Novel nonlinear system attack detection method and device based on encryption and decryption
By establishing a fully symmetric multicellular state estimation model and encryption and decryption processing, an attack detection model is constructed, which solves the shortcomings of active attack detection in nonlinear systems and ensures the security of the network control system.
Patent Information
- Application Number
- CN202511064495.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-09-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing technology lacks active attack detection methods for nonlinear systems, especially powerful attackers can easily avoid passive attack detection, resulting in insufficient security of network control systems.
A new nonlinear system attack detection method based on encryption and decryption is adopted. By obtaining system parameter information, a fully symmetric multicellular state estimation model is established, the output data is encrypted and decrypted, an attack detection model is constructed, and performance analysis is performed.
Effectively detect attacks in nonlinear systems, ensure the security of network control systems, and prevent false data injection attacks.
Smart Images

Figure CN120602220A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of system attack detection, and in particular to a novel nonlinear system attack detection method and device based on encryption and decryption. Background Art
[0002] In recent years, cyber-physical systems have been proposed to define physical systems equipped with communication and computing capabilities. However, due to the presence of communication networks, they are vulnerable to malicious attacks from competitors. Therefore, ensuring the security of networked control systems is essential. However, existing research focuses primarily on linear systems, with little research on nonlinear systems. Furthermore, attack detection is categorized into passive and active attack detection. Powerful attackers can easily evade passive attack detection. Therefore, research on active attack detection for nonlinear systems is essential. Summary of the Invention
[0003] The present invention provides a novel nonlinear system attack detection method and device based on encryption and decryption, which are used to solve the technical problem of attacks on nonlinear systems.
[0004] An embodiment of the present invention provides a novel nonlinear system attack detection method based on encryption and decryption, the method comprising: Acquiring parameter information related to the novel nonlinear system; Establishing a novel fully symmetric polytope state estimation model based on the parameter information; Performing encryption and decryption processing on the first output data in the parameter information to obtain encrypted and decrypted second output data; determining an attack detection model for the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model; The attack detection model is used to perform attack detection performance analysis.
[0005] In some embodiments, the parameter information includes state information, output information, interference information, and noise information of the system; and establishing a novel fully symmetric polytope state estimation model based on the parameter information includes: determining a discrete time function of the system according to the state information, the output information, the interference information and the noise information; Processing the discrete time function using a preset Taylor expansion method with remainder terms to obtain a nonlinear state observation model corresponding to the discrete time function; The fully symmetric polytope state estimation model is determined based on the nonlinear state observation model.
[0006] In some embodiments, encrypting and decrypting the first output data in the parameter information to obtain encrypted and decrypted second output data includes: Constructing a preset encryption processing strategy and a preset decryption strategy based on the first output data; encrypting the first output data using the encryption processing strategy to obtain encrypted third output data; The encrypted third output data is decrypted using the decryption processing strategy to obtain the second output data.
[0007] In some embodiments, constructing a preset encryption processing strategy and a preset decryption strategy based on the first output data includes: Obtaining seed information of a pseudo-random number generated by a preset pseudo-random number generator; the seed information is unknown to the attacker; A preset encryption processing strategy and a preset decryption strategy are constructed based on the first output data and the seed information.
[0008] In some embodiments, determining the attack detection model of the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model includes: Obtaining status information of whether the system is under attack; determining state estimation residual data of the system based on the state information and the second output data; The attack detection model is constructed according to the state estimation residual data and the fully symmetric polytope state estimation model.
[0009] In some embodiments, performing attack detection performance analysis using the attack detection model includes: When the system is attacked by false data injection, obtaining first output data and second output data corresponding to the system based on the attack detection model; Determine state estimation residual data corresponding to the system according to the first output data and the second output data; Attack detection performance analysis is performed based on central point data of the state estimation residual data corresponding to the system and the values of the state estimation residual data.
[0010] In some embodiments, performing attack detection performance analysis based on center point data of state estimation residual data corresponding to the system and values of the state estimation residual data includes: When the value of the state estimation residual data is a preset threshold, determining, based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data, that all attacks on the system will be detected according to the attack detection performance analysis; When the value of the state estimation residual data is not the preset threshold, the attack detection performance analysis is determined based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data to determine whether the upper bound of the system attack meets the conditions.
