Full-link detection and trusted industrial control method and system based on domestic chip
The full-link detection and trusted industrial control system built with domestic chips integrates multiple security technologies, solves the security backdoor and real-time problems of traditional systems, realizes hardware security, encryption operations and real-time anomaly detection, and improves the security and stability of industrial control systems.
Patent Information
- Application Number
- CN202510770627.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-16
AI Technical Summary
Traditional industrial control systems rely on foreign chips, which pose risks of security backdoors and firmware tampering. They lack full-link security verification, make it difficult to meet real-time requirements, and traditional security monitoring methods are unable to identify unknown attack patterns.
Domestic chips are used to build a full-link detection and trusted industrial control system, integrating a secure computing module, a dedicated hardware encryption acceleration module, a trusted execution environment module, anomaly detection module and a blockchain audit module. Combined with national secret algorithms and artificial intelligence anomaly detection, it achieves hardware security, encryption operations, trusted startup and real-time anomaly detection.
Provides comprehensive security protection, improves data security and system stability, and is suitable for industrial sites with high security requirements.
Smart Images

Figure CN120658448A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial automation and information security technology, and in particular to a full-link detection and trusted industrial control method and system based on domestic chips. Background Art
[0002] With the rapid development of the Industrial Internet and smart manufacturing, ICS (Industrial Control Systems) are evolving towards networking, digitization, and intelligence. However, traditional industrial control systems (ICSs) often rely on foreign chips, which pose security backdoors and firmware tampering risks. They also lack comprehensive security verification from hardware to software, making them vulnerable to malicious code attacks. Furthermore, general-purpose processors have low computational efficiency in data encryption and identity authentication, making them difficult to meet real-time requirements. Traditional security monitoring methods rely primarily on rule matching, which is unable to effectively and timely identify unknown attack patterns. System operation log storage is susceptible to tampering, and there is a lack of effective security auditing methods. Furthermore, with the increasing degree of automation and connected devices in industrial control systems, the security threats they face are becoming increasingly complex. Traditional security protection systems often struggle to provide adequate protection against complex attack patterns. Therefore, the use of advanced artificial intelligence algorithms for anomaly detection has become a key technology for improving security.
[0003] Therefore, there is an urgent need for an industrial control system that uses domestic chips and integrates multiple advanced security technologies to achieve comprehensive security protection from hardware security, encryption operations, trusted startup, real-time anomaly detection to log auditing. Summary of the Invention
[0004] In order to solve the technical problem of how to use domestic chips to build and integrate multiple advanced security technologies in an industrial control system to achieve comprehensive security protection from hardware security, cryptographic operations, trusted boot, real-time anomaly detection to log auditing, the embodiment of the present invention provides a full-link detection and trusted industrial control method and system based on domestic chips. The technical solution is as follows:
[0005] On the one hand, a full-link detection and trusted industrial control system based on domestic chips is provided. The system is used to implement a full-link detection and trusted industrial control method based on domestic chips. The system includes a secure computing module, a dedicated hardware encryption acceleration module, a trusted execution environment module, an anomaly detection module, a blockchain audit module, and a dynamic security policy engine; wherein,
[0006] The secure computing module is built by integrating the trusted platform module TPM inside the domestic chip, using the SM2 / SM3 / SM4 national encryption algorithm for hardware acceleration, and supporting a multi-level secure boot mechanism based on digital signatures to achieve full-link integrity verification from the basic input and output system BIOS to the application.
[0007] The dedicated hardware encryption acceleration module is designed based on the application-specific integrated circuit ASIC or field programmable gate array FPGA architecture and integrated into the domestic chip to achieve a throughput of more than 10Gbps to meet industrial real-time requirements.
[0008] The trusted execution environment module is built based on secure isolation technology and supports remote trusted measurement. The dynamic key generated by the trusted execution environment module is used to encrypt and protect sensitive information.
[0009] The anomaly detection module is built based on the pulse neural network and is used to detect anomalies in industrial data.
[0010] The blockchain audit module is built on the blockchain framework and is used to record and track key operations and abnormal events in real time.
[0011] The dynamic security policy engine is used to automatically trigger corresponding security response policies based on the detection results output by the anomaly detection module.
[0012] Optionally, the secure computing module is constructed by integrating a trusted platform module (TPM) into a domestic chip, including:
[0013] A trusted platform module TPM is integrated inside the domestic chip, and the trusted platform module TPM is connected to the main control unit of the domestic chip through the serial peripheral interface SPI to obtain a secure computing unit.
[0014] Among them, domestic chips include the domestic Feiteng E series and Loongson 3 series ARM v8 / RISC-V architecture chips.
[0015] The Trusted Platform Module (TPM) complies with the TPM 2.0 standard.
[0016] Optionally, a multi-level secure boot mechanism, including:
[0017] The root key in the system is stored in the secure storage area of the Trusted Platform Module (TPM). All signature keys are protected by a hardware fuse mechanism to prevent physical attacks from obtaining key information.
[0018] During the system startup process, the basic input and output system BIOS, boot loader, operating system and application are digitally signed and verified in sequence to ensure that all software components have not been tampered with.
[0019] When verification fails at any stage, the Trusted Platform Module (TPM) triggers a hardware reset and generates a security audit log, which is automatically uploaded to the blockchain audit module to ensure that tampering events are traceable.
[0020] Optionally, the dedicated hardware encryption acceleration module adopts a parallel pipeline structure to support hardware-level acceleration optimization of SM2 public key encryption, SM3 hash and SM4 symmetric encryption algorithms.
[0021] Optionally, the Trusted Execution Environment module runs security-critical code and data in an independent isolation zone to prevent malware attacks and unauthorized access.
[0022] Remote trusted measurement allows remote security monitoring centers to verify the integrity of system firmware and software through a trusted execution environment module.
[0023] The Trusted Execution Environment module supports remote identity authentication during secure boot and ensures the trustworthiness of remote systems through smart contracts.
