Decentralized robot cluster anti-intrusion system and method
By employing a decentralized network architecture and multi-party cross-verification mechanism, combined with environmental feature fingerprint matching and virtual attacker optimization, the system addresses the trust and security vulnerabilities of centralized multi-robot systems, achieving highly reliable intrusion prevention and dynamic defense capabilities.
Patent Information
- Application Number
- CN202511567271.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-02-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing centralized multi-robot scheduling systems lack a mechanism to physically verify the authenticity of data reported by robots when faced with internal or external collusion attacks, leading to a crisis of trust and security vulnerability. This results in insufficient system robustness, fraud risks, and potential physical security incidents.
A decentralized network architecture is adopted, and the authenticity of the robot's state is verified through multi-party cross-verification and environmental feature fingerprint matching mechanism. Combined with near-field physical channel authentication and temporary session key generation, a high-weight fixed notary node and virtual attacker robot optimization path strategy are introduced to build a hybrid audit and distributed evidence storage framework.
It effectively prevents malicious nodes from injecting false location information, prevents communication hijacking attacks, improves the system's data credibility and defense capabilities, has predictive defense capabilities that dynamically adapt to unknown threats, and ensures effective state witnessing and tamper-proof auditing in any region.
Smart Images

Figure CN121585989A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of robotics technology, specifically relating to a decentralized robot swarm intrusion prevention system and method. Background Technology
[0002] Multi-robot systems, such as automated guided vehicles and autonomous mobile robots, have been widely used in fields such as automated warehousing and intelligent manufacturing. Through collaborative operations, they have significantly improved the efficiency and accuracy of material handling, cargo sorting, and production line assembly, becoming an indispensable key infrastructure for building smart factories and smart logistics systems.
[0003] In existing technologies, most such systems employ a centralized scheduling architecture. Their operation involves a central scheduling server collecting real-time location, task status, and environmental perception data from all robots. A global path planning algorithm then calculates and assigns the optimal path and task instructions to each robot, achieving efficient, collision-free cluster collaboration. However, this centralized architecture has inherent technical flaws and serious security vulnerabilities. The central server is the system's "single point of failure" bottleneck; a failure or cyberattack will paralyze the entire robot cluster. Furthermore, in actual operation, if internal malicious actors collude with external attackers, it can lead to anything from large-scale operational congestion and drastic efficiency reduction to physical collisions and safety incidents.
[0004] Existing security measures primarily focus on network perimeter defense and communication encryption, proving largely ineffective against fraudulent data attacks originating from within the system and capable of bypassing authentication. Therefore, there is an urgent need for a novel scheduling mechanism that can break free from centralized dependence and establish verifiable consistency between data and the physical world, fundamentally addressing the trust vulnerabilities and security risks inherent in current technologies. Summary of the Invention
[0005] To address the problems mentioned in the background section, this invention provides a decentralized robot swarm intrusion prevention system and method.
[0006] To achieve the above objectives, the present invention provides the following technical solution: a decentralized robot cluster intrusion prevention method, comprising the following steps:
[0007] S1. Multiple robot entities and sensing devices together form a decentralized network without a central server. All devices in the network record a unified status log, which is used to update the status information of all robots and devices in the network in real time.
[0008] S2. Before communicating with each other, robot entities first perform one-time authentication through a close-range physical channel and generate a temporary session key;
[0009] S3. When any robot entity needs to declare or update its state, it executes the state proof protocol. The state proof protocol integrates a multi-party cross-verification mechanism and an environmental feature fingerprint matching mechanism to verify the authenticity of the physical state declared by the robot entity.
[0010] S4. When the number of other mobile robot entities within the preset range of the robot entity is lower than the minimum number required for witnessing, the system switches to hybrid witnessing mode; the robot entity then initiates a status proof request to the fixed notary node within the communication range, and the fixed notary node completes the status proof based on the higher witnessing weight.
[0011] In a preferred embodiment of the present invention, in step S2, the session key is tightly bound to the physical relative position, attitude, and environmental fingerprint of the two robot entities;
[0012] When the robot entity exceeds the preset physical relative distance, or its relative posture changes significantly, or the preset time window expires, the session key and related authorizations immediately become invalid.
[0013] In a preferred embodiment of the present invention, in S2, the near-field physical channel is implemented in the following way: the robot entities verify their physical proximity to each other by performing a preset, synchronous cooperative action; the robot entities record and exchange action data in real time; and only when the action data is highly consistent in time sequence and motion characteristics is their identity confirmed and communication established.
