A method and system for frequency conversion encrypted transmission of natural resource elements driven by environmental thresholds
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-09
- Publication Date
- 2026-08-14
AI Technical Summary
[0004]然而,上述现有技术在应对复杂的工业场景时存在明显缺陷
Smart Images

Figure CN122578281A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of secure communication technology for the Industrial Internet of Things, and relates to a method and system for frequency conversion encrypted transmission of natural resource elements driven by environmental thresholds. Background Technology
[0002] In modern industrial production and critical infrastructure management, precise monitoring and scheduling of natural resources such as water, electricity, and gas are crucial. Industrial Internet of Things (IIoT) technology, through the deployment of numerous sensors and controllers, enables real-time data acquisition and remote control of the physical status of these resources. This massive amount of data needs to be reliably transmitted between devices, edge computing, and cloud control centers to support upper-level applications such as status monitoring, fault diagnosis, and automated control. Therefore, ensuring secure data communication in an open network environment becomes a core requirement of the entire system.
[0003] Currently, to ensure the security of industrial data transmission, the commonly adopted technical solution is to deploy standard encryption protocols at the communication link layer, such as using Transport Layer Security (TLS) or building virtual private network (VPN) channels. At the device level, some systems use pre-configured shared keys or static certificates for device authentication and data encryption. Regarding data acquisition, monitoring systems typically use a fixed sampling frequency and reporting cycle for all monitoring points, polling and collecting environmental monitoring values from each node at fixed time intervals, and then encrypting this data before uploading it to a central server.
[0004] However, the aforementioned existing technologies have significant shortcomings when dealing with complex industrial scenarios. First, encryption mechanisms relying on static keys or universal certificates will render the system security mechanism ineffective if the key is leaked, and the distribution and rotation management of keys becomes increasingly difficult in large-scale device networks. Second, fixed-frequency data collection methods lack flexibility. When a partial system failure occurs, redundant data from a large number of passive alarm nodes triggered by the chain reaction will be reported along with the critical data from the source node, not only wasting network bandwidth but also potentially overwhelming genuine fault information and interfering with timely fault location. Furthermore, existing security mechanisms are often decoupled from the physical process itself. The encryption and decryption processes cannot perceive and verify the physical context of the data, allowing attackers to inject seemingly correct formatted but physically inconsistent forged data or control commands. Summary of the Invention
[0005] In view of this, in order to solve the problems mentioned in the background technology, a frequency conversion encryption transmission method and system for natural resource elements driven by environmental thresholds is proposed.
[0006] The objective of this invention can be achieved through the following technical solution: The first aspect of this invention provides a frequency conversion encryption transmission method for natural resource elements driven by environmental threshold, including: S1, obtaining the physical connection relationship and equipment operation dependency relationship of natural resource elements, constructing a causal directed acyclic graph, and converting the causal directed acyclic graph into a physical causal topology matrix containing physical transmission attributes.
[0007] S2. Collect environmental monitoring values of natural resource elements, compare the environmental monitoring values with environmental safety thresholds, and generate alarm events for exceeding limits.
[0008] S3. Map the over-limit alarm events to the physical causal topology matrix, perform causal intervention analysis, strip away the passive alarm nodes caused by environmental chain reactions, and extract the real intervention nodes located at the source of the causal chain.
[0009] S4. Adjust the network channel of the real intervention node to a preset high-frequency transmission state higher than the daily monitoring frequency to obtain source environmental data, and keep the passive alarm node in a preset low-frequency silent state that meets the basic heartbeat monitoring requirements.
[0010] S5. Extract the physical entropy source based on the structural characteristics and topological centrality of the real intervention node, input the physical entropy source into the nonlinear feedback shift register to generate a dynamic derived key, perform frequency conversion encryption on the transmitted data, and superimpose the identifiers of the real intervention node and its first-order downstream node and the synchronization timestamp as additional verification information into the ciphertext for transmission.
[0011] S6. Receive encrypted source data and decrypt it using the session key to obtain decrypted source data. Verify whether the physical entropy source of the session key matches the physical causal topology matrix. If the match is successful, perform counterfactual reasoning calculation on the decrypted source data to generate the target configuration change strategy.
[0012] S7. Convert the target configuration change strategy into underlying industrial control semantic instructions, perform data slicing on the underlying industrial control semantic instructions and encrypt them using national cryptographic algorithms to generate encrypted instruction slices, and send the encrypted instruction slices to the underlying control gateway to drive the hardware to perform physical state adjustments.
[0013] The second aspect of the present invention provides an environment threshold-driven frequency conversion encrypted transmission system for natural resource elements, comprising: a causal directed acyclic graph construction module, which acquires the physical connection relationships and equipment operation dependencies of natural resource elements, constructs a causal directed acyclic graph, and transforms the causal directed acyclic graph into a physical causal topology matrix containing physical transmission attributes.
[0014] The over-limit alarm event generation module collects environmental monitoring values of natural resource elements, compares the environmental monitoring values with environmental safety thresholds, and generates over-limit alarm events.
[0015] The real intervention node extraction module maps over-limit alarm events to a physical causal topology matrix, performs causal intervention analysis, strips away passive alarm nodes caused by environmental chain reactions, and extracts the real intervention nodes located at the source of the causal chain.
[0016] The source environment data acquisition module adjusts the network channel of the real intervention node to a preset high-frequency transmission state higher than the daily monitoring frequency to acquire source environment data, and keeps the passive alarm node in a preset low-frequency silent state that meets the basic heartbeat monitoring requirements.
[0017] The dynamic derived key generation module extracts the physical entropy source based on the structural characteristics and topological centrality of the real intervention node, inputs the physical entropy source into the nonlinear feedback shift register to generate a dynamic derived key, performs frequency conversion encryption on the transmitted data, and superimposes the identifiers of the real intervention node and its first-order downstream node and the synchronization timestamp as additional verification information into the ciphertext for transmission.
[0018] The target configuration change policy generation module receives encrypted source data and decrypts it using the session key to obtain decrypted source data. It verifies whether the physical entropy source of the session key matches the physical causal topology matrix. If the match is successful, it performs counterfactual reasoning calculations on the decrypted source data to generate the target configuration change policy.
[0019] The encrypted instruction slice generation module converts the target configuration change strategy into underlying industrial control semantic instructions, performs data slicing on the underlying industrial control semantic instructions and encrypts them using national cryptographic algorithms to generate encrypted instruction slices, and sends the encrypted instruction slices to the underlying control gateway to drive the hardware to perform physical state adjustments.
[0020] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects: (1) The present invention constructs a dynamic and physically rooted encrypted communication system by deeply integrating the topology of the physical system with cryptographic mechanisms. It utilizes a local causal topology matrix composed of real intervention nodes and their direct downstream nodes to extract a unique physical entropy source through eigenvalue decomposition, which is used to dynamically derive one-time session keys. The generation of this key is directly related to specific physical failure events and system structure, giving it enhanced unpredictability and contextual uniqueness, effectively improving key security and reducing attacks on static or pre-shared keys.
[0021] This invention achieves efficient and intelligent allocation of communication resources, improving fault response efficiency. Through causal intervention analysis, the system can accurately distinguish the source of a fault chain from affected downstream nodes, thereby adjusting the network channel of the actual intervention node to a high-frequency transmission state while maintaining passive alarm nodes in a low-frequency silent state. This differentiated data acquisition strategy avoids the impact of data storms caused by cascading alarms on network bandwidth, ensuring that the most critical source environmental data can be transmitted in a high-resolution, low-latency manner, providing a high-quality data foundation for subsequent accurate diagnosis and rapid decision-making.
[0022] This invention establishes an end-to-end closed-loop security protection mechanism from data acquisition to command execution. Not only is the source environmental data encrypted and transmitted using a key derived from the physical entropy source, but the subsequently generated control commands are also sliced, timestamped, and encrypted using national cryptographic algorithms. Furthermore, the receiving end verifies the authenticity of the data source by checking the consistency of the physical entropy source, effectively preventing man-in-the-middle forgery and injection attacks. This end-to-end security design, covering both data uplink and command downlink, ensures the integrity, confidentiality, and non-repudiation of the entire monitoring and control loop, safeguarding the physical security of the industrial system.
[0023] This invention, by combining a digital twin inference engine in subordinate features, can accurately predict and verify the effectiveness of configuration change strategies without interfering with the operation of the actual physical system. Furthermore, by using additional mechanisms such as entropy source comparison of additional verification information and fixed-length data block encryption of sequence numbers and timestamps, it not only ensures the integrity of instruction transmission, but also effectively defends against man-in-the-middle injection and replay attacks, thereby improving the security of the underlying industrial communication layer. Attached Figure Description
[0024] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is a schematic diagram of the method steps of the present invention.
[0026] Figure 2 This is a schematic diagram of the system structure connection of the present invention.
[0027] Figure 3 This is a schematic diagram of the closed-loop digital twin counterfactual deduction of the present invention.
[0028] Figure 4 This is a diagram of the underlying message data slicing and encryption encapsulation structure of the present invention. Detailed Implementation
[0029] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0030] Please see Figure 1 The first aspect of the present invention provides a frequency conversion encryption transmission method for natural resource elements driven by environmental thresholds, comprising: S1, obtaining the physical connection relationship and equipment operation dependency relationship of natural resource elements, constructing a causal directed acyclic graph, and converting the causal directed acyclic graph into a physical causal topology matrix containing physical transmission attributes.
