PLC behavior measurement method, device and equipment based on trusted 3.0 and national secret algorithm

CN120871729BActive Publication Date: 2026-08-21NINGBO HOLLYSHI INFORMATION SECURITY RES INST CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511005135.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-21
Publication Date
2026-08-21
Estimated Expiration
2045-07-21

AI Technical Summary

Technical Problem

[0003]1、网络攻击升级:针对PLC的恶意代码注入、中间人攻击、数据篡改等威胁加剧

Benefits of technology

[0055]The beneficial effects of the technical solution provided by this invention are as follows: First, the PLC controller in this embodiment is equipped with a hardware root of trust module, which is built based on the Trusted Computing 3.0 standard, thereby enabling trusted verification of the PLC controller during startup. Second, this invention uses a behavior measurement method based on the Trusted Computing 3.0 standard to measure the behavior of the PLC controller during operation, thus enabling real-time monitoring of the entire trust chain from startup to operation. Third, this invention uses a national cryptographic algorithm to encrypt and transmit the behavior measurement results to the security management platform. By combining the national cryptographic algorithm with the Trusted Computing 3.0 standard, it can resist complex attacks on the operational state. This invention can enhance equipment security and resistance to attacks, meeting the requirements of high security and low latency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120871729B_ABST
    Figure CN120871729B_ABST
Patent Text Reader

Abstract

The application discloses a PLC behavior measurement method, device and equipment based on trusted 3.0 and national secret algorithm, relates to the safety control field in an industrial control system, and comprises the following steps: performing trusted verification on a PLC controller at startup by using a hardware root of trust module pre-installed in the PLC controller, wherein the module is constructed based on a trusted computing 3.0 standard; after verification succeeds, obtaining a behavior feature vector of a PLC running state based on the trusted computing 3.0, wherein the vector comprises at least one of an integrity verification parameter, a resource consumption parameter, an operation parameter and a correlation parameter; generating behavior measurement data based on the trusted computing 3.0, and measuring the vector by using an Euclidean distance algorithm in combination with behavior baseline data; comparing the measurement result with a preset Euclidean distance threshold value, and transmitting the measurement result and the comparison result to a safety management platform by using a domestic key algorithm for encryption; and the application combines the trusted computing 3.0 (TC3.0) and the national secret algorithm, performs accurate behavior measurement on a running state, and can enhance the safety and attack resistance of equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of safety control technology in industrial control systems, and specifically relates to a PLC behavior measurement method, device and equipment based on Trusted 3.0 and national cryptographic algorithms. Background Technology

[0002] In industrial control systems (ICS), the PLC is a core control device, and its operational safety directly affects the stability of industrial production. Currently, PLCs face the following threats:

[0003] 1. Elevated cyberattacks: Threats such as malicious code injection, man-in-the-middle attacks, and data tampering targeting PLCs have intensified.

[0004] 2. Inadequate traditional security measures: Static protection (such as firewalls) and passive encryption cannot achieve real-time monitoring during operation, and rely on international cryptographic algorithms (such as AES and RSA), which poses risks to independent control.

[0005] 3. The potential of trusted computing technology: Trusted Computing 3.0 (TC3.0) can enhance the inherent security of devices through technologies such as root of trust and dynamic measurement. However, existing technologies are mostly focused on the PC side and lack optimization and integration for PLC scenarios.

[0006] In Industrial Control Systems (ICS), the PLC controller is one of the core devices for achieving automated control. The operational safety and stability of the PLC controller directly affect the normal operation of the industrial system. With the upgrading of cyberattack methods, PLC control systems face increasingly complex threats. Traditional security measures struggle to achieve real-time monitoring and accurate measurement of operational status in the face of attacks, failing to meet the demands for high security and low latency. Foreign trusted computing technologies (such as TPM) rely on passive invocation mechanisms and cannot actively monitor the PLC's operational behavior. While some domestic patents employ Chinese cryptographic algorithms, they are not integrated with trusted computing, making them vulnerable to complex attacks targeting the PLC's operational state. For example, patent CN119254811A discloses a remote control system and method using Chinese cryptographic algorithms, employing SM2 / SM4 for remote control communication encryption and verifying key security via Bluetooth UKEY and server. While focusing on communication encryption and using the SM2 / SM4 algorithm, it lacks integration with trusted computing and does not address PLC operational behavior measurement. Similarly, patent CN118133298A discloses an industrial control data security protection system based on domestic cryptography, employing SM2 / SM3 / SM4 for industrial control data storage and communication encryption, and hierarchical key management. While using the SM2 / SM3 / SM2 algorithm, it lacks integration with trusted computing and a baseline mechanism for operational behavior. The patent with publication number CN118981776 A discloses a multi-type algorithm encryption method that separates the CPU from the encryption task through SRAM and controller module to improve the efficiency of the algorithm module; this patent focuses on encryption efficiency optimization and is not combined with trusted computing. Summary of the Invention

[0007] To address the aforementioned issues, this invention provides a PLC behavior measurement method, apparatus, and device based on Trusted Computing 3.0 (TC3.0) and national cryptographic algorithms. By combining Trusted Computing 3.0 (TC3.0) with national cryptographic algorithms, it enables precise behavior measurement of the operating state, thereby enhancing device security and resistance to attacks.

[0008] In a first aspect, the present invention provides a PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms, comprising:

[0009] The PLC controller is verified during startup using a hardware root of trust module pre-installed in the PLC controller; wherein the hardware root of trust module is built based on the Trusted Computing 3.0 standard.

[0010] In response to the successful verification of the hardware trust root module, the current behavior feature vector of the PLC controller in its current operating state is obtained based on the Trusted Computing 3.0 standard; wherein, the current behavior feature vector is a multi-dimensional trusted state of the PLC controller during operation generated based on the Trusted Computing 3.0 standard, and the current behavior feature vector includes one or more of the following: integrity verification parameters, resource consumption parameters, operation parameters, and correlation parameters;

[0011] Based on the Trusted Computing 3.0 standard, behavioral measurement data is generated according to the current behavioral feature vector. Based on the Trusted Computing 3.0 standard, the current behavioral measurement data is measured using pre-established behavioral baseline data and Euclidean distance algorithm to obtain the measurement result.

[0012] The measurement result is compared with the preset Euclidean distance threshold to obtain the comparison result;

[0013] The measurement results and comparison results are encrypted and transmitted to the security management platform using a domestically developed key algorithm.

[0014] In an optional embodiment, the step of encrypting and transmitting the measurement result and the comparison result to the security management platform using a domestically developed key algorithm includes:

[0015] The hash value of the current behavior feature vector is generated using the SM3 algorithm;

[0016] The behavioral measurement data is digitally signed using the SM2 algorithm;

[0017] The measurement results and comparison results are encrypted and stored using the SM4 algorithm, and then transmitted to the security management platform in an encrypted manner.

[0018] In an optional embodiment, behavioral baseline data is constructed using the following method:

[0019] Obtain the historical behavior feature vector of the PLC controller under normal operating conditions; wherein the parameter types of the historical behavior feature vector and the current behavior feature vector are the same; the integrity verification parameters include firmware hash value and application hash value; the resource consumption parameters include CPU load parameters, memory occupancy rate parameters, memory usage parameters, and network communication volume parameters; the operation parameters include control command response delay parameters and sensor feedback time parameters.

