Cloud embedded information physical system security protection method based on elastic homomorphic encryption

By adopting elastic homomorphic encryption technology in cloud-embedded cyber-physical systems, hierarchical keys and inserting security tags, the problems of FDI attack detection and computational complexity of existing systems are solved, efficient FDI attack identification and signal recovery are achieved, and the security and privacy protection of the system are improved.

CN120729638AActive Publication Date: 2025-09-30NORTHEASTERN UNIV CHINA +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511196718.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-09-30
Estimated Expiration
2045-08-26

AI Technical Summary

Technical Problem

Existing cloud-embedded cyber-physical systems have security vulnerabilities in FDI attack detection and are unable to accurately identify multiplicative and additive-multiplicative FDI attacks. In addition, existing encryption methods have high computational complexity and are not suitable for practical engineering applications.

Method used

A method based on elastic homomorphic encryption is adopted to divide the keys into two levels. The low-level keys are authorized to the cloud server, and the high-level keys are retained in the CPS. The system plaintext signal is encrypted using partial homomorphic encryption technology, and a security label is inserted into the ciphertext signal. A pseudo-random sequence is generated through a 1-D chaotic system for supervision. After the cloud server performs feedback control calculations, the CPS performs key leakage detection and attack type identification.

Benefits of technology

It can effectively detect various complex types of FDI attacks, restore the original control signal, improve system security and privacy protection, reduce computational complexity, and is suitable for practical engineering applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729638A_ABST
    Figure CN120729638A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud embedded information physical system security protection method based on elastic homomorphic encryption, relates to the technical field of information physics, and divides an encryption key into two security levels based on partial homomorphic SWHE encryption technology standard design. Wherein the secret key of the second level is authorized to the cloud, and the secret key of the first level is only disclosed for the CPS, so that on the premise of ensuring the privacy of the cloud embedded CPS, the method designed by the invention not only can effectively detect whether the cloud embedded CPS is suffered from the FDI attack, but also can elastically recover the original system plaintext signal from the polluted system data aiming at the complex type of FDI attack, and can effectively detect whether the cloud embedded CPS is suffered from the original system plaintext signal. According to the method, the influence of the FDI attack on a system control signal is eliminated, the defects and deficiencies of an existing method in the aspects of privacy protection, FDI attack detection and elastic recovery of the cloud embedded information physical system are effectively overcome, and meanwhile, the designed security tag can monitor the key leakage risk in real time so as to effectively improve the security performance of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information-physical technology, and in particular to a cloud-embedded information-physical system security protection method based on elastic homomorphic encryption. Background Art

[0002] With the development of information technology, cyber-physical systems (CPS), which integrate sensing, computing, and communication, meet the requirements of today's era for intelligent control systems and satisfy people's needs for real-time monitoring, transmission, and processing of system information. As a result, they have been widely used in the fields of industry, energy, transportation, medical care, smart transportation, and military. Figure 1 .

[0003] In traditional CPS system architectures, all control information calculations are performed by the CPS feedback controller, placing all computational pressure on the CPS. Furthermore, if the feedback controller and its calculated feedback control signals are eavesdropped on by an attacker, the privacy and security of the control system will face significant risks and challenges.

[0004] The development of cloud computing technology has revolutionized data processing and further integrated the physical and network layers. To alleviate the computational burden of CPSs and improve the privacy protection of feedback controllers, the current solution is to encrypt feedback controller parameters and control signals and outsource feedback control computations to cloud servers. This solution framework, known as a cloud-embedded cyber-physical system, leverages the powerful storage and computing resources of cloud servers to effectively alleviate the computational burden on CPSs and prevent the leakage of feedback control information.

[0005] However, with the increasing frequency of system information interaction, cloud-embedded cyber-physical systems are facing increasing security risks. False data injection (FDI) attacks, a typical attack strategy, can manipulate the transmission signals between cloud servers and cyber-physical systems, misleading and driving control systems out of their normal operating state, thereby causing energy loss and damage to system hardware. To improve the security of control systems, the current protection strategy is to design FDI attack detectors in conjunction with data encryption mechanisms to identify attackers' tampering with control signals.

[0006] Because the cloud is generally considered insecure, and to prevent feedback control information from being leaked to attackers, data sent to the cloud for processing must be encrypted beforehand and then returned to the CPS for decryption. However, the computational complexity of currently used encryption methods based on public-key cryptography schemes such as RSA and Paillier exceeds the capacity of existing cyber-physical systems, making them unsuitable for practical engineering applications.

[0007] More importantly, current cloud-embedded cyber-physical system security protection methods have security vulnerabilities when it comes to detecting FDI attacks. While existing solutions can detect additive FDI attacks, they cannot accurately identify multiplicative and additive-multiplicative FDI attacks. Furthermore, current methods can only detect attacks but cannot eliminate the interference caused by FDI attacks on control signals. Consequently, the robustness of cyber-physical systems is severely weakened. Summary of the Invention

[0008] In view of the shortcomings of the existing technology, the purpose of the present invention is to propose a cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption, including: Step 1: Build a model of the cyber-physical system (CPS) and generate the original signal based on the model of the cyber-physical system (CPS) and , the original signal of the cyber-physical system CPS and Perform integer mapping to obtain the system plaintext signal after integer mapping and ; Step 2: Set secret parameters , , , , ,Will , , As the first level key, , As the second-level key; authorize the first-level key and the second-level key to the CPS, and authorize the second-level key to the cloud server; in, Expressed as: ,in, are all positive integers, To represent the dynamic template matrix, is a dynamic template vector, where and are all positive integers, and Used to mask the characteristics of the system's plaintext signal, and and Produced by a strong pseudo-random number generator iteratively with a random seed, is a positive integer, is a prime number greater than a preset threshold, is the static template matrix, is a static template vector, is a prime number greater than a preset threshold; Step 3: In CPS, based on partially homomorphic encryption SWHE technology, a homomorphic encryption algorithm is designed to encrypt the system plaintext signal based on secret parameters. and Encrypt and obtain the system ciphertext signal and ;CPS generates security labels , the security label Used for the first level key in homomorphic encryption and Monitor the leakage of Insert system ciphertext signal In the system, we get the coded signal with label , the tagged system ciphertext signal and system ciphertext signal Upload to the cloud server; Step 4: The cloud server receives the system ciphertext signal and the tagged system ciphertext signal , according to the coded signal of the system with label , get the security label and system ciphertext signal ; According to the system ciphertext signal and , the cloud server performs feedback control calculation and obtains the ciphertext feedback control signal ; Set the safety label Add pseudo-random noise , obtain the tagged ciphertext feedback control signal, and send the tagged ciphertext feedback control signal to the CPS; Step 5: Determine the key based on the ciphertext feedback control signal received by the CPS and Whether there is leakage; Step 6: CPS receives the tagged ciphertext feedback control signal, and determines whether to upload the tagged system ciphertext signal to the cloud server based on the received tagged ciphertext feedback control signal, the first level key and the second level key. and Whether the cloud server is attacked during the process of sending the coded feedback control signal with labels to the CPS, and whether the cloud server is attacked during the process of sending the coded feedback control signal with labels to the CPS, and In the process of sending the tagged ciphertext feedback control signal to the CPS, if the cloud server is attacked, execute step 7, and when the CPS uploads the tagged system ciphertext signal to the cloud server, and In the process of sending the coded feedback control signal with the tag to the CPS, if the cloud server is not attacked, execute step 8; Step 7: Determine whether the CPS uploads the labeled system ciphertext signal to the cloud server and The types of attacks in the process of sending coded feedback control signals with labels from the cloud server to the CPS; Step 8: Decrypt the ciphertext feedback control signal to obtain the system ciphertext signal and .

