An execution validity control device based on uniform identity chain continuity verification

CN122717833APending Publication Date: 2026-09-08GUANGZHOU HONGTENG TECHNOLOGY INVESTMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610565222.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-27
Publication Date
2026-09-08

AI Technical Summary

Technical Problem

[0004]然而,相关技术经过多次拆解流转或受通信影响的控制指令,在传递至下游硬件节点时往往仍能呈现出持有正确访问口令和会话标记的合法特征,但该请求最初锁定的真实责任主体、生效的时间窗口限制以及目标物理设备的控制准入边界,在流转过程中可能已经发生了失效或失配漂移,后续自动化系统因为其格式及凭证验证成功便将其释出执行,使得处于合法局部身份掩护下的越限操作或重放数据能够混入底层硬件驱动序列,降低自动化系统的安全性

Benefits of technology

[0028] 1. The execution effectiveness control device achieves strong binding of the source, content, and flow order of control commands by passing the preceding verification digest and timestamp level by level and using them as part of the verification digest of the next level node. The continuity interlock verification module ensures the logical immutability and unforgeability of the identity chain, while the time-series anti-counterfeiting verification module uses the time laws of the physical world to identify replay attacks that exceed the physical limits of the hardware. Once any verification fails, the effectiveness degradation control module immediately strips the physical execution authority of the command, thereby reducing the problem of broken responsibility chains caused by partial verification and improving the security of the automated system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122717833A_ABST
    Figure CN122717833A_ABST
Patent Text Reader

Abstract

The application discloses an execution validity control device based on uniform identity chain continuity verification and relates to the technical field of automation systems, which is used for improving the security of the automation system.In the device, the execution validity control device realizes the strong binding of the source, content and flow sequence of the control instruction by transmitting the previous verification digest and time stamp to the next level and taking the previous verification digest and time stamp as part of the verification digest of the next level node.The continuity interlocking verification module ensures that the identity chain is logically tamper-proof and unforgeable, and the time sequence anti-forgery verification module discriminates the replay attack beyond the hardware physical limit by using the time law of the physical world.Once any verification fails, the validity degradation control module will immediately strip the physical execution authority of the instruction, thereby reducing the problem of responsibility chain fracture caused by local verification, and further improving the security of the automation system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of automation system technology, and in particular to an execution effectiveness control device based on unified identity chain continuity verification. Background Technology

[0002] With the rapid application of artificial intelligence and automation technologies, automated systems have been widely deployed in high-consequence applications requiring direct manipulation of physical entities, such as energy storage systems, autonomous vehicles, and brain-computer interface devices. In these scenarios, automated systems involve multiple levels of control steps, including state assessment, policy governance, anomaly takeover, and low-level execution. The control actions at different stages are interconnected and irreversible once implemented, placing higher safety demands on the reliability of the source and accountability of the multi-module collaborative mechanisms within the automated control system.

[0003] Related automated systems typically employ source verification schemes based on distributed recording and local state verification. Specifically, these technologies establish authentication logic and record entries in various functional modules, communication network domains, and business approval platforms within the automated system. For example, the application layer's software backend records the operator's main account identifier and the approval conclusions of each node; the gateway layer primarily verifies the device's channel access characteristics; and the underlying execution unit mainly intercepts commands based on the password credentials or short-term session variables attached to the command message. When control commands flow and interact across multiple nodes, system levels, or different operational states, each receiving node compares the local identity variables in the currently received command against its own maintained local security rules and credential database. If the logical legality of the current step is verified correctly, the node generates a release signal to continue advancing the control chain.

[0004] However, control commands that have undergone multiple disassembly and transfer or are affected by communication issues often still exhibit legitimate characteristics of holding the correct access password and session tag when transmitted to downstream hardware nodes. However, the original responsible party, the effective time window limit, and the control access boundary of the target physical device may have become invalid or mismatched during the transfer process. Subsequent automated systems release and execute these commands because their format and credentials have been successfully verified. This allows unauthorized operations or replay data under the cover of legitimate local identities to infiltrate the underlying hardware driver sequence, reducing the security of the automated system. Summary of the Invention

[0005] This application provides an execution effectiveness control device based on unified identity chain continuity verification. It establishes a continuity interlock verification relationship between the preceding identity node and the current identity node, and couples the verification result with the granting or stripping of execution effectiveness for the control instruction to be executed. This is used to restrict control instructions lacking legitimate preceding identity dependencies from obtaining underlying physical execution qualifications. Compared with related technologies that allow control instructions to proceed solely based on local credentials, session variables, or single-node verification results, this application further combines continuity recalculation verification of preceding verification digests with physical timing constraint parameters bound to the underlying hardware to verify the continuity dependency of the control instruction to be executed after cross-layer transfer, and strips its physical execution permissions when verification fails.

[0006] The identity chain continuity verification in this application is used to determine whether the control instruction to be executed still has the conditions to obtain physical execution authority during cross-layer flow. In some embodiments, the verification does not rely on a single login credential or local session token, but combines the previous identity node, the current identity node, control parameters, and physical timing constraint parameters to verify the continuity dependency of the instruction.

[0007] In a first aspect, an execution effectiveness control device based on unified identity chain continuity verification is provided, characterized by comprising: an identity chain parsing module, used to receive cross-layer flow control instructions to be executed, and extract the preceding identity nodes and the current identity node arranged in the flow order; the preceding identity node includes a preceding verification digest and a preceding timestamp generated by the preceding control level, and the current identity node includes a target action digest generated by the current control level, the current timestamp, and the current verification digest; and a continuity interlock verification module, used to perform consistency recalculation verification based on the preceding verification digest and control parameters associated with the current identity node; verifying whether the recalculated digest features are consistent with the current verification digest, and if they are consistent, outputting a logical continuity code, and if they are inconsistent, determining that the identity chain is broken. The system outputs the first exception code; the timing anti-spoofing verification module is triggered when acquiring the logical continuity code, and is used to obtain the preset physical timing constraint parameters bound to the underlying hardware based on the target action summary; it judges whether the timing difference between the current timestamp and the previous timestamp is less than the preset physical timing constraint parameter. If so, it determines that there is an abnormal replay forgery that bypasses the physical limit and outputs the second exception code; otherwise, it outputs the timing compliance code; the effectiveness degradation control module is used to determine that the control instruction to be executed has lost its legitimate cross-layer continuity dependency when the first exception code or the second exception code is received, strips the physical execution permission of the control instruction to be executed to the underlying hardware, and downgrades it to a controlled isolation instruction; when the timing compliance code is received, it grants the control instruction to be executed formal physical drive permission.

[0008] By adopting the above technical solution, the execution effectiveness control device achieves strong binding of the source, content, and flow order of control commands by passing the preceding verification digest and timestamp level by level and using them as part of the verification digest of the next level node. The continuity interlock verification module ensures the logical immutability and unforgeability of the identity chain, while the time-series anti-counterfeiting verification module uses the time laws of the physical world to identify replay attacks that exceed the physical limits of the hardware. Once any verification fails, the effectiveness degradation control module immediately strips the physical execution authority of the command, thereby reducing the problem of broken responsibility chains caused by partial verification and improving the security of the automated system.

