A method for securing information physical system based on measuring output watermark encoding
By employing measurement output watermarking encoding technology in cyber-physical systems, the problems of replay attacks and erroneous data injection attacks are solved, achieving attack detection and privacy protection without affecting system control performance and reducing network bandwidth requirements.
Patent Information
- Application Number
- CN202511171326.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-21
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2045-08-21
AI Technical Summary
When facing replay attacks, existing cyber-physical systems (CPS) suffer from performance degradation due to current control input watermarking strategies, which fail to effectively identify erroneous data injection attacks. Furthermore, traditional methods cannot identify replay attacks without affecting system performance.
A security protection method based on measurement output watermark encoding is adopted. By constructing a watermark element set and performing permutation-transformation encryption, combined with secure Huffman coding, the watermark is embedded and removed from the sensor measurement signal. A chi-square detector is designed to detect attacks.
It effectively identifies replay attacks and erroneous data injection attacks, while reducing transmission signal capacity, saving network bandwidth, and providing privacy protection without affecting system control performance.
Smart Images

Figure CN120729624B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of control system security technology, and in particular relates to a cyber-physical system security protection method based on measurement output watermark encoding. Background Technology
[0002] The development of information technology has continuously enriched and improved the functionality of Cyber-Physical Systems (CPS), which integrate sensing, computing, and communication, leading to their widespread application in fields such as smart grids, intelligent transportation, and smart healthcare. However, in open network environments, the security of CPS is facing increasingly severe challenges. In recent years, security vulnerabilities in the network layer of CPS have been gradually discovered. By tampering with sensor measurement signals or control signals exposed in the transmission network, attackers can drive the control system away from its normal operating state, thereby triggering a series of security incidents.
[0003] Replay attacks, a representative type of attack, deceive widely used chi-square detectors by listening to sensor measurement signals transmitted over a network and replaying historical data back to the control system. Under this attack strategy, attackers do not need to design specific attack signals for the control system; they can easily achieve their target and threaten the security of cyber-physical systems simply by listening to and replaying historical sensor measurement data. Because the data replayed by the attacker comes from real measurement signals, the statistical characteristics of the detection residual probability distribution before and after the attack are completely consistent when the control system reaches a steady state. Therefore, existing chi-square detectors will be unable to detect replay attacks.
[0004] To detect replay attacks, current solutions involve adding perturbation signals to the CPS control input signals. These random perturbation signals, known as watermarks, disrupt the static characteristics exhibited by the cyber-physical system after reaching a stable state. Since the control watermarks added at different times are randomly generated, once historical sensor measurement signals are replayed by an attacker, the probability distribution statistics of the detection residuals will be affected by the watermark interference. In this case, a chi-square detector can be used for detection and verification, allowing the replay attack to be identified.
[0005] Methods based on control input watermarking can assist chi-square detectors in identifying replay attacks. However, this method comes at the cost of sacrificing some system control performance. Since the watermark itself is a disturbance signal to the control system, its introduction will inevitably have a negative impact on the control system's performance. The SCI research paper "Secure control against replay attacks" (In 2009 47th annual Allerton conference on communication, control, and computing (Allerton), pages 911-918) demonstrates the loss in system control performance caused by the introduced watermark. To minimize the frequency of watermark usage, current improvement methods combine event-triggered techniques to change the watermarking from continuous to intermittent injection. The SCI research paper "Recursive watermarking-based transient covert attack detection for the industrial CPS" (IEEE Transactions on Information Forensics and Security, 18:1709-1719, 2023) designs an event-triggered control input watermarking strategy. Using this method, while achieving the task of replay attack detection, the problem of degraded system control performance can be alleviated to some extent.
[0006] However, the above methods cannot fundamentally solve the problem of system control performance loss. Since the watermark added to the control input signal cannot be removed before attack detection is complete, a loss in system control performance is unavoidable. In this case, the system control signal is not optimal. Furthermore, to balance attack detection and system control performance, the covariance of the watermark cannot be too large. Otherwise, even in the absence of an attack, the system's control performance indicators will decline sharply, which is unacceptable to system administrators. Summary of the Invention
[0007] To address the shortcomings of existing technologies, this invention provides a cyber-physical system security protection method based on measurement output watermarking encoding, which addresses the security requirements of cyber-physical systems (CPS). This method overcomes the limitations of existing CPS in detecting replay attacks and provides the ability to identify false data injection (FDI) attacks. The watermarking encoding method designed in this invention can effectively reduce transmission signal capacity, save network bandwidth resources, and provide privacy protection for cyber-physical systems.
[0008] The technical solution of this invention is as follows:
[0009] A cyber-physical system security protection method based on measurement output watermark encoding includes the following steps:
[0010] A cyber-physical system is configured with a Kalman filter and a control system, and an operational model of the cyber-physical system is constructed. The Kalman filter is used to perform unbiased estimation of the state of the control system based on the operational model of the cyber-physical system, so as to obtain the posterior state estimate of the control system at the current moment. The control system is used to obtain the optimal control input signal based on the posterior state estimate of the control system at the current moment, so as to realize the control of the cyber-physical system.
[0011] Based on the operational model of cyber-physical systems, a chi-square detector is designed. The chi-square detector is used to detect whether the control system is subjected to replay attacks and erroneous data injection attacks.
[0012] Construct a basic watermark element set and select watermark elements from the basic watermark element set to construct a watermark. Add the watermark to the sensor measurement signal to obtain a watermark fusion signal.