[0014] In a preferred embodiment of the present invention, in S3, the multi-party cross-verification mechanism includes, when the robot entity declares, initiating a verification request to at least two witness robot entities or witness nodes that are geographically adjacent;
[0015] The witnessing robot entity or witnessing node uses the sensing devices it is equipped with to independently observe and verify the physical state declared by the robot entity;
[0016] If the observation result is consistent with the declared physical state within a preset error range, the witnessing robot entity or witnessing node uses its private key to cryptographically sign the verification result and reports the signature result along with the observation data digest to the decentralized network. The consensus protocol of the decentralized network requires a preset number of valid independent signers before the declared physical state can be accepted as valid.
[0017] In a preferred embodiment of the present invention, in step S3, the environmental feature fingerprint matching mechanism includes: the robot entity collecting unique features of its physical environment and generating an environmental fingerprint; the environmental fingerprint and the declared physical state being submitted to the state log together.
[0018] The status log queries the stored historical environment fingerprint database to verify whether the currently submitted environment fingerprint is highly consistent with the historical fingerprint of the declared location;
[0019] In a preferred embodiment of the present invention, in step S4, the fixed notary node independently observes and verifies the physical state of the robot entity requesting verification.
[0020] The robot entity requesting verification must submit data containing the characteristics of its location environment for comparison and secondary confirmation by a fixed notary node, thereby ensuring the absolute accuracy of the verification results.
[0021] In a preferred embodiment of the present invention, in step S4, when the fixed notary node witnesses the status of the robot entity, it generates an encrypted and tamper-proof log, calculates an irreversible cryptographic verification code on the log, and forcibly embeds the verification code into the digital signature of the robot entity. The digital signature and the verification code are permanently bound together to prevent subsequent tampering.
[0022] In a preferred embodiment of the present invention, the system further includes: a group of virtual attacker robots that continuously simulate attacks in a virtual network to find weaknesses in the current robot entity path planning scheme; and the robot entity optimizing its path strategy based on the results of the simulated attacks.
[0023] In a preferred embodiment of the present invention, the environmental fingerprint is generated by at least one of the following methods: geographic location mapping data based on Wi-Fi signal strength indication, spatial distribution characteristics based on geomagnetic field strength, and high-resolution visual images based on local ground texture, wall defects, and surface features of fixed structural components.
[0024] A decentralized robot swarm intrusion prevention system includes:
[0025] The camera module is used to capture visual features of the robot's appearance, posture, motion trajectory, and environment.
[0026] The density sensing module continuously monitors the density of other moving robot entities within a preset range around the robot entity;
[0027] The positioning module uses high-precision ranging capabilities to cross-verify the robot's position;
[0028] The radar module is used to generate 3D point cloud data of the surrounding environment and the observed robot entity, measure the robot's position, distance, and speed, and provide additional motion state verification.
[0029] An inertial measurement unit (IMU) is used to provide attitude and motion information of robot entities and to verify physical proximity by comparing motion data between robot entities.
[0030] The Wi-Fi module is used to measure the signal strength of surrounding APs to generate a Wi-Fi fingerprint for location verification;
[0031] The three-axis magnetic module is used to collect the geomagnetic field strength and direction at the current location of the robot to generate a geomagnetic fingerprint.
[0032] This invention addresses the shortcomings of the prior art and has the following beneficial effects:
[0033] 1. This invention uses a combination of multi-party cross-validation and environmental feature fingerprint matching to forcibly verify the physical authenticity of the robot's declared state. Any state update requires neighboring robots to independently observe and confirm using multiple sensors and compare it with the unique physical fingerprint of the environment. This fundamentally eliminates fraudulent information such as malicious nodes injecting false locations, and changes the security mode from trusting devices to verifying events, establishing a data credibility that is unparalleled by existing technologies.
[0034] 2. This invention designs an instantaneous identity authorization mechanism based on physical proximity. It requires robots to verify their identity through close-range, synchronous collaborative physical actions, such as specific swaying, before communication. Upon successful verification, a temporary session key is continuously bound to the relative physical positions and postures of both parties, and becomes invalid immediately if it exceeds a preset range. Compared to traditional technologies that rely on easily stolen digital certificates, this mechanism constructs an insurmountable physical barrier, completely eliminating remote identity impersonation and communication hijacking attacks.
[0035] 3. This invention integrates a generative adversarial swarm intelligence path-playing mechanism. By deploying virtual attacker robots in a digital twin environment to continuously simulate attacks, it proactively seeks vulnerabilities in the path planning and coordination strategies of the real robot swarm. The real robot swarm uses the results of these simulated attacks as learning input, continuously optimizing and evolving its collective behavior strategies, thereby gaining early immunity to potential attack patterns. This contrasts sharply with the passive defense model of existing technologies that rely on static optimization under benign assumptions, endowing the system with a dynamically adaptable and predictive defense capability against unknown threats.
