A security management method and system based on digital security twinning
By constructing a security management method based on digital security twins, and utilizing symplectic manifold boundaries and symplectic geometric integral algorithms, high-fidelity data fusion and self-healing capabilities for complex heterogeneous networks are achieved. This solves the problems of low data fusion fidelity and insufficient system self-healing capabilities in existing technologies, thereby improving the reliability and sensitivity of security management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 张琴
- Filing Date
- 2026-03-25
- Publication Date
- 2026-06-26
AI Technical Summary
Existing security management solutions lack deep closed-loop coupling constraints of physical energy fields and algebraic topology when facing complex heterogeneous networks and extreme adversarial environments. This results in low fidelity of cross-domain heterogeneous data fusion, easy divergence and collapse in long-term continuous situational simulations, and insufficient inherent anti-interference and self-healing capabilities of the system.
By collecting multidimensional security state features of the digital security twin, an initial dynamic tensor is constructed. Projection denoising is performed using symplectic manifold boundaries, the dominant singular value spectrum is extracted and mapped to nonlinear cooperative security potential energy, a fractional Hamiltonian dynamic evolution model is constructed, and a symplectic geometric integral algorithm is used for discrete derivation to generate a security management strategy. The predicted phase space state is then fed back to the next calculation cycle to form a security management closed loop.
It significantly improves the data fidelity of digital security twins in complex adversarial environments, enhances the system's sensitivity to micro-network connectivity anomalies and cross-domain security collaborative analysis capabilities, and ensures high reliability and self-healing capabilities for security management throughout the entire lifecycle.
Smart Images

Figure CN122293380A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security and digital twin technology, specifically a security management method and system based on digital security twins. Background Technology
[0002] With the deep integration of Industrial Internet and Internet of Things (IoT) technologies, digital twin technology is gradually extending into the security field, evolving into the emerging dynamic defense concept of digital security twins. Digital security twins aim to achieve security situational awareness, simulation, and control of complex heterogeneous networks encompassing both information technology (IT) and operational technology (OT) by constructing a virtual, high-fidelity mapping of physical entities. However, when facing increasingly complex network adversarial environments, existing security management solutions are gradually revealing significant limitations in their underlying architecture and evolving algorithms.
[0003] In the fusion processing stage of multi-source heterogeneous data, traditional digital twin systems usually rely on middleware to perform forced protocol conversion or static data format normalization operations. While forcibly smoothing out the differences in data structure among subsystems, this data preprocessing method also severely strips away the original physical semantics and micro-topological features of the underlying devices. When extremely covert topology probing or slow penetration scanning occurs in the network, the system is unable to keenly capture these weak abnormal signals because the connectivity algebraic features at the micro level are filtered or lost during format conversion, thus greatly limiting the cross-domain security collaborative analysis capability.
[0004] At the level of security situation analysis and prediction, most existing security management technologies are limited to rule matching based on static feature libraries or isolated statistical anomaly detection. This passive defense model lacks a macroscopic characterization of the global physical energy transmission characteristics of the entire network system and cannot transform discrete network events into continuous dynamic evolution processes. Therefore, traditional models are extremely difficult to effectively depict the long-range memory effect and slow evolution trajectory inherent in complex attack methods such as advanced persistent threats (APTs), resulting in the system's defense strategy always being in a state of delayed response and unable to achieve advanced situation prediction and proactive intervention.
[0005] Meanwhile, real-world physical network adversarial environments are often rife with network channel congestion, high-frequency data packet loss, and malicious data injection by attackers. Traditional situational simulation numerical models exhibit extremely poor robustness when encountering such extreme disturbances. When the probe data input to the model is extremely scarce or contaminated by high-dimensional noise, conventional solution algorithms such as gradient descent will diverge due to the rapid accumulation of computational errors, even causing the entire simulation system to collapse completely. Existing architectures lack an endogenous reverse constraint mechanism based on physical conservation laws, making it impossible to effectively identify and filter high-fidelity noise outside the physical boundaries at the data aggregation front end, or to ensure the geometric stability of the system's long-term simulation at the evolution back end. Ultimately, this results in the reliability and self-healing capabilities of digital security twin systems in complex, high-intensity adversarial scenarios failing to meet actual security requirements. Therefore, this invention designs a security management method and system based on digital security twins to address the aforementioned problems. Summary of the Invention
[0006] To address the shortcomings of existing technologies, this invention provides a security management method and system based on digital security twins. It solves the problems of low fidelity of cross-domain heterogeneous data fusion, easy divergence and collapse of long-term situational continuous extrapolation, and insufficient inherent anti-interference and self-healing capabilities of existing security management schemes when facing complex heterogeneous networks and extreme adversarial environments, due to the lack of deep closed-loop coupling constraints of physical energy fields and algebraic topology.