[0013] Based on the permutation-transformation framework, the watermark fusion signal is encrypted to obtain the encrypted watermark fusion signal.
[0014] The encrypted watermark fusion signal is subjected to secure Huffman coding to obtain the measured output watermark coded signal, which is sent to the control system along with the Huffman coding table used for secure Huffman coding.
[0015] The watermark is removed from the measurement output watermark encoded signal according to the received Huffman coding table to obtain the recovered sensor measurement signal;
[0016] The recovered sensor measurement signal is input into the chi-square detector to obtain the chi-square detection value, and the error data injection attack detection and replay attack detection are realized based on the chi-square detection value;
[0017] When no replay attack or erroneous data injection attack is detected, the control system generates the optimal input control signal to control the cyber-physical system based on the recovered sensor measurement signals.
[0018] Furthermore, the operational model of the cyber-physical system is as follows:
[0019] (1);
[0020] (2);
[0021] in, Cyber-physical systems The state vector at time t, Cyber-physical systems The state vector at time t, and Both are integers, used to represent the dimension of the cyber-physical system's state vector and the cyber-physical system's runtime, respectively; It is a control input signal. It is an integer representing the dimension of the control input signal; yes Time-based process noise, yes A dimensional system matrix yes A dimensional control matrix; an initial state vector. and process noise They are set to be independent Gaussian random variables. and , Indicates a Gaussian distribution. It is the initial state vector The mean, and These represent the initial state vectors respectively. and process noise The covariance matrix of the Gaussian distribution it follows; It is a sensor measurement signal. It is an integer representing the dimension of the sensor-measured signal. It is a measurement matrix. It is related to the initial state vector and process noise Independent Gaussian measurement noise, It is the covariance matrix of the Gaussian distribution to which the Gaussian measurement noise follows.
[0022] Furthermore, the chi-square detector is described as follows:
[0023] (16);
[0024] in, It is an integer representing the size of the detection window of the chi-square detector. This represents the chi-square test value. It is an integer variable representing time. for Sensor measurement signal at any time, for Prior state estimation for time-controlled systems It is the inverse covariance matrix of the detection residual under attack-free conditions.
[0025] Furthermore, the basic watermark element set is represented as follows: This includes several watermark elements. It is a positive real number. It is a positive integer;
[0026] The method of selecting watermark elements from the set of basic watermark elements to construct a watermark specifically involves randomly selecting several watermark elements with equal probability to construct a watermark.
[0027] The watermark fusion signal is represented as follows:
[0028] (18);
[0029] in, Indicates the watermark fusion signal. It is a static template matrix. yes Constantly add sensor measurement signals The watermark in This indicates the first time the sensor measures the signal. The watermark component added by wei The dimension number of the sensor's measured signal.
[0030] Furthermore, the watermark fusion signal The specific encryption method is as follows:
[0031] (19);
[0032] in, The signal after a binary XOR operation. It is a binary encoded sequence, symbol This represents the binary XOR operation. Represents binary conversion functions;
[0033] Next, the signal after the binary XOR operation... Perform the following permutation operation:
[0034] (20);
[0035] Wherein, the permutation function Used in permutation sequence Under the influence of binary XOR operation, the signal is... Perform a permutation transformation. This is to encrypt the watermarked signal.
[0036] Furthermore, the Huffman code table is encrypted using a single-table substitution method before being sent to the control system.
[0037] Furthermore, the step of performing secure Huffman coding on the encrypted watermark fusion signal to obtain the measured output watermark encoded signal specifically involves:
[0038] Fuse encrypted watermark signal Convert to real number signal And according to the Huffman coding table, the real number signal is processed. Perform secure Huffman coding, where The function represents the conversion of a binary number to a decimal number. The final measurement output watermark encoded signal is represented as:
[0039] (twenty one);
[0040] in, This represents the secure Huffman coding function. This indicates the measurement output watermark encoding signal.
[0041] Further, the step of removing the watermark from the measurement output watermark encoded signal according to the received Huffman coding table to obtain the recovered sensor measurement signal specifically involves:
[0042] S1: Decode the measured watermark code according to the Huffman coding table to obtain the encrypted watermark fusion signal. ;
[0043] (twenty two);
[0044] in, This is the encrypted watermark fusion signal obtained after decoding. express inverse function, for The inverse function;
[0045] S2: Perform an inverse permutation-transformation operation on the encrypted watermark fusion signal and obtain the signal after binary XOR operation. ;
[0046] (twenty three);
[0047] in, To obtain the signal after binary XOR operation by performing the inverse permutation-transformation operation, express The inverse function;
[0048] S3: The signal after the binary XOR operation The watermark was removed, and the recovered sensor measurement signal was obtained. ;
[0049] (twenty four);
[0050] in, The sensor measurement signal obtained after removing the watermark. It is a static template matrix The inverse matrix, express The inverse function of .
[0051] Furthermore, the method for detecting replay attacks and data injection attacks specifically involves setting an attack detection threshold. Once the chi-square test value If the chi-square test value is positive, it is determined that the control system has been attacked, and an alarm is issued to the control system. If not, the alarm will not be triggered.
