Rail transit quantum communication system data transmission method, device, system and medium
Through quantum key distribution and encryption technology, and utilizing the quantum communication dual-channel isolation architecture, the security issues of the train-to-ground communication system under quantum computing attacks have been resolved, achieving quantum-level security protection and efficient communication of train data.
Patent Information
- Application Number
- CN202510995060.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-18
- Publication Date
- 2025-10-14
AI Technical Summary
When facing quantum computing attacks, the existing train-to-ground communication system is difficult to defend against with traditional encryption technology, threatening the safety of train operations.
Quantum key distribution technology is used to distribute quantum keys through the first channel, and train data encrypted with quantum keys is transmitted through the second channel. The quantum communication dual-channel isolation architecture is used to physically isolate the key distribution and data transmission channels, and combined with the national secret algorithm, quantum-level security protection is achieved.
It effectively resists traditional eavesdropping and quantum computing attacks, ensures the security and integrity of train data during transmission, avoids safety accidents and economic losses caused by information leakage, and ensures low latency and high efficiency of the communication system.
Smart Images

Figure CN120785532A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data transmission technology, and specifically, to a data transmission method and device, a communication system, and a storage medium for a rail transit quantum communication system. Background Art
[0002] With the advancement of intelligent rail transit, vehicle communication networks in high-speed rail and urban rail transit are gradually breaking through the spatial and temporal limitations of information transmission, providing critical support for optimized scheduling and efficient operation of transportation networks. As the core foundation for safe train operation, the real-time and secure nature of vehicle-to-ground communication within railway communication systems is crucial. However, current vehicle-to-ground communication systems face the severe challenge of traditional encryption technologies being unable to withstand quantum computing attacks.
[0003] In related technologies, newly built urban rail vehicles connect to the ground-based PIS (Passenger Information System) network via onboard switches, enabling train-to-ground data transmission via dedicated wireless channels. This significantly improves security compared to public network transmission methods (such as 4G / 5G). For retrofitted vehicles, vehicle-to-ground transmission equipment with integrated WLAN and public network wireless transmission capabilities is installed, creating a topology similar to that of high-speed EMUs, enabling wireless transmission of data such as vehicle status and fault information.
[0004] During the implementation of the embodiments of the present application, it was found that at least the following problems exist in the related art:
[0005] The adoption of relevant technologies has improved the security of the communication system to a certain extent. However, in actual applications, when trains transmit data through the ground PIS dedicated wireless channel, with the development of quantum computing technology, attackers can use its powerful computing power to crack traditional encryption algorithms and then attack the train-ground wireless transmission channel, seriously threatening the normal operation safety of the train. Summary of the Invention
[0006] The embodiments of the present application provide a data transmission method and device for a rail transit quantum communication system, a communication system, and a storage medium.
[0007] A first aspect of the embodiments of the present application provides a data transmission method for a rail transit quantum communication system, comprising:
[0008] performing quantum key distribution via a first channel;
[0009] The train data encrypted with quantum key is transmitted through the second channel.
[0010] In an optional embodiment of the present application, performing quantum key distribution through the first channel includes:
[0011] generating a first quantum key corresponding to the vehicle attribute;
[0012] encrypting the secure cryptographic carrier with the first quantum key via the first channel.
[0013] In an optional embodiment of the present application, before the quantum key distribution via the first channel, further comprising:
[0014] preloading the quantum key into the secure cryptographic carrier using a quantum key injection device.
[0015] In an optional embodiment of the present application, transmitting the encrypted train data via the second channel, comprising:
[0016] encrypting the secure cryptographic carrier using the quantum key transmitted via the first channel, so that the secure cryptographic carrier is in an unusable state;
[0017] decrypting the secure cryptographic carrier using the quantum security gateway, so that the secure cryptographic carrier is in a usable state;
[0018] when the decrypted secure cryptographic carrier is inserted into the train-ground wireless communication device, encrypting the train data using the quantum key preloaded in the secure cryptographic carrier, and transmitting the encrypted train data.
[0019] In an optional embodiment of the present application, encrypting the train data using the quantum key pre-stored in the secure cryptographic carrier, comprising:
[0020] reading the quantum key preloaded in the secure cryptographic carrier using the train-ground wireless communication device, and performing symmetric encryption of the train data using the national cryptographic algorithm.
[0021] In an optional embodiment of the present application, the rail transit quantum communication system data transmission method further comprises:
[0022] receiving the encrypted train data using the ground security gateway, and performing traffic filtering and access control to block illegal requests;
[0023] analyzing the key address in the encrypted train data using the ground decryption server, and applying for the corresponding decryption quantum key from the quantum cryptographic service platform;
[0024] after the quantum cryptographic service platform verifies the legality of the key address, issuing the decryption quantum key to the ground decryption server;
[0025] making the ground decryption server decrypt the encrypted train data based on the national cryptographic algorithm using the decryption quantum key, and transmitting the decrypted train data to the ground business system for analysis and processing.
[0026] In an optional embodiment of the present application, the rail transit quantum communication system data transmission method further includes:
[0027] The quantum cryptography service platform is used to distribute regularly generated new quantum keys to each node of the communication system through the first channel to achieve dynamic update of the quantum keys of each node; wherein the nodes include vehicle-ground wireless communication equipment and / or ground decryption servers.
[0028] A second aspect of an embodiment of the present application provides a data transmission device for a rail transit quantum communication system, comprising a processor and a memory storing program instructions, wherein the processor is configured to execute the data transmission method for a rail transit quantum communication system as described in the first aspect of the embodiment of the present application when running the program instructions.
[0029] According to a third aspect of the embodiments of the present application, a communication system is provided, including:
[0030] a communication system body; and
[0031] As described in the second aspect of the embodiment of the present application, the data transmission device of the rail transit quantum communication system is installed in the communication system body.
[0032] A fourth aspect of the embodiments of the present application provides a computer-readable storage medium storing program instructions, which, when executed, enable a computer to execute the method for traffic control according to the first aspect of the embodiments of the present application.