[0009] Optionally, step 1 specifically includes: Step 1.1: Construct a model of the cyber-physical system (CPS). The operation of the cyber-physical system model is represented by the state equation, which is specifically expressed by the following formula: (1); in, Represents the cyber-physical system CPS k The state variables of the iteration, Represents the cyber-physical system CPS k+ State variables for 1 iteration, represents the sensor measurement signal of the cyber-physical system CPS, represents the control input signal of the cyber-physical system CPS, represents the noise vector applied to the cyber-physical system CPS, , , , , and is a real number matrix of different dimensions, which is used as the parameter of the cyber-physical system CPS to characterize the characteristics of the cyber-physical system CPS. represents the set of real numbers, are positive integers representing the dimensions of the matrix; The control signal in formula (1) The feedback control signal is calculated by the feedback controller. The calculation is represented by the following iterative equation: (2); in, Indicates the k The state variables of the feedback controller for the iteration, Indicates the k +1 iteration of the feedback controller's state variables, , , and is a real number matrix, which is used as the parameter of the feedback controller to characterize the characteristics of the feedback controller. is an integer representing the dimension of the state variable of the feedback controller; Rewrite formula (2) into matrix-vector product form, expressed as: (3); in, is the parameter matrix of the feedback controller, is a vector consisting of the state variables of the feedback controller and the sensor measurement signal. and As the original signal of the cyber-physical system CPS; among them, and are all positive integers, is a matrix Dimensions, is a vector Dimensions, , ; Step 1.2: Raw signals of cyber-physical systems (CPS) and Perform integer mapping, specifically expressed as: (4); (5); in, represents the quantization accuracy, and It is the system plaintext signal after integer mapping. Represents the ceiling function.

[0010] Optionally, step 3 specifically includes: Step 3.1: In CPS, based on partially homomorphic encryption SWHE technology, design a homomorphic encryption algorithm, based on secret parameters, to encrypt the system plaintext signal and Encryption is implemented using the following formula: (6); (7) ; Among them, the symbol Represents the multiplication operation between matrices or vectors within the element range, matrix Indicates system plaintext signal The system ciphertext signal, vector A system ciphertext signal representing a system plaintext signal; Step 3.2: CPS generates security labels , the security label Expressed as: (8); in, , and is a secret parameter, and are all prime numbers greater than the preset threshold, is a matrix Middle Any element in the row, and is a positive integer, and are natural numbers, represents the set of natural numbers, is a serial number used to identify the safety label, and d is an integer; Step 3.3: Insert the security tag into the system ciphertext signal through synchronization mode I Specifically, it includes: Based on the 1-D chaotic system, a pseudo-random sequence is obtained after multiple iterations according to the preset number of iterations. The 1-D chaotic system is expressed as: (9); in, and is the control parameter of the 1-D chaotic system, Indicates that the chaotic system t The pseudo-random number generated by the iteration, Indicates that the chaotic system t +1 pseudo-random number generated by iteration, and The values ​​of are all less than 1. is an integer that indicates the number of iterations of the chaotic system; The pseudo-random sequence and Multiply and round to get the insertion position information, and insert the security tag into the system ciphertext signal according to the insertion position information. In the system, we get the coded signal with label , Is an integer, indicating the total A security tag is inserted into the system ciphertext signal In the system, the coded signal with label and system ciphertext signal Upload to the cloud server.

[0011] Optionally, step 4 includes: Step 4.1: Cloud server receives system ciphertext signal and the tagged system ciphertext signal , in synchronization mode I from the tagged system ciphertext signal Specifically, the security tag is inserted into the system ciphertext signal using synchronization mode I. The same process is used for the 1-D chaotic system. Based on the 1-D chaotic system, a pseudo-random sequence is obtained, and then the insertion position information is obtained. According to the insertion position information, the insertion position is extracted to obtain a security tag. , and then get the system ciphertext signal ; Step 4.2: According to the system ciphertext signal and , the cloud server performs feedback control calculations, which are specifically expressed by the following formula: (10); in, Feedback control signal for ciphertext; Step 4.3: Add Security Label Pseudo-random noise is added , , specifically expressed by the following formula: (11); in, , is a security tag obtained after noise processing, the pseudo-random noise is known to the CPS; the security tag obtained after noise processing The feedback control signal is randomly inserted into the ciphertext in synchronization mode II , the coded feedback control signal with label is obtained, where the formula of synchronization mode II is the same as that of synchronization mode I, but the specific values ​​of the control parameters of the 1-D chaotic system are different. The coded feedback control signal with label is sent to the CPS.

[0012] Optionally, step 5 includes: Step 5.1: Receive the coded feedback control signal with tags sent by the cloud server at the CPS end, extract the coded feedback control signal with tags in synchronization mode II, and obtain the security tag , for security labels Perform security tag authentication operations, specifically expressed by the following formula: (12); in, Pseudo-random noise added to the cloud server can be removed by CPS. , is the result obtained after the security tag authentication operation, where The calculation formula of the operator is expressed as: (13); Among them, the parameters represents a vector consisting of binary numbers, represents any integer vector, is a positive integer; Step 5.2: Assuming the key and Leaked, and the attacker uploads the labeled system ciphertext signal to the cloud server in CPS In the process of injecting any attack signal , and in the process of the cloud server sending the labeled ciphertext feedback control signal to the CPS, an attack signal is injected In this case, the security label received by CPS is expressed as: (14); in, is a positive integer; Solving formula (14) and formula (12) together, we can obtain The specific value of = When CPS uploads the labeled system ciphertext signal to the cloud server In the process of sending the ciphertext feedback control signal with label to CPS, there is no FDI attack; when = + When CPS uploads the tagged system ciphertext signal to the cloud server In the process of sending the coded feedback control signal with label to CPS, the cloud server is attacked by FDI, and then executes step 5.3; Step 5.3: Substitute into the verification equation, where the verification equation is expressed as: (15); Determine whether the left and right sides of the verification equation are equal. If the left and right sides of the verification equation are equal, it indicates that the CPS will determine the key and has been leaked to the attacker, that is, the assumption in step 5.2 is established. When the left and right sides of the verification equation are not equal, CPS will determine that the key and It is not leaked to the attacker, which means the assumption in step 5.2 does not hold.

[0013] Optionally, step 6 includes: CPS receives the tagged ciphertext feedback control signal, extracts the security tag from the tagged ciphertext feedback control signal, and obtains the ciphertext feedback signal with the tag removed. , and then judge and Are they equal? and If they are equal, it indicates that CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the ciphertext feedback control signal with label to CPS, the cloud server was not attacked. and If they are not equal, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and The attack occurs during the process of the cloud server sending the ciphertext feedback control signal with labels to the CPS.

