Information fusion trusted computing design and implementation method of elastic PNT system

The trustworthiness of the PNT source is evaluated through the trust policy manager and the trust policy engine, and its access rights are dynamically controlled, which solves the problem of insufficient credibility assessment of information source in the PNT system, realizes secure and trustworthy information fusion computing, and improves the security and stability of the PNT system.

CN120378883APending Publication Date: 2025-07-25BEIDOU APPL DEV RES INST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411895537.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-22
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The prior art has failed to effectively evaluate the credibility of PNT information sources from the perspective of network security, resulting in security risks in PNT systems when fusion computing.

Method used

The trust policy manager is used to collect the characteristic values of the PNT source. The trust policy engine evaluates the trustworthiness based on the zero trust model, and dynamically controls the access rights of the PNT source through the policy execution point to ensure the secure and trustworthy fusion calculation of the information source.

Benefits of technology

It improves the trusted service capabilities of the PNT system, ensures the accuracy, completeness and continuity of the PVT solution results, and enhances its resistance to network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378883A_ABST
    Figure CN120378883A_ABST
Patent Text Reader

Abstract

The invention relates to an information fusion trusted computing design and implementation method of an elastic PNT system, and belongs to the field of positioning and navigation technologies and network security. According to the method, a trust policy manager collects various characteristic values related to a PNT source; the trust policy engine evaluates the credibility of the PNT source, and the core of implementation based on the zero trust model is evaluation of the credibility of the PNT source; and the policy execution point dynamically executes a security policy based on the credibility of the PNT source, and controls whether the PNT source has the PNT source information fusion calculation permission or not and whether the PNT source can access a PNT internal source component or not. According to the method, the trusted service capability of the PNT system is improved, and the method has important reference significance for designing current and future high-elasticity PNT systems capable of resisting threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the fields of positioning and navigation technology and network security, and particularly relates to a design and implementation method for information fusion trusted computing of an elastic PNT system. Background Art

[0002] The development of Beidou and other GNSS has promoted positioning, navigation, and timing (PNT) services, which are widely used in many fields of modern society and are essential for the operation of critical infrastructure of many departments (including power grids, communication infrastructure, transportation, agriculture, financial services, and emergency services, etc.). An elastic PNT system is the data ability to continuously and stably provide users with secure and trusted PVT information solutions within a specified time. The basis of elastic PNT is the need to measure the trust in PNT sources and PNT solution calculations. The credibility of PNT information sources is particularly important. Many studies on the credibility issues of PNT information have been carried out at home and abroad. The elasticity of multi-source information fusion is mainly ensured from the aspect of monitoring the functional integrity of PNT sources, and the elasticity of the PNT system is ensured by using the physical state of components of PNT service components as a trusted evaluation index, without introducing the evaluation of the credibility of PNT information sources from the perspective of network security. However, the PNT system contains computer elements and processes digital information, and any externally input PNT source may be attacked and damaged by the network, which may also attack and damage the PNT system. The PNT source is continuously verified before fusion calculation instead of blindly trusting them to ensure that the PNT source for fusion calculation is secure and trusted, and the access control policy for the PNT system is determined according to the credibility of the PNT information source, which not only ensures the security and trust of the information sources used in PNT fusion calculation but also guarantees that the fusion calculation is carried out in a secure environment. Summary of the Invention

[0003] (1) Technical Problems to be Solved

[0004] The technical problem to be solved by the present invention is how to provide a design and implementation method for information fusion trusted computing of an elastic PNT system to solve the problem of not evaluating the credibility of PNT information sources from the perspective of network security.

[0005] (2) Technical Solutions

[0006] To solve the above technical problems, the present invention proposes a design and implementation method for information fusion trusted computing of an elastic PNT system. The elastic PNT system includes: a subject, an object, and a trusted component; the access subject is various PNT sources; the object is the resource to be protected, including the PNT multi-source information fusion calculation module, the PNT internal source, and the PNT elastic processing system; the trusted component is located between the subject and the object and includes: a trust policy engine, a trust policy manager, and a policy enforcement point; the method includes:

[0007] Step 1: The trust policy manager collects various characteristic values related to the PNT source;

[0008] Step 2: The trust policy engine evaluates the credibility of the PNT source. The core of the implementation based on the zero trust model is the evaluation of the credibility of the PNT source;

[0009] Step 3: The policy enforcement point dynamically enforces security policies based on the credibility of the PNT source, controlling whether the PNT source has the permission for PNT source information fusion calculation and whether it can access the internal source components of the PNT.

