A security authentication method and system based on a secure computer

By deploying a miniature sensor array on a secure computer, generating thermoelectric coupling feature maps and performing dynamic phase spectrum analysis, the blind spot problem of traditional security authentication methods is solved, enabling real-time monitoring and adaptive response to microscopic physical anomalies, and improving the robustness and reliability of the secure computer.

CN120950326BActive Publication Date: 2026-04-17HUNAN AGRI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUNAN AGRI UNIV
Filing Date
2025-07-08
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Traditional security authentication methods cannot capture security risks caused by microscopic physical phenomena, lack runtime dynamic monitoring capabilities, and are difficult to identify new hardware-level threats.

Method used

By deploying a miniature sensor array on a secure computer, a microparticle thermoelectric coupling feature map is generated. Point-to-point time-series correlation analysis and nonlinear dynamic feature extraction are performed to construct a dynamic phase spectrum of secure computing behavior. Combined with historical data, real-time anomaly identification and adaptive response are performed to achieve high-precision monitoring and assessment of microscopic physical anomalies.

Benefits of technology

It enables real-time monitoring and anomaly identification of the microscopic physical characteristics of computers, improves the robustness and reliability of secure computers, ensures consistency of runtime behavior, and enhances the early detection capability of difficult-to-reproduce and new hardware-level threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120950326B_ABST
    Figure CN120950326B_ABST
Patent Text Reader

Abstract

This invention relates to the field of computer security authentication technology, and more particularly to a security authentication method and system based on a secure computer. The method includes the following steps: deploying a sensor array and acquiring data from the secure computer to obtain calibrated spatiotemporal synchronization data; performing temperature and current fusion processing on the calibrated spatiotemporal synchronization data to obtain a thermoelectric coupling feature spectrum; performing point-to-point temporal correlation analysis on the thermoelectric coupling feature spectrum to obtain a point-to-point cross-correlation matrix; extracting nonlinear features from the point-to-point cross-correlation matrix to obtain a nonlinear dynamic feature set; performing dynamic behavior analysis on the nonlinear dynamic feature set to obtain a dynamic phase spectrum of secure computing behavior; and calculating the phase difference of the dynamic phase spectrum of secure computing behavior to obtain a phase difference vector. This invention improves the early detection capability of difficult-to-reproduce and novel hardware-level threats through real-time monitoring and anomaly identification of the computer's microscopic physical characteristics.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer security authentication technology, and in particular to a security authentication method and system based on a secure computer. Background Technology

[0002] Traditional security authentication methods primarily rely on macroscopic temperature testing and functional verification, failing to detect and capture microscopic physical phenomena such as minute temperature rises and current density changes within the chip. This leads to security vulnerabilities such as gate circuit timing drift, signal integrity degradation, and soft errors, creating blind spots in security authentication. Traditional authentication methods mostly employ static testing or offline verification modes, lacking real-time monitoring capabilities when the computer performs security-critical tasks. This fails to guarantee the continuous consistency of runtime behavior, resulting in undetected security deviations during actual system operation. Existing technologies have limited detection capabilities for security threats arising at the microscopic physical level (such as side-channel attacks, fault injection, and hardware aging), especially those hardware-level threats that are difficult to reproduce or are covert, lacking effective early identification and defense methods.

[0003] In summary, existing technologies have several problems that urgently need to be addressed, including the inability to capture security risks caused by microscopic physical phenomena, a lack of runtime dynamic monitoring capabilities, and insufficient ability to identify threats at the new hardware level. Summary of the Invention

[0004] Therefore, it is necessary to provide a secure authentication method and system based on a secure computer to solve at least one of the above-mentioned technical problems.

[0005] To achieve the above objectives, a secure authentication method based on a secure computer includes the following steps:

[0006] Step S1: Deploy the sensor array and acquire data on the security computer to obtain calibrated spatiotemporal synchronization data; perform temperature and current fusion processing on the calibrated spatiotemporal synchronization data to obtain a thermoelectric coupling characteristic spectrum;

[0007] Step S2: Perform point-to-point time-series correlation analysis on the thermoelectric coupling feature map to obtain the point-to-point cross-correlation matrix; extract nonlinear features from the point-to-point cross-correlation matrix to obtain the nonlinear dynamic feature set; perform dynamic behavior analysis on the nonlinear dynamic feature set to obtain the dynamic phase spectrum of safe computing behavior;

[0008] Step S3: Obtain historical operation data; calculate the phase difference of the dynamic phase spectrum of the safe computing behavior to obtain the phase difference vector; determine the normal fluctuation range of the phase difference vector to obtain the normal fluctuation boundary; judge the abnormal mode based on the normal fluctuation boundary to obtain the abnormal type judgment result; perform spatial propagation characteristic analysis on the abnormal type judgment result and the phase difference vector to obtain the abnormal propagation characteristic map; calculate the abnormal index based on the abnormal propagation characteristic map.

[0009] Step S4: Match the anomaly index to the task security level to obtain the task security requirement table; calculate the security credibility score based on the task security requirement table; perform security authentication based on the security credibility score to obtain the security authentication status.

[0010] This invention achieves high-precision, spatiotemporally synchronized perception and feature extraction of microscopic thermoelectric physical phenomena at key nodes of a secure computer through step S1, generating a unique original feature map of microparticle thermoelectric coupling, overcoming the blind spots of traditional macroscopic testing methods. Step S2, based on this, deeply analyzes the temporal correlation and nonlinear dynamic characteristics between points, constructing a dynamic phase spectrum reflecting the complex dynamic behavior patterns of hardware under normal and secure conditions, providing a high-resolution dynamic benchmark. Step S3 uses this dynamic phase spectrum as a reference to monitor micro-thermoelectric behavior deviations in real time. Through precise difference calculation and determination of normal fluctuation range based on historical data, intelligent identification and low false alarm detection of microscopic physical anomalies are achieved, and the anomaly type, spatial propagation, and temporal evolution characteristics can be characterized in detail, quantifying the severity of the anomaly. Step S4 combines the microscopic anomaly index with the task security level and context environment to perform context-aware risk assessment and security credibility scoring, and triggers a graded adaptive response based on the scoring results, effectively addressing hidden threats caused by microscopic physical changes, ultimately providing a reliable runtime security authentication status, and improving the robustness and credibility of the secure computer. Therefore, this invention provides a security authentication method based on a secure computer. By deploying a high-precision micro-sensor array at key nodes of the secure computer, a microparticle-level thermal-electric coupling feature map and a dynamic temporal correlation analysis framework are established, enabling real-time monitoring and anomaly identification of the computer's microscopic physical characteristics. Combined with adaptive threshold detection and a security credibility assessment mechanism, this effectively solves the blind spot problem of traditional methods, ensures the consistency of the secure computer's runtime behavior, and improves the early detection capability for threats that are difficult to reproduce and new hardware-level threats.

[0011] Preferably, the present invention also provides a security authentication system based on a secure computer for performing the security authentication method based on a secure computer as described above, the security authentication system based on a secure computer comprising:

[0012] The thermoelectric feature map module is used to deploy sensor arrays and acquire data for the security computer to obtain calibrated spatiotemporal synchronization data; temperature and current fusion processing is performed on the calibrated spatiotemporal synchronization data to obtain thermoelectric coupling feature maps;

[0013] The dynamic phase spectrum module is used to perform point-to-point time-series correlation analysis on the thermoelectric coupling feature map to obtain the point-to-point cross-correlation matrix; to extract nonlinear features from the point-to-point cross-correlation matrix to obtain a nonlinear dynamic feature set; and to analyze the dynamic behavior of the nonlinear dynamic feature set to obtain the dynamic phase spectrum of safe computing behavior.

[0014] The abnormal state assessment module is used to acquire historical operation data; calculate the phase difference of the dynamic phase spectrum of safe computing behavior to obtain the phase difference vector; determine the normal fluctuation range of the phase difference vector to obtain the normal fluctuation boundary; judge the abnormal mode based on the normal fluctuation boundary to obtain the abnormal type judgment result; perform spatial propagation characteristic analysis on the abnormal type judgment result and the phase difference vector to obtain the abnormal propagation characteristic map; and calculate the abnormal index based on the abnormal propagation characteristic map.

[0015] The security credibility assessment and certification module is used to match the anomaly index with the task security level to obtain the task security requirement table; calculate the security credibility score based on the task security requirement table; and perform security certification based on the security credibility score to obtain the security certification status.

[0016] This invention relates to a security authentication system based on a secure computer. Its thermoelectric feature mapping module performs high-precision perception and feature extraction of internal microscopic physical phenomena, breaking through the blind spots of traditional macroscopic testing. The dynamic phase spectrum module, through in-depth analysis of the temporal correlation and nonlinear dynamics of microscopic physical signals, constructs a high-resolution "fingerprint" reflecting the unique dynamic behavior patterns of the hardware. The anomaly assessment module uses this dynamic fingerprint as a benchmark, combined with historical data and contextual information, to achieve intelligent, low-false-alarm identification of runtime microscopic physical anomalies. It can also characterize the anomaly type, spatial propagation, and temporal evolution characteristics in detail, providing a quantified anomaly index. The security trustworthiness assessment and authentication module performs context-aware risk assessment and trustworthiness quantification based on the anomaly index, and triggers a graded adaptive response according to the assessment results. This enables the secure computer to respond promptly and accurately to hidden or difficult-to-reproduce security threats caused by microscopic physical changes, significantly improving the system's runtime security and robustness.

[0017] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0018] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:

[0019] Figure 1 This is a flowchart illustrating the steps of a security authentication method based on a secure computer. Detailed Implementation

[0020] The technical method of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0021] Furthermore, the accompanying drawings are merely illustrative of the invention and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor methods and / or microcontroller methods.

[0022] It should be understood that although the terms "first," "second," etc., may be used herein to describe various units, these units should not be limited by these terms. These terms are used merely to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, a first unit may be referred to as a second unit, and similarly, a second unit may be referred to as a first unit. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0023] It should be noted that the acquisition, transmission, storage, use, and processing of data in the technical solution of this application all comply with relevant laws and regulations. In the embodiments of this application, certain existing industry solutions such as software, components, and models may be mentioned. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solution of this application, and do not imply that the applicant has already used or necessarily used such solutions.

[0024] In this embodiment of the invention, reference Figure 1 The diagram shown illustrates the steps of the security authentication method based on a secure computer according to the present invention. In this example, the security authentication method based on a secure computer includes the following steps:

[0025] Step S1: Deploy the sensor array and acquire data on the security computer to obtain calibrated spatiotemporal synchronization data; perform temperature and current fusion processing on the calibrated spatiotemporal synchronization data to obtain a thermoelectric coupling characteristic spectrum;

[0026] In this embodiment of the invention, by analyzing the circuit design documents and thermal / electrical simulation reports of the security computer, key nodes such as the CPU core, memory interface, and security modules that have the greatest impact on safety-critical tasks are identified, forming a key node distribution map. Subsequently, at these key node locations, miniature temperature sensors and current density detectors are deployed using micro / nano fabrication or high-precision mounting technologies, and a sensor network topology is established through a dedicated data acquisition system. In a controlled environment, a preset safety baseline code segment is executed using the JTAG interface, and precise execution trajectories and timestamps are recorded. The data acquisition system is synchronously triggered to acquire raw physical parameter data streams from all sensors at a high frequency (e.g., 1MHz). The acquired raw data undergoes sensor calibration, precise spatiotemporal synchronization calibration, and filtering to generate calibrated spatiotemporal synchronization data precisely aligned with the code execution timeline. Next, the calibrated data is separated into temperature and current density datasets. The spatial temperature gradient field and time rate of change field of the temperature data are calculated. Combining the temperature rate of change field, temperature gradient field, and current density data, the local thermoelectric coupling strength is calculated, and a thermoelectric coupling tensor is constructed. By comparing the execution logs of the security benchmark code, the corresponding code stages are marked for time slices in the thermoelectric coupling tensor. Representative thermoelectric feature points in the marked tensor are identified, and the response sequences of these feature points are extracted. Finally, the response sequences of the feature points are fused with other statistical or dimensionality-reduced information in the marked thermoelectric coupling tensor to generate a unique microparticle thermoelectric coupling original feature map for this computer, serving as a fundamental characterization of the hardware's microscopic physical properties.

