Software code security protection method and system based on domestic platform
By obtaining the sensing data flow on the domestic platform and performing millisecond alignment, using reinforcement learning to analyze the dynamic relationship between the device status and code instructions, real-time security protection rules are generated, and the problem of insufficient real-time security protection capabilities for the interaction between software code and mechanical equipment under the domestic platform is solved, and an adaptive closed-loop security protection mechanism is realized, which improves the security and operation efficiency of the system.
Patent Information
- Application Number
- CN202510724155.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-06-03
AI Technical Summary
The real-time security protection capability of software code and mechanical equipment interaction under the domestic platform is insufficient, and the existing static rule base cannot adapt to the dynamically changing equipment operation status, resulting in frequent misjudgment or misjudgment, lack of adaptive capabilities, and affecting the system operation efficiency.
By acquiring the sensing data flow, using the external clock synchronization module for millisecond alignment, combining the reinforcement learning mechanism in the memory isolation environment to analyze the operation event sequence, generate real-time security protection rules, and dynamically bind to the kernel layer to form a closed-loop protection mechanism.
Real-time perception of the operating status of mechanical equipment, accurately identify abnormal execution paths, generate protection strategies that adapt to complex working conditions, ensure system safety and operation efficiency, break through the limitations of static rules, and realize seamless thermal loading and real-time optimization of protection rules.
Smart Images

Figure CN120234801A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical fields of industrial automation control and embedded system security, and particularly to a software code security protection method and system based on a domestic platform. Background Art
[0002] In the fields of industrial automation, intelligent manufacturing, etc., the domestic platform needs to interact with mechanical equipment in real time to ensure the security and reliability of the software code execution process. Due to the complex operating environment of the equipment, the software code may cause mechanical failures due to abnormal instructions or external interference.
[0003] Currently, some solutions adopt a static rule library combined with hardware anomaly detection technology, and judge whether the software execution is compliant through a predefined whitelist of code behaviors and sensor thresholds. When it is detected that the code behavior or sensor data exceeds the preset range, the system triggers an interruption or an alarm and suspends the execution of the abnormal process.
[0004] The static rule library cannot adapt to the dynamically changing equipment operating state, resulting in frequent misjudgments or missed judgments; at the same time, relying on fixed thresholds is difficult to meet the real-time adjustment requirements under complex working conditions, and the protection strategy lacks adaptability, affecting the system operation efficiency. Summary of the Invention
[0005] This application provides a software code security protection method and system based on a domestic platform to solve the problem of poor real-time security protection ability of software code interacting with mechanical equipment under the domestic platform in the prior art.
[0006] In a first aspect, this application provides a software code security protection method based on a domestic platform, including: During the execution of the software code on the domestic platform, obtain the sensing data stream generated by the interaction between the domestic platform and external mechanical equipment, and the sensing data in the sensing data stream includes device state parameters associated with the software code execution process; In the external clock synchronization module of the domestic platform, align the time of the device state parameters with the execution nodes of the software code instructions to generate an operation event sequence, where the software code instructions are function calls, system interface requests, or machine-level operation instructions captured during the operation of the domestic platform; Through the memory isolation operating environment of the domestic platform, use a reinforcement learning mechanism to analyze the dynamic pattern of the operation event sequence, and generate real-time security protection rules for the software code execution path, where the software code execution path is the instruction execution order and branch structure restored from the operation event sequence; Dynamically bind the real-time security protection rules to the kernel layer of the domesticated platform to dynamically update the real-time security protection rules, and feedback the updated security protection rules to the kernel layer to form a closed-loop security protection mechanism.
[0007] Optionally, through the memory isolation operating environment of the domesticated platform, an enhanced learning mechanism is used to analyze the dynamic patterns of the operation event sequences to generate real-time security protection rules for the software code execution paths, including: In the memory isolation operating environment of the domesticated platform, frame-by-frame match the device status parameters in the operation event sequences with the execution nodes of the software code instructions to filter out continuous event segments corresponding to the software code execution paths; Based on the continuous event segments, extract the correlation weights of different instruction nodes in the software code execution paths and construct a dynamic dependency relationship between the instruction nodes and the continuous event segments; Through the enhanced learning mechanism, perform multi-stage state partitioning on the software code execution paths based on the dynamic dependency relationship; During the multi-stage state partitioning process, traverse the branch paths in each stage of the software code execution paths to generate path credibility scores for the branch paths; Generate real-time security protection rules based on the path credibility scores and the correlation weights.
[0008] Optionally, during the multi-stage state partitioning process, traversing the branch paths in each stage of the software code execution paths to generate path credibility scores for the branch paths includes: Based on the start instruction node and the end instruction node of each stage in the multi-stage state partitioning process, determine the execution flow directions of the software code execution paths within each stage; In the execution flow directions, identify the branch paths in the software code execution paths that conflict with the changing trends of the device status parameters in the dynamic dependency relationship and mark them as branch paths to be verified; For each branch path to be verified, obtain the measured values of the device status parameters corresponding to all instruction nodes in the branch path to be verified; Perform node-by-node comparison of the measured values with the expected values of the device status parameters in the dynamic dependency relationship; Based on the comparison results, count the number of deviations between the measured values and the expected values, and calculate the influence factor of the number of deviations on the branch path to be verified in combination with the correlation weights; Weightedly superimpose the influence factor and the timing density of the instruction nodes in the branch path to be verified to generate a path credibility score for the branch path to be verified.
[0009] Optionally, generating a real-time security protection rule according to the path credibility score and the relevance weight includes: Sort the path credibility scores from high to low, and combine the score distribution density to determine a credibility threshold, where the score distribution density is the proportion of the number of branch paths in the same score interval; According to the credibility threshold, filter out the branch paths whose path credibility scores are higher than the credibility threshold and whose relevance weights exceed a preset critical value to generate a set of allowed execution paths; In the set of allowed execution paths, assign a dynamic permission level to each branch path according to the timing density and relevance weight of the instruction nodes of the branch path; Generate a real-time security protection rule based on the dynamic permission level.
[0010] Optionally, generating a real-time security protection rule based on the dynamic permission level includes: Generate a permission level mapping table according to the mapping relationship between the dynamic permission level and the process execution priority in the kernel layer; Based on the boundary values of the memory access intervals in the kernel layer and the blocking instruction node pairs, construct a memory control policy set and a blocking condition set; Encapsulate the permission level mapping table, the memory control policy set, and the blocking condition set into a real-time security protection rule set in a preset format.
[0011] Optionally, in the external clock synchronization module of the domesticated platform, align the device state parameters with the execution nodes of the software code instructions to generate an operation event sequence, including: In the external clock synchronization module of the domesticated platform, respectively receive the sensing data timestamp from an external mechanical device and the instruction execution timestamp of the domesticated platform; Calculate the offsets of the sensing data timestamp and the instruction execution timestamp from the global time reference respectively through the global time reference of the external clock synchronization module; With the global time reference as the axis, within a preset time alignment tolerance range, perform one-to-one matching between the data points of the device state parameters and the execution nodes of the software code instructions. When the offset difference between the sensing data timestamp and the instruction execution timestamp does not exceed the time alignment tolerance, it is determined that the matching is successful; Bind and encapsulate the corresponding data points and execution nodes when the matching is successful to generate an operation event unit; Arrange all the operation event units in the order of the global time reference to form an operation event sequence.
