Industrial control equipment supply chain analysis method and system based on natural language processing technology

By constructing a knowledge graph of the industrial control equipment supply chain and combining it with natural language processing technology, the problems of processing unstructured data and insufficient understanding of upstream and downstream relationships in existing methods have been solved. This enables dynamic risk analysis and physical layer protection of the industrial control equipment supply chain, improving security and risk detection efficiency.

CN121744252APending Publication Date: 2026-03-27INST OF SOFTWARE - CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-17
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing industrial control equipment supply chain analysis methods are unable to effectively process dynamic unstructured text data, lack a deep understanding of upstream and downstream relationships, and cannot provide targeted guidance on hardware operation and firmware analysis, resulting in insufficient security risk identification and prevention measures.

Method used

By employing natural language processing technology, this method collects and cleans information from the industrial control equipment supply chain, extracts entities and relationships, constructs a knowledge graph of the industrial control equipment supply chain, and generates physical layer control commands under risk-triggered conditions, thereby enabling quantitative analysis and prevention of risks.

Benefits of technology

It significantly improves the accuracy of entity recognition and relationship extraction, can quantify the intensity of risk transmission, provide targeted preventive measures, and enhance the security and risk detection efficiency of industrial control equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121744252A_ABST
    Figure CN121744252A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial control equipment supply chain analysis method and system based on a natural language processing technology, and belongs to the technical field of industrial control equipment safety. The method comprises the following steps: collecting related documents of the industrial control equipment; performing entity identification on supply chain nodes contained in the document; extracting a node relationship in the supply chain; and fusing the entities and the relationships to generate the industrial control equipment supply chain knowledge graph. According to the method, necessary knowledge support and technical guidance can be provided for safety researchers, the safety researchers are helped to better master the safety condition of the industrial control equipment, and effective precautionary measures are taken before risks occur.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control equipment security technology, specifically to a method and system for industrial control equipment supply chain analysis based on natural language processing technology. Background Technology

[0002] With the rapid development of Industry 4.0, industrial control systems have become a core component of modern production. Within these systems, industrial control equipment (ICS) plays a crucial role in control and monitoring, and its security directly impacts the stability and reliability of the entire industrial production process. However, with the increasing complexity of ICS and the expansion of the global supply chain, security risks within the supply chain pose a growing threat to the security of ICS. Malicious suppliers, potential hardware backdoors, and software vulnerabilities can all infiltrate ICS through the supply chain, severely impacting the security of industrial control systems. Therefore, ensuring the security of ICS through a comprehensive analysis of the ICS supply chain has become a critical issue that urgently needs to be addressed.

[0003] Currently, supply chain analysis is gaining increasing importance in industrial control equipment (ICS) security research. ICS security relies not only on the protective measures of the equipment itself but also on a deep understanding of its supply chain. Especially in multi-layered supply chain structures, supply chain analysis allows security researchers to trace the origin of hardware devices, identify potential risky suppliers, and promptly discover potential security threats within the supply chain, such as hardware backdoors or software vulnerabilities, providing early warning information to the industry. Furthermore, supply chain analysis helps researchers master the operation methods of related hardware in ICS and firmware extraction techniques, enabling them to discover potential vulnerabilities, backdoors, or malicious code in the firmware, thereby taking appropriate protective measures. These are all crucial for ensuring the security of ICS.

[0004] Existing research methodologies still suffer from the following problems: First, security threats in the supply chain are often dynamic and constantly changing. Most existing methods rely on static, structured data, making it difficult to process and utilize dynamic, real-time unstructured text data, which often contains crucial information and trends related to security risks. Furthermore, traditional supply chain analysis methods lack a deep understanding of upstream and downstream relationships, making it difficult to identify potential supply chain risks from a holistic perspective. Finally, existing supply chain analysis tools lack design considerations for industrial control equipment, neglecting the analysis of its operational methods at supply chain nodes. Therefore, they cannot provide targeted hardware operation and firmware analysis guidance for security personnel to conduct in-depth research. Summary of the Invention

[0005] This invention discloses a supply chain analysis method and system for industrial control equipment based on natural language processing technology. It can provide necessary knowledge support and technical guidance for security researchers, help them better understand the security status of industrial control equipment, and take effective preventive measures before risks occur.

[0006] To achieve the above objectives, the present invention adopts the following technical solution.

[0007] A method for analyzing the industrial control equipment supply chain based on natural language processing technology, the method comprising: Collect information on the industrial control equipment supply chain; Extract entities and relationships from the industrial control equipment supply chain information; wherein, the entities include: supplier entities, supplier location regions, hardware operation characteristic entities, equipment component entities, supply chain security attribute entities, and vulnerability entities, and the relationships include: hardware operation relationships, vulnerability propagation relationships, geopolitical risk relationships, supply relationships, and security attribute relationships; Construct a knowledge graph of the industrial control equipment supply chain based on the entities and relationships described above; The analysis is performed based on the knowledge graph of the industrial control equipment supply chain, and when the analysis results trigger risk triggering conditions, the corresponding physical layer control command is generated.

[0008] Furthermore, collect information on the industrial control equipment supply chain, including: Using the requests and BeautifulSoup libraries in Python, we collected initial supply chain information from the design, production, and manufacturing documents of industrial control equipment, as well as from publicly available data sources, through web scraping technology. For the initial supply chain information of industrial control equipment manufacturers' supplier list, the Scrapy framework is used to crawl the web to obtain supplier background information, product descriptions, delivery records and market analysis reports from supplier websites and public databases. Then, the initial supply chain information is supplemented to obtain industrial control equipment supply chain information.