[0027] Step S2: Perform point-to-point time-series correlation analysis on the thermoelectric coupling feature map to obtain the point-to-point cross-correlation matrix; extract nonlinear features from the point-to-point cross-correlation matrix to obtain the nonlinear dynamic feature set; perform dynamic behavior analysis on the nonlinear dynamic feature set to obtain the dynamic phase spectrum of safe computing behavior;

[0028] In this embodiment of the invention, the time-series data in the original feature map of particle thermoelectric coupling is decomposed into point-time series datasets according to key nodes and physical quantity types. The first-order rate of change is calculated for each time series to obtain a parameter rate of change matrix, highlighting transient changes. Multi-scale wavelet decomposition is performed on each rate of change time series in the parameter rate of change matrix, decomposing the signal to different frequency scales and generating wavelet coefficient spectra. A list of point pairs is constructed based on the wavelet coefficient spectra, and the maximum values ​​of Pearson correlation coefficients or cross-correlation functions for different point pairs (including similar and dissimilar physical quantities) at each wavelet scale are calculated as coupling strengths, forming similar correlation matrices and dissimilar coupling matrices. The time delay of each point pair at each scale is calculated using the cross-correlation function to obtain a propagation delay table, and a signal propagation network diagram is constructed based on this table. Combining the signal propagation network diagram, similar correlation matrix, and dissimilar coupling matrix, coupling anomalies inconsistent with expected behavior patterns are identified through pattern matching, correlation strength spatial mapping, and correlation stability assessment, generating coupling anomaly markers. Finally, the correlation matrix of similar types, the coupling matrix of dissimilar types, the propagation delay table, and the coupling anomaly markers are integrated to form a point cross-correlation matrix reflecting the temporal correlation between each point. Specific time series or patterns are extracted from the point cross-correlation matrix, and reconstruction parameters are determined based on average mutual information and the pseudo-nearest neighbor method to reconstruct the phase space trajectory, resulting in a phase space trajectory map. The maximum Lyapunov exponent, correlation dimension, and other nonlinear invariants are calculated on the phase space trajectory map (resulting in a chaotic exponent table and fractal dimension values), and a recursive state diagram is constructed for recursive quantitative analysis (resulting in recursive statistical features) to quantify the nonlinear characteristics of hardware dynamics. Change points are detected in the sequence of indicators such as the chaotic exponent table, fractal dimension values, and recursive statistical features to obtain a phase transition point sequence, indicating the transformation of dynamic patterns. Finally, the nonlinear indicators are combined with the phase transition point information to generate a nonlinear dynamic feature set reflecting the complex dynamic characteristics of the system. Based on the nonlinear dynamic feature set, the point cross-correlation matrix, and the original time series data, characteristic frequencies related to the execution of the security baseline code are identified, resulting in a characteristic frequency spectrum. The instantaneous phase of each point at each characteristic frequency is calculated using methods such as Hilbert transform, and a phase relationship network is constructed to describe the temporal coordination between components. Finally, the characteristic frequency spectrum and the phase relationship network are integrated into a unified multidimensional representation to generate a unique physical behavior pattern representation of the secure computer under normal and secure conditions, namely, the dynamic phase spectrum of secure computing behavior.

[0029] Step S3: Obtain historical operation data; calculate the phase difference of the dynamic phase spectrum of the safe computing behavior to obtain the phase difference vector; determine the normal fluctuation range of the phase difference vector to obtain the normal fluctuation boundary; judge the abnormal mode based on the normal fluctuation boundary to obtain the abnormal type judgment result; perform spatial propagation characteristic analysis on the abnormal type judgment result and the phase difference vector to obtain the abnormal propagation characteristic map; calculate the abnormal index based on the abnormal propagation characteristic map.

[0030] In this embodiment of the invention, historical operational data collected and processed by the security computer during its normal historical operation is acquired, including historical phase difference vectors and related environmental context information. During the actual operation of the security computer, sensor data of the current state is collected in real time and converted into a current operational phase representation following the same process as the baseline spectrum construction. The current operational phase representation is compared feature-by-feature with a pre-established dynamic phase spectrum of security computing behavior, calculating the differences between the two in time, frequency, space, and phase / correlation / nonlinearity feature dimensions to obtain a phase difference vector. Statistical analysis is performed on the historical phase difference vector dataset to extract the basic statistical features of each dimension, and its distribution is estimated using kernel density to obtain a dimensional density distribution map. Confidence boundaries for each dimension are calculated based on the distribution map. Combining historical environmental factor data, the influence of environmental factors on the normal fluctuations of each component of the phase difference vector is analyzed to obtain an environmental correlation factor table, and a conditional fluctuation boundary set dependent on the environment is constructed accordingly. Time-series autocorrelation analysis is performed on the historical data to obtain time-series correlation features, and a fluctuation prediction model is constructed based on these features. By combining the fluctuation prediction model, dimensional confidence boundaries, and conditional fluctuation boundary set, the normal fluctuation boundary of the currently evaluated phase difference vector in the current environment is determined. The current phase difference vector is compared with the normal fluctuation boundary to identify anomalous components exceeding the boundary. These components are then matched against a predefined anomalous pattern library to obtain an anomaly type determination result. Based on this result, the main anomalous points are located from the phase difference vector, forming an anomalous source point set. Hardware material parameters and power network data are acquired, a regional thermal parameter table is configured, and current paths are mapped to obtain a current path diagram. The thermoelectric coupling coefficient is calculated based on the current path diagram and the regional thermal parameter table. Using the thermoelectric coupling coefficient and the anomalous source points as input, a simplified time-step heat propagation simulation is performed to obtain a time-series temperature distribution sequence and calculate the heat diffusion velocity field. Combining the time-series temperature distribution sequence and the current path diagram, the time-varying influence region of the anomalous impact over time is determined. By integrating the heat diffusion velocity field, the time-varying influence region, and the inferred propagation path, features such as the anomalous starting position, propagation velocity, and influence range are extracted to generate an anomalous propagation feature map describing the anomalous diffusion behavior in the hardware. Finally, based on the comprehensive anomaly type determination results, anomaly propagation characteristic map, and anomaly temporal evolution trend (obtained through continuous monitoring and analysis), a microphysical anomaly index reflecting the severity of the current microphysical anomaly is calculated according to the preset scoring rules.

[0031] Step S4: Match the anomaly index to the task security level to obtain the task security requirement table; calculate the security credibility score based on the task security requirement table; perform security authentication based on the security credibility score to obtain the security authentication status.

[0032] In this embodiment of the invention, the currently calculated microphysical anomaly index is clustered with historical anomaly indices and categorized into a known historical anomaly pattern category to obtain anomaly pattern classification results. Information on the security-critical tasks currently being executed by the secure computer (such as task security level and data sensitivity) is obtained. Based on the current task information and the anomaly pattern classification results, a preset task security policy repository is queried to extract specific security requirements for the current situation, forming a task security requirement table. This table defines the tolerable upper limit of the anomaly index and specific physical behavior constraints. Current system operating context information (such as load, ambient temperature, and power supply voltage) is obtained. Combining the anomaly pattern classification results, the task security requirement table, and real-time context information, a risk assessment model is used to evaluate the actual security risk of the current microphysical anomaly in the current environment, obtaining a context risk assessment value. Using a preset security trustworthiness scoring algorithm, considering the context risk assessment value, the microphysical anomaly index, and the degree of conformity with the task security requirement table, a security trustworthiness score (e.g., 0-100 points) reflecting the overall security health status of the system is calculated. The security trust score is compared with preset multi-level security thresholds to determine the current system security status level (e.g., secure, warning, minor anomaly, severe anomaly). Specific security response measures corresponding to this level are then retrieved from the response policy database to generate a tiered response plan. Finally, corresponding security protection measures are implemented according to the tiered response plan, such as isolating suspicious modules, adjusting task parameters, or triggering a hardware reset. Based on the implementation results and system status, the final security authentication status is determined (e.g., authentication successful, authentication successful (restricted), authentication failed).

[0033] Preferably, step S1, which involves deploying the sensor array and acquiring data from the security computer, includes:

[0034] The temperature critical nodes are mapped and determined based on the computer's circuit design data, resulting in a critical node distribution map;

[0035] Based on the distribution map of key nodes, the sensor array is deployed to obtain the sensor network topology;

[0036] Based on the sensor network topology, a preset security baseline code segment is executed to obtain security baseline execution data;

[0037] Based on the sensor network topology and security baseline execution data, multi-dimensional physical parameters are collected to obtain a physical parameter data stream.

[0038] The physical parameter data stream is spatiotemporally synchronized to obtain calibrated spatiotemporally synchronized data.

[0039] In this embodiment of the invention, a complete circuit design document for the secure computer is obtained, including schematics (PDF format), printed circuit board (PCB) layout files (Gerber format), and a bill of materials (BOM). Using professional electronic design automation (EDA) tools, such as Cadence Allegro or Altium Designer, the layout files are imported, and the integrated circuit chips (e.g., secure microcontrollers, encryption processors, Trusted Platform Module (TPM) chips, and core areas of the main processor with security extensions) that handle sensitive information, perform cryptographic operations, manage security states, or handle high power consumption, along with related power management units, high-speed interface controllers, and other key hardware components, are identified in conjunction with the schematics. Simultaneously, the computer's power integrity (PI) analysis report and thermal analysis report are imported. These reports are typically generated using finite element analysis (FEA) software, predicting power consumption distribution and expected hotspots on the chip surface and PCB board. Based on the locations of security-critical components identified through schematic analysis and the potential high-heat / high-current density areas indicated by the PI / thermal analysis reports, a set of critical nodes requiring monitoring is determined. For example, specific physical coordinates near the core area of ​​a certain encryption coprocessor, the interface pins of secure memory, and the fuse area in the main CPU used for secure boot are identified as critical nodes. The location information of these critical nodes (e.g., X, Y coordinates on the chip package or X, Y, Z coordinates on the PCB layer) is recorded to form a critical node distribution map. Based on the critical node distribution map determined in the previous step, micro-sensors are deployed on the surface of the printed circuit board or chip package of the security computer using micro-nano fabrication technology or high-precision mounting equipment. At critical nodes where temperature monitoring is required, thin-film resistance temperature detectors (RTDs) or miniature thermocouples with dimensions of approximately 100 μm × 100 μm are deployed; at critical power paths or signal lines where current density monitoring is required, miniature Hall effect sensors or precision shunt resistors with dimensions less than 1 mm are integrated or mounted. Thermally conductive adhesive or micro-soldering technology is used to ensure tight physical coupling between the sensors and the target monitoring points to maximize signal transmission efficiency. These micro-sensors are connected to a dedicated data acquisition (DAQ) system via fine wires or flexible circuit boards, which includes multiplexers and high-resolution (e.g., 24-bit) analog-to-digital converters (ADCs). The channel mapping of the DAQ system is configured to associate the ID of each sensor with its connected critical node, sensor type, and DAQ channel. Set the DAQ system's synchronous sampling frequency to 1MHz to ensure that data from all sensors are acquired at the same time, establishing the sensor network topology. In a laboratory environment, connect the security computer to be certified, configured with the sensor network, to the DAQ system. Load a pre-defined security baseline code segment with deterministic behavior via the JTAG interface or a security bootloader.This code segment contains a series of typical security-critical operations, such as performing AES-256 encryption using a hardware accelerator, performing SHA-3 hash calculations, generating and verifying digital signatures, and accessing secure storage areas. A dedicated test execution engine controls the code's execution flow, and utilizes a high-precision timer within the CPU or an external logic analyzer to record the start and end times of the entire benchmark code segment, as well as the precise timestamps and corresponding program counter (PC) values ​​of each critical security operation sub-stage (such as the key loading stage, encryption calculation stage, and result output stage), generating security benchmark execution data. At the precise moment the security benchmark code segment begins execution, the DAQ system is triggered by the start timestamp in the security benchmark execution data. Based on the sensor network topology configuration, the DAQ system continuously acquires raw electrical signals (e.g., RTD resistance values, thermocouple voltages, Hall sensor voltages, or shunt resistor voltages) from miniature temperature sensors and current density detectors deployed at various critical nodes at a synchronous sampling frequency of 1 MHz. The DAQ system associates a high-resolution global timestamp with each acquired sensor reading. This timestamp originates from the same synchronized clock source as the timestamp in the safety benchmark execution data. The acquisition process continues until the safety benchmark code segment execution concludes, generating a physical parameter data stream containing all raw sensor readings and their corresponding timestamps. Based on each sensor's calibration curve or pre-stored calibration coefficients, the electrical signals are converted into actual physical quantity units. For example, the resistance value of the RTD is converted to degrees Celsius (°C) via a lookup table or formula, and the voltage of the Hall sensor is converted to current density using a sensitivity coefficient. Calibration formula example: temperature ,in It is the current resistance. Reference temperature The resistance below, It is the temperature coefficient of resistance; current density in It is Hall voltage. It is the Hall coefficient. The control current is achieved through a Hall sensor. Next, spatiotemporal synchronization is performed. Due to slight time delays or sampling jitter in sensor acquisition, linear interpolation or spline interpolation methods are used to resample the calibrated data from all sensors onto a unified time axis recorded in the safety benchmark execution data. This ensures that synchronized physical parameter values ​​for all key nodes are available at any given time. For example, assuming the benchmark execution data is recorded with a 1-microsecond resolution, the sensor data is also synchronized to this 1-microsecond time granularity. Simultaneously, based on the spatial location information in the sensor network topology, the synchronized physical parameter values ​​are correlated with the corresponding spatial coordinates of key nodes, forming a dataset that is precisely aligned in both time and space. Finally, a digital filter (e.g., a Savitzky-Golay filter) is applied to smooth the data, removing high-frequency noise while preserving the transient characteristics of physical quantity changes, generating calibrated spatiotemporally synchronized data.

