Industrial control system industrial protocol communication safety prevention and control method based on 5G communication
Through the industrial protocol security control method based on 5G communication, the use of dynamic keys and physical layer feature binding, combined with lightweight digital twin models for real-time anomaly detection, the security challenges of traditional industrial control systems under 5G networks are solved, and efficient security protection and real-time control are achieved.
Patent Information
- Application Number
- CN202510907071.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-10-10
AI Technical Summary
Traditional industrial control systems face insufficient protocol parsing, static encryption, and real-time anomaly detection in the 5G network environment, and lack dynamic key mechanisms and physical layer identity authentication, which increases the risk of man-in-the-middle attacks.
An industrial protocol communication security prevention and control method based on 5G communication is adopted. The protocol is parsed through 5G edge computing to generate dynamic symmetric keys. Dual-channel transmission and physical layer feature binding are used for encryption. A lightweight digital twin model is combined for behavior prediction and abnormal circuit breaking to achieve field-level protection and real-time security protection.
It effectively reduces the risk of man-in-the-middle attacks, improves the security and real-time performance of industrial control systems, meets the low-latency requirements of industrial control, is compatible with mainstream industrial protocols, and provides a backup channel for quantum key distribution to deal with extreme attacks.
Smart Images

Figure CN120769255A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of industrial control, and in particular to an industrial protocol communication security prevention method for an industrial control system based on 5G communication. BACKGROUND
[0002] 5G refers to the fifth generation mobile communication technology, which is the latest generation of cellular mobile communication technology, and is an extension of 4G, 3G and 2G systems. The performance goals of 5G are high data rate, reduced latency, energy saving, cost reduction, improved system capacity and large-scale device connection. The traditional industrial control system faces security challenges brought by open interconnection. The existing scheme has defects in protocol analysis, encryption staticity and real-time abnormality detection, and the 5G network slicing technology provides a new path for differentiated security protection. The current industrial protocol (such as Modbus / TCP) lacks a dynamic key mechanism, and the physical layer characteristics are not used for identity authentication, resulting in increased risk of man-in-the-middle attacks. SUMMARY
[0003] The present application is based on the above problems, and proposes an industrial protocol communication security prevention method for an industrial control system based on 5G communication to solve the above problems.
[0004] To solve the above problems, the technical scheme of the present application is as follows:
[0005] An industrial protocol communication security prevention method for an industrial control system based on 5G communication, characterized in that it comprises the following steps:
[0006] S1, protocol analysis and data fragmentation: analyzing the industrial control protocol (such as Modbus / TCP, Profinet) at the 5G edge computing node, and splitting the original data into control instruction field, parameter field and check field;
[0007] S2, dynamic key generation: generating a dynamic symmetric key based on 5G network slicing ID, timestamp and device physical fingerprint, and encrypting the control instruction field;
[0008] S3, dual-channel transmission: transmitting the encrypted instruction field through 5G URLLC (ultra-reliable low-latency communication) slice, and transmitting the parameter field through eMBB (enhanced mobile broadband) slice;
[0009] S4, physical layer feature binding: embedding the device radio frequency fingerprint feature into the data packet header at the sending end, and verifying the matching degree of the radio frequency fingerprint and the device registration library at the receiving end;
[0010] S5, behavior prediction engine: after decryption at the receiving end, inputting the instruction into a lightweight digital twin model for millisecond-level behavior simulation to predict the device state trajectory;
[0011] S6, Abnormal fusing mechanism: if the simulation result exceeds the preset safety threshold, discard the data packet and trigger the key reset instruction; otherwise, execute the control instruction.
[0012] As a preferred embodiment of the present application, the dynamic key generation in S2 specifically comprises:
[0013] (1) Obtain the current slice ID and terminal device IMEI code through the 5G core network UPF node;
[0014] (2) Generate a device unique fingerprint in combination with the physical layer channel impulse response (CIR) characteristics;
[0015] (3) Use the lightweight national SM4 algorithm to update the encryption key rolling with slice ID + timestamp + device fingerprint as the seed.
[0016] As a further preferred embodiment of the present application, the physical layer feature binding in S4 comprises:
[0017] (1) The sending end implants the device radio frequency fingerprint (such as phase noise, power spectrum characteristics) in the 5G base station modulation stage;
[0018] (2) The receiving end compares the data packet header characteristics with the pre-stored device fingerprint library through a convolutional neural network (CNN), and determines that it is a man-in-the-middle attack if the matching deviation is > 5%.
[0019] As a further preferred embodiment of the present application, the behavior prediction engine in S5 specifically comprises:
[0020] (1) Establish a simplified digital twin model at the device level, which only contains mechanical motion equations and key state variables;
[0021] (2) After inputting the control instruction, predict the device position, temperature and pressure curve within 500ms in the future within <10ms;
[0022] (3) Trigger the fuse when the predicted value exceeds the safety threshold (such as position error ±0.1mm, temperature rise rate > 5℃ / s).
[0023] On the basis of the above-mentioned technology, the present application further comprises:
[0024] S7, Channel redundancy check: CRC32 check code and blockchain hash value of encrypted data are transmitted in parallel in the URLLC slice, and the receiving end performs triple consistency verification.
[0025] As a further preferred embodiment of the present application, after the abnormal fusing mechanism in S6 is triggered: isolate the attacked terminal through the 5G network slice manager, and start the standby quantum key distribution (QKD) channel to transmit the emergency shutdown instruction.
[0026] As a further preferred embodiment of the present application, the lightweight digital twin model adopts a simplified physical engine based on the CAD model of the industrial equipment, only retaining the rigid body dynamics equation, and deploying the model through a 5G MEC (Multi-Access Edge Computing) node to ensure a simulation delay of ≤3ms.
[0027] As a further preferred embodiment of the present application, the key rolling update strategy is:
[0028] (1) Automatically trigger key replacement when 10 data packets are successfully transmitted or the channel error rate is detected to be >10 -6
[0029] (2) The new key is transmitted through 5G air interface physical layer channel features (such as CSI) for concealed transmission.
[0030] As a further preferred embodiment of the present application, the special protection for industrial protocols includes:
[0031] (1) The Modbus function code field is nested encrypted, with a dynamic key used for the outer layer and a device firmware signature key used for the inner layer;
[0032] (2) Inserting false IO data packets in the Profinet protocol for attack trapping.
[0033] The present application also includes security situation awareness, specifically as follows:
[0034] (1) An AI analysis module is deployed in the 5G core network to monitor the data packet entropy value mutation of each slice in real time; (2) When the standard deviation of the entropy value of a specific industrial protocol message exceeds 30% of the baseline, the encryption algorithm is automatically upgraded to SM9 asymmetric encryption.
[0035] In terms of creativity, novelty and practicality, the present application has a greater breakthrough compared to the prior art, specifically as follows:
[0036] 1. In terms of creativity, specifically as follows:
[0037] (1) Fusion of 5G network slices to achieve differentiated transmission of industrial protocol fields, solving the problem of bandwidth waste in traditional single encryption;
[0038] (2) Original "physical layer radio frequency fingerprint + behavior prediction" dual-factor authentication, breaking through the limitation that traditional protocol layer encryption is easily cracked;
[0039] (3) Lightweight digital twin millisecond-level simulation fuse mechanism is proposed to replace the impractical three-dimensional model simulation in the reference patent.
[0040] 2. In terms of novelty, specifically as follows:
[0041] (1) First combine 5G URLLC slice characteristics with industrial protocol field-level protection;
[0042] (2) Innovatively use channel impulse response (CIR) as a key seed to realize physical layer unclonable secure binding;
[0043] (3) Design an entropy value mutation-based dynamic encryption upgrade strategy to realize active security protection.
[0044] 3. In terms of practicality, the following applies:
[0045] (1) Through MEC edge computing deployment (right 7), the real-time requirement of industrial control ≤10ms is met; (2) compatible with field-level protection of mainstream industrial protocols (Modbus / Profinet);
[0046] (3) Provide a quantum key distribution (QKD) backup channel to deal with extreme attack scenarios.
[0047] 4. This scheme also avoids the defects of the reference patent:
[0048] (1) Replace fixed keys with dynamic keys (to prevent key leakage);
[0049] (2) Replace complex three-dimensional modeling with lightweight simulation (to meet real-time control;
[0050] (3) Deeply integrate 5G slice characteristics (not just protocol transplantation). BRIEF DESCRIPTION OF DRAWINGS
[0051] Figure 1 The system architecture diagram of the 5G edge node, dual-channel transmission path and security module in the present application is shown;
[0052] Figure 2 The dynamic key generation flowchart containing slice ID and device fingerprint input logic in the present application is shown;
[0053] Figure 3 The digital twin prediction and fuse mechanism timing diagram in the present application is shown. DETAILED DESCRIPTION
[0054] The present application will be further described below with a specific implementation.
[0055] As can be seen from FIGS. Figure 2 and Figure 3 An industrial control system industrial protocol communication security prevention and control method based on 5G communication, characterized in that it comprises the following steps:
[0056] S1. Protocol parsing and data fragmentation: Parse industrial control protocols (such as Modbus / TCP and Profinet) at the 5G edge computing node and split the original data into control instruction fields, parameter fields, and checksum fields.
[0057] S2. Dynamic key generation: Generate a dynamic symmetric key based on the 5G network slice ID, timestamp, and device physical fingerprint to encrypt the control instruction field;
[0058] S3, dual-channel transmission: The encrypted instruction field is transmitted through 5G URLLC (ultra-reliable low-latency communication) slices, and the parameter field is transmitted through eMBB (enhanced mobile broadband) slices;
[0059] S4, physical layer feature binding: The sending end embeds the device's RF fingerprint feature into the data packet header, and the receiving end verifies the match between the RF fingerprint and the device registration database;
[0060] S5, Behavior Prediction Engine: After decryption at the receiving end, the instructions are input into the lightweight digital twin model for millisecond-level behavior simulation to predict the device status trajectory;
[0061] S6. Abnormal fuse mechanism: If the simulation result exceeds the preset security threshold, the data packet is discarded and the key reset instruction is triggered; otherwise, the control instruction is executed.
[0062] In the present invention, the preferred dynamic key generation in S2 specifically includes:
[0063] (1) Obtain the current slice ID and terminal device IMEI code through the 5G core network UPF node;
[0064] (2) Generate a unique device fingerprint by combining the physical layer channel impulse response (CIR) characteristics;
[0065] (3) Use the lightweight national encryption SM4 algorithm, with slice ID + timestamp + device fingerprint as the seed, to roll over the encryption key.
[0066] In the present invention, the preferred physical layer feature binding in S4 includes:
[0067] (1) The transmitter embeds the device’s RF fingerprint (such as phase noise and power spectrum characteristics) during the 5G base station modulation stage;
[0068] (2) The receiving end compares the packet header features with the pre-stored device fingerprint library through a convolutional neural network (CNN). If the matching deviation is greater than 5%, it is determined to be a man-in-the-middle attack.
[0069] In the present invention, the preferred behavior prediction engine in S5 is specifically:
[0070] (1) Establish a simplified digital twin model at the device level, only containing mechanical motion equations and key state variables;
[0071] (2) After inputting the control instruction, the device position, temperature and pressure curve in the future 500ms are predicted within 10ms;
[0072] (3) When the predicted value exceeds the safety threshold (such as position error ±0.1mm, temperature rise rate >5℃ / s), the fuse is triggered.
[0073] On the basis of the above-mentioned technology, the application also includes:
[0074] S7, channel redundancy check: CRC32 check code and blockchain hash value of encrypted data are transmitted in parallel in the URLLC slice, and the receiving end performs triple consistency verification.