[0033] The rail transit quantum communication system data transmission method and device, communication system, and storage medium provided in the embodiments of the present application have the following beneficial effects:
[0034] The embodiment of the present application performs quantum key distribution through a first channel and transmits quantum key-encrypted train data through a second channel. A dual-channel isolation architecture for quantum communication is adopted, with the first channel dedicated to quantum key distribution and the second channel dedicated to transmitting encrypted data. Quantum key distribution technology, based on the principles of quantum mechanics, implements information-theoretically secure key distribution. Key distribution is physically isolated from the data transmission channel to avoid the risk of mixed key and data leakage, effectively defending against traditional eavesdropping and quantum computing attacks. This ensures the security and integrity of train data during transmission, provides quantum-level security for train-to-ground communications, avoids security incidents and economic losses caused by information leakage, and ensures low latency and high efficiency of the communication system. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0036] Figure 1 is a schematic diagram of a communication system overall architecture provided by an embodiment of the present application;
[0037] Figure 2 is a schematic diagram of a rail transit quantum communication system data transmission method provided by an embodiment of the present application;
[0038] Figure 3 is a schematic diagram of a rail transit quantum communication system data transmission device provided by an embodiment of the present application.
[0039] Reference signs:
[0040] 800: rail transit quantum communication system data transmission device; 801: processor; 802: memory; 803: communication interface; 804: bus. DETAILED DESCRIPTION
[0041] In order to make the technical solutions and advantages in the embodiments of the present application clearer, the exemplary embodiments of the present application are further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, not all the embodiments. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.
[0042] QKD (Quantum Key Distribution, quantum key distribution) technology is based on quantum mechanics principles, and can realize information theory secure key distribution, and becomes a potential solution to this challenge. Quantum encryption communication performs excellently in key distribution efficiency, anti-eavesdropping ability and low latency communication, thereby avoiding security incidents and economic losses caused by information leakage, and providing quantum-level security for vehicles against external attacks. Existing researches focus on the application of QKD in optical fiber networks, but in mobile scenarios (such as train and ground communication), dynamic key management, multi-domain synchronization and hardware integration problems have not been fully solved.
[0043] In combination with Figure 1As shown, the embodiment of the present application proposes a communication system, comprising a quantum key generation and management terminal, a quantum cryptography service platform, a quantum security gateway, a secure cryptographic carrier, a vehicle-mounted communication terminal, a ground data processing unit and a dual-channel physical layer. The quantum key generation and management terminal is deployed at the ground end and generates quantum keys through a quantum key distribution network. The quantum cryptography service platform is connected to the quantum key generation and management terminal and comprises a key management, identity authentication and dynamic update module. The quantum security gateway is connected to the quantum cryptography service platform and performs secondary encryption and decryption operations of a super SIM card. The secure cryptographic carrier adopts a super SIM card and is pre-installed with quantum keys and digital certificates. The vehicle-mounted communication terminal comprises a train-ground wireless communication device and supports super SIM card insertion and data encryption. The ground data processing unit comprises a ground security gateway, a convergence switch and a decryption server connected in sequence. The dual-channel physical layer comprises a physically isolated first channel and a second channel. The first channel is dedicated to quantum key distribution, and the second channel is dedicated to transmission of train service data encrypted by a national cryptographic algorithm. The communication system further comprises a processor electrically connected to the modules and configured to control the modules to perform the above actions. The quantum key generation and management terminal is connected to the quantum cryptography service platform through the first channel. The platform is connected to the quantum security gateway through a bidirectional communication link. The quantum security gateway reads and writes key data in the super SIM card through a physical interface. The activated super SIM card is inserted into the train-ground wireless communication device in a detachable manner. The train-ground wireless communication device is wirelessly connected to the ground security gateway through the second channel and is connected to the decryption server through the convergence switch. The decryption server is connected to the quantum cryptography service platform through a bidirectional communication interface. In a redundant fault-tolerant architecture, two train-ground wireless communication devices of the head and tail cars are interconnected through a data synchronization bus, and the dual super SIM cards in a single device are connected through a hot standby control circuit.
[0044] Specifically, the quantum key generation and management terminal generates quantum keys and transmits the quantum keys to the quantum cryptography service platform through a first channel. The quantum cryptography service platform injects the keys into the super SIM card, and the quantum security gateway performs secondary encryption on the super SIM card according to a vehicle model differentiation strategy. The encrypted super SIM card is physically transported to the train end, and is inserted into the train-ground wireless communication device after being decrypted and activated by the quantum security gateway. The train-ground wireless communication device collects train operation data, reads the quantum keys in the super SIM card, and encrypts the data using a national encryption algorithm. After adding a key tag containing the vehicle identity to the encrypted data, the data is sent to the ground security gateway through a second channel. The ground security gateway intercepts illegal data streams based on a white list mechanism, and sends the data to the decryption server through a convergence switch. The decryption server parses the key tag and applies for a decryption key to the quantum cryptography service platform. After verifying the identity, the quantum cryptography service platform issues a decryption key, and the decryption server decrypts the data and transmits the data to the ground business system. When a super SIM card failure is detected, the head and tail car devices realize millisecond-level active-standby switching through a data synchronization bus, or continue to encrypt using the locally cached recent keys, while applying for a short-term temporary key from the platform until a new card is replaced.
[0045] Any one of the rail transit quantum communication system data transmission methods provided by the embodiments of the present application can be executed in a communication system or in a server or terminal device in communication connection with the communication system.
[0046] Based on the structure of the above-mentioned communication system, as shown in Figure 2 The embodiments of the present application provide a rail transit quantum communication system data transmission method, comprising:
[0047] S21, quantum key distribution is performed through a first channel.
[0048] S22, train data encrypted by the quantum key is transmitted through a second channel.