[0009] In conjunction with some embodiments of the first aspect, in some embodiments, the current identity node is obtained through a physical anti-counterfeiting generation module. The physical anti-counterfeiting generation module specifically includes: a physical feature acquisition unit, used to acquire the dynamic operating parameters of the underlying hardware of the current control layer, and convert the dynamic operating parameters into dynamic physical feature values, including hardware operating voltage fluctuation values ​​or instruction microarchitecture execution delay; and a digest encapsulation unit, used to perform arithmetic concatenation of the dynamic physical feature values ​​and the control parameters of the control instruction to be executed, and generate the current verification digest through an irreversible hash algorithm.

[0010] By adopting the above technical solution and introducing a physical anti-counterfeiting generation module, the unique and uncopyable dynamic operating parameters of the underlying hardware at a specific moment (such as voltage fluctuations or microarchitecture delays) are used as the key entropy source for generating the current verification digest. This is equivalent to marking each identity node with a unique mark based on physically unclonable features, thereby enhancing the anti-counterfeiting capability of the identity chain.

[0011] In conjunction with some embodiments of the first aspect, in some embodiments, the continuity interlock verification module specifically includes: a context feature extraction unit, used to extract the unique identifier of the controlled device bound to the target action summary and the current session lifecycle identifier from the control instruction to be executed; and a cross-interlock calculation unit, used to concatenate the unique identifier of the controlled device, the current session lifecycle identifier and the previous verification summary into a joint feature vector and then perform a hash operation to obtain a recalculated summary verification value when performing consistency recalculation verification, and to determine whether it is consistent with the current verification summary.

[0012] By adopting the above technical solution, and by additionally introducing the unique identifier of the controlled device and the current session lifecycle identifier in the continuous interlock verification, the continuity verification of the identity chain is strongly bound to the specific device entity and the communication session context. The joint feature vector generated by the cross-interlock calculation unit ensures that only instructions flowing on the correct device and in the correct session can pass the verification. This reduces the risk that legitimate instructions may be maliciously redirected to unexpected devices, or that verification may still pass after the session has been hijacked.

[0013] In conjunction with some embodiments of the first aspect, in some embodiments, the timing anti-counterfeiting verification module specifically includes: a hysteresis parameter matching unit, used to parse the control instruction corresponding to the target action summary to determine the corresponding end effector, and retrieve the shortest hardware response time required for the end effector to complete the physical action, and calibrate the shortest hardware response time as a preset physical timing constraint parameter, the physical action including mechanical displacement or capacitor charging and discharging; a time interval comparison unit, used to calculate the timing difference between the current timestamp and the previous timestamp, the previous timestamp being the time record of the last successful execution bound to the end effector; and an anomaly determination unit, used to determine whether the timing difference is less than the preset physical timing constraint parameter, if so, to determine that there is a high-frequency data injection forgery behavior exceeding the real hardware execution limit, and to output a second anomaly code.

[0014] By adopting the above technical solution, the hysteresis parameter matching unit can dynamically match the shortest hardware response time that conforms to physical laws according to the specific action of the instruction, providing a more accurate physical benchmark for timing judgment. Based on this physical benchmark, the anomaly detection unit judges the timing difference, enabling it to more accurately identify high-frequency data injection forgery behaviors that exploit the high-speed characteristics of the digital world to bypass physical limitations, thereby improving the security of the automated system.

[0015] In conjunction with some embodiments of the first aspect, some embodiments further include an implicit disconnection determination module, which is connected to the identity chain parsing module and is used to calculate the maximum survival time window based on a preset time multiple and preset physical timing constraint parameters. When the identity chain parsing module obtains the current identity node, it starts timing. If no downstream acknowledgment containing legal continuity verification feedback is received before the maximum survival time window expires, it is determined that there is an implicit disconnection in the cross-layer communication, and an implicit disconnection blocking signal is output to the effectiveness degradation control module. The effectiveness degradation control module is used to perform the operation of stripping the physical execution permissions of the control instruction to be executed on the underlying hardware when it receives the implicit disconnection blocking signal.

[0016] By adopting the above technical solution, the implicit link breakage detection module actively monitors the heartbeat of cross-layer communication by setting a dynamic maximum lifetime window based on physical execution time, rather than passively waiting for error reports. If a valid acknowledgment is not received from the downstream within the expected time, it can immediately determine that an implicit link breakage has occurred and perform permission stripping. This avoids systemic risks and state asynchrony problems that may result from indefinitely waiting for unresponsive nodes, enhancing the robustness and security of the automated system in complex and unreliable communication environments.

[0017] In conjunction with some embodiments of the first aspect, some embodiments further include an overreach control module, which is triggered when the current identity node contains a preset special intervention marker. The preset special intervention marker includes a maintenance marker or an overwrite marker. The overreach control module specifically includes: an authorization boundary extraction unit, used to obtain the preset physical interface range and the maximum permitted time limit corresponding to the preset special intervention marker; and a physical boundary verification unit, used to obtain the actual physical interface source of the control command to be executed, and determine whether the actual physical interface source exceeds the preset physical interface range, or whether the current timestamp exceeds the maximum permitted time limit; if so, even if the logical continuity code verification passes, it still forcibly blocks and outputs the first abnormal code.

[0018] By adopting the above technical solution, the unauthorized access control module extends authorization verification from a purely logical level to the dimensions of physical interfaces and time windows, ensuring that special instructions can only be executed within preset, secure physical boundaries (such as local debugging ports) and valid time periods. Even if an attacker steals legitimate logical credentials, as long as they attempt to launch an attack on an unauthorized physical path or at an unauthorized time, the physical boundary verification unit can forcibly block it and output the first exception code, thereby reducing the risk of legitimate identities being abused to perform unauthorized operations.

[0019] In conjunction with some embodiments of the first aspect, in some embodiments, the effectiveness degradation control module specifically includes: a low-level channel cutting-off unit, used to block the direct control enable signal of the bus where the low-level hardware corresponding to the target action digest is located at the hardware level when a first abnormal code or a second abnormal code is received; an instruction isolation redirection unit, used to redirect the transmission path of the control instruction to be executed to a virtual diagnostic sandbox that does not directly control the real physical components; and a security baseline takeover unit, used to call the security maintenance parameters for the low-level hardware to control the low-level hardware to maintain its current physical posture or return to a preset security baseline state.

[0020] By adopting the above technical solutions, the underlying channel interruption unit directly blocks the control path at the hardware level, improving the immediacy and reliability of isolation. The command isolation and redirection unit captures the blocked commands and sends them to the virtual diagnostic sandbox, preserving analysis samples for subsequent attack tracing and behavioral analysis. The security baseline takeover unit proactively intervenes to ensure that the affected physical system can be quickly restored to a known secure state.

[0021] In conjunction with some embodiments of the first aspect, some embodiments further include an identity chain dynamic reconstruction module, used to receive an error correction and reset beacon issued from the highest-authority trusted root node. The error correction and reset beacon contains a brand-new initial random seed, a reset timestamp, and an identity verification signature. After verifying that the identity verification signature is passed and the timing is compliant, the root identity node is regenerated by calling a preset identity node generation module based on the action parameters of the controlled isolation instructions in the virtual diagnostic sandbox and the initial random seed. The root identity node is then issued to replace the current identity node that has malfunctioned, so as to re-establish the coherent relationship of the unified identity chain and wake up the pending control instructions in the virtual diagnostic sandbox to enter the next verification process.

