Method and system for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets
The method and system for detecting tampering of real-world physical assets by validating fingerprints in digital twins address the challenge of maintaining trust and security in industrial environments, ensuring the integrity of both physical and digital assets.
Patent Information
- Application Number
- PCT/EP2023/080335
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-31
- Publication Date
- 2025-05-08
AI Technical Summary
Current systems lack the ability to accurately detect tampering of real-world physical assets in industrial environments, which can lead to unauthorized modifications and trust deficits in digital avatars within computer simulated environments.
A method and system that monitor digital twins corresponding to real-world physical assets by validating physics-based, electronic, and cryptographic fingerprints. This detection system alerts users and stakeholders of potential tampering, ensuring the integrity of both physical and digital assets.
The system effectively detects tampering of real-world physical assets, preventing unauthorized modifications and maintaining the trustworthiness of digital avatars in computer simulated environments, thereby enhancing the security and reliability of industrial operations.
Smart Images

Figure EP2023080335_08052025_PF_FP_ABST
Abstract
Description
[0001] METHOD AND SYSTEM FOR DETECTING MODIFICATION TO DIGITAL AVATARS IN A COMPUTER SIMULATED ENVIRONMENT BASED ON DETECTION OF TAMPERING OF REAL-WORLD PHYSICAL ASSETS
[0002] The present invention generally relates to computer simulated environments, and more specifically to a method and system for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets.
[0003] Industrial environments include plurality of machines or assets in an automated factory, or loT devices interacting with one another. Industrial environments thus often include multiple interconnected components in signal communication with each other, either directly or across a network. An emerging concept complementing the rapid industrial development is “the industrial metaverse”. The industrial metaverse is a next generation of fully immersive three- dimensional collaborative space that integrates multiple technical directions such as digital twin, internet of things, industrial internet, augmented reality, virtual reality, mixed reality, and the like. Metaverse is a virtual universe with shared, 3D virtual spaces where virtual assets can be owned, placed and interacted with. It also allows different users to interact with each other in the collaborative environment. These virtual assets can be simple entities like chair or table, or complex entities like industrial machinery.
[0004] For this purpose, a typical HoT (Industrial Internet of Things) solution in a metaverse would include building a digital of one or more assets in the industrial environment. In general, generating a digital twin (DT) involves collecting data from one or more data sources, modeling an asset (e.g., processing equipment) or a process to monitor or optimize the equipment or the process, and developing analytics to describe and predict equipment behavior or process behavior. A digital twin can, for example, represent a real-world power plant, a car, or an aircraft and replicates the features and parameters of the same. Furthermore, digital replicas of these digital twins can be rendered in the metaverse for a realistic and working representation of a real-world physical asset. The users in the metaverse can interact with the digital avatars to perform a variety of operations such as maintenance, asset custody and transfer, calibration, and so forth. Notably, these digital avatars are to be continuously in synchronization with the real-world data by updating the digital twins. However, this creates huge trust deficit in terms of identity and custody of the asset, for example the asset may have been replaced or tampered in an unauthorized manner. Currently, the sensors mounted on the assets form the only link between the virtual and real worlds opening a plethora of attack opportunities to tamper with the whole system while going undetected. A major challenge is that an asset maybe tampered with in the physical world and therefore data received in the digital twins and corresponding digital avatars is may also be modified by unauthorized sources. This may lead to rendering a different set of values or parameters in the metaverse that may affect the decision making of the users interacting in the metaverse. In turn this may lead to adverse outcomes in the industrial environment. Currently, there is no means of alerting the users in the metaverse that a corresponding real-world physical asset has been tampered with and actions should be taken accordingly. There is a need to accurately detect such attacks in the industrial environment first and then transmit the related information to the concerned stakeholders.
[0005] In the light of the above, there exists a need to provide a system and method for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets in order to build a trustworthy and secure computer simulated environment.
[0006] Therefore, the object of the invention is to provide a system and method for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets.
[0007] Throughout the present disclosure, the term “industrial environment” may refer to plurality of industrial assets connected with each other to achieve a function. The industrial environment may be comprised of industrial assets such as industrial machines, industrial devices, industrial controllers, and so forth. Example industrial environment may be a factory with a plurality of assets such as a power plant, wind farm, power grid, manufacturing facility, process plants and so on. Although the present disclosure has been described generally in terms of the industrial environment being some form of a factory floor, the term “industrial environment” as used in the preferred embodiments and claims according to the present disclosure should be understood broadly to include not only factory floors, but also other indoor facilities and buildings such as hospitals, office spaces, apartments, complexes, schools, training centers, and so forth. The term “industrial environment” may also include other outdoor facilities such as a parking lot, a traffic junction, and vehicles such as airplanes, ships and trucks.
[0008] Throughout the present disclosure, the term “one or more real-world physical assets” as used herein refers to any device, system, instrument, or machinery manufactured or used in an industry that may be employed for performing an operation. Example of assets include any machinery in an industrial environment or technical installation / facility such as motors, gears, bearings, shafts, switchgears, rotors, circuit breakers, protection devices, remote terminal units, transformers, reactors, disconnectors, gear- drive, gradient coils, magnets, radio frequency coils etc. The one or more assets may also include automated systems such as automated robots, semi- automated robots, remote-controlled robots, robotic arms, etc. that are employed in the industrial environment to perform an operation or task. Exemplary technical systems include turbines, large drives, Magnetic Resonance Imaging (MRI) scanner, etc. Example facility / technical installation may be a complex industrial set-up with a plurality of assets such as a power plant, wind farm, power grid, manufacturing facility, process plants and so on. These assets can further be classified as “simple assets” and “complex asset” and then pf the present invention, processed accordingly as per the embodiments.
[0009] Throughout the present disclosure, the term “computer simulated environment” as used herein refers to three-dimensional (3D) representation of a real or physical world. It can be understood as a virtual world. The computer-simulated environment is accessible by a user, i.e., it is accessible from the real / physical world. This comprises data exchange between the computer-simulated environment and the real / physical world. In particular, the computer-simulated environment can be understood as the “metaverse”. It is also possible to interact with the computer-simulated environment, i.e., to influence or use processes, components and / or functions in the computer-simulated environment. Therefore, processes in the computer-simulated environment may have direct influence on processes in the real / physical world, e.g., by modelling control processes virtually.
[0010] For example, it is possible that a user can access the computer-simulated environment via an interface, e.g., a virtual reality (VR) or augmented reality (AR) interface. The counterpart of the computer-simulated environment does not necessarily have to exist but can be for example a 3D model. It is also possible that physical forces and phenomena, e.g., gravity, are represented in a different way in the computer-simulated environment than in the real world, e.g., gravitational acceleration. For the purpose of this invention, the metaverse is comprised of one or more animated scenes being rendered corresponding to the plurality of entities interacting in the industrial environment.