[0009] Furthermore, after collecting information on the industrial control equipment supply chain, it also includes: The pandas library is used to clean the industrial control equipment supply chain information. The cleaning process includes removing duplicate information, blank items, and noisy data, and using the re library to format unstructured text. The formatting process includes removing HTML tags, special characters, and irrelevant information. The NLTK technology was used to perform word segmentation, word form restoration, stop word filtering, and numerical data standardization on the cleaned information.

[0010] Furthermore, extract entities from the industrial control equipment supply chain information, including: Load a BERT model pre-trained on an industrial control corpus and combine it with a CRF sequence labeling algorithm to perform entity recognition on industrial control equipment supply chain information; Obtain the supplier entity and the region where the supplier is located from the entity recognition results; The hardware operation feature entities are obtained from the entity recognition results. The hardware operation feature entities include: debugging interface type and firmware burning method. The device component entities are obtained from the entity recognition results. The device component entities include: device port components, device firmware components, device network components, and device supply chain. Obtain supply chain security attribute entities from the entity identification results. The supply chain security attribute entities include: supplier risk level, supplier compliance status, and whether they have ISO / IEC 62443 or ISO 9001 certification. The vulnerability entity is obtained from the entity identification results. The vulnerability entity includes: CVE number, vulnerability exploitation probability score (CVSS), and vulnerability type.

[0011] Furthermore, the hardware operation relationship is used to describe the operation dependency relationship between hardware operation feature entities and device component entities. The hardware operation relationship includes: the device component model relationship corresponding to the debugging interface type and the chip model relationship corresponding to the firmware burning method. The vulnerability propagation relationship is used to describe the vulnerability impact or propagation path between the vulnerability entity and the device component entity and the supplier entity. The vulnerability propagation relationship includes: the vulnerability-affected component relationship, the vulnerability-sourced supplier relationship, and the vulnerability co-occurrence relationship. The geopolitical risk relationship is used to describe the geopolitical or regional risk dependence between the supplier's region and the supplier entity. The geopolitical risk relationship includes: the relationship between regional risk level and supplier risk level, and the relationship between regional events and supplier compliance status. Supply relationships are used to describe the supply or manufacturing dependencies between supplier entities and equipment component entities. These supply relationships include: supplier component production relationships, supplier chip supply relationships, and supplier delivery record corresponding component relationships. Security attribute relationships are used to describe the security status association between supply chain security attribute entities and supplier entities. These security attribute relationships include: security certification relationships corresponding to supplier risk levels and certification system relationships corresponding to compliance status.

[0012] Furthermore, based on the knowledge graph of the industrial control equipment supply chain, analysis is performed, and when the analysis results trigger risk triggering conditions, corresponding physical layer control commands are generated, including: Detect transmission paths that match the characteristics of industrial control systems in the knowledge graph and set risk triggering conditions; Based on the knowledge graph, a directed transmission path is constructed from the supplier entity → equipment component entity → hardware operation feature entity → vulnerability entity → supply chain security attribute entity; Assign a base risk value to each node in the path. The basic risk value of the supplier entity is determined based on the supplier's risk level and compliance status. The risk value of the device component entity is calculated based on the number and severity of vulnerabilities associated with the device component entity. The risk value of the hardware operation feature entity is calculated based on the degree of interface exposure and firmware accessibility. The risk value of the vulnerability entity is determined based on its CVSS score and vulnerability type coefficient. The risk value of the supply chain security attribute entity is calculated based on the security certification level and historical event records. Assign a weight coefficient to each relation in the path. The weighting coefficient of the hardware operation relationship is calculated based on the component's dependence on the debugging interface; the weighting coefficient of the vulnerability propagation relationship is determined based on the vulnerability's propagation and co-occurrence probability; and the weighting coefficient of the geopolitical risk relationship is determined based on the regional risk level and supplier concentration. Overall Calculation of Path Total Risk Value ,in, This represents the total number of path nodes. For the first The number of relationships between nodes; Total risk value for all paths Normalization is performed, and the result is based on the set trigger threshold. Determine whether the normalized total path risk value meets the risk triggering condition; When the normalized total risk value of the path reaches the risk triggering condition, the corresponding physical layer control command is automatically generated according to the type of the affected device component entity in the path.

[0013] Furthermore, when the affected device component entity type is a device port component, the physical layer control command includes: disabling or restricting debug interface access; When the affected device component entity type is a device firmware component, the physical layer control command includes: triggering firmware lock, forcing verification and read-only mode, and restricting the flashing of signed firmware; When the affected device component entity type is a device network component, the physical layer control command includes: shutting down the external communication link of the supply chain associated device at the industrial control gateway layer and restricting the OTA upgrade channel; In cases where the affected device component entity type is the device supply chain, the physical layer control command includes: temporarily suspending firmware updates or parts procurement processes from high-risk vendors; The physical layer control command also includes: generating a risk reporting instruction, which is used to send high-risk path alarm information to the upper-layer security management system.