[0049] In the embodiments of the present disclosure, the first channel refers to a dedicated path at least for quantum key distribution, such as a key transmission link from the quantum key generation and management terminal to the quantum cryptography service platform, the quantum security gateway and the like. The second channel refers to a dedicated path at least for encrypted train data transmission, such as an encrypted data transmission link from the train-ground wireless communication device to the ground security gateway.
[0050] In an embodiment of the present application, a quantum key generation and management terminal is deployed in a railway communication center and connected to quantum cryptography service platforms along the line via quantum channels. The quantum key generation and management terminal regularly generates quantum keys and distributes the keys to the quantum cryptography service platforms at each station via quantum channels. The quantum cryptography service platform at each station injects the received quantum keys into a super SIM card and performs a secondary encryption on the super SIM card via a quantum security gateway. The encrypted super SIM card is transported to the train maintenance center, decrypted by professionals, and then inserted into the train-to-ground wireless communication device at the train end. When the train is running, the train-to-ground wireless communication device collects train operation data, such as speed, location, and fault information, and uses the quantum key in the super SIM card combined with the national secret SM4 algorithm to symmetrically encrypt the data. The encrypted data is transmitted to the ground security gateway via a classical channel (such as a 4G / 5G network). The ground security gateway performs traffic filtering and access control on the received data, blocks illegal requests, and then forwards the data to the decryption server via the aggregation switch. The decryption server parses the key address in the data and applies to the quantum cryptography service platform for the corresponding decryption quantum key. After verifying the legitimacy of the key address, the quantum cryptography service platform issues the decryption key to the decryption server. The decryption server uses this key to decrypt the encrypted data and transmits the decrypted data to the ground service system for analysis and processing. In other embodiments, a quantum key generation and management terminal is deployed in the subway control center and connected to the quantum cryptography service platform at each station via a quantum channel. The quantum key generation and management terminal generates a quantum key and distributes it to the quantum cryptography service platform at each station via a quantum channel. The quantum cryptography service platform at each station injects the quantum key into a super SIM card and re-encrypts the super SIM card via a quantum security gateway. The encrypted super SIM card is transported to the subway depot, decrypted by professionals, and then inserted into the subway train's wireless communication device (WTD). While the subway train is running, the WTD collects train operating data, such as door status, traction system status, and braking system status. This data is symmetrically encrypted using the quantum key in the super SIM card and the national secret SM4 algorithm. The encrypted data is transmitted to the ground security gateway via a classical channel (such as a WLAN network). The ground security gateway performs traffic filtering and access control on the received data, blocking illegal requests, and then forwards the data to the decryption server via the ground aggregation switch. The decryption server parses the key address in the data and requests the corresponding quantum decryption key from the quantum cryptography service platform. After verifying the legitimacy of the key address, the quantum cryptography service platform issues the decryption key to the decryption server. The decryption server uses this key to decrypt the encrypted data and transmits the decrypted data to the ground service system for analysis and processing.
[0051] The rail transit quantum communication system data transmission method provided in the embodiment of the application performs quantum key distribution through a first channel and transmits train data encrypted by quantum key through a second channel. The quantum communication dual-channel isolation architecture is adopted, that is, the first channel is used for quantum key distribution and the second channel is used for transmission of encrypted data. The quantum key distribution technology is used to realize the key distribution feature of information theory security based on the principle of quantum mechanics, the key distribution and the data transmission channel are physically isolated, the risk of mixed leakage of the key and the data is avoided, and thus the traditional eavesdropping and quantum computing attacks are effectively resisted, the safety and integrity of the train data in the transmission process are ensured, the quantum-level security guarantee is provided for the train-ground communication, the safety accidents and economic losses caused by information leakage are avoided, and the low latency and high efficiency of the communication system are ensured.
[0052] Optionally, the quantum key distribution through the first channel includes: generating a first quantum key corresponding to a vehicle attribute; and encrypting a secure password carrier by the first quantum key through the first channel.
[0053] In the embodiment, the quantum key generation and management terminal takes a vehicle identification number and a train-ground wireless communication device serial number as input parameters, generates a unique key string, that is, a first quantum key, through a quantum random number generator, and forms a strong binding relationship between the first quantum key and a specific train identity. Subsequently, the quantum key generation and management terminal transmits the first quantum key to a quantum password service platform through a quantum key distribution private network, the password service platform calls an encryption module, and performs an encrypted write operation on a storage area of a super SIM card by using the first quantum key, so that the key data in the secure password carrier is in an encrypted locked state, and physical isolation protection of the secure password carrier in the key distribution stage is realized. In some other embodiments, after the quantum password service platform receives the first quantum key sent by the quantum key generation and management terminal, a vehicle production batch number and a device model identifier associated with the first quantum key are extracted, and a composite key label is generated. The quantum password service platform transmits the first quantum key and the composite key label to an offline key injection workstation through the first channel, the offline key injection workstation uses a hardware encryption engine to write the first quantum key and the composite key label into a secure chip of the super SIM card, and performs quantum key encryption on a key access interface of the secure chip of the super SIM card, so that the secure password carrier completes double-binding encryption of the quantum key and the device attribute in the pre-installation stage, and the risk of unauthorized device reading is blocked.
[0054] In this way, the first quantum key corresponding to the vehicle attribute is generated, so that the key forms a strong binding relationship with a specific vehicle identity (such as a vehicle identification number and a device serial number), and the device specificity of the key distribution can be ensured from the root. By transmitting the key through the first channel and encrypting the secure password carrier, the security of the carrier is protected by using the physical isolation characteristics of the quantum channel, and the security of the carrier is protected during the key distribution stage, and the eavesdropping or tampering attack on the secure password carrier during the transmission process is blocked. The double mechanism cooperatively guarantees the security of the key in the generation and transmission link, establishes an unforgeable device identity authentication basis for subsequent vehicle-ground encryption communication, and effectively solves the technical problem that the key and the device cannot be reliably bound in a complex network environment.
[0055] Optionally, before the quantum key distribution through the first channel, the method further includes: preloading the quantum key into the secure password carrier by using a quantum key injection device.