[0011] The metaverse may comprise a plurality of computer-simulated components. The computer simulated components can for example be understood as a representation, in particular a 3D representation, of a real or physical component. A component can for example be a room, a building, an item, or an object. The computer-simulated component can have different functionalities / features, e.g., an access interface. The computer-simulated component further comprises data that are component-specific, e.g., sensor data of a virtual sensor, that can be retrieved for example via the access interface. An access to a computer-simulated component can for example comprise usage, modification, connection to other computer-simulated components, etc. The computer-simulated component can interact with the computer-simulated environment. For the purpose of this invention, the computer-simulated component may be one or more entities being rendered in the computer simulated collaborative environment or metaverse.
[0012] The metaverse can be realized by a hosting environment. The hosting environment can be for example be implemented as a cloud environment, an edge-cloud environment and / or on specific devices, e.g., mobile devices. Throughout the present disclosure, the term “digital twin” as used herein refers to digital model copy of a physical item (e.g., a real machine) is created that supports data access, command and control, remote configuration, as well as simulation and analytics. A DT is commonly created simultaneously with the real devices and systems, such as processing equipment and sensors in the facility. Once created by a specific vendor for their own specific equipment, the DT can be used to represent the machine in a digital representation of a real-world system. The DT is created such that it is identical in form and behavior of the corresponding machine. DTs may be supported by the vendors' own IIoT infrastructure. Thus, each DT is associated with one and only one asset. A customer deploying IIoT may thus end up having many such DTs deployed on a wide variety of infrastructures because IIoT vendors generally host their solutions on a variety of different cloud platforms (e.g. Microsoft AZURE, Amazon CLOUD, their own or third party data center), and may use a wide variety of open source and other components to create their digital twin solutions.
[0013] Throughout the present disclosure, the term “digital avatars” refers to digital model copy of the digital twins in the industrial environment. The digital avatars in an industrial metaverse scenario are graphical or 3D representations of real- world equipment, personnel, or automated systems, created to facilitate and enhance various industrial processes and activities within a virtual, interconnected, and immersive environment. In specificity, the digital avatars are the computer- generated representations of the digital twins of the physical assets in the industrial environment. The digital avatars can represent physical machinery, robots, and other industrial assets within a virtual factory or industrial environment. This allows for real-time monitoring, control, and simulation of these assets in the computer simulated environment. The digital avatars enable remote operation and control of machinery and equipment, allowing workers to manage and oversee industrial processes from anywhere with an internet connection, increasing efficiency and reducing physical presence requirements. The digital avatars can be used for training personnel in a safe, virtual environment. The digital avatars can visualize complex industrial data and analytics, providing a more intuitive and immersive way for users to understand and interact with large datasets, sensor readings, and performance metrics. The digital avatars can simulate hazardous scenarios, allowing users to assess risks and plan safety measures in advance, improving workplace safety. It should be noted that the digital avatars are a copy of the digital twins, therefore there could be multiple digital avatars rendered in the metaverse for a single digital twin. The object of the invention is achieved by a method for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets, wherein the one or more digital avatars correspond to the real-world physical assets in an industrial environment. The method comprises monitoring a digital twin corresponding to each of the digital avatars in the computer simulated environment by validating a physics-based fingerprint pertaining to the one or more real-world physical assets in the industrial environment; validating an electronic fingerprint pertaining to the one or more sensors associated with the real-world physical assets, arranged in the industrial environment; validating a first cryptographic fingerprint pertaining to a sensor security monitor configured for monitoring the one or more sensors; and validating a second cryptographic fingerprint pertaining to a sensor network gateway configured for providing sensor data to a network. The method comprises detecting tampering of the real-world physical assets based on the monitoring of the corresponding digital twins, when the validation of any one of the physics-based fingerprint, the electronic fingerprint, the first cryptographic fingerprint, or the second cryptographic fingerprint fails. The method comprises detecting, modification of the digital avatars based on detecting tampering of the corresponding real-world physical assets.
[0014] According to an embodiment, the method comprises generating visual alerts for one or more users interacting with the digital avatars in the computer simulated environment, wherein the visual alerts comprise information pertaining to tampering of the corresponding physical assets.
[0015] According to an embodiment, the method comprises generating one or more notifications to be transmitted to an owner of the one or more physical assets along with information pertaining to the tampering of the physical assets.
[0016] According to an embodiment, the physics-based fingerprint of the one or more assets in the industrial environment is derived from any one of physics-based model of the assets, statistical model of the assets, or a combination thereof, and wherein the physics-based fingerprint is a quantification of a feature vector, uniquely identifies an asset based on an operational behavior of the asset in the industrial environment.
[0017] According to an embodiment, the electronic fingerprint of the one or more sensors is a physically unclonable function that uniquely identifies a sensor in the industrial environment.
[0018] According to an embodiment, the first cryptographic fingerprint of the sensor security monitor is a one-way hash function of a unique cryptographic key registered for the sensor security monitor.
[0019] According to an embodiment, the second cryptographic fingerprint of the sensor network gateway is a one-way hash function of a unique cryptographic key registered for the sensor network gateway.
[0020] The object of the invention is also achieved by an apparatus for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets. The apparatus comprises one or more processing units, memory communicatively coupled to the one or more processing units. The memory comprises a module stored in the form of machine-readable instructions executable by the one or more processing units. The module is configured to perform the aforementioned method steps.
[0021] The object of the invention is also achieved by a system for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets, wherein the one or more digital avatars correspond to the real-world physical assets in an industrial environment. The system comprises one or more digital avatars interacting in a computer simulated environment. The one or more digital avatars correspond to one or more real-world physical assets in an industrial environment. The system comprises one or more digital twins communicatively coupled to the one or more digital avatars in the computer simulated environment. The one or more digital twins simulate a behavior of the corresponding one or more real-world assets. The system comprises an asset security monitor communicatively coupled to the one or more physical assets. The asset security monitor is configured for monitoring the one or more physical assets and generating physics-based fingerprints of the one or more physical assets. The system comprises a sensor security monitor communicatively coupled to the one or more sensors. The sensor security monitor is configured for monitoring the one or more sensors and generating an electronic fingerprint of the one or more sensors. The system comprises a master security monitor is configured for monitoring the sensor network gateway and the sensor security monitor. The master security monitor is configured for monitoring a first cryptographic fingerprint for the sensor network gateway and a second cryptographic fingerprint for the sensor security monitor. The system comprises an apparatus as aforementioned.
[0022] The object of the invention is also achieved by a computer program product comprising machine readable instructions, that when executed by one or more processing units, cause the one or more processing units to perform the aforementioned method steps.
[0023] The object of the present invention is further achieved by a computer readable medium on which program code sections of a computer program are saved, the program code sections being loadable into and / or executable in a system to make the system execute the method steps described above when the program code sections are executed in the system. This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the following description. It is not intended to identify features or essential features of the claimed subject matter. Furthermore, the claimed subject matter is not limited to implementations that solve any or all disadvantages noted in any part of this invention.
