A method and system for time service security isolation based on Beidou
By constructing a signal fingerprint baseline database and a consistency verification mechanism, forged signals can be identified and isolated in real time, solving the problem of preventing deceptive electromagnetic attacks on the time synchronization system, ensuring the accuracy and reliability of the time scale, and improving the system's adaptive capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BAIYIN YINZHU ELECTRIC POWER GRP CO LTD
- Filing Date
- 2026-01-28
- Publication Date
- 2026-04-28
AI Technical Summary
Existing time synchronization systems are unable to effectively identify and prevent deceptive electromagnetic attacks, leading to incorrect time stamp injection and affecting the stability of time-sensitive systems.
By collecting time synchronization security input data, a site-level signal fingerprint baseline library is constructed. Consistency checks and cross-domain conflict constraints are integrated to generate anomaly scoring streams. A security isolation and timekeeping maintenance execution mechanism is constructed, and a dual-redundant timekeeping architecture and a security back-off process are built to achieve real-time monitoring and automatic handling of signals.
It improves the ability to identify counterfeit signals, enhances protection capabilities, ensures the accuracy and reliability of time stamps, reduces manual intervention, improves operation and maintenance efficiency, and enhances compatibility with existing time synchronization equipment.
Smart Images

Figure CN121603960B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of time synchronization security technology, specifically to a time synchronization security isolation and protection method and system based on BeiDou. Background Technology
[0002] With the development of BeiDou timing technology, especially the official deployment of BeiDou-3, the accuracy, reliability, and global coverage of the timing system have been significantly improved. However, existing technologies are ill-equipped to effectively identify and counter deceptive electromagnetic attacks. These attacks, disguised as normal signals, silently affect time synchronization, posing a serious security threat to time-sensitive systems.
[0003] For example, invention patent CN101741401B discloses a timing system and method for a wireless receiving device, including: a logic circuit for generating second pulses, a memory for storing sampled data, a baseband processing module for performing baseband signal processing on the sampled data to obtain the original observations, a time calculation module for obtaining the second pulse time difference based on the latching time of the original observations, and a delay-locked loop that filters the second pulse time difference and feeds it back to the logic circuit; wherein, the logic circuit corrects the generation time of subsequent second pulses based on the feedback. This invention integrates the observations of all channels, achieving higher accuracy compared to a single channel, and is unaffected by the tracking performance and quality of specific channel signals. In the case of multiple timing signal sources, the signal sources can be fused, reducing measurement errors and improving timing accuracy; autonomous integrity detection can also be performed, improving the security and reliability of the timing system.
[0004] For example, invention patent CN104734769B discloses a ground equipment system based on BeiDou satellite timing signals, including: a dispatch center equipment subsystem and multiple station equipment subsystems; the dispatch center equipment subsystem includes: a dispatch center BeiDou satellite timing instrument, which corrects and outputs a clock signal based on the BeiDou satellite timing signal; a central clock server, which receives the clock signal output by the dispatch center BeiDou satellite timing instrument through an NTP central LAN, generates a central clock signal, and outputs it; and multiple line communication front-end servers, all of which receive and output the central clock signal through an NTP central LAN; the station equipment subsystem includes: an autonomous machine, which receives the central clock signal output by the line communication front-end server of the line to which the station belongs through an NTP wide area network; and a CBI, which obtains the central clock signal from the autonomous machine through a serial bus. In this invention, the ground equipment can operate based on a safer and more reliable clock signal, which is beneficial to ensuring train operation safety.
[0005] In existing technologies, existing systems rely on power monitoring and satellite loss alarms to detect timing anomalies. However, existing systems are difficult to identify and prevent deceptive attacks that use spoofed signals to slowly deflect the signal, resulting in the silent injection of incorrect time scales and affecting the stability of the entire system. This is especially true in time-sensitive systems such as protection and control, fault recording, and synchronization phasors in substations or power plants, where the consequences are often difficult to trace and locate.
[0006] Therefore, in order to address the above issues, there is an urgent need for a timing security isolation and protection method and system based on BeiDou. Summary of the Invention
[0007] Technical problems to be solved
[0008] To address the shortcomings of existing technologies, this invention provides a BeiDou-based time synchronization security isolation and protection method and system, which solves the problem that traditional time synchronization systems cannot effectively prevent deceptive electromagnetic attacks.
[0009] Technical solution
[0010] To achieve the above objectives, this invention provides the following technical solution: a BeiDou-based time synchronization security isolation and protection method, comprising: S1, collecting a time synchronization security input dataset, performing time-slice segmentation and normalization processing to form a time synchronization security acquisition data frame, and constructing a station-level signal fingerprint baseline library; S2, performing consistency checks and cross-domain contradiction constraint fusion based on the station-level signal fingerprint baseline library, outputting a set of suspicious satellite channels, and triggering isolation events with dual threshold judgments to generate an anomaly scoring stream; S3, constructing a security isolation and timekeeping maintenance execution mechanism, and constructing a dual-redundant timekeeping architecture, synchronously outputting a credibility label sequence; S4, constructing a security back-switch process based on the credibility label sequence, and building a full-event link traceability and intelligent strategy automatic handling system.
[0011] Further, the specific process of collecting the timing security input dataset and performing time-slice segmentation and normalization to construct the timing security acquisition data frame is as follows: The timing security input dataset is collaboratively collected through the in-situ serial connection of the BeiDou timing security isolation and protection device. The timing security input dataset includes: satellite timing radio frequency input dataset, signal and noise floor dataset, receiver link status dataset, device operation status indication dataset, and channel identifier dataset; timing security preprocessing is performed on the timing security input dataset: interval pruning and abrupt change detection are performed on the input power estimate, and impulse interference is eliminated through sliding window peak detection and gating suppression; the timing security input dataset is time-aligned and encapsulated using unified time-slice scheduling, and linear normalization is performed to construct the timing security acquisition data frame; the timing security acquisition data frame is written into the global acquisition queue in chronological order and a local queue is established by channel, and the data that has been collected and stored is marked as historical operation data.
[0012] Furthermore, the specific process of constructing a site-level signal fingerprint baseline library is as follows: Input timing safety acquisition data frames and historical operation data; construct a signal fingerprint learning window using the device learning process; filter, extract features, and model baselines for timing safety acquisition data frames within the learning window to generate a site-level signal fingerprint baseline library; perform steady-state screening and sample purification on the timing safety acquisition data frames within the learning window: mark frames where alarm lights maintain normal semantics during the learning phase as steady-state frames as baseline samples; extract signal fingerprint feature vector sets from the steady-state frame set; construct a site-level signal fingerprint baseline library based on the signal fingerprint feature vector sets: calculate the median, quantile band, and MAD scale parameters for each type of feature using robust statistical methods, and form a threshold template; organize the baseline library into daytime baselines, nighttime baselines, and special operating condition baselines according to time periods, and write the baseline library version number, learning batch number, and effective time into the baseline index table; perform fingerprinting preprocessing and robust normalization on the timing safety acquisition data frames during the online operation phase, and output the fingerprint feature frame stream.
[0013] Furthermore, the specific process of performing consistency checks and cross-domain conflict constraint fusion based on the site-level signal fingerprint baseline database to output a set of suspicious satellite channels is as follows: Input the fingerprint feature frame stream, and perform consistency checks on the normalized fingerprint vectors, fingerprint distance components, and feature confidence scores of each BDS and GPS channel within each time slice. In the frequency domain consistency check, extract frequency-related feature subsets from the normalized fingerprint vectors and calculate the frequency domain violation degree to generate a frequency domain consistency score item. In the code domain consistency check, extract code phase continuity and related peak shape feature subsets and calculate the code domain violation degree to generate a code domain consistency score item. In the carrier domain consistency check, extract carrier phase noise and phase acceleration feature subsets and calculate the carrier domain violation degree to generate a carrier domain consistency score item. In the message domain consistency check, extract the arrival time sequence of the navigation message. The jitter and message consistency feature subsets are used to calculate the message domain violation degree, generating a message domain consistency score item. The product of the frequency domain consistency score item and the frequency domain weight coefficient, the product of the code domain consistency score item and the code domain weight coefficient, the product of the carrier domain consistency score item and the carrier domain weight coefficient, and the product of the message domain consistency score item and the message domain weight coefficient are added to obtain a comprehensive item. The cross-domain contradiction constraint value is multiplied by the comprehensive item to obtain a comprehensive anomaly score value. The comprehensive anomaly score value is compared with the anomaly threshold in real time. When the comprehensive anomaly score value is greater than the anomaly threshold, it is determined to be an abnormal signal, triggering signal isolation or protection measures. When the comprehensive anomaly score value is less than or equal to the anomaly threshold, it is determined to be a normal signal, and the normal timing signal processing continues without intervention. The suspicious satellite channel set, comprehensive anomaly score sequence, and domain-level score item sequence are output.
[0014] Furthermore, the specific process of triggering isolation events with dual threshold judgment and generating anomaly score streams is as follows: Input the comprehensive anomaly score sequence, domain-level score item sequence, and fingerprint feature frame stream; construct the trend judgment quantity and time deviation proxy quantity; and use dual thresholds and persistence thresholds for drift identification: when the comprehensive anomaly score value is greater than or equal to the lower threshold, and the rate of change of the comprehensive anomaly score value is continuously positive within the window period, or the time deviation accumulates monotonically and exceeds the upper threshold of the drift warning, it is judged as a suspicious slow drift, triggering a soft isolation event; when the comprehensive anomaly score value is greater than or equal to the upper threshold, and the cross-domain contradiction constraint is continuously satisfied, or the time deviation accumulates within the window period and exceeds the upper limit of drift confirmation, it is judged as a deceptive confirmation, triggering a hard isolation event; and output the progressive drift identification result and the isolation event to form an event link evidence package, wherein the isolation event includes triggering a soft isolation event and triggering a hard isolation event.