[0036] 4. This invention constructs a hybrid auditing and distributed evidence storage framework. By introducing high-weight fixed notary nodes, it ensures effective state witnessing in any region and generates encrypted evidentiary logs permanently bound to physical evidence, such as video snapshots. To prevent evidence tampering, the decryption key and the data itself of this log are sliced, divided into fragments using the Shamir secret sharing algorithm, and randomly stored in a large number of mobile robots. This significantly increases the physical and cryptographic difficulty of tampering with or destroying evidence, establishing a completely decentralized and tamper-proof audit trail capability that far surpasses traditional centralized log systems. Attached Figure Description
[0037] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:
[0038] Figure 1 This is a flowchart of a preferred embodiment of the present invention. Detailed Implementation
[0039] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0040] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein. Therefore, the scope of protection of the invention is not limited to the specific embodiments disclosed below.
[0041] A decentralized robot cluster intrusion prevention method aims to fundamentally solve the trust crisis and security vulnerability caused by the lack of a mechanism to physically verify the authenticity of robot-reported data when existing centralized multi-robot scheduling systems encounter internal or external collusion attacks. This overcomes the technical challenges of insufficient system robustness, fraud risk, and potential physical security incidents.
[0042] like Figure 1 As shown, a decentralized robot cluster intrusion prevention method includes the following steps:
[0043] S1. Multiple robot entities and sensing devices together form a decentralized network without a central server. All devices in the network record a unified status log, which is used to update the status information of all robots and devices in the network in real time.
[0044] S2. Before communicating with each other, robot entities first perform one-time authentication through a close-range physical channel and generate a temporary session key;
[0045] S3. When any robot entity needs to declare or update its state, it executes the state proof protocol. The state proof protocol integrates a multi-party cross-verification mechanism and an environmental feature fingerprint matching mechanism to verify the authenticity of the physical state declared by the robot entity.
[0046] S4. When the number of other mobile robot entities within the preset range of the robot entity is lower than the minimum number required for witnessing, the system switches to hybrid witnessing mode; the robot entity then initiates a status proof request to the fixed notary node within the communication range, and the fixed notary node completes the status proof based on the higher witnessing weight.
[0047] In one specific embodiment, the present invention first constructs a decentralized network without a central server. All devices within the network jointly record a unified state log for real-time updates of the state information of all robots and devices in the network. Its core is a decentralized network specifically optimized for the Internet of Things (IoT) environment. Unlike the linear chain structure of traditional blockchains, the decentralized network adopts a customized directed acyclic graph (DAG) architecture. The core advantage of the DAG architecture is that it can support concurrent processing of multiple transactions, rather than serial block confirmation, thereby improving the throughput of state updates.
[0048] The following will describe each step in detail.
[0049] S1, multiple robot entities and sensing devices together form a decentralized network without a central server. All devices in the network jointly record a unified status log, which is used to update the status information of all robots and devices in the network in real time.
[0050] The decentralized network uses a directed acyclic graph (DAG) structure as its underlying data structure. Compared to the linear chain model of traditional blockchains, the DAG structure supports concurrent processing and asynchronous verification of multiple transactions, significantly improving the scalability and real-time performance of the network. Its core feature is that it abandons the central server in traditional centralized systems and instead consists of multiple robot entities and sensing devices forming a peer-to-peer network. Robot entities, fixed sensing nodes, and the system all act as peer participants in the network, jointly maintaining a unified state log.
[0051] Directed acyclic graph (DAG) is a non-linear data structure that allows robot entities and fixed sensing nodes to directly publish new transactions after verification and referencing a small number of recent transactions, rather than relying on the serial confirmation mechanism of traditional blocks. This significantly reduces transaction processing latency and can theoretically achieve tens of thousands to hundreds of thousands of state updates per second. Each robot entity and fixed sensing node generates an asymmetric key pair during startup through a secure bootstrapping process. The public key is used for network identity registration, and the private key is used for cryptographic signing of transaction processing to ensure data integrity and non-repudiation.
[0052] Specifically, when any robot entity in the cluster, such as an AGV-M100 robot entity performing a cargo handling task, needs to declare or update its status information to the decentralized network, such as the robot entity's current three-dimensional coordinate position, motion posture, task execution progress, battery level, load status, or channel occupancy, the robot entity must generate and submit a status log.
[0053] S2. Before communicating with each other, robot entities first perform one-time authentication through a close-range physical channel and generate a temporary session key.