[0024] The present invention is further described hereinafter with reference to illustrated embodiments shown in the accompanying drawings, in which:
[0025] FIG 1 is a block diagram of a system for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets, according to an embodiment of the present invention! FIG 2 is a block diagram of an exemplary apparatus for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets, according to an embodiment of the present invention! and
[0026] FIG 3 is a flowchart depicting steps of a method for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets, according to an embodiment of the present invention.
[0027] Hereinafter, embodiments for carrying out the present invention are described in detail. The various embodiments are described with reference to the drawings, wherein like reference numerals are used to refer to like elements throughout. In the following description, for purpose of explanation, numerous specific details are set forth in order to provide a thorough understanding of one or more embodiments. It may be evident that such embodiments may be practiced without these specific details.
[0028] FIG 1 is a block diagram of a system 100 for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets, according to an embodiment of the present invention. The system 100 comprises a computer simulated environment 102 comprising one or more digital avatars 104-1 to 104-N interacting with one or more users in the computer simulated environment 102. The computer simulated environment 102 corresponds to an industrial environment 106. Specifically, the one or more digital avatars 104-1 to 104-N correspond to one or more real-world physical assets 108-1 to 108-N and associated sensors 110-1 to 110-N in the industrial environment 106. Furthermore, the system 100 comprises a digital twin simulation environment 112 comprising one or more digital twins 114-1 to 114-N. The digital twin simulation environment 112 is communicatively coupled to the industrial environment 106 for simulating the one or more digital twins 114-1 to 114-N. In turn, the digital twin simulation environment 112 is communicatively coupled to the computer simulated environment 102. The system 100 further comprises an asset security monitor 116 communicatively coupled to the one or more real-world physical assets 108'1 to 108-N. The system 100 further comprises a sensor security monitor 118 communicatively coupled to the one or more sensors 110'1 to 110'N. The system 100 further comprises a master security monitor 122 communicatively coupled to a sensor network gateway 120 and the sensor security monitor 118. Furthermore, the system 100 comprises an apparatus 110 communicatively coupled to the one or more digital twins 114'1 to 114-N, the asset security monitor 116, the sensor security monitor 118, and the sensor network gateway 120 over a communication network 124.
[0029] The computer simulated environment 102 is a three-dimensional (3D) representation of a real or physical world. It can be understood as a virtual world representing one or more assets 104-1 to 104-N of the real-world such as machines, robots, conveyors, cranes, drills, etc.
[0030] The computer-simulated environment 102 is accessible by a user, i.e., it is accessible from the real / physical world. In particular, the computer-simulated environment 102 can be understood as the “metaverse”. It is also possible to interact with the computer-simulated environment 102, i.e., to influence or use processes, components and / or functions in the computer-simulated environment 102. The user or the avatar may interact with the objects rendered in the metaverse.
[0031] For example, it is possible that a user can access the computer-simulated environment 102 via an interface, e.g., a virtual reality (VR) or augmented reality (AR) interface. For the purpose of this invention, the metaverse is comprised of one or more animated scenes being rendered corresponding to the plurality of entities interacting in the industrial environment. The metaverse may comprise a plurality of computer-simulated components. The computer simulated components can for example be understood as a representation, in particular a 3D representation, of a real or physical component. A component can for example be a room, a building, an item, or an object. The computer-simulated component can have different functionalities / features, e.g., an access interface. The metaverse can be realized by a hosting environment. The hosting environment can be for example be implemented as a cloud environment, an edge-cloud environment and / or on specific devices, e.g., mobile devices. The industrial environment 106 may be comprised of industrial assets such as industrial machines, industrial devices, industrial controllers, and so forth. Example industrial environment 106 may be a factory with a plurality of assets such as a power plant, wind farm, power grid, manufacturing facility, process plants and so on. The industrial environment 106 comprises several real-world physical assets. Example of assets include any machinery in an industrial environment or technical installation / facility such as motors, gears, bearings, shafts, switchgears, rotors, circuit breakers, protection devices, remote terminal units, transformers, reactors, disconnectors, gear-drive, gradient coils, magnets, radio frequency coils etc. The one or more assets may also include automated systems such as automated robots, semi- automated robots, remote-controlled robots, robotic arms, etc. that are employed in the industrial environment to perform an operation or task. Exemplary technical systems include turbines, large drives, Magnetic Resonance Imaging (MRI) scanner, etc. Example facility / technical installation may be a complex industrial set-up with a plurality of assets such as a power plant, wind farm, power grid, manufacturing facility, process plants and so on.
[0032] The industrial environment 106 further comprises one or more sensors 110'1 to 110-N arranged to provide data from the physical assets 108-1 to 108-N. The sensors 110'1 to 110-N are electronic devices or instruments that are used to detect, measure, monitor, and collect data about various physical and environmental parameters. These sensors 110'1 to 110-N play a crucial role in industrial processes by providing real-time information that helps control and optimize manufacturing, production, and other operations. Sensors 110'1 to 110- N capture data related to a wide range of physical parameters, including temperature, pressure, humidity, flow rate, voltage, current, position, vibration, gas concentration, and more. Non-limiting examples of sensors are temperature sensors, pressure sensors, level sensors, flow sensors, proximity sensors, positions sensors, position sensors, vibration sensors, gas sensors, humidity sensors, photoelectric sensors, smoke sensors, fire sensors, load cells, IR gas sensors, radar level sensors, acoustic sensors and so forth.
[0033] The data from the sensors 110'1 to 110-N is provided to other networks, simulation environment, apparatuses, processing units over a sensor network gateway. The sensor network gateway 120 is a key component in a sensor network architecture designed to enable efficient and secure data exchange between a network of sensors and external systems. The gateway 120 collects data generated by various sensor nodes within the network. The gateway 120 may perform data preprocessing tasks, such as filtering, aggregation, or data fusion, to reduce noise, improve data quality, and reduce the volume of data transmitted to higher-level systems. Sensor nodes in a network may use different communication protocols or data formats. The gateway translates data from various sensors into a standardized format or protocol to ensure interoperability with external systems. Gateways often include security measures to protect data integrity and confidentiality. They may encrypt data, authenticate sensor nodes, and implement access control mechanisms to prevent unauthorized access. Gateways establish and manage communication links between the sensor network and external systems. They can use wired or wireless communication technologies to transmit data to local servers, cloud platforms, or other data consumers. Furthermore, sensor network gateways 120 integrate with higher- level applications, platforms, or services, enabling users to access and analyze sensor data for various applications, including industrial automation, environmental monitoring, healthcare, and smart cities.
