An industrial control device password migration strategy determination method, device, equipment and medium

CN122554095APending Publication Date: 2026-08-11CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-08
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

然而,现有技术方案多面向通用信息技术(InformationTechnology,IT)环境,其评估模型通常基于纯软件维度的“代码解耦度”进行打分,密码资产清单的生成则依赖人工调查或基于白盒环境的源代码扫描等单一技术手段

Benefits of technology

[0015]可见,本申请中,基于目标工控设备对应的物理隔离等级分别执行对应的资产探测方式,以得到相应的密码资产探测结果,并基于预设置信度权重值对所述密码资产探测结果进行融合,以得到密码资产初始数据;对所述密码资产初始数据进行结构化处理,以得到目标密码物料清单,并将所述目标密码物料清单输入至预设逻辑规则决策引擎中,以得到所述目标密码物料清单中各资产节点对应的敏捷性状态分级;基于所述敏捷性状态分级对所述各资产节点进行动态权重分配,以得到目标权重系数,并基于所述密码资产初始数据确定所述目标工控设备对应的软件敏捷性得分和硬件敏捷性得分;基于所述目标权重系数、所述软件敏捷性得分和所述硬件敏捷性得分确定工控密码敏捷性评估结果,以便基于所述工控密码敏捷性评估结果确定所述目标工控设备的密码迁移策略。即,通过针对不同物理隔离等级执行对应探测方式以获取多源结果,并依据预设置信度权重进行加权融合与冲突消解,以获取统一可信的密码资产初始数据。然后,将所述数据结构化为目标密码物料清单,输入逻辑规则决策引擎,输出各资产节点对应的敏捷性状态分级。基于所述分级动态分配软件与硬件权重系数,同时根据密码资产初始数据分别量化软件敏捷性得分与硬件敏捷性得分,最终加权计算得出综合评估结果。这样一来,通过多源融合消除单源偏差,将物理壁垒纳入评估标尺,使迁移策略精准匹配不同安全等级设备的实际改造条件,避免纯软件评估脱离物理约束导致的决策失误。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122554095A_ABST
    Figure CN122554095A_ABST
Patent Text Reader

Abstract

This application discloses a method, apparatus, device, and medium for determining cryptographic migration strategies for industrial control equipment (ICS), relating to the field of network security technology. The method includes: executing corresponding asset detection methods based on the physical isolation level of the target ICS to obtain corresponding cryptographic asset detection results; fusing these results based on pre-set confidence weight values ​​to obtain initial cryptographic asset data; inputting the initial cryptographic asset data into a target cryptographic material list after structured processing to a pre-set logical rule decision engine to obtain an agility status classification; dynamically assigning weights to each asset node based on the agility status classification to obtain target weight coefficients; and determining the ICS cryptographic agility assessment result based on the initial cryptographic asset data to determine the software agility score and hardware agility score corresponding to the target ICS, in order to formulate a cryptographic migration strategy. This enables a smooth migration of ICS to the target computational cryptography.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, device, and storage medium for determining password migration strategies for industrial control equipment. Background Technology

[0002] With the rapid development of quantum computing technology, existing public-key cryptography systems based on classical difficult problems face severe threats. The smooth migration of critical information infrastructure to post-quantum cryptography (PQC) has become a strategic issue urgently needing resolution. The prerequisite for implementing cryptographic agility transformation lies in achieving "asset detection visualization" and "agility baseline assessment." However, existing technical solutions are mostly geared towards general information technology (IT) environments, and their assessment models typically score based on the purely software dimension of "code decoupling." The generation of cryptographic asset inventories relies on single technical means such as manual investigation or source code scanning in a white-box environment.

[0003] In high-availability industrial operation technology (OT) environments such as nuclear power and power grids, the aforementioned IT solutions have significant drawbacks: First, pure software evaluation models ignore physical barriers such as long firmware re-authentication cycles and insufficient underlying hardware computing power, leading to evaluation results that are out of touch with reality and potentially causing production downtime risks. Second, standard cryptographic software bills of materials (CBOMs) only record algorithm names and cannot identify the unique hardware firmware status and physical security partitions of industrial control equipment, lacking on-site guidance significance. Third, many dumb devices in OT networks lack source code and cannot be probed, while high-security core systems such as 1E-level systems implement absolute physical isolation, strictly prohibiting network scanning or firmware extraction; existing automated probing tools fail in extremely restricted scenarios. These shortcomings increase the probability of infrastructure cryptographic migration failures in industrial control environments.

[0004] Therefore, there is an urgent need for a quantitative evaluation standard for cryptographic agility, which can improve the probability of successful cryptographic migration of infrastructure in industrial control environments. Summary of the Invention

[0005] In view of this, the purpose of this invention is to provide a method, apparatus, device, and storage medium for determining password migration strategies for industrial control equipment, which can more accurately quantify password agility results, thereby increasing the probability of successful password migration. The specific solution is as follows: In a first aspect, this application discloses a method for determining the password migration strategy of industrial control equipment, including: Based on the physical isolation level of the target industrial control equipment, the corresponding asset detection methods are executed to obtain the corresponding cryptographic asset detection results. The cryptographic asset detection results are then fused based on the preset confidence weight value to obtain the initial cryptographic asset data. The initial data of the cryptographic assets is structured to obtain a target cryptographic material list, and the target cryptographic material list is input into a preset logic rule decision engine to obtain the agility status classification of each asset node in the target cryptographic material list. Based on the agility status classification, dynamic weight allocation is performed on each asset node to obtain the target weight coefficient, and the software agility score and hardware agility score corresponding to the target industrial control equipment are determined based on the initial data of the cryptographic assets. The industrial control system cryptography agility assessment result is determined based on the target weight coefficient, the software agility score, and the hardware agility score, so as to determine the cryptographic migration strategy of the target industrial control equipment based on the industrial control cryptography agility assessment result.