[0020] The behavioral baseline data corresponding to each type of parameter in the current behavioral feature vector is determined based on historical behavioral feature vectors and statistical algorithms; wherein, the behavioral baseline data includes a benchmark value and / or a threshold range; the behavioral baseline data corresponding to the resource consumption parameters is determined based on the resource consumption parameters in the historical behavioral feature vectors and combined with a sliding window mean algorithm and a standard deviation analysis algorithm; the behavioral baseline data corresponding to the operation parameters is determined based on the operation parameters in the historical behavioral feature vectors and combined with a time series analysis algorithm; and the behavioral baseline data corresponding to the correlation parameters is determined based on the execution rules between various different operation parameters in the historical behavioral feature vectors and combined with covariance analysis or mutual information entropy.

[0021] The determined behavioral baseline data is encrypted and stored in the hardware trust root module using the SM4 algorithm.

[0022] In an optional embodiment, the measurement of the current behavioral measurement data based on the Trusted Computing 3.0 standard and utilizing pre-established behavioral baseline data and the Euclidean distance algorithm to obtain the measurement result includes:

[0023] The Euclidean distance D between the target parameter in the current behavioral feature vector and the corresponding behavioral baseline data is determined according to the following formula (1):

[0024]

[0025] In equation (1), x i b represents the feature value of the target parameter in the current behavior feature vector; 0i This represents the baseline value corresponding to the target parameter, where n is a positive integer;

[0026] The method further includes:

[0027] The Euclidean distance of the operating parameters is corrected by introducing an environmental disturbance factor using the following equation (2):

[0028]

[0029] In equation (2), E i Indicates the environmental disturbance factor offset value; α i This represents the sensitivity coefficient of the operating parameters to environmental disturbance factors;

[0030] The Euclidean distance D has a distance threshold T0. The distance threshold T0 corresponding to the resource consumption parameters is updated by introducing the equipment aging factor H through the following formula (3):

[0031] T0′=T0+β× (1-H) (3)

[0032] In equation (3), T0′ represents the distance threshold corresponding to the updated resource consumption parameter; H represents the relative ratio of the device's performance in the current state to its performance in the new state, H∈[0,1]; β represents the maximum relaxation range when relaxing the device's performance in the new state.

[0033] Introduce a network communication delay factor to correct the behavioral baseline data corresponding to network traffic parameters;

[0034] A security policy conflict factor is introduced to correct the behavioral baseline data corresponding to the resource consumption parameters.

[0035] In an optional embodiment, obtaining the current behavioral feature vector of the PLC controller during operation includes:

[0036] A priority scheduling algorithm is used to execute a measurement task during the idle time slice of the PLC controller to ensure that the control instructions of the PLC controller are executed first. The idle time slice begins with an interrupt signal indicating that the control instruction has been completed, and the measurement task is paused when a new control instruction arrives.

[0037] A lightweight metric agent is used to sample and monitor the current behavior feature vector.

[0038] In an optional embodiment, after encrypting the measurement result and the comparison result using a domestic key algorithm and transmitting them encrypted to the security management platform, the method further includes:

[0039] When the comparison result is abnormal, a security response operation is performed, which includes one or more of the following: isolation operation, restart operation, and recovery operation.

[0040] An audit analysis is performed on the encrypted stored behavioral feature vectors, behavioral baseline data, and comparison results to obtain analysis results, and the behavioral baseline data is updated based on the analysis results.

[0041] In an optional embodiment, the lightweight metric agent used samples and monitors the current behavior feature vector, including:

[0042] Identify security-sensitive areas in the application's memory pages, including the program entry function segment, input / output communication buffers, and configuration areas for key parameters in the current behavior feature vector;

[0043] The application memory pages are divided into multiple page blocks;

[0044] Page blocks containing the security-sensitive area are extracted in rotation for integrity verification, and a hash algorithm is used to determine the verification value of the extracted page blocks.

[0045] In an optional embodiment, the method further includes:

[0046] The threshold range of the CPU load parameters is dynamically adjusted using a phased relaxation of the threshold upper limit strategy.

[0047] Secondly, the present invention provides a PLC behavior measurement device based on Trusted 3.0 and national cryptographic algorithms, comprising:

[0048] A root trust module is used to perform trusted verification of the PLC controller during startup using a hardware root trust module pre-installed in the PLC controller; wherein the hardware root trust module is built based on the Trusted Computing 3.0 standard;

[0049] The data acquisition module is used to acquire the current behavior feature vector of the PLC controller in the current operating state based on the Trusted Computing 3.0 standard in response to the successful verification of the hardware trust root module. The current behavior feature vector is a multi-dimensional trusted state of the PLC controller during operation generated based on the Trusted Computing 3.0 standard, and the current behavior feature vector includes one or more of the following: integrity verification parameters, resource consumption parameters, operation parameters, and correlation parameters.

[0050] The behavior measurement module is used to generate behavior measurement data based on the Trusted Computing 3.0 standard and the current behavior feature vector, and to measure the current behavior measurement data based on the Trusted Computing 3.0 standard and using pre-established behavior baseline data and Euclidean distance algorithm to obtain the measurement results.

[0051] The threshold comparison module is used to compare the measurement result with a preset Euclidean distance threshold to obtain a comparison result;

[0052] An encrypted transmission module is used to encrypt and transmit the measurement results and the comparison results to the security management platform using a domestically developed key algorithm.

[0053] Thirdly, the present invention provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method described in any of the foregoing embodiments.

[0054] Fourthly, the present invention provides a computer-readable medium having processor-executable non-volatile program code, the program code causing the processor to perform the method described in any of the foregoing embodiments.

[0055] The beneficial effects of the technical solution provided by this invention are as follows: First, the PLC controller in this embodiment is equipped with a hardware root of trust module, which is built based on the Trusted Computing 3.0 standard, thereby enabling trusted verification of the PLC controller during startup. Second, this invention uses a behavior measurement method based on the Trusted Computing 3.0 standard to measure the behavior of the PLC controller during operation, thus enabling real-time monitoring of the entire trust chain from startup to operation. Third, this invention uses a national cryptographic algorithm to encrypt and transmit the behavior measurement results to the security management platform. By combining the national cryptographic algorithm with the Trusted Computing 3.0 standard, it can resist complex attacks on the operational state. This invention can enhance equipment security and resistance to attacks, meeting the requirements of high security and low latency. Attached Figure Description

[0056] Figure 1 This is a flowchart illustrating the PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms provided in an embodiment of the present invention.

[0057] Figure 2 A schematic diagram illustrating the principle of establishing a PLC running state behavior baseline provided in an embodiment of the present invention;

[0058] Figure 3 This is a schematic diagram of the anomaly detection and response mechanism provided in an embodiment of the present invention;

[0059] Figure 4 This is a schematic diagram of the security response and audit mechanism provided in an embodiment of the present invention;

[0060] Figure 5 The schematic diagram of the PLC behavior measurement device based on Trusted 3.0 and national cryptographic algorithm provided in the embodiment of the present invention;

[0061] Figure 6 The schematic diagram of the PLC behavior measurement device based on Trusted 3.0 and national cryptographic algorithm provided in the embodiment of the present invention;

[0062] Figure 7 A system schematic diagram of an electronic device provided in an embodiment of the present invention.

[0063] In the diagram: 100 - Trust Root Module; 200 - Data Acquisition Module; 300 - Behavior Measurement Module; 400 - Threshold Comparison Module; 500 - Encrypted Transmission Module; 1000 - Electronic Device; 1001 - Communication Interface; 1002 - Processor; 1003 - Memory; 1004 - Bus. Detailed Implementation

[0064] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0065] Reference Figure 1 A PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithm includes the following steps S100 to S500.