[0034] The data from the sensors 110-1 to 110-N may be provided to a simulation environment for generating a digital twin of the one or more physical assets or the industrial environment as a whole. The digital twins are a digital model copy of a physical item (e.g., a real machine) is created that supports data access, command and control, remote configuration, as well as simulation and analytics. A DT is commonly created simultaneously with the real devices and systems, such as processing equipment and sensors in the facility. Once created by a specific vendor for their own specific equipment, the DT can be used to represent the machine in a digital representation of a real-world system. The DT is created such that it is identical in form and behavior of the corresponding machine. DTs may be supported by the vendors' own IIoT infrastructure. Thus, each DT is associated with one and only one asset. A customer deploying IIoT may thus end up having many such DTs deployed on a wide variety of infrastructures because IIoT vendors generally host their solutions on a variety of different cloud platforms (e.g. Microsoft AZURE, Amazon CLOUD, their own or third party data center), and may use a wide variety of open source and other components to create their digital twin solutions.
[0035] In synchronization with the digital twins 114-1 to 114-N, several copies of digital avatars 104-1 to 104-N maybe created to be rendered in the metaverse 102. The digital avatars 104-1 to 104-N in an industrial metaverse scenario are graphical or 3D representations of real-world equipment, personnel, or automated systems, created to facilitate and enhance various industrial processes and activities within a virtual, interconnected, and immersive environment. In specificity, the digital avatars 104-1 to 104-N are the computer- generated representations of the digital twins 114-1 to 114-N of the physical assets 108-1 to 108-N in the industrial environment 106. The digital avatars 104-1 to 104-N can represent physical machinery, robots, and other industrial assets within a virtual factory or industrial environment. This allows for real-time monitoring, control, and simulation of these assets in the computer simulated environment. The digital avatars 104-1 to 104-N enable remote operation and control of machinery and equipment, allowing workers to manage and oversee industrial processes from anywhere with an internet connection, increasing efficiency and reducing physical presence requirements. The digital avatars 104-1 to 104-N can be used for training personnel in a safe, virtual environment. The digital avatars can visualize complex industrial data and analytics, providing a more intuitive and immersive way for users to understand and interact with large datasets, sensor readings, and performance metrics. The digital avatars 104-1 to 104-N can simulate hazardous scenarios, allowing users to assess risks and plan safety measures in advance, improving workplace safety. It should be noted that the digital avatars 104-1 to 104-N are a copy of the digital twins, therefore there could be multiple digital avatars 104-1 to 104-N rendered in the metaverse for a single digital twin.
[0036] The digital twin 114-1 to 1104-N of the assets is monitored by the asset security monitor 116, the sensor security monitor 118, and the master security monitor 122. The asset security monitor 116 is configured monitoring the one or more physical assets 108'1 to 108-N and generating physics-based fingerprints of the one or more physical assets 108'1 to 108-N. The sensor security monitor 118 is configured for monitoring the one or more sensors 110'1 to 110-N and generating electronic fingerprints of the one or more sensors 110'1 to 110'N. The master security monitor 122 is configured for monitoring the sensor network gateway 120 and the sensor security monitor 118. Further, the master security monitor 122 is configured for monitoring a first cryptographic fingerprint for the sensor network gateway 120 and a second cryptographic fingerprint for the sensor security monitor 118.
[0037] In one embodiment, the apparatus 110 is deployed in a cloud computing environment. As used herein, “cloud computing environment” refers to a processing environment comprising configurable computing physical and logical resources, for example, networks, servers, storage, applications, services, etc., and data distributed over the network 108, for example, the internet. The cloud computing environment provides on-demand network access to a shared pool of the configurable computing physical and logical resources. The apparatus 110 may include a module for managing access control for a plurality of digital twins 102'1 to 102-N interacting in a computer simulated collaborative environment over a distributed network.
[0038] Particularly, the system 100 comprises a cloud computing device configured for providing cloud services for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets. The cloud computing device comprises a cloud communication interface, a cloud computing hardware and OS, and a cloud computing platform. The cloud computing hardware and OS may include one or more servers on which an operating system (OS) is installed and includes one or more processing units, one or more storage devices for storing data, and other peripherals required for providing cloud computing functionality. The cloud computing platform is a platform which implements functionalities such as data storage, data analysis, data visualization, data communication on the cloud hardware and OS via APIs and algorithms; and delivers the aforementioned cloud services using cloud-based applications.
[0039] FIG 2 is a block diagram of an exemplary apparatus 126 for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets, according to an embodiment of the present invention. In an exemplary embodiment, the apparatus 126 is communicatively coupled to the computer simulated environment 102 rendering one or more digital avatars 104-1 to 104-N, the digital twin simulation environment 112 comprising one or more digital twins 114-1 to 114-N, the asset security monitor 116, the sensor security monitor 118, and the master security monitor 122.
[0040] The apparatus 126 may be a personal computer, a laptop computer, a tablet, a server, a virtual machine, and the like. The apparatus 126 includes a processing unit 202, a memory 204 comprising a module 206, a storage unit 220 comprising a database 222, an input unit 224, an output unit 226 and a bus 228.
[0041] The processing unit 202 as used herein, means any type of computational circuit, such as, but not limited to, a microprocessor, microcontroller, complex instruction set computing microprocessor, reduced instruction set computing microprocessor, very long instruction word microprocessor, explicitly parallel instruction computing microprocessor, graphics processor, digital signal processor, or any other type of processing circuit. The processing unit 202 may also include embedded controllers, such as generic or programmable logic devices or arrays, application specific integrated circuits, single-chip computers, and the like.
[0042] The memory 204 may be non-transitory volatile memory and / or non-volatile memory. The memory 204 may be coupled for communication with the processing unit 202, such as being a computer-readable storage medium. The processing unit 202 may execute instructions and / or code stored in the memory 204. A variety of computer-readable instructions may be stored in and accessed from the memory 204. The memory 204 may include any suitable elements for storing data and machine-readable instructions, such as read only memory, random access memory, erasable programmable read only memory, electrically erasable programmable read only memory, a hard drive, a removable media drive for handling compact disks, digital video disks, diskettes, magnetic tape cartridges, memory cards, and the like.
[0043] In the present embodiment, the memory 204 includes the module 206 stored in the form of machine-readable instructions on any of the above-mentioned storage media and may be in communication to and executed by the processing unit 202. When the machine-readable instructions are executed by the processing unit 202, the module 206 causes the processing unit 202 to detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets.
[0044] The module 206 further comprises a physics-based fingerprint validation module 208, electronic fingerprint validation module 210, a first cryptographic fingerprint module 212, second cryptographic fingerprint module 214, a tamper detection module 216 and an alert generation module 218.
[0045] The physics-based fingerprint validation module 208 is configured for validating a physics-based fingerprint pertaining to the one or more real-world physical assets 108'1 to 108-N in the industrial environment 106. The physics-based fingerprint is continuously validated for monitoring the digital twins 114-1 to 114-N corresponding to each of the digital avatars 104-1 to 104-N in the computer simulated environment 106.