[0006] Optionally, the step of performing corresponding asset detection methods based on the physical isolation level of the target industrial control equipment to obtain corresponding cryptographic asset detection results includes: Send an encrypted handshake inducement message to the service port of the first target industrial control device, and parse the response message corresponding to the encrypted handshake inducement message to obtain the cryptographic suite and public key signature parameters of the first target industrial control device; Obtain the firmware binary image of the second target industrial control device, locate the storage address of the cryptographic algorithm in the firmware binary image based on the preset cryptographic constant feature library, and calculate the call stack depth and static offset from the business calling function to the cryptographic primitive. An abstract syntax tree of the source code of the third target industrial control equipment is constructed to identify cryptographic function calls, and an algorithm strength evaluation is performed based on the cryptographic function calls to obtain the corresponding evaluation results. The encryption negotiation session of the fourth target industrial control device is analyzed to extract the corresponding cipher suites, certificate information and key exchange timing characteristics; The offline survey data entered by the fifth target industrial control device is received through a structured template; the offline survey data includes at least the device model, the cryptographic algorithms it claims to support, and hardware-based determination information.

[0007] Optionally, the fusion of the cryptographic asset detection results based on preset confidence weight values ​​to obtain initial cryptographic asset data includes: Based on the asset detection method, a pre-set confidence weight value is set for the cryptographic asset detection result; Determine whether there are conflicts among multiple cryptographic asset detection results targeting the same industrial control equipment; If a conflict exists, the conflicting cryptographic assets are weighted based on the preset confidence weight value, and the conflict resolution operation is performed on the conflicting cryptographic assets according to the weighted calculation result to obtain the processed assets. Based on the processed assets, the initial data of the merged cryptographic assets is determined to obtain the initial data of the cryptographic assets.

[0008] Optionally, the step of structuring the initial data of the cryptographic assets to obtain the target cryptographic material list includes: The initial data of the cryptographic assets is structured to obtain a hard-coded status bit field, a physical coupling degree field, and a security partition level field. The hard-coded status bit field is used to characterize the hardware solidification state of the corresponding asset node. The physical coupling degree field is used to characterize the degree of physical coupling between the asset node and the business logic. The security partition level field is used to characterize the physical security partition level to which the asset node belongs. The target cryptographic material list is determined based on the hard-coded status bit field, the physical coupling degree field, and the security partition level field.

[0009] Optionally, the step of inputting the target cryptographic bill of materials into a preset logical rule decision engine to obtain the agility status classification corresponding to each asset node in the target cryptographic bill of materials includes: If the security partition level field corresponding to the asset node is the preset highest security level and the hard-coded status bit represents hardware fixation, then the agility status level corresponding to the asset node is determined to be the unresponsive level. If the hard-coded status bit field corresponding to the asset node indicates that it is not hardware-fixed and the physical coupling degree is greater than the preset coupling degree threshold, then the agility status level corresponding to the asset node is determined as black box coupling level. If the asset node has an independent external cryptographic interface calling engine, then the agility status level corresponding to the asset node is determined to be the interface decoupling level. If the asset node supports dynamic negotiation and switching of multiple cryptographic suites, then the agility status level corresponding to the asset node is determined to be the dynamic negotiation level.

[0010] Optionally, the dynamic weight allocation of each asset node based on the agility status classification to obtain the target weight coefficient includes: If the agility status level corresponding to the asset node is a preset low level, then the hardware weight coefficient assigned to the asset node is greater than the software weight coefficient, so as to obtain the target weight coefficient. If the agility status level corresponding to the asset node is a preset high level, then the software weight coefficient assigned to the asset node is greater than the hardware weight coefficient, so as to obtain the target weight coefficient. The sum of the software weight coefficient and the hardware weight coefficient is a preset value.

[0011] Optionally, determining the software agility score and hardware agility score corresponding to the target industrial control equipment based on the initial data of the cryptographic assets includes: The software agility score corresponding to the target industrial control equipment is determined by weighted calculation based on the call decoupling degree, latency retention degree, and resource retention degree in the initial data of the cryptographic assets. The hardware agility score of the target industrial control equipment is determined by weighted calculation based on the hardware computing power transformation feasibility coefficient, authentication burden coefficient, and resource reserve coefficient in the initial data of the cryptographic assets.

[0012] Secondly, this application discloses an industrial control equipment password migration strategy determination device, comprising: The initial data acquisition module is used to execute the corresponding asset detection method based on the physical isolation level of the target industrial control equipment to obtain the corresponding cryptographic asset detection results, and to fuse the cryptographic asset detection results based on the preset confidence weight value to obtain the initial cryptographic asset data. The grade determination module is used to perform structured processing on the initial data of the cryptographic assets to obtain a target cryptographic material list, and input the target cryptographic material list into a preset logic rule decision engine to obtain the agility status grade corresponding to each asset node in the target cryptographic material list. The evaluation result acquisition module is used to dynamically assign weights to each asset node based on the agility status classification to obtain the target weight coefficient, and to determine the software agility score and hardware agility score corresponding to the target industrial control equipment based on the initial data of the cryptographic assets. The strategy determination module is used to determine the industrial control cryptography agility assessment result based on the target weight coefficient, the software agility score, and the hardware agility score, so as to determine the cryptographic migration strategy of the target industrial control equipment based on the industrial control cryptography agility assessment result.