[0054] Communication refers to the secure data exchange process between robot entities that involves instantaneous authorization and physical binding to achieve collaborative operations. Short-range physical channels specifically refer to short-range communication media based on physical layer characteristics used by robot entities to establish secure communication. They do not rely on traditional network layer protocols but verify the physical proximity and identity authenticity of the communicating parties through direct physical interaction or physical signal transmission.
[0055] Physical interaction is a method of verification through coordinated physical actions. Two robot entities record and exchange motion data in real time by performing a preset, synchronized coordinated action (e.g., a specific nodding, swaying, or circular motion). The system performs precise matching of the motion data in terms of time sequence and motion characteristics, and only confirms the legitimacy of each other's identities and establishes communication when the motion data is highly consistent.
[0056] Physical signal transmission involves the sender transmitting information by modulating infrared light pulses, and the receiver must respond within a very short time. For example, the sender transmits a pulse sequence at a specific frequency and with a specific encoding, and the receiver captures and decodes the signal. If the signal is correctly received within a preset time and the signal strength meets a proximity threshold, physical proximity is confirmed. Because infrared signals cannot penetrate obstacles and have a limited propagation distance, attackers find it difficult to deceive the receiver through remote relay or signal forgery.
[0057] A temporary session key is a symmetric encryption key that is dynamically generated and valid for a short period of time after both parties have completed one-time authentication through physical interaction or physical signal transmission. The usage period of a temporary session key is strictly constrained by physical conditions.
[0058] Spatial constraints: the two communicating parties cannot exceed a preset physical relative distance (e.g., 10 meters).
[0059] Attitude constraints: the relative attitude of the two parties cannot change beyond a preset threshold.
[0060] Time constraints, a preset time window (e.g., 10 seconds) from the time the key is generated.
[0061] Environmental fingerprint consistency: The current environmental fingerprint deviates significantly from the environmental fingerprint recorded when the key was generated.
[0062] The temporary session key and related authorizations will become invalid if the constraints are exceeded.
[0063] S3. When any robot entity needs to declare or update its state, it executes the state proof protocol. The state proof protocol integrates a multi-party cross-verification mechanism and an environmental feature fingerprint matching mechanism to verify the authenticity of the physical state declared by the robot entity.
[0064] Multi-party cross-verification (MCC) provides a verifiable, physically-based trust foundation for decentralized robot swarm systems, effectively resisting collusion attacks and the injection and tampering of false information. Specifically, when a robot entity needs to declare or update its state, it initiates a verification request to at least two geographically proximate mobile robot entities located from different observation angles, acting as witnesses. Upon receiving the request, the witnesses independently and in real-time observe and collect data on the physical state of the requesting robot entity.
[0065] The witness independently collects the physical state data of the requested robot entity, including but not limited to: visual images of the requested robot entity, such as the appearance, posture and motion trajectory of the requested robot entity;
[0066] 3D point cloud data is used to accurately verify the position and orientation of the requesting robot entity;
[0067] Distance localization is used to cross-validate the position of the requesting robot entity;
[0068] Inertial attitude measurement is used to measure distance, velocity, and angle of the requesting robot entity, providing additional motion state verification.
[0069] The witnessing party fuses and processes the collected data from various sensors, compares its own observation results with the sensor data, and verifies whether they are within a preset error range. When the observation results and the declared values are within the preset error range, the witnessing party considers the verification successful. For example, the position deviation is less than 5 centimeters and the attitude deviation is less than 2 degrees. After successful verification, the witnessing party uses its instantaneous private key to digitally sign the verification result and the observation data digest; generates a witness signature packet and sends it to the decentralized network.
[0070] After receiving multiple witness signature packets, the centralized network uses a consensus algorithm to determine:
[0071] Does it meet the preset number of independent signers (e.g., ≥3)?
[0072] Does it include verification results from different sensor types (heterogeneity requirement)?
[0073] Is there any rationality in the synchronization of signature time and spatial distribution?
[0074] When the verification result meets the conditions, the ledger confirms the validity of the state declaration and records the corresponding verification summary; if the conditions are not met, the request is rejected. Requests that fail verification generate a rejection signature for anomaly detection and log auditing. The multi-party cross-validation mechanism verifies the authenticity of the physical state declared by robot entities by introducing direct observational evidence from the real world, preventing any robot from reporting a falsified state.
[0075] The environmental fingerprint matching mechanism requires that when a machine reports its physical location, it must simultaneously collect unique, multimodal feature data of its physical environment and generate a comprehensive environmental fingerprint to prove the authenticity of its claimed location. Traditional positioning technologies are susceptible to signal spoofing or deception attacks. This mechanism, by comparing environmental features strongly bound to a specific physical space, makes it extremely difficult for attackers to simultaneously forge a complex, comprehensive environmental fingerprint that perfectly matches the false location, even if they can forge a positioning signal. Furthermore, direct physical observation by the witness may be subject to obstruction, blocked lines of sight, or sensor errors. In such cases, environmental fingerprint matching can serve as supplementary verification or cross-evidence, improving the system's robustness in judging anomalies or deviations.
