scieee Science in your language
[en] (orig)

An encrypted model predictive control strategy for resilience operations

Abstract

In this paper, a resilient model predictive control architecture is proposed for constrained cloud-based networked control systems subject to false data injections on both the controller-to-actuator and sensor-to-controller channels. The basic idea consists in exploiting the capability of the encryption process to hide the data structure, shared between the controller and plant sides, to any third-party. Then, by adequately coupling the latter with the resilient nature of the receding horizon control philosophy, an array of attack countermeasures is determined for the on-line operations. Besides this, in order to secure data packet transmissions, cloud computing operations are performed by adopting an additive homomorphic cryptosys-tern so that encrypted model predictive control sequences are obtained. Finally, a platoon of vehicles is used to validate the whole architecture in simulation.

Read accessible full text

An encrypted model predictive control strategy for resilience operations

Author: Franzè, Giuseppe,Puig Cayuela, Vicenç,Tedesco, Francesco
Year: 2024
DOI: 10.23919/ACC60939.2024.10644708
Source: https://upcommons.upc.edu/bitstream/2117/427887/1/Franze%20ACC%202024.pdf
An enc yp ed model p edic i e con ol s a egy o esilience ope a ions
Giuseppe F anz`
eSenio Membe , IEEE, Vicenc¸ Puig and F ancesco Tedesco Senio Membe , IEEE
Abs ac — In his pape , a esilien model p edic i e con ol
a chi ec u e is p oposed o cons ained cloud-based ne wo ked
con ol sys ems subjec o alse da a injec ions on bo h he
con olle - o-ac ua o and senso - o-con olle channels. The
basic idea consis s in exploi ing he capabili y o he enc yp ion
p ocess o hide he da a s uc u e, sha ed be ween he con olle
and plan sides, o any hi d-pa y. Then, by adequa ely
coupling he la e wi h he esilien na u e o he eceding
ho izon con ol philosophy, an a ay o a ack coun e measu es
is de e mined o he on-line ope a ions. Besides his, in o de o
secu e da a packe ansmissions, cloud compu ing ope a ions
a e pe o med by adop ing an addi i e homomo phic c yp osys-
em so ha enc yp ed model p edic i e con ol sequences a e
ob ained. Finally, a pla oon o ehicles is used o alida e he
whole a chi ec u e in simula ion.
I. INTRODUCTION
In ecen yea s, ad ancemen s in In e ne o Things
(IoT), Cybe -Physical Sys ems (CPSs), and sma g ids ha e
opened doo s o deploymen lexibili y and e iciency im-
p o emen s ac oss a ious ields. Howe e , his p og ess has
heigh ened he demand o sophis ica ed con ol a chi ec u es
o mee new enginee ing equi emen s. Ne wo ked con ol
sys ems inc easingly ely on cloud and dis ibu ed compu -
ing, whe e da a ulne abili y on cloud se e s is a c i ical
conce n.
Enc yp ed con ol, enabled by homomo phic enc yp ion
(HE) me hods, ensu es con iden iali y o sys em s a es and
con ol ac ions [1]. This app oach is pa icula ly ele an o
cloud-based ne wo ked con ol sys ems, whe e h ea s like
alse da a injec ions and ea esd opping jeopa dize no mal
ope a ions [2].
The concep o using HE o ne wo ked con ol sys-
ems’ p i acy was in oduced in [3], wi h subsequen e-
sea ch explo ing ad anced con ol schemes wi hin enc yp ion
amewo ks [4]. No ably, model p edic i e con ol (MPC)
app oaches ha e gained in e es [5], add essing challenges
such as handling enc yp ed da a o cloud-based sys ems.
This wo k was in pa suppo ed by he esea ch p ojec -
ID:20222N4C8E ”Resilien and Secu e Ne wo ked Mul i ehicle Sys ems
in Ad e sa y En i onmen s” g an ed by he I alian Minis y o Uni e si y
and Resea ch (MUR) wi hin he PRIN 2022 p og am and Eu opean Union
- Nex Gene a ion EU and in pa by he esea ch p ojec - ID:PE00000014
“SEcu i y and RIgh s in he Cybe Space - SERICS” g an ed by he I alian
Minis y o Uni e si y and Resea ch (MUR), and Eu opean Union wi hin
he Nex Gene a ionEU p og am.
Giuseppe F anz`
e is wi h DIMEG, Uni e si `
a della Calab ia,
Via Pie o Bucci, Cubo 42-C, Rende (CS), 87036, ITALY,
[email p o ec ed]
Vicenc¸ Puig is wi h CS2AC Uni e si a Poli ´
ecnica de Ca alunya
(UPC), Rambla San Neb idi, 22, 08222 Te assa and also wi h
CSIC-UPC, Ca e Llo ens A igas, 4-6, 08028 Ba celona, Spain,
[email p o ec ed]
F ancesco Tedesco is wi h DIMES, Uni e si `
a della Calab ia,
Via Pie o Bucci, Cubo 42-C, Rende (CS), 87036, ITALY,
[email p o ec ed]
To deal wi h hese issues, a cloud-based model p edic i e
con ol a chi ec u e is de eloped by in eg a ing in o a no el
esilien amewo k cloud compu ing echnology and homo-
mo phic c yp og aphy. In his con ex , he in oduc ion o
he cloud compu ing on enc yp ed da a has a wo old aim:
p o ec he ansmi ed packe s in e ms o con iden iali y and
educe he chance o in ude s o al e ing hei in eg i y.