[0007] To achieve the above objectives, the present invention provides the following technical solution: a security management method based on digital security twins, comprising the following steps: S1. First, collect the multidimensional security state characteristics of each heterogeneous subsystem in the digital security twin, and construct an initial dynamic tensor based on the multidimensional security state characteristics in the current calculation cycle; S2. Then, the symplectic manifold boundary fed back from the previous calculation cycle is obtained. The initial dynamic tensor is projected and denoised using the symplectic manifold boundary to obtain a high-fidelity tensor. The high-fidelity tensor is then decomposed to extract the dominant singular value spectrum of the high-fidelity tensor. S3. Map the dominant singular value spectrum to the nonlinear cooperative security potential between the heterogeneous subsystems, and combine the multidimensional security state characteristics of the heterogeneous subsystems with the nonlinear cooperative security potential to construct the fractional Hamiltonian dynamic evolution model of the digital security twin. S4. The fractional Hamiltonian dynamic evolution model is discretely derived using the symplectic geometric integral algorithm to solve for the predicted phase space state of the digital security twin in the next calculation cycle, and a security management strategy for the digital security twin is generated based on the predicted phase space state. S5. Finally, the security management strategy is executed, and the predicted phase space state is stretched into a new symplectic manifold boundary. The new symplectic manifold boundary is fed back to the next calculation cycle as the boundary condition for the projection denoising of the newly constructed initial dynamic tensor in the next calculation cycle, so as to realize the security management closed loop of the digital security twin.
[0008] Preferably, the step of collecting multidimensional security state features of each heterogeneous subsystem in the digital security twin, and constructing an initial dynamic tensor based on the multidimensional security state features in the current computation cycle, includes: Within the current time window, the network traffic characteristics, physical device status, and process call data of the heterogeneous subsystem are acquired as the multidimensional security status characteristics. The multidimensional security state features are mapped to an initial dynamic tensor of multiple orders according to the feature dimensions, wherein the order of the initial dynamic tensor is consistent with the total number of feature dimensions, and the length of each dimension of the initial dynamic tensor corresponds to the length of each feature dimension.
[0009] Preferably, the step of obtaining the symplectic manifold boundary fed back from the previous calculation cycle, and using the symplectic manifold boundary to perform projection denoising on the initial dynamic tensor to obtain a high-fidelity tensor, includes: Extract the space formed by the symplectic manifold boundary fed back from the previous calculation cycle; Calculate the topological projection distance from the initial dynamic tensor to the space; When the topological projection distance is greater than the set tolerance threshold, noise data outside the space is removed by the orthogonal projection operator, and the tensor processed by the orthogonal projection operator is output as the high-fidelity tensor.
[0010] Preferably, decomposing the high-fidelity tensor to extract the dominant singular value spectrum of the high-fidelity tensor includes: Perform high-order tensor singular value decomposition on the high-fidelity tensor to extract the core tensor; Obtain the set of singular values generated after the high-fidelity tensor is decomposed and arranged in descending order of numerical values. Cut off the set of singular values according to the set cutoff value to obtain the dominant singular value spectrum.
[0011] Preferably, mapping the dominant singular value spectrum to a nonlinear cooperative security potential among the heterogeneous subsystems includes: Calculate the logarithmic decay rate based on the adjacent singular values of the corresponding subsystem dimension in the dominant singular value spectrum; The logarithmic decay rate is input into a preset nonlinear scaling function to obtain the dynamic scaling coefficient; A basic connectivity basis function is constructed using the basic network topology of the digital security twin and the generalized security coordinates of the heterogeneous subsystem; Multiplying the dynamic scaling coefficient by the basic connectivity basis function yields the nonlinear cooperative security potential between the corresponding heterogeneous subsystems.
[0012] Preferably, by combining the multidimensional security state characteristics of each heterogeneous subsystem with the nonlinear cooperative security potential, a fractional-order Hamiltonian dynamic evolution model of the digital security twin is constructed, including: Obtain the generalized safety momentum and allocated virtual mass of each heterogeneous subsystem, and calculate the kinetic energy term of each heterogeneous subsystem; Obtain the local intrinsic security potential of each of the heterogeneous subsystems based on the multidimensional security state characteristics; The global Hamiltonian energy function characterizing the global state of the digital security twin is obtained by summing the kinetic energy term of all the heterogeneous subsystems, the local intrinsic security potential energy, and the nonlinear cooperative security potential energy among the heterogeneous subsystems.
[0013] Preferably, the fractional-order Hamiltonian dynamic evolution model for constructing the digital security twin further includes: Introduce fractional calculus operators of a predetermined order; Using the fractional-order calculus operator, the partial derivatives of the global Hamiltonian energy function with respect to the generalized safety momentum and the generalized safety coordinates are calculated to construct a continuous set of fractional-order dynamic equations, which are then used as the fractional-order Hamiltonian dynamic evolution model.
[0014] Preferably, the step of using a symplectic geometric integral algorithm to discretize the fractional-order Hamiltonian dynamic evolution model, solving for the predicted phase space state of the digital security twin in the next calculation cycle, and generating a security management strategy for the digital security twin based on the predicted phase space state includes: The fractional-order dynamic equations are discretized and solved using a symplectic geometric integral operator that preserves area characteristics, to obtain the predicted phase space state corresponding to the next calculation cycle. Calculate the energy difference between the global Hamiltonian in the predicted phase space state and the baseline steady-state Hamiltonian of the system; When the energy difference is greater than the set danger warning threshold, the safety management strategy is generated and output along the fastest gradient descent path of the predicted phase space state.