[0031] In a specific embodiment of the present invention, the physical connection relationship and equipment operation dependency relationship of natural resource elements are obtained, a causal directed acyclic graph is constructed, and the causal directed acyclic graph is transformed into a physical causal topology matrix containing physical conduction attributes, including: identifying the flow direction nodes of the natural resource pipeline network and the machine tool equipment nodes attached to the flow direction nodes, and determining the material flow direction and energy transfer path between nodes.
[0032] Directed edges are established between nodes based on the direction of material flow and the path of energy transfer, generating a causal directed acyclic graph.
[0033] Extract the physical propagation delay parameters and capacity constraint parameters of each directed edge in the causal directed acyclic graph, and fill the adjacency matrix with the physical propagation delay parameters and capacity constraint parameters to generate the physical causal topology matrix.
[0034] Specifically, this step aims to abstract and quantify the physical relationships between natural resource elements and the operational dependencies between equipment in an industrial scenario into a mathematical model that is easy for computers to process. The entire process begins with an in-depth analysis of the physical system, which first requires identifying all key components involved in the flow and consumption of resources within the system.
[0035] The first step is to identify the flow nodes of the natural resource pipeline network and the machine tool equipment nodes attached to them. Flow nodes refer to locations in the natural resource (such as cooling water, compressed air, and electricity) transmission network where the flow of resources converges, diverges, or changes in state; examples include pipe tees, valves, and transformers. Machine tool equipment nodes are the terminal units that consume these natural resources, such as CNC machine tools and stamping equipment, which are connected to the flow nodes via pipelines or cables. After identifying the nodes, it is necessary to determine the direction of material flow and the path of energy transfer between them. The direction of material flow describes the physical path of physical resources (such as water and air) flowing from one node to another. The path of energy transfer describes the transmission relationship of non-physical resources (such as electrical energy) from the power supply node to the power consumption equipment. The determination of these directions and paths is based on the system's engineering design drawings, pipeline layout diagrams, and equipment operation manuals, which together form the basis of the causal relationships within the system.
[0036] Once all nodes and their relationships are identified, directed edges can be established between nodes based on the direction of matter flow and the path of energy transfer, generating a causal directed acyclic graph (DAG). A DAG is a graphical data structure where nodes represent flow nodes or machine tool nodes in the system, and directed edges represent definite, unidirectional causal relationships between nodes. For example, if water flows from node A to node B, a directed edge from A to B is drawn in the graph, indicating that the change in state of A is the cause of the change in state of B. This graph is designed to be acyclic because in physical systems, the transfer of matter or energy follows a time series and does not form instantaneous self-circulation.
[0037] The final step is to transform this graphical structure into a numerical matrix representation. This is achieved by extracting the physical propagation delay and capacity constraint parameters of each directed edge in the causal directed acyclic graph and filling these parameters into the adjacency matrix, thus generating the physical causal topology matrix. The physical propagation delay parameter refers to the time required for a node's state change to propagate to its direct downstream nodes. The capacity constraint parameter represents the maximum resource flow that the path connecting two nodes can carry. These two parameters are crucial for describing the true properties of physical connections. The physical causal topology matrix is a two-dimensional array where the row and column indices correspond to node numbers in the system. If there is no direct connection between two nodes, the corresponding element in the matrix has an empty value or a specific identifier. If a connection exists, the element stores a data pair containing the physical propagation delay and capacity constraint parameters.
[0038] The specific calculation method for the physical conduction delay parameter is related to the resource type. For fluid resources, the calculation formula is:
[0039] In the formula, Represents the node To the node The physical conduction delay parameter, in seconds. It is a connection node To the node The actual length of the pipe or line, in meters. This is the average transmission rate of resources in pipelines or lines, measured in meters per second. Both of these fundamental data are obtained by consulting system design documents or conducting on-site measurements. For example, based on the analysis of 500 industrial equipment design blueprints and pipeline construction drawings, the length and design flow velocity of each pipeline section can be accurately determined.
[0040] The calculation of capacity limitation parameters also depends on the properties of the physical medium. For example, for fluid in a pipe, the calculation formula is:
[0041] In the formula, Represents the node To the node The capacity limit parameter is expressed in cubic meters per second. It is the cross-sectional area of the pipe connecting the two nodes, in square meters. It is the maximum safe flow rate allowed by the pipe material and design specifications, and the unit is meters per second.
[0042] For non-physical resources (such as electrical energy), their transmission delay and capacity limitations must be calculated based on electrical characteristics. The formula for calculating their physical conduction delay parameters is as follows: ,in The speed at which an electrical signal propagates in a conductive medium (a specific proportion close to the speed of light), measured in meters per second; the formula for calculating its capacity limitation parameter is: ,in The unit is watt or volt-ampere. This is the maximum safe current carrying capacity of the line connecting the two nodes, measured in amperes. This is the rated operating voltage of the transmission line, measured in volts.
[0043] Through the above process, the final physical causal topology matrix is generated. Its elements Defined as:
[0044] in, Represents the node To the node The connection attribute. If the node To the node If there is no direct directed edge, then It can be represented as This matrix, representing infinite latency and zero capacity, not only encodes the connections between nodes but also incorporates key physical constraints, providing a precise mathematical basis for subsequent causal analysis and system intervention.
[0045] For example, suppose a workshop's cooling water supply system needs to have its physical causal topology matrix constructed.
[0046] First, four key nodes were identified in the system: Node 1 is the main water supply valve, a flow node; Node 2 is the cooling water circulation pump, which is both a flow node and an equipment node; Node 3 is machine tool A, a machine tool node; and Node 4 is machine tool B, another machine tool node. By analyzing the pipeline diagram, the material flow direction was determined to be: cooling water from the main water supply valve flows to the cooling water circulation pump, and then the cooling water circulation pump supplies cooling water to machine tool A and machine tool B respectively. Therefore, the energy transfer path is consistent with the material flow direction.
[0047] Next, directed edges are established based on the determined flow direction. A directed edge e(1,2) is established connecting node 1 to node 2; a directed edge e(2,3) is established connecting node 2 to node 3; and a directed edge e(2,4) is established connecting node 2 to node 4. These three directed edges, together with the four nodes, form a causal directed acyclic graph.
[0048] Finally, physical parameters were extracted and a physical causal topology matrix was generated. Based on field surveys and equipment manuals, the following data was obtained: the length of the pipe connecting e(1,2). The design average flow rate is 20 meters. The speed is 2 m / s, and the cross-sectional area of the pipe is... The maximum safe flow rate is 0.01 square meters. The speed is 2.5 m / s. The length of the pipe connecting e(2,3) is... The design average flow velocity is 10 meters. The speed is 1 m / s, and the cross-sectional area of the pipe is... The maximum safe flow rate is 0.005 square meters. The speed is 1.5 m / s. The length of the pipe connecting e(2,4) is... The design average flow rate is 15 meters. The speed is 1 m / s, and the cross-sectional area of the pipe is... The maximum safe flow rate is 0.005 square meters. It is 1.5 m / s.
[0049] Calculate the physical conduction delay parameters for each side: .
[0050] Calculate the capacity limit parameters for each side: cubic meters per second cubic meters per second cubic meters per second.
[0051] Ultimately, the generated 4x4 physical causal topology matrix As shown below, unconnected elements are represented by... express: This matrix accurately describes the causal relationships, time delays, and transmission capacity between nodes in the cooling water system, completing the entire process of step S1.
[0052] S2. Collect environmental monitoring values of natural resource elements, compare the environmental monitoring values with environmental safety thresholds, and generate alarm events for exceeding limits.
[0053] Specifically, after constructing the physical causal topology matrix describing the system's physical structure, the core task of this step is to monitor the operational status of each natural resource element in the system in real time and promptly detect any abnormalities deviating from normal operating conditions. This process is achieved by continuously collecting environmental monitoring values and comparing them with preset environmental safety thresholds.
[0054] First, the system collects data from all flow nodes and machine tool nodes identified in step S1. Sensors deployed on these nodes, such as pressure gauges, thermometers, flow meters, or voltmeters, periodically measure physical quantities related to natural resource elements; these measurements are the environmental monitoring values. Environmental monitoring values are instantaneous data reflecting the state of a node at a specific moment, such as the cooling water inlet temperature of a machine tool node or the internal pressure of a main air supply pipeline.
[0055] After acquiring environmental monitoring values, the system immediately compares them with the corresponding environmental safety thresholds. Environmental safety thresholds are not single values, but rather a range of values defining the normal and safe operating state of equipment or pipelines, including an upper limit and a lower limit. The setting of this range is based on rigorous criteria, typically combining the operating manuals provided by the equipment manufacturer, national or industry-issued safety production standards, and the results of statistical analysis of massive amounts of historical data collected during the system's long-term stable operation. For example, a threshold might be based on the analysis of 10,000 hours of fault-free operation data, taking the mean plus or minus three standard deviations as the safe operating range.
[0056] In one specific embodiment of the present invention, the typical range of environmental safety threshold values in a cooling water system is specifically reflected in the outlet pressure range of the circulating pump. and the water inlet pressure range of machine tool equipment The threshold setting was based not only on the equipment operation manual and national industry safety standards, but more importantly, on the statistical analysis of massive historical operating data. Specifically, it involved extracting 10,000 hours of fault-free historical operating data from the equipment, calculating the mainstream mean of physical characteristics, and then taking the mean plus or minus three standard deviations. "To establish safe operating boundaries."
