Encryption-decryption scheme for detecting linear spoofing attack in cyber-physical system

By combining cryptographic technology and signal processing methods, the data changes before and after encryption are analyzed, and linear spoofing attacks in CPS are monitored in real time, the problem of difficulty in effectively detecting and defending in the existing technology is solved, and attack detection with high accuracy and low false alarm rate is achieved.

CN120200774APending Publication Date: 2025-06-24QINGDAO UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202411732386.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-29
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art is difficult to detect and defend effectively when facing linear spoofing attacks in information physics systems (CPS), especially in highly dynamic and complex environments, with high false positive rates and difficult to deal with carefully designed attacks.

Method used

A decryption scheme combining cryptography technology and signal processing methods is proposed. By analyzing the changes in data before and after encryption, data flow is monitored in real time and potential linear attacks are identified to improve detection accuracy and reliability.

Benefits of technology

This solution can effectively detect and defend against linear spoofing attacks in CPS without affecting the system performance, with a low false alarm rate and missed alarm rate, ensuring the security and integrity of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200774A_ABST
    Figure CN120200774A_ABST
Patent Text Reader

Abstract

The invention discloses a novel encryption-decryption scheme, and aims to detect and defend linear spoofing attacks on a cyber-physical system (CPS). With the wide application of CPS in key infrastructures such as industrial automation, smart power grids and automobile systems, it is particularly important to ensure the safety and integrity of CPS. Linear spoofing attacks are malicious behaviors, normal operation of the linear spoofing attacks is interfered by controlling input or output of a system, and a traditional security mechanism is often difficult to effectively cope with the type of attacks. According to the invention, an encryption algorithm is designed to protect data transmission of the CPS, and the encryption algorithm is combined to recover original data and identify potential attack signs at the same time. According to the scheme, the combination of the cryptography technology and the signal processing method is utilized, the data stream can be monitored in real time, and the possible linear attack is identified by analyzing the change of the data before and after encryption. In addition, according to the scheme, calculation efficiency and implementation feasibility are considered, and it is ensured that necessary safety guarantee is provided on the premise that system performance is not affected. Experimental results show that the proposed encryption-decryption scheme can effectively detect linear spoofing attacks in the cyber-physical system, and has relatively low false alarm rate and missing report rate. In addition, the scheme shows good adaptability and robustness in practical application, and provides a new thought and technical support for the security protection of the CPS in the future.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security defense strategies, and in particular relates to an encryption and decryption technology for detecting linear deception attacks in CPS. Background Art

[0002] The Cyber-Physical System (CPS) closely combines physical processes with computing resources, network communication, and user interfaces, and is widely used in many fields such as industrial automation, intelligent transportation, energy management, and healthcare. With the development of the Internet of Things (IoT) technology, CPS systems are becoming increasingly complex, and their security is facing unprecedented challenges. A CPS system usually consists of sensors, actuators, controllers, and communication networks. These components are interconnected through the network, achieving a deep integration of the physical world and the digital world. Sensors are used to collect data from the physical environment, controllers make decisions based on this data, and actuators are responsible for executing control instructions. The communication network is the bridge connecting each component, ensuring the real-time transmission of data.

[0003] A linear deception attack is a malicious behavior against CPS. Attackers tamper with sensor data or control instructions to make the system generate incorrect control actions, thereby achieving the purpose of disrupting the normal operation of the system. This attack is called "linear" because attackers usually utilize the linear characteristics of the system and generate seemingly reasonable but actually deceptive data through linear transformation or linear combination.

