Safety protection system and method applied to control system

By building a security protection system with deep collaboration between software and hardware and introducing dynamic trust assessment and edge computing security optimization technologies, the problem of the singleness of control system security protection has been solved, adaptive security protection throughout the entire life cycle has been achieved, and the system's security and anti-attack capabilities have been improved.

CN120811633APending Publication Date: 2025-10-17THREE GORGES INTELLIGENT CONTROL TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510884525.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

In the existing technology, the security protection method of the control system is single and cannot effectively deal with complex and changing security threats. It lacks a collaborative protection mechanism combining software and hardware, making it difficult to achieve comprehensive, efficient and reliable security protection.

Method used

Build a security protection system with deep collaboration between software and hardware, introduce dynamic trust assessment and edge computing security optimization technology, and achieve full life cycle and adaptive security protection of the control system through the collaborative work of hardware security protection modules, software security protection modules and security management center.

Benefits of technology

It enhances the security, reliability and anti-attack capability of the control system, realizes all-round and multi-level security protection, improves the system's adaptability and protection timeliness, reduces computing and storage resource consumption, reduces false alarm rate and missed alarm rate, and provides accurate intrusion detection and response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811633A_ABST
    Figure CN120811633A_ABST
Patent Text Reader

Abstract

The invention relates to the field of system security protection, in particular to a security protection system and method, and the system comprises a hardware security protection module which is used for carrying out the hardware identity authentication and hardware protection, carrying out the high-speed encryption processing of data, constructing a hardware firewall, and carrying out the flow management and control; the software security protection module is used for realizing dynamic authentication and abnormal behavior detection of a software program, software encryption and code protection, software intrusion detection and automatic generation of a response strategy; the security management center is used for uniformly managing authentication strategies and secret key management of the hardware equipment and the software program, dynamically managing the strategies to realize dynamic self-adaptive optimization of the security strategies, monitoring the running states of the hardware equipment and the software program in real time and performing auditing management; and the evaluation and optimization module is used for constructing a multi-dimensional trust evaluation model to dynamically evaluate the trust degree of the hardware equipment and the software program, and carrying out edge computing security optimization. According to the invention, the security, reliability and anti-attack capability of the system can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of control system security protection, and particularly relates to a security protection system and method applied to a control system. BACKGROUND

[0002] The statements in this section merely provide background information related to the present application and do not necessarily constitute the prior art.

[0003] With the rapid development of information technology, control systems are increasingly widely used in various fields such as industry, transportation and energy. However, the security threats faced by control systems are also becoming increasingly serious, including malicious software attacks, hardware tampering, data leakage, etc. Traditional security protection methods often only focus on the software or hardware level, and it is difficult to achieve comprehensive and effective security protection.

[0004] On the software level, common protection methods include firewalls, intrusion detection systems, virus scanning, etc. These methods mainly rely on the operation of software programs and are vulnerable to attacks and bypasses by malicious software. For example, malicious software can damage the normal operation of protection software by modifying system files, injecting malicious code, etc. On the hardware level, some protection methods such as hardware encryption chips and secure processors can provide some security guarantees, but these methods are usually independent of software protection and cannot effectively work together. In addition, hardware devices themselves may have security vulnerabilities such as hardware trojans and physical attacks, which threaten system security.

[0005] Therefore, the existing problems are that single software or hardware security protection methods cannot cope with complex and variable security threats, lack of a collaborative protection mechanism combining software and hardware, and it is difficult to achieve comprehensive, efficient and reliable security protection for control systems.

[0006] In view of the above defects, the present application makes improvements. SUMMARY

[0007] In order to overcome the deficiencies of the background art, the present application provides a security protection system and method applied to a control system, which builds a deep software and hardware collaborative security protection system, introduces dynamic trust evaluation and edge computing security optimization technology, realizes adaptive security protection for the entire life cycle of the control system, improves the security, reliability and attack resistance of the system, and ensures the stable operation of the control system in a complex network environment.

[0008] To achieve the above purpose, the present application provides the following technical solutions:

[0009] In a first aspect, a security protection system applied to a control system is provided, which comprises:

[0010] The hardware security protection module is used for hardware identity authentication and hardware protection, and is also used for high-speed encryption processing of data, and is also used for building a hardware firewall and flow control;

[0011] The software security protection module is used for dynamic authentication and abnormal behavior detection of software programs, and is also used for software encryption and code protection, and is also used for software intrusion detection and automatic generation of response strategies;

[0012] The security management center is used for unified management of authentication strategies and key management of hardware devices and software programs, and is also used for dynamic management of strategies to realize dynamic self-adaptive optimization of security strategies, and is also used for real-time monitoring of running states of hardware devices and software programs and audit management;

[0013] The evaluation and optimization module is used for building a multi-dimensional trust evaluation model to dynamically evaluate the trust degree of hardware devices and software programs, and is also used for security optimization of edge computing.