[0022] By adopting the above technical solution, the identity chain dynamic reconstruction module can rebuild a new, trusted identity chain without interrupting the overall system operation. This is achieved through authorization from the highest-level root of trust, utilizing the context information of the isolation command and a new random seed. This avoids business interruptions caused by simply discarding commands and bypasses the time-consuming and risky system restart process.

[0023] In conjunction with some embodiments of the first aspect, in some embodiments, the identity chain parsing module further includes a topology verification unit, used to extract the source physical MAC address corresponding to the preceding identity node and the destination physical MAC address corresponding to the current identity node; query the local network topology routing table to verify whether the number of physical network switching hops from the source physical MAC address to the destination physical MAC address matches the logical hierarchy difference generated by the flow; if they do not match, it is determined that the control instruction to be executed has a logical penetration attack across physical isolation domains, and the first exception code is output.

[0024] By employing the above technical solution and adding a topology verification unit during the identity chain resolution phase, the logical flow path of the instruction is cross-verified with the physical network transmission path. This effectively identifies and blocks logical penetration attacks across physically isolated domains achieved through illegal proxies, tunneling techniques, or network configuration vulnerabilities. By comparing the logical hierarchy difference with the physical network hop count, any mismatch on the path will expose the attacker's abnormal routing behavior, thus cutting off the attack path in the early stages of instruction execution and enhancing the automated system's ability to resist complex network attacks.

[0025] In conjunction with some embodiments of the first aspect, some embodiments further include an energy consumption fingerprint verification module, which is connected to the effectiveness degradation control module. This module is used to synchronously collect transient power waveforms of the underlying hardware during the entire execution of the target action after granting formal physical drive permissions; convert the transient power waveforms into actual action energy consumption feature vectors through feature extraction, and compare their similarity with a standard energy efficiency feature library integrated into the identity chain; if the result is lower than a preset response threshold, it is determined that the physical execution chain has experienced bypass hijacking or idle deception, triggering the effectiveness degradation control module to strip the subsequent physical execution permissions of the current instruction.

[0026] By adopting the above technical solution, and by comparing the actual transient power waveform during hardware execution with the standard energy efficiency feature library, the energy consumption fingerprint verification module can more accurately detect bypass hijacking or idle deception in the physical execution chain. Once it is found that the execution result in the physical world does not match the instruction intent in the digital world, the automation system can immediately strip away subsequent permissions, thereby improving the security of the automation system.

[0027] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:

[0028] 1. The execution effectiveness control device achieves strong binding of the source, content, and flow order of control commands by passing the preceding verification digest and timestamp level by level and using them as part of the verification digest of the next level node. The continuity interlock verification module ensures the logical immutability and unforgeability of the identity chain, while the time-series anti-counterfeiting verification module uses the time laws of the physical world to identify replay attacks that exceed the physical limits of the hardware. Once any verification fails, the effectiveness degradation control module immediately strips the physical execution authority of the command, thereby reducing the problem of broken responsibility chains caused by partial verification and improving the security of the automated system.

[0029] 2. The hysteresis parameter matching unit can dynamically match the shortest hardware response time that conforms to physical laws according to the specific action of the instruction, providing a more accurate physical benchmark for timing judgment. Based on this physical benchmark, the anomaly detection unit judges the timing difference, which can more accurately identify high-frequency data injection forgery behaviors that use the high-speed characteristics of the digital world to bypass the limitations of the physical world, thereby improving the security of the automated system.

[0030] 3. The identity chain dynamic reconstruction module can rebuild a new, trusted identity chain without interrupting the overall system operation. This is achieved through authorization from the highest-level root of trust, utilizing the context information of isolated commands and a new random seed. This avoids business interruptions caused by simply discarding commands and bypasses the time-consuming and risky system restart process. Attached Figure Description

[0031] Figure 1 This is a module architecture diagram of the execution effectiveness control device in the embodiments of this application.

[0032] Figure 2 This is a schematic diagram of the continuity interlock verification module of the execution effectiveness control device in the embodiments of this application.

[0033] Figure 3 This is a schematic diagram of the timing anti-counterfeiting verification module of the execution effectiveness control device in the embodiments of this application.

[0034] Figure 4 This is a schematic diagram of the effectiveness degradation control module of the effectiveness control device in the embodiments of this application. Detailed Implementation

[0035] The terminology used in the following embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. As used in the specification and appended claims of this application, the singular expressions “a,” “an,” “the,” “the,” “the,” and “this” are intended to include the plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in this application refers to and includes any or all possible combinations of one or more of the listed items.

[0036] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.

[0037] This application provides an execution effectiveness control device based on unified identity chain continuity verification to improve the security of automated systems.

[0038] Please see Figure 1 This is a module architecture diagram of the execution effectiveness control device in the embodiments of this application.

[0039] The execution effectiveness control device includes:

[0040] The identity chain parsing module 101 is used to receive the control instructions to be executed across layers and extract the previous identity nodes and the current identity nodes arranged in the flow order. The previous identity node contains the previous verification summary and the previous timestamp generated by the previous control level, and the current identity node contains the target action summary, the current timestamp and the current verification summary generated by the current control level.

[0041] In this context, cross-layer flow refers to the process of control instructions being passed step-by-step from higher-level control layers (such as the application policy layer) to lower-level control layers (such as the hardware driver layer). Control instructions awaiting execution refer to operation instructions awaiting final confirmation of execution authority. Identity nodes are the basic data units constituting a unified identity chain, recording verification information at a specific control level. A preceding identity node is a node in the identity chain generated by the previous control level that precedes the current identity node in terms of time sequence. A preceding verification digest represents a hash value generated by the preceding control level, used to prove the legitimacy of the link relationship with a more preceding node. A preceding timestamp indicates the time when the preceding identity node was created. The current identity node is the latest node generated by the current control level. A target action digest is a digest value generated after hashing the core operation parameters in the instruction, used to identify and protect the intent of the instruction. A current timestamp indicates the time when the current identity node was created. A current verification digest is a hash value generated by the current control level, used to prove its legitimacy downstream.

[0042] Specifically, when a control instruction containing a unified identity chain arrives at the control level of this device, the identity chain parsing module 101 is triggered. The function of the identity chain parsing module 101 is to parse the data structure of the control instruction according to a preset data protocol. The parsing process includes: extracting two adjacent nodes arranged in the flow order from the chain structure of the unified identity chain, namely the previous identity node and the current identity node. Subsequently, the identity chain parsing module 101 further separates the previous verification digest and previous timestamp from the previous identity node, and separates the target action digest, current timestamp, and current verification digest from the current identity node. These extracted structured data will be respectively sent to subsequent verification modules as the basic input for performing continuity and compliance verification.

