Communication authentication method and system of train on-board network, storage medium and equipment

By adopting identity-based cryptography mechanism for asymmetric encryption authentication and session key negotiation in the train on-board network, the problems of information security credibility and communication burden of the train on-board network are solved, efficient and secure communication authentication is achieved, illegal intrusion is prevented and computing overhead is reduced.

CN120675781APending Publication Date: 2025-09-19NAT HIGH SPEED TRAIN QINGDAO TECH INNOVATION CENT
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510899139.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-30
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

The existing train on-board network system lacks guarantees in terms of information security credibility. Attackers can infiltrate and release malicious programs, causing system functions to fail. In addition, the existing security transmission protocol fails to effectively provide communication confidentiality protection, increasing the communication burden.

Method used

It adopts the identity-based cryptography (IBC) mechanism to generate random numbers and private keys through identity information, perform asymmetric encryption authentication, simplify key management, and complete key negotiation in the initial communication. In subsequent communications, only session keys are used, reducing hash calls and lowering protocol computing overhead.

Benefits of technology

It improves the communication security and efficiency of the train's on-board network, prevents illegal equipment from accessing, reduces the communication burden, ensures the legitimacy of the identities of both communicating parties, reduces protocol calculation overhead, and avoids impact on real-time performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675781A_ABST
    Figure CN120675781A_ABST
Patent Text Reader

Abstract

The invention provides a communication authentication method and system for a train-mounted network, a storage medium and equipment, and the method only completes the key negotiation operation in the process of executing the communication authentication of the train-mounted network, enables the subsequent communication process to be executed based on a session key obtained through the negotiation of a first verification party and a second verification party, and improves the communication authentication efficiency. According to the method and the device, identity information of two communication parties is mutually verified, only a request carrying identity information of a verification party needs to be sent once in a primary communication process, only a session key generated by negotiation needs to be carried in a subsequent communication process, lightweight processing is performed on a communication authentication protocol, and the communication authentication protocol can be obtained by introducing a pairing-free password system based on an identity label. According to the method, a complex pairing process does not need to be executed, the number of calling times of Hash is reduced, the protocol calculation overhead is reduced, the communication efficiency is improved on the basis of ensuring the credible access authentication of a train-mounted network and the credible transmission of a control message, and the influence on the real-time performance of a train network monitoring management system is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of train communication technology, and in particular to a communication authentication method, system, storage medium and device for a train on-board network. Background Art

[0002] Existing train network system terminals mostly focus solely on functional safety, lacking sufficient assurance of the device's own information security and reliability. Once an attacker infiltrates the onboard network and releases destructive malicious programs, they could potentially delete critical applications or damage the underlying operating system, leading to system failure.

[0003] Current secure transmission protocols for train network monitoring and management systems primarily focus on providing integrity and data origin authentication for transmitted data, preventing tampering and forgery attacks. Confidentiality protection is typically not provided for control message transmission. Therefore, ensuring secure communication within train networks while reducing the communication burden is a pressing challenge for those skilled in the art. Summary of the Invention

[0004] The purpose of this application is to provide a communication authentication method, system, computer-readable storage medium and electronic device for a train on-board network, which can reduce the communication burden of the train on-board network and improve security performance while minimizing the impact on communication efficiency.

[0005] To solve the above technical problems, this application provides a communication authentication method for a train onboard network. The specific technical solution is as follows:

[0006] The first verification party generates a first random number based on the first identity information, and requests a key generation center to generate a first private key based on the first random number and the system master key;

[0007] The second verification party generates a second random number based on the second identity information, and requests the key generation center to generate a second private key based on the second random number and the system master key;

[0008] The first verifier calculates the second public key of the second verifier based on the second identity verification information of the second verifier, encrypts the first random number to obtain a first encrypted random number, and sends the first encrypted random number and the first identity information to the second verifier;

[0009] The second verifier uses the second private key to decrypt the first encrypted random number to obtain a first random number, calculates the first public key of the first verifier, and matches the first public key with the first identity information to obtain a matching result;

[0010] If the matching result is a successful match, the second verifier generates a response message; the response message includes a second random number and the matching result;

[0011] The first authenticator decrypts the response information to obtain the second random number, and authenticates the second authenticator using the second public key of the second authenticator;

[0012] If the identity authentication of the second authenticator is passed, a session key is generated; the session key is used to be embedded in a communication data message to represent the communication security between the first authenticator and the second authenticator.