[0057] When a node's environmental monitoring value exceeds its environmental safety threshold (i.e., above the upper limit or below the lower limit), the system determines that the node has malfunctioned and immediately generates an over-limit alarm event. An over-limit alarm event is a structured data record; it is not merely a simple alarm signal, but contains detailed contextual information that triggered the alarm, such as the node identifier where the malfunction occurred, the exact timestamp of the event, the specific environmental monitoring value that caused the alarm, and the environmental safety threshold that was breached.
[0058] This decision-making process can be precisely described by a logical expression. For any node in the system... At a certain point in time The status is determined by an alarm function. Decide:
[0059] In the formula, For nodes In time The alarm status is set to 1, indicating that an over-limit alarm event has been generated, and 0, indicating that the status is normal. It is in time Collected nodes Environmental monitoring values, whose units are consistent with the specific physical quantities, such as megapascals. or Celsius . and These are nodes The upper and lower limits of the set environmental safety thresholds, and their units and... They are exactly the same, ensuring consistency of dimensions. When When the value changes from 0 to 1, an over-limit alarm event containing detailed information is created and logged.
[0060] For example, continuing the cooling water supply system case established in step S1, the system includes node 1 (main water supply valve), node 2 (cooling water circulation pump), node 3 (machine tool A), and node 4 (machine tool B). Now, step S2 is performed on this system.
[0061] First, pressure sensors were deployed at nodes 2, 3, and 4 to collect environmental monitoring values, specifically the inlet or outlet water pressure at each node. Based on the equipment operation manual and statistical analysis of 2000 hours of stable operation data, environmental safety thresholds were set for these nodes.
[0062] For node 2 (circulation pump), its normal outlet pressure should be maintained at Therefore, its environmental safety threshold is set to approximately [value missing]. ,Right now , For nodes 3 and 4 (machine tool equipment), the normal inlet water pressure should be within [specific range]. Nearby, an environmental safety threshold is set as follows: ,Right now .
[0063] During system operation, the monitoring system continuously collects environmental monitoring values from each node. Assuming at the timestamp... At that time, environmental monitoring values were collected at node 2. The system performs a comparison: ,and .because ,satisfy conditions.
[0064] Therefore, the system determines that node 2 has malfunctioned and generates an over-limit alarm event. This event is recorded as: {Node ID: 2, Timestamp: 10:00:00, Environmental Monitoring Value: 0.38} Environmental safety threshold: [0.4, 0.6] }
[0065] Due to physical conduction delay parameters The pressure anomaly at node 2 will affect node 3 in 10 seconds. (Timestamp) At that time, the system collected environmental monitoring values at node 3. It is 0.24 .
[0066] The system performs a comparison: ,and .because ,satisfy The system generates a second over-limit alarm event for node 3: {Node ID:3, Timestamp:10:00:10, Environmental Monitoring Value:0.24}. Environmental safety threshold: [0.25, 0.35] }
[0067] Similarly, due to the physical conduction delay parameter Seconds, in timestamps At that time, the system collected environmental monitoring values at node 4. .
[0068] The system performs a comparison: ,and .because ,satisfy The system generates a third over-limit alarm event for node 4: {Node ID: 4, Timestamp: 10:00:15, Environmental Monitoring Value: 0.23}. Environmental safety threshold: [0.25, 0.35] }
[0069] At this point, step S2 is complete, and its output is three consecutive over-limit alarm events generated within 15 seconds. These events will be used as input for the causal analysis in the subsequent step S3.
[0070] S3. Map the over-limit alarm events to the physical causal topology matrix, perform causal intervention analysis, strip away the passive alarm nodes caused by environmental chain reactions, and extract the real intervention nodes located at the source of the causal chain.
[0071] In a specific embodiment of the present invention, the over-limit alarm event is mapped to a physical causal topology matrix, causal intervention analysis is performed, passive alarm nodes generated by environmental chain reactions are stripped away, and the real intervention nodes located at the source of the causal chain are extracted, including: locating multiple initial alarm nodes corresponding to the over-limit alarm event in the physical causal topology matrix.
[0072] Block the in-degree edges pointing to the initial alarm nodes in the physical causal topology matrix, and calculate the probability of state change for each initial alarm node after blocking.
[0073] Nodes whose state change probability is not affected by in-degree edge blocking are selected as real intervention nodes, and nodes whose state change probability is reduced due to in-degree edge blocking are marked as passive alarm nodes.
[0074] Specifically, after the system generates a series of limit-breaking alarm events, this step aims to accurately identify the root cause of the problem from the surface-level, chain-reaction alarms using a method called causal intervention analysis. This process utilizes the physical causal topology matrix constructed in step S1 to perform in-depth analysis of the alarm events generated in step S2, ultimately classifying alarm nodes into two categories: real intervention nodes that truly require intervention, and passive alarm nodes that are merely the result of fault propagation.
[0075] The first step in this process is to locate the multiple initial alarm nodes corresponding to the out-of-limit alarm events in the physical causal topology matrix. Initial alarm nodes refer to the set of all nodes whose environmental monitoring values exceeded the environmental safety threshold and generated out-of-limit alarm events in step S2. The system will traverse all alarm events, extract the node identifiers, and form a list of initial alarm nodes to be analyzed.
[0076] Next, the core operation of causal intervention analysis is to block the in-degree edges pointing to the initial alarm nodes in the physical causal topology matrix and calculate the state change probability of each initial alarm node after blocking. Here, "blocking in-degree edges" is a logical, analogous operation aimed at assessing the extent to which the abnormal state of each initial alarm node is transmitted from the abnormality of its upstream nodes. For this, it is necessary to calculate the state change probability in two scenarios: before intervention and after intervention. The state change probability is defined here as the probability that a node transitions to an alarm state.
[0077] The probability of state change before intervention is calculated based on the actual observed system state. For an initial alarm node... Its state change probability It depends on two factors: the node's own inherent instability, and all its upstream parent nodes. The influence of the state propagated through physical connections. This can be represented as:
[0078] In the formula, Represents a node It is in alarm mode. It is a node The inherent alarm probability is a dimensionless probability value representing the tendency of the node to malfunction or malfunction without any external influence. This value is set based on the equipment's mean time between failures (MTBF) or long-term operation and maintenance records. For example, based on the analysis of failure data from 500 similar water pumps over the past three years, a corresponding inherent alarm probability can be set: 0.1 for relatively vulnerable components (such as circulating pumps), and 0.01 for more stable terminal entities (such as machine tools).
[0079] In the physical causal topology matrix, all nodes that directly point to each other are... The set of parent nodes. Parent node The observed state, if the node It is also an initial alarm node, then ,otherwise . From the parent node To child nodes The anomaly propagation probability quantifies how likely an anomaly in a parent node will trigger an anomaly in its child nodes. This probability is closely related to the properties of physical connections, and its calculation method is as follows:
[0080] In the formula, From node To the node The capacity limit parameters are expressed in cubic meters per second or amperes, etc. It is the largest capacity constraint parameter in the entire system among subnets belonging to the same type of natural resource (i.e., media of the same dimension) as the connection, and is used as a normalization factor to ensure... It is a dimensionless value between 0 and 1. The physical meaning of this formula is that the smaller the connection capacity is relative to the system's maximum capacity, the more likely the connection is to become a bottleneck, leading to a higher probability of anomaly propagation. For heterogeneous topology networks containing multiple media such as water and electricity, the maximum capacity limit parameters for each corresponding medium need to be extracted for different resource subnets and then processed into dimensionless values.
[0081] The probability of state change after intervention, i.e., the probability after "blocking in-degree edges," simulates the situation after cutting off all upstream influences. At this point, the node... An alarm can only be caused by its own internal factors. Therefore, the probability of its state change is... This is equivalent to its inherent alarm probability:
[0082] The final step involves comparing the probabilities of state changes before and after intervention to identify the truly intervened nodes. If a node's state change probability is unaffected by blocking its in-degree edge, it means its alarm probability hardly changes before and after intervention. This indicates that its alarm state is primarily determined by its own factors, rather than being transmitted from upstream. Such nodes are identified as truly intervened nodes. Conversely, if a node's state change probability significantly decreases after blocking its in-degree edge, it indicates that its alarm state is highly dependent on the input from upstream nodes; it is merely one link in a chain reaction and is therefore marked as a passive alarm node. The selection criterion can be expressed as: like Then the node This represents the actual intervention node.
[0083] like Then the node This is a passive alarm node.
[0084] in, It is a threshold used to determine whether a change in probability is significant, and is usually set to a value close to 0.
[0085] In a specific embodiment of the present invention, the significance determination threshold is... The typical value is explicitly defined as 0.001 in the causal analysis embodiment (i.e., a value infinitely close to 0). The setting of this parameter is not based on subjective guesswork, but strictly on the "range of calculation error allowed by the system". That is, it is based on engineering practice and is specifically used to absorb and filter the extremely small precision errors generated by the computer when performing calculations on huge matrices and floating-point formulas. This proves that the alarm probability of a certain node before and after intervention has actually reached a truly "unchanged" isolation state.
[0086] As an example, continuing with the aforementioned cooling water supply system case, in step S2, the system generates over-limit alarm events for nodes 2, 3, and 4.
[0087] First, locate the initial alarm nodes. Based on the alarm events, the initial set of alarm nodes is {2,3,4}.
[0088] Next, we will conduct a causal intervention analysis.
[0089] Based on the equipment's historical maintenance records, the inherent alarm probability of each node is set: Node 2 is a circulating pump, which is relatively vulnerable, and is set as follows: Nodes 3 and 4 are machine tools, which are relatively stable and are set... .