[0014] Further,

[0015] The hardware security protection module includes a hardware identity authentication and protection unit, a hardware encryption acceleration unit, and a hardware firewall and flow control unit;

[0016] The hardware identity authentication and protection unit is used for hardware identity authentication based on a physically unclonable function (PUF), configures an authentication key for each hardware device, and simultaneously integrates a hardware attack detection sensor to monitor abnormalities in real time, and when a physical attack is detected, triggers a device self-destruction or isolation mechanism;

[0017] The hardware encryption acceleration unit is used for high-speed encryption processing of data using an encryption chip and integrating an encryption algorithm, and optimizes edge computing nodes using a lightweight encryption algorithm;

[0018] The hardware firewall and flow control unit is used for implementing a programmable hardware firewall based on a field programmable gate array (FPGA), and performing data packet filtering and flow behavior analysis and processing.

[0019] Further,

[0020] The software security protection module includes a software dynamic authentication and protection unit, a software encryption and code protection unit, and a software intrusion detection and response unit;

[0021] The software dynamic authentication and protection unit is used for performing hash calculation on software behavior using a hash chain, forming a dynamic behavior hash chain, and comparing the dynamic behavior hash chain with a normal behavior hash chain pre-stored in the security management center to perform dynamic authentication and abnormal behavior detection of software programs;

[0022] The software encryption and code protection unit is configured to perform virtualization processing on software key code, and to perform dynamic key encryption on sensitive data generated during software running, and the key is updated in real time according to the running state of the control system.

[0023] The software intrusion detection and response unit is configured to construct an intrusion detection model based on a long short-term memory (LSTM) algorithm to realize dynamic detection of new attacks, and to automatically generate a response strategy when an intrusion behavior is detected.

[0024] Further,

[0025] The security management center comprises an authentication and key management module, a policy dynamic management module, and a monitoring and auditing management module.

[0026] The authentication and key management module is configured to uniformly manage authentication policies of hardware devices and software programs, to perform key negotiation and distribution by using an ECDH algorithm, and to perform full-life-cycle management of the key, including key generation, storage, update, and destruction.

[0027] The policy dynamic management module is configured to adjust hardware firewall policies, software protection policies, and intrusion detection policies in real time according to the running state of the control system, security threat intelligence, and dynamic trust evaluation results, to realize dynamic self-adaptive optimization of security policies.

[0028] The monitoring and auditing management module is configured to monitor the running state of hardware devices and software programs in real time, to audit and record security events, and to perform deep mining of audit logs by correlation analysis, to generate a security situation analysis report.

[0029] Further,

[0030] The evaluation and optimization module comprises a dynamic trust evaluation unit and an edge computing security optimization unit.

[0031] The dynamic trust evaluation unit is configured to construct a multi-dimensional trust evaluation model, to perform dynamic evaluation of the trust degree of hardware devices and software programs from three dimensions of device identity legitimacy, historical security record, and current behavior compliance by using evidence theory.

[0032] The edge computing security optimization unit is configured to deploy a lightweight security protection component on an edge computing node, the lightweight security protection component comprising an edge intrusion detection agent and an edge encryption gateway, and is further configured to realize secure data interaction and policy synchronization between the edge computing node and the security management center by using a security cooperation protocol.

[0033] The second aspect also provides a security protection method applied to a control system, based on the security protection system applied to the control system as described above, and the method comprises the following steps.

[0034] The hardware security protection module cooperates with the security management center to authenticate the hardware devices accessing the system, the software security protection module cooperates with the security management center to dynamically authenticate the software programs before running, and the evaluation and optimization module dynamically evaluates the trust degree of the hardware devices and the software programs.

[0035] The security management center, the hardware security protection module and the software security protection module cooperatively perform dynamic data encryption transmission.

[0036] The security management center, the software security protection module and the evaluation and optimization module cooperatively perform dynamic intrusion detection and response.

[0037] The security management center and the evaluation and optimization module cooperatively perform security cooperative protection.

[0038] Further,

[0039] The hardware security protection module cooperates with the security management center to authenticate the hardware devices accessing the system, the software security protection module cooperates with the security management center to dynamically authenticate the software programs before running, and the evaluation and optimization module dynamically evaluates the trust degree of the hardware devices and the software programs.

[0040] When the hardware device accesses the system, the hardware security protection module generates an authentication request through a physically unclonable function (PUF), and then the security management center uses an ECDH algorithm to perform key negotiation with the hardware device to obtain the identity information of the hardware device and perform verification.

[0041] Before the software program runs, the software security protection module calculates an initial behavior hash chain of the software program and compares it with pre-stored information of the security management center.

[0042] During the running of the hardware device and the software program, the security management center continuously monitors the behavior of the hardware device and the software program, and the evaluation and optimization module updates the trust degree in real time. If the trust degree is lower than a preset threshold, the identity authentication is performed again or the operation permission of the hardware device and the software program is limited.