[0011] An embodiment of the present invention further provides a novel nonlinear system attack detection device based on encryption and decryption, the device comprising: An acquisition unit, configured to acquire parameter information related to the novel nonlinear system; An establishing unit, configured to establish a novel fully symmetric polytope state estimation model according to the parameter information; a processing unit, configured to perform encryption and decryption processing on the first output data in the parameter information to obtain second output data after encryption and decryption processing; a determining unit, configured to determine an attack detection model of the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model; An analysis unit is used to perform attack detection performance analysis using the attack detection model.
[0012] An embodiment of the present invention provides a novel nonlinear system attack detection device based on encryption and decryption, the device comprising: a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the steps of any one of the above methods when running the computer program.
[0013] An embodiment of the present invention provides a storage medium having a computer program stored thereon; when the computer program is executed by a processor, the steps of any one of the above methods are implemented.
[0014] An embodiment of the present invention provides a novel nonlinear system attack detection method based on encryption and decryption, the method comprising: obtaining parameter information related to the novel nonlinear system; establishing a novel fully symmetric polytope state estimation model based on the parameter information; encrypting and decrypting first output data in the parameter information to obtain encrypted and decrypted second output data; determining an attack detection model for the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model; and analyzing attack detection performance using the attack detection model. Using the technical solution of the present application, a novel fully symmetric polytope state estimation model is established by obtaining parameter information related to the novel nonlinear system; encrypting and decrypting first output data in the parameter information to obtain encrypted and decrypted second output data; determining an attack detection model for the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model; and analyzing attack detection performance using the attack detection model. That is, by establishing a novel fully symmetric polytope state estimation model and attack detection model, the problems of nonlinear state attacks and attack detection are solved, ensuring the security of network control systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 A schematic flow chart of a novel nonlinear system attack detection method based on encryption and decryption provided by an embodiment of the present invention; Figure 2 A schematic structural diagram of a novel nonlinear system attack detection device based on encryption and decryption provided by an embodiment of the present invention; Figure 3 The figure is a hardware structure diagram of a novel nonlinear system attack detection device based on encryption and decryption according to an embodiment of the present invention. DETAILED DESCRIPTION
[0016] In order to make the objectives, technical solutions and advantages of the present invention more clear, the present invention is described in detail below with reference to the accompanying drawings and specific embodiments.
[0017] The various specific technical features in the various embodiments described in the specific implementation methods can be combined in various ways without contradiction. For example, different implementation methods can be formed by combining different specific technical features. In order to avoid unnecessary repetition, the various possible combinations of the specific technical features in the present invention will not be described separately.
[0018] It should also be noted here that, in order to avoid obscuring the present invention due to unnecessary details, only structures and / or processing steps closely related to the solutions of the present invention are shown in the drawings, while other details that are not closely related to the present invention are omitted.
[0019] In addition, it should be noted that the terms "include", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the following description, the terms "first\second\..." involved are merely used to distinguish different objects and do not indicate that there is any similarity or connection between the objects. It should be understood that the directions described by the directional nouns such as "above", "below", "inside" and "outside" are all directions in normal use.
[0020] To make the purpose, technical solutions and advantages of the embodiments of the present invention more clear, the specific technical solutions of the invention will be described in further detail below in conjunction with the accompanying drawings in the embodiments of the present invention. The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0021] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0022] The present invention provides a novel nonlinear system attack detection method based on encryption and decryption, such as Figure 1 As shown, Figure 1 A schematic flow chart of a novel nonlinear system attack detection method based on encryption and decryption provided in an embodiment of the present invention; the method comprises: Step S101: Acquire parameter information related to the novel nonlinear system.
[0023] Step S102: establishing a new fully symmetric polytope state estimation model according to the parameter information.
[0024] Step S103: encrypt and decrypt the first output data in the parameter information to obtain encrypted and decrypted second output data.
[0025] Step S104: determining an attack detection model for the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model.
[0026] Step S105: Analyze attack detection performance using the attack detection model.
[0027] In this embodiment, the drone can be determined according to actual conditions and is not limited here. As an example, the drone can be a quad-rotor drone.
[0028] The novel nonlinear system attack detection method based on encryption and decryption can be determined based on actual conditions and is not limited here. As an example, the novel nonlinear system attack detection method based on encryption and decryption can be a novel nonlinear system attack detection method based on encryption and decryption for a quadrotor in the presence of a network attack.