[0024] Optionally, the anomaly detection module is built based on a spiking neural network to detect anomalies in industrial data, including:
[0025] Acquire multi-source time series data in industrial control systems and convert the multi-source time series data into pulse signals through time series encoding.
[0026] The pulse signal is input into the pulse neuron layer of the pulse neural network. After receiving the pulse signal, the membrane potential of each neuron in the pulse neuron layer will be updated according to the pulse frequency until the membrane potential reaches the threshold, at which time the neuron will emit a pulse signal and perform abnormality detection based on the pulse signal.
[0027] Among them, the spiking neural network uses the pulse timing dependency learning rule to adjust the connection weights between neurons.
[0028] After the spiking neural network is deployed, it is fine-tuned based on newly collected real-time industrial data through an incremental learning method; incremental learning uses an online gradient descent algorithm.
[0029] Optionally, the blockchain audit module automatically records security events triggered by the anomaly detection module through smart contracts.
[0030] During the event recording process, the blockchain audit module performs one-way desensitization processing on the device serial number using the SM3 hash algorithm, retaining only the first 6 bytes to prevent the leakage of the device's complete identity information; the geographic location information is encrypted and stored using the SM4 algorithm, and the encryption key is dynamically generated and protected by the trusted execution environment module to ensure the security of the geographic location information during storage and transmission.
[0031] Optionally, the dynamic security policy engine is further configured to:
[0032] Record security logs, including archiving detailed information about abnormal events to ensure traceability later.
[0033] Limit communication bandwidth, including dynamically adjusting bandwidth limits on devices or network channels based on anomaly levels to slow the spread of potential attacks.
[0034] Disconnect from the network, including automatically isolating the affected device or service and severing its connection to external networks or other devices to prevent further malicious activity.
[0035] On the other hand, a full-link detection and trusted industrial control method based on domestic chips is provided. The method is implemented by a full-link detection and trusted industrial control system based on domestic chips, and the method includes:
[0036] S1. By integrating the trusted platform module TPM inside the domestic chip to build a secure computing module, the secure computing module uses the SM2 / SM3 / SM4 national encryption algorithm for hardware acceleration, and supports a multi-level secure boot mechanism based on digital signatures to achieve full-link integrity verification from the basic input and output system BIOS to the application.
[0037] S2. Design a dedicated hardware encryption acceleration module based on the application-specific integrated circuit ASIC or field-programmable gate array FPGA architecture. The dedicated hardware encryption acceleration module is integrated into the domestic chip to achieve a throughput of more than 10Gbps to meet industrial real-time requirements.
[0038] S3. Build a trusted execution environment module based on secure isolation technology. The trusted execution environment module supports remote trusted measurement. The dynamic key generated based on the trusted execution environment module is used to encrypt and protect sensitive information.
[0039] S4. Build an anomaly detection module based on the pulse neural network. The anomaly detection module is used to detect anomalies in industrial data.
[0040] S5. Build a blockchain audit module based on the blockchain framework. The blockchain audit module is used to record and track key operations and abnormal events in real time.
[0041] S6. Build a dynamic security policy engine to automatically trigger corresponding security response policies based on the detection results output by the anomaly detection module.
[0042] Optionally, the secure computing module is constructed by integrating a trusted platform module (TPM) into a domestic chip, including:
[0043] A trusted platform module TPM is integrated inside the domestic chip, and the trusted platform module TPM is connected to the main control unit of the domestic chip through the serial peripheral interface SPI to obtain a secure computing unit.
[0044] Among them, domestic chips include the domestic Feiteng E series and Loongson 3 series ARM v8 / RISC-V architecture chips.
[0045] The Trusted Platform Module (TPM) complies with the TPM 2.0 standard.
[0046] Optionally, a multi-level secure boot mechanism, including:
[0047] The root key in the system is stored in the secure storage area of the Trusted Platform Module (TPM). All signature keys are protected by a hardware fuse mechanism to prevent physical attacks from obtaining key information.
[0048] During the system startup process, the basic input and output system BIOS, boot loader, operating system and application are digitally signed and verified in sequence to ensure that all software components have not been tampered with.
[0049] When verification fails at any stage, the Trusted Platform Module (TPM) triggers a hardware reset and generates a security audit log, which is automatically uploaded to the blockchain audit module to ensure that tampering events are traceable.
[0050] Optionally, the dedicated hardware encryption acceleration module adopts a parallel pipeline structure to support hardware-level acceleration optimization of SM2 public key encryption, SM3 hash and SM4 symmetric encryption algorithms.
[0051] Optionally, the Trusted Execution Environment module runs security-critical code and data in an independent isolation zone to prevent malware attacks and unauthorized access.
[0052] Remote trusted measurement allows remote security monitoring centers to verify the integrity of system firmware and software through a trusted execution environment module.
[0053] The Trusted Execution Environment module supports remote identity authentication during secure boot and ensures the trustworthiness of remote systems through smart contracts.
[0054] Optionally, the anomaly detection module is built based on a spiking neural network to detect anomalies in industrial data, including:
[0055] Acquire multi-source time series data in industrial control systems and convert the multi-source time series data into pulse signals through time series encoding.
[0056] The pulse signal is input into the pulse neuron layer of the pulse neural network. After receiving the pulse signal, the membrane potential of each neuron in the pulse neuron layer will be updated according to the pulse frequency until the membrane potential reaches the threshold, at which time the neuron will emit a pulse signal and perform abnormality detection based on the pulse signal.
[0057] Among them, the spiking neural network uses the pulse timing dependency learning rule to adjust the connection weights between neurons.
[0058] After the spiking neural network is deployed, it is fine-tuned based on newly collected real-time industrial data through an incremental learning method; incremental learning uses an online gradient descent algorithm.
[0059] Optionally, the blockchain audit module automatically records security events triggered by the anomaly detection module through smart contracts.
[0060] During the event recording process, the blockchain audit module performs one-way desensitization processing on the device serial number using the SM3 hash algorithm, retaining only the first 6 bytes to prevent the leakage of the device's complete identity information; the geographic location information is encrypted and stored using the SM4 algorithm, and the encryption key is dynamically generated and protected by the trusted execution environment module to ensure the security of the geographic location information during storage and transmission.