[0014] Optionally, step 7 specifically includes: Step 7.1: The cloud server calculates the FDI multiplicative attack factor using the second-level key and , specifically calculated by the following formula: (16); (17); in, and Indicates the system ciphertext signal uploaded by CPS to the cloud server that has been attacked; The calculated multiplicative attack factor and When it is equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the coded feedback control signal with label to the CPS, if the attack type is not a multiplicative FDI attack, proceed to step 7.2. The calculated multiplicative attack factor and When it is not equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the coded feedback control signal with labels to the CPS, the attack type is multiplicative FDI attack. Then the cloud server filters out the multiplicative attack, which is achieved by the following formula: (18); (19); The cloud server filters out the multiplicative attack factors in the received ciphertext feedback control signal and , filtering out the multiplicative attack factors in the received ciphertext feedback control signal on the cloud server and The subsequent signal is expressed as: (20); From formula (20), we can see that filtering out multiplicative attacks and The subsequent signal also contains a multiplicative attack factor , calculate the multiplicative attack factor The value of is realized by the following formula: (twenty one); Multiplicative Attack Factor Filter out multiplicative attacks and Remove the signal after filtering the multiplicative attack, and obtain the ciphertext feedback control signal after filtering the multiplicative attack. Substitute the ciphertext feedback control signal after filtering the multiplicative attack into the formula (22) In the original system plaintext signal and , formula (22) is expressed as: (twenty two); Step 7.2: CPS calculates the multiplicative attack factor in the additive-multiplicative FDI attack using the following formula: (twenty three); The calculated multiplicative attack factor When it is equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the labeled ciphertext feedback control signal from the cloud server to the CPS, if the attack type is not an additive-multiplicative FDI attack, proceed to step 7.3; The calculated multiplicative attack factor When it is not equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the coded feedback control signal with label from the cloud server to the CPS, the attack type is additive-multiplicative FDI attack, which factors the multiplicative attack into Remove the ciphertext feedback control signal received from the CPS to obtain the purified ciphertext feedback control signal , and then the purified ciphertext is fed back to the control signal Substitute into formula (24), remove the signal injected by the additive FDI attack, and obtain the original system plaintext signal and , formula (24) is expressed as: (twenty four); Step 7.3: Upload the labeled system ciphertext signal to the cloud server in CPS and In the process of sending the coded feedback control signal with label from the cloud server to the CPS, if the attack type is neither additive-multiplicative FDI attack nor multiplicative FDI attack, the attack type is characterized as additive FDI attack. Then, the coded feedback control signal received by the CPS is substituted into the formula (22): In the original system plaintext signal and .

[0015] Optionally, step 8 is specifically implemented by the following formula: (25); Based on formula (25), the system ciphertext signal is calculated as and .

[0016] The beneficial effects of adopting the above technical solution are: This invention, based on the somewhat homomorphic encryption (SWHE) encryption technology standard, divides encryption keys into two security levels. The lower-level (second-level) keys are authorized to the cloud, while the higher-level (first-level) keys are disclosed only to the CPS. Compared with existing cloud-embedded cyber-physical system security protection methods, the proposed method not only effectively detects FDI attacks while ensuring the privacy of cloud-embedded cyber-physical systems, but also resiliently recovers the original system plaintext signal from contaminated system data against complex FDI attacks (additive, multiplicative, and additive-multiplicative), eliminating the impact of FDI attacks on system control signals. This effectively addresses the drawbacks and shortcomings of existing methods in privacy protection, FDI attack detection, and resilient recovery for cloud-embedded cyber-physical systems. The proposed method offers excellent detection performance, high-quality reconstructed signals, and sufficient protection of the CPS's privacy. The proposed method boasts high accuracy, fast computation speed, and low latency, ensuring the secure, real-time, and stable operation of cloud-embedded cyber-physical systems.

[0017] The method proposed in this paper has low computational complexity, offering significant advantages over homomorphic encryption algorithms such as RSA and Paillier, and is suitable for practical engineering applications. Furthermore, the security tag designed in this paper can monitor the risk of key leakage in real time, effectively improving system security. Under the framework of the proposed security protection method, the security performance of cloud-embedded cyber-physical systems will be significantly improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 A conceptual diagram of a cloud-embedded cyber-physical system in an embodiment of the present invention; Figure 2 Schematic diagram of the process of a cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption in an embodiment of the present invention; Figure 3 This is a flowchart of the security tag operation in an embodiment of the present invention; Figure 4 Schematic diagrams of various types of FDI attack detection results in embodiments of the present invention, wherein (a) is a schematic diagram of additive FDI attack detection results, (b) is a schematic diagram of multiplicative FDI attack detection results, (c) is a schematic diagram of additive-multiplicative FDI attack detection results, and (d) is a schematic diagram of large-scale additive FDI attack detection results; Figure 5Schematic diagram of the removal performance of various types of existing FDI attacks in an embodiment of the present invention, wherein (a) is a schematic diagram of the elastic recovery error under additive FDI attack, (b) is a schematic diagram of the elastic recovery error under multiplicative FDI attack, and (c) is a schematic diagram of the elastic recovery error under additive-multiplicative FDI attack; Figure 6 Schematic diagram of the security tag's assessment of key leakage risk in an embodiment of the present invention. DETAILED DESCRIPTION

[0019] The following embodiments of the present invention are described in further detail with reference to the accompanying drawings and examples. The following examples are used to illustrate the present invention but are not intended to limit the scope of the present invention.

[0020] To address the challenges of existing technologies, this paper designs a security protection method for cloud-enabled cyber-physical systems (CECPS) based on elastic homomorphic encryption (EHE) technology, specifically tailored to the security requirements of these systems. This method addresses existing challenges in computational complexity, FDI attack detection, and resilience. The proposed method boasts low computational complexity, making it suitable for practical engineering applications. It can effectively detect various complex FDI attacks and recover and reconstruct the original control signal from the attack signal.

[0021] Specifically, the present invention provides a cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption. Aiming at the characteristics of cloud-embedded cyber-physical systems, the present invention uses homomorphic encryption technology to achieve the goals of controller privacy protection, FDI attack detection and control signal reconstruction. Figure 2 , which may include the following steps: Step 1: Build a model of the cyber-physical system (CPS) and generate the original signal based on the model of the cyber-physical system (CPS) and , the original signal of the cyber-physical system CPS and Perform integer mapping to obtain the system plaintext signal after integer mapping and ; Step 1.1: Build a CPS model. A CPS uses deployed sensors to monitor and estimate the system state in real time. The operation of the CPS model is represented by a state equation, specifically the following formula: (1); in, Represents the cyber-physical system CPSk The state variables of the iteration, Represents the cyber-physical system CPS k+ State variables for 1 iteration, represents the sensor measurement signal of the cyber-physical system CPS, represents the control input signal of the cyber-physical system CPS, represents the noise vector applied to the cyber-physical system CPS, , , , , and is a real number matrix of different dimensions, which is used as the parameter of the cyber-physical system CPS to characterize the characteristics of the cyber-physical system CPS. represents the set of real numbers, are positive integers representing the dimensions of the matrix; The control signal in formula (1) The feedback control signal is calculated by the feedback controller. The calculation is represented by the following iterative equation: (2); in, Indicates the k The state variables of the feedback controller for the iteration, Indicates the k +1 iteration of the feedback controller's state variables, , , and is a real number matrix, which is used as the parameter of the feedback controller to characterize the characteristics of the feedback controller. is an integer representing the dimension of the state variable of the feedback controller; Rewrite formula (2) into matrix-vector product form, expressed as: (3); in, is the parameter matrix of the feedback controller, is a vector consisting of the state variables of the feedback controller and the sensor measurement signal. and As the original signal of the cyber-physical system CPS; among them, and are all positive integers, is the dimension of matrix F, is a vector Dimensions, , ; Since the system's raw signals need to be transmitted over an open network, to prevent leakage of control system information, they must be encrypted before being transmitted to a cloud server over the network to complete the calculation of the feedback control signal. However, since non-homomorphic encryption algorithms cannot guarantee decryption correctness, it is necessary to design an encryption algorithm that meets homomorphic properties. Compared to fully homomorphic encryption (FHE), partially homomorphic encryption (SWHE) offers a balance between cryptographic security and computational efficiency, making it more suitable for practical engineering applications. To design a SWHE algorithm that meets these goals, the system's raw signals must first be mapped into integer signals. See step 1.2 for details.