[0056] In the embodiments of the present application, the quantum key injection device connects the quantum password service platform through a physically isolated hardware interface and receives a quantum key data packet issued by the quantum password service platform. The quantum key injection device parses the vehicle identification number and the device serial number in the data packet, writes the quantum key matched with the vehicle identification number and the device serial number into the quantum key storage area of the super SIM card, and activates the hardware-level access lock of the security chip, so that the key can only be read through authorized decryption operation. In other embodiments, for the super SIM card replacement scene, the authorized personnel operate the offline quantum key injection device to connect the local key backup library. The sub-key injection device automatically identifies the vehicle attribute information corresponding to the faulty card, extracts the three groups of quantum keys recently used by the vehicle from the backup library, and synchronously injects the secure storage partition of the new super SIM card by using the fragmentation writing technology. After preloading is completed, the device generates a key binding certificate and burns it into the read-only area in the card, realizing seamless binding of the new carrier and the original vehicle identity.
[0057] In this way, the quantum key is preloaded into the secure password carrier in a physically isolated environment by using the quantum key injection device, and the network transmission risk during the first distribution of the key is avoided from the source. By offline preloading, a hardware-level binding relationship between the device and the key is established, so that the secure password carrier has an unforgeable device identity certificate before deployment, thereby eliminating the eavesdropping or man-in-the-middle attack risk in the initial trust establishment stage before the key is enabled. This mechanism provides a verifiable trust anchor for the quantum key distribution process, and ensures that the security of the subsequent first channel key transmission is based on the reliability of the device identity authenticity.
[0058] Optionally, the train data encrypted by the quantum key is transmitted through the second channel, including: encrypting the secure password carrier using the quantum key transmitted through the first channel, so that the secure password carrier is in an unusable state; decrypting the secure password carrier using the quantum security gateway, so that the secure password carrier is in a usable state; when the decrypted secure password carrier is inserted into the train-ground wireless communication device, encrypting the train data using the quantum key pre-installed in the secure password carrier, and transmitting the encrypted train data.
[0059] In the embodiments of the present application, the quantum security gateway receives the quantum key distributed by the quantum cryptography service platform through the quantum channel, and calls the high-speed rail vehicle type exclusive encryption algorithm library to process the key. The processed encryption instruction is written to the super SIM card control module, and the hardware locking mechanism in the card is activated to make the secure password carrier in an unusable state. When the authorized personnel inserts the encrypted super SIM card into the quantum security gateway special interface, the quantum security gateway verifies the device digital certificate and performs quantum-level decryption operation to release the function restriction of the secure password carrier. When the secure password carrier is inserted into the card slot of the train-ground wireless communication device, the security chip of the train-ground wireless communication device automatically reads the pre-installed quantum key, performs national secret algorithm encryption on the real-time collected train positioning data, and sends the ciphertext data packet through the wireless transmission module. In other embodiments, the quantum cryptography service platform transmits the subway vehicle type exclusive quantum key to the quantum security gateway through the quantum channel. The quantum security gateway converts the key format using the subway encryption strategy, and performs quantum state writing operation on the super SIM card key storage area to trigger the physical locking function of the security chip. In the train repair depot, the operator places the locked super SIM card into the decryption terminal of the quantum security gateway, and the decryption terminal of the quantum security gateway completes the decryption activation of the super SIM card through a two-way authentication protocol. After the super SIM card is loaded into the train-ground wireless communication device, the train-ground wireless communication device calls the pre-installed key of the super SIM card to encrypt the speed sensor data in real time, and the encrypted data stream is transmitted to the ground terminal through the special wireless channel.
[0060] In this way, the secure password carrier is encrypted using the quantum key transmitted through the first channel, so that the secure password carrier is in an unusable state, and non-authorized access in the transportation process is blocked by physical isolation means. Then, the secure password carrier is restored to a usable state by authorized decryption of the quantum security gateway, realizing double authority control in the key enabling stage. When the decrypted secure password carrier is inserted into the train-ground wireless communication device, the pre-installed quantum key is called to encrypt the data, ensuring that the whole process from storage to use of the key is in a hardware-level secure environment. By establishing a dynamic encryption and decryption barrier in the key distribution and device enabling link, the key leakage risk of the secure password carrier in the transportation and storage stages is eliminated, and secondary identity authentication is forced to be completed before the device is used, providing end-to-end security for train-ground communication.
[0061] Optionally, the train data is encrypted using a quantum key pre-stored in the secure cryptographic carrier, including: reading the quantum key pre-installed in the secure cryptographic carrier using the train-ground wireless communication device, and performing symmetric encryption on the train data using a national cryptographic algorithm.
[0062] In the embodiments of the present application, the train-ground wireless communication device reads the pre-installed quantum key of the super SIM card through the secure chip interface, calls the built-in national cryptographic algorithm encryption engine after extracting the key. The train-ground wireless communication device divides the real-time collected running state data of the train into data blocks, and encrypts the data content block by block using the quantum key as the symmetric encryption key of the national cryptographic algorithm. Key identifiers and timestamps are added during the encryption process, and after generating complete ciphertext data packets, they are sent through the wireless transmission module. In some other embodiments, when the train-ground wireless communication device detects that the main super SIM card is invalid, it automatically switches to the backup card slot to read the pre-installed quantum key in the backup super SIM card. The security processing unit of the train-ground wireless communication device calls the national cryptographic algorithm library and combines the current key to perform real-time frame encryption processing on the train positioning data stream. Each data frame adds a frame check sequence and an encryption protocol header to form an encrypted message that conforms to the wireless transmission protocol and is continuously sent to the ground receiving end.
[0063] In this way, the train-ground wireless communication device directly reads the pre-installed quantum key in the secure cryptographic carrier, uses a hardware-level isolation mechanism to prevent the key from being intercepted by unauthorized programs during the reading process, and then uses a national cryptographic algorithm to perform symmetric encryption on the train data. Combined with the unbreakable nature of the quantum key and the independent controllability of the national standard algorithm, the encryption strength is guaranteed while meeting the safety compliance requirements in the field of rail transit. Through the synergistic effect of the hardware carrier and the national cryptographic algorithm, the risk of key leakage and algorithm cracking during encryption is reduced, providing data protection capabilities for train-ground communication that take into account efficiency and security.