[0012] Optionally, the dynamically binding the real-time security protection rules to the kernel layer of the domesticated platform to dynamically update the real-time security protection rules includes: Pre-set a rule loading interface in the kernel layer of the domesticated platform, and register the privilege level mapping table, memory control policy set and blocking condition set of the real-time security protection rules as kernel environment variables through the rule loading interface; Establish a real-time monitoring channel between the kernel layer environment variables and the sensing data stream; Compare the device state parameters to be updated with the preset sensing data thresholds in the blocking condition set through the real-time monitoring channel; When the device state parameters to be updated exceed the sensing data thresholds, trigger a rule update condition; Dynamically update the real-time security protection rules based on the rule update condition.
[0013] In a second aspect, the present application provides a software code security protection system based on a domesticated platform, including: An acquisition module, configured to acquire a sensing data stream generated by the interaction between the domesticated platform and external mechanical equipment during the execution of the software code on the domesticated platform, and the sensing data in the sensing data stream includes device state parameters associated with the software code execution process; An alignment module, configured to align the device state parameters with the execution nodes of the software code instructions in the external clock synchronization module of the domesticated platform to generate an operation event sequence, where the software code instructions are function calls, system interface requests or machine-level operation instructions captured during the operation of the domesticated platform; An analysis module, configured to analyze the dynamic pattern of the operation event sequence by using a reinforcement learning mechanism through the memory isolation running environment of the domesticated platform to generate real-time security protection rules for the software code execution path, where the software code execution path is the instruction execution order and branch structure restored from the operation event sequence; An update module, configured to dynamically bind the real-time security protection rules to the kernel layer of the domesticated platform to dynamically update the real-time security protection rules, and feedback the updated security protection rules to the kernel layer to form a closed-loop security protection mechanism.
[0014] In a third aspect, the present application provides a computing device, including a processor and a memory. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the method for software code security protection based on a domesticated platform according to any one of the first aspects.
[0015] In a fourth aspect, the present application provides a computer storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the method for software code security protection based on a domesticated platform according to any one of the first aspects is implemented.
[0016] In the present application, a method for software code security protection based on a domesticated platform is provided. The method includes: during the execution of the software code on the domesticated platform, acquiring a sensing data stream generated by the interaction between the domesticated platform and external mechanical equipment, where the sensing data in the sensing data stream includes device state parameters associated with the software code execution process; in the external clock synchronization module of the domesticated platform, aligning the time of the device state parameters with the execution nodes of the software code instructions to generate an operation event sequence, where the software code instructions are function calls, system interface requests, or machine-level operation instructions captured during the operation of the domesticated platform; through the memory isolation running environment of the domesticated platform, using a reinforcement learning mechanism to analyze the dynamic pattern of the operation event sequence to generate real-time security protection rules for the software code execution path, where the software code execution path is the instruction execution order and branch structure restored from the operation event sequence; dynamically binding the real-time security protection rules to the kernel layer of the domesticated platform to dynamically update the real-time security protection rules, and feeding back the updated security protection rules to the kernel layer to form a closed-loop security protection mechanism.
[0017] The technical solution provided by the present application has the following beneficial effects: The present application collects the operation state of mechanical equipment in real time, provides a hardware behavior data basis for security protection, and ensures that the protection system can perceive changes in the physical environment. Through an independent clock module, millisecond-level time alignment is achieved, accurately establishing the causal relationship between code instructions and device states, and solving the misjudgment problem caused by timing misalignment in traditional solutions. In an isolated environment, a reinforcement learning mechanism is used to dynamically model the code-hardware interaction mode, automatically identify abnormal execution paths, and generate protection strategies suitable for complex working conditions. Seamless hot loading of protection rules is realized, and the rules are optimized in real time through sensing data feedback to form an adaptive protection closed-loop of "monitoring - decision - execution".
[0018] Furthermore, the present application also matches the device status and instruction nodes frame by frame in a memory isolation environment, screens continuous event segments and constructs dynamic dependency relationships, divides multi-stage execution path states based on reinforcement learning, and generates real-time protection rules by combining branch path credibility scores and relevance weights.
[0019] Moreover, this solution breaks through the limitations of static rules, realizes the accurate quantification of the influence weight of code instructions on the hardware state; dynamically identifies abnormal branch paths and scores them; adjusts the priority of the protection strategy according to the real-time working conditions, enabling the system to maintain the best operating efficiency while ensuring security.
[0020] These aspects or other aspects of the present application will be more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following briefly introduces the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0022] Figure 1 It is a flowchart of a software code security protection method based on a domestic platform provided by an embodiment of the present application; Figure 2 It is a schematic structural diagram of a software code security protection system based on a domestic platform provided by an embodiment of the present application; Figure 3 It is a schematic structural diagram of a computing device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0023] In order to enable those skilled in the art to better understand the solution of the present application, the following clearly and completely describes the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application.
[0024] In some processes described in the specification and claims of the present application and the above drawings, there are multiple operations that appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order in which they appear in this article or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this article are used to distinguish different messages, devices, modules, etc., and do not represent a sequence, nor do they limit that "first" and "second" are of different types.
[0025] Researchers found that in the scenario of the collaborative operation of domestic platforms and mechanical equipment, traditional protection methods are difficult to achieve the precise correlation between software code execution and hardware state changes, and lack the ability to dynamically adjust protection strategies, resulting in problems such as high false alarm rates and response lags. Based on this, a software code security protection method based on a domestic platform is provided. This method can achieve millisecond-level instruction-sensing data alignment through clock synchronization, use reinforcement learning to analyze the dynamic relationship between code execution paths and device states in a memory isolation environment, and establish kernel-level protection rules that can be updated in real time, forming a closed-loop security protection mechanism for software and hardware collaboration. The technical solution of this application can be applied to domestic platform application scenarios that require high-real-time security protection, such as industrial automation and intelligent manufacturing.
[0026] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of the present application.
[0027] Figure 1 The flowchart of a software code security protection method based on a domestic platform provided for the embodiments of the present application is as Figure 1 shown, and this method includes: Step 101: During the execution of the software code on the domestic platform, obtain the sensing data stream generated by the interaction between the domestic platform and external mechanical equipment. The sensing data in the sensing data stream includes device state parameters associated with the software code execution process.
[0028] In this step, the sensing data stream represents the continuous monitoring data collected by sensors during the operation of mechanical equipment, including physical quantities such as pressure and temperature. The device state parameters are quantitative indicators characterizing the operating state of mechanical equipment, such as specific parameter values such as motor speed and hydraulic pressure.
[0029] In the embodiments of the present application, various sensors deployed on mechanical equipment are used to collect operation data in real time. After converting the analog signals output by the sensors into digital signals, a continuous sensing data stream is formed, and the device state parameters associated with software control instructions are screened out. For example, the speed data synchronously collected when the motor control instruction is executed, and these parameters will be matched and aligned with subsequent software instructions.
[0030] For example, in a certain numerical control machine tool control system, the rotational speed signal is collected by an encoder installed on the spindle motor, and at the same time, the cutting force data is obtained through a force sensor. When the system executes the "start spindle" instruction, the motor speed and cutting force at this time are recorded as the associated device status parameters, and these data are transmitted to the data acquisition module of the domestic platform through the fieldbus.
[0031] Step 102: In the external clock synchronization module of the domestic platform, align the time of the device status parameters with the execution nodes of the software code instructions to generate an operation event sequence. The software code instructions are function calls, system interface requests, or machine-level operation instructions captured during the operation of the domestic platform.
[0032] In this step, the external clock synchronization module represents a dedicated time synchronization unit independent of the system main clock. The operation event sequence represents an instruction-status data combination unit arranged in chronological order. The software code instructions refer to the actual instruction stream during the operation of the domestic platform: the specific machine instructions or operation instructions corresponding to high-level languages generated when the software code (such as industrial control programs, embedded system codes) executed on the domestic platform is running (for example: function calls, system API requests, memory read and write instructions). These instructions are captured in real time through the runtime monitoring module of the domestic platform (such as debugging interfaces, kernel hooks) and recorded together with their corresponding timestamps to form an analyzable instruction sequence. The execution node is not a simple time point, but a combination unit of "instruction + context". Instruction itself: the specific operation currently being executed (for example: "open a certain file", "write data to a certain register"). The execution context includes the timing information of the instruction (such as the clock cycle number), the hardware environment status (such as CPU register values, memory addresses), and the associated mechanical sensing data (such as the real-time position of the robotic arm when executing this instruction).