[0010] (3) Beneficial effects

[0011] The present invention proposes a design and implementation method for information fusion trusted computing of an elastic PNT system. Compared with the prior art, the present invention discloses a method for implementing secure computing of information source fusion of an elastic PNT system, including a trusted model and calculation method of the PNT source and a secure and controllable access control mechanism of the PNT system. When performing fusion calculation, the PNT system first evaluates the trust metrics of information sources from multiple sources with different levels of trust, and determines how to use those PNT sources for calculation and what services to provide according to the security state of the system and the application scenario, ensuring the accuracy, integrity, availability, and continuity of the PVT solution results. The trusted evaluation of the PNT information source in the present invention introduces a dynamic verification mechanism and multiple trust factors related to network security. The PNT information source is verified before each use instead of blindly trusting it, and security threats, security protection technologies, and situation awareness (SA) and other trust assumptions and evaluations of the information source are integrated into the trusted evaluation, improving the trusted service ability of the PNT system, which has important reference significance for designing current and future highly resilient PNT systems with threat resistance. Description of the drawings

[0012] Figure 1 It is a system component diagram of the present invention;

[0013] Figure 2 It is an interaction diagram of trusted components;

[0014] Figure 3 It is a flowchart of a preferred embodiment of the processing procedure of the present invention;

[0015] Figure 4 It is a flowchart for calculating the trust value of the PNT information source;

[0016] Figure 5 It is a flowchart for continuously verifying the trust value of the PNT information source. Specific implementation manners

[0017] To make the objectives, content, and advantages of the present invention clearer, the following further describes the specific implementation manners of the present invention in detail with reference to the accompanying drawings and embodiments.

[0018] The present invention provides a design and implementation method for information fusion trusted computing of an elastic PNT system. By establishing a trust computing engine that includes a trust evaluation model and trust algorithms for PNT sources, the ability to evaluate the trust of PNT sources is realized, and access control and computing policies for PNT sources to the PNT system, access policies between PNT information source components, and elastic disposal policies of the PNT system are controlled according to the credibility of the PNT information sources. By combining multi-dimensional factors such as the security posture of the PNT system, security protection technologies, the influence probability of security threats on PNT information sources, and considering the fusion computing strategy and elastic processing strategy of PNT sources, the trust of PNT sources is continuously evaluated, and the corresponding permissions are dynamically adjusted according to the trust level to form a secure and trusted fusion computing result of PNT information sources, and enable the PNT system to have a strong ability to respond to security risks.

[0019] The present invention provides a design and implementation method for information fusion trusted computing of an elastic PNT system. The implementation composition block diagram of the elastic PNT system is as Figure 1 shown, including three parts: a subject, an object, and a trusted component.

[0020] The access subject is various PNT sources, including: autonomous PNT sources, space-based PNT information sources, ground-based PNT information sources, etc.;

[0021] The object is the resource to be protected, including the PNT multi-source information fusion computing module, PNT internal sources, PNT elastic processing system, etc.

[0022] The trusted component is located between the subject and the object and mainly includes: a trust policy engine, a trust policy manager, a policy enforcement point, etc. The specific interaction is as Figure 2 shown.

[0023] The information fusion trusted computing method of the present invention enables the PNT system to continuously and stably provide users with original position, speed, and time data within a specified time. That is to say, on the one hand, it is necessary to ensure the security and trustworthiness of the information sources used for multi-source information fusion computing, and decide whether they can be used as information sources for fusion computing according to the trustworthiness of the information sources. The system must also dispose of the PNT elastic recovery mechanism according to the PNT information sources to provide security and trustworthiness guarantees for the PNT system in terms of signal sources and the system.

