A network security communication method and system based on commercial cipher

By generating adversarial data and using multi-dimensional anomaly identification methods, combined with commercial cryptographic encryption, the problem of identifying subtle data tampering in industrial networks has been solved, achieving real-time security of data communication and stability of production.

CN120880775BActive Publication Date: 2025-12-09SHAANXI QINGSHAN SIJI INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511339738.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-19
Publication Date
2025-12-09
Estimated Expiration
2045-09-19

AI Technical Summary

Technical Problem

Existing technologies struggle to identify subtle tampering of operational data in industrial networks, leading to decreased production accuracy and economic losses. Furthermore, traditional methods lack adaptability and dynamism in industrial production.

Method used

By generating adversarial data that closely resembles real-world scenarios, and combining multiple perspectives to comprehensively judge data anomalies, a counterfeit detection model is formed through mutual game and iterative optimization of discriminators. Combined with commercial cryptographic encryption, subtle abnormal data can be identified and processed.

Benefits of technology

It enables real-time identification and processing of data in industrial production, ensures data communication security, avoids production errors, adapts to complex industrial scenarios, and meets real-time and dynamic requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880775B_ABST
    Figure CN120880775B_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of industrial network security communication, and particularly relates to a network security communication method and system based on commercial cipher, which comprises the following steps: obtaining a historical data sequence and a real-time target data sequence; generating adversarial data and sequence in combination with the historical data; calculating the adversarial disturbance degree according to the similarity and difference between the historical and adversarial data; inputting the adversarial data sequence into a discriminator A as a to-be-tested sequence and calculating a to-be-tested anomaly index according to the byte feature difference; calculating the accuracy and error degree of the discriminator A according to the adversarial disturbance degree, the difference between the index, the consistency between the adversarial degree of adjacent data of the to-be-tested sequence and the fluctuation of the anomaly index; inputting the accuracy and error degree into discriminators B and C, and obtaining a discrimination model through multiple game iterations; inputting the target data into the model to calculate a target anomaly index, and encrypting according to the security level. The present application solves the problems of insufficient adaptability and dynamicity of the prior art in identifying intrusion data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of industrial network security communication. More particularly, the present application relates to a network security communication method and system based on commercial cryptography. BACKGROUND

[0002] With the deep integration of industrial internet and intelligent manufacturing, real-time communication between devices in high-end CNC machine tool clusters and other industrial scenarios has become the core support for production efficiency and precision. Shop floor data usually contains a large amount of sensitive information, i.e. device parameters, temperature, tool pressure, etc. The working condition data is usually encrypted by relying on commercial cryptography technology during transmission.

[0003] However, due to fierce commercial competition, attackers often tamper with data through direct contact with industrial equipment, use of industrial network vulnerabilities, and attack on data platforms and accounts. Tampered working condition data, such as tampered tool compensation parameters, false temperature or pressure readings, if used for production decision-making as normal data, may cause processing precision to decline, batch parts to be scrapped, and even equipment collision accidents, causing huge economic losses. The tampering process includes subtle tampering of multiple working condition data points, making individual data appear normal, but the overall production process deviates. Traditional detection methods based on encryption are difficult to capture subtle tampering of working condition data.

[0004] To solve the problem of subtle tampering of working condition data being difficult to capture, existing technologies based on machine learning and deep learning construct models to identify deviated data by learning a large number of normal working condition data, improving the accuracy and efficiency of judging abnormal data. However, it strongly depends on a large amount of high-quality normal data, which contradicts the characteristics of industrial data often containing noise and missing, making it difficult for the model to function stably in actual production, and it is difficult to identify new attack patterns in a timely manner and needs to be retrained and updated, which cannot meet the real-time and dynamic requirements of industrial production. SUMMARY

[0005] To solve the technical problems of insufficient adaptability and dynamics of existing technologies for identifying intrusion data, the present application provides solutions in the following aspects.

[0006] In a first aspect, the present application provides a network security communication method based on commercial cryptography, comprising:

[0007] The workshop historical working condition data of one period representing the same kind is recorded as a historical data sequence, and the real-time working condition data of the same kind is recorded as a target data sequence; the historical data sequence and the target data sequence include byte frequency, adjacent bytes and byte proportion of corresponding data; the historical data sequence is randomly disturbed in combination with the fluctuation degree of the historical data sequence to generate adversarial data and an adversarial data sequence; the adversarial disturbance degree is calculated according to the similarity of the historical data sequence and the adversarial data sequence in combination with the size difference between the historical data and the adversarial data; the adversarial data sequence is input into the discriminator A and recorded as a to-be-tested sequence; the to-be-tested anomaly index is calculated according to the byte frequency, adjacent bytes and byte proportion difference of the to-be-tested sequence; the accuracy of the discriminator A is calculated according to the difference between the adversarial disturbance degree and the to-be-tested anomaly index; the error degree of the discriminator A is calculated according to the fluctuation consistency of the adversarial degree of adjacent data of the to-be-tested sequence and the to-be-tested anomaly index; the accuracy and error degree of the discriminator A are input into discriminators B and C, and the discriminators A, B and C are adjusted through multiple games and iterations to obtain a discrimination model; the target data is input into the discrimination model to calculate a target anomaly index, and the target data type is classified according to a safety level and corresponding algorithm encryption.

