Industrial control system-oriented full-link cross-layer security simulation verification method and system
By constructing a cross-layer coupling model and multi-platform collaborative simulation, the problem of accuracy in cross-layer attack assessment in industrial control systems was solved, realizing dynamic quantitative assessment and proactive defense of end-to-end security, and improving the system's security and defense capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- JINAN UNIVERSITY
- Filing Date
- 2025-08-26
- Publication Date
- 2026-06-26
AI Technical Summary
Existing technologies struggle to implement cross-layer coupling models in industrial control systems, making it difficult to effectively assess the impact of cross-layer attacks on control accuracy and system stability. Furthermore, the lack of domestically produced hardware compatibility limits the accuracy and comprehensiveness of security assessments.
A cross-layer coupling model of the physical layer, network layer and control layer is constructed. Combining multi-platform collaborative simulation and semi-physical verification, the simulation output of the cross-layer coupling model is generated through dynamic interaction and joint simulation architecture. Programmable delay injection and data synchronization are performed to achieve full-link cross-layer security assessment.
It enables dynamic quantitative assessment of the full-link cross-layer security of industrial control systems, improves the practicality and coverage of security testing, provides a high-fidelity verification environment, and enhances the proactive defense capability against cross-layer attacks.
Smart Images

Figure CN121056362B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial Internet of Things (IoT) security verification technology, and in particular to a full-link cross-layer security simulation verification method and system for industrial control systems. Background Technology
[0002] As industrial control systems become increasingly intelligent and networked, the security threats they face are evolving from single-dimensional to cross-layer coupling. Traditional security verification methods often focus on network layer encryption or physical layer signal isolation, lacking the ability to model the collaborative mechanisms of the physical layer, network layer, and control layer. This makes it impossible to quantitatively assess the comprehensive impact of cross-layer attacks (such as delay injection and channel interference) on control accuracy and system stability. Existing simulation platforms are limited by single-dimensional analysis and struggle to reproduce multi-level attack scenarios in complex industrial environments. Hardware-in-the-loop (HIL) verification technologies, due to heterogeneous hardware interfaces and insufficient real-time performance, struggle to achieve high-precision delay injection and cross-layer data synchronization, limiting the accuracy and comprehensiveness of security assessments. Furthermore, the lack of domestic hardware compatibility further restricts the construction of an independent and controllable industrial security system. Summary of the Invention
[0003] The main objective of this invention is to provide a full-link cross-layer security simulation and verification method and system for industrial control systems. By constructing a cross-layer coupling model of physical layer-network layer-control layer, and combining multi-platform collaborative simulation and semi-physical verification, the invention aims to achieve dynamic quantitative evaluation of the full-link cross-layer security of industrial control systems and improve their proactive defense capabilities.
[0004] To achieve the above objectives, this invention provides a full-link, cross-layer security simulation and verification method for industrial control systems, comprising the following steps:
[0005] Construct a cross-layer coupled model of the physical layer, network layer, and control layer, and generate simulation output of the cross-layer coupled model through dynamic interaction between each layer and joint simulation architecture;
[0006] Semi-physical verification is performed by intercepting communication commands from the industrial control system in real time and injecting programmable delays. The impact of the delay on control accuracy is determined by combining the preset quantization mapping relationship in the cross-layer coupling model.
[0007] Data interaction and synchronous transmission between different levels are achieved through collaboration across multiple simulation platforms;
[0008] Based on the simulation output of the cross-layer coupling model, the delay impact data in the semi-physical verification, and the real-time data of multi-platform collaborative transmission, the data coupling effect between each layer and the preset safety threshold are compared to conduct dynamic simulation verification of the cross-layer security of the entire industrial control system.
[0009] Furthermore, the steps of constructing a cross-layer coupled model of the physical layer, network layer, and control layer, and generating the simulation output of the cross-layer coupled model through dynamic interaction between each layer and a co-simulation architecture, include:
[0010] By integrating simulation data from various layers through the dynamic interaction between the physical layer, network layer, and control layer;
[0011] A wireless transmission environment simulation model is established at the physical layer to generate channel bit error rate and transmission delay data.
