Data transmission encryption method, system, medium and program for flexible production
By combining the Kalman estimator and the chi-square detector, pseudo-random numbers are dynamically generated for data encryption, which solves the problems of high computational complexity and large storage space in flexible production systems, realizes real-time attack detection and data protection, and adapts to system reconstruction.
Patent Information
- Application Number
- CN202511120363.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-12
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-08-12
AI Technical Summary
Existing technologies in flexible production systems have high computational complexity, large storage space and lack of universality, making it difficult to adapt to system structure adjustments, increasing implementation difficulty and maintenance burden.
The Kalman estimator is used for state estimation and noise identification, the measurement output is encrypted in real time through the Kalman gain, and a chi-square detector is used to detect attacks. Pseudo-random numbers are dynamically generated for data encryption. It is suitable for state estimation and attack detection in flexible production systems.
It reduces the amount of calculation, saves storage space, adapts to system reconstruction, is applicable to most measurement equipment, and realizes real-time attack detection and data protection.
Smart Images

Figure CN120614216B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of information physical system data transmission security, and particularly relates to a data transmission encryption method and system for flexible production, a medium and a program. BACKGROUND
[0002] Flexible production is a flexible and efficient production mode, and a production line thereof can adjust a process, device configuration, and even reconstruct a production flow to adapt to manufacturing of different products. In order to react to a system running state and product quality in real time, the flexible production system is equipped with multiple measurement devices to collect production data online. However, the measurement data is subject to attack risks of interception and tampering at any time during transmission. Attackers generally design more covert attack methods to evade detection. After the flexible production system is attacked, the normal operation of the device, the decision-making process of the server, and even the life safety of personnel are affected. Therefore, an encryption method and system suitable for flexible production are needed, which can timely and accurately detect whether the flexible production system is attacked and weaken the attack effect to the greatest extent.
[0003] The prior art generally updates a key by using historical data and constructs a dynamic relationship between different data to detect attacks. Some schemes also need to upgrade the hardware of the measurement device to improve the computing performance and combine watermark embedding and other means to realize data encryption.
[0004] However, these technologies have problems of high computing complexity, large storage space occupation, and the like, and are difficult to adapt to conventional sensor devices, increasing the system cost. More importantly, the flexible production system has a reconfigurable feature, so that the existing technology lacks universality, and the data protection mechanism often needs to be redesigned after the system structure is adjusted, increasing the implementation difficulty and maintenance burden. SUMMARY
[0005] In view of the deficiencies of the prior art, the application provides a data transmission encryption method and system for flexible production, a medium and a program to solve the problems of high computing complexity, large required storage space and lack of universality of the prior art.
[0006] The technical scheme of the application is as follows:
[0007] The application provides a data transmission encryption method for flexible production, comprising the following steps:
[0008] establishing a state space model for a local system, the local system being a flexible production system requiring data transmission encryption;
[0009] identifying covariance of process noise and covariance of measurement output noise in the state space model of the local system in a non-attack environment of the local system;
[0010] Based on the state-space model of the local system, the covariance of the identified process noise, the covariance of the measurement output noise, and the received measurement output of the local system, the state of the local system is estimated through a Kalman estimator. During the estimation process, the steady-state Kalman gain of the Kalman estimator is obtained, and the covariance of the Kalman innovation at this time is calculated;
[0011] After the local system is officially put into operation, the measurement output is encrypted in real time according to the steady-state Kalman gain of the Kalman estimator to obtain the encrypted measurement output;
[0012] Sending the encrypted measurement output to a receiving end of a local system, and then decrypting the encrypted measurement output to obtain a decrypted measurement output;
[0013] Based on the decrypted measurement output, the Kalman innovation of the local system in the formal operation phase is calculated in real time;
[0014] Based on the covariance of the Kalman innovations in the formal operation phase and the Kalman innovations calculated in the non-attack environment, a chi-square detector is used to detect whether the local system is under attack, and to determine whether to trust the current measurement output, thereby estimating the state of the local system.