F om a con ol poin o iew, his is ansla ed in o de ining
a sequence o se -con ainmen condi ions, complying wi h a
se - heo e ic wo s -case app oach, ha unequi ocally iden i y
any admissible a ack occu ence and p o ide a easible
command inpu a each ime ins an .
A second con ibu ion elies on he cha ac e iza ion o
he compu a ions among enc yp ed da a pe o med on he
cloud. To his end, an ad-hoc a ian o he adi ional MPC
algo i hm is conside ed in [5].
Al hough easible, bo h app oaches p esen he ollowing
weaknesses: he con olle s uc u e mus be a ailable on he
ac ua o side; hey lead o conse a i e con ol ac ions due
o he exploi a ion o a single P oximal G adien Me hod
(PGM) i e a ion [9].
The p oposed scheme subs an ially educes (o e en o e -
comes) hese de imen al e ec s in i ue o he ollowing
easons: 1) he ull con olle s uc u e is no manda o y
on he ac ua o , in ac ew p elimina y in o ma ion a e
exploi ed; 2) con ol pe o mance losses only occu when
enc yp ed ope a ions a e in oked.
PRELIMINARIES AND NOTATION
Th ough his pape , we use he ollowing no a ions.
Le ( +k| ), k( ) = ˆ kbe he k−s eps s a e ahead
p edic ion o a gene ic sys em a iable om onwa d.
De ini ion 1: Gi en he se s A,E ⊂ IRn,A ∼E := {a∈
A:a+e∈ A,∀e∈ E} is he Pon yagin-Minkowski
Di e ence.2
Gi en a symme ic ma ix P∈IRn×n, P > 0 (P≥0)
means ha i is posi i e de ini e (semide ini e).
Homomo phic Enc yp ion [10]
Le IR,ZZ,S,Kp,Ks,Mand Cbe he se o eal
numbe s, in ege s, secu i y pa ame e s, public keys, secu i y
keys, plain ex s (message space), and ciphe ex s. Mo eo e ,
conside he se s ZZ+:= {z∈ZZ |z≥0}and ZZn:= {z∈
ZZ |0≤z≤n}.
Then, a public-key enc yp ion scheme is a iple
(GEN, ENC, DEC)whe e GEN :S → Kp× Ks:k7→
(pk, sk)is a key gene a ion algo i hm, ENC :Kp× M →
C: (pk, m)7→ cis an enc yp ion algo i hm, DEC :
Ks× C → M : (sk, c)7→ mis a dec yp ion algo i hm, kis
he key leng h (secu i y pa ame e ) and (pk, sk) = GEN(k)
a pai o public and sec e keys. The ope a o s ENC and
DEC pe o m componen -wise ac ions on ec o s and ma-
ices. Public-key enc yp ion schemes sa is y he ollowing
p ope y:
P ope y 1 -
DEC(sk, ENC(pk, m)) = m,
∀m∈ M and ∀(pk, sk) = GEN(k)
De ini ion 2: The scheme (GEN, ENC, DEC)is an ad-
di i e homomo phic enc yp ion i DEC(sk, c ⊕c0) = m+
m0,∀m, m0∈ M and c, c0∈ C such ha ENC(pk, m) = m
and ENC(pk, m0) = m0,wi h ⊕:C × C → C a bina y
ope a ion o e C.
The Paille scheme [11] is an addi i e homomo phic enc yp-
ion scheme. As mos o c yp osys ems, i is based on a
subse o in ege s, whose ca dinali y depends on he chosen
key o he enc yp ion. The key gene a ion complies wi h he
ollowing ule:
GEN :k7→ (pk, sk)=(a·b, lcm(a−1, b −1))
whe e aand ba e wo la ge p ime numbe s o he same
leng h, i.e. a, b ∈(2k−1,2k), o some k∈ZZ+,such
ha gcd(ab, (a−1)(b−1)) = 1.No ice ha gcd(·,·)
and lcm(·,·)is he g ea es common di iso and he leas
common mul iple ope a o s, espec i ely.
Fo he enc yp ion o any plain ex m∈ZZpk,a andom
in ege ∈ZZ∗
pk := {m∈ZZpk |gcd(m, pk) = 1}is chosen
and he ciphe ex is ob ained as
ENC : ( , m)7→ c= ((pk + 1)m pk mod pk2)
Con e sely, o any ciphe ex c∈ZZpk2, he co esponding
plain ex esul s om he dec yp ion
DEC : (sk, c)7→ Lpk(csk mod pk2)µmod pk
wi h Lpk(γ) := (γ−1)/pk and µ:= sk −1mod pk he
so-called modula mul iplica i e in e se. I can be shown
ha enc yp ion ollowed by dec yp ion p o ides an in ege
equi alen o he plain ex .