[0008] The application can effectively solve the problem of difficult identification of subtle abnormal data in the prior art. By generating adversarial data close to the real situation, sufficient training samples are provided for the identification tool, without relying on a large amount of historical normal data, even if the data contains some interference or missing, the abnormality can be accurately identified. At the same time, through comprehensive judgment of data anomaly from multiple angles, combined with the continuous optimization of the model, new emerging abnormal patterns can be found in time without frequent re-adjustment. The whole process is efficient and fast, which can meet the real-time requirement of data processing in industrial production, so that various subtle problems in data transmission can be found and processed in time, and the safety of data communication is ensured.

[0009] Preferably, the adversarial data satisfies the following expression:

[0010] ;

[0011] In the formula, is the i th adversarial data; represents the i th historical data in the historical data sequence; n represents the number of historical data in the historical data sequence; represents the mean value of the historical data in the historical data sequence; represents the random disturbance coefficient of the i th historical data in the historical data sequence, and the random disturbance coefficient is randomly generated in the value range of [-1, 1]; represents the absolute value function; represents the normalization function.

[0012] The generation of the adversarial data in the application can combine the overall fluctuation of the historical data and add appropriate random fluctuations. The generated adversarial data is related to the original historical data and has certain abnormal characteristics, like simulating data that may appear in actual various subtle changes. Such adversarial data can provide more realistic samples for subsequent identification of abnormalities, so that the tool used to judge the abnormality can be exposed to various possible problem data in advance, so as to more sensitively discover abnormalities in actual use.

[0013] Preferably, the adversarial disturbance degree satisfies the following expression:

[0014] ;

[0015] In the formula, represents the adversarial disturbance degree; represents the correlation of the historical data sequence with a length of j and the adversarial data sequence with a length of j; n represents the number of data in the historical data sequence and the adversarial data sequence; represents the i-th adversarial data in the adversarial data sequence; represents the i-th historical data in the historical data sequence; represents the absolute value function; represents the exponential function with the natural constant as the base; represents the normalization function.

[0016] When calculating the adversarial disturbance degree, the application not only considers the overall similarity of the historical data and the adversarial data, but also pays attention to the difference of the single data. This way avoids the one-sidedness of only looking at whether the single data is abnormal, and also avoids ignoring the local abnormality because the overall looks similar.

[0017] Preferably, the calculation of the to-be-tested abnormality index comprises:

[0018] Obtaining the to-be-tested byte entropy, the to-be-tested variance, and the to-be-tested byte proportion;

[0019] The to-be-tested abnormality index satisfies the following expression:

[0020] ;

[0021] In the formula, represents the abnormality index of the i-th to-be-tested data in the to-be-tested sequence; 、 、 represents the to-be-tested byte entropy, the to-be-tested variance, and the to-be-tested byte proportion of the i-th to-be-tested data in the to-be-tested sequence; 、 、 represents the mean value of the to-be-tested byte entropy, the mean value of the to-be-tested variance, and the mean value of the to-be-tested byte proportion in the to-be-tested sequence. Represents the absolute value function; This represents the normalization function.

[0022] Preferably, the entropy, variance, and percentage of the byte to be tested are obtained, including:

[0023] The adversarial data sequence is input into discriminator A and denoted as the test sequence. Discriminator A converts the test sequence into a byte array and then into a test byte array. The frequency of each byte in the test byte array is counted and denoted as the test byte frequency. The test byte frequencies of all test sequences are extracted and the entropy value is calculated and denoted as the test byte entropy. The variance of adjacent bytes of the test data in the test byte array is calculated and denoted as the test variance. The proportion of 0x00 bytes and 0xFF bytes in the test data in the test byte array is calculated to obtain the test byte proportion.

[0024] Preferably, the accuracy of discriminator A includes:

[0025] ;

[0026] In the formula, This represents the accuracy of discriminator A; n represents the number of data points in the test data sequence. This indicates the degree of resistance to perturbation of the i-th data point in the data sequence. This represents the anomaly index of the i-th data point in the data sequence to be tested. Represents the absolute value function; This represents an exponential function with the natural constant as its base.

[0027] This invention calculates the accuracy of the judgment tool by comparing the degree of anomaly in the adversarial data with the judged anomaly index, clearly revealing the tool's accuracy. A small difference indicates accurate judgment, while a large difference suggests room for improvement. This method objectively reflects the tool's performance, helps identify its shortcomings, and allows for targeted adjustments, enabling the tool to more accurately identify anomalies in subsequent uses.

[0028] Preferably, calculating the error of discriminator A includes:

[0029] Extract the confrontation degree sequence and the to-be-tested anomaly index sequence, calculate the difference in confrontation disturbance degree of adjacent to-be-tested data of the i-th to-be-tested data, denoted as confrontation disturbance degree fluctuation, calculate the difference in to-be-tested anomaly index of adjacent to-be-tested data of the i-th to-be-tested data, denoted as to-be-tested anomaly index fluctuation, calculate the difference between the ratio of the confrontation disturbance degree fluctuation and the to-be-tested anomaly index fluctuation and 1, and take the positive value by using the absolute value, to represent whether the fluctuation trend of the confrontation degree and the to-be-tested anomaly index of adjacent data of the i-th to-be-tested data is consistent, denoted as the fluctuation consistency of the i-th to-be-tested data, and calculate the fluctuation consistency of all to-be-tested data and take the average, denoted as the error degree of the discriminator A.

[0030] Preferably, the anti-counterfeiting model is obtained, comprising:

[0031] The accuracy of the discriminator A and the error degree of the discriminator A are simultaneously input into the discriminators B and C, the discriminators B and C perform multiple games, and the anti-counterfeiting mode of the discriminator A is iteratively adjusted, and finally an anti-counterfeiting model with extremely high anti-counterfeiting mode is obtained, the anti-counterfeiting model comprising the discriminator A for judging the anomaly degree of to-be-tested data and the discriminators B and C for continuously promoting the discriminator A to improve the discrimination accuracy through continuous games.