[0033] In the embodiment of the present application, an independent external clock synchronization module is used to stamp a unified timestamp on the sensing data and instruction execution, and the device status parameters are matched with the corresponding software instruction execution nodes through a time alignment algorithm. When the time deviation between the two is within the allowable range, they are bound to generate an operation event unit containing instruction content, status data, and accurate timestamps, and arranged in chronological order to form a complete operation event sequence.
[0034] For example, continuing with the numerical control machine tool as an example, the external clock module stamps a synchronous timestamp on the "start spindle" instruction and the corresponding rotational speed data, and generates an operation event unit containing instruction code, rotational speed value, and time information after alignment processing. The same processing is performed when the "feed cutting" instruction is executed, and finally an ordered sequence containing multiple operation events is formed.
[0035] Step 103: Through the memory isolation running environment of the domestic platform, analyze the dynamic pattern of the operation event sequence by using a reinforcement learning mechanism, and generate real-time security protection rules for the software code execution path. The software code execution path is the instruction execution order and branch structure restored from the operation event sequence.
[0036] In this step, the memory isolation running environment refers to a dedicated memory area isolated from the main system. The dynamic pattern of the operation event sequence refers to the regular correlation features found between software instruction execution and device state changes by analyzing the instruction-state data combination after time series alignment. These patterns are derived from the statistical learning and feature extraction of the instruction node execution order, device state parameter change trend, and their time series relationship in the historical operation event sequence, and are specifically manifested as quantifiable features such as the typical change curve of device parameters when a specific instruction combination is executed, and the state mutation corresponding to an abnormal instruction sequence. The software code execution path refers to the topological structure of the instruction execution flow restored from the operation event sequence, including the main path of normal execution and the sub-paths generated by conditional branches. Its source is to reconstruct the complete code execution trajectory by analyzing the time sequence relationship and jump logic of instruction nodes in the operation event sequence, which contains path branches corresponding to program structures such as sequential execution, loop, and conditional judgment. The real-time security protection rules refer to a set of security control policies that can take effect immediately and are generated based on the dynamic analysis results, including specific rule entries such as the whitelist of instruction paths allowed to execute, high-risk operation sequences that need to be blocked, and system privilege configurations corresponding to different security levels. These rules have the characteristic of being dynamically adjusted according to changes in the running environment.
[0037] In the embodiment of the present application, the operation event sequence is loaded in the isolated memory area, the correlation law between the instruction execution pattern and the device state change is analyzed by using a reinforcement learning algorithm, the influence weight of different instruction nodes on the device state is calculated, multi-stage states are divided according to the strength of the correlation between each instruction in the execution path, the credibility of the branch paths in each stage is evaluated, and finally, security protection rules including allowed execution paths and blocked paths are generated.
[0038] For example, by analyzing the operation event sequence of a numerically controlled machine tool, it is found that when the rotational speed drops beyond the normal range after the "feed cutting" instruction, abnormal vibration often occurs. The system marks this execution path as high risk. When the feed instruction branch corresponding to the sudden change in cutting force is rated as low credibility, a protection rule is generated to prohibit the execution of such abnormal paths.
[0039] Step 104: Dynamically bind the real-time security protection rules to the kernel layer of the domestic platform to dynamically update the real-time security protection rules, and feedback the updated security protection rules to the kernel layer to form a closed-loop security protection mechanism.
[0040] In this step, closed-loop security protection refers to a protection mechanism with feedback regulation function. The kernel layer of the domestic platform refers to the core part of the autonomous and controllable operating system, including basic functional modules such as process scheduling, memory management, and device drivers, providing low-level interfaces such as environment variable configuration and system call interception. In this solution, it specifically refers to the set of system core components that can receive and execute security protection rules.
[0041] In an embodiment of the present application, the generated security protection rules are written into the environment variables of the kernel layer through the system interface, and the device status changes are monitored in real time. When abnormal fluctuations are detected, the rule update mechanism is triggered, the path credibility is re-evaluated and the protection strategy is adjusted. The updated rules take effect immediately to form a closed-loop control, ensuring that the protection strategy always matches the current device status.
[0042] For example, when the spindle vibration sensor of a CNC machine tool detects an abnormal signal, the system immediately updates the protection rules to limit the feed rate parameters that may cause vibration, and automatically lifts the restriction after the vibration returns to normal. The entire process does not require human intervention.
[0043] This method achieves adaptive safety protection based on actual working conditions by accurately synchronizing device status and software instructions, establishing a dynamic correlation model between the two, and effectively preventing equipment failures caused by code anomalies. It improves the reliability and safety of the control system under the domestic platform, while ensuring the real-time and accuracy of the protection strategy through a closed-loop update mechanism.
[0044] In order to solve the dynamic security protection problem when software code and mechanical equipment are running in coordination in the localized platform, in some embodiments, step 103: the dynamic pattern of the operation event sequence is analyzed by a reinforcement learning mechanism through the memory isolation operation environment of the localized platform to generate real-time security protection rules for the software code execution path, including: Step 201: In the memory isolation operating environment of the localized platform, the device state parameters in the operation event sequence are matched with the execution nodes of the software code instructions frame by frame to filter out continuous event segments corresponding to the software code execution path.
[0045] In step 201, the device status parameters in the sensing data stream and the device status parameters in the operation event sequence are manifestations of the same data entity at different processing stages; the device status parameters in the sensing data stream represent the original physical quantity data stream directly obtained from mechanical sensors (such as pressure and displacement sensors). Continuous signals not aligned with the code execution time (such as 1000 pressure samples per second); only the time stamps of the sensors themselves are marked (not associated with software instructions). The device status parameters in the operation event sequence represent the parameter values bound to the execution nodes of the software code instructions after clock synchronization processing of the original sensing data stream. Discrete parameter values aligned with the instruction execution time at the millisecond level (such as the torque sensor reading at the moment when a certain "motor drive" instruction is executed); additional instruction context (such as associated code functions and memory addresses). The continuous quantity is determined by a preset time window or the number of instruction nodes (such as data within 10 consecutive instruction nodes or 200 milliseconds), and the specific value is dynamically adjusted according to the scenario and is not fixed. The continuous event segment refers to the continuous interval in which the device status parameters and the instruction nodes in the operation event sequence are closely related in time, and is used to analyze the dynamic dependency relationship between code execution and hardware status.
[0046] In the embodiment of the present application, after the system loads the operation event sequence in the memory isolation area, it uses the sliding window technology to intercept data segments according to a fixed time length, and filters out the continuous intervals in which the device status changes are highly correlated with the instruction execution through a matching algorithm, and eliminates the noise interference data to obtain continuous event segments reflecting the real control process.
[0047] Step 202: Based on the continuous event segments, extract the correlation weights of different instruction nodes in the software code execution path, and construct the dynamic dependency relationship between the instruction nodes and the continuous event segments.