[0015] Furthermore, the specific process of constructing a security isolation and time-keeping maintenance execution mechanism is as follows: constructing an isolation event linkage decision logic, executing differentiated isolation operations, and simultaneously completing security signal standard adaptation and operational status visualization feedback: receiving isolation events, trigger reason codes, and suspicious satellite channel identifiers, combining them with the received link status dataset to form the basis for isolation decisions, and executing the construction of a security hierarchical isolation and time-keeping maintenance execution mechanism; adopting a multi-lamp collaborative feedback mechanism with semantics consistent with the device operational status indication dataset to clarify the triggering conditions, lamp status definitions, data upload requirements, and status switching rules for each operational status.
[0016] Furthermore, the specific process of constructing a dual-redundant timekeeping architecture and synchronously outputting the credibility label sequence is as follows: A dual-redundant architecture of atomic clock and oven-controlled crystal oscillator is adopted. The timekeeping clock is calibrated using satellite signals combined with a site-level signal fingerprint baseline library, and drift characteristic parameters are recorded. Timekeeping activation conditions include: satellite signal interruption after triggering a hard isolation event, or time deviation proxy quantity continuously exceeding the warning upper limit threshold and without signal markers after triggering a soft isolation event. The future drift quantity is predicted using an LSTM model, and combined with the drift deviation threshold of the segmented baseline, a dynamic compensation quantity is generated to correct the oven-controlled crystal oscillator output signal: the time deviation proxy quantity is divided by the gating coefficient threshold, and the ratio is substituted into the hyperbolic tangent function to obtain the deviation gating adjustment term; the future time drift upper limit is divided by the scale parameter, and the ratio is... Substituting the hyperbolic tangent function yields the drift amplitude control term. The sign of the time deviation proxy is used as the direction determination term. The maximum unidirectional compensation amplitude is multiplied sequentially by the aforementioned deviation gating adjustment term, drift amplitude control term, and direction determination term to obtain the dynamic compensation amount. A reliability label corresponding one-to-one with the time synchronization result is synchronously output through the management port and extended fields. When the reliability level is level three, cross-site time fusion is prohibited; when the reliability level is level two, participation in cross-site time fusion is restricted; providing time observations is allowed, and participation in cross-site time fusion is permitted when the reliability level is level one. Simultaneously, the isolation log, timekeeping compensation record, and reliability label sequence are written to the historical operation database, and the reliability label sequence and the historical operation database are output.
[0017] Furthermore, the specific process of constructing a secure back-cut process based on the credibility tag sequence is as follows: The credibility tag sequence is accessed, and the site-level signal fingerprint baseline library and comprehensive anomaly scoring sequence are simultaneously invoked to construct a secure back-cut process. Through Slew rate limiting and hysteresis control, secondary disturbances to the downstream caused by timescale step jumps are avoided. The process requires both conditions to be met simultaneously: the comprehensive anomaly score value must be below the back-cut threshold, and the window relearning fingerprint consistency verification must be passed; neither condition can be omitted. A combined strategy of Slew rate limiting for smooth back-cutting and hysteresis control for jitter prevention is adopted to prohibit timescale step jumps. The stability of the downstream timescale, which is sensitive to time, is ensured throughout the process, completely avoiding the risk of secondary damage during recovery. After the back-cut is completed, the system automatically switches to normal operation mode and simultaneously uploads the back-cut completion signal and back-cut process data to the control center.
[0018] Furthermore, the specific process of building a full-event chain traceability and intelligent policy automatic handling system is as follows: Constructing a full-event chain traceability and intelligent policy automatic handling system to form an irrefutable audit record for the entire time-sensorship security process; integrating all data to form a full-process audit record chain, with the recorded content encrypted with timestamps and stored with dual backups on both local and cloud platforms; building a hierarchical automatic handling strategy based on a rule engine, monitoring the entire process operation data in real time, and automatically executing the corresponding contingency plan when a rule is triggered; obtaining integrated feature terms through tensor operations using spatial feature matrices, environmental feature vectors, and historical event feature vectors; and combining the spatiotemporal coupling tensor with the integrated feature terms. Tensor operations are performed to obtain correlation terms; correlation terms are processed through fusion calculation to obtain evaluation sub-terms; status terms are obtained by performing moving average calculations using the back-cut success rate time series and the device covariance matrix; evaluation sub-terms and status terms are substituted into the hyperbolic tangent normalized fusion function to obtain the strategy evaluation value; after each automatic triggering and execution of the strategy, the strategy evaluation value before and after the action is automatically recorded, and the strategy improvement rate is calculated. Based on the improvement rate and the strategy evaluation value, the strategy execution effect is automatically classified and rated; all actions are recorded throughout, forming a closed-loop traceability link, and outputting a safe back-cut status signal and a set of operation and maintenance audit records.
[0019] Furthermore, a second aspect of the present invention provides a BeiDou-based time synchronization security isolation and protection system, applied to a BeiDou-based time synchronization security isolation and protection method, comprising: a satellite time synchronization signal acquisition module, used to acquire a time synchronization security input dataset, and perform time-slice segmentation and normalization processing to form a time synchronization security acquisition data frame, and construct a station-level signal fingerprint baseline library; a consistency verification module, used to perform consistency verification and cross-domain contradiction constraint fusion based on the station-level signal fingerprint baseline library, output a set of suspicious satellite channels, and perform dual-threshold judgment to trigger isolation events, generating an anomaly scoring stream; a security isolation and time synchronization maintenance module, used to construct a security isolation and time synchronization maintenance execution mechanism, and construct a dual-redundant time synchronization architecture, synchronously outputting a credibility label sequence; and a security back-off and operation and maintenance audit module, used to construct a security back-off process based on the credibility label sequence, and build a full event link traceability and intelligent strategy automatic handling system.
[0020] Beneficial effects
[0021] The present invention has the following beneficial effects:
[0022] (1) This invention improves the ability of the timing system to identify forged signals by introducing a signal fingerprint learning mechanism. By monitoring and analyzing the characteristic changes of satellite signals in real time, it can quickly identify and isolate signals that deviate from the normal pattern, thus avoiding the impact of deceptive electromagnetic attacks on the system's time scale. It also enhances the protection against various signal anomalies.
[0023] (2) This invention improves the protection capability of the time synchronization system against slow drift attacks by gradually identifying drift. It can monitor changes in the time scale in real time and promptly identify any abnormal synchronization deviations, avoiding the accumulation of time scale errors and ensuring accuracy and reliability. It also enhances compatibility with existing time synchronization equipment.
[0024] (3) This invention provides a long-term stability reference for signal characteristics by constructing a site-level signal fingerprint baseline library. This baseline library can accumulate and update historical data on the signal characteristics of each site, ensuring a rapid response based on signal change trends and improving the accuracy of protection. It avoids immediate relocking that could cause timescale jumps, ensuring a smooth and interference-free recovery process.
[0025] (4) This invention achieves automated response to timing signal anomalies through strategy orchestration and automatic handling mechanisms. It can automatically execute preset measures such as isolation, back-switching, or switching to backup signal sources when an anomaly is detected, reducing the need for manual intervention, improving operation and maintenance efficiency, and enhancing the system's adaptability.
[0026] Of course, any product implementing this invention does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description
[0027] Figure 1 This is a flowchart of a BeiDou-based time synchronization security isolation and protection method according to the present invention.
[0028] Figure 2 This is a structural diagram of a BeiDou-based time synchronization security isolation and protection system according to the present invention.
[0029] Figure 3 This is a time-series variation diagram of the core features of the signal fingerprint within the learning window of this invention;
[0030] Figure 4 This is a graph showing the combined abnormal score changes and dual threshold decision results of this invention. Detailed Implementation
[0031] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0032] Please see Figures 1-4This invention provides a technical solution: a BeiDou-based time synchronization security isolation and protection method, comprising: S1, collecting a time synchronization security input dataset, performing time-slice segmentation and normalization processing to form a time synchronization security acquisition data frame, and constructing a station-level signal fingerprint baseline library; S2, performing consistency verification and cross-domain contradiction constraint fusion based on the station-level signal fingerprint baseline library, outputting a set of suspicious satellite channels, and triggering isolation events with dual threshold judgments to generate an anomaly scoring stream; S3, constructing a security isolation and timekeeping maintenance execution mechanism, and constructing a dual-redundant timekeeping architecture, synchronously outputting a credibility label sequence; S4, constructing a security back-switch process based on the credibility label sequence, and building a full-event link traceability and intelligent strategy automatic handling system.
[0033] Specifically, the process of collecting the timing security input dataset and performing time-slicing and normalization to form a timing security acquisition data frame is as follows: The timing security input dataset is collaboratively collected via in-situ serial connection of the BeiDou timing security isolation and protection device. This dataset includes: satellite timing radio frequency input dataset, signal and noise floor dataset, receiver link status dataset, device operation status indication dataset, and channel identifier dataset. The satellite timing radio frequency input dataset includes: BDS and GPS navigation timing radio frequency signal streams from the satellite receiving antenna, obtained by connecting the device antenna to the TNC interface to receive satellite signals and introducing them into the acquisition channel. The device input supports BDS and GPS and acts as a protective front end located between the satellite navigation signal and the timing system. The signal and noise floor dataset includes: input signal power estimate, noise floor level, AGC operating point, and power mutation markers, obtained by performing power window detection and noise floor analysis on the input radio frequency link. The estimated input signal power range can be referenced to the device's operating range of -90dBm to -125dBm for initial anomaly screening. The receiver link status dataset includes: antenna feed status, RF cable connection tightness status markers, and signal and obstruction suspected markers. These are generated through interface electrical status detection, connection status self-test, and no-signal statistical rules to distinguish between link fault-type and attack-type anomaly contexts. The device operation status indication dataset includes: status codes and durations of power lights, status lights, learning lights, alarm lights, and protection lights. These are obtained by reading the semantics of the device panel indicator lights and forming a state machine sequence. The learning, alarm, and protection lights respectively reflect the learning process, signal quality anomalies, and safe signal output status. The channel identifier dataset includes: acquisition time slice start time, time slice number, input channel identifier, and acquisition batch number. These are identifier fields added to each record by the device during internal unified time slice scheduling for unified sorting and traceability.