Mo e o mally, o e e y m∈ZZpk one has ha
DEC(ENC(m, )) = m, ∀ ∈ZZ∗
pk .Mo eo e , no ice ha
o e e y m1, m2∈ZZpk such ha m1+m2∈ZZpk, he
ollowing p ope y holds
ENC(m1, )⊕ENC(m2, s) =
ENC(m1, )ENC(m2, s)mod pk2=
ENC(m1+m2, ·s),∀ , s ∈ZZ∗
pk
(1)
Acco ding o (1), a semi-enc yp ed p oduc can be also
compu ed. In ac , o e e y m1, m2∈ZZpk such ha
m1·m2∈ZZpk,one has
m2ENC(m1, s) =ENC(m1, )m2mod pk2
=ENC(m1·m2, m1
),∀ ∈ZZ∗
pk
(2)
II. PROBLEM FORMULATION
Conside he class o Cloud-based Ne wo ked Con ol
Sys ems (Cb-NCS) depic ed in Fig. 1 whose physical plan s
a e desc ibed by he ollowing disc e e- ime linea in a ian
s a e space models:
x( + 1) = Ax( ) + Bu( ) + Bdd( )(3)
P
Ac ua o Senso
Con olle
u( )
x( )
z( )
u( )
c
u( )
a
CLOUD
Fig. 1. Cloud-based ne wo ked con ol sys em subjec o ad e sa y a acks
whe e x( )∈IRnxdeno es he s a e, u( )∈IRnu he
command inpu and d( )∈ D ⊂ IRnx,∀ ∈ZZ+:=
{0,1, . . .},an exogenous dis u bance. Mo eo e , he ollow-
ing cons ain s a e p esc ibed:
u( )∈ U, x( )∈ X (4)
wi h Uand Xcon ex and compac subse s o IRnuand IRnx,
espec i ely, and 0nu∈ U,0nx∈ X.
In he sequel, i is hypo hesized ha plan /con olle ope a-
ions may be comp omised because o he ollowing easons:
•exchanged da a - malicious ex e nal agen s mod-
i y command inpu and senso measu emen s when
sen / ecei e ope a ions a e pe o med h ough a com-
munica ion medium:
- con olle - o-ac ua o link: u( ) := uc( ) + ua( )
- senso - o-con olle link: z( ) := x( ) + xa( )
whe e ua( )∈IRnuand xa( )∈IRnxa e unknown and
unbounded malicious signals, while u( )∈IRnuand
z( )∈IRnxaccoun o he esul ing co up ed con ol
signals and s a e measu emen s, espec i ely.
•cloud laye - s eal hy malwa es (see [12] and e e ences
he ein), in en ionally designed o cause dis up ion o
se e capabili ies, ope a e on he con olle uni by
a wo old ac ion: 1) ea esd opping on he compu ed
con ol inpu s; 2) eco d and eplay ope a ions on he
ansmi ed da a.
Then, he p oblem o be sol ed is s a ed as ollows:
Gi en he Cb-NCS o Fig. 1 desc ibed by (3)-(4) and
subjec o
•FDI a acks on bo h command and measu emen com-
munica ion channels,
•malwa e h ea s on he emo e side,
de elop a con ol a chi ec u e enjoying a ack de ec ion
capabili ies and da a con iden iali y p ope ies, such ha he
esul ing con olle , based on he ully a ailabili y o he s a e
ec o u(·) = g(z(·)), egula es he s a e ajec o y in a
Uni o mly Ul ima e Bounded (UUB) sense [13] despi e any
admissible dis u bance ealiza ion and a ack occu ence.
III. THE PROPOSED SOLUTION:AN OVERVIEW
In he sequel, wo me hodologies a e exploi ed: model p e-
dic i e con ol philosophy and c yp osys ems. In pa icula ,
wo MPC s a egies, namely Nominal-MPC and Resilien -
MPC a e designed o comply wi h esilien asks, while
enc yp ion/dec yp ion ac ions a e pe o med o make sa e
he da a ansmission be ween plan and con olle sides. he
p oposed solu ion is summa ized in he scheme o Fig. 2
and he ea e discussed. The s a ing poin consis s in cha ac-
e izing he emo e side acco ding o enc yp ion/dec yp ion
a gumen s. Speci ically, he equi ed compu a ions usually
pe o med on he so-called Physical Laye a e spli as
ollows:
• he Nominal-MPC con olle is used du ing a ack-
ee condi ions bu pu aside as soon as he a ack is
ecognized, he De ec o and a Con olle Bu e (used
o s o e he las admissible a ack- ee s a e measu e-
men , he ea e deno ed as z−1) in cha ge o e eal he
p esence o a acks;
•a second con olle Resilien -MPC, ac i a ed unde
a ack scena ios, is compu ed on he cloud whe e high
compu a ional esou ces a e a ailable.