[0022] Step 1.2: Raw signals of cyber-physical systems (CPS) and Perform integer mapping to directly map the original signal of the system to an integer signal. The mapping range space includes positive integer space and negative integer space. Specifically, let Indicates the quantization accuracy, which needs to meet the control system's requirements for quantization error. Based on this, the original signal of the cyber-physical system CPS and The specific expression for integer mapping is: (4); (5); in, represents the quantization accuracy, and It is the system plaintext signal after integer mapping. Represents the ceiling function. When the integer mapping is completed, and The requirements of partially homomorphic encryption algorithms will be met.

[0023] Since the cloud is generally considered to be insecure, the system control signal cannot be directly disclosed to the cloud server. Therefore, in the present invention, all keys are divided into two levels, see step 2 for details.

[0024] Step 2: Set secret parameters , , , , ,Will , , As the first level key, , As the second-level key; authorize the first-level key and the second-level key to the CPS, and authorize the second-level key to the cloud server; in, Expressed as: ,in, are all positive integers, To represent the dynamic template matrix, is a dynamic template vector, where and are all positive integers, and Used to mask the characteristics of the system's plaintext signal, and and Produced by a strong pseudo-random number generator iteratively with a random seed, is a positive integer, is a prime number greater than a preset threshold, which can be 2 to the power of 30. is the static template matrix, is a static template vector, is a prime number greater than a preset threshold; Since the first-level key is unknown, the cloud server cannot correctly decrypt the system plaintext signal even if it has the second-level key. In this case, the system information of the CPS is always confidential to the cloud server, and the privacy of the control system can be protected. Based on the above two-level key distribution authorization, the system plaintext signal and Will be encrypted by the cyber-physical system (CPS), which will be accomplished by step 3 below.

[0025] Step 3: In CPS, based on partially homomorphic encryption SWHE technology, a homomorphic encryption algorithm is designed to encrypt the system plaintext signal based on secret parameters. and Encrypt and obtain the system ciphertext signal and ;CPS generates security labels , the security label Used for the first level key in homomorphic encryption and Monitor the leakage of Insert system ciphertext signal In the system, we get the coded signal with label , the tagged system ciphertext signal and system ciphertext signal Upload to the cloud server; Step 3.1: In CPS, based on partially homomorphic encryption SWHE technology, design a homomorphic encryption algorithm, based on secret parameters, to encrypt the system plaintext signal and Encryption is implemented using the following formula: (6); (7) ; Among them, the symbol Represents the multiplication operation between matrices or vectors within the element range, matrix Indicates system plaintext signal The system ciphertext signal, vector A system ciphertext signal representing a system plaintext signal; When the homomorphic encryption operation is completed, due to It does not need to be transmitted frequently, so the risk of attack is lower and it can be sent directly to the cloud. The security tags will be inserted and then sent to the cloud for further feedback control calculation.

[0026] Step 3.2: Combine Figure 3 , CPS generates security labels , security labels are used to identify the first-level keys in homomorphic encryption and Once the key and If is leaked to the attacker, the FDI attack carried out by the attacker using the leaked key will be detected by CPS. Without loss of generality, let , is a positive integer (defined above), whereby the security label Expressed as: (8); in, , and is a secret parameter, and are all prime numbers greater than a preset threshold, which can be 2 to the power of 30. is a matrix Middle Any element in the row, and is a positive integer, and are natural numbers, represents the set of natural numbers, is a serial number used to identify the safety label, and d is an integer; Step 3.3: Insert the security tag into the system ciphertext signal through synchronization mode I In the process, when the system plaintext signal is encrypted into the system ciphertext signal and the security tag is generated by CPS, the cyber-physical system (CPS) will send the system ciphertext signal to the system in synchronization mode I. The security tags are randomly inserted into the ciphertext signal. Note that the meaning of the synchronization mode means that the security tags are inserted into the ciphertext signal The position in is controllable, which can be achieved by controlling a chaotic system.

[0027] Specifically, based on the 1-D chaotic system, according to the preset number of iterations, a pseudo-random sequence is obtained after multiple iterations, wherein the 1-D chaotic system is expressed as: (9); in, and is the control parameter of the 1-D chaotic system, Indicates that the chaotic system t The pseudo-random number generated by the iteration, Indicates that the chaotic system t +1 pseudo-random number generated by iteration, and The values ​​of are all less than 1. is an integer that indicates the number of iterations of the chaotic system; In the specific implementation, the initial values ​​of the chaotic system control parameters are set to meet the and Under the condition of , the control system will enter a chaotic state through iteration and generate a pseudo-random sequence.

[0028] The pseudo-random sequence and Multiply and round to get the insertion position information, and insert the security tag into the system ciphertext signal according to the insertion position information. In the system, we get the coded signal with label , Is an integer, indicating the total A security tag is inserted into the system ciphertext signal In the system, the coded signal with label and system ciphertext signal Upload to the cloud server.

[0029] Step 4: The cloud server receives the system ciphertext signal and the tagged system ciphertext signal , according to the coded signal of the system with label , get the security label and system ciphertext signal ; According to the system ciphertext signal and , the cloud server performs feedback control calculation and obtains the ciphertext feedback control signal ; Set the safety label Add pseudo-random noise , obtain the tagged ciphertext feedback control signal, and send the tagged ciphertext feedback control signal to the CPS; Step 4.1: Cloud server receives system ciphertext signal and the tagged system ciphertext signal , in synchronization mode I from the tagged system ciphertext signal Specifically, the security tag is inserted into the system ciphertext signal using synchronization mode I. The same process is used for the 1-D chaotic system. Based on the 1-D chaotic system, a pseudo-random sequence is obtained, and then the insertion position information is obtained. According to the insertion position information, the insertion position is extracted to obtain a security tag. , and then get the system ciphertext signal ; It should be noted that the safety label The security tags extracted by the cloud may be tampered by attackers during the transmission process from CPS to the cloud. If the security tag is not attacked by FDI, then .

[0030] Step 4.2: According to the system ciphertext signal and , the cloud server performs feedback control calculations, which are specifically expressed by the following formula: (10); in, Feedback control signal for ciphertext; Step 4.3: Add Security Label Pseudo-random noise is added , , to cover the feedback control calculation processing behavior, specifically expressed by the following formula: (11); in, , is a security tag obtained after noise processing, the pseudo-random noise is known to the CPS; the security tag obtained after noise processing The feedback control signal is randomly inserted into the ciphertext in synchronization mode II , the ciphertext feedback control signal with the tag is obtained. Among them, the formula of synchronization mode II is the same as that of synchronization mode I, but the specific values ​​of the control parameters of the 1-D chaotic system are different. Similarly, referring to synchronization mode I, a pseudo-random sequence is generated through the chaotic system, and then the insertion position information is determined. According to the insertion position information, the security tag is inserted. Inserted into the ciphertext feedback control signal In the process, the tagged ciphertext feedback control signal is obtained and the tagged ciphertext feedback control signal is sent to the CPS.

[0031] Among them, the pseudo-random noise is known to the cyber-physical system (CPS) and can therefore be eliminated at the CPS end.

