A multi-element industrial control security defense method and system based on digital twinning

By using digital twin technology to build a digital space consistent with the physical industrial control system, isolating communication links, configuring redundant units, verifying command security, synchronizing status, collecting and analyzing multi-dimensional data, identifying anomalies, outputting early warnings, and constructing a full-process defense system, this solves the problems of single protection mechanisms and weak data integration and analysis in existing technologies, and achieves full-process security protection for industrial control systems.

CN121193467BActive Publication Date: 2026-03-31SHENYANG INSTITUTE OF CHEMICAL TECHNOLOGY
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-04
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing industrial control system security defense methods rely on a single protection mechanism, lack virtual simulation verification, have weak data integration and analysis capabilities, and are lagging in threat identification, making it impossible to deal with industrial control system security threats throughout the entire process.

Method used

The multi-dimensional industrial control security defense method based on digital twins constructs a digital space unit with the same functions as the physical industrial control system, sets up a virtual human-machine interface, isolates the communication link from the virtual interface to the PLC, configures identity authentication, fault tolerance redundancy and communication units, receives encrypted operation instructions, simulates the operation process based on the real asset model and standard database, verifies the security of instructions, synchronizes the communication protocols of physical and virtual devices, replicates the status of the physical PLC to the virtual PLC, compares status differences, collects and analyzes multi-dimensional data, identifies anomalies, outputs early warning information, and provides feedback to adjust the physical industrial control system.

Benefits of technology

It achieves full-process defense, prevents unauthorized operations and equipment/path failures, intercepts untrusted operations, promptly detects anomalies such as PLC tampering, quickly responds to malicious attacks and risks, and ensures the safe and stable operation of physical industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121193467B_ABST
    Figure CN121193467B_ABST
Patent Text Reader

Abstract

The application provides a multi-element industrial control safety defense method and system based on digital twinning, relates to the technical field of industrial control safety, and comprises the following steps: a twinning isolation module is used to build a digital space and isolate a communication link; a verification and evaluation module is used to verify the safety of instructions; a state synchronization module is used to synchronize the states of devices, identify differences, collect and analyze data, and give early warnings and adjustments; and corresponding operation processes are provided.The application cooperates with multiple modules, builds a defense system based on digital twinning, isolates man-in-the-middle attacks, intercepts illegal operations, identifies PLC tampering, detects malicious intrusion, effectively deals with industrial control threats, avoids abnormalities of physical industrial control systems, and ensures stable operation of the industrial control systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control security technology, and more specifically, to a multi-faceted industrial control security defense method and system based on digital twins. Background Technology

[0002] As industrial control systems upgrade towards intelligence and networking, physical industrial control systems interact more with external networks, facing security threats such as man-in-the-middle attacks, PLC code tampering, illegal parameter injection, and malicious network intrusion. At the same time, operator errors may also cause equipment failures. Furthermore, the multi-dimensional data generated during the operation of physical industrial control systems lacks effective integration and analysis methods, making it difficult to identify potential risks in real time. Traditional defense methods are no longer suitable for the security needs of complex industrial control environments.

[0003] Traditional industrial control system security defense methods often rely on a single protection mechanism, such as isolating the network through a firewall or monitoring and identifying anomalies using a single parameter. These methods cannot achieve full-process protection from operation command verification to system status synchronization and risk warning. Furthermore, the lack of a virtual space corresponding to the physical industrial control system makes it difficult to simulate operations and identify security risks in advance without affecting the operation of the physical system. In addition, the data collection dimensions are limited and the analysis capabilities are insufficient, resulting in delayed threat identification and low defense efficiency.

[0004] Therefore, it is necessary to design a multi-faceted industrial control security defense method and system based on digital twins to solve the problems of existing technology protection mechanisms being single, lacking virtual simulation verification links, having weak data integration and analysis capabilities, lagging threat identification, and being unable to deal with industrial control security threats throughout the entire process. Summary of the Invention

[0005] In view of this, the present invention proposes a multi-dimensional industrial control security defense method and system based on digital twins, which aims to solve the problems of existing technology protection mechanisms being single, lacking virtual simulation verification, having weak data integration and analysis, lagging threat identification, and being unable to deal with industrial control security threats throughout the entire process.

[0006] In one aspect, this invention proposes a multi-faceted industrial control system security defense method based on digital twins, comprising:

[0007] S1, build a digital space unit with the same functions as the physical industrial control system, set up a virtual human-machine interface, isolate the communication link from the virtual interface to the PLC, configure the identity authentication unit, fault-tolerant redundancy unit and communication unit, and connect the physical space unit and the digital space unit.

[0008] S2, receive the encrypted operation instructions transmitted by the twin isolation module, simulate the operation process based on the real asset model and the standard database, verify the security of the instructions, and output the trusted instructions to the physical industrial control system and the status synchronization module;

[0009] S3 receives trusted commands, synchronizes the communication protocols of physical and virtual devices, copies the physical PLC status to the virtual PLC, compares the status of the physical industrial control system and the virtual industrial control system, and identifies status differences.

[0010] S4 collects, stores, and analyzes multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical industrial control system, identifies anomalies, outputs early warning information, and provides feedback to adjust the physical industrial control system.

[0011] Furthermore, a digital space unit with the same functions as the physical industrial control system is constructed, a virtual human-machine interface is set up, the communication link from the virtual interface to the PLC is isolated, and an authentication unit, a fault-tolerant redundancy unit, and a communication unit are configured. When connecting the physical space unit and the digital space unit, the following is included:

[0012] Establish a mapping relationship between physical space units and digital space units;

[0013] The physical space unit includes the physical equipment, sensors, actuators, control units, and operating environment of the physical industrial control system;

[0014] The digital spatial unit replicates the equipment configuration, sensor layout, and production line process of the physical spatial unit;

[0015] When connecting physical space units and digital space units, a communication unit is set up. The communication unit includes an industrial communication unit and a network communication unit. The industrial communication unit uses industrial communication protocols to interconnect industrial equipment, and the network communication unit uses wired or wireless networks to connect the digital and physical spaces.

[0016] When setting up a virtual human-machine interface, a virtual network card is set up between the virtual interface and the physical PLC to isolate the communication link.

[0017] When configuring the identity authentication unit, a user identity information database is established to store user identity identifiers and set user operation permission levels. When a user accesses the interface, the user identity identifier is collected and compared with the information database. When the collected identity identifier matches the information database, the corresponding permission level is read and the corresponding operation function is enabled. When the collected identity identifier does not match the information database, the operation function is denied.

[0018] When configuring the fault-tolerant redundancy unit, a backup device and a backup network path are set. The backup device and the primary device are of the same type, and the backup network path and the primary path have the same communication protocol. The operating status of the primary device and the primary path is monitored. When the primary device fails, the system switches to the backup device. When the primary path is interrupted, the system switches to the backup path.

[0019] Furthermore, when receiving the encrypted operation instructions transmitted by the twin isolation module, simulating the operation process based on the real asset model and the standard database, verifying the security of the instructions, and outputting trusted instructions to the physical industrial control system and the status synchronization module, the process includes:

[0020] Decrypt the command and obtain the decrypted command content;

[0021] Establish a real asset model by collecting the structural, operational, and performance parameters of physical equipment in the physical industrial control system. Construct an asset model based on the collected parameters, with the model structure and operational parameter range consistent with the physical equipment.

[0022] Establish a standardized database to store the operating procedures, safety standards, and configuration parameters of the physical industrial control system. The operating procedures include the equipment operation steps and sequence, the safety standards include parameter thresholds and operating restrictions, and the configuration parameters include the equipment operating baseline parameters.

[0023] During the simulation operation, the decryption command is input into the real asset model to drive the real asset model to run, and the status data of the real asset model is collected. The status data includes the equipment operating parameters and the operation execution results.

[0024] When verifying the security of instructions, the status data is compared with the security standards in the standard database, the parameter thresholds and operation restrictions in the standards are extracted, and the operating parameters and thresholds, operation results and restrictions of the real asset model are compared.

[0025] When the operating parameters of the real asset model are within the threshold and the operation result meets the restriction conditions, the instruction is determined to be a reliable instruction and is output to the physical industrial control system and the state synchronization module.

[0026] If the parameters of the real asset model exceed the threshold or the operation result does not meet the restriction conditions, the instruction is determined to be an untrusted instruction and the output is rejected.

[0027] Set the time compression unit, adjust the simulation time rate, collect the status data after the rate is increased, and repeatedly verify the safety of the instruction. Repeat the verification at least twice. When the two verification results are consistent, determine the judgment result. When the two results are inconsistent, readjust the rate and verify until the results are consistent.