[0013] Optionally, also include:

[0014] The key generation center is called to generate the system master key using elliptic curve parameters.

[0015] Optionally, the calling of a key generation center to use elliptic curve parameters to generate the system master key includes:

[0016] Determine elliptic curve parameters;

[0017] Selecting a target generator on the ellipse corresponding to the elliptic curve parameter; the order of the target generator is the largest prime number and can generate all points on the elliptic curve;

[0018] Generate an initial master key using a random number generator;

[0019] The system master key is generated according to the target generator and the initial master key.

[0020] Optionally, generating a session key includes:

[0021] Based on a set data structure, a session key of an unsigned 32-bit integer value is generated through a cyclic redundancy check; the set data structure at least includes a user-defined security information identifier, a reserved field, a protocol version number, a unique train identifier and a unique train identifier.

[0022] Optionally, after generating the session key, the method further includes:

[0023] The session key is used as an implicit area, and message content data and tail data are added to obtain a communication data message; the communication data message communicates based on a train communication network protocol.

[0024] Optionally, after generating the session key, the method further includes:

[0025] Key management security parameters are set and session keys are updated based on corresponding policies; the policies are used to derive new session keys based on old session keys.

[0026] The present application also provides a communication authentication system for a train onboard network, comprising:

[0027] A first private key generation module, applied to the first verifier, configured to generate a first random number based on the first identity information, and request a first private key generated based on the first random number and the system master key from the key generation center;

[0028] A second private key generation module, applied to the second verification party, for the second verification party to generate a second random number based on the second identity information, and request a key generation center to generate a second private key based on the second random number and the system master key;

[0029] a first verification module, applied to the first verifier, configured to calculate the second public key of the second verifier based on the second identity authentication information of the second verifier, encrypt the first random number to obtain a first encrypted random number, and send the first encrypted random number and the first identity information to the second verifier;

[0030] a second verification module, applied to the second verifier, configured to decrypt the first encrypted random number using the second private key to obtain a first random number, calculate the first public key of the first verifier, and match the first public key with the first identity information to obtain a matching result;

[0031] A response information generation module, applied to the second verification party, is used to generate a response message if the matching result is a successful match; the response message includes a second random number and the matching result;

[0032] a third verification module, applied to the first verification party, configured to decrypt the response information to obtain the second random number, and authenticate the second verification party using the second public key of the second verification party;

[0033] The interactive authentication module is used to generate a session key if the identity authentication of the second authenticator is passed; the session key is used to be embedded in the communication data message to represent the communication security between the first authenticator and the second authenticator.

[0034] The present application also provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of the communication authentication method described above are implemented.

[0035] The present application also provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of the communication authentication method described above are implemented.

[0036] The present application also provides a computer program product, comprising a computer program, which implements the steps of the communication authentication method described above when executed by a processor.

[0037] The present application provides a communication authentication method for a train on-board network, comprising: a first verifier generates a first random number based on first identity information, and requests a first private key generated based on the first random number and a system master key from a key generation center; a second verifier generates a second random number based on second identity information, and requests the key generation center to generate a second private key based on the second random number and the system master key; the first verifier calculates a second public key of the second verifier based on the second identity information of the second verifier, encrypts the first random number to obtain a first encrypted random number, and sends the first encrypted random number and the first identity information to the second verifier; the second verifier decrypts the first encrypted random number using the second private key to obtain a first random number, calculates the first public key of the first verifier, and matches the first public key with the first identity information to obtain a matching result; if the matching result is a successful match, the second verifier generates a response message; the response message includes the second random number and the matching result; the first verifier decrypts the response message to obtain the second random number, and authenticates the second verifier using the second public key of the second verifier; if the second verifier passes the authentication, a session key is generated; the session key is used to be embedded in a communication data message to indicate the communication security between the first and second verifiers.