[0024] The PNT sources are divided into three categories: one is the space-based information source, such as Beidou and other GNSS; the second is the ground-based information source, such as the ground source that can provide augmentation information, such as pseudolites; the third is the autonomous navigation source that can provide local navigation information, such as INS, visual odometer, wheel odometer, lidar, etc.

[0025] The information fusion trusted computing design and implementation method of the elastic PNT system of the present invention is mainly completed by the fusion calculation of the trusted component and the PNT source. The trusted component is mainly responsible for evaluating the trust of the PNT source, and determining whether the PNT source can enter the PNT source fusion calculation module for calculation and control according to the evaluation value of the PNT source trust. The PNT source fusion calculation component is responsible for aggregating all trusted PNT sources for calculation.

[0026] The method includes the following steps as Figure 3 shown:

[0027] Step 1: The trust policy manager collects various characteristic values related to the PNT source, such as the physical facility characteristic values of the PNT source, the characteristic values of the PNT source itself, security protection policies, security attack parameters, security situation information, and other auxiliary sources. Among them,

[0028] For the physical facilities of the PNT source, such as Beidou receivers or 5G chips, etc., the working principles of each component are different. However, the difference between these components and GNSS is that although they will not be interfered by radio signals, their credibility is also different. The main reason is that the probabilities of different physical facilities being attacked are different, the credibility of signals is different, and the impacts of equipment aging and damage on signal quality are different, which will also affect the credibility of signals. It is necessary to initialize a trust value according to the security characteristics of the physical facilities of each type of PNT source as an attribute factor for calculating the credibility of the PNT source.

[0029] Step 2: The trust policy engine evaluates the credibility of the PNT source. The core of the implementation based on the zero-trust model is the dynamic evaluation of the credibility of the PNT source. The specific steps of the PNT source credibility evaluation are as Figure 3 shown.

[0030] The calculation of the credibility of the PNT source includes input, processing, and output.

[0031] The input includes data, such as: the observation values, probability models, and credibility evaluation models collected by the collector when the PNT system is used.

[0032] The processing mainly includes the credible evaluation calculation of the input data, including the probability distribution between the input data, the quantization of data characteristic values, the quantization of probability distributions, and the calculation and reasoning of credibility evaluation values;

[0033] The output is mainly the credibility of the PNT source, including the evaluation parameters for the integrity, credibility, and availability of the information source. These parameters are the metric parameters that can be recognized by the trust policy engine. The specific principle is as Figure 4 .

[0034] Among them,

[0035] The input of the trust policy engine considers multiple PNT source trust attributes, including: attribute characteristics related to the PNT source itself, security protection policies, security situation information, and other auxiliary sources (such as network data), and also includes the prior trust assumptions of the information source measurement values;

[0036] The attribute characteristics related to the PNT source itself include the physical facilities that generate the PNT source, the characteristics of the PNT source itself, etc.;

[0037] The security situation information includes the security situation of the PNT system and external interference and deception event information, etc. According to the security situation information, security threat characteristics are obtained. The security threat characteristics can be the responses of the system or signal to ignore, deceive, and / or delete threats, involving measurements of spectrum, signal data, and / or threat direction, and are used as references for inferring the types and intentions of interference and deception, etc.;

[0038] The security protection policies include signal feature hiding technology, restricted untrusted external input technology, security detection technology, etc.; other auxiliary resources include network data, etc.

[0039] The processing of the trust policy engine includes:

[0040] Constructing a stochastic relationship between the observed values of the PNT source and other variables. The attacker parameters may correspond to one or more attack families, and these attack parameters affect the integrity and availability of the PNT source, etc. For example, an attacker may deceive GNSS signals and use one of several configuration files to obtain the PNT fusion calculation result. Evaluate continuous or discrete variables of the possibility of adversarial operations according to the status information of the PNT source (such as: pseudocode, radio frequency signal, or surveying information, etc.). For example, given the prior distribution of random variables such as power, position, speed, clock rate, and CCD in a given attack scenario, and the prior assumption about the probability of this scenario, the posterior distribution under a given security protection policy and situation awareness scenario can be estimated, and the probability that the observed values in the window match the assumed speed prior can be estimated. Since these security threat indicators are used to evaluate the credibility of the PNT source, and credibility is quantified by probability distribution, it is necessary to convert them into continuous or discrete trust values (numbers or labels) that can be recognized by the zero-trust architecture's policy manager and trust policy engine.