[0052] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0053] This invention addresses the security needs of cyber-physical systems (CPS) by designing a CPS security protection method based on measurement output watermarking encoding. This method can help chi-square detectors identify replay attacks and erroneous data injection attacks. Based on watermarking encryption technology, the method constructs a watermark element set and selects watermark elements with moderate probability, achieving rapid and cyclic watermark generation. Sensor measurement data is marked with randomly generated watermarks, encoded, and transmitted in ciphertext form over the network. Secure Huffman coding effectively reduces data transmission volume while ensuring data privacy. Compared to protection strategies that add watermarks to control input signals, the method designed in this invention exhibits superior performance in identifying replay attacks. Since the introduced watermark can be completely removed, zero control performance loss is achieved. Attached Figure Description
[0054] Figure 1 This is a flowchart of Huffman coding in an embodiment of the present invention;
[0055] Figure 2 This is a flowchart of the measurement output watermark encoding method in an embodiment of the present invention;
[0056] Figure 3 This is a comparison diagram of sensor measurement signals before and after encoding in an embodiment of the present invention;
[0057] Figure 4 This is a comparison diagram of the number of transmitted signal bits before and after encoding in an embodiment of the present invention;
[0058] Figure 5 This is a schematic diagram of the chi-square detection results for replay attacks in an embodiment of the present invention. Detailed Implementation
[0059] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0060] The cyber-physical system security protection method based on measurement output watermarking encoding designed in this invention, targeting the security characteristics of the control system, utilizes watermarking encoding technology to achieve the goals of attack detection and privacy protection. Simultaneously, this invention can effectively reduce the transmission signal capacity of the control system and save network bandwidth. Specifically, a cyber-physical system security protection method based on measurement output watermarking encoding includes the following steps:
[0061] Step 1: Assume the Cyber-Physical System (CPS) is equipped with a Kalman filter and a control system, and construct the CPS operating model. The Kalman filter is used to perform unbiased estimation of the control system's state based on the CPS operating model, obtaining the posterior state estimate of the control system at the current moment. The control system is used to obtain the optimal control input signal based on the posterior state estimate of the control system at the current moment, thereby realizing the control of the CPS. The control system includes a Linear Quadratic Gaussian (LQG) controller, a state estimator, actuators, and a plant, etc.
[0062] Cyber-physical systems (CPS) use sensors to monitor and regulate their state in real time. The operation of a cyber-physical system can be represented by the following state-space equations, i.e., the operational model of a cyber-physical system is:
[0063] (1);
[0064] (2);
[0065] in, Cyber-physical systems The state vector at time t, Cyber-physical systems The state vector at time t, and Both are integers, used to represent the dimension of the cyber-physical system's state vector and the cyber-physical system's runtime, respectively; It is a control input signal. It is an integer representing the dimension of the control input signal; yes Time-based process noise, yes A dimensional system matrix yes A dimensional control matrix; an initial state vector. and process noise They are set to be independent Gaussian random variables, that is and , Indicates a Gaussian distribution. It is the initial state vector The mean, and These represent the initial state vectors respectively. and process noise The covariance matrix of the Gaussian distribution it follows; It is a sensor measurement signal. It is an integer representing the dimension of the sensor-measured signal. It is a measurement matrix. It is related to the initial state vector and process noise Independent Gaussian measurement noise, It is the covariance matrix of the Gaussian distribution to which the Gaussian measurement noise follows;
[0066] Kalman filters are used to perform unbiased estimation of the state of a control system, specifically:
[0067] The iterative estimation process of the Kalman filter is expressed as follows:
[0068] (3);
[0069] (4);
[0070] (5);
[0071] (6);
[0072] (7);
[0073] in, express Posterior state estimation for time-controlled systems and They represent and Prior state estimation for time-controlled systems express Error covariance of the posterior state estimation of a time-controlled system. and They represent and Error covariance of prior state estimation for a time-controlled system. express Kalman filter gain at time t. express An identity matrix of dimension 1 Represents the inverse of a matrix. Represents the transpose of a matrix; a matrix , , , and As defined above; without loss of generality, the initial prior state estimate of the control system is set as follows: Under detectable conditions in the control system, the gain of the Kalman filter will rapidly converge to a steady value after a finite number of iterations. Therefore, the Kalman gain that converges to a steady state is defined as:
[0074] (8);
[0075] in, This represents the Kalman gain that converges to a steady state. In this case, the estimation of the control system state (prior state estimation and posterior state estimation) is expressed as:
[0076] (9);
[0077] (10);
[0078] The optimal control input signal is obtained using a Linear Quadratic Gaussian (LQG) controller in the control system.