[0048] In step 202, the instruction node represents the further analysis object of the execution node, specifically referring to the instruction execution unit that is filtered out in the continuous event segment and strongly associated with the device state parameters. Newly added attributes: the relevance weight assigned through dynamic dependency analysis (such as the influence intensity of a certain instruction on the sensor value); the path branch attribute in the multi-stage state division (such as whether to trigger the exception handling branch). It is used to construct the protection rule generation logic of the code execution path. The execution node represents the smallest logical unit in which the software code instruction is bound to its execution timestamp and the associated mechanical sensing data (device state parameters) during the operation of the domestic platform. Constituent elements: software code instructions (such as function calls, machine instructions); the precise timestamp after clock synchronization; the device state parameters corresponding to the instruction execution (such as sensor readings). It is used to establish the association relationship of instruction-time-hardware state in the operation event sequence. The execution node focuses on describing the original relevance in the data acquisition and alignment stage; the instruction node focuses on describing the analysis object in the rule generation stage. The two are the manifestation forms of the same entity in different technical stages. The relevance weight is a parameter that quantifies the influence degree of the instruction node on the device state. The dynamic dependency relationship represents the causal association strength between instruction execution and state change.
[0049] In the embodiment of the present application, time-frequency analysis and correlation calculation are performed on each continuous event segment, the deviation degree of the device state parameters after the execution of each instruction node is statistically calculated, the weight value in the 0-1 interval is obtained through normalization processing, and a mapping relationship matrix of instruction-state change is established to form a dynamic dependency relationship model.
[0050] Step 203: Through the reinforcement learning mechanism, perform multi-stage state division on the software code execution path based on the dynamic dependency relationship.
[0051] In step 203, the multi-stage state division refers to dividing the code execution process into several state intervals with different characteristics according to the dynamic dependency relationship. The division basis for each stage is the cumulative offset of the device state parameters of the continuous event segment within the preset time window.
[0052] In the embodiment of the present application, the reinforcement learning model analyzes the dynamic dependency relationship matrix, identifies the state mutation points and the turning points of the behavior patterns, and divides the execution path into different stages such as initialization, stable operation, and exception handling with these key nodes as the boundaries. Each stage contains specific instruction combinations and state change characteristics.
[0053] Step 204: During the multi-stage state division process, traverse each branch path in the software code execution path to generate the path credibility score of the branch path.
[0054] In step 204, the branch paths at each stage within the software code execution path refer to the different execution flows generated by the program control logic within each stage after multi-stage state partitioning, including jump paths triggered by conditional statements, exception handling branches, and repetitive execution paths generated by loop structures; these branch paths are derived from the analysis of the execution order of instruction nodes in the operation event sequence. By identifying control flow change points such as conditional jump instructions and interrupt call instructions in the program, and combining the corresponding device state parameter change characteristics, all possible execution path branches that the code may take during actual operation are restored. The path credibility score is a quantitative indicator for evaluating the security of branch paths.
[0055] In the embodiment of the present application, the system traverses all possible branch paths within each stage, calculates the instruction compliance and state stability indicators of each path in combination with the dynamic dependency relationship, and comprehensively evaluates through a weighted algorithm to obtain a credibility score ranging from 0 to 100 points.
[0056] Step 205: Generate real-time security protection rules according to the path credibility score and the relevance weight.
[0057] In the embodiment of the present application, the system sets a hierarchical protection strategy according to the scoring results, adds high-scoring paths to the whitelist and assigns operation permissions, sets monitoring and early warning for medium-scoring paths, directly blocks low-scoring paths, and generates a rule configuration file that can be loaded into the kernel.
[0058] The following is a specific example: In the specific implementation of a numerical control machine tool control system, the system first aligns the "start spindle" instruction with the corresponding rotational speed data (such as 1200 revolutions per minute) and the "feed cutting" instruction with the cutting force data (such as 500N) in terms of time to form an operation event sequence including instructions, parameter values, and timestamps; in the memory isolation environment, the system analyzes and finds that when the rotational speed drops by more than the normal range (the calculation standard is: current rotational speed < reference rotational speed × 0.8, where the reference rotational speed is the average value of the last 10 normal cuttings) after the "feed cutting" instruction is executed, and at the same time the cutting force fluctuation exceeds the threshold (cutting force change rate > 50N / ms), the relevance weight of this instruction node is calculated to be 0.9 through the reinforcement learning model (weight calculation formula: relevance weight = rotational speed deviation coefficient × 0.6 + cutting force fluctuation coefficient × 0.4), and the system classifies this execution path as a high-risk stage; when evaluating the credibility of the branch path, if it is detected that the "rapid feed" branch path satisfies both the conditions of rotational speed drop and cutting force fluctuation, then a credibility score of 30 points is given to this path (score calculation: basic score 100 points - rotational speed deviation deduction 40 points - cutting force fluctuation deduction 30 points), and finally a protection rule is generated to limit the feed rate not to exceed 70% of the set value.
[0059] In the embodiments of the present application, the method realizes adaptive safety protection based on the actual working conditions by establishing a dynamic association model between code execution and device status, effectively preventing and controlling device failures caused by anomalies, and at the same time taking into account system security and operation efficiency through a hierarchical protection mechanism.
[0060] In order to improve the accuracy of software code execution path safety assessment in the domestic platform, in some embodiments, step 204: In the multi-stage state partitioning process, traverse each branch path in the software code execution path to generate a path credibility score for the branch path, including: Step 301: Determine the execution flow of the software code execution path in each stage according to the start instruction node and end instruction node of each stage in the multi-stage state partitioning process.
[0061] In step 301, the execution flow refers to all possible instruction execution sequences and jump relationships of the code within a specific stage.
[0062] In the embodiments of the present application, the system extracts all control flow transfer relationships between the start and end instruction nodes according to the stage partitioning result, and enumerates a complete set of execution paths including normal flow, exception handling, conditional branches, etc. through a graph traversal algorithm.
[0063] Step 302: In the execution flow, identify a branch path in the software code execution path that conflicts with the change trend of the device status parameter in the dynamic dependency relationship, and mark it as a branch path to be verified.
[0064] In step 302, a conflict means that in the execution flow, when the measured change trend of the device status parameter corresponding to the instruction node sequence included in a branch path is inconsistent with the expected trend recorded in the dynamic dependency relationship, it is determined as a conflict. For example: the branch path includes instruction nodes A to B to C, and the dynamic dependency relationship stipulates that the pressure sensor value should increase when executing node A, while the measured data shows that the pressure value decreases or remains unchanged after executing node A, then this branch path is marked as a branch path to be verified. A branch path to be verified refers to a code execution branch where the actual change of the device status differs from the expected model.
[0065] In the embodiments of the present application, the system performs a similarity match between the device status change curve of each branch path and the dynamic dependency relationship model. When the correlation coefficient between the actual parameter change trend and the expected model is lower than the set threshold, the path is marked as a to-be-verified state.
[0066] Step 303: For each branch path to be verified, obtain the measured values of the device status parameters corresponding to all instruction nodes in the branch path to be verified.
[0067] In step 303, the measured value refers to the numerical value of the device status parameter actually collected during the execution of the branch path.
[0068] In the embodiment of the present application, the system extracts all the sensor data corresponding to the path to be verified from the operation event sequence, including the instantaneous value at the time of instruction execution and the change amount after execution, to form a complete record of the status parameters of the path.
[0069] Step 304: Compare the measured value with the expected value of the device status parameter in the dynamic dependency one by one for each node.
[0070] In step 304, the expected value is the theoretical change range of the device status calculated according to the dynamic dependency model.
[0071] In the embodiment of the present application, the system calculates the reasonable fluctuation range of the device status parameter after each instruction execution according to the correlation weight of the instruction node and the historical normal data, as the comparison benchmark.
[0072] Step 305: According to the comparison result, count the number of deviations between the measured value and the expected value, and calculate the influence factor of the number of deviations on the path to be verified in combination with the correlation weight.
[0073] In step 305, the influence factor is a comprehensive index that quantifies the degree of influence of abnormal deviation on the path security.
