A multi-parameter collaborative control method and system for a vacuum leak detection process
Patent Information
- Application Number
- CN202610971344.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-01
- Publication Date
- 2026-09-29
AI Technical Summary
[0005]针对现有技术的不足,本发明提供了一种真空检漏过程多参数协同控制方法及系统,解决了现有的真空检漏系统在控制指令验证过程中依赖单一网络报文,导致设备易受异常指令干扰、引发检测部件损坏及最终漏率数据偏差的问题
1、本发明通过生成映射的动态阀控序列驱动比例阀在管路内产生受控物理通量扰动,同步采集压力与离子电流信号提取流体力学响应特征,将量化后的物理特征与检漏业务报文及固件度量值融合生成认证令牌进行鉴权,将数字空间的通信指令与真空管路的实时物理状态进行了绑定,使得网络攻击者即便截获并破解了通信协议,也无法伪造出符合当前真实气体流态的验证响应特征,提高了真空检漏系统抵抗非法指令注入和数据篡改的安全防护能力。
Smart Images

Figure CN122845201A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vacuum leak detection technology, specifically to a multi-parameter collaborative control method and system for the vacuum leak detection process. Background Technology
[0002] Existing vacuum leak detection systems typically rely on network-level digital encryption and authentication for command verification when performing remote control. When the communication protocol is cracked or the gateway is compromised, attackers can directly forge messages to issue malicious commands. Because the system does not cross-verify digital communication commands with the real-time fluid dynamics of the vacuum pipeline, the equipment cannot identify illegal injection commands that violate objective physical laws.
[0003] When attempting to introduce physical state parameters to assist in authentication to address the aforementioned issues, inherent geometric tolerances in the on-site vacuum piping during processing and assembly, as well as environmental background noise during sensor measurement, inevitably lead to slight deviations between the expected response values derived from the theoretical model and the actual measured values. This inherent measurement bias in the physical system can easily cause misjudgments of legitimate control commands during the comparison process, affecting the reliability of the equipment operating in the industrial field.
[0004] Furthermore, the processor time for data bit comparison in existing system cryptographic authentication logic is prone to fluctuations depending on the data content, making the device vulnerable to side-channel attacks due to external computation time differences. Simultaneously, when the system suffers network anomalies or attacks, existing equipment security protection strategies still heavily rely on industrial digital communication buses for interlocking command transmissions, failing to construct an underlying hardware protection path independent of the digital network. If communication network delays or disruptions occur, valves whose opening cannot be promptly restricted can easily cause abnormal pressure fluctuations within the pipeline, leading to damage to the core detection components inside the leak detector due to high-pressure airflow. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this invention provides a multi-parameter collaborative control method and system for vacuum leak detection processes. This solves the problem that existing vacuum leak detection systems rely on a single network message during the control command verification process, which makes the equipment susceptible to interference from abnormal commands, leading to damage to detection components and deviations in the final leak rate data.
[0006] To achieve the above objectives, the present invention provides the following technical solution: The first aspect of this invention provides a multi-parameter coordinated control method for a vacuum leak detection process, comprising the following steps: An encrypted random number and instruction identifier are generated and mapped to a dynamic valve control sequence, which in turn drives the proportional valve to generate controlled physical flux disturbances in the pipeline system. Simultaneously collect controlled physical flux disturbances to form pressure sampling data columns and ion current sampling data columns, obtain real leak detection business messages, and extract response delay characteristics and decay time constant characteristics from them; The eigenvalues of the covariance matrix of the pressure sampling data column and the ion current sampling data column are extracted, and the discrete status code vector is generated by combining the response delay feature and the decay time constant feature. The authentication token is generated by merging the encrypted random number, the instruction identifier and the hash digest of the real leak detection business message. The gateway inputs the dynamic valve control sequence into the physical baseline model to expand and generate a discrete state expectation candidate set, and infers the expected hash token candidate set to determine whether the authentication token matches, and outputs the authentication result; When the authentication result is a successful match, the test pressure of the pipeline system is maintained according to the test command sequence to obtain the final leak rate data; when the authentication result is a failed match, subsequent control messages are isolated, the power supply to the test valve is cut off, and the exhaust gas discharge channel is switched to limit the rate of change of the proportional valve opening. By introducing physical state data from the fluid dynamics dimension into the command authentication, the system's ability to identify and isolate abnormal commands is improved.
[0007] Furthermore, the control gateway generates encrypted random numbers and instruction identifiers, maps them to dynamic valve control sequences, and sends them to the edge nodes. The edge nodes then drive the proportional valves according to these dynamic valve control sequences. The process by which the edge nodes collect controlled physical flux disturbances to form pressure sampling data sequences and ion current sampling data sequences includes: The internal logic array enables dual-rate collaborative data acquisition. Within a specified sampling time window, the logic array continuously acquires the transient absolute pressure signal output from the thin-film gauge, forming a pressure sampling data series. Simultaneously, the logic array acquires the transient ion current signal output from the electrometer interface of the leak detector through an analog signal acquisition channel, forming an ion current sampling data series. This dual-rate data acquisition method satisfies the sampling time requirements of the absolute pressure signal and the high-frequency transient ion current signal across different hardware channels.
[0008] Furthermore, the process of mapping encrypted random numbers and instruction identifiers to dynamic valve control sequences includes: obtaining the current steady-state absolute pressure and steady-state temperature of the pipeline system, and calculating the molecular mean free path by combining the Boltzmann constant and the effective molecular diameter. The Knudsen number is obtained by calculating the ratio of the molecular mean free path to the characteristic geometric inner diameter of the pipeline system. When the Knudsen number is less than or equal to the upper limit threshold for viscous flow, the gas is determined to be in the viscous flow region; when the Knudsen number is greater than or equal to the lower limit threshold for molecular flow, the gas is determined to be in the molecular flow region; and when the Knudsen number is between the upper limit threshold for viscous flow and the lower limit threshold for molecular flow, the gas is determined to be in the transition flow region.
[0009] Based on the determined gas flow regime, a corresponding amplitude constraint coefficient is assigned. The amplitude constraint coefficient for the molecular flow regime is less than that for the viscous flow regime. The binary bit segment of the encrypted random number is divided into a preset byte length and mapped to the basic valve opening change value. The basic valve opening change value is multiplied by the amplitude constraint coefficient to generate a dynamic valve control sequence. Gas dynamic parameters are used to constrain the valve opening change value to prevent pressure fluctuations deviating from the set detection range caused by valve control actions.
[0010] Furthermore, the process of extracting response delay features and decay time constant features from edge nodes includes: calculating the arithmetic mean of the pressure sampling data column and the ion current sampling data column, and subtracting the corresponding arithmetic mean from the pressure sampling data column and the ion current sampling data column respectively to obtain the zero baseline pressure data column and the zero baseline ion current data column.
[0011] Discrete cross-correlation operations are performed on the zero-baseline pressure data series and the zero-baseline ion current data series to obtain a cross-correlation function sequence. The global maximum peak value is then searched within this sequence. When the global maximum peak value exceeds the effective peak value threshold, the discrete hysteresis count corresponding to the global maximum peak value is extracted. This discrete hysteresis count is then multiplied by the hardware sampling period of the high-frequency transient channel to obtain the response delay characteristics.
[0012] The decay segment data after the response delay feature is extracted from the zero-baseline ion current data series. The steady-state base current is subtracted from the decay segment data, and data points whose absolute difference is greater than a preset noise lower limit are used as valid fitting points. A natural logarithmic transformation is performed on the absolute value of the difference between the valid fitting points, or the difference after adding a positive lower limit, to transform the nonlinear exponential decay model into a first-order linear equation. A linear regression is performed on the first-order linear equation to obtain the slope, and the reciprocal of the absolute value of the slope is used to obtain the decay time constant feature.
[0013] Furthermore, the process of generating discrete state code vectors by edge node quantization includes: normalizing the pressure sampling data column and the ion current sampling data column to obtain dimensionless pressure data column and dimensionless ion current data column. The covariance matrix of the dimensionless pressure data column and the dimensionless ion current data column is calculated, and eigenvalue decomposition is performed to extract the eigenvalues of the covariance matrix. The eigenvalues of the covariance matrix, the response delay feature, and the decay time constant feature are sequentially concatenated to construct a four-dimensional continuous physical state vector. Each element in the continuous physical state vector is divided by the corresponding step size constant in the preset tolerance step size vector to obtain the quotient vector. The quotient values in the quotient vector are rounded to the nearest integer, discarding floating-point residuals, and the discrete state code vector is output.
[0014] Furthermore, the process of edge node fusion to generate authentication tokens includes: extracting the actual leak detection service message temporarily stored in the FIFO double-buffered register and performing a secure hash algorithm to calculate the corresponding hash digest; extracting the underlying firmware metric hash value; and sequentially concatenating the encrypted random number, instruction identifier, sampling time window identifier, discrete status code vector, hash digest of the actual leak detection service message, and underlying firmware metric hash value to generate a combined data sequence. The edge-side symmetric authentication key stored in the secure isolation zone is invoked, and the edge-side symmetric authentication key is used to calculate the message authentication code on the combined data sequence to obtain a fixed-length ciphertext output as the authentication token. The edge node then transmits the authentication token and the actual leak detection service message to the control gateway.
[0015] Furthermore, the control gateway internally runs a physical baseline model. The process of the control gateway performing extended generation of discrete state expectation candidate sets includes: inputting the dynamic valve control sequence, the current steady-state absolute pressure and steady-state temperature of the pipeline system into the physical baseline model, using the equivalent fluid resistance-capacitance network algorithm to simulate the gas dynamic response characteristics of the pipeline system under the corresponding boundary conditions, calculating and outputting the expected theoretical continuous response vector, which includes the expected covariance matrix eigenvalues, the expected response delay characteristics, and the expected decay time constant characteristics.
[0016] Each element of the expected theoretical continuous response vector is divided by the corresponding step size constant in the preset tolerance step size vector to obtain the quotient vector, and the quotient vector is rounded to obtain the baseline discrete vector. The single-point offset values of each dimension are limited to -1, 0, and 1, and a preset neighborhood offset combination space is constructed through full permutation combinations. The baseline discrete vector is added to each neighborhood offset vector in the neighborhood offset combination space to obtain multiple extended state code vectors, which constitute the discrete state expectation candidate set.
[0017] Furthermore, the control gateway's operation to determine whether the authentication token matches includes: performing local hash calculation on the received real leak detection service message to generate a local verification hash digest, and extracting the underlying firmware baseline metric hash value stored in the local security configuration database. The encrypted random number, instruction identifier, sampling time window identifier, extended status code vector, local verification hash digest, and underlying firmware baseline metric hash value are sequentially concatenated to generate a local combined data sequence. The expected hash token is obtained by calculating the message authentication code on the local combined data sequence using a symmetric verification key. Finally, all extended status code vectors in the discrete state expected candidate set are traversed to generate an expected hash token candidate set containing multiple expected hash tokens.
[0018] This algorithm employs an XOR logic unit and introduces an accumulation variable. It performs a bitwise XOR operation on each data bit of the authentication token and the expected hash token, accumulating the result into an accumulation variable. The comparison loop continues running without premature termination until all data bits have been traversed. After traversing all data bits, it checks if the accumulation variable is zero. If the accumulation variable is zero, it indicates a match with completely identical data bits exists. If a match exists in the expected hash token candidate set, the authentication result is output. This continuous operation until the end of the traversal avoids computation time fluctuations caused by differences in data bits during the comparison process.
[0019] Furthermore, the test command sequence is issued by the control gateway to the edge node for execution. The control gateway performs the operation of isolating subsequent control messages and sends instructions to the safety controller to cooperate in the operation of switching the exhaust gas discharge channel. Among them, the process of limiting the opening rate of the proportional valve includes: synchronously acquiring the time series corresponding to the transient absolute pressure signal and the transient ion current signal, and respectively taking the derivative with respect to the time variable to obtain the instantaneous derivative function of the pressure signal as the pressure drop slope, and acquiring the instantaneous derivative function of the ion current signal as the background ion current change rate.
[0020] When the absolute value of the pressure drop slope is greater than or equal to 80% of the preset pressure drop safety threshold, or the absolute value of the background ion current change rate is greater than or equal to 80% of the preset ion flow fluctuation safety threshold, an exhaust flow limit command is sent to the safety controller via a hard-wired safety output interface independent of the industrial communication bus. The safety controller then dynamically reduces the proportional valve's opening step size by outputting a suppression signal to the proportional valve's safety limit input via a hard-wired limit control terminal.
[0021] A second aspect of the present invention provides a multi-parameter collaborative control system for a vacuum leak detection process, used to implement the aforementioned multi-parameter collaborative control method for a vacuum leak detection process, including a control gateway, an edge node, a proportional valve, a piping system, a diaphragm gauge, a leak detector, and a safety controller.
[0022] The control gateway generates encrypted random numbers and instruction identifiers, maps them to dynamic valve control sequences, and sends them to edge nodes.
[0023] Edge nodes drive proportional valves to generate controlled physical flux disturbances within the pipeline system based on dynamic valve control sequences. Edge nodes acquire signals from membrane gauges and leak detectors to form pressure and ion current sampling data sequences. They extract response delay and decay time constant features, and combine these features to quantize and generate discrete status code vectors. These vectors are then fused with encrypted random numbers, command identifiers, and hash digests of externally input real leak detection service messages to generate an authentication token, which is transmitted to the control gateway.
[0024] The control gateway runs a physical baseline model, expands the dynamic valve control sequence to generate a discrete state expectation candidate set, and infers the expected hash token candidate set to determine whether the authentication token matches, and outputs the authentication result.
[0025] For successful authentication results, the control gateway maintains the test pressure of the pipeline system according to the test command sequence; for unsuccessful authentication results, the control gateway isolates subsequent control messages and sends instructions to the safety controller, which then performs operations such as cutting off the power supply to the sustaining power circuit coil of the test valve, switching the exhaust gas discharge channel of the pipeline system, and limiting the opening rate of the proportional valve.
[0026] This invention provides a multi-parameter coordinated control method and system for a vacuum leak detection process. It has the following beneficial effects: 1. This invention drives a proportional valve to generate controlled physical flux disturbances in the pipeline by generating a dynamic valve control sequence of mapping. It simultaneously collects pressure and ion current signals to extract fluid dynamic response characteristics. The quantified physical characteristics are fused with leak detection service messages and firmware metrics to generate authentication tokens for authentication. This binds the communication commands in the digital space with the real-time physical state of the vacuum pipeline, so that even if network attackers intercept and crack the communication protocol, they cannot forge verification response characteristics that conform to the current real gas flow state. This improves the security protection capability of the vacuum leak detection system against illegal command injection and data tampering.
[0027] 2. This invention calculates the theoretical continuous response vector by running a physical baseline model inside the control gateway, performs division and rounding operations on it to obtain a reference discrete vector, and introduces a preset neighborhood offset permutation combination to expand and generate a discrete state expectation candidate set containing multiple state codes for token comparison. This compensates for the inherent geometric tolerances in the processing and assembly of physical equipment on site, eliminates environmental background noise interference in the sensor measurement process, reduces the false judgment rate of legitimate command authentication caused by small measurement deviations in the physical system, and ensures the reliability of the authentication mechanism in industrial field operation.
[0028] 3. This invention obtains the time-series derivative function of absolute pressure and ion current. When the pressure drop slope or ion current change rate reaches the safety threshold ratio, it uses a hard-wired safety output interface independent of the communication bus to link with the safety controller to reduce the opening step size of the proportional valve. At the same time, in the gateway authentication and comparison logic, a bitwise XOR operation is used to traverse all data bits before ending the loop. This not only prevents side-channel attacks caused by external computation time difference, but also builds a pure hardware-level protection path for the system that is independent of the digital communication network, preventing the core detection components from being damaged by abnormal airflow impact. Attached Figure Description
[0029] Figure 1This is a macroscopic flowchart of the multi-parameter coordinated control method for vacuum leak detection in this invention. Figure 2 This is a flowchart illustrating the zero-trust access and controlled physical perturbation generation logic of the present invention. Figure 3 This is a flowchart of the edge-side high-frequency synchronous acquisition and physical feature extraction logic of the present invention; Figure 4 This is a flowchart illustrating the logic of dimensionality reduction quantization and hardware-level cryptographic trust binding in this invention. Figure 5 This is a flowchart of the baseline model derivation and tolerance collision authentication logic of the main control device of the present invention; Figure 6 This is a two-parameter transient response curve under controlled physical flux perturbation according to an embodiment of the present invention; Figure 7 To extract response delay feature maps for discrete cross-correlation calculation according to an embodiment of the present invention; Figure 8 This is a first-order linear fit plot of logarithmically decayed segment data according to an embodiment of the present invention; Figure 9 This is a comparison chart of isolation response pressure after encountering a network waveform injection attack according to an embodiment of the present invention. Detailed Implementation
[0030] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0031] This invention provides a multi-parameter collaborative control system for a vacuum leak detection process, including: a control gateway, an edge node, a proportional valve, a test valve, an exhaust valve, a diaphragm gauge, a leak detector, and a safety controller. It also includes a temperature sensor for acquiring the steady-state temperature of the pipeline system, and an external interaction interface for inputting real leak detection service messages.
[0032] The control gateway sends commands to the edge nodes and receives data feedback through the industrial communication bus, and connects to the abnormal status input terminal of the safety controller through a hard-wired safety output interface that is independent of the industrial communication bus data link.
[0033] The edge node integrates a logic array, a main control chip, and security elements. It is deployed at the field end close to the piping system to collect its operating parameters.
[0034] A proportional valve and diaphragm gauge are installed in the detection gas path of the pipeline system to establish gas flow within the detection gas path. The leak detector's inlet is connected to the pipeline system to extract a gas sample.
[0035] The thin-film gauge is used to sense absolute pressure changes in the piping system and connects the signal output to the logic array within the edge node. The leak detector provides an electrometer interface, which is directly connected to the analog signal acquisition channel of the logic array. The edge node is equipped with a drive output port, which connects to the control terminal of the proportional valve to drive the proportional valve to change the cross-sectional area of the airflow channel.
[0036] The test valve is positioned at the front end of the high-sensitivity analysis chamber of the leak detector to cut off or allow airflow. The exhaust valve is positioned in the exhaust channel of the piping system to release gas. The safety controller is independent of the control gateway's data link and is connected to the sustaining power circuit coil of the test valve and the actuation control coil of the exhaust valve via an external hardwired control bus. It is also connected to the safety limiting input of the proportional valve via a hardwired limiting control terminal, used to bring the proportional valve to a preset safe opening degree or limit its opening rate of change in abnormal isolation conditions.
[0037] See attached document Figure 1 This invention provides a multi-parameter coordinated control method for a vacuum leak detection process, comprising the following steps: S10. Initiate an access request and inject controlled physical perturbations. The edge node sends a cooperative control access request to the control gateway. The control gateway generates an encrypted random number and a command identifier, obtains the current steady-state absolute pressure and steady-state temperature of the pipeline system through the operating parameters uploaded by the edge node, and estimates the Knudsen number according to fluid dynamics rules to determine the gas flow regime. After the determination is completed, the control gateway maps the encrypted random number to a dynamic valve control sequence based on the gas flow regime and sends the dynamic valve control sequence to the edge node. The edge node drives the proportional valve to change the cross-sectional area of the airflow channel according to the dynamic valve control sequence, generating a controlled physical flux perturbation corresponding to the dynamic valve control sequence in the detection gas path.
[0038] S20. Perform multi-parameter synchronous acquisition and physical feature extraction. Based on the controlled physical flux disturbance generated within the pipeline system, the edge nodes utilize a logic array to initiate dual-rate collaborative data acquisition. Within a specified sampling time window, the logic array continuously acquires the transient absolute pressure signal output by the thin-film gauge and forms a pressure sampling data series. Simultaneously, it acquires the transient ion current signal output by the electrometer interface through the analog signal acquisition channel and forms an ion current sampling data series.
[0039] While performing data acquisition at the edge nodes, the edge nodes also read the actual leak detection service messages input from the external interaction interface. The actual leak detection service messages include at least one of the following: workpiece identifier, batch identifier, process recipe index, test request parameters, and upper-level system task number, but do not include the final leak rate data that has not yet been generated for the current leak detection cycle. The logic array acquires the zero-baseline pressure data column and the zero-baseline ion current data column, performs discrete cross-correlation calculations and exponential fitting operations, and extracts the response delay characteristics and decay time constant characteristics corresponding to the controlled physical flux disturbance.
[0040] S30. Construct the feature covariance matrix and perform hardware-level data binding. The main control chip at the edge node acquires the zero-baseline pressure data column and the zero-baseline ion current data column, and calculates the covariance matrix of the dimensionless pressure data column and the dimensionless ion current data column after normalization. After the calculation is completed, the main control chip performs eigenvalue decomposition on the covariance matrix to extract the eigenvalues of the covariance matrix. After extraction, the main control chip combines the eigenvalues of the covariance matrix, the response delay feature, and the decay time constant feature to generate a continuous physical state vector.
[0041] The main control chip performs discrete alignment quantization on the continuous physical state vector using a preset tolerance step size vector, outputting a discrete state code vector. The security element extracts the underlying firmware metric hash value, concatenates the discrete state code vector, encrypted random number, instruction identifier, and hash digest of the actual leak detection service message, and generates an authentication token using a message authentication code algorithm. The edge node outputs the authentication token and the actual leak detection service message to the control gateway.
[0042] S40. The control gateway derives the physical baseline model of the equipment and performs multi-candidate tolerance authentication. It inputs the dynamic valve control sequence, steady-state absolute pressure, and steady-state temperature issued by itself into the locally running physical baseline model, calculating and outputting the expected theoretical continuous response vector. After calculation, the control gateway combines the tolerance step size vector and a preset neighborhood offset to expand the theoretical continuous response vector into a discrete-state expected candidate set. Based on the discrete-state expected candidate set, the control gateway derives the expected hash token candidate set, determines whether the received authentication token belongs to the expected hash token candidate set, and outputs the authentication result accordingly.
[0043] S50. Perform cross-domain collaborative control and physical domain failure security isolation. Based on the authentication result, when the authentication token exists in the expected hash token candidate set, the control gateway transmits the real leak detection business message to the manufacturing execution system and extracts the corresponding process recipe. Then, based on the process recipe, it issues the subsequent test instruction sequence to the edge node. The edge node adjusts the proportional valve according to the subsequent test instruction sequence to maintain a constant test pressure in the pipeline system, so as to control the leak detector to perform leak rate measurement, obtain the final leak rate data, and complete the current leak detection cycle.
[0044] Conversely, when the authentication token fails to match, the control gateway maintains the existing network session state in the digital domain and redirects subsequent control messages from the edge node to the virtual trap sandbox environment for behavioral analysis and feature recording. Simultaneously, the control gateway sends an abnormal status signal to the security controller via a hardwired security output interface. Upon receiving the abnormal status signal, the security controller initiates multi-parameter collaborative isolation control. While cutting off the power supply to the test valve's sustaining power circuit coil to mechanically reset and lock it, it outputs an opening signal to the exhaust valve's control coil to switch the exhaust gas discharge channel of the pipeline system. It also coordinates with the control gateway to adjust the opening of the proportional valve to match the exhaust flow rate. Simultaneously, it monitors the pressure drop slope (i.e., the rate of pressure transient change) of the pipeline system and the background ion current change rate of the leak detector through the membrane gauge and electrometer interfaces, ensuring that the physical parameters of the pipeline system and the leak detector remain within a safe range during the isolation process.
[0045] See attached document Figure 2 In the multi-parameter collaborative control method for vacuum leak detection provided by this invention, step S10, initiating an access request and injecting controlled physical perturbations, includes the following sub-steps: S11. Establish communication connection and initialize environment awareness. The edge node sends a collaborative control access request containing the node identifier and device certificate to the control gateway via the industrial communication bus. The control gateway receives the collaborative control access request and verifies the device certificate using a pre-configured public key infrastructure. If the verification fails, the collaborative control access request is rejected and a security log is recorded. Alternatively, if the verification passes, an encrypted random number is generated using an internal hardware random number generator. and the instruction identifier corresponding to the encrypted random number. For signature verification, existing asymmetric encryption verification frameworks can be used. The certificate chain verification logic is a well-known technology in this field and will not be elaborated here.
[0046] During the communication handshake, the edge node invokes its internal low-frequency acquisition channel to obtain the steady-state absolute pressure of the pipeline system under the current resting vacuum state. and steady-state temperature The system encapsulates the steady-state absolute pressure and steady-state temperature as operating parameters and uploads them to the control gateway, which then obtains the current steady-state absolute pressure and steady-state temperature of the pipeline system. The logic for extracting hardware entropy sources to generate random data is well-known technology and will not be elaborated upon here.
[0047] S12. Evaluate the fluid flow regime range based on environmental parameters. The gas flow pattern inside the pipeline system affects the propagation delay and attenuation characteristics of subsequently applied physical perturbations, because the transmission mechanism of pressure disturbances differs under different flow regimes.
[0048] After receiving the steady-state absolute pressure and steady-state temperature, the control gateway calculates the mean free path of molecules, which characterizes the collisional properties of gas molecules. And based on the molecular mean free path Calculate the Knudsen number of the gas inside the piping system. The Knudsen number represents the ratio of the mean free path of gas molecules to the characteristic dimension of the conduit. The mean free path of molecules and the Knudsen number are calculated using the following formula: ; ; in, Indicates the mean free path of molecules; This represents the Boltzmann constant, which is a known physical constant. Indicates steady-state temperature; This indicates the effective molecular diameter of the gas being measured in the current pipeline system, which can be obtained by querying the physical property table based on the actual type of background gas or helium gas extracted. Represents steady-state absolute pressure; Represents the Knudsen number; This represents the characteristic geometric inner diameter of the piping system; This represents the average thermodynamic kinetic energy factor of gas molecules at steady-state temperature; This represents the effective collision cross-sectional area of gas molecules.
[0049] The control gateway divides the flow regime into intervals based on the calculated Knudsen number. Specifically, the lower-level decision criteria are as follows: when the Knudsen number is less than or equal to the upper threshold of viscous flow, the gas is determined to be in the viscous flow interval, where collisions between gas molecules are frequent and disturbances propagate in the airflow in a wave-like manner; when the Knudsen number is greater than or equal to the lower threshold of molecular flow, the gas is determined to be in the molecular flow interval, where collisions between gas molecules and the pipe wall are dominant and disturbances propagate in the form of molecular diffusion; when the Knudsen number is between the upper threshold of viscous flow and the lower threshold of molecular flow, the gas is determined to be in the transition flow interval.
[0050] In a specific embodiment of the present invention, the upper limit threshold of viscous flow can be set to a value of 0.01, and the lower limit threshold of molecular flow can be set to a value of 0.3. The upper limit threshold of viscous flow and the lower limit threshold of molecular flow can be adjusted according to actual needs.
[0051] S13. Perform safety constraint mapping for the dynamic valve control sequence. After determining the gas flow range, the control gateway establishes mapping rules, converting encrypted random numbers into dynamic valve control sequences used to drive the hardware. The dynamic valve control sequence consists of a series of discrete opening control codes. The mathematical process of transforming it into a dynamic valve control sequence is established through the following mapping function: ; in, Indicates a dynamic valve control sequence; Represents a mapping function; Represents an encrypted random number; Represents the Knudsen number; Represents steady-state absolute pressure; This indicates the steady-state temperature.
[0052] To prevent the injected airflow disturbance from causing signal saturation in the high-voltage electrometer inside the leak detector, or from exceeding the baseline drift limit of the leak detector's background ion current, the control gateway assigns corresponding amplitude constraint coefficients based on the determined flow regime. The allocation logic is as follows: changes in conductivity within the molecular flow regime tend to cause significant ion current fluctuations; therefore, the amplitude constraint coefficient for the molecular flow regime is smaller than that for the viscous flow regime. In actual parameter configurations, the amplitude constraint coefficient for the molecular flow regime can be set from 0.1 to 0.3, and the amplitude constraint coefficient for the viscous flow regime can be set from 0.7 to 0.9.
[0053] The control gateway divides the binary segment of the encrypted random number into a preset byte length to map to the base opening change value. The preset byte length can be set to 8 bits or 16 bits depending on the microprocessor architecture. The control gateway multiplies the base opening change value by an amplitude constraint coefficient to generate a dynamic valve control sequence. By introducing the amplitude constraint coefficient, the control gateway limits the maximum gas flux change value generated by the dynamic valve control sequence driving the proportional valve to be less than the background ion current fluctuation limit allowed for normal operation of the leak detector. The specific value of the background ion current fluctuation limit is determined based on the maximum range of the electrometer inside the leak detector. The control gateway sets the background ion current fluctuation limit to 5% of the maximum range to ensure that the total amplitude of the ion current signal after superimposed physical perturbations is within the linear amplification range of the electrometer and to prevent hardware saturation.
[0054] S14. Physical Perturbation Execution Response of Edge Nodes. The control gateway sends downlink data packets containing encrypted random numbers, instruction identifiers, and dynamic valve control sequences to the edge nodes. After receiving the downlink data packets, the edge nodes parse and extract the dynamic valve control sequences, latch the encrypted random numbers and instruction identifiers into the authentication buffer corresponding to the current sampling time window, and convert the discrete opening control codes in the dynamic valve control sequences into continuously changing analog voltage quantities through a digital-to-analog converter. These analog voltage quantities are then applied to the piezoelectric ceramic actuator of the proportional valve through the drive output port.
[0055] The hardware working mechanism of a digital-to-analog converter that converts discrete digital signals into continuous analog voltage quantities can be implemented using existing digital-to-analog converter chip interface protocols. The signal reconstruction process is a well-known technology in this field and will not be elaborated here.
[0056] The piezoelectric ceramic actuator of the proportional valve responds to changes in the analog voltage and generates μm-level deformation to adjust the internal valve core displacement, performing millisecond-level micro-amplitude opening adjustment and changing the cross-sectional area of the airflow channel in the detection gas path in real time. The dynamic change of the airflow channel cross-sectional area directly modulates the gas flow rate inside the pipeline system, thereby exciting a controlled physical flux disturbance within the pipeline system that corresponds to the characteristics of the dynamic valve control sequence.
[0057] See attached document Figure 3 In the multi-parameter collaborative control method for vacuum leak detection provided by this invention, step S20, performing multi-parameter synchronous acquisition and physical feature extraction, includes the following sub-steps: S21. Establish a dual-rate, multi-parameter synchronous acquisition channel. After receiving a downlink data packet containing an instruction identifier, the logic array of the edge node triggers a dual-rate collaborative data acquisition action, assigns a sampling time window identifier to the current data acquisition cycle, sets the corresponding total sampling time window length, and configures a hardware timer to establish a high-frequency transient channel and a low-frequency steady-state channel. In the high-frequency transient channel, pressure sampling and ion current sampling share the same hardware sampling trigger source or a unified hardware timestamp to ensure that they perform cross-correlation calculations under the same sampling time reference. The low-frequency steady-state channel is used for temperature acquisition and baseline compensation, and its sampling timing can be independent of the high-frequency transient channel. Based on the Shannon-Nyquist sampling theorem, the logic array sets the sampling frequency range of the high-frequency transient channel to 10kHz to 100kHz.
[0058] At the underlying implementation of hardware-level sampling timing control, the logic array utilizes two sets of independent hardware clock trees that do not interfere with each other as driving sources, thereby decoupling the sampling timing of the high-frequency transient channel and the low-frequency steady-state channel at the physical layer. The logic array continuously acquires the transient absolute pressure signal output by the thin-film gauge through the high-frequency transient channel and forms a pressure sampling data series, while simultaneously acquiring the transient ion current signal output by the electrometer interface to form an ion current sampling data series with a corresponding timestamp to the pressure sampling data series.
[0059] Meanwhile, to avoid the low-pass filtering circuit conventionally configured inside the leak detector motherboard erasing the true high-frequency perturbation characteristics, the logic array adopts a specific hardware-level lossless acquisition path for transient ion current signals: In the first implementation, the logic array directly connects to the electrometer's underlying circuitry of the leak detector through the analog signal acquisition channel, and a high-impedance isolation buffer circuit, a current-limiting protection circuit, and an anti-aliasing filter circuit are set between the analog signal acquisition channel and the electrometer's underlying circuitry to avoid the sampling action changing the original operating point of the electrometer, acquiring the original analog current signal without the motherboard's digital low-pass filtering and forming an ion current sampling data series; In the second implementation, the logic array directly acquires the equivalent original ion source signal through the high-speed analog diagnostic interface reserved in the leak detector and forms an ion current sampling data series.
[0060] The sampling frequency of the high-frequency transient channel is determined by the highest effective frequency component of the controlled physical flux disturbance and the effective analog bandwidth of the thin-film gauge, electrometer interface and analog-to-digital converter, and the sampling frequency is not less than twice the highest effective frequency component.