[0004] Currently, the security protection measures for CPS mainly include data encryption, authentication, anomaly detection, etc. However, these methods still have certain limitations when facing linear deception attacks: Although data encryption can prevent data from being stolen during transmission, it cannot completely prevent data from being tampered with. Authentication: It is mainly used to verify the identities of both communication parties, but it is powerless against internal attackers who have already entered the system. Anomaly detection: Statistical or machine learning-based methods can detect some abnormal behaviors, but in the highly dynamic and complex CPS environment, the false alarm rate is relatively high, and it is difficult to cope with carefully designed linear deception attacks. Summary of the Invention

[0005] (1) Technical Problems to be Solved

[0006] 1. The present invention proposes a new encryption-decryption scheme specifically for linear deception attacks in the Cyber-Physical System (CPS). This scheme can not only protect the data transmission of CPS, but also identify potential attack signs during the decryption process.

[0007] 2. The invention innovatively combines cryptography techniques and signal processing methods, enabling real-time monitoring of data streams and identifying potential linear attacks by analyzing the changes in data before and after encryption. This combination improves the accuracy and reliability of detection.

[0008] 3. The invention fully considers computational efficiency and implementation feasibility during design, ensuring necessary security guarantees without compromising system performance. Experimental results show that the proposed solution can effectively detect linear deception attacks in CPS and has a low false alarm rate and missed alarm rate.

[0009] (II) Technical Solution

[0010] The present invention aims to solve the problem of linear deception attacks in Cyber-Physical Systems (CPS). Linear deception attacks interfere with the normal operation of the system by manipulating its inputs or outputs, and traditional security mechanisms often struggle to effectively counter such attacks. The present invention proposes a new encryption-decryption scheme that can, while protecting CPS data transmission, detect and identify potential linear deception attacks in real time, thereby ensuring the security and integrity of the system. The present invention provides a new encryption-decryption scheme, which specifically includes the following steps:

[0011] S1. Data preprocessing: Collect sensor data in the CPS system and perform preprocessing,

[0012] including data cleaning and formatting.

[0013] S2. Analyze the concealment of linear deception attacks in the CPS system and the specific attack methods of such attacks.

[0014] S3. Design an encryption-decryption scheme to identify potential linear deception attacks by analyzing the changes in data before and after encryption.

[0015] S4. Attack detection: Anomaly detection is based on statistical or machine learning methods to detect abnormal patterns in the data. Threshold judgment: Set a threshold, and when the detected data change exceeds the threshold, it is determined as a potential linear deception attack.

[0016] The present invention proposes a new encryption-decryption scheme aimed at detecting and defending against linear deception attacks on Cyber-Physical Systems (CPS). This scheme combines cryptography techniques and signal processing methods, enabling real-time monitoring and identification of potential attack signs while protecting CPS data transmission.

[0017] 1. The step S1 of this scheme is as follows: We consider a linear discrete-time system

[0018] x k+1 = Ax k + w k

[0019] y k = Cx k + v k

[0020] where x k ∈ R n represents the state vector of the system at time k, and y k ∈ R m represents the measurement output value of the system. The noises w k and v k are uncorrelated. And the process noise w k ~ N(0, Q) and the measurement noise v k ~ N(0, R) are independent zero-mean Gaussian white noises. The initial condition x0 follows x0 ~ N(0, σ) and is independent of w k and v k .

[0021] To make better use of the system's observations and perform optimal estimation of the system state, here we adopt the standard Kalman filter. Its main form is as follows:

[0022]

[0023] Here, z k is the local residual value passed to the remote estimator, and are the prior and posterior minimum mean square error (MMSE) estimates of the state x k . and P k are the corresponding error covariances respectively. Here, K k is the Kalman gain. In practical applications, after a period of iteration, the Kalman filter exponentially converges to a constant under any initial condition. The convergence process is given below. For simplicity, we also define the Lyapunov and Riccati operators h,

[0024] h(X) = AXA T + Q

[0025]

[0026] When the Kalman filter reaches convergence, the steady-state error covariance at this time is: where is 's unique positive semi-definite solution. For the convenience of subsequent research, assume that the Kalman filter starts from the steady state then there is