[0074] In the embodiment of the present application, the system counts the number of parameter points exceeding the expected range, multiplies it by the correlation weight of the corresponding instruction node, and then divides it by the total number of instructions in the path to obtain the standardized influence factor value.
[0075] Step 306: Weight and superimpose the influence factor with the timing density of the instruction nodes in the path to be verified to generate the path credibility score of the path to be verified.
[0076] In step 306, the timing density is the number of instruction nodes executed per unit time in the branch path.
[0077] In the embodiment of the present application, the system calculates the average number of instructions per unit time in the path, sums the influence factor and the timing density by weighted summation according to a preset ratio, and finally generates a path credibility score in the range of 0 - 100.
[0078] The following is a specific example: During the machining process of a numerically controlled machine tool, the system first identifies that the start instruction for the "finish machining stage" is "turn on the coolant", and the end instruction is "turn off the coolant", and determines that this stage includes two execution paths: "conventional feed" and "high-speed feed"; when it detects that in the "high-speed feed" path, the spindle speed drops suddenly from 1200 revolutions per minute to 900 revolutions per minute (lower than the reference speed of 1200×0.8 = 960 revolutions per minute), and at the same time the cutting force rises rapidly from 500N to 650N (the change rate of 60N / ms > the threshold of 50N / ms), the system marks this path as a branch to be verified; obtain the measured speed values [1200, 1150, 900] revolutions per minute and the cutting force values [500, 580, 650]N corresponding to all instruction nodes under this path; compare them point by point with the expected values in the dynamic dependency relationship (the speed should be maintained within [1150, 1250] revolutions per minute, and the change rate of the cutting force should be < 50N / ms), and find that there is 1 deviation point for the speed (900 revolutions per minute) and 2 deviation points for the cutting force (580N and 650N); calculate the impact factor as (1×0.6 + 2×0.4) / 3 = 0.47 according to the correlation weight (speed weight 0.6, cutting force weight 0.4); combined with the high time sequence density of this path (4 instructions / ms), perform weighted calculation according to the impact factor weight of 70% and the time sequence density weight of 30%, and finally generate the path credibility score = 100×(1 - 0.47)×0.7 + 100×(1 - 0.2)×0.3 = 58 points (where the time sequence density deduction of 0.2 is calculated according to the ratio of the density exceeding the standard value of 3 instructions / ms).
[0079] In the embodiment of the present application, this method realizes the accurate identification and hierarchical control of abnormal execution modes by quantitatively evaluating the safety of code branch paths in multiple dimensions, effectively prevents abnormal operation of equipment caused by code logic defects, and at the same time avoids the impact of overprotection on normal machining efficiency.
[0080] In order to further improve the accuracy and adaptability of generating safety protection rules for domestic platforms, in some embodiments, step 205: generating real-time safety protection rules according to the path credibility score and the correlation weight includes: Step 401: Sort the path credibility scores from high to low, and determine the credibility threshold in combination with the score distribution density, where the score distribution density is the proportion of the number of branch paths in the same score interval.
[0081] In step 401, the scoring distribution density refers to the proportion of the number of branch paths in each scoring interval to the total number of paths. The credibility threshold is the critical scoring value for dividing safe and risky paths. The proportion of the number of branch paths refers to the proportion of the number of branch paths in the same scoring interval to the total number of all traversed branch paths (for example: there are 5 branch paths with a score of 7 - 8, and a total of 20 branch paths are traversed, so the proportion is 25%).
[0082] In the embodiment of the present application, the system divides the credibility scores of all branch paths into intervals (such as 0 - 30 points, 31 - 60 points, 61 - 100 points), calculates the proportion of the number of paths in each interval, and selects the score corresponding to the sudden drop point of the proportion as the credibility threshold to ensure that high - risk paths can be effectively identified.
[0083] Step 402: According to the credibility threshold, filter out the branch paths whose path credibility scores are higher than the credibility threshold and whose relevance weights exceed the preset critical value to generate a set of allowed execution paths.
[0084] In step 402, the preset critical value is the lowest passing value of the relevance weight. The set of allowed execution paths is a collection of safe paths that have undergone double - screening.
[0085] In the embodiment of the present application, the system first filters out the paths with scores higher than the credibility threshold, and then selects the paths whose relevance weights exceed the critical value (such as 0.7) to add to the set, ensuring that the selected paths meet the standards in both behavioral safety and hardware impact.
[0086] Step 403: In the set of allowed execution paths, assign dynamic permission levels to each branch path according to the instruction node timing density and relevance weight of each branch path.
[0087] In step 403, the dynamic permission level is the operation permission level assigned according to the path characteristics.
[0088] In the embodiment of the present application, the system constructs a two - dimensional evaluation matrix using the timing density and relevance weight, divides the paths into multiple permission levels, assigns high permissions (modifiable core parameters) to high - density and high - weight paths, and assigns basic permissions (only read permissions) to low - density and low - weight paths.
[0089] Step 404: Generate real - time security protection rules based on the dynamic permission levels.
[0090] In the embodiment of the present application, the system maps the permission levels to specific operation restriction rules. For example, high - permission paths can adjust the upper limit of the feed speed, low - permission paths can only use default parameters, and an audit mechanism for path switching is set.
[0091] The following is a specific example: During the machining process of the CNC machine tool, after the system evaluates 15 machining paths, the credibility score distributions of each path are as follows: 3 paths with scores of 90 - 100 (accounting for 20%), 5 paths with scores of 70 - 89 (accounting for 33%), 4 paths with scores of 50 - 69 (accounting for 27%), 2 paths with scores of 30 - 49 (accounting for 13%), and 1 path with scores of 0 - 29 (accounting for 7%). A credibility threshold of 70 points is selected (because the decline rate of the proportion from 70 - 89 points to 50 - 69 points is the largest); 7 paths with scores ≥ 70 and relevance weights ≥ 0.8 are screened out to form an allowable execution set, including the "finish machining - low - speed feed" path (score 85 points, weight 0.85) and the "rough machining - medium - speed feed" path (score 75 points, weight 0.8); According to the timing density (3.2 instructions / millisecond for finish machining, 4.1 instructions / millisecond for rough machining) and the weight, the permission value is calculated (permission value = timing density × 0.4 + weight × 0.6). The finish machining path (permission value = 3.2 × 0.4 + 0.85 × 0.6 = 0.78) is classified as a level 2 permission, and the rough machining path (permission value = 4.1 × 0.4 + 0.8 × 0.6 = 0.86) is classified as a level 3 permission; The finally generated protection rules stipulate that level 3 paths can adjust the rotational speed (±15%) and the feed speed (±20%), level 2 paths can only adjust the feed speed (±10%), and other paths use fixed parameters. When executing "finish machining - low - speed feed", the system allows the operator to finely adjust the feed speed within 10%, but prohibits modifying the spindle speed parameter.
[0092] In the embodiment of the present application, through multi - dimensional evaluation and hierarchical control, the method realizes the refined security management of the code execution path, which not only ensures the effective prevention of high - risk operations, but also guarantees the flexible control of the normal machining process, and improves the security and usability of the domestic CNC system.
[0093] In order to further improve the systematicness and enforceability of the security protection rules for the domestic platform, in some embodiments, step 404: generating real - time security protection rules based on the dynamic permission level includes: Step 501: Generate a permission level mapping table according to the mapping relationship between the dynamic permission level and the process execution priority in the kernel layer.
[0094] In step 501, the kernel layer is the core component of the domestic platform, referring to the kernel space of the domestic operating system, which directly manages hardware resources and process scheduling. The execution of software code depends on basic services provided by the kernel layer, such as process management (e.g., priority scheduling) and memory access control (e.g., interval boundaries). The process execution priority is an existing parameter of the kernel layer environment variable. The permission level mapping table is a correspondence table between the dynamic permission level and the kernel process scheduling parameters.