[0061] Optionally, the dynamic security policy engine is further configured to:
[0062] Record security logs, including archiving detailed information about abnormal events to ensure traceability later.
[0063] Limit communication bandwidth, including dynamically adjusting bandwidth limits on devices or network channels based on anomaly levels to slow the spread of potential attacks.
[0064] Disconnect from the network, including automatically isolating the affected device or service and severing its connection to external networks or other devices to prevent further malicious activity.
[0065] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0066] This invention combines domestic chips, hardware acceleration, trusted execution environment, artificial intelligence anomaly detection and blockchain log audit modules to provide comprehensive protection from hardware security, encryption operations to real-time anomaly detection and security auditing. It aims to cope with security threats in complex industrial environments, improve data security and system stability, and is suitable for industrial sites with extremely high security requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0068] Figure 1 This is a block diagram of a full-link detection and trusted industrial control system based on domestic chips provided by an embodiment of the present invention;
[0069] Figure 2 This is a multi-level secure startup flow chart provided by an embodiment of the present invention;
[0070] Figure 3 This is a schematic diagram of the internal structure of the AI anomaly detection module provided by an embodiment of the present invention;
[0071] Figure 4 This is a flowchart of incremental learning provided by an embodiment of the present invention;
[0072] Figure 5 This is a schematic diagram of a blockchain security audit module provided by an embodiment of the present invention;
[0073] Figure 6 This is a block diagram of the overall structure of the system provided by an embodiment of the present invention;
[0074] Figure 7 This is a flow chart of a full-link detection and trusted industrial control method based on domestic chips provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0075] The technical solution of the present invention is described below in conjunction with the accompanying drawings.
[0076] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as an "exemplary" in the present invention should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner. Furthermore, in the embodiments of the present invention, "and / or" can mean both or either of the two.
[0077] In the embodiments of the present invention, the terms "image" and "picture" may be used interchangeably. It should be noted that, when the distinction between them is not emphasized, their intended meanings are the same. The terms "of," "corresponding," and "corresponding" may be used interchangeably. It should be noted that, when the distinction between them is not emphasized, their intended meanings are the same.
[0078] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are the same.
[0079] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0080] The embodiment of the present invention provides a full-link detection and trusted industrial control system based on domestic chips, such as Figure 1 The block diagram of the full-link detection and trusted industrial control system based on domestic chips shown in the figure includes a secure computing module, a dedicated hardware encryption acceleration module, a trusted execution environment module, an anomaly detection module, a blockchain audit module, and a dynamic security policy engine; among which:
[0081] The secure computing module is built by integrating the trusted platform module TPM inside the domestic chip, using the SM2 / SM3 / SM4 national encryption algorithm for hardware acceleration, and supporting a multi-level secure boot mechanism based on digital signatures to achieve full-link integrity verification from the basic input and output system BIOS to the application.
[0082] In a feasible implementation, the present invention constructs a secure computing unit based on a TPM (Trusted Platform Module) module and a domestic chip with a national secret algorithm, and a boot chain integrity protection method with multi-level signature verification.
[0083] Specifically, a domestic chip platform designed for the domestic Feiteng E series or Loongson 3 series ARM v8 / RISC-V architecture chips is used, and a trusted platform module that complies with the TPM 2.0 standard is integrated into it. It is connected to the chip main control unit via the SPI (Serial Peripheral Interface) interface to build a secure computing unit with the ability to accelerate the national secret algorithm, achieving hardware-level secure computing and firmware integrity verification. For example, a domestic Feiteng series chip (such as Feiteng 4000) is used as the main processor. This chip supports the ARM v8 architecture and has high computing performance and security.
[0084] Furthermore, the secure computing unit uses the SM2 / SM3 / SM4 national encryption algorithms for hardware acceleration and supports a multi-level secure boot mechanism based on digital signatures.
[0085] Among them, a multi-level secure boot trust chain is adopted to ensure the integrity verification from firmware, boot program, operating system to application program, such as Figure 2 The mechanism includes:
[0086] Key Management: Root keys are stored in the TPM secure storage area. All signing keys are protected by hardware fuses to prevent physical attacks from obtaining key information. The TPM module stores the root key and generates a hardware chain of trust, ensuring system integrity at every stage from boot to operation.
[0087] Step-by-step verification: First, the system is powered on or reset. Upon powering on or resetting, the system first checks the hardware connections and establishes an SPI connection with the TPM module. During the boot process, BIOS verification is performed: The system verifies the digital signature of the BIOS (Basic Input / Output System) to ensure that the BIOS firmware has not been tampered with. If verification passes, the system continues booting and enters the next stage. Firmware verification is further performed: Under the control of the TPM module, the system verifies the digital signature of the boot firmware (such as the bootloader) to ensure that the firmware has not been tampered with. Operating system kernel verification is performed: The system further verifies the digital signature of the operating system kernel to ensure the integrity of the operating system. Finally, a hardware chain of trust is formed: The TPM module records the signature information of each verification stage through the hardware chain of trust to ensure that all boot stages are protected. If verification fails at any stage, the TPM module immediately triggers a hardware reset to prevent unsafe software from loading. It also generates a security audit log, which is automatically uploaded to the blockchain security audit module to ensure tampering events are traceable and trigger security alerts. Through step-by-step signature verification, a complete boot chain of trust with integrity is established from hardware to software.
[0088] The dedicated hardware encryption acceleration module is designed based on the application-specific integrated circuit ASIC or field programmable gate array FPGA architecture and integrated into the domestic chip to achieve a throughput of more than 10Gbps to meet industrial real-time requirements.
[0089] In a feasible implementation, the present invention constructs a dedicated encryption acceleration and a high-concurrency and low-latency data encryption and decryption method based on an ASIC / FPGA (Application-Specific Integrated Circuit / Field Programmable Gate Array) parallel architecture for national secret algorithms.