[0061] Compared to the high-frequency transient channel, considering the physical thermal inertia of the temperature sensor, the logic array sets the sampling frequency of the low-frequency steady-state channel to 1Hz to 10Hz. It then periodically collects multi-point average temperature data from the pipeline system using this low-frequency steady-state channel. This multi-point average temperature data is then used to perform thermal drift compensation and baseline calibration on the pressure and ion current sampling data series to eliminate measurement baseline shifts caused by gradual changes in ambient temperature. The oversampling operation of the analog-to-digital converter and the hardware circuit design for thermal drift compensation can be implemented using existing signal conditioning circuits and digital filter chips. The sampling and compensation mechanisms are well-known technologies in this field and will not be elaborated upon here.
[0062] S22. Non-blocking parallel reading mechanism for real leak detection service messages. While the edge node continuously constructs pressure sampling data columns and ion current sampling data columns using the logic array, the edge node initiates non-blocking parallel reading of real leak detection service messages. The edge node's main control chip activates a dedicated peripheral interaction interface to receive externally input real leak detection service messages and configures an independent direct memory access channel to avoid large-capacity service data messages occupying the central processing unit's processing time, thereby preventing high-frequency transient channels from experiencing nested interrupt losses or timing blockages.
[0063] During the data reading and transfer phase, the actual leak detection service messages received by the peripheral interaction interface are directly moved into a dedicated first-in-first-out (FIFO) double-buffered register in parallel through the direct memory access channel without intervention from the main CPU. The main control chip asynchronously and non-blockingly reads the actual leak detection service messages in the FIFO double-buffered register in a low-priority service communication thread independent of the hardware sampling clock, thereby ensuring that the pressure sampling data series and the ion current sampling data series maintain hardware-level temporal continuity within the specified sampling time window.
[0064] S23. Resting DC Bias Elimination and Mean Reduction of Physical Signals. The logic array extracts the pressure sampling data series and ion current sampling data series within the total sampling time window. Due to the initial steady-state DC bias in the analog signals output from the underlying circuitry of the thin-film gauge and leak detector, the unremoved steady-state DC bias will generate non-zero baseline drift during subsequent cross-correlation calculations, thus masking the cross-correlation peak reflecting the true perturbation propagation delay. To eliminate the interference of the resting substrate signal on feature extraction, the logic array calculates the arithmetic mean of the pressure sampling data series and the ion current sampling data series respectively. Then, the corresponding arithmetic mean is subtracted from the original pressure sampling data series to obtain the zero-baseline pressure data series, and the corresponding arithmetic mean is subtracted from the original ion current sampling data series to obtain the zero-baseline ion current data series.
[0065] S24. Discrete cross-correlation calculation extracts response delay features. The logic array acquires the zero-baseline pressure data series and the zero-baseline ion current data series, and performs discrete cross-correlation calculation and exponential fitting operation. Specifically, the logic array uses the pre-processed zero-baseline pressure data series and the zero-baseline ion current data series, and performs discrete cross-correlation operation on the two through the internal hardware multiplier-accumulator core to obtain the cross-correlation function sequence of the two in the time domain. Due to the inherent physical delay in the propagation of controlled physical flux disturbances in the pipeline system, and the spatial distance between the physical installation positions of the membrane gauge and the leak detector, the change in ion current lags behind the change in absolute pressure on the time axis. The discrete cross-correlation function is calculated using the following formula: ; in, Variable identifiers representing a sequence of cross-correlation functions; This represents the total number of sampling points within the total sampling time window. Represents the physical quantity of zero baseline pressure; Represents the physical quantity of zero-baseline ion current; This represents the number of discrete lag cycles. The numerical value of the cross-correlation function; Represents the discrete sampling sequence number from 0 to... The summation operation; Indicates discrete sampling number The corresponding zero baseline pressure sampling value; Indicates discrete sampling number The corresponding zero-baseline ion current sampling value; Indicates discrete sampling number Corresponding pressure sample value and discrete sample number The instantaneous product of the corresponding zero-baseline ion current sample values.
[0066] Discrete hysteresis counts within the configuration range of the logic array traversal Calculate and output the complete sequence of cross-correlation functions. Discrete lag time. The search range is set based on the actual physical length of the pipeline system and the maximum delay time estimated by the sound velocity. To prevent false calculated peak values from high-frequency electromagnetic noise in the industrial environment, the logic array is pre-configured with an effective peak threshold. The effective peak threshold is obtained as follows: with the pipeline system in a resting, undisturbed state, the logic array collects resting pressure data and resting ion current data, calculates the resting cross-correlation function sequence, calculates the standard deviation or root mean square value of the resting cross-correlation function sequence, and multiplies it by a preset safety margin coefficient to obtain the effective peak threshold. The safety margin coefficient can be a constant between 3 and 5.
[0067] The logic array searches for the global maximum peak value in the cross-correlation function sequence and determines whether the global maximum peak value is greater than the effective peak value threshold. When the global maximum peak value is less than or equal to the effective peak value threshold, the logic array determines that the current signal is overwhelmed by noise and discards the current data. When the global maximum peak value is greater than the effective peak value threshold, the logic array extracts the discrete hysteresis count corresponding to the global maximum peak value and multiplies the discrete hysteresis count corresponding to the global maximum peak value by the hardware sampling period of the high-frequency transient channel to analyze and obtain the response delay characteristics of the controlled physical flux disturbance in the pipeline system.
[0068] S25. The time constant features are extracted using an exponential decay model. After the controlled physical flux disturbance reaches its peak, the gas pressure in the pipeline system and the ion flow inside the leak detector gradually decrease to the steady-state baseline level. The logic array extracts the decay segment data from the ion current sampling data column after the response delay feature, and fits the decay segment data using an exponential decay model. The exponential decay model describes the physical recovery process using the following formula: ; in, Represents the physical quantity of ion current; The peak amplitude parameter represents the transient ion current signal; This represents the response delay features extracted in step S24; Indicates the characteristics of the decay time constant; This represents the steady-state base current of the leak detector under the current environmental flow conditions; Representing the independent variable of time The corresponding transient ion current signal magnitude; This represents the time difference calculated from the moment the response delay is characterized. It represents the dimensionless elapsed time rate measured by the decay time constant, and the leading negative sign indicates a decreasing trend; This represents the transient dynamic current response term that decays exponentially over time.
[0069] Considering that directly running the nonlinear solver using a field-programmable gate array would consume a large amount of underlying logic resources, as a preferred hardware implementation, the logic array first subtracts the steady-state base current from the attenuation segment data. Data points whose absolute difference is greater than a preset noise lower limit are selected as valid fitting points. The preset noise lower limit is obtained in a similar way to the peak effective threshold in step S24, which is the root mean square value of the ion current noise statistically analyzed by the logic array when the pipeline system is in a resting state multiplied by a preset cutoff coefficient (e.g., 1 to 2).
[0070] Subsequently, the absolute value of the difference between the valid fitted points is either added to the logic array as a positive lower bound. The difference is then subjected to a natural logarithmic transformation, with a lower limit for positive numbers. Used to prevent logarithmic overflow, its value is the minimum effective non-zero quantization step value set according to the resolution of the internal analog-to-digital converter of the leak detector, or a preset small positive real constant.
[0071] Through the aforementioned natural logarithmic transformation, the nonlinear exponential decay model is transformed into a first-order linear equation. A linear regression is then performed on this first-order linear equation to calculate the slope. The reciprocal of the absolute value of the slope is then taken to obtain the decay time constant characteristic. The data processing logic for linearizing the exponential curve using logarithmic transformation and solving for the slope through linear regression can be implemented using existing basic digital signal processing algorithm libraries. The mathematical transformation process is well-known in this field and will not be elaborated upon here.
[0072] The decay time constant characteristic reflects the inherent ratio between the current effective vacuum rate of the pipeline system and the total volume of the test chamber. After the edge node completes the dynamic feature extraction of the controlled physical flux disturbance, it temporarily latches the extracted response delay feature and decay time constant feature. Together with the real leak detection service message that it reads in parallel without blocking in step S22 and temporarily stores in the first-in-first-out double buffer register, they serve as the core data source carrier for subsequent hardware-level trust binding.
[0073] See attached document Figure 4 In the multi-parameter collaborative control method for vacuum leak detection provided by this invention, step S30, constructing the characteristic covariance matrix and performing hardware-level data binding, includes the following sub-steps: S31. Constructing the statistical covariance and eigenvalue extraction of physical parameters. Since independently extracted time-domain features are easily affected by single-point impulse noise, the system needs to further extract the statistical coupling characteristics of the dimensionless pressure data series and the dimensionless ion current data series during time-domain fluctuations. The main control chip acquires the zero-baseline pressure data series and zero-baseline ion current data series obtained from the preprocessing in step S20, and normalizes them according to the noise standard deviation or full-scale calibration value of the pressure channel and ion current channel in the resting state, respectively, to obtain the dimensionless pressure data series and the dimensionless ion current data series, in order to calculate the covariance matrix of the dimensionless pressure data series and the dimensionless ion current data series.
[0074] In the specific matrix construction process, the main control chip calculates the autovariance of the dimensionless pressure data column, the autovariance of the dimensionless ion current data column, and the cross-variance of the dimensionless pressure data column and the dimensionless ion current data column, and uses the autovariance and cross-variance to construct a two-dimensional covariance matrix.
[0075] The diagonal elements of the two-dimensional covariance matrix reflect the respective fluctuation amplitudes, while the off-diagonal elements characterize the linear correlation between dimensionless pressure and dimensionless ion current. The specific calculation of the two-dimensional covariance matrix uses the following formula: ; in, Represent the covariance matrix; This represents the variance of a dimensionless pressure data column; This represents the cross-variance between the dimensionless pressure data series and the dimensionless ion current data series. This represents the cross-variance between the dimensionless ion current data series and the dimensionless pressure data series, and satisfies... Represents the variance of a dimensionless ion current data series; This represents a two-dimensional multivariate data structure composed of the autovariance and cross-variance arranged in matrix elements.
[0076] After constructing the covariance matrix, the main control chip performs eigenvalue decomposition on the covariance matrix to extract its eigenvalues. The specific eigenvalue decomposition uses the following formula: ; in, Represent the covariance matrix; Represents the eigenvector; Represents eigenvalues; This represents the matrix product term between the covariance matrix and the eigenvectors; This represents the scalar multiplication of the eigenvalue and the eigenvector.
[0077] The main control chip sorts the eigenvalues of the two real covariance matrices generated by eigenvalue decomposition in descending order, and obtains the parameters characterizing the directional energy of the principal and secondary components of the data, namely the principal coupling eigenvalues and the secondary coupling eigenvalues. The aforementioned well-known matrix eigenvalue decomposition algorithm can be implemented directly using existing linear algebra libraries.
[0078] S32. Constructing a continuous physical state vector and side-channel quantization mapping. The main control chip combines the covariance matrix eigenvalues, response delay features, and decay time constant features to generate a continuous physical state vector. In the specific feature combination process, the main control chip uses the extracted principal coupling eigenvalues and secondary coupling eigenvalues as covariance matrix eigenvalues, and sequentially concatenates them with the response delay features and decay time constant features extracted in step S20 to complete the construction of a four-dimensional continuous physical state vector. The continuous physical state vector contains the energy distribution and time-domain recovery properties of the controlled physical flux disturbance.
[0079] To suppress noise and block side-channel derivation using computational residuals, the main control chip uses a preset tolerance step size vector (composed of four independent step size constants corresponding to the dimensions of each dimension) to perform discrete alignment quantization on the continuous physical state vector and output a discrete state code vector.