[0015] Preferably, the step of stretching the predicted phase space state into a new symplectic manifold boundary and feeding the new symplectic manifold boundary back to the next calculation cycle as a boundary condition for projective denoising of the newly constructed initial dynamic tensor in the next calculation cycle includes: Extract the predicted generalized safety coordinates and predicted generalized safety momentum from the predicted phase space state corresponding to the next calculation cycle; The predicted generalized safety coordinates and the predicted generalized safety momentum are stretched into the new symplectic manifold boundary for the current calculation period; The new symplectic manifold boundary is stored in a cache as the orthogonal projection constraint space when processing the newly constructed initial dynamic tensor in the next computation cycle.
[0016] Preferably, a security management system based on digital security twins includes: The tensor construction module is used to collect multi-dimensional security state characteristics of each heterogeneous subsystem in the digital security twin, and construct an initial dynamic tensor based on the multi-dimensional security state characteristics in the current calculation cycle. The closed-loop denoising and decomposition module is used to obtain the symplectic manifold boundary fed back from the previous calculation cycle, use the symplectic manifold boundary to project and denoise the initial dynamic tensor to obtain a high-fidelity tensor, and decompose the high-fidelity tensor to extract the dominant singular value spectrum of the high-fidelity tensor. The potential energy mapping module is used to map the dominant singular value spectrum into a nonlinear cooperative security potential energy between the heterogeneous subsystems. The dynamic model construction module is used to combine the multidimensional security state characteristics of each heterogeneous subsystem with the nonlinear cooperative security potential energy to construct a fractional-order Hamiltonian dynamic evolution model of the digital security twin. The structure-preserving deduction and strategy generation module is used to perform discrete deduction on the fractional-order Hamiltonian dynamic evolution model using the symplectic geometric integral algorithm, solve for the predicted phase space state of the digital security twin in the next calculation cycle, and generate a security management strategy for the digital security twin based on the predicted phase space state. The boundary feedback and execution module is used to execute the security management strategy, stretch the predicted phase space state into a new symplectic manifold boundary, and feed the new symplectic manifold boundary back to the closed-loop denoising and decomposition module as the boundary condition for projective denoising of the newly constructed initial dynamic tensor in the next calculation cycle.
[0017] This invention provides a security management method and system based on digital security twins. It has the following beneficial effects: 1. This invention establishes an intrinsic anti-interference mechanism that does not rely on a static feature library by projecting the initial dynamic tensor onto the symplectic manifold boundary fed back from the previous calculation cycle. This mechanism can accurately identify and forcibly use orthogonal projection operators to remove high-dimensional noise and maliciously forged injected data that are outside the physical boundary, significantly improving the high fidelity of the underlying data of the digital security twin in complex adversarial environments.
[0018] 2. This invention uses a symplectic geometric integral algorithm to discretize the dynamic model and feeds back the predicted phase space state as a new symplectic manifold boundary to the next calculation cycle, thus constructing a system self-healing closed loop with strong resilience. At the same time, the geometric boundary at the end of the deduction is fed back to the front-end data filtering stage, ensuring high reliability of safety management throughout the entire life cycle.
[0019] 3. This invention breaks through the bottleneck of loss of underlying physical semantics caused by traditional fixed protocol conversion by collecting multidimensional security state features of various heterogeneous subsystems and constructing them into an initial dynamic tensor. By utilizing high-dimensional algebraic space, fragmented cross-protocol network traffic, physical device status and process calls are directly transformed into a unified topology base, thereby establishing a consistent and complete mathematical expression for complex heterogeneous security networks while preserving the original microscopic features.
[0020] 4. This invention maps the dominant singular value spectrum extracted by high-fidelity tensor decomposition into nonlinear cooperative security potential energy between heterogeneous subsystems, achieving deep cross-domain coupling from pure data algebraic features to macroscopic physical evolution models. This mechanism enables extremely hidden network structural anomalies (such as algebraic spectrum distribution fine-tuning caused by slow topology probing and penetration scanning) within digital twins to be instantly amplified and transformed into drastic distortions of physical potential terrain, greatly enhancing the system's sensitivity to microscopic network connectivity anomalies and its cross-domain security cooperative analysis capabilities.