[0079] Specifically, the objective function of the Linear Quadratic Gaussian (LQG) controller is expressed as:
[0080] (11);
[0081] in, Let be the objective function for the Linear Quadratic Gaussian (LQG) controller. and All are positive semi-definite matrices. It is an integer representing the total number of moments. It represents the expected value of a random variable;
[0082] The optimal solution to the objective function of the above Linear Quadrature Gaussian (LQG) controller, i.e., the optimal control input signal, is expressed as:
[0083] (12);
[0084] (13);
[0085] in, Represents the optimal control input signal, matrix To satisfy the following solution to the Riccati equation:
[0086] (14);
[0087] In the optimal control input signal Given a fixed condition, the objective function of the Linear Quadratic Gaussian (LQG) controller can be expressed as:
[0088] (15);
[0089] in, Represents the trace of a matrix. It is the optimal control input signal The value of the optimization objective function of the linear squared Gaussian (LQG) controller;
[0090] Step 2: Design a chi-square detector based on the operational model of the cyber-physical system;
[0091] In this invention, the chi-square detector is described as follows:
[0092] (16);
[0093] in, It is an integer representing the size of the detection window of the chi-square detector. This represents the chi-square test value. It is an integer variable representing time. for Sensor measurement signal at any time, for Prior state estimation for time-controlled systems It is the inverse covariance matrix of the detection residuals under attack-free conditions; without loss of generality, the attack detection threshold is set by the control system administrator. ,once The chi-square detector will then determine that the control system has been attacked and will send an alarm to the control system. If so, the alarm will not be triggered;
[0094] Replay Attack Strategy Analysis: The replay attack type considered in this invention is a more concealed, discontinuous replay attack. Under this attack strategy, the attacker breaks down the entire replay attack task into several sub-tasks, which are implemented by corresponding sub-attacks. Before the attack begins, the attacker monitors the control system's transmission network and records a sufficient number of sensor measurement signals as replay signal sources. During the attack execution phase, each sub-attack is activated sequentially. The replay attack immediately stops after each sub-attack is completed. A random time interval is maintained between any two sub-attacks to conceal the attack behavior. When all sub-tasks are completed, the entire replay attack task is also completed. For a discontinuous replay attack, the duration of a sub-attack can be expressed as:
[0095] (17);
[0096] in, It is an integer representing the duration of a sub-attack; It is an integer representing the actual execution time of the sub-attack, which is related to the specific sub-task; It is an integer random variable used to represent the time interval between two adjacent sub-attacks;
[0097] Step 3: Construct a basic watermark element set and select watermark elements from the basic watermark element set to construct a watermark. Add the watermark to the sensor measurement signal to obtain the watermark fusion signal.
[0098] The watermarks required in this embodiment of the invention can be generated cyclically and reused. The basic watermark element set is represented as follows: This includes several watermark elements. It is a positive real number. It is a positive integer;
[0099] The method of selecting watermark elements from the set of basic watermark elements to construct a watermark specifically involves randomly selecting several watermark elements with equal probability to construct a watermark.
[0100] The watermark fusion signal is represented as follows:
[0101] (18);
[0102] in, Indicates the watermark fusion signal. It is a static template matrix used to further hide the real sensor measurement signals. yes Constantly add sensor measurement signals The watermark in This indicates the first time the sensor measures the signal. The watermark component added by wei The dimension number of the sensor's measured signal;
[0103] Step 4: Based on the permutation-diffusion framework, fuse the watermark signal. Encryption is performed to obtain an encrypted watermark fusion signal, which effectively protects the privacy of the control system;
[0104] The watermark fusion signal The specific encryption method is as follows:
[0105] (19);
[0106] in, The signal after a binary XOR operation. It is a binary encoded sequence, which is kept secret from attackers; the symbols... This represents the binary XOR operation. This represents a binary conversion function; after conversion, the watermark fusion signal... Each decimal digit is represented by a set of 4-bit binary numbers. Specifically, the correspondence between binary and binary conversion is shown in the table below.
[0107] Table I. Binary Conversion Reference Table
[0108] 0000-1001 1010 1111 1110 0-9 Distinguish between integer and decimal places ‘+’ ‘-’
[0109] Next, the signal after the binary XOR operation... Perform the following permutation operation:
[0110] (20);
[0111] Wherein, the permutation function Used in permutation sequence Under the influence of binary XOR operation, the signal is... After performing the permutation-transformation operation, the encrypted watermark fusion signal is obtained. Real sensor measurement signals The information is therefore hidden;
[0112] Step 5: Merge the encrypted watermark signal Perform secure Huffman coding to obtain the measurement output watermark code signal and send it to the control system along with the Huffman code table used for secure Huffman coding.
[0113] like Figure 1As shown, Huffman coding is an optimal coding scheme that can effectively reduce the signal capacity of network transmission. Because this coding method has the characteristic of no prefix, the control system (receiving end) can immediately decode the unique original signal after receiving the symbol.
[0114] In this invention, the Huffman code table is encrypted using a single-table substitution method before being sent to the control system (receiving end), and this is referred to as secure Huffman coding. In this case, if the transmitted signal is tampered with by an attacker, decoding may be impossible, and the attacker's destructive actions will be exposed.
[0115] like Figure 2 As shown, in this invention, the encrypted watermark is fused with the signal. Convert to real number signal And according to the Huffman coding table, the real number signal is processed. Perform secure Huffman coding, where This represents a function that converts a binary number to a decimal number. For example, for the symbols and frequencies given in Table II below, the number of symbol savings after secure Huffman coding is... .
[0116] Table II. Examples of Secure Huffman Coding
[0117] symbol 0 1 2 3 4 5 6 7 8 9 frequency 3 2 0 8 2 1 5 2 4 6 coding 1001 0000 100000 11 10001 100001 101 0001 001 01
[0118] Based on the above security operation process, the final measurement output watermark encoded signal is represented as:
[0119] (twenty one);
[0120] in, This represents the secure Huffman coding function. This indicates the measured output watermark encoded signal. As noted in Table II, the data obtained after secure Huffman coding is a digital signal composed of 0s and 1s. This digital signal is transmitted through the network layer and decrypted upon reaching the control system (receiving end).