No ice ha z−1is cons an ly upda ed du ing he a ack- ee
ope a ions, while, unde an a ack scena io, he las s o ed
da a is used o ini ialize he suppo con olle Resilien -
MPC. Acco ding o his amewo k, enc yp ion/dec yp ion
ope a ions ake place only when a acks a e unde way.
Speci ically he ollowing ac ions a e pe o med on he
emo e side. Du ing he a ack- ee ope a ions (Label No),
he plan Pis exclusi ely egula ed by means o he com-
mand inpu uc( ) ha is ne e enc yp ed. Once he De ec o
e eals he a ack occu ence (Label Yes), he communica ion
medium is no longe eliable and he plan p oceeds in an
open-loop ashion by using i s uc( )(consecu i ely usable
o a ini e numbe o s eps) hen he Nleng h esilien
sequence uMP C ( )as soon as i has been ecei ed.
Since he a ack du a ion is no a-p io i known, a each
N ime s eps uMP C (·)is upda ed in o de o enjoy esilien
capabili ies. He e, his is add essed by mainly ope a ing
on he cloud and by p ese ing he con iden iali y o he
da a sen along he communica ion ne wo k. The la e is
achie ed hanks o enc yp ion/dec yp ion ope a ions o he
s o ed measu emen z−1 ha allows o a oid om one hand
ea esd opping phenomena and om he o he hand, when he
enc yp ed da a [[uMP C ( )]] is ansmi ed, he oppo uni y o
he in ude o p ope ly in e he sha ed in o ma ion.
On he plan side, one has he ollowing easoning. Unde
a ack- ee scena ios, he Sma Dec yp ion ecognizes ha a
single ec o , namely uc( ),has been ecei ed and he e o e
no dec yp ion ope a ions a e equi ed. Then, he Sma Ac u-
a o selec s u eas( ) = u( −1) ( ha is admissible because i
has been designed o be usable o se e al consecu i e ime
ins an s): such an ac ion is manda o y since i is unknown
i he cu en ecei ed inpu u( )has been ins an aneously
modi ied (u( ) = uc( ) + ua( )). Hence, he command u( )
is i s checked by using he win model Σand hen applied
a he nex ime ins an . Con e sely, he Sma Dec yp ion
ac i a es he dec yp ion phase when a sequence o con ol
mo es is ecei ed, while he Sma Ac ua o applies he
same k− h mo e o uMP C ( )bo h o Pand Σ,i.e.,
u( ) = u eas( )=(uM P C ( ))k.
No e ha , wi hin his amewo k, a each ime ins an he
De ec o ecei es he pai (z( ), zΣ( )) in o de o iden i y
he cu en ope a ing condi ion o he plan P, and e en ually
o eco e he a ack- ee mode.
Σ
Sma
Ac ua o Senso
Ac ua o
P
u( )
u ( )
eas
u( -1)
Sma
Dec yp ion
a
u ( )
Nominal-MPC
Con olle
z -1
De ec o
Enc yp ion
Resilien -MPC
Enc yp ed ope a ions
a
x ( )
c
u ( )
[
|
[
|
z -1
z( )
No
Yes
u( )
x( ), x ( )
( )
Σ
z( ), z ( )
( )
Σ
[
|
[
|
MPC
u ( )
Fig. 2. Resilien enc yp ed-based con ol a chi ec u e
IV. DETECTION,COUNTERMEASURES AND ON-LINE
OPERATIONS
Acco ding o he discussion on he a chi ec u e o Fig. 2,
he design o he Nominal-MPC and Resilien -MPC mus
be join ly pe o med in o de o ensu e he easibili y e en-
ion. In he sequel, a se - heo e ic app oach will be pu sued
by exploi ing he a gumen s o [7], [6] and [8] p ope ly
adap ed o he p oposed amewo k. Fi s , an admissible
obus posi i ely in a ian (RPI) egion E0 o he closed-loop
s a e e olu ions (6) is de i ed by conside ing he ollowing
s a e- eedback con ol law
uc( ) = K x( −τ( )) (5)
which sa is ies he p esc ibed cons ain s (4) and ensu es ha
he egula ed s a e ajec o y
x( + 1) = Ax( ) + B K x( −τ( )) + Bdd( )(6)
is UUB i espec i e o any delay occu ence τ( )≤
τmax, τmax ≥1.Then, he uppe bound ¯
Non he con ol
ho izon leng h pe aining o he Resilien -MPC con olle is
gi en by:
¯
N:= max
k{k∈ZZ+|E0∼
k−1
X
i=0
AiBdS 6=∅},(7)
As a consequence, le N≤¯
Nbe gi en, he RPI egion
Ξ0 o he closed-loop s a e e olu ions is de e mined along
he same lines exploi ed o E0wi h
N−1
X
=0
A BdD.Hence,
he sequence o obus one-s ep s a e ahead con ollable se s
{Ξi}is compu ed acco ding o he ollowing ecu sions:
Ξi={x∈IRn:∃u∈ U | Ax +Bu ∈˜
Ξi−1}(8)
wi h
˜
Ξi:=Ξi∼
N−i−1
X
=0
A BdD, i = 1, . . . , N −1,(9)
Con e sely, he sequence {Ei}is compu ed as ollows:
Ei:= {x:∃u∈ U|Ax +Bu +Bdd∈ Ei−1,∀d∈ D
Aτmax x+
τmax−1
X
i=0
Aτmax−1−iBu ∈˜
Ξi−1}
(10)
No ice ha he u he equi emen in (10) imposes ha
he consecu i e applica ion o he command inpu u o
τmax ime ins an s d i es he egula ed s a e ajec o y wi hin
L
[
i=0
Ξi.Then, he ollowing esul s holds ue.