[0041] Data quantization is instantiated in various implementations according to the tasks of the PNT source and the access to various inputs. The inputs and outputs of the trust model engine are both data streams. For example, pseudocode or IMU (Inertial Measurement Unit) measurements can be considered data streams, and periodic position, velocity, and time estimates can also be used as data streams. The probabilistic program quantization in the data quantization model is a probability distribution conditional on observations, which converts the observed data stream into a data stream of probability distributions. Other data streams will consist of a sequence of probability distribution objects and be sampled.

[0042] The output of the trust policy engine includes posterior trust assessment and the credibility of the PNT information source. The credibility metrics of the PNT information source include integrity, availability, accuracy, continuity, etc., which are quantified into policies that can be recognized by the trust security policy. Integrity means that the signal data has not been tampered with or damaged. The availability metric determines the probability that the PNT source component provides the required positioning accuracy during fault-free operation. Accuracy refers to the probability that the positioning provided by the PNT source component is accurate. The continuity metric is determined based on the probability of providing the required performance within a certain time without service interruption, and the continuity risk probability can be used to divide the grading intervals. The continuous evaluation and verification adopted for the credibility assessment of the PNT source are as Figure 4 shown.

[0043] Step 3: The policy enforcement point dynamically enforces the security policy based on the credibility of the PNT source, controlling whether the PNT source has the permission for PNT source information fusion calculation and whether it can access the internal PNT source components, etc. The internal PNT source components here mainly refer to information sources that can obtain measurement signals without relying on external information, such as inertial navigation.

[0044] The PNT source information fusion calculation policy comprehensively evaluates the credibility of the PNT source, the system security state, and the application scenario. Based on the attribute metrics of the PNT source credibility assessment result: the four metrics of integrity, availability, accuracy, and continuity are used as the security control policy for fusion calculation. Different information sources with different credibility levels are selected according to the application scenario. For example, for scenarios with high precision requirements, information sources with the highest credibility for high-precision PNT information are considered for fusion calculation, while for application scenarios with high security requirements, information sources with the highest credibility for signal integrity are selected for fusion. The security status of the system is evaluated based on the PNT system situation information, and it is evaluated whether the multi-source information fusion credible calculation can be performed, and the calculation result will not be affected by the system being attacked to ensure the accuracy of the calculation result.

[0045] The elastic processing system needs to evaluate the current security posture according to the security posture information of the PNT system. Controllable trust control is adopted for the secure access between PNT source components. The access between components is mainly based on the trust value as the main access basis. The secure access between components is mainly based on the trust value of the integrity of the information source. In principle, access is allowed between trust values of the same level, and access is not possible when the difference between trust levels is large. Information source components with a low trust level cannot access information source components with a high trust level.

[0046] The policy of the PNT elastic processing system needs to consider the security status of the PNT system and the trust evaluation of the PNT information source in combination. The trust value of the integrity of the PNT source is used as a basis for policy recovery, and the security status of the PNT system is used as a reference. The elastic recovery policy is divided into four methods. At the first level, in the case of a security threat, if the credibility of the PNT source is relatively low, services need to be provided after the system security is restored. If the credibility of the PNT source is relatively high, services can be directly provided by an external PNT source with a high credibility. For the second level, isolate the PNT source with low credibility and use a high-level trusted PNT source to provide services. For the third level, isolate each information source component according to the trust level of the PNT source and provide services within the boundary where the security threat is controllable. For the fourth level, in the case of a security threat to the PNT system, make service responses according to the different trust levels of the PNT source. When the security threat is cleared or the damage ends, responses can be made by using different types of PNT sources, and when the threat is cleared or the damage ends, the affected PNT source can be restored.