[0040] Preferably, step S1, which involves temperature and current fusion processing of the calibrated spatiotemporal synchronization data, includes:

[0041] Data separation was performed on the calibrated spatiotemporal synchronization data to obtain temperature data and current density data;

[0042] Calculate the temperature gradient field of the temperature data;

[0043] Calculate the temperature change rate field of the temperature data;

[0044] The thermoelectric coupling strength is calculated based on the temperature change rate field, temperature gradient field, and current density data to obtain the thermoelectric coupling tensor.

[0045] Obtain the security baseline code execution log, mark the code stage based on the thermoelectric coupling tensor, and obtain the marked thermoelectric coupling tensor;

[0046] Feature point identification is performed on the labeled thermoelectric coupling tensor to obtain a set of thermoelectric feature points;

[0047] Feature point responses are extracted from the thermoelectric feature point set to obtain the feature point response sequence;

[0048] Generate a thermoelectric coupling feature map based on the feature point response sequence and the labeled thermoelectric coupling tensor.

[0049] In this embodiment of the invention, calibrated spatiotemporal synchronization data is received. This data includes temperature measurements (in °C) and current density measurements (in A / cm²) collected by miniature temperature sensors and current density detectors deployed at key nodes during the execution of the safety baseline code at precise synchronization points, and is associated with the corresponding key node spatial coordinates (e.g., (x, y, z)) and timestamps. This dataset is logically grouped according to sensor type. All time-series data associated with temperature sensors are extracted to form a temperature dataset, which is a three-dimensional structure with dimensions of time, node ID, and temperature value. Similarly, all time-series data associated with current density detectors are extracted to form a current density dataset, which is also a three-dimensional structure with dimensions of time, node ID, and current density value.

[0050] Based on the temperature dataset, at each time step, the temperature values ​​of all key nodes are treated as samples at these discrete spatial points. A continuous temperature field model is constructed over the key node distribution region using a three-dimensional interpolation method (e.g., radial basis function interpolation or kriging interpolation). Then, the spatial partial derivatives of this continuous temperature field model are calculated at each key node location. These partial derivatives constitute the temperature gradient vector. For each time step and each critical node, a temperature gradient vector is calculated. These vectors are combined to form a temperature gradient field, which is a four-dimensional structure with three components: time, node ID, and the temperature gradient vector.

[0051] Based on the temperature dataset, the rate of change of the temperature time series of each key node is calculated using a numerical differential algorithm. For example, using the central difference formula to calculate at time point... rate of change: ( ,in This refers to the sampling time interval. The time series expression for each key node is calculated point-by-point to obtain the temperature change rate over time for each node at each time point. This set of scalar values ​​forms a temperature change rate field, a three-dimensional structure with dimensions of time, node ID, and temperature change rate value.

[0052] By combining temperature change rate field, temperature gradient field, and current density data, a multidimensional data structure characterizing local thermoelectric coupling properties—the thermoelectric coupling tensor—is constructed at each time step and at each key node location. This tensor captures the relationship or combination between the temperature change rate, temperature gradient vector, and current density at each spatiotemporal point. For example, at each node... and time Construct a feature vector: [ ],in It is a node In time current density, It is the temperature gradient vector in directional components, This is the rate of change of temperature over time. These feature vectors are stacked along the time dimension and combined along the node dimension to form a three-dimensional tensor with the shape (number of time steps) × (number of nodes) × (number of feature dimensions, e.g., 5). This three-dimensional tensor represents the set of local thermoelectric states of all key nodes at all time steps, i.e., the thermoelectric coupling tensor.

[0053] The execution log of the security baseline code is obtained. This log records the precise start and end timestamps of different security-critical operation stages (such as key loading, encryption operations, and signature generation) during the execution of the preset security baseline code segment. By referring to the time dimension of the thermoelectric coupling tensor, and based on the time periods in the execution log, a corresponding code execution stage label is assigned to the data at each time step in the tensor (i.e., each time slice). For example, if time step t falls within the time range of the "encryption operation" stage, then that time slice is labeled as "encryption operation." This allows subsequent analysis to distinguish the hardware microscopic physical responses of different computational task stages, resulting in labeled thermoelectric coupling tensors.

[0054] The labeled thermoelectric coupling tensor is analyzed to identify representative or discriminative microscopic physical feature points across different code execution phases. For example, during the "encryption operation" phase, the time points and corresponding node locations where current density or temperature change rate spikes are identified. During the "key loading" phase, points where the direction of the temperature gradient field vector changes significantly are identified. Threshold detection methods are used to mark spatiotemporal points where the current density value, temperature change rate, or temperature gradient magnitude exceeds a specific dynamic threshold (which can be determined based on historical normal data distribution). Alternatively, dimensionality reduction techniques such as principal component analysis (PCA) or independent component analysis (ICA) are used to identify the feature dimension (a physical quantity at a node) that contributes the most to the overall data variance at a specific code phase, and the extreme values ​​in these dimensions are marked as feature points. The set of these identified spatiotemporal points with significant physical responses constitutes the thermoelectric feature point set.

[0055] The physical measurements corresponding to these feature points are precisely extracted from the labeled thermoelectric coupling tensor. For each point in the thermoelectric feature point set (identified by time, node ID, and feature type), the corresponding value in the labeled thermoelectric coupling tensor is queried. The extracted values ​​and their associated metadata (timestamp, node ID, feature type, code stage label) are organized into an ordered list or structured array to form a feature point response sequence. This sequence contains the most representative transient response information of the hardware's microscopic physical behavior during the execution of the security benchmark code.

[0056] By fusing the feature point response sequences with statistical information or dimensionality-reduced representations of other non-feature points in the labeled thermoelectric coupling tensor, a unique original feature map of particle thermoelectric coupling for this secure computer is generated. For example, the feature map can be a high-dimensional vector composed of: the values ​​of the feature point response sequences; statistics (such as mean, standard deviation, peak value, and maximum rate of change) calculated for the time series of each physical quantity at each key node in the labeled thermoelectric coupling tensor at each code execution phase; and a low-dimensional latent representation extracted from the labeled thermoelectric coupling tensor through nonnegative matrix factorization (NMF) or an autoencoder. This comprehensive multidimensional data structure fully and concisely characterizes the microscopic thermoelectric behavior patterns of the secure computer when executing secure baseline code, generating the original feature map of particle thermoelectric coupling.

[0057] Preferably, step S2 includes:

[0058] Step S21: Decompose the thermoelectric coupling feature map into multi-point data to obtain a point time series dataset;

[0059] Step S22: Calculate the rate of change of the point time series dataset to obtain the parameter rate of change matrix;

[0060] Step S23: Perform multi-scale wavelet decomposition on the parameter change rate matrix to obtain the wavelet coefficient spectrum;

[0061] Step S24: Analyze the inter-point correlation of the wavelet coefficient spectrum to obtain the point cross-correlation matrix;

[0062] Step S25: Perform nonlinear feature extraction on the cross-correlation matrix of the points to obtain a nonlinear dynamic feature set;

[0063] Step S26: Identify the characteristic frequencies of the nonlinear dynamic feature set to obtain the characteristic frequency spectrum;

[0064] Step S27: Construct phase relationships from the characteristic frequency spectrum to obtain a phase relationship network;

[0065] Step S28: Perform dynamic behavior spectrum synthesis on the phase relationship network and characteristic frequency spectrum to obtain the dynamic phase spectrum of secure computing behavior.

[0066] In this embodiment of the invention, a raw feature map of particle thermoelectric coupling is received. This map is the output of step S1 and contains time-series data of physical quantities such as temperature and current density at each critical node during the execution of the safety baseline code by the safety computer, as well as features extracted from this data. The raw time-series data portion of the map is parsed. This data portion is organized into a multi-dimensional array, for example, one dimension represents the time step, another dimension represents the critical node ID, and the third dimension represents the physical quantity type (temperature, current density). From this multi-dimensional array, logical segmentation is performed according to the critical node ID and physical quantity type. For example, the temperature time series of node 1, the current density time series of node 1, the temperature time series of node 2, the current density time series of node 2, and so on, until all monitored physical quantities of all critical nodes are separated into independent, one-dimensional time-series arrays. Each time-series array contains a sequence of measurements of that specific node and that specific physical quantity changing over time during the entire execution of the safety baseline code. This collection of independent time-series arrays with explicit node IDs and physical quantity type labels constitutes a point-based time-series dataset.

[0067] For each independent time series (e.g., node) in the point time series dataset Temperature time series The rate of change of time is calculated using a numerical differential algorithm. The central difference method is used to calculate the time points. rate of change ,in It is a time series in time The value, This is the sampling time interval. For the start and end points of the time series, forward differencing is used. and backward difference This process is repeated for all temperature and current density time series in the point-to-point time series dataset, calculating the rate of change of temperature and current density at each critical node at each time point. These rates of change themselves constitute new time series. These new rate of change time series are then organized by node ID and physical quantity type into a matrix or similar structure, where rows represent time steps and columns represent specific node-physical quantity rate of change combinations (e.g., node 1 temperature rate of change, node 1 current density rate of change, node 2 temperature rate of change, etc.). This matrix is ​​the parameter rate of change matrix, which highlights the transient changes of physical quantities over time.

[0068] For each column of the rate of change matrix (representing the time series of the rate of change of a certain physical quantity at a certain node), apply the Discrete Wavelet Transform (DWT). Choose a specific family of wavelet basis functions, such as Daubechies (dbN) or Symlets (symN) wavelets, and determine the number of decomposition levels L. Perform L-level DWT decomposition on each time series, decomposing the original signal into L detail coefficient sequences (D1, D2, ..., D) and an approximate coefficient sequence (A). Each detail coefficient sequence D represents the fluctuation of the original signal within a specific frequency range (scale), and the approximate coefficient sequence A represents the low-frequency trend of the signal. For example, for a sampling rate of... The signal, the The frequency band corresponding to the layer detail factor is approximately [ Multi-scale wavelet decomposition is performed on all columns of the parameter rate of change matrix. Each original time series decomposes to produce L+1 wavelet coefficient sequences. The wavelet coefficient sequences of all nodes and all physical quantities at all decomposition scales are collected to form a wavelet coefficient spectrum, which is a multi-dimensional data structure. The dimensions include node ID, physical quantity type, wavelet decomposition scale, and time step (or wavelet coefficient index).

[0069] Based on wavelet coefficient spectra, the temporal correlations between different key nodes, or between different physical quantities of the same node, at specific wavelet scales are calculated. One or more wavelet decomposition scales of interest are selected (e.g., scales corresponding to characteristic frequencies of microscopic physical processes such as gate circuit delay and signal propagation time). For each selected scale... Extract the wavelet coefficient sequences of all key nodes and physical quantities at this scale. Then, compute the wavelet coefficient sequences of any two key nodes i and k (or nodes k). physical quantity With nodes physical quantity ) at scale Cross-correlation function between wavelet coefficient sequences ],in and These are nodes and nodes In scale ,time wavelet coefficients, It's a time lag. After calculating the cross-correlation function, extract indicators representing the strength of the correlation, such as the maximum value of the cross-correlation function (...). and their corresponding lag time ( For all key node pairs and all physical quantity pairs of interest, these correlation indices are calculated at all selected scales. These indices are then organized into a matrix, where rows and columns represent different node-physical quantity combinations, and matrix elements represent the correlation strength or lag information of the corresponding combination at a specific scale. For example, a matrix can be constructed where the element (m, n) stores the maximum cross-correlation value between node-physical quantity combination m and node-physical quantity combination n at a certain scale. This set of matrices containing correlation information between points at different scales constitutes the point cross-correlation matrix.