[0043] Further,

[0044] The security management center, the hardware security protection module and the software security protection module cooperatively perform dynamic data encryption transmission, which includes:

[0045] The security management center dynamically selects an encryption algorithm and a key according to the data type of the data to be sent by a data sending end, a transmission environment and a trust degree of a receiving end.

[0046] During the data transmission process, the hardware security protection module and the software security protection module cooperatively perform layered encryption on the data.

[0047] After the receiving end receives the data, the data is decrypted according to the encryption strategy of the sending end obtained from the security management center and the negotiation key, and the data integrity is checked.

[0048] Further,

[0049] The dynamic intrusion detection and response through the cooperation of the security management center, the software security protection module and the evaluation and optimization module comprises:

[0050] The software security protection module collects system running data in real time, learns the normal behavior mode of the system through the long short-term memory network (LSTM) algorithm, and constructs a behavior baseline;

[0051] When it is detected that the data deviates from the behavior baseline, the software security protection module judges whether it is an intrusion behavior in combination with the dynamic trust evaluation result of the evaluation and optimization module;

[0052] If the intrusion is confirmed, the software security protection module automatically generates a response strategy, and reports the intrusion event to the security management center, and the security management center updates the security strategy and records the audit log.

[0053] Further,

[0054] The security collaborative protection through the cooperation of the security management center and the evaluation and optimization module comprises:

[0055] The running state and data interaction of the edge computing node are monitored in real time through the evaluation and optimization module;

[0056] When a security threat is detected, the evaluation and optimization module transmits the threat information to the security management center after encryption processing;

[0057] The security management center generates a security strategy according to the threat type, and issues the security strategy to the edge computing node through a security collaborative protocol, so that the edge computing node and the security management center realize security collaborative protection.

[0058] Compared with the prior art, the present application has the following beneficial effects:

[0059] 1. The security protection capability is enhanced: through the deep cooperation of software and hardware, dynamic trust evaluation and edge computing security optimization, a comprehensive and multi-level security protection system is constructed, new attacks and unknown threats are effectively resisted, and the overall security of the system is improved;

[0060] 2. Adaptive dynamic protection: based on real-time security situation awareness and dynamic trust evaluation, the automatic adjustment and optimization of the security strategy are realized, so that the system can quickly adapt to the changing security environment, and the timeliness and effectiveness of the protection are improved;

[0061] 3. Efficient resource utilization: Given the resource-constrained nature of edge computing nodes, lightweight security protection techniques and optimization algorithms are employed to reduce computational and storage resource consumption while ensuring security, thereby improving the operational efficiency of edge computing nodes;

[0062] 4. Precise intrusion detection and response: Using LSTM algorithms and evidence theory, precise intrusion detection and dynamic response are achieved, reducing false positive and false negative rates, shortening attack response time, and reducing losses caused by security incidents;

[0063] 5. Comprehensive security audit and situation analysis: Through comprehensive audit and in-depth analysis of security incidents, intuitive security situation analysis reports are generated to provide decision support for security managers, helping to identify potential security risks in advance and take preventive measures.

[0064] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the application. The objects and other advantages of the present application can be realized and attained by the structure particularly pointed out in the description, claims, and drawings.

[0065] The present application will be further described below with reference to the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS

[0066] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.

[0067] Figure 1 The structure diagram of the security protection system applied to the control system according to an embodiment of the present application;

[0068] Figure 2 The specific structure diagram of the security protection system applied to the control system according to an embodiment of the present application;

[0069] Figure 3 The flowchart of the security protection method applied to the control system according to an embodiment of the present application;

[0070] Figure 4 The schematic diagram of the security protection mechanism based on the security protection system according to an embodiment of the present application. DETAILED DESCRIPTION

[0071] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0072] like Figure 1 As shown, the first embodiment of the present invention provides a safety protection system applied to a control system, the safety protection system comprising:

[0073] Hardware security protection module, used for hardware identity authentication and hardware protection, high-speed data encryption, building hardware firewalls and traffic control;

[0074] Software security protection module, used to implement dynamic authentication and abnormal behavior detection of software programs, as well as software encryption and code protection, and software intrusion detection and automatic generation of response strategies;

[0075] The Security Management Center is used to centrally manage authentication policies and key management for hardware devices and software programs. It is also used for dynamic policy management to achieve dynamic adaptive optimization of security policies. It is also used to monitor the operating status of hardware devices and software programs in real time and conduct audit management.

[0076] The evaluation and optimization module is used to build a multi-dimensional trust evaluation model to dynamically evaluate the trust of hardware devices and software programs, and is also used for edge computing security optimization.

[0077] The above technical solution utilizes a hardware security protection module, a software security protection module, a security management center, and an evaluation and optimization module. By building a security protection system that deeply collaborates with both software and hardware, and introducing dynamic trust assessment and edge computing security optimization technologies, it achieves full-lifecycle, adaptive security protection for control systems, improving the system's security, reliability, and anti-attack capabilities, and ensuring the stable operation of control systems in complex network environments. The above technical solution effectively provides a control system security protection mechanism that combines software and hardware, effectively resolving issues inherent in traditional protection methods, such as software and hardware separation, static protection, and an inability to adapt to dynamic attacks.