[0032] Step 5: Determine the key based on the ciphertext feedback control signal received by the CPS and Whether there is leakage; Step 5.1: Receive the coded feedback control signal with tags sent by the cloud server at the CPS end, extract the coded feedback control signal with tags in synchronization mode II, and obtain the security tag , for security labels Perform security tag authentication operations, specifically expressed by the following formula: (12); in, The pseudo-random noise added to the cloud server can be removed by CPS. The pseudo-random noise can be removed by CPS. , is the result obtained after the security tag authentication operation, where The calculation formula of the operator is expressed as: (13); Among them, the parameters represents a vector consisting of binary numbers, represents any integer vector, is a positive integer; Step 5.2: Assuming the key and Leaked, and the attacker uploads the labeled system ciphertext signal to the cloud server in CPS In the process of injecting any attack signal , and in the process of the cloud server sending the labeled ciphertext feedback control signal to the CPS, an attack signal is injected In the case of , the above-mentioned form of FDI attack injection will be able to evade the attack detector in the absence of a security tag. However, when the security tag is inserted, once it is attacked by FDI, the security tag received by the cyber-physical system (CPS) will be tampered with. At this time, the security tag received by the CPS is expressed as: (14); in, is a positive integer; Solving formula (14) and formula (12) together, we can obtain The specific value of = When CPS uploads the labeled system ciphertext signal to the cloud server In the process of sending the ciphertext feedback control signal with label to CPS, there is no FDI attack; when = + When CPS uploads the tagged system ciphertext signal to the cloud server In the process of sending the coded feedback control signal with label to CPS, the cloud server is attacked by FDI, and then executes step 5.3; Step 5.3: Substitute into the verification equation, where the verification equation is expressed as: (15); Determine whether the left and right sides of the verification equation are equal. If the left and right sides of the verification equation are equal, it indicates that the CPS will determine the key and has been leaked to the attacker, that is, the assumption in step 5.2 is established. When the left and right sides of the verification equation are not equal, CPS will determine that the key and It is not leaked to the attacker, which means the assumption in step 5.2 does not hold.

[0033] Step 6: CPS receives the tagged ciphertext feedback control signal, and determines whether to upload the tagged system ciphertext signal to the cloud server based on the received tagged ciphertext feedback control signal, the first level key and the second level key. and Whether the cloud server is attacked during the process of sending the coded feedback control signal with labels to the CPS, and whether the cloud server is attacked during the process of sending the coded feedback control signal with labels to the CPS, and In the process of sending the tagged ciphertext feedback control signal to the CPS, if the cloud server is attacked, execute step 7, and when the CPS uploads the tagged system ciphertext signal to the cloud server, and In the process of sending the coded feedback control signal with the tag to the CPS, if the cloud server is not attacked, execute step 8; Specifically, CPS receives the tagged ciphertext feedback control signal, extracts the security tag from the tagged ciphertext feedback control signal, and obtains the ciphertext feedback signal with the tag removed. , and then judge and Are they equal? and If they are equal, it indicates that CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the ciphertext feedback control signal with label to CPS, the cloud server was not attacked. and If they are not equal, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and The attack occurs during the process of the cloud server sending the ciphertext feedback control signal with labels to the CPS.

[0034] It should be noted that in step 6, the CPS is determined to upload the labeled system ciphertext signal to the cloud server. and In the process of sending the labeled ciphertext feedback control signal to the CPS, and whether the cloud server is attacked, in the theoretical design stage, the present invention conducts theoretical analysis on three different attacks: additive FDI attack, multiplicative FDI attack and additive-multiplicative FDI attack. However, in the actual implementation process, it is impossible to judge the type of attack received when receiving the labeled ciphertext feedback control signal. Therefore, these three attacks are only used for theoretical analysis. The specific implementation process still executes step 6. The theoretical analysis is to design Table 1, a list of FDI attack detection and elastic recovery conditions for the cloud embedded homomorphic encryption scheme.

[0035] Table 1 List of FDI attack detection and resilience recovery conditions for cloud-embedded homomorphic encryption scheme;

[0036] Based on Table 1, the theoretical analysis of the present invention includes: 1. Detection of additive FDI attacks, assuming that CPS uploads a labeled system ciphertext signal to the cloud server The process of sending the coded feedback control signal with labels to the CPS is attacked by additive FDI, and the CPS uploads the coded system signal with labels to the cloud server. The attack injection signal received during the process is , the attack injection signal received by the cloud server during the process of sending the labeled ciphertext feedback control signal to the CPS is , then the tampered ciphertext feedback control signal will be expressed as: (26); When the additive FDI attack detection condition I given in Table 1 is met, CPS will obtain the following calculation results: (27); in, Therefore, when When, due to is known (as the key), the additive FDI attack will be identified by the attack detector.

[0037] 2. Detection of Multiplicative FDI Attacks. Assume that CPS uploads a labeled system ciphertext signal to the cloud server. The process of the cloud server sending the labeled ciphertext feedback control signal to the CPS is subject to multiplicative FDI attack, and the CPS uploads the labeled system ciphertext signal to the cloud server. The attack injection signal received during the process is , the attack injection signal received by the cloud server during the process of sending the labeled ciphertext feedback control signal to the CPS is ,in, express The set of positive integers of dimension, express dimensional positive integer set, then the tampered ciphertext feedback control can be expressed as: (28); When the multiplicative FDI attack detection condition II in Table 1 is met, CPS verifies the following formula: (29); in, = Therefore, when When , the multiplicative FDI attack is identified by the attack detector.

[0038] 3. Detection of additive-multiplicative FDI attacks. Assume that CPS uploads a labeled system ciphertext signal to the cloud server. The process is attacked by additive FDI, and the attack injection signal is , assuming that the cloud server is attacked by additive FDI and multiplicative FDI in the process of sending the labeled ciphertext feedback control signal to the CPS, the additive attack injection signal is , the multiplicative attack injection signal is , then the tampered ciphertext feedback control signal is: (30); When the additive-multiplicative FDI attack detection conditions in Table 1 are met, CPS verifies the following formula: (31); when When , the additive-multiplicative FDI attack is identified by the attack detector.

[0039] Step 7: Determine whether the CPS uploads the labeled system ciphertext signal to the cloud server and The types of attacks in the process of sending coded feedback control signals with labels from the cloud server to the CPS; Step 7.1: The cloud server calculates the FDI multiplicative attack factor using the second-level key and , specifically calculated by the following formula: (16); (17); in, and Indicates the system ciphertext signal uploaded by CPS to the cloud server that has been attacked; The calculated multiplicative attack factor and When it is equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the coded feedback control signal with label to the CPS, if the attack type is not a multiplicative FDI attack, proceed to step 7.2. The calculated multiplicative attack factor and When it is not equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the coded feedback control signal with labels to the CPS, the attack type is multiplicative FDI attack. Then the cloud server filters out the multiplicative attack, which is achieved by the following formula: (18); (19); The cloud server filters out the multiplicative attack factors in the received ciphertext feedback control signal and , filtering out the multiplicative attack factors in the received ciphertext feedback control signal on the cloud server and The subsequent signal is expressed as: (20); From formula (20), we can see that filtering out multiplicative attacks and The subsequent signal also contains a multiplicative attack factor , calculate the multiplicative attack factor The value of is realized by the following formula: (twenty one); Multiplicative Attack Factor Filter out multiplicative attacks and Remove the signal after filtering the multiplicative attack, and obtain the ciphertext feedback control signal after filtering the multiplicative attack. Substitute the ciphertext feedback control signal after filtering the multiplicative attack into the formula (22) In the original system plaintext signal and , formula (22) is expressed as: (twenty two); Step 7.2: CPS calculates the multiplicative attack factor in the additive-multiplicative FDI attack using the following formula: (twenty three); The calculated multiplicative attack factor When it is equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the labeled ciphertext feedback control signal from the cloud server to the CPS, if the attack type is not an additive-multiplicative FDI attack, proceed to step 7.3; The calculated multiplicative attack factor When it is not equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the coded feedback control signal with label from the cloud server to the CPS, the attack type is additive-multiplicative FDI attack, which factors the multiplicative attack into Remove the ciphertext feedback control signal received from the CPS to obtain the purified ciphertext feedback control signal , and then the purified ciphertext is fed back to the control signal Substitute into formula (24), remove the signal injected by the additive FDI attack, and obtain the original system plaintext signal and , formula (24) is expressed as: (twenty four); It should be noted that, in the theoretical design part, the present invention needs to determine whether the additive-multiplicative elasticity condition in Table 1 holds before step 7.2, and execute step 7.2 if it holds. However, in the specific implementation process, it is impossible to determine whether the additive-multiplicative elasticity condition holds, so no determination is made during the specific implementation.

