To address the security and the collaborative scheduling issues of multiple decision scheduling dielets (DSDs) in the endogenous security structure of software-defined system on wafer (SDSoW), a multi-level distributed dynamic heterogeneous redundancy (DHR) architecture (MD2HR) is proposed. Firstly, by interconnecting multiple local heterogeneous DSDs through a software-defined network on wafer, a dynamic multimode decision model (DMDM) is formed. Secondly, a dynamic decision switching algorithm based on trust and optimal delay is proposed to solve the optimization problem of dynamic switching among DSDs. Finally, a traffic game-based collaborative scheduling algorithm is designed to achieve collaboration of the output decision information from heterogeneous DSDs. A test system is constructed, and an on-chip secure interconnect dielets that simultaneously support multiple heterogeneous attributes and decision scheduling functions is realized. Experimental analysis shows that, compared to traditional single and multiple decision structures, the proposed architecture and model can defend against the differential mode attack targeting any DSDs with a controllable delay overhead of 5.11% to 47.40%.
软件定义晶上系统(Software Defined System on Wafer, SDSoW)[1]通过高密度集成技术,将异构异质功能芯粒在晶圆上互连,是一种典型的信息物理系统(Cyber-Physical Systems, CPS)。由于集成过程不可避免的不确定物理失效、不可信第三方芯粒、不可控分离设计制造以及高动态的应用特征,SDSoW面临复杂的广义功能安全威胁。基于动态异构冗余(Dynamic Heterogeneous Redundancy, DHR)的内生安全防御[2-3]是解决CPS安全问题的新范式技术,其中裁决调度模块作为DHR的核心,其安全性至关重要。受限于SDSoW的超大集成规模,其DHR构造需划分为分布式多区域,多区域裁决调度的协同成为难点。因此,如何确保DHR构造中裁决调度模块的安全并确保分布式裁决调度的协同成为必须要解决的问题。
SDSoW的互连接口呈现出物理位置异构的冗余特性,业务处理区域内及区域间的内生安全构造具有对称性,理论上,SDSoW任何芯粒的核心处理逻辑都可执行拟态括号的裁决调度处理功能。为解决芯粒灵活互连问题,SDSoW构建了多维灵活互连的软件定义晶上互连网络(Software Defined Network on Wafer, SDNoW)。裁决芯粒均互连互通,可实现同一维度的动态变换。由于集成芯粒的异构性,裁决芯粒形成实际意义上的异构,这使得系统级的DHR构造中,各异构业务处理区域的裁决芯粒可构成异构的裁决调度执行体,形成DHR构造的多模裁决结构。
WANGZ H, JIANGD D, LYUZ H. AI-assisted trustworthy architecture for industrial IoT based on dynamic heterogeneous redundancy[J]. IEEE Transactions on Industrial Informatics, 2023,19(2):2019-2027.
[5]
YINGF, ZHAOS J, DENGH. Microservice security framework for IoT by mimic defense mechanism[J]. Sensors, 2022,22(6):No.2418.
[6]
FENGF, ZHOUX B, LIB, et al. Modelling the mimic defence technology for multimedia cloud servers[J]. Security and Communication Networks, 2020,2020(1):No.8819958.
[7]
SENJIEL, QINRANGL, YITENGW, et al. A self-adaptive timeout mechanism in Mimic Defense System[C]∥Proceedings of the 2017 8th IEEE International Conference on Software Engineering and Service Science. Piscataway, USA: IEEE, 2017:588-591.
[8]
WEID, XIAOL, SHIL, et al. Mimic web application security technology based on dhr architecture[C]∥Proceedings of the 2022 International Conference on Artificial Intelligence and Intelligent Information Processing. Washington, USA: SPIE, 2022:118-124.
[9]
ZHANGH, WANGY, LIUH, et al. Intelligent dynamic heterogeneous redundancy architecture for IoT systems[J]. China Communications, 2024,21(7):291-306.
LIY F, LIUQ, ZHUANGW H, et al. Dynamic heterogeneous redundancy-based joint safety and security for connected automated vehicles: preliminary simulation and field test results[J]. IEEE Vehicular Technology Magazine, 2023,18(2):89-97.
OUYANGL, SONGK, LUX Y, et al. Analysis of mimic defense and defense capabilities based on four-executor[C]∥Proceedings of the 2018 International Conference on Advanced Mechatronic Systems. Piscataway, USA: IEEE, 2018:137-142.
RENQ, GUOZ H, WUJ X, et al. SDN-ESRC: a secure and resilient control plane for software-defined networks[J]. IEEE Transactions on Network and Service Management, 2022,19(3):2366-2381.