[0021] 5. This invention constructs a fractional Hamiltonian dynamic evolution model by combining the multidimensional security state characteristics of various heterogeneous subsystems with nonlinear cooperative security potential energy. By introducing fractional calculus operators, it not only effectively characterizes the long-range memory and slow evolution effects unique to advanced persistent threats (APTs), but also integrates the originally discrete and isolated cybersecurity events within the entire system into a continuous physical motion equation with global energy conduction characteristics, laying a solid theoretical foundation for high-dimensional security situation prediction and deduction. Attached Figure Description
[0022] Figure 1 This is one of the schematic diagrams of the method flow of the present invention; Figure 2 This is a second schematic diagram of the method flow of the present invention; Figure 3This is the third schematic diagram of the method flow of the present invention; Figure 4 This is the fourth schematic diagram of the method flow of the present invention; Figure 5 This is the fifth schematic diagram of the method flow of the present invention; Figure 6 This is the sixth schematic diagram of the method flow of the present invention; Figure 7 This is a schematic diagram of the system flow of the present invention. Detailed Implementation
[0023] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0024] Please see the appendix Figure 1 -Appendix Figure 6 This invention provides a security management method based on digital security twins, comprising the following steps: S1. First, collect the multidimensional security state features of each heterogeneous subsystem in the digital security twin, and construct an initial dynamic tensor based on the multidimensional security state features in the current calculation cycle. This includes: within the current time window, acquiring the network traffic features, physical device status, and process call data of the heterogeneous subsystems as multidimensional security state features; mapping the multidimensional security state features to a multi-order initial dynamic tensor according to the feature dimensions, wherein the order of the initial dynamic tensor is consistent with the total number of feature dimensions, and the length of each dimension of the initial dynamic tensor corresponds to the length of each feature dimension. Specifically, within the time window of the current calculation cycle Inside, the system collects a full dataset of the digital security twin through deployed probes. The invention addresses the multidimensional security state characteristics of heterogeneous subsystems (e.g., servers on the IT side and programmable logic controllers (PLCs) on the OT side). These multidimensional security state characteristics include network traffic characteristics, physical device status (e.g., CPU utilization, temperature), and process call data. To overcome the bottleneck of traditional format conversion, this invention does not perform forced semantic alignment but instead directly maps the multidimensional security state characteristics of each subsystem to an initial dynamic tensor in a higher-order topological space according to their inherent dimensional attributes. Specifically, building Initial dynamic tensor of order ,in The total number of feature dimensions. Indicates the first The length of each feature dimension, this tensor quantization process enables heterogeneous data to obtain a unified algebraic mathematical representation while preserving the original physical microscopic features.
[0025] S2. Subsequently, the symplectic manifold boundary fed back from the previous computation cycle is obtained. The initial dynamic tensor is then projected and denoised using the symplectic manifold boundary to obtain a high-fidelity tensor. The high-fidelity tensor is then decomposed to extract its dominant singular value spectrum. This process includes: extracting the space formed by the symplectic manifold boundary fed back from the previous computation cycle; calculating the topological projection distance from the initial dynamic tensor to the space; and when the topological projection... When the shadow distance exceeds a set tolerance threshold, noise data outside the space is removed by orthogonal projection operator, and the tensor processed by orthogonal projection operator is output as a high-fidelity tensor. The high-fidelity tensor is decomposed to extract the dominant singular value spectrum of the high-fidelity tensor, including: performing high-order tensor singular value decomposition on the high-fidelity tensor to extract the core tensor; obtaining the set of singular values generated by the high-fidelity tensor after decomposition in descending order of values; truncating the set of singular values according to a set cutoff value to obtain the dominant singular value spectrum. Specifically, due to network jitter or malicious data injection attacks that often exist in the physical environment, directly analyzing the initial dynamic tensor can easily lead to misjudgments. Therefore, this invention introduces a noise reduction mechanism based on the conservation law of precursor physics. First, the system extracts the noise from the previous calculation cycle. ( The space formed by the symplectic manifold boundary of the feedback (for discrete sampling periods) Then calculate the current initial dynamic tensor. To that space Topological projection distance The calculation formula is as follows: ; In the formula, For orthogonal projection operators, For Frobenius norm, if Greater than the system's set tolerance threshold If the newly collected data contains high-dimensional noise (such as forged messages) that does not conform to the law of conservation of physical energy of the system, then the orthogonal projection operator is used. Forcefully remove data outside the boundary and output a high-fidelity tensor. Next, the high-fidelity tensor Perform high-order tensor singular value decomposition (t-SVD) to reduce dimensionality without losing the core structure and extract the core tensor. Simultaneously, it obtains the set of singular values generated during the decomposition, arranged in descending order of numerical value, and determines the cutoff value based on the system settings. , cut off Each singular value constitutes the dominant singular value spectrum set. This dominant singular value spectrum encapsulates the algebraic topological essence of the current global network. Hidden network structural anomalies within a digital twin (such as slow topology probing scans) can lead to fine-tuning of the tensor-dominant singular value distribution. This invention addresses this by using a set of dominant singular value spectra. Mapped to heterogeneous subsystems With subsystem Nonlinear cooperative security potential between The mapping equation is as follows: ; In the formula, and Subsystems With subsystem The generalized safety coordinates (scalars that characterize its safety state). and For set The logarithm of the ratio of adjacent singular values in the corresponding dimension. That is, the logarithmic decay rate; For the preset non-linear scaling function, This is the dynamic scaling factor; Basic connectivity basis functions The adjacency weights, determined by the underlying network topology of the digital security twin, cause the micro-offsets of algebraic singularities to be instantaneously amplified into distortions of macroscopic physical potential terrain.