[0064] Optionally, the rail transit quantum communication system data transmission method further includes: receiving the encrypted train data using a ground security gateway, and performing traffic filtering and access control to block illegal requests; using a ground decryption server to parse the key address in the encrypted train data, and applying for the corresponding decryption quantum key from the quantum cryptographic service platform; using the quantum cryptographic service platform to verify the legality of the key address, and issuing the decryption quantum key to the ground decryption server; causing the ground decryption server to decrypt the encrypted train data based on the national cryptographic algorithm using the decryption quantum key, and transmitting the decrypted train data to the ground business system for analysis and processing.
[0065] In the embodiments of the present application, the ground security gateway receives the encrypted data stream sent by the train-ground wireless communication device, performs white list filtering on the data source address through the preset access control strategy, and intercepts illegal data requests sent by unauthorized devices. The ground decryption server parses the key address field in the encrypted data packet header, extracts the vehicle identification number and device serial number combination identifier, and submits a decryption key application to the quantum cryptography service platform. The quantum cryptography service platform checks the consistency of the combination identifier with the pre-stored device white list, and after verification, the corresponding decryption quantum key is issued through the quantum channel. The ground decryption server calls the key to restore the plaintext data combined with the national secret algorithm decryption engine, and after data verification, the data is transmitted to the ground operation monitoring system for real-time analysis. In other embodiments, when the encrypted train data arrives at the ground security gateway, the ground security gateway activates the traffic shaping module to block high-frequency abnormal access requests, and only data packets carrying valid quantum encryption protocol identifiers are released. The ground decryption server extracts the key index code from a specific position in the data frame and initiates a key application request with a digital signature to the quantum cryptography service platform. After the quantum cryptography service platform verifies the vehicle registration state and the key validity period associated with the index code, it returns the decryption quantum key transmitted through the encrypted channel to the decryption server. The decryption server uses the key to perform reverse operation of the national secret algorithm, restores the original train operation data and pushes it to the ground fault diagnosis system for automatic processing.
[0066] In this way, the ground security gateway receives encrypted data and performs traffic filtering and access control, effectively intercepting illegal requests and attack traffic in public network environments, reducing security threats to data transmission channels. The ground decryption server parses the key address in the encrypted data and applies for a decryption key to the quantum cryptography service platform, and through the precise matching mechanism of the key address and the vehicle identity identifier, the object legality of the decryption key application is ensured. After the quantum cryptography service platform verifies the legality of the key address, it issues the decryption key, and the ground decryption server completes the decryption operation based on the national secret algorithm, forming a closed-loop control process of key application, verification and issuance. Through multi-layer collaborative verification, the security and reliability of the decryption process are improved, and the application of the national secret algorithm ensures the decryption efficiency and compliance, providing a trusted data source for ground business systems.
[0067] Optionally, the rail transit quantum communication system data transmission method further comprises: using the quantum cryptography service platform to distribute the newly generated quantum key to each node of the communication system through the first channel to realize dynamic updating of the quantum key of each node; wherein the nodes include the train-ground wireless communication device and / or the ground decryption server.
[0068] In the embodiments of the present application, after the quantum password service platform detects that the preset key update period arrives, the quantum key generation and management terminal is instructed to generate a new quantum key string. The quantum password service platform distributes the key to the train-ground wireless communication equipment security chip through the quantum channel. After the train-ground wireless communication equipment receives the key, it automatically replaces the old key storage area content and updates the local key version index, completing the dynamic update of the on-board node key. In other embodiments, when the quantum password service platform detects that the quantum channel transmission error rate is abnormal, it immediately triggers an emergency key update process. The quantum password service platform controls the terminal to generate a backup quantum key, which is synchronously distributed to the ground decryption server key pool and the train-ground wireless communication equipment through the quantum channel. The decryption server writes the new key into the active storage partition, and the train-ground equipment switches the encryption module interface to achieve seamless replacement of all node keys.
[0069] In this way, the quantum password service platform periodically distributes new quantum keys to each node of the communication system, including the train-ground wireless communication equipment and the ground decryption server, through the first channel, and uses the dynamic rotation mechanism of the quantum key to reduce the probability of breaking the same key for a long time. By transmitting the new key through the first channel, the security of the key update process itself is ensured. After each node updates the key synchronously, even if some historical keys are leaked, the security of subsequent encrypted communication can be ensured. Through periodic key update and the physical isolation characteristics of the quantum channel, the continuous defense capability of the train-ground communication system against quantum computing attacks is improved.
[0070] Optionally, it is determined that the train-ground wireless communication equipment respectively arranged in the first car and the second car are master equipment and backup equipment; wherein the master equipment and the backup equipment perform heartbeat monitoring through a data synchronization bus; when it is monitored that the master equipment does not respond for a set number of times in succession, it is determined that the security password carrier corresponding to the master equipment is faulty, and the backup equipment is switched to take over the encryption transmission function assumed by the master equipment.
[0071] In the embodiments of the present application, when the security password carrier fails, the head and tail carriages' train-ground wireless communication devices perform heartbeat monitoring through the data synchronization bus. When the main device of the head carriage does not respond for a continuous set number of times, the switching mechanism is triggered, and the standby device of the tail carriage takes over the encryption transmission function. Specifically, the train-ground wireless communication device of the head carriage as the main device continuously sends heartbeat signals through the data synchronization bus, and the train-ground wireless communication device of the tail carriage as the standby device monitors the heartbeat signals sent by the train-ground wireless communication device of the head carriage in real time. When the standby device detects that the main device heartbeat signal is continuously lost for a set number of times, it immediately activates its encryption transmission module to take over the data transmission function. The standby device reads the local super SIM card preloaded quantum key and seamlessly continues the encryption and sending tasks of the train operation data undertaken by the main device. In other embodiments, the main and standby train-ground wireless communication devices establish a bidirectional state monitoring channel through the data synchronization bus. The main device periodically sends heartbeat data packets containing encryption status codes, and the standby device checks the validity of the status codes. When the standby device continuously receives invalid status codes for a set number of times, the standby device automatically switches to the working host, starts its wireless communication module and security chip, and calls the quantum key in the standby device corresponding to the super SIM card to continue the train data encryption transmission.