[0029] In step S101, the parameter information may be determined according to actual conditions and is not limited here. As an example, the parameter information may include the state information, output information, interference information, and noise information of the system; wherein the state information may also be referred to as the system state, which may be recorded as ; The output information can also be called system output, which can be recorded as The interference information can also be called system interference, which can be recorded as The noise information can also be called the measurement noise of the sensor, which can be recorded as .
[0030] In step S102, the specific process of establishing the novel fully symmetric polytope state estimation model based on the parameter information can be determined based on actual circumstances and is not limited herein. As an example, the parameter information includes state information, output information, interference information, and noise information of the system; establishing the novel fully symmetric polytope state estimation model based on the parameter information may include: determining a discrete-time function of the system based on the state information, the output information, the interference information, and the noise information; processing the discrete-time function using a preset Taylor expansion method with remainder terms to obtain a nonlinear state observation model corresponding to the discrete-time function; and determining the fully symmetric polytope state estimation model based on the nonlinear state observation model.
[0031] In step S103, the specific process of encrypting and decrypting the first output data in the parameter information to obtain the encrypted and decrypted second output data can be determined based on actual circumstances and is not limited herein. As an example, encrypting and decrypting the first output data in the parameter information to obtain the encrypted and decrypted second output data may include constructing a preset encryption processing strategy and a preset decryption strategy based on the first output data; encrypting the first output data using the encryption processing strategy to obtain encrypted third output data; and decrypting the encrypted third output data using the decryption processing strategy to obtain the second output data.
[0032] In step S104, the specific process of determining the attack detection model for the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model can be determined based on actual conditions and is not limited herein. As an example, determining the attack detection model for the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model can include obtaining state information regarding whether an attack exists on the system; determining state estimation residual data for the system based on the state information and the second output data; and constructing the attack detection model based on the state estimation residual data and the fully symmetric polytope state estimation model.
[0033] In step S105, the specific analysis process of using the attack detection model to perform attack detection performance analysis can be determined based on actual circumstances and is not limited herein. As an example, using the attack detection model to perform attack detection performance analysis can include, when the system is attacked by false data injection, obtaining first output data and second output data corresponding to the system based on the attack detection model; determining state estimation residual data corresponding to the system based on the first output data and the second output data; and performing attack detection performance analysis based on center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data.
[0034] An embodiment of the present invention provides a novel nonlinear system attack detection method based on encryption and decryption. The method establishes a novel fully symmetric polytope state estimation model using acquired parameter information related to the novel nonlinear system. First output data in the parameter information is encrypted and decrypted to obtain second output data after the encryption and decryption process. An attack detection model for the novel nonlinear system is determined based on the second output data and the fully symmetric polytope state estimation model. Finally, attack detection performance is analyzed using the attack detection model. By establishing the novel fully symmetric polytope state estimation model and attack detection model, the method addresses the issues of nonlinear state attacks and attack detection, ensuring the security of network control systems.
[0035] In some embodiments, the parameter information includes state information, output information, interference information, and noise information of the system; and establishing a novel fully symmetric polytope state estimation model based on the parameter information includes: determining a discrete time function of the system according to the state information, the output information, the interference information and the noise information; Processing the discrete time function using a preset Taylor expansion method with remainder terms to obtain a nonlinear state observation model corresponding to the discrete time function; The fully symmetric polytope state estimation model is determined based on the nonlinear state observation model.
[0036] In this embodiment, the parameter information includes the state information, output information, interference information and noise information of the system; wherein, the state information can also be called the system state, which can be recorded as ; The output information can also be called system output, which can be recorded as The interference information can also be called system interference, which can be recorded as The noise information can also be called the measurement noise of the sensor, which can be recorded as .
[0037] The specific determination process of determining the discrete time function of the system according to the state information, the output information, the interference information and the noise information can be determined according to actual conditions and is not limited here. As an example, the discrete time function can be recorded as 、 The discrete time function of the system determined according to the state information, the output information, the interference information and the noise information can be ; ;in, is the system status, is the system output, For system interference, is the measurement noise of the sensor, B and is a known system matrix; nonlinear function is continuously quadratically differentiable.