[0013] Thirdly, this application discloses an electronic device, including: Memory, used to store computer programs; A processor is used to execute the computer program to implement the aforementioned method for determining the password migration strategy for industrial control equipment.

[0014] Fourthly, this application discloses a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the aforementioned method for determining the password migration strategy for industrial control equipment.

[0015] As can be seen, in this application, corresponding asset detection methods are executed based on the physical isolation level of the target industrial control equipment to obtain corresponding cryptographic asset detection results. These results are then fused based on pre-set confidence weights to obtain initial cryptographic asset data. The initial cryptographic asset data is then structured to obtain a target cryptographic material list, which is input into a pre-set logical rule decision engine to obtain an agility status classification for each asset node in the target cryptographic material list. Based on the agility status classification, dynamic weight allocation is performed on each asset node to obtain a target weight coefficient. The software agility score and hardware agility score of the target industrial control equipment are then determined based on the initial cryptographic asset data. Finally, the industrial control cryptographic agility assessment result is determined based on the target weight coefficient, the software agility score, and the hardware agility score, so as to determine the cryptographic migration strategy for the target industrial control equipment. In other words, by executing corresponding detection methods for different physical isolation levels to obtain multi-source results, and performing weighted fusion and conflict resolution based on pre-set confidence weights, unified and reliable initial cryptographic asset data is obtained. Then, the data is structured into a target cryptographic material list, input into a logical rule decision engine, and outputs an agility status rating for each asset node. Based on this rating, software and hardware weight coefficients are dynamically allocated, and software and hardware agility scores are quantified separately according to the initial cryptographic asset data. Finally, a weighted calculation yields a comprehensive evaluation result. In this way, multi-source fusion eliminates single-source bias, incorporates physical barriers into the evaluation scale, and ensures that migration strategies accurately match the actual modification conditions of equipment with different security levels, avoiding decision-making errors caused by pure software evaluation detached from physical constraints. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0017] Figure 1 This is a flowchart of a method for determining password migration strategies for industrial control equipment disclosed in this application; Figure 2 This is a flowchart of a specific method for multi-source heterogeneous data acquisition and conflict resolution disclosed in this application; Figure 3 This application discloses a flowchart of a specific method for determining password migration strategies for industrial control equipment. Figure 4 This is a schematic diagram of the structure of a device for determining password migration strategies for industrial control equipment disclosed in this application; Figure 5 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation

[0018] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0019] Existing OT solutions neglect physical barriers such as long firmware authentication cycles and insufficient hardware computing power. Furthermore, the lack of hardware-defined status fields in the CBOM (Content Management Object Model) and the prohibition of scanning high-security devices lead to unrealistic assessment results, increasing the probability of password migration failures. Therefore, there is an urgent need for a password agility assessment scheme that integrates hardware and software constraints with multi-source probing to improve the success rate of password migration for industrial control infrastructure.

[0020] See Figure 1 As shown in the figure, this application discloses a method for determining the password migration strategy of industrial control equipment, including: Step S11: Based on the physical isolation level of the target industrial control equipment, execute the corresponding asset detection method to obtain the corresponding cryptographic asset detection results, and fuse the cryptographic asset detection results based on the preset confidence weight value to obtain the initial cryptographic asset data.

[0021] In this embodiment, the step of executing corresponding asset detection methods based on the physical isolation level of the target industrial control device to obtain corresponding cryptographic asset detection results includes: sending an encrypted handshake inducement message to the service port of the first target industrial control device; parsing the response message corresponding to the encrypted handshake inducement message to obtain the cryptographic suite and public key signature parameters of the first target industrial control device. Specifically, for a network-reachable target industrial control node, the IP address and service port of the target industrial control node are obtained as input data; the detection engine sends a customized encrypted handshake inducement message to the service port and receives the response message; the response message is parsed to extract the cryptographic suites and public key signature parameters supported by the target industrial control node.

[0022] The firmware binary image of the second target industrial control device is acquired, and the storage address of the cryptographic algorithm is located in the firmware binary image based on a pre-set cryptographic constant feature library. The call stack depth and static offset from the business calling function to the cryptographic primitive are calculated. Specifically, for the target industrial control node where firmware extraction is permitted, the underlying firmware binary image extracted via network packet capture or physical interface is acquired as input data; a pre-set cryptographic constant feature library is loaded (the feature library includes, but is not limited to, national cryptographic S-box feature constants and / or AES (Advanced Encryption Standard) feature constants), and the physical storage starting address of the cryptographic algorithm is accurately located in the image using a sliding window algorithm; a control flow graph is constructed upwards using a disassembler engine, and the call stack depth and static offset from the business calling function to the cryptographic primitive are calculated.