[0066] Step S100: The hardware root of trust module pre-installed in the PLC controller is used to perform a trusted verification of the PLC controller at startup; wherein the hardware root of trust module is built based on the Trusted Computing 3.0 standard.

[0067] Here, the PLC controller is equipped with a hardware root of trust module built based on the Trusted Computing 3.0 standard. During the startup phase, the hardware root of trust module acts as the initial source of trust, ensuring that the PLC controller is in a trusted state from the start through hardware-level trust metrics (such as firmware hash verification). For example, when the PLC controller is powered on, the hardware root of trust module first verifies the integrity of the bootloader and operating system. If the hash value matches the pre-stored baseline value, startup is allowed; otherwise, a security alarm is triggered and the startup process is aborted.

[0068] During the PLC controller's operation, the hardware trust root module continuously extends the trust chain to the PLC controller's application, configuration files, and communication modules. Through dynamic behavior metrics (such as real-time hash calculation and memory status monitoring) in steps S200 to S500, the integrity of the runtime code and data is verified. All measurement results are signed and stored by the hardware trust root module to ensure immutability.

[0069] In this embodiment, the hardware root of trust module integrates Trusted Computing 3.0. In the dual-architecture of Trusted Computing 3.0, the hardware root of trust module acts as the "root of trust," supporting the "trusted execution environment" and "trusted connection." It achieves full lifecycle trusted verification of the PLC's runtime state through an active measurement mechanism. That is, the Trusted Computing 3.0 architecture in this embodiment establishes a trust chain through the hardware root of trust (i.e., the Trusted Platform Control Module, also known as the TPCM module), sequentially verifying the integrity of the bootloader, operating system kernel, and application.

[0070] In summary, this embodiment maintains the level of trust in the PLC controller's operational state by integrating a Trusted Computing 3.0 root module into the PLC controller to perform startup and behavior measurements.

[0071] In step S200, in response to the successful verification of the hardware trust root module, the current behavior feature vector of the PLC controller under the current operating state is obtained based on the Trusted Computing 3.0 standard. The current behavior feature vector is a multi-dimensional trusted state of the PLC controller under the operation generated based on the Trusted Computing 3.0 standard. The current behavior feature vector includes one or more of the following: integrity verification parameters, resource consumption parameters, operation parameters, and correlation parameters.

[0072] Step S100 verifies the integrity of the firmware and operating system of the PLC controller during startup using a hardware root trust module. Successful verification by the hardware root trust module proves the PLC controller is trustworthy during startup. Further, during the PLC controller's operation phase, the trustworthiness of the runtime data is measured using the Trusted Computing 3.0 standard and national cryptographic algorithms. By introducing a behavioral measurement mechanism and encryption algorithms compliant with national cryptographic standards, the security and anti-attack capabilities of the PLC controller are improved, enabling real-time and accurate measurement of the operational state. If the hardware root trust module verification fails, the PLC controller's startup process is terminated, and a trust report is sent to the security management platform.

[0073] The current behavior feature vector refers to the operational data of key objects of the PLC controller in the current state. These key objects are reflected in multiple dimensions, including current integrity verification data (including firmware integrity and application integrity, etc.), current system resource consumption data (such as CPU, memory, etc.), and current operation parameter data (such as operation delay, sensor feedback time, etc.).

[0074] Step S300: Generate behavioral measurement data based on the Trusted Computing 3.0 standard and the current behavioral feature vector; measure the current behavioral measurement data based on the Trusted Computing 3.0 standard and using pre-established behavioral baseline data and Euclidean distance algorithm to obtain the measurement result.

[0075] Step S400: Compare the measurement result with the preset Euclidean distance threshold to obtain the comparison result.

[0076] This embodiment provides a detailed introduction to the establishment of behavioral baseline data and the principles of behavioral measurement through a specific case.

[0077] For example, the target PLC controller is responsible for controlling the liquid filling process on the industrial production line, specifically including the following key operation steps (1) to (4).

[0078] (1) Start-up equipment check: After the control system is powered on, the PLC automatically checks the status of equipment such as pumps, valves, and sensors.

[0079] (2) Tank level monitoring: Real-time monitoring of the readings of the level sensor. When the level is lower than the set value, the filling pump is triggered to start.

[0080] (3) Liquid filling: According to the set formula and liquid level target, control the filling pump to pump the liquid to the target liquid level at a certain speed.

[0081] (4) Fault monitoring and alarm: During the filling process, sensor data is monitored in real time. If any abnormality occurs (such as liquid overflow, excessive pressure, etc.), an alarm is immediately triggered and filling is stopped.

[0082] During the baseline establishment process, for each business step and related operation, the normal behavior baseline data of the PLC controller is established step by step using the following steps (1) to (3):

[0083] Step (1) Obtain the historical behavior feature vector of the PLC controller under normal operating conditions; wherein, the parameter types of the historical behavior feature vector and the current behavior feature vector are the same; the integrity verification parameters include firmware hash value and application hash value; the resource consumption parameters include CPU load parameters, memory occupancy parameters, memory usage parameters and network communication parameters; the operation parameters include control command response delay parameters and sensor feedback time parameters.

[0084] Here, behavioral feature vectors collected multiple times under the same operating condition are used as historical behavioral feature vectors. These historical behavioral feature vectors are derived from historical data collected from the PLC controller. Referring to the current behavioral feature vector mentioned earlier, they are determined using the same principles as the behavioral feature vectors, i.e., the historical data is processed according to the Trusted Computing 3.0 standard and a predefined parameter order. The historical behavioral feature vectors include one or more of the following: integrity verification parameters, resource consumption parameters, operational parameters, and correlation parameters. The feature values ​​corresponding to these parameters are generated based on the historical data, and the feature values ​​in the current behavioral feature vector are generated according to the same parameter structure and order.

[0085] Integrity verification parameters include firmware hash value and application hash value. These two values ​​are used to verify the integrity of firmware and application. This embodiment adopts deterministic verification, calculates the hash value of the firmware of PLC controller and filling control application, and records the initial hash value of these data as the baseline value for verification.

[0086] Record and monitor the PLC controller's resource consumption data such as CPU utilization, memory usage, and network communication volume under normal filling tasks. These parameters are recorded within the value range under specific operating conditions to obtain CPU load parameters, memory utilization parameters, memory usage parameters, and network communication volume parameters.

[0087] The specific execution logic of operations such as liquid level monitoring, filling pump start-up, and alarm is recorded to obtain operation parameters. For example, historical data such as the response delay time after the PLC controller issues a pump start command and the valve opening and closing angle are recorded to obtain control command response delay parameters and sensor feedback time parameters.

[0088] Step (2): Determine the baseline data of behavior corresponding to each type of parameter in the current behavior feature vector based on the historical behavior feature vector and statistical algorithms; wherein, the baseline data of behavior includes the benchmark value and / or threshold range; determine the baseline data of behavior corresponding to the resource consumption parameter based on the resource consumption parameter in the historical behavior feature vector and combined with the sliding window mean algorithm and standard deviation analysis algorithm; determine the baseline data of behavior corresponding to the operation parameter based on the operation parameter in the historical behavior feature vector and combined with the time series analysis algorithm; determine the baseline data of behavior corresponding to the correlation parameter based on the execution rules between various different operation parameters in the historical behavior feature vector and combined with covariance analysis or mutual information entropy.