[0090] Based on the capacity limitation parameters obtained in step S1 Determine the maximum capacity of the system. cubic meters per second. Calculate the probability of anomaly propagation: .
[0091] Now, calculate the probability of state change before and after intervention for each initial alarm node: For node 2, its parent node is node 1. Node 1 did not issue any alarms, so its observation status is... . , For node 3, its parent node is node 2. Node 2 has triggered an alarm, so its observation status... . , For node 4, its parent node is also node 2, and the observed state is... . , .
[0092] Finally, filter and tag the nodes. Set a threshold. .
[0093] For node 2: The probability remained unaffected, therefore node 2 was selected as the actual intervention node. For node 3: The probability is significantly reduced, therefore node 3 is marked as a passive alarm node. For node 4: The probability is significantly reduced, therefore node 4 is marked as a passive alarm node.
[0094] Through this series of calculations, the system successfully separated the passive alarm nodes (nodes 3 and 4) generated by the chain reaction from the three alarm nodes, and accurately extracted the real intervention node (node 2) located at the source of the causal chain.
[0095] S4. Adjust the network channel of the real intervention node to a preset high-frequency transmission state higher than the daily monitoring frequency to obtain source environmental data, and keep the passive alarm node in a preset low-frequency silent state that meets the basic heartbeat monitoring requirements.
[0096] Specifically, after successfully identifying the actual intervention node at the source of the causal chain and the passive alarm nodes affected by it in step S3, this step aims to dynamically optimize the data acquisition strategy to concentrate resources on acquiring the most valuable information for fault diagnosis and decision-making. This process adjusts the data communication behavior of different nodes to precisely target the system's focus on the root cause of the problem.
[0097] Based on the output of step S3, the system first sends configuration commands to the communication modules associated with each node. For devices identified as actual intervention nodes, the system adjusts their network channels to a high-frequency transmission state. A network channel refers to the communication link between the sensors or controllers on the node and the central monitoring system for data exchange. High-frequency transmission means the system instructs the node's sensors to sample physical quantities at a higher frequency and report the collected data at a higher frequency. This adjustment aims to acquire source environmental data—a continuous data stream with high temporal resolution from the source of the fault—which is crucial for capturing the dynamic evolution of abnormal states and conducting refined fault analysis.
[0098] Meanwhile, for devices marked as passive alarm nodes, the system maintains their network channels in a low-frequency silent state. Low-frequency silent mode is an energy-saving and bandwidth-saving communication mode. In this mode, the node's sensor sampling frequency and data reporting frequency are reduced to a basic level, used only to maintain basic online status monitoring of the equipment, without uploading large amounts of process data. This effectively avoids network congestion and reduces the burden on the central processing system, as it prevents redundant, secondary alarm data generated by cascading alarms from overwhelming the communication channel.
[0099] This differentiated communication strategy can be formally described using a frequency adjustment function. For any node in the system... Its data transmission frequency The adjustment logic is as follows:
[0100] In the formula, It is a node The adjusted data transmission frequency is expressed in Hertz (Hz). It is a dimensionless classification label, derived from the output of step S3: if the node If it is a real intervention node, then If node If it is a passive alarm node, then . It is the frequency value corresponding to the preset high-frequency transmission state. The setting is based on the analysis of the dynamic response characteristics of the physical process of the fault. For example, based on the data analysis of 300 equipment fault simulation experiments, the minimum sampling frequency that can completely capture the fault characteristics is determined. The typical value is clearly defined as 10Hz in the monitoring embodiment of the cooling water circulation pump. This is a preset frequency value corresponding to a low-frequency silent state. Its setting aims to meet the minimum requirements for equipment heartbeat monitoring, and is typically based on the watchdog timer requirements of industrial network communication protocols. In this embodiment, the typical value is clearly defined in machine tool equipment monitoring as follows: This formula ensures dimensional consistency because the unit of frequency (Hz) is determined solely by... and Introduced, and The switching factor is dimensionless.
[0101] For example, the scenario of the aforementioned cooling water supply system is continued. In step S3, the system has determined that node 2 (cooling water circulation pump) is the actual intervention node, while node 3 (machine tool A) and node 4 (machine tool B) are passive alarm nodes.
[0102] Before the failure occurred, all nodes were operating at normal monitoring frequencies, assuming that... That is, pressure data is collected and reported once per second.
[0103] Based on the analysis of failure modes of rotating equipment such as circulating pumps, in order to capture subtle changes in pressure pulsation, the system's preset high-frequency transmission state frequency is: .
[0104] To maintain basic status monitoring of machine tool equipment, the preset low-frequency silent state frequency is: That is, data is reported every 10 seconds.
[0105] The system performs the following steps in step S4: For node 2, since it is identified as a genuine intervention node, its classification label... The system sends a command to the communication module of node 2 to adjust its data transmission frequency to: .
[0106] Subsequently, the central monitoring system began receiving stress data from node 2 at a frequency of 10 times per second. This high-density data constituted the source environmental data for in-depth analysis.
[0107] For node 3, since it is marked as a passive alarm node, its classification label... The system sends a command to the communication module of node 3 to adjust its data transmission frequency to: Node 4, also marked as a passive alarm node, has the following classification label: The system also sends a command to its communication module to adjust the data transmission frequency to: .
[0108] Through the above adjustments, the system, which originally received 3 data points per second, now receives 100 data points from node 2 every 10 seconds, and 1 data point each from nodes 3 and 4. The focus of data acquisition has been successfully shifted to the source of the fault, while the overall network load has been optimized, laying the foundation for subsequent accurate analysis and secure communication.
[0109] S5. Extract the physical entropy source based on the structural characteristics and topological centrality of the real intervention node, input the physical entropy source into the nonlinear feedback shift register to generate a dynamic derived key, perform frequency conversion encryption on the transmitted data, and superimpose the identifiers of the real intervention node and its first-order downstream node and the synchronization timestamp as additional verification information into the ciphertext for transmission.
[0110] In a specific embodiment of the present invention, a physical entropy source is extracted based on the structural characteristics and topological centrality of the real intervention node. The physical entropy source is input into a nonlinear feedback shift register to generate a dynamically derived key. The transmitted data is then encrypted using frequency conversion. The identifiers of the real intervention node and its first-order downstream nodes, along with the synchronization timestamp, are superimposed on the ciphertext as additional verification information for transmission. This includes: calculating the dimensionless connection weights from the real intervention node to each first-order downstream node based on the propagation delay parameter and capacity limitation parameter of the directed edges connected in the local causal topology matrix.
[0111] For all extracted first-order downstream nodes, the geometric average of the connection weights of the two directed edges from the real intervention node to any two first-order downstream nodes is taken as the symmetric weight representing the intervention correlation. In this way, the downstream correlation symmetric numerical matrix after dedirection processing is constructed as the dimensionality reduction structure tensor matrix representation of the subgraph.
[0112] The principal eigenvalue of the downstream correlation symmetric numerical matrix is calculated as the topological centrality, and when the principal eigenvalue exceeds the global preset divergence threshold, an instruction to increase the local encryption frequency of the subgraph is triggered.
[0113] The downstream correlated symmetric numerical local causal topology matrix is decomposed into eigenvalues to extract the largest real eigenvalue and the corresponding eigenvector, which are then combined with the current synchronization timestamp to form a physical entropy source.
[0114] The physical entropy source is input into a shift register with nonlinear feedback logic for perturbation processing, and the output is a session key that meets the requirements of cryptographic randomness.
[0115] Specifically, after the system has identified the source of the fault and begun high-frequency collection of source environmental data, the core objective of this step is to ensure the confidentiality and integrity of this critical data during transmission. To this end, the system has designed a unique dynamic key generation mechanism. This mechanism utilizes the system's current physical topology as a source of cryptographic randomness to generate a one-time session key, which is then used to encrypt the source environmental data.
[0116] The process begins by extracting a snapshot of a local system directly related to the fault. The system iterates through the real intervention nodes identified in step S3 and searches for all out-degree edges in the global physical causal topology matrix constructed in step S1. An out-degree edge is a directed connection from a real intervention node to other nodes. By extracting the real intervention nodes and all their directly adjacent first-order downstream nodes connected via out-degree edges, the system constructs a smaller local causal topology matrix. This matrix is a subset of the global topology and precisely describes the physical connectivity properties of the fault source and its most direct area of influence.
[0117] Since the original local causal topology matrix stores data pairs containing physical propagation delay and capacity constraint parameters, it needs to be transformed into a single-valued weighted adjacency matrix for subsequent mathematical operations. Each element in the matrix... Represents the node To the node The connection weights are calculated in a way that comprehensively reflects the physical characteristics of the connections.
[0118] In the formula, It is a dimensionless connection weight value. and They are from the nodes To the node The physical conduction delay parameters and capacity limitation parameters. These are dimensionless weighting coefficients used to adjust the relative importance of latency and capacity in the final weighting, and their sum is 1. For example, depending on the system's focus on time sensitivity or traffic bottlenecks, they can be set to... . It is a reference capacity value, such as the average capacity of all connections with the same type of resource (same dimension) within the system, used to normalize the capacity limit parameter and ensure consistency of dimensions. The reference conduction delay constant, for example set to 1 second, is introduced to normalize the delay parameter to ensure dimensional consistency of the formula.