[0012] A dynamic encryption module is integrated into the network layer, and the key update cycle is synchronized with the motion control cycle of the industrial control system.
[0013] A closed-loop control model is constructed at the control layer, and the network layer delay data is correlated to the control accuracy deviation through a preset quantization mapping relationship;
[0014] Based on the simulation data at each level, the simulation output of the cross-layer coupled model is generated.
[0015] Furthermore, the steps for establishing a wireless transmission environment simulation model include:
[0016] A multipath fading channel model is used to establish a simulation model of complex industrial environments at the physical layer to characterize signal attenuation and multipath effects.
[0017] Furthermore, the step of integrating a dynamic encryption module at the network layer includes:
[0018] A dynamic encryption algorithm is used to deploy a synchronization update module at the network layer for the synchronization update of encryption keys and motion control cycles.
[0019] Furthermore, the steps for constructing a closed-loop control model at the control layer include:
[0020] A closed-loop model is established at the control layer using proportional-integral-derivative control logic to correlate network layer delay data with physical layer channel state data to control accuracy deviation.
[0021] Furthermore, the steps for conducting semi-physical verification include:
[0022] Intercept the communication protocol command stream of the industrial control system through a real-time simulation platform;
[0023] A programmable delay is injected into the communication protocol instruction stream, and the injection precision of the programmable delay reaches the nanometer level;
[0024] The delayed communication protocol command stream is input into the cross-layer coupling model, and the dynamic impact of the delay on control accuracy is determined by combining the preset quantization mapping relationship.
[0025] Furthermore, the steps for intercepting the communication protocol command stream of an industrial control system through a real-time simulation platform include:
[0026] The motion control command transmission link is analyzed based on the industrial Ethernet protocol, and the communication protocol command stream is intercepted through a real-time simulation platform.
[0027] Furthermore, the steps for data interaction and synchronous transmission between different levels through multi-simulation platform collaboration include:
[0028] By utilizing a multi-simulation platform collaborative architecture, control commands generated by the control layer and encrypted data from the network layer are mapped in real time through a high-frequency interface;
[0029] The physical layer wireless signals and network layer transmitted data are synchronized through a low-latency hardware interface.
[0030] Furthermore, the steps for dynamically simulating and verifying the cross-layer security of the entire industrial control system through collaborative data interaction and synchronous transmission across multiple simulation platforms include:
[0031] The simulation output data of the cross-layer coupling model, the delay impact data measured in the semi-physical verification, and the real-time data of multi-platform collaborative transmission are correlated and analyzed to generate cross-layer security performance evaluation results.
[0032] Based on the comparison between the cross-layer security performance evaluation results and the preset security threshold range, the full-link cross-layer security of the industrial control system is determined.
[0033] This invention also provides a full-link, cross-layer security simulation and verification system for industrial control systems, comprising:
[0034] The model building unit is used to build cross-layer coupled models of the physical layer, network layer and control layer, and generates simulation output of the cross-layer coupled models through dynamic interaction between the layers and joint simulation architecture.
[0035] The hardware-in-the-loop verification unit is used to perform hardware-in-the-loop verification, intercept the communication commands of the industrial control system in real time and inject programmable delays, and determine the impact of delays on control accuracy by combining the preset quantization mapping relationship in the cross-layer coupling model.
[0036] The data interaction unit is used to conduct data interaction and synchronous transmission between different levels through the collaboration of multiple simulation platforms;
[0037] The security verification unit is used to compare the data coupling effect between each layer with the preset security threshold based on the simulation output of the cross-layer coupling model, the delay impact data in the semi-physical verification, and the real-time data of multi-platform collaborative transmission, and to perform dynamic simulation verification of the cross-layer security of the entire link of the industrial control system.