[0089] Here, each type of parameter is set with corresponding behavioral baseline data. The behavioral baseline data can be a threshold or a threshold range (e.g., [μ-kσ,μ+kσ], where μ is the expected value, σ is the standard deviation, and k is the confidence factor).

[0090] In this embodiment, based on the historical behavior feature vectors collected in step (1), statistical analysis is first performed to calculate the normal fluctuation range of the historical behavior feature vectors. For example, the sampling frequency, numerical stability, and start-up time of the filling pump of the liquid level sensor data are used as the reference range of the baseline parameters. Then, the behavior feature vectors are defined, that is, behavior feature vectors (such as firmware hash, CPU utilization, memory utilization, operation delay time, sensor feedback time, etc.) are established based on the collected historical behavior feature vectors.

[0091] Statistical methods are used to determine the baseline data for behavior characteristic vectors, that is, to specify the expected range for the parameters in each behavior characteristic vector. For example, the feedback value of a liquid level monitoring sensor should fluctuate within a specific numerical range, and the CPU load should typically remain around a certain percentage. Behaviors exceeding preset thresholds are marked as abnormal. Here, deterministic verification is used for integrity verification parameters such as firmware hash values, directly recording the initial hash value as the baseline value without statistical analysis. For historical resource consumption parameters and operational parameters, differentiated statistical methods are used to determine the baseline data for behavior. For example, for resource consumption parameters, the sliding window mean method and standard deviation analysis are used to dynamically calculate the resource usage range under normal operating conditions. For example, based on CPU utilization data within a time window, its mean μ and standard deviation σ are calculated, and a threshold of μ±3σ is set to cover 99.7% of normal fluctuations. For operational parameters, time series analysis (ARIMA model) is used to predict the time distribution characteristics of normal operation and set confidence intervals. For correlated parameters, such as the start-up of a filling pump and changes in liquid level, covariance analysis or mutual information entropy is used to quantify the correlation strength between parameters; if the correlation is lower than the threshold, it is considered abnormal.

[0092] Step (3) uses the SM4 algorithm to encrypt and store the determined behavioral baseline data in the hardware trust root module.

[0093] In one possible embodiment, refer to Figure 2 The steps for establishing behavioral baseline data may include the following steps S310 to S340.

[0094] Step S310: Collect multi-dimensional behavioral data (firmware hash, CPU resources, sensor data).

[0095] Step S320: Calculate the statistically normal range of fluctuation (calculate the mean, standard deviation, range of fluctuation, etc.).

[0096] Step S330: Define the behavior feature vector and specify the behavior threshold (generate feature vector, set anomaly threshold).

[0097] Step S340: Behavioral baseline data established.

[0098] Once the behavioral baseline data is established, the baseline hash value is signed using the SM3 algorithm and encrypted using the SM4 algorithm before being stored in the PLC's root of trust module (trusted computing module) to ensure that the baseline data is not tampered with during subsequent operation. A periodic update strategy is set to allow for the safe re-collection of behavioral baseline data based on changes in the actual operating environment (such as seasonal effects or production process adjustments).

[0099] The behavioral baseline data established through steps (1)-(3) above will serve as the comparison standard for operational behavior measurement (i.e., real-time measurement), enabling real-time safety monitoring and anomaly detection of the PLC during business operations. The principle of operational behavior measurement will be explained below.

[0100] During PLC controller operation, the operational status of key objects is continuously measured, generating real-time hash values ​​and feature data, which are then compared with behavioral baseline data. Assume the PLC controller's behavioral feature vector is B = [b1, b2, ..., bn], where each bi (i = 1, 2, ..., n) represents a measure of a certain behavior. The current behavioral feature vector is B0 = [b01, b02, ..., b0n] (measurement under normal conditions). When comparing the behavioral baseline data D = [d1, d2, ..., dn] with the behavioral baseline B0, the Euclidean distance D(B0, D) is used to measure the difference between them.

[0101] The Euclidean distance D between the target parameter in the current behavioral feature vector and the corresponding behavioral baseline data is determined according to the following formula (1):

[0102]

[0103] In equation (1), x i b represents the feature value of the target parameter in the current behavior feature vector; 0i This represents the baseline value corresponding to the target parameter, where n is a positive integer.

[0104] If the Euclidean distance D(B0,D) exceeds the preset distance threshold T0, it is determined to be abnormal behavior and an alarm is triggered.

[0105] When the behavior measurement module detects that the deviation between real-time measurement data and the behavior baseline exceeds a preset safety threshold, it determines that an anomaly has occurred, triggers an alarm, and records an event log. Simultaneously, the abnormal measurement data is sent to the safety management platform via an encrypted channel for further auditing and analysis. Based on this abnormal data, the safety management platform generates a safety response strategy and can issue commands to isolate, restart, or restore the PLC controller.

[0106] In one possible embodiment, refer to Figure 3 The anomaly detection and response mechanism may include the following steps S410 to S440.

[0107] Step S410: The current behavioral features are compared with the behavioral baseline data (data comparison, anomaly detection).

[0108] Step S420: An anomaly is detected, triggering an alarm (alarm notification, anomaly identifier).

[0109] Step S430: Perform isolation (isolation, restart, logging, etc.) through the security response mechanism.

[0110] Step S440: Safety response measures completed.

[0111] The setting of the distance threshold T0 will be explained below through an example.

[0112] For example, in a liquid filling production line scenario, the parameters of the behavioral feature vector include: firmware hash value, CPU utilization parameter (unit: %), memory usage parameter (unit: MB), pump start command delay time (operation parameter, unit: ms), and liquid level change rate (operation parameter, unit: L / s). The baseline value, current value, and difference of each parameter are shown in Table 1.

[0113] Table 1

[0114] CPU utilization 45% 70% 25 Memory usage 300MB 350MB 50 Pump start-up delay 150ms 500ms 350 Liquid level change rate 1.5L / s 0.2L / s 1.3

[0115] Calculate the Euclidean distance value based on the data in Table 1: When setting the threshold, considering that the Euclidean distance D within the normal operating fluctuation range generally does not exceed 100, the threshold T0 of D is set to 200 (considering normal operating conditions, load changes, and external disturbances). However, the Euclidean distance in the table above is 353.63, which is greater than 200, therefore the liquid filling production line is abnormal.

[0116] For example, in power automation protection scenarios, the parameters of the behavioral feature vector include: interrupt response time (μs), message transmission frequency (Hz), memory utilization (%), and power current acquisition delay (ms). Under normal operation, the response time varies very little, fluctuating within ±10μs; the message frequency remains within ±2Hz. Therefore, the distance threshold T0 is set to 30–50 (more stringent). These scenarios have extremely high requirements for time accuracy and real-time performance; therefore, the value of the distance threshold T0 should be significantly smaller than that of liquid filling scenarios.

[0117] For example, in a chemical process control scenario (high-risk scenario), the parameters of the behavioral feature vector include: valve opening / closing angle error (unit: °), pressure feedback delay (unit: ms), temperature fluctuation rate (unit: °C / min), and safety command response time (unit: ms). Under normal conditions, the system tolerates very small errors (e.g., valve angle ±1°, response delay ±10ms); the distance threshold T0 is set to 10–20, exceeding which is considered a potential chemical reaction safety risk.

[0118] In summary, for ordinary production lines (ordinary scenarios), such as liquid filling and packaging lines, system fluctuations are relatively large; therefore, a distance range of 100–200 from the threshold T0 is recommended. For power systems, such as power grid relay protection scenarios, the system has high real-time performance and small errors; therefore, a distance range of 20–50 from the threshold T0 is recommended. For high-risk production lines, such as chemical or metallurgical control scenarios, safety tolerance is extremely low; therefore, a distance range of 10–30 from the threshold T0 is recommended.