[0032] The present application obtains the final anti-counterfeiting model through the mutual game and continuous adjustment of multiple judgment tools, and can continuously optimize the model in competition. Each judgment tool promotes the model improvement from different angles, so that the model can accurately identify the anomaly of a single data and stably judge the change of continuous data. The model formed in this way can adapt to various complex situations and accurately identify different types of abnormal data, greatly improving the reliability and adaptability of the model in actual use.

[0033] Preferably, the target anomaly index is calculated, comprising:

[0034] The target data is input into the anti-counterfeiting model, the to-be-tested anomaly index of the target data is calculated, denoted as the target anomaly index, a first threshold value is preset, when the target anomaly index is greater than or equal to the first threshold value, the target data is considered as disguised data and is marked, and if the target anomaly index is less than the first threshold value, the target data is treated as normal data for security level division.

[0035] In a second aspect, the present application provides a network security communication system based on commercial cryptography, comprising a processor and a memory, the memory stores computer program instructions, when the computer program instructions are executed by the processor, the above-mentioned network security communication method based on commercial cryptography is realized.

[0036] By adopting the above technical solution, the network security communication method based on commercial cryptography is generated into a computer program and stored in the memory to be loaded and executed by the processor, so that a terminal device is made according to the memory and the processor, and the use is convenient.

[0037] The method provides reliable protection for this field. It can sensitively find data that is slightly changed, avoid these data from causing errors in production, such as part scrap or equipment damage, and reduce economic losses. At the same time, by reasonably dividing the security level and corresponding processing, the safety is guaranteed while the data transmission efficiency is not affected, and the production process is smoother. This method adapts to the complex situation of data in the industrial scene and can play a long-term stable role, providing strong support for the safe use of data in industry, and helping to promote the safe and efficient production of industry. BRIEF DESCRIPTION OF DRAWINGS

[0038] Figure 1 is a flow chart schematically showing a network security communication method based on commercial cryptography in the present application;

[0039] Figure 2 is a structure diagram schematically showing a forgery identification model structure diagram-discriminator A, B and C architecture diagram. DETAILED DESCRIPTION

[0040] The embodiment of the present application discloses a network security communication method based on commercial cryptography, referring to Figure 1 , comprising steps S1-S4:

[0041] S1: obtaining a historical data sequence and a target data sequence.

[0042] It should be noted that the scene to which the present application is applied is mainly the network communication environment of equipment such as numerical control machine tools in an industrial workshop. In this kind of scene, the equipment needs to transmit a large amount of working condition data in real time, and these data are directly related to production precision and efficiency, such as tool compensation parameters which will affect the machining size of parts and cutting force data which can reflect the running state of the equipment. Due to the continuity of the production process, data transmission needs to be kept efficient and real-time, and cannot be obviously delayed due to security detection. At the same time, these data often contain core information of the equipment and are easy to become tampering targets, and the tampering methods are mostly subtle adjustments, and it may be difficult to detect abnormalities by looking at a certain data, but the cumulative data will cause serious production problems. The present application simulates real tampered data, identifies abnormalities in multiple dimensions, dynamically optimizes the formation of a forgery identification model by using discriminators to compete with each other, and combines commercial cryptography encryption, to guarantee real-time communication while accurately intercepting abnormal data, meeting the dual needs of safety and efficiency in industrial production.

[0043] It should be noted that the same kind of working condition data is divided into independent historical data sequence and target data sequence, because different kinds of data, such as tool compensation parameters and cutting time fluctuation law under normal working condition, byte distribution characteristics exist differences, separate processing can avoid different characteristics data interference, let the subsequent abnormal analysis more in line with the actual characteristics of each data.

[0044] Specifically, a period of tool compensation parameters, cutting force, cutting time and other data of the numerical control machine tool are obtained from the historical database, and the historical working condition data of the same kind in a period are recorded as a historical data sequence; a period of tool compensation parameters, cutting force, cutting time and other data in the processing process are collected in real time, and the same kind of real-time working condition data is recorded as a target data sequence; the historical data sequence and the target data sequence contain byte frequency, adjacent byte and byte proportion of corresponding data and other information. It should be noted that the byte frequency, adjacent byte and byte proportion and other information contained in the historical and target data sequence are the direct embodiment of the data bottom structure, even if the data surface value changes slightly, these byte level features may also appear abnormal, providing a key basis for identifying some seemingly normal but tampered data.

[0045] S2: combining the fluctuation degree of the historical data sequence, randomly disturbing the historical data sequence to generate the adversarial data and the adversarial data sequence; according to the similarity of the historical data sequence and the adversarial data sequence, combining the size difference between the historical data and the adversarial data, calculating the adversarial disturbance degree.

[0046] It should be noted that the core purpose of generating the adversarial data sequence is to simulate the tampered data injected by the attacker in the industrial scene, the noise interference data in the transmission link and other abnormal data, which often have high similarity with normal historical data, such as consistent overall trend but local slight deviation, which is difficult to be effectively identified by simple threshold. Therefore, the adversarial data is generated by controllable disturbance to the historical data, so that it can not only retain the basic characteristics of the historical data, but also contain a certain degree of disturbance.