[0119] Next, the system performs eigenvalue decomposition on this numericalized local causal topology matrix to extract its inherent structural information. Eigenvalue decomposition is a mathematical method that decomposes a matrix into its basic components (eigenvalues and eigenvectors). This process satisfies the following relationship:
[0120] in, This is a symmetric downstream association matrix derived from the previous local network step. Since the eigenvalues of the direct adjacency matrix of a causal directed acyclic graph are always zero, to extract the non-zero real eigenvalues representing the structure, the system performs a symmetric mapping: for the dimension-reduced symmetric local matrix composed of all first-order downstream nodes, its off-diagonal elements are redefined as the geometric mean of the connection weights from the intervention node to the corresponding two first-order downstream nodes, i.e. Set the diagonal elements to 0. It is the symmetric matrix An eigenvalue is a scalar that represents the degree to which a matrix stretches a vector in a specific direction. It is related to eigenvalues The corresponding eigenvector indicates the direction of stretching. The system will calculate... The system generates all eigenvalues and eigenvectors, and extracts the largest real-value eigenvalue and its corresponding eigenvector. This combination, uniquely determined by the physical topology associated with the current fault, reflects the system's intrinsic space structure. However, to prevent replay attacks where the session key is identical for each fault due to a static physical structure, the system concatenates or XORs the extracted largest real-value eigenvalue and its corresponding eigenvector with the additional synchronization timestamp generated when the current physical event occurs, forming a physical entropy source. This physical entropy source is the original seed for generating random numbers; its quality directly determines the security of the final key and guarantees the "one-time pad" property of cryptography.
[0121] Finally, this physical entropy source is injected into a random number generator to derive the session key. Specifically, the system inputs the physical entropy source into a nonlinear feedback shift register (NLFSR) for perturbation. The NLFSR is a highly efficient pseudo-random number generation circuit. Its internal nonlinear Boolean function feedback logic effectively avoids the security vulnerability of purely linear structures, which are easily reverse-engineered by the Berlekamp-Massey (BM) algorithm. It receives an initial state (seed) and then generates a seemingly random bit in each clock cycle through its internal feedback logic. By using the physical entropy source, the largest real eigenvalue, and the binary representation of the eigenvector as the initial seed of the NLFSR, and running it for a sufficient number of cycles, the register outputs a bit sequence that meets the requirements of cryptographic randomness. This bit sequence is the session key used for this communication.
[0122] After obtaining the session key, the system uses a symmetric encryption algorithm, such as the SM4 algorithm released by the State Cryptography Administration, to encrypt the source environmental data collected at high frequency, and finally generate encrypted source data, ensuring that the data cannot be deciphered even if it is intercepted during transmission.
[0123] For example, we continue with the case based on the cooling water supply system. Steps S3 and S4 have identified node 2 as the actual intervention node and have begun high-frequency data acquisition from it.
[0124] First, extract the local causal topology matrix. The actual intervention node is node 2. In the global physical causal topology matrix, the out-degree edges of node 2 point to nodes 3 and 4. Therefore, the adjacent first-order downstream nodes are nodes 3 and 4. Extract the local causal topology matrix formed by nodes {2,3,4}.
[0125] Based on the data from step S1: , Assume the system reference capacity. cubic meters per second, reference conduction delay constant Seconds, weighting coefficient .
[0126] Computing numerical matrices Elements: .
[0127] To facilitate eigenvalue decomposition, a symmetric 2x2 matrix is constructed to represent the association between nodes 3 and 4 caused by their common upstream node 2. Its diagonal elements are 0, and the off-diagonal elements are the geometric mean of the connection weights between the two nodes. .
[0128]
[0129] Next, for Perform eigenvalue decomposition.
[0130] Solve the equation ,Right now The eigenvalues are obtained. The largest real eigenvalue is Its corresponding eigenvector By solving Obtain, for Therefore, the sources of physical entropy are combined into .
[0131] Then, generate the session key.
[0132] The numerical values in the physical entropy source are converted to binary representation. For example, 0.4133 and 0.707 are converted to fixed-point binary numbers and concatenated to form an initial seed, such as "011010011...10110101". This seed is loaded into a 128-bit non-linear feedback shift register. The register is started and iterated 128 times, outputting one bit each time. These 128 bits are concatenated to form a 128-bit session key, such as "11010010...01101100".
[0133] Finally, using this 128-bit session key and the SM4 encryption algorithm, the 10Hz source environmental data pressure value sequence collected from node 2 is encrypted to generate encrypted source data, ready for secure transmission.
[0134] See Figure 3 S6. Receive encrypted source data and decrypt it using the session key to obtain decrypted source data. Verify whether the physical entropy source of the session key matches the physical causal topology matrix. If the match is successful, perform counterfactual reasoning calculation on the decrypted source data to generate the target configuration change strategy.
[0135] In a specific embodiment of the present invention, receiving encrypted source data and decrypting it using a session key to obtain decrypted source data, and verifying whether the physical entropy source of the session key matches the physical causal topology matrix, includes: extracting additional verification information during the session key generation process, and parsing the node identifier and synchronization timestamp required for the physical entropy source of the receiving end from the additional verification information.
[0136] The physical entropy source at the receiving end is compared with the corresponding node feature values and synchronization timestamps of the globally stored physical causal topology matrix to generate entropy source comparison results.
[0137] Based on the entropy source comparison results, it is determined whether the encrypted source data has been forged and injected by a man-in-the-middle. When the entropy source comparison results are consistent, the match is deemed successful and counterfactual reasoning calculation is triggered.
[0138] In a specific embodiment of the present invention, after the matching is successful, counterfactual reasoning calculation is performed on the decrypted source data to generate a target configuration change strategy, including: extracting abnormal resource parameters from the decrypted source data and inputting the abnormal resource parameters into the digital twin inference engine.
[0139] In the digital twin simulation engine, the valve opening degree or frequency converter frequency and switching level state corresponding to the real intervention node are virtually changed, and the predicted value of global resource distribution after the virtual change is calculated.
[0140] Evaluate whether the predicted global resource distribution eliminates the resource bottlenecks corresponding to abnormal resource parameters, and output the virtual change actions that can eliminate resource bottlenecks as the target configuration change strategy.
[0141] Specifically, once the encrypted source data carrying critical fault information arrives at the central processing system, this step will execute a complete process including decryption, verification, and decision-making. Its ultimate goal is to automatically generate a target configuration change strategy that can resolve the current problem based on verified real data.
[0142] The entire process begins with data restoration and verification. The system receives the encrypted source data generated in step S5 and decrypts it using the corresponding session key. Since the session key is dynamically derived based on the physical topology, the receiving end needs to reconstruct the session key through the exact same process as the sending end. Based on the currently determined real intervention node and its first-order downstream nodes, the receiving end extracts the same local causal topology matrix from its locally stored global physical causal topology matrix, performs identical eigenvalue decomposition and nonlinear feedback shift register operations, thereby generating the session key for decryption. After decryption, the original, high-resolution decrypted source data is obtained.
[0143] After decryption, the system immediately performs a critical security verification step: verifying whether the physical entropy source of the session key matches the physical causal topology matrix to confirm the authenticity of the data source and prevent man-in-the-middle injection attacks. This process begins by extracting additional verification information from the session key generation process. This information is typically transmitted along with the encrypted data and includes the node identifiers used to generate the physical entropy source, i.e., the IDs of the actual intervening node and its first-order downstream nodes. The system parses these node IDs from the additional verification information and, based on these IDs, recalculates a reference physical entropy source from the locally stored global physical causal topology matrix. This entropy source generated locally at the receiving end is called the receiving end physical entropy source.
[0144] Subsequently, the system performs a consistency comparison between the physical entropy source at the receiving end and the physical entropy source declared by the sending end in the additional verification information, generating an entropy source comparison result. This comparison process can be quantified using a distance function:
[0145] In the formula, It is a dimensionless measure of entropy source difference. These are the largest real eigenvalue and the corresponding eigenvector calculated by the receiving end, respectively. These are the feature values and feature vectors used in the sender's declaration, parsed from the additional verification information. It is the dimension of the feature vector. If Less than a preset minimum tolerance threshold Based on the precision setting of floating-point calculation If the entropy source comparison result is "consistent", the system determines that the data source is trustworthy, the match is successful, and subsequent counterfactual reasoning calculations are triggered.
[0146] Once the data verification is successful, the system begins to execute counterfactual reasoning calculations to generate the target configuration change strategy. The counterfactual reasoning calculations in this invention refer to causal logical deductions performed by the system based on hypothetical action conditions that did not actually occur but are intended to eliminate the fault; this is achieved using digital twin technology. First, the system extracts abnormal resource parameters from the decrypted source data, i.e., the specific values that caused the alarm, such as "pressure below 0.4". This abnormal resource parameter was input into a digital twin simulation engine. The digital twin simulation engine is a real-time, high-fidelity computer simulation model of the entire physical system. It can simulate the flow of matter and energy in the system, and its behavior is constrained by physical causal topology matrices and other physical equations.