[0026] S3. Map the dominant singular value spectrum to nonlinear cooperative security potential between heterogeneous subsystems. Combining the multidimensional security state characteristics and nonlinear cooperative security potential of each heterogeneous subsystem, construct a fractional-order Hamiltonian dynamic evolution model of the digital security twin. This includes: calculating the logarithmic decay rate based on adjacent singular values of the corresponding subsystem dimension in the dominant singular value spectrum; inputting the logarithmic decay rate into a preset nonlinear scaling function to obtain dynamic scaling coefficients; constructing basic connectivity basis functions using the basic network topology of the digital security twin and the generalized security coordinates of the heterogeneous subsystems; multiplying the dynamic scaling coefficients by the basic connectivity basis functions to obtain the corresponding nonlinear cooperative security potential between each heterogeneous subsystem; and constructing a digital security twin model by combining the multidimensional security state characteristics and nonlinear cooperative security potential of each heterogeneous subsystem. The fractional-order Hamiltonian dynamic evolution model of the full digital twin includes: obtaining the generalized safety momentum and allocated virtual mass of each heterogeneous subsystem, and calculating the kinetic energy term of each heterogeneous subsystem; obtaining the local intrinsic safety potential energy of each heterogeneous subsystem based on the multidimensional safety state characteristics; summing the kinetic energy term, local intrinsic safety potential energy, and nonlinear cooperative safety potential energy among all heterogeneous subsystems to obtain the global Hamiltonian energy function characterizing the global state of the digital security twin, and constructing the fractional-order Hamiltonian dynamic evolution model of the digital security twin; and further includes: introducing a fractional-order calculus operator of a preset order; using the fractional-order calculus operator to calculate the partial derivatives of the global Hamiltonian energy function with respect to the generalized safety momentum and generalized safety coordinates, constructing a continuous set of fractional-order dynamic equations, and using the set of fractional-order dynamic equations as the fractional-order Hamiltonian dynamic evolution model. Specifically, the discrete network security problem described above is transformed into a continuous physical system motion problem. First, the heterogeneous subsystems are obtained. Generalized safety momentum (i.e., the rate of change of the security state), and the allocated virtual quality. (The physical inertia that characterizes the node's resilience to risk) Calculate its kinetic energy term. Simultaneously, the local intrinsic security potential energy of each subsystem based on multidimensional security state characteristic representation is obtained. The global Hamiltonian energy function is constructed by summing the kinetic energy terms of all subsystems, the local intrinsic safety potential energy, and the nonlinear cooperative safety potential energy generated in step S2. : ; In the formula, and These are global vectors containing the generalized coordinates and momentum of all subsystems. To accurately describe the long-range memory effect of complex advanced persistent threats (APTs), a preset order of [order missing] is introduced. ( Fractional calculus operators Calculate the partial derivatives of the global Hamiltonian energy function with respect to generalized momentum and generalized coordinates, and establish a system of fractional-order dynamic equations: ; The above set of equations constitutes a fractional Hamiltonian dynamic evolution model for the digital security twin, which enables the system to continuously extrapolate the global situation.
[0027] S4. The fractional-order Hamiltonian dynamics evolution model is discretized using a symplectic geometric integral algorithm to solve for the predicted phase space state of the digital security twin in the next calculation cycle. Based on the predicted phase space state, a security management strategy for the digital security twin is generated. This includes: using a symplectic geometric integral operator with area-preserving properties to discretize and solve the fractional-order dynamics equations to obtain the predicted phase space state corresponding to the next calculation cycle; calculating the energy difference between the global Hamiltonian in the predicted phase space state and the system baseline steady-state Hamiltonian; and generating and outputting the security management strategy along the fastest gradient descent path of the predicted phase space state when the energy difference exceeds a set danger warning threshold. Specifically, in order to maintain the reliability of system simulations under extreme network adversarial environments (such as large-scale data packet loss or node failures), this invention abandons traditional explicit numerical solution methods such as gradient descent and adopts a symplectic geometric integral operator with area-preserving properties. The fractional-order dynamic equations constructed in step S3 are discretized and solved. This operator strictly adheres to the symplectic structure of the phase space during the iteration process (i.e., (Conservation) can avoid computational divergence caused by long-range extrapolation, and solve for the time corresponding to the next calculation cycle. Predicted phase space state ; Subsequently, the global Hamiltonian and the system baseline steady-state Hamiltonian under the predicted phase space state are calculated. Energy difference between ,when When the value exceeds the set danger warning threshold, it indicates that the system energy is fluctuating abnormally, and the system is moving along the gradient of the predicted phase space state. The fastest descent path is generated, and the optimal safety management strategy (such as communication link isolation or computational resource scheduling parameters) that enables the system to recover to steady-state energy is generated and output.