[0038] During the communication authentication process of the train's onboard network, this application only completes the key negotiation operation, so that subsequent communication processes are executed based on the session key obtained through negotiation between the first and second authenticators to mutually verify the identity information of both communicating parties. Only one request carrying the identity information of the authenticator needs to be sent during the initial communication process, and only the session key generated through negotiation needs to be carried during subsequent communication processes. This lightweight processing of the communication authentication protocol is achieved by introducing a non-pairing identity-based cryptographic system, eliminating the need to perform a complex pairing process, reducing the number of hash calls, and lowering the protocol calculation overhead. While ensuring trusted access authentication and trusted transmission of control messages for the train's onboard network, this reduces protocol calculation overhead, improves communication efficiency, and avoids affecting the real-time performance of the train network monitoring and management system.

[0039] The present application also provides a communication authentication system for a train on-board network, a computer-readable storage medium, an electronic device, and a computer program product, which have the above-mentioned beneficial effects and are not further described here. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0041] Figure 1 A flow chart of a communication authentication method for a train on-board network provided in an embodiment of the present application;

[0042] Figure 2 A schematic diagram of a communication data message structure provided in an embodiment of the present application;

[0043] Figure 3 This is the flow chart of the authentication and key exchange protocol of the existing national secret SM9;

[0044] Figure 4 This is a flowchart of the authentication and key exchange protocol based on the national secret SM9 implemented in this application;

[0045] Figure 5 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0046] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0047] In an in-vehicle network environment, there are a large number of device nodes, and key management of authentication schemes based on symmetric mechanisms is difficult. Asymmetric cryptography can greatly simplify the complexity of key management for in-vehicle network node authentication. Identity-Based Cryptography (IBC) directly uses the entity's identity information (such as a device's unique identifier) ​​as the public key. The two parties do not need to transmit or store public key certificates in advance, reducing communication and storage overhead. In terms of computational complexity, the computational overhead required to derive the public key from the identifier is close to the overhead of PKI using the CA public key to verify the certificate signature. This application is based on an in-vehicle network node access authentication protocol based on the IBC mechanism, and addresses the two issues of the standard IBC authentication protocol having many interaction rounds and the high overhead of IBC signature verification by respectively achieving a lightweight access authentication protocol and a pairless IBC signature system.

[0048] Specifically, in terms of lightweighting the access authentication protocol, the main goal of the present invention is to reduce the number of interaction rounds and interaction parameters of the IBC authentication protocol and reduce the protocol calculation overhead.

[0049] See also Figure 1 , Figure 1 A flow chart of a communication authentication method for a train on-board network provided in an embodiment of the present application, the method comprising:

[0050] S101: A first verifier generates a first random number based on first identity information, and requests a key generation center to generate a first private key based on the first random number and a system master key;

[0051] S102: The second verifier generates a second random number based on the second identity information, and requests the key generation center to generate a second private key based on the second random number and the system master key;

[0052] S103: The first verifier calculates the second public key of the second verifier based on the second identity verification information of the second verifier, encrypts the first random number to obtain a first encrypted random number, and sends the first encrypted random number and the first identity information to the second verifier;

[0053] S104: The second verifier uses the second private key to decrypt the first encrypted random number to obtain a first random number, calculates the first public key of the first verifier, and matches the first public key with the first identity information to obtain a matching result;

[0054] S105: If the matching result is successful, the second verifier generates a response message; the response message includes a second random number and the matching result;

[0055] S106: The first verifier decrypts the response information to obtain the second random number, and authenticates the second verifier using the second public key of the second verifier;

[0056] S107: If the identity authentication of the second authenticator is passed, a session key is generated; the session key is used to be embedded in a communication data message to indicate the communication security between the first authenticator and the second authenticator.

[0057] The Train Real-Time Data Protocol (TRDP) is a real-time transport protocol for trains. The TRDP layer sits between the application layer and the transport layer, which uses the TCP / UDP protocol.

[0058] The first verifier generates a first random number with sufficient entropy based on its own identity (first identity information, such as the device's unique serial number or network address) using a predefined random number generation algorithm. This random number plays a critical role in the subsequent key generation and identity authentication process. Simultaneously, the first verifier sends a private key request message to the key generation center, containing the first identity information and the first random number. Upon receiving the request, the key generation center generates a first private key for the first verifier using a specific key generation algorithm (such as elliptic curve cryptography) based on the system master key and the first random number.