[0047] Specifically, any kind of historical data sequence is extracted, a sliding window is preset, the window size is a data point, and the sliding window moving step is a data point; the fluctuation degree of the data in the sliding window is calculated according to the variance of the data in the sliding window, which is recorded as the window fluctuation degree; the window disturbance coefficient is calculated according to the window fluctuation degree; according to the window disturbance coefficient, the disturbance coefficient of all data in the historical data sequence is obtained by combining the window of the historical data; the disturbed historical data in the historical data sequence is calculated, which is recorded as the adversarial data.

[0048] It should be noted that the historical data sequence is locally analyzed by the sliding window and the adversarial data is generated, so that the disturbance characteristics of the adversarial data are more in line with the local time sequence characteristics of the data in the industrial scene. The working condition data of the numerical control machine tool often presents different fluctuation rules in different machining stages, for example, the cutting force fluctuation is large in the rough machining stage, and the machining stage is relatively stable.

[0049] It should be noted that the working condition data has natural fluctuations due to material differences, equipment vibration and environmental changes, and attackers often hide and tamper with parameters. In order to accurately simulate real threats, when constructing adversarial data, first, based on the average fluctuation degree of historical data, make the adversarial data fit the normal production characteristics and not deviate from the reasonable range. Then, by normalizing the fluctuation scale of different data, avoid the disturbance of large and small numerical data due to the absolute value difference. Then, use [-1, 1] random disturbance to cover the tampering mode of the attacker to increase or decrease the data. Finally, adjust the generated adversarial data in proportion to the original data, so that the disturbance is as subtle and hidden as real attacks.

[0050] The adversarial data satisfies the following expression:

[0051] ;

[0052] In the formula, is the ith adversarial data; represents the ith historical data in the historical data sequence; n represents the number of historical data in the historical data sequence; represents the mean value of the historical data sequence; represents the random disturbance coefficient of the ith historical data in the historical data sequence, which is randomly generated in the value range of [-1, 1]; represents the absolute value function; represents the normalization function.

[0053] In the formula, represents the difference between the ith data in the historical data sequence and the mean value of the historical data sequence; represents the average difference between all historical data in the historical data sequence and the mean value of the historical data sequence, which is used to describe the fluctuation degree of the historical data sequence, that is, the larger the data, the greater the fluctuation degree of the historical data; represents the product of the fluctuation degree of the historical data sequence and the random disturbance coefficient, that is, the disturbance degree value, if the fluctuation degree of the historical data sequence is greater, then the degree of the historical data sequence disturbed by the random disturbance threshold is greater; The expression represents the disturbed data, i.e., the adversarial data, which is composed of the historical data and the product of the disturbance degree and the historical data. It should be noted that the random disturbance coefficient is limited in [-1, 1], which is to ensure that the disturbance direction is random, so that the adversarial data covers positive and negative tampering scenarios, provides comprehensive abnormal data samples for subsequent training of the identification model, and ensures that the model can identify various potential attacks or abnormal data.

[0054] Preferably, the adversarial data corresponding to all historical data in the historical data sequence is calculated, and these adversarial data are recorded as an adversarial data sequence. It should be noted that the adversarial data corresponding to all historical data is integrated into the adversarial data sequence, which constructs a comparison sample set consistent with the structure of the historical data sequence, and the sequence form retains the time sequence characteristics, which adapts to the continuity and correlation of the working condition data of the numerical control machine tool.

[0055] At this point, the adversarial data sequence is obtained.

[0056] It should be noted that the correlation mode of the working condition data of the numerical control machine tool is different between a short period such as a single process and a long period such as all-day production. The correlation of multiple lengths can more comprehensively evaluate the overall similarity between the adversarial data sequence and the historical data sequence. By converting the overall similarity into an adversarial degree index, and then multiplying it by the normalized deviation of a single data point, the adversarial disturbance degree of the data is finally obtained.

[0057] Preferably, the historical data sequence and the disturbed data sequence are obtained, and the same data points of the historical data sequence and the disturbed data sequence are aligned; the correlation between the historical data sequence and the disturbed data sequence in different lengths is calculated using the Pearson correlation coefficient, which is recorded as the correlation between the historical data sequence and the disturbed data sequence; the deviation degree of the adversarial data sequence is calculated; and the disturbance degree of the adversarial data is calculated according to the deviation degree of the adversarial data sequence and in combination with the historical data characteristics, which is recorded as the adversarial disturbance degree.

[0058] The adversarial disturbance degree satisfies the following expression:

[0059] ;

[0060] In the formula, The expression represents the adversarial disturbance degree. The expression represents the correlation between the historical data sequence of length j and the adversarial data sequence of length j; n represents the number of data in the historical data sequence and the adversarial data sequence. The expression represents the i-th adversarial data in the adversarial data sequence. The expression represents the i-th historical data in the historical data sequence. The expression represents the absolute value function. The expression represents the exponential function with a natural constant as the base number. The expression represents the normalization function.

[0061] In the formula, represents the sum of the correlations of the historical data sequence and the adversarial data sequence at all lengths; wherein the number of data in the historical data sequence and the adversarial data sequence is n, which means that there are n correlation values between the historical data sequence and the adversarial data sequence, and the smaller the sum of the correlations of the historical data sequence and the adversarial data sequence at all lengths, the lower the similarity between the historical data sequence and the adversarial data sequence, and the greater the deviation of the adversarial data sequence, and the greater the value of is; represents the difference between the i-th adversarial data in the adversarial data sequence and the i-th historical data in the historical data sequence, that is, the deviation of the adversarial data, and the greater the value, the greater the perturbation degree of the i-th adversarial data in the adversarial data sequence. The product of the deviation of the adversarial data sequence and the deviation of the adversarial data and the historical data is used to represent the perturbation degree of the i-th adversarial data in the adversarial data sequence, denoted as adversarial perturbation degree, and the greater the value, the greater the perturbation degree of the adversarial data. It should be noted that the calculation method of the adversarial perturbation degree is realized by the product of the overall sequence correlation and the individual data deviation, which avoids the defect of incomplete judgment of only relying on the deviation of a single data point, for example, a single data anomaly but the overall trend is consistent, and also makes up for the defect of ignoring key data tampering by only relying on the overall sequence similarity, for example, the overall data sequence trend is similar but the core parameter is maliciously adjusted.