[0095] In the embodiment of the present application, the system establishes a three-level permission mapping relationship: level 1 is mapped to the normal priority, allowing basic operations; level 2 is mapped to the higher priority, enabling parameter adjustment; level 3 is mapped to the real-time priority, allowing critical operations. By querying the system scheduling parameter range, a complete mapping table including permission levels, priority intervals, and available system call lists is automatically generated.
[0096] Step 502: Based on the boundary values of the memory access intervals and the blocking instruction node pairs in the kernel layer, construct a memory control policy set and a blocking condition set.
[0097] In step 502, the boundary values of the memory access intervals are calculated based on the product of the instruction node timing density and the correlation weight, representing the boundaries of the memory address range that a process can access in the kernel layer (such as the starting address 0x1000 and the ending address 0x2000). The blocking instruction nodes are combinations of the starting instruction node and the ending instruction node extracted from the blocking path set, representing the identification of abnormal code jump behaviors that need to be blocked (such as the illegal jump from instruction A to instruction D). The memory control policy set is a set of control rules that define the memory access ranges for each permission level. The blocking condition set is a combination of instruction sequences that trigger protection and sensor thresholds.
[0098] In the embodiment of the present application, the system divides the memory access intervals according to the permission levels: level 1 can access the user space, level 2 adds the device mapping area, and level 3 can access all spaces. The blocking condition set analyzes historical abnormal data to record dangerous instruction combinations (such as "high-speed feed + coolant off") and corresponding sensor thresholds (vibration > 5mm / s).
[0099] Step 503: Package the permission level mapping table, the memory control policy set, and the blocking condition set into a real-time security protection rule set in a preset format.
[0100] In the embodiment of the present application, the system packages the mapping table, the control policy, and the blocking condition in a preset format, including three modules: permission definition, memory area, and blocking rule. The hot loading of the configuration is implemented through the kernel module interface to ensure that rule updates do not affect the system operation.
[0101] The following is a specific example: During the implementation of the numerical control machine tool control system, the system first establishes the mapping relationship between dynamic permission levels and kernel parameters: map the level 3 permission (rough machining - medium-speed feed path) to the real-time priority value 80 (range 1 - 99), allowing up to 90% of CPU resources to be occupied; map the level 2 permission (finish machining - low-speed feed path) to the normal priority value -10 (range -20 to 19), restricting CPU occupancy to no more than 70%. The memory access interval boundary values are calculated according to the permission levels: level 3 can access the entire memory space from 0x00000000 to 0x3fffffff (calculation method: base address 0x00000000 plus permission value 0.86 × 0x40000000); level 2 is restricted to 0x00000000 to 0x2ffffff (base address plus permission value 0.78 × 0x40000000). The blocking condition set records that the instruction combination when the spindle speed exceeds 1500 revolutions and the vibration is greater than 0.05 mm is a dangerous operation. Finally, the system encapsulates these rules in a structured text format, including three parts: the permission mapping part records the relationship between levels and kernel parameters, the memory control part defines the accessible address ranges for each level, and the blocking condition part lists 10 groups of dangerous instruction and sensor threshold combinations.
[0102] In the embodiment of the present application, through a systematic rule organization and dynamic loading mechanism, the method realizes the deep integration of the security protection strategy and the platform kernel, ensuring both the protection effect and the real-time performance and stability of the system operation, and effectively improving the security protection ability of the domestic industrial control system.
[0103] In order to further improve the time synchronization accuracy of the device status and software instructions in the domestic platform, in some embodiments, step 102: in the external clock synchronization module of the domestic platform, align the time of the device status parameters with the execution nodes of the software code instructions to generate an operation event sequence, including: Step 601: In the external clock synchronization module of the domestic platform, receive the sensing data timestamp from the external mechanical equipment and the instruction execution timestamp of the domestic platform respectively.
[0104] In step 601, the sensing data timestamp is the moment when the sensor data is collected recorded by the local clock of the mechanical equipment. The instruction execution timestamp is the moment when the code instruction starts to be executed recorded by the domestic platform. Among them, the sensing data timestamp is generated by the local clock of the mechanical equipment, and the instruction execution timestamp is generated by the auxiliary timing unit of the domestic platform.
[0105] In the embodiments of the present application, the external clock synchronization module respectively receives the sensor data packet (including the pressure value and the timestamp) from the PLC controller and the instruction execution log (including the instruction content and the execution time) of the domestic platform through a dedicated interface to ensure the integrity of the original time information.
[0106] Step 602: Calculate the offsets of the sensor data timestamp and the instruction execution timestamp from the global time reference of the external clock synchronization module respectively through the global time reference of the external clock synchronization module.
[0107] In step 602, the global time reference is a highly accurate unified time reference maintained by the external clock synchronization module. The offset is the time difference between each timestamp and the reference.
[0108] In the embodiments of the present application, the module uses a precision clock source (such as an atomic clock) as the reference, and calculates the millisecond-level differences between the sensor timestamp and the instruction timestamp and the reference respectively. For example, the sensor timestamp is 1.2 milliseconds slower than the reference, and the instruction timestamp is 0.8 milliseconds faster than the reference.
[0109] Step 603: Using the global time reference as the axis, within the preset time alignment tolerance range, perform one-to-one matching between the data points of the device state parameters and the execution nodes of the software code instructions. When the offset difference between the sensor data timestamp and the instruction execution timestamp does not exceed the time alignment tolerance, it is determined that the matching is successful.
[0110] In step 603, the time alignment tolerance is the maximum allowable time matching error range.
[0111] In the embodiments of the present application, a tolerance value of 2 milliseconds is set. When the absolute difference (2.0 milliseconds) between the sensor offset (+1.2 ms) and the instruction offset (-0.8 ms) does not exceed the tolerance, it is determined that the pressure data and the instruction match successfully.
[0112] Step 604: Bind and encapsulate the corresponding data points and execution nodes when the matching is successful to generate an operation event unit.
[0113] In step 604, the operation event unit is a successfully bound instruction-state data combination. Each operation event unit includes at least the instruction content, the device state parameter value, and the alignment timestamp under the global time reference.
[0114] In the embodiments of the present application, the successfully matched "start the main shaft" instruction (execution time T1) and the pressure sensor data (acquisition time T2) are encapsulated into a unit, including the instruction code, the pressure value, and the calibrated unified time ((T1 + T2) / 2).
[0115] Step 605: Arrange all the operation event units in the order of the global time reference to form an operation event sequence.
[0116] In the embodiment of the present application, the system sorts all event units according to a unified time. For example, the "start spindle" event (time T) is arranged first, and then the "feed cutting" event (time T + 10 ms) is arranged to form a complete machining process sequence.
[0117] The following is a specific example: During the implementation of the numerical control machine tool control system, the external clock synchronization module refers to the global time reference established by a high-precision clock source (for example, the reference time is set to 08:00:00.000). When the system executes the "start spindle" instruction, the platform instruction execution timestamp is recorded as 08:00:01.005. At the same time, the rotational speed data of 1200 revolutions per minute reported by the encoder and its local timestamp of 08:00:01.008 are received. The instruction time offset is calculated as +5 milliseconds (08:00:01.005 - 08:00:00.000), and the rotational speed data offset is +8 milliseconds (08:00:01.008 - 08:00:00.000). The deviation of 3 milliseconds exceeds the preset tolerance of 2 milliseconds, so it is determined that they do not match. Subsequently, when the "feed cutting" instruction is executed, the platform records the instruction time as 08:00:05.002, the force sensor reports the cutting force data of 500 N and the timestamp of 08:00:05.003. The instruction offset is calculated as +2 milliseconds, and the cutting force offset is +3 milliseconds. The deviation of 1 millisecond is within the tolerance range. After successful matching, an operation event unit is generated (instruction: "feed cutting", cutting force: 500 N, calibration time: 08:00:05.0025). This time value takes the average of the two timestamps ((08:00:05.002 + 08:00:05.003) / 2). Finally, all the event units with successful matching are sorted according to the calibration time. For example, the "feed cutting" event is arranged after the "start spindle" event to form a complete machining process operation event sequence, providing an accurate timing data basis for subsequent analysis.