[0090] Specifically, a dedicated encryption acceleration module is integrated into domestically produced Feiteng E-series or Loongson 3 series chips. Based on a configurable ASIC or FPGA architecture, the encryption acceleration module utilizes a parallel pipeline structure to support hardware-level acceleration optimization for SM2 public key encryption, SM3 hashing, and SM4 symmetric encryption algorithms. The module complies with the GM / T0001-2023 certification standard issued by the State Cryptography Administration.
[0091] The dedicated hardware encryption accelerator utilizes an ASIC architecture, achieving an encryption throughput of 10Gbps with 1,000 concurrent connections and 512-byte data packets, while reducing data encryption and decryption latency to less than 2μs. Alternatively, using an FPGA architecture, encryption throughput can be expanded to 20Gbps. This performance improves encryption by at least five times compared to CPU-based encryption, meeting the encryption requirements of high-concurrency, high-data-volume environments. This encryption accelerator meets the certification standards of the National Cryptography Administration and utilizes a parallel pipeline architecture to optimize the computational load of high-concurrency industrial data transmission.
[0092] Specifically, performance tests were conducted in a high-concurrency communication environment simulating an industrial control system. The chip model was Feiteng E2000Q, with a main frequency of 2.0GHz. The test conditions were 1000 concurrent connections and 512-byte industrial protocol data packets. The iperf3 tool was used to measure the throughput from the encryption end to the decryption end. The results are as follows: SM4 symmetric encryption throughput is 10.5Gbps, with a latency of 1.8μs, SM3 hash throughput is 9.8Gbps, and SM2 public key encryption throughput is 3.2Gbps, with a latency of 5.6μs.
[0093] The trusted execution environment module is built based on secure isolation technology and supports remote trusted measurement. The dynamic key generated by the trusted execution environment module is used to encrypt and protect sensitive information.
[0094] In a feasible implementation manner, the present invention constructs a trusted execution environment and a remote trusted measurement method based on ARM TrustZone hardware isolation technology.
[0095] Specifically, the present invention protects sensitive code and data in a TEE (Trusted execution environment) and verifies whether the system has been tampered with through remote trusted measurement, specifically including:
[0096] ARM TrustZone or equivalent security isolation technology is used to build a trusted execution environment (TEE) within the system. The TEE module isolates security-critical code from data and runs them in an independent, isolated zone to prevent malware attacks and unauthorized access, ensuring high system security. The TEE module supports remote trusted attestation, allowing external security monitoring centers to verify the integrity of system firmware and software through the TEE, ensuring that the system has not been tampered with during operation.
[0097] During the boot process, TEE supports remote identity authentication, using digital signature technology to verify the trustworthiness of remote devices. It can also further enhance the system's remote security and reliability through smart contract mechanisms. Dynamic keys generated by TEE can be used to encrypt and protect sensitive information, such as user data and configuration files, ensuring the confidentiality and integrity of data during transmission.
[0098] The anomaly detection module is built based on a spiking neural network and is used to detect anomalies in industrial data.
[0099] In a feasible implementation, in order to enhance the anomaly detection capability of the system, the present invention adopts an AI anomaly detection module based on a pulse neural network, which monitors the operating status of industrial field equipment in real time and promptly detects potential security threats, such as Figure 3 The data can be multi-source time series data in industrial control systems (such as sensor data, control instructions, and communication data), specifically including:
[0100] By using spiking neural networks for time series data analysis, various potential security threats, such as illegal instructions, abnormal data flows, and communication anomalies, can be efficiently and accurately detected. Compared to traditional convolutional neural networks, spiking neural networks exhibit higher computational efficiency and lower power consumption when processing time series data, making them particularly suitable for application in industrial environments.
[0101] By simulating the pulse signal transmission mechanism of biological neurons and utilizing the neuron's membrane potential and pulse emission to process input signals, spiking neural networks can more accurately capture changing trends and potential abnormal patterns in time series data. Spiking neural networks use the STDP (Spike-Timing-Dependent Plasticity) rule to adjust the connection weights between neurons, further optimizing the network's learning ability and anomaly detection performance. The model's online learning mechanism enables the system to automatically adjust model parameters based on real-time data, thereby improving its ability to recognize unknown attack patterns and enhancing the system's adaptability.
[0102] Specifically include:
[0103] S41: Data preprocessing and input layer:
[0104] Data acquisition: The system collects industrial field sensor data (such as temperature, pressure, and vibration), control instructions (such as PLC instructions), and communication data (such as Modbus / TCP protocol messages) in real time. The collected data provides the basis for subsequent anomaly detection.
[0105] Temporal encoding: The temporal characteristics of input data are crucial for detecting anomalies. In this paper, data is converted into pulse signals through temporal encoding. The value of each sensor data point is encoded as the frequency of the pulse, thus preserving the temporal information of the data. Assuming the input data is x(t), where t represents the time step, the pulse signal p(t) input to the SNN can be expressed by the following formula:
[0106] p(t)=Encode(x(t)) (1)
[0107] Among them, Encode converts the sensor data x(t) into a pulse signal p(t) through a time encoding method. Each data point x(t) is converted into a pulse p(t) of the corresponding frequency. The frequency of the pulse represents the strength of the sensor signal.
[0108] Sliding window processing: To improve model accuracy, the system uses a sliding window method (window length 1 second, step length 0.5 second) to partition time series data and extract useful time series features from continuous data streams;
[0109] Normalization: Normalize all input data to the range of [-1, 1] to avoid the impact of numerical range differences on model training. The specific formula is as follows:
[0110]
[0111] Where x(t) is the input data, x′(t) is the normalized data, μ is the mean of the input data, and σ is the standard deviation.
[0112] Noise filtering: A low-pass filter (cut-off frequency 10 Hz) is used to remove high-frequency noise and improve signal quality and model stability.
[0113] The input layer receives time series data from the industrial control system. The sensor data at each moment is converted into a pulse signal through time series encoding. The input data is converted into a pulse frequency using the time series encoding method described above.