[0043] In some embodiments, the identity chain parsing module 101 can be implemented in different ways: Optionally, in one implementation, the identity chain parsing module 101 can be deployed as a fixed hardware message parsing circuit. Specific steps include: First, defining a set of instruction message protocols, where the preceding identity node and the current identity node, along with their internal fields (such as digest and timestamp), have fixed offset addresses and data lengths in the message data frame. Second, after receiving a serial or parallel data stream, the hardware circuit directly captures the corresponding data segment from the specified offset position through address decoding and a data latch. Finally, the captured data segments are stored in dedicated registers for reading by other hardware verification units. Optionally, in another implementation, the identity chain parsing module 101 can be implemented through a software program running on an embedded processor. Specific steps include: First, the program receives a complete data packet containing control instructions (e.g., a JSON object or a custom binary structure). Then, the program calls a deserialization function to map the data packet content to a data object in memory according to a predefined structure template. Finally, the program directly accesses the corresponding members of the data object through pointers or object references, thereby obtaining the summaries and timestamps of the previous and current identity nodes.

[0044] In some embodiments, the current identity node can be obtained through a physical anti-counterfeiting generation module. The physical anti-counterfeiting generation module includes:

[0045] The physical feature acquisition unit is used to acquire the dynamic operating parameters of the underlying hardware at the current control level and convert the dynamic operating parameters into dynamic physical feature values. The dynamic operating parameters include hardware operating voltage fluctuation values ​​or instruction microarchitecture execution latency.

[0046] Dynamic operating parameters refer to instantaneous physical quantities with minute random fluctuations, determined by the hardware's physical characteristics and operating environment during operation. Hardware operating voltage fluctuations refer to minute voltage noise in conductors caused by temperature and load changes. Instruction microarchitecture execution latency refers to the minute differences in execution time of the same code segment within the processor due to variations in cache hits, branch predictions, and other states. Dynamic physical characteristic values ​​are obtained by digitizing these dynamic operating parameters and possess non-replicable and instantaneously unique properties.

[0047] Specifically, the physical feature acquisition unit samples specific physical quantities of the underlying hardware at the nanosecond or microsecond level using a high-precision analog-to-digital converter or a high-resolution timer. For example, it might acquire the voltage noise waveform on the processor core power rail, or execute a piece of standard test code and precisely measure its execution cycle count. The acquired raw analog signal or time count value is converted into a fixed-length binary sequence, which serves as the dynamic physical feature value and a key input for generating the current verification summary.

[0048] The digest encapsulation unit is used to perform an arithmetic concatenation of dynamic physical feature values ​​and control parameters of the control instruction to be executed, and generate the current verification digest through an irreversible hash algorithm.

[0049] Arithmetic concatenation refers to the process of combining multiple different data items (such as dynamic physical characteristics and control parameters) into a single data block through predefined mathematical operations (such as XOR and concatenation). Irreversible hash algorithms (such as SHA-256) ensure that even if the output digest is known, it is impossible to deduce any input information in reverse.

[0050] Specifically, the digest encapsulation unit receives dynamic physical feature values ​​generated by the physical feature acquisition unit, as well as other control parameters constituting the identity chain (e.g., prior verification digest, target action digest, current timestamp, etc.). Subsequently, the digest encapsulation unit concatenates or XORs the dynamic physical feature values ​​with these control parameters to form an extended joint feature vector that incorporates the randomness of the physical world. Finally, this joint feature vector is used as the overall input and fed into a hash algorithm for computation; the output is the final current verification digest. The introduction of dynamic physical feature values ​​provides a physical layer defense against software-level replay and simulation attacks.

[0051] In some embodiments, the identity chain parsing module 101 further includes: a topology verification unit, used to extract the source physical MAC address corresponding to the preceding identity node and the destination physical MAC address corresponding to the current identity node; query the local network topology routing table to verify whether the number of physical network switching hops from the source physical MAC address to the destination physical MAC address matches the logical hierarchy difference generated by the flow; if they do not match, it is determined that the control instruction to be executed has a logical penetration attack across physical isolation domains, and the first exception code is output.

[0052] The source and destination physical MAC addresses are unique hardware addresses used at the data link layer to identify network interfaces. The local network topology routing table is a pre-configured data structure that records the physical connections and shortest path hop counts between devices in the network. Logical hierarchy difference refers to the number of layers that control commands traverse when flowing between different abstraction levels (such as policy, coordination, and execution layers) in an automated system. A logic penetration attack across physical isolation domains refers to an attacker bypassing pre-defined network segmentation and security domain boundaries through some means (such as unauthorized proxies or tunnels), causing the logical flow path of commands to differ from the physical network path.

[0053] Specifically, the topology verification unit first extracts the source and destination MAC addresses from the metadata of the preceding and current identity nodes. Simultaneously, based on the identity chain structure, it determines the logical level difference (usually 1) for this transfer. Next, using the extracted MAC address pairs as indexes, the topology verification unit queries the local network topology routing table for the physical hop count between them. Finally, a comparison is performed: if the queried physical hop count does not match the expected logical level difference (e.g., 1 or 2 hops between adjacent levels) (e.g., adjacent communication that should be 1 hop shows 0 hops or more than a preset threshold), it indicates that the instruction may have been forwarded by an unauthorized man-in-the-middle attack or injected directly from a network segment that should not be communicating directly. In this case, the topology verification unit determines that a logical penetration attack exists and directly outputs the first anomaly code, blocking the suspicious instruction in advance.

[0054] The continuity interlock verification module 102 is used to perform consistency recalculation verification based on the previous verification digest and the control parameters associated with the current identity node; it verifies whether the recalculated digest features are consistent with the current verification digest. If they are consistent, it outputs a logical continuity code; if they are inconsistent, it determines that the identity chain is broken and outputs the first abnormal code.

[0055] Consistency recalculation verification refers to a verification method that recalculates the digest value using the same input data and hash algorithm as the original digest generation process, and compares it with the received digest value. The digest feature refers to a fixed-length numerical value derived from hash operations that represents the original data block. The logical continuity code is an internal signal whose output indicates that the encrypted link between the current identity node and its predecessor identity node has been verified successfully. An identity chain break is an abnormal state indicating that the current identity node has failed the continuity check with its predecessor identity node. The first anomaly code is a signal used to explicitly identify the identity chain break anomaly, triggering subsequent security control procedures.

[0056] Specifically, after the identity chain parsing module 101 completes data extraction, the continuity interlock verification module 102 starts running. The function of the continuity interlock verification module 102 is to verify the logical integrity and continuity of the unified identity chain. Its execution process is as follows: The continuity interlock verification module 102 receives the preceding verification digest provided by the identity chain parsing module 101 and obtains all control parameters associated with the current identity node used to generate the current verification digest. Subsequently, the continuity interlock verification module 102 combines the preceding verification digest and the aforementioned control parameters according to preset concatenation rules and order, and uses the combined data as input to call a preset hash algorithm to perform a hash operation, thereby obtaining a recalculated digest feature. Finally, the continuity interlock verification module 102 compares the recalculated digest feature with the current verification digest extracted from the current identity node bit by bit. If the two are completely consistent, the identity chain is determined to be logically continuous, and the module outputs a logical continuity code. If they are inconsistent, the identity chain is determined to be broken, and the module outputs the first exception code.

[0057] The timing anti-counterfeiting verification module 103 is triggered when acquiring the logical continuity code. It is used to obtain the preset physical timing constraint parameters bound to the underlying hardware based on the target action summary; determine whether the timing difference between the current timestamp and the previous timestamp is less than the preset physical timing constraint parameters. If so, it is determined that there is an abnormal replay forgery that bypasses the physical limit and outputs the second abnormal code. If not, it outputs the timing compliance code.