[0046] The electronic fingerprint validation module 210 is configured for validating an electronic fingerprint pertaining to the one or more sensors 110'1 to 110'N corresponding to the one or more real-world physical assets 108'1 to 108'N arranged in the industrial environment 106. The electronic fingerprint is continuously validated for monitoring the digital twins corresponding to each of the digital avatars 104-1 to 104-N in the computer simulated environment 106.
[0047] The first cryptographic fingerprint module 212 is configured for validating a first cryptographic fingerprint pertaining to a sensor security monitor 118 configured for monitoring the one or more sensors 110'1 to 110'N. The first cryptographic fingerprint is continuously validated for monitoring the digital twins corresponding to each of the digital avatars 104-1 to 104-N in the computer simulated environment 102.
[0048] The second cryptographic fingerprint module 214 is configured for validating a second cryptographic fingerprint pertaining to a sensor security gateway 120 configured for providing sensor data to a network 124. The second cryptographic fingerprint is continuously validated for monitoring the digital twins 114-1 to 114-N corresponding to each of the digital avatars 104-1 to 104-N in the computer simulated environment 102.
[0049] The tamper detection module 216 is configured for detecting tampering of the real-world physical assets 108'1 to 1-8-N in the industrial environment 106 based on the monitoring of the corresponding digital twins 114-1 to 114-N in the digital twin simulation environment 112. The tamper detection module 216 is configured for validating the physics-based fingerprint, the electronic fingerprint, the first cryptographic fingerprint, and the second cryptographic fingerprint and then detecting tampering of the real-world physical assets if the validation fails. The tamper detection module 216 is further configured for detecting modification of the digital avatars 104-1 to 104-N corresponding to the digital twins 114-1 to 114- N based on the detecting tampering of the real-world physical assets 108-1 to 108-N.
[0050] The alert generation module 218 is configured for generating visual alerts for one or more users interacting with the digital avatars 104-1 to 104-N in the computer simulated environment 102. The alert generation module 218 is configured to determine the information pertaining to tampering of the real-world physical assets 108-1 to 108-N and then render the visual alerts along with the tamper information of the real-world physical assets 108'1 to 108-N to the one or more users of the digital avatars in the computer simulated environment 102.
[0051] The processing unit 202 is configured for performing all the functionality of the module 206. The processing unit 202 is configured to monitor a digital twin 114'1 to 114-N corresponding to each of the digital avatars 104-1 to 104-N in the computer simulated environment 102. The processing unit 202 is configured to monitor the digital twin 114'1 to 114-N by validating a physics-based fingerprint pertaining to the one or more real-world physical assets 108'1 to 108-N in the industrial environment 106. The processing unit 202 is configured to monitor the digital twin 114'1 to 114-N by validating the electronic fingerprint pertaining to the one or more sensors 110-1 to 110-N associated with the real-world physical assets 108-1 to 108-N, wherein the sensors 110-1 to 110-N are arranged in the industrial environment 106. The processing unit 202 is configured to monitor the digital twin 114-1 to 114-N by validating the first cryptographic fingerprint pertaining to a sensor security monitor 118 configured for monitoring the one or more sensors 110'1 to 110-N arranged in the industrial environment 106. The processing unit 202 is configured to monitor the second cryptographic fingerprint pertaining to the sensor security gateway 120 configured for providing sensor data to a network. The processing unit 202 is configured to detect tampering of the real-world physical assets 108-1 to 108-N based on the monitoring of the corresponding digital twins, when the validation of any one of the physics-based fingerprint, the electronic fingerprint, the first cryptographic fingerprint, or the second cryptographic fingerprint fails. The processing unit 202 is configured to detect modification of the digital avatars 104-1 to 104-N based on detecting tampering of the real-world physical assets 108'1 to 108-N in the industrial environment 106.
[0052] The storage unit 220 comprises the database 222 for storing the digital avatars, digital twins, encryption keys etc.. The storage unit 220 and / or database 222 may be provided using various types of storage technologies, such as solid state drives, hard disk drives, flash memory, and may be stored in various formats, such as relational databases, non-relational databases, flat files, spreadsheets, and extended markup files, etc.
[0053] The input unit 224 may provide ports to receive input from input devices such as keypad, touch -sensitive display, camera (such as a camera receiving gesturebased inputs), etc. capable of receiving inputs from the . The display unit 224 may provide ports to output data via output device with a graphical user interface for visual indicators when tampering of digital avatars, digital twins, assets, network gateway is detected in the computer simulated virtual environment 102. The bus 228 acts as interconnect between the processing unit 202, the memory 204, the storage unit 220, the input unit 224, and the display unit 226.
[0054] Those of ordinary skilled in the art will appreciate that the hardware depicted in FIG 3 may vary for particular implementations. For example, other peripheral devices such as an optical disk drive and the like, Local Area Network (LAN) / Wide Area Network (WAN) / Wireless (e.g., Wi-Fi) adapter, graphics adapter, disk controller, input / output (I / O) adapter also may be used in addition to or in place of the hardware depicted. The depicted example is provided for the purpose of explanation only and is not meant to imply architectural limitations with respect to the present disclosure.
[0055] FIG 3 is a flowchart depicting steps of a method 300 for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets, wherein the one or more digital avatars correspond to the real-world physical assets in an industrial environment, according to an embodiment of the present invention.
[0056] At 302, a digital twin 114-1 to 114-N corresponding to each of the digital avatars 104-1 to 104-N in the computer simulated environment 102 is monitored by validating a physics-based fingerprint pertaining to the one or more real-world physical assets 108'1 to 108-N in the industrial environment 106. The physicsbased fingerprint refers to a unique and highly detailed digital representation or profile of a specific industrial asset, such as a machine, equipment, or component, created through the analysis of its physical characteristics and behavior. This fingerprint is based on the fundamental physical properties and behaviors of the asset 108-1 to 108-N and is used for various purposes in industrial applications. In an embodiment, the physics-based fingerprint of the one or more assets 108'1 to 108'N in the industrial environment 106 is derived from any one of physics based model of the assets, statistical model of the assets, or a combination thereof, and wherein the physics-based fingerprint is a quantification of a feature vector, uniquely identifies an asset based on an operational behavior of the asset in the industrial environment 106.