[0114] S42: Spiking neuron layer and membrane potential update:
[0115] The spiking neuron layer is the core of the SNN, responsible for extracting spatiotemporal features from the input data. Each neuron simulates information processing through changes in membrane potential. Upon receiving a spike signal, the membrane potential V(t) of each neuron is updated based on the input spike frequency. The membrane potential update formula is as follows:
[0116]
[0117] Among them, V(t) is the membrane potential of the neuron at time t; τ is the time constant of the membrane potential; I(t) is the input pulse signal from the previous layer of neurons.
[0118] When the membrane potential V(t) reaches the threshold V th When the pulse signal is emitted, the neuron will emit a pulse signal. The update of the neuron membrane potential and the pulse emission ensure that the timing information can be effectively transmitted, and abnormality detection can be performed based on the pulse signal.
[0119] S43: Hidden layer:
[0120] Depending on the depth of the network and the complexity of the features to be extracted, the network may include multiple layers of spiking neurons. Neurons in each layer transmit information through membrane potential and spike firing. The number and structure of neurons in each layer can be flexibly adjusted to meet specific needs. Neurons in each layer receive spike signals from the previous layer and adjust their weights based on temporal dependencies.
[0121] S44: Spiking Neural Network Weight Learning
[0122] Spiking neural networks learn using the spike timing-dependent learning (STDP) rule, which adjusts the connection weights based on the time difference between the spikes emitted by neurons. The mathematical representation of the STDP rule is as follows:
[0123]
[0124] Where Δw ij A is the weight update between neuron i and neuron j; + and A - are constants of positive and negative time delays, respectively, which control the amplitude of weight update; Δt is the time difference between the pulse emission of neurons i and j; τ + and τ - is a time constant that controls the time scale of weight updates.
[0125] When the pulse emission of neuron i precedes that of neuron j, the weight increases; conversely, if the pulse emission of neuron i lags behind that of neuron j, the weight decreases.
[0126] S45: Output layer:
[0127] The neuron layer passes the processed pulse signal to the next layer and calculates the abnormal probability of the data through the pulse frequency. The output layer determines whether the current data is abnormal based on the pulse emission frequency of the neuron and calculates the abnormal probability:
[0128]
[0129] Among them, P abnormalIndicates the probability that the data is abnormal; spike_frequency is the pulse frequency of the neuron; k is the adjustment factor.
[0130] When the output layer pulse frequency is high, it indicates that the possibility of data anomaly increases, otherwise it indicates that the data is normal.
[0131] S46: Training strategy:
[0132] The model training process is divided into two stages: pre-training and online learning. In the pre-training stage, the training set, validation set, and test set are constructed using historical data, and the model is trained offline. The specific settings are as follows:
[0133] Dataset division: 80% training set, 20% test set. All data are divided in chronological order to ensure that the test set contains unseen data patterns.
[0134] Optimizer: Adam. The initial learning rate can be set to 1e-3 and dynamically adjusted based on the performance of the validation set.
[0135] Batch size: Select an appropriate batch size (for example, 32 or 64) based on the data size and hardware resources.
[0136] The number of iterations is determined based on the accuracy of the validation set and the loss curve. Early stopping is often used to prevent overfitting.
[0137] Cross-validation: 5-fold cross validation is used to avoid overfitting problems caused by data partitioning and improve the generalization ability of the model.
[0138] Model evaluation: Use the validation set to monitor model performance, such as accuracy, recall, and F1 score. For anomaly detection tasks, ROC curves and AUC metrics can also be used for evaluation.
[0139] S47 deployment and online learning expansion:
[0140] Pre-trained model deployment: The pre-trained SNN model is deployed into the industrial control system as the initial anomaly detection module.
[0141] Online learning extension: After deployment, the model uses incremental learning algorithms such as Figure 4 As shown in the figure, model parameters are updated every 24 hours to automatically adapt to feature shifts caused by device aging and environmental changes. This mechanism ensures that the system's detection performance remains highly accurate even during long-term operation. The core algorithm of incremental learning is online gradient descent, which updates model parameters by calculating the gradient of the loss function in real time.
[0142] Fine-tune the model based on newly collected real-time data without completely retraining. The update formula of the online gradient descent algorithm used in incremental learning is as follows:
[0143]
[0144] where θ t represents the model parameters of the tth iteration; η is the learning rate, and its initial value is set to 1×10 -3 , and dynamically adjust according to the validation set loss (for example, if the loss does not decrease, it will be attenuated to 0.1 times the original value); Based on the current batch data B t Calculate the gradient of the loss function; the loss function J(θ) is defined as the sum of the cross entropy loss and the L2 regularization term:
[0145]
[0146] Where λ is the regularization coefficient (the default value is 1×10 -4 ; is the model prediction value, y i is the true label.
[0147] The specific experimental settings and details are as follows:
[0148] Incremental data flow: Each update uses only the newly collected real-time data batch B t (Batch size is 32) to avoid retraining on all data;
[0149] Gradient calculation: Automatic differentiation (Autograd) is used to calculate the gradient of the current batch in real time, reducing memory usage to less than 5% of traditional batch processing;
[0150] Learning rate adaptation: Use exponential decay strategy. If the loss does not decrease for three consecutive batches, then η←0.1←η.
[0151] Model stability: Save parameter snapshots regularly (every 24 hours) to prevent model drift caused by abnormal data during online learning.
[0152] Combined with transfer learning technology, the pre-trained model parameters are used as the initial weights to quickly adapt to the feature distribution changes of the current operating environment through a small amount of field data.
[0153] The blockchain audit module is built on the blockchain framework and is used to record and track key operations and abnormal events in real time.
[0154] In a feasible implementation, in order to ensure the transparency and auditability of system operations, the present invention constructs a blockchain audit mechanism based on Hyperledger Fabric and an abnormal event recording and privacy protection method driven by smart contracts. Figure 5 shown.