[0028] Furthermore, when receiving trusted commands, synchronizing the communication protocols of physical and virtual devices, copying the physical PLC status to the virtual PLC, comparing the status of the physical industrial control system and the virtual industrial control system, and identifying status differences, the process includes:

[0029] Use trusted instructions as the baseline instructions for state synchronization;

[0030] Configure a protocol synchronization protection unit, establish a protocol conversion mechanism, and collect the communication protocol types of physical devices and virtual devices; when the protocols of physical devices and virtual devices are inconsistent, the protocol conversion mechanism is activated to convert the protocol of one party to the protocol supported by the other party.

[0031] Collect communication data between physical and virtual devices and monitor the integrity of data transmission; when data is lost, retransmit the lost data.

[0032] Set up a status synchronization control unit to collect the operating status data of the physical PLC. The operating status data includes the PLC's input parameters, output parameters, and program running status. Transmit the collected operating status data to the virtual PLC and update the virtual PLC status.

[0033] Establish physical twin component units to copy the status data of physical devices in the physical industrial control system. The status data includes device operating parameters, fault status, and working mode. Transmit the copied status data to the virtual environment and update the virtual device status.

[0034] A state consistency check is performed by collecting real-time operating data from the physical industrial control system and the virtual industrial control system. The real-time operating data includes equipment parameters, operation execution data, and network transmission data. The real-time operating data of the physical industrial control system and the virtual industrial control system are compared one by one, and the data difference value is calculated. When the data difference value is less than the preset difference threshold, the physical industrial control system and the virtual industrial control system are determined to be consistent. When the data difference value is greater than or equal to the preset difference threshold, the physical industrial control system and the virtual industrial control system are determined to be inconsistent. The device or module information corresponding to the difference data is collected, and the difference information is output.

[0035] Furthermore, the process of collecting, storing, and analyzing multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical control system, identifying anomalies, outputting early warning information, and providing feedback for adjusting the physical control system includes:

[0036] Set up a data acquisition unit, establish a data acquisition link, and connect the status synchronization module, physical industrial control system, twin isolation module, and verification and evaluation module to collect multi-dimensional data from each module and the physical industrial control system. The multi-dimensional data includes equipment operation status data, environmental monitoring data, production process data, energy consumption data, equipment performance data, and network security data.

[0037] Set the data acquisition frequency: the equipment operation status data acquisition frequency is higher than the environmental monitoring data, and the production process data acquisition frequency is higher than the energy consumption data; when collecting data, convert data of different formats into a unified format, mark the data acquisition timestamp and data source identifier, the timestamp is accurate to the second, and the data source identifier includes the module name and equipment name;

[0038] Set up a data management storage unit and build a cloud storage node. The storage node includes a data storage area, an encryption area, and an index area. The converted data is transmitted to the storage area. In the encryption area, the data is processed using symmetric or asymmetric encryption methods. In the index area, a data index is created, which includes the data identifier, storage location, and timestamp range.

[0039] Monitor cloud storage capacity. When the storage capacity utilization rate reaches the preset capacity threshold, delete historical data that exceeds the preset storage time or transfer it to a backup storage node; when the storage capacity utilization rate is lower than the preset capacity threshold, continue to store new data.

[0040] Furthermore, the process of collecting, storing, and analyzing multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical control system, identifying anomalies, outputting early warning information, and providing feedback for adjusting the physical control system also includes:

[0041] A data analysis unit is set up to read data from the data management and storage unit and preprocess the data, including data cleaning, deduplication, and completion. During data cleaning, invalid data is deleted, including data with incorrect format or data that exceeds the reasonable range. During data deduplication, duplicate data is deleted, including data with the same timestamp, the same source identifier, and the same content. During data completion, interpolation is used to supplement missing data, and missing data is data that is consecutively missing no more than a preset number of records.

[0042] Feature extraction is performed on the preprocessed data, including time features, numerical features, and correlation features. Time features include data change period and peak occurrence time, numerical features include data mean and variance, and correlation features include numerical correlations between different data types.

[0043] The extracted features are input into the trained deep learning model, and anomaly prediction is performed on the input features to calculate the anomaly score.

[0044] When the anomaly score is less than the anomaly detection threshold, the system is considered to be in normal condition.

[0045] When the anomaly score is greater than or equal to the anomaly determination threshold, the system state is determined to be abnormal, and the data source and type corresponding to the anomaly characteristics are marked.

[0046] Furthermore, the process of collecting, storing, and analyzing multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical control system, identifying anomalies, outputting early warning information, and providing feedback for adjusting the physical control system also includes:

[0047] Set up early warning units and establish rules for classifying early warning levels. The early warning levels include Level 1, Level 2, and Level 3. Different levels correspond to different degrees of abnormality. The degree of abnormality is determined based on the degree of difference between abnormal and normal characteristics.

[0048] When a system anomaly is detected, the warning level is determined according to the degree of anomaly, with Level 1 warning corresponding to the lowest degree of anomaly and Level 3 warning corresponding to the highest degree of anomaly.

[0049] When the early warning output is initiated, the early warning information is transmitted to the human-computer interaction interface, which displays the early warning level, abnormal data source, abnormal type, and abnormal time.

[0050] Establish an email sending link, connect to the SMTP server, edit the warning information into email content, including the warning level, anomaly details, and handling suggestions, obtain the staff's email address, and send the email to the corresponding email address;

[0051] Monitor the status of receiving early warning information. When a read confirmation is detected, stop resending the email. If no read confirmation is detected and the time since the last sending exceeds the preset sending interval, resend the email.

[0052] Furthermore, the process of collecting, storing, and analyzing multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical control system, identifying anomalies, outputting early warning information, and providing feedback for adjusting the physical control system also includes:

[0053] Set up a feedback adjustment unit to receive the anomaly judgment results from the data analysis unit and the warning level from the early warning unit, and formulate adjustment strategies based on the warning level;

[0054] When the warning level is Level 1, the operating parameters of the physical control system are adjusted. The operating parameters include equipment operating speed, operating temperature, and production cycle time. The adjustment range is a preset fine adjustment range. After adjustment, real-time data from the system is collected and re-analyzed. If the anomaly is eliminated, the adjusted parameters are maintained. If the anomaly is not eliminated, the adjustment range is increased to a preset medium adjustment range.

[0055] When the warning level is level 2, the backup equipment is activated, the abnormal equipment in the physical control system is stopped, the backup equipment is connected to the physical control system to replace the abnormal equipment, the operating data of the backup equipment is collected, and its operating status is monitored.

[0056] When the warning level is level three, some production processes in the physical industrial control system are suspended, equipment with safety risks in the physical industrial control system is shut down, and staff are notified to investigate the fault on-site. After the fault is investigated, the equipment is started for trial operation, trial operation data is collected, and normal production of the physical industrial control system is restored after confirming that there are no abnormalities.

[0057] Furthermore, in the fault-tolerant redundancy unit of the twin isolation module, when monitoring the operating status of the main device, the operating parameters of the main device are collected. The operating parameters include operating current, voltage, temperature, and response time, and the normal range of each parameter is set.

[0058] The collected parameters are compared with the normal range. If any parameter is out of range and the duration exceeds the preset fault judgment time, the main equipment is judged to be faulty.

[0059] When all parameters are within the normal range, the main device is considered to be functioning normally.

[0060] When monitoring the primary network path, collect communication parameters, including data transmission rate, packet loss rate, and network latency, and set normal thresholds for each parameter;

[0061] The collected parameters are compared with normal thresholds. If the transmission rate is lower than the normal threshold, the packet loss rate is higher than the normal threshold, or the delay is higher than the normal threshold and the duration exceeds the preset interruption judgment time, the primary path is judged to be interrupted.

[0062] When all parameters meet the normal threshold requirements, the primary path is considered to be normal.

[0063] When switching equipment, disconnect the primary equipment from the physical industrial control system, establish a connection between the backup equipment and the physical industrial control system, and transmit the current operating parameters of the primary equipment to the backup equipment so that the initial parameters of the backup equipment are consistent with those of the primary equipment.

[0064] When performing a network switch, disconnect the primary path communication link, establish a backup path link, and synchronize the primary path communication configuration to the backup path to make the backup path configuration consistent with the primary path.

[0065] Compared with existing technologies, the beneficial effects of this invention are as follows: This invention provides a multi-dimensional industrial control security defense method based on digital twins. Through a twin isolation module, it constructs a digital space consistent with the physical industrial control system, isolates communication links, and configures redundant units, thus preventing unauthorized operations and equipment / path failures. The verification and evaluation module relies on a real asset model and a standardized database to verify instruction security and intercept untrusted operations. The status synchronization module synchronizes the status of physical and virtual devices and identifies differences, enabling timely detection of anomalies such as PLC tampering. The analysis and optimization module collects multi-dimensional data and analyzes, provides early warnings, and offers feedback adjustments, enabling rapid response to malicious attacks and risks. The collaborative construction of multiple modules forms a comprehensive defense system, effectively ensuring the safe and stable operation of the physical industrial control system.