[0062] S3: input the adversarial data sequence into the discriminator A, denoted as the test sequence; calculate the test anomaly index according to the byte frequency, adjacent bytes and byte proportion difference of the test sequence; calculate the accuracy of the discriminator A according to the difference between the adversarial perturbation degree and the test anomaly index; calculate the error degree of the discriminator A according to the consistency of the adversarial degree of the adjacent data of the test sequence and the fluctuation of the test anomaly index; input the accuracy and error degree of the discriminator A into the discriminators B and C, and obtain the identification model by multiple games and iterative adjustment of the discriminators A, B and C.

[0063] It should be noted that the discriminator A calculates the test anomaly index by the multi-dimensional feature difference at the byte level, in order to accurately capture the subtle differences between the adversarial data and the historical data in the underlying data structure. After converting the data into a byte array, the byte frequency is counted and the entropy value is calculated, which can reflect the randomness characteristics of the data. The byte distribution of the normal working condition data usually presents a stable rule, while the tampered adversarial data often breaks this rule, resulting in abnormal byte entropy.

[0064] Specifically, the adversarial data sequence is input into the discriminator A, denoted as a test sequence; the discriminator A performs byte array conversion on the test sequence, converting it into a test byte array; the frequency of each byte in the test byte array is counted, denoted as a test byte frequency; the test byte frequencies of all test sequences are extracted, and the entropy value is calculated, denoted as a test byte entropy; the variance of adjacent bytes of the test data in the test byte array is calculated, denoted as a test variance; the proportion of 0x00 bytes and the proportion of 0xFF bytes of the test data in the test byte array are calculated to obtain a test byte proportion.

[0065] Preferably, in combination with the test byte entropy, the test variance, and the test byte proportion, the abnormality degree of any sequence in the test sequence composed of the adversarial data sequence in the discriminator A is calculated, denoted as a test abnormality index.

[0066] The test abnormality index satisfies the following expression:

[0067] ;

[0068] In the formula, represents the abnormality index of the i-th test data in the test sequence; 、 、 represents the test byte entropy, the test variance, and the test byte proportion of the i-th test data in the test sequence; 、 、 represents the mean value of the test byte entropy, the mean value of the test variance, and the mean value of the test byte proportion in the test sequence; represents an absolute value function; represents a normalization function.

[0069] In the formula, 、 、 represents the difference between the test byte entropy, the test variance, and the test byte proportion of the i-th test data in the test sequence and the mean value of the test byte entropy, the mean value of the test variance, and the mean value of the test byte proportion in the test sequence. The greater the difference, the greater the test abnormality index.

[0070] At this point, the test abnormality index is obtained.

[0071] It should be noted that the discriminator A is used to determine the abnormal condition of the input test data, and the abnormal condition of the test data is output through the test anomaly index. However, the discriminator only relies on the difference between the byte frequency, adjacent byte and byte proportion of the test data in the test sequence and the corresponding mean value to identify the abnormal condition when making a judgment. Such identification method cannot accurately identify the abnormality of the test data. This step judges the accuracy of the discriminator A in calculating the test anomaly index according to the difference between the adversarial perturbation degree and the test anomaly index, which is recorded as the accuracy of the discriminator A.

[0072] Preferably, all test anomaly indexes of the test data are calculated in the discriminator A, which is recorded as a test anomaly index sequence; all data adversarial degrees in the adversarial data sequence are calculated, which is recorded as an adversarial degree sequence; and the accuracy of the discriminator A is calculated according to the adversarial degree sequence and the test anomaly index sequence.

[0073] It should be noted that the adversarial perturbation degree is used as an index to measure the accuracy of the discriminator A. The core lies in that the adversarial perturbation degree is a known abnormal benchmark in the adversarial data sequence. The adversarial data sequence is generated by controllable random disturbance on the historical data sequence, and its adversarial perturbation degree quantifies the degree of deviation of each adversarial data from the original historical data, which is a benchmark value of the real abnormal degree of data. The function of the discriminator A is to identify the abnormality and calculate the test anomaly index, and the adversarial perturbation degree as a real standard can verify the accuracy of the discriminator A by the difference between the test anomaly index. The smaller the difference between the two is, the more accurate the identification is.

[0074] The accuracy of the discriminator A satisfies the following expression:

[0075] ;

[0076] In the formula, The accuracy of the discriminator A; n represents the number of data in the test data sequence; The adversarial perturbation degree of the i-th test data in the test data sequence; The test anomaly index of the i-th test data in the test data sequence; The absolute value function; The exponential function with natural constant as base.

[0077] In the formula, The difference between the adversarial perturbation degree of the i-th test data in the test data sequence and the test anomaly index of the i-th test data; The mean value of the difference between the adversarial perturbation degree and the test anomaly index of the i-th test data in the test data sequence, which is used to express the accuracy of the discriminator A in outputting the test anomaly index.