[0038] The discrete time function is processed using a preset Taylor expansion method with remainder terms to obtain the specific processing process in the nonlinear state observation model corresponding to the discrete time function. The specific processing process can be determined according to the actual situation and is not limited here. The nonlinear state observation model can also be called a nonlinear state observer and can be recorded as .
[0039] As an example, the discrete time function is processed by a preset Taylor expansion method with a remainder term, and the nonlinear state observation model corresponding to the discrete time function can be obtained by assuming , , ,in, Indicates the center point is , the generating matrix is The fully symmetric polytope of , . and The same definition is used for the fully symmetric polytopes below. ,in Represents the number of states. Using the first-order Taylor expansion method with remainder terms, the nonlinear system is calculated as follows: ; ; in, , is the Minkowski sum, , , is the linearization point, , .
[0040] Assume that at time k ,So can be selected as the center point of the state estimation set, that is, .
[0041] Further we can get Based on the above formula, the nonlinear state observer designed by the present invention satisfies the following conditions: ; in, is the observer gain matrix The i-th row of .
[0042] The specific determination process of determining the fully symmetric polytope state estimation model based on the nonlinear state observation model can be determined according to actual conditions and is not limited here. As an example, the fully symmetric polytope state estimation model can be recorded as The fully symmetric polytope state estimation model determined based on the nonlinear state observation model can be defined as .
[0043] because ,so , Further calculations show that, ,in, , , which means the following relationship holds: , ; Next, calculate and Taking into account , we can get: in, ; in, So there is , , , This means that It can be expressed as follows: ; also, It can be calculated as follows: ; Based on the above calculation results, the state estimation set at time k+1 can be obtained, namely: ,in, , , , , , , , , , .
[0044] definition , we can get .Will Substituting in, we can get: ; Differentiating the above formula, we can get: ; By solving , we can get the optimal observer gain matrix ,Right now: ;in, , .
[0045] In some embodiments, encrypting and decrypting the first output data in the parameter information to obtain encrypted and decrypted second output data includes: Constructing a preset encryption processing strategy and a preset decryption strategy based on the first output data; encrypting the first output data using the encryption processing strategy to obtain encrypted third output data; The encrypted third output data is decrypted using the decryption processing strategy to obtain the second output data.
[0046] In this embodiment, in this embodiment, the first output data may also be referred to as output data.
[0047] The specific construction process of constructing the preset encryption processing strategy and the preset decryption strategy based on the first output data can be determined based on actual circumstances and is not limited here. As an example, constructing the preset encryption processing strategy and the preset decryption strategy based on the first output data can include obtaining seed information of a pseudo-random number generated by a preset pseudo-random number generator; the seed information is unknown to the attacker; and constructing the preset encryption processing strategy and the preset decryption strategy based on the first output data and the seed information.
[0048] In practical applications, the seed information can be recorded as and ; and It can be generated by a pseudo-random number generator, and it is assumed that the seed information of the pseudo-random number is unknown to the attacker.
[0049] In practical applications, as an example, the present invention encrypts the output data, that is, ; in, , , The diagonal elements are diagonal matrix, and is reversible, i.e. Not equal to 0.
[0050] Based on the encryption function, the corresponding decryption process is as follows: ; During the encryption and decryption process, the parameters and It can be generated by a pseudo-random number generator, and it is assumed that the seed information of the pseudo-random number is unknown to the attacker.
[0051] In some embodiments, constructing a preset encryption processing strategy and a preset decryption strategy based on the first output data includes: Obtaining seed information of a pseudo-random number generated by a preset pseudo-random number generator; the seed information is unknown to the attacker; A preset encryption processing strategy and a preset decryption strategy are constructed based on the first output data and the seed information.
[0052] In this embodiment, the seed information can be recorded as and ; and It can be generated by a pseudo-random number generator, and it is assumed that the seed information of the pseudo-random number is unknown to the attacker.
[0053] In practical applications, as an example, the present invention encrypts the output data, that is: ; in, , , The diagonal elements are diagonal matrix, and is reversible, i.e. Not equal to 0.
[0054] Based on the encryption function, the corresponding decryption process is as follows: ; During the encryption and decryption process, the parameters and It can be generated by a pseudo-random number generator, and it is assumed that the seed information of the pseudo-random number is unknown to the attacker.