[0076] Specifically, when a robot entity needs to declare its location, it collects characteristic data of its environment. Environmental fingerprints are generated by fusing the following data sources, including but not limited to:
[0077] Geographic location mapping data based on Wi-Fi signal strength: Measure the signal strength of multiple known access points (APs) in the vicinity, generate a signal strength vector, and form a Wi-Fi signal map fingerprint.
[0078] Based on the spatial distribution characteristics of geomagnetic field intensity: collect the geomagnetic field intensity and direction unique to the current location to generate a geomagnetic fingerprint.
[0079] Local environmental features based on visual images: capture local ground textures, wall imperfections, and surface features of fixed structural components in the surrounding environment, and generate visual feature fingerprints.
[0080] The robot entity submits the generated environmental fingerprint along with its declared physical location information to the state log, which is then received by the decentralized network. Upon receiving the data, the decentralized network queries a pre-built and stored historical environmental fingerprint database. It performs a high-precision matching verification between the submitted environmental fingerprint and the historical fingerprints corresponding to the declared location stored in the database. Only when the submitted environmental fingerprint highly matches the historical fingerprint of the declared location is the robot entity's location declaration confirmed as genuine and valid.
[0081] S4. When the number of other mobile robot entities within the preset range of the robot entity is lower than the minimum number required for witnessing, the system switches to hybrid witnessing mode; the robot entity then initiates a status proof request to the fixed notary node within the communication range, and the fixed notary node completes the status proof based on the higher witnessing weight.
[0082] In remote corners of a warehouse or during off-peak hours, a single robot may not have enough mobile companions to complete multi-party cross-verification. The hybrid witness mode provides a reliable alternative, ensuring that any robot entity can effectively prove its physical state at any time and in any location. Multiple fixed notary nodes are pre-deployed in the operating environment. These fixed notary nodes are given higher witness weight by the consensus protocol. In the warehouse, these fixed notary nodes can be smart charging piles, high-precision monitoring camera systems, or automated loading and unloading platforms.
[0083] To further enhance the absolute authenticity and anti-spoofing capability of the verification, the robot entity requesting verification will include additional environmental feature auxiliary verification data when submitting its status certificate to the fixed notary node. This auxiliary verification data is based on permanent and immutable physical characteristics of the robot entity's environment. These physical characteristics include, but are not limited to: the geometry of ground cracks, the texture of wall stains, specific scratches on load-bearing columns, or images of equipment serial numbers. Upon receiving the auxiliary verification data, the fixed notary node will compare it with historical feature points in its pre-stored high-precision environmental map to double-confirm the physical position and orientation of the requesting robot, effectively eliminating the possibility of GPS signal spoofing.
[0084] Upon receiving a verification request, the fixed notary node generates a transparent log, which is an encrypted and immutable data packet. This data packet is a snapshot of the original data at the moment the robot entity made the request, such as a high-resolution encrypted video stream or 3D point cloud data, capturing the complete process of the robot entity performing a specific action. After generating the transparent log, the fixed notary node calculates its irreversible ciphertext checksum and forcibly embeds the checksum into its digital signature for the robot transaction.
[0085] Furthermore, to prevent the fixed notary node from tampering with or destroying the evidentiary log, this invention employs a sliced evidence storage mechanism. The fixed notary node uses a one-time generated symmetric key to encrypt the complete evidentiary log, and the symmetric key is divided into K key fragments using Shamir's Secret Sharing algorithm. The encrypted evidentiary log data is also divided into multiple data blocks. Several key fragments and data blocks are randomly distributed to N mobile robot entities in a decentralized distributed ledger technology network. Each mobile robot entity only holds a few meaningless key fragments or encrypted data blocks. A single robot entity cannot reconstruct the original content from the fragments it holds.
[0086] The mathematical model of Shamir's Secret Sharing algorithm is defined as follows:
[0087]
[0088] Where S represents the log encryption key, i represents the node index currently being calculated, j represents the indexes of other nodes found, x represents the node ID of the current node, y represents the value of the key fragments held by the current node, and k represents the minimum number of shares required to recover the secret.