[0015] Furthermore, the method for encrypting the measurement output in real time is:
[0016] (8);
[0017] in, is the encrypted measurement output, For practical use The encrypted signal on For the moment;
[0018] Dynamically generated by equations (9) and (10):
[0019] (9);
[0020] (10);
[0021] in, is a dynamic state, Is subject to covariance Pseudo-random numbers from a zero-mean Gaussian process; by designing encryption parameters To determine the covariance of pseudorandom numbers ,in yes dimensional identity matrix, is the local system matrix, is the output matrix, is the dimension of the state of the local system, The dimensions of the measurement output for the local system; is the steady-state Kalman gain.
[0022] Furthermore, the method for decrypting the encrypted measurement output is:
[0023] (11);
[0024] in, is the decrypted measurement output.
[0025] Furthermore, the Kalman innovation of the local system in the formal operation phase is calculated in real time based on the decrypted measurement output, specifically:
[0026] First, the Kalman estimator is used to calculate the one-step prediction value of the state of the local system after it is put into operation based on the measured output of the local system after it is put into operation:
[0027] (12);
[0028] (13);
[0029] Then, the Kalman innovation is calculated based on the one-step prediction of the state of the local system after it is put into operation:
[0030] (14);
[0031] in, is the one-step prediction value of the state of the local system after it is put into operation, It is the measurement update value of the state of the local system after it was put into operation at the last moment. It is the attack detection variable of the last moment, and its value is 1 or 0. It takes 0 when the local system is attacked at the last moment, and takes 1 when it is not attacked. is the Kalman innovation, is the input matrix.
[0032] Furthermore, based on the Kalman innovation, a chi-square detector is used to detect whether the local system is under attack, and to determine whether to trust the current measurement output, thereby estimating the state of the local system. Specifically,
[0033] Calculate statistics using the chi-squared test and compare it with the threshold For comparison, if , then it is determined that the local system is under attack at the current moment, and the measurement output is not trusted at this time. Otherwise, it is determined that there is no attack, and the measurement output is trusted. ;
[0034] The calculation method of the statistic is:
[0035] (15);
[0036] in, is the chi-square test value, is the Kalman innovation, is the number of the Kalman innovation, for The inverse matrix of is the detection window size of the detector which can be selected independently;
[0037] The method to estimate the state of the local system is:
[0038] (16);
[0039] in, The measurement update value of the local system after it is put into operation at the current moment.
[0040] A second aspect of the present invention provides a data transmission encryption system for flexible production, which is used to implement a data transmission encryption method for flexible production, including:
[0041] A state space model building module, used to build a state space model for the local system;
[0042] Identification module, used to identify the covariance of process noise in the state space model of the local system during the local system debugging phase and the covariance of the measured output noise to identify;
[0043] The parameter solution module is used to estimate the state of the local system through the Kalman estimator based on the received measurement output of the local system, obtain the steady-state Kalman gain of the Kalman estimator during the estimation process, and calculate the covariance of the Kalman innovation at this time;
[0044] The encryption module is used to encrypt the measured output according to the steady-state Kalman gain of the Kalman estimator after the local system is officially put into operation. Perform real-time encryption to obtain encrypted measurement output;
[0045] a transmission module for sending the encrypted measurement output to a receiving end of a local system;
[0046] A decryption module, used for decrypting the encrypted measurement output to obtain the decrypted measurement output;
[0047] The attack detection and local system state estimation module is used to calculate the Kalman information of the local system in real time during the formal operation phase based on the decrypted measurement output. Based on the covariance of the Kalman information and the calculated Kalman information, a chi-square detector is used to detect whether the local system is under attack, and to determine whether to trust the current measurement output, thereby estimating the state of the local system.
[0048] A third aspect of the present invention provides a computer-readable storage medium storing computer-readable program instructions, which are executed by a processor to execute the steps of the data transmission encryption method for flexible production.
[0049] A fourth aspect of the present invention provides a computer program product, comprising a computer program, which, when executed by a processor, executes the steps of the data transmission encryption method for flexible production of the present invention.