[0040] Step 7.3: Upload the labeled system ciphertext signal to the cloud server in CPS and In the process of sending the coded feedback control signal with label from the cloud server to the CPS, if the attack type is neither additive-multiplicative FDI attack nor multiplicative FDI attack, the attack type is characterized as additive FDI attack. Then, the coded feedback control signal received by the CPS is substituted into the formula (22): In the original system plaintext signal and .

[0041] It should be noted that in the theoretical design process, step 7.3 needs to determine whether the additive elasticity condition in Table 1 is established. However, since it is impossible to determine whether it is established during the specific implementation process, the present invention does not perform this determination during the specific implementation process.

[0042] Step 8: Decrypt the ciphertext feedback control signal to obtain the system ciphertext signal and , which is specifically achieved through the following formula: (25); Based on formula (25), the system ciphertext signal is calculated as and .

[0043] Note that while FDI attack types vary, the attack detection mechanism remains consistent. Therefore, system administrators no longer need to implement different FDI attack detection strategies for different attack types, which facilitates attack detection. Once an FDI attack is detected by the detector, the cyber-physical system can resiliently recover the system's ciphertext signals, filtering out the attacker's injected FDI attack signals and restoring the system's original control signals, ensuring secure and stable system operation.

[0044] Based on the above steps, the cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption proposed in the present invention, combined with the theoretical analysis part, can be implemented by the following algorithm 1.

[0045] Algorithm 1: Cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption; Input: Feedback controller matrix , , , , the feedback controller state variable , the sensor measures .

[0046] Output: state variables of the controller at the next moment , feedback control signal .

[0047] CPS side: 1: The controller and sensor will feedback the controller matrix , , , , state variables and sensor measurements Integrate into system matrix and system vector .

[0048] 2: According to formula (4) and (5), the plaintext signal and Mapped to integer matrices and integer vectors .

[0049] 3: Encrypt the integer signal using (6) and (7) and , and get the ciphertext signal and .

[0050] 4: Generate Security Tags Insert it in synchronous mode I and upload the control system signal containing the safety tag to the cloud server.

[0051] Cloud server side: 5: Extract using synchronous mode I Security Tags , and according to formula (11), insert pseudo-random noise and update the security label to .

[0052] 6: Perform multiplicative FDI attack detection. According to the multiplicative FDI attack detection condition V in Table 1, use the authorized secondary key to filter the multiplicative FDI attack factor. and .

[0053] 7: Calculate the matrix-vector product , and obtain the feedback control signal.

[0054] 8: Will Security Tags Inserting feedback control signals in synchronous mode II and returns the result to CPS.

[0055] CPS side: 9: Extract in Synchronous Mode II Security Tags , decrypt the security tag and assess the key leakage risk.

[0056] 10: if the key is safe; 11: Perform attack detection, capture additive, multiplicative, and additive-multiplicative FDI attacks, and record FDI attack detection information; 12: if no FDI attack triggers the detector alarm; 13: According to formula (25), decrypt , performs the inverse integer mapping and , according to (3) to extract the feedback controller state and control inputs .

[0057] 14: else if the FDI attack identified by the detector is within the system resilience range; 15: Remove various types of FDI attacks and decrypt correctly .

[0058] 16: end if; 17: end if the security label evaluation key has been compromised; 18: Terminate the decryption operation, reset the key security parameters, and request data retransmission.

[0059] 19: end if.

[0060] In response to the security requirements of cloud-embedded cyber-physical systems (CPSs), this paper designs a CPS security protection method based on elastic homomorphic encryption. This method can detect false data injection (FDI) attacks and achieve signal resilience recovery for CPSs. This method, based on the somewhat homomorphic encryption (SWHE) encryption technology standard, divides encryption keys into two security levels. The lower-level (second-level) keys are authorized to the cloud, while the higher-level (first-level) keys are disclosed only to the CPS. Compared with existing CPS security protection methods, this method not only effectively detects various complex FDI attacks (additive, multiplicative, and additive-multiplicative) while ensuring the privacy of the CPS, but also eliminates the impact of FDI attacks on system control signals.

[0061] The method proposed in this paper has low computational complexity, offering significant advantages over homomorphic encryption algorithms such as RSA and Paillier, and is suitable for practical engineering applications. Furthermore, the security tag designed in this paper can monitor the risk of key leakage in real time, effectively improving system security. Under the framework of the proposed security protection method, the security performance of cloud-embedded cyber-physical systems will be significantly improved.

[0062] The present invention utilizes homomorphic encryption technology to construct an attack detector through dynamic secret parameters while ensuring the privacy of the system. This allows detection and identification of various complex types of existing FDI attacks, and can elastically recover the original system plaintext signal from the contaminated system data, effectively solving the drawbacks and shortcomings of existing methods in terms of privacy protection, FDI attack detection, and elastic recovery of cloud-embedded cyber-physical systems. The method proposed in the present invention has good detection performance, high reconstructed signal quality, and can provide sufficient protection for CPS privacy. The method designed by the present invention is not only highly accurate, but also has fast computing speed and low latency, which can ensure the safe, real-time, and stable operation of cloud-embedded cyber-physical systems.

[0063] To verify the safety performance of this invention, we used MATLAB as a simulation test platform and a classic four-cylinder water tank control system as the simulation object. The control system state was the water level in the four-cylinder water tank, and the control input was the pressure in the water pump. In the experiment, we set the sampling interval of the sensor measurement signal to 1 second. Specifically, the parameters of the four-cylinder water tank system were quantified as follows: ;

[0064] ;

[0065] The parameters of the feedback controller are quantized as: ;

[0066] ;

[0067] In simulation, the key , and p are set within a reasonable range to ensure that the above keys have a sufficient security distance and thus correctly decrypt the control system signal. Specifically, the secret parameters , , . Strong pseudo-random number generator through random seed iteration, dynamic modular matrix and dynamic modulus vector can be generated. The experimental results are rounded to two decimal places, so .

[0068] Figure 4 The figure shows the detection effect of the security protection method designed by the present invention on various existing FDI attacks, where (a) is a schematic diagram of the detection results of additive FDI attacks, (b) is a schematic diagram of the detection results of multiplicative FDI attacks, (c) is a schematic diagram of the detection results of additive-multiplicative FDI attacks, and (d) is a schematic diagram of the detection results of large-scale additive FDI attacks.