[0047] Compared with the prior art, the present invention discloses a method for realizing the information source fusion security calculation of an elastic PNT system, including a trust model and calculation method of the PNT source and a secure and controllable access control mechanism of the PNT system. When performing fusion calculation, the PNT system first evaluates the trust metrics of information sources from multiple sources with different degrees of trust, and decides how to use those PNT sources for calculation and what services to provide according to the security state and application scenario of the system, ensuring the accuracy, integrity, availability and continuity of the PVT solution result. The trust evaluation of the PNT information source in the present invention introduces a dynamic verification mechanism and multiple trust factors related to network security. The PNT information source is verified before each use instead of blindly trusting them, and security threats, security protection technologies and situation awareness (SA), etc. are integrated into the trust evaluation of the information source trust hypothesis and evaluation, improving the trusted service ability of the PNT system, which has important reference significance for designing a highly elastic PNT system that can resist threats currently and in the future.

[0048] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A method for designing and implementing information fusion trusted computing of an elastic PNT system, characterized in that The elastic PNT system includes: a subject, an object, and a trusted component; the access subject is various PNT sources; the object is the resource to be protected, including the PNT multi-source information fusion calculation module, the PNT internal source, and the PNT elastic processing system; the trusted component is located between the subject and the object and includes: a trust policy engine, a trust policy manager, and a policy enforcement point; the method includes: Step 1, the trust policy manager collects various characteristic values related to the PNT source; Step 2, the trust policy engine evaluates the credibility of the PNT source. The core of the implementation based on the zero-trust model is the dynamic evaluation of the credibility of the PNT source; Step 3, the policy enforcement point dynamically executes the security policy based on the credibility of the PNT source, and controls whether the PNT source has the PNT source information fusion calculation permission and whether it can access the PNT internal source component.

2. The information fusion trusted computing design and implementation method of the elastic PNT system according to claim 1, wherein The PNT sources are divided into three categories: space-based information sources, ground-based information sources, and autonomous navigation sources that can provide local navigation information.

3. The information fusion trusted computing design and implementation method of the elastic PNT system according to claim 1, wherein, In the above Step 1, the various characteristic values related to the PNT source include: the physical facility characteristic value of the PNT source, the characteristic value of the PNT source itself, security protection policies, security attack parameters, security situation information, and other aids; a trust value is initialized according to the security characteristics of the physical facilities of each type of PNT source and used as an attribute factor for calculating the credibility of the PNT source.

4. The information fusion trusted computing design and implementation method of the elastic PNT system according to claim 1, characterized in that, In the above Step 2, the calculation of the credibility of the PNT source includes input, processing, and output; The input includes: the observed values, probability models, and trusted evaluation models collected by the collector when the PNT system is used; The processing includes performing trusted evaluation calculations on the input data, including the probability distribution between the input data, the quantization of data characteristic values, the quantization of probability distributions, and the calculation and inference of trusted evaluation values; The output is the credibility of the PNT source, including the evaluation parameters of the integrity, credibility, and availability of the information source, and these parameters are index parameters that can be recognized by the trust policy engine.

5. The information fusion trusted computing design and implementation method of the elastic PNT system according to claim 4, characterized in that, The input of the trust policy engine takes into account multiple information sources, including: the attribute characteristics related to the PNT source itself, security protection policies, security situation information, and other auxiliary sources, and also includes the prior trust assumptions of the information source measurement values; The attribute characteristics related to the PNT source itself include the physical facilities that generate the PNT source and the characteristics of the PNT source itself; The security situation information includes the security situation of the PNT system and external interference and deception event information. Security threat characteristics are obtained based on the security situation information. The security threat characteristics are the responses of the system or signal to be able to ignore, deceive, and / or delete threats, involving measurements of spectrum, signal data, and / or threat directions, and are used as references for inferring the types and intentions of interference and deception; The security protection policies include signal feature hiding technology, restricting untrusted external input technology, and security detection technology; Other auxiliary resources include network data.