[0078] The following combination Figure 2 The specific components of the hardware security protection module, software security protection module, security management center, and evaluation and optimization module are further explained.

[0079] As a preferred technical solution, Figure 2As shown, the hardware security protection module includes a hardware identity authentication and protection unit, a hardware encryption acceleration unit and a hardware firewall and traffic control unit; the hardware identity authentication and protection unit is configured to perform hardware identity authentication based on a physically unclonable function (PUF), configure an authentication key for each hardware device, and simultaneously integrate a hardware attack detection sensor to monitor abnormalities in real time, and when a physical attack is detected, trigger a device self-destruction or isolation mechanism; the hardware encryption acceleration unit is configured to use an encryption chip and integrate an encryption algorithm to perform high-speed encryption processing on data, and optimize edge computing nodes using a lightweight encryption algorithm; and the hardware firewall and traffic control unit is configured to implement a programmable hardware firewall based on a field programmable gate array (FPGA), and perform data packet filtering and traffic behavior analysis and processing.

[0080] The various units of the hardware security protection module are further described below.

[0081] Hardware identity authentication and protection unit: a hardware identity authentication technology based on a physically unclonable function (PUF) is used, and each hardware device has a unique authentication key generated based on physical characteristics. A hardware attack detection sensor is integrated to monitor abnormalities such as voltage and electromagnetic radiation in real time, and when a physical attack is detected, a device self-destruction or isolation mechanism is triggered.

[0082] Hardware encryption acceleration unit: a dedicated encryption chip is used, and a national encryption SM4 symmetric encryption algorithm and an SM2 asymmetric encryption algorithm are integrated to perform high-speed encryption processing on data. For edge computing nodes, a lightweight encryption algorithm optimization scheme is used to reduce the consumption of computing resources while ensuring security.

[0083] Hardware firewall and traffic control unit: a programmable hardware firewall is implemented based on a field programmable gate array (FPGA), and in addition to the traditional data packet filtering function, a traffic behavior analysis module is added to monitor the rate, protocol distribution and other characteristics of network traffic in real time, and to block and limit abnormal traffic.

[0084] As a preferred technical solution, as Figure 2As shown, the software security protection module includes a software dynamic authentication and protection unit, a software encryption and code protection unit, and a software intrusion detection and response unit; the software dynamic authentication and protection unit is configured to perform hash calculation on software behavior using a hash chain, form a dynamic behavior hash chain, and compare the dynamic behavior hash chain with a normal behavior hash chain pre-stored in a security management center to perform dynamic authentication and abnormal behavior detection on the software program; the software encryption and code protection unit is configured to perform virtualization processing on software key code and dynamically key encrypt sensitive data generated during software running, and the key is updated in real time according to the running state of the control system; the software intrusion detection and response unit is configured to construct an intrusion detection model based on a long short-term memory (LSTM) algorithm to realize dynamic detection of new attacks, and automatically generate a response strategy when an intrusion behavior is detected.

[0085] The various units of the software security protection module are further described below.

[0086] Software dynamic authentication and protection unit: introduce software behavior hash chain technology, perform hash calculation on system calls, file access, and other behaviors during software program running to form a dynamic behavior hash chain. By comparing with the normal behavior hash chain pre-stored in the security management center, dynamic authentication and abnormal behavior detection of the software program are realized.

[0087] Software encryption and code protection unit: use code virtualization technology to perform virtualization processing on software key code to increase the difficulty of reverse analysis; use dynamic key encryption technology to encrypt sensitive data generated during software running, and the key is updated in real time according to the system running state.

[0088] Software intrusion detection and response unit: construct an intrusion detection model based on a machine learning algorithm, combine real-time collected system logs, network traffic, and other data, learn the normal behavior pattern of the system through a long short-term memory (LSTM) algorithm, realize dynamic detection of new attacks, and automatically generate a response strategy such as process isolation, network connection blocking, etc. when an intrusion behavior is detected.

[0089] As a preferred technical solution, as Figure 2As shown, the security management center includes an authentication and key management module, a policy dynamic management module, and a monitoring and audit management module; the authentication and key management module is configured to uniformly manage authentication policies of hardware devices and software programs, to implement key negotiation and distribution using an ECDH algorithm, and to perform full-life-cycle management of keys, including key generation, storage, updating, and destruction; the policy dynamic management module is configured to adjust hardware firewall policies, software protection policies, and intrusion detection policies in real time according to a running state of the control system, security threat intelligence, and dynamic trust evaluation results, to achieve dynamic adaptive optimization of security policies; and the monitoring and audit management module is configured to monitor running states of hardware devices and software programs in real time, to audit and record security events, and to perform deep mining of audit logs through correlation analysis to generate a security posture analysis report.