[0014] A supply chain analysis system for industrial control equipment based on natural language processing technology, the system comprising: The information collection module is used to collect supply chain information for industrial control equipment. The information extraction module is used to extract entities and relationships in the industrial control equipment supply chain information; wherein, the entities include: supplier entities, supplier location regions, hardware operation characteristic entities, equipment component entities, supply chain security attribute entities, and vulnerability entities, and the relationships include: hardware operation relationships, vulnerability propagation relationships, geopolitical risk relationships, supply relationships, and security attribute relationships; The graph construction module is used to construct a knowledge graph of the industrial control equipment supply chain based on the entities and relationships. The graph analysis module is used to perform analysis based on the industrial control equipment supply chain knowledge graph, and generate corresponding physical layer control commands when the analysis results trigger risk triggering conditions.

[0015] An electronic device includes: a processor and a memory storing computer program instructions; the processor, when executing the computer program instructions, implements the industrial control equipment supply chain analysis method based on natural language processing technology described above.

[0016] A computer-readable storage medium, characterized in that the computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the industrial control equipment supply chain analysis method based on natural language processing technology described above.

[0017] Compared with the prior art, the present invention has at least the following beneficial effects.

[0018] a. This invention combines professional knowledge in the field of industrial control with the characteristics of security scenarios to extract entities and relationships in a targeted manner, making the knowledge graph more aligned with the business logic of the industrial control equipment supply chain, and significantly improving the accuracy and practicality of entity recognition and relationship extraction; b. This invention achieves quantitative analysis of risk transmission intensity through path risk accumulation calculation, which can not only intuitively assess the risk level of a single node or relationship, but also comprehensively reflect the risk level of the entire path; c. To address different types of risks, this invention proposes a physical layer blocking instruction generation mechanism. For example, it generates instructions to flash signed firmware and disable the programming interface to address firmware backdoor risks, and generates instructions to cut PCB circuits and install EMI shielding to address hardware interface exposure risks. This approach, which extends from the software logic layer to the hardware physical layer, overcomes the limitations of existing technologies that rely solely on logic isolation and software patches, significantly improving the effectiveness and reliability of the handling process. d. This invention can integrate knowledge graphs with existing security threat intelligence databases to automatically update information such as vulnerabilities and attack events in industrial control equipment, thereby enabling intelligent matching and early warning of known threats; e. This invention can be embedded in an enterprise's internal audit system to quickly identify high-risk suppliers and key equipment through supply chain transaction graph analysis, thereby focusing audit resources and improving the efficiency of risk discovery and the rate of problem detection. Attached Figure Description

[0019] Figure 1 This is a flowchart of a supply chain analysis method for industrial control equipment based on natural language processing technology.

[0020] Figure 2 This is a flowchart of the information collection process for the industrial control equipment supply chain.

[0021] Figure 3 This is a flowchart of data preprocessing in the industrial control equipment supply chain.

[0022] Figure 4 This is a flowchart for entity identification and relationship extraction in the industrial control equipment supply chain.

[0023] Figure 5 It is a flowchart for constructing a knowledge graph of the industrial control equipment supply chain. Detailed Implementation

[0024] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be noted that the embodiments described below are intended to facilitate the understanding of the present invention and do not limit it in any way.

[0025] This invention discloses a method and system for analyzing the industrial control equipment supply chain. By integrating advanced natural language processing technology and supply chain analysis methods, it extracts text data related to the industrial control equipment supply chain from multiple data sources and constructs a knowledge graph of the industrial control equipment supply chain. The knowledge graph can not only identify potential supply chain security risk factors in industrial control equipment in a timely manner, but also serve as a reference system for security analysis, providing necessary knowledge support and technical guidance for security researchers. This helps security researchers better understand the security status of industrial control equipment and take effective preventative measures before risks occur.

[0026] The industrial control equipment supply chain analysis method of the present invention, such as Figure 1 As shown, it includes the following steps 1 to 4.

[0027] Step 1: Collect relevant documents for industrial control equipment.

[0028] This invention employs a distributed crawling engine based on a hybrid scheduler of Scrapy / Playwright, combined with a proxy pool, certificate verification, and robots.txt compliance checks. It periodically or in an event-driven manner collects publicly available and authorized data related to the target device in parallel. The collection sources include, but are not limited to: manufacturer websites, data tables, manufacturing specifications, firmware images, factory batch records, purchase contracts, SBOMs, open-source code repositories, vulnerability databases (CVE / NVD), industry reports, patent documents, forums and mailing lists, third-party threat intelligence streams, and supplier qualification certificates, etc.

[0029] The collected raw data is recorded with a traceable chain of evidence, including: capture timestamps, request / response headers, capture proxy fingerprints, content fingerprint SHA-256, storage location, and access permissions. For binary or firmware files, block hashing, symbol table extraction, segment analysis, and compiler fingerprinting are performed.

[0030] The application utilizes an Apache Spark / Flink cleaning pipeline to perform character set unification, language detection and domain-adaptive translation, time zone and timestamp normalization, missing value estimation and confidence labeling, fuzzy hashing for deduplication, and metadata completion. During this process, immutable audit logs are generated for compliance review.