[0023] An abstract syntax tree (AST) of the source code of the third target industrial control device is constructed to identify cryptographic function calls. Based on these function calls, an algorithm strength assessment is performed to obtain the corresponding evaluation results. Specifically, for development environments, simulation testing platforms, or operating systems with access to the source code, the source code data of the target system (including version control repository code, offline code packages, or mounted source code directories) is obtained as input data. The execution logic includes: constructing an abstract syntax tree for the programming language of the target system's source code through syntax tree parsing, and identifying cryptographic function calls based on this tree; performing dependency chain tracing by parsing and compiling dependency files to identify the version information of the referenced cryptographic libraries and cross-referencing it with a preset vulnerability library and quantum vulnerability knowledge base; performing hard-coded credential detection using regular expressions and entropy analysis algorithms to detect the presence of hard-coded keys, certificates, or sensitive parameters in the source code; and conducting an algorithm strength assessment by extracting algorithm call parameters and determining whether the security strength of the used cryptographic algorithm is lower than a preset quantum security baseline threshold. Based on the above results, a structured report is generated, which includes at least a list of cryptographic algorithms, dependency library versions, and algorithm strength compliance indicators.

[0024] The encryption negotiation session of the fourth target industrial control device is analyzed to extract the corresponding cipher suites, certificate information, and key exchange timing characteristics. Specifically, for target nodes whose network traffic can be obtained through port mirroring, splitters, or offline data packets, real-time mirrored traffic or offline packet capture files are obtained as input data. The execution logic includes: through protocol identification and filtering, based on a preset industrial control protocol feature library, selecting target business sessions containing encryption negotiation or cryptographic applications from the input data; extracting cipher suites by parsing the encryption protocol messages in the target business session to extract the cipher suite list, signature algorithm, elliptic curve parameters, and certificate information; performing weak password detection to identify whether the target business session uses obsolete or weak cryptographic algorithms with security below a preset threshold; extracting timing characteristics by recording the establishment time, certificate validity period, and key exchange time of the target business session to provide a basis for calculating negotiation delays for subsequent agility assessments; and identifying abnormal behavior by detecting risky behaviors such as expired certificates, self-signed certificates, incomplete certificate chains, or downgraded encryption protocols in the target business session. Based on the above results, generate a structured report that includes at least the session quintuple, a list of negotiation algorithms, certificate chain information, weak password alerts, and timing statistics.

[0025] The system receives offline survey data from the fifth target industrial control device via a structured template. This offline survey data includes at least the device model, claimed supported cryptographic algorithms, and hardware firmware verification information. Specifically, for high-level isolated nodes where scanning and firmware extraction are strictly prohibited, the system obtains the device purchase manual, original manufacturer's technical white paper, historical security assessment reports, and structured questionnaires as input data. A standardized mapping template is provided to receive offline survey results manually entered by the terminal. The data structure of these offline survey results includes at least: device model, claimed supported cryptographic algorithms, key carrier format, and hardware firmware verification feedback.

[0026] In this embodiment, the step of fusing the cryptographic asset detection results based on a preset confidence weight value to obtain initial cryptographic asset data includes: setting a preset confidence weight value for the cryptographic asset detection results based on the asset detection method; determining whether there are conflicts among multiple cryptographic asset detection results targeting the same industrial control device; if conflicts exist, performing a weighted calculation on the conflicting cryptographic assets based on the preset confidence weight value, and performing a conflict resolution operation on the conflicting cryptographic assets according to the weighted calculation result to obtain processed assets; and determining the fused initial cryptographic asset data based on the processed assets to obtain the initial cryptographic asset data. That is, as shown... Figure 2As shown, different confidence weights are pre-assigned to the acquired data sources (for example, the confidence of binary reverse data source is set to C_bin, the confidence of active probe data source is set to C_net1, the confidence of manually surveyed data source is set to C_man, the confidence of static source code analysis is set to C_source, and the confidence of network traffic analysis is set to C_net2). When there is a conflict between the multi-source probe or input results for the same target industrial control node, the weighted confidence calculation mechanism is triggered to automatically verify and generate a conflict alarm. The data conflict is resolved based on the confidence verification result, and finally the multi-dimensional fused initial data of cryptographic assets is output.

[0027] Step S12: Perform structured processing on the initial data of the cryptographic assets to obtain the target cryptographic material list, and input the target cryptographic material list into the preset logic rule decision engine to obtain the agility status classification corresponding to each asset node in the target cryptographic material list.

[0028] In this embodiment, the structuring of the initial cryptographic asset data to obtain the target cryptographic bill of materials includes: structuring the initial cryptographic asset data to obtain a hard-coded status bit field, a physical coupling degree field, and a security partition level field; the hard-coded status bit field is used to characterize the hardware solidification state of the corresponding asset node; the physical coupling degree field is used to characterize the degree of physical coupling between the asset node and the business logic; the security partition level field is used to characterize the physical security partition level to which the asset node belongs; and the target cryptographic bill of materials is determined based on the hard-coded status bit field, the physical coupling degree field, and the security partition level field. That is, the multi-source data obtained in step S11 is structured to generate a CBOM_OT based on JSON (JavaScript Object Notation) / XML (Extensible Markup Language) format. The specialized data structure is defined. In addition to the standard fields, each cryptographic asset instance node includes the following OT-specific constraint fields: 1) Hardcoded_Flag, a Boolean type, is a hard-coded status flag. For automated analysis devices, it is marked as True if the call stack depth is 1 or the data is stored in ROM; for manually surveyed devices, it is marked as True if the input record is "algorithm embedded in ASIC / FPGA chip".

[0029] 2) Coupling_Ratio, physical coupling degree, Float type: set a range value [0, 1] based on manual or automated evaluation.