6. The information fusion trusted computing design and implementation method of the elastic PNT system according to claim 4, characterized in that, The processing of the trust policy engine includes: Construct a stochastic relationship between the observations of the PNT source and other variables. The attacker parameters may correspond to one or more attack families, and these attack parameters affect the integrity and availability of the PNT source; a continuous or discrete variable for evaluating the likelihood of adversarial operations based on the status information of the PNT source; given the prior distributions of the random variables power, position, speed, clock rate, and CCD for a given attack scenario, as well as the prior assumptions about the probability of that scenario, estimate the posterior distribution given a security protection policy and a situation awareness scenario, and estimate the probability that the observations in the estimation window match the assumed speed prior; since these security threat metrics are used to evaluate the trustworthiness of the PNT source, and trustworthiness is quantified by a probability distribution, it is necessary to convert them into continuous or discrete trust values that can be recognized by the policy manager and trust policy engine of the zero-trust architecture. Data quantization is instantiated in various implementations according to the tasks of the PNT source and the access to various inputs; both the input and output of the trust model engine are data streams; the probabilistic program quantization in the data quantization model is a probability distribution conditional on observations, which converts the observed data stream into a data stream of probability distributions; other data streams will consist of sequences of probability distribution objects and are sampled from them.

7. The information fusion trusted computing design and implementation method of the elastic PNT system according to claim 4, characterized in that The output of the trust policy engine includes the posterior trust assessment and the credibility of the PNT information source; the trust metrics of the PNT information source include integrity, availability, accuracy, and continuity, which are quantified as policies that can be recognized by the trust security policy. Integrity means that the signal data has not been tampered with or damaged. The availability metric is determined by the probability that the PNT source components provide the required positioning accuracy during fault-free operation. Accuracy refers to the probability that the positioning provided by the PNT source components is accurate. The continuity metric is determined based on the probability of providing the required performance within a certain time without service interruption, and the continuity risk probability is used to divide the grading intervals; continuous evaluation and verification are adopted for the trustworthiness assessment of the PNT source.

8. The information fusion trusted computing design and implementation method of the elastic PNT system according to any one of claims 4-7, characterized in that, In step three mentioned above, The PNT source information fusion calculation strategy comprehensively evaluates the trustworthiness of the PNT source, the system security state, and the application scenario. According to the attribute metrics of the PNT source trust assessment results: the four metrics of integrity, availability, accuracy, and continuity are used as the security control strategy for fusion calculation, and information sources with different credibility levels are selected according to the application scenario; for scenarios with high precision requirements, it is necessary to consider the information source with the highest high-precision credibility of the PNT information source for fusion calculation, while for application scenarios with high security requirements, select the information source with the highest signal integrity credibility for fusion; evaluate the security status of the system according to the PNT system situation information, evaluate whether the multi-source information fusion trust calculation can be performed, and the calculation result will not be affected by the accuracy of the calculation result due to the system being attacked.

9. The information fusion trusted computing design and implementation method of the elastic PNT system according to claim 8, characterized in that, The elastic processing system needs to evaluate the current security posture according to the security posture information of the PNT system. Controllable trust control is adopted for secure access between PNT source components. The access between each component is based on the trust value as the main access basis. The secure access between components is mainly based on the trust value of the integrity of the information source. In principle, access is allowed between trust values of the same level, and access is not possible when the difference between trust levels is large; For information source components with a low trust level, they cannot access information source components with a high trust level.

10. The information fusion trusted computing design and implementation method of the elastic PNT system as described in claim 9, characterized in that, The strategy of the elastic processing system needs to consider the security status of the PNT system and the trust evaluation of the PNT information source in combination, taking the integrity trust value of the PNT source as a basis for policy recovery and the security status of the PNT system as a reference; The elastic recovery strategy is divided into four methods. The first level, in the case of a security threat, if the credibility of the PNT source is relatively low, services need to be provided after the system security is restored. If the credibility of the PNT source is relatively high, external PNT sources with a relatively high credibility are directly used to provide services; The second level, isolate PNT sources with low credibility and use high-level credible PNT sources to provide services; The third level, isolate each information source component according to the trust level of the PNT source and provide services within the boundary where the security threat is controllable; The fourth level, in the state of security threat of the PNT system, make service responses according to the different trust levels of the PNT source. When the security threat is cleared or the damage ends, make responses by using different types of PNT sources, and when the threat is cleared or the damage ends, the affected PNT sources can be restored.