As Moore's law approaches its fundamental physical and economic limits, the semiconductor industry faces unprecedented challenges in maintaining performance growth. This study presents the revolutionary evolution from software-defined interconnect (SDI) to software-defined system-on-wafer (SDSoW), a paradigm-shifting architectural approach that transcends traditional scaling constraints through wafer-level heterogeneous integration. Our proposed SDSoW enables dynamic reconfiguration of thousands of computing chiplets across an entire wafer, achieving superlinear performance scaling and significantly improving energy efficiency. We establish a comprehensive theoretical framework with mathematical models covering key aspects, such as interconnect flexibility and integration scaling, and propose an application-driven dynamic architecture reconfiguration (ADR) paradigm that optimizes wafer-scale resources in real time and may foster emergent intelligence in large, heterogeneous systems. Simulation results (128-1024 nodes) demonstrate that SDSoW outperforms conventional multi-chip systems, delivering approximately 3.73 & times;-4.39 & times; higher throughput, 79.2% lower latency, and 2.8 & times; higher power efficiency. As a paradigm shift comparable to the invention of integrated circuits (ICs), it provides a viable pathway beyond Moore's law through innovative architectural design rather than process scaling.
Existing PLC security solutions face a fundamental conflict between stringent real-time requirements and robust protection: traditional IT security mechanisms (e.g., encryption, authentication) introduce unacceptable latency, while software-based redundancy schemes operate at millisecond scale and remain vulnerable to common-cause failures. To bridge this gap, this study proposes MimicPLC v1.0, a dynamic defense mechanism based on a heterogeneous multi-core architecture that integrates threat perception, dynamic fault tolerance, and rapid recovery within a single chip, thereby reconciling real-time determinism with proactive security in industrial control systems. The architecture integrates three distinct CPU cores (MIPS, ARM, and RISC-V) within a single system-on-chip (ESC0830), coordinated by a dedicated hardware-based mimic scheduling subsystem. This subsystem performs real-time, loosely coupled, transaction-level consistency checks on the AHB-Lite bus operations of the heterogeneous processors, achieving nanosecond-scale arbitration latency for threat detection. We evaluate the proposed design using an industrial-strength testbed, incorporating a custom development board and the Synopsys Verdi simulation environment, under critical attack scenarios including Denial-of-Service (DoS), replay, code injection, and parameter overwrite attacks. The system maintains continuous operation through adaptive redundancy, demonstrating attack perception within 73 clock cycles and leveraging instruction-set asymmetry for effective threat containment. Rigorous validation, including 100 consecutive parameter override attacks, confirms a 100% interception rate within our tested attack scenarios, with zero false positives observed. The design complies with the IEC 61131-3 real-time standard, exhibiting a worst-case recovery duration of 9.3 ms and a 95% confidence interval for recovery latency of [4.0354, 4.0363] ms. This work pioneers a paradigm of rapid-detection endogenous security with nanosecond-scale arbitration for next-generation industrial control systems.
The robustness of Internet of Things (IoT) communication topologies against internal failures and external perturbations is a fundamental prerequisite for maintaining system stability. This paper studies IoT topology robustness from two perspectives: robustness metric and optimization. Existing robustness metrics, primarily based on the maximum connected subgraph, neglect contributions from other connected subgraphs, thereby inadequately capturing dynamic topological changes. To address this issue, we propose a robustness metric based on topology data reachability, which sensitively reflects the data transmission capability of an IoT topology under arbitrary perturbations. Regarding robustness optimization, most existing methods adopt centralized strategies that rely on global information, resulting in inefficiencies and limited adaptability in decentralized IoT environments. We propose DecTRO, a Decentralized Topology Robustness Optimization method for IoT via multi-agent graph reinforcement learning. To mitigate partial observability, DecTRO employs a scalable graph attention network enhanced with multi-modal sampling, which aggregates cross-agent information and captures spatiotemporal correlations. Furthermore, a topology robustness-oriented node sampling method is introduced to reduce action-space complexity and accelerate convergence, while a decentralized heuristic reward function enables efficient online decentralized learning. Experimental results show that DecTRO achieves up to two orders of magnitude (5–125×) greater improvement in robustness per unit time compared with state-of-the-art baselines, striking a favorable balance between robustness enhancement and computational efficiency.
Efficient information infrastructure services are realized through the intelligent collaborative scheduling of cloud and network resources in cloud-network convergence. However, security issues such as blurred security boundaries and dynamic policy changes are also introduced. The traditional boundaries between internal and external networks are broken by the security architecture based on the zero trust concept, and security threats in the cloud-network environment can be effectively addressed. First, the research progress of cloud-network convergence was systematically reviewed, and the security risks in this scenario were analyzed in depth. Secondly, aiming at the security requirements, the protection advantages of the zero trust mechanism in this scenario were clarified, and the security concept, key technologies, and core architecture of zero trust were discussed. Subsequently, the importance and implementation paths of introducing the zero trust security protection mechanism in the cloud-network convergence scenario were explored. Finally, the challenges faced by the research on zero trust security in cloud-network convergence are summarized, and future development directions are prospected.
