A railway track traffic control management method and system

By analyzing the vulnerabilities of the NTP protocol and verifying dynamic keys, a synchronization timestamp is generated, real-time train operation parameters are collected, and the tracking interval is determined. This solves the problems of safety and efficiency in train operation control and achieves precise time synchronization and safe control of the railway system.

CN121985315BActive Publication Date: 2026-06-26LANZHOU JIAOTONG UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-04-03
Publication Date
2026-06-26

Smart Images

  • Figure CN121985315B_ABST
    Figure CN121985315B_ABST
Patent Text Reader

Abstract

The application provides a railway track traffic control management method and system, and relates to the technical field of railway track traffic control.The method comprises the following steps: establishing a time synchronization network based on a railway NTP protocol; using a colored Petri net model to perform vulnerability state reachability analysis on an NTP protocol authentication process based on a trusted certificate, and judging whether the current protocol has vulnerability; determining a first dynamic key and a second dynamic key according to key parameters of the NTP protocol authentication process; performing verification according to the first dynamic key and the second dynamic key; if the verification is passed, correcting a synchronization time signal; generating a synchronization timestamp for a target train; collecting real-time running parameters; determining a tracking interval time; and generating and issuing a control instruction.According to the application, the running state of the train can be controlled according to the communication security state and the tracking interval time, and the reliability of the real-time running parameters in time and the line utilization rate of the train are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of railway track traffic control technology, and in particular to a railway track traffic control and management method and system. Background Technology

[0002] Current technologies, while using traffic signals and communications to control train safety, do not consider the impact of communication security and tracking intervals on train operation. In other words, they cannot control train operation based on communication security status and tracking intervals.

[0003] The information disclosed in the background section of this application is intended only to enhance the understanding of the general background of this application and should not be construed as an admission or in any way implying that the information constitutes prior art known to those skilled in the art. Summary of the Invention

[0004] This invention provides a railway track traffic control and management method and system, which can solve the technical problem that related technologies cannot control the train operation status based on communication security status and tracking interval.

[0005] According to a first aspect of the present invention, a railway track traffic control and management method is provided, comprising: establishing a railway-based NTP protocol time synchronization network, wherein the time synchronization network includes at least one primary time node and at least one secondary time node; performing vulnerability state reachability analysis on the NTP protocol authentication process based on trusted certificates using a colored Petri net model to determine whether the current protocol has vulnerabilities; if the current protocol has vulnerabilities, determining a first dynamic key and a second dynamic key based on key parameters of the NTP protocol authentication process, wherein the key parameters include a primary time node public key, a primary time node private key, and a secondary time node public key; performing verification based on the first dynamic key and the second dynamic key; if the verification is successful, correcting the synchronization time signal based on the timestamp information in the time synchronization response message; generating a synchronization timestamp for a target train based on the synchronization time signal; collecting real-time operating parameters of the target train in a target track section based on the synchronization timestamp, wherein the real-time operating parameters include the train's instantaneous speed and instantaneous acceleration; determining a tracking interval time based on the real-time operating parameters; and generating and issuing control commands to the onboard equipment of the target train and its subsequent trains based on the tracking interval time.

[0006] Furthermore, a colored Petri net model is used to perform vulnerability state reachability analysis on the NTP protocol authentication process based on trusted certificates to determine whether the current protocol has vulnerabilities. This includes: constructing a formal model, wherein the formal model includes a normal NTP protocol authentication process CPN model based on trusted certificates and an authentication process CPN model with man-in-the-middle intrusion; and verifying, through vulnerability state reachability analysis, whether there is an insecure termination state in the protocol authentication process under a man-in-the-middle attack. If so, the current protocol is determined to have vulnerabilities.

