Cross-fault-domain zero-trust security arbitration system for non-deterministic controller and hierarchical response method based on effect verification

By implementing a cross-fault domain zero-trust security arbitration system, the controller achieves physical isolation in the dimensions of power supply, clock, and ground plane, dynamic threshold triggering, and one-way veto. This solves the problems of common-cause failure and arbitration points not being at physical boundaries, ensuring that the safe response time under dynamic operating conditions is less than the control cycle, thus improving the safety and reliability of the controller.

CN122431310APending Publication Date: 2026-07-21GUANGZHOU GUCE CANGQIONG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGZHOU GUCE CANGQIONG TECHNOLOGY CO LTD
Filing Date
2026-03-24
Publication Date
2026-07-21

Smart Images

  • Figure CN122431310A_ABST
    Figure CN122431310A_ABST
Patent Text Reader

Abstract

The application discloses a cross-fault-domain zero-trust security arbitration system for a non-deterministic controller and a hierarchical response method based on effect verification, and relates to the technical field of non-deterministic controller security arbitration. The control unit is used for running a non-deterministic control strategy to generate a control instruction; a residual energy accumulation module is arranged in the security unit, and a deviation between the control instruction and an actual execution effect is accumulated as a residual energy accumulation metric Σe(t) in a sliding time window; a hierarchical response is triggered when Σe(t) exceeds a dynamic threshold; the security unit is used for calculating a risk degree and combining the residual energy accumulation metric, and when the risk degree or the residual energy accumulation metric exceeds a corresponding dynamic threshold, a corresponding hierarchical response is triggered, an enable signal of the security unit is output in a failure state, and a lock trigger signal is output; no matter what state the control instruction is in, when the enable signal is in a failure state, a lock state signal output by an interlocking reset module is received, or in the case of energy loss, a blocking state is entered, and a system security lock response time τ_lock is satisfied.
Need to check novelty before this filing date? Find Prior Art