[0027] 2. The steps of S2 are as follows: The linear deception attack model plays an important role in attack stealth analysis and subsequent detection strategy design. The linear deception attack will degrade the system's remote estimation performance and is difficult to be detected by the detector. During the information transmission process, the attacker injects the measurement value y k into the attack vector a k to cause a linear attack. Specifically, it is expressed as:

[0028]

[0029] Here represents the measurement value after the sensor is attacked, and a k ~N(0,θ) is a zero-mean Gaussian distribution independent of y k . For the attacker, we assume here that the attacker has the system information. That is, according to the relevant information of the system, the attacker can select an appropriate attack vector because the χ 2 detector tests the residuals. A simple strategy for inducing false data is to cancel the sensor measurement value and add false data, as follows

[0030]

[0031] where b k is the false data injected into the estimator. As we have shown, the attacker can choose b k to make the chi-square detector useless under the condition of system information. Next, we analyze the residual z k . When the system is attacked, the residual z k becomes

[0032]

[0033] The attacker mentioned above has systematic information, and the attacker can select an appropriate attack vector to change the residual to bypass the bad data detection of the attack detector. The attacker must ensure that is a very small value. This will depend on the threshold selected in the χ 2 detection. It can be easily seen from the above formula that the attacker can choose Here γ k represents an arbitrary vector. Since the attacker can access the system matrix, the attacker can calculate the predicted state. At this time, the residual z k becomes γ k . Therefore, as long as γ k can be an arbitrary vector. Therefore, the attack vector is as follows:

[0034]

[0035] Of course, we assume that the attacker has access to the current sensor measurements. This is a standard assumption of the attacker's capabilities. The attack signal is the false true measurement injected into the system at any time k according to the attack model (20). After a linear spoofing attack, the system becomes:

[0036]

[0037] At this time, the linear attack strategy satisfies the detection constraint, that is, the attack detector of the system achieves a stealth effect. Therefore, the estimated residual of the corresponding system can be expressed as:

[0038]

[0039] Then, we define Here

[0040] In the considered false information injection attack model, the main purpose of the attacker is as follows: Inject the attack vector a k , and cause damage to the system. Use false data to replace the true measurement value y k , in order to prevent being detected by the χ 2 detector. If identifies the residual k from the "normal" residual z that is considered to be problematic (under a linear spoofing attack), it may be challenging for the χ 2 detector.

[0041] 3. Step S3 is as follows: Design an encryption and decryption method to protect the data during the system transmission process. There are mainly two objectives: One is the objective of this encryption and decryption method without damaging the system performance. Secondly, in order to improve the detection efficiency, it is very important to reasonably design the encryption and decryption method. The encryption and decryption process is as Figure 3 shown. The sensor measurement value y k encrypts the data through the encryption factor c k designed by us, and then restores the encrypted data according to the encrypted data by introducing the decryption factor d k , and finally transmits the data to the estimator side. The encryption process is as follows:

[0042]

[0043] where is the encrypted measurement value. c k is the pre-designed encryption factor. Here sk ~N(0,S) is zero-mean Gaussian white noise generated by a random number generator. It should be noted that y k instead of is transmitted through the network during the transmission process. Then the encrypted data is decrypted into y k The corresponding process is as follows:

[0044]

[0045] where is the decrypted value of y k and d k is the dynamic key in the decryption process. F is the encryption matrix designed by us. This matrix F must be full-rank and unknown to the attacker. It should be noted here that d k = F -1 c k , and later we will explain why it is designed in this way, and the random number generator in the encryption and decryption processes uses the same random seed to ensure that the s k is the same.

[0046] 4. Step S4 is as follows: Detect the data according to the threshold structure of the chi-square detector. Specifically, a malicious attacker can tamper with the data transmitted through the wireless channel. From the perspective of the system, a suitable detection mechanism is crucial for limiting the impact of the attack on the entire system. The system can timely remind the operator to take corrective measures when an attack is sensed and detected. In this paper, we use the χ 2 detector to detect the bad data during the transmission process. The χ 2 detector is a commonly used residual-based method for identifying anomalies in the system. The authenticity of the residual z k is judged by examining its statistical characteristics.