[0031] In one embodiment, the supply chain information collection and preprocessing process of the present invention is as follows: Figure 2 and Figure 3 As shown, it includes the following steps: (1-1) Collect relevant documents for industrial control equipment. Use the requests and BeautifulSoup libraries in Python to crawl and collect supply chain information from design, production, and manufacturing documents of industrial control equipment, as well as from publicly available data sources. For PDF documents, use the PyPDF2 or pdfminer.six libraries to extract the content into text format. For scanned document images, use the Tesseract OCR tool to extract the text from the images. (1-2) Collect supplier information. Use the Scrapy framework for large-scale web crawling to obtain supplier background information, product descriptions, delivery records, and market analysis reports from supplier websites and public databases. For data sources provided by APIs, use the requests library to call API interfaces to obtain structured data; (1-3) Use the pandas library to clean the collected data, removing duplicate information, blank items, and noisy data. Use the re library to format unstructured text, removing HTML tags, special characters, and irrelevant information; (1-4) Use NLTK for word segmentation and word form restoration. Stop word filtering should exclude industrial control hardware terms. Standardize numerical data and map supplier risk level and CVE score to a unified range.

[0032] (1-5) Fusion of ontology mapping and semantics.

[0033] Prepare an initial draft of the domain ontology, including core concepts such as: devices, components, interfaces, protocols, firmware, patches, vendors, delivery batches, CVEs, vulnerability patterns, geolocation, compliance constraints, certificates, and signature chains. The ontology supports subsequent automatic expansion modules, discovering new concepts through word vector clustering and entity co-occurrence statistics.

[0034] A hybrid mapping strategy, combining rule-driven and statistical learning, is employed to map cleaned heterogeneous data to an ontology concept space. The rule engine uses OWL / RIF rules to describe common patterns, while the statistical mapping uses semantic similarity and embedding distance to supplement uncovered patterns. The mapping results form standardized triples, and confidence, timestamp, and source fingerprint are calculated for each triple.

[0035] To support cross-language and cross-format entity alignment, an entity alignment pipeline is introduced. Entities with the same origin are uniformly identified through string similarity, multi-dimensional feature matching, and candidate merging strategies, while the source reference is retained for traceability.

[0036] Step 2: Identify the entities of the supply chain nodes contained in the document.

[0037] This invention employs a two-stage entity extraction process. Stage one involves high-recall rule / lexicon extraction, while stage two is precise deep learning extraction. The deep model utilizes the domain-adaptive fine-tuning Transformer series DeBERTa, and integrates Conditional Random Field (CRF) or span-based annotations at the sequence labeling layer to support nested entities. To handle cross-sentence / document entities, a core referential parsing mechanism is combined with a document-level context encoder.

[0038] For specific entity types, such as hardware interfaces JTAG / SWD / UART, chip models ARM Cortex-M3, protocol SWD programming, CVE numbers, firmware version numbers, signature fingerprints, supplier organizations, production batches, and delivery time windows, we define refined annotation specifications. Through an active learning mechanism and manual review, we form a closed-loop annotation system. After manual review, the model undergoes incremental fine-tuning to improve domain adaptability.

[0039] In one embodiment, the entity and relation extraction process of the present invention is as follows: Figure 4 As shown, it includes the following steps.

[0040] (2-1) Load the BERT model pre-trained on the industrial control corpus and combine it with the CRF sequence labeling method to perform command entity recognition on the text.

[0041] (2-2) Extract the supplier entity and the region where the supplier is located.

[0042] (2-3) Extract hardware operation feature entities, including debugging interface types UART and JTAG, and firmware burning methods ISP and SWD.

[0043] (2-4) Extract the physical components of the equipment, including the PLC module model, industrial chip model, and sensor model.

[0044] (2-5) Extract the entities with supply chain security attributes, including the supplier's risk level, whether it has ISO / IEC 62443 or ISO 9001 certification, and the supplier's compliance status.

[0045] (2-6) Extract the vulnerability entity, including CVE number, vulnerability exploitation probability score (CVSS), and vulnerability type.

[0046] Step 3: Extract the node relationships in the supply chain.

[0047] This invention employs Graph Attention Network (GAT) and multi-head self-attention mechanism for relation extraction, used to extract semantic dependencies, vulnerability propagation, physical adjacency, upstream and downstream relationships in the supply chain, signature / certificate chain relationships, etc. Relationship modeling supports hyperedge representation to express complex influence relationships; edge attributes include: confidence, timeliness, source credibility, attack surface metrics, and patch state vector.

[0048] In one embodiment, the relationship includes: hardware operation relationship, vulnerability propagation relationship, geopolitical risk relationship, supply relationship, and security attribute relationship.

[0049] Hardware operation relationships are used to describe the operational dependencies between hardware operation feature entities and device component entities. The hardware operation relationships include: the device component model relationship corresponding to the debugging interface type and the chip model relationship corresponding to the firmware burning method.

[0050] Vulnerability propagation relationships are used to describe the impact or propagation path of vulnerabilities between vulnerable entities and device component entities, and vendor entities. The vulnerability propagation relationships include: vulnerability-affected component relationships, vulnerability-sourced vendor relationships, and vulnerability co-occurrence relationships.

[0051] Geopolitical risk relationships are used to describe the geopolitical or regional risk dependence between the supplier's region and the supplier entity. These geopolitical risk relationships include: the relationship between regional risk level and supplier risk level, and the relationship between regional events and supplier compliance status.

[0052] Supply relationships are used to describe the supply or manufacturing dependencies between supplier entities and equipment component entities. These supply relationships include: supplier component production relationships, supplier chip supply relationships, and supplier delivery record corresponding component relationships.

[0053] Security attribute relationships are used to describe the security status association between supply chain security attribute entities and supplier entities. These security attribute relationships include: security certification relationships corresponding to supplier risk levels and certification system relationships corresponding to compliance status.

[0054] Step 4: Integrate entities and relationships to generate a knowledge graph of the industrial control equipment supply chain.