[0007] Furthermore, the construction of the formal model includes: establishing a normal authentication process CPN model between the first-level and second-level time nodes based on the NTP protocol interaction sequence based on trusted certificates. The normal authentication process CPN model includes multiple libraries and transitions to describe the authentication process of cookie requests, cookie responses, time synchronization requests, and time synchronization responses. In the normal authentication process CPN model, a man-in-the-middle node is added to construct an authentication process CPN model with added man-in-the-middle intrusion. The man-in-the-middle node simulates an attack on the protocol authentication process by intercepting, tampering with, and forwarding communication messages between the first-level and second-level time nodes.

[0008] Furthermore, if the current protocol has vulnerabilities, the first dynamic key and the second dynamic key are determined based on the key parameters of the NTP protocol authentication process, including: obtaining the network address identification information of the first-level time node and the network address identification information of the second-level time node; obtaining the first-level random number generated by the first-level time node and the first-level timestamp when the random number was generated; obtaining the second-level random number generated by the second-level time node and the second-level timestamp when the random number was generated; and determining the first dynamic key and the second dynamic key based on the key parameters, the network address identification information of the first-level time node, the network address identification information of the second-level time node, the first-level random number, the first-level timestamp, the second-level random number, and the second-level timestamp.

[0009] Further, based on the key parameters, the network address identifier information of the first-level time node, the network address identifier information of the second-level time node, the first-level random number, the first-level timestamp, the second-level random number, and the second-level timestamp, the first dynamic key and the second dynamic key are determined, including: according to the formula: , Determine the first dynamic key Second dynamic key ,in, For collision-resistant hash functions, This is the public key for the first-level time node. This is the public key for the second-level time node. This is a level 1 random number. It is a level 2 random number. This is a first-level timestamp. It is a second-level timestamp. This is the private key for the first-level time node. To obtain the x-coordinate of a point by performing a dot product operation on an elliptic curve, Network address identification information for the first-level time node. Network address identification information for secondary time nodes, For bit string concatenation operations, This is a bitwise XOR operation.

[0010] Further, verification based on the first dynamic key and the second dynamic key includes: a secondary time node sending a time synchronization request message to a primary time node, wherein the time synchronization request message contains a first message authentication code generated based on the first dynamic key; the primary time node receiving the time synchronization request message, verifying the first message authentication code based on the first dynamic key, and generating a time synchronization response message after successful verification, wherein the time synchronization response message contains a second message authentication code generated based on the second dynamic key; and the secondary time node receiving the time synchronization response message and verifying the second message authentication code based on the second dynamic key.

[0011] Further, determining the tracking interval time based on the real-time operating parameters includes: obtaining the first length of the target train and the second length of the target track section; setting the short-term prediction duration and the basic safe tracking time margin; obtaining the maximum speed limit of the target track section; and determining the tracking interval time based on the real-time operating parameters, the first length, the second length, the short-term prediction duration, the basic safe tracking time margin, and the maximum speed limit of the track.

[0012] Further, based on the real-time operating parameters, the first length, the second length, the short-term prediction duration, the basic safety tracking time margin, and the line's maximum speed limit, the tracking interval time is determined, including: according to the formula: Determine the tracking interval ,in, The first length, For the second length, The instantaneous speed of the train For the instantaneous acceleration of the train, For short-term prediction duration, Based on the margin of safety tracking time. This is the maximum speed limit for the line.

[0013] According to a second aspect of the present invention, a railway track traffic control and management system is provided, comprising: a time synchronization network module for establishing a time synchronization network based on the railway NTP protocol, wherein the time synchronization network includes at least one primary time node and at least one secondary time node; a judgment module for performing vulnerability state reachability analysis on the NTP protocol authentication process based on trusted certificates using a colored Petri net model to determine whether the current protocol has a vulnerability; a dynamic key module for determining a first dynamic key and a second dynamic key based on key parameters of the NTP protocol authentication process if the current protocol has a vulnerability, wherein the key parameters include a primary time node public key, a primary time node private key, and a secondary time node public key; and a verification module. The system includes: a module for verification based on the first dynamic key and the second dynamic key; a correction module for correcting the synchronization time signal based on the timestamp information in the time synchronization response message if the verification is successful; a synchronization timestamp module for generating a synchronization timestamp for the target train based on the synchronization time signal; a real-time operating parameter module for collecting real-time operating parameters of the target train on the target track section based on the synchronization timestamp, wherein the real-time operating parameters include the instantaneous speed and instantaneous acceleration of the train; a tracking interval time module for determining the tracking interval time based on the real-time operating parameters; and a control command module for generating and issuing control commands to the onboard equipment of the target train and its subsequent trains based on the tracking interval time.