[0078] It should be noted that the game logic of discriminators B and C with discriminator A is to promote discriminator A to achieve the balance between accuracy and stability in iteration through the maximization of respective indicators, so as to adapt to the demand of continuous data security identification in industrial scenarios. Discriminator B aims to maximize the accuracy of discriminator A.

[0079] The maximization behavior of discriminator B is to train discriminator A from a single data identification dimension, to constantly correct the abnormal judgment deviation of single data in training by strengthening the requirement for the accuracy of discriminator A, and to improve the identification accuracy of isolated abnormal data.

[0080] Discriminator C aims to maximize the error degree of discriminator A, which reflects the consistency capture ability of discriminator A to the trend of continuous data time series. The maximization behavior of discriminator C is to form a game with discriminator A from the continuous trend identification dimension, that is, to expose the shortcomings of discriminator A in capturing overall abnormal trend by amplifying the defects of discriminator A in continuous data fluctuation synchronization, and to promote discriminator A to optimize the adaptation ability to the fluctuation rule of continuous data in iteration.

[0081] Preferably, the error degree of discriminator A is calculated according to the sequence of confrontation degree and the sequence of abnormality index to be measured.

[0082] The error degree of discriminator A satisfies the following formula:

[0083] ;

[0084] In the formula, Error degree of discriminator A; n represents the number of data in the sequence of data to be measured; 、 Confrontation disturbance degree of the i+1th and ith data to be measured in the sequence of data to be measured; 、 Abnormality index to be measured of the i+1th and ith data to be measured in the sequence of data to be measured; It is a very small positive number, which ensures that the denominator is not zero; It is an absolute value function; It is a normalization function.

[0085] In the formula, Time series fluctuation of the confrontation disturbance degree of the i+1th data to be measured; Time series fluctuation of the abnormality index to be measured of the i+1th data to be measured; Ratio of the time series fluctuation of the confrontation disturbance degree to the time series fluctuation of the abnormality index to be measured of the i+1th data to be measured; The degree of deviation of the ratio of the time sequence fluctuation of the anti-interference degree to the time sequence fluctuation of the abnormality index from 1, the greater the deviation, the more different the fluctuations are out of sync; The mean of the deviation degree of all the test data, the greater the value, the greater the error degree of the discriminator A.

[0086] It should be noted that the game of maximizing the accuracy of the discriminator B and maximizing the error degree of the discriminator C makes the discriminator A need to improve the accuracy of individual data judgment and enhance the stability of continuous trend capture under the pressure of both, and finally the identification model formed through multiple iterations can better adapt to the scene of continuous and large data interaction in industrial networks.

[0087] Preferably, the accuracy of the discriminator A and the error degree of the discriminator A are input into the discriminators B and C at the same time, the discriminators B and C are subjected to multiple games, and the discriminator A is iteratively adjusted, and finally an identification model with extremely high identification mode is obtained, the identification model includes the discriminator A for judging the abnormality degree of the test data, and the discriminators B and C for continuously promoting the discriminators A to improve the discrimination accuracy.

[0088] It should be noted that the discriminators A, B and C and the game and iterative adjustment process described herein are models proposed by the present application to optimize the performance of the identification model, such as Figure 2 : Identification model structure diagram - discriminator A, B and C architecture diagram, which can be realized through mature and well-known technologies in the field of machine learning, and the specific corresponding relationship and implementation path are as follows:

[0089] The discriminator A is a parameterizable calculation model, which is an industrial data feature analysis module, can be developed based on the software level and through the Python / TensorFlow framework, and the core consists of three sub-modules, and the specific structure and functions are as follows: the first module is a byte array conversion sub-module, which receives an anti-interference data sequence, such as a numerical control machine tool compensation parameter, the data type is a 32-bit floating point number, and each data point is converted into a 4-byte array according to the little-end storage rule, for example, the numerical control machine tool compensation parameter 0.12 corresponds to the 32-bit floating point number hexadecimal 0x3D99999A, which is converted into a byte array [0x9A, 0x99, 0x99, 0x3D], to ensure that the data bottom byte features can be extracted; the second module is a multi-dimensional feature extraction sub-module, which is a bottom data feature analysis module suitable for industrial working condition data characteristics, through multi-dimensional operations such as byte frequency statistics, Shannon entropy calculation, adjacent byte variance solution, and specific byte proportion analysis, the bottom byte features of industrial working condition data such as numerical control machine tool compensation parameters are converted into more intuitive indicators; the third module is an abnormality index calculation sub-module, which is a conversion module of multi-dimensional feature extraction and identification model judgment, i.e. converting the bottom byte features into specific indicators that can be directly used for abnormality judgment.

[0090] Both discriminators B and C are parameter optimization game modules, which can be developed based on the software level and through the PyTorch framework. In the anti-fake model composed of discriminators B, C and A: the discriminator B maximizes the accuracy of the discriminator A to ensure that A accurately identifies the anomaly of a single data point. First, the accuracy indicator is defined, which is obtained by dividing the sum of the number of correctly identified abnormal data and the number of correctly identified normal data by the total number of data points. Then, loss function one is constructed, which converts the maximization of accuracy into the minimization of the loss function. Then, the gradient of the loss function one with respect to the parameters of the discriminator A is calculated through the automatic differentiation mechanism and is back propagated. Finally, the gradient signal is fed back to the discriminator A to guide the fine-tuning of the parameters.

