hardware features are collected, a timestamp is generated by the real-time clock and appended to the feature data packet; For circuit fingerprints, when capturing circuit signals through a logic analyzer, the offset between the signal occurrence time and the real-time clock time is synchronously recorded; For firmware behavior, time recording instructions are inserted into the firmware code, and when the behavior occurs, the real-time clock timestamp is immediately obtained; For environmental fingerprints, when the environmental sensor collects data, each frame of data carries the real-time clock timestamp; For network behavior, when the link layer monitor captures data packets, a nanosecond-level timestamp is embedded in the packet header through the hardware timestamp unit; Taking the hardware fingerprint collection time as a reference, set a time window, and filter the circuit fingerprint, firmware behavior, environmental fingerprint, and network behavior data collected within this window.
[0020] Each time a hardware fingerprint event triggers the window to slide, the window overlap rate is 50% to avoid data fragmentation. If there is no data for a certain modality within the window, fill in null values and mark anomalies such as circuit signal interference. When there is a time jump, detect whether the real-time clock has an accidental reset, and trigger a system security audit.
[0021] Refer to Figure 6 As shown, the forged feature simulation module specifically includes: For the simulated replacement attack, the generator forges a modal data feature while keeping other features unchanged; For the simulated injection attack, an abnormal pattern is inserted into the normal feature; Combining the replacement attack and the injection attack to generate a composite forged sample; By adjusting the amplitude of the input noise of the generator, control the deviation degree of the forged feature, set the proportion of the forged feature, and simulate at least one attack scale; Generate 10 forged samples for each real sample to form a positive-negative sample ratio of 1:10. Mix the real samples and the forged samples according to the ratio to construct a training set, a validation set, and a test set; During the training process, switch the training state of the generative adversarial model at the same interval each time, so that the classifier can adapt to the dynamically changing forged samples.
[0022] Steps for replacement attack: Select the target modality, randomly select one of the hardware fingerprint, firmware behavior, environmental fingerprint, or network behavior as the replacement target, generate forged features, and use the generator to generate forged data similar to the target modality distribution; Steps for injection attack: Select the injection location, randomly insert abnormal patterns such as mutated power noise and abnormal interrupt latency into the normal feature sequence, generate abnormal patterns, based on historical attack data such as known malicious firmware behavior patterns or rule libraries such as the periodic characteristics of network scanning, maintain data integrity, ensure that the data length and timestamp continuity remain unchanged after injection, and avoid being detected by simple verification mechanisms.
[0023] Refer to Figure 7 As shown, the credibility verification module specifically includes: Calculate the cosine similarity matrix of static features and dynamic features, and obtain the attention weight matrix through normalization; Weighted sum the dynamic feature embedding vectors according to the attention weights to generate weighted dynamic features; Extract the abnormal indicators in the dynamic features and amplify their weights through a gating mechanism: Calculate the attention weights of the dynamic features to the static features to generate weighted static features: Concatenate the weighted static features and the enhanced dynamic features into a fusion vector; The input layer of the credibility scoring model is the fusion feature vector, the hidden layer is a three-layer fully connected network, and the output layer is a single-node output of the credibility score.
[0024] Cosine distance, also known as cosine similarity, is a measure that uses the cosine value of the angle between two vectors in a vector space to measure the size of the difference between two individuals. The closer the cosine value is to 1, the closer the angle is to 0 degrees, that is, the more similar the two vectors are.
[0025] Furthermore, this solution also proposes a computer-readable storage medium, on which a computer-readable program is stored. When the computer-readable program is called, it executes the above-mentioned X86 industrial control motherboard identity authentication system based on multi-modal fusion.
[0026] It can be understood that the storage medium can be a magnetic medium, for example, a floppy disk, a hard disk, a magnetic tape; an optical medium such as a DVD; or a semiconductor medium such as a solid-state drive Solid State Disk, SSD, etc.
[0027] In summary, the advantages of the present invention are as follows: By performing cross-modal correlation analysis on hardware fingerprints, circuit fingerprints, firmware behaviors, environmental fingerprints, and network behaviors, a multi-level identity profile is constructed to enhance the detection ability against composite attacks. Based on the X86 hardware virtualization technology, the firmware call chain and interrupt latency are recorded, and combined with the timing characteristics of network packets, runtime anomalies are captured in real time to enhance the awareness of advanced threats. The weights of static features and dynamic features are dynamically adjusted through the attention mechanism to highlight the impact of runtime abnormal behaviors, and a hierarchical response based on credibility scoring is achieved.