[0055] In some embodiments, determining the attack detection model of the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model includes: Obtaining status information of whether the system is under attack; determining state estimation residual data of the system based on the state information and the second output data; The attack detection model is constructed according to the state estimation residual data and the fully symmetric polytope state estimation model.
[0056] In this embodiment, the state information of whether the system has an attack can be determined according to actual conditions and is not limited here. As an example, the state information of whether the system has an attack can include state information of whether the system has no attack or whether the system has an attack.
[0057] The specific determination process of determining the state estimation residual data of the system based on the state information and the second output data can be determined according to actual conditions and is not limited here. As an example, the state estimation residual data of the system can be a state estimation residual; the determination of the state estimation residual data of the system based on the state information and the second output data can be a state estimation residual defined when there is no attack on the system. , ; in, , .
[0058] When the system is attacked, becomes .
[0059] The specific construction process of constructing the attack detection model based on the state estimation residual data and the fully symmetric polytope state estimation model can be determined according to actual conditions and is not limited here. Among them, the attack detection model can also be understood as an attack detector.
[0060] As an example, suppose that the estimated residual set The center point is , the corresponding attack detector is designed as follows: ; in, , Representation matrix No. i Column. It can be seen The upper bound of k is time-varying. To solve this problem, the present invention selects .
[0061] In some embodiments, performing attack detection performance analysis using the attack detection model includes: When the system is attacked by false data injection, obtaining first output data and second output data corresponding to the system based on the attack detection model; Determine state estimation residual data corresponding to the system according to the first output data and the second output data; Attack detection performance analysis is performed based on central point data of the state estimation residual data corresponding to the system and the values of the state estimation residual data.
[0062] In this embodiment, when the system is attacked by false data injection, the specific acquisition process of obtaining the first output data and the second output data corresponding to the system based on the attack detection model can be determined according to actual conditions and is not limited here.
[0063] As an example, the first output data can be recorded as , the second output data can be recorded as .
[0064] When the system is attacked by false data injection, , .
[0065] The specific determination process of determining the state estimation residual data corresponding to the system based on the first output data and the second output data can be determined according to actual conditions and is not limited here.
[0066] As an example, the state estimation residual data corresponding to the system can also be called a state estimation set; the state estimation residual data corresponding to the system determined according to the first output data and the second output data can be when the system is attacked by false data injection. , ; The corresponding state estimation set is expressed as follows: ; ; definition ,So .
[0067] definition , , then there is .
[0068] This means ; in, , , .
[0069] So, we can get .
[0070] The specific analysis process in the attack detection performance analysis based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data can be determined according to the actual situation and is not limited here. As an example, the attack detection performance analysis based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data can include, when the value of the state estimation residual data is a preset threshold, determining that all attacks on the system will be detected based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data; when the value of the state estimation residual data is not the preset threshold, determining that the upper bound of the attack on the system satisfies the condition based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data.
[0071] In some embodiments, performing attack detection performance analysis based on center point data of state estimation residual data corresponding to the system and values of the state estimation residual data includes: When the value of the state estimation residual data is a preset threshold, determining, based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data, that all attacks on the system will be detected according to the attack detection performance analysis; When the value of the state estimation residual data is not the preset threshold, the attack detection performance analysis is determined based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data to determine whether the upper bound of the system attack meets the conditions.
[0072] In this embodiment, the state estimation residual data can be recorded as ; The center point data of the state estimation residual data corresponding to the system can be recorded as .
[0073] The preset threshold value can be determined according to actual conditions and is not limited here. As an example, the preset threshold value can be .
[0074] The value of the state estimation residual data is a preset threshold value, which can be understood as: .
[0075] The specific determination process of determining the attack detection performance analysis based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data that all attacks on the system will be detected can be determined according to actual conditions and is not limited here.
[0076] As an example, In this case, due to , we can get: , if ,So .
[0077] However, the attacker cannot obtain the parameters and information, so if If set to 0, all attacks will be detected.
[0078] The value of the state estimation residual data is not the preset threshold value, which can be understood as .
[0079] The specific determination process of determining the attack detection performance analysis based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data as the upper bound of the system attack meets the conditions can be determined according to actual conditions and is not limited here.
[0080] As an example, In this case, assuming , , ,in , and For a given value, we can calculate: ; if , ,So ; According to the attack detector, the following privacy conditions can be obtained: ; Therefore, the upper bound of the attack can be obtained It can be seen that if you choose and / or , then there is .