[0069] In the simulation, the FDI attack was set to be launched during 31-50 seconds, 101-130 seconds, and 151-160 seconds. , , and All are randomly generated by the simulation test platform. In order to quantify the detection results of the three types of FDI attacks, the following detection indicators are given: (32); (33); (34); in, , and Respectively represent the detection indicators for additive, multiplicative and additive-multiplicative FDI attacks. Figure 2 It can be seen that although attackers try to construct various complex types of FDI attack injection forms to evade detectors, under the attack detection method designed by the present invention, FDI attacks are effectively identified and captured.

[0070] Figure 5 The performance of removing various existing FDI attacks is demonstrated. (a) shows the resilient recovery error under an additive FDI attack, (b) shows the resilient recovery error under a multiplicative FDI attack, and (c) shows the resilient recovery error under an additive-multiplicative FDI attack. By independently running a homomorphic decryption filtering attack algorithm on the CPS and the cloud, the original system information can be extracted and recovered from the control signal contaminated by the FDI attack. In the simulation, the cloud server, after obtaining the secondary authorization key, filters the multiplicative FDI attack signal. In this case, the quality of the control system signal reconstruction is guaranteed.

[0071] Figure 6 The results of security tags monitoring the risk of key leakage are shown. In the simulation, it is assumed that the attacker steals the key and When the FDI attacker injects random attacks during the periods of 0-10 seconds and 31-60 seconds, and injects covert additive attacks during the period of 11-30 seconds, the system administrator can analyze and evaluate the risk of key leakage based on the verification results of the security label, and accurately infer that the attack during the period of 11 seconds to 30 seconds is at the key leakage point. and It was launched when it was leaked. Figure 6 In the example, represents the number of security tags attacked, represents the number of security tags that are inconsistent with the preset pseudo-plaintext after decryption, and represents the number of security tags that meet the key leakage judgment condition given by formula (15) after decryption. Since the simulation simulates the situation when the attacker accurately obtains the key and launches the FDI attack, and since the disturbance of the security tags by random attacks can be filtered by the decryption algorithm, Figure 6 The and marked points in are coincident.

[0072] The above description is merely an illustration of the preferred embodiments of the present disclosure and the technical principles employed. Those skilled in the art should understand that the scope of the invention encompassed by the embodiments of the present disclosure is not limited to technical solutions formed by specific combinations of the aforementioned technical features. It also encompasses other technical solutions formed by any combination of the aforementioned technical features or their equivalents, without departing from the aforementioned inventive concept. For example, a technical solution formed by replacing the aforementioned features with (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure.

Claims

1. A cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption, characterized in that: include: Step 1: Build a model of the cyber-physical system (CPS) and generate the original signal based on the model of the cyber-physical system (CPS) and , the original signal of the cyber-physical system CPS and Perform integer mapping to obtain the system plaintext signal after integer mapping and ; Step 2: Set secret parameters , , , , ,Will , , As the first level key, , As the second-level key; authorize the first-level key and the second-level key to the CPS, and authorize the second-level key to the cloud server; in, Expressed as: ,in, are all positive integers, To represent the dynamic template matrix, is a dynamic template vector, where and are all positive integers, and Used to mask the characteristics of the system's plaintext signal, and and Produced by a strong pseudo-random number generator iteratively with a random seed, is a positive integer, is a prime number greater than a preset threshold, is the static template matrix, is a static template vector, is a prime number greater than a preset threshold; Step 3: In CPS, based on partially homomorphic encryption SWHE technology, a homomorphic encryption algorithm is designed to encrypt the system plaintext signal based on secret parameters. and Encrypt and obtain the system ciphertext signal and ;CPS generates security labels , the security label Used for the first level key in homomorphic encryption and Monitor the leakage of Insert system ciphertext signal In the system, we get the coded signal with label , the tagged system ciphertext signal and system ciphertext signal Upload to the cloud server; Step 4: The cloud server receives the system ciphertext signal and the tagged system ciphertext signal , according to the coded signal of the system with label , get the security label and system ciphertext signal ; According to the system ciphertext signal and , the cloud server performs feedback control calculation and obtains the ciphertext feedback control signal ; Set the safety label Add pseudo-random noise , obtain the tagged ciphertext feedback control signal, and send the tagged ciphertext feedback control signal to the CPS; Step 5: Determine the key based on the ciphertext feedback control signal received by the CPS and Whether there is leakage; Step 6: CPS receives the tagged ciphertext feedback control signal, and determines whether to upload the tagged system ciphertext signal to the cloud server based on the received tagged ciphertext feedback control signal, the first level key and the second level key. and Whether the cloud server is attacked during the process of sending the coded feedback control signal with labels to the CPS, and whether the cloud server is attacked during the process of sending the coded feedback control signal with labels to the CPS, and In the process of sending the tagged ciphertext feedback control signal to the CPS, if the cloud server is attacked, execute step 7, and when the CPS uploads the tagged system ciphertext signal to the cloud server, and In the process of sending the coded feedback control signal with the tag to the CPS, if the cloud server is not attacked, execute step 8; Step 7: Determine whether the CPS uploads the labeled system ciphertext signal to the cloud server and The types of attacks in the process of sending coded feedback control signals with labels from the cloud server to the CPS; Step 8: Decrypt the ciphertext feedback control signal to obtain the system ciphertext signal and .

2. The cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption according to claim 1 is characterized in that: Step 1 specifically includes: Step 1.1: Construct a model of the cyber-physical system (CPS). The operation of the cyber-physical system model is represented by the state equation, which is specifically expressed by the following formula: (1); in, Represents the cyber-physical system CPS k The state variables of the iteration, Represents the cyber-physical system CPS k+ State variables for 1 iteration, represents the sensor measurement signal of the cyber-physical system CPS, represents the control input signal of the cyber-physical system CPS, represents the noise vector applied to the cyber-physical system CPS, , , , , and is a real number matrix of different dimensions, which is used as the parameter of the cyber-physical system CPS to characterize the characteristics of the cyber-physical system CPS. represents the set of real numbers, are positive integers representing the dimensions of the matrix; The control signal in formula (1) The feedback control signal is calculated by the feedback controller. The calculation is represented by the following iterative equation: (2); in, Indicates the k The state variables of the feedback controller for the iteration, Indicates the k +1 iteration of the feedback controller's state variables, , , and is a real number matrix, which is used as the parameter of the feedback controller to characterize the characteristics of the feedback controller. is an integer representing the dimension of the state variable of the feedback controller; Rewrite formula (2) into matrix-vector product form, expressed as: (3); in, is the parameter matrix of the feedback controller, is a vector consisting of the state variables of the feedback controller and the sensor measurement signal. and As the original signal of the cyber-physical system CPS; and are all positive integers, is a matrix Dimensions, is a vector Dimensions, , ; Step 1.2: Raw signals of cyber-physical systems (CPS) and Perform integer mapping, specifically expressed as: (4); (5); in, represents the quantization accuracy, and It is the system plaintext signal after integer mapping. Represents the ceiling function.