[0058] The preset physical timing constraint parameter refers to a time value pre-calibrated based on the physical characteristics of the underlying hardware, representing the minimum time overhead required for the hardware to complete a basic action. The timing difference refers to the time interval between the current timestamp and the previous timestamp. In this embodiment, the previous and current timestamps are maintained by a unified timestamp management mechanism. For the first operation of any specific underlying hardware, its previous timestamp can be set to an initial safe value. When a control instruction passes all checks and is granted formal physical drive permissions, the current timestamp of the instruction is recorded in the storage area associated with that specific underlying hardware. For subsequent instructions sent to the same underlying hardware, the previous timestamp used when generating its identity chain will be directly taken from the timestamp of the last successful operation recorded in that storage area. Anomaly replay forgery refers to an attack that attempts to achieve malicious control by repeatedly sending legitimate instruction data packets at a physically impossible high frequency. The second anomaly code is a signal used to explicitly identify timing verification failures (i.e., violations of physical laws). The timing compliance code is an internal signal whose output indicates that the instruction flow time interval conforms to physical timing constraints.

[0059] Specifically, the timing anti-spoofing verification module 103 is triggered when it receives the logical continuity code output by the continuity interlock verification module 102. The function of the timing anti-spoofing verification module 103 is to identify timing-level forgery attacks based on the objective laws of the physical world. Its operation process is as follows: First, the timing anti-spoofing verification module 103 queries a preset parameter table based on the target action digest obtained from the current identity node to obtain the preset physical timing constraint parameters of the underlying hardware directly associated with the target action. Next, the timing anti-spoofing verification module 103 calculates the difference between the current timestamp and the previous timestamp to obtain the timing difference. Finally, the timing anti-spoofing verification module 103 determines whether the timing difference is less than the preset physical timing constraint parameters. If so, it determines that the instruction flow speed exceeds the physical limit, and there is a possibility of abnormal replay forgery, and outputs a second abnormal code. If not (i.e., the timing difference is greater than or equal to the constraint parameters), it determines that the timing is normal and outputs a timing compliance code.

[0060] The effectiveness degradation control module 104 is used to determine, upon receiving the first or second exception code, that the control instruction to be executed has lost its legitimate cross-layer continuity dependency, strip the physical execution permission of the control instruction to be executed to the underlying hardware, and downgrade it to a controlled isolation instruction; upon receiving the timing compliance code, it grants the control instruction to be executed formal physical drive permission.

[0061] Loss of legitimate cross-layer continuity dependency refers to the failure to verify the source credibility, content integrity, or timing rationality of the control instruction to be executed, thus rendering it no longer eligible for legitimate execution. Stripping physical execution permissions refers to using technical means to remove the instruction's control over the underlying hardware. Controlled isolation instructions are those that, after being stripped of execution permissions, are not discarded but marked and placed in a secure, isolated environment for analysis. Granting formal physical driver permissions means allowing the instruction to enter the normal hardware driver process after its legitimacy has been confirmed.

[0062] Specifically, the effectiveness degradation control module 104, as the final execution unit of the security policy, determines its operating mode based on the received signals. When the effectiveness degradation control module 104 receives either the first or second exception code, it determines that the control instruction to be executed is illegal or abnormal. At this time, the effectiveness degradation control module 104 performs an effectiveness degradation operation, which includes: stripping the physical execution permission of the control instruction to be executed from the underlying hardware, converting the instruction into a controlled isolation instruction, and sending it to a preset isolation area. When the effectiveness degradation control module 104 receives a timing compliance code (meaning that all pre-verifications have passed), it determines that the control instruction to be executed is a legal instruction. At this time, the effectiveness degradation control module 104 grants the instruction formal physical drive permission, allowing it to be sent to the underlying hardware for execution.

[0063] In some embodiments, the execution effectiveness control device further includes: an identity chain dynamic reconstruction module, used to receive an error correction and reset beacon issued from the highest-authority trusted root node. After verifying that the identity verification signature is successful and the timing is compliant, the root identity node is regenerated by calling a preset identity node generation module based on the action parameters of the controlled isolated instructions in the virtual diagnostic sandbox and the initial random seed; the root identity node is then issued to replace the current identity node that has malfunctioned, so as to re-establish the coherent relationship of the unified identity chain and wake up the control instructions to be executed in the virtual diagnostic sandbox to enter the next verification process.

[0064] The highest-authority trusted root node is the only trusted authority in the system authorized to initiate a global state reset. The error-correction reset beacon is a special instruction containing initial parameters for rebuilding the identity chain. The identity verification signature is a digital signature generated by the trusted root node using its private key on the beacon content, used to verify the beacon's authenticity and integrity. The initial random seed is a new random number used as the cryptographic starting point for the new identity chain. The root identity node is the first node in the identity chain.

[0065] Specifically, when one or more instructions are isolated in a virtual diagnostic sandbox, the automated system can be triggered by an administrator or a preset policy to request intervention from the highest-level trusted root node. The trusted root node issues a correction and reset beacon. Upon receiving the beacon, the identity chain dynamic reconstruction module first verifies the identity verification signature using the trusted root's public key and checks its timestamp to prevent replay. After successful verification, the identity chain dynamic reconstruction module extracts the core action parameters of the isolated instruction from the virtual diagnostic sandbox and, combined with the new initial random seed provided by the beacon, calls the automated system's identity node generation logic to create a new, legitimate root identity node. Subsequently, this newly generated root identity node is used to replace the original abnormal node that caused the break, essentially connecting a new, trusted chain at the breakpoint. After the replacement is complete, the identity chain dynamic reconstruction module wakes up the instructions in the sandbox, re-sends them to the identity chain parsing module, and begins a new round of verification. This allows the automated system to dynamically repair the damaged identity chain and restore normal control flow without restarting or completely stopping the service.

[0066] In some embodiments, the execution effectiveness control device further includes: an energy consumption fingerprint verification module, which is connected to the effectiveness degradation control module. After granting formal physical drive permissions, the module is used to synchronously collect the transient power waveform of the underlying hardware during the entire process of executing the target action; convert the transient power waveform into an actual action energy consumption feature vector through feature extraction, and compare it with the standard energy efficiency feature library integrated in the identity chain; if the result is lower than a preset response threshold, it is determined that the physical execution chain has been bypassed or spoofed, and the effectiveness degradation control module is triggered to strip the subsequent physical execution permissions of the current instruction.

[0067] The transient power waveform is the curve showing the instantaneous power consumption of the hardware as a function over time. The actual action energy consumption feature vector is a numerical vector extracted from the power waveform through signal processing (such as Fourier transform and wavelet analysis) that represents the energy consumption characteristics of the action. The standard energy efficiency feature library is a pre-measured set of standard energy consumption feature vectors corresponding to legitimate actions, which can be transmitted with instructions as part of the identity chain. Bypass hijacking refers to an attacker physically altering the behavior of the actuator after the instruction is issued. Idle deception refers to the actuator not actually performing an action (such as a motor running idle) but sending false information of completion to the upper layer.