[0059] For example, assume the system master key is a pre-set, highly confidential parameter. When the first authenticator sends its identity information (e.g., device ID "Train_Device_001") and a generated first random number (e.g., random number R1 = 345678) to the key generation center, the key generation center calculates the system master key, R1, and the identity information of "Train_Device_001" according to a predetermined algorithm to generate a private key (the first private key) unique to the first authenticator. This process is similar to customizing a unique "key" for each device for subsequent encryption and decryption operations.

[0060] The second verifier also generates a second random number based on its own identity (second identity information). It also sends a private key request message to the key generation center, including its second identity information and the second random number. Upon receiving the message, the key generation center generates a second private key based on the system master key and the second random number and securely sends it to the second verifier.

[0061] The first verifier uses the second verifier's second identity verification information (such as the second verifier's public key identifier or identity certificate) to calculate the second verifier's second public key using a pre-defined public key calculation algorithm. This step is based on the principles of identity-based cryptography (IBC), which derives the other party's public key from known identity information.

[0062] The first verifier then uses the calculated second public key to encrypt the previously generated first random number, generating a first encrypted random number. This encryption process utilizes an asymmetric encryption algorithm, such as elliptic curve cryptography (ECC), ensuring that only the second verifier, holding the corresponding private key, can decrypt the first random number. The first verifier then encapsulates the encrypted first random number and its first identity information into a data packet and sends it to the second verifier.

[0063] After receiving the data packet, the second verifier first uses the second private key it previously obtained from the key generation center to decrypt the first encrypted random number. Because the second private key and the second public key appear in pairs, the second verifier can successfully decrypt the first random number.

[0064] Next, the second verifier calculates the first public key of the first verifier based on the first identity information sent by the first verifier, using the same public key calculation method. The calculated first public key is then matched and verified against the first identity information. This verification process primarily checks whether the sender's identity information corresponds to the calculated public key, ensuring the other party's identity is legitimate.

[0065] If the second verifier confirms a successful match during the matching verification process, i.e., confirms the legitimacy of the first verifier, it will generate a response message. This response message includes the second random number and a successful match flag or result. The second random number was generated in step S102 and is used in the subsequent session key generation process. The successful match flag can be a simple confirmation flag or a piece of data containing successful verification information.

[0066] After receiving the response from the second verifier, the first verifier decrypts the response using the previously calculated second public key (calculated in step S103) to obtain a second random number. Simultaneously, the first verifier authenticates the second verifier using the second public key. This verification process, based on the binding relationship between the second verifier's public key and its identity information, ensures the second verifier's identity is authentic and valid.

[0067] After the first authenticator confirms the second authenticator's identity, both parties use a predefined session key generation algorithm (such as a key derivation function (KDF)) based on the previously exchanged random numbers (first random number R1 and second random number R2) to generate a session key. This session key is used for subsequent communication data encryption and decryption operations to ensure the confidentiality and integrity of the communication content.

[0068] The specific content and structure of the session key are not limited here. In one feasible implementation, a session key consisting of an unsigned 32-bit integer value can be generated based on a set data structure through a cyclic redundancy check. The set data structure includes at least a user-defined security information identifier, a reserved field, a protocol version number, a unique train identifier, and a unique train identifier. See Table 1 for an exemplary session key data structure:

[0069] Table 1 Session key data structure table

[0070]

[0071] Table 1 includes the user-defined safety information identifier SMI, the reserved fields reserved01 and reserved02, the protocol version number SDTProtVers, the unique train group identifier cstUUID, and the train unique identifier SafeTopoCount. Those skilled in the art may also adaptably add other fields or identifiers based on what is shown in Table 1, and all such additions are intended to fall within the scope of protection of this application.

[0072] This application can be applied to the Safe Data Transmission version 2 (SDTv2), a protocol that adds secure data transmission to the application data layer and is primarily suitable for train Ethernet communications. SDTv2 provides a secure communication path between a safety-related (critical) data source (SDSRC) and one or more safety-related data sinks (SDSINK). This secure communication path is called an "SDTv2 channel." The primary task of the SDTv2 layer on the SDSRC side is to add protocol information, forming the VDP necessary for secure data transmission at the transport layer before transmission. The SDTv2 layer on the SDSINK side confirms the received VDP and, if successful, presents the included critical data on the SDTv2 application interface.

[0073] All safety-related data sources (SDSRC) are identified by a source identifier (SID). The SID can be configured as a UINT32 value calculated using the SC-32 cyclic redundancy check as shown above.