[0121] Step 6: Remove the watermark from the measurement output watermark encoding signal according to the received Huffman coding table to obtain the recovered sensor measurement signal;
[0122] Step 6.1: Decode the measured watermark code according to the Huffman coding table to obtain the encrypted watermark fusion signal. ;
[0123] (twenty two);
[0124] in, This is the encrypted watermark fusion signal obtained after decoding. express inverse function, for The inverse function;
[0125] Step 6.2: Perform an inverse permutation-transformation operation on the encrypted watermark fusion signal and obtain the signal after binary XOR operation. ;
[0126] (twenty three);
[0127] in, To obtain the signal after binary XOR operation by performing the inverse permutation-transformation operation, express The inverse function;
[0128] Step 6.3: From the signal after binary XOR operation The watermark was removed, and the recovered sensor measurement signal was obtained. ;
[0129] Specifically, the control system eliminates the interference of the watermark on the sensor measurement signal by performing the following operations:
[0130] (twenty four);
[0131] in, The sensor measurement signal obtained after removing the watermark. It is a static template matrix The inverse matrix, express The inverse function;
[0132] It can be seen that, under normal circumstances, the control system will not suffer any loss in control performance, and the control input signal will always be the optimal control input signal. ;
[0133] Step 7: Input the recovered sensor measurement signal into the chi-square detector to obtain the chi-square detection value and realize replay attack detection based on the chi-square detection value;
[0134] Watermark Statistical Characteristics Analysis: For replay attacks, set... Time measurement outputs watermark encoded signal quilt The historical measurement of time outputs the watermark encoded signal. The replacement, of which and Since all numbers are integers, the decoding result of the control system is represented as:
[0135] (25);
[0136] in, Indicates replay attack Decoding the measurement signal at any given time, This represents the secure Huffman coding function. express inverse function, express Watermark of a moment;
[0137] Because the sensor measurement signals at different times are marked with different watermarks, when a replay attack occurs, the decoded measurement signals at the receiving end... With the actual decoded measurement signal There will be discrepancies between them, specifically, let express Time and The difference in the watermark added at each moment, express The watermark at any given time, since the watermark is selected from the set of basic watermark elements with equal probability, therefore for any... Time and The probability of the watermark component selected at time step 1 can be expressed as:
[0138] (26);
[0139] in, express Select watermark component at any time The probability, express The watermark weight of time, express Select watermark component at any time The probability of;
[0140] In this case Time and The difference in watermarks added at different times The expectation is:
[0141] (27);
[0142] in, express Expectations express Expectations express Expectations;
[0143] From equation (26), the components of the watermark , The variance is expressed as:
[0144] (28);
[0145] in, express variance express Expectations express The square of the expectation, Represents an integer variable;
[0146] because , It is the component of the replayed historical watermark, therefore its variance Note the components of the watermark. , , and Any two in the set are independent of each other, where, , and To represent two distinct integers, therefore, Time and The difference in watermarks added at different times The covariance is:
[0147] (29);
[0148] in, The covariance of a random variable express The above equation (29) reveals the statistical characteristics of the difference between the watermarks added at different times. Using these statistical characteristics, replay attacks can be identified by the chi-square detector.
[0149] For ease of explanation, the following two variables are defined. and .in, This indicates the error introduced by the incorrect decoding measurement output watermark encoding signal. express Time and The difference between signals measured by the time sensor;
[0150] Set replay attack from At the start of the time, when a replay attack is not initiated, the measured output watermark encoded signal is... It can be correctly decoded, at which point the control system is in The state estimate at time t is expressed as:
[0151] (30);
[0152] Configure attacker to select from A historical sensor measurement signal, starting from a specific moment, is used as the replay signal source. Once a replay attack occurs... It is activated at all times because it measures the output watermark encoding signal. Marked by the watermark, the watermark-encoded signal replayed by the attacker will deviate from the actual decrypted signal after decryption. Without loss of generality, we define variables... Therefore, the state estimation of the control system under a replay attack is expressed as:
[0153] (31);
[0154] in, Indicates the impact of a replay attack Prior state estimation for time-controlled systems Indicates the impact of a replay attack Posterior state estimation for time-controlled systems Indicates the impact of a replay attack Prior state estimation for time-controlled systems Indicates the impact of a replay attack The control input signal at any given time;
[0155] The state estimates represented by equations (30) and (31) above can be derived through further iterations. Estimation of the control system state up to a given time;
[0156] Considering that the replay attack is from It starts at a certain time, therefore state estimation and The difference between them is expressed as:
[0157] (32);
[0158] in, It is an integer variable. Indicates the impact of a replay attack Prior state estimation for time-controlled systems express Prior state estimation of the time-lapse control system; Equation (32) above reveals the impact of replay attacks on the state estimation of the control system. When the control system reaches a steady state, the added watermark will have a decisive impact on the state estimation performance. Based on Equation (32), the control system state estimation and The difference between them can be further expressed as:
[0159] (33);
[0160] in, It is an integer variable. Indicates the impact of a replay attack Prior state estimation for time-controlled systems express Prior state estimation of the time-control system; note that, since the erroneous decoding originates from... It begins at a certain moment, therefore Established, that is to say, The control system state estimate prior to time step [time] will not be affected by the replay attack. In this case, the detection residual of the chi-square detector is expressed as:
[0161] (34);
[0162] Under the influence of a replay attack, the probability distribution of the aforementioned detection residuals will be disturbed; therefore... The chi-square test value at time t is expressed as:
[0163] (35);
[0164] in, express The chi-square test value at time; It is an integer variable, a set , representing the entire set of detection times. Indicates the impact of a replay attack Prior state estimation for time-controlled systems;
[0165] From equation (34), based on variables Definition of residual detection Further expressed as:
[0166] (36);
[0167] Combining equations (35) and (36) above, the chi-square detection value under the influence of a replay attack is:
[0168] (37);
[0169] in, It is a vector, specifically, , , , It is an integer variable; the parameter in equation (37) ;
[0170] Comparison of replay attack detection performance with control input watermarking strategies: To compare the measurement output watermarking encoding method designed in this invention with existing control input watermarking strategies, a virtual system is introduced, which can be regarded as the latency of the real control system, and is represented as follows:
[0171] (38);
[0172] (39);
[0173] (40);
[0174] (41);
[0175] (42);
[0176] in, , and These represent the state vector of the virtual system, the control input signal, and the sensor measurement signal, respectively. express Posterior state estimation of a time-limited virtual system and They represent and Prior state estimation of a time-limited virtual system and These represent the process noise and measurement noise of the virtual system, respectively; the initial state of the virtual system is assumed to be... and ,in This represents the initial state of the virtual system at time 0. This represents the initial prior state estimate of the virtual system at time 0. Prior state estimation at time 1 Represented as:
[0177] (43);
[0178] For virtual systems, when a replay attack originates from... The time lasts until At time t, the state estimate of the disturbed virtual system is expressed as:
[0179] (44);
[0180] Among them, integer variables , express Prior state estimation of a virtual system that is constantly perturbed by replay attacks. express The prior state estimation of the virtual system constantly perturbed by the replay attack; therefore, for discrete linear time-invariant systems, based on the iterative equations given in equations (43) and (44), the virtual system state estimation... and The difference between them is expressed as:
[0181] (45);
[0182] in, express Prior state estimation of a time-limited virtual system express Prior state estimation of a virtual system that is constantly perturbed by replay attacks;
[0183] For the sake of simplicity, let The detection residual of the chi-square detector Represented as:
[0184] (46);
[0185] Due to the replay attack from Starts up at any time and continues until At that moment, equation (46) can therefore be further rewritten as:
[0186] (47);
[0187] Considering that the latency of a virtual system can be viewed as that of a real control system, therefore:
[0188] (48);
[0189] Based on the definition of a virtual system and on equation (48), we can further deduce that:
[0190] (49);
[0191] make Based on the probabilistic statistical properties of watermarks, it can be concluded that... Note that the residual It is independent of Therefore The covariance is expressed as:
[0192] (50);
[0193] Given the addition of a watermark component to the sensor measurement signal and They are independent of each other, among which , and Representing two distinct integers, therefore The covariance is expressed as:
[0194] (51);
[0195] For ease of explanation, the following variables are defined:
[0196] (52);
[0197] in, It is an integer variable. ;
[0198] Substituting equations (51) and (52) into equation (50), we get:
[0199] (53);
[0200] As can be seen from equation (53), for replay attacks, the measurement output watermarking encoding method designed in this invention has better attack detection performance compared to the control input watermarking strategy. Because the watermark introduced in this invention can be completely removed, the watermark added to the measurement signal will not damage the system's control performance. In this case, by adjusting the watermark parameters... Replay attacks will be accurately identified by the chi-square detector;
[0201] Step 8: Input the recovered sensor measurement signal into the chi-square detector to obtain the chi-square detection value and implement error data injection attack detection based on the chi-square detection value;
[0202] FDI Attack Detection Performance Analysis: The method designed in this invention also exhibits good attack detection performance against False Data Injection (FDI) attacks. (Secret parameters) , , , and In the absence of leakage, an FDI attack on the measurement output watermark encoded signal is represented as follows:
[0203] (54);
[0204] in, This indicates the measurement output watermark encoded signal injected by an FDI attack. This indicates an FDI attack injection; to evade the Chi-square detector, the attacker needs to ensure the Chi-square detection metrics are accurate. Not exceeding the detection threshold :
[0205] (55);
[0206] in, It is an integer variable. This represents the chi-square detection metric under FDI attacks. The sensor measurement signal is decoded under an FDI attack. For the control system under FDI attack Prior state estimation at time step;
[0207] Based on the watermarking encoding method designed in this invention, the FDI attack process shown in equation (54) is further expressed as:
[0208] (56);
[0209] However, due to secret parameters , , , and It is unknown whether an FDI attack will be detected by a chi-square detector. This is for several reasons: First, the attacker outputs a watermark-encoded signal to the measurement system. Injected attack signals This will disrupt Huffman coding rules and potentially cause decoding chaos. Once decoding becomes chaotic and erroneous, FDI attacks will be easily detected. Secondly, even if the signal subjected to an FDI attack can be decoded, the secret parameters will be lost. , , , and Unknown, injection attacks are possible within the permutation-transformation protection framework designed in this invention. Disturbances to the state estimation of the control system cannot be predicted, making it difficult for attackers to conceal their destructive actions; in this case, FDI attacks will be detected by the chi-square detector.