[0072] In this way, when the super SIM card fails, the train-ground wireless communication devices of the head and tail carriages perform heartbeat monitoring through the data synchronization bus, and when the main device does not respond for a continuous set number of times, the switching mechanism is triggered, and the millisecond-level main and standby switching is realized by using the device-level hardware redundancy architecture. The standby device physically isolated in real time takes over the encryption transmission function, effectively avoids the risk of communication interruption caused by single point failure, and improves the continuous operation ability of the train-ground communication system. The dual-device cooperative working mode ensures the continuity of quantum encryption transmission when the core security component fails, and provides uninterrupted security protection for the key train operation data.
[0073] Optionally, when the security password carrier fails and / or there is no available standby device, the most recent set number of groups of quantum keys cached in the local security chip of the train-ground wireless communication device are called to continue encrypting the train data, and a temporary quantum key with an effective period less than a set time length is applied to the quantum password service platform for subsequent encryption or decryption operations.
[0074] In the embodiments of the present application, when the train-ground wireless communication device detects that the super SIM card key reading fails, the locally cached latest available quantum key group in the security chip is immediately started. The train-ground wireless communication device automatically calls the latest valid key in the key group, and performs continuous encryption operation on the real-time running data of the train in combination with the national encryption algorithm. At the same time, the train-ground wireless communication device sends a temporary key application request to the quantum cryptography service platform through the encrypted communication link. The cryptography service platform generates and issues a short-term valid quantum key for subsequent encryption after responding. In some other embodiments, when the super SIM card hardware fails and the quantum key access is interrupted, the security processing unit of the train-ground wireless communication device automatically switches to the key cache area. The train-ground wireless communication device calls the latest stored several groups of quantum keys in time reverse order, and selects the available keys to encrypt and package the train speed data by using the polling mechanism. The temporary key application protocol is triggered synchronously, and the quantum cryptography service platform distributes the time-limited quantum key after verifying the device identity. The train-ground wireless communication device receives the key and immediately applies it to the encryption processing of the new data packet.
[0075] In this way, when the train-ground wireless communication device detects that the super SIM card is invalid, the latest set number of quantum key groups cached in the local security chip are called to continue encrypting data, and the hardware-level key temporary storage mechanism provides a buffer period for emergency communication. At the same time, a temporary quantum key with an effective period less than a set time length is applied to the quantum cryptography service platform, and the centralized control ability of the platform is used to realize the safe supply of short-term keys. The continuity of encrypted transmission is maintained, and the risk of long-term exposure of keys is reduced through the time limitation of temporary keys. On the premise of ensuring uninterrupted train-ground communication, the adaptive recovery capability of the system to hardware failure is improved.
[0076] Optionally, according to the vehicle type, the encryption algorithm library corresponding to the vehicle type is called to process the original quantum key generated and managed by the terminal to generate the first quantum key corresponding to the vehicle type.
[0077] In the embodiment of the present application, the quantum security gateway adopts a vehicle model differentiation strategy for secondary encryption of the secure password carrier. For high-speed rail vehicles, a first encryption algorithm library is called to process the original quantum key generated and managed by the terminal to generate a first quantum key corresponding to the high-speed rail vehicle. For subway vehicles, a second encryption algorithm library is called to process the original quantum key to generate a first quantum key corresponding to the subway vehicle. Specifically, after receiving the original quantum key generated and managed by the terminal, the quantum security gateway calls the preset first encryption algorithm library for processing for high-speed rail vehicles. The algorithm library performs a composite operation on the high-speed rail dedicated equipment feature code and the original key to generate a first quantum key corresponding to the high-speed rail vehicle. The high-speed rail exclusive encryption key is written into the super SIM card control module through the first channel to realize binding with the encryption strategy of the high-speed rail system. When processing the subway vehicle scenario, the quantum security gateway activates the key conversion engine in the second encryption algorithm library. The engine performs nonlinear transformation processing on the original quantum key and the subway equipment type identifier to generate a first quantum key corresponding to the subway vehicle. The converted subway exclusive encryption key string is written into the designated storage area of the super SIM card through the first channel, and the differentiated encryption strategy implementation for the subway vehicle is completed.
[0078] In this way, the quantum security gateway calls differentiated encryption algorithm libraries to process the original quantum key for different vehicle models, and generates exclusive encryption keys through vehicle model adapted encryption strategies. By utilizing the differences in hardware characteristics and security requirements of different vehicle models, the combination of encryption algorithms and key lengths is optimized to match the actual running environment of the vehicle, ensuring the security of the quantum key source while improving the adaptability of the encryption strategy to the actual running environment of the vehicle. Through differentiated processing, the performance loss or security redundancy caused by a unified encryption scheme is reduced, achieving a balance between security and efficiency of the train-ground communication system in complex multi-vehicle scenarios.
[0079] Optionally, the key address parsed by the decryption server includes a combined identifier of the vehicle identification number and the device serial number, and the quantum password service platform verifies that the combined identifier is consistent with the pre-stored device whitelist before issuing the decryption quantum key.