[0147] In a digital twin simulation engine, the system virtually changes the controllable physical state of real intervention nodes, such as valve opening, inverter frequency, or switch level. For each virtual change, the engine performs a complete simulation calculation to predict the resource distribution of the entire system under that action, i.e., the global resource distribution prediction. This simulation process can be abstractly represented as:
[0148] in, It is the current global state vector of the system, which contains the monitoring values of all nodes. It is a virtual control action, such as "increase the power of node 2 by 10%". This represents the internal dynamics model of the digital twin simulation engine. In the fluid natural resource scenario of this invention, the internal dynamics model... It is not simply a black box of data fitting, but rather a combination of physical causal topological matrices. The capacity constraint parameters are deeply tied to the partial differential equation solver of the fluid dynamics continuity equation and Bernoulli equation to verify the model. For example, when When the output flow rate or pressure of a node is changed, the model It will be based on the propagation delay parameters between nodes in the matrix. The effects of computational flow resistance and steady-state propagation time are investigated to achieve high-fidelity physical rule-driven computation. It is the future global state vector derived from the deduction, that is, the predicted value of global resource distribution.
[0149] Finally, the system evaluates each global resource distribution prediction to determine if it can eliminate the resource bottlenecks reflected by abnormal resource parameters. If a prediction shows that after implementing a virtual change action, the monitoring values of all nodes have recovered to within their environmental safety thresholds, then this virtual change action is considered effective. The system will select an action that meets the preset comprehensive evaluation indicators from all effective virtual change actions and output it as the target configuration change policy.
[0150] An example is a case of a continuous cooling water supply system.
[0151] The central system receives encrypted source data from node 2. The system knows that the actual intervention node is 2, and its downstream nodes are 3 and 4. Therefore, it independently executes step S5 to calculate the physical entropy source. This process generates a 128-bit session key, "11010010...01101100". Using this key, the system successfully decrypts the data, obtaining the source data, which is a series of pressure values, such as [0.380, 0.381, 0.379,...].
[0152] Next, verification is performed. The system receives additional verification information, which declares the feature value used by the sender. The characteristic value calculated by the receiving end itself is... Perform a consistency check. This value is less than the tolerance threshold. Therefore, the entropy source comparison result is consistent, and the match is successful.
[0153] The system triggers counterfactual reasoning calculations.
[0154] The abnormal resource parameter extracted from the decrypted source data is "Node 2 pressure is 0.38". "Below 0.4" The lower limit is a resource bottleneck. Input this parameter into the digital twin simulation engine. The engine identifies the real intervention node 2 as a water pump. It begins simulating different virtual change actions: Action 1: Increase the operating power of the pump at node 2 by 5%. Engine simulation calculations yield the following global resource distribution prediction: Node 2 pressure 0.39. Node 3 pressure 0.245 Node 4 pressure 0.24 .
[0155] Action 2: Increase the operating power of the pump at node 2 by 10%. Engine simulation calculations yield the following global resource distribution prediction: Node 2 pressure 0.42. Node 3 pressure 0.26 Node 4 pressure 0.255 .
[0156] Evaluate the prediction results. For the predicted value of Action 1, the pressure on nodes 2, 3, and 4 remains below their respective environmental safety thresholds, failing to eliminate the resource bottleneck. For the predicted value of Action 2, the pressure on node 2 is 0.42. In [0.4, 0.6] Within the range, the pressure at node 3 is 0.26. The pressure at node 4 is 0.255. All are within [0.25, 0.35] Within the specified range, the pressure on all relevant nodes has returned to normal, successfully eliminating the resource bottleneck.
[0157] Therefore, the system outputs the virtual change action corresponding to action 2 as the target configuration change strategy: "Increase the operating power of the water pump at node 2 by 10%".
[0158] See Figure 4 S7. Convert the target configuration change strategy into underlying industrial control semantic instructions, perform data slicing on the underlying industrial control semantic instructions and encrypt them using national cryptographic algorithms to generate encrypted instruction slices, and send the encrypted instruction slices to the underlying control gateway to drive the hardware to perform physical state adjustments.
[0159] In a specific embodiment of the present invention, the target configuration change strategy is converted into underlying industrial control semantic instructions, and the underlying industrial control semantic instructions are sliced into data, including: parsing the action objects and action parameters in the target configuration change strategy, and querying the underlying hardware mapping table.
[0160] Based on the underlying hardware mapping table, the action object and action parameters are translated into underlying industrial control semantic instructions that can be directly read by the programmable logic controller.
[0161] Based on the register bit width limitation of the programmable logic controller, the underlying industrial control semantic instructions are divided into multiple fixed-length data blocks to generate an instruction slice set.
[0162] In a specific embodiment of the present invention, the encrypted instruction slices are generated using the national cryptographic algorithm, including: obtaining the sequence number and timestamp of each fixed-length data block in the instruction slice set.
[0163] The national cryptographic algorithm is used in combination with the sequence number and timestamp to encrypt fixed-length data blocks one by one, generating ciphertext data blocks.
[0164] Multiple encrypted data blocks are concatenated and encapsulated in the order of execution to generate encrypted instruction slices.
[0165] Specifically, after generating the target configuration change strategy aimed at solving the fundamental problem in step S6, the task of this step is to transform it from a high-level, human-understandable decision into secure machine instructions that can be directly executed by the underlying industrial hardware. This process involves three core steps: translation, fragmentation, and encryption, to ensure the accurate transmission and secure execution of the instructions.
[0166] The first step in this process is to parse the action objects and action parameters in the target configuration change policy and query the underlying hardware mapping table. The target configuration change policy is a structured instruction, such as "adjust parameter Y of node X to Z". The system first decomposes it into action objects (node X) and action parameters (adjusting parameter Y to Z). Action objects are the device entities that need to perform physical state adjustments, while action parameters define the specific content and target value of the adjustment. Subsequently, the system uses the action objects as indexes to query a pre-configured underlying hardware mapping table. This table is a crucial conversion medium; it establishes the correspondence between logical device identifiers and physical hardware addresses. Its content is set based on the factory's electrical design drawings and network topology, ensuring that each logical node can be accurately mapped to a specific hardware controller and its register address.
[0167] After retrieving information from the underlying hardware mapping table, the system translates the action object and action parameters into low-level industrial control semantic instructions that can be directly read by the programmable logic controller (PLC). The PLC is the core unit used to execute automated control in industrial settings. Low-level industrial control semantic instructions are binary data sequences conforming to a specific industrial communication protocol (such as Modbus-TCP or Profinet). This translation process essentially assembles the target register address, the value to be written, and necessary function codes and checksums into a complete message according to the protocol specifications.
[0168] For example, a translation function can convert logical instructions into a sequence of binary instructions:
[0169] In the formula, It is the generated underlying industrial control semantic instruction, which is a byte sequence. It is the object of the action. These are action parameters. It is hardware information obtained from the underlying hardware mapping table, including controller address, register type, and register address. This represents translation logic that follows specific industry protocols.
[0170] Because industrial networks have limitations on data packet size and the length of data that a programmable logic controller (PLC) can process at one time, potentially excessively long low-level industrial control semantic instructions need to be segmented into multiple fixed-length data blocks, generating instruction slice sets, according to the PLC's register bit width limitations. The register bit width, such as 16 bits or 32 bits, is the basic data processing unit determined by the controller's hardware design. Based on an analysis of 200 mainstream PLC technical manuals, the size of the fixed-length data block is typically set to an integer multiple of this bit width to optimize write efficiency. This process ensures that long instructions can be sent and processed reliably in batches.
[0171] To ensure the security and integrity of instructions during transmission, the system encrypts each fixed-length data block in the instruction slice set using a national cryptographic algorithm. First, the system obtains the sequence number and timestamp of each fixed-length data block. The sequence number identifies the order of the data block within the original instruction, ensuring the receiving end can correctly reassemble it. The timestamp records the time the instruction was generated, used to defend against replay attacks.
[0172] Subsequently, the system uses a national cryptographic algorithm combined with sequence numbers and timestamps to encrypt fixed-length data blocks one by one, generating ciphertext data blocks. Specifically, the SM4 block cipher algorithm can be used. The input to the encryption process is not only the data block itself, but also the concatenation of the data block, sequence number, and timestamp. This ensures that even if two data blocks have the same content, the generated ciphertext will be different due to differences in the sequence number or timestamp. The encryption key is a hardware-level key that is securely shared in advance between the central system and the underlying control gateway.
[0173] The encryption process can be represented as:
[0174] In the formula, It is the generated first A block of encrypted data. It is a pre-shared hardware key. It is the first A fixed-length data block. and These are its serial number and timestamp, respectively. This represents a binary concatenation operation. This means that the concatenated mixed metadata will be padded to the standard 128-bit data block length required by the SM4 algorithm. In this embodiment, the PKCS#7 padding protocol rule is preferred for byte padding, thereby increasing the encryption complexity and preventing tampering.
[0175] Finally, the system concatenates and encapsulates multiple encrypted data blocks in execution order to generate an encrypted instruction slice. This encrypted instruction slice is a final data packet containing all the encrypted data blocks, ready to be sent over the network.
[0176] For example, we continue with the case of the cooling water supply system. The target configuration change strategy for step S6 is: "Increase the operating power of the node 2 water pump by 10%".
[0177] First, the system identifies the action object as "Node 2 water pump" and the action parameter as "increase operating power by 10%". Querying the underlying hardware mapping table, the system obtains the information corresponding to Node 2 water pump: {Controller IP: 192.168.1.20, Protocol: Modbus-TCP, Register Address: 40100, Data Type: 16-bit unsigned integer}. Assuming the current power setting value in the register is 2000, an increase of 10% means an increase of 200, resulting in a new value of 2200.
[0178] Next, the system translates this operation into a Modbus-TCP "write single register" instruction. The target value is 2200 (0x0898 in hexadecimal). The generated low-level industrial control semantic instructions... It is a byte sequence, for example: [Transaction Identifier (2 bytes), Protocol Identifier (2 bytes), Length (2 bytes), Unit Identifier (1 byte), Function Code 0x06 (1 byte), Register Address 40100 (2 bytes), Write Value 0x0898 (2 bytes)], with a total length of 12 bytes.