[0090] The various modules of the security management center are described in further detail below.

[0091] The authentication and key management module is configured to uniformly manage authentication policies of hardware devices and software programs, to implement key negotiation and distribution using an elliptic curve Diffie-Hellman (ECDH) algorithm, and to ensure security of key transmission; and to perform full-life-cycle management of system keys, including key generation, storage, updating, and destruction.

[0092] The policy dynamic management module is configured to adjust hardware firewall policies, software protection policies, and intrusion detection policies in real time according to a running state of the control system, security threat intelligence, and dynamic trust evaluation results, to achieve dynamic adaptive optimization of security policies.

[0093] The monitoring and audit management module is configured to monitor running states of hardware devices and software programs in real time, to audit and record security events, and to perform deep mining of audit logs through correlation analysis to generate a security posture analysis report.

[0094] As a preferred technical solution, as shown in Figure 2 The evaluation and optimization module includes a dynamic trust evaluation unit and an edge computing security optimization unit; the dynamic trust evaluation unit is configured to construct a multi-dimensional trust evaluation model, to dynamically evaluate trust degrees of hardware devices and software programs using evidence theory from three dimensions of device identity legitimacy, historical security records, and current behavior compliance; and the edge computing security optimization unit is configured to deploy lightweight security protection components, including edge intrusion detection agents and edge encryption gateways, at edge computing nodes, and to implement secure data interaction and policy synchronization between the edge computing nodes and the security management center through a security coordination protocol.

[0095] The various units of the evaluation and optimization module are described in further detail below.

[0096] Dynamic Trust Assessment Unit: Builds a multi-dimensional trust assessment model, using evidence theory (DS theory) to dynamically assess the trust of devices and software from dimensions such as device identity legitimacy, historical security records, and current behavior compliance. The trust calculation formula is as follows:

[0097] T=ω1×I+ω2×H+ω3×B

[0098] Among them, T is the comprehensive trust, I is the identity authentication score, H is the historical security record score, B is the current behavior compliance score, ω1, ω2, and ω3 are the weight coefficients of each dimension, and ω1+ω2+ω3=1.

[0099] Edge Computing Security Optimization Unit: This unit deploys lightweight security protection components, including edge intrusion detection agents and edge encryption gateways, at edge computing nodes. It uses a secure collaboration protocol to enable secure data exchange and policy synchronization between edge computing nodes and central systems, ensuring data security and system stability in edge computing environments.

[0100] like Figure 3 As shown, the second embodiment of the present invention provides a security protection method applied to a control system. Based on the security protection system applied to a control system as described above, the method includes the following steps:

[0101] S1. The hardware security protection module collaborates with the security management center to authenticate the hardware devices connected to the system. The software security protection module collaborates with the security management center to dynamically authenticate software programs before they are run. The evaluation and optimization module dynamically evaluates the trustworthiness of hardware devices and software programs.

[0102] S2, dynamic data encryption transmission is carried out through the collaboration of the security management center, hardware security protection module and software security protection module;

[0103] S3, through the collaboration of the security management center, software security protection module, and assessment and optimization module, dynamic intrusion detection and response;

[0104] S4. Collaborative security protection is carried out through the security management center and the assessment and optimization modules.

[0105] As a preferred technical solution, the step S1 comprises: when the hardware device accesses the system, the hardware security protection module first generates an authentication request through a physical unclonable function (PUF), then the security management center uses an ECDH algorithm to perform key negotiation with the hardware device, and obtains the identity information of the hardware device and performs verification; before the software program runs, the software security protection module calculates an initial behavior hash chain of the software program, and compares the initial behavior hash chain with pre-stored information of the security management center; during the running of the hardware device and the software program, the behavior of the hardware device and the software program is continuously monitored by the security management center, and the trust degree is updated in real time by the evaluation and optimization module, and if the trust degree is lower than a preset threshold, identity authentication is performed again or the operation permission of the hardware device and the software program is limited.

[0106] The embodiment gives a dynamic identity authentication process, and the dynamic identity authentication process is further described below.

[0107] When the hardware device accesses the system, the hardware identity authentication and protection unit first generates an authentication request through a PUF, the security management center uses an ECDH algorithm to perform key negotiation with the device, and obtains the identity information of the device and performs verification. Meanwhile, before the software program runs, the software dynamic authentication and protection unit calculates an initial behavior hash chain of the software program, and compares the initial behavior hash chain with pre-stored information of the security management center. During the running of the device and the software, the behavior of the device and the software is continuously monitored, and the trust degree is updated in real time by the dynamic trust evaluation unit, and if the trust degree is lower than a threshold, identity authentication is performed again or the operation permission of the device and the software is limited.

[0108] The dynamic identity authentication process solves the problem of soft and hardware collaborative security authentication, overcomes the problem of illegal device access and malicious software running caused by the separation of traditional hardware device and software program authentication, and realizes bidirectional dynamic security authentication between the hardware device and the software program.