[0089] Only when key fragments and corresponding data blocks held by at least K different robot entities are collected can the complete encrypted content be reconstructed and decrypted using the reconstructed key. The decentralized distributed ledger network records each evidential physical event log along with its corresponding hash value, fragment allocation, and the custodian's identity. An attacker not only needs to successfully compromise a specific fixed notary node, but must also simultaneously locate and compromise more than K dynamically moving robot entities distributed throughout the warehouse to tamper with or destroy a complete evidential log evidence. This is virtually impossible in practice because the mobile robots are constantly moving, their positions and network topology dynamically change, and the attack difficulty increases exponentially.
[0090] Furthermore, a decentralized robot cluster intrusion prevention method further includes: audit nodes in the decentralized network can initiate audit requests for historical transactions signed by fixed notary nodes at any time; the audit nodes collect a sufficient number of fragments to reconstruct and decrypt the evidential physical event log; the audit nodes compare the reconstructed evidential log content with the signature of the fixed notary node and its contained hash value recorded in the original state log in the decentralized network; if the audit result shows that the evidential log content does not match the original application statement, the consensus protocol of the decentralized network automatically executes penalty measures.
[0091] Audit requests can be triggered automatically by the system or initiated by manual commands. Once an audit is triggered, the bot entity transmits the fragments it holds to the designated audit node. After collecting a sufficient number (K) of fragments, the audit node reconstructs and decrypts the evidential log. The reconstructed evidential log content is then compared with the signature of the fixed notary node recorded in the original decentralized network's state log and its contained hash value.
[0092] The final audit results will trigger a pre-set penalty mechanism. If the reconstructed evidential log content matches the original statement signed by the fixed notary node on the stateless log, the audit passes, and the trust level of the fixed notary node is increased. If the audit results show that the evidential log content does not match the original statement, it constitutes clear fraud. The decentralized network's consensus protocol will automatically execute the penalty measures: permanently revoke the fixed notary node's network trust, mark all its historical signatures as untrusted on the decentralized state ledger, and issue the highest level of security alert to the system administrator and all relevant bot entities.
[0093] Furthermore, a decentralized robot cluster intrusion prevention method also includes: a group of virtual attacker robots within the system continuously simulating attacks in a virtual network to find weaknesses in the current robot entity path planning scheme; and the robot entity self-optimizing its path strategy based on the results of the simulated attacks.
[0094] Virtual attacker bots are not physical entities, but intelligent software agents that exist in a simulated digital twin environment identical to the actual working environment. Each virtual attacker is driven by a deep reinforcement learning model. Unlike real bots that aim to maximize efficiency, virtual attackers have the opposite programming goal. Their reward function aims to: minimize the task efficiency of the group of executors, maximize path congestion and create deadlocks, induce potential collisions, and exploit system rule vulnerabilities to find weaknesses.
[0095] The virtual attacker robot simulates creating fake congestion at key traffic nodes, such as deliberately occupying charging stations and sending signals that the charging stations are charging to hinder other robot entities from charging. It observes how real robots respond, so that after being deceived, the robot entity will turn on its camera to check whether the charging station is actually charging the next time it receives a signal from the system that the charging station is charging.
[0096] A successful attack orchestrated by a virtual traitor serves as a negative reward signal, feeding back to the real robot swarm. This forces the real robot swarm to use these negative rewards as input for strategy optimization, continuously adjusting and evolving their collective path-playing strategies to evade attack patterns detected by the virtual traitor. This allows the swarm's strategy to dynamically adapt and defend against potential attack patterns. For example, when a virtual traitor simulates blocking a critical path, the swarm learns how to anticipate and avoid that path, or, if necessary, collaborate to create alternative paths. The disruptive advantage of generative adversarial swarm intelligence path-playing mechanism lies in the fact that the system no longer seeks a static optimal solution, but evolves a dynamic strategy that continuously improves itself and possesses predictive defense capabilities against potential attacks.
[0097] Furthermore, a decentralized robot swarm intrusion prevention system also includes:
[0098] The camera module employs an industrial-grade stereo camera module, such as two Sony IMX386 sensors with a 6mm focal length and a resolution of 1920x1080@60fps. It captures images and video streams of the robot's appearance, posture, motion trajectory, and the objects it is manipulating. This allows for accurate identification of the robot's model and identification code, and estimation of the robot's 3D pose. To verify the robot's location, the camera module captures unique and tamper-proof visual features of its physical environment, including localized ground textures, wall imperfections, and surface features of fixed structural components.
[0099] The density sensing module is used to continuously monitor the density of other mobile robot entities within a preset range around the robot entity. It achieves the monitoring of robot entity density in the surrounding environment through communication signal strength between robot entities and visual recognition.
[0100] The positioning module, used for cross-validation of the robot's declared location information, is a UWB module based on the Decawave DW1000 chipset, achieving a ranging accuracy of up to 10cm. The witness can accurately pinpoint the robot's declared location and cross-validate it with the GPS data reported by the declaring robot.