[0074] After the session key is generated, it is embedded into the communication data message. The session key can be used as an implicit area, and the message content data and tail data can be added to obtain the communication data message. The communication data message is based on the train communication network protocol. For example, a field containing a session key identifier or an encrypted session key can be added to the header or tail of each communication data packet, or a specific key encapsulation mechanism can be used to bind the session key to the data content. In this way, in the subsequent communication process, the communicating parties can encrypt and decrypt the data based on the embedded session key to ensure the security of the communication. Figure 2 , Figure 2 A schematic diagram of a communication data message structure provided in an embodiment of the present application. Figure 2In the datagram, the session key exists in an implicit area as a SID source identifier, along with important process data and tail data. The implicit area refers to an area that is not explicitly identified in the data message, but has implicit meaning or function for data transmission and processing, and is usually not directly included in the explicit structure of the message. This embodiment ensures the trusted access authentication of device nodes in the TCMS network and the trusted transmission of control messages by constructing a dedicated access authentication scheme, key management system, and secure transmission protocol suitable for the TCMS network, ultimately forming a trusted isolation environment for the core security domain based on cryptographic technology, and avoiding the impact of the introduction of security mechanisms on the real-time performance of the TCMS system.

[0075] During the communication authentication process of the train's onboard network, this application only completes the key negotiation operation, so that subsequent communication processes are executed based on the session key obtained through negotiation between the first and second authenticators to mutually verify the identity information of both communicating parties. Only one request carrying the identity information of the authenticator needs to be sent during the initial communication process, and only the session key generated through negotiation needs to be carried during subsequent communication processes. This lightweight processing of the communication authentication protocol is achieved by introducing a non-pairing identity-based cryptographic system, eliminating the need for a complex pairing process, reducing the number of hash calls, and lowering the protocol calculation overhead. While ensuring trusted access authentication and trusted transmission of control messages for the train's onboard network, this improves communication efficiency and avoids impacting the real-time performance of the train network monitoring and management system.

[0076] Furthermore, this embodiment ensures the authenticity and legitimacy of the identities of both communicating parties through multiple rounds of interactive verification based on identity information and random numbers, effectively preventing unauthorized devices from accessing the train's onboard network. Furthermore, session keys are generated using random numbers and key derivation functions and embedded in communication data packets. Each communication has a unique session key, improving the confidentiality and integrity of communications and reducing the risk of data theft and tampering. This application can be integrated with existing train onboard network communication protocols and work in conjunction with existing network architectures and security measures (such as firewalls and intrusion detection systems) to form a more comprehensive security protection system.

[0077] There are no restrictions on how the system master key is generated. A key generation center can be invoked to generate the system master key using elliptic curve parameters. Specifically, the elliptic curve parameters can be determined first, and then a target generator is selected on the ellipse corresponding to the elliptic curve parameters; the order of the target generator is the largest prime number that can generate all points on the elliptic curve. A random number generator is then used to generate the initial master key, and the system master key is generated based on the target generator and the initial master key.

[0078] First, determine the elliptic curve, then the finite field. Based on the specific communication security requirements, a prime number p is determined such that the elliptic curve is over the finite field GF(p) modulo p. The size of p is generally related to the required security level. The number of all points of the elliptic curve (including points at infinity) over the selected finite field is calculated as the order of the elliptic curve, denoted as n. This order n should be a large prime number or a multiple thereof to ensure the difficulty of the elliptic curve discrete logarithm problem (ECDLP).

[0079] Starting from a non-zero point on the elliptic curve, examine each point one by one. For each point P examined, determine its order by repeatedly adding P to itself (i.e., performing addition on the elliptic curve) until a point at infinity, O, is obtained. If O is obtained after k additions, then k is the order of point P. Find a point with the largest prime order that can generate all points on the elliptic curve (i.e., it is a generator on the elliptic curve). Use this point as the target generator G.

[0080] Call a secure random number generator (such as a hardware random number generator or a certified software random number generation algorithm) to generate a random number of sufficient length as the initial master key s. The length of the random number should match the elliptic curve parameters to ensure security. For example, in a 256-bit elliptic curve cryptography system, the random number length should be 256 bits.

[0081] Based on the target generator G and the initial master key s, the system master key point P = sG is calculated using scalar multiplication on the elliptic curve. Here, scalar multiplication means adding the generator G to itself s-1 times.