[0057] The physics-based fingerprint includes detailed information about the physical attributes of the industrial asset, such as its size, shape, material composition, weight, and structural properties. These characteristics are typically captured through sensors, measurements, or digital imaging techniques. In addition to static physical attributes, the fingerprint incorporates dynamic behavioral data. This data encompasses how the asset operates, its performance metrics (e.g., temperature, pressure, vibration), response to various inputs, and other real-time behaviors. It is often collected through sensors and monitoring systems. Sensors and monitoring devices are crucial for capturing both the physical characteristics and behavioral data of the asset. These sensors may include accelerometers, temperature sensors, pressure sensors, cameras, and more. The data from these sensors is continuously collected and analyzed. Physics-based models and analytical techniques are applied to the collected data to derive meaningful insights about the asset's behavior. This can involve using physics-based simulations, machine learning algorithms, or mathematical models to interpret and predict how the asset should behave under different conditions. The analysis process results in the creation of a unique, digital "fingerprint" or profile of the industrial asset. This fingerprint represents physical and behavioral characteristics of the asset in a structured and standardized format. Notably, the physics-based fingerprint of industrial assets has various applications, including predictive maintenance, quality control, anomaly detection, asset tracking, and optimization of industrial processes. For example, it can be used to predict when maintenance is required based on deviations from expected behavior, to identify defects or irregularities in manufacturing processes, or to track the location and condition of assets in a factory or logistics chain. Furthermore, the physics-based fingerprint serve as a security measure to ensure the authenticity and integrity of industrial assets, preventing counterfeiting or tampering by comparing realtime data with the expected physics-based fingerprint. Advantageously, in the context of the present invention, the physics-based fingerprint of industrial assets is a comprehensive digital profile that combines static physical characteristics with dynamic behavioral data to create a unique and valuable representation of an industrial asset that is essential for securing the assets in the industrial environment.
[0058] In an example, the physics-based fingerprint maybe generated for each of the real-world physical assets 108'1 to 108-N in the industrial environment 106. It should be understood that the physics-based fingerprint of an asset is also the physics-based fingerprint of the corresponding digital twin and hence by monitoring the digital twin of the asset, a potential tampering of the physical asset can be detected. Notably, detecting the tampering of assets 108-1 to 1-8-N using a physics-based fingerprint involves comparing the real-time physical and behavioral characteristics of the asset (corresponding digital twin in this case) to its expected or baseline fingerprint. Any deviation from the expected fingerprint can indicate potential tampering or unauthorized changes to the asset. The baseline or initial physics-based fingerprint for the asset is established and then stored as in the digital twin of the asset. In an example, the data for the baseline fingerprint is collected through sensors and monitoring systems during the asset calibration or setup phase. Once the asset is in operation, sensors and monitoring systems continuously collect data related to the asset's physical attributes and behavior for continuously updating the digital twin. This data is compared to the baseline fingerprint. Real-time data is compared to the baseline fingerprint of the digital twin to identify any discrepancies or anomalies. These anomalies could be caused by various forms of tampering or unauthorized changes to the asset.
[0059] At step 304, a digital twin 114-1 to 114-N corresponding to each of the digital avatars 104-1 to 1-4-N in the computer simulated environment 106 is monitored by validating an electronic fingerprint pertaining to the one or more sensors 108- 1 to 108-N associated with the real-world physical assets 108-1 to 108-N, arranged in the industrial environment 106. In an embodiment, the electronic fingerprint of the one or more sensors is a physically unclonable function that uniquely identifies a sensor in the industrial environment. The physically Unclonable Functions (PUFs) for sensors refer to specialized electronic components or techniques used in sensor technology that leverage the inherent physical variations within semiconductor devices to create unique and unclonable digital signatures or identifiers. Physically Unclonable Functions (PUFs) for sensors are security mechanisms that utilize the inherent physical variations in semiconductor devices to create unique, unpredictable, and tamper-resistant electronic signatures. These signatures enhance the security, authenticity, and reliability of sensor data and are valuable in various applications, including authentication, anti-counterfeiting, and secure communication in sensor networks.
[0060] Each sensor's PUF generates a distinct electronic signature or key due to the microscopic variations that occur during the manufacturing process. These variations are nearly impossible to replicate accurately, making each sensor inherently unique. PUFs are designed to produce unpredictable output, even if an attacker has extensive knowledge of the sensor's physical structure. The output is not based on a predetermined algorithm but is a result of the specific physical characteristics of the device. Furthermore, PUFs operate using a challenge-response mechanism. When a challenge is provided to the PUF, it generates a unique response based on its physical properties. This response can be used as a cryptographic key or to authenticate the sensor. It should be understood that the PUF is used to authenticate sensors and the data they produce. By comparing the sensor's response to a previously recorded reference response, it can be determined whether the sensor is genuine and unaltered. Furthermore, PUFs help prevent counterfeiting of sensors. Since each sensor has a unique PUF response, counterfeit or cloned sensors can be easily detected by comparing their responses to the genuine sensor's response. In a specific example, an electronic fingerprint is generated for securing sensor data and communication. These keys are derived from the PUF response and are highly resistant to external attacks. Advantageously, the PUFs are used to verify the integrity of the sensor. Any physical tampering or alteration of the sensor's components would likely result in a different PUF response.
[0061] In the context of the present invention, the validation of the electronic fingerprint is done by monitoring the digital twin associated with the sensors arranged in the industrial environment. Before deploying a PUF, a reference baseline electronic fingerprint is generated by characterizing the behavior of the sensor and recording the responses to specific challenges or stimuli. This baseline electronic fingerprint represents the expected behavior of the PUF when it is in its original, untampered state. It is to be noted that this baseline electronic fingerprint is also communicated to the corresponding digital twin that is continuously monitored to detect tampering of the sensors. The method comprises regularly comparing the real-time behavior of the PUF i.e. the electronic fingerprint of the sensor, as observed through its responses to challenges or stimuli, to the reference baseline electronic fingerprint stored in the corresponding digital twin. This comparison can involve statistical analysis or direct comparison of response patterns. Furthermore, the validation of the electronic fingerprint of the sensors can also be done by employing anomaly detection techniques to identify any deviations or anomalies in the PUF's behavior compared to the reference baseline. Anomalies may include changes in response patterns, response time, or other observable characteristics. Furthermore, the validation of the electronic fingerprint can also be done by monitoring the environmental conditions surrounding the PUF, such as temperature, humidity, and electromagnetic interference. Changes in these conditions can sometimes affect the behavior of electronic components.