[0109] As a preferred technical solution, the step S2 comprises: the security management center dynamically selects an encryption algorithm and a key according to a data type of data to be sent by a data sending end, a transmission environment and a trust degree of a receiving end; during data transmission, the hardware security protection module and the software security protection module work collaboratively to perform layered encryption on the data; after the receiving end receives the data, the receiving end performs decryption according to an encryption strategy and a negotiation key of the sending end obtained from the security management center, and performs verification on the data integrity.

[0110] The embodiment gives a dynamic data encryption transmission process, and the dynamic data encryption transmission process is further described below.

[0111] The data sending end dynamically selects an encryption algorithm and a key from the security management center according to a data type, a transmission environment and a trust degree of a receiving party. In a data transmission process, a hardware encryption acceleration unit and a software encryption and code protection unit work cooperatively to perform layered encryption on the data. After receiving the data, the receiving end decrypts the data according to an encryption strategy and a negotiation key of the sending end, and checks the data integrity, using a Hash Message Authentication Code (HMAC) algorithm, as follows:

[0112]

[0113] wherein K is a key, M is a message, H is a hash function, ipad and opad are fixed padding values.

[0114] The dynamic data encryption and transmission process solves the dynamic data encryption and transmission security problem, breaks through the limitation of a static encryption algorithm in a complex network environment, realizes dynamic adaptive adjustment of a data encryption strategy, guarantees the security and integrity of data in a transmission and storage process, and resists threats such as flow analysis and man-in-the-middle attacks.

[0115] As an optimal technical solution, the step S3 comprises: the software security protection module collects system running data in real time, learns a normal behavior pattern of the system through a long short-term memory network (LSTM) algorithm, and constructs a behavior baseline; when it is detected that data deviates from the behavior baseline, the software security protection module judges whether it is an intrusion behavior in combination with a dynamic trust evaluation result of the evaluation and optimization module; if the intrusion is confirmed, the software security protection module automatically generates a response strategy, and reports the intrusion event to the security management center, and the security management center updates a security strategy and records an audit log.

[0116] The embodiment gives a dynamic intrusion detection and response process, and the dynamic intrusion detection and response process is further described below.

[0117] The software intrusion detection and response unit collects system running data in real time, learns a normal behavior pattern of the system through an LSTM algorithm, and constructs a behavior baseline. When it is detected that data deviates from the behavior baseline, a judgment is made on whether it is an intrusion behavior in combination with a dynamic trust evaluation result. If the intrusion is confirmed, the intrusion detection unit automatically generates a response strategy, such as isolating an infected process and blocking a network connection of an attack source, and reports the intrusion event to the security management center, and the security management center updates a security strategy and records an audit log.

[0118] The dynamic intrusion detection and response process solves the real-time dynamic intrusion detection and response problem, overcomes the defects of a traditional intrusion detection that relies on a static feature library and cannot respond to new attacks in time, establishes an intrusion detection mechanism based on dynamic trust evaluation and behavior pattern analysis, and realizes real-time and accurate detection and rapid response to intrusion behaviors.

[0119] The algorithm formula of the LSTM algorithm is further given below.

[0120] LSTM-based intrusion detection algorithm: The LSTM network controls the transmission of information through the forget gate, input gate, and output gate. Its core calculation formula is as follows:

[0121] Forget Gate:

[0122] f t =σ(W f *[h t-1 , x t ]+b f )

[0123] Input Gate:

[0124] i t =σ(W i *[h t-1 , x t ]+b i )

[0125] Status Update:

[0126]

[0127] Output Gate:

[0128] o t =σ(W o *[h t-1 , x t ]+b o )

[0129] h t =o t *tanh(C t )

[0130] Among them, f t 、i t 、o t are the outputs of the forget gate, input gate, and output gate respectively, C t is the state, h t is the hidden layer output, σ is the Sigmoid function, tanh is the hyperbolic tangent function, W is the weight matrix, and b is the bias vector.

[0131] As a preferred technical solution, step S4 includes: real-time monitoring of the operating status and data interaction of the edge computing node through the evaluation and optimization module; when a security threat is detected, the evaluation and optimization module encrypts the threat information and transmits it to the security management center; the security management center generates a security policy based on the threat type, and sends it to the edge computing node through the security collaboration protocol, thereby realizing security collaborative protection between the edge computing node and the security management center.

[0132] This embodiment provides an edge computing security collaboration process, which is further explained below.

[0133] Lightweight security protection components deployed on edge computing nodes monitor node operating status and data interaction in real time. When a security threat is detected, the edge intrusion detection agent reports the threat information to the edge encryption gateway, which encrypts the data and transmits it to the central system (i.e., the security management center). The central system generates a security policy based on the threat type and distributes it to the edge computing node via a security collaboration protocol, enabling collaborative security protection between the edge computing node and the central system.