[0030] 3) Security_Zone, security zone level, Enum type: reads the network topology and assigns a value of High-Safety (high security level, such as core level 1E), Safety (general security level) or Non-Safety (non-security level).

[0031] In this embodiment, inputting the target cryptographic material list into a preset logical rule decision engine to obtain the agility status classification corresponding to each asset node in the target cryptographic material list includes: if the security partition level field corresponding to the asset node is the preset highest security level and the hard-coded status bit indicates hardware solidification, then the agility status classification corresponding to the asset node is determined to be unresponsive; if the hard-coded status bit field corresponding to the asset node indicates non-hardware solidification and the physical coupling degree is greater than a preset coupling degree threshold, then the agility status classification corresponding to the asset node is determined to be black-box coupling; if the asset node corresponds to an independent external cryptographic interface calling engine, then the agility status classification corresponding to the asset node is determined to be interface decoupling; if the asset node corresponds to support dynamic negotiation switching of multiple cryptographic suites, then the agility status classification corresponding to the asset node is determined to be dynamic negotiation. Then, the CBOM_OT instance is input into the preset logical rule decision engine, and the following judgment rules are executed: IF Security_Zone == High-Safety AND Hardcoded_Flag == True: The rightarrow is mapped to Level 0, an unresponsive level, meaning that the original firmware is absolutely untouchable.

[0032] If Hardcoded_Flag == False AND Coupling_Ratio > Set the threshold: The rightarrow is mapped to Level 1, a known or black-box coupling level.

[0033] If there is an independent external Crypto API calling engine (such as Engine or Wrapper): Rightarrow is mapped to Level 2, the interface decoupling level.

[0034] IF supports dynamic negotiation and switching of multiple cipher suites: The rightarrow is mapped to Level 3 or Level 4, with the level dynamically negotiated.

[0035] Step S13: Based on the agility status classification, dynamically assign weights to each asset node to obtain the target weight coefficient, and determine the software agility score and hardware agility score corresponding to the target industrial control equipment based on the initial data of the cryptographic assets.

[0036] In this embodiment, the dynamic weight allocation of each asset node based on the agility status classification to obtain a target weight coefficient includes: if the agility status classification corresponding to the asset node is a preset low level, then the hardware weight coefficient allocated to the asset node is greater than the software weight coefficient to obtain the target weight coefficient; if the agility status classification corresponding to the asset node is a preset high level, then the software weight coefficient allocated to the asset node is greater than the hardware weight coefficient to obtain the target weight coefficient; wherein, the sum of the software weight coefficient and the hardware weight coefficient is a preset value. That is, the software weight W_sw and hardware weight W_hw (W_sw + W_hw = 1) are dynamically allocated according to the asset's Security_Zone and baseline mapping rightarrow. If it is a low level (such as Level 0-2), the hardware modification resistance is extremely high, and W_hw is assigned a large value (such as 0.85); if it is a high level (such as Level 3-4), W_sw is assigned a very large value (such as 0.75).

[0037] In this embodiment, determining the software agility score and hardware agility score corresponding to the target industrial control equipment based on the initial data of the cryptographic assets includes: determining the software agility score corresponding to the target industrial control equipment by weighted calculation based on the call decoupling degree, latency retention degree, and resource retention degree in the initial data of the cryptographic assets; and determining the hardware agility score corresponding to the target industrial control equipment by weighted calculation based on the hardware computing power modification feasibility coefficient, authentication burden coefficient, and resource reserve coefficient in the initial data of the cryptographic assets. The formula for the software agility score (Score_sw) is as follows: ; Among them, Score_sw is the comprehensive score of software agility, reflecting the adaptability of the software system when cryptographic algorithms are replaced. It is a normalized value of [0, 1] or [0, 100]. The higher the score, the more agile the software. DID is the call decoupling degree, which measures the degree of decoupling between the cryptographic module and the business logic, that is, whether the cryptographic algorithm can be replaced without affecting the business code. The value range is normalized to [0, 1], where 1 represents complete decoupling (such as through a unified API or plug-in mechanism) and 0 represents hard coding. The latency jitter / increase calculated when concurrently loading the PQC algorithm is the additional communication / computation delay caused by the introduction of quantum-resistant cryptography or dynamic reconstruction. This is the maximum tolerable latency threshold for this service, representing a hard red line for the business. The latency utilization rate is the proportion of newly added latency to the allowable latency budget. The closer the value is to 1, the closer it is to the red line. If it is greater than 1, it is unacceptable. This is the latency retention score, a normalized latency metric. 1 point is awarded when the new latency is 0, 0 points are awarded when the new latency equals the maximum allowable latency, and negative points are awarded if it exceeds this limit. The increase in memory and other resources is due to the introduction of new cryptographic algorithms or dynamic reconstruction, resulting in additional memory and other resource usage. Maximum allowable increase in memory and other resources: Under the premise of ensuring system stability, the upper limit of the budget for additional memory and other resources that the cryptographic module can occupy. The normalized resource metric score represents the retention of resources such as memory. Following the same logic as the latency metric, it reflects the constraints imposed by limited resources. λ1, λ2, and λ3 are weighting coefficients, corresponding to the importance percentage of each of the three metrics in the overall evaluation, satisfying λ1 + λ2 + λ3 = 1.