[0118] In the embodiment of the present application, this method ensures the precise association between the device state and the software instruction through high-precision time alignment, provides a reliable timing data basis for subsequent safety analysis, and effectively solves the misjudgment problem caused by time asynchronization in traditional methods.
[0119] To further improve the dynamic update ability of the domestic platform security protection rules, in some embodiments, step 104: The dynamically binding the real-time security protection rules to the kernel layer of the domestic platform to dynamically update the real-time security protection rules includes: Step 701: pre-set a rule loading interface in the kernel layer of the localized platform, and register the permission level mapping table, memory control policy set and blocking condition set of the real-time security protection rules as kernel environment variables through the rule loading interface.
[0120] In step 701, the rule loading interface is a dedicated configuration channel provided by the kernel layer for safely injecting protection rules.
[0121] In an embodiment of the present application, the system creates a specific character device file by developing a kernel module, and writes the permission level mapping table, memory control policy and blocking condition set into the kernel environment variable area in a structured data format to ensure that the rule loading process does not interfere with normal system scheduling.
[0122] Step 702: Establish a real-time monitoring channel between the kernel layer environment variables and the sensor data stream.
[0123] In step 702, the real-time monitoring channel is a data path connecting the sensor data and the kernel rules.
[0124] In an embodiment of the present application, the system uses an interrupt mechanism and shared memory technology to build a monitoring channel. When the sensor data is updated, an interrupt is immediately triggered, and the latest data is passed to the kernel layer through a pre-allocated shared memory area to achieve a microsecond response.
[0125] Step 703: Compare the device status parameter to be updated with the sensor data threshold preset in the blocking condition set through the real-time monitoring channel.
[0126] In step 703, the device state parameter to be updated is the latest sensor data that needs to be evaluated.
[0127] In an embodiment of the present application, the system obtains real-time sensor readings from the monitoring channel (such as the current spindle vibration value of 0.05mm), compares it with the threshold value preset in the blocking condition set (such as the vibration threshold value of 0.03mm), and calculates the degree of deviation.
[0128] Step 704: When the device state parameter to be updated exceeds the sensor data threshold, a rule update condition is triggered.
[0129] In step 704, the rule update condition is a criterion for triggering the protection rule adjustment.
[0130] In the embodiment of the present application, when the vibration value is detected to exceed the threshold value (0.03 mm) for three consecutive times and the excess amplitude increases by more than 20% each time, it is determined that the update condition is met and a rule update instruction is generated.
[0131] Step 705: Dynamically update the real-time security protection rules based on the rule update conditions.
[0132] In step 705, dynamic update refers to the hot replacement of rules without restarting the system.
[0133] In the embodiment of the present application, the system recalculates the safety path score based on the latest sensor data analysis results, generates an updated permission mapping table and blocking conditions, and replaces the old rules in the kernel environment variables through atomic operations to ensure that the update process does not interrupt the system operation.
[0134] The following is a specific example: During the implementation of the numerical control machine tool control system, the system loads the initial safety protection rules into the kernel environment variable area through the rule configuration interface preset in the kernel, including setting that the speed range adjustable by permission level 3 is ±10% (1200 ± 120 rpm), and the blocking condition is "vibration value > 0.03 mm and cutting force > 550 N"; establish a real-time monitoring channel for sensor data. When the vibration values reach 0.035 mm, 0.042 mm, and 0.050 mm (each increasing by more than 20% each time) continuously during the "precision machining" process, and the cutting force rises to 580 N, the system determines that the rule update condition is met (vibration overrun amplitude = (current value - threshold) / threshold × 100%, and the three calculation results are 16.7%, 40%, and 66.7% respectively); based on the latest sensor data analysis, recalculate that the safe speed range should be reduced to ±5% (1200 ± 60 rpm), and update the blocking condition to "vibration > 0.025 mm or cutting force > 500 N"; the system hot-updates the new rules to the kernel through atomic operations, immediately limits the current machining speed to 1140 rpm, and automatically restores the original speed adjustment permission after the vibration drops below 0.02 mm and lasts for 10 seconds. The whole process does not require shutdown and maintains machining continuity.
[0135] In the embodiment of the present application, this method realizes the real-time adaptation of the protection strategy to the device state through the rule dynamic binding and update mechanism at the kernel level, effectively prevents potential safety hazards caused by rule lag, and at the same time ensures the continuity and stability of the industrial control process.
[0136] Figure 2 It is a schematic structural diagram of a software code security protection system based on a domestic platform provided for the embodiment of the present application, as Figure 2 shown, the system includes: An acquisition module 21, configured to acquire a sensing data stream generated by the interaction between the domestic platform and external mechanical equipment during the execution of the software code on the domestic platform, and the sensing data in the sensing data stream includes device state parameters associated with the software code execution process.
[0137] An alignment module 22, which is used to align the device status parameters with the execution nodes of the software code instructions in the external clock synchronization module of the domestic platform to generate an operation event sequence, where the software code instructions are function calls, system interface requests, or machine-level operation instructions captured during the operation of the domestic platform.
[0138] An analysis module 23, which is used to analyze the dynamic pattern of the operation event sequence through the memory isolation running environment of the domestic platform by adopting a reinforcement learning mechanism to generate real-time security protection rules for the software code execution path, where the software code execution path is the instruction execution order and branch structure restored from the operation event sequence.
[0139] An update module 24, which is used to dynamically bind the real-time security protection rules to the kernel layer of the domestic platform to dynamically update the real-time security protection rules and feedback the updated security protection rules to the kernel layer to form a closed-loop security protection mechanism.
[0140] Figure 2 The described software code security protection system based on a domestic platform can execute Figure 1 The software code security protection method based on a domestic platform shown in the illustrated embodiment, and its implementation principle and technical effects will not be elaborated further. For the software code security protection system based on a domestic platform in the above embodiment, the specific ways for each module and unit to execute operations have been described in detail in the embodiment related to the method, and will not be elaborated here.
[0141] In a possible design, Figure 2 The software code security protection system based on a domestic platform shown in the illustrated embodiment can be implemented as a computing device, such as Figure 3 shown, and this computing device can include a storage component 31 and a processing component 32; The storage component 31 stores one or more computer instructions, where the one or more computer instructions are called and executed by the processing component 32.
[0142] The processing component 32 is used to execute the Figure 1 software code security protection method based on a domestic platform shown in the above
[0143] Among them, the processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above-mentioned method. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components, and is used to execute the above-mentioned method.
[0144] The storage component 31 is configured to store various types of data to support the operation of the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disc.
[0145] Of course, the computing device may also necessarily include other components, such as input / output interfaces, display components, communication components, etc.
[0146] The input / output interface provides an interface between the processing component and the peripheral interface module, and the above-mentioned peripheral interface module may be an output device, an input device, etc.
[0147] The communication component is configured to facilitate communication between the computing device and other devices in a wired or wireless manner, etc.
[0148] Among them, the computing device may be a physical device or an elastic computing host provided by a cloud computing platform, etc. At this time, the computing device may refer to a cloud server, and the above-mentioned processing component, storage component, etc. may be basic server resources leased or purchased from a cloud computing platform.