[0070] Based on the point cross-correlation matrix, which characterizes the temporal coupling relationships of different key nodes and physical quantities at different wavelet scales, nonlinear dynamic analysis methods are applied to this correlation information to capture more complex and nonlinear hardware dynamic behavior patterns. For example, phase space reconstruction can be performed on the time-varying indices in the point cross-correlation matrix (if the sliding window correlation is calculated in S24) or on the correlation profile spanning different wavelet scales. Appropriate embedding dimensions *m* and time delays are then selected. (For example, parameters are determined from correlated data using mutual information and pseudo-nearest neighbor methods.) Each correlated time series or profile is reconstructed into an m-dimensional phase space, forming a phase space trajectory. Nonlinear invariants, such as Lyapunov exponents (the maximum Lyapunov exponent is used to quantify the degree of chaos), correlation dimension, or information dimension (used to quantify the complexity or fractal properties of the phase space), are calculated for these phase space trajectories. Simultaneously, a recurrence plot is constructed from the reconstructed phase space trajectories, and statistical features such as recurrence rate (RR), determinism (DET), and lamination (LAM) are extracted through recurrence quantitative analysis (RQA). These features reflect the repeatability and structure of the system's dynamics. The calculated Lyapunov exponents, dimensions, and RQA features are summarized for each correlated point pair and scale. This summarized set of nonlinear indicators constitutes a nonlinear dynamic feature set, which quantifies the complex dynamic characteristics in the microscopic physical behavior of hardware that are difficult to capture using linear methods.

[0071] Although the nonlinear dynamic feature set itself is not directly frequency information, it contains information about the system's dynamic patterns. By combining the original point time-series dataset or parameter rate-of-change matrix and wavelet coefficient spectrum, representative physical response frequencies related to the execution of safety baseline code are identified. For each time series in the parameter rate-of-change matrix, a power spectral density (PSD) estimation method, such as the Welch method, is applied to calculate its frequency domain distribution throughout the execution process. Frequency points with significant energy peaks in the PSD plot are identified; these are the characteristic frequencies of the signal. These characteristic frequencies are correlated with the nonlinear dynamic feature set; for example, nodes or physical quantities whose oscillation modes at specific characteristic frequencies are associated with specific nonlinear indices (such as high chaos exponents or specific RQA modes) are identified. Frequency components that appear simultaneously at multiple critical nodes or are significantly enhanced at specific code execution phases are identified as characteristic frequencies of the hardware performing safety-critical tasks. These characteristic frequency lists, along with their corresponding power or amplitude information and associated critical node and code phase information, are organized to form a characteristic frequency spectrum.

[0072] Based on the characteristic frequencies identified in step S26, return to the original point time series dataset or parameter change rate matrix. For each identified characteristic frequency f, extract the instantaneous phase information of that frequency component from the time series of all key nodes and physical quantities. Process each time series using the Hilbert Transform to obtain its analytic signal; the argument of the analytic signal is the instantaneous phase Φ(t). Calculate the instantaneous phase difference ΔΦ(t,f) = Φ between any two key nodes i and k (or physical quantity P1 of node i and physical quantity P2 of node k) at the characteristic frequency f. i (t,f)-Φ(t,f). The phase difference is averaged over time, or a phase synchronization index (such as phase lock value or average phase consistency) is calculated to obtain the average phase relationship between the two points at frequency f. A graph structure is constructed by using the average phase difference or phase synchronization index of all key node pairs (and related physical quantity pairs) at all characteristic frequencies as attributes of the "edges" connecting these points. The nodes of the graph represent key nodes or the physical quantities they monitor, and the weights or labels on the edges represent their phase relationships at specific characteristic frequencies. This graph structure is the phase relationship network, which describes the timing coordination patterns of different parts of the hardware at the microscopic level.

[0073] The characteristic frequency spectrum obtained in step S26 (containing characteristic frequencies, power / amplitude, and associated node / stage information) is integrated with the phase relationship network obtained in step S27 (containing information on the phase relationship between nodes at each characteristic frequency). A multidimensional data structure is created that can simultaneously represent time (if the analysis includes temporal evolution), frequency, spatial location, and phase information. For example, a three-dimensional tensor can be constructed, where one dimension represents a time slice (corresponding to different stages of the execution of the security baseline code), another dimension represents the characteristic frequency, and the third dimension contains a substructure, which is a matrix or graph, representing the phase relationship between all critical node pairs at that time slice and that characteristic frequency. Alternatively, a nested data structure can be constructed, with a list of characteristic frequencies at the top, each frequency containing a matrix, and matrix elements (i,j) storing the phase difference and phase consistency index between node i and node j at that frequency. This comprehensive graph, containing frequency and phase information, fully and accurately characterizes the unique, dynamic microphysical behavior pattern of the security computer when performing security-critical tasks, namely, the dynamic phase spectrum of the computer's security computing behavior.

[0074] Most importantly, the analysis of inter-point correlation in the wavelet coefficient spectrum specifically involves: constructing a list of point pairs based on the wavelet coefficient spectrum; performing correlation calculations on the wavelet coefficient spectrum for similar physical quantities based on the list of point pairs to obtain a similar correlation matrix; performing coupling analysis on the wavelet coefficient spectrum for dissimilar physical quantities based on the list of point pairs to obtain a dissimilar coupling matrix; performing time-delay correlation calculations on the similar correlation matrix and the dissimilar coupling matrix to obtain a propagation delay table; performing correlation and coupling analysis on the propagation delay table to obtain coupling anomaly markers; and generating a point cross-correlation matrix based on the coupling anomaly markers.

[0075] In this embodiment of the invention, an input wavelet coefficient spectrum is received, which contains the time-series wavelet coefficients of key nodes and physical quantities of the security computer at different wavelet scales. First, based on all monitoring entities (combinations of key nodes and physical quantities) contained in the wavelet coefficient spectrum, a list containing all unique entity pairs is constructed, forming a point pair list. Then, the point pair list is traversed. For entity pairs with the same physical quantity type (e.g., both are temperature change rates), the correlation (e.g., Pearson correlation coefficient) between their wavelet coefficient time series at a selected wavelet scale is calculated, and the result is stored in a homogeneous correlation matrix. Next, for entity pairs with different physical quantity types (e.g., temperature change rate and current density change rate), the coupling strength (e.g., maximum value of the cross-correlation function) between their wavelet coefficient time series at a selected wavelet scale is calculated, and the result is stored in a heterogeneous coupling matrix. Based on the calculation process of the homogeneous correlation matrix and the heterogeneous coupling matrix (e.g., cross-correlation function), the dominant time delay of signal propagation for each point pair at each scale is determined, resulting in a propagation delay table. Using the time delay information in the propagation delay table, a signal propagation network diagram reflecting signal flow direction and delay is constructed. Combining the correlation, coupling strength, and time delay values ​​in the signal propagation network diagram, the similar correlation matrix, and the dissimilar coupling matrix, a comparative analysis is performed with the expected normal behavior pattern. Interactions that significantly deviate from the normal pattern are identified, and the involved point pairs and scales are marked as coupling anomalies. Finally, the information from the similar correlation matrix, the dissimilar coupling matrix, the propagation delay table, and the coupling anomaly markers are integrated to generate a comprehensive point cross-correlation matrix reflecting the temporal correlation characteristics between key points at different scales.

[0076] Most importantly, the correlation and coupling analysis based on the propagation delay table specifically involves: constructing a signal propagation network diagram based on the propagation delay table; performing coupling pattern matching on similar correlation matrices and dissimilar coupling matrices based on the signal propagation network diagram to obtain behavioral pattern identifiers; performing correlation intensity space mapping on similar correlation matrices and dissimilar coupling matrices to obtain correlation heatmaps; evaluating the correlation stability of similar correlation matrices and dissimilar coupling matrices to obtain correlation stability indices; and detecting abnormal couplings on the correlation heatmaps and correlation stability indices based on behavioral pattern identifiers to obtain coupling anomaly markers.

[0077] In this embodiment of the invention, a propagation delay table is received, which records the dominant signal delays between key point pairs at different wavelet scales. Based on the point pairs and delay information in the propagation delay table, a directed weighted graph is constructed, where nodes represent monitored entities, edges represent signal propagation directions, and weights are delays or propagation speeds, forming a signal propagation network graph describing the flow of microscopic signals. Using this signal propagation network graph, combined with the correlation / coupling strength values ​​in similar and dissimilar coupling matrices, a comparison and matching with a preset normal behavior pattern library is performed to identify which known pattern the current microscopic physical interaction pattern is closest to, thus obtaining a behavior pattern identifier. Simultaneously, the physical spatial coordinates of key nodes are obtained, and the correlation / coupling strength values ​​in similar and dissimilar coupling matrices are mapped to these spatial locations. A correlation heatmap is generated using visualization methods such as color or line width to intuitively display the spatial distribution of interaction strength. Furthermore, the fluctuations of the correlation / coupling strength values ​​in similar and dissimilar coupling matrices over time or through repeated execution are analyzed, and their statistical instability index is calculated to obtain a correlation stability index. Finally, based on behavioral pattern identifiers (to determine whether the current pattern deviates from expectations), and by comparing relevant heat maps (to identify abnormal intensity or spatial distribution) and relevant stability indices (to identify abnormal instability), pre-set rules or models are used to detect abnormal interactions that do not conform to the normal pattern, and the involved point pairs and scales are marked as having coupling anomalies, generating coupling anomaly markers.

[0078] Preferably, the nonlinear feature extraction of the point cross-correlation matrix in step S2 includes:

[0079] The reconstruction parameter set is determined based on the cross-correlation matrix of the points;

[0080] Phase space trajectory is reconstructed based on the reconstructed parameter set and the point cross-correlation matrix to obtain the phase space trajectory map;

[0081] The degree of chaos is quantified by analyzing the phase space trajectory diagram to obtain a table of chaos indices.

[0082] Fractal characteristic analysis was performed on the phase space trajectory diagram to obtain the fractal dimension value;

[0083] Construct a recursive state diagram based on the phase space trajectory diagram;

[0084] Recursive quantitative feature extraction is performed on the recursive state diagram to obtain recursive statistical features;

[0085] Phase transition points are detected by analyzing the chaos index table, fractal dimension values, and recursive statistical features to obtain a phase transition point sequence.

[0086] A nonlinear dynamic feature set is generated based on the phase transition point sequence.

[0087] In this embodiment of the invention, a point cross-correlation matrix is ​​received. This matrix contains the temporal correlation, coupling strength, and time delay information of key nodes and physical quantities of the security computer at different wavelet scales. Time series for nonlinear analysis are extracted from this matrix. These time series can be sequences representing the changes in correlation coefficients or coupling strengths of specific key point pairs (e.g., the rate of temperature change of node A and the rate of current density change of node B) over time (if a sliding window calculation was used in S24) at a selected wavelet scale, or sequences representing the distribution of a specific correlation / coupling index (such as the maximum cross-correlation value) across different point pairs or scales during the entire security benchmark execution period.

[0088] Representative time series from the cross-correlation matrix of the points are selected as input (e.g., correlation or coupling strength time series at several key point pairs and important wavelet scales). The Average Mutual Information (AMI) method is applied to these time series to calculate the average mutual information between the signal and its own lagged version. Find the first local minimum. This value was determined to be the appropriate time delay. Next, the False Nearest Neighbors (FNN) method was applied to these time series, progressively increasing the embedding dimension m to calculate the percentage of false neighbors in the m-dimensional phase space. The smallest dimension m at which the percentage of false neighbors decreased to below a preset threshold (e.g., 1%) was selected. The calculated time delay was then... The values ​​of the embedding dimension m are combined to form a set of reconstruction parameters. These parameters are used for subsequent phase space reconstruction.

[0089] Using the reconstruction parameter set determined in the previous step ( For each selected time series S(t) in the cross-correlation matrix, phase space reconstruction is performed. For each time point in the time series... Construct an m-dimensional phase space vector Repeat this process until the last valid point of the time series, generating a series of m-dimensional vectors. The sequence of these vectors in m-dimensional space constitutes the phase space trajectory of the time series. Phase space reconstruction is performed on all time series in the point cross-correlation matrix that are intended for nonlinear analysis. The phase space trajectories obtained from all reconstructions are collected to form a phase space trajectory diagram, which is a collection that visualizes or represents the dynamic behavior of the original time series in a high-dimensional space.