[0081] In practical applications, as an example, the novel nonlinear system attack detection method based on encryption and decryption can be specifically a novel nonlinear system attack detection method based on encryption and decryption to solve the problems of nonlinear state attacks and attack detection; it can be specifically implemented through the following steps.
[0082] (1) Establish a new fully symmetric polytope state estimator Consider the following discrete-time nonlinear system, (1); (2); in, is the system status, is the system output, For system interference, is the measurement noise of the sensor, B and is a known system matrix; nonlinear function is continuously quadratically differentiable. Assume , , ,in, Indicates the center point is , the generating matrix is The fully symmetric polytope of , . and The same definition is used, and the following fully symmetric polytopes are also represented and calculated using the same method.
[0083] Notice ,in Represents the number of states. Using the first-order Taylor expansion method with remainder terms, the nonlinear system is calculated as follows: (3); in, , is the Minkowski sum, , , is the linearization point, , .
[0084] Assume that k time ,So can be selected as the center point of the state estimation set, that is, . We can further get: (4); Based on the above formula, the nonlinear state observer designed by the present invention satisfies the following conditions: (5); in, is the observer gain matrix No. i OK.
[0085] definition .
[0086] because ,so , Further calculations show that, ,in, , , which means the following relationship holds: , (6); Next, calculate and Taking into account , we can get: in, ; in, So there is , , , This means that It can be expressed as follows: ; also, It can be calculated as follows: ; Based on the above calculation results, the state estimation set at time k+1 can be obtained, namely: ,in, , , , , , , , , , .
[0087] definition , we can get .Will Substituting, we can get (7); Differentiating the above formula, we can get (8); By solving , we can get the optimal observer gain matrix ,Right now (9); in, , .
[0088] (2) Design nonlinear encryption and decryption strategies and attack detectors The present invention encrypts the output data, that is, (10); in, , , The diagonal elements are diagonal matrix, and is reversible, i.e. Not equal to 0.
[0089] Based on the encryption function, the corresponding decryption process is as follows: (11); During the encryption and decryption process, the parameters and It can be generated by a pseudo-random number generator, and it is assumed that the seed information of the pseudo-random number is unknown to the attacker.
[0090] When there is no attack on the system, define the state estimation residual , ,in , .
[0091] When the system is attacked, becomes .
[0092] Assume that the estimated residual set The center point is , the corresponding attack detector is designed as follows: (12); in, , Representation matrix No. i Column. It can be seen The upper bound of k is time-varying. To solve this problem, the present invention selects .
[0093] (3) Establish attack detection performance analysis method When the system is attacked by false data injection, the following formula is established: , (13); Therefore, the corresponding state estimation set is expressed as follows: (14); (15); definition ,So .
[0094] definition , , then there is This means ; in, , , . So, we can get: (16); Scenario 1: In this case, due to , we can get: if ,So However, the attacker cannot obtain the parameters and information, so if If set to 0, all attacks will be detected.
[0095] Scenario 2: In this case, assuming , , ,in , and For a given value, we can calculate: if , ,So (17); According to the attack detector, the following privacy conditions can be obtained: (18); Therefore, the upper bound of the attack can be obtained to satisfy It can be seen that if you choose and / or , then there is .
[0096] The present invention targets discrete-time nonlinear systems containing unknown but bounded noise. The present invention adopts the Taylor expansion method with remainder terms and the quadratic mapping theory of sets to propose a nonlinear state estimation method in the presence of false data injection attacks. On this basis, a corresponding attack detector is designed to solve the attack problem of nonlinear systems.
[0097] Based on the same inventive concept as above, Figure 2 A schematic diagram of the structure of a novel nonlinear system attack detection device based on encryption and decryption provided by an embodiment of the present invention is shown in FIG. Figure 2 As shown, the device 200 includes: An acquisition unit 201 is configured to acquire parameter information related to the novel nonlinear system; An establishing unit 202 is used to establish a new fully symmetric polytope state estimation model according to the parameter information; The processing unit 203 is configured to perform encryption and decryption processing on the first output data in the parameter information to obtain encrypted and decrypted second output data; a determining unit 204, configured to determine an attack detection model for the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model; The analysis unit 205 is configured to perform attack detection performance analysis using the attack detection model.