[0066] On the other hand, this invention proposes a multi-faceted industrial control security defense system based on digital twins, comprising:

[0067] The twin isolation module is used to build a digital space unit with the same functions as the physical industrial control system, set up a virtual human-machine interface, isolate the communication link from the virtual interface to the PLC, configure an identity authentication unit, a fault-tolerant redundancy unit and a communication unit, and connect the physical space unit and the digital space unit.

[0068] The verification and evaluation module is used to receive the encrypted operation instructions transmitted by the twin isolation module, simulate the operation process based on the real asset model and the standard database, verify the security of the instructions, and output the trusted instructions to the physical industrial control system and the status synchronization module.

[0069] The status synchronization module is used to receive trusted instructions, synchronize the communication protocols of physical and virtual devices, copy the status of the physical PLC to the virtual PLC, compare the status of the physical industrial control system and the virtual industrial control system, and identify status differences.

[0070] The analysis and optimization module is used to collect, store and analyze multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module and the physical industrial control system, identify anomalies, output early warning information, and provide feedback to adjust the physical industrial control system.

[0071] It is understandable that the aforementioned digital twin-based multi-factor industrial control security defense method and system have the same beneficial effects, and will not be elaborated further here. Attached Figure Description

[0072] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0073] Figure 1 A flowchart of a multi-faceted industrial control security defense method based on digital twins provided in an embodiment of the present invention;

[0074] Figure 2 A functional block diagram of a multi-dimensional industrial control security defense system based on digital twins provided in an embodiment of the present invention;

[0075] Figure 3 This is a schematic diagram of the framework of a multi-dimensional industrial control security defense system based on digital twins, provided in an embodiment of the present invention.

[0076] Figure 4 A flowchart of the multi-element industrial control security defense system based on digital twins provided in this embodiment of the invention.

[0077] Figure 5 This is a schematic diagram of the twin isolation module framework provided in an embodiment of the present invention;

[0078] Figure 6 This is a schematic diagram of the analysis and optimization module framework provided in an embodiment of the present invention. Detailed Implementation

[0079] Exemplary embodiments of the present invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present invention and to fully convey the scope of the invention to those skilled in the art. It should be noted that, without conflict, the embodiments and features described herein can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0080] Reference Figure 1 and Figure 3-6 As shown in some embodiments of this application, a multi-faceted industrial control system security defense method based on digital twins includes:

[0081] S1, build a digital space unit with the same functions as the physical industrial control system, set up a virtual human-machine interface, isolate the communication link from the virtual interface to the PLC, configure the identity authentication unit, fault-tolerant redundancy unit and communication unit, and connect the physical space unit and the digital space unit.

[0082] S2, receive the encrypted operation instructions transmitted by the twin isolation module, simulate the operation process based on the real asset model and the standard database, verify the security of the instructions, and output the trusted instructions to the physical industrial control system and the status synchronization module;

[0083] S3 receives trusted commands, synchronizes the communication protocols of physical and virtual devices, copies the physical PLC status to the virtual PLC, compares the status of the physical industrial control system and the virtual industrial control system, and identifies status differences.

[0084] S4 collects, stores, and analyzes multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical industrial control system, identifies anomalies, outputs early warning information, and provides feedback to adjust the physical industrial control system.

[0085] Specifically, a physical control system (PCS) refers to a system encompassing physical equipment, sensors, actuators, programmable logic controllers (PLCs), distributed control systems (DCS), and their operating environment. It is widely used in critical infrastructure sectors such as power, petrochemicals, transportation, water treatment, and the military, undertaking actual industrial production control functions and serving as the physical operation object of multi-mode collaborative security defense systems. A physical space unit is the actual operating environment of a PCS, including equipment configuration, sensor placement, and production line processes, directly reflecting the hardware layout and actual production operation process of the PCS. A digital space unit is a virtual representation that maintains consistency with the physical space unit in function and content. It simulates the behavior, state, and dynamic interaction processes of the physical space unit through software technology, providing a virtual carrier for subsequent security defense aspects such as operation verification and state synchronization. A real asset model is a digital representation constructed based on the structural, operational, and performance parameters of the physical equipment in the PCS. The model, whose structure is completely identical to the corresponding physical equipment and whose operating parameter range matches the physical equipment, can be used to simulate the operating state of physical equipment in a virtual environment, providing a virtual simulation object for operational safety verification. The specification database is a database that integrates domain knowledge and expert knowledge, specifically storing the operating specifications (including equipment operation steps and sequences), safety standards (including parameter thresholds and operating restrictions) and configuration parameters (including equipment operating baseline parameters) of the physical industrial control system, providing data support for modules such as operation verification and status synchronization, ensuring that related operations comply with safety requirements and industry standards. The virtual industrial control system consists of digital space units, virtual PLCs, virtual human-machine interfaces, etc. By replicating the equipment operating state and control logic implementation of the physical industrial control system in real time and through bidirectional dynamic mapping with the physical industrial control system, it can perform operations such as operation verification and attack scenario simulation in a virtual environment without directly affecting the actual operation of the physical industrial control system. It is the core virtual carrier for realizing multi-mode collaborative security defense.

[0086] Understandably, by clearly defining the core processes of building a digital space, verifying command security, synchronizing device status, and collecting and analyzing data, a full-process defense framework of "isolation-verification-synchronization-analysis" is constructed, providing a foundation for subsequent refinement of protection measures. This comprehensively covers the key aspects of physical industrial control system security defense and initially solves the problem of traditional defenses lacking systematicity.

[0087] In some embodiments of this application, a digital space unit with the same functions as the physical industrial control system is constructed, a virtual human-machine interface is set up, the communication link from the virtual interface to the PLC is isolated, and an authentication unit, a fault-tolerant redundancy unit, and a communication unit are configured. When connecting the physical space unit and the digital space unit, the following are included:

[0088] Establish a mapping relationship between physical space units and digital space units;

[0089] The physical space unit includes the physical equipment, sensors, actuators, control units, and operating environment of the physical industrial control system;

[0090] The digital spatial unit replicates the equipment configuration, sensor layout, and production line process of the physical spatial unit;

[0091] When connecting physical space units and digital space units, a communication unit is set up. The communication unit includes an industrial communication unit and a network communication unit. The industrial communication unit uses industrial communication protocols to interconnect industrial equipment, and the network communication unit uses wired or wireless networks to connect the digital and physical spaces.

[0092] When setting up a virtual human-machine interface, a virtual network card is set up between the virtual interface and the physical PLC to isolate the communication link.

[0093] When configuring the identity authentication unit, a user identity information database is established to store user identity identifiers and set user operation permission levels. When a user accesses the interface, the user identity identifier is collected and compared with the information database. When the collected identity identifier matches the information database, the corresponding permission level is read and the corresponding operation function is enabled. When the collected identity identifier does not match the information database, the operation function is denied.

[0094] When configuring the fault-tolerant redundancy unit, a backup device and a backup network path are set. The backup device and the primary device are of the same type, and the backup network path and the primary path have the same communication protocol. The operating status of the primary device and the primary path is monitored. When the primary device fails, the system switches to the backup device. When the primary path is interrupted, the system switches to the backup path.

[0095] Specifically, the operation isolation design of this invention aims to prevent interference between the virtual environment and the physical PLC during system development, debugging, and operation by effectively isolating the virtual PLC from the physical PLC. The TwinCAT 2.11 64-bit programming software in the physical space unit runs on a 64-bit computer system with Windows 10 operating system, responsible for programming and debugging the PLC and controlling the operation of the hardware. The TwinCAT 2.11R3 software generates a virtual PLC in the digital space, distributed on a 32-bit virtual machine system with Windows 7 operating system. It is also programmed and debugged by the TwinCAT 2.11 64-bit programming software. Since programming and debugging occur only in the virtual environment and do not directly affect the operation of the physical equipment, operational safety is ensured. The virtual human-machine interface in the digital space is designed and developed using VejioDesigner software and communicates with the virtual PLC via the Modbus TCP protocol, thereby enabling monitoring and operation of the PLC control system status. The local area network in the network communication unit connects the two operating hosts, enabling data transmission and sharing. The Modbus TCP protocol in the industrial communication unit is used to connect virtual and physical PLCs, transmitting data and commands. The TS6250 also integrates Modbus TCP services, enabling it to act as a Modbus TCP server or client, communicating with other devices that support this protocol. An authentication unit is integrated into the virtual HMI to ensure each operator is authenticated when accessing the interface, restricting the operational permissions of different users. The fault-tolerant and redundant units in the digital space include redundant PLCs, redundant networks, and redundant power supply systems. Critical system configurations include primary and backup PLCs, dual network cards or redundant Ethernet to ensure stable communication, and dual power supplies or uninterruptible power supplies to ensure continued operation during power outages.