[0091] The discriminator C maximizes the error degree of the discriminator A to amplify the defects of the discriminator A in the identification of continuous data fluctuations, and promotes the A to improve the time consistency in the opposite direction. The error degree indicator is defined, which is obtained by dividing the number of groups of more than three consecutive abnormal data misjudged as normal by the total number of consecutive abnormal groups. Then, loss function two is constructed, which converts the maximization of error degree into the minimization of the loss function. Similarly, with the help of the automatic differentiation mechanism, the gradient of the loss function two with respect to the parameters of the discriminator A is calculated and back propagated. The gradient signal is fed back to A to adjust the parameters. In the collaborative game, a batch of industrial data is input in each iteration, the discriminators A, B and C calculate the accuracy, error degree and corresponding loss function respectively, then the gradients of the two are merged according to the weight, and the Adam optimizer adjusts the parameters of the discriminator A according to the total gradient. After several iterations, the discriminator A can accurately identify single abnormal data and sensitively capture continuous data fluctuation anomalies, and finally form a high-performance anti-fake model. Among them, according to the little-end storage rule, the construction of the loss function, the calculation of the gradient and the back propagation of the automatic differentiation mechanism, and the adjustment of the parameters by the Adam optimizer are prior art.

[0092] S4: input the target data into the anti-fake model to calculate the target abnormal index, and divide the security level and the corresponding algorithm encryption according to the type of the target data.

[0093] It should be noted that in the communication of the numerical control machine tool cluster, the primary goal for the disguised data is to block its propagation. For normal data, different encryption strengths are matched according to their sensitivity to avoid delay caused by excessive encryption, so as to balance communication efficiency while ensuring security. Through the anti-fake model, the target data is calculated for the abnormal index and compared with the first threshold value, realizing the rapid and safe screening of the target data. This process directly adapts to the high requirements of real-time communication in industrial scenarios. The first threshold value is preset as a judgment critical point, which can quickly identify the disguised data that deviates obviously from the normal characteristics and mark it in time to avoid its entering the subsequent communication process and causing device abnormalities.

[0094] Specifically, the target data is input into the identification model, an abnormality index of the target data is calculated, and the abnormality index is denoted as a target abnormality index; a first threshold is preset, and when the target abnormality index is greater than or equal to the first threshold, the target data is considered to be disguised data, and the target data is marked; if the target abnormality index is less than the first threshold, the target data is regarded as normal data for security level division.

[0095] It should be noted that the Chinese patent document with the authorization announcement number CN103780622B, named a data classification encryption method for cloud storage, classifies industrial data into three levels of general level L1, sensitive level L2 and secret level L3 by analyzing data leakage risk and business impact, providing an industry general classification logic for the method. On this basis, the method further combines commercial cryptographic compliance requirements to further adapt the level division to the domestic SM series algorithm. And this step can avoid resource waste and communication delay caused by over-encryption of low-sensitive data, while ensuring that high-sensitive data is protected with sufficient strength.

[0096] Preferably, all target data sequences are divided into security levels according to categories, for example, tool compensation parameters are divided into L3, cutting forces are divided into L3, equipment vibration noise is divided into L2, and environmental temperature is divided into L1, and are represented by target data L1, target data L2 and target data L3 respectively. Obtain the commercial cryptographic algorithm of the SM series, and encrypt the target data L1 using a low-sensitivity commercial encryption algorithm, for example, the SM4 encryption algorithm which is suitable for encrypting open and efficient data and is suitable for frequent collection and low security requirements; the target data L2 is encrypted using a medium-sensitivity commercial encryption algorithm or a password combination, for example, the SM4+SM3 encryption algorithm, which meets the needs of encryption efficiency and identity credibility; and the target data L3 is encrypted using a high-sensitivity commercial encryption algorithm or a password combination, for example, the SM2+SM4 encryption algorithm, which prevents the encrypted data from being cracked and leaked.

[0097] At this point, the secure communication of the data is completed.

[0098] The embodiment of the application also discloses a network security communication system based on commercial cryptography, comprising a processor and a memory, and the memory stores computer program instructions, which realize the network security communication method based on commercial cryptography according to the application when the computer program instructions are executed by the processor.

[0099] The above system also includes a communication bus and a communication interface and other components familiar to those skilled in the art, and their settings and functions are known in the art, so they will not be described here.

[0100] While the specification has illustrated and described various embodiments of the application, it will be clear to those of ordinary skill in the art that various changes, modifications, and substitutions can be made thereto without departing from the spirit and scope of the application. It is understood that in the process of practicing the application, various alternatives, modifications, and equivalents can be employed.

Claims

1. A network security communication method based on a commercial cipher, characterized by, The application relates to a method for generating an anti-fake model for real-time data. The same kind of time interval workshop historical working condition data is recorded as a historical data sequence, and the same kind of real-time working condition data is recorded as a target data sequence; the historical data sequence and the target data sequence contain byte frequency, adjacent bytes and byte proportion of corresponding data; The historical data sequence is randomly disturbed in combination with the fluctuation degree of the historical data sequence to generate anti-data and an anti-data sequence; the anti-disturbance degree is calculated according to the similarity of the historical data sequence and the anti-data sequence and the size difference between the historical data and the anti-data; The anti-data sequence is input into a discriminator A and recorded as a to-be-tested sequence; the to-be-tested anomaly index is calculated according to the byte frequency, adjacent bytes and byte proportion difference of the to-be-tested sequence; the accuracy of the discriminator A is calculated according to the difference between the anti-disturbance degree and the to-be-tested anomaly index; the error degree of the discriminator A is calculated according to the fluctuation consistency of the anti-disturbance degree of adjacent data of the to-be-tested sequence and the to-be-tested anomaly index; The accuracy and error degree of the discriminator A are input into discriminators B and C, and the discriminators A, B and C are adjusted through multiple games and iterations to obtain the anti-fake model; The target data is input into the anti-fake model to calculate a target anomaly index, and the target data is classified according to a safety level and encrypted according to a corresponding algorithm.