[0098] In some embodiments, the parameter information includes state information, output information, interference information and noise information of the system; the establishment unit 202 is also used to determine the discrete time function of the system based on the state information, the output information, the interference information and the noise information; the discrete time function is processed using a preset Taylor expansion method with remainder terms to obtain a nonlinear state observation model corresponding to the discrete time function; and the fully symmetric polyhedral state estimation model is determined based on the nonlinear state observation model.
[0099] In some embodiments, the processing unit 203 is further used to construct a preset encryption processing strategy and a preset decryption strategy based on the first output data; use the encryption processing strategy to encrypt the first output data to obtain encrypted third output data; and use the decryption processing strategy to decrypt the encrypted third output data to obtain the second output data.
[0100] In some embodiments, the processing unit 203 is further used to obtain seed information of a pseudo-random number generated by a preset pseudo-random number generator; the seed information is unknown to the attacker; and a preset encryption processing strategy and a preset decryption strategy are constructed based on the first output data and the seed information.
[0101] In some embodiments, the determination unit 204 is further used to obtain status information of whether the system is attacked; determine the state estimation residual data of the system based on the status information and the second output data; and construct the attack detection model based on the state estimation residual data and the fully symmetric polyhedral state estimation model.
[0102] In some embodiments, the analysis unit 205 is also used to obtain the first output data and the second output data corresponding to the system based on the attack detection model when the system is attacked by false data injection; determine the state estimation residual data corresponding to the system based on the first output data and the second output data; and perform attack detection performance analysis based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data.
[0103] In some embodiments, the analysis unit 205 is further used to determine, when the value of the state estimation residual data is a preset threshold, based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data, that all attacks on the system will be detected in the attack detection performance analysis; and when the value of the state estimation residual data is not the preset threshold, based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data, determine, when the attack detection performance analysis is that the upper bound of the attack on the system meets the condition.
[0104] It should be noted that the novel nonlinear system attack detection device based on encryption and decryption provided in the embodiment of the present invention and the configuration method provided in the aforementioned embodiment of the present invention belong to the same inventive concept. The meanings of the terms appearing here have been explained in detail above and will not be repeated here.
[0105] An embodiment of the present invention further provides a storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the above-mentioned method embodiment are implemented. The aforementioned storage medium includes: a mobile storage device, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program code.
[0106] An embodiment of the present invention also provides a new type of nonlinear system attack detection device based on encryption and decryption, which includes: a processor and a memory for storing a computer program that can be run on the processor, wherein when the processor is used to run the computer program, it executes the steps of the above-mentioned method embodiment stored in the memory.
[0107] Figure 3 This is a hardware structure diagram of a new type of nonlinear system attack detection device based on encryption and decryption according to an embodiment of the present invention. The new type of nonlinear system attack detection device based on encryption and decryption 300 includes: at least one processor 301, a memory 302. Optionally, the new type of nonlinear system attack detection device based on encryption and decryption 300 may further include at least one communication interface 303. The various components in the new type of nonlinear system attack detection device based on encryption and decryption 300 are coupled together through a bus system 304. It can be understood that the bus system 304 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 304 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, Figure 3 Various buses are labeled as bus system 304 .
[0108] It is understood that memory 302 can be volatile memory or non-volatile memory, or can include both volatile and non-volatile memory. Non-volatile memory can include read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disk, or compact disc read-only memory (CD-ROM); magnetic surface memory can include magnetic disk storage or magnetic tape storage. Volatile memory can include random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory 302 described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memory.
[0109] The memory 302 in the embodiment of the present invention is used to store various types of data to support the operation of the novel encryption and decryption-based nonlinear system attack detection device 300. Examples of such data include any computer program for operating on the novel encryption and decryption-based nonlinear system attack detection device 300. The program implementing the method of the embodiment of the present invention may be included in the memory 302.
[0110] The methods disclosed in the above embodiments of the present invention can be applied to or implemented by processor 301. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor or by software instructions. The above processor may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware components, etc. The processor can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present invention can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium located in a memory. The processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.
[0111] In an exemplary embodiment, the novel nonlinear system attack detection device 300 based on encryption and decryption can be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the above method.