[0034] The timing security input dataset undergoes timing security preprocessing: interval pruning and abrupt change detection are performed on the input power estimate; when the power exceeds the safety window or the noise floor suddenly increases, a suspected interference marker is generated; pulse-type interference is eliminated through sliding window peak detection and gating suppression; transient spikes are avoided from contaminating the learning statistics; priority labeling is applied to the "loose connection, obstruction, no signal" conditions in the received link status dataset to form link-type anomaly cause codes, providing a basis for differentiation in isolation strategies; state machine encoding is performed on the device operation status indication dataset, and stage division and time period slice management are carried out based on the working semantics of entering learning after startup, locking after successful learning, and entering alarm and safety output when interference and anomalies are detected.
[0035] A unified time-slice scheduling method is used to time-align and encapsulate the time-safe input dataset, followed by linear normalization to construct a time-safe acquisition data frame. This data frame includes at least: frame number, acquisition time-slice start time, BDS and GPS input channel identifiers, input power estimate, noise floor level, AGC operating point, power mutation marker, no signal and obstruction marker, link cause code, learning status code, alarm status code, protection status code, and a quality marker field. The quality marker field records four basic quality conclusions: suspected interference, suspected no signal, suspected link fault, and normal. The input power estimate, AGC operating point, and noise floor level are normalized using a linear normalization method, mapping data from different devices and signal sources to a unified standard range. This eliminates data bias caused by device and signal strength differences, ensuring consistency and comparability in the analysis.
[0036] Time-synchronized security data frames are written to a global acquisition queue in chronological order and local queues are established by channel. In queue management, key frames within the learning window and before and after alarm triggering are prioritized to ensure complete reproducibility of fingerprint learning and post-event auditing. These time-synchronized security data frames serve as standardized input for signal fingerprint learning and multi-domain consistency verification. Completed and stored data is marked as historical operational data, which includes: device operation history, alarm and protection event records, device operating status information, historical acquisition sequences, and historical baseline parameter versions.
[0037] This implementation plan significantly reduces the risk of transient spikes and link failures contaminating fingerprint learning and improves the accuracy of abnormal context identification. It ensures that fingerprint baseline construction, abnormal trigger evidence, and subsequent handling processes can be fully reproduced and audited, thereby providing a stable and consistent input basis for signal fingerprint baseline modeling, multi-domain consistency verification, dual-threshold decision-making, and isolation or time-keeping maintenance actions, and improving the availability and reliability of project implementation.
[0038] Specifically, the process of constructing a site-level signal fingerprint baseline library is as follows: input timing security acquisition data frames and historical operation data, construct a signal fingerprint learning window using the device learning process, filter, extract features and model baselines for timing security acquisition data frames within the learning window to generate a site-level signal fingerprint baseline library; the learning window is the time period from when the device starts learning until it successfully locks. The learning process is continuous and enters a stable working state after successful learning. The learning lock semantics are determined by the device learning light status and operation instructions.
[0039] Steady-state screening and sample purification are performed on the timing security acquisition data frames within the learning window: frames exhibiting "sudden changes in input power, sudden increases in noise floor, suspected absence of signal and obstruction, and suspected link failure" are marked as non-steady-state frames and their weights are reduced or they are removed; frames where the alarm lights maintain normal semantics during the learning phase are marked as steady-state frames and used as baseline samples; a signal fingerprint feature vector set is extracted from the steady-state frame set; the signal fingerprint feature vector set includes at least: morphological statistics of C and N0 distribution for each satellite, statistics of Doppler and rate of change, characterization of code phase continuity, characterization of correlation peak morphology, characterization of carrier phase noise and phase acceleration, characterization of navigation message arrival timing jitter, and statistics of AGC operating point distribution and noise floor; among them, C and N0, Doppler, code and carrier consistency, and message timing jitter are used to characterize deceptive anomalies where power spoofing is not possible due to the incompatibility of phase and timing.
[0040] A site-level signal fingerprint baseline library is constructed based on the signal fingerprint feature vector set. For each type of feature, the median, quantile band, and MAD scale parameters are calculated using robust statistical methods, and a threshold template is formed. The baseline library is segmented into daytime baselines, nighttime baselines, and special operating condition baselines according to time periods. The segmented baseline switching criteria are as follows: the time period is jointly determined by the site's local time and the context of illumination and load. The sunrise and sunset timetables and fixed buffer windows are used to divide the daytime and nighttime segments. The effective interval of the daytime baseline is [after sunrise and before sunset], and the effective interval of the nighttime baseline is [after sunset and before sunrise the next day]. When the drift amplitude of key features obtained from historical operating data (such as the width of the quantile band of message timing jitter, phase noise MAD, and median distance of the correlation peak shape) simultaneously meets one of the statistical drift ranges of the daytime segment or the statistical drift range of the nighttime segment within K consecutive time slices, the corresponding segmented baseline is confirmed as the current candidate effective segment. If both segments meet the criteria, the segment with the smaller overall fingerprint distance component is selected as the effective segment to avoid accidental switching at boundary times. The special operating condition baseline switching criteria are as follows: when the special operating condition cause code "suspected obstruction, suspected no signal, abnormal drift of AGC working point, continuous rise of noise floor, strong interference operation in the station" appears in the received link status dataset or device operation status indication dataset, the special operating condition baseline is entered; when the cause code no longer appears in K consecutive time slices and the fingerprint distance falls back to within the normal threshold, the special operating condition baseline is exited and the daytime and nighttime baselines are restored.
[0041] By statistically analyzing the feature drift range of different time periods in historical operational data and adaptively updating the segment boundaries, the problem of difficulty in setting thresholds due to natural fluctuations at the same site is solved; and the baseline library version number, learning batch number, and effective time are written into the baseline index table to achieve baseline traceability and rollback. The version and batch activation logic is as follows: the baseline library uses "site identifier, segment type and version number" as the version key, and the learning batch number is used to identify the training source and sample window within the same version; after a new batch is completed, it first enters the candidate state, which is only used for parallel evaluation and does not directly replace the current effective baseline; the candidate state evaluation uses the online fingerprint feature frames of the most recent M time slices for comparison, calculates the fingerprint distance distribution and false alarm rate index under the candidate baseline, and when the candidate baseline meets the following conditions in a continuous period: the false alarm rate is less than or equal to the false alarm rate threshold, the anomaly detection retention rate is greater than or equal to the retention rate threshold, and the width of the key feature quantile band does not expand beyond the width threshold, it is switched to the effective state and the effective time is written; the false alarm rate threshold is obtained by statistical calibration of the sample of historical operation data at the station, the retention rate threshold is obtained by the replay evaluation of confirmed anomalies, and the width threshold is obtained by the upper bound of the natural fluctuation of the quantile band width of the learning window sample. If the evaluation fails, it is marked as a rejection state and the reason code and evaluation summary are retained. The effective switching adopts a dual-write and rollback mechanism: within the first period after the switch, the new effective baseline score and the old baseline score are output simultaneously for audit comparison. If K consecutive time-slices of new baselines cause false alarms or abnormally amplified fingerprint distance, the system will automatically roll back to the previous effective version and mark this batch as rollback state.
[0042] Fingerprinting preprocessing and robust normalization are performed on the timing security acquisition data frames during the online operation phase, outputting a fingerprint feature frame stream. The online feature vectors are robustly normalized and mapped to a dimensionless space according to the corresponding segmented baselines to generate normalized fingerprint vectors; missing features are marked with masks and feature confidence scores are given to avoid misuse of reliable features in no-signal scenarios; key features (such as message timing jitter, phase noise, and correlation peak morphology) are smoothed using a sliding window while retaining the original values for auditing.
[0043] Construct and output signal fingerprint feature frames: Signal fingerprint feature frames include at least: frame number, time slice time, channel identifier, normalized fingerprint vector, fingerprint baseline version number, fingerprint distance component, feature confidence score, and contextual labels obtained by mapping alarm, protection and learning states; wherein the contextual labels are used to identify the current state of learning, normal, alarm or security signal output and maintenance, so as to link with the "progressive bias recognition, confidence-driven output and security back-switch" strategy.
[0044] like Figure 3The time-series variation graph of the core features of the signal fingerprint within the learning window shows the fluctuations of different signal features during the learning process. The blue curve represents the high-frequency noise feature, showing significant fluctuations during the learning process, indicating that the high-frequency noise feature changes significantly over different time periods, possibly due to signal quality fluctuations or external interference. The green dashed line represents the Doppler frequency shift feature, mainly used to describe changes in signal frequency. As the learning time progresses, the Doppler frequency shift feature fluctuates, possibly indicating a frequency shift in the signal, affecting system stability. The red curve represents the signal phase fluctuation feature, reflecting fluctuations in signal time synchronization. As the learning time increases, the signal phase fluctuation may increase, affecting the synchronization accuracy and overall stability of the system. The black dashed line represents the signal amplitude variation feature, reflecting changes in signal strength. Amplitude fluctuations may be affected by environmental changes, equipment failures, or interference, thus affecting signal quality and system stability. The yellow shaded area in the graph may indicate a specific time period during the learning process, during which the signal features change drastically, possibly indicating a severe anomaly or interference during that period, requiring appropriate isolation or adjustment measures. Overall, the temporal changes in signal fingerprint features reveal the signal stability and quality fluctuations during the learning process. By monitoring these feature changes, anomalies can be identified in a timely manner, the learning process can be optimized, and strategies can be dynamically adjusted to ensure signal quality and operational stability.
[0045] In this implementation scheme, through the above-mentioned learning modeling and fingerprinting preprocessing, the input satellite signal is transformed from a "trusted direct connection" into a "quantifiable, comparable, and traceable" fingerprint data stream, providing a site-level baseline for identifying deceptive slow drift and providing interpretable triggering conditions for isolation and maintenance actions.