[0038] The present invention provides a full-link cross-layer security simulation and verification method and system for industrial control systems, which has the following beneficial effects: The present invention achieves dynamic simulation and quantitative assessment of full-link security risks in industrial control systems by constructing a cross-layer coupling model of the physical layer, network layer, and control layer. First, the co-simulation architecture breaks through the limitations of traditional single-dimensional analysis. Through dynamic interaction modeling between layers, it accurately reproduces the coupling effect of multi-path attacks on control performance, providing a high-fidelity verification environment for cross-layer security threats. Second, the semi-physical verification platform, combined with domestic hardware interfaces and nanosecond-level latency injection technology, supports accurate parsing and attack simulation of real industrial protocols, significantly improving the practicality and coverage of security testing. Simultaneously, the multi-simulation platform collaboration mechanism ensures real-time interaction and consistency of cross-layer data through high-frequency data mapping and low-latency synchronous transmission, providing a reliable data foundation for security decisions in complex industrial scenarios. Furthermore, through dynamic determination of security thresholds and adaptive evaluation logic, a closed-loop verification system from risk identification to protection strategy generation is formed, effectively improving the proactive defense capability and overall security resilience of industrial control systems in the face of cross-layer attacks. Attached Figure Description
[0039] Figure 1 This is a flowchart illustrating a full-link cross-layer security simulation and verification method for industrial control systems according to an embodiment of the present invention.
[0040] Figure 2 This is a structural block diagram of a full-link cross-layer security simulation and verification system for industrial control systems according to an embodiment of the present invention.
[0041] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0042] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0043] Reference Figure 1 This is a flowchart illustrating a full-link cross-layer security simulation and verification method for industrial control systems proposed in this invention, comprising the following steps:
[0044] S1, construct a cross-layer coupled model of the physical layer, network layer and control layer, and generate the simulation output of the cross-layer coupled model through dynamic interaction between each layer and joint simulation architecture;
[0045] S2, perform semi-physical verification, intercept the communication commands of the industrial control system in real time and inject programmable delay, and determine the impact of delay on control accuracy by combining the preset quantization mapping relationship in the cross-layer coupling model;
[0046] S3 enables data interaction and synchronous transmission between different levels through the collaboration of multiple simulation platforms;
[0047] S4. Based on the simulation output of the cross-layer coupling model, the delay impact data in the semi-physical verification, and the real-time data of multi-platform collaborative transmission, the data coupling effect between each layer and the preset safety threshold are compared to perform dynamic simulation verification of the cross-layer security of the entire industrial control system.
[0048] In one embodiment, for step S1,
[0049] The steps for constructing a cross-layer coupled model of the physical layer, network layer, and control layer, and generating simulation output of the cross-layer coupled model through dynamic interaction between each layer and a co-simulation architecture, include:
[0050] By integrating simulation data from various layers through the dynamic interaction between the physical layer, network layer, and control layer;
[0051] A wireless transmission environment simulation model is established at the physical layer to generate channel bit error rate and transmission delay data.
[0052] A dynamic encryption module is integrated into the network layer, and the key update cycle is synchronized with the motion control cycle of the industrial control system.
[0053] A closed-loop control model is constructed at the control layer, and the network layer delay data is correlated to the control accuracy deviation through a preset quantization mapping relationship;
[0054] Based on the simulation data at each level, the simulation output of the cross-layer coupled model is generated.