[0090] For each reconstructed trajectory in the phase space trajectory diagram, calculate its maximum Lyapunov exponent ( The Lyapunov exponent measures the average rate at which adjacent trajectories in phase space separate exponentially over time; a positive maximum Lyapunov exponent is a hallmark of chaotic systems. It is calculated using algorithms such as the Rosenstein algorithm or the Kantz algorithm. For each reconstructed trajectory, a... Value. These The values ​​are organized into a table, where each item corresponds to a reconstructed trajectory (i.e., a specific time series in the point cross-correlation matrix), and its calculated maximum Lyapunov exponent is recorded. This table is the chaos index table, which quantifies the degree of chaos in the dynamic patterns of microphysical interactions in secure computers.

[0091] For each reconstructed trajectory in the phase space trajectory diagram, its fractal dimension is calculated. The fractal dimension describes the efficiency with which the phase space trajectory fills the space, reflecting the complexity and self-similarity of the system. It can be used in conjunction with correlation dimension (...). Calculation method. Correlation dimension. By calculating the distance between pairs of points in phase space, it is found that the distance is less than... The quantity varies The rate of change is used to estimate, that is , where N p It is a point-to-point quantity. It's the Heaviside function. It is a distance metric. When When it approaches 0, ,but For each reconstructed trajectory, a fractal dimension value is calculated. These fractal dimension values ​​are then organized into a list or table, with each entry corresponding to a reconstructed trajectory and recording its calculated fractal dimension. This list or table represents the fractal dimension values, quantifying the geometric complexity of the dynamic modes of microscopic physical interactions in phase space.

[0092] For each reconstructed trajectory {V} in the phase space trajectory diagram i}, construct its recurrence plot (RP). The recurrence plot is an N×N binary matrix RP, where N is the number of trajectory points. Matrix elements If and only if phase space points and Distance between Less than or equal to a preset threshold ;otherwise Threshold The choice of recursive state graphs is typically based on a percentage of the average or maximum diameter of the trajectory. Recursive state graphs reveal the repeatability and proximity of phase space trajectories in a two-dimensional graphical form, serving as a tool for visualizing the dynamic behavior of high-dimensional systems. A recursive state graph is constructed for each reconstructed trajectory, forming a set of recursive state graphs.

[0093] For each recurrence state graph, Recurrence Quantitative Analysis (RQA) was applied to extract statistical features. RQA analysis quantifies the structural features in the recurrence state graph, such as the density and length distribution of patterns like diagonals, vertical lines, and isolated points. Extracted features include: Recurrence Rate (RR): Recurrence Points (RP) ij The proportion of the total number of points in the matrix to the total number of points (=1). Determinism (DET): Forms a diagonal (length ≥ The proportion of recursive points to all recursive points.

[0094]

[0095] in It is a length of A histogram of the number of diagonals. It is the minimum line segment length threshold. Lamination (LAM): forms vertical lines (length...) The proportion of recursive points to all recursive points.

[0096]

[0097] in It is a length of A histogram of the number of vertical lines. It is the minimum line segment length threshold. Entropy (ENT): Shannon entropy of the diagonal length distribution, reflecting the complexity of the system. Trend (TREND): The degree to which the recursive point deviates from the main diagonal, reflecting the non-stationarity of the system.

[0098] Calculate these RQA eigenvalues ​​for each recursive state graph. Organize these eigenvalues ​​into a table, where each row corresponds to a reconstructed trajectory and its recursive state graph, recording the set of calculated RQA eigenvalues. This table represents the recursive statistical features, quantifying the repeatability, determinism, complexity, and stationarity of the dynamic patterns of microscopic physical interactions.

[0099] Values ​​in the chaos index table, fractal dimension values, and recursive statistical features are considered as sequences of indicators that change over time (if the original time series is computed using a sliding window) or with different stages of code execution. Change point detection algorithms are applied to these sequences, such as statistically based methods (e.g., CUSUM, EWMA control charts for detecting changes in mean or variance), nonparametric methods (e.g., the Mann-Whitney U test applied to a sliding window), or model-based Bayesian change point detection algorithms. These sequences are examined for statistically significant, persistent, or abrupt changes throughout the execution of the safety benchmark code. These changes signify shifts in the microphysical dynamics of the safety computer, such as a transition from a steady state to a quasi-periodic oscillation or chaotic state, or a significant change in the degree / complexity of chaos. The timestamps or corresponding code execution stages of all detected changes are recorded, forming a phase transition sequence.

[0100] A final nonlinear dynamic feature set is constructed using the phase transition point sequence. One generation method is to use the phase transition point sequence itself as the feature set, i.e., the feature set is a list of timestamps or code stage identifiers for all detected phase transition points. Another generation method is to combine values ​​from the chaos index table, fractal dimension values, and recursive statistical features with the phase transition point information. For example, the feature set may include: the corresponding chaos index, fractal dimension, and RQA feature value at each detected phase transition point; or, calculating the statistics (such as mean, standard deviation, and magnitude of change) of these nonlinear indicators between adjacent phase transition points or within a specific code stage. Alternatively, the phase transition point sequence can be used as an index to extract a set of nonlinear indicators for a specific time or stage from the original chaos index table, fractal dimension values, and recursive statistical feature table. This final structured dataset comprehensively reflects the nonlinear characteristics of the microphysical dynamic patterns of a security computer performing security-critical tasks and their evolution over time; this is the nonlinear dynamic feature set.

[0101] Preferably, step S3 includes the following steps:

[0102] Step S31: Collect and perform real-time feature acquisition and transformation on the current operating status sensor data to obtain the current operating phase representation;

[0103] Step S32: Perform multidimensional difference calculation on the dynamic phase spectrum of the current running phase characterization and safe computing behavior to obtain the phase difference vector;

[0104] Step S33: Determine the normal fluctuation range of the phase difference vector to obtain the normal fluctuation boundary;

[0105] Step S34: Construct an adaptive threshold based on the normal fluctuation boundary to obtain a dynamic detection threshold set;

[0106] Step S35: Classify the phase difference vector into anomaly patterns based on the dynamic detection threshold set to obtain the anomaly type determination result;

[0107] Step S36: Perform spatial propagation feature analysis on the anomaly type determination result and phase difference vector to obtain an anomaly propagation feature map;

[0108] Step S37: Extract the temporal evolution pattern from the anomaly propagation feature map to obtain the anomaly evolution trend;

[0109] Step S38: Calculate the anomaly index based on the anomaly type determination result, the anomaly propagation characteristic map, and the anomaly evolution trend.

[0110] In this embodiment of the invention, during the actual operation of the secure computer, when performing security-critical tasks, measurement data of physical parameters such as temperature and current density are collected in real time through miniature sensor arrays deployed at critical nodes. The collected raw sensor data (including timestamps, node IDs, and physical quantity values) is transmitted to the data processing unit. This processing unit performs the same operations as the security baseline data processing chain: first, the raw data is calibrated and spatiotemporally synchronized to generate calibrated spatiotemporally synchronized data for the current operating state. Then, temperature and current fusion processing is performed on the data to generate a thermoelectric coupling feature representation for the current operating state (not necessarily a complete spectrum, but a real-time slice). Next, point-to-point time-series correlation analysis is performed on the feature representation to calculate the point-to-point cross-correlation matrix within the current time window. Finally, nonlinear feature extraction is performed on the real-time cross-correlation matrix to identify characteristic frequencies and construct phase relationships, generating a real-time multidimensional representation reflecting the microscopic physical dynamics of the current operating state, i.e., the current operating phase characterization. This process uses the exact same algorithm, parameters (such as wavelet basis, number of decomposition layers, reconstruction parameters) and processing flow as when constructing the dynamic phase spectrum of secure computational behavior (step S2), ensuring comparability with the benchmark spectrum.

[0111] The system receives the current operational phase representation (real-time) and a pre-established dynamic phase spectrum of safe computing behavior (benchmark). Both data structures characterize the microphysical dynamics of the safe computer in a multidimensional form, with dimensions including time (or code phase), frequency, space (point pairs), and phase / correlation / nonlinearity features. The current operational phase representation is compared element-wise or feature-wise with the benchmark dynamic phase spectrum. For example, it compares the phase difference, correlation coefficient, or coupling strength between a key point pair at a specific code execution phase and a specific feature frequency with the corresponding values ​​in the benchmark spectrum. The set of these differences is calculated. If the phase spectrum is represented as a high-dimensional vector or tensor, the difference calculation can be performed by subtracting corresponding elements to obtain a difference vector or difference tensor, Diff = Current - Baseline. This difference vector or tensor contains the degree of deviation between the current operational state and the expected safe benchmark state in various aspects of microphysical dynamic behavior. For example, a component of the phase difference vector represents the difference between the temperature correlation coefficient between node A and node B at a frequency of 100 kHz and the benchmark value. This multidimensional set of differences constitutes the phase difference vector.

[0112] Acquire a large amount of phase difference vector data collected by secure computers under normal operating conditions from a historical operational database. This historical data is accumulated under different normal environmental conditions and loads by calculating the differences between real-time operational phase representations and baseline phase spectra. Perform statistical analysis on these historical phase difference vector data. For each dimension of the phase difference vector, calculate the statistical distribution characteristics of its historical data, such as mean, standard deviation, minimum, maximum, and quantiles (e.g., 1%, 5%, 95%, 99%). Use statistical methods (e.g., hypothesis testing, control chart theory) or probability distribution models (e.g., Gaussian distribution, extreme value distribution) to determine the statistical fluctuation range of each dimension under normal operating conditions. For example, for a certain difference component d... i Determine its 99% confidence interval [L] i U i ], that is, d under normal circumstances i There is a 99% probability that it falls within this range. These statistical fluctuation ranges, which define each dimension of the phase difference vector, constitute the normal fluctuation boundary.

[0113] Based on the normal fluctuation boundary [L] determined in the previous step i U i This sets an initial anomaly detection threshold for each dimension of the phase difference vector. For example, the threshold can be set to the maximum permissible absolute deviation from the normal range, i.e., Threshold. i =max(|L i |,|U iAn adaptive mechanism is introduced to dynamically adjust these thresholds based on the current operating context of the secure computer and the set security policies. The contextual information considered includes the current system load, ambient temperature, power supply voltage fluctuations, and the security criticality level of the currently executed task. For example, if the system load is currently high and physical fluctuations are expected to increase, some or all thresholds can be appropriately relaxed according to a preset scaling factor (e.g., a lookup table or model based on the relationship between load and fluctuations). If the currently executed task is a high-security-level encryption operation, the thresholds can be tightened to improve detection sensitivity. These adjustment factors and rules are stored in the security policy configuration. The thresholds for each dimension, calculated or adjusted according to the current context, are aggregated to form a dynamic detection threshold set.

[0114] Compare each component d of the currently calculated phase difference vector i Its corresponding dynamic detection threshold Threshold i If there exist one or more components that satisfy |d i |>Threshold i If a microphysical anomaly is detected, the current operating state is determined to have a microphysical anomaly. Further analysis is performed to identify which components exceed the threshold, the magnitude of the exceedance, and the position of these components in the phase difference vector (corresponding to which critical node pair, physical quantity, frequency, or code stage), and this is matched against a predefined anomaly pattern library. The anomaly pattern library stores typical characteristic patterns (e.g., which components are anomalous, the direction and magnitude of the anomaly) exhibited on the phase difference vector by known types of microphysical anomalies (such as decreased correlation of specific nodes due to hardware aging, power / temperature fluctuation pattern changes at specific stages due to side-channel attacks, and transient timing anomalies caused by fault injection). Pattern matching algorithms (e.g., rule-based expert systems, support vector machines (SVM), neural networks) are used to compare the currently detected anomaly difference patterns with patterns in the library, determining the anomaly type and providing a confidence level. The determination result includes a list of detected anomaly types, the confidence level for each type, and the main anomaly difference components involved. This information constitutes the anomaly type determination result.

[0115] Based on the anomaly type determination, identify the physical quantities and key nodes primarily affected by the current anomaly. For example, if determined to be a "thermal anomaly," focus on temperature-related difference components; if determined to be a "power supply anomaly," focus on current density-related difference components. Backtrack to the phase difference vector to identify components exceeding thresholds or exhibiting significant differences, and associate these components with the spatial coordinates of key nodes (from the key node distribution map in step S1). Analyze the distribution and timing of these anomaly differences in the hardware space (if the phase difference vector is calculated using a sliding window). For example, if multiple physically adjacent node difference values ​​simultaneously or sequentially exceed the threshold with short time delays, it indicates that the anomaly is propagating outward from a source point. Combine the physical topology of the security computer (power network, heat conduction paths) to infer the anomaly's source, propagation path, and impact range. Use graph theory methods or physical simulation models (simplified thermal / circuit models) to simulate or analyze the diffusion process of the anomaly signal in the hardware, comparing it with the actually observed spatial patterns of anomaly differences. Output a visual or structured representation showing the spatial location, source, propagation direction, scope of influence, and propagation speed of the anomaly (if these can be inferred from temporal differences), forming an anomaly propagation feature map.