[0046] Specifically, the process of performing consistency checks and cross-domain contradiction constraint fusion based on the site-level signal fingerprint baseline library to output a set of suspicious satellite channels is as follows: Input fingerprint feature frame stream, perform consistency checks on the normalized fingerprint vector, fingerprint distance component and feature confidence score of each BDS and GPS channel in each time slice. In the frequency domain consistency check, extract the frequency domain-related feature subset from the normalized fingerprint vector and calculate the frequency domain violation degree to generate a frequency domain consistency score item. The frequency domain feature subset includes at least: Doppler and rate of change representation, noise floor rise representation, and AGC operating point drift representation. The frequency domain violation degree is composed of the weighted sum of "Doppler residual", "noise floor rise residual" and "AGC drift residual", and the weight is adaptively adjusted by the feature confidence score to automatically reduce the contribution of the frequency domain item to the total score in the context of occlusion and no signal. In the code domain consistency test, a subset of code phase continuity and related peak shape features is extracted and the code domain violation degree is calculated to generate a code domain consistency score item. The code domain feature subset includes at least: code phase continuity representation quantity and related peak shape representation quantity. The code domain violation degree is jointly constructed by "outlier rate of code phase differential jitter" and "related peak shape distance" to capture abnormal clues that are difficult to completely simulate the related peak shape under power camouflage conditions.
[0047] In carrier domain consistency testing, a subset of carrier phase noise and phase acceleration features is extracted and the carrier domain violation is calculated to generate a carrier domain consistency score. The carrier domain feature subset includes at least: carrier phase noise characterization, phase acceleration characterization, and code-carrier consistency residual. The carrier domain violation is used to characterize the deception feature of "maintaining lock but phase evolution not conforming to physical constraints," and improves the judgment sensitivity when deviations continue to accumulate after learning lock. In message domain consistency testing, a subset of navigation message arrival timing jitter and message consistency features is extracted and the message domain violation is calculated to generate a message domain consistency score. The message domain feature subset includes at least: message arrival timing jitter characterization and subframe boundary consistency characterization. The message domain violation is used to characterize the abnormal clue of "when a pseudo-signal drags the time parameter or code phase, the message boundary and timing jitter show an irreconcilable contradiction."
[0048] The comprehensive term is obtained by adding the products of the frequency domain consistency score and the frequency domain weight coefficient, the code domain consistency score and the code domain weight coefficient, the carrier domain consistency score and the carrier domain weight coefficient, and the message domain consistency score and the message domain weight coefficient. The comprehensive anomaly score is obtained by multiplying the cross-domain contradiction constraint value by the comprehensive term. The specific calculation formula for the comprehensive anomaly score is as follows:
[0049] ;
[0050] In the formula, This represents the comprehensive anomaly score, used to comprehensively assess the degree of anomaly in the signal; This represents the frequency domain weighting coefficient, which is obtained through statistical analysis of the contribution of frequency domain anomaly scores in historical operating data. The value ranges from 0 to 1 and is used to adjust the degree of influence of the frequency domain consistency test results on the comprehensive anomaly score. The frequency domain consistency score is obtained by analyzing the signal's spectrum and calculating the Doppler frequency shift, bandwidth matching, and noise floor characteristics. It is used to reflect whether the frequency domain conforms to the standards of a normal GNSS signal. This represents the code domain weight coefficient, which is obtained through statistical analysis of the contribution of code domain anomaly scores in historical operating data. The value ranges from 0 to 1 and is used to adjust the degree of influence of code domain consistency test results on the comprehensive anomaly score. The code domain consistency score is calculated by analyzing the continuity of the code phase and the shape of the correlation peak, and is used to reflect whether the code domain conforms to the standard of normal GNSS signals. This represents the carrier domain weighting coefficient, which is obtained through statistical analysis of the contribution of carrier domain anomaly scores in historical operating data. The value ranges from 0 to 1 and is used to adjust the degree of influence of carrier domain consistency test results on the comprehensive anomaly score. The carrier domain consistency score is obtained by analyzing carrier phase noise and phase acceleration characteristics, and is used to reflect whether the carrier domain conforms to the standard of normal GNSS signals. The weight coefficient of the message domain is obtained through statistical analysis of the contribution of message domain anomaly scores in historical operation data. The value ranges from 0 to 1 and is used to adjust the degree of influence of the message domain consistency test results on the comprehensive anomaly score. The message domain consistency score is obtained by analyzing the timing structure, bit flipping, and subframe boundary consistency characteristics of navigation messages. It is used to reflect whether the message domain conforms to the standards of normal GNSS signals. This represents the cross-domain conflict constraint value, which is obtained by detecting inconsistencies in features across multiple domains and is used to penalize signals that are inconsistent across multiple domains.
[0051] The system compares the comprehensive anomaly score with the anomaly threshold in real time. The anomaly threshold is obtained through statistical calibration and segmented adaptive analysis of historical operational data. When the comprehensive anomaly score exceeds the anomaly threshold, it is determined to be an anomaly signal, triggering signal isolation or protection measures, such as switching to a backup signal source or outputting a safety signal to maintain stability, and notifying the administrator for further inspection and handling. When the comprehensive anomaly score is less than or equal to the anomaly threshold, it is determined to be a normal signal, and routine timing signal processing continues without intervention, maintaining the current signal source, and without any isolation or protection measures. It also outputs a set of suspicious satellite channels, a sequence of comprehensive anomaly scores, and a sequence of domain-level scoring items. The output set of suspicious satellite channels includes at least: a list of channel identifiers, Top-K anomaly domain labels, domain-level scoring items, and a comprehensive score and evidence summary field (the evidence summary field records the key feature names that led to the increased score and their deviation, facilitating auditing and maintenance location).
[0052] Table 1, as shown in the multi-domain consistency scoring table, records the results of the multi-domain consistency test of the BDS-B1 and GPS-L1 channel signals by the BeiDou timing security isolation and protection system over six consecutive time slices:
[0053] For time slot SLOT-001 corresponding to BDS-B1 channel: frequency domain consistency score 0.12, code domain consistency score 0.08, carrier domain consistency score 0.10, message domain consistency score 0.09, cross-domain conflict constraint value 1.0, overall anomaly score 0.10, anomaly marked as "none", indicating the signal for this time slot is normal. For time slot SLOT-002 corresponding to BDS-B1 channel: frequency domain consistency score 0.15, code domain consistency score 0.11, carrier domain consistency score 0.12, message domain consistency score 0.10, cross-domain conflict constraint value 1.0, overall anomaly score 0.12, anomaly marked as "none", indicating the signal remains normal. For the GPS-L1 channel corresponding to time slice SLOT-003: frequency domain consistency score 0.18, code domain consistency score 0.13, carrier domain consistency score 0.14, message domain consistency score 0.12, cross-domain conflict constraint value 1.0, no cross-domain inconsistency phenomenon; comprehensive anomaly score value 0.14, anomaly marked as "none", GPS-L1 channel signal is normal.
[0054] Time slot SLOT-004, corresponding to the BDS-B1 channel: Frequency domain consistency score 0.45, code domain consistency score 0.38, carrier domain consistency score 0.42, message domain consistency score 0.39, cross-domain conflict constraint value 1.2, overall anomaly score 0.41, anomaly marked as "yes", indicating an anomaly in this time slot signal, requiring vigilance against the risk of slow drift. Time slot SLOT-005, corresponding to the GPS-L1 channel: Frequency domain consistency score 0.52, code domain consistency score 0.46, carrier domain consistency score 0.49, message domain consistency score 0.45, cross-domain conflict constraint value 1.3, overall anomaly score 0.48, anomaly marked as "yes", indicating a clear anomaly in the GPS-L1 channel signal, suspected to be a precursor to a deception attack. For time slot SLOT-006, corresponding to the BDS-B1 channel: frequency domain consistency score 0.78, code domain consistency score 0.72, carrier domain consistency score 0.75, message domain consistency score 0.71, cross-domain conflict constraint value 1.5, comprehensive anomaly score 0.74, anomaly marked as "severe", indicating that the BDS-B1 channel of this time slot has suffered a clear spoofing attack and a hard isolation event must be triggered immediately.
[0055] Table 1 Multidomain Consistency Scoring Table
[0056]
[0057] like Figure 4 The graph showing the changes in the overall anomaly score and the results of the dual-threshold decision reveals trends in the overall anomaly score (red line) and time deviation proxy (blue line) over time, indicating anomalies in time synchronization and signal stability. Soft isolation events are typically used for adjustments in cases of minor anomalies, while hard isolation events are used for more severe anomalies, potentially including emergency operations such as switching signal sources or stopping system operation. The increase in the overall anomaly score and the increase in time deviation proxy show a positive correlation, indicating that time synchronization error may be a key factor in anomalies; as the time synchronization error increases, the anomaly score also increases. In the graph, the dual-threshold decision mechanism helps the system take appropriate measures based on the severity of the anomaly. When the overall anomaly score reaches the upper threshold, a hard isolation event is automatically triggered to prevent the anomaly from escalating. Between the lower and upper thresholds, a soft isolation event may be triggered for continuous monitoring and adjustment. Overall, the graph effectively demonstrates how the dual-threshold mechanism categorizes anomalies, ensuring timely response and appropriate measures to stabilize operation when problems occur.
[0058] This implementation plan enables tiered triggering of soft and hard isolation events, which can suppress the spread of risks by limiting the rate, reducing the weight, and freezing the event in the early stage of deviation, and can also quickly cut off and switch events in the confirmation stage to prevent the time stamp from being continuously dragged. This significantly improves the ability to detect slow deviations and deceptive attacks in a timely manner, the certainty of handling them, and the maintainability of the project.
[0059] Specifically, the process of triggering isolation events with dual threshold decisions and generating anomaly score streams is as follows: Input the comprehensive anomaly score sequence, domain-level score item sequence, and fingerprint feature frame stream; construct trend decision quantity and time deviation proxy quantity; and use dual thresholds and persistence thresholds for drag identification. The trend decision quantity includes at least the exponentially weighted moving average of the comprehensive anomaly score value and the score slope. The time deviation proxy quantity is obtained by jointly mapping the message timing jitter, code phase continuity residual, and carrier phase evolution residual. This is used to transform multi-domain anomalies into a more direct time drift representation of timing risks and to identify silent injection processes that are still locked and synchronized but whose time stamps are dragged.