[0119] In this embodiment, various interference factors are considered for behavioral baseline data, Euclidean distance, distance threshold, etc., and these parameters are dynamically adjusted. For example, for the Euclidean distance D, an environmental interference factor is introduced to correct the Euclidean distance of the operating parameter:

[0120]

[0121] In equation (2), E i This represents the offset value of environmental disturbance factors, such as temperature difference and humidity fluctuation; α i This represents the sensitivity coefficient of the operating parameters to environmental disturbance factors, which can be obtained by fitting historical data.

[0122] Environmental factors (such as temperature, humidity, electromagnetic interference, etc.) can significantly affect the sampling stability of certain sensors and the response characteristics of controllers. In order to avoid misjudging such deviations as abnormal behavior, this embodiment introduces an environmental correction factor to dynamically adjust the relevant feature values ​​in the behavior feature vector. The correction mechanism of equation (2) is mainly applied to the feature items of temperature, current and liquid level sensors. By judging abnormalities through the corrected feature deviations, non-malicious deviations induced by the environment can be effectively shielded.

[0123] For the distance threshold T0, the distance threshold T0 corresponding to the resource consumption parameter is updated by introducing the equipment aging factor H through the following formula (3):

[0124] T0′=T0+β× (1-H) (3)

[0125] In equation (3), T0′ represents the distance threshold corresponding to the updated resource consumption parameter; H represents the relative ratio of the device's performance in the current state to its performance in the new state, H∈[0,1]; β represents the maximum relaxation range when relaxing the device's performance in the new state.

[0126] As the PLC controller ages, its processing performance and response capability will inevitably degrade. To avoid false alarms caused by equipment aging due to static thresholds, this embodiment introduces an equipment health factor mechanism to dynamically adjust the behavior measurement threshold. H in equation (3) is the equipment health coefficient, used to evaluate indicators including CPU load fluctuation, response delay increment, memory fragmentation rate, and equipment working time, which are obtained through standardized comprehensive evaluation. T0 in equation (3) is the initially set behavior distance threshold, which is appropriately relaxed according to the equipment health status. The adjusted threshold is: T0′ is the adjusted distance threshold; β is set empirically, such as 20%; the smaller H is, the more obvious the equipment aging, and the corresponding tolerance range increases.

[0127] The environmental interference correction mechanism and the dynamic adjustment mechanism for equipment aging threshold proposed in this embodiment introduce multi-dimensional compensation modeling on the basis of traditional static measurement, which effectively improves the accuracy, robustness and adaptability of anomaly detection to actual deployment.

[0128] This embodiment also introduces a network communication latency factor to correct the behavioral baseline data corresponding to network traffic parameters, normalizes the response time of the communication module, and combines network status (such as bandwidth utilization) to determine whether the anomaly is caused by external interference. This embodiment also introduces a security policy conflict factor to correct the behavioral baseline data corresponding to resource consumption parameters. For example, encrypted communication may cause a brief peak in resource consumption, and such "strategic fluctuations" need to be marked as normal behavior in the behavioral baseline data.

[0129] This embodiment also dynamically adjusts the threshold through a baseline update mechanism (such as gradually relaxing the CPU load limit) to avoid false alarms caused by hardware performance degradation. Specifically, gradually relaxing the CPU load limit refers to dynamically adjusting the threshold range of the CPU load parameters using a phased relaxation strategy.

[0130] In the context of equipment aging, CPU utilization is one of the most sensitive indicators. To ensure that the controller is not misjudged within an acceptable performance degradation range, this embodiment sets a sliding window adaptive adjustment strategy to gradually relax the CPU utilization threshold.

[0131] Assuming the initial CPU utilization threshold is The average exceedance within the current sliding window is δ. Under the condition of no false alarms / no security events, the update rule is as follows (4):

[0132]

[0133] In equation (4), γ represents the relaxation rate factor, γ∈(0,1); δ represents the average overshoot value in the near period; and t is an integer.

[0134] This embodiment determines the temperature conduction rate based on the product of the processor load change rate and the heat dissipation compensation coefficient. The boundary range of the processor load tolerance interval is dynamically expanded based on the temperature conduction rate. The expanded tolerance interval boundary is then coordinated with the device health factor to determine the final upper limit of the threshold. Through this mechanism, the system can adapt to changes in controller load during long-term operation, improving system stability and anomaly identification and fault tolerance. The utilization rate threshold upper limit in the formula is typically set to 85%–90% to prevent the system from entering a resource exhaustion state.

[0135] Step S500: The measurement and comparison results are encrypted and transmitted to the security management platform using a domestic key algorithm.

[0136] Specifically, the SM3 algorithm (hash algorithm) is used to generate the hash value of the current behavior feature vector to ensure the uniqueness and immutability of the data. The SM2 algorithm (asymmetric encryption algorithm) is used to digitally sign the behavior measurement data to ensure its authenticity and non-repudiation, and the digital signature is stored in the tamper-proof area of ​​the hardware root of trust module. The SM4 algorithm (symmetric encryption algorithm) is used to encrypt and transmit the measurement results and comparison results (stored in the hardware root of trust module, and encrypted transmission to the security management platform) to ensure the security of the measurement records and prevent data from being eavesdropped on or tampered with during network transmission. This embodiment uses encryption algorithm standards (such as SM2, SM3, and SM4) to encrypt and sign the measurement data to ensure the security of the measurement information. Historical measurement records are periodically audited and analyzed to detect potential security vulnerabilities or malicious attacks through source tracing. Therefore, in some possible embodiments, the method of this embodiment further includes:

[0137] Step S600: When the comparison result is abnormal, perform a security response operation, which includes one or more of the following: isolation operation, restart operation, and recovery operation.

[0138] Step S700: Perform audit analysis on the encrypted stored behavioral feature vectors, behavioral baseline data, and comparison results to obtain analysis results, and update the behavioral baseline data based on the analysis results.

[0139] In some possible embodiments, such as Figure 4 As shown, storing and auditing the results of behavioral measurement can include the following steps S601 to S604.

[0140] Step S601: Encrypt the abnormal data and transmit it to the security management platform (encrypt the data and transmit it to the host platform).

[0141] Step S602: The security management platform analyzes the abnormal data and generates a security response strategy (data analysis, response strategy generation).

[0142] Step S603: Execute a security response (such as isolation, restart, etc.) (execute the response operation and update the security status).

[0143] Step S604: Security response completed.

[0144] In some possible embodiments, the method further includes:

[0145] The priority scheduling algorithm executes the measurement task during the PLC controller's idle time slice to ensure that the PLC controller's control instructions are executed first. The idle time slice begins with an interrupt signal indicating that the control instruction has been completed, and the measurement task is paused when a new control instruction arrives.

[0146] A lightweight metric agent is used to sample and monitor the current behavior feature vector.

[0147] In one possible embodiment, the priority scheduling algorithm includes the following steps (1) to (3).

[0148] Step (1): In response to the hardware interrupt signal indicating the completion of the control instruction, activate the idle time slice of a preset duration.

[0149] Step (2): Start the behavior measurement task during the idle time slice.

[0150] Step (3): When a new control command arrives, immediately suspend all measurement tasks and release processor resources.