[0155] Specifically, building a high-security blockchain audit system based on the Hyperledger Fabric blockchain framework includes:
[0156] The system, deployed jointly by an industrial on-site server and a cloud-based monitoring center, uses Hyperledger Fabric as a private blockchain platform to achieve high data security and privacy protection. The blockchain audit module automatically records security events triggered by the AI anomaly detection module through smart contracts, which are triggered by the detection of an anomaly.
[0157] When storing audit logs, data anonymization and encryption protection measures are implemented to ensure compliance with national data security regulations:
[0158] The device serial number is one-way desensitized using the SM3 hash algorithm, retaining only the first 6 bytes to prevent the leakage of the device's complete identity information; the geographic location information is encrypted and stored using the SM4 algorithm. The encryption key is dynamically generated by the TEE module and ensures that the location information can only be decrypted in a trusted environment, ensuring the security of the geographic location information during storage and transmission.
[0159] This blockchain audit system supports real-time query and traceability. Operation logs (such as user logins, command issuance, and abnormal events) are automatically written to the blockchain through smart contracts, ensuring that the logs cannot be tampered with. Each log entry is timestamped with millisecond-level accuracy. Any attempt to tamper with blockchain data or change block content will result in a hash chain break, triggering a system alarm, ensuring the immutability of audit data. This module records and tracks critical operations and abnormal events in real time, providing strong support for security incident analysis, auditing, and accountability.
[0160] Furthermore, Hyperledger Fabric adopts the Raft consensus mechanism, and the node roles include orderer and peer.
[0161] Smart contract triggering logic: When the AI anomaly detection module outputs an anomaly probability that exceeds a threshold (e.g., 0.9), the contract is automatically called to write the event into the blockchain, along with a millisecond timestamp generated by the GPS timing module.
[0162] The audit chain supports real-time query and traceability. Users or administrators can query the blockchain to understand the system's operation history. If any log entry is tampered with or the hash chain is broken, the system will trigger a security alert, promptly identifying potential security issues.
[0163] The dynamic security policy engine is used to automatically trigger corresponding security response policies based on the detection results output by the anomaly detection module.
[0164] In a feasible implementation, the present invention designs a dynamic security response strategy engine and an adaptive security protection method based on AI detection results.
[0165] Specifically, developing a security response strategy that is automatically triggered when an AI anomaly detection real-time monitoring system detects an anomaly includes:
[0166] This invention builds a dynamic security policy engine that automatically triggers appropriate security response strategies based on the anomaly level and type information output by the AI anomaly detection module. The engine can adjust the system's security measures in real time, including but not limited to: recording security logs to archive detailed information about anomalies for traceability; limiting communication bandwidth to dynamically adjust the bandwidth limits of devices or network channels based on the anomaly level to slow the spread of potential attacks; and disconnecting the network to automatically isolate affected devices or services, severing connections to external networks or other devices to prevent further malicious activity.
[0167] Upon detecting abnormal instructions or data tampering, the system automatically isolates the affected device and closes the abnormal communication port. It also sends an alert to the security monitoring center, providing real-time security monitoring and response. Integrating the TEE module's remote trusted authentication capabilities, the system authenticates the suspicious device, confirms compliance with security requirements, and verifies system integrity. If the system is confirmed to have been attacked or tampered with, it performs remediation actions, including restoring the original secure state and restarting the system, to ensure the normal operation of the device and system.
[0168] This method has adaptive adjustment capabilities, can automatically adjust security policies according to different types and levels of anomalies, and supports remote control, enabling the system to flexibly respond to various security threats and enhance the overall security and stability of industrial control systems.
[0169] like Figure 6 As shown, through the organic integration and coordinated operation of the above modules, this invention achieves comprehensive security protection for industrial control systems, from hardware to software, and from data transmission to real-time monitoring. This system is not only innovative in secure boot, data encryption, trusted execution, anomaly detection, and log auditing, but also effectively improves the system's real-time performance, stability, and adaptive security protection capabilities by introducing dedicated hardware acceleration and dynamic online learning mechanisms.
[0170] In addition, it should be noted that this system is based on the domestic chip security computing unit of the TPM module and the national secret algorithm, which has been verified through experiments. The specific implementation details are provided below.
[0171] Existing industrial control systems mainly rely on Intel SGX or TPM 2.0 to achieve secure boot, but there are compatibility issues in the environment of domestic chips. This invention is based on the domestic Feiteng / Loongson architecture and adopts an independent trusted computing module (TPM), providing the following optimizations:
[0172] Table 1 Comparative analysis of the present invention and traditional safety technology
[0173]
[0174] The specific comparison in Table 1 shows that the present invention has obvious advantages in terms of localization adaptability, startup integrity protection, and support for national encryption algorithms, and is particularly suitable for industrial control systems with high security requirements.
[0175] In addition, it should be noted that the encryption throughput of the system's dedicated hardware encryption accelerator has been tested. The specific test methods and results are provided below:
[0176] (1) Test environment:
[0177] Chip model: Feiteng E2000Q (ARMv8 architecture, 4-core CPU, main frequency 2.0GHz);
[0178] Data packet size: 512 bytes (simulating industrial control protocol data traffic);
[0179] Number of concurrent connections: 1000 (simulating large-scale industrial data transmission scenarios).
[0180] (2) Test method:
[0181] A dedicated FPGA-based encryption accelerator is used to accelerate the SM2 public key encryption, SM3 hash, and SM4 symmetric encryption algorithms.
[0182] A two-end test (encryption end-decryption end) is used to measure end-to-end throughput and calculate the average encryption speed.
[0183] Use the iperf3 tool to simulate large-scale concurrent connections and test the data transmission rate.
[0184] (3) Experimental results:
[0185] SM4 symmetric encryption: throughput 10.5 Gbps, latency 1.8 μs;
[0186] SM3 hash calculation: throughput 9.8Gbps, hash calculation time 2.1μs;
[0187] SM2 public key encryption: throughput 3.2 Gbps, latency 5.6 μs.
[0188] The results show that the encryption accelerator of the present invention can effectively reduce computing delay and improve throughput under high concurrency conditions, thus meeting the real-time requirements of industrial control systems.