[0060] When the comprehensive anomaly score is greater than or equal to the lower threshold, and the rate of change of the comprehensive anomaly score remains positive within the window period, or the time deviation accumulates monotonically and exceeds the upper threshold of the drift warning, it is determined to be a suspicious slow drift, triggering a soft isolation event. The soft isolation event carries a set of protection parameters for the downstream time synchronization link, including: the upper limit of the time adjustment rate, the correction gain freeze flag, and the downweight usage flag of the suspicious satellite channel, which are used to limit the spread of the dragged-off effect without breaking the link. When the comprehensive anomaly score is greater than or equal to the upper threshold, and the cross-domain contradiction constraint is continuously satisfied, or the time deviation accumulates to exceed the upper limit of drift confirmation within the window period, it is determined to be a deceptive confirmation, triggering a hard isolation event. The progressive drag-off identification result is output and the isolation event forms an event link evidence package. The isolation event includes triggering a soft isolation event and triggering a hard isolation event. The event link evidence package includes: trigger markers for soft and hard isolation events, trigger cause codes (frequency domain dominant, code domain dominant, carrier dominant, message dominant, or cross-domain contradiction dominant), trigger window numbers, current confidence levels, and auditable evidence summaries (Top-K anomaly features and their deviations, and indexes of key domain score curve segments). The lower bound threshold is determined by the comprehensive anomaly score distribution of trusted context time slices in historical operational data; the upper bound threshold is determined by the lower bound of the scores of confirmed anomaly samples in historical operational data; the drift confirmation upper bound threshold is derived by inversely calculating the acceptable risk upper limit and downstream time tolerance; and the drift warning upper bound threshold is obtained by statistically analyzing the natural cumulative upper bound of the time deviation proxy quantity during the trusted time synchronization phase.
[0061] In this implementation plan, each judgment is supported by interpretable, traceable, and verifiable evidence, avoiding mishandling or omissions due to single-point alarms. This improves the detection capability and handling certainty of scenarios where the time stamp is silently dragged even though the time is still locked and the time is correct. It also provides standardized input and closed-loop support for isolated execution, on-time maintenance, and audit accountability.
[0062] Specifically, the process of constructing a security isolation and time-keeping maintenance mechanism is as follows: Constructing a linkage decision logic for isolation events, executing differentiated isolation operations, and simultaneously completing security signal standard adaptation and operational status visualization feedback: Receiving isolation events, trigger cause codes, and suspicious satellite channel identifiers, combining them with the received link status dataset to form the basis for isolation decisions, and executing the construction of a security-graded isolation and time-keeping maintenance mechanism; When a hard isolation event is received, immediately cutting off the radio frequency input of the suspicious satellite channel and initiating dual isolation at the physical and protocol layers. The physical layer switches to the secure signal channel via a high-speed radio frequency switch, and the protocol layer freezes the time parameter update of the suspicious channel; simultaneously triggering a constant-on protection light, recording the isolation initiation timestamp, suspicious channel identifier, and the entire isolation action's time consumption, meeting the power station's rapid response requirements. When a soft isolation event is received, a deweighted operation and real-time monitoring strategy is adopted, not cutting off the signal link but reducing the synchronization weight of the abnormal channel, freezing the correction gain update, and limiting the time adjustment rate; simultaneously triggering a slow flashing protection light, and if the comprehensive abnormal score value rises to the upper threshold, automatically escalating to a hard isolation event. The minimum feasible set of differentiated isolation operations includes: satellite switching (adding the corresponding satellite or channel to the isolation blacklist according to the suspicious channel identifier and freezing its time parameter updates), weight reduction (synchronizing the weight of suspicious channels and limiting the maximum proportion of participation in fusion), backup switching (switching the output source from the primary BDS or GPS channel to the pre-configured backup channel or security signal channel and recording the switching number), amplitude limiting (setting an upper limit on the time adjustment amount of a single time slice and freezing the correction gain update), rate limiting (setting an upper limit on the time adjustment rate to suppress step jumps), and freezing (freezing the correction gain and message parameter updates of suspicious channels until the release condition is met). Among them, soft isolation events must perform at least {weight reduction, amplitude limiting, and freezing}, hard isolation events must perform at least {satellite switching, backup switching, and freezing}, and timekeeping maintenance must perform at least {backup switching, rate limiting, and amplitude limiting}. The effective timestamp, target (channel or parameter), duration, and revocation conditions of each action are written to the isolation log to support auditing and rollback.
[0063] Adapting to the input requirements of existing time synchronization equipment at power stations, it supports GPS-L1 and BDS-B1 frequency band signal output, achieving seamless integration with the original time synchronization system. It features a built-in multi-standard signal conversion module that reads channel identifiers and matches the carrier frequency, modulation method, and code rate of the output signal. Through joint testing and verification with mainstream time synchronization devices at power stations, it ensures a signal access success rate of ≥99.9%, a timing synchronization deviation of ≤100%, and no signal loss during continuous 72 hours of operation. It employs a multi-lamp collaborative feedback mechanism with semantics consistent with the device's operating status indication dataset to clearly define the triggering conditions for each operating status, lamp status definitions, data upload requirements, and status switching rules. This ensures that the operating status is intuitively identifiable and traceable. The minimum set of lamps for the multi-lamp collaborative feedback mechanism is five lamps: Power lamp P (green or solid indicates normal power supply, red or solid indicates undervoltage or power failure risk), Status lamp S (green or solid indicates the main state machine is in a serviceable state, yellow or solid indicates a switching or evaluation transition state, red or solid indicates a fault lock), Learning lamp L (blue or flashing indicates fingerprint learning or relearning window, blue or solid indicates learning completed and baseline locked), Alarm lamp A (red or flashing at different frequencies indicates an abnormal level), and Protection lamp G (green or flashing at different frequencies indicates isolation or protection action has taken effect). The lamp output uses a unified encoded field {P, S, L, A, G, duration} to be written into the device operation status indication dataset and uploaded with the event link. The state machine switching conditions employ a three-element constraint of entry threshold, exit threshold, and minimum hold duration: When the comprehensive anomaly score is less than or equal to the anomaly threshold for K consecutive time slices, and there are no isolation events, and the link cause code is not a fault type, the system enters the normal state; when the comprehensive anomaly score is within the range of (lower threshold, upper threshold) for K consecutive time slices, or when the time deviation proxy quantity shows monotonically accumulating and does not meet the hard isolation condition, the system enters the soft isolation state; when the comprehensive anomaly score is greater than or equal to the upper threshold for K consecutive time slices, or when the cross-domain conflict constraint remains valid, the system enters the hard isolation state; when no signal flag is established after triggering a hard isolation event, or when the time deviation proxy quantity continuously exceeds the warning upper bound after triggering a soft isolation event and no signal flag is established, the system enters the timekeeping maintenance state; each state exits... The requirements are that the score and reason code must fall below the corresponding exit threshold within K consecutive time slices and meet the minimum hold duration to avoid jitter and repeated switching. Normal state: The comprehensive anomaly score is less than or equal to the anomaly threshold, there is no isolated event, the alarm light is off, the protection light is on, and the current baseline library version number and real-time signal quality data are uploaded; Hard isolation state: The alarm light flashes at high frequency (2Hz), the protection light is on, and the trigger reason code and suspicious channel identifier are uploaded; Soft isolation state: The alarm light flashes at low frequency (0.5Hz), the protection light flashes slowly, and the real-time comprehensive anomaly score and weighting coefficient are uploaded; Time-keeping maintenance state: The learning light flashes at high frequency (3Hz), the alarm light is on, the protection light is on, and the maintenance start time and link reason code are uploaded.
[0064] This implementation plan enables station personnel to quickly identify the current handling level and whether the action is effective without relying on complex diagnostic tools; it achieves an engineering closed loop of "actions that can be executed, processes that can be observed, results that can be traced, and anomalies that can be rolled back", which significantly improves the timeliness, certainty, and auditability of power station time synchronization security handling.
[0065] Specifically, the process of constructing a dual-redundant timekeeping architecture and synchronously outputting a reliability label sequence is as follows: a dual-redundant architecture of atomic clock and temperature-controlled crystal oscillator is adopted, and the timekeeping clock is calibrated by combining satellite signals with a site-level signal fingerprint baseline library, and drift characteristic parameters are recorded; the timekeeping start conditions include: satellite signal interruption after triggering a hard isolation event, or time deviation proxy quantity continuously exceeding the warning upper limit threshold and without signal marking after triggering a soft isolation event; during the timekeeping period, dynamic compensation is performed based on historical operating data and drift prediction model to ensure time synchronization accuracy ≤500ns and timekeeping duration ≥60 minutes.
[0066] The LSTM model predicts future drift and, combined with the drift deviation threshold of the segmented baseline, generates a dynamic compensation value to correct the output signal of the isothermal crystal oscillator. The drift deviation threshold is obtained by statistical calibration of drift samples during the timekeeping phase in historical operating data. The input feature vector for LSTM drift prediction consists of three types of fields: "timekeeping clock observations, environmental and power supply context, and control loop state variables". These include at least the time deviation proxy sequence of the most recent n time slices, the historical compensation output sequence, the isothermal crystal oscillator control word or tuning voltage sequence, the local oscillator temperature and temperature control deviation sequence, the power supply voltage or current fluctuation sequence, and the link cause code, context code for obstruction or no signal marker. The above fields are aligned according to a unified time slice to form a sliding window of length n as the model input, which is used to output the drift prediction sequence or the upper bound of the future drift for the next m time slices.
[0067] LSTM training and online updates employ a two-stage mechanism: In the offline stage, time-lapse samples from multiple sites are extracted from the historical operating database, and the basic model is trained hierarchically according to daytime baseline, nighttime baseline, and special operating condition baseline; In the online stage, lightweight adaptive updates are only allowed when safe learning conditions are met, i.e., within a window where the comprehensive anomaly score value does not exceed the lower bound threshold within a certain number of consecutive time slices, no hard isolation event is triggered, and the link cause code does not belong to the fault category, small-step incremental updates are performed using the most recent W time slice samples, or only the output layer parameters are updated. At the same time, update cooldown time and maximum update steps are set to avoid writing anomaly drift into the model under interference or attack contexts. To ensure that the compensation can be implemented, the dynamic compensation amount must meet the constraints of the clock control loop: the compensation step of a single time slice shall not exceed the upper limit of the step, the compensation amplitude shall not exceed the upper limit of the physical range of the control channel, and the speed limit and amplitude limit shall be automatically triggered when the control amount approaches the saturation range to prevent the compensation action from causing a time scale step; the prediction result, the constraint trigger flag and the final issued control word shall be bound to the time-keeping compensation record according to the same source timestamp. The record shall at least include the input window number, the upper limit of the prediction drift, the amplitude limit, the speed limit and saturation trigger flag, the final compensation output value and the effective time slice number, for playback reproduction and post-event auditing.