[0151] Specifically, the high-frequency data acquisition of the behavior measurement module may consume CPU resources of the PLC controller, affecting control tasks. Therefore, each embodiment introduces a priority scheduling algorithm and a lightweight measurement agent. The priority scheduling algorithm allocates measurement tasks to the PLC's idle time slices, ensuring that control instructions are executed with priority. The lightweight measurement agent performs sampling measurement only on critical objects (such as application memory pages).

[0152] PLC controllers prioritize real-time control. Frequent execution of behavioral measurement tasks can lead to resource contention, causing delays or even loss of control commands. In practice, a priority scheduling algorithm dynamically allocates measurement resources based on control task priority. This algorithm schedules measurement tasks for execution during CPU idle periods, ensuring the priority of control operations. This embodiment further illustrates this using a liquid filling task as an example.

[0153] First, tasks are categorized and prioritized. For example, tasks are divided into high, medium, and low priorities. High-priority tasks (P1) handle the main control program (such as liquid level judgment and pump start control), medium-priority tasks (P2) handle anomaly detection and alarm output, and low-priority tasks (P3) handle behavioral measurement tasks (such as hash value calculation and resource usage sampling). Second, time slices and slot reservations are implemented. In each PLC controller cycle (e.g., 200ms), only 5%–10% of the time is allocated to low-priority (P3) tasks, while the remaining time is used to prioritize high-priority and medium-priority (P1 and P2) tasks. When executing the scheduling strategy, if the control task of the current cycle is completed and resources are released early, low-priority (P3) tasks are dynamically filled; if a high-priority (P1) task times out, low-priority (P3) tasks of the current cycle are automatically skipped to avoid affecting the main control logic. For example, in cycle t1: the main control task takes 150ms, with the remaining 50ms used for hash sampling and CPU recording; in cycle t2: a fault alarm is triggered, skipping the execution of behavior metrics; in cycle t3: with ample time for all tasks to complete, the complete metric logic is executed. This embodiment improves the response time of control commands through a priority scheduling algorithm, effectively reducing the system resource consumption of the behavior metrics function.

[0154] Traditional behavioral metrics require hashing and integrity verification of all running memory / program data, which consumes a lot of computational resources and is not suitable for resource-constrained embedded PLC environments. Therefore, this embodiment adopts a lightweight metric proxy strategy. This embodiment takes the application memory page as an example for illustration, including the following steps (1) to (3).

[0155] Step (1) Identify the security-sensitive areas in the application memory pages. The security-sensitive areas include the program entry function segment, the input / output communication buffer, and the configuration area of ​​key parameters in the current behavior feature vector.

[0156] Step (2) divides the application memory pages into multiple page blocks;

[0157] Step (3) involves taking turns extracting page blocks containing security-sensitive areas for integrity verification and using a hash algorithm to determine the verification value of the extracted page blocks.

[0158] Specifically, the program space is divided into N page blocks (e.g., each 4KB), and 10%–15% of these page blocks are selected for measurement according to preset rules. Page block selection supports periodic rotation to cover the entire system (e.g., rotating a batch of page blocks every 10 cycles). During measurement, a hash calculation is first performed on the target page block in a low-priority thread; then, a quick comparison is made with the baseline value; if a hash deviation is found, the page block is marked, and the process is switched to the complete measurement flow to eliminate false alarms. For example, with a total memory of 64KB, divided into 16 page blocks; the current period's measurement page blocks are [0, 3, 5, 8, 12]; the hash value of page block 5 is offset by 3 bits, triggering the alarm module to perform full-area verification. In specific implementation, the key area determination rules are defined as follows: the program entry function segment (including the main control logic loop), the buffer address segment related to field I / O communication, and the configuration area containing key parameters (e.g., formula parameters, tank level settings). This lightweight measurement algorithm reduces measurement time and CPU utilization without affecting CPU control performance.

[0159] The priority scheduling algorithm and lightweight metric proxy technology proposed in this embodiment are both designed to ensure the real-time performance of control tasks and the sustainability of system performance, effectively control the resource consumption caused by behavior metrics, and improve the implementation capability in resource-constrained PLC systems.

[0160] Reference Figure 5 In real-time, the method of this embodiment can be implemented through the following module engine.

[0161] The trust root module 21 initiates a self-test to achieve secure startup, obtaining startup measurement data which is then sent to the behavior measurement engine 22. The behavior measurement engine 22 performs real-time monitoring for security event monitoring, obtaining real-time monitoring data. This monitoring data is then sent to the domestic key algorithm engine 23 for data encryption and key management, resulting in encrypted transmission data. Finally, the encrypted transmission data is sent to the security management platform 24.

[0162] This embodiment proposes a PLC runtime behavior measurement method that combines Trusted Computing 3.0 with domestically developed cryptographic algorithms, aiming to enhance the security of PLC controllers, resist complex attacks against PLCs, and ensure the stable operation of industrial control systems.

[0163] This embodiment enhances the inherent security of the device by introducing the Trust Root module and behavior measurement module of Trusted Computing 3.0 to achieve secure startup and monitoring of PLC's operational behavior. This embodiment combines domestic cryptographic algorithms such as SM2, SM3, and SM4 to encrypt, sign, and securely transmit measurement data, complying with domestic security standards and ensuring data confidentiality, integrity, and availability to prevent data tampering and leakage. This embodiment establishes operational behavior baseline data by collecting PLC controller behavior data during normal operation (such as firmware hash values, resource consumption, and operating parameters), and monitors PLC behavior in real time using real-time measurement data. By comparing the measurement data with historical behavior baselines, potential security threats can be identified and responded to promptly, ensuring controller security. This embodiment uses the comparison of behavior measurement data with the baseline to detect abnormal behavior in real time. Once an anomaly is detected, an alarm is immediately triggered and corresponding security response measures are initiated. This embodiment executes security responses (such as isolation, restart, and recovery operations) based on the anomaly detection results and performs audit analysis using encrypted historical measurement data.

[0164] This embodiment enhances security by employing behavioral metrics and national cryptographic algorithms to achieve highly secure operational management of the PLC controller. Its real-time behavioral metrics function enables rapid detection and response to potential attacks, ensuring stable control system operation. Furthermore, this embodiment's automated behavioral metrics based on trusted computing reduce the need for manual maintenance, lower costs, and improve the system's level of automation.

[0165] See Figure 6This invention provides a PLC behavior measurement device based on Trusted Computing 3.0 and national cryptographic algorithms, comprising a trust root module 100, a data acquisition module 200, a behavior measurement module 300, a threshold comparison module 400, and an encrypted transmission module 500. The trust root module 100 is used to perform trusted verification of the PLC controller during startup using a hardware trust root module pre-installed in the PLC controller; wherein the hardware trust root module is constructed based on the Trusted Computing 3.0 standard. The data acquisition module 200, in response to successful verification by the hardware trust root module, acquires the current behavior feature vector of the PLC controller in its current operating state based on the Trusted Computing 3.0 standard; wherein the current behavior feature vector is a multi-dimensional trusted state of the PLC controller during operation, generated based on the Trusted Computing 3.0 standard, and includes one or more of integrity verification parameters, resource consumption parameters, operation parameters, and correlation parameters. The behavior measurement module 300 generates behavior measurement data based on the Trusted Computing 3.0 standard and the current behavior feature vector. It then measures the current behavior measurement data using pre-established behavior baseline data and an Euclidean distance algorithm, based on the Trusted Computing 3.0 standard, to obtain the measurement result. The threshold comparison module 400 compares the measurement result with a preset Euclidean distance threshold to obtain the comparison result. The encrypted transmission module 500 uses a domestically developed key algorithm to encrypt and transmit the measurement result and comparison result to the security management platform.