[0096] Understandably, refining the operation of the twin isolation module, by establishing a mapping between physical and digital spaces, setting up dual communication units, and configuring identity authentication and fault-tolerant redundancy units, can not only achieve a precise correspondence between physical and digital spaces, but also prevent unauthorized access, cope with equipment failures and network interruptions, and improve the system's isolation protection and risk resistance capabilities.

[0097] In some embodiments of this application, when receiving the encrypted operation instructions transmitted by the twin isolation module, simulating the operation process based on the real asset model and the standard database, verifying the security of the instructions, and outputting trusted instructions to the physical industrial control system and the status synchronization module, the process includes:

[0098] Decrypt the command and obtain the decrypted command content;

[0099] Establish a real asset model by collecting the structural, operational, and performance parameters of physical equipment in the physical industrial control system. Construct an asset model based on the collected parameters, with the model structure and operational parameter range consistent with the physical equipment.

[0100] Establish a standardized database to store the operating procedures, safety standards, and configuration parameters of the physical industrial control system. The operating procedures include the equipment operation steps and sequence, the safety standards include parameter thresholds and operating restrictions, and the configuration parameters include the equipment operating baseline parameters.

[0101] During the simulation operation, the decryption command is input into the real asset model to drive the real asset model to run, and the status data of the real asset model is collected. The status data includes the equipment operating parameters and the operation execution results.

[0102] When verifying the security of instructions, the status data is compared with the security standards in the standard database, the parameter thresholds and operation restrictions in the standards are extracted, and the operating parameters and thresholds, operation results and restrictions of the real asset model are compared.

[0103] When the operating parameters of the real asset model are within the threshold and the operation result meets the restriction conditions, the instruction is determined to be a reliable instruction and is output to the physical industrial control system and the state synchronization module.

[0104] If the parameters of the real asset model exceed the threshold or the operation result does not meet the restriction conditions, the instruction is determined to be an untrusted instruction and the output is rejected.

[0105] Set the time compression unit, adjust the simulation time rate, collect the status data after the rate is increased, and repeatedly verify the safety of the instruction. Repeat the verification at least twice. When the two verification results are consistent, determine the judgment result. When the two results are inconsistent, readjust the rate and verify until the results are consistent.

[0106] Specifically, the physical twin component unit in the twin simulation verification unit collects physical device data in real time through a sensor network and generates a physical twin using digital twin 3D modeling technology, ensuring consistency between the physical and virtual environments. The twin configuration unit uses graphical configuration tools and a relational database to configure the mapping relationship between the physical and digital twins, supporting user-defined attributes and behaviors. The virtual twin control unit uses the MATLAB Simulink high-performance simulation engine to simulate the control logic of the physical devices, supporting user verification of control strategies and outputting simulation results and operation logs. The time-lapse unit improves the efficiency of the simulation process through CPU acceleration technology. Furthermore, this unit integrates the Metasploit attack simulation engine for comprehensive security testing of the system's protection strategies and fault tolerance capabilities. The specification database unit integrates domain knowledge and expert knowledge, storing the operating specifications, safety standards, and configuration parameters of the industrial control system, ensuring the legality and rationality of safe operations and providing data support for state synchronization and operation verification. Through the physical twin component unit, twin configuration unit, virtual twin control unit, specification database unit, and operation verification and evaluation unit, the system comprehensively verifies operations, ensuring that each operational step complies with safety specifications.

[0107] Understandably, optimizing the instruction verification process involves decrypting instructions, building a real asset model, establishing a standardized database, and repeatedly verifying instructions to ensure that only trusted instructions that meet security standards are applied to the physical industrial control system. This effectively intercepts untrusted operations, avoids security risks caused by illegal instructions, and improves the security of instruction execution.

[0108] In some embodiments of this application, when receiving trusted instructions, synchronizing the communication protocols of physical and virtual devices, copying the physical PLC state to the virtual PLC, comparing the states of the physical industrial control system and the virtual industrial control system, and identifying state differences, the process includes:

[0109] Use trusted instructions as the baseline instructions for state synchronization;

[0110] Configure a protocol synchronization protection unit, establish a protocol conversion mechanism, and collect the communication protocol types of physical devices and virtual devices; when the protocols of physical devices and virtual devices are inconsistent, the protocol conversion mechanism is activated to convert the protocol of one party to the protocol supported by the other party.

[0111] Collect communication data between physical and virtual devices and monitor the integrity of data transmission; when data is lost, retransmit the lost data.

[0112] Set up a status synchronization control unit to collect the operating status data of the physical PLC. The operating status data includes the PLC's input parameters, output parameters, and program running status. Transmit the collected operating status data to the virtual PLC and update the virtual PLC status.

[0113] Establish physical twin component units to copy the status data of physical devices in the physical industrial control system. The status data includes device operating parameters, fault status, and working mode. Transmit the copied status data to the virtual environment and update the virtual device status.

[0114] A state consistency check is performed by collecting real-time operating data from the physical industrial control system and the virtual industrial control system. The real-time operating data includes equipment parameters, operation execution data, and network transmission data. The real-time operating data of the physical industrial control system and the virtual industrial control system are compared one by one, and the data difference value is calculated. When the data difference value is less than the preset difference threshold, the physical industrial control system and the virtual industrial control system are determined to be consistent. When the data difference value is greater than or equal to the preset difference threshold, the physical industrial control system and the virtual industrial control system are determined to be inconsistent. The device or module information corresponding to the difference data is collected, and the difference information is output.

[0115] Specifically, the preset difference threshold is a key value used by the state synchronization module to determine whether the states of the physical industrial control system and the virtual system are consistent when performing state consistency verification on the physical industrial control system and the virtual system. It analyzes the range of data deviations that naturally occur during normal operation due to factors such as minor equipment fluctuations and data transmission delays by statistically analyzing the real-time operating data (including equipment parameters, operation execution data, network transmission data, etc.) of the physical industrial control system and the virtual system under historical normal operating conditions. Then, it determines the maximum allowable data deviation value. This value can accommodate reasonable deviations during normal operation of the physical and virtual systems to avoid misjudgment, and can also accurately identify deviations that exceed the reasonable range caused by PLC code block tampering, equipment abnormalities, or data transmission failures. This provides a clear judgment standard for subsequent collection of equipment or module information corresponding to the difference data and output of difference information.

[0116] Specifically, the protocol synchronization protection unit consists of a protocol converter and a synchronization controller. The core function of the protocol converter is to realize data conversion and communication between different protocols. In a real environment, data acquisition and remote monitoring in industrial sites use the MoxaMGate5101 protocol converter, which is responsible for the conversion from Modbus RTU to Modbus TCP. In an industrial Ethernet environment, the Siemens SCALANCE protocol converter is used, which is responsible for the conversion from PROFIBUS to PROFINET. The ABB AC800M acts as the central control system, integrating data from Modbus TCP and PROFINET, and performing remote monitoring and management via OPCUA. In a virtual environment, the software protocol converter KepwareKEPServerEX is used to convert Modbus TCP to OPCUA. The protocol converter ensures that data in the real and virtual environments can communicate in a consistent format, ensuring communication protocol synchronization. The synchronization controller receives Modbus RTU and PROFIBUS data from the real environment, converts it to Modbus TCP, PROFINET, and OPCUA protocols through the protocol converter, and sends it to the virtual environment, ensuring data consistency between the virtual and real environments. An ACK confirmation mechanism prevents data loss or interruption. The state synchronization control unit achieves real-time data synchronization, firstly through TSN (Time-Sensitive Networking) technology and PTP (Precise Time Protocol) for time synchronization. Next, a data scheduling mechanism is configured to prioritize critical data. Simultaneously, network devices and controllers are configured to support TSN functionality, ensuring consistency of system time and network parameters across all devices and controllers. The programs and states of physical and virtual PLCs are periodically synchronized to ensure consistency between them. The state synchronization module ensures a high degree of consistency between the virtual and real environments, detecting anomalies in PLC blocks through consistency checks with the real industrial control system.

[0117] Understandably, improving the state synchronization mechanism, based on trusted instructions, and through protocol conversion, data integrity monitoring, state replication and consistency verification, ensures that the physical and virtual devices are in the same state, can promptly identify state differences, quickly detect anomalies such as PLC tampering, and provide accurate basis for troubleshooting system anomalies.

[0118] In some embodiments of this application, the process of collecting, storing, and analyzing multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical control system, identifying anomalies, outputting early warning information, and providing feedback for adjusting the physical control system includes:

[0119] Set up a data acquisition unit, establish a data acquisition link, and connect the status synchronization module, physical industrial control system, twin isolation module, and verification and evaluation module to collect multi-dimensional data from each module and the physical industrial control system. The multi-dimensional data includes equipment operation status data, environmental monitoring data, production process data, energy consumption data, equipment performance data, and network security data.