[0179] Then, assuming the register width of the programmable logic controller is limited to 32 bits (4 bytes), the system will use 12 bytes of... Divide the data into 3 fixed-length blocks to generate a set of instruction slices.
[0180] .
[0181] Subsequently, the system assigns a sequence number and a timestamp to each data block. , , .
[0182] Next, the system uses the pre-shared hardware key. Each data block is encrypted using the SM4 algorithm. ,calculate Generate the first ciphertext data block .right ,calculate Generate a second ciphertext data block. .right ,calculate Generate the third ciphertext data block .
[0183] Finally, the system concatenates the three ciphertext data blocks in sequence and adds metadata containing the total number of slices (3) to the header, encapsulating them into the final encrypted instruction slice, ready to be sent to the underlying control gateway with IP address 192.168.1.20.
[0184] In a specific embodiment of the present invention, the encrypted instruction slice is sent to the underlying control gateway to drive the hardware to perform physical state adjustment, including: receiving the encrypted instruction slice and using the corresponding hardware decryption module to restore the instruction slice set.
[0185] The instruction slice set is reorganized into a complete underlying industrial control semantic instruction according to the sequence number contained in the instruction slice set.
[0186] The underlying industrial control semantic instructions are written into the corresponding hardware registers, and the physical state adjustment is completed by driving the physical relays by changing the level state of the hardware registers.
[0187] Specifically, this step is the endpoint of the entire automated response process, responsible for translating securely encapsulated digital instructions into real physical-world actions. It executes on the underlying control gateway located in the industrial field, ensuring that decisions issued from the cloud or central controller are accurately and securely executed on specific hardware devices.
[0188] The process begins with the lower-level control gateway receiving the encrypted instruction slice generated in step S7. The lower-level control gateway is a dedicated computing device deployed at the edge of the operating technology network, acting as a bridge between information technology systems and industrial control systems. Upon receiving the data, the gateway immediately invokes its internally integrated hardware decryption module to reconstruct the instruction slice set. The hardware decryption module is a dedicated, physically secure cryptographic processor pre-loaded with a hardware key shared with the central system. Using this module for decryption prevents the key from being exposed in the general-purpose operating system memory, thus providing a high level of security. The decryption process is the inverse operation of the encryption process:
[0189] In the formula, It is the restored first A fixed-length data block. This indicates the restoration operation after removing standard padding bytes such as PKCS#7. This represents a function that uses the SM4 algorithm for decryption. It is a pre-shared hardware key. Is the first received A block of encrypted data. and This is the sequence number and timestamp extracted from the metadata portion of the encrypted instruction slice. The gateway verifies the timestamp before decryption. This ensures that the difference between the current time and the specified time is within a preset effective window (e.g., 500 milliseconds). If the difference exceeds this window, it is considered a replay attack and the instruction is discarded, thus guaranteeing the real-time nature and uniqueness of the instruction.
[0190] After successfully decrypting and restoring all fixed-length data blocks to form an instruction slice set, the gateway reassembles these data blocks into complete underlying industrial control semantic instructions according to the sequence numbers contained in the instruction slice set. This is a deterministic sorting and splicing process. The gateway reads the sequence number attached to each data block, rearranges the data blocks in order from 1 to N, and then concatenates them end to end to recover the generated, unsegmented original instructions.
[0191] After reassembly, the underlying control gateway writes the complete low-level industrial control semantic instructions into the corresponding hardware registers. Hardware registers are tiny memory units within the programmable logic controller (PLC) used to store data and control states. The write operation is performed via an industrial network protocol (such as Modbus-TCP), where the gateway sends a write instruction message to the specified IP address and port of the target PLC. When the PLC receives this message and executes it successfully, the binary value of a specific hardware register within it is changed.
[0192] This change in internal value directly alters the voltage level of the physical output port associated with that register. The voltage level refers to the output port's voltage, for example, changing from 0 volts (low level) to 24 volts (high level). This change in voltage level drives an externally connected physical relay to perform an action. A physical relay is an electromechanical switch that generates an electromagnetic force when its control coil receives a high-level signal from the programmable logic controller (PLC), causing the relay's mechanical contacts to close and thus connecting a separate, higher-power circuit. Ultimately, this connected circuit drives the target hardware device (such as a motor or valve) to perform an action, completing the final physical state adjustment.
[0193] For example, the instructions generated in step S7 to resolve the insufficient cooling water pressure problem are continued.
[0194] At the end of step S7, a block of three encrypted data is encapsulated. Encrypted instruction slices are generated and distributed.
[0195] First, the underlying control gateway located at IP address 192.168.1.20 receives this encrypted command slice. The gateway's hardware decryption module extracts the pre-shared hardware key. and to Decryption is performed one by one, while verifying the timestamp. Upon successful decryption, three fixed-length data blocks containing the sequence number are reconstructed, which constitute the instruction slice set. .
[0196] Next, the gateway reassembles the instruction slice set according to the sequence number. It arranges the data blocks in the order of 1, 2, 3 and splices them together to recover a complete 12-byte low-level industrial control semantic instruction, which means "write the value 2200 to register address 40100".
[0197] Finally, the underlying control gateway sends this Modbus-TCP instruction to the programmable logic controller (PLC) controlling the water pump via the network. Upon receiving the instruction, the PLC updates the value of its internal hardware register at address 40100 to 2200. This update causes the voltage level of a port on the digital output module connected to that register to change from low to high. This high-level signal is transmitted to a physical relay, energizing its coil and closing its contacts. The closing of the relay contacts activates the control loop of the water pump's inverter driver, instructing the inverter to increase the water pump's operating power by 10%. The water pump speed increases accordingly, and the pressure in the cooling water network begins to rise, ultimately completing the physical state adjustment aimed at eliminating resource bottlenecks.
[0198] Reference Figure 2 The second aspect of the present invention provides an environment threshold-driven frequency conversion encrypted transmission system for natural resource elements, comprising: a causal directed acyclic graph construction module, an over-limit alarm event generation module, a real intervention node extraction module, a source environmental data acquisition module, a dynamic derived key generation module, a target configuration change strategy generation module, and an encrypted instruction slice generation module.
[0199] The causal directed acyclic graph construction module is connected to the limit-over alarm event generation module. The limit-over alarm event generation module is connected to the real intervention node extraction module. The real intervention node extraction module is connected to the source environment data acquisition module. Both the real intervention node extraction module and the source environment data acquisition module are connected to the dynamic derived key generation module. The dynamic derived key generation module is connected to the target configuration change strategy generation module. The target configuration change strategy generation module is connected to the encrypted instruction slice generation module.
[0200] The causal directed acyclic graph (CAG) construction module obtains the physical connection relationships and equipment operation dependencies of natural resource elements, constructs a causal CAG, and transforms the causal CAG into a physical causal topology matrix containing physical transmission attributes.
[0201] The over-limit alarm event generation module collects environmental monitoring values of natural resource elements, compares the environmental monitoring values with environmental safety thresholds, and generates over-limit alarm events.
[0202] The real intervention node extraction module maps over-limit alarm events to a physical causal topology matrix, performs causal intervention analysis, strips away passive alarm nodes caused by environmental chain reactions, and extracts the real intervention nodes located at the source of the causal chain.
[0203] The source environment data acquisition module adjusts the network channel of the real intervention node to a preset high-frequency transmission state higher than the daily monitoring frequency to acquire source environment data, and keeps the passive alarm node in a preset low-frequency silent state that meets the basic heartbeat monitoring requirements.
[0204] The dynamic derived key generation module extracts the physical entropy source based on the structural characteristics and topological centrality of the real intervention node, inputs the physical entropy source into the nonlinear feedback shift register to generate a dynamic derived key, performs frequency conversion encryption on the transmitted data, and superimposes the identifiers of the real intervention node and its first-order downstream node and the synchronization timestamp as additional verification information into the ciphertext for transmission.
[0205] The target configuration change policy generation module receives encrypted source data and decrypts it using the session key to obtain decrypted source data. It verifies whether the physical entropy source of the session key matches the physical causal topology matrix. If the match is successful, it performs counterfactual reasoning calculations on the decrypted source data to generate the target configuration change policy.
[0206] The encrypted instruction slice generation module converts the target configuration change strategy into underlying industrial control semantic instructions, performs data slicing on the underlying industrial control semantic instructions and encrypts them using national cryptographic algorithms to generate encrypted instruction slices, and sends the encrypted instruction slices to the underlying control gateway to drive the hardware to perform physical state adjustments.
[0207] The above content is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, and all such modifications and additions should fall within the protection scope of the present invention.