[0068] The time deviation surrogate quantity is divided by the gating coefficient threshold, and the ratio is substituted into the hyperbolic tangent function to obtain the deviation gating adjustment term. The upper bound of the future time drift is divided by the scale parameter, and the ratio is substituted into the hyperbolic tangent function to obtain the drift amplitude control term. The sign of the time deviation surrogate quantity is used as the direction determination term. The maximum unidirectional compensation amplitude is multiplied sequentially by the above deviation gating adjustment term, drift amplitude control term, and direction determination term to obtain the dynamic compensation quantity. The specific calculation formula for the dynamic compensation quantity is as follows:
[0069] ;
[0070] In the formula, This represents the dynamic compensation amount, used to suppress timekeeping drift and reduce time deviation proxy. This represents the time deviation proxy amount, which is obtained by filtering or estimating the observations during the time synchronization process. It is used to calculate the compensation amount and determines the strength of the compensation. The threshold value represents the gating coefficient. It is obtained by filtering the set of time slices in historical operation data that have not triggered soft isolation state, hard isolation state, not in time maintenance, and whose comprehensive abnormal score value is not higher than the lower threshold for several consecutive time slices and whose link cause code is not a fault type. The corresponding time deviation proxy quantity sequence is extracted, and the upper bound of natural fluctuation is estimated by robust statistics. The upper bound is then used to avoid frequent adjustments due to small fluctuations. It represents the upper bound of future time drift, obtained through a regression model based on drift data in historical operating data, and is used to control the adjustment of the compensation amount; The scale parameter, obtained by measuring drift tolerance and historical drift data, is used to determine the extent to which predicted drift affects the compensation amount. This represents the maximum compensation amplitude per time slice, obtained through the effective dynamic range and minimum step resolution of the OCXO control channel. The value range is a real number greater than zero, used to ensure that the compensation process is smooth and controllable, and will not amplify the error into a step disturbance. The direction determination sign function is obtained directly from the sign of the time deviation proxy quantity, and its value range is {−1, 0, +1}. It is used to ensure that the compensation quantity is opposite to the deviation direction.
[0071] The system synchronously outputs a credibility tag corresponding to the time synchronization result through the management interface and extended fields. This tag is used for hierarchical handling by the control center and is compatible with the power time synchronization device ecosystem. The credibility tag includes at least: credibility level, reason code for entering time synchronization maintenance, cumulative maintenance duration, upper bound of predicted drift, and anomaly evidence index. The tag and time synchronization output are bound to the same source timestamp and encapsulated in a fixed frame format to ensure that the tag is traceable, parsable, and auditable. In terms of ecosystem adaptation, the time synchronization output format and management protocol comply with GB and T-25931-2010, RFC-5905, and IEEE-1588, respectively, and the interface supports BNC. It supports common physical types of RJ45 power station terminals and enables status interaction and alarm linkage with existing time synchronization devices, thus achieving access without modifying the original system. In terms of hierarchical strategy adaptation, cross-station time fusion strategy is implemented according to the trust level: the trust level is divided into three levels: C1, C2, and C3. C1 level trust is not in soft isolation, not in hard isolation, not in timekeeping maintenance, the comprehensive anomaly score value of 3 consecutive time slices is less than or equal to the lower threshold, the predicted drift upper bound is less than or equal to the drift upper bound and lower threshold, the trigger reason code is empty or there is no anomaly, and the anomaly evidence index does not increase within 3 consecutive time slices. C2 Level 2 Trusted is in soft isolation (RF input not cut off, performing weight reduction and frozen gain update), maintaining timekeeping, and the cumulative timekeeping duration is less than or equal to the timekeeping duration threshold. Simultaneously, the predicted upper drift bound is less than or equal to the upper drift bound threshold. It is not in hard isolation, but the comprehensive anomaly score value is within the range of [lower threshold, upper threshold] for three consecutive time slots. C3 Level 3 Trusted is in hard isolation (suspicious channel RF input cut off, physical and protocol layer dual isolation activated), maintaining timekeeping, and the cumulative timekeeping duration is greater than the timekeeping duration threshold. The predicted upper drift bound is greater than the upper drift bound threshold, and the comprehensive anomaly score value is greater than the upper threshold. The triggering cause codes are interference, spoofing, and line anomaly risk cause codes, and the anomaly evidence index has been continuously increasing for the last three time slots.
[0072] When the confidence level is Level 3, cross-site time fusion is prohibited. This device does not provide time observations that can be used for fusion solution to the cross-site fusion module, but only reports the confidence level, cause code, anomaly evidence index, upper bound of prediction drift, and timekeeping duration for control center alarms and audits. When the confidence level is Level 2, participation in cross-site time fusion is restricted. Time observations are allowed, but the fusion module outputs a "fusion weight coefficient," which reduces the participation intensity of site observations according to the fusion weight coefficient. The fusion weight coefficient is determined by the upper bound of prediction drift and the timekeeping duration, and the value of the fusion weight coefficient ranges from 0 to 1. The larger the upper bound of prediction drift or the longer the timekeeping duration, the smaller the fusion weight coefficient. When the confidence level is Level 1, participation in cross-site time fusion is allowed. This device provides time observations, allowing the fusion module to use the site observations with full participation intensity.
[0073] Feedback on reliability level and key timeliness constraints: When the reliability level drops to Level 3, or the upper bound of the prediction drift exceeds the upper bound threshold, or the cumulative timeliness duration exceeds the maintenance duration threshold, a hard isolation event is triggered to strengthen the system and keep the abnormal channel frozen, prohibiting automatic recovery of the abnormal channel; when the reliability level is Level 1 and the comprehensive abnormal score value of three consecutive time slices is not higher than the lower bound threshold, and the abnormal evidence index corresponding to the isolation trigger cause code is no longer updated, a soft isolation event release suggestion is triggered and the recovery assessment process is allowed; at the same time, the isolation log, timeliness compensation record, and reliability tag sequence are written to the historical operation database, and the reliability tag sequence and historical operation database are output to form a closed loop of collection, verification, judgment, execution and feedback, supporting post-event auditing and accountability tracing.
[0074] In this implementation plan, timekeeping drift is controlled within acceptable boundaries and compensation actions are guaranteed not to introduce step disturbances. At the same time, the timekeeping results and credibility tags of each time slice are bound and encapsulated using the same source timestamp and continuously output. The credibility tags present the "handling level, entry reason, cumulative maintenance duration, predicted drift upper bound and abnormal evidence index" in a structured manner, enabling the control center to execute a hierarchical strategy for cross-station time fusion based on this, forming an auditable, reproducible and traceable full-link closed loop, which significantly improves the continuity of power station time synchronization, the certainty of handling, and the security of cross-station collaboration in complex electromagnetic environments.
[0075] Specifically, the process of constructing a secure back-cut process based on the credibility tag sequence is as follows: The credibility tag sequence is accessed, and the site-level signal fingerprint baseline library and comprehensive anomaly scoring sequence are synchronously invoked to construct the secure back-cut process. Slew rate limiting and hysteresis control are used to avoid secondary disturbances to the downstream caused by time-scale step transitions. The process requires simultaneous fulfillment of two conditions: the comprehensive anomaly score value must be below the back-cut threshold, and the window relearning fingerprint consistency verification must be passed; neither condition can be omitted. The window relearning fingerprint consistency verification process involves: starting a 3-minute relearning window, collecting the fingerprint feature vector of the recovered external signal, including C and N0 distributions, Doppler rate of change, and code phase continuity core features, comparing it with the site-level signal fingerprint baseline library, and calculating the fingerprint distance deviation value. When the deviation value is less than or equal to the consistency threshold set by the baseline library (obtained through baseline sample distribution statistics), the verification is considered successful; otherwise, the signal is deemed not truly recovered, and back-cut is prohibited.
[0076] A combined strategy of Slew speed-limited smooth cutback and hysteresis control to prevent jitter is adopted to prohibit timescale step jumps. The Slew speed-limited smooth cutback logic calculates the smooth cutback rate, which is strictly limited to the safe range allowed by the power time-sensitive system. By gradually releasing the correction gain, the timescale is pulled back to the external signal reference. During the pullback process, the timescale synchronization status of the downstream fault recording, synchronization phasor, and protection and control system is monitored in real time. If the timescale fluctuation exceeds the fluctuation threshold, the cutback is immediately suspended to maintain the timekeeping state. The hysteresis control logic sets two hysteresis thresholds: a cutback start threshold and a cutback pause threshold. When the abnormal score rises to a value greater than or equal to the cutback pause threshold during the cutback process, the cutback process is immediately terminated and the system switches back to the timekeeping state to avoid a vicious cycle of repeated switching between cutback and isolation due to signal jitter. The system ensures the stability of downstream time-sensitive time scales throughout the entire process, completely avoiding the risk of secondary damage during recovery. After the back-cut is completed, it automatically switches to normal operation mode and simultaneously uploads back-cut completion signals and back-cut process data to the control center, including back-cut start time, pull-back rate, time scale deviation of each time segment, and verification results.
[0077] This implementation plan ensures that fluctuations in abnormal scores near the boundary do not lead to repeated switching between back-cut and isolation, thus avoiding a vicious cycle. After the back-cut is completed, process data such as start-up time, pull-back rate, deviation of each time slice, and verification results are reported and stored in the database, making the back-cut behavior auditable, reviewable, and accountable, achieving a smooth transition under external signal recovery conditions and ensuring the stability of downstream time scales.