[0080] To obtain the threshold reference for the tolerance step size setting, the control gateway drives the thin film gauge and leak detector to execute the no-load background measurement program during the device initialization phase. It calculates the hardware timer resolution and the effective value and distribution variance of the noise floor of the stable vacuum environment sensing data. Based on this, the above four independent step size constants are set to ensure that the quantization grid is slightly larger than the background noise limit.
[0081] In terms of specific parameter configuration, the step size constant corresponding to the response delay feature is set to a range of 0.1ms to 1.0ms, the step size constant corresponding to the decay time constant feature is set to a range of 0.5ms to 5.0ms, and the step size constant corresponding to the covariance matrix eigenvalues is set to a range of 1.5 to 3.0 times the standard deviation of the current covariance background noise. The specific mapping quantization calculation uses the following formula: ; in, Represents a discrete state code vector; Represents a continuous physical state vector; This represents the preset tolerance step size vector; Indicates the element-wise division operation of a vector; Indicates the alignment operation to the nearest integer; This represents the quotient vector obtained by dividing each element in the continuous physical state vector by the corresponding step size constant in the preset tolerance step size vector. This represents an alignment quantization operation that performs rounding on each quotient in the quotient vector to discard the floating-point residuals generated by the division operation.
[0082] The main control chip discards the floating-point residuals of physical measurements introduced by the hardware background noise through rounding operations, obtains the discrete status code vector and stores it in memory for subsequent calculations, thereby reducing the possibility that external probes will use tiny numerical fluctuations to inversely deduce the internal decision logic of the control gateway.
[0083] S33. Hardware Trust Root Extraction and Service Message Hash Digest Generation. The secure element is configured as an independent and protected execution environment within the edge node. The secure element extracts the underlying firmware metric hash value from the read-only storage area within the secure element. The underlying firmware metric hash value is solidified during the edge node's manufacturing or firmware upgrade phase and is used to characterize the integrity and legitimate identity of the currently running code on the edge node.
[0084] Simultaneously, the main control chip extracts the actual leak detection service message temporarily stored in the first-in-first-out double-buffered register and executes a secure hash algorithm to calculate the hash digest of the actual leak detection service message. Existing domestic SM3 or SHA-256 and other well-known cryptographic standards can be used to construct the secure hash algorithm. After the hash digest is generated, changes to core data content such as workpiece identifiers, process recipe indexes, or test request parameters contained in the actual leak detection service message will cause the hash digest value to change.
[0085] S34. Cross-dimensional multi-source data concatenation and authentication token generation. After preparing all verification factors, the secure element performs hardware-level data binding. The secure element extracts the underlying firmware metric hash value, concatenates the discrete status code vector, encrypted random number, instruction identifier, and hash digest of the actual leak detection service message, and generates an authentication token through the message authentication code algorithm. In the specific generation mechanism of the authentication token, the secure element calls the edge-side symmetric authentication key stored in the secure isolation zone of the secure element, and performs ciphertext generation calculation based on the message authentication code algorithm.
[0086] The message authentication code can be calculated directly using existing well-known architectures such as HMAC-SHA256 or HMAC-SM3. The specific logic for generating the authentication token uses the following formula: ; in, Indicates an authentication token; This represents the identifier of the hash-based message authentication code operation function; Indicates the edge-side symmetric authentication key; Represents an encrypted random number; Indicates the instruction identifier; Indicates the sampling time window identifier; Represents a discrete state code vector; A hash digest representing the actual leak detection message; This represents the underlying firmware metric hash value; Indicates a data segment concatenation operation identifier; This represents a combined data sequence generated by sequentially concatenating encrypted random numbers, instruction identifiers, sampling time window identifiers, discrete status code vectors, hash digests of actual leak detection service messages, and underlying firmware metric hash values.
[0087] The secure element outputs the completed authentication token. The edge node outputs the authentication token, sampling time window identifier, and genuine leak detection service message to the control gateway. In the specific data transmission mechanism, the edge node packages the authentication token, sampling time window identifier, instruction identifier, and genuine leak detection service message into an uplink communication frame and transmits it back via the industrial communication bus. By performing bit-segment concatenation and ciphertext calculation, the genuine leak detection service message establishes a data association at the cryptographic level with specific temporal physical perturbation events, environmental response parameters, and hardware device identity to increase the difficulty of forging transmitted data.
[0088] See attached document Figure 5 In the multi-parameter collaborative control method for vacuum leak detection provided by this invention, step S40, which involves deriving the physical baseline model of the equipment and performing multi-candidate tolerance authentication, includes the following sub-steps: S41. Physical Baseline Model Derivation and Calculation. The control gateway inputs its own dynamic valve control sequence, steady-state absolute pressure, and steady-state temperature into the locally running physical baseline model. The physical baseline model uses an equivalent fluid resistance-capacitance network algorithm to simulate the gas dynamic response characteristics of the pipeline system under corresponding boundary conditions, and calculates and outputs the expected theoretical continuous response vector. The specific physical baseline model derivation logic adopts the following formula: ; in, This represents the expected theoretical continuous response vector; Indicates the identifier of the physical baseline model derivation function; Indicates a dynamic valve control sequence; Represents steady-state absolute pressure; Indicates steady-state temperature; Knudsen number is a gas property parameter that represents the ratio of the mean free path of the gas molecules being tested to the characteristic size of the pipeline. It is used to determine whether the system is in a viscous flow, transitional flow, or molecular flow state. This refers to the set of device parameters that are pre-calibrated and stored in the local security configuration database of the control gateway during the device initialization phase. The set of device parameters includes at least one of the following: characteristic inner diameter of the piping system, pipe length, equivalent volume of the cavity, proportional valve conductivity, equivalent pumping speed of the vacuum pump, installation position of the diaphragm gauge, inlet position of the leak detector, and sensor response bandwidth.
[0089] In the specific physical baseline model derivation calculations, the equivalent fluid resistance-capacitance network algorithm maps the geometric structure and physical fluid properties of the pipeline system into an electrical equivalent model. Specifically, the equivalent fluid resistance-capacitance network algorithm equates the flow resistance of the airflow to a resistance parameter, the gas volume of the vacuum cavity to a capacitance parameter, the absolute pressure in the pipeline to a voltage variable, and the mass flow rate of the gas to a current variable. Through the equivalent mapping of the physical domain, the control gateway uses the existing circuit network numerical simulation calculation framework to analyze the propagation process of controlled physical flux disturbances in the pipeline system. The establishment of its partial differential equation system and the numerical discretization solution process are well-known techniques in this field and will not be elaborated here.
[0090] Expected theoretical continuous response vector It includes the expected covariance matrix eigenvalues, expected response delay characteristics, and expected decay time constant characteristics derived from the model derivation.
[0091] S42. Tolerance Expansion of Discrete-State Expected Candidate Set. The control gateway combines the tolerance step size vector and a preset neighborhood offset to expand the expected theoretical continuous response vector to generate a discrete-state expected candidate set. The tolerance step size vector is pre-calibrated based on the inherent resolution of the sensors configured in the pipeline system and the amplitude of the system environment's floor noise, used to smooth the measurement error of analog signals. Due to electromagnetic interference in the industrial environment and the inherent thermal noise of the sensors, signal fluctuations may occur, and the actual measured value of the continuous response may jump to adjacent integer intervals during quantization. To cover the quantization jump range, the control gateway constructs a multi-dimensional preset neighborhood offset combination space and performs the generation of the discrete-state expected candidate set. The specific generation logic adopts the following formula: ; in, Represents the expected candidate set of discrete states; This represents the expected theoretical continuous response vector; This represents the preset tolerance step size vector; Indicates the element-wise division operation of a vector; Indicates the alignment operation to the nearest integer; Represents the neighborhood offset vector; This represents a preset neighborhood offset combination space; This indicates a set generation operation identifier that meets the set conditions; This means dividing each element in the expected theoretical continuous response vector by the corresponding step size constant in the tolerance step size vector to obtain the quotient vector; This represents the benchmark discrete vector obtained by benchmark quantization of the expected theoretical continuous response vector according to the tolerance step size vector; This represents the extended status code vector obtained by adding the baseline discrete vector to the neighborhood offset vector.
[0092] For the expected theoretical continuous response vector in four dimensions, the control gateway limits the single-point offset values of each dimension to three integers: -1, 0, and 1. This allows for the construction of a preset neighborhood offset combination space containing 81 elements through independent permutations. Limiting the single-point offset values to -1, 0, and 1 allows for the coverage of single-step quantization transitions with relatively low computational overhead. The control gateway calculates and outputs a discrete state expectation candidate set containing multiple extended state code vectors.
[0093] S43. Parallel Derivation of Multiple Candidate Hash Tokens. The control gateway receives an uplink communication frame containing an authentication token and a genuine leak detection service message. It uses an independently configured secure hash algorithm to perform local hash calculations on the received genuine leak detection service message to generate a local verification hash digest. Simultaneously, it extracts the underlying firmware baseline metric hash value stored in the local security configuration database. The underlying hash operation mechanism is a well-known technology in the field and will not be elaborated upon here.
[0094] The control gateway generates a desired hash token candidate set through parallel deduction of each extended state code vector contained within the discrete state expectation candidate set. The specific hash token candidate set deduction logic adopts the following formula: ; in, The expected hash token candidate set number is The expected hash token; This represents the identifier of the hash-based message authentication code operation function; This indicates the symmetric authentication key configured in the local security storage area of the control gateway. The symmetric authentication key is pre-configured to be the same key as the edge-side symmetric authentication key used on the edge node side, or it is generated from the same root key through a key derivation function. Represents an encrypted random number; Indicates the instruction identifier; Indicates the sampling time window identifier; The index number in the discrete state expectation candidate set is The extended status code vector; Represents the local check hash digest; This represents the underlying firmware baseline metric hash value; Indicates a data segment concatenation operation identifier; This indicates that the encrypted random number, instruction identifier, sampling time window identifier, and sequence number will be used. The extended status code vector, the local check hash digest, and the underlying firmware benchmark metric hash value are sequentially concatenated to generate a local combined data sequence. This represents the fixed-length ciphertext output obtained by calculating the message authentication code using a symmetric authentication key on a locally combined data sequence.
[0095] The control gateway traverses all extended state code vectors in the discrete state expectation candidate set and generates an expected hash token candidate set containing multiple expected hash tokens.
[0096] S44. Multi-candidate authentication token matching and authentication with anti-side-channel comparison. The control gateway determines whether the received authentication token belongs to the expected hash token candidate set and outputs the authentication result accordingly. The specific comparison method is as follows: the control gateway treats the authentication token returned by the edge node as a complete data block, configures the hardware logic comparator to perform a bit comparison operation with each expected hash token in the expected hash token candidate set one by one for a fixed clock cycle.