2. The network security communication method based on commercial cipher according to claim 1, characterized in that, The anti-data satisfies the following expression: ; In the formula, is the ith adversarial data; represents the ith historical data in the historical data sequence; n represents the number of historical data in the historical data sequence; represents the mean of the historical data in the historical data sequence; represents the random disturbance coefficient of the ith historical data in the historical data sequence, which is randomly generated in the value range of [-1, 1]; represents the absolute value function; represents the normalization function.

3. The network security communication method based on commercial cipher according to claim 1, characterized in that, The anti-disturbance degree satisfies the following expression: ; wherein, represents the degree of adversarial perturbation; represents the correlation of the history data sequence with length j and the adversarial data sequence with length j; n represents the number of data in the history data sequence and the adversarial data sequence; represents the i-th adversarial data in the adversarial data sequence; represents the i-th history data in the history data sequence; represents the absolute value function; represents the exponential function with the natural constant as the base number; represents the normalization function.

4. The network security communication method based on commercial cipher according to claim 1, characterized in that, The to-be-tested anomaly index is calculated, including: The to-be-tested byte entropy, to-be-tested variance and to-be-tested byte proportion are obtained; The to-be-tested anomaly index satisfies the following expression: ; In the formula, represents the anomaly index of the i-th to-be-tested data in the to-be-tested sequence; , , represents the to-be-tested byte entropy, to-be-tested variance, and to-be-tested byte proportion of the i-th to-be-tested data in the to-be-tested sequence; , , represents the mean value of the to-be-tested byte entropy, to-be-tested variance, and to-be-tested byte proportion in the to-be-tested sequence; represents an absolute value function; represents a normalization function.

5. The network security communication method based on commercial cipher according to claim 4, characterized in that, The to-be-tested byte entropy, to-be-tested variance and to-be-tested byte proportion are obtained, including: The anti-data sequence is input into the discriminator A and recorded as a to-be-tested sequence; the discriminator A converts the to-be-tested sequence into a to-be-tested byte array; the frequency of each byte in the to-be-tested byte array is counted and recorded as to-be-tested byte frequency; the to-be-tested byte frequency of all to-be-tested sequences is extracted to calculate an entropy value, which is recorded as to-be-tested byte entropy; the variance of adjacent bytes of to-be-tested data in the to-be-tested byte array is calculated and recorded as to-be-tested variance; the 0x00 byte proportion and 0xFF byte proportion of to-be-tested data in the to-be-tested byte array are calculated to obtain to-be-tested byte proportion.

6. The network security communication method based on commercial cipher according to claim 1, characterized in that, The accuracy of the discriminator A includes: ; In the formula, represents the accuracy of discriminator A; n represents the number of data in the data sequence to be tested; represents the degree of adversarial disturbance of the ith data to be tested in the data sequence to be tested; represents the abnormality index to be tested of the ith data to be tested in the data sequence to be tested; represents the absolute value function; represents the exponential function with the natural constant as the base.

7. The network security communication method based on commercial cipher according to claim 1, characterized in that, The error degree of the discriminator A includes: The anti-disturbance degree difference of adjacent to-be-tested data of the i-th to-be-tested data is calculated and recorded as anti-disturbance degree fluctuation; the to-be-tested anomaly index difference of adjacent to-be-tested data of the i-th to-be-tested data is calculated and recorded as to-be-tested anomaly index fluctuation; the difference between the ratio of the anti-disturbance degree fluctuation and the to-be-tested anomaly index fluctuation and 1 is calculated, and the absolute value is taken as a positive value, which is used to represent whether the fluctuation trend of the anti-disturbance degree of adjacent data of the i-th to-be-tested data and the to-be-tested anomaly index is consistent, recorded as the fluctuation consistency of the i-th to-be-tested data; the fluctuation consistencies of all to-be-tested data are calculated and averaged to obtain the error degree of the discriminator A.

8. The network security communication method based on commercial cipher according to claim 1, characterized in that, The anti-fake model is obtained, including: The accuracy of the discriminator A and the error degree of the discriminator A are input into discriminators B and C at the same time, the discriminators B and C perform multiple games, and the identification mode of the discriminator A is iteratively adjusted, and finally an identification mode with extremely high identification mode is obtained, the identification mode includes the discriminator A for judging the abnormality degree of the to-be-tested data, and the discriminators B and C for continuously promoting the discriminator A to improve the identification precision.

9. The network security communication method based on commercial cipher according to claim 1, characterized in that, The target abnormality index is calculated, comprising: The target data is input into the identification mode, the to-be-tested abnormality index of the target data is calculated, and the to-be-tested abnormality index is recorded as a target abnormality index; a first threshold value is preset, when the target abnormality index is greater than or equal to the first threshold value, the target data is considered as disguised data, and is marked; if the target abnormality index is less than the first threshold value, the target data is regarded as normal data and is subjected to security level division.

10. A network security communication system based on a commercial cipher, characterized by Comprise: A processor and a memory, the memory stores computer program instructions, when the computer program instructions are executed by the processor, a network security communication method based on commercial cryptography according to any one of claims 1-9 is realized.

Citation Information

Patent Citations

  • A data classification encryption method for cloud storage

    CN103780622B

  • Voice verification code generation method based on generative adversarial network

    CN112287323A

  • Text-based risk prevention and control processing method, device and equipment

    CN113961704A