[0038] The formula for the hardware agility score (Score_hw) is as follows: ; Among them, Score_hw is the comprehensive score of hardware agility, reflecting the actual support capability of hardware devices when facing the replacement of cryptographic algorithms. It is a normalized value of [0, 1] or [0, 100]. The higher the score, the more agile the hardware is; F_hw is the feasibility coefficient of hardware computing power transformation; P_cert is the authentication burden coefficient, such as the firmware re-authentication cycle penalty factor; F_bitw is the resource margin, that is, how much computing power, storage and bandwidth can accommodate the new cryptographic algorithm under the current load; µ1, µ2 and µ3 are weight coefficients, which correspond to the importance ratio of the three indicators in the comprehensive evaluation, satisfying µ1+µ2+µ3=1.

[0039] Step S14: Determine the industrial control cryptography agility assessment result based on the target weight coefficient, the software agility score, and the hardware agility score, so as to determine the cryptography migration strategy of the target industrial control equipment based on the industrial control cryptography agility assessment result.

[0040] In this embodiment, the target weight coefficient, the software agility score, and the hardware agility score are finally summarized to obtain the final output summary: .

[0041] After obtaining the corresponding summary score, such as Figure 3 As shown, if the score is extremely low, the "internal code upgrade" option will be rejected outright, and the migration route such as "external mounting of a bypass transparent cryptographic module" will be recommended.

[0042] As can be seen, in this embodiment, corresponding asset detection methods are executed based on the physical isolation level of the target industrial control equipment to obtain corresponding cryptographic asset detection results. These results are then fused based on preset confidence weight values ​​to obtain initial cryptographic asset data. The initial cryptographic asset data is then structured to obtain a target cryptographic material list, which is input into a preset logical rule decision engine to obtain an agility status classification for each asset node in the target cryptographic material list. Based on the agility status classification, dynamic weight allocation is performed on each asset node to obtain a target weight coefficient. The software agility score and hardware agility score of the target industrial control equipment are determined based on the initial cryptographic asset data. Finally, the industrial control cryptographic agility assessment result is determined based on the target weight coefficient, the software agility score, and the hardware agility score, so as to determine the cryptographic migration strategy for the target industrial control equipment. In other words, by executing corresponding detection methods for different physical isolation levels to obtain multi-source results, and performing weighted fusion and conflict resolution based on preset confidence weights, unified and reliable initial cryptographic asset data is obtained. Then, the data is structured into a target cryptographic material list, input into a logical rule decision engine, and outputs an agility status rating for each asset node. Based on this rating, software and hardware weight coefficients are dynamically allocated, and software and hardware agility scores are quantified separately according to the initial cryptographic asset data. Finally, a weighted calculation yields a comprehensive evaluation result. In this way, multi-source fusion eliminates single-source bias, incorporates physical barriers into the evaluation scale, and ensures that migration strategies accurately match the actual modification conditions of equipment with different security levels, avoiding decision-making errors caused by pure software evaluation detached from physical constraints.

[0043] refer to Figure 4 The present application also discloses a device for determining password migration strategies for industrial control equipment, comprising: The initial data acquisition module 11 is used to execute the corresponding asset detection method based on the physical isolation level of the target industrial control equipment to obtain the corresponding cryptographic asset detection results, and to fuse the cryptographic asset detection results based on the preset confidence weight value to obtain the initial data of the cryptographic assets. The grade determination module 12 is used to perform structured processing on the initial data of the cryptographic assets to obtain a target cryptographic material list, and input the target cryptographic material list into a preset logic rule decision engine to obtain the agility status grade corresponding to each asset node in the target cryptographic material list. The evaluation result acquisition module 13 is used to dynamically assign weights to each asset node based on the agility status classification to obtain the target weight coefficient, and to determine the software agility score and hardware agility score corresponding to the target industrial control equipment based on the initial data of the cryptographic assets. The strategy determination module 14 is used to determine the industrial control cryptography agility assessment result based on the target weight coefficient, the software agility score and the hardware agility score, so as to determine the cryptography migration strategy of the target industrial control equipment based on the industrial control cryptography agility assessment result.

[0044] As can be seen, this application obtains multi-source results by performing corresponding probing methods for different physical isolation levels, and then performs weighted fusion and conflict resolution based on pre-set confidence weights to obtain unified and reliable initial data for cryptographic assets. Then, the data is structured into a target cryptographic material list, input into a logical rule decision engine, and outputs an agility status classification for each asset node. Based on the classification, software and hardware weight coefficients are dynamically allocated, and software agility scores and hardware agility scores are quantified separately according to the initial cryptographic asset data. Finally, a weighted calculation yields a comprehensive evaluation result. In this way, multi-source fusion eliminates single-source bias, incorporates physical barriers into the evaluation scale, and ensures that migration strategies accurately match the actual modification conditions of devices with different security levels, avoiding decision-making errors caused by pure software evaluation detached from physical constraints.

[0045] In some specific embodiments, the initial data acquisition module 11 may specifically include: The message parsing unit is used to send an encrypted handshake inducement message to the service port of the first target industrial control device, and parse the response message corresponding to the encrypted handshake inducement message to obtain the cryptographic suite and public key signature parameters of the first target industrial control device. The image processing unit is used to acquire the firmware binary image of the second target industrial control equipment, locate the storage address of the cryptographic algorithm in the firmware binary image based on the preset cryptographic constant feature library, and calculate the call stack depth and static offset from the business calling function to the cryptographic primitive. The evaluation result determination unit is used to construct an abstract syntax tree of the source code of the third target industrial control equipment to identify password-related function calls, and to perform algorithm strength evaluation based on the password-related function calls to obtain the corresponding evaluation result; The timing feature acquisition unit is used to parse the encryption negotiation session of the fourth target industrial control device in order to extract the corresponding cipher suite, certificate information and key exchange timing features; The offline data acquisition unit is used to receive offline survey data entered by the fifth target industrial control device through a structured template; the offline survey data includes at least the device model, the cryptographic algorithms claimed to be supported, and hardware-based determination information.