[0112] In the several embodiments provided herein, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is merely a logical functional division. In actual implementation, other divisions may be employed, such as combining multiple units or components, integrating them into another system, or omitting or disabling certain features. Furthermore, the coupling, direct coupling, or communication connection between the components shown or discussed may be through interfaces. The indirect coupling or communication connection between devices or units may be electrical, mechanical, or other. The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of these units may be selected to achieve the objectives of the present embodiments according to actual needs. Furthermore, the functional units in the various embodiments of the present invention may all be integrated into a single processing module, each unit may be a separate unit, or two or more units may be integrated into a single unit. These integrated units may be implemented in hardware or as hardware plus software functional units.
[0113] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention.
Claims
1. A novel nonlinear system attack detection method based on encryption and decryption, characterized in that: The method comprises: Acquiring parameter information related to the novel nonlinear system; Establishing a novel fully symmetric polytope state estimation model based on the parameter information; Performing encryption and decryption processing on the first output data in the parameter information to obtain encrypted and decrypted second output data; determining an attack detection model for the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model; The attack detection model is used to perform attack detection performance analysis.
2. The method according to claim 1, characterized in that The parameter information includes state information, output information, interference information and noise information of the system; and establishing a novel fully symmetric polytope state estimation model based on the parameter information includes: determining a discrete time function of the system according to the state information, the output information, the interference information and the noise information; Processing the discrete time function using a preset Taylor expansion method with remainder terms to obtain a nonlinear state observation model corresponding to the discrete time function; The fully symmetric polytope state estimation model is determined based on the nonlinear state observation model.
3. The method according to claim 1, characterized in that The encrypting and decrypting the first output data in the parameter information to obtain the encrypted and decrypted second output data includes: Constructing a preset encryption processing strategy and a preset decryption strategy based on the first output data; encrypting the first output data using the encryption processing strategy to obtain encrypted third output data; The encrypted third output data is decrypted using the decryption processing strategy to obtain the second output data.
4. The method according to claim 3, characterized in that The step of constructing a preset encryption processing strategy and a preset decryption strategy based on the first output data includes: Obtaining seed information of a pseudo-random number generated by a preset pseudo-random number generator; the seed information is unknown to the attacker; A preset encryption processing strategy and a preset decryption strategy are constructed based on the first output data and the seed information.
5. The method according to claim 1, wherein The determining of the attack detection model of the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model includes: Obtaining status information of whether the system is under attack; determining state estimation residual data of the system based on the state information and the second output data; The attack detection model is constructed according to the state estimation residual data and the fully symmetric polytope state estimation model.
6. The method according to any one of claims 1 to 5, characterized in that The performing attack detection performance analysis using the attack detection model includes: When the system is attacked by false data injection, obtaining first output data and second output data corresponding to the system based on the attack detection model; Determine state estimation residual data corresponding to the system according to the first output data and the second output data; Attack detection performance analysis is performed based on central point data of the state estimation residual data corresponding to the system and the values of the state estimation residual data.
7. The method according to claim 6, characterized in that The attack detection performance analysis based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data includes: When the value of the state estimation residual data is a preset threshold, determining, based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data, that all attacks on the system will be detected according to the attack detection performance analysis; When the value of the state estimation residual data is not the preset threshold, the attack detection performance analysis is determined based on the center point data of the state estimation residual data corresponding to the system and the value of the state estimation residual data to determine whether the upper bound of the system attack meets the conditions.
8. A novel nonlinear system attack detection device based on encryption and decryption, characterized in that: The device comprises: An acquisition unit, configured to acquire parameter information related to the novel nonlinear system; An establishing unit, configured to establish a novel fully symmetric polytope state estimation model according to the parameter information; a processing unit, configured to perform encryption and decryption processing on the first output data in the parameter information to obtain second output data after encryption and decryption processing; a determining unit, configured to determine an attack detection model of the novel nonlinear system based on the second output data and the fully symmetric polytope state estimation model; An analysis unit is used to perform attack detection performance analysis using the attack detection model.
9. A novel nonlinear system attack detection device based on encryption and decryption, characterized in that: The device comprises: a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the steps of the method according to any one of claims 1 to 7 when running the computer program.
10. A storage medium, characterized in that: The storage medium stores a computer program; when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Active network defense method and system based on watermark and moving target fusion
CN120166406A
Method and system for attack detection in a sensor network of a networked control system
WO2020246944A1