[0047]

[0048] where l is the size of the detection window and P is the covariance matrix of z k . g k is a chi-square 2 distribution with P degrees of freedom. Specifically, at each time step k, the χ 2 detector compares g k with the threshold η (η is predetermined as a specific false alarm probability). If the value of g k exceeds the threshold η, the detector will trigger an alarm. Here, we define the probability of detecting an attack as α = Pr(g k > η).

[0049] If the attacker has complete information about the system, according to the system parameters A, C, Q, R, then the attacker can use the obtained information to select an appropriate attack vector a k , in order to achieve the effect of attacking the system stealthily. In the following discussion, we will study how the attacker selects the attack vector to achieve the effect of attack stealth. We assume that the attacker has no information about the system, then at this time the attacker needs to find a way to obtain the data information of the system before launching an attack. The attacker obtains z by estimating the information about the system k 's mean and variance, which can use the data from the sample to estimate the population data in statistics. Let {U1, U2…U n} be independent samples of a normal population, with mean μ and variance σ 2

[0050]

[0051] Here S 2 is the variance of the sample, is the mean of the sample. To further estimate the population mean from the sample mean, we need

[0052]

[0053] where t(n - 1) represents the student's t-distribution with n - 1 degrees of freedom. μ is the mean of the sample population. For a given confidence level 1 - α, we obtain

[0054]

[0055] where 1 - α is the probability that the estimated value μ is within the confidence interval. Similarly, for the estimation of the population variance, we can draw the following conclusion

[0056]

[0057] where χ 2 (n - 1) represents the χ 2 distribution. Assume that the given confidence level is 1 - β, and the probability that the estimated value lies between two random endpoints is as follows:

[0058]

[0059] The above formula shows that when n is sufficiently large, a high confidence level and a small confidence interval can be obtained. This means that even if the attacker does not know the parameters of the system, the attacker can launch an attack and successfully estimate the mean and variance of z k . However, it should be noted that this kind of attack cannot be guaranteed not to be detected. Description of the Drawings

[0060] Figure 1 Flow chart for detecting linear spoofing attacks under an encryption - decryption scheme;

[0061] Figure 2 Schematic diagram of the system framework under linear spoofing attacks;

[0062] Figure 3 Schematic diagram of the proposed encryption - decryption scheme process;

[0063] Figure 4 Schematic diagram of the encryption and decryption processes when suffering from linear spoofing attacks;

[0064] Figure 5 For χ 2 Effect diagram of the detector attack detection;

[0065] Figure 6 For the comparison diagram of the residual z k before and after the attack;

[0066] Figure 7 For the comparison diagram of g k before and after being attacked. Specific implementation manner

[0067] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0068] As Figure 2 shown in the classical CPS framework. The main components include sensors, remote estimators, Kalman filters, and chi - square detectors. Consider a linear discrete - time system:

[0069] x k+1 = Ax k + w k

[0070] y k = Cx k + v k

[0071] In order to better utilize the observed values of the system and perform optimal estimation of the system state, here we adopt a standard Kalman filter. Its main form is as follows:

[0072]

[0073] At this time, through the iteration of the Kalman filter, it enters a stable state, and the observed data I need can be obtained.

[0074] Through Figure 3 To elaborate on our data encryption and decryption process. This is the case when there is no attack on the system. The encryption and decryption processes are as Figure 3 shown. The sensor measurement value y k is encrypted by the encryption factor c k designed by us for the data, and then the encrypted data is restored by introducing the decryption factor d k for the encrypted data, and finally the data is transmitted to the estimator side. The encryption process is as follows:

[0075]

[0076] Where is the encrypted measurement value. c k is the pre-designed encryption factor. Here, s k ~N(0,S) is the zero-mean Gaussian white noise generated by the random number generator. It should be noted that y k Rather than is transmitted through the network during the transmission process. Then, the process of decrypting the encrypted data into y k is as follows:

[0077]

[0078] Where is the decrypted value of y k , d k is the dynamic key during the decryption process. F is the encryption matrix designed by us. This matrix F must be full-rank and unknown to the attacker. It should be pointed out here that d k = F -1 c k , and we will explain why it is designed like this later. And the random number generator in the encryption and decryption processes uses the same random seed to ensure that the s k in the encryption and decryption sides is the same. Obviously, when the system is not maliciously damaged by the attacker, we can obtain:

[0079]

[0080] That is, in the absence of malicious attacks by the attacker, the decrypted sensor measurement value satisfies the following conditions

[0081]

[0082] Figure 4Illustrates the effectiveness of the encryption and decryption methods in detecting linear spoofing attacks, as follows: When the system is under a linear spoofing attack, our encryption and decryption methods are as Figure 4 shown. When the system is attacked, the encryption and decryption system becomes

[0083]

[0084] Then the residual becomes

[0085]

[0086] Since the χ 2 detector is based on the statistical characteristics of the residual values, we then analyzed the system residual after the attack By analyzing the encryption-decryption scheme we proposed and analyzing the statistical values of the residual z k .

[0087] (1) When the attacker has the encrypted message and the encryption matrix F is -I and I, the interception and modification of the encrypted data: The attacker tampers with the encryption factor, which is selected here as

[0088]

[0089] At this time, the residual after being attacked has the same statistical properties as z k . At this time, for the attacker, the attack achieves concealment.

[0090] (2) When the attacker is not aware of our encryption strategy or does not have complete encryption information, for the defender to defend against the attack by adjusting the values of the encryption matrix F and the encryption factor. Specifically, when F is ±I, that is, when the difference between the residual z k after the attack and is maximized, it is more conducive to the detector to detect the attack.

[0091] To prove the analysis results, this part presents numerical simulation experiments. First, we considered the detection performance of the χ 2 detector without encryption and decryption. The specific numerical values are as follows: Assume that the process noise and the measurement noise are both zero-mean Gaussian white noise, Q = I 2×2 , R = I 2×2 . When the Kalman filter enters the steady state point, the converged Kalman gain K and P are

[0092]

[0093] This attack uses a χ 2The detector is tested against the original unencrypted and decrypted scheme. Here we choose the threshold η = 4.2. The simulation results of the simulation experiment according to the embodiment are as Figures 5 - 7 shown:

[0094] χ 2 The detection effect of the detector with and without encryption and decryption under attacks can be seen in Figure 5 . From Figure 6 it can be seen that at the moment when the attacker injects the attack, the value of the residual z k changes significantly. Here the attack vector a k satisfies the concealment condition mentioned above, that is, when the attacker intercepts the information such that F = -I and F = I, the difference in the residual can be seen in subsequent iterations.

[0095] In Figure 7 we can see the comparison of g k before and after encryption and decryption and after using the encryption and decryption scheme. Here we choose the encryption matrices F = -I and F = I. Through comparison, we can effectively verify the second part of Theorem 2. This makes it possible to effectively improve the detection effect after encryption and decryption.

[0096] The above simulation results show an encryption and decryption scheme against linear spoofing attacks. It is proved that in the absence of attacks, the encryption and decryption scheme has no impact on the stability of the system. And further through simulation examples, it is verified that the scheme has a certain effect on improving the detection performance of the χ 2 detector.

[0097] Of course, the above description is not a limitation of the present invention, and the present invention is not limited to the above examples. Those of ordinary skill in the art in the essence of the present invention, any changes, modifications, additions or substitutions should fall within the protection scope of the present invention.