[0055] like Figure 5 As shown, this invention stores all extracted relations in a triplet structure, in the form of (entity 1, relation 1, entity 2), and writes them into a graph database, such as Neo4j, JanusGraph, or a graph framework based on TinkerPop. Each node / edge carries a meta-attribute vector, including confidence, timestamp, source, version, geographic label, availability index, etc. Simultaneously, a temporal index layer is established to support graph snapshot queries and temporal differential updates based on time windows.

[0056] To support rapid simulation and incremental updates, the system is designed with a caching strategy and tiered storage: hot data is stored in the memory acceleration layer, near-hot data is stored in the SSD index layer, and historical cold data is sharded and archived to object storage, providing the ability to backtrack and re-analyze.

[0057] Step 5: Analyze the industrial control equipment supply chain based on the knowledge graph to obtain the industrial control equipment supply chain analysis results.

[0058] (5-1) Detect transmission paths that conform to industrial control characteristics in the knowledge graph and set trigger conditions.

[0059] (5-2) Based on the entity nodes and their relationship types in the knowledge graph, construct a system from the supplier... Components Hardware features Vulnerability The directed transmission path of security attributes.

[0060] This invention generates the directed propagation path by establishing a propagation model on a knowledge graph. Specifically, this invention combines a temporal graph neural network (TNN) with a random walk algorithm to simulate the propagation of risk on multi-hop paths. For the path... Define the edge propagation probability. Where the edge propagation probability... The probability distribution is obtained by mapping the edge attribute vector through a Bayesian neural network trained on the probability mapping network. The mapping network integrates factors such as CVE exposure, patch status, delivery frequency, supplier historical event rate, geopolitical disturbance factor, and time decay function, and outputs a probability distribution with uncertainty estimation.

[0061] Next, Monte Carlo simulations were used to sample the given time window map N times, and the occurrence frequency, impact distribution, and confidence interval of critical paths and nodes were statistically analyzed to calculate expected loss and extreme value risk. Simultaneously, Bayesian updates were employed to fuse prior historical data with real-time observational monitoring to correct the posterior risk distribution.

[0062] (5-3) Assign a basic risk value to each node in the path. The basic risk value is determined based on the entity type, wherein: - The supplier node risk value is determined based on the supplier's risk level and compliance status; - The risk value of a device component node is calculated based on the number and severity of vulnerabilities associated with that component; - The risk value of hardware operation feature nodes is calculated based on the degree of interface exposure and firmware accessibility; - The risk value of a vulnerable node is determined based on its CVSS score and vulnerability type coefficient; - The risk value of supply chain security attribute nodes is calculated based on security certification level and historical event records.

[0063] (5-4) Assign a weight coefficient to each relation in the path. The weights reflect the transmission strength of the relationship, wherein: - Hardware operation relationship weights are calculated based on the component's dependency on the debugging interface; - The weight of vulnerability propagation relationships is determined based on the vulnerability's propagation potential and co-occurrence probability; - The weighting of geopolitical risk relationships is determined based on the regional risk level and supplier concentration.

[0064] (5-5) Calculate the total risk value of the comprehensive path The calculation formula is as follows: in, Let i be the risk value of the i-th entity in the path. The weight of the relationship associated with this entity. This represents the total number of path nodes. Let be the number of relationships of the i-th node.

[0065] (5-6) Normalize all path risk values ​​and apply them according to the set trigger threshold. Determine whether the risk triggering conditions have been met.

[0066] The threshold of this invention adopts an adaptive mechanism, taking into account historical alarm performance, current operation and maintenance resources and business SLA. When the risk value of a certain path crosses the adaptive threshold, a graded alarm is triggered and a set of suggested actions is generated.

[0067] (5-7) When the total risk value of the path reaches the triggering condition, the corresponding physical layer control command is automatically generated according to the type of the affected component or device in the path.

[0068] The physical layer control commands include: Device port components: disable or restrict debug interface access; Device firmware components trigger firmware locking, forced verification, and read-only mode, restricting the flashing of signed firmware. The device network component closes the external communication links of the supply chain-related devices at the industrial control gateway layer, thus restricting OTA upgrade channels. The equipment supply chain has temporarily suspended firmware updates or parts procurement processes from high-risk suppliers. The risk reporting instruction sends a high-risk path alarm message to the upper-level security management system. The following examples use PLC, smart camera, and automotive ECU as case studies for detailed explanation.

[0069] Example 1: Implementation process for PLC.

[0070] For PLC programmable logic controller devices, the system collects their design documents, manufacturing specifications, firmware images, chip data sheets, supplier delivery history, procurement records, and public vulnerability notices in parallel; it also performs static feature extraction of strings, symbol import / export, function hashing, and establishes a construction chain fingerprint for the firmware.

[0071] The domain-adapted BERT+CRF model extracts key entities: identifying JTAG debugging interface, SWD programming protocol, ARM Cortex-M3 chip model, patch number, CVE-2024-7883, etc.; and performs function-level fingerprint comparison of binary similarity to identify code fragment propagation across products.

[0072] Triples are formed in the knowledge graph, such as “SWD burning protocol — dependent — JTAG interface”, “CVE-2024-7883 — impact — ARM Cortex-M3”, “vendor X — located in — high-risk area”, etc. The triples are accompanied by timestamps and confidence vectors and persisted to the graph database.