[0028] S5. Finally, execute the security management strategy and span the predicted phase space state into a new symplectic manifold boundary. Feed the new symplectic manifold boundary back to the next calculation cycle as the boundary condition for projection denoising of the newly constructed initial dynamic tensor in the next calculation cycle, so as to realize the security management closed loop of the digital security twin. Spanning the predicted phase space state into a new symplectic manifold boundary and feeding the new symplectic manifold boundary back to the next calculation cycle as the boundary condition for projection denoising of the newly constructed initial dynamic tensor in the next calculation cycle includes: extracting the predicted generalized security coordinates and predicted generalized security momentum from the predicted phase space state corresponding to the next calculation cycle; spanning the predicted generalized security coordinates and predicted generalized security momentum into a new symplectic manifold boundary for the current calculation cycle; and storing the new symplectic manifold boundary in a cache as the orthogonal projection constraint space when processing the newly constructed initial dynamic tensor in the next calculation cycle. Specifically, this step completes the closed-loop feedback of the entire twin system. First, the security management policy generated in step S4 is converted into corresponding control signals and sent to the underlying physical devices and II protection devices for execution, so as to realize the physical defense response and the synchronous calibration status of the twin system. At the same time, the system extracts the time. Predicted generalized safe coordinates and predicting generalized safety momentum Using this set of predicted phase space state parameters as a basis, a new symplectic manifold boundary is spanned for the current computation period. ; Then the new symplectic manifold boundary will be... This boundary is stored in the system cache, and when the system enters the next computation cycle, it will be directly used as the initial dynamic tensor for processing in the next cycle. The orthogonal projection constraint space at that time (i.e. seamlessly connects to the next step S2), and thus the present invention establishes a digital security twin closed-loop management mechanism with strong resilience and self-healing capabilities through the interlocking steps of prior physical boundary noise reduction, topological feature potential energy mapping, dynamic structure preservation deduction, and manifold boundary reverse feedback.
[0029] Please see the appendix Figure 7 A security management system based on digital security twins includes: The tensor construction module is used to collect multi-dimensional security state characteristics of each heterogeneous subsystem in the digital security twin, and construct an initial dynamic tensor based on the multi-dimensional security state characteristics in the current calculation cycle. Specifically, this module connects to various probes within the digital security twin (covering servers and routers on the IT side, as well as sensor nodes and industrial control equipment on the OT side) through a driver interface at the underlying level, within a preset continuous time window. Data is aggregated internally, and the aggregated multi-dimensional security status features cover cross-protocol network traffic characteristics, physical device status (such as firmware operating temperature and memory consumption), and process call data.
[0030] The closed-loop denoising and decomposition module is used to obtain the symplectic manifold boundary fed back from the previous calculation cycle, use the symplectic manifold boundary to project and denoise the initial dynamic tensor to obtain a high-fidelity tensor, and decompose the high-fidelity tensor to extract the dominant singular value spectrum of the high-fidelity tensor. Specifically, the closed-loop noise reduction and decomposition module is the core of the system's intrinsic anti-interference mechanism. The module contains a high-dimensional space filter to obtain the symplectic manifold boundary fed back from the previous calculation cycle. The initial dynamic tensor is denoised by projection using the symplectic manifold boundary to obtain a high-fidelity tensor. The high-fidelity tensor is then decomposed to extract the dominant singular value spectrum of the high-fidelity tensor.
[0031] The potential energy mapping module is used to map the dominant singular value spectrum into a nonlinear cooperative security potential between heterogeneous subsystems. Specifically, any covert network probe or slow infiltration will cause a fine-tuning of the network connectivity algebraic characteristics (i.e., singular value distribution) at the micro level. This module aims to amplify such micro algebraic changes into macroscopic physical energy fluctuations.
[0032] The dynamic model construction module is used to combine the multidimensional security state characteristics and nonlinear cooperative security potential of each heterogeneous subsystem to construct a fractional-order Hamiltonian dynamic evolution model of the digital security twin. Specifically, this module abstracts the entire security network as a continuously moving physical and mechanical system. The module's computing unit quantifies the inherent security potential energy of each subsystem based on the characteristics of the nodes. And its virtual kinetic energy term for resisting risk (composed of generalized safety momentum) and virtual quality The underlying mathematical mechanism ensures the system's ability to accurately describe the temporal evolution of complex attacks.
[0033] The structure deduction and strategy generation module is used to perform discrete deduction of the fractional order Hamiltonian dynamic evolution model using the symplectic geometric integral algorithm, solve for the predicted phase space state of the digital security twin in the next calculation cycle, and generate a security management strategy for the digital security twin based on the predicted phase space state. Specifically, the structure deduction and strategy generation module is the deduction brain of the system. It is used to perform discrete deduction on the fractional Hamiltonian dynamic evolution model using the symplectic geometric integral algorithm, solve for the predicted phase space state of the digital security twin in the next calculation cycle, and generate a security management strategy for the digital security twin based on the predicted phase space state.