[0116] Throughout the execution of safety-critical tasks, steps S31-S36 are continuously processed in real-time or near real-time. This generates a series of anomaly type determination results and anomaly propagation characteristic maps that change over time. These time-series anomaly characteristics are analyzed to extract the temporal evolution patterns of the anomalies. For example, the anomaly index (see S38) is monitored over time to identify its trend (rising, falling, stable), volatility (periodic, random), and duration. The anomaly propagation characteristic map series is analyzed to observe whether the anomaly's impact range is expanding or shrinking, whether the propagation speed is accelerating or slowing down, and whether the anomaly source point has shifted. Time series analysis techniques (such as regression analysis and Hidden Markov Models, HMM) are applied to model the temporal behavior of the anomalies. The observed temporal patterns are classified into predefined states, such as "instantaneous pulse," "continuous stability," "slow diffusion," and "periodic occurrence." It is determined whether the anomaly is strengthening, weakening, or remaining stable. These analytical results are combined to form a description of the current microscopic physical anomaly's evolution trend.

[0117] Based on the output information from steps S35, S36, and S37, a single quantitative indicator reflecting the severity of microphysical anomalies in secure computers is calculated: the Microphysical Anomaly Index. A scoring function or rule set is defined, taking anomaly type, spatial propagation characteristics, and temporal evolution trend as input. For example, different base risk weights are assigned to different anomaly types (e.g., fault injection > side-channel attack > hardware aging). Based on the anomaly propagation characteristic map, the base risk weights are adjusted considering the number of critical nodes affected by the anomaly, the size of the impact range, and the propagation speed (e.g., the larger the impact range and the faster the propagation speed, the higher the risk). The risk weights are further adjusted based on the anomaly evolution trend (e.g., anomalies in a "rapidly increasing" trend are more risky than anomalies in a "slowly declining" trend). The scoring function can weight and sum these factors or use a non-linear combination. For example: Anomaly Index = W <type>×Risk(AnomalyType)+W <spatial>×Risk(SpatialFeatures)+W <temporal>×Risk(TemporalEvolution), where W is the preset weight and Risk is the risk scoring function for the corresponding feature. The calculated value is the microphysical anomaly index, which is a continuous value between 0 and 100, where 0 represents no anomaly and 100 represents the most severe anomaly.

[0118] Preferably, step S3, determining the normal fluctuation range of the phase difference vector, includes:

[0119] Basic statistical features are extracted from the phase difference vector to obtain a set of dimensional statistical features.

[0120] Kernel density distribution estimation is performed on the dimensional statistical feature set to obtain the dimensional density distribution map;

[0121] Dimension confidence boundaries are calculated based on the dimensionality density distribution map;

[0122] Based on the dimensional confidence boundary, an environmental factor correlation analysis was performed on the historical operational data to obtain an environmental correlation factor table;

[0123] Construct a conditional fluctuation boundary set based on the environmental correlation factor table;

[0124] Time-series autocorrelation analysis was performed on historical operational data to obtain time-series correlation characteristics;

[0125] A volatility prediction model is constructed based on time-series correlation characteristics;

[0126] Normal fluctuation boundaries are generated based on the fluctuation prediction model, dimensional confidence boundary, and conditional fluctuation boundary set.

[0127] In this embodiment of the invention, a large dataset of phase difference vectors collected by a secure computer under normal operating conditions and stored in a historical operation database is received. This dataset contains phase difference vectors collected at multiple time points or during code execution phases. Each vector has the same dimension N, where N is the number of components of the phase difference vector. Each component corresponds to a specific key node pair, physical quantity, wavelet scale, and combination of phase / correlation / nonlinear features.

[0128] Perform independent statistical analysis on each dimension (i.e., each component) of the historical phase difference vector dataset. For the i-th dimension (i=1,...,N), extract the set of values ​​for that dimension across all historical samples. Calculate descriptive statistics for this set of values, including the mean μ. i Standard deviation σ i Minimum value min i Maximum value (max) i , median median i quartile Q1 i and Q3 i skewness i and kurtosis i These statistics characterize the central location, dispersion, range, and distribution shape of the historical fluctuation data for that dimension. These statistics for all dimensions are collected into a table or structure, where each row corresponds to a dimension and the columns are the calculated statistical feature values. This table is the set of dimensional statistical features.

[0129] Using the data provided by the dimensional statistical feature set (actually the set of values ​​for each dimension in the original historical data), nonparametric estimation of the numerical distribution of each dimension is performed. For the historical numerical set of the i-th dimension... (A total of M historical samples) are used to estimate their probability density function (PDF) using the kernel density estimation (KDE) method. Choose the Gaussian kernel function. and appropriate bandwidth h i (For example, using Silverman's Law) IQR i It is the interquartile range The estimated PDF is... Perform KDE on all N dimensions to generate N estimated probability density function curves. The set of these PDF curves constitutes a dimensionality density distribution map, which smoothly represents the distribution of historical values ​​for each dimension.

[0130] PDF estimation based on each dimension of the dimensional density distribution map Determine a minimum interval [L] that contains a pre-set confidence level P (e.g., 99%). i U i One way to calculate this interval is to find the cumulative distribution function (CDF, ​​i.e., the integral of the PDF). of and Quantiles. For example, for a 99% confidence level, find quantiles. and of and These two values The range of numerical fluctuation for the i-th dimension under normal operating conditions is defined as 99%. Confidence boundaries are calculated for all N dimensions. These are defined by N intervals [ The set of elements constitutes the dimension confidence boundary.

[0131] Acquire environmental factor data recorded simultaneously with historical operational data, such as system CPU load (%), ambient temperature (°C), power supply voltage (V), and network throughput (Mbps). For each sample in the historical phase difference vector dataset, in addition to recording the values ​​of its N components, also record the environmental factor values ​​at that time. Analyze the value d of each phase difference vector dimension i. i Environmental factors collected at the same time The relationship between them. A multiple linear regression model is used. ,in It is the regression coefficient. It's the residual. Calculate each regression coefficient. The value of and its statistical significance (e.g., p-value). Significantly nonzero. Indicates environmental factors Dimension The normal fluctuations have a linear impact on the mean. Alternatively, analyze the effect of environmental factors on the dimension. The effect of the range of fluctuations (e.g., standard deviation or interquartile range) is assessed using a regression model. Or perform grouped statistical analysis (such as ANOVA) to compare dimensions under different environmental conditions. The variance of the values. (This refers to all dimensions.) With all environmental factors The results of the association analysis (e.g., regression coefficients, The results of the analysis of values ​​and variance are summarized in a table. This table is the environmental correlation factor table, which quantifies which environmental factors affect the normal fluctuation characteristics of each component of the phase difference vector.

[0132] Based on the significant correlations identified in the environmental correlation factor table, a conditional fluctuation boundary model dependent on environmental factors is constructed for each dimension of the phase difference vector. For dimensions significantly correlated with environmental factors... The mean is defined according to the association model. and / or standard deviation How to adapt to environmental factors (A vector containing the current values ​​of all relevant environmental factors) changes. For example, if the regression model shows... If the load L increases linearly, then define If variance As the ambient temperature T increases, then the definition is... ,in It is an increasing function. Using these conditional means and standard deviations, or conditional distribution information directly derived from environmental correlation analysis, dimensions are defined. Conditional confidence interval under specific environment E For example, based on the conditional mean and standard deviation, one can use... As a conditional boundary, Z is the Z-value derived from the standard normal distribution according to the required confidence level. For dimensions that are not significantly associated with environmental factors, the conditional boundary can remain the dimensional confidence boundary. These boundary definition rules or function sets, which are constructed for all dimensions and depend on environmental factors, constitute the conditional fluctuation boundary set.

[0133] The historical phase difference vector dataset is treated as a multivariate time series. For each dimension i, the time series... Perform time series analysis. Calculate the autocorrelation function (ACF) and partial autocorrelation function (PACF) for each dimension. ACF(k) measures... and The linear correlation between dimensions is analyzed, and PACF(k) measures the direct correlation after removing intermediate lags. Analyzing the ACF and PACF plots identifies significant autocorrelation lags k, such as the presence of periodicity (ACF peaks within a period) or trends (ACF slowly decays). Furthermore, the Granger causality test can be used to analyze whether there are temporal interactions between different dimensions, such as whether historical values ​​of dimension i can predict future values ​​of dimension j. These ACF, PACF, and Granger causality analysis results constitute the temporal correlation characteristics.

[0134] By leveraging temporal correlation features, a time series forecasting model is constructed for each dimension of the phase difference vector. For example, if the ACF and PACF of dimension i exhibit autoregressive and moving average characteristics, an ARIMA(p,d,q) model can be used, where p, d, and q are the model orders, determined based on the ACF / PACF plot or information criteria (such as AIC, BIC). The model form is as follows:

[0135]

[0136] Where L is the lag operator. If the time series is nonlinear or contains complex dependencies (e.g., cross-dimensional effects discovered through Granger causality), more sophisticated models, such as Vector Autoregressive (VAR) models, can be used to model interactions between multiple dimensions, or neural network-based models, such as Long Short-Term Memory (LSTM) networks, can be used. These models aim to predict the current time step. Below, dimension In the next moment The expected value or its probability distribution These trained models, capable of predicting future fluctuations, constitute a volatility prediction model.

[0137] Combining the results of the previous steps, the normal fluctuation boundary of the phase difference vector being evaluated at the current moment is generated. For the current moment... The acquired phase difference vector is used to obtain the environmental factor value E(t) at the current moment. First, the conditional fluctuation boundary set and... Calculate each dimension Preliminary conditional fluctuation boundary Then, using a fluctuation prediction model, input historical phase difference data from the current moment and previous times. and current environmental factors Prediction dimension The expected value or its probability distribution at the next time step (the current evaluation time). By combining the predicted distribution and the initial conditional boundary, the final normal fluctuation boundary is generated. For example, the final boundary can be defined as the 99% high-density interval of the predicted distribution, or the initial conditional boundary can be dynamically adjusted based on the prediction uncertainty (e.g., prediction variance). Alternatively, if a multivariate prediction model is used, the joint probability distribution of the entire phase difference vector at the current time can be directly predicted. The normal fluctuation boundary is defined as the 99% confidence region of this multidimensional distribution. This set of expected fluctuation regions or fluctuation intervals in each dimension in the multidimensional space determined by the currently assessed phase difference vector is the normal fluctuation boundary.

[0138] Preferably, step S3, which involves spatial propagation feature analysis of the anomaly type determination result and the phase difference vector, includes:

[0139] Based on the anomaly type determination results, thermoelectric anomaly points are located using the phase difference vector to obtain the anomaly source point set;

[0140] Obtain hardware material parameters, combine them with the set of abnormal source points to configure heat conduction parameters, and obtain a regional thermal parameter table;

[0141] A current path near mapping is performed on the set of abnormal source points to obtain the current path diagram;

[0142] The thermoelectric coupling coefficient was calculated based on the current path diagram and the regional thermal parameter table.

[0143] Time-step propagation simulation was performed based on the thermoelectric coupling coefficient to obtain the time-series temperature distribution sequence;

[0144] The thermal diffusion velocity field is obtained by calculating the diffusion velocity of the time-series temperature distribution sequence.

[0145] The time-varying influence region is determined based on the time-series temperature distribution sequence and current path diagram;

[0146] The propagation path of the thermal diffusion velocity field and the time-varying influence region is extracted to obtain the abnormal propagation path;

[0147] Propagation mode features were extracted from the thermal diffusion velocity field, time-varying influence area, and abnormal propagation path to obtain an abnormal propagation feature map.

[0148] In this embodiment of the invention, an anomaly type determination result and a phase difference vector are received. The anomaly type determination result indicates the type of the currently detected microscopic physical anomaly (e.g., thermal anomaly, electrical anomaly, thermoelectric coupling anomaly), while the phase difference vector quantifies the degree of deviation between the current operating state and the reference state at each key node, each physical quantity, and each wavelet scale.