[0210] Analysis of the impact of FDI attacks on control performance under the condition of secret parameter leakage: Assume that the attacker obtains the secret parameters through some method. , , , and The information is crucial. If an attacker can only tamper with the sensor measurement signals, the control performance of the control system will be weakened. For an attacker, a feasible attack strategy is to disguise an FDI attack as measurement noise. Therefore, if the secret parameters are leaked, the injection attack is represented as:
[0211] (57);
[0212] in, This represents the injected sensor measurement signal. This indicates an injection attack. , express The covariance of the control system will decrease in this case, and for ease of description, we define... Considering the impact of FDI attacks, The state of the control system at a given time is represented as follows:
[0213] (58);
[0214] Without loss of generality, The cost function of the control system at time t is defined as:
[0215] (59);
[0216] in, Let represent the cost function of the control system at time t. Represent an integer, Let an integer variable be an integer variable. In this case, the optimization objective function of the LQG controller is... For a given moment Define the following variables ,and ;
[0217] (60);
[0218] in, This indicates the sensor measurement signals available to the control system. This represents an integer variable; therefore, This represents the system control cost index obtained under the conditions of received sensor measurement signals, denoted by... According to the definition, the following recursive expression holds:
[0219] (61);
[0220] Next, we will first prove that the optimal control input signal Below The following recursive equation is satisfied:
[0221] (62);
[0222] Among them, matrix This can be represented by the following recursive expression:
[0223] (63);
[0224] With matrix Similarly, matrix Represented by the following recursive expression:
[0225] (64);
[0226] in, and , express Error covariance of posterior state estimation of a time-controlled system, matrix ,when When the recursive expression (62) is true, set Satisfying equation (62), now it is necessary to prove... Based on the above assumptions, the following derivation is obtained:
[0227] (65);
[0228] because and They are independent of each other, therefore The expectation is expressed as:
[0229] (66);
[0230] Based on equation (58), we can derive:
[0231] (67);
[0232] Substituting equations (66) and (67) into equation (65) above, we get:
[0233] (68);
[0234] As can be seen from equation (68) above, the optimal control input signal of the control system is determined by the last term in equation (68). Therefore, the optimal control input signal is... Represented as:
[0235] (69);
[0236] Substituting (69) into equation (65) yields:
[0237] (70);
[0238] because For any positive semidefinite matrix Both are true, therefore we can deduce that:
[0239] (71);
[0240] in, Indicating the impact of FDI attacks The covariance of the posterior system state estimation error at time t;
[0241] Then according to The recursive expression (63) is derived as follows:
[0242] (72);
[0243] therefore, Represented as:
[0244] (73);
[0245] because Through iteration The recursive expression is derived as follows:
[0246] (74);
[0247] Therefore, the objective function for optimizing the LQG controller is expressed as:
[0248] (75);
[0249] The above derivation results show that when secret parameters are leaked, an attacker launching an FDI attack disguised as noise will interfere with the system's control performance. However, since a large-scale FDI attack will expose its own attack behavior while damaging the system's control performance, the security performance of the control system can still be guaranteed under the protection of the detection mechanism designed in this invention.
[0250] Step 9: When no replay attack or erroneous data injection attack is detected, the control system generates the optimal input control signal to control the cyber-physical system based on the recovered sensor measurement signals.
[0251] To verify the safety performance of this invention, MATLAB was used as the simulation test platform, and a classic four-cylinder water tank control system was used as the simulation object for testing. The state of the control system was the water level in the four-cylinder water tank, and the control signal input was the pressure in the water pump. In the experiment, the sampling interval of the sensor measurement signals was set to 1 second. Specifically, the parameters of the four-cylinder water tank system were quantified as follows:
[0252] (76);
[0253] (77);
[0254] (78);
[0255] The covariance matrices of process noise and measurement noise are respectively , The LQG controller parameters are:
[0256] (79);
[0257] The equilibrium point of a four-cylinder water tank system is:
[0258] (80);
[0259] Figure 3 The changes in sensor measurement signals before and after encoding are shown. It can be seen that the encoded measurement signal exhibits strong randomness. Because the watermark is dynamically and randomly selected from the set of watermark elements with equal probability, the actual sensor measurement signal is hidden under the protection of the encoding mechanism. In this case, it will be difficult for attackers to extract the watermark-encoded signal. The system's true information can be inferred from this, thus protecting the system's privacy.
[0260] The method designed in this invention can save the channel bandwidth occupied by the transmitted signal. Figure 4 This demonstrates the coding efficiency performance of this invention. It can be seen that, using the method designed in this invention, approximately 20% of the information in the encoded sensor measurement signal can be saved. Given the prefix-free nature of Huffman coding, the received codewords can be decoded immediately, which effectively reduces the decoding time. It is worth emphasizing that the coding efficiency will be further improved as the dimension of the sensor measurement signal increases.
[0261] To verify the effectiveness of the measurement output watermark encoding method in detecting replay attacks, a simulation was conducted where an attacker... The system constantly replays historical sensor measurement signals to deceive the chi-square detector. Figure 5 The results of the chi-square detector against replay attacks are demonstrated under the protection of the watermarking strategy designed in this invention. In the simulation, the detection window is set... It can be seen that, with the change in watermark parameters... As the value increases, the chi-square detection value will also increase. In this case, replay attacks will not be able to escape the chi-square detector. It should be noted that since the proposed scheme does not cause a decrease in system control performance, the watermark parameters... It can be large enough that replay attacks will be more easily detected by detectors.
Claims
1. A cyber-physical system security protection method based on measurement output watermark encoding, characterized in that, Includes the following steps: A cyber-physical system is configured with a Kalman filter and a control system, and an operational model of the cyber-physical system is constructed. The Kalman filter is used to perform unbiased estimation of the state of the control system based on the operational model of the cyber-physical system, so as to obtain the posterior state estimate of the control system at the current moment. The control system is used to obtain the optimal control input signal based on the posterior state estimate of the control system at the current moment, so as to realize the control of the cyber-physical system. Based on the operational model of cyber-physical systems, a chi-square detector is designed. The chi-square detector is used to detect whether the control system is subjected to replay attacks and erroneous data injection attacks. Construct a basic watermark element set and select watermark elements from the basic watermark element set to construct a watermark. Add the watermark to the sensor measurement signal to obtain a watermark fusion signal. Based on the permutation-transformation framework, the watermark fusion signal is encrypted to obtain the encrypted watermark fusion signal. The encrypted watermark fusion signal is subjected to secure Huffman coding to obtain the measured output watermark coded signal, which is sent to the control system along with the Huffman coding table used for secure Huffman coding. The watermark is removed from the measurement output watermark encoded signal according to the received Huffman coding table to obtain the recovered sensor measurement signal; The recovered sensor measurement signal is input into the chi-square detector to obtain the chi-square detection value, and the error data injection attack detection and replay attack detection are realized based on the chi-square detection value; When no replay attack or erroneous data injection attack is detected, the control system generates the optimal input control signal to control the cyber-physical system based on the recovered sensor measurement signals.