[0062] At step 306, a digital twin 114-1 to 114-N corresponding to each of the digital avatars 104-1 to 104-N in the computer simulated environment 106 is monitored by validating a first cryptographic fingerprint pertaining to the sensor security monitor 118 configured for monitoring the one or more sensors 110'1 to 110-N. In an embodiment, the first cryptographic fingerprint of the sensor security monitor 118 is a one-way hash function of a unique cryptographic key registered for the sensor security monitor 118. The first cryptographic fingerprint for the sensor security monitor 118 is a unique and secure digital representation generated from the configuration, firmware, or hardware attributes of the sensor security monitor using cryptographic techniques. This fingerprint serves to verify the identity and integrity of the sensor security monitor 118 in the network. The first cryptographic fingerprint is inherently unique to each individual sensor security monitor 118. It is generated based on characteristics and data that are distinctive to that device, ensuring that no two sensor security monitors produce the same fingerprint. Any unauthorized alterations or tampering with the configuration, firmware, or hardware of the sensor security monitor can change the first cryptographic fingerprint. By comparing the current fingerprint with a trusted reference, administrators can detect any tampering or unauthorized changes. The first cryptographic fingerprint is used to authenticate the sensor security monitor when it connects to a network or communicates with other devices or servers. Verification of the fingerprint against a known and trusted reference ensures that the sensor security monitor is genuine and has not been replaced or compromised. In an example, the sensor security monitor is a PUF, and therefore a first cryptographic fingerprint of the PUF is generated and stored as an element in the corresponding digital twin. The first cryptographic fingerprint is validated against an initial baseline to detect tampering of the PUF itself.
[0063] At step 308, a digital twin 114-1 to 114-N corresponding to each of the digital avatars 104-1 to 104-N in the computer simulated 102 environment is monitored by validating a second cryptographic fingerprint pertaining to a sensor network gateway 120 configured for providing sensor data to a network. In an embodiment, the second cryptographic fingerprint of the sensor network gateway is a one-way hash function of a unique cryptographic key registered for the sensor network gateway 120.
[0064] The second cryptographic fingerprint for the sensor network gateway 120 is a unique and secure digital representation generated from the configuration, firmware, or hardware attributes of the sensor security monitor 118 using cryptographic techniques. This fingerprint serves to verify the identity and integrity of the sensor network gateway in the network. The second cryptographic fingerprint is inherently unique to each individual sensor network gateway 120. It is generated based on characteristics and data that are distinctive to that device, ensuring that no two sensor network gateways produce the same fingerprint. Any unauthorized alterations or tampering with the configuration, firmware, or hardware of the sensor network gateway 120 can change the second cryptographic fingerprint. By comparing the current second cryptographic fingerprint with a trusted reference, administrators can detect any tampering or unauthorized changes. The second cryptographic fingerprint is used to authenticate the sensor network gateway 120 when it connects to a network or communicates with other devices or servers. Verification of the second cryptographic fingerprint against a known and trusted reference ensures that the sensor network gateway 120 is genuine and has not been replaced or compromised. The second cryptographic fingerprint is validated against an initial baseline to detect tampering of the sensor network gateway 120.
[0065] At step 310, tampering of the real-world physical assets 108-1 to 108-N is detected based on the monitoring of the corresponding digital twins 114-1 to 114- N, when the validation of any one of the physics-based fingerprint, the electronic fingerprint, the first cryptographic fingerprint, or the second cryptographic fingerprint fails. It should be understood the tampering of the digital twin is detected when the validation of any one of the physics-based fingerprint, the electronic fingerprint, the first cryptographic fingerprint, or the second cryptographic fingerprint fails.
[0066] There could be several means of tampering a physical asset 108-1 to 108-N, or a sensor 110'1 to 110-N, a sensor security monitor 118, a sensor network gateway 120, that can be detected. In one example, if someone physically alters the asset 108-1 to 108'N or its components, the sensor 110'1 to 110'N, the asset security monitor 116, the sensor security monitor 118, the sensor network gateway 120 such as removing or replacing parts, the physical attributes recorded by sensors may change. These changes can be detected through the comparison of the current physical data with the baseline fingerprint of the digital twin such as the physics-based fingerprint, the electronic fingerprint, the first cryptographic fingerprint, and second cryptographic fingerprint. In another example, unauthorized changes to the operating parameters or behaviors of the asset, sensor, sensor network gateway, such as adjusting settings or introducing software modifications, can also be detected as tampering. In yet another example, changes in the operating environment of the physical asset, the sensors, the sensor security monitor, the sensor network gateway, such as temperature, humidity, or pressure, can affect its behavior. The fingerprint can account for these environmental factors, and deviations outside the expected range can be flagged.
[0067] At step 312, modification of the digital avatars 104-1 to 104-N is detected based on detecting tampering of the corresponding real-world physical assets 108'1 to 108'N. The tampering of the physical assets 108-1 to 108-N, sensors 110-1 to 110- N, asset security monitor 116, sensor security monitor 118, sensor network gateway 120 is detected by the monitoring the corresponding digital twin for detecting any modifications to the digital avatars 104-1 to 104-N in the metaverse. According to an embodiment, the method further comprises generating visual alerts for one or more users interacting with the digital avatars 104-1 to 104-N in the computer simulated environment 102. The visual alerts comprise information pertaining to tampering of the digital avatars 104-1 to 104- N and corresponding physical assets 104-1 to 104-N, sensors 108'1 to 108'N, sensor security monitor 118, sensor network gateway 120 as detected by monitoring the digital twin 114-1 to 114-N. The visual alerts are graphical or visual cues and notifications designed to capture a user's attention and convey important information, messages, or events within the metaverse. Herein, the visual alerts comprise information pertaining to tampering of the digital avatars 104-1 to 104-N while the user is interacting with the digital avatars 104-1 to 104- N. According to an embodiment, the method further comprises generating one or more notifications to be transmitted to an owner of the one or more physical assets 108'1 to 108'N along with information pertaining to the tampering of the physical assets. It should be understood that in an industrial environment, the ownership of the physical assets, networks, monitoring systems can he with different entities, therefore the when the tampering of assets is detected, one or more notifications are generated and transmitted to the entities owning the assets.
[0068] The present invention aims to provide capability of tamper detection for digital avatars in the metaverse. The present invention also aims to provide a method for generation of multi-dimensional fingerprints for a multi-pronged approach in order to detect tampering at different levels of the industrial environment, namely physical assets, sensors, and communications. Advantageously, the present invention aims at providing a method to identify and report to the users in the metaverse that a corresponding asset, sensor or network has been tampered with. Furthermore, the present invention provides a method to send visual indicators to the users in the metaverse and thereby preventing any inaccurate actions in the metaverse.
[0069] While the present invention has been described in detail with reference to certain embodiments, it should be appreciated that the present disclosure is not limited to those embodiments. The foregoing examples have been provided merely for the purpose of explanation and are in no way to be construed as limiting of the present invention disclosed herein. While the invention has been described with reference to various embodiments, it is understood that the words, which have been used herein, are words of description and illustration, rather than words of limitation. Further, although the invention has been described herein with reference to particular means, materials, and embodiments, the invention is not intended to be limited to the particulars disclosed herein! rather, the invention extends to all functionally equivalent structures, methods and uses, such as are within the scope of the appended claims. Those skilled in the art, having the benefit of the teachings of this specification, may effect numerous modifications thereto and changes may be made without departing from the scope of the invention in its aspects. List of references
[0070] 100 system
[0071] 102 computer simulated environment
[0072] 104-1 to 104-N digital avatars
[0073] 106 industrial environment
[0074] 108-1 to 108-N one or more physical assets
[0075] 110-1 to 110-N one or more sensors
[0076] 112 simulation environment
[0077] 114-1 to 114-N one or more digital twins
[0078] 116 asset security monitor
[0079] 118 sensor security monitor
[0080] 120 sensor network gateway
[0081] 122 master security monitor
[0082] 124 communication netowrk
[0083] 126 apparatus
[0084] 202 one or more processing units
[0085] 204 memory unit
[0086] 206 module
[0087] 208 physics-based fingerprint validation module
[0088] 210 electronic fingerprint validation module
[0089] 212 first cryptographic fingerprint module
[0090] 214 second cryptographic fingerprint module
[0091] 216 tamper detection module
[0092] 218 alert generation module
[0093] 220 storage unit
[0094] 222 database
[0095] 224 input unit
[0096] 226 display unit
[0097] 228 bus
[0098] 300 flowchart depicting steps of a method for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets
Claims
CLAIMS1. A method (300) for detecting modification to digital avatars (104-1 to 104- N) in a computer simulated environment (102) based on detection of tampering of real-world physical assets (108-1 to 1-8-N), wherein the one or more digital avatars (104-1 to 104-N) correspond to the real-world physical assets in an industrial environment (106), and wherein the method comprises: monitoring, by the processing unit (202), a digital twin (114-1 to 114-N) corresponding to each of the digital avatars (104-1 to 104-N) in the computer simulated environment (102) by: validating a physics-based fingerprint pertaining to the one or more real-world physical assets (108'1 to 108-N) in the industrial environment (106); validating an electronic fingerprint pertaining to the one or more sensors (110'1 to 110-N) arranged in the industrial environment (106); validating a first cryptographic fingerprint pertaining to a sensor security monitor (118) configured for monitoring the one or more sensors (110'1 to 110-N); and validating a second cryptographic fingerprint pertaining to a sensor security gateway (120) configured for providing sensor data to a network; detecting, by the processing unit (202), tampering of the real-world physical assets (108'1 to 108-N) based on the monitoring of the corresponding digital twins (114'1 to 114-N), when the validation of any one of the physicsbased fingerprint, the electronic fingerprint, the first cryptographic fingerprint, or the second cryptographic fingerprint fails; and detecting, by the processing unit (202), modification of the digital avatars (104-1 to 104-N) based on detecting tampering of the corresponding real-world physical assets (108-1 to 108-N).
2. A method (300) according to claim 1, further comprising generating visual alerts for one or more users interacting with the digital avatars (104'1 to 104-N) in the computer simulated environment (102), wherein the visual alerts comprise information pertaining to tampering of the corresponding physical assets (108'1 to 108-N).
3. A method (300) according to claim 1, further comprising generating one or more notifications to be transmitted to an owner of the one or more physical assets (108'1 to 108'N) along with information pertaining to the tampering of the physical assets.
4. A method (300) according to any of the preceding claims, wherein the physics-based fingerprint of the one or more assets (108'1 to 108'N) in the industrial environment is derived from any one of physics based model of the assets, statistical model of the assets, or a combination thereof, and wherein the physics-based fingerprint is a quantification of a feature vector, uniquely identifies an asset based on an operational behavior of the asset (108-1 to 108-N) in the industrial environment (106).
5. A method (300) according to any of the preceding claims, wherein the electronic fingerprint of the one or more sensors (110'1 to 110'N) is a physically unclonable function that uniquely identifies a sensor in the industrial environment (106).
6. A method (300) according to any of the preceding claims, the first cryptographic fingerprint of the sensor security monitor (118) is a one-way hash function of a unique cryptographic key registered for the sensor security monitor.
7. A method (300) according to any of the preceding claims, wherein the first cryptographic fingerprint of the sensor security gateway (120) is a one-way hash function of a unique cryptographic key registered for the sensor security gateway.
8. An apparatus (126) for detecting modification to digital avatars (104-1 to 104-N) in a computer simulated environment (102) based on detection of tampering of real-world physical assets (108'1 to 108'N), wherein the one or more digital avatars correspond to the real-world physical assets in an industrial environment, the apparatus comprising: one or more processing units (202); and, a memory (204) communicatively coupled to the one or more processing units (202), the memory comprising a module (206) stored in the form of machine-readable instructions executable by the one or more processing units(202), wherein the module is configured to perform the method steps according to claims 1 to 79. A system (100) for detecting modification to digital avatars (104-1 to 104- N) in a computer simulated environment (102) based on detection of tampering of real-world physical assets (108-1 to 108-N), wherein the one or more digital avatars (104-1 to 104-N) correspond to the real-world physical assets (108-1 to 108'N) in an industrial environment (106), the system comprising: one or more digital avatars (104-1 to 104-N) interacting in a computer simulated environment (102), wherein the one or more digital avatars (108'1 to 108'N) correspond to one or more real-world physical assets in an industrial environment (106); one or more digital twins (114'1 to 114-N) communicatively coupled to the one or more digital avatars (104-1 to 104-N) in the computer simulated environment (102), wherein the one or more digital twins simulate a behavior of the corresponding one or more real-world assets (108-1 to 108-N); an asset security monitor (116) communicatively coupled to the one or more physical assets (108'1 to 108-N), wherein the asset security monitor is configured for monitoring the one or more physical assets and generating physics-based fingerprints of the one or more physical assets; a sensor security monitor (118) communicatively coupled to the one or more sensors (110'1 to 110'N), wherein sensor security monitor is configured for monitoring the one or more sensors and generating an electronic fingerprints of the one or more sensors; a master security monitor (122) communicatively coupled to a sensor network gateway (120) for providing data pertaining to one or more sensors (108- 1 to 108'N) and the sensor security monitor (118), wherein the master security (122) monitor is configured for monitoring the sensor network gateway (120) and the sensor security monitor (118), and wherein the master security monitor is configured for monitoring a first cryptographic fingerprint for the sensor network gateway and a second cryptographic fingerprint for the sensor security monitor; and an apparatus (126) according to claim 8, communicatively coupled to the one or more digital twins (114'1 to 114-N), the asset security monitor (116), the sensor security monitor (118), and the sensor security gateway (120) over acommunication network (124), wherein the apparatus (126) is configured for detecting modification to digital avatars in a computer simulated environment based on detection of tampering of real-world physical assets, according to any of the method claims 1 to 7.
10. A computer-program product, having computer-readable instructions stored therein, that when executed by a processing unit, cause the processing unit to perform method steps according to any of the claims 1 to 7.
Citation Information
Patent Citations
System and method for trusted platform attestation
EP2645294B1
Devices, systems, and methods using microtransponders
US20220083641A1
Systems and methods for data lifecycle management with code content optimization and servicing
US20230152789A1
Quantum, biological, computer vision, and neural network systems for industrial internet of things
US20230176557A1