[0189] In addition, it should be noted that the AI anomaly detection module of this system has been specifically tested. The specific test items and test results are provided below:
[0190] Training and evaluation methods for AI anomaly detection models
[0191] (1) Data source:
[0192] This test uses industrial control system (ICS) data from a smart manufacturing plant. The data set includes 10,000 sensor data items (temperature, pressure, and vibration), PLC instructions, and Modbus / TCP protocol communication logs.
[0193] (2) Data preprocessing:
[0194] The sliding window length is 1 second and the step size is 0.5 second to capture the timing patterns in a short time.
[0195] Normalize to [-1, 1] to prevent the numerical range from affecting the model convergence.
[0196] A low-pass filter (cut-off frequency 10 Hz) is used to remove high-frequency noise and improve model stability.
[0197] (3) Experimental verification method:
[0198] Dataset partitioning: 80% training set, 20% test set. All data are divided in chronological order to ensure that the test set contains unseen data patterns.
[0199] Cross-validation: 5-fold cross validation is used to avoid overfitting problems caused by data partitioning and improve the generalization ability of the model.
[0200] Model evaluation metrics:
[0201] F1 score ≥ 0.9 (comprehensive measurement of precision and recall);
[0202] Accuracy ≥ 95%, False Positive Rate ≤ 5%;
[0203] ROC curve and AUC index (AUC ≥ 0.95) were used to evaluate the detection ability of the model at different thresholds.
[0204] (4) Experimental results:
[0205] Experiments were conducted on a dataset of 10,000 records. The average F1 score for 5-fold cross-validation was 0.91, the false alarm rate was 4.8%, and the recall rate was 93.5%, indicating that the model has good anomaly detection performance. See Table 2 for details.
[0206] Table 2 Anomaly detection test results based on the Feiteng E2000Q chip
[0207] Test items Traditional solution Improved plan Secure Boot takes time 3.5 seconds 2.5 seconds (30% reduction) AI Anomaly Detection F1 Score 0.75 ≥0.9 Encrypted throughput 2Gbps ≥10Gbps Log tampering detection success rate 70% 100%
[0208] In the embodiments of the present invention, domestic chips, hardware acceleration, trusted execution environment, artificial intelligence anomaly detection and blockchain log audit modules are combined to provide comprehensive protection from hardware security, encryption operations to real-time anomaly detection and security auditing. It aims to cope with security threats in complex industrial environments, improve data security and system stability, and is suitable for industrial sites with extremely high security requirements.
[0209] Figure 7 A method for full-link detection and trusted industrial control based on a domestic chip is shown according to an exemplary embodiment. The method can be implemented by a full-link detection and trusted industrial control system based on a domestic chip. The system includes a secure computing module, a dedicated hardware encryption acceleration module, a trusted execution environment module, an anomaly detection module, a blockchain audit module, and a dynamic security policy engine. The processing flow of the method may include the following steps:
[0210] S1. By integrating the trusted platform module TPM inside the domestic chip to build a secure computing module, the secure computing module uses the SM2 / SM3 / SM4 national encryption algorithm for hardware acceleration, and supports a multi-level secure boot mechanism based on digital signatures to achieve full-link integrity verification from the basic input and output system BIOS to the application.
[0211] S2. Design a dedicated hardware encryption acceleration module based on the application-specific integrated circuit ASIC or field-programmable gate array FPGA architecture. The dedicated hardware encryption acceleration module is integrated into the domestic chip to achieve a throughput of more than 10Gbps to meet industrial real-time requirements.
[0212] S3. Build a trusted execution environment module based on secure isolation technology. The trusted execution environment module supports remote trusted measurement. The dynamic key generated based on the trusted execution environment module is used to encrypt and protect sensitive information.
[0213] S4. Build an anomaly detection module based on the pulse neural network. The anomaly detection module is used to detect anomalies in industrial data.
[0214] S5. Build a blockchain audit module based on the blockchain framework. The blockchain audit module is used to record and track key operations and abnormal events in real time.
[0215] S6. Build a dynamic security policy engine to automatically trigger corresponding security response policies based on the detection results output by the anomaly detection module.
[0216] In the embodiments of the present invention, domestic chips, hardware acceleration, trusted execution environment, artificial intelligence anomaly detection and blockchain log audit modules are combined to provide comprehensive protection from hardware security, encryption operations to real-time anomaly detection and security auditing. It aims to cope with security threats in complex industrial environments, improve data security and system stability, and is suitable for industrial sites with extremely high security requirements.
[0217] The above embodiments can be implemented in whole or in part through software, hardware (such as circuits), firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired method (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0218] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0219] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0220] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0221] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0222] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0223] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of the device or unit, which can be electrical, mechanical or other forms.
[0224] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0225] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0226] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0227] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A full-link detection and trusted industrial control system based on domestic chips, characterized by: The system includes a secure computing module, a dedicated hardware encryption acceleration module, a trusted execution environment module, an anomaly detection module, a blockchain audit module, and a dynamic security policy engine; wherein, The secure computing module is built by integrating the Trusted Platform Module (TPM) inside a domestic chip, adopting the SM2 / SM3 / SM4 national encryption algorithm for hardware acceleration, and supporting a multi-level secure boot mechanism based on digital signatures to achieve full-link integrity verification from the basic input and output system (BIOS) to the application; The dedicated hardware encryption acceleration module is designed based on the application-specific integrated circuit ASIC or field programmable gate array FPGA architecture and integrated into the domestic chip to achieve a throughput of more than 10Gbps to meet industrial real-time requirements; The trusted execution environment module is built based on secure isolation technology and supports remote trusted measurement. The dynamic key generated based on the trusted execution environment module is used to encrypt and protect sensitive information. The anomaly detection module is built based on a spiking neural network and is used to detect anomalies in industrial data. The blockchain audit module is built on the blockchain framework and is used to record and track key operations and abnormal events in real time; The dynamic security policy engine is used to automatically trigger corresponding security response policies based on the detection results output by the anomaly detection module.