[0166] In an optional embodiment, the encrypted transmission module 500 includes:

[0167] The hash value of the current behavior feature vector is generated using the SM3 algorithm;

[0168] Digital signatures for behavioral measurement data are performed using the SM2 algorithm;

[0169] The SM4 algorithm is used to encrypt and store the measurement and comparison results and transmit them to the security management platform.

[0170] In an optional embodiment, behavioral baseline data is constructed using the following modules: a historical data acquisition module, a behavioral baseline data module, and an encrypted storage module. The historical data acquisition module acquires historical behavioral feature vectors of the PLC controller under normal operating conditions; wherein the parameter types of the historical behavioral feature vectors and the current behavioral feature vectors are the same; integrity verification parameters include firmware hash values ​​and application hash values; resource consumption parameters include CPU load parameters, memory occupancy parameters, memory usage parameters, and network traffic parameters; and operation parameters include control command response delay parameters and sensor feedback time parameters. The behavioral baseline data module determines the behavioral baseline data corresponding to each type of parameter in the current behavioral feature vector based on the historical behavioral feature vectors and statistical algorithms; wherein the behavioral baseline data includes a baseline value and / or a threshold range; it determines the behavioral baseline data corresponding to resource consumption parameters based on resource consumption parameters in the historical behavioral feature vectors, combined with a sliding window mean algorithm and a standard deviation analysis algorithm; it determines the behavioral baseline data corresponding to operation parameters based on operation parameters in the historical behavioral feature vectors, combined with a time series analysis algorithm; and it determines the behavioral baseline data corresponding to associated parameters based on the execution rules between various different operation parameters in the historical behavioral feature vectors, combined with covariance analysis or mutual information entropy. The encrypted storage module is used to encrypt and store the determined behavioral baseline data to the hardware root trust module using the SM4 algorithm.

[0171] In an optional embodiment, the behavior measurement module 300 includes an Euclidean distance module,

[0172] The Euclidean distance module is used to determine the Euclidean distance D between the target parameter in the current behavior feature vector and the corresponding behavior baseline data according to the following equation (1):

[0173]

[0174] In equation (1), x i b represents the feature value of the target parameter in the current behavior feature vector; 0i This represents the baseline value corresponding to the target parameter, where n is a positive integer.

[0175] The device also includes an Euclidean distance adjustment module, a distance threshold adjustment module, a network communication delay factor module, and a security policy conflict factor introduction module.

[0176] The Euclidean distance adjustment module is used to correct the Euclidean distance of the operating parameters by introducing the environmental disturbance factor through the following equation (2):

[0177]

[0178] In equation (2), E i Indicates the environmental disturbance factor offset value; α iThis represents the sensitivity coefficient of the operating parameters to environmental disturbance factors.

[0179] The distance threshold adjustment module is used to adjust the distance threshold T0 corresponding to the resource consumption parameters by introducing the equipment aging factor H through the following formula (3):

[0180] T0′=T0+β×(1-H)(3)

[0181] In equation (3), T0′ represents the distance threshold corresponding to the updated resource consumption parameter; H represents the relative ratio of the device's performance in the current state to its performance in the new state, H∈[0,1]; β represents the maximum relaxation range when relaxing the device's performance in the new state.

[0182] The network communication delay factor module is used to introduce a network communication delay factor to correct the behavioral baseline data corresponding to network traffic parameters. The security policy conflict factor module is used to introduce a security policy conflict factor to correct the behavioral baseline data corresponding to resource consumption parameters.

[0183] In an optional embodiment, the data acquisition module 200 includes a priority scheduling module and a lightweight measurement agent module. The priority scheduling module executes measurement tasks during the PLC controller's idle time slice using a priority scheduling algorithm to ensure that the PLC controller's control instructions are executed with priority; wherein, the idle time slice begins with an interrupt signal indicating the completion of a control instruction, and the measurement task is paused when a new control instruction arrives. The lightweight measurement agent module is used to sample and monitor the current behavioral feature vector using a lightweight measurement agent.

[0184] In an optional embodiment, the apparatus further includes a security response module and an audit analysis module. The security response module performs a security response operation when the comparison result is abnormal. The security response operation includes one or more of isolation, restart, and recovery operations. The audit analysis module performs audit analysis on the encrypted stored behavioral feature vectors, behavioral baseline data, and comparison results to obtain analysis results and updates the behavioral baseline data based on the analysis results.

[0185] In an optional embodiment, the lightweight metric agent module includes a security-sensitive region location module, a memory page partitioning module, and a sampling detection module. The security-sensitive region location module identifies security-sensitive regions within the application's memory pages. These regions include the program entry function segment, input / output communication buffers, and configuration areas for key parameters in the current behavior feature vector. The memory page partitioning module divides the application's memory pages into multiple page blocks. The sampling detection module periodically extracts page blocks containing security-sensitive regions for integrity verification and uses a hash algorithm to determine the verification value of the extracted page blocks.

[0186] In an optional embodiment, the apparatus of this embodiment further includes a CPU load adjustment module, used to dynamically adjust the threshold range of CPU load parameters using a phased relaxation of the threshold upper limit strategy.

[0187] The apparatus provided in the embodiments of this application has the same inventive concept as the method provided in the embodiments of this application. As long as the method can solve the technical problem, the apparatus can also solve the technical problem. This will not be elaborated here.

[0188] Reference Figure 7 The present invention also provides an electronic device 1000, including a communication interface 1001, a processor 1002, a memory 1003, and a bus 1004. The processor 1002, the communication interface 1001, and the memory 1003 are connected via the bus 1004. The memory 1003 is used to store a computer program that supports the processor 1002 in executing the above-described method. The processor 1002 is configured to execute the program stored in the memory 1003.

[0189] Optionally, embodiments of the present invention also provide a computer-readable medium having non-volatile program code executable by a processor 1002, the program code causing the processor 1002 to perform the methods as described in the above embodiments.

[0190] As is known from common technical knowledge, this invention can be implemented through other embodiments that do not depart from its spirit or essential characteristics. Therefore, the disclosed embodiments described above are merely illustrative in all respects and are not the only ones. All modifications within the scope of this invention or its equivalents are included in this invention.

Claims

1. A PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms, characterized in that, include: The PLC controller is verified during startup using a hardware root of trust module pre-installed in the PLC controller; wherein the hardware root of trust module is built based on the Trusted Computing 3.0 standard. In response to the successful verification of the hardware trust root module, the current behavior feature vector of the PLC controller in its current operating state is obtained based on the Trusted Computing 3.0 standard; wherein, the current behavior feature vector is a multi-dimensional trusted state of the PLC controller during operation generated based on the Trusted Computing 3.0 standard, and the current behavior feature vector includes one or more of the following: integrity verification parameters, resource consumption parameters, operation parameters, and correlation parameters; Based on the Trusted Computing 3.0 standard, behavioral measurement data is generated according to the current behavioral feature vector. Based on the Trusted Computing 3.0 standard, the current behavioral measurement data is measured using pre-established behavioral baseline data and Euclidean distance algorithm to obtain the measurement result. The measurement result is compared with the preset Euclidean distance threshold to obtain the comparison result; The measurement results and the comparison results are encrypted and transmitted to the security management platform using a domestically developed key algorithm. The behavioral baseline data is constructed using the following method: Obtain the historical behavior feature vector of the PLC controller under normal operating conditions; wherein the parameter types of the historical behavior feature vector and the current behavior feature vector are the same; the integrity verification parameters include firmware hash value and application hash value; the resource consumption parameters include CPU load parameters, memory occupancy rate parameters, memory usage parameters, and network communication volume parameters; the operation parameters include control command response delay parameters and sensor feedback time parameters. The behavioral baseline data corresponding to each type of parameter in the current behavioral feature vector is determined based on historical behavioral feature vectors and statistical algorithms; wherein, the behavioral baseline data includes a benchmark value and / or a threshold range; the behavioral baseline data corresponding to the resource consumption parameters is determined based on the resource consumption parameters in the historical behavioral feature vectors and combined with a sliding window mean algorithm and a standard deviation analysis algorithm; the behavioral baseline data corresponding to the operation parameters is determined based on the operation parameters in the historical behavioral feature vectors and combined with a time series analysis algorithm; and the behavioral baseline data corresponding to the correlation parameters is determined based on the execution rules between various different operation parameters in the historical behavioral feature vectors and combined with covariance analysis or mutual information entropy.