[0149] Analyze which components in the phase difference vector significantly exceed the normal fluctuation boundary. Associate these anomalous components with their corresponding key node IDs and physical quantity types (temperature or current density). Based on the anomaly type determination, further filter or weight these anomalous points. For example, if the determination is "thermal anomaly," focus on points with significant temperature differences; if the determination is "electrical anomaly," focus on points with significant current density differences; if the determination is "thermoelectric coupling anomaly," focus on points that exhibit anomalies in both temperature and current density correlation differences, or points that exhibit anomalies in the coupling strength / time delay of dissimilar physical quantities. Among these identified key nodes with significant anomalies, infer the anomaly initiation point or influence center based on their anomalous amplitude, the timing of anomaly occurrence, and their correlation with surrounding nodes (e.g., an anomaly in a node precedes its neighboring nodes). The set of key nodes identified as anomaly sources or strong anomaly manifestation points, along with their corresponding physical quantity types and anomaly intensity information, constitutes the anomaly source point set.

[0150] Obtain detailed material composition information for secure computer hardware, including printed circuit board (PCB) substrate materials (e.g., FR-4), copper layer thickness, solder type, chip packaging materials (e.g., epoxy resin, ceramic), and heat sink materials (e.g., aluminum, copper). These materials possess different thermophysical properties, such as thermal conductivity λ (W / (m·K)), density ρ (kg / m³), and specific heat capacity c. p (J / (kg·K)). Based on the key node locations within the anomaly source set, appropriate thermophysical parameters are configured for different material components containing these anomaly sources and their surrounding areas on the physical model of the security computer (e.g., a finite element mesh model constructed from PCB layout files and 3D models). For example, the thermal conductivity of the CPU package area is set to the weighted average of silicon and the package material, and the thermal conductivity of the PCB copper traces is set to the value for copper. These configured regions, materials, and their corresponding thermal conductivity parameters (λ, ρ, c) are then configured. p The information is organized into a table to form a regional thermal parameter table.

[0151] Acquire power network design data for the security computer, including power planes, ground planes, power traces, voltage regulator modules (VRMs), and power pin connections for critical chips. For points involving current density within anomaly source clusters (typically current density anomalies), use the power network design data to trace the power traces or planes containing these points, tracing upstream to the power output (e.g., VRM) and downstream to the load (e.g., internal chip functional units). Identify the main current paths associated with these anomalies. Visualize these identified current paths on the security computer's physical topology, using arrows to indicate current direction. If the anomaly source is a temperature anomaly, but its anomaly type is determined to be related to electrical activity (e.g., side-channel attack), then the current paths of critical circuits near that temperature point also need to be analyzed. This collection of visualized or structured current path information constitutes a current path diagram.

[0152] The thermoelectric coupling coefficient characterizes how electrical activity is converted into heat and how temperature changes affect electrical behavior (e.g., resistivity changes with temperature). Based on the current distribution in the current path diagram and material properties in the regional thermal parameter table, the local thermoelectric coupling strength in key regions is calculated. For example, the Joule heat generation rate Q = J²·ρ <e>Where J is the current density, ρ <e>It refers to the resistivity of the material. Resistivity ρ <e>It usually varies with temperature T, for example, ρ <e>(T)=ρ <e0>[1+α(T-T0)], where p <e0>Here, α is the resistivity at the reference temperature, and α is the temperature coefficient of resistance. At each critical node region, based on its material properties and current density, the heat generated per unit current activity or the impact of per unit heat on electrical parameters is calculated. For example, the ratio of a local heat power generation density to the square of the current density, Q / J², is calculated. These local or regional thermoelectric coupling strength quantifications are compiled into a thermoelectric coupling coefficient table, which describes the efficiency of electrical activity in converting to heat energy and the effect of temperature on electrical characteristics in different physical regions of the secure computer.

[0153] A simplified transient heat conduction simulation is performed on a physical model of a safety computer using a regional thermal parameter table and thermoelectric coupling coefficient. The simulation input is the anomalous thermal power generated by electrically active points within the anomalous source set (estimated using the thermoelectric coupling coefficient based on the anomalous current density amplitude). The initial condition for the simulation is the temperature distribution under the baseline state. At the discretized time step, Fourier's law of heat conduction is applied. T / t=α <thermal> ²T+Q / (ρc p The hardware model is used to calculate the propagation and diffusion of anomalous thermal power over time, including boundary conditions (such as convection and radiation). α... <thermal>=λ / (ρc p ) represents thermal diffusivity. The simulation process begins at the time point of an anomaly occurrence and continues for a certain period. At each time step, the temperature values ​​at critical node locations or other regions of interest are recorded. This set of temperature values ​​changing over time represents the time-series temperature distribution sequence caused by the propagation of additional thermal effects generated by the anomaly source within the hardware.

[0154] Based on a time-series temperature distribution sequence, the propagation speed of heat in the hardware is analyzed. For the region near the anomaly source, the time required for temperature peaks or temperature change rate peaks to propagate from the source to surrounding critical nodes is monitored. The average speed of temperature signal propagation from one critical node to another in different directions is calculated. For example, if the temperature change rate of a source reaches its peak at time t1, and the temperature change rate of its neighboring node reaches its peak at time t2, and the spatial distance between the two points is d, then the propagation speed in that direction is ≈ d / (t2-t1). Calculations are performed in multiple directions within the anomaly's influence area to obtain the heat propagation speed in different directions. These calculated local propagation speed values ​​are aggregated to form a thermal diffusion velocity field, which is a spatially distributed vector field indicating the speed and direction of heat propagation in different areas of the hardware.

[0155] By combining time-series temperature distribution sequences and current path diagrams, the hardware regions affected by anomalies over time are identified. For each time step in the time-series temperature distribution sequence, key nodes are identified where temperature values ​​significantly deviate from the normal range (e.g., exceeding a reference temperature plus a certain threshold). These nodes constitute the thermal anomaly-affected region within that time step. Simultaneously, if the anomaly involves current density, hardware components and regions associated with the abnormal current path are identified based on the current path diagram. As time progresses, the thermal anomaly-affected region expands, and the impact range of the current anomaly extends along the current path. These sets of key nodes or hardware regions affected by the anomaly identified at different time steps are recorded to form a time-varying impact region sequence, which describes the dynamic change of the anomaly's impact range over time.

[0156] By synthesizing the thermal diffusion velocity field, the time-varying sequence of affected regions, and further extracting the anomaly propagation path from this information (e.g., the trajectory formed over time by connecting the center or boundary of the time-varying affected region), key features characterizing the anomaly propagation pattern are extracted. These features include, for example, the anomaly's starting location (set of anomaly source points), propagation direction (main direction of the thermal diffusion velocity field), propagation speed (average speed of the thermal diffusion velocity field or speed on the critical path), maximum affected area (maximum area of ​​the time-varying affected region), propagation duration, and the complexity of the propagation path (e.g., whether it propagates along a specific power line or heat conduction path, or whether it crosses an isolation boundary). These quantified propagation feature values ​​are aggregated to form a structured data representation. Furthermore, a visualization can be generated, overlaying the anomaly source points, propagation path, time-varying boundaries, and velocity vectors onto the hardware physical topology map. This set of quantified propagation features and / or visualizations constitutes the anomaly propagation feature map, which comprehensively describes the spatial and temporal diffusion behavior of microphysical anomalies in secure computer hardware.

[0157] Preferably, step S4 includes the following steps:

[0158] Step S41: Perform historical abnormal index clustering on historical operational data and abnormal indices to obtain abnormal pattern classification results;

[0159] Step S42: Obtain information on the currently executing task; perform task security level matching based on the current executing task information and the abnormal mode classification results to obtain the task security requirement table;

[0160] Step S43: Perform a context-aware risk assessment based on the task safety requirements table to obtain the context risk assessment value;

[0161] Step S44: Based on the contextual risk assessment value, anomaly index, and task security requirements table, calculate the credibility score using a preset scoring algorithm to obtain the security credibility score;

[0162] Step S45: Compare the security trust score with the preset multi-level security thresholds to determine the response level that needs to be activated and generate the corresponding graded response plan;

[0163] Step S46: Perform security authentication according to the hierarchical response scheme to obtain the security authentication status.

[0164] In this embodiment of the invention, a historical dataset of microphysical anomaly indices recorded by a security computer during long-term operation and stored in a historical operational database is obtained. This dataset contains a large number of anomaly index values ​​and relevant contextual information (e.g., anomaly type, propagation characteristics) when these indices are detected. These historical anomaly index values ​​are treated as a dataset and subjected to unsupervised learning analysis using the K-Means clustering algorithm. The number of clusters K is set (e.g., K=3, representing three modes: low anomaly, medium anomaly, and high anomaly, or the optimal K value can be determined based on the historical data distribution using the elbow method or silhouette coefficient method). The algorithm iteratively calculates K cluster centers and assigns each historical anomaly index sample to the cluster containing the nearest cluster center. After clustering, each cluster represents a historical anomaly pattern category. Statistical characteristics of each cluster are calculated, such as the mean and variance of the anomaly index within the cluster, and the location of the cluster center. The microphysical anomaly index calculated at the current moment is received. The distance between the current anomaly index and these K historical cluster centers is calculated (e.g., Euclidean distance), and the current index is assigned to the nearest cluster. The identifier of the cluster (e.g., cluster ID or predefined pattern name such as "moderate anomaly pattern") is the result of the anomaly pattern classification.

[0165] Obtain detailed information about the security-critical tasks currently being performed by the secure computer. This information typically includes a unique task identifier, a pre-assigned task security criticality level (e.g., Level 1 - highest, Level 4 - lowest), and the data sensitivity classification being processed (e.g., Top Secret, Confidential, Public). Access a pre-configured task security policy repository. This repository is a mapping table or rule base that defines detailed constraints and tolerance requirements for microphysical anomaly indices and related physical behaviors under different combinations of task security criticality levels, data sensitivity classifications, and various anomaly pattern classification results. For example, the policy might state: "If the task security level is 1 and the anomaly pattern classification result is 'moderate anomaly pattern,' then the microphysical anomaly index must be less than 20, and the thermal coupling stability index of the critical node encryption module must not decrease by more than 5%." Based on the currently obtained task information and the anomaly pattern classification results from the previous step, search for matching entries in this repository and extract the specific security requirements set for the current situation. These requirements include upper thresholds for anomaly indices, allowable fluctuation ranges or minimum requirements for specific physical characteristics (such as the correlation of certain bit pairs, phase consistency at specific stages), etc., forming a task security requirement table.

[0166] Obtain the current operating context information of the secure computer, including real-time system load (CPU utilization, memory usage), environmental sensor readings (internal chassis temperature, humidity), power supply voltage fluctuations, network connectivity status (whether there is an external secure connection), and user operation type (e.g., whether remote management is in progress). Refer to the task security requirements table, which defines the expected security status under the current task and anomalous mode. Combine this real-time context information with a risk assessment model or rule set to evaluate the actual security risk of the current microphysical anomaly (whose category and index are known) in the current operating environment. For example, a rule could be defined as: "If the anomaly mode is classified as 'power-related anomaly' and the current power supply voltage fluctuation exceeds the normal range, while the task security level is 1, then the risk is increased to 'high'." Alternatively, a Bayesian network-based risk model can be used, taking the anomaly index, anomaly mode, task characteristics, environmental factors, and system state as input variables, and outputting a quantified contextual risk assessment value (e.g., a probability value between 0 and 1 or a risk level between 1 and 5). This value reflects the likelihood and potential impact of the current microphysical anomaly combined with the context on the system security objectives.

[0167] A predefined security trustworthiness scoring algorithm is used. This algorithm takes as input a context risk assessment value, a current microphysical anomaly index, and a task security requirement table. The algorithm aims to synthesize these factors to calculate a single numerical value characterizing the overall trustworthiness of the current operational state of the secure computer. The scoring algorithm can be designed as follows: an initial maximum score (e.g., 100 points), followed by deductions based on the anomaly index, context risk, and deviation from task security requirements. For example, the base deduction is positively correlated with the anomaly index (the higher the index, the more points are deducted). The deductions are then weighted and adjusted based on the context risk assessment value (the higher the risk, the greater the weight of the deduction). Finally, referring to the task security requirement table, if the current microphysical state (reflected in the anomaly index and the original phase difference vector) fails to meet the specific requirements in the table, additional deductions are made based on the degree of non-compliance and the importance of the requirements. For example, score = 100 - f1(anomaly index) × w1(context risk assessment value) - ∑<i=1> <req>Penalty (requirements) i Does it meet the requirements? i The importance of the system is calculated using the following formulas: f1 is an increasing function, w1 is an increasing weight function, and Penalty is a penalty term calculated based on the failure to meet requirements. The calculated value is the security and trustworthiness score, which is usually within a fixed range (e.g., 0-100 points). The higher the score, the more trustworthy the current operating state of the system.