[0034] The boundary feedback and execution module is used to execute the safety management strategy and tensor the predicted phase space state into a new symplectic manifold boundary. The new symplectic manifold boundary is fed back to the closed-loop denoising and decomposition module as the boundary condition for projecting denoising of the newly constructed initial dynamic tensor in the next calculation cycle. Specifically, the boundary feedback and execution module is a key closing component for realizing the system's adaptive closed loop. It is used to execute security management policies and stretch the predicted phase space state into a new symplectic manifold boundary. The new symplectic manifold boundary is fed back to the closed-loop denoising and decomposition module as the boundary condition for projecting and denoising the newly constructed initial dynamic tensor in the next calculation cycle. This module contains bidirectional data links to the outside and inside. On the outside link, the module distributes the generated security management policies to the underlying physical actuator and network firewall corresponding to the twin, forcing the physical side to execute the response, so that the twin and the physical entity can re-synchronize their states.
[0035] In summary, this invention provides a security management method and system based on digital security twins. By obtaining the symplectic manifold boundary fed back from the previous calculation cycle, the initial dynamic tensor is projected and denoised, establishing an intrinsic anti-interference mechanism that does not rely on a static feature library. This mechanism uses the physical energy conservation law followed by the system's forward inference as a mathematical "noise reduction filter" for the current cycle. By calculating the topological projection distance, it can accurately identify and forcibly use orthogonal projection operators to remove high-dimensional noise and maliciously injected data that are outside the physical boundary. This significantly improves the high fidelity of the underlying data of the digital security twin in complex adversarial environments. Furthermore, by using a symplectic geometric integral algorithm to discretize the dynamic model and feeding back the predicted phase space state as a new symplectic manifold boundary to the next calculation cycle, it constructs a system self-healing closed loop with strong resilience. The symplectic geometric inference algorithm with high area characteristics ensures that even when encountering large-scale network congestion or high-frequency packet loss leading to an extreme scarcity of probe data, the mathematical model can still maintain stable inference without diverging or collapsing, relying on the energy conservation law. At the same time, the geometric boundary at the end of the inference is fed back to the front-end data filtering stage, completely opening up the nonlinear strong coupling path from "back-end model inference" to "front-end projection noise reduction", ensuring high reliability of security management throughout the entire life cycle.
[0036] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A security management method based on digital security twins, characterized in that, Includes the following steps: S1. First, collect the multidimensional security state characteristics of each heterogeneous subsystem in the digital security twin, and construct an initial dynamic tensor based on the multidimensional security state characteristics in the current calculation cycle; S2. Then, the symplectic manifold boundary fed back from the previous calculation cycle is obtained. The initial dynamic tensor is projected and denoised using the symplectic manifold boundary to obtain a high-fidelity tensor. The high-fidelity tensor is then decomposed to extract the dominant singular value spectrum of the high-fidelity tensor. S3. Map the dominant singular value spectrum to the nonlinear cooperative security potential between the heterogeneous subsystems, and combine the multidimensional security state characteristics of the heterogeneous subsystems with the nonlinear cooperative security potential to construct the fractional Hamiltonian dynamic evolution model of the digital security twin. S4. The fractional Hamiltonian dynamic evolution model is discretely derived using the symplectic geometric integral algorithm to solve for the predicted phase space state of the digital security twin in the next calculation cycle, and a security management strategy for the digital security twin is generated based on the predicted phase space state. S5. Finally, the security management strategy is executed, and the predicted phase space state is stretched into a new symplectic manifold boundary. The new symplectic manifold boundary is fed back to the next calculation cycle as the boundary condition for the projection denoising of the newly constructed initial dynamic tensor in the next calculation cycle, so as to realize the security management closed loop of the digital security twin.
2. The security management method based on digital security twins according to claim 1, characterized in that, The process involves acquiring multidimensional security state characteristics of each heterogeneous subsystem within the digital security twin, and constructing an initial dynamic tensor based on these multidimensional security state characteristics in the current computation cycle, including: Within the current time window, the network traffic characteristics, physical device status, and process call data of the heterogeneous subsystem are obtained as the multidimensional security status characteristics. The multidimensional security state features are mapped to an initial dynamic tensor of multiple orders according to the feature dimensions, wherein the order of the initial dynamic tensor is consistent with the total number of feature dimensions, and the length of each dimension of the initial dynamic tensor corresponds to the length of each feature dimension.
3. A security management method based on digital security twins according to claim 2, characterized in that, The step of obtaining the symplectic manifold boundary fed back from the previous calculation cycle, and using the symplectic manifold boundary to project and denoise the initial dynamic tensor to obtain a high-fidelity tensor includes: Extract the space formed by the symplectic manifold boundary fed back from the previous calculation cycle; Calculate the topological projection distance from the initial dynamic tensor to the space; When the topological projection distance is greater than the set tolerance threshold, noise data outside the space is removed by the orthogonal projection operator, and the tensor processed by the orthogonal projection operator is output as the high-fidelity tensor.
4. A security management method based on digital security twins according to claim 3, characterized in that, Decomposing the high-fidelity tensor to extract the dominant singular value spectrum of the high-fidelity tensor includes: Perform high-order tensor singular value decomposition on the high-fidelity tensor to extract the core tensor; Obtain the set of singular values generated after the high-fidelity tensor is decomposed and arranged in descending order of numerical values. Cut off the set of singular values according to the set cutoff value to obtain the dominant singular value spectrum.