[0120] Set the data acquisition frequency: the equipment operation status data acquisition frequency is higher than the environmental monitoring data, and the production process data acquisition frequency is higher than the energy consumption data; when collecting data, convert data of different formats into a unified format, mark the data acquisition timestamp and data source identifier, the timestamp is accurate to the second, and the data source identifier includes the module name and equipment name;

[0121] Set up a data management storage unit and build a cloud storage node. The storage node includes a data storage area, an encryption area, and an index area. The converted data is transmitted to the storage area. In the encryption area, the data is processed using symmetric or asymmetric encryption methods. In the index area, a data index is created, which includes the data identifier, storage location, and timestamp range.

[0122] Monitor cloud storage capacity. When the storage capacity utilization rate reaches the preset capacity threshold, delete historical data that exceeds the preset storage time or transfer it to a backup storage node; when the storage capacity utilization rate is lower than the preset capacity threshold, continue to store new data.

[0123] Specifically, the preset capacity threshold refers to the proportion of storage capacity occupied in the data management storage unit of the analysis and optimization module. This is determined by statistically analyzing the total storage capacity of the cloud storage nodes and the daily increment of multi-dimensional data (including equipment operation status data, environmental monitoring data, production process data, etc.) generated during the daily operation of the physical industrial control system, combined with the need to ensure normal data storage and avoid overloading of storage nodes. The preset storage duration refers to the length of time that data is retained in the cloud storage nodes in the same data management storage unit. This is determined by analyzing the frequency of use of relevant data from the physical industrial control system (e.g., some key production data are used frequently, while ordinary environmental monitoring data is used infrequently) and the importance of the data (e.g., key data related to production safety is of high importance, while routine operation log data is of relatively low importance). This is done to avoid redundant storage occupying resources and to ensure the traceability of necessary data.

[0124] Specifically, the data acquisition unit is responsible for acquiring real-time data from the digital space of the twin clone. Sensors are the core components of the data acquisition unit, capable of measuring and converting various physical quantities (such as temperature, pressure, and flow rate) into processable electrical signals in real time. The gateway connects different types of sensors to achieve comprehensive data collection on equipment operating status, environmental parameters, and other data. After the OPCUA server reads the collected data, it uploads it to the cloud platform via the OPCUA client. OPCUA's own security mechanism ensures that the data is protected by TLS / SSL protocols, message signing, and encryption during transmission. In the cloud domain, block storage technology from cloud storage is used to divide the data into fixed blocks for storage and management, enabling large-scale data analysis, big data storage, distributed cloud node management, and other operations. Edge computing nodes are deployed at the network edge between the cloud platform and industrial control equipment. These edge computing nodes can execute artificial intelligence algorithms such as deep learning and reinforcement learning to achieve lightweight processing of local data and small-scale data storage. This not only effectively reduces the load on the cloud platform but also enables lower-latency decision support. The data analysis unit uses Generative Adversarial Networks (GANs) with spatiotemporal convolutional blocks and Transformer coding blocks as the basic models to model the data under the deep learning framework of TensorFlow 1.12.0 and CUDA 11.8. The steps are as follows: (1) Data preprocessing. The sensor and actuator data collected from the industrial control system field or simulation test platform are processed into csv format. Then, the original dataset is cleaned, categorical features are quantified, numerical features are standardized, and data is normalized to obtain a standardized dataset. Data normalization formula:

[0125]

[0126] in, It is the training set. and These represent the minimum and maximum values ​​of the training set, respectively. It is the training set after normalization. (2) After calculating the covariance matrix of the data using principal component analysis (PCA), the eigenvectors corresponding to the k largest eigenvalues ​​are selected, and the data is projected onto the new space to achieve dimensionality reduction of the data features. The preprocessed dataset is then divided into training sets. (Normal data) and test set (Some abnormal data exists) .in For feature dimension, The length of the training set sequence. The length of the test set sequence. (3) Use the grid search method to select the most suitable threshold from all possible thresholds. (4) An unsupervised anomaly detection method based on WGAN is constructed, which uses temporal convolutional blocks and Transformer encoding blocks to capture the spatial and temporal features of the data. The Wasserstein distance is used to replace the JS divergence in the original GAN ​​network to avoid the generator gradient vanishing and mode collapse problems in the training process of GAN network. At the same time, a gradient penalty term (Gradient Penalty, GP) is added to the WGAN network to avoid the parameters being basically at the limit boundary value due to weight pruning, thus wasting the model parameters. The Sigmoid function of the last layer is removed in the WGAN network, and a fully connected layer is used to output the values ​​of various distributions. The loss function of its discriminator is... Defined as:

[0127]

[0128] Loss function of generator Defined as:

[0129]

[0130] in It is the data distribution of the real sample. It is the true distribution of the generated samples. It is the sample distribution generated by the random latent space. It is a gradient penalty term that constrains the L2 norm of the discriminator relative to the input to be around 1, ensuring Lipschitz continuity. (5) Using the training dataset To train the model, a sliding window technique is used to divide the data into multiple subsequences. Let the sliding window size be... Step size is The subsequence of the training set is ,in Let be the number of subsequences. Accordingly, a set of subsequences is extracted from the random space. ,Will and The data is fed into the WGAN network for training. The generator and discriminator are trained through minimax game, and sufficient training iterations are performed to maximize the loss function of the discriminator and minimize the loss function of the generator. That is, the generator can generate data with the same distribution as the real data, and the discriminator can accurately distinguish between the generated data and the real data. (6) Test set It also uses a sliding window to divide into Subsequences, ,in Calculate the anomaly score for each test subsequence. The anomaly score is the sum of the generator's reconstruction error and the discriminator's discrimination error. Then, multiply this score by a preset threshold. The comparison is used to determine whether the window is abnormal. Finally, a binary label is assigned to each subsequence in the test dataset. ,in Indicates the first The window is abnormal. Indicates the first One window is normal. Abnormal score. The definition of is:

[0131]

[0132] in, and It is a weighting coefficient, and , express Norm. Based on the prediction results of the data analysis unit, the system can identify potential faults or anomalies and issue early warning signals through the early warning unit. Early warning information can be displayed in real time through the HMI interface and sent to the email addresses of operators and maintenance personnel via an SMTP server, ensuring timely action to prevent faults or equipment damage. The feedback adjustment unit automatically adjusts the operating status of the physical space system based on the results of the data analysis unit in the digital space. When a potential equipment failure is predicted, parameters are adjusted via PLC, backup equipment is activated, or control strategies are optimized to achieve fault prevention and production optimization.

[0133] Understandably, standardizing data collection and storage processes, by establishing multi-module data collection links, setting differentiated collection frequencies, unifying data formats, building encrypted cloud storage and dynamically managing capacity, enables comprehensive and standardized storage of multi-dimensional data, providing a high-quality data foundation for subsequent data analysis, while ensuring data security and storage stability.

[0134] In some embodiments of this application, when collecting, storing, and analyzing multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical control system, and identifying anomalies, outputting early warning information, and providing feedback for adjusting the physical control system, the method further includes:

[0135] A data analysis unit is set up to read data from the data management and storage unit and preprocess the data, including data cleaning, deduplication, and completion. During data cleaning, invalid data is deleted, including data with incorrect format or data that exceeds the reasonable range. During data deduplication, duplicate data is deleted, including data with the same timestamp, the same source identifier, and the same content. During data completion, interpolation is used to supplement missing data, and missing data is data that is consecutively missing no more than a preset number of records.

[0136] Feature extraction is performed on the preprocessed data, including time features, numerical features, and correlation features. Time features include data change period and peak occurrence time, numerical features include data mean and variance, and correlation features include numerical correlations between different data types.

[0137] The extracted features are input into the trained deep learning model, and anomaly prediction is performed on the input features to calculate the anomaly score.

[0138] When the anomaly score is less than the anomaly detection threshold, the system is considered to be in normal condition.

[0139] When the anomaly score is greater than or equal to the anomaly determination threshold, the system state is determined to be abnormal, and the data source and type corresponding to the anomaly characteristics are marked.

[0140] Specifically, the preset number of records is the maximum number of consecutive missing data allowed during the missing data completion stage of the analysis and optimization module's preprocessing of multi-dimensional data (including equipment operating status data, environmental monitoring data, etc.) of the physical control system. This is to ensure that the completed data can meet the accuracy requirements of subsequent feature extraction and anomaly identification, and to avoid distortion of the completed data due to excessive missing data. It is determined by statistically analyzing common consecutive missing data situations during the historical data acquisition process of the physical control system, combined with the minimum data continuity standard required for data analysis. Only data with consecutive missing records not exceeding the preset number of records is completed using interpolation, in order to adapt to the requirements of multimodal data analysis for data integrity and reliability.