[0075] In the application, preferably, after the abnormal fuse mechanism in S6 is triggered: the attacked terminal is isolated by the 5G network slice manager, and an emergency shutdown instruction is transmitted through a standby quantum key distribution (QKD) channel.
[0076] In the application, preferably, the lightweight digital twin model adopts a simplified physical engine based on an industrial equipment CAD model, only rigid body dynamics equations are retained, and the model is deployed through a 5G MEC (multi-access edge computing) node, ensuring that the simulation delay is ≤3ms.
[0077] In the application, preferably, the key rolling update strategy is:
[0078] (1) When 10 data packets are successfully transmitted or the channel error rate is detected to be >10 -6 , the key replacement is automatically triggered;
[0079] (2) The new key is transmitted through the 5G air interface physical layer channel characteristics (such as CSI).
[0080] In the application, preferably, the special protection for the industrial protocol includes:
[0081] (1) The Modbus function code field is nested encrypted, the outer layer uses a dynamic key, and the inner layer uses a device firmware signature key;
[0082] (2) False IO data packets are inserted in the Profinet protocol for trapping attacks.
[0083] The application also includes security situation awareness, specifically as follows:
[0084] (1) Deploy AI analysis module in 5G core network, monitor the data packet entropy value mutation of each slice in real time; (2) When the standard deviation of the entropy value of the specific industrial protocol message exceeds 30% of the baseline, automatically upgrade the encryption algorithm to SM9 asymmetric encryption.
[0085] Embodiment 1: Dynamic key and dual-channel transmission
[0086] Scenario: Welding robot control in automobile manufacturing plant.
[0087] 1. Implementation steps:
[0088] (1) Edge node parses Profinet protocol, splits welding parameters (current, speed) and motion instructions;
[0089] (2) Generate SM4 dynamic key based on robot IMEI code and 5G slice ID, encrypt motion instructions; (3) URLLC slice transmits encrypted instructions (latency <2ms), eMBB slice transmits welding parameters.
[0090] 2. Effect of this embodiment: Key is replaced every 10 packets, cracking cost increases by 300%.
[0091] Embodiment 2: Radio frequency fingerprint and fuse mechanism
[0092] Scenario: Remote monitoring of petrochemical pump station.
[0093] 1. Implementation steps:
[0094] (1) Radio frequency fingerprint (phase noise) of pump station PLC is embedded in data packet header;
[0095] (2) Receiver CNN model compares fingerprint library, deviation exceeding 5% triggers fuse;
[0096] (3) Digital twin predicts pump pressure curve anomaly (>0.1 MPa / ms), switches to QKD channel for shutdown.
[0097] 2. Effect: Man-in-the-middle attack identification accuracy reaches 99.7%.
[0098] Embodiment 3: Lightweight digital twin prediction
[0099] Scenario: High-precision machining of numerical control machine tool.
[0100] 1. Implementation steps:
[0101] (1) Establish simplified twin body based on CAD model (only axial dynamics equation is retained);
[0102] (2) Discard instructions when tool path error exceeds ±0.05mm;
[0103] (3) Achieve 3ms level simulation response through MEC nodes.
[0104] 2. Effect: The processing scrap rate is reduced by 90%.
[0105] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for industrial control system industrial protocol communication security prevention and control based on 5G communication, characterized in that: The following steps are involved: S1. Protocol parsing and data fragmentation: Parse industrial control protocols such as Modbus, TCP, or Profinet at the 5G edge computing node, and split the original data into control instruction fields, parameter fields, and checksum fields. S2. Dynamic key generation: Generate a dynamic symmetric key based on the 5G network slice ID, timestamp, and device physical fingerprint to encrypt the control instruction field; S3, dual-channel transmission: the encrypted instruction field is transmitted through the 5G URLLC slice, and the parameter field is transmitted through the eMBB slice; S4, physical layer feature binding: The sending end embeds the device's RF fingerprint feature into the data packet header, and the receiving end verifies the match between the RF fingerprint and the device registration database; S5, Behavior Prediction Engine: After decryption at the receiving end, the instructions are input into the lightweight digital twin model for millisecond-level behavior simulation to predict the device status trajectory; S6. Abnormal fuse mechanism: If the simulation result exceeds the preset security threshold, the data packet is discarded and the key reset instruction is triggered; otherwise, the control instruction is executed.