P oposi ion 1: Le x(0) ∈
L
[
i=0
Ξibe an ini ial s a e con-
di ion o he egula ed sys em (3) unde he ac ion o he
Nominal MPC. I a a ce ain ime ins an ˆ
> 0an a ack
is de ec ed, he con olle swi ching Nominal MPC →
Resilien MPC is always iable.
P oo - Omi ed o space easons. 2
Finally, du ing he on-line phase he Nominal MPC and
Resilien MPC command inpu s a e ob ained as ollows.
Gi en a gene ic s a e x∈ Ei( ), he Nominal MPC com-
pu es he admissible con ol ac ion by sol ing he ollowing
op imiza ion p oblem:
uc( ) := a g min Fj( )(x, uc)s. . (11)
Ax +Buc∈ Ei( )−1(12)
whe e Fj( )(x, uc)∈F:= {Fh(x, uc)}
h=1 a se o penaliz-
ing unc ions ha a e andomly chosen a each ime ins an
by he eal- alued unc ion j( ) : ZZ+→ {1, . . . , }.
Con e sely, by assuming ha x∈Ξip ec ⊆ΞL he Resilien
MPC sequence o Ncon ol mo es is ob ained by sol ing
he ollowing con ex op imiza ion p oblem:
min
{˜uk}max
˜xk
N−1
X
k=0 k˜xkk2
Rx+k˜ukk2
Ru(13)
˜xk+1 =A˜xk+B˜uk;(14)
˜x0=x; ˜xN∈Ξ0;(15)
˜uk∈ U,˜xk∈ΞL;k= 0, . . . , N −1(16)
whe e ˜xkis he k−s a e ahead dis u bance- ee p edic ion,
Rx=RT
x≥0and Ru=RT
u>0s a e and inpu shaping
ma ices, espec i ely.
A. Anomaly de ec o
This uni has he aim o check he admissibili y o ans-
mi ed da a z( ), zΣ( ).and z+
Σ( ).Recall ha Σdeno es he
win model o he plan P, z( ) he ecei ed s a e measu e-
men esul ing om he applica ion o he cu en easible
command u eas( )while zΣ( )accoun s o he ou pu o he
applica ion o he inpu u( ) o Σ.Finally z−1is he a ack-
ee measu emen s o ed in he Con olle Bu e which is
possibly upda ed a each ime ins an . By using simila
a gumen s as in [6], he ollowing wo-s eps de ec o comes
ou .
S a ing om he so-called easible measu emen z( ),one
has ha on he con olle side he ollowing logical se -
membe ship condi ions mus be e i ied:
z∈Ξi⇒∃uc∈U such ha ∀d∈ D, Az+Buc∈˜
Ξi−1
he e o e i
z−1∈Ξiand z( )∈Ξj, j > i, (17)
hen an a ack is unde way.
The FDI occu ence can be e ealed by exploi ing he
concep o expec ed one-s ep p edic ion se Z+.Speci ically,
Z+(z−1,u( −1)):=
{z+∈IRn:z+=Az−1+Bu( −1)+Bdd, ∀d∈D} ⊂ Ξi−1
(18)
whe e z−1∈Ξiis he a ailable in o ma ion a he p e ious
ime ins an and u( −1) is he easible, hough no op imal,
command. Then, he ollowing logics comes ou :
D+(z( )) := a ack,i z( )/∈Z+(z−1, u( −1))
no a ack, o he wise (19)
As he measu emen zΣ( )is conce ned, he FDI a ack
de ec ion exac ly ollows he same lines abo e desc ibed, i.e.
zΣ( )in place o z( )in (17). Con e sely, he de ec ion o
FDI occu ences needs a u he condi ion in addi ion o (19).
Since zΣ( ) ep esen s he one-s ep s a e p edic ion unde he
ac ion o u( )and i is equi ed o check i u( )is admissible
o he plan Pa he nex ime ins an + 1, hen one has
o e i y i s se -membe ship o
Z++(z−1,{u( −1), u( −1)}) :=
AZ+(z−1,u( −1))+Bu( −1)+BdD ⊂ Ξi−2(20)
and, as a consequence, he de ec ion logics is
D++(zΣ( )) :=
a ack, i zΣ( )/∈Z++(z−1,{u( −1), u( −1)})
no a ack, o he wise
(21)
Con e sely once he a ack is e ealed, he se -membe ship
es s (17) and (19) will be e alua ed by conside ing he
con ol mo es o uMP C ( )in place o uc( ),i.e.,
u( )←uMP C ( )k
wi h
zΣ( ) = Ax( ) + BuMP C ( )k+Bdd( )(22)
Then, acco ding o he abo e analysis, he ollowing esul
summa izes ha FDIs canno emain inde ini ely s eal hy.