[0050] Compared with the prior art, the present invention has the following beneficial effects:
[0051] Compared with the prior art, the technical solution proposed in the present invention uses a dynamic system to generate an encryption method with real-time guarantees, and performs incremental calculations rather than full recalculation, which greatly reduces the amount of calculation. In addition, the encryption method does not need to store historical data, saving storage space. In the generation of pseudo-random numbers, there is no need to rely on the model parameter information of the local system. Therefore, its generation method does not change after the flexible system is reconstructed, making the encryption method more suitable for flexible production systems. The technical solution proposed in the present invention does not require the measurement equipment of the local system to have high computing power in terms of hardware, and is applicable to most measurement equipment. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 is a structural block diagram of a computer system or server in an embodiment of the present invention;
[0053] Figure 2 This is a flow chart of a data transmission encryption method for flexible production in an embodiment of the present invention;
[0054] Figure 3 is a schematic diagram of a local system in an embodiment of the present invention;
[0055] Among them, 12-computer system or server; 14-external device; 16-processor; 18-data bus; 20-network adapter; 22-input or output interface; 24-display; 28-computer-readable storage medium; 30-cache; 32-random access memory; 34-non-volatile memory; 40-program product; 42-program module. DETAILED DESCRIPTION
[0056] The following detailed description of embodiments of the present invention provides a detailed description of how to implement and use the embodiments of the present invention, and is intended to enable those skilled in the art to clearly understand the technical solutions of the present invention. Without departing from the essence and spirit of the present invention, the relevant technical features may be adjusted, replaced, or combined, and may be applied to other embodiments of the flexible production system. Therefore, the present invention is not limited to the specific embodiments described, but should be given the broadest interpretation consistent with the disclosure of the present invention.
[0057] Figure 1 FIG1 shows a block diagram of an exemplary computer system or server 12 for implementing embodiments of the present invention. The system can be deployed as a central control node or an edge data processing device in a flexible manufacturing system. Figure 1 The structure shown is based on a general computing device architecture and is merely an exemplary platform for implementing the present invention, and does not constitute a limitation on hardware implementation methods.
[0058] like Figure 1 As shown, computer system or server 12 includes, but is not limited to, the following components: one or more processors 16 , computer-readable storage media 28 , and a data bus 18 for connecting the various components.
[0059] Computer-readable storage media 28 includes volatile and / or non-volatile storage media. Volatile memory may include cache 30, random access memory 32, and other memory devices, providing high-speed data access and processing support. Non-volatile memory 34 may be provided by a storage system, such as a solid-state drive (SSD), a mechanical hard drive (HDD), a magnetic tape device, or other persistent storage media. These storage components can be connected to the data bus 18 via one or more media interfaces, enabling the system to cache raw data, analyze and process process data, and store final results during the flexible manufacturing process.
[0060] Program product 40 may be stored in computer-readable storage medium 28 and includes at least one program module 42 for implementing the secure data collection and transmission mechanism described herein. Program module 42 may include an operating system, one or more application programs, an encryption or decryption component, a data synchronization module, a communication protocol processing module, and the like. The combination of these modules may be customized and adjusted based on actual deployment requirements.
[0061] The computer system or server 12 can also communicate with multiple external devices 14, such as data acquisition terminals, industrial cameras, and touch screen displays, via input or output interfaces 22. System status and alarm information can be visualized on a display 24. Furthermore, the computer system or server 12 can access industrial Ethernet, fieldbus, or other industrial communication networks via a network adapter 20, enabling bidirectional communication with other manufacturing equipment or remote servers. The network adapter 20 connects to modules such as the processor and storage system via a data bus 18, ensuring efficient data exchange.
[0062] To enhance the stability, data security, and scalability of the system in a flexible manufacturing environment, the computer system or server 12 may also integrate, but is not limited to, the following components: firmware extension modules, device drivers, redundant processing units, external disk drive arrays, RAID systems, virtual device drivers, data backup storage systems, error checking memory (ECC RAM), security coprocessors, protocol conversion controllers, and other industrial field communication adapter modules.
[0063] To facilitate distinction from the data transmission encryption system for flexible production proposed in the present invention, the flexible production system requiring data transmission encryption is referred to as a local system in this embodiment.