[0141] Specifically, the deep learning model can be a generative adversarial network that integrates spatiotemporal convolutional blocks and Transformer coding blocks. This model has been trained using historical data from the normal operation of the physical control system, learning and fitting the data distribution patterns of normal system operation. The anomaly score is determined by a weighted sum of the reconstruction error of the model generator and the discrimination error of the discriminator, with the sum of the weight coefficients of the two parts being 1. The anomaly determination threshold is determined based on the normal operation status of the physical control system before using the deep learning model (such as a generative adversarial network integrating spatiotemporal convolutional blocks and Transformer coding blocks) for anomaly prediction. Historical data and a small number of labeled abnormal data samples were used to screen key values ​​from multiple candidate thresholds using a grid search method. During the screening process, the goal was to balance the model's misclassification rate for normal data (avoiding misclassifying normal data as abnormal) with its missed classification rate for abnormal data (avoiding missed classification of abnormal data as normal). Finally, the value that enabled the model to achieve the optimal anomaly identification accuracy (such as the highest F1 score) on the historical data test set was selected as the final threshold. This threshold was then compared with the anomaly score output by the model (obtained by weighted summation of generator reconstruction error and discriminator discrimination error) to accurately determine whether the system state was abnormal.

[0142] Understandably, by optimizing data analysis and clearly defining the operational standards for each stage of data preprocessing (such as the scope of invalid data judgment, the basis for identifying duplicate data, and the limit on the number of missing data entries to be filled), the preprocessing process is ensured to be standardized and uniform, avoiding data quality issues caused by operational differences. By quantitatively calculating anomaly scores (reflecting the degree to which data deviates from the normal distribution) and using preset anomaly judgment thresholds as an objective basis to determine the system status, replacing subjective judgment, the consistency and fairness of the anomaly judgment process are guaranteed. The entire analysis process forms a closed-loop control from data input to result output, which not only achieves accurate identification of anomalies in the industrial control system, but also ensures the stability and reliability of data analysis and optimization through process standardization. At the same time, it marks the data sources and types corresponding to anomaly characteristics, providing clear guidance for quickly locating the source of the fault and formulating targeted handling strategies, greatly improving the efficiency and effectiveness of industrial control system security defense, and better adapting to the security needs of complex industrial control environments.

[0143] In some embodiments of this application, when collecting, storing, and analyzing multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical control system, and identifying anomalies, outputting early warning information, and providing feedback for adjusting the physical control system, the method further includes:

[0144] Set up early warning units and establish rules for classifying early warning levels. The early warning levels include Level 1, Level 2, and Level 3. Different levels correspond to different degrees of abnormality. The degree of abnormality is determined based on the degree of difference between abnormal and normal characteristics.

[0145] When a system anomaly is detected, the warning level is determined according to the degree of anomaly, with Level 1 warning corresponding to the lowest degree of anomaly and Level 3 warning corresponding to the highest degree of anomaly.

[0146] When the early warning output is initiated, the early warning information is transmitted to the human-computer interaction interface, which displays the early warning level, abnormal data source, abnormal type, and abnormal time.

[0147] Establish an email sending link, connect to the SMTP server, edit the warning information into email content, including the warning level, anomaly details, and handling suggestions, obtain the staff's email address, and send the email to the corresponding email address;

[0148] Monitor the status of receiving early warning information. When a read confirmation is detected, stop resending the email. If no read confirmation is detected and the time since the last sending exceeds the preset sending interval, resend the email.

[0149] Specifically, the preset sending interval is a time interval set in the early warning unit of the analysis and optimization module to balance the timely delivery of early warning information from the physical control system with avoiding repeated email harassment to staff. It is determined by comprehensively analyzing the urgency of the early warning response corresponding to different anomalies in the physical control system (e.g., for high-urgency anomalies that may cause malfunctions in the physical control system, the interval needs to be shortened to ensure that staff can quickly obtain information; for low-urgency anomalies with less impact, the interval can be appropriately extended) and the need for staff to work normally without interference. It also combines actual scenario data such as the average time for staff to process early warnings and the distribution of working hours in the daily operation of the physical control system to ensure that the early warning information is not delayed in delivery without causing harassment due to excessively frequent email sending.

[0150] Understandably, refining the early warning mechanism, by classifying early warning levels, disseminating early warning information through multiple channels, and monitoring feedback, can provide accurate early warnings based on the degree of anomaly, ensuring that staff receive risk information in a timely manner, preventing risks from escalating due to untimely early warnings, and improving risk response efficiency.

[0151] In some embodiments of this application, when collecting, storing, and analyzing multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical control system, and identifying anomalies, outputting early warning information, and providing feedback for adjusting the physical control system, the method further includes:

[0152] Set up a feedback adjustment unit to receive the anomaly judgment results from the data analysis unit and the warning level from the early warning unit, and formulate adjustment strategies based on the warning level;

[0153] When the warning level is Level 1, the operating parameters of the physical control system are adjusted. The operating parameters include equipment operating speed, operating temperature, and production cycle time. The adjustment range is a preset fine adjustment range. After adjustment, real-time data from the system is collected and re-analyzed. If the anomaly is eliminated, the adjusted parameters are maintained. If the anomaly is not eliminated, the adjustment range is increased to a preset medium adjustment range.

[0154] When the warning level is level 2, the backup equipment is activated, the abnormal equipment in the physical control system is stopped, the backup equipment is connected to the physical control system to replace the abnormal equipment, the operating data of the backup equipment is collected, and its operating status is monitored.

[0155] When the warning level is level three, some production processes in the physical industrial control system are suspended, equipment with safety risks in the physical industrial control system is shut down, and staff are notified to investigate the fault on-site. After the fault is investigated, the equipment is started for trial operation, trial operation data is collected, and normal production of the physical industrial control system is restored after confirming that there are no abnormalities.

[0156] Specifically, the preset fine-tuning range is the minimum range used by the feedback adjustment unit in the analysis and optimization module when adjusting the operating parameters of the physical industrial control system (such as equipment operating speed, operating temperature, and production cycle time). It is determined by analyzing the sensitivity of equipment parameters in the physical industrial control system (i.e., the degree of impact of small changes in equipment parameters on the overall operating state of the physical industrial control system) and the stability requirements of the physical industrial control system (i.e., the requirement for the physical industrial control system to maintain normal operation and avoid operational fluctuations or failures after parameter adjustment). It is used to initially adjust parameters to attempt to eliminate minor anomalies when the warning level is Level 1, and to avoid affecting the stability of the physical industrial control system due to excessive parameter adjustment. The preset medium-range adjustment range is the medium range used by the feedback adjustment unit when adjusting the operating parameters of the physical industrial control system. It is determined by analyzing the adjustment range of equipment parameters in the physical industrial control system (i.e., the range of parameter values ​​that the equipment itself can safely adjust) and production requirements (i.e., the target requirements such as production efficiency and product quality that the physical industrial control system needs to maintain). It is used to further adjust parameters when the warning level is Level 1 and the anomaly has not been eliminated after fine-tuning, to ensure that the physical industrial control system can still maintain safe operation and meet production requirements while adjusting to a larger extent to eliminate the anomaly.

[0157] Understandably, improving feedback and adjustment strategies and developing differentiated adjustment plans based on different early warning levels, from fine-tuning parameters to activating backup equipment and suspending processes to troubleshoot faults, can achieve graded handling of risks. This can quickly eliminate minor risks and properly address serious hidden dangers, reducing the impact of risks on physical industrial control systems.

[0158] In some embodiments of this application, in the fault-tolerant redundancy unit of the twin isolation module, when monitoring the operating status of the primary device, the operating parameters of the primary device are collected. The operating parameters include operating current, voltage, temperature, and response time, and the normal range of each parameter is set.

[0159] The collected parameters are compared with the normal range. If any parameter is out of range and the duration exceeds the preset fault judgment time, the main equipment is judged to be faulty.

[0160] When all parameters are within the normal range, the main device is considered to be functioning normally.

[0161] When monitoring the primary network path, collect communication parameters, including data transmission rate, packet loss rate, and network latency, and set normal thresholds for each parameter;

[0162] The collected parameters are compared with normal thresholds. If the transmission rate is lower than the normal threshold, the packet loss rate is higher than the normal threshold, or the delay is higher than the normal threshold and the duration exceeds the preset interruption judgment time, the primary path is judged to be interrupted.

[0163] When all parameters meet the normal threshold requirements, the primary path is considered to be normal.

[0164] When switching equipment, disconnect the primary equipment from the physical industrial control system, establish a connection between the backup equipment and the physical industrial control system, and transmit the current operating parameters of the primary equipment to the backup equipment so that the initial parameters of the backup equipment are consistent with those of the primary equipment.

[0165] When performing a network switch, disconnect the primary path communication link, establish a backup path link, and synchronize the primary path communication configuration to the backup path to make the backup path configuration consistent with the primary path.