P oposi ion 2: Gi en he Cb-NCS a chi ec u e o Fig. 2,
a se o penalizing unc ions Fand a eal- alued unc ion
j( ).Le uc( )be he nominal command inpu solu ion o he
op imiza ion (11)-(12) and uMP C ( ) he esilien sequence
compu ed by sol ing he SDP (13)-(16). Then, he se -
membe ship logics (17), (19) and (21) always de ec in a
ini e ime FDI a acks.
P oo - Omi ed o space easons.
As he eco e y om he a ack is conce ned, simila a -
gumen s can be exploi ed downline o he applica ion o
uMP C ( ).Le de ec be he de ec ion ime ins an , one has
ha i x(¯
)∈ E ,¯
> de ec , < ide ec ,(23)
wi h ide ec he se -le el complying wi h (17), hen he plan
Pis no longe unde a ack. Then, he ollowing esul holds
ue.
Co olla y 1: I he e exis s a ime ins an ¯
> de ec
sa is ying (23) such ha z(¯
)∈Z+(z−1, u( −1)) wi h z(¯
)
as in (22), hen he NCS o Fig. 2 is a ack- ee.
P oo - I s aigh o wa dly ollows by cons uc ion and
collec ing he abo e de elopmen s. 2
B. On-line ope a ions and coun e measu es
The de elopmen s o he p e ious sec ions a e he e col-
lec ed o desc ibe he modus ope andi o he esilien a chi-
ec u e o Fig. 2.
Wi hou loss o gene ali y, i is assumed ha ini ially he
plan Pis a ack- ee. Du ing his phase, he ea e deno ed
as he nominal mode, he plan is egula ed by exploi ing
uc( ),i.e., he admissibili y o he ecei ed command u( )
is i s checked by (19) and (21), hen i is applied a he
nex ime ins an + 1.This easoning applies un il one
o he logics (17), (19), (21) e eals an a ack occu ence,
namely a de ec >0.As a consequence, he Nominal-MPC
canno be longe upda ed and he ollowing coun e measu e
akes place acco ding o an open-loop ashion. Fi s , he
command u( −1) is consecu i ely e-used o he τmax −1
ime ins an s so ha he esul ing s a e condi ion x( de ec +
τmax −1) ∈SiΞi,as p esc ibed in (10). Hence, he
Resilien -MPC can be ac i a ed and he enc yp ed sequence
[[uMP C ( de ec +τmax )]] compu ed on he basis o he las
s o ed measu emen [[z−1]].This swi ching is iable in i ue
o he ollowing esul .
P oposi ion 3: Le z=Aτmax x+
τmax−1
X
i=0
Aτmax−1−iBuc+
Bdd( ),wi h d( )∈ D,be he τmax− h s a e ahead e olu ion
on he plan side o Fig. 2. Then, he dis u bance- ee
e olu ion ˜zcompu ed on he con olle side
˜z:= Aτmax z−1+
τmax−1
X
i=0
Aτmax−1−iBuc(24)
is an admissible ini ial condi ion o he Resilien -MPC
scheme.
P oo - Omi ed o space easons.
C. S abili y issue
The nex p oposi ion s a es he s abili y p ope y o he
p oposed esilien scheme.
Theo em 1: Le {Ei}L
i=0 and {Ξi}L
i=0 be non-emp y one-
s ep s a e ahead con ollable se amilies and x(0) ∈ EL.
Then, he Cb-NCS a chi ec u e o Fig. 2 ensu es cons ain s
sa is ac ion and UUB o any admissible a ack occu ence
and dis u bance ealiza ion.
P oo - Omi ed o space easons.
V. ENCRYPTED CLOUD COMPUTING
This sec ion is de o ed o desc ibe he enc yp ed op-
e a ions wi hin he Pallie HE c yp osys em o sol e he
op imiza ion (13)-(16). To his end, he i s s ep consis s in
ew i ing (13)-(16) as he ollowing Quad a ic P og amming
(QP) p oblem:
q?(x) := a g min
q∈Q(x) (x, q)(25)
whe e q:= {˜uk}N−1
k=0 ∈IRNm
Q(x) := 


q∈IRNm |∃{˜xk}N−1
k=0 ∈IR(N+1)n
s. .(q,{˜xk}N−1
k=0 ∈IRNn)
sa is ies (14) −(16) wi h ˜x0=x



and (x, q) := 1
2qTHq+xTFTq.In wha ollows, he
me hod in oduced in [4], which exploi s a p ojec ed g adien
scheme (PGS) belonging o he class o p oximal algo i hms
[15], will be used o add essing he op imiza ion (25). In
pa icula , a PGS is ca ied ou by he ollowing ecu sions
qj+1 =p ojQ(x)(qj−α∆q (x, qj))
p ojQ(x)(qj−α(Hqj+Fx)) (26)
wi h p ojQ(·)being he p ojec ion ope a o in o a se Q.