[0028] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and what is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, various changes and improvements will occur to the present invention, and all these changes and improvements fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. An X86 industrial control motherboard identity authentication system based on multimodal fusion, characterized in that, Including: A hardware feature collection module, which is used to obtain a key through a trusted password module chip, generate a dynamic hardware fingerprint by combining the cache topology and instruction latency of an X86 central processing unit, collect physical unclonable function features of power noise and clock jitter using dedicated sensors on the motherboard, and generate a circuit fingerprint by combining the differences in the wiring resistance distribution of the printed circuit board; A firmware behavior collection module, which is used to record the loading sequence, memory mapping, and interrupt vector table configuration of the firmware, generate a firmware execution trace, record the dynamic behaviors of the call chain and interrupt handling latency through the hardware virtualization technology of X86, and construct a firmware runtime feature library; An environmental feature collection module, which is used to integrate motherboard-level environmental sensors, collect the spatio-temporal features of the device deployment environment, generate an environmental fingerprint by combining geofencing technology, capture the timing features of network packets through the link layer monitor of the motherboard, and generate a network behavior portrait by combining the device topology relationship; A modal data synchronization module, which is used to synchronize the timestamps of the hardware fingerprint, circuit fingerprint, firmware behavior, environmental fingerprint, and network behavior, and eliminate the time offset of at least one modal data; A forged feature simulation module, which is used to simulate fingerprint data tampering attacks through a generative adversarial network and train a robust classifier to identify forged features; A credibility verification module, which is used to perform weighted fusion of static features and dynamic features through an attention mechanism, highlighting the impact of runtime abnormal behaviors on identity credibility. The static features include hardware fingerprint, circuit fingerprint, and environmental fingerprint, and the dynamic features include firmware behavior and network behavior; An identity authentication response module, which is used to trigger corresponding authentication policies based on the identity credibility score and implement irreversible response execution. The authentication policies include warnings, restricted functions, and system locks.
2. The X86 industrial control motherboard identity authentication system based on multimodal fusion according to claim 1, characterized in that, The hardware feature collection module specifically includes: The trusted password module generates a root key based on the unique hardware identifier built into the chip, calculates a session key through a hash algorithm, and generates a dynamic key by combining the current timestamp and a random number; Perform an exclusive OR operation on the dynamic key and the cache sharing topology feature of the central processing unit to generate a key bound to the hardware architecture; Loop and execute a specific instruction sequence in the processor core, read the processor information and timestamp, measure the number of time cycles required for instruction execution, record its fluctuation range, dynamically adjust the delay measurement value in combination with the processor temperature change, and perform linear weighted correction on the delay value; Obtain the cores sharing the same cache block by forcibly refreshing the cache and measuring the delay difference of at least two cores accessing the same memory area, construct a cache sharing topology structure diagram, convert the topology structure into binary encoding, and generate a feature code of a fixed length through a hash algorithm; In the idle state of the processor, repeatedly execute basic arithmetic instructions, and count the average delay time of instruction execution. The basic arithmetic instructions include addition and exclusive OR instructions; Combine the processor load rate and temperature data to perform non-linear correction on the baseline latency, and generate latency characteristics adapted to each operating state; Use the voltage monitoring chip on the motherboard to collect the voltage fluctuation data of the power supply line, record the instantaneous voltage value, perform spectral analysis on the voltage fluctuation data, and calculate the complexity of its frequency distribution as the unique characteristic of the power supply noise; By capturing the clock signal of the processor, measure the time interval between adjacent clock rising edges, statistically analyze its fluctuation range and distribution law, convert the clock jitter data into standard deviation and skewness statistics, and combine with Fourier transform to extract high-frequency jitter components to generate a multi-dimensional jitter feature vector; Inject a constant current at both ends of the memory bus signal path on the circuit board, measure the voltage drop on the path, calculate the actual resistance value, compare the measured resistance value with the theoretical design value, calculate the resistance deviation rate of each path, and generate a feature vector reflecting the manufacturing process differences of the circuit board; Map the resistance deviation rate to the two-dimensional coordinate system of the circuit board to form a heat map of the resistance value distribution, and perform discrete cosine transform on the heat map as the unique fingerprint feature of the circuit board.
3. The X86 industrial control motherboard identity authentication system based on multimodal fusion according to claim 2, characterized in that, The firmware behavior acquisition module specifically includes: When the computer starts up and the power supply is stable, the motherboard control chipset removes the reset signal, and the central processing unit starts to execute instructions from the fixed address of the system basic input / output system; Execute the power-on self-test, and sequentially detect the core hardware of the memory and the graphics card. When detecting the memory, test the conventional memory area; Generate a memory mapping table according to the hardware configuration, and allocate physical memory, video memory, and input / output port resources to at least two address spaces; Record the start address, end address, and type of the physical memory in the memory mapping table, and analyze whether the memory block allocation strategy is continuous allocation or discontinuous allocation; The interrupt vector table is located at the memory start address 0, and stores the segment address and offset address of the interrupt service routine. After entering the protected mode, the interrupt vector table is replaced by the interrupt descriptor table and can be stored at any memory location; Traverse the interrupt vector table and the interrupt descriptor table, record the entry address of the service routine corresponding to each interrupt, and analyze the interrupt handling process; Decompose the interrupt processing latency into interrupt response time, interrupt service routine execution time, and context switch time. The interrupt response time is from the interrupt trigger to the start of the processor to execute the first instruction of the interrupt service routine, and the context switch time is recorded as the register save and restore overhead time; Save the return address and stack frame pointer when a function is called, construct a function call chain, analyze the depth and width of the call chain, and identify the core functions called and potential recursive calls; Associate the instruction execution trace, call chain, and context snapshot to form a complete execution trace, and compress the trace data using differential coding and hash algorithm; In a virtualized environment, through dynamic instrumentation technology, insert hook functions when a function is called and returns, record the real-time changes of the call chain, analyze the branch probability, loop count, and call frequency of the call chain, and identify hot functions and abnormal call paths; Fuse the firmware loading sequence, memory mapping, interrupt vector table configuration, execution trace, call chain, interrupt handling latency, and hardware virtualization dynamic behavior characteristics, and use feature vector splicing or graph structure representation methods to construct a firmware runtime feature library.