[0097] The specific logic for preventing side-channel matching is as follows: The control gateway uses an XOR logic unit and introduces an internal accumulation variable. It performs a bitwise XOR operation on each data bit of the authentication token and the expected hash token, and accumulates the result of the bitwise XOR operation into the accumulation variable. Before completing the traversal of all data bits, even if the accumulation variable is already non-zero (i.e., a mismatch has been found), the control gateway continues to run the comparison loop without performing an early termination operation. After traversing all data bits, the control gateway outputs the comparison result by checking if the accumulation variable is zero. This ensures that the number of processor instruction cycles consumed by a single matching operation remains constant regardless of whether the match is successful or not, thereby blocking the side-channel timing eavesdropping path implemented by external detection devices based on the comparison time difference and enhancing the security of the authentication process.
[0098] If all data bits of the authentication token match any expected hash token in the expected hash token candidate set, the control gateway determines that the spatiotemporal propagation response of the controlled physical flux disturbance matches the device physical baseline model, and that the uplink communication frame maintains data integrity during transmission, and outputs an authentication result indicating successful authentication.
[0099] If no matching item is found after traversing all elements in the expected hash token candidate set, the control gateway determines that the pipeline system's operating environment has unknown physical characteristics drift, the edge node has been subjected to analog signal injection attack, or the uplink communication frame has been tampered with, and outputs an authentication failure result.
[0100] In the multi-parameter collaborative control method for vacuum leak detection provided by this invention, step S50, performing cross-domain collaborative control and physical domain failure safety isolation, includes the following sub-steps: S51. Authentication passes through a multi-system manufacturing flow and constant test pressure closed-loop control. Based on the authentication result, when the authentication token exists in the expected hash token candidate set, the control gateway transmits the actual leak detection service message to the manufacturing execution system. The manufacturing execution system returns the corresponding production response instruction based on the workpiece identifier and process recipe index in the actual leak detection service message. At the same time, it parses the production response instruction to extract the corresponding process recipe, and then issues the subsequent test instruction sequence to the edge node based on the process recipe.
[0101] The edge node analyzes the process formula to extract the set target pressure value, which represents the constant test vacuum boundary required for standard leak rate analysis. The edge node adjusts the proportional valve according to the subsequent test command sequence to maintain the test pressure of the pipeline system constant and match the set target pressure value.
[0102] In the specific closed-loop control process of constant test pressure, the edge node uses a logic array to read the transient absolute pressure signal fed back by the diaphragm gauge. Combined with the set target pressure value, and based on well-known closed-loop control specifications in the field, a proportional-integral-derivative (PID) algorithm is used to output an adjustment signal to the control terminal of the proportional valve through the drive output port configured on the edge node, thereby dynamically fine-tuning the cross-sectional area of the proportional valve's airflow channel. Under the baseline flow condition of maintaining constant test pressure, the control gateway sends a measurement trigger command to the leak detector, controlling the leak detector to perform a leak rate measurement operation to obtain the final leak rate data. This final leak rate data is then associated with the workpiece identifier, authentication token, and sampling time window identifier before being uploaded to the manufacturing execution system, completing the current leak detection cycle.
[0103] S52. Digital Domain Session Impersonation and Virtual Decoy Sandbox Redirection Analysis on the Authentication Failure Side. Conversely, when the authentication token fails to match, the control gateway maintains the existing industrial communication session state in the digital domain; when the underlying communication protocol uses Transmission Control Protocol and Internet Protocol, the control gateway maintains the corresponding TCP / IP network session state to implement digital session impersonation, avoids triggering the escape mechanism of external probe programs, and simultaneously redirects subsequent control messages from edge nodes to the virtual decoy sandbox environment for behavioral analysis and network traffic isolation recording.
[0104] The virtual decoy sandbox environment simulates the response characteristics of real vulnerability detection services and performs interactive tests on subsequent control messages after redirection. Potential network attack signatures are extracted by parsing the instruction structure of abnormal data frames. For the network request mirroring and abnormal behavior pattern feature matching mechanism of the virtual decoy sandbox environment, existing network honeypot technology can be deployed. Its sandbox isolation and behavior capture logic are well-known technologies in the field and will not be elaborated upon here.
[0105] S53. Physical domain collaborative isolation control based on out-of-band triggering and multi-parameter dynamic matching. Synchronously, the control gateway sends an abnormal status signal to the safety controller through a hard-wired safety output interface. After receiving the abnormal status signal, the safety controller initiates multi-parameter collaborative isolation control. While cutting off the power supply to the sustaining power circuit coil of the test valve to force it to reset to the normally closed state using a mechanical spring according to the fail-safe principle, it outputs an opening signal to the action control coil of the exhaust valve, forcibly redirecting the potential abnormal airflow to the exhaust gas discharge channel of the pipeline system and discharging it into the exhaust gas main pipe. It also uses a hard-wired limiting control terminal to bring the proportional valve to a preset safe opening degree or limit the rate of change of the proportional valve's opening.
[0106] The preset safe opening degree is calculated and set based on the ratio of the rated safe exhaust flow rate of the vacuum pump connected to the system to the maximum conductivity of the pipeline. Its engineering value range is typically set to 10% to 20% of the full-range opening of the proportional valve. For the hardware limitation of the opening change rate, the safety controller forcibly lengthens the charging and discharging time constant of the valve drive motor by cutting off the high-speed power supply branch of the proportional valve driver and inserting a fixed damping resistor in series. This limits the valve opening and closing rate in a hardware fail-safe manner without software intervention. The control gateway only issues the auxiliary exhaust flow rate limit command when the edge node is still under control; this auxiliary exhaust flow rate limit command is not the sole condition for physical domain fail-safe isolation.
[0107] During the dynamic adjustment process of multi-parameter collaborative isolation, the control gateway synchronously acquires the physical state data of the pipeline system output by the thin-film gauge sensor through the logic array inside the edge node, and synchronously acquires the physical state data of the leak detector input by the electrometer interface through the analog signal acquisition channel of the logic array. The control gateway calculates the pressure drop slope and the background ion current change rate based on the physical state data. By calculating the first derivative of the physical quantities, the transient change trend of the physical quantities is obtained, enabling proactive control and suppression before the physical parameters deviate from the safe range. The specific multi-parameter dynamic matching calculation uses the following formula: ; ; in, This represents the pressure drop slope. Since physical isolation actions often cause a sharp drop in internal pipeline pressure or a sudden rise due to backflow of air, this slope may be negative or positive. In subsequent safety control logic, its absolute value is used to characterize the severity of the pressure change. This represents the time series corresponding to the transient absolute pressure signal; Represents a time variable; This represents the differential term of the time series corresponding to the transient absolute pressure signal; The differential term representing the time variable; This represents the instantaneous derivative function of the pressure signal obtained by differentiating the time series corresponding to the transient absolute pressure signal with respect to the time variable; This represents the rate of change of the background ion current. Similarly, in the control logic, the absolute value is used to characterize the severity of the ion current fluctuation. This represents the time series corresponding to the transient ion current signal; This represents the differential term of the time series corresponding to the transient ion current signal; This represents the instantaneous derivative function of the ion current signal obtained by differentiating the time series corresponding to the transient ion current signal with respect to the time variable.
[0108] The control gateway compares the absolute value of the calculated pressure drop slope with the absolute value of the preset pressure drop safety threshold, and also compares the absolute value of the background ion current change rate with the absolute value of the preset ion current fluctuation safety threshold. The preset pressure drop safety threshold is obtained through kinetic calibration based on the maximum pressure release rate of the pipeline system. To ensure consistent comparison logic, the preset pressure drop safety threshold is defined as a positive transient amplitude limit, with an engineering setting range limited to 100 Pa / s to 500 Pa / s. The preset ion current fluctuation safety threshold is obtained through hardware calibration based on the impact protection limit of the electrometer interface, and is also defined as a positive transient amplitude limit, with an engineering setting range limited to... to .
[0109] When the absolute value of the pressure drop slope is greater than or equal to 80% of the preset pressure drop safety threshold, or the absolute value of the background ion current change rate is greater than or equal to 80% of the preset ion flow fluctuation safety threshold, the control gateway sends an exhaust flow limit command to the safety controller through a hard-wired safety output interface independent of the industrial communication bus. The safety controller's hard-wired limiting control terminal outputs a suppression signal to the proportional valve's safety limiting input terminal to dynamically reduce the proportional valve's opening change step size, thereby limiting the exhaust flow. This ensures that the physical parameters of the pipeline system and the leak detector remain within a safe range during the isolation process, preventing damage to sensitive sensing components such as the electrometer interface from sudden valve switching caused by airflow shock waves. After multi-parameter collaborative isolation control is completed, the pipeline system and test valve maintain a system lockout state until the safety controller receives a manual reset command from the field, at which point the system lockout state is released and normal control is restored.
[0110] See attached document Figure 6 To be continued Figure 9To further illustrate the specific implementation of this invention, a specific application example is given, using a helium mass spectrometry vacuum leak detection operation scenario for spacecraft fuel tanks. In this application scenario, the tested volume is large, the pipeline is long, and it is susceptible to external electromagnetic interference or malicious network injection attacks. This example will demonstrate in detail how the system implements security control and failure isolation through multi-parameter collaboration and cryptographic binding mechanisms.
[0111] In the hardware configuration of this embodiment, the edge node's built-in main control chip is a 32-bit RISC microprocessor with an independent direct memory access controller. The security element is an independent encryption chip with a built-in hardware cryptographic coprocessor, supporting the national standard SM3 hash algorithm and hash-based message authentication code operations, and featuring tamper-proof isolated storage. The peripheral interaction interface uses a serial peripheral interface supporting direct memory access, internally configured with a 256-byte deep FIFO double-buffered register. The temperature sensor is a thin-film platinum resistance temperature detector, mounted close to the outer wall of the pipeline. For the equivalent fluid resistance-capacitance network algorithm, the control gateway uses a system of difference equations simplified from the one-dimensional compressible fluid Navier-Stokes equations using the lumped parameter method to achieve numerical solution.
[0112] Edge nodes send collaborative control access requests to the control gateway via an Ethernet-based industrial communication bus. The control gateway uses an internal hardware random number generator based on a ring oscillator array to generate a 128-bit encrypted random number and a corresponding 16-bit instruction identifier. The control gateway receives the steady-state absolute pressure and steady-state temperature uploaded by the edge nodes, measuring the steady-state absolute pressure in the spacecraft's fuel tank and piping system to be 0.005 Pa and the steady-state temperature measured by the patch on the outer wall of the piping to be 293 K.
[0113] The characteristic geometric inner diameter of the piping system is specified as 0.04 m. The test medium is helium, and the effective diameter of helium molecules is set to [missing value]. Given that the Boltzmann constant is Control gateway input and The formula was used to calculate that the mean free path of the gas molecules was approximately 2.69 m, and the Knudsen number was then calculated to be approximately 67.25.
[0114] Since the calculated Knudsen number is much greater than the preset molecular flow lower limit threshold of 0.3, the control gateway determines that the current gas flow state is completely within the molecular flow range. The control gateway selects 0.1 as the amplitude constraint coefficient according to preset rules. The control gateway divides the 128-bit encrypted random number into 8-bit segments, converts it into 16 basic opening change values, and multiplies them by the amplitude constraint coefficient 0.1 to generate a dynamic valve control sequence containing 16 discrete quantization steps. This sequence is sent to the edge node along with the downlink data packet. The edge node uses its internal 12-bit digital-to-analog converter chip to convert the dynamic valve control sequence into a voltage analog quantity with minute fluctuations in the 0 to 5V range. This drives the piezoelectric ceramic actuator inside the proportional valve to deform, superimposing a micrometer-level displacement on top of a constant opening, thereby exciting a controlled physical flux disturbance corresponding to the encrypted random number within the leak detection pipeline.
