Cross-fault-domain zero-trust security arbitration system for non-deterministic controller and hierarchical response method based on effect verification
By implementing a cross-fault domain zero-trust security arbitration system, the controller achieves physical isolation in the dimensions of power supply, clock, and ground plane, dynamic threshold triggering, and one-way veto. This solves the problems of common-cause failure and arbitration points not being at physical boundaries, ensuring that the safe response time under dynamic operating conditions is less than the control cycle, thus improving the safety and reliability of the controller.
CN122431310APending Publication Date: 2026-07-21GUANGZHOU GUCE CANGQIONG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU GUCE CANGQIONG TECHNOLOGY CO LTD
- Filing Date
- 2026-03-24
- Publication Date
- 2026-07-21
Smart Images

Figure CN122431310A_ABST
Abstract
The application discloses a cross-fault-domain zero-trust security arbitration system for a non-deterministic controller and a hierarchical response method based on effect verification, and relates to the technical field of non-deterministic controller security arbitration. The control unit is used for running a non-deterministic control strategy to generate a control instruction; a residual energy accumulation module is arranged in the security unit, and a deviation between the control instruction and an actual execution effect is accumulated as a residual energy accumulation metric Σe(t) in a sliding time window; a hierarchical response is triggered when Σe(t) exceeds a dynamic threshold; the security unit is used for calculating a risk degree and combining the residual energy accumulation metric, and when the risk degree or the residual energy accumulation metric exceeds a corresponding dynamic threshold, a corresponding hierarchical response is triggered, an enable signal of the security unit is output in a failure state, and a lock trigger signal is output; no matter what state the control instruction is in, when the enable signal is in a failure state, a lock state signal output by an interlocking reset module is received, or in the case of energy loss, a blocking state is entered, and a system security lock response time τ_lock is satisfied.
Need to check novelty before this filing date? Find Prior Art