[0068] Specifically, when the efficiency degradation control module grants formal physical drive permission to an instruction, the energy consumption fingerprint verification module starts simultaneously. Using a current sensor and high-speed sampling circuit connected in series with the hardware power path, the energy consumption fingerprint verification module collects the complete transient power waveform of the hardware during the execution of the action in real time. After the action is completed, the energy consumption fingerprint verification module extracts features from the collected waveform to generate an actual action energy consumption feature vector. Then, it compares this vector with the standard energy efficiency feature library corresponding to the target action, either carried in the instruction identity chain or stored locally (e.g., calculating Euclidean distance or cosine similarity). If the similarity is lower than a preset threshold (e.g., below 95%), it indicates an anomaly in the physical execution process, such as a motor load far exceeding expectations (possibly due to jamming or additional actions) or far below expectations (possibly due to no-load deception). At this time, the energy consumption fingerprint verification module immediately sends an alarm signal to the efficiency degradation control module, triggering it to strip the subsequent (if it is a continuous action) physical execution permission of the instruction and enter a safety handling process, thereby achieving closed-loop verification of the execution result.

[0069] In some embodiments, the execution effectiveness control device further includes: an implicit link break determination module, which is connected to the identity chain parsing module, for calculating the maximum survival time window based on a preset time multiple and preset physical timing constraint parameters; when the identity chain parsing module obtains the current identity node and starts timing, if no downstream receipt containing legal continuity verification feedback is received before the maximum survival time window expires, it is determined that there is an implicit link break in the cross-layer communication, and an implicit link break blocking signal is output to the effectiveness degradation control module.

[0070] The maximum survival time window is a dynamically calculated timeout threshold, representing the longest allowed completion time for a single cross-layer instruction interaction. The preset time multiplier is a configurable safety factor used to adjust timeout sensitivity. Downstream acknowledgment refers to the confirmation or status report message sent by a downstream node to an upstream node after verifying and executing the instruction. Implicit link failure refers to the failure of instruction flow without explicit error reporting due to communication interruption caused by network congestion, node failure, or malicious interference. The implicit link failure blocking signal is a specific signal used to notify the effectiveness degradation control module to perform emergency measures.

[0071] Specifically, when the execution effectiveness control device, acting as an intermediate node, prepares to forward instructions downstream, the implicit link failure determination module first calculates a reasonable maximum survival time window by multiplying the preset physical timing constraint parameter corresponding to the instruction (which reflects the inherent time consumption of downstream actions) by a preset time multiplier (e.g., 3 times). After the node sends a control instruction containing the new identity node to the downstream node, the implicit link failure determination module immediately starts a countdown timer. If the node successfully receives an acknowledgment message containing a valid verification result from the downstream node before the timer expires, the timer is reset, and communication is considered normal. Conversely, if no valid acknowledgment is received when the timer reaches zero, the implicit link failure determination module determines that an implicit link failure has occurred. At this time, the implicit link failure determination module generates and outputs an implicit link failure blocking signal to its own effectiveness degradation control module. Upon receiving this signal, the effectiveness degradation control module immediately performs the operation of stripping physical execution permissions from the downstream hardware and can trigger a mechanism to report communication failures to the upstream node, thereby preventing systemic risks caused by waiting for unresponsive downstream nodes.

[0072] In some embodiments, the execution effectiveness control device further includes: an overreach control module, configured to be triggered when the current identity node contains a preset special intervention marker, wherein the preset special intervention marker includes a maintenance marker or an overwrite marker. The overreach control module specifically includes:

[0073] The authorization boundary extraction unit is used to obtain the preset physical interface range and maximum license time limit corresponding to the preset special intervention mark.

[0074] The preset special intervention flag is a flag in the instruction used to indicate that its intent is to perform unconventional operations (such as debugging or firmware updates). The preset physical interface range defines the list of physical ports or buses that are allowed to be accessed in the special operation mode (e.g., only allowing access via the local USB debugging interface). The maximum permitted time limit defines the time validity window for this special operation.

[0075] The physical boundary verification unit is used to obtain the actual physical interface source of the control command to be executed, and to determine whether the actual physical interface source exceeds the preset physical interface range, or whether the current timestamp exceeds the maximum permitted time limit; if so, even if the logical continuity code verification passes, it will still forcibly block and output the first abnormal code.

[0076] The actual physical interface source refers to the physical channel information (e.g., from which Ethernet port, serial port, or wireless interface the instruction data packet actually enters the local node) obtained by the system.

[0077] Specifically, when the identity chain parsing module detects a special intervention marker in the current identity node, the unauthorized access control module is activated. The authorization boundary extraction unit first queries a security policy database based on the marker to obtain the authorization boundary associated with this marker, i.e., the allowed physical interface range and the permitted time limit. Simultaneously, the physical boundary verification unit obtains information about the source of the current command packet from the operating system or hardware driver layer, such as whether it comes from the eth0 network interface or the ttyS0 serial port. Next, the physical boundary verification unit performs a double check: 1. Determines whether the actual physical interface source exists in the preset physical interface range list; 2. Determines whether the timestamp of the current identity node is within the maximum permitted time limit. If either condition is not met (for example, an overwrite command that should only be issued through the local maintenance port is received from a public network interface), the physical boundary verification unit determines it as unauthorized behavior. In this case, even if the continuity interlock verification (logical continuity code) of the command has passed, the unauthorized access control module will force the output of the first exception code, thereby effectively preventing legitimate identities from being abused to perform high-risk operations on unexpected physical boundaries.

[0078] The above describes the module architecture diagram of the execution effectiveness control device in the embodiments of this application. The modules are described below.

[0079] Please refer to the following: Figure 2 This is a schematic diagram of the continuity interlock verification module of the execution effectiveness control device in the embodiments of this application.

[0080] The continuity interlock verification module 102 includes:

[0081] The context feature extraction unit 1021 is used to extract the unique identifier of the controlled device bound to the target action summary and the current session lifecycle identifier from the control instruction to be executed.

[0082] The controlled device unique identifier is a globally unique code that identifies the physical hardware device, such as a MAC address or device serial number. The current session lifecycle identifier is a temporary identifier used to distinguish different communication sessions, such as a random token generated when the session is established. This identifier expires when the session ends.

[0083] Specifically, the context feature extraction unit 1021 operates before the continuity interlock verification module 102 performs consistency recalculation verification. The function of the context feature extraction unit 1021 is to extract additional information from the control instruction to be executed or its transmission context to enhance the verification dimensions. The context feature extraction unit 1021 parses the control instruction to be executed and extracts the unique identifier of the controlled device intended to be controlled by the instruction based on the instruction content (such as a target action summary or a specified device name). Simultaneously, the context feature extraction unit 1021 extracts the current session lifecycle identifier from the current communication session context (e.g., from network connection metadata or application layer protocol header information). The extracted unique identifier of the controlled device and the current session lifecycle identifier are provided as context features to the cross-interlock calculation unit 1022.

[0084] The cross-interlocked calculation unit 1022 is used to concatenate the unique identifier of the controlled device, the current session lifecycle identifier and the previous verification digest into a joint feature vector when performing consistency recalculation verification, and then perform hash operation to obtain the recalculated digest verification value, and determine whether it is consistent with the current verification digest.