3. The cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption according to claim 2 is characterized in that: Step 3 specifically includes: Step 3.1: In CPS, based on partially homomorphic encryption SWHE technology, design a homomorphic encryption algorithm, based on secret parameters, to encrypt the system plaintext signal and Encryption is implemented using the following formula: (6); (7) ; Among them, the symbol Represents the multiplication operation between matrices or vectors within the element range, matrix Indicates system plaintext signal The system ciphertext signal, vector A system ciphertext signal representing a system plaintext signal; Step 3.2: CPS generates security labels , the security label Expressed as: (8); in, , and is a secret parameter, and are all prime numbers greater than the preset threshold, is a matrix Middle Any element in the row, and is a positive integer, and are natural numbers, represents the set of natural numbers, is a serial number used to identify the safety label, and d is an integer; Step 3.3: Insert the security tag into the system ciphertext signal through synchronization mode I Specifically, it includes: Based on the 1-D chaotic system, a pseudo-random sequence is obtained after multiple iterations according to the preset number of iterations. The 1-D chaotic system is expressed as: (9); in, and is the control parameter of the 1-D chaotic system, Indicates that the chaotic system t The pseudo-random number generated by the iteration, Indicates that the chaotic system t +1 pseudo-random number generated by iteration, and The values ​​of are all less than 1. is an integer that indicates the number of iterations of the chaotic system; The pseudo-random sequence and Multiply and round to get the insertion position information, and insert the security tag into the system ciphertext signal according to the insertion position information. In the system, we get the coded signal with label , Is an integer, indicating the total A security tag is inserted into the system ciphertext signal In the system, the coded signal with label and system ciphertext signal Upload to the cloud server.

4. The cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption according to claim 3 is characterized in that: Step 4 includes: Step 4.1: Cloud server receives system ciphertext signal and the tagged system ciphertext signal , in synchronization mode I from the tagged system ciphertext signal Specifically, the security tag is inserted into the system ciphertext signal using synchronization mode I. The same process is used for the 1-D chaotic system. Based on the 1-D chaotic system, a pseudo-random sequence is obtained, and then the insertion position information is obtained. According to the insertion position information, the insertion position is extracted to obtain a security tag. , and then get the system ciphertext signal ; Step 4.2: According to the system ciphertext signal and , the cloud server performs feedback control calculations, which are specifically expressed by the following formula: (10); in, Feedback control signal for ciphertext; Step 4.3: Add Security Label Pseudo-random noise is added , , specifically expressed by the following formula: (11); in, , is a security tag obtained after noise processing, the pseudo-random noise is known to the CPS; the security tag obtained after noise processing The feedback control signal is randomly inserted into the ciphertext in synchronization mode II , the coded feedback control signal with label is obtained, where the formula of synchronization mode II is the same as that of synchronization mode I, but the specific values ​​of the control parameters of the 1-D chaotic system are different. The coded feedback control signal with label is sent to the CPS.

5. The cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption according to claim 4 is characterized in that: Step 5 includes: Step 5.1: Receive the coded feedback control signal with tags sent by the cloud server at the CPS end, extract the coded feedback control signal with tags in synchronization mode II, and obtain the security tag , for security labels Perform security tag authentication operations, specifically expressed by the following formula: (12); in, Pseudo-random noise added to the cloud server can be removed by CPS. , is the result obtained after the security tag authentication operation, where The calculation formula of the operator is expressed as: (13); Among them, the parameters represents a vector consisting of binary numbers, represents any integer vector, is a positive integer; Step 5.2: Assuming the key and Leaked, and the attacker uploads the labeled system ciphertext signal to the cloud server in CPS In the process of injecting any attack signal , and in the process of the cloud server sending the labeled ciphertext feedback control signal to the CPS, an attack signal is injected In this case, the security label received by CPS is expressed as: (14); in, is a positive integer; Solving formula (14) and formula (12) together, we can obtain The specific value of = When CPS uploads the labeled system ciphertext signal to the cloud server In the process of sending the ciphertext feedback control signal with label to CPS, there is no FDI attack; when = + When CPS uploads the tagged system ciphertext signal to the cloud server In the process of sending the coded feedback control signal with label to CPS, the cloud server is attacked by FDI, and then executes step 5.3; Step 5.3: Substitute into the verification equation, where the verification equation is expressed as: (15); Determine whether the left and right sides of the verification equation are equal. If the left and right sides of the verification equation are equal, it indicates that the CPS will determine the key and has been leaked to the attacker, that is, the assumption in step 5.2 is established. When the left and right sides of the verification equation are not equal, CPS will determine that the key and It is not leaked to the attacker, which means the assumption in step 5.2 does not hold.

6. The cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption according to claim 5 is characterized in that: Step 6 includes: CPS receives the tagged ciphertext feedback control signal, extracts the security tag from the tagged ciphertext feedback control signal, and obtains the ciphertext feedback signal with the tag removed. , and then judge and Are they equal? and If they are equal, it indicates that CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the ciphertext feedback control signal with label to CPS, the cloud server was not attacked. and If they are not equal, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and The attack occurs during the process of the cloud server sending the ciphertext feedback control signal with labels to the CPS.

7. The cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption according to claim 6 is characterized in that: Step 7 specifically includes: Step 7.1: The cloud server calculates the FDI multiplicative attack factor using the second-level key and , specifically calculated by the following formula: (16); (17); in, and Indicates the system ciphertext signal uploaded by CPS to the cloud server that has been attacked; The calculated multiplicative attack factor and When it is equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the coded feedback control signal with label to the CPS, if the attack type is not a multiplicative FDI attack, proceed to step 7.

2. The calculated multiplicative attack factor and When it is not equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the coded feedback control signal with labels to the CPS, the attack type is multiplicative FDI attack. Then the cloud server filters out the multiplicative attack, which is achieved by the following formula: (18); (19); The cloud server filters out the multiplicative attack factors in the received ciphertext feedback control signal and , filtering out the multiplicative attack factors in the received ciphertext feedback control signal on the cloud server and The subsequent signal is expressed as: (20); From formula (20), we can see that filtering out multiplicative attacks and The subsequent signal also contains a multiplicative attack factor , calculate the multiplicative attack factor The value of is realized by the following formula: (21); Multiplicative Attack Factor Filter out multiplicative attacks and Remove the signal after filtering the multiplicative attack, and obtain the ciphertext feedback control signal after filtering the multiplicative attack. Substitute the ciphertext feedback control signal after filtering the multiplicative attack into the formula (22) In the original system plaintext signal and , formula (22) is expressed as: (22); Step 7.2: CPS calculates the multiplicative attack factor in the additive-multiplicative FDI attack using the following formula: (23); The calculated multiplicative attack factor When it is equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the labeled ciphertext feedback control signal from the cloud server to the CPS, if the attack type is not an additive-multiplicative FDI attack, proceed to step 7.3; The calculated multiplicative attack factor When it is not equal to 1, it indicates that the CPS uploads the labeled system ciphertext signal to the cloud server. and In the process of sending the coded feedback control signal with label from the cloud server to the CPS, the attack type is additive-multiplicative FDI attack, which factors the multiplicative attack into Remove the ciphertext feedback control signal received from the CPS to obtain the purified ciphertext feedback control signal , and then the purified ciphertext is fed back to the control signal Substitute into formula (24), remove the signal injected by the additive FDI attack, and obtain the original system plaintext signal and , formula (24) is expressed as: (24); Step 7.3: Upload the labeled system ciphertext signal to the cloud server in CPS and In the process of sending the coded feedback control signal with label from the cloud server to the CPS, if the attack type is neither additive-multiplicative FDI attack nor multiplicative FDI attack, the attack type is characterized as additive FDI attack. Then, the coded feedback control signal received by the CPS is substituted into the formula (22): In the original system plaintext signal and .

8. The cloud-embedded cyber-physical system security protection method based on elastic homomorphic encryption according to claim 7 is characterized in that: Step 8 is specifically implemented by the following formula: (25); Based on formula (25), the system ciphertext signal is calculated as and .

Citation Information

Patent Citations

  • Error data injection attack defense method based on hybrid homomorphic encryption

    CN110545289A

  • Semi-homomorphic encryption trusted model prediction control method and device

    CN120068137A

  • Methods and systems for implementing secure and trustworthy artificial intelligence

    WO2025042692A1