[0046] In some specific embodiments, the initial data acquisition module 11 may specifically include: The weight value setting unit is used to set a preset confidence weight value for the cryptographic asset detection result based on the asset detection method. The conflict determination unit is used to determine whether there is a conflict between multiple cryptographic asset detection results targeting the same industrial control equipment. The conflict handling unit is used to perform a weighted calculation on the conflicting cryptographic assets based on the preset confidence weight value if a conflict exists, and to perform a conflict resolution operation on the conflicting cryptographic assets according to the weighted calculation result to obtain the processed assets. The data determination unit is used to determine the initial data of the fused cryptographic assets based on the processed assets, so as to obtain the initial data of the cryptographic assets.

[0047] In some specific embodiments, the level determination module 12 may specifically include: The cryptographic processing unit is used to perform structured processing on the initial data of the cryptographic assets to obtain a hard-coded status bit field, a physical coupling degree field, and a security partition level field; the hard-coded status bit field is used to characterize the hardware solidification state of the corresponding asset node; the physical coupling degree field is used to characterize the degree of physical coupling between the asset node and the business logic; and the security partition level field is used to characterize the physical security partition level to which the asset node belongs. The bill of materials determination unit is used to determine the target cryptographic bill of materials based on the hard-coded status bit field, the physical coupling degree field, and the security partition level field.

[0048] In some specific embodiments, the level determination module 12 may specifically include: The first classification determination unit is used to determine the agility status classification of the asset node as unresponsive if the security partition level field corresponding to the asset node is the preset highest security level and the hard-coded status bit represents hardware solidification. The second classification determination unit is used to determine the agility status classification of the asset node as black-box coupling level if the hard-coded status bit field corresponding to the asset node represents non-hardware solidification and the physical coupling degree is greater than a preset coupling degree threshold. The third classification determination unit is used to classify the agility status of the asset node as interface decoupling level if the asset node has an independent external cryptographic interface calling engine. The fourth classification determination unit is used to determine the agility status classification of the asset node as dynamic negotiation level if the asset node supports dynamic negotiation switching of multiple cryptographic suites.

[0049] In some specific embodiments, the evaluation result acquisition module 13 may specifically include: The first weight coefficient allocation unit is used to allocate a hardware weight coefficient greater than the software weight coefficient to the asset node if the agility status level corresponding to the asset node is a preset low level, so as to obtain the target weight coefficient. The second weight coefficient allocation unit is used to allocate a software weight coefficient to the asset node that is greater than the hardware weight coefficient if the agility status level corresponding to the asset node is a preset high level, so as to obtain the target weight coefficient.

[0050] In some specific embodiments, the evaluation result acquisition module 13 may specifically include: The software agility score determination unit is used to determine the software agility score corresponding to the target industrial control equipment by weighted calculation based on the call decoupling degree, latency retention degree and resource retention degree in the initial data of the cryptographic assets; The hardware agility score determination unit is used to determine the hardware agility score corresponding to the target industrial control equipment by weighted calculation based on the hardware computing power transformation feasibility coefficient, authentication burden coefficient and resource reserve coefficient in the initial data of the cryptographic assets.

[0051] Furthermore, embodiments of this application also disclose an electronic device, Figure 5 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0052] Figure 5 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the industrial control equipment password migration strategy determination method disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0053] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0054] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0055] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the industrial control equipment password migration strategy determination method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks.

[0056] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned method for determining the password migration strategy for industrial control equipment. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0057] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0058] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0059] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0060] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0061] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method for determining password migration strategies for industrial control equipment, characterized in that, include: Based on the physical isolation level of the target industrial control equipment, the corresponding asset detection methods are executed to obtain the corresponding cryptographic asset detection results. The cryptographic asset detection results are then fused based on a pre-set confidence weight value to obtain the initial cryptographic asset data. The initial data of the cryptographic assets is structured to obtain a target cryptographic material list, and the target cryptographic material list is input into a preset logical rule decision engine to obtain the agility status classification of each asset node in the target cryptographic material list. Based on the agility status classification, dynamic weight allocation is performed on each asset node to obtain the target weight coefficient, and the software agility score and hardware agility score corresponding to the target industrial control equipment are determined based on the initial data of the cryptographic assets. The industrial control system cryptography agility assessment result is determined based on the target weight coefficient, the software agility score, and the hardware agility score, so as to determine the cryptography migration strategy of the target industrial control equipment based on the industrial control cryptography agility assessment result.