[0115] To capture the aforementioned perturbations, the logic array of the edge nodes (using a field-programmable gate array) triggers dual-rate collaborative data acquisition. The logic array configures the hardware timer sampling frequency of the high-frequency transient channel to 50kHz. The transient absolute pressure signal is input to the analog-to-digital converter via a thin-film gauge conditioning circuit, while the transient ion current signal is directly extracted from the electrostatic meter interface inside the leak detector. To preserve the high-frequency perturbation components, a second-order Butterworth passive low-pass filter is deployed at the front end of the analog signal acquisition channel as an anti-aliasing filter circuit, with its cutoff frequency set to 20kHz. This avoids sampling frequency aliasing while preventing the conventional low-pass filter circuit inside the leak detector's mainboard from erasing the true high-frequency perturbation characteristics.
[0116] The logic array synchronously acquires 2000 sampling points from dual channels, with a total time window of 40ms. After acquiring the data, the logic array calculates the arithmetic mean of the two sets of data and performs mean-reduction processing to obtain the zero-baseline pressure data series and the zero-baseline ion current data series. Simultaneously, the main control chip, in a low-priority thread, non-blockingly extracts the current workpiece identifier, process formula index, and other real leak detection service messages from the double-buffered register of the serial peripheral interface through the direct memory access channel.
[0117] As attached Figure 6 The figure shows the two-parameter transient response curves under controlled physical flux perturbation, with the sampling time window (ms) on the horizontal axis and the dimensionless signal amplitude on the vertical axis. The solid line represents the zero-baseline absolute pressure response, and the dashed line represents the zero-baseline ion current response. Because the control gateway applies a small opening perturbation with a low amplitude constraint coefficient after determining the molecular flow range, the physical flux perturbation is strictly controlled within a very small range. The pressure exhibits a rapid rise followed by oscillating decay, while the ion flow curve shows a significant peak misalignment hysteresis and a gentle exponential downward decline. This response pattern provides the original high-frequency physical basis for subsequent feature extraction.
[0118] The logic array utilizes its internal digital signal processing multiply-accumulate module to perform discrete cross-correlation calculations on the zero-baseline pressure data series and the zero-baseline ion current data series. After traversing the calculations and outputting the complete sequence of cross-correlation functions, the logic array identifies the global maximum peak value of the cross-correlation function. (See attached...) Figure 7 The discrete cross-correlation calculation extracted the response delay feature map shown. The map uses discrete lag time (ms) as the horizontal axis and cross-correlation function values as the vertical axis. The cross-correlation sequence is obtained by calling the internal hardware multiplier-accumulator core to perform accumulation, clearly indicating the response delay corresponding to the maximum peak: 12.5ms. This value physically characterizes the time difference in the propagation of the concentration wave from the thin-film gauge to the leak detector analysis chamber caused by the thermal motion and collision diffusion of helium molecules with the tube wall.
[0119] After obtaining the delay characteristics, the logic array extracts the attenuation segment of the current waveform, subtracts the steady-state base current, and adds a preset positive lower limit. Perform a natural logarithmic transformation. Then, use the least squares method to convert the logarithmic data into a first-order linear equation and perform a linear regression to calculate the slope. (See attached diagram.) Figure 8 The graph shown is a first-order linear fit plot of the logarithmic decay segment data. The plot is plotted with the time base difference (ms) on the horizontal axis and the logarithmic amplitude on the horizontal axis. The graph, with the vertical axis as the scatter plot, shows the effective fitted points and the calculated linear regression line. Taking the reciprocal of the absolute value of the slope, the decay time constant is determined to be 45.2 ms. This value physically characterizes the dynamic exhaust recovery constant of the test volume under the current vacuum capacity.
[0120] Subsequently, the main control chip performs full-scale calibration normalization on the zero-baseline pressure data series and the zero-baseline ion current data series, and calculates the covariance matrix of the dimensionless pressure data series and the dimensionless ion current data series, thereby constructing a 2x2 dimension covariance matrix. The Jacobi iteration method is used to perform eigenvalue decomposition on the covariance matrix to extract eigenvalues, extracting the principal coupling eigenvalue (0.82) and the secondary coupling eigenvalue (0.15). The main control chip sequentially combines the principal coupling eigenvalue, the secondary coupling eigenvalue, the response delay feature, and the decay time constant feature to generate a four-dimensional continuous physical state vector [0.82, 0.15, 12.5, 45.2].
[0121] During device initialization, the control gateway pre-stores tolerance step size vectors corresponding to four dimensions, set to [0.05, 0.05, 0.5, 1.0]. The main control chip divides each element of the continuous physical state vector by its corresponding step size constant and quantizes it to the nearest integer, generating a discrete state code vector [16, 3, 25, 45]. The security element extracts the underlying firmware metric hash value and concatenates it bit-by-bit with the encrypted random number, instruction identifier, discrete state code vector, and hash digest of the actual leak detection service message. Subsequently, the security element calls the edge-side symmetric authentication key stored in the internal isolation zone, uses the HMAC-SM3 algorithm to process the concatenated data, outputs a 256-bit authentication token, and transmits it back to the control gateway via the industrial communication bus.
[0122] Based on the issued dynamic valve control sequence and the measured steady-state absolute pressure and steady-state temperature, the control gateway substitutes the preset set of equipment parameters such as pipeline inner diameter, length, and pumping speed into the equivalent fluid resistance-capacitance network equations for differential solution, deriving the expected theoretical continuous response vector [0.80, 0.14, 12.3, 44.8]. Combined with the same tolerance step size vector, the baseline quantization value is [16, 3, 25, 45]. The control gateway sets the neighborhood offset values for each dimension to {-1, 0, 1}, generating a discrete state expectation candidate set containing 81 extended state code vectors. For each extended state code vector, the control gateway performs HMAC-SM3 calculations in parallel to generate an expected hash token candidate set containing 81 expected hash tokens.
[0123] The control gateway performs a fixed-clock-cycle bit comparison operation on each of the expected hash tokens in the candidate set of expected hash tokens, using the authentication token returned by the edge node. The internal hardware comparator performs a bitwise XOR operation using an XOR gate array and introduces an accumulation variable. Even if a mismatch occurs at some point, causing the accumulation variable to be non-zero, the comparator still completes all 256 clock cycles before outputting the result. After a full traversal, the control gateway finds that the returned authentication token is completely consistent with the expected hash token generated based on the quantized value [16,3,25,45], and the accumulation variable is ultimately determined to be 0. Based on this, the control gateway outputs an authentication result confirming that the data has not been tampered with and that the actual physical fluid field response around the edge node matches the model's expectations. Subsequently, the control gateway pushes the actual business message to the manufacturing execution system, issues a subsequent test command sequence to control the edge node to perform proportional-integral-differential operations, maintain the set vacuum level, and obtain the final leak rate data.
[0124] To further enhance the authenticity and persuasiveness of the present invention, a set of comparative experiments was designed. The system was deployed in operational conditions, incorporating both a conventional digital certificate authentication scheme (control group) and the multi-parameter collaborative control scheme of this invention (experimental group). Using professional testing equipment, replay messages with forged edge node identities were continuously injected into the industrial communication bus. These messages carried previously intercepted legitimate business credentials and waveforms of simulated pressure sensor data. During the experiment, because the injected messages carried legitimate signatures, the control group system determined them as legitimate sessions and continued execution. However, the virtual waveforms caused its control logic to issue an abnormally full-open command to the control valve, triggering the high-pressure protection of the leak detector, resulting in a sudden and drastic change in airflow within the pipeline.
[0125] Conversely, in the experimental scenario, although the control gateway received a valid uplink message in the digital domain, the discrete status code vector contained in the replayed message could not match the expected token corresponding to the random flux perturbation generated in the current environment within the tolerance extension set. Therefore, the control gateway immediately output an authentication failure result. While maintaining the underlying TCP session, the control gateway forwarded abnormal traffic to the virtual trap sandbox environment. Furthermore, it sent an abnormal status signal to the safety controller through a hardwired safety output interface. At this point, the absolute value of the calculated pressure drop slope reached 350 Pa / s, exceeding 80% of the preset pressure drop safety threshold absolute value of 300 Pa / s.
[0126] The safety controller immediately cuts off the power supply to the sustaining circuit coil of the test valve, forcibly locking it in place by spring force. It then outputs an opening signal to the exhaust valve's control coil, switching the exhaust gas discharge channel of the pipeline system to release residual gas. More importantly, by cutting off the high-speed power supply branch of the proportional valve driver and connecting a high-power damping resistor, the safety controller forcibly increases the circuit discharge constant of the proportional valve motor, smoothly extending the proportional valve's turn-off time from the rated 15ms to 150ms.
[0127] Experimental verification conclusions and analysis of innovative effects: Based on the above implementation steps and the attached data, a clear conclusion can be drawn: conventional security schemes relying solely on the information layer key system have blind spots in physical characteristics. Because they lack on-site physical verification, attackers can easily intercept credentials and subsequently simulate legitimate waveform data to deceive the communication gateway. (See attached...) Figure 9 The graph shows a comparison of isolation response pressures after a network waveform injection attack. The horizontal axis is the time (s) after the attack, and the vertical axis is the absolute pressure (Pa) in the pipeline. The physical shock response under the conventional authentication scheme shows that after the injection, the uncontrolled gas leakage inside the pipeline system causes destructive abrupt oscillations, and the instantaneous pressure exceeds the equipment's safe pressure limit marked in the graph.
[0128] This invention proposes to establish a physical challenge and response barrier based on the current specific time and specific fluid dynamic conditions by determining the flow regime interval, performing small flux perturbations and extracting multi-dimensional physical coupling states across parameters.
[0129] Appendix Figure 6 Recorded two-parameter curves and appendices Figure 7 and attached Figure 8 The presented feature extraction computation fully demonstrates the effectiveness of hardware-level signal sampling combined with discrete cross-correlation and quantization algorithms for capturing weak dynamic features. Because each request injects unpredictable dynamic perturbations, and the physical baseline model is deeply dependent on the current, unforgeable transient environmental temperature and resting pressure, any attacker lacking a field physical probe cannot calculate a signature that falls within the tolerance expectation range.
[0130] Furthermore, when the system is in an authentication failure state, unlike the conventional approach of immediately issuing a shutdown command on the communication bus, which may cause network congestion or command failure, this solution instead utilizes an out-of-band hard-wired mechanism to perform isolation. By forcibly binding the differential function operation with the hardware discharge characteristics of the security controller, the physical pressure relief process is smoothly transformed from a step-like strong oscillation to a state similar to the attached [example / parameter / etc.] while eliminating the root cause of the threat. Figure 9 The solid line illustrates that this invention, based on smooth discharge through multi-parameter collaborative isolation, eliminates the risk of airflow shock waves damaging the high-precision electrometer at the physical level. The closed-loop mechanism formed by multi-parameter synchronous verification and failure-safe physical isolation establishes the high resilience and durability of the vacuum leak detection process.