[0080] In an embodiment of the present application, the ground decryption server parses the header field of the encrypted data packet and extracts the combined identifier of the vehicle identification number and the serial number of the vehicle-to-ground wireless communication device. The decryption server encapsulates the combined identifier into a key application request and sends it to the quantum cryptography service platform via a secure channel. The quantum cryptography service platform searches the pre-stored device whitelist database, verifies that the combined identifier completely matches the registered device information, and then sends the corresponding decryption quantum key to the decryption server through the quantum channel. In other embodiments, when the ground decryption server processes encrypted train data, it reads the concatenated string of the vehicle identification number and the device hardware serial number from a fixed offset position in the data frame. The decryption server submits a key request instruction containing the string to the quantum cryptography service platform. The quantum cryptography service platform calls the device authentication module to verify whether the concatenated string exists in the valid device whitelist. After confirmation, it generates an encrypted response message, which encapsulates the target decryption quantum key and returns it to the decryption server.
[0081] In this way, when the decryption server parses the key address in the encrypted data, it extracts the combined identifier of the vehicle identification number and the device serial number, and accurately locates the device identity through a dual hardware identification binding mechanism. The quantum cryptography service platform verifies the consistency of this combined identifier with the pre-stored device whitelist, ensuring that the decryption key is only issued to authorized devices. Using the tamper-proof device hardware identifier as a verification foundation can effectively prevent unauthorized devices from obtaining decryption permissions by forging a single code, improving the reliability of identity authentication in the vehicle-to-ground communication system and providing a traceable device trust chain for secure key distribution in complex network environments.
[0082] Optionally, the super SIM card is pre-installed with the initial quantum key and digital certificate offline through physically isolated dedicated equipment. The pre-installation process is completed in a closed environment, and each super SIM card establishes a hardware-level binding relationship with a specific vehicle-ground wireless communication device.
[0083] In an embodiment of the present application, a quantum key injection device is connected to an offline key database in an electromagnetic shielding room to extract the initial quantum key and digital certificate data packet of the target vehicle. The quantum key injection device writes to the super SIM card security storage area through a dedicated interface, and at the same time burns the physical serial number of the vehicle-to-ground wireless communication device into the read-only area of the card, thereby realizing a non-removable hardware-level binding between the super SIM card and the specific communication device. In other embodiments, authorized personnel start the offline pre-installation system in a closed operating console. The offline pre-installation system reads the hardware identification code of the vehicle-to-ground wireless communication device to be bound, and generates a composite data block in combination with the initial quantum key pre-stored in the quantum cryptography service platform. The data block is written to the super SIM card security chip through a physically isolated card writing device, and the device binding identification is burned in the chip fuse area to complete the lifelong hardware-level association between the card and the device.
[0084] In this way, the super SIM card is preloaded with initial quantum keys and digital certificates offline in a closed environment through a physically isolated dedicated device, so as to isolate the threat of network attacks to the initial key distribution process from the source. Meanwhile, each super SIM card establishes a hardware-level binding relationship with a specific vehicle-ground wireless communication device, and uses a unique physical identifier (such as a secure chip serial number) to realize an uncopyable identity authentication basis. This mechanism significantly reduces the tampering and forgery risks in the key initialization stage through the double protection of physical isolation and hardware binding, provides a verifiable trust root for the quantum key distribution system, and ensures that the security of the subsequent communication process is based on reliable device identity authentication.
[0085] In combination Figure 3 As shown in the figure, the embodiment of the present application provides a rail transit quantum communication system data transmission device 800, which includes a processor 801 and a memory 802. Optionally, the device can also include a communication interface 803 and a bus 804. Wherein the processor 801, the communication interface 803, the memory 802 can complete the mutual communication through the bus 804. The communication interface 803 can be used for information transmission. The processor 801 can call the logical instructions in the memory 802 to execute the rail transit quantum communication system data transmission method of the above-mentioned embodiment.
[0086] In addition, the logical instructions in the memory 802 described above can be implemented in the form of a software function unit and sold or used as an independent product, which can be stored in a computer readable storage medium.
[0087] The memory 802 as a kind of computer readable storage medium can be used to store software programs, computer executable programs, such as the program instructions / modules corresponding to the method in the embodiment of the present application. The processor 801 executes the program instructions / modules stored in the memory 802, thereby executing function application and data processing, i.e. realizing the rail transit quantum communication system data transmission method in the above-mentioned embodiment.
[0088] The memory 802 can include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required by a function; the data storage area can store data created according to the use of the terminal device, etc. In addition, the memory 802 can include a high-speed random access memory, and can also include a non-volatile memory.
[0089] The embodiment of the present application provides a communication system, comprising: a communication system body and the rail transit quantum communication system data transmission device 800. The rail transit quantum communication system data transmission device 800 is installed in the communication system body. The installation relationship described herein is not limited to being placed in the communication system, and also includes installation connection with other components of the communication system, including but not limited to physical connection, electrical connection or signal transmission connection and the like. Those skilled in the art can understand that the rail transit quantum communication system data transmission device 800 can be adapted to a feasible communication system body, and thus realize other feasible embodiments.
[0090] The embodiment of the present application provides a computer readable storage medium, which stores computer executable instructions, and the computer executable instructions are configured to execute the rail transit quantum communication system data transmission method.
[0091] The technical scheme of the embodiment of the present application can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes one or more instructions to make a computer device (which can be a personal computer, a server or a network device) execute all or part of the steps of the method described in the embodiment of the present application. The storage medium can be a non-transitory storage medium, including a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk and various media that can store program codes.
[0092] The technical scheme of the embodiment of the present application can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes one or more instructions to make a computer device (which can be a personal computer, a server or a network device) execute all or part of the steps of the method described in the embodiment of the present application. The storage medium can be a non-transitory storage medium, including a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk and various media that can store program codes.
[0093] The above description and the accompanying drawings fully illustrate the embodiments of the present application so that those skilled in the art can practice them. Other embodiments may include structural, logical, electrical, process and other changes. The embodiments represent only possible variations. Unless explicitly required, separate components and functions are optional, and the order of operations may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. Moreover, the words used in this application are only used to describe the embodiments and are not used to limit the claims. As used in the description of the embodiments and claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to also include plural forms. Similarly, the term "and / or" as used in this application refers to any and all possible combinations of one or more associated listings. In addition, when used in this application, the term "comprise" and its variations "comprises" and / or comprising refer to the presence of stated features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups thereof. In the absence of further restrictions, an element defined by the statement "comprises a..." does not exclude the presence of other identical elements in the process, method or device that includes the element. In this article, each embodiment may focus on the differences from other embodiments, and the same and similar parts between the various embodiments can be referenced to each other. For the methods, products, etc. provided in the embodiments, if they correspond to the method part provided in the embodiments, then the relevant parts can be found in the description of the method part.