[0073] A dynamic graph computation engine, such as the TinkerPop-based framework, is used to perform random walks and combine them with a temporal GNN to calculate path propagation probability and influence strength; when the path "CVE-2024-7883" is... ARM Cortex-M3 A "High Risk - Blocking" level alarm is triggered when the risk value of the PLC controller exceeds the adaptive threshold and the patch is unavailable.

[0074] The system automatically generates a set of physical layer blocking instructions. Exemplary actions include: disabling unauthorized programming interfaces through the device management agent; issuing trusted firmware signed with an HSM and triggering mandatory verification during secure boot; whitelisting PLC access to the upper-level SCADA system at the switch level; and isolating critical I / O channels if the device supports remote relays. For any mandatory action, the system first simulates it in a digital twin and executes it after obtaining manual or rule-based automatic permission.

[0075] Provides a federated learning variant for cross-enterprise scenarios: each participant trains an entity extraction and probability mapping model locally, exchanges model weights or cryptographic gradients, and uses differential privacy and secure multi-party computation to avoid compliance conflicts caused by sharing raw data.

[0076] In a cloud-edge hybrid deployment, latency-sensitive detection modules, such as interface abuse detection, are deployed on the on-site edge bastion host, while offline large-scale training and graph indexing are deployed in the cloud. The two are synchronized and aggregated through a secure channel to ensure the convergence of the federated policy.

[0077] The system generates immutable audit logs for every action and model update, which can be implemented based on blockchain or verifiable log technology. The audit logs include action signatures, pre- and post-execution snapshots, rollback pointers, and the responsible person's signature. All critical actions undergo consistency checks and regression tests before and after execution to ensure business continuity.

[0078] It should be noted that this method is not limited to PLCs, but can be extended to smart grid substations, building automation, rail transit signals, automotive ECUs, medical equipment and aerospace ground stations, etc. The subject and risk indicators can be expanded for different fields. For example, frequency / voltage stability indicators can be added for power scenarios, and CAN bus message mode features can be added for automotive scenarios.

[0079] To adapt to actual engineering deployments, it provides multi-level access control, audit and compliance modules, legal and compliance strategy engines, and external emergency response interfaces, such as CERT / ISA / local regulatory agency interfaces. It also provides pluggable operation dashboards and drill modules for operation and maintenance personnel training and emergency response drills.

[0080] Example 2: Implementation process for smart cameras.

[0081] Data Acquisition and Preprocessing. This embodiment employs an adaptive crawler system based on deep reinforcement learning to collect data from multiple channels, including technical white papers, firmware update logs, and vulnerability disclosure platforms for smart camera products. Simultaneously, it acquires compliance documents, ISO certification status, geopolitical risk indicators, and historical delivery records from image sensor chip and Wi-Fi communication module suppliers. The acquired data undergoes feature extraction, missing value imputation, and anomaly detection through a Pandas and NumPy-driven data pipeline, and a risk metric is standardized using the Z-score method. For multimodal data such as text, images, and firmware binary data, PCA dimensionality reduction and t-SNE visualization are additionally performed to aid in anomaly clustering.

[0082] Semantic parsing and entity recognition. A hybrid architecture combining BERT and Bi-LSTM is used for named entity recognition. Key entities such as UART debugging interface, OTA upgrade mechanism, ARM Cortex-A7 graphics processing unit, IEEE 802.11ac wireless module, ISO 27001 certification status, supplier risk level, and CVE-2024-10929 are extracted from the collected data. For firmware images, function fingerprinting and symbolic call relationship analysis are performed to associate potential vulnerabilities with hardware components.

[0083] Relationship modeling and knowledge graph construction. Multi-level semantic relationship extraction is performed using a Graph Attention Network (GAT), generating weighted triples, such as "OTA upgrade mechanism". use UART interface, CVE-2024-10929 use "ARM Cortex-A7", "Wireless Module Supplier" Belonging to "High-risk countries". These triples are imported into the JanusGraph graph database to form a dynamically updated knowledge graph. The edge attributes of the knowledge graph include confidence, source credibility, timeliness, patch status, etc., for subsequent inference.

[0084] Dynamic risk simulation and mitigation. Risk path simulation is performed on the knowledge graph based on a temporal graph neural network, combined with Monte Carlo sampling to calculate the propagation probability. When "CVE-2024-10929"... ARM Cortex-A7 When the risk value of a "smart camera" path exceeds an adaptive threshold, the system triggers handling strategies, including: disabling the OTA upgrade port, flashing firmware with a cryptographic signature, and physically isolating the UART debugging interface. Simultaneously, when high-risk national suppliers are detected participating in critical components, fuzzy logic reasoning is used to increase the overall risk level of the device, and a supply chain early warning report is automatically generated and submitted to the operations and compliance team.

[0085] Example 3: Quantitative analysis and proactive protection of supply chain security risks for automotive ECUs.

[0086] Data Acquisition and Distributed Processing. A multi-threaded crawler engine was used to collect ECU design specifications, automotive-grade chip technical documents, and AUTOSAR compatibility reports. Simultaneously, supplier ISO 26262 functional safety certification status, delivery reliability indicators, and geopolitical risk scores were obtained from the SAE industry database. All collected data was imported into a Hadoop-driven data lake architecture for distributed cleaning, format conversion, and metadata annotation. Semantic disambiguation algorithms, based on contextual embedding similarity, were used to eliminate terminological ambiguity and improve data consistency.