[0064] The present invention proposes a data transmission encryption method for flexible production, which mainly includes the following steps: state modeling of the local system, state estimation and innovation generation using the Kalman estimator, identification of noise covariance and calculation of innovation covariance during the debugging phase, encryption of measurement output after operation, synchronous decryption, and attack identification combined with chi-square detection. Figure 1 The computer system or server 12 shown executes, as Figure 2 As shown, the specific steps include:
[0065] Step 1: Establish a state space model for the local system, where the local system is a flexible production system that requires data transmission encryption;
[0066] The state space model in this embodiment is:
[0067] (1);
[0068] (2);
[0069] in, is the status of the local system, For the moment, is the dimension of the state of the local system, is the measured output of the local system, is the dimension of the measurement output of the local system, is the control input, To control the input dimension, is the process noise, To measure the output noise, is the local system matrix, is the input matrix, is the output matrix; in this embodiment, and are modeled as independent zero-mean Gaussian processes with covariances of and ,and is observable, It is stable, It is controllable;
[0070] Step 2: During the local system debugging phase (in a non-attack environment), the covariance of the process noise in the state space model of the local system is calculated. and the covariance of the measured output noise to identify;
[0071] In this embodiment, the covariance of the process noise in the state space model of the local system is calculated using the autocovariance least squares method. and the covariance of the measured output noise to identify;
[0072] Step 3: Based on the state space model of the local system, identify the covariance of the process noise , measure the covariance of the output noise The state of the local system is estimated by the Kalman estimator based on the measured output of the local system received. During the estimation process, the steady-state Kalman gain of the Kalman estimator is obtained, and the covariance of the Kalman innovation at this time is calculated.
[0073] The Kalman estimator is:
[0074] (3);
[0075] (4);
[0076] (5);
[0077] (6);
[0078] (7);
[0079] in, is the one-step prediction value of the state of the local system, Updated values for measurements of the local system's state, is the Kalman gain, is the one-step forecast error covariance, is the mathematical expectation, is the measurement update error covariance, for dimensional identity matrix, is transposed;
[0080] By solving the algebraic Riccati equation: , we can obtain the steady-state value of the one-step forecast error covariance , and then obtain the steady-state Kalman gain: , the final estimated state: ,in ; In this embodiment, Kalman innovation is defined as , which conforms to the Gaussian distribution , and the covariance By the formula given;
[0081] Step 4: After the local system is officially put into operation, the measured output is calculated based on the steady-state Kalman gain of the Kalman estimator. Perform real-time encryption to obtain encrypted measurement output;
[0082] The method for encrypting the measurement output in this embodiment is:
[0083] (8);
[0084] in, is the encrypted measurement output, For practical use Encrypted signal on
[0085] Dynamically generated by equations (9) and (10):
[0086] (9);
[0087] (10);
[0088] in, is a dynamic state, Is subject to covariance Pseudorandom numbers from a zero-mean Gaussian process;
[0089] In this embodiment, the encryption parameters can be designed To determine the covariance of pseudorandom numbers ,in yes -dimensional identity matrix;
[0090] Step 5: Send the encrypted measurement output to the receiving end of the local system, and then decrypt the encrypted measurement output to obtain the decrypted measurement output;
[0091] The method for decrypting the encrypted measurement output in this embodiment is:
[0092] (11);
[0093] in, is the decrypted measurement output;
[0094] In this embodiment, the pseudo-random number used for decryption in the local system and the pseudo-random number used for encryption use the same random seed, thus ensuring that the two pseudo-random number sequences are consistent, that is, the decryption method can obtain the same random number as the encryption method. , where the sequence of pseudo-random numbers at different times is called a pseudo-random number sequence;
[0095] Step 6: Based on the decrypted measurement output, calculate the Kalman innovation of the local system in real time during the formal operation phase;
[0096] First, the Kalman estimator is used to calculate the one-step prediction value of the state of the local system after it is put into operation based on the measured output of the local system after it is put into operation:
[0097] (12);
[0098] (13);
[0099] Then, the Kalman innovation is calculated based on the one-step prediction of the state of the local system after it is put into operation:
[0100] (14);
[0101] in, is the one-step prediction value of the state of the local system after it is put into operation, It is the measurement update value of the state of the local system after it was put into operation at the last moment. It is the attack detection variable of the last moment, and its value is 1 or 0. It takes 0 when the local system is attacked at the last moment, and takes 1 when it is not attacked. New information for Kalman;
[0102] Step 7: Based on the covariance of the Kalman innovations in the formal operation phase and the Kalman innovations calculated in the non-attack environment, a chi-square detector is used to detect whether the local system is under attack, and to determine whether to trust the current measurement output, thereby estimating the state of the local system.