[0078] Specifically, the process of building a full-event chain traceability and intelligent policy automatic handling system is as follows: The system creates an undeniable audit record for all events related to time-sensor security. Policy orchestration reduces the burden of manual monitoring and improves operational efficiency. All data is integrated to form a full-process audit record chain. Recorded content is timestamped and stored with dual backups on both local and cloud platforms. Core fields of the audit record include: event type code (0-fraud detection event, 1-isolation action, 2-timekeeping maintenance, 3-switchback process, 4-deployment and debugging), event trigger timestamp, event duration, associated channel identifier, core parameters (anomaly score, fingerprint deviation, time stamp deviation), execution result, operator (automatic and manual), and device status snapshot (light position status combination). Audit records are archived hierarchically by day, week, and month, with a retention period of no less than one year. Precise retrieval by event type, time range, and channel identifier is supported, providing complete evidence for operational positioning and incident tracing.
[0079] A hierarchical automatic handling strategy is built based on a rule engine, which monitors the entire process data in real time and automatically executes the corresponding contingency plan when a rule is triggered. The core rules and handling logic of the strategy are as follows: Rule 1 - Continuous Synchronization Anomaly Trigger: When the comprehensive anomaly score of a certain channel for three consecutive time slices is greater than or equal to the upper threshold, and a hard isolation state is triggered two or more times, the system automatically switches to the backup time source (such as the Beidou-2 backup channel), and sends an SMS and platform alarm to the administrator, along with an anomaly evidence summary; Rule 2 - Deviation Exceeds Limit Trigger: During the timekeeping maintenance process, if the time scale drift is continuously greater than the time scale drift threshold, the system will automatically switch to the backup time source (such as the Beidou-2 backup channel), and send an SMS and platform alarm to the administrator. When the timekeeping compensation parameters are adjusted automatically, if there is still no improvement after adjustment, an emergency alarm will be triggered to notify the operation and maintenance personnel to conduct on-site troubleshooting; Rule 3 - Switchback failure trigger: If the time scale fluctuation exceeds the fluctuation threshold during a single switchback, the switchback will be automatically terminated, the timekeeping status will be maintained, the cause of failure (such as fingerprint inconsistency, signal jitter) will be recorded and uploaded, and the switchback will be restarted after manual confirmation; Rule 4 - Link failure trigger: If the link cause code continuously shows the "connection loose, antenna abnormal" mark, the link failure alarm will be automatically triggered, clearly indicating the location of the fault (such as XX channel antenna) to assist the operation and maintenance personnel in accurate troubleshooting.
[0080] The integrated feature term is obtained through tensor operations using the spatial feature matrix, environmental feature vector, and historical event feature vector. Tensor operations are then performed between the spatiotemporal coupling tensor and the integrated feature term to obtain the correlation term. The correlation term is then processed through fusion calculation to obtain the evaluation sub-term. The state term is obtained by performing a moving average operation using the back-cut success rate time series and the device covariance matrix. Finally, the evaluation sub-term and the state term are substituted into the hyperbolic tangent normalized fusion function to obtain the policy evaluation value. The specific calculation formula for the policy evaluation value is as follows:
[0081] ;
[0082] In the formula, This represents the strategy evaluation value, used to measure whether the current state requires intervention and the urgency of such intervention. The spatiotemporal coupling tensor is obtained by tensor operations on the temporal feature matrix, spatial feature matrix, and environmental feature vector, and is used to comprehensively reflect the current spatiotemporal environment state. The spatial feature matrix, obtained from system topology data, is used to describe spatial layout and connectivity. The environmental feature vector is obtained from sensor data (such as electromagnetic interference intensity) and equipment operating time (aging coefficient) and is used to reflect the impact of the external environment. The feature vector representing historical events is extracted from historical event data in audit records and is used to help decision-making consider long-term trends. The time series representing the success rate of the back-cut operation is calculated from the back-cut operation records and is used to measure the fluctuation and correlation of the equipment status. The equipment covariance matrix is calculated from equipment status snapshots (such as lamp position status combinations) and is used to measure the fluctuation and correlation of equipment status.
[0083] Each time a strategy is automatically triggered and executed, the system will automatically record the strategy evaluation value before and after the action, and calculate the strategy improvement rate. Based on the improvement rate and strategy evaluation value, the system will automatically classify and rate the strategy execution effect; Category A (Excellent Strategy): The improvement rate is greater than or equal to the excellent strategy improvement rate threshold, and the strategy evaluation value after action is less than the excellent strategy post-action threshold. The system will automatically store this strategy parameter and action scenario in the "Best Practice Library" for priority use in similar scenarios.
[0084] Category B (Good Strategy): The improvement rate is greater than or equal to the good strategy improvement rate threshold, and the post-treatment strategy evaluation value is less than the good strategy post-treatment threshold. The strategy will be retained, and this effective execution record will be recorded to reinforce the strategy's trigger confidence.
[0085] Category C (Strategies to be Optimized): The improvement rate is less than the threshold for good strategies, or the post-implementation evaluation value of the strategy is greater than the post-implementation threshold for strategies to be optimized. Optimization suggestions (such as adjusting trigger thresholds or modifying action parameters) will be automatically generated and pushed to operations personnel for confirmation.
[0086] Category D (Failed Strategy): The post-treatment strategy evaluation value is greater than or equal to the pre-treatment strategy evaluation value. The strategy will be automatically paused, an alarm will be triggered, and the system will roll back to the previous stable version. At the same time, the failure scenario will be recorded for in-depth analysis.
[0087] All handling processes are recorded in their entirety, forming a closed-loop traceability chain to ensure that the effectiveness of each action is quantifiable, assessable, and optimizable. A safe switchback status signal and a set of operation and maintenance audit records are output.
[0088] This implementation plan ensures that strategy orchestration is not a one-time configuration but a closed loop that can be quantified, evaluated, and continuously optimized. This enables fully automated and controllable handling of the entire process, while integrating strategy evaluation values into rule triggering, action selection, and effect acceptance. This significantly reduces the burden of manual monitoring and improves the certainty and auditability of the handling of timing security incidents by the station and control center.
[0089] Specifically, the second aspect of this invention provides a BeiDou-based time synchronization security isolation and protection system, applied to a BeiDou-based time synchronization security isolation and protection method, comprising: a satellite time synchronization signal acquisition module, used to acquire a time synchronization security input dataset, and perform time-slice segmentation and normalization processing to form a time synchronization security acquisition data frame, while carrying channel identifiers, link cause codes and device lamp position status codes, ensuring that inspection and auditing can be reproduced by time-slice playback, and constructing a site-level signal fingerprint baseline library; a consistency verification module, used to perform consistency verification and cross-domain contradiction constraint fusion based on the site-level signal fingerprint baseline library, output a set of suspicious satellite channels, and perform dual-threshold judgment to trigger isolation events, and bind the trigger cause code with the window number, so as to facilitate the isolation strategy to be implemented according to the cause, and generate an anomaly scoring stream; a security isolation and time synchronization maintenance module, used to construct a security isolation and time synchronization maintenance execution mechanism, and construct a dual-redundant time synchronization architecture, synchronously outputting a credibility label sequence; ensuring that the control center can perform graded handling and cross-site fusion control based on the credibility level. The security rollback and operations audit module is used to construct a security rollback process based on a trustworthiness tag sequence, and to build a full-event traceability and intelligent policy automatic handling system. The rollback process uses rate limiting adjustment and hysteresis criteria to prevent time stamp jumps, and writes the fraud detection, isolation, timekeeping, rollback and handling results into a non-repudiable audit record chain to support accountability.
[0090] In this implementation plan, the timing input is collected into frames according to time slices and a station-level signal fingerprint baseline is established. Suspicious channels and abnormal score streams are output under the constraints of multi-domain consistency verification and cross-domain contradiction. Then, isolation is triggered by dual threshold judgment and dual redundancy is linked to maintain timekeeping. At the same time, a credibility label is output for the control center to handle in a hierarchical manner and cross-station fusion control. When the signal is restored, relearning consistency verification, Slew rate limiting and hysteresis criteria are used to achieve safe back-switching, thereby realizing time synchronization security isolation protection that is detectable, hierarchical, uninterrupted, back-switching and traceable.
[0091] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0092] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. A time-synchronization security isolation and protection method based on BeiDou, characterized in that, Includes the following steps: S1, collect the time synchronization security input dataset, and perform time-slice segmentation and normalization processing to form a time synchronization security acquisition data frame, and build a site-level signal fingerprint baseline library; S2, based on the site-level signal fingerprint baseline library, performs consistency verification and cross-domain contradiction constraint fusion, outputs a set of suspicious satellite channels, generates an abnormal score stream, and triggers isolation events based on the abnormal score stream with dual threshold judgment; S3 constructs a secure isolation and time-keeping execution mechanism, and builds a dual-redundant time-keeping architecture to synchronously output a trustworthiness label sequence; S4 builds a secure back-switch process based on trustworthy label sequences, establishing a full-event chain tracing and intelligent strategy automatic handling system.
2. The BeiDou-based time synchronization security isolation and protection method according to claim 1, characterized in that: The specific process of collecting the time-synchronization security input dataset and performing time-slicing and normalization processing to form a time-synchronization security acquisition data frame is as follows: The timing security input dataset is collaboratively acquired through in-situ serial connection of the BeiDou timing security isolation and protection device. The timing security input dataset includes: satellite timing radio frequency input dataset, signal and noise floor dataset, receiver link status dataset, device operation status indication dataset, and channel identifier dataset. Timing security preprocessing is performed on the timing security input dataset: interval pruning and abrupt change detection are performed on the input power estimate, and impulse interference is eliminated through sliding window peak detection and gating suppression. The timing security input dataset is time-aligned and encapsulated using unified time-slice scheduling, and linear normalization is performed to construct timing security acquisition data frames. The timing security acquisition data frames are written into the global acquisition queue in chronological order and local queues are established by channel. Data that has been acquired and stored is marked as historical operation data.