[0101] The radar module generates 3D point cloud data of the surrounding environment and the observed robot entity, measuring the robot entity's position, distance, and velocity. The core function of the radar module is to provide independent and accurate physical world observation data for a multi-party cross-validation mechanism, thereby verifying the authenticity of other robot state claims. When a robot entity updates its state, surrounding witness robot entities use their radar modules to independently measure the position, distance, and velocity of the claiming robot. The 3D point cloud data generated by the radar module can be matched with the geometric model provided by the requesting robot entity, verifying whether the requesting robot entity's position and distance are consistent with its submitted claim.
[0102] The radar module provides a verification dimension independent of GPS, camera, or UWB, greatly enhancing the system's ability to identify misinformation and defend against attacks.
[0103] An inertial measurement unit (IMU) provides attitude and motion information for a robot entity. It accurately measures the robot's angular velocity and acceleration, thereby calculating its attitude and trajectory data. In a multi-party cross-validation mechanism, when a robot entity updates its motion state, surrounding witness robots independently observe it using their own IMUs. The witnesses can compare their IMU data with the motion trajectory data reported by the requesting robot entity, thus providing additional physical evidence of the authenticity of its motion state.
[0104] Inertial measurement units (IMUs) are also used to establish instantaneous and secure communication authorization. When two robotic entities need to establish communication, they perform a pre-defined, synchronized cooperative action (e.g., a specific nodding or swaying motion). Each robotic entity records and exchanges motion data in real time using its own IMU. Only when the motion data of both parties are highly consistent in terms of time series and motion characteristics will the system confirm that they are in a state of physical proximity, approve the establishment of communication, and generate a temporary key, fundamentally preventing remote identity impersonation and hijacking attacks.
[0105] The Wi-Fi module is used to measure the signal strength indicators of multiple wireless access points within a preset range around the robot entity to generate a Wi-Fi fingerprint for subsequent location verification. The robot entity uses the onboard Wi-Fi module to actively or passively scan and detect at least three known wireless access points within its communication range. For each detected wireless access point, the Wi-Fi module measures its signal strength indicator value in real time. The measured signal strength indicator values are combined to generate a signal strength vector, which constitutes a type of Wi-Fi signal strength-based geographic location mapping data, i.e., a Wi-Fi fingerprint, according to this invention.
[0106] When a robot declares its physical location, it must simultaneously submit a Wi-Fi fingerprint of the current environment generated by the Wi-Fi module. The verifier will query a pre-built and stored historical environmental fingerprint database to perform a high-precision match between the submitted Wi-Fi fingerprint and the historical fingerprints of the declared location. Only when the two are highly consistent within a preset threshold is the location declaration confirmed as genuine and valid. This leverages the uniqueness and stability of Wi-Fi signal distribution in a specific physical space, making it extremely difficult for attackers to simultaneously forge a complex and comprehensive environmental fingerprint composed of signal strengths from multiple wireless access points that perfectly matches the false location, even if they can forge traditional GPS positioning signals. This effectively prevents location spoofing attacks.
[0107] A three-axis magnetometer module is a sensing unit used to sense the magnetic field characteristics of the surrounding environment. It collects the geomagnetic field strength and direction at the current physical location of the robot entity in real time to generate a unique and verifiable geomagnetic fingerprint. The robot entity is equipped with a high-precision three-axis magnetometer. When it is necessary to generate an environmental fingerprint, the three-axis magnetometer collects the geomagnetic field strength and direction specific to the current location, forming a vector data containing three orthogonal axis magnetic field components. The collected geomagnetic field strength and direction vector constitutes the geomagnetic fingerprint described in this invention.
[0108] When a robot reports its physical location, it must simultaneously submit a geomagnetic fingerprint generated by a three-axis magnetometry module. The system matches this fingerprint against a pre-built database of geomagnetic field characteristics of warehouse environments. Because materials such as steel bars in the building structure generate unique and consistent interference with the geomagnetic field, the geomagnetic fingerprint for each location is highly unique. Only when the submitted fingerprint is highly consistent with the historical fingerprints of the corresponding location in the database is its location claim further confirmed as authentic and reliable.
[0109] The triaxial magnetic module provides another perspective on the environmental feature fingerprint matching mechanism in the physical world state proof module of this invention, and is strongly bound to the physical space. It is also used to fuse multimodal data such as Wi-Fi fingerprints and visual fingerprints to provide a comprehensive spatial positioning evidence that is extremely difficult to forge.
[0110] In the description of this invention, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.
[0111] In the description of this specification, the terms "one embodiment," "some embodiments," "embodiment," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example that are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example.