[0103] In this embodiment, the chi-square detector is used to calculate the statistic and compare it with the threshold For comparison, if , then it is determined that the local system is under attack at the current moment, and the measurement output is not trusted at this time. Otherwise, it is determined that there is no attack, and the measurement output is trusted. ;
[0104] The calculation method of the statistic is:
[0105] (15);
[0106] in, is the chi-square test value, is the Kalman innovation, is the number of the Kalman innovation, for The inverse matrix of is the detection window size of the detector which can be selected independently. According to the embodiment of the present invention, the above threshold The degrees of freedom can be The chi-square distribution confidence interval is obtained by looking up the table;
[0107] The method to estimate the state of the local system is:
[0108] (16);
[0109] in, The measurement update value of the local system after it is put into operation at the current moment.
[0110] The data transmission encryption method disclosed herein enables real-time detection of attacks within flexible production systems, enabling timely remediation measures, improving system efficiency, and reducing the impact on server decision-making processes. Even if an attacker launches an attack unaware of the encryption system in the local system's data transmission, the local system can achieve a near-100% alert rate. Even if the attacker is aware of the encryption system and redesigns the attack to avoid detection, the encryption method can still render the attack nearly ineffective.
[0111] The present invention can be implemented in the form of a system, a method, and a computer program product.
[0112] This embodiment further provides a data transmission encryption system for flexible production, which is used to implement a data transmission encryption method for flexible production, including:
[0113] A state space model building module, used to build a state space model for the local system;
[0114] Identification module for the covariance of process noise in the state space model of the local system in a non-attack environment and the covariance of the measured output noise to identify;
[0115] The parameter solution module is used to estimate the state of the local system through the Kalman estimator based on the received measurement output of the local system, obtain the steady-state Kalman gain of the Kalman estimator during the estimation process, and calculate the covariance of the Kalman innovation at this time;
[0116] The encryption module is used to encrypt the measured output according to the steady-state Kalman gain of the Kalman estimator after the local system is officially put into operation. Perform real-time encryption to obtain encrypted measurement output;
[0117] a transmission module for sending the encrypted measurement output to a receiving end of a local system;
[0118] A decryption module, used for decrypting the encrypted measurement output to obtain the decrypted measurement output;
[0119] The attack detection and local system state estimation module is used to calculate the Kalman information of the local system in real time during the formal operation phase based on the decrypted measurement output. Based on the covariance of the Kalman information and the calculated Kalman information, a chi-square detector is used to detect whether the local system is under attack, and to determine whether to trust the current measurement output, thereby estimating the state of the local system.
[0120] According to an embodiment of the present invention, the data transmission encryption system for flexible production can be implemented in software, hardware, or a combination of software and hardware to adapt to the deployment requirements of different industrial control systems or intelligent manufacturing platforms.
[0121] According to another embodiment of the present invention, the data transmission encryption system for flexible production is applicable to a variety of flexible systems with strong real-time performance and significant dynamic changes, such as Figure 3 The multi-model body-in-white flexible assembly system shown.
[0122] This embodiment further provides a computer-readable storage medium, in which computer-readable program instructions are stored. When the computer-readable program instructions are executed by a processor, the steps of the data transmission encryption method for flexible production are executed.