3. The BeiDou-based time synchronization security isolation and protection method according to claim 2, characterized in that: The specific process for constructing the site-level signal fingerprint baseline library is as follows: Input timing security acquisition data frames and historical operation data, construct a signal fingerprint learning window using the device learning process, filter, extract features and model baselines of timing security acquisition data frames in the learning window, and generate a site-level signal fingerprint baseline library. Steady-state screening and sample purification are performed on the time-synchronized security data frames within the learning window: frames in which the alarm light maintains normal semantics during the learning phase are marked as steady-state frames and used as baseline samples; signal fingerprint feature vector sets are extracted from the set of steady-state frames; A site-level signal fingerprint baseline library is constructed based on the signal fingerprint feature vector set: for each type of feature, a robust statistical method is used to calculate the median, quantile band and MAD scale parameters, and a threshold template is formed; The baseline library is divided into daytime baselines, nighttime baselines, and special operating condition baselines according to time periods. The baseline library version number, learning batch number, and effective time are written into the baseline index table. Fingerprinting preprocessing and robust normalization are performed on the time synchronization security acquisition data frames during the online operation phase, and fingerprint feature frame streams are output.
4. The BeiDou-based time synchronization security isolation and protection method according to claim 3, characterized in that: The specific process of performing consistency checks and cross-domain contradiction constraints based on the site-level signal fingerprint baseline database to output a set of suspicious satellite channels and generate an anomaly scoring stream is as follows: Input fingerprint feature frame stream, and perform consistency checks on the normalized fingerprint vector, fingerprint distance component, and feature confidence score of each BDS and GPS channel within each time slice. In the frequency domain consistency check, extract frequency-domain related feature subsets from the normalized fingerprint vector and calculate the frequency domain violation, generating a frequency domain consistency score item. In the code domain consistency check, extract code phase continuity and related peak shape feature subsets and calculate the code domain violation, generating a code domain consistency score item. In the carrier domain consistency check, extract carrier phase noise and phase acceleration feature subsets and calculate the carrier phase noise and phase acceleration. The frequency domain violation is used to generate a carrier domain consistency score. In the message domain consistency check, the arrival time jitter and message consistency feature subset of the navigation message are extracted and the message domain violation is calculated to generate a message domain consistency score. The product of the frequency domain consistency score and the frequency domain weight coefficient, the product of the code domain consistency score and the code domain weight coefficient, the product of the carrier domain consistency score and the carrier domain weight coefficient, and the product of the message domain consistency score and the message domain weight coefficient are added to obtain a comprehensive term. The cross-domain contradiction constraint value is multiplied by the comprehensive term to obtain a comprehensive anomaly score. The system compares the comprehensive anomaly score with the anomaly threshold in real time. The anomaly threshold is obtained through statistical calibration and segmented adaptive analysis of historical operational data. When the comprehensive anomaly score is greater than the anomaly threshold, it is determined to be an anomaly signal, triggering signal isolation or protection measures. When the comprehensive anomaly score is less than or equal to the anomaly threshold, it is determined to be a normal signal, and routine timing signal processing continues without intervention. The system also outputs a set of suspicious satellite channels, a comprehensive anomaly score sequence, and a domain-level score item sequence.
5. The BeiDou-based time synchronization security isolation and protection method according to claim 4, characterized in that: The specific process of triggering isolation events based on dual threshold judgment using anomaly scoring stream is as follows: Input the comprehensive anomaly score sequence, domain-level score item sequence, and fingerprint feature frame stream to construct trend decision quantity and time deviation proxy quantity. Use dual thresholds and persistence thresholds to identify drift. Output soft isolation trigger event and hard isolation trigger event: when the comprehensive anomaly score value is greater than or equal to the lower threshold and the rate of change of the comprehensive anomaly score value is continuously positive within the window period, or when the time deviation is monotonically accumulated and exceeds the upper threshold of the drift warning, it is judged as a suspicious slow drift and a soft isolation event is triggered. When the comprehensive anomaly score is greater than or equal to the upper threshold and the cross-domain contradiction constraint is continuously satisfied, or the time deviation accumulates to exceed the upper limit of drift confirmation within the window period, it is determined to be a deceptive confirmation, triggering a hard isolation event, and outputting the progressive drag identification result and the isolation trigger event to form an event link evidence package.
6. The BeiDou-based time synchronization security isolation and protection method according to claim 1, characterized in that: The specific process for constructing the secure isolation and time-keeping execution mechanism is as follows: Construct a linkage decision logic for isolation trigger events, execute differentiated isolation operations, and simultaneously complete the adaptation of security signal standards and the visualization feedback of operational status: receive isolation trigger events, trigger reason codes and suspicious satellite channel identifiers, combine them with the received link status dataset to form the basis for isolation decisions, and execute the construction of a security hierarchical isolation and time-keeping maintenance execution mechanism; adopt a multi-lamp collaborative feedback mechanism with semantics consistent with the device operational status indication dataset to clarify the trigger conditions, lamp status definitions, data upload requirements and status switching rules for each operational status.
7. The BeiDou-based time synchronization security isolation and protection method according to claim 1, characterized in that: The specific process of constructing a dual-redundant time-keeping architecture and synchronously outputting the credibility label sequence is as follows: A dual-redundancy architecture of atomic clock and temperature-controlled crystal oscillator is adopted. The timekeeping clock is calibrated by combining satellite signal with a site-level signal fingerprint baseline library, and drift characteristic parameters are recorded. The timekeeping start conditions include: satellite signal interruption after hard isolation, or time deviation proxy quantity continuously exceeding the warning upper limit threshold and without signal marker after soft isolation. The future drift quantity is predicted by LSTM model, and dynamic compensation quantity is generated by combining the drift deviation threshold of segmented baseline to correct the output signal of temperature-controlled crystal oscillator: the time deviation proxy quantity is divided by the gating coefficient threshold, and the ratio is substituted into the hyperbolic tangent function to obtain the deviation gating adjustment term; the future time drift upper limit is divided by the scale parameter, and the ratio is substituted into the hyperbolic tangent function to obtain the drift amplitude control term; the sign of the time deviation proxy quantity is used as the direction determination term; the maximum unidirectional compensation amplitude is multiplied by the above deviation gating adjustment term, drift amplitude control term, and direction determination term in sequence to obtain the dynamic compensation quantity. The system synchronously outputs trustworthiness tags that correspond one-to-one with the time synchronization results through the management interface and extended fields. When the trustworthiness level is level three, cross-site time fusion is prohibited; when the trustworthiness level is level two, participation in cross-site time fusion is restricted; time observations are allowed, and when the trustworthiness level is level one, participation in cross-site time fusion is allowed; at the same time, isolation logs, timekeeping compensation records, and trustworthiness tag sequences are written to the historical operation database, and the trustworthiness tag sequences and historical operation database are output.
8. A timing security isolation and protection method based on BeiDou according to claim 7, characterized in that: The specific process of constructing a secure back-cutting process based on the credibility tag sequence is as follows: By accessing the trustworthy label sequence and synchronously calling the site-level signal fingerprint baseline library and comprehensive anomaly scoring sequence, a safe back-off process is constructed. Through Slew rate limiting and hysteresis control, secondary disturbances to downstream caused by timescale step jumps are avoided. The process requires the simultaneous fulfillment of two conditions: the comprehensive anomaly score value must be lower than the back-off threshold and the window relearning fingerprint consistency verification must be passed. Both conditions must be met. A combination strategy of Slew rate limiting for smooth back-off and hysteresis control for jitter prevention is adopted to prohibit timescale step jumps. The stability of downstream timescales that are sensitive to time is ensured throughout the process, and the risk of secondary damage during recovery is completely avoided. After the back-off is completed, the system automatically switches to normal operation mode and synchronously uploads the back-off completion signal and back-off process data to the control center.
9. A timing security isolation and protection method based on BeiDou according to claim 1, characterized in that: The specific process for establishing a full-event chain tracing and intelligent strategy automatic handling system is as follows: Construct a full-event chain traceability and intelligent strategy automatic handling system to form an irrefutable audit record for all time-security events: integrate all data to form a full-process audit record chain, and use timestamp encryption and dual backup storage in local and cloud; build a hierarchical automatic handling strategy based on a rule engine, monitor the full-process operation data in real time, and automatically execute the corresponding contingency plan when a rule is triggered; By using spatial feature matrix, environmental feature vector, and historical event feature vector, tensor operations are performed to obtain integrated feature terms; tensor operations are then performed between the spatiotemporal coupling tensor and the integrated feature terms to obtain correlation terms. The evaluation sub-item is obtained by processing the correlation terms through fusion calculation; the state term is obtained by performing a moving average operation on the back-cut success rate time series and the device covariance matrix; the evaluation sub-item and the state term are substituted into the hyperbolic tangent normalized fusion function to obtain the strategy evaluation value. Each time a strategy is automatically triggered and executed, the strategy evaluation value before and after the action will be automatically recorded, and the strategy improvement rate will be calculated. Based on the improvement rate and the strategy evaluation value, the strategy execution effect will be automatically classified and rated. All actions will be recorded in their entirety, forming a closed-loop traceability link, and outputting a security back-switch status signal and a set of operation and maintenance audit records.
10. A BeiDou-based time synchronization security isolation and protection system, employing the BeiDou-based time synchronization security isolation and protection method as described in any one of claims 1-9, characterized in that, include: The satellite timing signal acquisition module is used to acquire timing security input datasets, and perform time-slice segmentation and normalization processing to form timing security acquisition data frames, and build a station-level signal fingerprint baseline library; The consistency verification module is used to perform consistency verification and cross-domain contradiction constraint fusion based on the site-level signal fingerprint baseline library, output a set of suspicious satellite channels, generate an abnormal score stream, and trigger isolation events based on the abnormal score stream with dual threshold judgment. The security isolation and timekeeping maintenance module is used to build a security isolation and timekeeping maintenance execution mechanism, and to build a dual-redundant timekeeping architecture to synchronously output a trustworthiness tag sequence; The security rollback and operation and maintenance audit module is used to build a security rollback process based on the trust label sequence, and to build a full event link traceability and intelligent policy automatic handling system.
Citation Information
Patent Citations
Time service system of radio receiver and time service method
CN101741401B
Ground equipment system based on Beidou satellite timing signal
CN104734769B
Beidou anti-deception jamming method and GNSS time service type receiving device
CN110954925A
Navigation satellite radio frequency fingerprint feature extraction and deception signal detection method
CN117849828A