[0134] By adopting the above-mentioned edge computing security collaboration process, the security protection problem in the edge computing environment is well solved, the problem of limited resources and weak security protection of edge computing nodes is solved, the edge computing security architecture is optimized, and the security collaborative protection of edge computing nodes and central systems is realized.

[0135] Regarding the method in the above embodiment, the specific manner in which each unit or module performs the operation has been described in detail in the embodiment of the system and will not be elaborated here.

[0136] like Figure 4 As shown, an embodiment of the present invention further provides a schematic diagram of a security protection mechanism based on the aforementioned security protection system applied to a control system. Figure 4 The system architecture of the entire security protection mechanism is demonstrated, including the hardware security protection module, software security protection module, security management center, and dynamic trust assessment and edge computing security optimization module (the aforementioned assessment and optimization module). Each module interacts with each other and collaborates through secure communication interfaces, intuitively presenting the composition and interrelationships of the system's various components. Figure 4 The safety management and early warning center is the aforementioned safety management center.

[0137] In several embodiments provided in the present application, it should be understood that the disclosed system and method can be implemented in other manners. For example, the division of the system embodiments described above is merely a logical division, and there can be other division manners in actual implementation. For example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the modules shown or discussed can be indirect coupling or communication connection through some interfaces, and can be electrical, mechanical or other forms.

[0138] The modules described as separated components can or can not be physically separated, and the components shown as modules can or can not be physical modules, i.e., can be located in one place, or can be distributed on a plurality of network modules. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments. In addition, the functional modules in each embodiment of the present application can be integrated in one processing module, or each module can be physically present alone, or two or more modules can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software function module.

[0139] The integrated module, if realized in the form of a software function module and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0140] It should be noted that, for the foregoing method embodiments, in order to facilitate description, they are all described as a series of action combinations, but those skilled in the art should know that the present application is not limited by the order of the described actions, because according to the present application, some steps can be performed in other orders or at the same time. In addition, those skilled in the art should know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily all the essential actions of the present application.

[0141] In the above-mentioned embodiments, the description of each embodiment is focused on, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0142] The parts not involved in the above-mentioned embodiments are the same as or can be realized by the prior art, and will not be described further.

[0143] Although the present application has been described in detail with reference to the foregoing embodiments, it should be understood by those skilled in the art that the technical solutions recorded in the foregoing embodiments can still be modified, or some technical features can be replaced by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A safety protection system applied to a control system, characterized in that: The safety protection system includes: Hardware security protection module, used for hardware identity authentication and hardware protection, high-speed data encryption, building hardware firewalls and traffic control; Software security protection module, used to implement dynamic authentication and abnormal behavior detection of software programs, as well as software encryption and code protection, and software intrusion detection and automatic generation of response strategies; The Security Management Center is used to centrally manage authentication policies and key management for hardware devices and software programs. It is also used for dynamic policy management to achieve dynamic adaptive optimization of security policies. It is also used to monitor the operating status of hardware devices and software programs in real time and conduct audit management. The evaluation and optimization module is used to build a multi-dimensional trust evaluation model to dynamically evaluate the trust of hardware devices and software programs, and is also used for edge computing security optimization.

2. A safety protection system for a control system according to claim 1, characterized in that: The hardware security protection module includes a hardware identity authentication and protection unit, a hardware encryption acceleration unit, and a hardware firewall and traffic control unit; The hardware authentication and protection unit is used to perform hardware authentication based on the physically unclonable function (PUF), configure an authentication key for each hardware device, and integrate a hardware attack detection sensor to monitor anomalies in real time. When a physical attack is detected, it triggers a device self-destruction or isolation mechanism; The hardware encryption acceleration unit is used to use an encryption chip and an integrated encryption algorithm to perform high-speed encryption processing on data, and optimize the edge computing node using a lightweight encryption algorithm; The hardware firewall and traffic control unit is used to implement a programmable hardware firewall based on a field programmable gate array (FPGA), and perform data packet filtering and traffic behavior analysis and processing.

3. The safety protection system for control systems according to claim 1, characterized in that: The software security protection module includes a software dynamic authentication and protection unit, a software encryption and code protection unit, and a software intrusion detection and response unit; The software dynamic authentication and protection unit is used to perform hash calculation on the software behavior using a hash chain to form a dynamic behavior hash chain, and dynamically authenticate the software program and detect abnormal behavior by comparing it with the normal behavior hash chain pre-stored in the security management center; The software encryption and code protection unit is used to virtualize the key software code and perform dynamic key encryption on the sensitive data generated during the software operation. The key is updated in real time according to the operating status of the control system; The software intrusion detection and response unit is used to build an intrusion detection model based on the long short-term memory network (LSTM) algorithm to achieve dynamic detection of new attacks and automatically generate a response strategy when an intrusion behavior is detected.