Claims
1. A frequency conversion encrypted transmission method for natural resource elements driven by environmental thresholds, characterized in that, include: S1. Obtain the physical connection relationships and equipment operation dependencies of natural resource elements, construct a causal directed acyclic graph, and transform the causal directed acyclic graph into a physical causal topology matrix containing physical transmission attributes; S2. Collect environmental monitoring values of natural resource elements, compare the environmental monitoring values with environmental safety thresholds, and generate alarm events for exceeding limits; S3. Map the over-limit alarm events to the physical causal topology matrix, perform causal intervention analysis, strip away the passive alarm nodes caused by environmental chain reactions, and extract the real intervention nodes located at the source of the causal chain. S4. Adjust the network channel of the real intervention node to a preset high-frequency transmission state higher than the daily monitoring frequency to obtain source environmental data, and keep the passive alarm node in a preset low-frequency silent state that meets the basic heartbeat monitoring requirements. S5. Extract the physical entropy source based on the structural characteristics and topological centrality of the real intervention node, input the physical entropy source into the nonlinear feedback shift register to generate a dynamic derived key, perform frequency conversion encryption on the transmitted data, and superimpose the identifiers of the real intervention node and its first-order downstream node and the synchronization timestamp as additional verification information into the ciphertext for transmission. S6. Receive encrypted source data and decrypt it using the session key to obtain decrypted source data. Verify whether the physical entropy source of the session key matches the physical causal topology matrix. If the match is successful, perform counterfactual reasoning calculation on the decrypted source data to generate the target configuration change strategy. S7. Convert the target configuration change strategy into underlying industrial control semantic instructions, perform data slicing on the underlying industrial control semantic instructions and encrypt them using national cryptographic algorithms to generate encrypted instruction slices, and send the encrypted instruction slices to the underlying control gateway to drive the hardware to perform physical state adjustments.
2. The environmental threshold-driven frequency conversion encrypted transmission method for natural resource elements according to claim 1, characterized in that, The process of acquiring the physical connectivity relationships and equipment operational dependencies of natural resource elements, constructing a causal directed acyclic graph (DAG), and transforming the DAG into a physical causal topology matrix containing physical transmission attributes includes: Identify the flow nodes of the natural resource pipeline network and the machine tool equipment nodes attached to the flow nodes, and determine the direction of material flow and energy transfer path between the nodes; Directed edges are established between nodes based on the direction of material flow and the path of energy transfer, generating a causal directed acyclic graph; Extract the physical propagation delay parameters and capacity constraint parameters of each directed edge in the causal directed acyclic graph, and fill the adjacency matrix with the physical propagation delay parameters and capacity constraint parameters to generate the physical causal topology matrix.
3. The environmental threshold-driven frequency conversion encrypted transmission method for natural resource elements according to claim 1, characterized in that, The process of mapping out-of-limit alarm events to a physical causal topology matrix, performing causal intervention analysis, stripping away passive alarm nodes caused by environmental chain reactions, and extracting the real intervention nodes located at the source of the causal chain includes: Locate the multiple initial alarm nodes corresponding to the out-of-limit alarm events in the physical cause-effect topology matrix; Block the in-degree edges pointing to the initial alarm nodes in the physical causal topology matrix, and calculate the probability of state change of each initial alarm node after blocking. Nodes whose state change probability is not affected by in-degree edge blocking are selected as real intervention nodes, and nodes whose state change probability is reduced due to in-degree edge blocking are marked as passive alarm nodes.
4. The environmental threshold-driven frequency conversion encrypted transmission method for natural resource elements according to claim 1, characterized in that, The process involves extracting the physical entropy source based on the structural characteristics and topological centrality of the actual intervention node, inputting the physical entropy source into a nonlinear feedback shift register to generate a dynamically derived key, performing frequency conversion encryption on the transmitted data, and superimposing the identifiers of the actual intervention node and its first-order downstream nodes along with the synchronization timestamp as additional verification information into the ciphertext for transmission. This includes: Based on the propagation delay parameter and capacity constraint parameter of the directed edges in the local causal topology matrix, the dimensionless connection weights from the actual intervention node to each first-order downstream node are calculated. For all extracted first-order downstream nodes, the geometric average of the connection weights of the two directed edges from the real intervention node to any two first-order downstream nodes is taken as the symmetric weights representing the intervention correlation. In this way, the downstream correlation symmetric numerical matrix after dedirection processing is constructed as the dimensionality reduction structure tensor matrix representation of the subgraph. The principal eigenvalue of the downstream correlation symmetric numerical matrix is calculated as the topological centrality, and when the principal eigenvalue exceeds the global preset divergence threshold, an instruction to increase the local encryption frequency of the subgraph is triggered. Eigenvalue decomposition is performed on the downstream correlated symmetric numerical local causal topology matrix to extract the largest real eigenvalue and the corresponding eigenvector, and then combined with the current synchronization timestamp to form a physical entropy source. The physical entropy source is input into a shift register with nonlinear feedback logic for perturbation processing, and the output is a session key that meets the requirements of cryptographic randomness.
5. The environmental threshold-driven frequency conversion encrypted transmission method for natural resource elements according to claim 1, characterized in that, The process of receiving encrypted source data and decrypting it using the session key to obtain decrypted source data, and verifying whether the physical entropy source of the session key matches the physical causal topology matrix, includes: Extract additional verification information during the session key generation process, and parse the node identifier and synchronization timestamp required by the physical entropy source of the receiving end from the additional verification information; The physical entropy source at the receiving end is compared with the corresponding node feature values and synchronization timestamps of the globally stored physical causal topology matrix to generate entropy source comparison results. Based on the entropy source comparison results, it is determined whether the encrypted source data has been forged and injected by a man-in-the-middle. When the entropy source comparison results are consistent, the match is deemed successful and counterfactual reasoning calculation is triggered.
6. The environmental threshold-driven frequency conversion encrypted transmission method for natural resource elements according to claim 1, characterized in that, The step of performing counterfactual reasoning calculations on the decrypted source data after a successful match to generate a target configuration change strategy includes: Extract abnormal resource parameters from the decrypted source data and input the abnormal resource parameters into the digital twin inference engine; In the digital twin simulation engine, the valve opening degree or frequency converter frequency and switching level state corresponding to the real intervention node are virtually changed, and the predicted value of global resource distribution after the virtual change is calculated. Evaluate whether the predicted global resource distribution eliminates the resource bottlenecks corresponding to abnormal resource parameters, and output the virtual change actions that can eliminate resource bottlenecks as the target configuration change strategy.
7. The environmental threshold-driven frequency conversion encrypted transmission method for natural resource elements according to claim 1, characterized in that, The step of converting the target configuration change strategy into underlying industrial control semantic instructions and performing data slicing on the underlying industrial control semantic instructions includes: Analyze the action objects and action parameters in the target configuration change policy, and query the underlying hardware mapping table; Based on the underlying hardware mapping table, the action object and action parameters are translated into underlying industrial control semantic instructions that can be directly read by the programmable logic controller. Based on the register bit width limitation of the programmable logic controller, the underlying industrial control semantic instructions are divided into multiple fixed-length data blocks to generate an instruction slice set.
8. The environmental threshold-driven frequency conversion encrypted transmission method for natural resource elements according to claim 1, characterized in that, The process of generating encrypted instruction slices using national cryptographic algorithms includes: Obtain the sequence number and timestamp of each fixed-length data block in the instruction slice set; The national cryptographic algorithm is used in combination with sequence number and timestamp to encrypt fixed-length data blocks one by one to generate ciphertext data blocks; Multiple encrypted data blocks are concatenated and encapsulated in the order of execution to generate encrypted instruction slices.
9. The environmental threshold-driven frequency conversion encrypted transmission method for natural resource elements according to claim 1, characterized in that, The step of sending encrypted instruction slices to the underlying control gateway to drive the hardware to perform physical state adjustments includes: Receive encrypted instruction slices and use the corresponding hardware decryption module to restore the instruction slice set; The instruction slice set is reorganized into a complete underlying industrial control semantic instruction according to the sequence number contained in the instruction slice set; The underlying industrial control semantic instructions are written into the corresponding hardware registers, and the physical state adjustment is completed by driving the physical relays by changing the level state of the hardware registers.
10. A frequency conversion encrypted transmission system for natural resource elements driven by environmental thresholds, characterized in that, include: The causal directed acyclic graph (CAG) construction module obtains the physical connection relationships and equipment operation dependencies of natural resource elements, constructs a causal CAG, and transforms the causal CAG into a physical causal topology matrix containing physical transmission attributes. The over-limit alarm event generation module collects environmental monitoring values of natural resource elements, compares the environmental monitoring values with environmental safety thresholds, and generates over-limit alarm events. The real intervention node extraction module maps over-limit alarm events to a physical causal topology matrix, performs causal intervention analysis, strips away passive alarm nodes caused by environmental chain reactions, and extracts the real intervention nodes located at the source of the causal chain. The source environment data acquisition module adjusts the network channel of the real intervention node to a preset high-frequency transmission state higher than the daily monitoring frequency to acquire source environment data, and keeps the passive alarm node in a preset low-frequency silent state that meets the basic heartbeat monitoring requirements. The dynamic derived key generation module extracts the physical entropy source based on the structural characteristics and topological centrality of the real intervention node, inputs the physical entropy source into the nonlinear feedback shift register to generate a dynamic derived key, performs frequency conversion encryption on the transmitted data, and superimposes the identifiers of the real intervention node and its first-order downstream node and the synchronization timestamp as additional verification information into the ciphertext for transmission. The target configuration change policy generation module receives encrypted source data and decrypts it using the session key to obtain decrypted source data. It verifies whether the physical entropy source of the session key matches the physical causal topology matrix. If the match is successful, it performs counterfactual reasoning calculations on the decrypted source data to generate the target configuration change policy. The encrypted instruction slice generation module converts the target configuration change strategy into underlying industrial control semantic instructions, performs data slicing on the underlying industrial control semantic instructions and encrypts them using national cryptographic algorithms to generate encrypted instruction slices, and sends the encrypted instruction slices to the underlying control gateway to drive the hardware to perform physical state adjustments.