[0085] The joint feature vector is a single data block formed by concatenating multiple independent feature data (such as pre-verification digest, device identifier, and session identifier) ​​in a predetermined order. The recalculated digest verification value is the output result obtained by the cross-interlocked computing unit 1022 performing a hash operation on the joint feature vector.

[0086] Specifically, the cross-interlocking calculation unit 1022 begins operation after receiving the preceding verification digest and various context features provided by the context feature extraction unit 1021. The function of the cross-interlocking calculation unit 1022 is to perform an enhanced consistency recalculation verification with added context information. The execution process is as follows: the cross-interlocking calculation unit 1022 combines the controlled device unique identifier, the current session lifecycle identifier, and the preceding verification digest into a joint feature vector according to a fixed concatenation order. Subsequently, the cross-interlocking calculation unit 1022 uses this joint feature vector as input, substitutes it into a preset hash algorithm, and performs calculations to obtain a recalculated digest verification value. Finally, the cross-interlocking calculation unit 1022 compares this digest verification value with the current verification digest extracted from the current identity node to determine whether the two are consistent.

[0087] Please refer to the following: Figure 3 This is a schematic diagram of the timing anti-counterfeiting verification module of the execution effectiveness control device in this application embodiment.

[0088] The time-series anti-counterfeiting verification module 103 includes:

[0089] The hysteresis parameter matching unit 1031 is used to parse the control instruction corresponding to the target action summary to determine the corresponding end effector, and retrieve the shortest hardware response time required for the end effector to complete the physical action. The shortest hardware response time is calibrated as the preset physical timing constraint parameter. The physical action includes mechanical displacement or capacitor charging and discharging.

[0090] An end effector refers to a hardware component that directly generates physical motion, such as a motor or solenoid valve. The shortest hardware response time is a parameter characterizing the physical properties of hardware, indicating the lower limit of the time required for the end effector to complete its smallest unit action. Physical motion includes, but is not limited to, the displacement of mechanical parts or the charging and discharging process of capacitors in a circuit.

[0091] Specifically, the hysteresis parameter matching unit 1031 operates first within the timing anti-counterfeiting verification module 103. The function of the hysteresis parameter matching unit 1031 is to provide an accurate physical benchmark for timing verification. Its workflow is as follows: The hysteresis parameter matching unit 1031 parses the control command corresponding to the target action summary to determine the end effector corresponding to the control command. Then, the hysteresis parameter matching unit 1031 uses the identifier of the end effector as an index to query a preset parameter library, which stores the shortest hardware response time required for each piece of hardware in the system to complete a physical action. After finding the corresponding shortest hardware response time, the hysteresis parameter matching unit 1031 calibrates it as the preset physical timing constraint parameter used in this verification and outputs it to subsequent units.

[0092] The time difference comparison unit 1032 is used to calculate the time difference between the current timestamp and the previous timestamp, where the previous timestamp is the time record of the last successful execution bound to the end effector.

[0093] Specifically, the function of the time interval comparison unit 1032 is to calculate the time interval between two consecutive legal operations on the same end effector. The time interval comparison unit 1032 obtains the current timestamp and the preceding timestamp extracted by the identity chain parsing module 101. Then, the time interval comparison unit 1032 performs a subtraction operation, that is, subtracting the preceding timestamp from the current timestamp. The result of the operation is the time interval difference. This time interval difference is then output to the anomaly determination unit 1033.

[0094] The anomaly determination unit 1033 is used to determine whether the timing difference is less than the preset physical timing constraint parameter. If so, it determines that there is a high-frequency data injection forgery behavior that exceeds the actual hardware execution limit and outputs a second anomaly code.

[0095] Among them, high-frequency data injection forgery is an attack that sends instructions at a rate exceeding the physical execution limits of the hardware.

[0096] Specifically, the anomaly determination unit 1033 receives the timing difference calculated by the timing comparison unit 1032 and the preset physical timing constraint parameters provided by the hysteresis parameter matching unit 1031. Then, the anomaly determination unit 1033 performs a comparison operation to determine whether the timing difference is less than the preset physical timing constraint parameters. If so, it determines that there is an abnormal behavior exceeding the actual hardware execution limit and outputs a second exception code. If not, it determines that the timing is normal.

[0097] Please refer to the following: Figure 4 This is a schematic diagram of the effectiveness degradation control module of the effectiveness control device in the embodiments of this application.

[0098] The effectiveness degradation control module 104 includes:

[0099] The underlying channel cutoff unit 1041 is used to block the direct control enable signal of the underlying hardware bus corresponding to the target action digest at the hardware level when a first abnormal code or a second abnormal code is received.

[0100] Hardware-level blocking refers to physically interrupting hardware communication or power supply, rather than purely software logic control. Direct control enable signals are electrical signals used to activate hardware modules to respond to bus commands.

[0101] Specifically, the underlying channel disconnection unit 1041 operates when the effectiveness degradation control module 104 receives the first or second exception code. Based on the target action summary in the exception instruction, the underlying channel disconnection unit 1041 locates the corresponding underlying hardware. Then, through a trusted management path, the underlying channel disconnection unit 1041 blocks the direct control enable signal of the bus containing that hardware at the hardware level. For example, it disconnects the physical bus connection by controlling a GPIO pin, or issues instructions to the bus controller or power management unit to disable the target device's interface or cut off its power supply.

[0102] The instruction isolation redirection unit 1042 is used to redirect the transmission path of the control instruction to be executed to a virtual diagnostic sandbox that does not directly control the real physical components.

[0103] The virtual diagnostic sandbox is a simulation environment isolated from the physical world for executing and analyzing instructions.

[0104] Specifically, the function of the instruction isolation and redirection unit 1042 is to redirect instructions deemed abnormal from the normal execution path and send them to a secure environment for analysis. When an instruction is deprived of its physical execution privileges, the instruction isolation and redirection unit 1042 modifies the instruction's routing information. This modification causes the instruction's transmission path to no longer point to the underlying hardware driver, but instead be redirected to a virtual diagnostic sandbox. The sandbox receives the instruction and simulates its execution, recording its behavior and parameters, but without producing any physical consequences.

[0105] The safety baseline takeover unit 1043 is used to invoke the safety maintenance parameters for the underlying hardware to control the underlying hardware to maintain its current physical posture or return to a preset safety baseline state.

[0106] Among them, the safety maintenance parameters are a set of preset instructions or configuration values ​​that enable the hardware to enter a stable and safe state. Maintaining the current physical posture means commanding the hardware to remain in the state before the operation was interrupted. Returning to the preset safe baseline state means commanding the hardware to return to an initial, safe state.

[0107] Specifically, the security baseline takeover unit 1043 retrieves the corresponding security maintenance parameters from a security policy library based on the affected underlying hardware. Then, the security baseline takeover unit 1043 issues new control commands to the underlying hardware through a trusted management channel, controlling the hardware to perform the actions defined by the security maintenance parameters, such as maintaining the current physical posture or returning to a preset security baseline state.

[0108] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0109] As used in the above embodiments, depending on the context, the term "when..." can be interpreted as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if (the stated condition or event) is interpreted as meaning "if determining...", "in response to determining...", "when (the stated condition or event) is detected", or "in response to detecting (the stated condition or event)".

[0110] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0111] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.