[0082] Verify the validity of the system master key point: Verify that the calculated system master key point P is on the elliptic curve. Substitute the coordinates of P into the elliptic curve equation to check whether the equation satisfies the equation. Also, verify that the order of point P is n. If verification fails, regenerate the initial master key s and recalculate the system master key point P.

[0083] In addition, the generated system master key point P and the initial master key s (need to be securely stored) can be recorded in the secure storage area of ​​the key generation center. These keys will be used in the subsequent private key generation process.

[0084] See also Figure 3 and Figure 4 , Figure 3 This is the flow chart of the authentication and key exchange protocol of the existing national secret SM9. Figure 4 This is a flowchart of the authentication and key exchange protocol based on the national secret SM9 implemented in this application.

[0085] See also Figure 3In the IBC system, both parties need to calculate the public key through the identity of the other party, and the exchange of secret random numbers in the protocol usually needs to be encrypted using the public key of the recipient. Finally, the corresponding response result needs to be calculated based on the random numbers exchanged by both parties to complete the two-way authentication. Therefore, the general IBC authentication and key exchange protocol requires a four-step communication process (see Figure 3 ), which brings high additional overhead to the vehicle network. Figure 3 SA is user A's digital signature on the message, used to prove user B's identity and the integrity of the message. SB is user B's digital signature on the message, used to prove user B's identity and the integrity of the message.

[0086] and Figure 4 In [1], the authentication scheme is modified based on the implicit authentication strategy. That is, only the key negotiation operation is completed during the access process, and the correctness of the session key negotiated by both parties is confirmed during the subsequent secure transmission process, which also completes the identity authentication function. This can compress the access process to 3 steps. Figure 4 , that is, remove Figure 3 Medium S B and S A Considering that only an identity identifier (usually only 4 bytes) is sent as an access request in the first step, the number of protocol interaction rounds and protocol calculation overhead are reduced after the simplification. Figure 4 The authentication process is described as follows:

[0087] First round of communication (from initiator to responder):

[0088] Initiator (User B): First, the initiator User B generates a random number RA and sends it together with its own identity ID A to the responder User A. The purpose of this step is to identify itself to the responder and provide a random number for subsequent authentication and session key generation.

[0089] Second round of communication (from responder to initiator):

[0090] Responder (User A): After receiving RA and IDA, responder User A generates its own random number RB and sends RB to initiator User B. At the same time, the responder will verify the received IDA and other relevant information (such as system parameters, keys, etc.) to ensure the legitimacy of the initiator's identity.

[0091] The third round of communication (from initiator to responder):

[0092] Initiator (User B): After receiving the RB, User B performs further processing based on the RB and the previously generated RA, such as generating a session key, KAB. The initiator then verifies the correctness of KAB and sends the verification result to User A, the responder.

[0093] Complete the establishment of secure communication:

[0094] Use of session keys: Once both parties have verified each other's identities and negotiated the same session key KAB, subsequent communications can be end-to-end encrypted and decrypted based on this session key, thereby ensuring the security of communication.

[0095] During the identity authentication process, both parties only need to verify the correctness of KAB to complete the authentication of each other's identities, ensuring the legitimacy of the communicating parties and preventing man-in-the-middle attacks and other illegal intrusions.

[0096] It can be seen that this application introduces the IBC system without pairing, reduces the number of Hash calls, and ultimately reduces the protocol calculation overhead. Figure 4 Taking the simplified national secret SM9 protocol as an example, the bilinear pairing operation of the single-side user of this scheme is reduced from 2 times in the standard scheme to 1 time, which can greatly reduce the computational overhead of the protocol. At the same time, common IBC systems are all based on bilinear pairing construction, and the computational complexity of bilinear pairing is much higher than the discrete logarithm operation on the elliptic curve, and the operation time of linear pairing operation can reach 2-7 times that of ECC operation, resulting in a large computational overhead for protocol signing and verification. Therefore, this application adopts the IBC algorithm without pairing, which can greatly reduce the computational overhead of the authentication process.

[0097] To summarize, this application can provide trusted security protection and trusted isolation measures for security domain partitioning based on cryptographic technology for train on-board network transmission through the above-mentioned dedicated access authentication scheme, key management system and secure transmission protocol for the TCMS network.