[0112] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make modifications, alterations, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. A method for intrusion detection in a decentralized robot swarm, characterized in that, The method comprises the following steps: S1, a plurality of robot entities and sensing devices jointly constitute a decentralized network without a central server, and all devices in the network jointly record a unified state log for real-time updating of state information of all robots and devices in the network; S2, before communication between robot entities, one-time identity authentication is performed through a short-distance physical channel, and a temporary session key is generated; S3, when any robot entity needs to declare or update its own state, a state proof protocol is executed, and the state proof protocol integrates a multi-party cross verification mechanism and an environment feature fingerprint matching mechanism to verify the authenticity of the declared physical state of the robot entity; S4, when the number of other mobile robot entities within the preset range of the robot entity is less than the minimum number required for witnessing, the system switches to a hybrid witnessing mode; the robot entity initiates a state proof request to a fixed notary node within the communication range, and the fixed notary node completes the state proof according to a higher witnessing weight.
2. The method of claim 1, wherein: In the S2, the session key is closely bound to the physical relative position, posture and environment fingerprint of the two robot entities; When the robot entity exceeds the preset physical relative distance, or the relative posture changes significantly, or the preset time window expires, the session key and the related authorization are immediately invalidated.
3. The method of claim 1, wherein: In the S2, the short-distance physical channel is realized by the following method: the robot entities verify the physical proximity of each other by performing a preset, synchronized cooperative action, and real-time record and exchange action data between the robot entities, and only when the action data is highly consistent in time sequence and motion characteristics, the identity is confirmed and the communication is established.
4. The method of claim 1, wherein: In the S3, the multi-party cross verification mechanism includes that the robot entity declares to at least two witness robot entities or witness nodes adjacent in geographical position to initiate a verification request; The witness robot entities or witness nodes independently observe and verify the physical state declared by the robot entity by using the sensing device carried thereby; If the observation result is consistent with the declared physical state within a preset error range, the witness robot entity or witness node uses a private key to sign the verification result cryptographically, and reports the signature result together with an observation data digest to the decentralized network; the consensus protocol of the decentralized network requires that a preset number of valid independent signature parties are reached before the declared physical state is accepted as valid.
5. The method of claim 2, wherein: In the S3, the environment feature fingerprint matching mechanism includes that the robot entity collects unique features of the physical environment and generates an environment fingerprint; the environment fingerprint is submitted to the state log together with the declared physical state; The state log queries a stored historical environment fingerprint database to verify whether the currently submitted environment fingerprint is highly consistent with the historical fingerprint of the declared position.
6. The method of claim 1, wherein: In the S4, the fixed notary node independently observes and verifies the physical state of the robot entity subject to the request verification; The robot entity requesting verification needs to submit a data containing the environmental features of its location for comparison and secondary confirmation by the fixed notary node, so as to ensure the absolute accuracy of the verification result.
7. The method of claim 1, wherein: In the S4, the fixed notary node generates an encrypted, tamper-proof proof log when witnessing the state of the robot entity, and calculates an irreversible cryptographic verification code for the proof log. The verification code is forcibly embedded into the digital signature of the robot entity, and the digital signature is permanently bound with the verification code to prevent subsequent tampering.
8. The method of claim 1, wherein, Also includes: A set of virtual attacker robots are installed in the system, which continuously simulate attacks in the virtual network to find the weaknesses of the current robot entity path planning scheme; according to the results of the simulated attack, the robot entity optimizes the path strategy.
9. The method of claim 5, wherein: The environmental fingerprint is generated by at least one of the following methods: geographic location mapping data based on Wi-Fi signal strength indication, spatial distribution characteristics based on geomagnetic field strength, and high-resolution visual images based on local ground texture, wall flaws, and fixed structure surface features.
10. A decentralized robot swarm intrusion prevention system, characterized in that, Includes: Camera module for capturing visual features of the appearance, posture, motion trajectory of the robot entity and the environment; Density perception module, continuously monitoring the density of other moving robot entities within a predetermined range around the robot entity; Positioning module, cross-verify the position of the robot through high-precision ranging capability; Radar module for generating three-dimensional point cloud data of the surrounding environment and the observed robot entity, measuring the position, distance and speed of the robot, and providing additional motion state verification; Inertial measurement unit for providing attitude and motion information of the robot entity, and verifying physical proximity by comparing action data between robot entities; Wi-Fi module for measuring the signal strength of surrounding APs to generate Wi-Fi fingerprints for position verification; Three-axis magnetic force module for collecting the geomagnetic field strength and direction at the current robot entity position to generate geomagnetic fingerprints.
Citation Information
Cited By
Mine multi-network integration security communication scheduling method and system
CN122054146A