[0055] In practical implementation, the physical layer employs the Nakagami-m channel model to simulate wireless transmission scenarios in complex industrial environments. Its signal fading characteristics are controlled by a shape parameter m (ranging from 1.5 to 3.5), used to generate channel bit error rate (BER) and transmission delay data. The value of m is dynamically adjusted based on measured data from the field environment to accurately characterize multipath effects and signal attenuation. The network layer deploys a dynamic SM4 encryption module, whose key update cycle is strictly synchronized with the motion control cycle of the industrial control system (e.g., updated every 10ms). Adjustable delays (0.1–10μs) are injected to simulate network attacks or communication congestion scenarios. The control layer constructs a closed-loop control model based on proportional-integral-derivative (PID) logic, defining the quantitative mapping relationship between trajectory deviation Δ and network delay as Δ = K. p ·Δ d K p K is the proportionality constant (experimentally measured). p =2.5μm / μs), Δ dThe delay injected into the network layer is verified through calibration experiments of an actual control system. Data from each layer is integrated with the MATLAB control model via the OPNET network simulation platform running on the Loongson 3C5000 server, and low-latency (<100μs) interaction is achieved with the dSPACE real-time simulation platform through the PCIe interface, ultimately generating simulation output data for the cross-layer coupled model. For example, in the semiconductor bonding machine embodiment, when Δ is injected into the network layer... d With a delay of 2μs, the placement position deviation predicted by the simulation model is Δ. sim =5.2μm, compared with the measured value Δ real =5.0μm. The error of 5.0μm is less than 4% (ε=|Δ sim -Δ real | / Δ real *100% = 4%), verifying the accuracy of the model. This implementation's cross-layer modeling method, through dynamic interaction and data coupling between layers, achieves joint simulation analysis of multi-level security risks in industrial control systems, providing a high-fidelity simulation environment for subsequent security verification.
[0056] In one embodiment, the steps of establishing a wireless transmission environment simulation model include:
[0057] A multipath fading channel model is used to establish a simulation model of complex industrial environments at the physical layer to characterize signal attenuation and multipath effects.
[0058] Specifically, when establishing a wireless transmission environment simulation model at the physical layer, the Nakagami-m channel model is used to simulate the multipath fading effect in complex industrial environments. Its signal power fading probability density function is:
[0059]
[0060] Where m is the shape parameter (m∈[1.5,3.5]), used to characterize the multipath scattering intensity (the smaller the value of m, the more significant the fading), Ω is the average received power, r is the instantaneous signal amplitude, and Γ(·) is the gamma function. By adjusting the value of m, different industrial scenarios can be adapted (such as m=1.5 in a metal workshop, m=3.5 in an open factory), thereby generating the channel bit error rate. ( (Signal-to-noise ratio) and transmission delay τ p hy.
[0061] In one embodiment, the step of integrating a dynamic encryption module at the network layer includes:
[0062] A dynamic encryption algorithm is used to deploy a synchronization update module at the network layer for the synchronization update of encryption keys and motion control cycles.
[0063] Specifically, when deploying a dynamic encryption module at the network layer, the SM4 national cryptographic algorithm is used to achieve key synchronization and updates, with a key update cycle T. key Strictly synchronized with the motion control cycle (e.g., T) key =10ms), encryption delay Δ d By injecting hardware programmable logic, the Δ requirement is satisfied. d ∈[0.1,10]μs. The key update trigger condition is driven by the periodic signal of the motion control command, ensuring seamless integration of the encryption process with the control timing. For example, when the motion controller (such as Googol GTS-800) sends a position command with a period of 10ms, the SM4 module synchronously updates the key and inserts Δ into the EtherCAT protocol data frame. d =2μs delay to simulate a man-in-the-middle attack scenario.
[0064] In one embodiment, the step of constructing a closed-loop control model at the control layer includes:
[0065] A closed-loop model is established at the control layer using proportional-integral-derivative control logic to correlate network layer delay data with physical layer channel state data to control accuracy deviation.
[0066] Specifically, when constructing the closed-loop control model at the control layer, the proportional-integral-derivative (PID) algorithm is used to adjust the network layer delay Δ. d The quantization relationship between the physical layer channel state data and the control precision deviation Δ is as follows:
[0067]
[0068] Wherein, the proportionality coefficient K p =2.5μm / μs, integral coefficient K i =0.1μm / (μs·s), differential coefficient K d =0.05μm / % / s, which is the control parameter calibrated through a step response experiment; d(BER) / dt represents the integral effect of the injection delay over time; d(BER) / dt is the rate of change of the bit error rate, which characterizes the instantaneous deterioration rate of the physical layer channel state (such as signal interference).