Since he Pallie c yp osys em is no o de -p ese ing, he
p ojec ion canno be pe o med in he enc yp ion domain
as well as he op imal solu ion o (13)-(16). This nume ical
d awback can be o e come by conside ing a single i e a ion
o (26):
˜
q1=q0−α(Hq0+Fx) = (I−αH)q0−αFx (27)
wi h ˜
q1compu ed on he cloud as
[[˜
q1]] = (Ecd∆(I−αH)[[q0]])⊕(Ecd∆(αF)[[x]]) (28)
Finally, he esilien MPC ac ion, compu ed on he ac ua o
side, is:
uMP C ( ) = p ojQ(x)(Dcd∆(˜
q1) := a g min
q∈Q(x)kq−˜
q1k
(29)
VI. SIMULATIONS
Conside a pla oon o wo ehicles wi h pi( ), i( )and
ai( )deno ing posi ion, eloci y and accele a ion o ehicle
Vi( ), espec i ely, and d2( )being hei in e -dis ance. The
con ol objec i e is o ensu e ha he pla oon dynamics
con e ge o an asymp o ically s able equilib ium: all in e -
ehicle dis ance e o s ei( ) := d2, −d2( )con e ge o ze o
wi h d2, = 2[m] he a ge dis ance be ween he ehicles.
To his end he ollowing con ol-o ien ed model has been
de i ed
˙x( )=






0 1 0 0 0
0−1/τ 0 0 0
100−1 0
0 0 0 0 −1
0 0 0 0 −1/τ






x( )+






0 0
1/τ 0
0 0
0 0
0 1/τ






u( )
whe e τ= 0.18s, x( ) = [ 1( ), a1( ), d2( ), 2( ), a2( )]T
and u( ) = [u1( ), u2( )],wi h ui∈ U := [−2,2]m
s2, he
command inpu in cha ge o ac ua e he engine. In u n, his
model can be ecas as (3) by a o wa d Eule disc e iza ion
unde he sampling ime Ts= 0.1s.
In he sequel, he ollowing ope a ing scena io is conside ed:
S a ing om he ini ial condi ions x(0) =
[5.93,14.60,3.20,9.47,1.43]Ti is equi ed ha he
egula ed s a e ajec o y is d i en o he a ge
x = [10,0,2,10,0]Twhile keeping he p esc ibed
cons ain s.
The Nominal-MPC is ini ialized ollowing guidelines om
Sec ions III-IV, gene a ing a sequence o 150 con ollable
se s cen e ed a x wi h a maximum du a ion o 14 s eps. Fo
he cloud in as uc u e, a Resilien -MPC scheme is imple-
men ed based on Sec ions IV and VI, wi h a con ol ho izon
o 46 s eps using PGS wi h s ep size α= 0.01. Enc yp ed
con olle ope a ions a e execu ed using he Py hon lib a y

eclib wi h key sizes o 1024 bi s. Simula ion esul s a e
p esen ed in Figu es 3-6. In an a ack- ee scena io, Figu e 3
demons a es he con e gence o he pla oon unde Nominal-
MPC, eaching he e minal se Ξ0a = 13.5sas expec ed.
In a co e a ack scena io anging om = 4 s o =
9s, he esilien a chi ec u e p omp ly de ec s he a ack a
= 4.4swhen z(4.4) ∈Ξ96 using he D++ de ec o uni
(Figu e 4). Ini ially, he sa e command sequence om he
ac ua o bu e is applied o he nex 1.4s, while he cloud
compu es a new Resilien -MPC sequence o be con eyed in
an enc yp ed o m. Once a ailable, he enc yp ed sequence is
applied o he successi e 4.6s. Despi e a sligh pe o mance
loss, wi h he a ge se Ξ0 eached a = 15 s, he a acke ’s
ac ions a e ende ed ine ec i e due o he use o enc yp ed
da a.
A = 9.2s, when z(9.2) ∈Z+(z(4.4), uMP C (7.6)16),
he eco e y phase is igge ed acco ding o P oposi ion
3, swi ching he De ec o ’s s a us o ”no a ack” and e-
ac i a ing he Nominal-MPC.
0
50
100
150
i( )
0 5 10 15 20
Time [s]
Fig. 3. No a ack scena io: se -membe ship le el o he quan i y x( )−x .