[0087] Entity Recognition and Risk Labeling. Using a pre-trained BERT model combined with domain-adaptive fine-tuning, entity extraction is performed on ECU documentation to identify CAN bus debugging interfaces, OTA upgrade protocols, automotive-grade MCUs, Ethernet communication chips, power management ICs, ASIL levels, and supplier risk levels, which are then mapped to the CVE-2023-28895 automotive communication hijacking attack vulnerability. The certification status and operating region of each supplier are also labeled.

[0088] Relationship modeling and multi-model database storage. A transformer encoder-decoder architecture is employed to extract communication dependencies, vulnerability propagation, and geopolitical risk relationships, forming a model similar to an "OTA upgrade protocol." rely CAN bus interface, CVE-2023-28895 Influence "Automotive-grade MCU", "Tier-1 supplier" Operating in The database identifies triples representing "high-risk areas" and stores the relationships in the ArangoDB multi-model database. This database supports graph, document, and key-value multi-modal queries, facilitating cross-dimensional joint retrieval.

[0089] Risk analysis and proactive protection. A reinforcement learning-driven risk decision engine performs path analysis on a real-time knowledge graph. When "CVE-2023-28895" is detected... Automotive-grade MCU ECU When the risk value of the "vehicle network" path exceeds a preset threshold, the system automatically generates a set of physical layer handling instructions. For example, enabling a secure boot mechanism to restrict unauthorized OTA updates, flashing integrity protection firmware, and physically isolating the CAN bus interface. At the same time, it combines Bayesian network inference to assess the potential impact of geopolitical risks on the vehicle supply chain, dynamically adjusts the vehicle risk rating, and triggers a cross-domain early warning mechanism.

[0090] This invention can be extended to fields such as smart home IoT nodes, smart meters, medical image processing terminals, rail transit signaling systems, and aerospace embedded computing platforms, loading exclusive ontology and compliance indicator libraries according to different scenarios.

[0091] In terms of deployment mode, a cloud-edge-device collaborative architecture can be adopted, with edge nodes performing low-latency detection and local processing, the cloud completing large-scale graph inference and model training, and the device side performing interface-level physical blocking. The three communicate with each other through encrypted channels to achieve a dynamic risk prevention and control closed loop.

[0092] In summary, through combinations and variations of the above embodiments, this invention achieves a complete technical route from multi-source data acquisition, semantic fusion, deep entity and relation extraction, dynamic graph-based risk modeling, probabilistic risk propagation deduction, to cross-layer automatic handling and closed-loop optimization based on security reinforcement learning. This route has significant advantages in improving risk detection accuracy, reducing false alarm rates, increasing handling robustness, and ensuring compliance. Through specific implementations in different application scenarios, such as PLC controllers, IoT smart cameras, and automotive ECUs, this invention demonstrates the broad applicability and significant advantages of the knowledge graph-based industrial control equipment supply chain risk path identification and blocking method. It further verifies the universality and scalability of this invention in multimodal data acquisition, semantic parsing, dynamic graph modeling, probabilistic deduction, and reinforcement learning-based handling. Therefore, this invention not only solves problems such as risk path concealment, delayed threat response, and lack of physical layer handling methods in existing technologies, but also has cross-industry and cross-equipment type promotion value.

[0093] It should be understood that the above embodiments are only used to illustrate the principles and effects of the present invention, and not to limit its scope of protection; without departing from the core concept of the present invention, those skilled in the art can make various modifications and equivalent substitutions to its form and steps, and all such modifications and substitutions should fall within the scope of protection of the present invention.

Claims

1. A supply chain analysis method for industrial control equipment based on natural language processing technology, characterized in that, The method includes: Collect information on the industrial control equipment supply chain; Extract entities and relationships from the industrial control equipment supply chain information; wherein, the entities include: supplier entities, supplier location regions, hardware operation characteristic entities, equipment component entities, supply chain security attribute entities, and vulnerability entities, and the relationships include: hardware operation relationships, vulnerability propagation relationships, geopolitical risk relationships, supply relationships, and security attribute relationships; Construct a knowledge graph of the industrial control equipment supply chain based on the entities and relationships described above; The analysis is performed based on the knowledge graph of the industrial control equipment supply chain, and when the analysis results trigger risk triggering conditions, the corresponding physical layer control command is generated.

2. The method according to claim 1, characterized in that, Collect information on the industrial control equipment supply chain, including: Using the requests and BeautifulSoup libraries in Python, we collected initial supply chain information from the design, production, and manufacturing documents of industrial control equipment, as well as from publicly available data sources, through web scraping technology. For the initial supply chain information of industrial control equipment manufacturers' supplier list, the Scrapy framework is used to crawl the web to obtain supplier background information, product descriptions, delivery records and market analysis reports from supplier websites and public databases. Then, the initial supply chain information is supplemented to obtain industrial control equipment supply chain information.

3. The method according to claim 1, characterized in that, After collecting information on the industrial control equipment supply chain, the following is also included: The pandas library is used to clean the industrial control equipment supply chain information. The cleaning process includes removing duplicate information, blank items, and noisy data, and using the re library to format unstructured text. The formatting process includes removing HTML tags, special characters, and irrelevant information. The NLTK technology was used to perform word segmentation, word form restoration, stop word filtering, and numerical data standardization on the cleaned information.