[0069] In one embodiment, for step S2,
[0070] The steps for conducting semi-physical verification include:
[0071] Intercept the communication protocol command stream of the industrial control system through a real-time simulation platform;
[0072] A programmable delay is injected into the communication protocol instruction stream, and the injection precision of the programmable delay reaches the nanometer level;
[0073] The delayed communication protocol command stream is input into the cross-layer coupling model, and the dynamic impact of the delay on control accuracy is determined by combining the preset quantization mapping relationship.
[0074] In practical implementation, the communication protocol command stream of the industrial control system is intercepted through the EtherCAT slave module of a real-time simulation platform (such as dSPACE SCALEXIO), for example, the position command frame of the Googol GTS-800 motion controller. The command stream parsing is based on the industrial Ethernet protocol stack, ensuring lossless capture of the original control timing, while bypass monitoring technology avoids interference with the real-time control loop. Secondly, when injecting programmable delays into the command stream, a nanosecond-level (±50ns) precision delay injection module is implemented using FPGA (Field-Programmable Gate Array) hardware. Its logic design is based on a timestamp interpolation algorithm, and the delay amount Δ is configured through a hardware description language (such as Verilog). d ∈[0.1,10]μs, and supports dynamic adjustment. For example, in a semiconductor bonding machine scenario, Δ is inserted into the Cycle Time field of the EtherCAT data frame. d A delay of 2μs is used to simulate man-in-the-middle attacks or network congestion scenarios. Finally, the delayed command stream is input into the cross-layer coupling model, and the control accuracy deviation is dynamically calculated based on the quantization mapping relationship preset in step S1. This embodiment achieves seamless interaction between physical devices and simulation models through hardware-in-the-loop (HIL) technology, providing a high-precision experimental environment for the end-to-end security verification of industrial control systems.
[0075] In one embodiment, the step of intercepting the communication protocol command stream of an industrial control system through a real-time simulation platform includes:
[0076] The motion control command transmission link is analyzed based on the industrial Ethernet protocol, and the communication protocol command stream is intercepted through a real-time simulation platform.
[0077] Specifically, an EtherCAT master / slave configuration mode is adopted, and the periodic data frames sent by the motion controller are parsed in real time through the protocol stack parsing engine. During the parsing process, the bypass monitoring mode of the EtherCAT slave interface card is used to extract application data units in the synchronization manager channel, including target position, velocity, and acceleration parameters, while ensuring the real-time performance of the main control loop (period ≤ 1ms). When intercepting the communication protocol command stream through the real-time simulation platform, the EtherCAT interface module of the dSPACESCALEXIO system is used. Its hardware logic integrates a timestamp marking function (accuracy ±10ns). The intercepted command stream is buffered in the original binary format in a circular buffer and transmitted to the cross-layer coupling model at a rate of 10Gbps through the PCIe interface. This embodiment uses a real-time simulation platform to perform in-depth parsing and command interception of the communication link of industrial Ethernet protocols (such as EtherCAT), ensuring lossless capture and accurate injection of motion control commands.
[0078] In one embodiment, for step S3,
[0079] The steps for data interaction and synchronous transmission between different levels through multi-simulation platform collaboration include:
[0080] By utilizing a multi-simulation platform collaborative architecture, control commands generated by the control layer and encrypted data from the network layer are mapped in real time through a high-frequency interface;
[0081] The physical layer wireless signals and network layer transmitted data are synchronized through a low-latency hardware interface.