[0098] In one feasible embodiment, an efficient session key management strategy can be proposed for session keys based on the security requirements of rail vehicle onboard networks. Security parameters such as the key lifecycle and session period can be set, and session keys can be updated according to the strategy to ensure forward security of the protocol. Specifically, key management security parameters are set, and session keys are updated based on the corresponding strategy; the strategy is used to derive new session keys based on the old session keys. For example, in the key update mechanism, when the old session key expires, the device will perform a key update process with the key management server, and a new key can be derived from the old key:

[0099] ;

[0100] Key orchestration optimization involves efficient key storage and retrieval, as well as flexible key usage during encryption, ensuring that each key operation minimizes computational overhead. By working together at both the data and algorithm levels, we can collaboratively improve the efficiency of lightweight cryptographic algorithms.

[0101] The present application also provides a communication authentication system for a train onboard network, comprising:

[0102] A first private key generation module, applied to the first verifier, configured to generate a first random number based on the first identity information, and request a first private key generated based on the first random number and the system master key from the key generation center;

[0103] A second private key generation module, applied to the second verification party, for the second verification party to generate a second random number based on the second identity information, and request a key generation center to generate a second private key based on the second random number and the system master key;

[0104] a first verification module, applied to the first verifier, configured to calculate the second public key of the second verifier based on the second identity authentication information of the second verifier, encrypt the first random number to obtain a first encrypted random number, and send the first encrypted random number and the first identity information to the second verifier;

[0105] a second verification module, applied to the second verifier, configured to decrypt the first encrypted random number using the second private key to obtain a first random number, calculate the first public key of the first verifier, and match the first public key with the first identity information to obtain a matching result;

[0106] A response information generation module, applied to the second verification party, is used to generate a response message if the matching result is a successful match; the response message includes a second random number and the matching result;

[0107] a third verification module, applied to the first verification party, configured to decrypt the response information to obtain the second random number, and authenticate the second verification party using the second public key of the second verification party;

[0108] The interactive authentication module is used to generate a session key if the identity authentication of the second authenticator is passed; the session key is used to be embedded in the communication data message to represent the communication security between the first authenticator and the second authenticator.

[0109] The present application also provides an embodiment corresponding to a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the method described in the above method embodiment.

[0110] It is understandable that if the method in the above embodiment is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and executes all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program code.

[0111] The computer-readable storage medium provided in this embodiment includes the above-mentioned method, and the effect is the same as above.

[0112] The computer program product provided in this embodiment also includes the above-mentioned method and can implement the steps of the method described in any of the above embodiments, with the same effect as above.

[0113] This application also provides an electronic device, see Figure 5 , a structural diagram of an electronic device provided in an embodiment of the present application, such as Figure 5 As shown, a processor 1410 and a memory 1420 may be included.

[0114] The processor 1410 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 1410 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 1410 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 1410 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 1410 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0115] The memory 1420 may include one or more computer-readable storage media, which may be non-transitory. The memory 1420 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory 1420 is at least used to store the following computer program 1421, wherein, after the computer program is loaded and executed by the processor 1410, it can implement the relevant steps in the method performed by the electronic device side disclosed in any of the aforementioned embodiments. In addition, the resources stored in the memory 1420 may also include an operating system 1422 and data 1423, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 1422 may include Windows, Linux, Android, etc.

[0116] In some embodiments, the electronic device may further include a display screen 1430 , an input / output interface 1440 , a communication interface 1450 , a sensor 1460 , a power supply 1470 , and a communication bus 1480 .

[0117] certainly, Figure 5 The structure of the electronic device shown does not constitute a limitation on the electronic device in the embodiment of the present application. In actual applications, the electronic device may include Figure 5 More or fewer components than shown, or combinations of certain components.

[0118] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the systems provided in the embodiments, since they correspond to the methods provided in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.

[0119] This document uses specific examples to illustrate the principles and implementation methods of this application. The description of the above examples is only intended to help understand the method and core ideas of this application. It should be noted that for those skilled in the art, without departing from the principles of this application, various improvements and modifications can be made to this application, and such improvements and modifications also fall within the scope of protection of this application.

[0120] It should also be noted that, in this specification, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.

Claims

1. A communication authentication method for a train onboard network, characterized in that: include: The first verification party generates a first random number based on the first identity information, and requests a key generation center to generate a first private key based on the first random number and the system master key; The second verification party generates a second random number based on the second identity information, and requests the key generation center to generate a second private key based on the second random number and the system master key; The first verifier calculates the second public key of the second verifier based on the second identity verification information of the second verifier, encrypts the first random number to obtain a first encrypted random number, and sends the first encrypted random number and the first identity information to the second verifier; The second verifier uses the second private key to decrypt the first encrypted random number to obtain a first random number, calculates the first public key of the first verifier, and matches the first public key with the first identity information to obtain a matching result; If the matching result is a successful match, the second verifier generates a response message; the response message includes a second random number and the matching result; The first authenticator decrypts the response information to obtain the second random number, and authenticates the second authenticator using the second public key of the second authenticator; If the identity authentication of the second authenticator is passed, a session key is generated; the session key is used to be embedded in a communication data message to represent the communication security between the first authenticator and the second authenticator.

2. The communication authentication method according to claim 1, wherein: Also includes: The key generation center is called to generate the system master key using elliptic curve parameters.

3. The communication authentication method according to claim 2, wherein: The calling key generation center to use elliptic curve parameters to generate the system master key includes: Determine elliptic curve parameters; Selecting a target generator on the ellipse corresponding to the elliptic curve parameter; the order of the target generator is the largest prime number and can generate all points on the elliptic curve; Generate an initial master key using a random number generator; The system master key is generated according to the target generator and the initial master key.

4. The communication authentication method according to claim 1, wherein: Generating a session key comprises: Based on a set data structure, a session key of an unsigned 32-bit integer value is generated through a cyclic redundancy check; the set data structure at least includes a user-defined security information identifier, a reserved field, a protocol version number, a unique train identifier and a unique train identifier.

5. The communication authentication method according to claim 1, wherein: After generating the session key, the method further includes: The session key is used as an implicit area, and message content data and tail data are added to obtain a communication data message; the communication data message communicates based on a train communication network protocol.

6. The communication authentication method according to claim 1, wherein: After generating the session key, the method further includes: Key management security parameters are set and session keys are updated based on corresponding policies; the policies are used to derive new session keys based on old session keys.

7. A communication authentication system for a train onboard network, characterized in that: include: A first private key generation module, applied to the first verifier, configured to generate a first random number based on the first identity information, and request a first private key generated based on the first random number and the system master key from the key generation center; A second private key generation module, applied to the second verification party, for the second verification party to generate a second random number based on the second identity information, and request a key generation center to generate a second private key based on the second random number and the system master key; a first verification module, applied to the first verifier, configured to calculate the second public key of the second verifier based on the second identity authentication information of the second verifier, encrypt the first random number to obtain a first encrypted random number, and send the first encrypted random number and the first identity information to the second verifier; a second verification module, applied to the second verifier, configured to decrypt the first encrypted random number using the second private key to obtain a first random number, calculate the first public key of the first verifier, and match the first public key with the first identity information to obtain a matching result; A response information generation module, applied to the second verification party, is used to generate a response message if the matching result is a successful match; the response message includes a second random number and the matching result; a third verification module, applied to the first verification party, configured to decrypt the response information to obtain the second random number, and authenticate the second verification party using the second public key of the second verification party; The interactive authentication module is used to generate a session key if the identity authentication of the second authenticator is passed; the session key is used to be embedded in the communication data message to represent the communication security between the first authenticator and the second authenticator.

8. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the method according to any one of claims 1 to 6 when executing the computer program.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which implements the steps of the method according to any one of claims 1 to 6 when executed.

10. A computer program product, characterized in that The invention comprises a computer program, which implements the steps of the method according to any one of claims 1 to 6 when the computer program is executed.

Citation Information

Cited By

  • Zero-trust gateway data access method, client, gateway, communication system, storage medium and computer program product

    CN121173591A

  • Zero trust gateway data access method, client, gateway, communication system, storage medium and computer program product

    CN121173591B

  • Anti-skipping verification key packaging method and device based on identity binding confirmation code

    CN121217342A

  • Unmanned aerial vehicle-oriented key management method, medium and equipment

    CN121984789A

  • A key management method, medium and device for unmanned aerial vehicles

    CN121984789B