4. The safety protection system for control systems according to claim 1, characterized in that: The security management center includes an authentication and key management module, a policy dynamic management module, and a monitoring and audit management module; The authentication and key management module is used to uniformly manage the authentication strategies of hardware devices and software programs, implement key negotiation and distribution using the ECDH algorithm, and manage the keys throughout their lifecycle, including key generation, storage, update, and destruction. The policy dynamic management module is used to adjust the hardware firewall policy, software protection policy and intrusion detection policy in real time according to the operating status of the control system, security threat intelligence and dynamic trust assessment results, so as to achieve dynamic adaptive optimization of security policy; The monitoring and audit management module is used to monitor the operating status of hardware devices and software programs in real time, audit and record security events, and conduct in-depth mining of audit logs through correlation analysis to generate security situation analysis reports.

5. The safety protection system for control systems according to claim 1, characterized in that: The evaluation and optimization module includes a dynamic trust evaluation unit and an edge computing security optimization unit; The dynamic trust evaluation unit is used to build a multi-dimensional trust evaluation model, using evidence theory to dynamically evaluate the trust of hardware devices and software programs from three dimensions: device identity legitimacy, historical security records, and current behavior compliance; The edge computing security optimization unit is used to deploy lightweight security protection components on edge computing nodes. The lightweight security protection components include edge intrusion detection agents and edge encryption gateways. They are also used to realize security data interaction and policy synchronization between edge computing nodes and security management centers through security collaboration protocols.

6. A safety protection method for a control system, based on the safety protection system for a control system according to any one of claims 1 to 5, characterized in that: The method comprises: The hardware security protection module collaborates with the security management center to authenticate the hardware devices connected to the system. The software security protection module collaborates with the security management center to dynamically authenticate software programs before they are run. The evaluation and optimization module also dynamically evaluates the trustworthiness of hardware devices and software programs. Dynamic data encryption transmission is performed through the collaboration of the security management center, hardware security protection module, and software security protection module; Dynamic intrusion detection and response are carried out through the collaboration of the security management center, software security protection module, and assessment and optimization module; Collaborative security protection is achieved through the security management center and the assessment and optimization modules.

7. A safety protection method for a control system according to claim 6, characterized in that: The hardware security protection module and the security management center collaborate to authenticate the hardware devices connected to the system, the software security protection module and the security management center collaborate to dynamically authenticate the software programs before they are run, and the evaluation and optimization module dynamically evaluates the trustworthiness of the hardware devices and software programs, including: When a hardware device is connected to the system, the hardware security protection module first generates an authentication request using the physical unclonable function (PUF). The security management center then uses the ECDH algorithm to negotiate a key with the hardware device, obtain the hardware device's identity information, and verify it. Before the software program runs, the software security protection module calculates its initial behavior hash chain and compares it with the pre-stored information of the security management center; During the operation of hardware devices and software programs, their behavior is continuously monitored through the security management center, and the trust level is updated in real time through the evaluation and optimization module. If the trust level is lower than the preset threshold, identity authentication is performed again or the operating permissions are restricted.

8. The safety protection method for a control system according to claim 6, characterized in that: The dynamic data encryption transmission by the collaboration of the security management center, the hardware security protection module and the software security protection module includes: The security management center dynamically selects encryption algorithms and keys based on the data type, transmission environment, and trustworthiness of the data to be sent by the data sender. During data transmission, the hardware security protection module and the software security protection module work together to perform layered encryption on the data; After receiving the data, the receiving end decrypts it according to the encryption policy and negotiated key of the sending end obtained from the security management center, and verifies the data integrity at the same time.

9. The safety protection method for a control system according to claim 6, characterized in that: The dynamic intrusion detection and response is performed through the collaboration of the security management center, the software security protection module, and the evaluation and optimization module, including: The software security protection module collects system operation data in real time and uses the long short-term memory network (LSTM) algorithm to learn the system's normal behavior patterns and build a behavior baseline. When data is detected to deviate from the behavioral baseline, the software security protection module will combine the dynamic trust assessment results of the evaluation and optimization module to determine whether it is an intrusion behavior; If an intrusion is confirmed, the software security protection module automatically generates a response strategy and reports the intrusion event to the security management center, which then updates the security strategy and records the audit log.

10. The safety protection method for a control system according to claim 6, characterized in that: The collaborative security protection through the security management center and the assessment and optimization module includes: The evaluation and optimization module monitors the operating status and data interaction of edge computing nodes in real time; When a security threat is detected, the assessment and optimization module encrypts the threat information and transmits it to the security management center; The security management center generates security policies based on threat types and sends them to edge computing nodes through security collaboration protocols, thus achieving collaborative security protection between edge computing nodes and the security management center.

Citation Information

Patent Citations

  • Power distribution Internet of Things edge Internet of Things proxy network security protection method and system

    CN114584331A

  • Industrial personal computer hardware security module integration method and system

    CN118842576A

  • Security authentication method and system of Internet of Things equipment, medium and equipment

    CN119484161A

  • Industrial control system safety protection algorithm design method

    CN119576288A

  • Security protection method for remote code injection prevention of industrial software

    CN120105405A