[0123] A computer-readable storage medium is any medium capable of storing instructions in a tangible form for a device to read and execute. Examples include, but are not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor memory devices, or any combination thereof. Specific examples include, but are not limited to, hard disks, USB flash drives, RAM, ROM, flash memory, CD-ROMs, DVDs, memory sticks, SD cards, punch cards, and mechanically encoded media. It should be noted that this invention does not consider transient propagating signals (such as radio waves or electromagnetic waves propagating through optical or electrical cables) to be computer-readable media.
[0124] The computer-readable program instructions may be loaded directly from a storage medium onto a computing or processing device, or downloaded to a target device via a network environment (including wired and / or wireless networks). Networks may include, but are not limited to, the Internet, local area networks, and wide area networks. Connections may involve copper wires, optical fibers, wireless communications, routers, firewalls, switches, and other components. The downloaded program instructions may be stored in a computer-readable storage medium locally on the computing or processing device for subsequent execution or invocation.
[0125] The computer-readable program instructions that implement the functions of the present invention can be written in assembly language, ISA instructions, microcode, firmware, state machine data, or one or more programming languages (such as the object-oriented language Smalltalk, C++, or the procedural language C). The program instructions can be executed on a local computer, a remote server, or a combination of both. In certain applications, programmable logic circuits such as FPGAs and PLAs can be customized using these instructions to implement the corresponding logical functions.
[0126] This embodiment further provides a computer program product, including a computer program. When the computer program is executed by a processor, the computer program performs the steps of the data transmission encryption method for flexible production of the present invention.
[0127] The various embodiments of the present invention can be described in conjunction with the flowcharts or block diagrams in the accompanying drawings. Each functional step shown in the flowcharts or block diagrams can be implemented by one or more program modules, subroutines or executable instructions.
[0128] These program instructions can be executed by a processor in a general-purpose computing device, a special-purpose computing device, or other programmable device to implement the functional operations defined in the flowchart or block diagram.
[0129] Instructions can also be stored in a medium so that the device operates in a specific manner after loading, thereby achieving the corresponding function. In some embodiments, these instructions are loaded into the device, driving the device to perform multiple steps to form a complete computer-implemented processing flow, thereby realizing the functional modules defined in the flowchart or block diagram.
[0130] The flowcharts and block diagrams shown in the accompanying figures illustrate the system architecture and functional processes of various embodiments. Each functional block can be implemented using software modules, hardware modules, or a combination of software and hardware. Depending on specific implementation requirements, some steps can be executed in parallel, their order adjusted, or partially combined to accommodate different deployment scenarios.
[0131] It should be understood that the above embodiments are only used to illustrate the principles of the present invention and are not intended to limit the present invention. Without departing from the basic idea of the present invention, those skilled in the art may make various modifications and changes to the present invention. The terms used in this embodiment are only for the convenience of explanation and understanding and are not intended to limit the technical scope thereof. All equivalent replacements and extensions made based on the technical ideas of the present invention shall fall within the scope of protection of the present invention.
Claims
1. A data transmission encryption method for flexible production, characterized in that: The following steps are involved: Establishing a state space model for a local system, wherein the local system is a flexible production system requiring data transmission encryption; In a non-attack environment of the local system, the covariance of the process noise and the covariance of the measurement output noise in the state space model of the local system are identified; Based on the state-space model of the local system, the covariance of the identified process noise, the covariance of the measurement output noise, and the received measurement output of the local system, the state of the local system is estimated through a Kalman estimator. During the estimation process, the steady-state Kalman gain of the Kalman estimator is obtained, and the covariance of the Kalman innovation at this time is calculated; After the local system is officially put into operation, the measurement output is encrypted in real time according to the steady-state Kalman gain of the Kalman estimator to obtain the encrypted measurement output; Sending the encrypted measurement output to a receiving end of a local system, and then decrypting the encrypted measurement output to obtain a decrypted measurement output; Based on the decrypted measurement output, the Kalman innovation of the local system in the formal operation phase is calculated in real time; Based on the covariance of the Kalman innovations in the formal operation phase and the Kalman innovations calculated in the non-attack environment, a chi-square detector is used to detect whether the local system is under attack, and to determine whether to trust the current measurement output, thereby estimating the state of the local system.