[0166] Specifically, the normal range is determined based on the design parameters, factory standards, and historical operating parameters such as operating current, voltage, temperature, and response time collected under normal operating conditions of the main equipment in the physical industrial control system (belonging to the monitoring object of the twin isolation module fault-tolerant redundancy unit, corresponding to the physical control system hardware components contained in the physical space unit). This range reflects the reasonable fluctuations of various parameters during fault-free operation. The preset fault judgment time is determined by analyzing the typical fault development process of the main equipment in the physical industrial control system, the duration of common instantaneous parameter fluctuations, and the system's time requirements for fault response. It is the shortest duration confirmed as a real fault after parameters exceeded the normal range in historical fault cases, used to eliminate misjudgments caused by instantaneous parameter fluctuations and ensure accurate fault judgment of the main equipment. The threshold is determined based on the design bandwidth, communication protocol requirements, and statistical analysis of communication parameters such as data transmission rate, packet loss rate, and network latency collected during historical normal operation of the primary network path in the physical industrial control system (a key part of the twin isolation module communication unit connecting the physical and digital spaces). It reflects the reasonable limit values ​​of each communication parameter when there is no risk of network path interruption. The preset interruption judgment duration is determined by analyzing the duration of common instantaneous communication fluctuations (such as short-term rate drops and packet loss caused by signal interference) in the primary network path of the physical industrial control system and the network communication stability requirements. It is the shortest duration confirmed as a real interruption after communication parameters exceed the normal threshold in historical network interruption cases. It is used to eliminate misjudgments caused by instantaneous fluctuations in communication parameters and ensure the accuracy of primary network path interruption judgment.

[0167] Understandably, refining the fault diagnosis and switching operations of the fault-tolerant redundancy unit, by setting normal parameter ranges and judgment durations and clarifying the switching process, can accurately identify equipment failures and network interruptions, ensure that parameters and configurations are consistent when switching to backup devices / paths, further enhance the system's ability to cope with hardware and network failures, and ensure the continuous and stable operation of the system.

[0168] Reference Figure 2-4 As shown in some embodiments of this application, a multi-dimensional industrial control security defense system based on digital twins includes:

[0169] The twin isolation module is used to build a digital space unit with the same functions as the physical industrial control system, set up a virtual human-machine interface, isolate the communication link from the virtual interface to the PLC, configure an identity authentication unit, a fault-tolerant redundancy unit and a communication unit, and connect the physical space unit and the digital space unit.

[0170] The verification and evaluation module is used to receive the encrypted operation instructions transmitted by the twin isolation module, simulate the operation process based on the real asset model and the standard database, verify the security of the instructions, and output the trusted instructions to the physical industrial control system and the status synchronization module.

[0171] The status synchronization module is used to receive trusted instructions, synchronize the communication protocols of physical and virtual devices, copy the status of the physical PLC to the virtual PLC, compare the status of the physical industrial control system and the virtual industrial control system, and identify status differences.

[0172] The analysis and optimization module is used to collect, store and analyze multi-dimensional data from the twin isolation module, the verification and evaluation module, the state synchronization module and the physical industrial control system, identify anomalies, output early warning information, and provide feedback to adjust the physical industrial control system.

[0173] Specifically, the workflow of the multi-dimensional industrial control security defense system based on digital twins provided by this invention is as follows: Operation command information from the digital space monitoring station in the twin isolation module is encrypted using the TLS / SSL protocol and then transmitted to the twin-simulated security operation and evaluation module. The operation verification and evaluation unit of this module evaluates the command information, and reliable operation information is then used in the real industrial control system and transmitted to the state synchronization module as the basis for consistency checks with the real industrial control system. Simultaneously, the process multimodal data analysis module collects, stores, and analyzes the data from the state synchronization module, responds with warnings based on the analysis results, and provides feedback to adjust the real industrial control system.

[0174] It is understandable that the aforementioned digital twin-based multi-factor industrial control security defense method and system have the same beneficial effects, and will not be elaborated further here.

[0175] It should be noted that:

[0176] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of this application may be practiced without these specific details. In some instances, well-known structures and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0177] Furthermore, those skilled in the art will understand that although some embodiments described herein include certain features included in other embodiments but not others, combinations of features from different embodiments are meant to be within the scope of this application and form different embodiments.

[0178] The above description is merely a preferred embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A multi-element industrial control security defense method based on digital twinning, characterized in that, Comprise: S1, build a digital space unit consistent with the function of the physical industrial control system, set up a virtual human-computer interaction interface, isolate the communication link of the virtual interaction interface to the PLC, configure the identity authentication unit, fault-tolerant redundancy unit and communication unit, connect the physical space unit and the digital space unit; S2, receive the operation instruction transmitted by the twin isolation module, simulate the operation process according to the real asset model and the specification database, verify the safety of the instruction, and output the trusted instruction to the physical industrial control system and the state synchronization module; S3, receive the trusted instruction, synchronize the communication protocol of the physical and virtual devices, copy the physical PLC state to the virtual PLC, compare the state of the physical industrial control system and the virtual industrial control system, and identify the state difference; S4, collect, store and analyze the multi-dimensional data of the twin isolation module, the verification and evaluation module, the state synchronization module and the physical industrial control system, identify the abnormality, output the warning information, and feedback the adjustment of the physical industrial control system; When building a digital space unit consistent with the function of the physical industrial control system, setting up a virtual human-computer interaction interface, isolating the communication link of the virtual interaction interface to the PLC, configuring the identity authentication unit, fault-tolerant redundancy unit and communication unit, and connecting the physical space unit and the digital space unit, it comprises: Establish the mapping relationship between the physical space unit and the digital space unit; The physical space unit includes the physical devices, sensors, actuators, control units and operating environment of the physical industrial control system; Copy the device configuration, sensor arrangement and production line process of the digital space unit to the physical space unit; When connecting the physical space unit and the digital space unit, set up the communication unit, which includes the industrial communication unit and the network communication unit. The industrial communication unit realizes the interconnection of industrial devices using industrial communication protocols, and the network communication unit connects the digital and physical space using wired or wireless networks; When setting up a virtual human-computer interaction interface, set up a virtual network card between the virtual interaction interface and the physical PLC to isolate the communication link; When configuring the identity authentication unit, establish a user identity information library to store user identity identifiers and set user operation permission levels. When a user accesses the interface, the user's identity identifier is collected and compared with the information library. If the collected identity identifier is consistent with the information library, the corresponding permission level is read and the corresponding operation function is opened. If the collected identity identifier is inconsistent with the information library, the operation function is refused to open; When configuring the fault-tolerant redundancy unit, set up standby devices and standby network paths. The standby devices are consistent with the main devices in type, the standby network paths are consistent with the main paths in communication protocol, and the running status of the main devices and the main paths is monitored. When the main device fails, switch to the standby device. When the main path is interrupted, switch to the standby path; When receiving the operation instruction transmitted by the twin isolation module, simulating the operation process according to the real asset model and the specification database, verifying the safety of the instruction, and outputting the trusted instruction to the physical industrial control system and the state synchronization module, it comprises: Decrypt the instruction and obtain the decrypted instruction content; A real asset model is established, structure parameters, operation parameters and performance parameters of physical devices in the physical industrial control system are collected, and an asset model is constructed based on the collected parameters, the model structure is consistent with the physical devices, and the operation parameter range is consistent with the physical devices; A standard database is established to store operation specifications, safety standards and configuration parameters of the physical industrial control system. The operation specifications include device operation steps and sequences, the safety standards include parameter thresholds and operation limitation conditions, and the configuration parameters include device operation reference parameters; When simulating the operation process, the decrypted instructions are input into the real asset model to drive the real asset model to run, and state data of the real asset model running is collected, including device operation parameters and operation execution results; When verifying the safety of the instructions, the state data is compared with the safety standards in the standard database to extract the parameter thresholds and operation limitation conditions in the standards, and the real asset model operation parameters and thresholds and the operation results and limitation conditions are compared; When the real asset model operation parameters are within the thresholds and the operation results meet the limitation conditions, the instructions are determined to be trusted instructions, and are output to the physical industrial control system and the state synchronization module; When the real asset model operation parameters exceed the thresholds or the operation results do not meet the limitation conditions, the instructions are determined to be untrusted instructions and are rejected; A time scaling unit is set to adjust the simulation time rate, collect state data after the rate is increased, repeatedly verify the safety of the instructions, and the number of repetitions is greater than or equal to two times; when the two verification results are consistent, the determination result is determined; when the two results are inconsistent, the rate is adjusted again and verified until the results are consistent; The trusted instructions are received, the communication protocols of the physical and virtual devices are synchronized, the physical PLC state is copied to the virtual PLC, the states of the physical and virtual industrial control systems are compared, and when the state difference is identified, including: The trusted instructions are used as the reference instructions for state synchronization; A protocol synchronization protection unit is set to establish a protocol conversion mechanism, and the communication protocol types of the physical and virtual devices are collected; when the protocols of the physical and virtual devices are inconsistent, the protocol conversion mechanism is started to convert one protocol to the protocol supported by the other party; Communication data of the physical and virtual devices are collected, and data transmission integrity is monitored; when data is lost, the lost data is retransmitted; A state synchronization control unit is set to collect running state data of the physical PLC, the running state data includes input parameters, output parameters and program running state of the PLC, the collected running state data is transmitted to the virtual PLC, and the virtual PLC state is updated; A physical twin component unit is established to copy state data of physical devices in the physical industrial control system, including device operation parameters, fault state and working mode, the copied state data is transmitted to the virtual environment, and the virtual device state is updated; The state consistency check is performed, real-time running data of the physical industrial control system and the virtual industrial control system is collected, the real-time running data includes device parameters, operation execution data, network transmission data, the real-time running data of the physical industrial control system and the virtual industrial control system is compared one by one, and a data difference value is calculated; when the data difference value is less than a preset difference threshold, it is determined that the state of the physical industrial control system and the virtual industrial control system is consistent; when the data difference value is greater than or equal to the preset difference threshold, it is determined that the state of the physical industrial control system and the virtual industrial control system is inconsistent, and device or module information corresponding to the difference data is collected, and difference information is output; The multi-dimensional data of the twin isolation module, the verification and evaluation module, the state synchronization module and the physical industrial control system is collected, stored and analyzed, and an exception is identified, early warning information is output, and the physical industrial control system is adjusted, including: A data collection unit is set, a data collection link is established, the state synchronization module, the physical industrial control system, the twin isolation module and the verification and evaluation module are connected, multi-dimensional data of each module and the physical industrial control system is collected, and the multi-dimensional data includes device running state data, environment monitoring data, production process data, energy consumption data, device performance data and network security data; A data collection frequency is set, the device running state data collection frequency is higher than the environment monitoring data, and the production process data collection frequency is higher than the energy consumption data; when collecting data, different format data is converted into a unified format, a timestamp of data collection and a data source identifier are marked, the timestamp is accurate to seconds, and the data source identifier includes a module name and a device name; A data management and storage unit is set, a cloud storage node is built, the storage node includes a data storage area, an encryption area and an index area, the converted data is transmitted to the storage area, the data is processed in the encryption area by using a symmetric or asymmetric encryption method, and a data index is established in the index area, the index includes a data identifier, a storage location and a timestamp range; The cloud storage capacity is monitored, when the storage capacity occupancy rate reaches a preset capacity threshold, historical data exceeding a preset storage time length is deleted or transferred to a backup storage node; when the storage capacity occupancy rate is lower than the preset capacity threshold, new data is continuously stored; The multi-dimensional data of the twin isolation module, the verification and evaluation module, the state synchronization module and the physical industrial control system is collected, stored and analyzed, and an exception is identified, early warning information is output, and the physical industrial control system is adjusted, including: A data analysis unit is set, data is read from the data management and storage unit, and the data is preprocessed, the preprocessing includes data cleaning, deduplication and completion; when the data is cleaned, invalid data is deleted, the invalid data includes data with format errors and data exceeding a reasonable range; when the data is deduplicated, duplicate data is deleted, the duplicate data includes data with the same timestamp, the same source identifier and the same content; when the data is completed, interpolation is used to supplement missing data, and the missing data is data that is continuously missing for no more than a preset number of times. The pre-processed data is subjected to feature extraction, including time features, numerical features, and correlation features. The time features include data change period and peak occurrence time. The numerical features include data mean and variance. The correlation features include numerical correlations between different data types. The extracted features are input into the trained deep learning model, and the input features are subjected to anomaly prediction to obtain an anomaly score. If the anomaly score is less than the anomaly determination threshold, the system state is determined to be normal. If the anomaly score is greater than or equal to the anomaly determination threshold, the system state is determined to be abnormal, and the data source and type corresponding to the abnormal features are marked.