2. The full-link detection and trusted industrial control system based on domestic chips according to claim 1 is characterized in that: The secure computing module is constructed by integrating a trusted platform module (TPM) into a domestic chip, and includes: A trusted platform module TPM is integrated inside the domestic chip, and the trusted platform module TPM is connected to the main control unit of the domestic chip through a serial peripheral interface SPI to obtain a secure computing unit; Among them, the domestic chips include the domestic Feiteng E series and Loongson 3 series ARM v8 / RISC-V architecture chips; The Trusted Platform Module (TPM) complies with the TPM 2.0 standard.
3. The full-link detection and trusted industrial control system based on domestic chips according to claim 1 is characterized in that: The multi-level secure startup mechanism includes: The root key in the system is stored in the secure storage area of the Trusted Platform Module (TPM). All signature keys are protected by a hardware fuse mechanism to prevent physical attacks from obtaining key information. During the system startup process, the basic input and output system (BIOS), boot loader, operating system, and application programs are digitally signed and verified in sequence to ensure that all software components have not been tampered with. When verification fails at any stage, the trusted platform module TPM triggers a hardware reset and generates a security audit log, which is automatically uploaded to the blockchain audit module to ensure that tampering events are traceable.
4. The full-link detection and trusted industrial control system based on domestic chips according to claim 1 is characterized in that: The dedicated hardware encryption acceleration module adopts a parallel pipeline structure and supports hardware-level acceleration optimization of SM2 public key encryption, SM3 hash and SM4 symmetric encryption algorithms.
5. The full-link detection and trusted industrial control system based on domestic chips according to claim 1 is characterized in that: The trusted execution environment module runs security-critical code and data in an independent isolation area to prevent malware attacks and unauthorized access; The remote trusted measurement allows a remote security monitoring center to verify the integrity of system firmware and software through the trusted execution environment module; The trusted execution environment module supports remote identity authentication during secure boot and ensures the trustworthiness of the remote system through smart contracts.
6. The full-link detection and trusted industrial control system based on domestic chips according to claim 1 is characterized in that: The anomaly detection module is built based on a spiking neural network and is used to detect anomalies in industrial data, including: Acquire multi-source time series data in an industrial control system, and convert the multi-source time series data into a pulse signal through time series coding; The pulse signal is input into the spiking neuron layer of the spiking neural network. After receiving the pulse signal, the membrane potential of each neuron in the spiking neuron layer is updated according to the pulse frequency until the membrane potential reaches a threshold value, at which time the neuron emits a pulse signal, and abnormality detection is performed based on the pulse signal. The spiking neural network uses a pulse timing dependency learning rule to adjust the connection weights between neurons; After the spiking neural network is deployed, it is fine-tuned based on newly collected real-time industrial data through an incremental learning method; incremental learning uses an online gradient descent algorithm.
7. The full-link detection and trusted industrial control system based on domestic chips according to claim 1 is characterized in that: The blockchain audit module automatically records security events triggered by the anomaly detection module through smart contracts; During the event recording process, the blockchain audit module performs one-way desensitization processing on the device serial number using the SM3 hash algorithm, retaining only the first 6 bytes to prevent the leakage of the device's complete identity information; the geographic location information is encrypted and stored using the SM4 algorithm, and the encryption key is dynamically generated and protected by the trusted execution environment module to ensure the security of the geographic location information during storage and transmission.
8. The full-link detection and trusted industrial control system based on domestic chips according to claim 1 is characterized in that: The dynamic security policy engine is further used to: Record security logs, including archiving detailed information about abnormal events to ensure traceability; Limiting communication bandwidth, including dynamically adjusting bandwidth limits on devices or network channels based on anomaly levels to slow the spread of potential attacks; Disconnect from the network, including automatically isolating the affected device or service and severing its connection to external networks or other devices to prevent further malicious activity.
9. A full-link detection and trusted industrial control method based on domestic chips, characterized in that: The method is implemented by a full-link detection and trusted industrial control system based on domestic chips. The system includes a secure computing module, a dedicated hardware encryption acceleration module, a trusted execution environment module, an anomaly detection module, a blockchain audit module, and a dynamic security policy engine. The method includes: S1. A secure computing module is built by integrating a trusted platform module (TPM) into a domestic chip. The secure computing module uses the SM2 / SM3 / SM4 national encryption algorithm for hardware acceleration and supports a multi-level secure boot mechanism based on digital signatures, achieving full-link integrity verification from the basic input and output system (BIOS) to the application. S2. Design a dedicated hardware encryption acceleration module based on the application-specific integrated circuit ASIC or field-programmable gate array FPGA architecture. The dedicated hardware encryption acceleration module is integrated into the domestic chip to achieve a throughput of more than 10Gbps to meet industrial real-time requirements; S3. Building a trusted execution environment module based on security isolation technology, wherein the trusted execution environment module supports remote trusted measurement, and a dynamic key generated based on the trusted execution environment module is used to encrypt and protect sensitive information; S4. Constructing an anomaly detection module based on a pulse neural network, wherein the anomaly detection module is used to detect anomalies in industrial data; S5. Building a blockchain audit module based on the blockchain framework, which is used to record and track key operations and abnormal events in real time; S6. Build a dynamic security policy engine to automatically trigger corresponding security response policies based on the detection results output by the anomaly detection module.
10. The full-link detection and trusted industrial control method based on domestic chips according to claim 9 is characterized in that: The secure computing module is constructed by integrating a trusted platform module (TPM) into a domestic chip, and includes: A trusted platform module TPM is integrated inside the domestic chip, and the trusted platform module TPM is connected to the main control unit of the domestic chip through a serial peripheral interface SPI to obtain a secure computing unit; Among them, the domestic chips include the domestic Feiteng E series and Loongson 3 series ARM v8 / RISC-V architecture chips; The Trusted Platform Module (TPM) complies with the TPM 2.0 standard.
Citation Information
Cited By
Implementation method of safe and credible intelligent decentralized control system
CN121325784A
Numerical control equipment working data acquisition and processing platform
CN121326679A