IP Library Granted Patent US 12,192,215
Granted Patent B2
US 12,192,215 · App. 17/939,577 · Granted Jan 7, 2025

Method and architecture for providing integrated design of cyber-physical system with watermarking

Inventors: Raman Goyal (Mountain View, CA); Christoforos Somarakis (Gilroy, CA); Erfaun Noorani (Fairless Hill, PA); Aleksandar B. Feldman (Santa Cruz, CA); Shantanu Rane (Palo Alto, CA)
Assignee: Xerox Corporation
H04L63/1416H04L63/1425H04L63/145H04L63/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,215
App. No.
17/939,577
Granted
Jan 7, 2025
Kind
B2
Abstract

Embodiments described herein provide a design architecture for co-designing a controller and a watermarking signal for a cyber-physical system. During operation, the architecture can determine, in conjunction with each other, respective values of a first set of parameters indicating operations of the controller and a second set of parameters representing the watermarking signal. Here, the watermarking signal is combinable with a control signal from the controller for monitoring an output signal of the cyber-physical system for detecting malicious data at different time instances. Subsequently, the architecture can determine a state manager for determining the states of the cyber-physical system from the monitored output signal based on the first and second sets of parameters. The architecture can also determine a detector capable of identifying presence of an attack from the states of the cyber-physical system at a plurality of time instances using the watermarking signal.

Claims (47)

1. A computer-executable method for co-designing a controller and a watermarking signal for a cyber-physical system, the method comprising:

determining a first set of values of a first set of parameters indicating operations of the controller based on an initial set of values of a second set of parameters representing the watermarking signal, wherein the watermarking signal is a type of signal combinable with a control signal from the controller for monitoring an output signal of the cyber-physical system for detecting malicious data at a plurality of time instances;

determining a second set of values of the second set of parameters based on the first set of values;

determining a state manager based on the first and second sets of values, wherein the state manager determines states of the cyber-physical system from the monitored output signal; and

determining a detector capable of identifying presence of an attack from the states of the cyber-physical system at the plurality of time instances using the watermarking signal.

2. The method of claim 1 , wherein the attack comprises replaying a previously recorded output of the cyber-physical system.

3. The method of claim 1 , wherein determining the first and second sets of values further comprises:

enhancing a set of predetermined values of the first set of parameters based on the initial set of values of the second set of parameters to generate the first set of values; and

enhancing the initial set of values of the second set of parameters based on the first set of values to generate the second set of values.

4. The method of claim 3 , wherein enhancing a respective set of values further comprises iterating the enhancement until a convergence is reached.

5. The method of claim 3 , wherein the generation of the first set of values corresponds to a performance metric for the cyber-physical system; and

wherein the generation of the second set of values corresponds to a detection rate for the attack.

6. The method of claim 1 , wherein determining the first and second sets of values further comprises:

identifying the first set of values of the first set of parameters based on the initial set of values of the second set of parameters, wherein the first set of values is associated with the controller is existing in the cyber-physical system; and

enhancing the initial set of values of the second set of parameters based on the identified first set of values to generate the second set of values.

7. The method of claim 1 , wherein the state manager includes a Kalman filter for determining the states of the cyber-physical system.

8. The method of claim 1 , wherein the detector includes a chi-square detector for detecting the attack.

9. The method of claim 1 , further comprising bounding the first set of values of the first set of parameters to a norm indicating that the controller is a stable dynamic feedback controller.

10. A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for co-designing a controller and a watermarking signal for a cyber-physical system, the method comprising:

determining a first set of values of a first set of parameters indicating operations of the controller based on an initial set of values of a second set of parameters representing the watermarking signal, wherein the watermarking signal is a type of signal combinable with a control signal from the controller for monitoring an output signal of the cyber-physical system for detecting malicious data at a plurality of time instances;

determining a second set of values of the second set of parameters based on the first set of values;

determining a state manager based on the first and second sets of values, wherein the state manager determines states of the cyber-physical system from the monitored output signal; and

determining a detector capable of identifying presence of an attack from the states of the cyber-physical system at the plurality of time instances using the watermarking signal.

11. The non-transitory computer-readable storage medium of claim 10 , wherein the attack comprises replaying a previously recorded output of the cyber-physical system.

12. The non-transitory computer-readable storage medium of claim 10 , wherein determining the first and second sets of values further comprises:

enhancing a set of predetermined values of the first set of parameters based on the initial set of values of the second set of parameters to generate the first set of values; and

enhancing the initial set of values of the second set of parameters based on the first set of values to generate the second set of values.