Claims

1. An execution effectiveness control device based on unified identity chain continuity verification, characterized in that, include: The identity chain parsing module is used to receive control instructions to be executed across layers and extract the previous identity nodes and the current identity nodes arranged in the flow order. The preceding identity node includes a preceding verification digest and a preceding timestamp generated by the preceding control layer, and the current identity node includes a target action digest, a current timestamp, and a current verification digest generated by the current control layer. The continuity interlock verification module is used to perform consistency recalculation verification based on the preceding verification digest and the control parameters associated with the current identity node; verify whether the recalculated digest features are consistent with the current verification digest. If they are consistent, output the logical continuity code; if they are inconsistent, determine that the identity chain is broken and output the first abnormal code. The timing anti-counterfeiting verification module is triggered when the logical continuity code is obtained. It is used to obtain the preset physical timing constraint parameters bound to the underlying hardware based on the target action summary; determine whether the timing difference between the current timestamp and the previous timestamp is less than the preset physical timing constraint parameters. If so, it is determined that there is an abnormal replay forgery that bypasses the physical limit and outputs a second abnormal code. If not, it outputs a timing compliance code. The effectiveness degradation control module is used to determine, upon receiving the first exception code or the second exception code, that the control instruction to be executed has lost its legitimate cross-layer continuity dependency, strip the physical execution permission of the control instruction to be executed to the underlying hardware, and downgrade it to a controlled isolation instruction; and upon receiving the timing compliance code, to grant the control instruction to be executed formal physical drive permission.

2. The execution efficiency control device according to claim 1, characterized in that, The current identity node is obtained through a physical anti-counterfeiting generation module, which specifically includes: The physical feature acquisition unit is used to acquire the dynamic operating parameters of the underlying hardware at the current control level and convert the dynamic operating parameters into dynamic physical feature values. The dynamic operating parameters include hardware operating voltage fluctuation values ​​or instruction microarchitecture execution latency. The digest encapsulation unit is used to perform an arithmetic concatenation of the dynamic physical feature value and the control parameters of the control instruction to be executed, and generate the current verification digest through an irreversible hash algorithm.

3. The execution efficiency control device according to claim 1, characterized in that, The continuity interlock verification module specifically includes: The context feature extraction unit is used to extract the unique identifier of the controlled device bound to the target action summary and the current session lifecycle identifier from the control instruction to be executed; The cross-interlocked calculation unit is used to, when performing the consistency recalculation verification, concatenate the unique identifier of the controlled device, the current session lifecycle identifier and the previous verification digest into a joint feature vector, then perform a hash operation to obtain a recalculated digest verification value, and determine whether it is consistent with the current verification digest.

4. The execution effectiveness control device according to claim 1, characterized in that, The time-series anti-counterfeiting verification module specifically includes: Hysteresis parameter matching unit is used to parse the control instruction corresponding to the target action summary to determine the corresponding end effector, and retrieve the preset shortest hardware response time required for the end effector to complete the physical action, and calibrate the shortest hardware response time as the preset physical timing constraint parameter, wherein the physical action includes mechanical displacement or capacitor charging and discharging; The time interval comparison unit is used to calculate the time difference between the current timestamp and the preceding timestamp, wherein the preceding timestamp is the time record of the last successful execution bound to the end effector; An anomaly determination unit is used to determine whether the timing difference is less than the preset physical timing constraint parameter. If so, it determines that there is a high-frequency data injection forgery behavior that exceeds the actual hardware execution limit and outputs the second anomaly code.

5. The execution efficiency control device according to claim 1, characterized in that, It also includes an implicit disconnection determination module, which is connected to the identity chain parsing module. This module calculates the maximum lifetime window based on a preset time multiple and the preset physical timing constraint parameters. When the identity chain parsing module obtains the current identity node, it starts timing. If no downstream acknowledgment containing valid continuity verification feedback is received before the maximum lifetime window expires, it determines that there is an implicit disconnection in the cross-layer communication and outputs an implicit disconnection blocking signal to the effectiveness degradation control module. Upon receiving the implicit disconnection blocking signal, the effectiveness degradation control module performs the operation of stripping the physical execution permissions of the control instruction to be executed on the underlying hardware.

6. The execution effectiveness control device according to claim 1, characterized in that, It also includes an overreach control module, which is triggered when the current identity node contains a preset special intervention marker. The preset special intervention marker includes a maintenance marker or an overwrite marker. The overreach control module specifically includes: The authorization boundary extraction unit is used to obtain the preset physical interface range and maximum license time limit corresponding to the preset special intervention mark; The physical boundary verification unit is used to obtain the actual physical interface source of the control command to be executed, and to determine whether the actual physical interface source exceeds the preset physical interface range, or whether the current timestamp exceeds the maximum permitted time limit; if so, even if the logical continuity code verification passes, the first abnormal code is still forcibly blocked and output.

7. The execution effectiveness control device according to claim 1, characterized in that, The effectiveness degradation control module specifically includes: The underlying channel cutoff unit is used to block the direct control enable signal of the underlying hardware bus corresponding to the target action digest at the hardware level when the first abnormal code or the second abnormal code is received. The instruction isolation and redirection unit is used to redirect the transmission path of the control instruction to be executed to a virtual diagnostic sandbox that does not directly control the real physical components; The safety baseline takeover unit is used to invoke the safety maintenance parameters for the underlying hardware and control the underlying hardware to maintain its current physical posture or revert to a preset safety baseline state.

8. The execution efficiency control device according to claim 7, characterized in that, It also includes an identity chain dynamic reconstruction module, used to receive error correction and reset beacons issued from the highest-authority trusted root node. The error correction and reset beacon contains a brand-new initial random seed, a reset timestamp, and an identity verification signature. After verifying that the identity verification signature is valid and the timing is compliant, the root identity node is regenerated by calling a preset identity node generation module based on the action parameters of the controlled isolation instructions in the virtual diagnostic sandbox and the initial random seed. The root identity node is then issued to replace the current identity node that has malfunctioned, so as to re-establish the coherent relationship of the unified identity chain and wake up the control instructions to be executed in the virtual diagnostic sandbox to enter the next verification process.

9. The execution efficiency control device according to claim 1, characterized in that, The identity chain parsing module further includes a topology verification unit, used to extract the source physical MAC address corresponding to the preceding identity node and the destination physical MAC address corresponding to the current identity node; query the local network topology routing table to verify whether the number of physical network switching hops from the source physical MAC address to the destination physical MAC address matches the logical hierarchy difference generated by the flow; if they do not match, it is determined that the control instruction to be executed has a logical penetration attack across physical isolation domains, and the first exception code is output.

10. The execution efficiency control device according to claim 1, characterized in that, It also includes an energy consumption fingerprint verification module, which is connected to the effectiveness degradation control module. After granting formal physical drive permissions, the module is used to synchronously collect the transient power waveform of the underlying hardware during the entire process of executing the target action. The transient power waveform is converted into an actual action energy consumption feature vector through feature extraction and compared with the standard energy efficiency feature library fused in the identity chain. If the result is lower than a preset response threshold, it is determined that the physical execution chain has been bypassed or spoofed, triggering the effectiveness degradation control module to strip the subsequent physical execution permissions of the current instruction.