2. The PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms according to claim 1, characterized in that, The step of encrypting and transmitting the measurement result and the comparison result to the security management platform using a domestically developed key algorithm includes: The hash value of the current behavior feature vector is generated using the SM3 algorithm; The behavioral measurement data is digitally signed using the SM2 algorithm; The measurement results and comparison results are encrypted and stored using the SM4 algorithm, and then transmitted to the security management platform in an encrypted manner.

3. The PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms according to claim 1, characterized in that, Behavioral baseline data was also constructed using the following methods: The determined behavioral baseline data is encrypted and stored in the hardware trust root module using the SM4 algorithm.

4. The PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms according to claim 1, characterized in that, The current behavioral measurement data is measured based on the Trusted Computing 3.0 standard and using pre-established behavioral baseline data and the Euclidean distance algorithm to obtain the measurement results, including: The Euclidean distance between the target parameter in the current behavioral feature vector and the corresponding behavioral baseline data is determined according to the following formula (1). D : (1) In equation (1), This represents the feature value of the target parameter in the current behavior feature vector; This represents the baseline value corresponding to the target parameter. n It is a positive integer; The method further includes: The Euclidean distance of the operating parameters is corrected by introducing the environmental disturbance factor through the following equation (2): (2) In equation (2), Indicates the offset value of the environmental interference factor; This represents the sensitivity coefficient of the operating parameters to environmental disturbance factors; Euclidean distance D Distance threshold is set The equipment aging factor is introduced through the following formula (3). H Update the distance threshold corresponding to the resource consumption parameters. : (3) In equation (3), This represents the distance threshold corresponding to the updated resource consumption parameters; H This represents the ratio of the device's performance in its current state to its performance when it was brand new. H ∈[0,1]; This indicates the maximum extent of performance relaxation when the equipment is in a new operating state; Introduce a network communication delay factor to correct the behavioral baseline data corresponding to network traffic parameters; A security policy conflict factor is introduced to correct the behavioral baseline data corresponding to the resource consumption parameters.

5. The PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms according to claim 1, characterized in that, The process of obtaining the current behavior feature vector of the PLC controller during operation includes: A priority scheduling algorithm is used to execute a measurement task during the idle time slice of the PLC controller to ensure that the control instructions of the PLC controller are executed first. The idle time slice begins with an interrupt signal indicating that the control instruction has been completed, and the measurement task is paused when a new control instruction arrives. A lightweight metric agent is used to sample and monitor the current behavior feature vector.

6. The PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms according to claim 1, characterized in that, After encrypting the measurement result and the comparison result using a domestic key algorithm and transmitting them encrypted to the security management platform, the process further includes: When the comparison result is abnormal, a security response operation is performed, which includes one or more of the following: isolation operation, restart operation, and recovery operation. An audit analysis is performed on the encrypted stored behavioral feature vectors, behavioral baseline data, and comparison results to obtain analysis results, and the behavioral baseline data is updated based on the analysis results.

7. The PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms according to claim 5, characterized in that, The lightweight metric agent used samples and monitors the current behavior feature vector, including: Identify security-sensitive areas in the application's memory pages, including the program entry function segment, input / output communication buffers, and configuration areas for key parameters in the current behavior feature vector; The application memory pages are divided into multiple page blocks; Page blocks containing the security-sensitive area are extracted in rotation for integrity verification, and a hash algorithm is used to determine the verification value of the extracted page blocks.

8. The PLC behavior measurement method based on Trusted 3.0 and national cryptographic algorithms according to claim 3, characterized in that, The method further includes: The threshold range of the CPU load parameters is dynamically adjusted using a phased relaxation of the threshold upper limit strategy.

9. A PLC behavior measurement device based on Trusted 3.0 and national cryptographic algorithms, characterized in that, include: A root trust module is used to perform trusted verification of the PLC controller at startup using a hardware root trust module pre-installed in the PLC controller; wherein the hardware root trust module is built based on the Trusted Computing 3.0 standard; The data acquisition module is used to acquire the current behavior feature vector of the PLC controller in the current operating state based on the Trusted Computing 3.0 standard in response to the successful verification of the hardware trust root module. The current behavior feature vector is a multi-dimensional trusted state of the PLC controller during operation generated based on the Trusted Computing 3.0 standard, and the current behavior feature vector includes one or more of the following: integrity verification parameters, resource consumption parameters, operation parameters, and correlation parameters. The behavior measurement module is used to generate behavior measurement data based on the Trusted Computing 3.0 standard and the current behavior feature vector, and to measure the current behavior measurement data based on the Trusted Computing 3.0 standard and using pre-established behavior baseline data and Euclidean distance algorithm to obtain the measurement results. The threshold comparison module is used to compare the measurement result with a preset Euclidean distance threshold to obtain a comparison result; An encrypted transmission module is used to encrypt and transmit the measurement result and the comparison result to the security management platform using a domestically developed key algorithm. The behavioral baseline data is constructed through the following modules: historical data acquisition module and behavioral baseline data module; The historical data acquisition module is used to acquire the historical behavior feature vectors of the PLC controller under normal operating conditions. The parameter types of the historical behavior feature vectors and the current behavior feature vectors are the same. The integrity verification parameters include firmware hash values ​​and application hash values. The resource consumption parameters include CPU load parameters, memory utilization parameters, memory usage parameters, and network communication parameters. The operation parameters include control command response delay parameters and sensor feedback time parameters. The behavioral baseline data module is used to determine the behavioral baseline data corresponding to each type of parameter in the current behavioral feature vector based on historical behavioral feature vectors and statistical algorithms. The behavioral baseline data includes a benchmark value and / or a threshold range. It determines the behavioral baseline data corresponding to resource consumption parameters based on resource consumption parameters in historical behavioral feature vectors, combined with sliding window mean and standard deviation analysis algorithms. It also determines the behavioral baseline data corresponding to operational parameters based on operational parameters in historical behavioral feature vectors, combined with time series analysis algorithms. Finally, it determines the behavioral baseline data corresponding to related parameters based on the execution rules between various operational parameters in historical behavioral feature vectors, combined with covariance analysis or mutual information entropy.

10. An electronic device, characterized in that, The method includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Industrial control data security protection system based on domestic password and working method thereof

    CN118133298A

  • Multi-type algorithm encryption method, device and system

    CN118981776A

  • Remote control system and method adopting national secret algorithm

    CN119254811A

  • Measurement mechanism-based credible PLC starting method

    CN106775716A

  • Trusted verification method and device

    CN109586920A