[0082] In practical implementation, control commands generated by the control layer (such as motion trajectory parameters output by the PID algorithm) and encrypted data from the network layer (such as EtherCAT protocol frames encrypted with SM4) are mapped in real time through a high-frequency interface (such as PCIe 4.0). Control commands are generated by the MATLAB / Simulink simulation platform, converted into a network-layer-recognizable data format (such as a binary stream) by a customized driver module on the server, and transmitted to the OPNET network simulation platform via the PCIe interface at a sampling rate of 1MHz. During this process, the high-frequency interface uses Direct Memory Access (DMA) technology to bypass CPU interrupt latency, ensuring that the data transmission rate strictly matches the motion control cycle (such as 10ms), with a mapping error of less than 0.1μs. Secondly, physical layer wireless signals (such as RF signals generated by the Nakagami-m channel model) and network layer transmitted data are synchronized through a low-latency hardware interface (such as an FPGA board). Physical layer signals are generated by a wireless channel simulator (such as Keysight PXIe), parsed into a baseband IQ data stream by the FPGA's hardware logic, and synchronized with the encrypted data stream from the network layer through a timestamp alignment mechanism (based on the IEEE 1588PTP protocol). The FPGA board integrates a nanosecond-level clock synchronization module to ensure that the time deviation between physical layer signals and network data is less than 50ns. For example, in a semiconductor bonding machine verification scenario, when the physical layer simulates multipath fading, causing a signal delay (5μs), the network layer synchronously adjusts the transmission timing of encrypted data and feeds it back to the control layer through a cross-layer coupling model, ultimately stabilizing the mounting accuracy deviation at Δ1μm. This implementation, through hardware acceleration and protocol optimization in a multi-simulation platform collaborative architecture, solves the data barriers between heterogeneous platforms, providing spatiotemporal consistency guarantees for efficient interaction and accurate synchronization of cross-layer data across the entire link.
[0083] In one embodiment, for step S4,
[0084] The steps for dynamically simulating and verifying the end-to-end cross-layer security of industrial control systems through collaborative data interaction and synchronous transmission across multiple simulation platforms include:
[0085] The simulation output data of the cross-layer coupling model, the delay impact data measured in the semi-physical verification, and the real-time data of multi-platform collaborative transmission are correlated and analyzed to generate cross-layer security performance evaluation results.
[0086] Based on the comparison between the cross-layer security performance evaluation results and the preset security threshold range, the full-link cross-layer security of the industrial control system is determined.
[0087] In practical implementation, when performing correlation analysis on the simulation output data of the cross-layer coupling model, the delay impact data measured in the semi-physical verification, and the real-time data of multi-platform collaborative transmission, a data fusion algorithm (such as Kalman filtering or weighted averaging) is used to integrate the multi-source heterogeneous data. The transmission delay generated by the physical layer, the delay injected by the network layer, and the trajectory deviation output by the control layer are input into the joint analysis module after being timestamped. The cross-layer coupling relationship Δ = K is preset in the module. p ·Δ d +f(BER) dynamically calculates security performance indicators (such as trajectory deviation rate and communication integrity score) to generate cross-layer security performance evaluation results (such as security index S∈[0,1], where S≥0.8 indicates security). Secondly, based on the comparison between the evaluation results and preset security threshold ranges, the system security is determined. For example, when the physical layer bit error rate (BER) > 10... -3 Network layer delay Δ d A safety alarm is triggered when the time exceeds 5μs or the control deviation Δ exceeds 10μm. This embodiment updates the safety benchmark in real time through a dynamic threshold adaptive mechanism (such as sliding window statistics) to ensure that the verification results match the time-varying characteristics of the industrial scenario, ultimately providing a quantitative decision-making basis for end-to-end security protection.
[0088] Reference Figure 2 Here is a structural block diagram of a full-link cross-layer security simulation and verification system for industrial control systems according to an embodiment of the present invention, comprising:
[0089] The model building unit is used to build cross-layer coupled models of the physical layer, network layer and control layer, and generates simulation output of the cross-layer coupled models through dynamic interaction between the layers and joint simulation architecture.
[0090] The hardware-in-the-loop verification unit is used to perform hardware-in-the-loop verification, intercept the communication commands of the industrial control system in real time and inject programmable delays, and determine the impact of delays on control accuracy by combining the preset quantization mapping relationship in the cross-layer coupling model.
[0091] The data interaction unit is used to conduct data interaction and synchronous transmission between different levels through the collaboration of multiple simulation platforms;
[0092] The security verification unit is used to compare the data coupling effect between each layer with the preset security threshold based on the simulation output of the cross-layer coupling model, the delay impact data in the semi-physical verification, and the real-time data of multi-platform collaborative transmission, and to perform dynamic simulation verification of the cross-layer security of the entire link of the industrial control system.