D+
D++
0 5 10 15 20
Time [s]
no a ack
a ack
no a ack
a ack
Fig. 4. De ec o s signals
-3
-2
-1
0
1
ua
(1) ( )
0 5 10 15 20
Time [s]
-3
-2
-1
0
ua
(2) ( )
Fig. 5. Applied inpu : esilien con olle
VII. CONCLUSIONS
In his pape , a no el model p edic i e con ol s a egy
o cons ained cybe -physical sys ems subjec o di e en
classes o a acks has been concei ed. In o de o ake
ad an age o enc yp ion/dec yp ion ea u es and cloud com-
pu ing, he p oposed con olle is de eloped on wo laye s: a
0
50
100
150
i( )
0 5 10 15 20
Time [s]
con eyed
ac ual
3.5 4 4.5
88
90
92
94
96
Fig. 6. Se -membe ship le el o he quan i ies x( )−x (ac ual) and
z( )−x (con eyed): esilien con olle
con olle de o ed o add ess a ack- ee scena io and an en-
c yp ed uni de i ed on he cloud and in cha ge o be esilien
e sus c i ical e en s. In addi ion he cloud-based con olle
has been designed by exploi ing a eal ime PGS whose
enc yp ion has been achie ed h ough a semi-homomo phic
c yp osys em. Finally, a pla oon o ehicles has been used
o alida e he whole a chi ec u e in simula ion.
REFERENCES
[1] P. Paillie ,“Public-key c yp osys ems based on composi e deg ee esid-
uosi y classes,” In P oc. Ad ances C yp ology—EUROCRYPT ’99: In .
Con . Theo y Appl. C yp og . Tech., pp. 223-23, 1999.
[2] W. Lucia, B. Sinopoli and G. F anz`
e, “A se - heo e ic app oach o
secu e and esilien con ol o cybe -physical sys ems subjec o alse
da a injec ion a acks”, IEEE SOSCYPS, pp. 1-5, 2016.
[3] K. Kogiso and T. Fuji a, “Cybe -secu i y enhancemen o ne wo ked
con ol sys ems using homomo phic enc yp ion”, In P oc. IEEE Con .
Decis. Con ol (CDC), 2015, pp. 6836-6843, 2015.
[4] M. Schulze Da up, A. Redde , I. Shames, F. Fa okhi and D. Que edo,
“Towa ds enc yp ed MPC o linea cons ained sys ems”, IEEE
Con ol Sys ems Le e s, Vol. 2, No. 2, pp. 195-200, 2018.
[5] A. M. Nase i, W. Lucia and A. Yousse , “Enc yp ed Cloud-Based Se -
Theo e ic Model P edic i e Con ol”, IEEE Con ol Sys ems Le e s,
Vol. 6, pp. 3032-3037, 2022.
[6] G. F anz`
e, W. Lucia and F. Tedesco,“Resilien model p edic i e con ol
o cons ained cybe -physical sys ems subjec o se e e a acks on he
communica ion channels”, IEEE T ans. on Au o. Con ., Vol. 67, No.
4, pp. 1822-1836, 2022.
[7] G. F anz`
e, F. Tedesco and D. Famula o, “Model p edic i e con ol o
cons ained ne wo ked sys ems subjec o da a losses,” Au oma ica,
Vol. 54, pp. 272–278, 2015.
[8] G. F anz`
e., D. Famula o, W. Lucia, and F.Tedesco, “Cybe –physical
sys ems subjec o alse da a injec ions: A model p edic i e con-
ol amewo k o esilience ope a ions”, Au oma ica, Vol. 152,
pp.110957, 2023.
[9] R. Van Pa ys and G. Pipelee s,“Real- ime p oximal g adien me hod
o linea MPC,” In P oc. ECC 2018, pp. 1142-1147, 2018.
[10] A. Aca , H. Aksu, A. S. Uluagac and M. Con i,“A su ey on ho-
momo phic enc yp ion schemes: Theo y and implemen a ion”, IACM
Compu ing Su eys , Vol. 51, No. 4, pp. 1-35, 2018.
[11] P. Paillie ,“Public-key c yp osys ems based on composi e deg ee esid-
uosi y classes”, In Ad ances in C yp ology - Eu oc yp ’99, Vol. 1592
o Lec u e No es in Compu e S., pp. 223-238, Sp inge , 1999.
[12] E. M. Rudd, A. Rozsa, M. G¨un he , and T. E. Boul ,“A Su ey o
S eal h Malwa e A acks, Mi iga ion Measu es, and S eps Towa d
Au onomous Open Wo ld Solu ions,” IEEE T ans. on In e ne o
Things, Vol. 19, No. 2, pp. 1145-1172, 2017.
[13] F. Blanchini and S. Miani,“Se -Theo e ic Me hods in Con ol”,
Bi k¨
ause , Bos on, 2008.
[14] W. Felle , “An in oduc ion o p obabili y heo y and i s applica ions”,
Vol 2, John Wiley &Sons, 2008.
[15] N. Pa ikh and S. Boyd,“P oximal algo i hms”, Founda ions and T ends
in Op imiza ion, Vol. 1, No. 3, pp. 123-231, 2014.
[16] J. Ploeg, B. T. Scheepe s, E. Van Nunen, N. Van de Wouw, and
H. Nijmeije . “Design and expe imen al e alua ion o coope a i e
adap i e c uise con ol”, 14 h IEEE ITSC, pp 260-265, 2011.