4. The X86 industrial control motherboard identity authentication system based on multimodal fusion according to claim 3, characterized in that, The environment feature acquisition module specifically includes: Deploy six types of environmental sensors, namely temperature, humidity, air pressure, light, acceleration, and magnetic field, on the motherboard, and the sensors communicate with the motherboard management controller; The sensors generate a data frame at the same interval, and the data frame includes the current values of each sensor and a timestamp; The three-axis data of the acceleration sensor calculates the device attitude angle through vector synthesis, and estimates the device altitude change in combination with the air pressure data; Obtain the device's longitude and latitude coordinates, delimit a polygon fence area on the electronic map, and use the ray casting method to determine whether the device is located within the fence. When the coordinates are outside the fence for 3 consecutive times, an out-of-bounds alarm is triggered; Statistically calculate the mean and variance of the environmental data of the device within at least one time period within the fence to generate an environmental baseline model; Deploy a link layer monitor between the motherboard network card chips, copy all incoming and outgoing data packets through the mirror port, and capture the five-tuple, timestamp, data packet length, and frame check sequence error flag of the data packet. The five-tuple includes source IP, destination IP, source port, destination port, and protocol type; Calculate the periodicity of the data packet arrival rate through the autocorrelation function to identify periodic scanning behaviors, statistically calculate the delay distribution of retransmitted packets, calculate the average delay, maximum delay, and delay variance, and generate a delay jitter feature vector; Collect the mapping relationship between the MAC addresses and IP addresses of active devices in the local area network to generate an initial topology map; Listen to the link layer discovery protocol packets in the network, extract the device model, port identifier, and management IP address, and improve the device attribute information of the topology map; Draw a device topology map, where the size of the node represents the importance of the device, and the thickness of the edge represents the size of the communication traffic.
5. The X86 industrial control motherboard identity authentication system based on multimodal fusion according to claim 4, wherein, The modal data synchronization module specifically includes: For the hardware fingerprint, a timestamp is generated by the real-time clock and appended to the feature data packet each time the hardware features are collected; For the circuit fingerprint, when the circuit signal is captured by the logic analyzer, the offset between the signal occurrence time and the real-time clock time is synchronously recorded; For the firmware behavior, time recording instructions are inserted into the firmware code, and when the behavior occurs, the real-time clock timestamp is immediately obtained; For the environmental fingerprint, each frame of data carries a real-time clock timestamp when the environmental sensor collects data; For the network behavior, when the link layer monitor captures a data packet, a nanosecond-level timestamp is embedded in the data packet header through the hardware timestamp unit; Taking the hardware fingerprint collection time as the benchmark, set a time window to filter the circuit fingerprint, firmware behavior, environmental fingerprint, and network behavior data collected within this window.
6. The X86 industrial control motherboard identity authentication system based on multimodal fusion according to claim 5, wherein, The forged feature simulation module specifically includes: Simulate a replacement attack, where the generator forges a modal data feature while keeping other features unchanged; Simulate an injection attack by inserting an abnormal mode into the normal feature; Combine the replacement attack and the injection attack to generate a composite forged sample; Control the deviation degree of the forged feature by adjusting the amplitude of the input noise of the generator, set the proportion of the forged feature, and simulate at least one attack scale. Generate 10 forged samples for each real sample to form a positive-negative sample ratio of 1:
10. Mix the real samples and the forged samples according to the ratio to construct the training set, validation set, and test set. During the training process, switch the training state of the generative adversarial model at the same interval each time to enable the classifier to adapt to the dynamically changing forged samples.
7. The X86 industrial control motherboard identity authentication system based on multimodal fusion according to claim 6, wherein, The credibility test module specifically includes: Calculate the cosine similarity matrix of the static features and the dynamic features, and obtain the attention weight matrix through normalization. Weighted sum the dynamic feature embedding vectors according to the attention weights to generate weighted dynamic features. Extract the abnormal indicators in the dynamic features and amplify their weights through the gating mechanism. Calculate the attention weights of the dynamic features to the static features to generate weighted static features. Concatenate the weighted static features and the enhanced dynamic features into a fusion vector. The input layer of the credibility scoring model is the fusion feature vector, the hidden layer is a three-layer fully connected network, and the output layer is a single-node output of the credibility score.
Citation Information
Cited By
Key generation method and system based on sip module and related equipment
CN120415730A
Network attack defense system based on virtual honeypot
CN120825333A
Data acquisition system and data acquisition method for self-adaptive memory test
CN121858395A
Data acquisition system and data acquisition method for adaptive memory test
CN121858395B