[0168] Obtain a pre-configured set of multi-level security thresholds. This set contains multiple numerical thresholds that divide the security trustworthiness score range into different security status levels (e.g., score >= 90 for "Safe", 70 <= score < 90 for "Warning", 50 <= score < 70 for "Minor Anomaly", and score < 50 for "Severe Anomaly"). Compare the currently calculated security trustworthiness score with these thresholds to determine which security status level range the current score falls into. Based on the determined security status level, search for the corresponding graded response plan in a pre-defined response strategy database. This database maps each security status level to a series of specific security response measures. Find the list of specific response measures corresponding to the current security status level to form a graded response plan.

[0169] The security measures specified in the hierarchical response scheme generated in the previous step are executed. This involves sending instructions to the low-level control interface of the security computer, the Hardware Security Module (HSM), the power management unit, or the operating system security kernel to perform operations such as isolating modules, adjusting parameters, and triggering resets. For example, sending instructions to the HSM via the security bus to reject subsequent encryption requests; shutting off power to a certain area via the power controller; or writing a specific value to a watchdog timer to trigger a system reset. After executing the response measures, the final security authentication status is determined based on the execution result (success or failure) and the current state of the system (e.g., whether the module was successfully isolated, whether the task has stopped). The security authentication status is a discrete identifier that reflects the final security judgment of the system after microphysical monitoring and response. Security authentication statuses include: "Authentication Passed" (high score, no response or slight response), "Authentication Passed (Restricted)" (medium score, some functions are restricted), and "Authentication Failed" (low score, severe response was taken, the system has stopped or reset). This status is the system's final judgment on its current microphysical security health.

[0170] Therefore, the embodiments should be considered as exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of the equivalents of the application are intended to be included within the invention.

[0171] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0172] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0173] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0174] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0175] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0176] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0177] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0178] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0179] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.< / req> < / thermal> < / thermal> < / e> < / e> < / e> < / e> < / temporal> < / spatial> < / type>

Claims

1. A security authentication method based on a security computer, characterized by, Includes the following steps: Step S1: Deploy the sensor array and collect data on the security computer to obtain calibrated spatiotemporal synchronization data; Temperature and current fusion processing was performed on the calibrated spatiotemporal synchronization data to obtain a thermoelectric coupling characteristic spectrum. Step S2: Perform point-to-point time-series correlation analysis on the thermoelectric coupling feature map to obtain the point-to-point cross-correlation matrix; extract nonlinear features from the point-to-point cross-correlation matrix to obtain the nonlinear dynamic feature set; perform dynamic behavior analysis on the nonlinear dynamic feature set to obtain the dynamic phase spectrum of safe computing behavior; Step S3: Obtain historical operation data; calculate the phase difference of the dynamic phase spectrum of the safe computing behavior to obtain the phase difference vector; determine the normal fluctuation range of the phase difference vector to obtain the normal fluctuation boundary; judge the abnormal mode based on the normal fluctuation boundary to obtain the abnormal type judgment result; perform spatial propagation characteristic analysis on the abnormal type judgment result and the phase difference vector to obtain the abnormal propagation characteristic map; calculate the abnormal index based on the abnormal propagation characteristic map. Step S4: Match the anomaly index to the task security level to obtain the task security requirement table; calculate the security credibility score based on the task security requirement table; perform security authentication based on the security credibility score to obtain the security authentication status.

2. The security authentication method based on a secure computer according to claim 1, characterized by, Step S1, which involves deploying the sensor array and acquiring data from the security computer, includes: The temperature critical nodes are mapped and determined based on the computer's circuit design data, resulting in a critical node distribution map; Based on the distribution map of key nodes, the sensor array is deployed to obtain the sensor network topology; Based on the sensor network topology, a preset security baseline code segment is executed to obtain security baseline execution data; Based on the sensor network topology and security baseline execution data, multi-dimensional physical parameters are collected to obtain a physical parameter data stream. The physical parameter data stream is spatiotemporally synchronized to obtain calibrated spatiotemporally synchronized data.

3. The security authentication method based on a security computer according to claim 1, characterized by, Step S1 involves temperature and current fusion processing of the calibrated spatiotemporal synchronization data, including: Data separation was performed on the calibrated spatiotemporal synchronization data to obtain temperature data and current density data; Calculate the temperature gradient field of the temperature data; Calculate the temperature change rate field of the temperature data; The thermoelectric coupling strength is calculated based on the temperature change rate field, temperature gradient field, and current density data to obtain the thermoelectric coupling tensor. Obtain the security baseline code execution log, mark the code stage according to the thermoelectric coupling tensor, and obtain the marked thermoelectric coupling tensor; Feature point identification is performed on the labeled thermoelectric coupling tensor to obtain a set of thermoelectric feature points; Feature point responses are extracted from the thermoelectric feature point set to obtain the feature point response sequence; Generate a thermoelectric coupling feature map based on the feature point response sequence and the labeled thermoelectric coupling tensor.

4. The security authentication method based on a security computer according to claim 1, characterized by, Step S2 includes the following steps: Step S21: Decompose the thermoelectric coupling feature map into multi-point data to obtain a point time series dataset; Step S22: Calculate the rate of change of the point time series dataset to obtain the parameter rate of change matrix; Step S23: Perform multi-scale wavelet decomposition on the parameter change rate matrix to obtain the wavelet coefficient spectrum; Step S24: Analyze the inter-point correlation of the wavelet coefficient spectrum to obtain the point cross-correlation matrix; Step S25: Perform nonlinear feature extraction on the cross-correlation matrix of the points to obtain a nonlinear dynamic feature set; Step S26: Identify the characteristic frequencies of the nonlinear dynamic feature set to obtain the characteristic frequency spectrum; Step S27: Construct phase relationships from the characteristic frequency spectrum to obtain a phase relationship network; Step S28: Perform dynamic behavior spectrum synthesis on the phase relationship network and characteristic frequency spectrum to obtain the dynamic phase spectrum of secure computing behavior.

5. The security authentication method based on a secure computer according to claim 1, characterized in that, Step S2 involves nonlinear feature extraction of the point cross-correlation matrix, including: The reconstruction parameter set is determined based on the cross-correlation matrix of the points; Phase space trajectory is reconstructed based on the reconstructed parameter set and the point cross-correlation matrix to obtain the phase space trajectory map; The degree of chaos is quantified by analyzing the phase space trajectory diagram to obtain a table of chaos indices. Fractal characteristic analysis was performed on the phase space trajectory diagram to obtain the fractal dimension value; Construct a recursive state diagram based on the phase space trajectory diagram; Recursive quantitative feature extraction is performed on the recursive state diagram to obtain recursive statistical features; Phase transition points are detected by analyzing the chaos index table, fractal dimension values, and recursive statistical features to obtain a phase transition point sequence. A nonlinear dynamic feature set is generated based on the phase transition point sequence.

6. The security authentication method based on a secure computer according to claim 1, characterized in that, Step S3 includes the following steps: Step S31: Collect and perform real-time feature acquisition and transformation on the current operating status sensor data to obtain the current operating phase representation; Step S32: Perform multidimensional difference calculation on the dynamic phase spectrum of the current running phase characterization and safe computing behavior to obtain the phase difference vector; Step S33: Determine the normal fluctuation range of the phase difference vector to obtain the normal fluctuation boundary; Step S34: Construct an adaptive threshold based on the normal fluctuation boundary to obtain a dynamic detection threshold set; Step S35: Classify the phase difference vector into anomaly patterns based on the dynamic detection threshold set to obtain the anomaly type determination result; Step S36: Perform spatial propagation feature analysis on the anomaly type determination result and phase difference vector to obtain an anomaly propagation feature map; Step S37: Extract the temporal evolution pattern from the anomaly propagation feature map to obtain the anomaly evolution trend; Step S38: Calculate the anomaly index based on the anomaly type determination result, the anomaly propagation characteristic map, and the anomaly evolution trend.

7. The security authentication method based on a secure computer according to claim 1, characterized in that, Step S3, determining the normal fluctuation range of the phase difference vector, includes: Basic statistical features are extracted from the phase difference vector to obtain a set of dimensional statistical features. Kernel density distribution estimation is performed on the dimensional statistical feature set to obtain the dimensional density distribution map; Dimension confidence boundaries are calculated based on the dimensionality density distribution map; Based on the dimensional confidence boundary, an environmental factor correlation analysis was performed on the historical operational data to obtain an environmental correlation factor table; Construct a conditional fluctuation boundary set based on the environmental correlation factor table; Time-series autocorrelation analysis was performed on historical operational data to obtain time-series correlation characteristics; A volatility prediction model is constructed based on time-series correlation characteristics; Normal fluctuation boundaries are generated based on the fluctuation prediction model, dimensional confidence boundary, and conditional fluctuation boundary set.

8. The security authentication method based on a secure computer according to claim 1, characterized in that, Step S3 involves spatial propagation feature analysis of the anomaly type determination result and phase difference vector, including: Based on the anomaly type determination results, thermoelectric anomaly points are located using the phase difference vector to obtain the anomaly source point set; Obtain hardware material parameters, combine them with the set of abnormal source points to configure heat conduction parameters, and obtain a regional thermal parameter table; A current path near mapping is performed on the set of abnormal source points to obtain the current path diagram; The thermoelectric coupling coefficient was calculated based on the current path diagram and the regional thermal parameter table. Time-step propagation simulation was performed based on the thermoelectric coupling coefficient to obtain the time-series temperature distribution sequence; The thermal diffusion velocity field is obtained by calculating the diffusion velocity of the time-series temperature distribution sequence. The time-varying influence region is determined based on the time-series temperature distribution sequence and current path diagram; The propagation path of the thermal diffusion velocity field and the time-varying influence region is extracted to obtain the abnormal propagation path; Propagation mode features were extracted from the thermal diffusion velocity field, time-varying influence area, and abnormal propagation path to obtain an abnormal propagation feature map.

9. The security authentication method based on a secure computer according to claim 1, characterized in that, Step S4 includes the following steps: Step S41: Perform historical abnormal index clustering on historical operational data and abnormal indices to obtain abnormal pattern classification results; Step S42: Obtain information on the currently executing task; perform task security level matching based on the current executing task information and the abnormal mode classification results to obtain the task security requirement table; Step S43: Perform a context-aware risk assessment based on the task safety requirements table to obtain the context risk assessment value; Step S44: Based on the contextual risk assessment value, anomaly index, and task security requirements table, calculate the credibility score using a preset scoring algorithm to obtain the security credibility score; Step S45: Compare the security trust score with the preset multi-level security thresholds to determine the response level that needs to be activated and generate the corresponding graded response plan; Step S46: Perform security authentication according to the hierarchical response scheme to obtain the security authentication status.

10. A security authentication system based on a secure computer, characterized in that, For performing the secure computer-based security authentication method as described in claim 1, the secure computer-based security authentication system comprises: The thermoelectric feature map module is used to deploy sensor arrays and acquire data for the security computer to obtain calibrated spatiotemporal synchronization data; temperature and current fusion processing is performed on the calibrated spatiotemporal synchronization data to obtain thermoelectric coupling feature maps; The dynamic phase spectrum module is used to perform point-to-point time-series correlation analysis on the thermoelectric coupling feature map to obtain the point-to-point cross-correlation matrix; to extract nonlinear features from the point-to-point cross-correlation matrix to obtain a nonlinear dynamic feature set; and to analyze the dynamic behavior of the nonlinear dynamic feature set to obtain the dynamic phase spectrum of safe computing behavior. The abnormal state assessment module is used to acquire historical operation data; calculate the phase difference of the dynamic phase spectrum of safe computing behavior to obtain the phase difference vector; determine the normal fluctuation range of the phase difference vector to obtain the normal fluctuation boundary; judge the abnormal mode based on the normal fluctuation boundary to obtain the abnormal type judgment result; perform spatial propagation characteristic analysis on the abnormal type judgment result and the phase difference vector to obtain the abnormal propagation characteristic map; and calculate the abnormal index based on the abnormal propagation characteristic map. The security credibility assessment and certification module is used to match the anomaly index with the task security level to obtain the task security requirement table; calculate the security credibility score based on the task security requirement table; and perform security certification based on the security credibility score to obtain the security certification status.

Citation Information

Patent Citations

  • Fan current detection method and system, computer equipment and storage medium

    CN119807680A

  • Equipment anomaly detection method and system based on multi-source heterogeneous data

    CN120145206A