2. The data transmission encryption method for flexible production according to claim 1, characterized in that: The method for encrypting the measurement output in real time is: (8); in, is the encrypted measurement output, For practical use The encrypted signal on For the moment; Dynamically generated by equations (9) and (10): (9); (10); in, is a dynamic state, Is subject to covariance Pseudo-random numbers from a zero-mean Gaussian process; by designing encryption parameters To determine the covariance of pseudorandom numbers ,in yes -dimensional identity matrix, is the local system matrix, is the output matrix, is the dimension of the state of the local system, The dimensions of the measurement output for the local system; is the steady-state Kalman gain.
3. The data transmission encryption method for flexible production according to claim 1, characterized in that: The method for decrypting the encrypted measurement output is: (11); in, is the decrypted measurement output.
4. The data transmission encryption method for flexible production according to claim 1, characterized in that: The Kalman innovation of the local system in the formal operation phase is calculated in real time based on the decrypted measurement output, specifically: First, the Kalman estimator is used to calculate the one-step prediction value of the state of the local system after it is put into operation based on the measured output of the local system after it is put into operation: (12); (13); Then, the Kalman innovation is calculated based on the one-step prediction of the state of the local system after it is put into operation: (14); in, is the one-step prediction value of the state of the local system after it is put into operation, It is the measurement update value of the state of the local system after it was put into operation at the last moment. It is the attack detection variable of the last moment, and its value is 1 or 0. It takes 0 when the local system is attacked at the last moment, and takes 1 when it is not attacked. is the Kalman innovation, is the input matrix.
5. The data transmission encryption method for flexible production according to claim 1, characterized in that: Based on the Kalman innovation, the chi-square detector is used to detect whether the local system is under attack, and to determine whether to trust the current measurement output, and then estimate the state of the local system. Specifically: Calculate statistics using the chi-squared test and compare it with the threshold For comparison, if , then it is determined that the local system is under attack at the current moment, and the measurement output is not trusted at this time. Otherwise, it is determined that there is no attack, and the measurement output is trusted. ; The calculation method of the statistic is: (15); in, is the chi-square test value, is the Kalman innovation, is the number of the Kalman innovation, for The inverse matrix of is the detection window size of the detector which can be selected independently; The method to estimate the state of the local system is: (16); in, The measurement update value of the local system after it is put into operation at the current moment.
6. A data transmission encryption system for flexible production, characterized in that: A data transmission encryption method for flexible production according to any one of claims 1 to 5 is implemented, comprising: A state space model building module, used to build a state space model for the local system; Identification module for the covariance of process noise in the state space model of the local system in a non-attack environment and the covariance of the measured output noise to identify; The parameter solution module is used to estimate the state of the local system through the Kalman estimator based on the received measurement output of the local system, obtain the steady-state Kalman gain of the Kalman estimator during the estimation process, and calculate the covariance of the Kalman innovation at this time; The encryption module is used to encrypt the measured output according to the steady-state Kalman gain of the Kalman estimator after the local system is officially put into operation. Perform real-time encryption to obtain encrypted measurement output; a transmission module for sending the encrypted measurement output to a receiving end of a local system; A decryption module, used for decrypting the encrypted measurement output to obtain the decrypted measurement output; The attack detection and local system state estimation module is used to calculate the Kalman information of the local system in real time during the formal operation phase based on the decrypted measurement output. Based on the covariance of the Kalman information and the calculated Kalman information, a chi-square detector is used to detect whether the local system is under attack, and to determine whether to trust the current measurement output, thereby estimating the state of the local system.
7. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-readable program instructions, which, when executed by a processor, execute the steps of the data transmission encryption method for flexible production according to any one of claims 1 to 5.
8. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the computer program executes the steps of the data transmission encryption method for flexible production according to any one of claims 1 to 5.
Citation Information
Patent Citations
Fault and attack detection method, system, medium and program based on KL divergence
CN115186690A
Industrial control system dual-channel false data injection attack detection method
CN117081780A