[0093] For the specific implementation of each unit in the above device example, please refer to the method embodiments described above, and will not be repeated here.
[0094] In summary, this invention constructs a cross-layer coupling model of the physical layer, network layer, and control layer. Through dynamic interaction between layers and a co-simulation architecture, it generates simulation outputs of the cross-layer coupling model. It performs hardware-in-the-loop (HIL) verification, intercepting communication commands from the industrial control system in real time and injecting programmable delays. The impact of these delays on control accuracy is determined by combining the preset quantization mapping relationships in the cross-layer coupling model. Data interaction and synchronous transmission between layers are achieved through collaboration across multiple simulation platforms. Based on the simulation outputs of the cross-layer coupling model, the delay impact data from the HIL verification, and the real-time data transmitted collaboratively across multiple platforms, the data coupling effects between layers are compared with preset security thresholds. This dynamic simulation verification of the end-to-end cross-layer security of the industrial control system aims to achieve dynamic quantitative assessment and enhanced proactive defense capabilities for the end-to-end cross-layer security of the industrial control system.
[0095] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the present invention and embodiments can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual-rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM, etc.
[0096] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.
[0097] The above description is merely a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A full-link, cross-layer security simulation and verification method for industrial control systems, characterized in that, Includes the following steps: A cross-layer coupled model of the physical layer, network layer, and control layer is constructed. Simulation output of the cross-layer coupled model is generated through dynamic interaction between the layers and a co-simulation architecture. Specifically, the dynamic interaction between the layers involves the physical layer transmitting the generated channel bit error rate and transmission delay data to the network and control layers in real time; the network layer synchronously transmitting encrypted control commands and injected delay data to the control layer; and the control layer feeding back the calculated control accuracy deviation to the network and physical layers, achieving bidirectional real-time interaction of the three layers. The co-simulation architecture employs the OPNET network simulation platform, the MATLAB control simulation platform, and the dSPACE real-time simulation platform to construct a heterogeneous co-simulation architecture. Low-latency data interaction between the platforms is achieved through the PCIe interface, with an interaction latency of less than 100μs. Semi-physical verification is performed by intercepting communication commands from the industrial control system in real time and injecting programmable delays. The impact of the delay on control accuracy is determined by combining the preset quantization mapping relationship in the cross-layer coupling model. Data interaction and synchronous transmission between different levels are achieved through collaboration across multiple simulation platforms; Based on the simulation output of the cross-layer coupling model, the delay impact data in the semi-physical verification, and the real-time data of multi-platform collaborative transmission, the data coupling effect between each layer and the preset safety threshold are compared to conduct dynamic simulation verification of the cross-layer security of the entire industrial control system.
2. The end-to-end cross-layer security simulation and verification method for industrial control systems according to claim 1, characterized in that, The steps of constructing a cross-layer coupled model of the physical layer, network layer, and control layer, and generating simulation output of the cross-layer coupled model through dynamic interaction between each layer and a joint simulation architecture, include: By integrating simulation data from various layers through the dynamic interaction between the physical layer, network layer, and control layer; A wireless transmission environment simulation model is established at the physical layer to generate channel bit error rate and transmission delay data. A dynamic encryption module is integrated into the network layer, and the key update cycle is synchronized with the motion control cycle of the industrial control system. A closed-loop control model is constructed at the control layer, and the network layer delay data is correlated to the control accuracy deviation through a preset quantization mapping relationship; Based on the simulation data at each level, the simulation output of the cross-layer coupled model is generated.
3. The end-to-end cross-layer security simulation and verification method for industrial control systems according to claim 2, characterized in that, The steps for establishing a wireless transmission environment simulation model include: A multipath fading channel model is used to establish a simulation model of complex industrial environments at the physical layer to characterize signal attenuation and multipath effects.