Claims
1. A multi-parameter coordinated control method for a vacuum leak detection process, characterized in that, Includes the following steps: An encrypted random number and instruction identifier are generated and mapped to a dynamic valve control sequence, which in turn drives the proportional valve to generate controlled physical flux disturbances in the pipeline system. The controlled physical flux disturbance is collected to form a pressure sampling data column and an ion current sampling data column. The real leak detection service message is obtained, and the response delay feature and decay time constant feature are extracted from it. Extract the covariance matrix feature values of the pressure sampling data column and the ion current sampling data column, combine them with the response delay feature and the decay time constant feature to quantize and generate a discrete status code vector, and fuse them with the encrypted random number, the instruction identifier and the hash digest of the real leak detection service message to generate an authentication token; The dynamic valve control sequence is input into the physical baseline model to expand and generate a discrete state expectation candidate set. Based on this, the expected hash token candidate set is deduced to determine whether the authentication token matches and the authentication result is output. When the authentication result is a successful match, the test pressure of the pipeline system is maintained according to the test instruction sequence to obtain the final leakage rate data. When the authentication result is a failed match, subsequent control messages are isolated, the power supply to the test valve is cut off, and the exhaust gas discharge channel is switched to limit the opening rate of the proportional valve.
2. The multi-parameter coordinated control method for vacuum leak detection process according to claim 1, characterized in that, The control gateway generates the encrypted random number and the instruction identifier, maps them to the dynamic valve control sequence, and sends them to the edge node, which then drives the proportional valve to operate according to the dynamic valve control sequence. The process by which the edge node acquires the controlled physical flux perturbation to form the pressure sampling data series and the ion current sampling data series specifically includes: The internal logic array is used to initiate dual-rate collaborative data acquisition. The logic array continuously acquires the transient absolute pressure signal output by the thin film gauge within a specified sampling time window to form the pressure sampling data column; The logic array synchronously acquires the transient ion current signal output from the electrometer interface of the leak detector through the analog signal acquisition channel to form the ion current sampling data column.
3. The multi-parameter coordinated control method for vacuum leak detection process according to claim 1, characterized in that, The process of mapping the encrypted random number and the instruction identifier to the dynamic valve control sequence includes: Obtain the current steady-state absolute pressure and steady-state temperature of the pipeline system, and calculate the molecular mean free path by combining the Boltzmann constant and the effective molecular diameter. Calculate the ratio of the molecular mean free path to the characteristic geometric inner diameter of the pipeline system to obtain the Knudsen number. When the Knudsen number is less than or equal to the upper limit threshold of viscous flow, the gas is determined to be in the viscous flow range; when the Knudsen number is greater than or equal to the lower limit threshold of molecular flow, the gas is determined to be in the molecular flow range; when the Knudsen number is between the upper limit threshold of viscous flow and the lower limit threshold of molecular flow, the gas is determined to be in the transition flow range. The amplitude constraint coefficient is assigned according to the determined gas flow state interval, and the amplitude constraint coefficient corresponding to the molecular flow interval is less than the amplitude constraint coefficient corresponding to the viscous flow interval. The binary bit segment of the encrypted random number is divided into basic opening change values according to a preset byte length, and the basic opening change values are multiplied by the amplitude constraint coefficient to generate the dynamic valve control sequence.
4. The multi-parameter coordinated control method for a vacuum leak detection process according to claim 1, characterized in that, The process of extracting the response delay feature and the decay time constant feature from the edge node specifically includes: Calculate the arithmetic mean of the pressure sampling data column and the ion current sampling data column, and subtract the corresponding arithmetic mean from the pressure sampling data column and the ion current sampling data column respectively to obtain the zero baseline pressure data column and the zero baseline ion current data column; Perform discrete cross-correlation operation between the zero baseline pressure data series and the zero baseline ion current data series to obtain a cross-correlation function sequence, and find the global maximum peak value in the cross-correlation function sequence; When the global maximum peak value is greater than the effective peak value threshold, the discrete lag count corresponding to the global maximum peak value is extracted, and the discrete lag count corresponding to the global maximum peak value is multiplied by the hardware sampling period of the high-frequency transient channel to obtain the response delay feature. Extract the decay segment data from the zero baseline ion current data column after the response delay feature, and subtract the steady-state base current from the decay segment data to obtain data points whose absolute difference is greater than the preset noise lower limit as valid fitting points; Perform a natural logarithmic transformation on the absolute value of the difference between the effective fitted points or the difference after adding a positive lower limit to transform the nonlinear exponential decay model into a first-order linear equation. Perform a linear regression calculation on the first-order linear equation to obtain the slope, and take the reciprocal of the absolute value of the slope to obtain the decay time constant feature.
5. The multi-parameter coordinated control method for a vacuum leak detection process according to claim 1, characterized in that, The process of generating discrete state code vectors through edge node quantization specifically includes: The pressure sampling data column and the ion current sampling data column are normalized to obtain a dimensionless pressure data column and a dimensionless ion current data column. Calculate the covariance matrix of the dimensionless pressure data column and the dimensionless ion current data column, and perform eigenvalue decomposition to extract the eigenvalues of the covariance matrix; The covariance matrix eigenvalues, response delay features, and decay time constant features are sequentially concatenated and combined to construct a four-dimensional continuous physical state vector; Divide each element in the continuous physical state vector by the corresponding step size constant in the preset tolerance step size vector to obtain the quotient vector. Perform rounding operation on each quotient in the quotient vector to discard the floating-point residual and output the discrete state code vector.
6. The multi-parameter coordinated control method for a vacuum leak detection process according to claim 1, characterized in that, The process of edge node fusion to generate authentication tokens specifically includes: Extract the actual leak detection service message temporarily stored in the first-in-first-out double buffer register, and execute the secure hash algorithm to calculate the corresponding hash digest, and extract the underlying firmware metric hash value; The encrypted random number, the instruction identifier, the sampling time window identifier, the discrete status code vector, the hash digest of the real leak detection service message, and the underlying firmware metric hash value are sequentially concatenated to generate a combined data sequence; The edge-side symmetric authentication key stored in the secure isolation zone is invoked. The edge-side symmetric authentication key is used to calculate the message authentication code of the combined data sequence to obtain a fixed-length ciphertext output result as the authentication token. The edge node then transmits the authentication token and the real leak detection service message to the control gateway.
7. The multi-parameter coordinated control method for a vacuum leak detection process according to claim 1, characterized in that, The physical baseline model runs internally within the control gateway. The process by which the control gateway performs the expansion to generate the discrete state expectation candidate set specifically includes: The dynamic valve control sequence, the current steady-state absolute pressure and steady-state temperature of the pipeline system are input into the physical baseline model. The gas dynamic response characteristics of the pipeline system under the corresponding boundary conditions are simulated using the equivalent fluid resistance-capacitance network algorithm. The expected theoretical continuous response vector is calculated and output. The expected theoretical continuous response vector includes the expected covariance matrix eigenvalues, the expected response delay characteristics and the expected decay time constant characteristics. Divide each element in the expected theoretical continuous response vector by the corresponding step size constant in the preset tolerance step size vector to obtain the quotient vector, and perform a rounding operation on the quotient vector to obtain the benchmark discrete vector. The single-point offset values of each dimension are limited to -1, 0, and 1. A preset neighborhood offset combination space is constructed through full permutation and combination. The reference discrete vector is added to each neighborhood offset vector in the neighborhood offset combination space to obtain multiple extended state code vectors to form the discrete state expectation candidate set.
8. The multi-parameter coordinated control method for a vacuum leak detection process according to claim 7, characterized in that, The operation of determining whether the authentication token matches by the control gateway specifically includes: The received real leak detection service message is subjected to local hash calculation to generate a local verification hash digest, and the underlying firmware benchmark metric hash value stored in the local security configuration database is extracted. The encrypted random number, the instruction identifier, the sampling time window identifier, the extended status code vector, the local verification hash digest, and the underlying firmware baseline metric hash value are sequentially concatenated to generate a local combined data sequence. The message authentication code is calculated on the local combined data sequence using a symmetric verification key to obtain the expected hash token. All the extended status code vectors in the discrete state expected candidate set are traversed to generate the expected hash token candidate set containing multiple expected hash tokens. Using an XOR logic unit and introducing an accumulation variable, a bitwise XOR operation is performed on each data bit of the authentication token and the expected hash token, and the result of the bitwise XOR operation is accumulated into the accumulation variable. The comparison loop continues to run without performing an early termination operation until all data bits have been traversed. After traversing all data bits, determine whether the accumulated variable is zero. When the accumulated variable is zero, it is determined that there is a matching item with completely identical data bits. If the matching item exists in the expected hash token candidate set, the authentication result of successful matching is output.
9. The multi-parameter coordinated control method for a vacuum leak detection process according to claim 1, characterized in that, The test command sequence is issued by the control gateway to the edge node for execution. The control gateway performs the operation of isolating the subsequent control messages and sends instructions to the safety controller to cooperate in switching the exhaust gas discharge channel. Specifically, the process of limiting the opening rate of the proportional valve includes: The time series corresponding to the transient absolute pressure signal and the transient ion current signal are acquired synchronously, and the derivatives are calculated with respect to the time variable to obtain the instantaneous derivative function of the pressure signal as the pressure drop slope, and the instantaneous derivative function of the ion current signal as the background ion current change rate. When the absolute value of the pressure drop slope is greater than or equal to 80% of the absolute value of the preset pressure drop safety threshold, or when the absolute value of the background ion current change rate is greater than or equal to 80% of the absolute value of the preset ion flow fluctuation safety threshold, an exhaust flow limit command is sent to the safety controller through a hard-wired safety output interface independent of the industrial communication bus. The safety controller outputs a suppression signal to the safety limiting input of the proportional valve via a hard-wired limiting control terminal to dynamically reduce the opening change step size of the proportional valve.
10. A multi-parameter collaborative control system for a vacuum leak detection process, characterized in that, The method for multi-parameter coordinated control of a vacuum leak detection process as described in any one of claims 1-9 includes: The control gateway generates encrypted random numbers and instruction identifiers, maps them to dynamic valve control sequences, and sends them to the edge nodes. The edge node drives the proportional valve to generate controlled physical flux disturbances within the pipeline system based on the dynamic valve control sequence. The edge node collects signals from the thin film gauge and the leak detector to form a pressure sampling data column and an ion current sampling data column. It extracts response delay features and decay time constant features, and combines the response delay features and decay time constant features to quantize and generate a discrete status code vector. It also fuses the encrypted random number, the instruction identifier, and the hash digest of the externally input real leak detection service message to generate an authentication token, which is then transmitted to the control gateway. The control gateway runs a physical baseline model internally, expands the dynamic valve control sequence to generate a discrete state expectation candidate set, and infers the expected hash token candidate set to determine whether the authentication token matches, and outputs the authentication result. In response to the successful authentication result, the control gateway maintains the test pressure of the pipeline system according to the test instruction sequence; In response to the authentication result that failed to match, the control gateway isolates subsequent control messages and sends an instruction to the safety controller, which then performs operations such as cutting off the power supply to the sustaining power circuit coil of the test valve, switching the exhaust gas discharge channel of the pipeline system, and limiting the opening rate of the proportional valve.