[0094] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments provided herein can be implemented with electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software may depend on the specific application and design constraints of the technical solution. The technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the embodiments of the present application. The technicians will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0095] In the embodiments disclosed herein, the disclosed methods, products (including but not limited to apparatuses, devices, etc.), can be implemented in other manners. For example, the apparatus embodiments described above are merely schematic. For example, the division of the units is merely logical function division. There can be other division manners in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or among them, can be indirect couplings or communication connections through some interfaces, devices, or units, and can be in electric, mechanical, or other forms.
[0096] The flowcharts and block diagrams in the drawings show the possible implementation architectures, functions, and operations of the systems, methods, and computer program products according to the embodiments of the present application. In this regard, each block in the flowcharts or block diagrams can represent a module, a program segment, or a part of code, which contains one or more executable instructions for implementing the specified logical functions. In some alternative implementations, the functions noted in the blocks can occur in different orders from those noted in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and sometimes they can be executed in reverse order, depending on the functions involved. In the descriptions corresponding to the flowcharts and block diagrams in the drawings, the operations or steps corresponding to different blocks can also occur in different orders from those disclosed in the descriptions, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps can actually be executed substantially in parallel, and sometimes they can be executed in reverse order, depending on the functions involved. Each block in the block diagrams and / or flowcharts, and the combination of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
Claims
1. A data transmission method for a rail transit quantum communication system, characterized in that: include: performing quantum key distribution via a first channel; The train data encrypted with quantum key is transmitted through the second channel.
2. The method according to claim 1, characterized in that Performing quantum key distribution via the first channel, including: generating a first quantum key corresponding to the vehicle attribute; The secure cryptographic carrier is encrypted by transmitting the first quantum key through the first channel.
3. The method according to claim 1, characterized in that Before quantum key distribution is performed through the first channel, the method further includes: Use a quantum key injection device to pre-install the quantum key into a secure cryptographic carrier.
4. The method according to claim 1, wherein The train data encrypted by quantum key is transmitted through the second channel, including: encrypting the secure cryptographic carrier using the quantum key transmitted via the first channel, thereby rendering the secure cryptographic carrier unusable; Use the quantum security gateway to decrypt the secure cryptographic carrier, making it available; When the decrypted secure cryptographic carrier is inserted into the train-ground wireless communication device, the train data is encrypted using the quantum key pre-installed in the secure cryptographic carrier, and the encrypted train data is transmitted.
5. The method according to claim 4, characterized in that Encrypt train data using quantum keys pre-stored in a secure cryptographic carrier, including: Use the train-ground wireless communication equipment to read the quantum key pre-installed in the secure cryptographic carrier, and use the national secret algorithm to symmetrically encrypt the train data.
6. The method according to any one of claims 1 to 5, characterized in that Also includes: Use a ground security gateway to receive encrypted train data, perform traffic filtering and access control, and block illegal requests; Use the ground decryption server to parse the key address in the encrypted train data and apply for the corresponding decryption quantum key from the quantum cryptography service platform; After verifying the legitimacy of the key address using the quantum cryptography service platform, the decrypted quantum key is sent to the ground decryption server; The ground decryption server decrypts the encrypted train data using the decryption quantum key based on the national secret algorithm, and transmits the decrypted train data to the ground business system for analysis and processing.
7. The method according to any one of claims 1 to 5, characterized in that Also includes: The quantum cryptography service platform is used to distribute regularly generated new quantum keys to each node of the communication system through the first channel to achieve dynamic update of the quantum keys of each node; wherein the nodes include vehicle-ground wireless communication equipment and / or ground decryption servers.
8. The method according to any one of claims 1 to 5, characterized in that Also includes: Determine that the vehicle-ground wireless communication devices respectively provided in the first carriage and the second carriage are the main device and the backup device; wherein the main device and the backup device perform heartbeat monitoring via a data synchronization bus; When it is detected that the main device does not respond for a set number of consecutive times, it is determined that the security password carrier corresponding to the main device is faulty, and the backup device is switched to take over the encryption transmission function undertaken by the main device.
9. The method according to claim 8, characterized in that Also includes: When the security cryptographic carrier fails and there is no available backup equipment, the most recently set number of quantum keys cached in the local security chip of the train-ground wireless communication device are called to continue encrypting the train data, and a temporary quantum key with a validity period less than the set time is applied to the quantum cryptography service platform for subsequent encryption or decryption operations.
10. A data transmission device for a rail transit quantum communication system, comprising a processor and a memory storing program instructions, characterized in that: The processor is configured to execute the rail transit quantum communication system data transmission method according to any one of claims 1 to 9 when running the program instructions.
11. A communication system, characterized in that: include: Communication system ontology; The rail transit quantum communication system data transmission device according to claim 10 is installed in the communication system body.
12. A computer-readable storage medium storing program instructions, characterized in that: When the program instructions are executed, the computer is used to execute the data transmission method for a rail transit quantum communication system according to any one of claims 1 to 9.
Citation Information
Patent Citations
Power distribution terminal encryption communication system and method based on quantum encryption
CN114745109A
Multi-user QKD system and method with priority ranking function
CN117879805A
Quantum encryption communication method, device and equipment for rail transit signal system
CN119316128A
Data transmission method and device, computer equipment and readable storage medium
CN119743754A
Data transmission method and device and data transmission system
CN119945786A
Cited By
Vehicle and cloud communication method, electronic equipment and vehicle
CN121547272A
Network security isolation system based on rail transit vehicle network information processing
CN121585462A