4. The method according to claim 1, characterized in that, Extract entities from the industrial control equipment supply chain information, including: Load a BERT model pre-trained on an industrial control corpus and combine it with a CRF sequence labeling algorithm to perform entity recognition on industrial control equipment supply chain information; Obtain the supplier entity and the region where the supplier is located from the entity recognition results; The hardware operation feature entities are obtained from the entity recognition results. The hardware operation feature entities include: debugging interface type and firmware burning method. The device component entities are obtained from the entity recognition results. The device component entities include: device port components, device firmware components, device network components, and device supply chain. Obtain supply chain security attribute entities from the entity identification results. The supply chain security attribute entities include: supplier risk level, supplier compliance status, and whether they have ISO / IEC 62443 or ISO 9001 certification. The vulnerability entity is obtained from the entity identification results. The vulnerability entity includes: CVE number, vulnerability exploitation probability score (CVSS), and vulnerability type.

5. The method according to claim 1, characterized in that, The hardware operation relationship is used to describe the operation dependency relationship between hardware operation feature entities and device component entities. The hardware operation relationship includes: the device component model relationship corresponding to the debug interface type and the chip model relationship corresponding to the firmware burning method. The vulnerability propagation relationship is used to describe the vulnerability impact or propagation path between the vulnerability entity and the device component entity and the supplier entity. The vulnerability propagation relationship includes: the vulnerability-affected component relationship, the vulnerability-sourced supplier relationship, and the vulnerability co-occurrence relationship. The geopolitical risk relationship is used to describe the geopolitical or regional risk dependence between the supplier's region and the supplier entity. The geopolitical risk relationship includes: the relationship between regional risk level and supplier risk level, and the relationship between regional events and supplier compliance status. Supply relationships are used to describe the supply or manufacturing dependencies between supplier entities and equipment component entities. These supply relationships include: supplier component production relationships, supplier chip supply relationships, and supplier delivery record corresponding component relationships. Security attribute relationships are used to describe the security status association between supply chain security attribute entities and supplier entities. These security attribute relationships include: security certification relationships corresponding to supplier risk levels and certification system relationships corresponding to compliance status.

6. The method according to claim 1, characterized in that, Based on the knowledge graph of the industrial control equipment supply chain, analysis is performed, and when the analysis results trigger risk triggering conditions, corresponding physical layer control commands are generated, including: Detect transmission paths that match the characteristics of industrial control systems in the knowledge graph and set risk triggering conditions; Based on the knowledge graph, a directed transmission path is constructed from supplier entity → equipment component entity → hardware operation feature entity → vulnerability entity → supply chain security attribute entity; Assign a base risk value to each node in the path. The basic risk value of the supplier entity is determined based on the supplier's risk level and compliance status. The risk value of the device component entity is calculated based on the number and severity of vulnerabilities associated with the device component entity. The risk value of the hardware operation feature entity is calculated based on the degree of interface exposure and firmware accessibility. The risk value of the vulnerability entity is determined based on its CVSS score and vulnerability type coefficient. The risk value of the supply chain security attribute entity is calculated based on the security certification level and historical event records. Assign a weight coefficient to each relation in the path. The weighting coefficient of the hardware operation relationship is calculated based on the component's dependence on the debugging interface; the weighting coefficient of the vulnerability propagation relationship is determined based on the vulnerability's propagation and co-occurrence probability; and the weighting coefficient of the geopolitical risk relationship is determined based on the regional risk level and supplier concentration. Overall Calculation of Path Total Risk Value ,in, This represents the total number of path nodes. For the first The number of relationships between nodes; Total risk value for all paths Normalization is performed, and the result is based on the set trigger threshold. Determine whether the normalized total path risk value meets the risk triggering condition; When the normalized total risk value of the path reaches the risk triggering condition, the corresponding physical layer control command is automatically generated according to the type of the affected device component entity in the path.

7. The method according to claim 1, characterized in that, When the affected device component entity type is a device port component, the physical layer control command includes: disabling or restricting debug interface access; When the affected device component entity type is a device firmware component, the physical layer control command includes: triggering firmware lock, forcing verification and read-only mode, and restricting the flashing of signed firmware; When the affected device component entity type is a device network component, the physical layer control command includes: shutting down the external communication link of the supply chain associated device at the industrial control gateway layer and restricting the OTA upgrade channel; In cases where the affected device component entity type is the device supply chain, the physical layer control command includes: temporarily suspending firmware updates or parts procurement processes from high-risk vendors; The physical layer control command also includes: generating a risk reporting instruction, which is used to send high-risk path alarm information to the upper-layer security management system.

8. A supply chain analysis system for industrial control equipment based on natural language processing technology, characterized in that, The system includes: The information collection module is used to collect supply chain information for industrial control equipment. The information extraction module is used to extract entities and relationships in the industrial control equipment supply chain information; wherein, the entities include: supplier entities, supplier location regions, hardware operation characteristic entities, equipment component entities, supply chain security attribute entities, and vulnerability entities, and the relationships include: hardware operation relationships, vulnerability propagation relationships, geopolitical risk relationships, supply relationships, and security attribute relationships; The graph construction module is used to construct a knowledge graph of the industrial control equipment supply chain based on the entities and relationships. The graph analysis module is used to perform analysis based on the industrial control equipment supply chain knowledge graph, and generate corresponding physical layer control commands when the analysis results trigger risk triggering conditions.

9. An electronic device, characterized in that, The electronic device includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the industrial control equipment supply chain analysis method based on natural language processing technology as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the industrial control equipment supply chain analysis method based on natural language processing technology as described in any one of claims 1-7.