4. The end-to-end cross-layer security simulation and verification method for industrial control systems according to claim 2, characterized in that, The step of integrating a dynamic encryption module at the network layer includes: A dynamic encryption algorithm is used to deploy a synchronization update module at the network layer for the synchronization update of encryption keys and motion control cycles.
5. The end-to-end cross-layer security simulation and verification method for industrial control systems according to claim 2, characterized in that, The step of constructing a closed-loop control model at the control layer includes: A closed-loop model is established at the control layer using proportional-integral-derivative control logic to correlate network layer delay data with physical layer channel state data to control accuracy deviation.
6. The end-to-end cross-layer security simulation and verification method for industrial control systems according to claim 1, characterized in that, The steps for performing semi-physical verification include: Intercept the communication protocol command stream of the industrial control system through a real-time simulation platform; A programmable delay is injected into the communication protocol instruction stream, and the injection precision of the programmable delay reaches the nanometer level; The delayed communication protocol command stream is input into the cross-layer coupling model, and the dynamic impact of the delay on control accuracy is determined by combining the preset quantization mapping relationship.
7. The end-to-end cross-layer security simulation and verification method for industrial control systems according to claim 6, characterized in that, The step of intercepting the communication protocol command stream of the industrial control system through a real-time simulation platform includes: The motion control command transmission link is analyzed based on the industrial Ethernet protocol, and the communication protocol command stream is intercepted through a real-time simulation platform.
8. The end-to-end cross-layer security simulation and verification method for industrial control systems according to claim 1, characterized in that, The steps for data interaction and synchronous transmission between different levels through multi-simulation platform collaboration include: By utilizing a multi-simulation platform collaborative architecture, control commands generated by the control layer and encrypted data from the network layer are mapped in real time through a high-frequency interface; The physical layer wireless signals and network layer transmitted data are synchronized through a low-latency hardware interface.
9. The end-to-end cross-layer security simulation and verification method for industrial control systems according to claim 1, characterized in that, The steps for dynamically simulating and verifying the cross-layer security of the entire industrial control system through collaborative data interaction and synchronous transmission between multiple simulation platforms include: The simulation output data of the cross-layer coupling model, the delay impact data measured in the semi-physical verification, and the real-time data of multi-platform collaborative transmission are correlated and analyzed to generate cross-layer security performance evaluation results. Based on the comparison between the cross-layer security performance evaluation results and the preset security threshold range, the full-link cross-layer security of the industrial control system is determined.
10. A full-link, cross-layer security simulation and verification system for industrial control systems, characterized in that, include: The model building unit is used to construct a cross-layer coupled model of the physical layer, network layer, and control layer. It generates simulation output of the cross-layer coupled model through dynamic interaction between layers and a co-simulation architecture. Specifically, the dynamic interaction between layers involves the physical layer transmitting the generated channel bit error rate and transmission delay data to the network and control layers in real time; the network layer synchronously transmitting encrypted control commands and injected delay data to the control layer; and the control layer feeding back the calculated control accuracy deviation to the network and physical layers, achieving bidirectional real-time interaction of the three layers. The co-simulation architecture uses the OPNET network simulation platform, the MATLAB control simulation platform, and the dSPACE real-time simulation platform to construct a heterogeneous co-simulation architecture. Low-latency data interaction between the platforms is achieved through the PCIe interface, with an interaction latency of less than 100μs. The hardware-in-the-loop verification unit is used to perform hardware-in-the-loop verification, intercept the communication commands of the industrial control system in real time and inject programmable delays, and determine the impact of delays on control accuracy by combining the preset quantization mapping relationship in the cross-layer coupling model. The data interaction unit is used to conduct data interaction and synchronous transmission between different levels through the collaboration of multiple simulation platforms; The security verification unit is used to compare the data coupling effect between each layer with the preset security threshold based on the simulation output of the cross-layer coupling model, the delay impact data in the semi-physical verification, and the real-time data of multi-platform collaborative transmission, and to perform dynamic simulation verification of the cross-layer security of the entire link of the industrial control system.