2. A method for industrial control system industrial protocol communication security prevention and control based on 5G communication according to claim 1, characterized in that: The dynamic key generation in S2 specifically includes: (1) Obtain the current slice ID and terminal device IMEI code through the 5G core network UPF node; (2) Generate a unique device fingerprint by combining the physical layer channel impulse response characteristics; (3) Use the lightweight national encryption SM4 algorithm, with slice ID + timestamp + device fingerprint as the seed, to roll over the encryption key.
3. The method for industrial protocol communication security control of an industrial control system based on 5G communication according to claim 1 is characterized in that: The physical layer feature binding in S4 includes: (1) The transmitter implants the device’s RF fingerprint, such as phase noise or power spectrum characteristics, during the 5G base station modulation stage; (2) The receiving end compares the data packet header features with the pre-stored device fingerprint library through a convolutional neural network. If the matching deviation is greater than 5%, it is determined to be a man-in-the-middle attack.
4. The method for industrial protocol communication security control of an industrial control system based on 5G communication according to claim 1, characterized in that: The behavior prediction engine in S5 is specifically: (1) Establish a simplified digital twin model at the device level, which only contains mechanical motion equations and key state variables; (2) After inputting the control command, the device position, temperature, and pressure curves within the next 500ms are predicted within <10ms; (3) When the predicted value exceeds the safety threshold, such as position error ±0.1mm, and temperature rise rate >5℃ / s, the fuse is triggered.
5. The method for industrial protocol communication security control of an industrial control system based on 5G communication according to claim 1 is characterized in that: Also includes: S7. Channel redundancy check: The CRC32 checksum and blockchain hash value of the encrypted data are transmitted in parallel in the URLLC slice, and the receiving end performs triple consistency verification.
6. The method for industrial protocol communication security control of an industrial control system based on 5G communication according to claim 1, characterized in that: After the abnormal fuse mechanism in S6 is triggered: the attacked terminal is isolated through the 5G network slice manager, and the backup quantum key distribution channel is started to transmit the emergency shutdown instruction.
7. The method for industrial protocol communication security control of an industrial control system based on 5G communication according to claim 1, characterized in that: The lightweight digital twin model adopts a simplified physics engine based on the industrial equipment CAD model, retaining only the rigid body dynamics equations, and deploying the model through multi-access edge computing nodes to ensure that the simulation delay is ≤3ms.
8. The method for industrial protocol communication security control of an industrial control system based on 5G communication according to claim 2, characterized in that: The key rolling update strategy is: (1) Every time 10 data packets are successfully transmitted or a channel error rate > 10 is detected -6 When , the key replacement is automatically triggered; (2) The new key is transmitted covertly through the 5G air interface physical layer channel characteristics.
9. The method for industrial protocol communication security control of an industrial control system based on 5G communication according to claim 1, characterized in that: Special protections for industrial protocols include: (1) Nested encryption is performed on the Modbus function code field, with the outer layer using a dynamic key and the inner layer using the device firmware signature key; (2) Insert fake IO data packets into the Profinet protocol for trapping attacks.
10. The method for industrial protocol communication security control of an industrial control system based on 5G communication according to claim 1, characterized in that: Also includes security situational awareness: (1) Deploy an AI analysis module in the 5G core network to monitor the entropy mutation of data packets in each slice in real time; (2) When the standard deviation of the entropy value of a specific industrial protocol message exceeds 30% of the baseline, the encryption algorithm is automatically upgraded to SM9 asymmetric encryption.