Deep Packet Inspection (DPI) faces significant bottlenecks in regular expression (regex) matching due to escalating rule complexity and traffic volume. Existing FPGA-based solutions inefficiently process all packets through every automaton, incurring substantial resource overhead. This article proposes OD-REM, an on-demand regex matching architecture for FPGAs that dramatically improves efficiency. In addition to this novel architecture, OD-REM also introduces three innovations: (1) A Counter-Enabled Fast Reconfigurable Automaton (cFRA) compresses regex states by 97.5% via counting semantics, eliminating state explosion for bounded repetitions; (2) A Ring Queue (RQ) scheduler dynamically dispatches packets only to automata relevant to their candidate rules (identified via pre-filtering); (3) A modular pipeline for per-packet, on-chip run-time reconfiguration. Implemented on a Xilinx VU9P FPGA with 32 parallel cFRAs, OD-REM achieves 41.18 Gbps throughput-roughly 3 & times; to 40 & times; higher than the similar works while still performing a full reconfiguration on every packet. It reduces packet latency by 3.73 & micro;s versus sliding-window scheduling. Integrated with Pigasus, OD-REM offloads complex rules, accelerating Hyperscan software matching by up to 37 & times;. This work demonstrates FPGA-centric regex matching as a scalable, high-throughput solution for modern DPI systems.
Fault-tolerant systems are crucial for ensuring the reliability and availability of mission-critical applications in modern computing environments. The dynamic heterogeneous redundancy (DHR) architecture is a key component in constructing fault-tolerant systems, particularly in areas such as national security, power networks, and banking private networks. DHR is transforming the cyberspace security industry chain by accommodating a broader range of applications and increasingly capturing the market. However, the development of applications for DHR architecture encounters challenges due to the complexities of handling heterogeneity, managing dynamism, and maintaining usability. To address these issues, we introduce MimicStudio, a comprehensive development framework with a standardized workflow. To our knowledge, MimicStudio is the first effective solution for DHR software development. We present a detailed implementation of MimicStudio with a heterogeneous microcontroller unit project, encompassing three CPUs with different instruction set architectures. The paper evaluates MimicStudio's support for essential features, including zero-copy synchronization, parallelized build, multi-core collaborative debugging, and dynamic adjustment of the software system's structure. Our results show that MimicStudio provides a flexible and efficient solution for supporting the dynamic, heterogeneous, and redundant features of fault-tolerant systems.
Nowadays, the world is embarking on a process of transformation in the underlying dynamics of the digital ecosystem. With the aim of mitigating systematic cyber risks and reshaping the global competition landscape of digital industries, the developed countries are pushing the paradigm shift in the underlying dynamics of the digital ecosystems. Thorough research on this subject holds immense significance for boosting China's strength in cyber, digital, and intelligent development. Focusing on major developed countries, this study integrates literature reviews, intelligence analysis, and comparison study to investigate the essence, driving factors, primary objectives, and outlook of this shift. Drawing upon the fundamental principles of a paradigm shift, the study explores the core features of this underlying-dynamics shift, spanning aspects like mindset, methodology, practical norms, advancement strategies, security commitments, and ecological incubation models. Additionally, it delineates emerging trends, technological frameworks, and associated governance principles related to this paradigm shift. Challenges faced by developed countries' transformation strategies are discussed, along with the enabling advantages of China's endogenous security and safety (ESS) theory. The research puts forward five recommendations: (1) leveraging the first-mover advantage of the ESS theory to overcome limitations; (2) addressing pain points in critical areas of digital transformation; (3) maximizing the advantages of the large-scale domestic market by introducing more effective industrial policies to bolster novel paradigm shifts; (4) renewing the concept of personal training by cultivating responsible developers with "security-by-design" capabilities; and (5) enhancing the trustworthiness of Chinese digital products through technological innovation, thus facilitating China's Going Global initiative.
Super-converged generative information network (SoGIN) envisions the integration of human-physical and digital networks, with development requirements centered on space-air-ground integration, computing-storage-sensing-intelligence integration, and availability-reliability-trustworthiness integration. Following the new development paradigm of decoupling network support environments from application network systems, SoGIN would build an AI-empowered, highly integrated, efficiently collaborative, trustworthy intelligent information network system based on the deep integration of digital-operation-information-communication technology (DOICT). This provides the foundational support environment for realizing 6G visions. This paper discusses the challenges and fundamental theoretical issues faced by SoGIN. Firstly, the development vision and demands of SoGIN are elaborated. Then, the theoretical and technical challenges in achieving the vision of SoGIN are analyzed. Finally, related theoretical and technical practices about polymorphic network environments, cloud-native-based super-converged network infrastructures, new cybersecurity paradigm, cyberspace resilience empowered by endogenous security and safety (ESS), and the physical foundation of next-generation digital systems technology based on wafer-level computing are described.