2. The method of claim 1, wherein the method further comprises: The method of performing corresponding asset detection based on the physical isolation level of the target industrial control equipment to obtain corresponding cryptographic asset detection results includes: Send an encrypted handshake inducement message to the service port of the first target industrial control device, and parse the response message corresponding to the encrypted handshake inducement message to obtain the cryptographic suite and public key signature parameters of the first target industrial control device; Obtain the firmware binary image of the second target industrial control device, locate the storage address of the cryptographic algorithm in the firmware binary image based on the preset cryptographic constant feature library, and calculate the call stack depth and static offset from the business calling function to the cryptographic primitive. An abstract syntax tree of the source code of the third target industrial control equipment is constructed to identify cryptographic function calls, and an algorithm strength evaluation is performed based on the cryptographic function calls to obtain the corresponding evaluation results; The encryption negotiation session of the fourth target industrial control device is analyzed to extract the corresponding cipher suites, certificate information and key exchange timing characteristics; The offline survey data entered by the fifth target industrial control device is received through a structured template; the offline survey data includes at least the device model, the cryptographic algorithms it claims to support, and hardware-based determination information.

3. The method of claim 1, wherein the method further comprises: The process of fusing the cryptographic asset detection results based on pre-set confidence weight values ​​to obtain initial cryptographic asset data includes: Based on the asset detection method, a pre-set confidence weight value is set for the cryptographic asset detection result; Determine whether there are conflicts among multiple cryptographic asset detection results targeting the same industrial control equipment; If a conflict exists, the conflicting cryptographic assets are weighted based on the preset confidence weight value, and the conflict resolution operation is performed on the conflicting cryptographic assets according to the weighted calculation result to obtain the processed assets. Based on the processed assets, the initial data of the merged cryptographic assets is determined to obtain the initial data of the cryptographic assets.

4. The method of claim 1, wherein the method further comprises: The process of structuring the initial data of the cryptographic assets to obtain the target cryptographic material list includes: The initial data of the cryptographic assets is structured to obtain a hard-coded status bit field, a physical coupling degree field, and a security partition level field. The hard-coded status bit field is used to characterize the hardware solidification state of the corresponding asset node. The physical coupling degree field is used to characterize the degree of physical coupling between the asset node and the business logic. The security partition level field is used to characterize the physical security partition level to which the asset node belongs. The target cryptographic material list is determined based on the hard-coded status bit field, the physical coupling degree field, and the security partition level field.

5. The method of claim 4, wherein the method further comprises: The step of inputting the target cryptographic bill of materials into a preset logic rule decision engine to obtain the agility status classification corresponding to each asset node in the target cryptographic bill of materials includes: If the security partition level field corresponding to the asset node is the preset highest security level and the hard-coded status bit represents hardware fixation, then the agility status level corresponding to the asset node is determined to be the unresponsive level. If the hard-coded status bit field corresponding to the asset node indicates that it is not hardware-fixed and the physical coupling degree is greater than the preset coupling degree threshold, then the agility status level corresponding to the asset node is determined as black box coupling level. If the asset node has an independent external cryptographic interface calling engine, then the agility status level corresponding to the asset node is determined to be the interface decoupling level. If the asset node supports dynamic negotiation and switching of multiple cryptographic suites, then the agility status level corresponding to the asset node is determined to be the dynamic negotiation level.

6. The method of claim 1, wherein the method further comprises: The dynamic weight allocation of each asset node based on the agility status classification to obtain the target weight coefficient includes: If the agility status level corresponding to the asset node is a preset low level, then the hardware weight coefficient assigned to the asset node is greater than the software weight coefficient, so as to obtain the target weight coefficient. If the agility status level corresponding to the asset node is a preset high level, then the software weight coefficient assigned to the asset node is greater than the hardware weight coefficient, so as to obtain the target weight coefficient. The sum of the software weight coefficient and the hardware weight coefficient is a preset value.

7. The method of claim 1 to 6, wherein, The process of determining the software agility score and hardware agility score corresponding to the target industrial control equipment based on the initial data of the cryptographic assets includes: The software agility score corresponding to the target industrial control equipment is determined by weighted calculation based on the call decoupling degree, latency retention degree, and resource retention degree in the initial data of the cryptographic assets. The hardware agility score of the target industrial control equipment is determined by weighted calculation based on the hardware computing power transformation feasibility coefficient, authentication burden coefficient, and resource reserve coefficient in the initial data of the cryptographic assets.

8. A device for determining password migration strategy for industrial control equipment, characterized in that, include: The initial data acquisition module is used to execute the corresponding asset detection method based on the physical isolation level of the target industrial control equipment to obtain the corresponding cryptographic asset detection results, and to fuse the cryptographic asset detection results based on the preset confidence weight value to obtain the initial cryptographic asset data. The grade determination module is used to perform structured processing on the initial data of the cryptographic assets to obtain a target cryptographic material list, and input the target cryptographic material list into a preset logic rule decision engine to obtain the agility status grade corresponding to each asset node in the target cryptographic material list. The evaluation result acquisition module is used to dynamically assign weights to each asset node based on the agility status classification to obtain the target weight coefficient, and to determine the software agility score and hardware agility score corresponding to the target industrial control equipment based on the initial data of the cryptographic assets. The strategy determination module is used to determine the industrial control cryptography agility assessment result based on the target weight coefficient, the software agility score, and the hardware agility score, so as to determine the cryptographic migration strategy of the target industrial control equipment based on the industrial control cryptography agility assessment result.

9. An electronic device, comprising: include: Memory, used to store computer programs; A processor is configured to execute the computer program to implement the method for determining the password migration strategy of industrial control equipment as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Used to store computer programs, which, when executed by a processor, implement the method for determining password migration strategies for industrial control equipment as described in any one of claims 1 to 7.