Claims

1. An encryption-decryption scheme for detecting linear spoofing attacks in cyber-physical systems, characterized in that It can detect and identify potential linear spoofing attacks in real time while protecting CPS data transmission, thereby ensuring the security and integrity of the system. The specific steps include: S1. Data preprocessing collects sensor data in the CPS system and performs preprocessing, including data cleaning and formatting; S2, analyze the concealment of linear deception attacks in CPS systems and the specific attack methods of the attacks; S3. Design encryption and decryption schemes to identify potential linear spoofing attacks by analyzing the changes in data before and after encryption; S4, Attack Detection,Anomaly detection is based on statistical or machine learning methods to detect abnormal patterns in data.,Threshold judgment sets a threshold, and when the detected data change exceeds the threshold, it is determined to be a potential linear deception attack.

2. According to claim 1, an encryption-decryption scheme for detecting linear deception attacks in cyber-physical systems, for the data preprocessing in step S1 to collect sensor data in the CPS system, its characteristics are as follows: We consider a linear discrete-time system, the main components of which include sensors, remote estimators, Kalman filters, and chi-square detectors. In order to better utilize the observed values ​​of the system and make the best estimate of the state of the system, we use a standard Kalman filter here. By iterating the Kalman filter to enter a stable state, the observation data I need can be obtained.

3. According to the encryption-decryption scheme for detecting linear deception attacks in cyber-physical systems described in claim 1, the characteristics of analyzing the concealment of linear deception attacks encountered in CPS systems in step S2 and the specific attack methods of the attacks are as follows: The linear deception attack model plays an important role in attack stealth analysis and subsequent detection strategy design. Linear deception attacks will reduce the long-range estimation performance of the system and are difficult to be detected by the detector. During the information transmission process, the attacker changes the sensor's measurement value y k Inject into attack vector a k In this case, a linear attack occurs. Specifically, it is expressed as: here Represents the measured value after the sensor is attacked, Obey one and y k Unrelated zero-mean Gaussian distribution. For the attacker, we assume here that the attacker has system information. That is, the attacker can choose a suitable attack vector based on the relevant information of the system, because χ 2 The detector is a test of the residuals. A simple strategy to induce false data is to cancel the sensor measurements and add false data, as shown below in, b k Therefore, the attacker can choose b k This makes the chi-square detector useless in the presence of system information.

4. The encryption-decryption scheme for detecting linear deception attacks in cyber-physical systems according to claim 3, characterized in that: the residual z k The attacker mentioned above has systematic information, and the attacker can choose a suitable attack vector to change the residual to bypass the bad data detection of the attack detector. The attacker must ensure ε>0 is a very small value. This will depend on the 2 The threshold selected in the detection.

5. According to the encryption-decryption scheme for detecting linear deception attacks in cyber-physical systems according to claims 1, 3, and 4, the encryption-decryption scheme designed in step S3 is characterized as follows: the sensor measurement value y k Through the encryption factor c we designed k Encrypt the data, and then introduce the decryption factor d based on the encrypted data k The encrypted data is restored and finally transmitted to the estimator.

6. According to claims 1 and 5, an encryption-decryption scheme for detecting linear deception attacks in information-physical systems, for the attack detection using the encryption-decryption scheme in step S4, the characteristics are as follows: Since the detector is based on the statistical characteristics of the residual value, we then analyze the system residual after the attack. By analyzing the encryption-decryption scheme we proposed and analyzing the statistical values ​​of the residual. 1) When the attacker has an encrypted message and the encryption matrix F is -I and I, the encrypted data is intercepted and modified. The attacker tampers with the encryption factor, which is selected as At this time, the residual after the attack With z k The same statistical properties. At this point, the attack is concealed from the attacker; 2) When the attacker is unaware of our encryption strategy or does not have complete encryption information, the defender can defend against the attack by adjusting the encryption matrix F and the encryption factor.

Citation Information

Cited By

  • Distributed elastic state estimation method and system based on encryption-decryption

    CN120567586A

  • Flexible production-oriented data transmission encryption method, system, medium and program

    CN120614216A

  • Multi-unmanned vehicle anti-spoofing attack predetermined time control method based on dimension expansion encryption

    CN121568119A