[0149] The embodiments of the present application also provide a computer storage medium storing a computer program, which can implement the above-mentioned Figure 1 software code security protection method based on a domestic platform shown in the embodiments.
[0150] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0151] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0152] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0153] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments or equivalently replace some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A software code security protection method based on a domestic platform, characterized in that Including: During the execution of the software code on the domesticated platform, obtain the sensor data stream generated by the interaction between the domesticated platform and external mechanical equipment. The sensor data in the sensor data stream includes device state parameters associated with the software code execution process; In the external clock synchronization module of the domesticated platform, align the device state parameters with the execution nodes of the software code instructions in terms of time to generate an operation event sequence. The software code instructions are function calls, system interface requests, or machine-level operation instructions captured during the operation of the domesticated platform; Through the memory isolation running environment of the domesticated platform, analyze the dynamic pattern of the operation event sequence using a reinforcement learning mechanism to generate real-time security protection rules for the software code execution path. The software code execution path is the instruction execution order and branch structure restored from the operation event sequence; Dynamically bind the real-time security protection rules to the kernel layer of the domesticated platform to dynamically update the real-time security protection rules and feedback the updated security protection rules to the kernel layer to form a closed-loop security protection mechanism.
2. The method according to claim 1, characterized in that, The step of analyzing the dynamic pattern of the operation event sequence using a reinforcement learning mechanism through the memory isolation running environment of the domesticated platform to generate real-time security protection rules for the software code execution path includes: In the memory isolation running environment of the domesticated platform, perform frame-by-frame matching of the device state parameters in the operation event sequence with the execution nodes of the software code instructions to filter out continuous event segments corresponding to the software code execution path; Based on the continuous event segments, extract the correlation weights of different instruction nodes in the software code execution path and construct a dynamic dependency relationship between the instruction nodes and the continuous event segments; Through the reinforcement learning mechanism, perform multi-stage state division on the software code execution path based on the dynamic dependency relationship; During the multi-stage state division process, traverse the branch paths in each stage of the software code execution path to generate path credibility scores for the branch paths; Generate real-time security protection rules according to the path credibility scores and the correlation weights.
3. The method according to claim 2, wherein The step of traversing the branch paths in each stage of the software code execution path during the multi-stage state division process to generate path credibility scores for the branch paths includes: According to the start instruction node and end instruction node of each stage in the multi-stage state division process, determine the execution flow of the software code execution path within each stage; In the execution flow, identify the branch paths in the software code execution path that conflict with the change trend of the device state parameters in the dynamic dependency relationship and mark them as branch paths to be verified; For each branch path to be verified, obtain the measured values of the device state parameters corresponding to all instruction nodes in the branch path to be verified; Perform node-by-node comparison of the measured values with the expected values of the device state parameters in the dynamic dependency relationship; According to the comparison result, count the number of deviations between the measured value and the expected value, and calculate the influence factor of the number of deviations on the branch path to be verified in combination with the relevance weight; Weightedly superimpose the influence factor and the timing density of the instruction nodes in the branch path to be verified to generate a path credibility score for the branch path to be verified.
4. The method according to claim 2, characterized in that, Generating a real-time security protection rule according to the path credibility score and the relevance weight includes: Sort the path credibility scores from high to low, and determine a credibility threshold in combination with the score distribution density, where the score distribution density is the proportion of the number of branch paths in the same score interval; According to the credibility threshold, filter out the branch paths whose path credibility scores are higher than the credibility threshold and whose relevance weights exceed a preset critical value to generate a set of allowed execution paths; In the set of allowed execution paths, assign a dynamic permission level to each branch path according to the instruction node timing density and relevance weight of the branch path; Generate a real-time security protection rule based on the dynamic permission level.
5. The method according to claim 4, wherein Generating a real-time security protection rule based on the dynamic permission level includes: Generate a permission level mapping table according to the mapping relationship between the dynamic permission level and the process execution priority in the kernel layer; Based on the boundary values of the memory access intervals in the kernel layer and the blocking instruction node pairs, construct a memory control policy set and a blocking condition set; Package the permission level mapping table, the memory control policy set, and the blocking condition set into a real-time security protection rule set in a preset format.
6. The method according to claim 1, wherein In the external clock synchronization module of the domesticated platform, align the device state parameters with the execution nodes of the software code instructions in time to generate an operation event sequence, including: In the external clock synchronization module of the domesticated platform, receive the sensing data timestamp from the external mechanical device and the instruction execution timestamp of the domesticated platform respectively; Calculate the offsets of the sensing data timestamp and the instruction execution timestamp from the global time reference respectively through the global time reference of the external clock synchronization module; Taking the global time reference as the axis, within a preset time alignment tolerance range, perform one-to-one matching between the data points of the device state parameters and the execution nodes of the software code instructions. When the offset difference between the sensing data timestamp and the instruction execution timestamp does not exceed the time alignment tolerance, it is determined that the matching is successful; Bind and package the corresponding data points and execution nodes when the matching is successful to generate an operation event unit; Arrange all the operation event units in the order of the global time reference to form an operation event sequence.
7. The method according to claim 1, characterized in that, Dynamically binding the real-time security protection rule to the kernel layer of the domesticated platform to dynamically update the real-time security protection rule includes: Pre-set a rule loading interface in the kernel layer of the domesticated platform, and register the permission level mapping table, the memory control policy set, and the blocking condition set of the real-time security protection rule as kernel environment variables through the rule loading interface; Establish a real-time monitoring channel between the kernel layer environment variables and the sensing data stream; Compare the device status parameters to be updated with the sensing data thresholds preset in the blocking condition set through the real-time monitoring channel; When the device status parameters to be updated exceed the sensing data thresholds, trigger the rule update condition; Based on the rule update condition, dynamically update the real-time security protection rules.
8. A software code security protection system based on a domesticated platform, characterized in that, Including: An acquisition module, configured to acquire, during the execution of the software code of the domestic platform, the sensing data stream generated by the interaction between the domestic platform and external mechanical equipment, and the sensing data in the sensing data stream includes device status parameters associated with the software code execution process; An alignment module, configured to align the device status parameters with the execution nodes of the software code instructions in the external clock synchronization module of the domestic platform to generate an operation event sequence, where the software code instructions are function calls, system interface requests, or machine-level operation instructions captured during the operation of the domestic platform; An analysis module, configured to analyze the dynamic pattern of the operation event sequence through the memory isolation running environment of the domestic platform by using a reinforcement learning mechanism to generate real-time security protection rules for the software code execution path, where the software code execution path is the instruction execution order and branch structure restored from the operation event sequence; An update module, configured to dynamically bind the real-time security protection rules to the kernel layer of the domestic platform to dynamically update the real-time security protection rules and feedback the updated security protection rules to the kernel layer to form a closed-loop security protection mechanism.
9. A computing device, characterized in that, Including a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a software code security protection method based on a domestic platform according to any one of claims 1 to 7.
10. A computer storage medium, characterized in that, Stores a computer program, and when the computer program is executed by a computer, it implements a software code security protection method based on a domestic platform according to any one of claims 1 to 7.
Citation Information
Patent Citations
Intelligent vulnerability mining platform construction method and system based on large model
CN119760730A
ESIM remote configuration management method based on cloud platform and cloud platform
CN119922081A
Multi-modal feature fusion software supply chain vulnerability intelligent positioning method
CN120068095A
Cloud laboratory architecture design method and system
CN120075282A
A System for analyzing applications in order to find security and quality issues
US20150309813A1
Cited By
Perceptual execution synchronization method and device, electronic equipment and storage medium
CN120729879A