2. The cyber-physical system security protection method based on measurement output watermark encoding according to claim 1, characterized in that, The operational model of the cyber-physical system is as follows: (1); (2); in, Cyber-physical systems The state vector at time t, Cyber-physical systems The state vector at time t, and Both are integers, used to represent the dimension of the cyber-physical system's state vector and the cyber-physical system's runtime, respectively; It is a control input signal. It is an integer representing the dimension of the control input signal; yes Time-based process noise, yes A dimensional system matrix yes A dimensional control matrix; an initial state vector. and process noise They are set to be independent Gaussian random variables. and , Indicates a Gaussian distribution. It is the initial state vector The mean, and These represent the initial state vectors respectively. and process noise The covariance matrix of the Gaussian distribution it follows; It is a sensor measurement signal. It is an integer representing the dimension of the sensor-measured signal. It is a measurement matrix. It is related to the initial state vector and process noise Independent Gaussian measurement noise, It is the covariance matrix of the Gaussian distribution to which the Gaussian measurement noise follows.
3. The cyber-physical system security protection method based on measurement output watermark encoding according to claim 1, characterized in that, The chi-square detector is described as follows: (16); in, It is an integer representing the size of the detection window of the chi-square detector. This represents the chi-square test value. It is an integer variable representing time. for Sensor measurement signal at any time, for Prior state estimation for time-controlled systems It is the inverse covariance matrix of the detection residual under attack-free conditions.
4. The cyber-physical system security protection method based on measurement output watermark encoding according to claim 1, characterized in that, The basic watermark element set is represented as follows: This includes several watermark elements. It is a positive real number. It is a positive integer; The method of selecting watermark elements from the set of basic watermark elements to construct a watermark specifically involves randomly selecting several watermark elements with equal probability to construct a watermark. The watermark fusion signal is represented as follows: (18); in, Indicates the watermark fusion signal. It is a static template matrix. yes Constantly add sensor measurement signals The watermark in This indicates the first time the sensor measures the signal. The watermark component added by wei The dimension number of the sensor's measured signal.
5. A cyber-physical system security protection method based on measurement output watermark encoding according to claim 1, characterized in that, The watermark fusion signal The specific encryption method is as follows: (19); in, The signal after a binary XOR operation. It is a binary encoded sequence, symbol This represents the binary XOR operation. Represents binary conversion functions; Next, the signal after the binary XOR operation... Perform the following permutation operation: (20); Wherein, the permutation function Used in permutation sequence Under the influence of binary XOR operation, the signal is... Perform a permutation transformation. This is to encrypt the watermarked signal.
6. A cyber-physical system security protection method based on measurement output watermark encoding according to claim 1, characterized in that, The Huffman coding table is encrypted using a single-table substitution method before being sent to the control system.
7. A cyber-physical system security protection method based on measurement output watermark encoding according to claim 1, characterized in that, The process of performing secure Huffman coding on the encrypted watermark fusion signal to obtain the measured output watermark encoded signal is as follows: Fuse encrypted watermark signal Convert to real number signal And according to the Huffman coding table, the real number signal is processed. Perform secure Huffman coding, where The function represents the conversion of a binary number to a decimal number. The final measurement output watermark encoded signal is represented as: (21); in, This represents the secure Huffman coding function. This indicates the measurement output watermark encoding signal.
8. A cyber-physical system security protection method based on measurement output watermark encoding according to claim 1, characterized in that, The step of removing the watermark from the measurement output watermark encoded signal according to the received Huffman coding table to obtain the recovered sensor measurement signal specifically involves: S1: Decode the measured watermark code according to the Huffman coding table to obtain the encrypted watermark fusion signal. ; (22); in, This is the encrypted watermark fusion signal obtained after decoding. express inverse function, for The inverse function; S2: Perform an inverse permutation-transformation operation on the encrypted watermark fusion signal and obtain the signal after binary XOR operation. ; (23); in, To obtain the signal after binary XOR operation by performing the inverse permutation-transformation operation, express The inverse function; S3: The signal after the binary XOR operation The watermark was removed, and the recovered sensor measurement signal was obtained. ; (24); in, The sensor measurement signal obtained after removing the watermark. It is a static template matrix The inverse matrix, express The inverse function of .
9. A cyber-physical system security protection method based on measurement output watermark encoding according to claim 1, characterized in that, The methods for detecting replay attacks and data injection attacks specifically involve setting attack detection thresholds. Once the chi-square test value If the chi-square test value is positive, it is determined that the control system has been attacked, and an alarm is issued to the control system. If not, the alarm will not be triggered.
Citation Information
Patent Citations
Industrial control system dual-channel false data injection attack detection method
CN117081780A
Watermark Detection Method with Highly ImprovedAbility of Resistance to Sensitivity Attack and TheSystem
KR1020030077868A