5. A security management method based on digital security twins according to claim 4, characterized in that, The mapping of the dominant singular value spectrum to the nonlinear cooperative security potential among the heterogeneous subsystems includes: Calculate the logarithmic decay rate based on the adjacent singular values of the corresponding subsystem dimension in the dominant singular value spectrum; The logarithmic decay rate is input into a preset nonlinear scaling function to obtain the dynamic scaling coefficient; A basic connectivity basis function is constructed using the basic network topology of the digital security twin and the generalized security coordinates of the heterogeneous subsystem; Multiplying the dynamic scaling coefficient by the basic connectivity basis function yields the nonlinear cooperative security potential between the corresponding heterogeneous subsystems.
6. A security management method based on digital security twins according to claim 5, characterized in that, Combining the multidimensional security state characteristics of each heterogeneous subsystem with the nonlinear cooperative security potential, a fractional-order Hamiltonian dynamic evolution model of the digital security twin is constructed, including: Obtain the generalized safety momentum and allocated virtual mass of each heterogeneous subsystem, and calculate the kinetic energy term of each heterogeneous subsystem; Obtain the local intrinsic security potential of each of the heterogeneous subsystems based on the multidimensional security state characteristics; The global Hamiltonian energy function characterizing the global state of the digital security twin is obtained by summing the kinetic energy term of all the heterogeneous subsystems, the local intrinsic security potential energy, and the nonlinear cooperative security potential energy among the heterogeneous subsystems.
7. A security management method based on digital security twins according to claim 1, characterized in that, The fractional-order Hamiltonian dynamics evolution model for constructing a digital security twin also includes: Introduce fractional calculus operators of a predetermined order; Using the fractional-order calculus operator, the partial derivatives of the global Hamiltonian energy function with respect to the generalized safety momentum and the generalized safety coordinates are calculated to construct a continuous set of fractional-order dynamic equations, which are then used as the fractional-order Hamiltonian dynamic evolution model.
8. A security management method based on digital security twins according to claim 7, characterized in that, The method employs a symplectic geometric integral algorithm to discretize the fractional-order Hamiltonian dynamic evolution model, solving for the predicted phase space state of the digital security twin in the next calculation cycle, and generating a security management strategy for the digital security twin based on the predicted phase space state, including: The fractional-order dynamic equations are discretized and solved using a symplectic geometric integral operator that preserves area characteristics, to obtain the predicted phase space state corresponding to the next calculation cycle. Calculate the energy difference between the global Hamiltonian in the predicted phase space state and the baseline steady-state Hamiltonian of the system; When the energy difference is greater than the set danger warning threshold, the safety management strategy is generated and output along the fastest gradient descent path of the predicted phase space state.
9. A security management method based on digital security twins according to claim 8, characterized in that, The step of stretching the predicted phase space state into a new symplectic manifold boundary and feeding the new symplectic manifold boundary back to the next calculation cycle as a boundary condition for projective denoising of the newly constructed initial dynamic tensor in the next calculation cycle includes: Extract the predicted generalized safety coordinates and predicted generalized safety momentum from the predicted phase space state corresponding to the next calculation cycle; The predicted generalized safety coordinates and the predicted generalized safety momentum are stretched into the new symplectic manifold boundary for the current calculation period; The new symplectic manifold boundary is stored in a cache as the orthogonal projection constraint space when processing the newly constructed initial dynamic tensor in the next computation cycle.
10. A security management system based on digital security twins, characterized in that, A security management method based on digital security twin according to any one of claims 1-9, comprising: The tensor construction module is used to collect multi-dimensional security state characteristics of each heterogeneous subsystem in the digital security twin, and construct an initial dynamic tensor based on the multi-dimensional security state characteristics in the current calculation cycle. The closed-loop denoising and decomposition module is used to obtain the symplectic manifold boundary fed back from the previous calculation cycle, use the symplectic manifold boundary to project and denoise the initial dynamic tensor to obtain a high-fidelity tensor, and decompose the high-fidelity tensor to extract the dominant singular value spectrum of the high-fidelity tensor. The potential energy mapping module is used to map the dominant singular value spectrum into a nonlinear cooperative security potential energy between the heterogeneous subsystems. The dynamic model construction module is used to combine the multidimensional security state characteristics of each heterogeneous subsystem with the nonlinear cooperative security potential energy to construct a fractional-order Hamiltonian dynamic evolution model of the digital security twin. The structure-preserving deduction and strategy generation module is used to perform discrete deduction on the fractional-order Hamiltonian dynamic evolution model using the symplectic geometric integral algorithm, solve for the predicted phase space state of the digital security twin in the next calculation cycle, and generate a security management strategy for the digital security twin based on the predicted phase space state. The boundary feedback and execution module is used to execute the security management strategy, stretch the predicted phase space state into a new symplectic manifold boundary, and feed the new symplectic manifold boundary back to the closed-loop denoising and decomposition module as the boundary condition for projective denoising of the newly constructed initial dynamic tensor in the next calculation cycle.