2. The multi-element industrial control security defense method based on digital twinning according to claim 1, characterized in that, The multi-dimensional data of the twin isolation module, the verification and evaluation module, the state synchronization module, and the physical industrial control system are collected, stored, and analyzed, and abnormalities are identified. When feedback is required to adjust the physical industrial control system, the following steps are included: An early warning unit is set up, and early warning level division rules are established. The early warning levels include first, second, and third level warnings. Different levels correspond to different degrees of abnormality. The degree of abnormality is determined based on the difference between abnormal features and normal features. When the system is determined to be abnormal, the early warning level is determined based on the degree of abnormality. The first level warning corresponds to the lowest degree of abnormality, and the third level warning corresponds to the highest degree of abnormality. When the early warning output is started, the early warning information is transmitted to the human-machine interface. The interface displays the early warning level, abnormal data source, abnormal type, and abnormal time. An email sending link is established to connect the SMTP server. The early warning information is edited as email content, which includes early warning level, abnormal details, and processing suggestions. The email address of the staff is obtained, and the email is sent to the corresponding mailbox. When the email has been read, the repeated sending is stopped. If no read feedback is monitored and the time since the last sending exceeds the preset sending interval, the email is resent.

3. The multi-element industrial control security defense method based on digital twinning according to claim 2, characterized in that, When feedback is required to adjust the physical industrial control system, the following steps are included: A feedback adjustment unit is set up to receive the anomaly determination results of the data analysis unit and the early warning levels of the early warning unit. Adjustment strategies are developed based on the early warning levels. When the early warning level is first, the operating parameters of the physical industrial control system are adjusted. The operating parameters include device operating speed, working temperature, and production rhythm. The adjustment amplitude is the preset fine adjustment amplitude. After the adjustment, the system real-time data is collected and reanalyzed. If the abnormality is eliminated, the adjusted parameters are maintained. If the abnormality is not eliminated, the adjustment amplitude is increased to the preset medium adjustment amplitude. When the early warning level is second, the standby device is enabled, and the abnormal device in the physical industrial control system is stopped. The standby device is connected to the physical industrial control system to replace the abnormal device. The operating data of the standby device is collected, and its operating state is monitored. When the early warning level is third, part of the production process in the physical industrial control system is suspended, and the devices with safety risks in the physical industrial control system are turned off. The staff is notified to troubleshoot the fault on site. After troubleshooting, the device is started for trial operation, the trial operation data is collected, and the physical industrial control system is restored to normal production after confirming that there is no abnormality.

4. The multi-element industrial control safety defense method based on digital twinning according to claim 3, characterized in that, in the fault-tolerant redundancy unit of the twinning isolation module, the operating parameters of the main equipment are collected when monitoring the operating state of the main equipment, the operating parameters include working current, voltage, temperature, and response time, and the normal range of each parameter is set; the collected parameters are compared with the normal range, and if any parameter exceeds the range and the duration exceeds the preset fault determination time length, it is determined that the main equipment is faulty; when all parameters are within the normal range, it is determined that the main equipment is normal; when monitoring the main network path, communication parameters are collected, including data transmission rate, packet loss rate, and network delay, and the normal threshold of each parameter is set; the collected parameters are compared with the normal threshold, and if the transmission rate is lower than the normal threshold, the packet loss rate is higher than the normal threshold, or the delay is higher than the normal threshold and the duration exceeds the preset interruption determination time length, it is determined that the main path is interrupted; when all parameters meet the normal threshold requirements, it is determined that the main path is normal; when switching the equipment, disconnect the main equipment from the physical industrial control system, establish the connection between the standby equipment and the physical industrial control system, and transfer the current operating parameters of the main equipment to the standby equipment, so that the initial parameters of the standby equipment are consistent with those of the main equipment; when switching the network, disconnect the main path communication link, establish the standby path link, and synchronize the main path communication configuration to the standby path, so that the standby path configuration is consistent with the main path configuration.

5. A multi-element industrial control security defense system based on digital twinning, characterized in that, A multi-element industrial control safety defense method based on digital twinning according to any one of claims 1-4, comprising: a twinning isolation module for building a digital space unit consistent with the function of the physical industrial control system, setting up a virtual human-computer interaction interface, isolating the communication link of the virtual interaction interface to the PLC, configuring an identity authentication unit, a fault-tolerant redundancy unit, and a communication unit, and connecting the physical space unit and the digital space unit; a verification and evaluation module for receiving operation instructions encrypted and transmitted by the twinning isolation module, simulating the operation process according to the real asset model and the specification database, verifying the safety of the instructions, and outputting trusted instructions to the physical industrial control system and the state synchronization module; a state synchronization module for receiving trusted instructions, synchronizing the communication protocols of physical and virtual equipment, copying the state of physical PLC to virtual PLC, comparing the states of physical and virtual industrial control systems, and identifying state differences; an analysis and optimization module for collecting, storing, and analyzing multi-dimensional data of the twinning isolation module, the verification and evaluation module, the state synchronization module, and the physical industrial control system, identifying abnormalities, outputting warning information, and feeding back to adjust the physical industrial control system.

Citation Information

Patent Citations

  • Autonomous security risk sensing system and method based on digital twin industrial control network

    CN120281563A