Network failures, whether due to random disruptions or malicious attacks, pose significant challenges for uncrewed aerial vehicle (UAV) swarm networks. One critical concern is determining which failed UAVs to recover or replace under limited resource conditions to enhance the robustness of their communication networks. Current research primarily considers static structural characteristics of the network and struggles to uncover deep features that influence network robustness, and the efficiency cannot meet the real-time needs in UAV swarm scenarios. To address these issues, we introduce a Prioritized Recovery strategy for failed nodes based on graph reinforcement learning (PRGRL). This approach integrates a random SAmpling neighbor method with a multihead attention mechanism to create a novel graph convolutional kernel (SAGCK). This kernel is designed to extract global structural information and relative positional information of nodes within the graph. Additionally, we develop a deep policy network (DPN) that explores the intricate relationships between graph-level and node embedding features, enabling the assessment of nodes' impact on overall robustness. PRGRL's network parameters are automatically updated and optimized using scalable deep reinforcement learning. Importantly, PRGRL prioritizes the recovery of boundary nodes within connected components to enhance network robustness further. Our experiments, conducted on both simulated and real-world networks, demonstrate that PRGRL outperforms existing methods of robustness enhancement across various recovery ratios, attack strategies, and network sizes while delivering superior real-time performance.
A polymorphic network provides a unified architecture to deploy multiple network protocols. Various network protocols are complemented to accommodate diverse network services. However, conventional implementation strategies relying on naive protocol stacking or virtualization-based deployment have led to uncontrolled network complexity, making it increasingly difficult to support diversified and personalized application demands. This article proposes DEEP, a system that enables multi-protocol deployment with two major goals: performance isolation and unified resource allocation. For performance isolation, DEEP constructs a two-level programmable packet scheduler, providing fine-grained traffic management for various network protocols. It achieves the quality of service (QoS) assurance of multi-protocol in a unified network infrastructure. For unified resource allocation, DEEP prices heterogeneous resources according to QoS requirements of services, realizing dynamic adaptation from heterogeneous resources to network protocols. Finally, we implement DEEP on the polymorphic network devices. The evaluation indicates that DEEP achieves isolation among protocols and high resource utilization for multi-protocol deployment.
Intelligent connected vehicles(ICVs)are a new type of cyber-physical systems;consequently,they encounter safety issues related to software and hardware failures.Additionally,they encounter security issues related to cyberattacks,and emerging safety-security(S&S)issues arising from the interaction of the above factors.Developing a resilient S&S technology system that is reliable and trustworthy,and enables ICVs to prevent,withstand,recover,and adapt to these challenges is highly important in the automotive industry.To achieve this objective,we propose a resilient technology framework for ICVs empowered by endogenous security & safety.Initially,we consider the advanced driving assistance system(ADAS),which is a key system in ICVs,and propose a resilience improvement method based on a dynamic heterogeneous redundancy(DHR)architecture.Next,we propose a resilience quantitative evaluation method based on system-theoretical process analysis for safety and security(STPA-safesec)as well as Bayesian networks.The resilience effectiveness of the proposed DHR-based ADAS is verified by conducting real vehicle testing and model-based evaluation.Based on the above,we further propose a systematic resilience engineering solution for the entire vehicle intelligent network system and verify its effectiveness in dealing with different types of vulnerabilities.
Various network protocols and technologies are complemented to accommodate diverse and indeterministic network services, and advances in programmable switches allow network administrators to develop these emerging protocols. However, the increasing demand for the number and length of match fields and the action types of diverse network protocols exacerbates the storage pressure on storage chips, such as Ternary Content Addressable Memory (TCAM), which significantly increases the implementation complexity. The existing flow table compression algorithms for the single protocol network scenario are not applicable to multi-protocol network scenario owing to two key issues: (1) the increase in match fields causes an increase in the storage width of the flow table rules, which puts pressure on the TCAM resource capacity and has a high implementation complexity; (2) the storage sharing of flow table between different protocols will cause semantic ambiguity between match fields, resulting in incorrect action matching. To support multi-protocol flow tables and improve hardware resource utilization, we propose MP-Cos, an efficient storage compression and optimization scheme that supports multi-protocol flow tables, and design a match field trimming algorithm based on statistical features to support the field splitting within a single protocol; We also design a dynamic protocol field mapping mechanism to optimize the field merging between different protocols. MP-Cos not only facilitates the sharing of flow table storage among different protocol fields but also addresses the serious resource storage consumption caused by the scale of flow tables in multi-protocol network scenarios.
The security of information transmission and processing due to unknown vulnerabilities and backdoors in cyberspace is becoming increasingly problematic. However, there is a lack of effective theory to mathematically demonstrate the security of information transmission and processing under nonrandom noise (or vulnerability backdoor attack) conditions in cyberspace. This paper first proposes a security model for cyberspace information transmission and processing channels based on error correction coding theory. First, we analyze the fault tolerance and non-randomness problem of Dynamic Heterogeneous Redundancy (DHR) structured information transmission and processing channel under the condition of non-random noise or attacks. Secondly, we use a mathematical statistical method to demonstrate that for non-random noise (or attacks) on discrete memory channels, there exists a DHR-structured channel and coding scheme that enables the average system error probability to be arbitrarily small. Finally, to construct suitable coding and heterogeneous channels, we take Turbo code as an example and simulate the effects of different heterogeneity, redundancy, output vector length, verdict algorithm and dynamism on the system, which is an important guidance for theory and engineering practice.
Fault-tolerant technology is becoming increasingly critical due to the growing complexity of computing systems and escalating demands for reliability. Conventional recovery mechanisms in asymmetric multiprocessor systems often incur substantial overhead or exhibit inefficiencies, such as prolonged rollback latency and complex synchronization protocols. This paper introduces an adaptive fast recovery scheme based on checkpoints that minimizes reliance on rollback by prioritizing roll-forward execution where feasible, while retaining rollback capabilities for severe failures. Using a triple modular redundancy system as a case study, we comprehensively detail the proposed scheme’s operation. By modeling fault occurrences via a Poisson process, we theoretically analyze the performance of conventional rollback algorithms against the proposed strategy. The scheme is implemented on an FPGA platform with heterogeneous processors (ARM, MIPS, and RISC-V), demonstrating practical synchronization across diverse architectures. Experimental results demonstrate that our scheme achieves over 10% reduction in average execution time compared to traditional rollback methods, thereby providing an efficient and hardware-validated fault-tolerant solution for advanced multiprocessor systems.
Aiming at the problem of image classification with insignificant morphological structural features, strong target correlation, and low signal-to-noise ratio, combined with prior feature knowledge embedding, a deep learning method based on ResNet and Radial Basis Probabilistic Neural Network (RBPNN) is proposed model. Taking ResNet50 as a visual modeling network, it uses feature pyramid and self-attention mechanism to extract appearance and semantic features of images at multiple scales, and associate and enhance local and global features. Taking into account the diversity of category features, channel cosine similarity attention and dynamic C-means clustering algorithms are used to select representative sample features in different category of sample subsets to implicitly express prior category feature knowledge, and use them as the kernel centers of radial basis probability neurons (RBPN) to realize the embedding of diverse prior feature knowledge. In the RBPNN pattern aggregation layer, the outputs of RBPN are selectively summed according to the category of the kernel center, that is, the subcategory features are combined into category features, and finally the image classification is implemented based on Softmax. The functional module of the proposed method is designed specifically for image characteristics, which can highlight the significance of local and structural features of the image, form a non-convex decision-making area, and reduce the requirements for the completeness of the sample set. Applying the proposed method to medical image classification, experiments were conducted based on the brain tumor MRI image classification public dataset and the actual cardiac ultrasound image dataset, and the accuracy rate reached 85.82% and 83.92% respectively. Compared with the three mainstream image classification models, the performance indicators of this method have been significantly improved.
The question of whether an ideal network exists with global scalability in its full life cycle has always been a first-principles problem in the research of network systems and architectures. Thus far, it has not been possible to scientifically practice the design criteria of an ideal network in a unimorphic network system, making it difficult to adapt to known services with clear application scenarios while supporting the ever-growing future services with unexpected characteristics. Here, we theoretically prove that no unimorphic network system can simultaneously meet the scalability requirement in a full cycle in three dimensions—the service-level agreement (S), multiplexity (M), and variousness (V)—which we name as the “impossible SMV triangle” dilemma. It is only by transforming the current network development paradigm that the contradiction between global scalability and a unified network infrastructure can be resolved from the perspectives of thinking, methodology, and practice norms. In this paper, we propose a theoretical framework called the polymorphic network environment (PNE), the first principle of which is to separate or decouple application network systems from the infrastructure environment and, under the given resource conditions, use core technologies such as the elementization of network baselines, the dynamic aggregation of resources, and collaborative software and hardware arrangements to generate the capability of the “network of networks.” This makes it possible to construct an ideal network system that is designed for change and capable of symbiosis and coexistence with the generative network morpha in the spatiotemporal dimensions. An environment test for principle verification shows that the generated representative application network modalities can not only coexist without mutual influence but also independently match well-defined multimedia services or custom services under the constraints of technical and economic indicators.