13. The non-transitory computer-readable storage medium of claim 12 , wherein enhancing a respective set of values further comprises iterating the enhancement until a convergence is reached.

14. The non-transitory computer-readable storage medium of claim 12 , wherein the generation of the first set of values corresponds to a performance metric for the cyber-physical system; and

wherein the generation of the second set of values corresponds to a detection rate for the attack.

15. The non-transitory computer-readable storage medium of claim 10 , wherein determining the first and second sets of values further comprises:

identifying the first set of values of the first set of parameters based on the initial set of values of the second set of parameters, wherein the first set of values is associated with the controller existing in the cyber-physical system; and

enhancing the initial set of values of the second set of parameters based on the identified first set of values to generate the second set of values.

16. The non-transitory computer-readable storage medium of claim 10 , wherein the state manager includes a Kalman filter for determining the states of the cyber-physical system.

17. The non-transitory computer-readable storage medium of claim 10 , wherein the detector includes a chi-square detector for detecting the attack.

18. The non-transitory computer-readable storage medium of claim 10 , further comprising bounding the first set of values of the first set of parameters to a norm indicating that the controller is a stable dynamic feedback controller.

19. A computer system, comprising:

a storage device;

a processor;

a non-transitory computer-readable storage medium storing instructions, which when executed by the processor causes the processor to perform a method for co-designing a controller and a watermarking signal for a cyber-physical system, the method comprising:

determining a first set of values of a first set of parameters indicating operations of the controller based on an initial set of values of a second set of parameters representing the watermarking signal, wherein the watermarking signal is a type of signal combinable with a control signal from the controller for monitoring an output signal of the cyber-physical system for detecting malicious data at a plurality of time instances;

determining a second set of values of the second set of parameters based on the first set of values;

determining a state manager based on the first and second sets of values, wherein the state manager determines states of the cyber-physical system from the monitored output signal; and

determining a detector capable of identifying presence of an attack from the states of the cyber-physical system at the plurality of time instances using the watermarking signal.

20. The computer system of claim 19 , wherein determining the first and second sets of values further comprises:

enhancing a set of predetermined values of the first set of parameters based on the initial set of values of the second set of parameters to generate the first set of values; and

enhancing the initial set of values of the second set of parameters based on the first set of values to generate the second set of values.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2026
From: XEROX CORPORATION
To: GENESEE VALLEY INNOVATIONS, LLC
Reel/Frame 075020/0755 →
SECOND LIEN NOTES PATENT SECURITY AGREEMENT Recorded Jul 2, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 071785/0550 →
FIRST LIEN NOTES PATENT SECURITY AGREEMENT Recorded Apr 11, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 070824/0001 →
SECURITY INTEREST Recorded Feb 13, 2024
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066741/0001 →
SECURITY INTEREST Recorded Nov 20, 2023
From: XEROX CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 065628/0019 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVAL OF US PATENTS 9356603, 10026651, 10626048 AND INCLUSION OF US PATENT 7167871 PREVIOUSLY RECORDED ON REEL 064038 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 28, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064161/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064038/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2022
From: GOYAL, RAMAN; SOMARAKIS, CHRISTOFOROS; NOORANI, ERFAUN; FELDMAN, ALEKSANDAR B.; RANE, SHANTANU
To: PALO ALTO RESEARCH CENTER INCORPORATED
Reel/Frame 061050/0756 →
Continuity (1)
Related Publication 20240080325A1 · Mar 7, 2024
References Cited (13)
US 7523311B1 · Matsui · 2009 [cited by examiner]
US 8249350B2 · Voloshynovskyy · 2012 [cited by examiner]
US 8667275B2 · Rhoads · 2014 [cited by examiner]
US 9087377B2 · Hernandez-Avalos · 2015 [cited by examiner]
US 10826932B2 · Abbaszadeh · 2020 [cited by examiner]
US 11159540B2 · Abbaszadeh · 2021 [cited by examiner]
US 11361055B1 · Levacher · 2022 [cited by examiner]
US 20020078359A1 · Seok · 2002 [cited by examiner]
US 20060031938A1 · Choi · 2006 [cited by examiner]
US 20070300308A1 · Mishura · 2007 [cited by examiner]
US 20130117570A1 · Petrovic · 2013 [cited by examiner]
US 20220217159A1 · Ito · 2022 [cited by examiner]
Pranatyasto, Toto Nugroho, and S. Joe Qin “Sensor Validation and process fault diagnosis for FCC units under MPC Feedback” Control Engineering Practice 9.8 (2001): 877-888, (Year: 2001). [cited by applicant]