信息网络安全 ›› 2022, Vol. 22 ›› Issue (11): 68-76.doi: 10.3969/j.issn.1671-1122.2022.11.009

• 技术研究 • 上一篇    下一篇

工业控制系统功能安全和信息安全策略优化方法

宋晶1,2,3(), 刁润2,3, 周杰2,3, 戚建淮1,2,3   

  1. 1. 西南交通大学信息化研究院,成都 610036
    2. 成都市以太节点科技有限公司,成都 610036
    3. 深圳市永达电子信息股份有限公司,深圳 518055
  • 收稿日期:2022-06-06 出版日期:2022-11-10 发布日期:2022-11-16
  • 通讯作者: 宋晶 E-mail:jesen811206@126.com
  • 作者简介:宋晶(1981—),男,四川,助理研究员,硕士,主要研究方向为网络安全和应用数学|刁润(1993—),男,四川,硕士,主要研究方向为网络安全和机器学习|周杰(1996—),男,四川,主要研究方向为网络安全和机器学习|戚建淮(1965—),男,安徽,教授,博士,主要研究方向为网络安全和机器学习

The Optimization Method of Industrial Control System Functional Safety and Information Security Policy

SONG Jing1,2,3(), DIAO Run2,3, ZHOU Jie2,3, QI Jianhuai1,2,3   

  1. 1. Information Technology Research Institute of Southwest Jiaotong University, Chengdu 610036, China
    2. Chengdu Ethernet Node Technology Co., Ltd., Chengdu 610036, China
    3. Shenzhen Yongda Electronics Information Co., Ltd., Shenzhen 518055, China
  • Received:2022-06-06 Online:2022-11-10 Published:2022-11-16
  • Contact: SONG Jing E-mail:jesen811206@126.com

摘要:

针对当前工业控制安全兼容性难以解决的问题,在功能安全与信息安全资源消耗竞争的本质层面上,文章提出支持功能安全与信息安全冲突协商的形式化模型,从数学上刻画工业控制系统安全策略的功能安全程度、信息安全程度、CPU占用和内存占用。文章将这4个数学函数作为衡量安全策略优劣的目标函数进行多目标优化,充分考虑功能安全、信息安全、时间延迟、资源消耗等工业控制系统的关键因素,构建目标函数的参数空间,利用空间间隔挑选出最优策略。文章克服传统的矛盾屏蔽方法只能在不影响功能安全的前提下进行定性配置的局限,为工业控制系统提供一套完整的策略优化方案和算法。模拟实验将策略优化算法应用到列车控制系统中,获取车载列车自动防护(Automatic Train Protection,ATP)系统的最优安全策略方案,实验结果表明,文章提出的安全策略优化方法,可以量化安全策略的优劣,并有效地选取最优安全策略方案,保障工业控制系统安全。

关键词: 信息安全, 功能安全, 时间复杂度, 空间复杂度, 遗传算法

Abstract:

In view of the problem that is difficult to solve in current industrial control security compatibility, at the essential level of the competition between functional safety and information security resource consumption, a formal model supporting the conflict between functional safety and information security is proposed. The functional safety degree, information security degree, CPU occupation, and memory occupation of the security policy of the industrial control system are mathematically described. This paper took four mathematical functions as objective functions to measure the advantages and disadvantages of the security policy for multi-objective optimization. It fully considered the key factors of industrial control systems such as functional safety, information security, time delay, and resource consumption, constructed the parameter space of the objective function, and used the space interval to select the optimal strategy. This paper overcomes the limitation that the traditional contradiction shielding method can only be qualitatively configured without affecting functional safety, and provides a complete set of policy optimization schemes and algorithms for industrial control systems. The strategy optimization algorithm is applied to the train control system to obtain the optimal safety strategy scheme of the Automatic Train Protection (ATP) system.Experimental results show that the security strategy optimization method proposed in this paper can quantify the advantages and disadvantages of security strategies, and effectively select the optimal scheme of security strategy to ensure the security of industrial control systems.

Key words: information security, functional safety, time complexity, space complexity, genetic algorithm

中图分类号: