Railway equipment access and data security transmission method and system based on railway private network
Through the combination of railway equipment data transmission module, access module and gateway forwarding service module, combined with the State Secret algorithm and token identity authentication, the compatibility, security and stability problems of railway equipment terminals when connecting to railway dedicated networks are solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510594297.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-08-15
AI Technical Summary
Railway equipment terminals are incompatible, security, stability and reliability when connecting to railway dedicated networks, and are vulnerable to external attacks and interference, resulting in data leakage and transmission interruption.
The railway equipment data transmission module is used for data processing and slicing, the railway equipment data access module is assembled and decrypted, the gateway forwarding service module is encrypted and forwarded, and secure access and data transmission is achieved through railway dedicated network access equipment and SIM cards. Combined with the national secret algorithm and token identity authentication, a full life cycle management system is provided.
It improves the access capability of railway equipment terminals and the security, stability and reliability of data transmission, and enhances communication efficiency and security management capabilities.
Smart Images

Figure CN120498743A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet of Things communication technology, and in particular to a railway equipment access and data security transmission method and system based on a railway dedicated network. Background Art
[0002] In recent years, with the rapid development of Internet of Things (IoT) technology, its application in railway equipment terminal management, monitoring, data collection and transmission has become increasingly widespread. However, due to the wide variety of railway equipment terminals, high data transmission security requirements, and complex operating environments, railway equipment terminal access still has shortcomings in terms of compatibility, security, stability, and reliability. In particular, during data transmission, it is vulnerable to external attacks and interference, leading to data leaks and transmission interruptions.
[0003] Therefore, it is urgent to develop a new type of access equipment and data security transmission method based on the railway dedicated network to improve the adaptability and compatibility of railway equipment terminal access and improve the security, stability and reliability of railway equipment terminal data transmission, which is of great significance. Summary of the Invention
[0004] In order to solve the access adaptation and compatibility problems of the above-mentioned diversified railway equipment terminals in the railway dedicated network, and to ensure the security, stability and reliability of data transmission of railway equipment terminals, a railway equipment access and data security transmission method and system based on the railway dedicated network are provided to address the above-mentioned defects of the existing technology.
[0005] In a first aspect, an embodiment of the present application provides a railway equipment access and data security transmission system based on a railway dedicated network, the system comprising:
[0006] Railway equipment data transmission module: It is set on the railway terminal equipment and is used to process the data to be transmitted by the railway terminal and convert it into a binary array; slice and splice the binary array and upload the sliced data;
[0007] Railway equipment data access module: set in the access service network, used to receive the slice data sent by the railway equipment data transmission module, assemble the slice data into a complete binary array, restore the binary array, and then decompress and decrypt it;
[0008] Gateway forwarding service module: Set up in the railway dedicated network, used to receive the restored railway equipment data sent by the railway equipment data access module, obtain authorization information and carry the authorization token to encrypt and forward the railway equipment data;
[0009] Railway equipment data service receiving module: set on the railway server device, used to receive and decrypt the authorization token verification data sent by the gateway forwarding service module, give the device data receipt, and manage the railway terminal equipment and its data, completing railway equipment access and data security transmission.
[0010] In a specific embodiment of the present invention, the railway equipment data transmission module includes:
[0011] Data processing module: used to encapsulate railway data in a unified railway equipment data packet format, encrypt the unified encapsulated format data using a national encryption algorithm, compress the encrypted data, and convert the compressed data into a binary array. The railway equipment data packet format includes: data packet ID, railway terminal equipment number, railway terminal equipment unit, equipment MAC address, module IMEI number, SIM card number, data timestamp, data packet content, and authorization token;
[0012] Data slicing module: used to slice the converted binary array according to the data length and the preset message length value, and splice the slice data header and slice data tail; wherein, the slice data includes: slice data header, device slice data and slice data check tail; the slice data header includes: communication sequence number, total data packet length, slice sequence number, slice message length, command number, status, manufacturer number and device number;
[0013] Data upload module: used to upload slice data and resend failed data within a preset time.
[0014] In a specific embodiment of the present invention, the railway equipment data access module includes:
[0015] Data receiving module: used to receive slice data, verify the slice data according to the slice data header, and respond to each slice data within a preset time;
[0016] Data assembly module: used to assemble the verified slice data, and assemble the slice data into a complete binary array according to the slice data header;
[0017] Data restoration module: used to restore and decompress the assembled binary array, decrypt it using the corresponding encryption algorithm, and generate restored railway equipment data.
[0018] In a specific embodiment of the present invention, the gateway forwarding service module further performs:
[0019] After obtaining the authorization information, the gateway forwarding service module carries the authorization token and encrypts and forwards the restored railway equipment data; the railway equipment data service receiving module receives the railway equipment data, receives and decrypts the authorization token verification data, and gives the equipment data receipt, and encrypts and compresses the receipt information and returns it.
[0020] In a second aspect, an embodiment of the present application provides an access device based on a railway dedicated network, comprising: a main control module, an encryption and decryption module, an interface module, a railway dedicated network access module, and a device terminal data transmission module;
[0021] The railway dedicated network access module is connected to the internal service network of the railway integrated information network via the railway APN dedicated line;
[0022] The interface module includes multiple interfaces, and the interface module is connected to the railway equipment terminal;
[0023] The encryption and decryption module is connected to the railway dedicated network access module and the interface module to encrypt and decrypt the transmitted data;
[0024] The device terminal data transmission module is connected to the encryption and decryption module for transmitting encrypted and decrypted data;
[0025] The main control module is connected to the railway dedicated network access module, interface module, encryption and decryption module and equipment terminal data transmission module, and is used for the transmission of central control access equipment data.
[0026] In a specific embodiment of the present invention, the above-mentioned SIM card slot is equipped with a railway-oriented 4G / 5G Internet of Things SIM card, and the Internet of Things SIM card is directed to access the railway comprehensive information network through a railway-specific APN channel.
[0027] In a specific embodiment of the present invention, the IMEI number of the access device based on the railway dedicated network, the railway-oriented 4G / 5G Internet of Things SIM card number, and the MAC address of the railway equipment terminal are bound one-to-one.
[0028] In a third aspect, an embodiment of the present application provides a method for railway equipment access and data secure transmission based on a railway dedicated network, using the railway equipment access and data secure transmission system based on a railway dedicated network as described above, the method comprising:
[0029] Railway equipment data transmission steps: using the railway equipment data transmission module to process the data to be transmitted by the railway terminal equipment and convert it into a binary array; slicing and splicing the binary array, and uploading the sliced data;
[0030] Railway equipment data access step: using the railway equipment data access module to receive the slice data sent by the railway equipment data transmission module, assembling the slice data into a complete binary array, restoring the binary array, and then decompressing and decrypting it;
[0031] Gateway forwarding service steps: The gateway forwarding service module receives the restored railway equipment data sent by the railway equipment data access module, obtains the authorization information, and then encrypts and forwards the railway equipment data with the authorization token;
[0032] Railway equipment data service receiving steps: The railway equipment data service receiving module is used to receive and decrypt the authorization token verification data sent by the gateway forwarding service module, give the device data receipt, and complete the railway equipment access and data security transmission.
[0033] In a specific embodiment of the present invention, the railway equipment data transmission step includes:
[0034] Data processing steps: Encapsulate the railway data in a unified railway equipment data packet format, encrypt the unified encapsulated format data using a national encryption algorithm, compress the encrypted data, and convert the compressed data into a binary array;
[0035] Data slicing step: Slice the converted binary array according to the data length and the preset message length value, and splice the slice data header and slice data tail;
[0036] Data upload step: upload the slice data and resend the failed data within the preset time.
[0037] In a specific embodiment of the present invention, the railway equipment data access step includes:
[0038] Data receiving step: receiving slice data, verifying the slice data according to the slice data header, and responding to each slice data within a preset time;
[0039] Data assembly step: assemble the verified slice data and assemble the slice data into a complete binary array according to the slice data header;
[0040] Data restoration steps: restore and decompress the assembled binary array, use the corresponding encryption algorithm to decrypt it, and generate the restored railway equipment data.
[0041] Compared with the related existing technologies, it has the following outstanding beneficial effects:
[0042] 1) The method of the present invention can improve the access capability of railway equipment terminals and meet the needs of diversified railway equipment terminals and complex railway network environments;
[0043] 2) The method of the present invention improves the safety management capability of railway equipment terminals;
[0044] 3) The method of the present invention improves the security, stability and reliability of data transmission of railway equipment terminals;
[0045] 4) The method of the present invention improves the communication efficiency of railway equipment terminals. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0047] Figure 1 This is a schematic diagram of the railway equipment access and data security transmission system of the present invention;
[0048] Figure 2 This is a schematic diagram of a railway equipment access network channel according to an embodiment of the present invention;
[0049] Figure 3 This is a flow chart of railway equipment data access according to an embodiment of the present invention;
[0050] Figure 4 This is a schematic diagram of the railway equipment data format design according to an embodiment of the present invention;
[0051] Figure 5 This is a schematic diagram of railway equipment data packet slicing according to an embodiment of the present invention;
[0052] Figure 6 This is a schematic diagram of the railway equipment access and data security transmission method of the present invention;
[0053] Figure 7 This is a schematic diagram of the access equipment structure based on the railway dedicated network. DETAILED DESCRIPTION
[0054] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0055] It should also be understood that the term "and / or" in this document simply describes an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " in this document generally indicates an "or" relationship between the related objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0056] It should also be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0057] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of the device or unit, which can be electrical, mechanical or other forms.
[0058] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0059] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0060] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0061] To illustrate the above-mentioned features and effects of the present invention more clearly and easily, the following embodiments are specifically described below with reference to the accompanying drawings. This specification discloses one or more embodiments incorporating the features of the present invention. The disclosed embodiments are for illustrative purposes only. The scope of protection of the present invention is not limited to the disclosed embodiments; the present invention is defined by the appended claims.
[0062] The following is a system embodiment corresponding to the above method embodiment. This embodiment can be implemented in conjunction with the above embodiment. The relevant technical details mentioned in the above embodiment are still valid in this embodiment and will not be repeated here to reduce repetition. Accordingly, the relevant technical details mentioned in this embodiment can also be applied to the above embodiment.
[0063] In the description of the present invention, it should be understood that the term "railway equipment terminal" is used to summarize the equipment terminals used in the operation and maintenance of railway units; the term "railway integrated information network" refers to the railway's internal private network; the term "SIM card" stands for Subscriber Identity Module, which is a smart card used to store user contract information in mobile communication networks; the term "IMEI" stands for International Mobile Equipment Identity, which is a unique number used to identify mobile devices; the term "MAC" stands for Media Access Control Address, which is a unique identifier used to identify network devices; the term "APN" stands for Access Point Name, which is a network access technology; the term "SDK" stands for Software Development Kit, which is a software package that provides developers with specific tools, library files, documentation and sample codes so that they can develop applications based on a certain software platform, hardware platform or operating system; the term "UDP" stands for User Datagram Protocol, which is a datagram-oriented transport layer protocol.
[0064] The present invention aims to provide a method for equipment access and data security transmission based on a railway dedicated network, thereby improving the access capability of railway equipment and ensuring the safe, stable, reliable and efficient transmission of railway equipment data.
[0065] The present invention provides an access device and integration solution based on a railway dedicated network. Through multiple interfaces such as USB and serial ports, it is compatible with different types of railway equipment terminals, thereby improving the compatibility of railway equipment terminal access.
[0066] Railway-specific 4G / 5G IoT SIM cards and railway equipment terminals, which are one-to-one bound to access devices based on railway-specific networks, as well as railway-specific APN mobile network access points, ensure the security of railway equipment terminal access;
[0067] Safe railway equipment data transmission methods and stable and reliable communication protocols ensure the security and stability of railway equipment terminal data transmission.
[0068] Railway equipment terminal data transmission SDK compatible with mainstream domestic operating systems, Windows, Linux, and Android operating systems, improving the compatibility of railway equipment terminal data transmission;
[0069] A full life cycle security management system for access equipment and railway equipment terminals based on railway dedicated networks improves the security management capabilities of railway equipment terminals.
[0070] Specifically, such as Figure 1 As shown, Figure 1 This is a schematic diagram of a railway equipment access and data security transmission system. This embodiment of the application provides a railway equipment access and data security transmission system based on a railway dedicated network, the system comprising:
[0071] Railway equipment data transmission module 101: is set on the railway terminal equipment, and is used to process the data to be transmitted by the railway terminal and convert it into a binary array; slice and splice the binary array, and upload the sliced data;
[0072] Railway equipment data access module 102: set in the access service network, used to receive the slice data sent by the railway equipment data transmission module, assemble the slice data into a complete binary array, restore the binary array, and then decompress and decrypt it;
[0073] Gateway forwarding service module 103: set in the railway dedicated network, used to receive the restored railway equipment data sent by the railway equipment data access module, obtain authorization information and carry the authorization token to encrypt and forward the railway equipment data;
[0074] Railway equipment data service receiving module 104: set on the railway server device, used to receive and decrypt the authorization token verification data sent by the gateway forwarding service module, give the device data receipt, and manage the railway terminal equipment and its data, completing railway equipment access and data security transmission.
[0075] In a specific embodiment of the present invention, the railway equipment data transmission module 101 includes:
[0076] Data processing module: used to encapsulate railway data in a unified railway equipment data packet format, encrypt the unified encapsulated format data using a national encryption algorithm, compress the encrypted data, and convert the compressed data into a binary array. The railway equipment data packet format includes: data packet ID, railway terminal equipment number, railway terminal equipment unit, equipment MAC address, module IMEI number, SIM card number, data timestamp, data packet content, and authorization token;
[0077] Data slicing module: used to slice the converted binary array according to the data length and the preset message length value, and splice the slice data header and slice data tail; wherein, the slice data includes: slice data header, device slice data and slice data check tail; the slice data header includes: communication sequence number, total data packet length, slice sequence number, slice message length, command number, status, manufacturer number and device number;
[0078] Data upload module: used to upload slice data and resend failed data within a preset time.
[0079] In a specific embodiment of the present invention, the railway equipment data access module 102 includes:
[0080] Data receiving module: used to receive slice data, verify the slice data according to the slice data header, and respond to each slice data within a preset time;
[0081] Data assembly module: used to assemble the verified slice data, and assemble the slice data into a complete binary array according to the slice data header;
[0082] Data restoration module: used to restore and decompress the assembled binary array, decrypt it using the corresponding encryption algorithm, and generate restored railway equipment data.
[0083] In a specific embodiment of the present invention, the gateway forwarding service module 103 further performs:
[0084] After obtaining the authorization information, the gateway forwarding service module carries the authorization token and encrypts and forwards the restored railway equipment data; the railway equipment data service receiving module receives the railway equipment data, receives and decrypts the authorization token verification data, and gives the equipment data receipt, and encrypts and compresses the receipt information and returns it.
[0085] More specifically, in a specific embodiment of the present invention, in order to meet the access needs of diverse railway equipment in a complex railway network environment, based on railway network security requirements, through field research, a secure railway equipment access network channel is designed and built, the 4G / 5G Internet of Things communication module structure is selected and optimized, the railway equipment is transformed and upgraded to enable it to have mobile network access capabilities, and a safe, stable and reliable equipment data transmission SDK program and a supporting railway equipment full life cycle safety management system are packaged and developed to achieve secure access and data transmission of railway equipment.
[0086] Figure 2 FIG1 is a diagram showing the access network architecture of an access device based on a railway dedicated network according to an embodiment of the present invention. Figure 2After installing access equipment based on the railway private network, the railway equipment terminals shown above utilize the mobile operator's network, access the railway integrated information network's external service network through the railway-specific APN channel, and then connect to the railway integrated information network's internal service network through the railway secure access platform. The railway-specific APN logically isolates the network from the public internet, ensuring the security of sensitive data and reducing potential network attack risks. The railway-specific APN provides access control and permission management, ensuring that only authorized devices and users can access the APN network, preventing unauthorized access and potential security threats. Through network isolation, security authentication, and identity verification, the railway-specific APN ensures the security and trustworthiness of communications between access devices based on the railway private network.
[0087] Based on the Railway Comprehensive Information Network, railway equipment has been retrofitted with 4G / 5G IoT communication modules and uses railway-specific IoT SIM cards. These equipment connects to the Railway Comprehensive Information Network's internet access zone via dedicated APN lines, connects to the Railway Comprehensive Information Network's external service network via a gateway server, and then connects to the Railway Comprehensive Information Network's internal service network via a gateway server based on the China Railway Corporation's secure access platform. Secure and effective network firewalls are deployed between the internet access zone and the Railway Comprehensive Information Network's external service network, and between the external service network and the internal service network. Data transmission between the Railway Comprehensive Information Network's external service network access server and the internet access zone's gateway server utilizes encrypted transmission using a national secret algorithm. Data transmission between the Railway Comprehensive Information Network's internal service network gateway server and the external service network gateway server is based on the China Railway Corporation's secure transmission platform, with user authorization and server IP binding mechanisms added. The railway internal service network gateway server utilizes user authorization, server IP binding, and interface service address binding mechanisms for data services provided to railway equipment data servers, ensuring the security of data transmission from railway equipment. The railway comprehensive information network's internal service network gateway server, external service network gateway server, external service network access server, and Internet access zone gateway server are all equipped with hardware load balancing servers and software multi-instance load balancing deployments, independently deploying different types of railway equipment data services to improve the stability and reliability of railway equipment data transmission.
[0088] The 4G / 5G IoT communication module structure is optimized based on the interface and internal space structure of railway equipment. A 4G / 5G IoT communication module that meets the requirements for retrofitting and modification of the internal space of railway equipment and supports USB and 282 / 454 serial ports is provided, enabling railway equipment to have IoT communication capabilities.
[0089] Railway-specific IoT SIM cards connect to the railway integrated information network's internet access zone via a dedicated railway APN access point, prohibiting access to public internet addresses. Railway-specific APNs logically isolate networks from the public internet, ensuring the security of sensitive data and mitigating potential cyberattacks. Railway-specific APNs provide access control and permission management, ensuring only authorized railway equipment and users can access the APN network, preventing unauthorized access and potential security threats. Railway-specific APNs ensure the security and trustworthiness of railway equipment communications through network isolation, security authentication, and identity verification.
[0090] The Railway Equipment Data Transmission Lifecycle Management System, deployed within the internal service network of the Railway Integrated Information Network, implements one-to-one registration, binding, and deregistration of railway equipment MAC addresses, 4G / 5G IoT communication module IMEI serial numbers, and railway-specific IoT SIM card numbers. It also provides authorized access settings for user units, users, and roles to prevent unauthorized access and achieve full lifecycle management of railway equipment, 4G / 5G IoT communication modules, and railway-specific IoT SIM cards. The Railway Equipment Data Transmission Lifecycle Management System, integrated with the Railway Equipment Data Transmission SDK, monitors railway equipment MAC addresses, 4G / 5G IoT communication module IMEI serial numbers, railway-specific IoT SIM card numbers, user units, and authorized users in real time, promptly disconnecting and isolating abnormal data transmission access. The Railway Equipment Data Transmission Lifecycle Management System monitors and records the entire railway equipment data transmission process, providing alarms for data access anomalies and excessive network bandwidth and server performance, improving the ability to handle exceptions in railway equipment data transmission.
[0091] The Railway Equipment Data Transfer SDK provides data transmission services between railway equipment devices and railway equipment data servers. Versions compatible with mainstream domestic operating systems such as Kylin and Tongxin, as well as Windows, Linux, and Android operating systems, are available. This makes it suitable for use cases with a wide range of railway equipment types and operating system versions, enhancing the SDK's compatibility. To meet the stringent requirements for stable and secure railway equipment data transmission, the Railway Equipment Data Transfer SDK encapsulates a dedicated railway equipment data communication protocol based on the UDP protocol. This includes a unified design for railway equipment data formats, encapsulation of sequence numbers, timestamps, encrypted payloads, and authentication, compression and unpacking of uplink and downlink data, and packet validation, timeout, and retransmission mechanisms. This ensures the integrity and accuracy of railway equipment data transmission, enabling efficient transmission and guaranteeing the stability and reliability of railway equipment data transmission. Advanced encryption algorithms such as SM4 and AES, along with end-to-end encryption technologies, encrypt railway equipment data for transmission. Token authentication and anomaly detection mechanisms are introduced to monitor anomalies during device data transmission in real time, enhancing the security of railway equipment data transmission.
[0092] Figure 3 This is the railway equipment data access flow diagram for an embodiment of the present invention. Step 1: The device data transmission SDK encapsulates railway data in a unified format at the railway equipment terminal, encrypts the unified format data using a national encryption algorithm, compresses the encrypted data, and converts the compressed data into a binary array. Step 2: The device data transmission SDK slices the converted binary array according to the data length according to the set value and concatenates the slice data header and slice data footer. Step 3: The device data transmission SDK uploads the sliced data and retransmits failed data within a specified timeframe. Step 4: The data access service receives the sliced data, verifies it based on the slice data header, and responds to each slice within a specified timeframe. Step 5: The data access service assembles the sliced data, concatenating the slice data into a complete binary array based on the slice data header. Step 6: The data access service restores the data, decompresses the restored binary array, and decrypts it using the corresponding encryption algorithm. Step 7: The gateway forwarding service forwards the railway equipment data, obtains authorization information, and then encrypts and forwards the railway equipment data with the authorization token. In step 8, the railway equipment data service receives the equipment data and decrypts the authorization token verification data. In step 9, the railway equipment data service gives the equipment data receipt and returns the receipt information in an encrypted and compressed form.
[0093] Figure 4This is a design diagram for the unified format of railway equipment data in an embodiment of the present invention. The unified packaging of railway equipment data includes the railway equipment data packet unique number, device number, device unit, device MAC address, 4G / 5G IoT communication module IMEI number, railway-specific SIM card number, railway equipment data packet timestamp, authorization verification token information, and railway equipment data packet content.
[0094] Figure 5 This figure shows a schematic diagram of railway equipment data packet slicing according to an embodiment of the present invention. The railway equipment data packet is sliced according to the slice length setting based on the railway equipment data packet size, and a slice data header and slice data trailer are added to each slice. The slice data header is used to verify and splice the railway equipment data slices and includes the railway equipment data packet communication sequence number, total packet length, slice sequence number, slice message length, command number, status, vendor number, and device number; the slice data trailer is used to verify the integrity of the slice data.
[0095] Example 2
[0096] like Figure 6 As shown, an embodiment of the present application provides a method for railway equipment access and data security transmission based on a railway dedicated network, using the railway equipment access and data security transmission system based on a railway dedicated network as described above, the method includes:
[0097] Railway equipment data transmission step 201: using a railway equipment data transmission module to process the data to be transmitted from the railway terminal and convert it into a binary array; slicing and splicing the binary array, and uploading the sliced data;
[0098] Railway equipment data access step 202: using the railway equipment data access module to receive the slice data sent by the railway equipment data transmission module, assembling the slice data into a complete binary array, restoring the binary array, and then decompressing and decrypting it;
[0099] Gateway forwarding service step 203: using the gateway forwarding service module to receive the restored railway equipment data sent by the railway equipment data access module, and after obtaining the authorization information, encrypting and forwarding the railway equipment data with the authorization token;
[0100] Railway equipment data service receiving step 204: The railway equipment data service receiving module is used to receive and decrypt the authorization token verification data sent by the gateway forwarding service module, and a data receipt is given to the device to complete the railway equipment access and data security transmission.
[0101] In a specific embodiment of the present invention, the railway equipment data transmission step 201 includes:
[0102] Data processing steps: Encapsulate the railway data in a unified railway equipment data packet format, encrypt the unified encapsulated format data using a national encryption algorithm, compress the encrypted data, and convert the compressed data into a binary array;
[0103] Data slicing step: Slice the converted binary array according to the data length and the preset message length value, and splice the slice data header and slice data tail;
[0104] Data upload step: upload the slice data and resend the failed data within the preset time.
[0105] In a specific embodiment of the present invention, the railway equipment data access step 202 includes:
[0106] Data receiving step: receiving slice data, verifying the slice data according to the slice data header, and responding to each slice data within a preset time;
[0107] Data assembly step: assemble the verified slice data and assemble the slice data into a complete binary array according to the slice data header;
[0108] Data restoration steps: restore and decompress the assembled binary array, use the corresponding encryption algorithm to decrypt it, and generate the restored railway equipment data.
[0109] Example 3
[0110] like Figure 7 As shown, the present invention provides an access device based on a railway dedicated network, comprising: a main control module 10, an encryption and decryption module 20, an interface module 30, a railway dedicated network access module 40 and a device terminal data transmission module 50;
[0111] The railway dedicated network access module 40 accesses the internal service network of the railway comprehensive information network via the railway APN dedicated line; the interface module 30 includes multiple interfaces, and the interface module 30 is connected to the railway equipment terminal; the encryption and decryption module 20 is connected to the railway dedicated network access module 40 and the interface module 30, and is used for encryption and decryption of transmitted data; the equipment terminal data transmission module 50 is connected to the encryption and decryption module 20, and is used for transmitting encrypted and decrypted data; the main control module 10 is connected to the railway dedicated network access module 40, the interface module 30, the encryption and decryption module 20 and the equipment terminal data transmission module 50, and is used for central control of the transmission of access device data.
[0112] In this embodiment of the present invention, the interface module 30 includes a USB port, a serial port, and a SIM card slot. In this embodiment, the SIM card slot is equipped with a railway-specific 4G / 5G IoT SIM card, which connects to the railway integrated information network via a railway-specific APN channel. In this embodiment, the IMEI of the access device based on the railway-specific network, the railway-specific 4G / 5G IoT SIM card number, and the MAC address of the railway terminal device are bound one-to-one.
[0113] Access devices based on the railway private network are available in USB and serial port versions, and include modules such as a SIM card slot and USB / serial interface. The SIM card slot of the access device based on the railway private network is equipped with a railway-specific 4G / 5G IoT SIM card. This IoT SIM card connects to the railway integrated information network through a railway-specific APN channel and is bound one-to-one with the access device based on the railway private network via the IMEI, improving access security for the access device based on the railway private network.
[0114] Access equipment based on railway dedicated networks is provided with a supporting full-life cycle security management system. The system implements one-to-one registration, binding, and deregistration functions for the IMEI of access equipment based on railway dedicated networks and the MAC address of railway equipment terminals, preventing illegal access and achieving full-life cycle security management of access equipment based on railway dedicated networks and railway equipment terminals.
[0115] In the embodiment of the present invention, the encryption and decryption module 20 includes a token identity authentication and anomaly detection module, and adopts SM4 and AES encryption algorithms and end-to-end encryption technology during data transmission.
[0116] Access equipment based on the railway dedicated network uses advanced encryption algorithms and end-to-end encryption technologies such as SM4 and AES during data transmission, introduces token identity authentication and anomaly detection mechanisms, and monitors anomalies in the data transmission process of device terminals in real time, thereby improving the security of data transmission of railway equipment terminals.
[0117] In the embodiment of the present invention, the terminal data transmission module 50 adopts a data transmission SDK.
[0118] Access devices based on railway-specific networks provide a supporting data transmission SDK for railway equipment terminals or their host computers and industrial computers. This SDK encapsulates the dedicated communication protocol for railway-specific network-based access devices based on the UDP protocol. This SDK includes a unified design for railway equipment terminal data formats, compression and unpacking mechanisms for uplink and downlink data, and packet verification, timeout, and retransmission mechanisms. This ensures the integrity and accuracy of data transmission from railway equipment terminals, enabling efficient data transmission and guaranteeing the stability and reliability of data transmission from railway equipment terminals.
[0119] The access equipment based on the railway dedicated network and its supporting security management system and data transmission SDK are compatible with mainstream domestic operating systems, Windows, Linux and other operating systems, meeting the application requirements of diverse railway equipment terminal operating systems.
[0120] The present invention also provides an access system based on a railway dedicated network, which includes the access equipment based on the railway dedicated network, a dedicated line access server, a firewall and a railway integrated information network as described above.
[0121] In order to meet the access needs of diversified railway equipment terminals in a complex network environment, through field research, for different types of railway equipment terminals, the present invention selects three representative equipment terminals: railway mobile train supply, railway magnetic particle inspection trolley, and railway ultrasonic inspection. The access equipment structure design based on the railway dedicated network is selected and optimized, and the railway equipment terminals are transformed and upgraded to enable the railway equipment terminals to have mobile network access capabilities.
[0122] One specific application scenario of this invention involves upgrading railway magnetic particle inspection vehicles with 282 / 454 serial ports. This involves selecting access equipment based on a dedicated railway network and equipped with 282 / 454 serial ports. Another specific application scenario involves upgrading railway ultrasonic flaw detection equipment, which has a compact internal space and no external interfaces. Based on the internal space structure of the equipment, the design of the access equipment based on the dedicated railway network is optimized, enabling upgrading of the equipment through internal welding.
[0123] In summary, the present invention's method for device access and secure data transmission based on a railway dedicated network improves railway equipment access capabilities, enhances the stability and reliability of railway equipment communications, and enhances the security of railway equipment data transmission through aspects such as railway network access channel design, 4G / 5G Internet of Things communication module optimization, railway-specific SIM card and APN access channel customization, development of a railway equipment full lifecycle safety management system, and railway equipment data transmission SDK program packaging. It has broad application prospects and market value, and will play an important role in railway equipment management, status monitoring, data acquisition and transmission, and other fields.
[0124] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0125] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.
Claims
1. A railway equipment access and data security transmission system based on a railway dedicated network, characterized in that: The system comprises: Railway equipment data transmission module: set on the railway terminal equipment, used to process the data to be transmitted by the railway terminal and convert it into a binary array; slice and splice the binary array, and upload the sliced data; Railway equipment data access module: set in the access service network, used to receive the slice data sent by the railway equipment data transmission module, assemble the slice data into a complete binary array, restore the binary array, and then decompress and decrypt it; Gateway forwarding service module: set in the railway dedicated network, used to receive the restored railway equipment data sent by the railway equipment data access module, obtain authorization information and carry the authorization token to encrypt and forward the railway equipment data; Railway equipment data service receiving module: set on the railway server device, used to receive and decrypt the authorization token verification data sent by the gateway forwarding service module, give the device data receipt, and manage the railway terminal equipment and its data, completing railway equipment access and data security transmission.
2. The railway equipment access and data security transmission system based on the railway dedicated network according to claim 1 is characterized in that: The railway equipment data transmission module includes: Data processing module: used to encapsulate railway data in a unified railway equipment data packet format, encrypt the unified encapsulated format data using a national secret algorithm, compress the encrypted data, and convert the compressed data into a binary array; wherein the railway equipment data packet format includes: data packet ID, railway terminal equipment number, railway terminal equipment unit, equipment MAC address, module IMEI number, SIM card number, data timestamp, data packet content and authorization token; Data slicing module: used to slice the converted binary array according to the data length according to the preset message length value, and splice the slice data header and slice data tail; wherein, the slice data includes: slice data header, device slice data and slice data check tail; the slice data header includes: communication sequence number, total data packet length, slice sequence number, slice message length, command number, status, manufacturer number and device number; Data upload module: used to upload the slice data and resend failed data within a preset time.
3. The railway equipment access and data security transmission system based on the railway dedicated network according to claim 2 is characterized in that: The railway equipment data access module includes: Data receiving module: used for receiving the slice data, verifying the slice data according to the slice data header, and responding to each slice data within a preset time; Data assembly module: used for assembling the verified slice data, and assembling the slice data into a complete binary array according to the slice data header; Data restoration module: used to restore and decompress the assembled binary array, decrypt it using the corresponding encryption algorithm, and generate restored railway equipment data.
4. The railway equipment access and data security transmission system based on a railway dedicated network according to claim 1 is characterized in that: The gateway forwarding service module further performs: After obtaining the authorization information, the gateway forwarding service module carries the authorization token and encrypts and forwards the restored railway equipment data; the railway equipment data service receiving module receives the railway equipment data, receives and decrypts the authorization token verification data, and gives the equipment data receipt, and encrypts and compresses the receipt information and returns it.
5. An access device based on a railway dedicated network, characterized in that: Contains: main control module, encryption and decryption module, interface module, railway dedicated network access module and equipment terminal data transmission module; The railway dedicated network access module is connected to the internal service network of the railway integrated information network via the railway APN dedicated line; The interface module includes multiple interfaces, and the interface module is connected to the railway equipment terminal; The encryption and decryption module is connected to the railway dedicated network access module and the interface module for encrypting and decrypting transmitted data; The device terminal data transmission module is connected to the encryption and decryption module for transmitting encrypted and decrypted data; The main control module is connected to the railway dedicated network access module, the interface module, the encryption and decryption module and the device terminal data transmission module, and is used for centrally controlling the transmission of access device data.
6. The access device based on the railway dedicated network according to claim 5, characterized in that: The SIM card slot is equipped with a railway-oriented 4G / 5G Internet of Things SIM card, and the Internet of Things SIM card is directed to access the railway comprehensive information network through a railway-specific APN channel.
7. The access device based on the railway dedicated network according to claim 6, characterized in that: The IMEI number of the access device based on the railway dedicated network, the railway-oriented 4G / 5G Internet of Things SIM card number, and the MAC address of the railway equipment terminal are bound one-to-one.
8. A railway equipment access and data security transmission method based on a railway dedicated network, characterized in that: Using the railway equipment access and data security transmission system based on a railway dedicated network as described in any one of claims 1 to 4, the method includes: Railway equipment data transmission step: using the railway equipment data transmission module to process the data to be transmitted from the railway terminal and convert it into a binary array; slicing and splicing the binary array, and uploading the sliced data; Railway equipment data access step: using a railway equipment data access module to receive the slice data sent by the railway equipment data transmission module, assembling the slice data into a complete binary array, restoring the binary array, and then decompressing and decrypting it; Gateway forwarding service step: using the gateway forwarding service module to receive the restored railway equipment data sent by the railway equipment data access module, and after obtaining authorization information, encrypting and forwarding the railway equipment data with the authorization token; Railway equipment data service receiving step: using the railway equipment data service receiving module to receive and decrypt the authorization token verification data sent by the gateway forwarding service module, and giving the device data receipt to complete the railway equipment access and data security transmission.
9. The method for railway equipment access and data security transmission based on a railway dedicated network according to claim 8, characterized in that: The railway equipment data transmission step includes: Data processing steps: Encapsulate the railway data in a unified railway equipment data packet format, encrypt the unified encapsulated format data using a national encryption algorithm, compress the encrypted data, and convert the compressed data into a binary array; Data slicing step: slicing the converted binary array according to the data length and the preset message length value, and splicing the slice data header and the slice data tail; Data uploading step: uploading the slice data and resending failed data within a preset time.
10. The railway equipment access and data security transmission method based on a railway dedicated network according to claim 8, characterized in that: The railway equipment data access step includes: Data receiving step: receiving the slice data, verifying the slice data according to the slice data header, and responding to each slice data within a preset time; Data assembly step: assembling the verified slice data, and splicing the slice data into a complete binary array according to the slice data header; Data restoration step: restoring and decompressing the assembled binary array, decrypting it using a corresponding encryption algorithm, and generating restored railway equipment data.
Citation Information
Cited By
Multi-dimensional security protection method for mobile security interconnection of railway signal system
CN121194180A
Railway signal system mobile internet service continuity guarantee system supporting 5G and 4G dual-mode switching
CN121418935A
Railway signal system mobile internet business continuity assurance system supporting 5g and 4g dual-mode switching
CN121418935B