[0014] Technical Effects: According to this invention, by employing a colored Petri net model to perform vulnerability and reachability analysis on the NTP protocol authentication process based on trusted certificates, the first and second dynamic keys are determined and verified, effectively preventing malicious attacks and unauthorized access, and providing a precise and unified time reference for the entire railway system. Based on this, a synchronization timestamp is generated, thereby accurately collecting real-time train operating parameters and improving the temporal reliability of these parameters. Determining the tracking interval based on real-time operating parameters allows trains to maintain a safe distance, improving line utilization. When determining the first and second dynamic keys, the timestamp is used as a key parameter for generating the first dynamic key, and information from both parties is fused through an XOR operation, improving the forward and backward security of the first dynamic key and reducing the risk of complete key cracking due to random number leakage from one party. By introducing elliptic curve multiplication, the second dynamic key is strongly bound to both parties, achieving the integration of identity authentication and key negotiation. No third party can calculate the key without possessing the private key of the communicating party, greatly enhancing authentication security. When determining the tracking interval, short-term predictions can be used to understand the target train's operation within that timeframe, thus ensuring a safe distance between trains. The tracking interval can be dynamically adjusted based on different track conditions, enabling trains to operate safely and efficiently in various track environments.

[0015] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the invention. Other features and aspects of the invention will become clearer from the following detailed description of exemplary embodiments with reference to the accompanying drawings. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other embodiments can be obtained based on these drawings without creative effort.

[0017] Figure 1 A schematic flowchart of a railway track traffic control and management method according to an embodiment of the present invention is shown as an example;

[0018] Figure 2 An exemplary diagram of the NTP protocol interaction process based on a trusted certificate according to an embodiment of the present invention is shown.

[0019] Figure 3 An exemplary model of the normal authentication process of the NTP protocol based on a trusted certificate, according to an embodiment of the present invention, is shown.

[0020] Figure 4 An illustrative example of an authentication process CPN model incorporating man-in-the-middle intrusion according to an embodiment of the present invention is shown;

[0021] Figure 5 A flowchart illustrating the calculation of a first dynamic key and a second dynamic key according to an embodiment of the present invention is shown as an example.

[0022] Figure 6 An exemplary flowchart of the verification process according to an embodiment of the present invention is shown;

[0023] Figure 7 An exemplary flowchart illustrating the calculation of the tracking interval time according to an embodiment of the present invention is shown;

[0024] Figure 8 A block diagram of a railway track traffic control and management system according to an embodiment of the present invention is shown as an example. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0026] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0027] Figure 1An exemplary flowchart of a railway track traffic control and management method according to an embodiment of the present invention is shown. The method includes: Step S1, establishing a time synchronization network based on the railway NTP protocol, wherein the time synchronization network includes at least one primary time node and at least one secondary time node; Step S2, performing vulnerability state reachability analysis on the NTP protocol authentication process based on trusted certificates using a colored Petri net model to determine whether the current protocol has vulnerabilities; Step S3, if the current protocol has vulnerabilities, determining a first dynamic key and a second dynamic key based on the key parameters of the NTP protocol authentication process, wherein the key parameters include the primary time node public key, the primary time node private key, and... Secondary time node public key; Step S4, verify according to the first dynamic key and the second dynamic key; Step S5, if the verification is successful, correct the synchronization time signal according to the timestamp information in the time synchronization response message; Step S6, generate a synchronization timestamp for the target train according to the synchronization time signal; Step S7, collect the real-time operating parameters of the target train in the target track section according to the synchronization timestamp, wherein the real-time operating parameters include the instantaneous speed and instantaneous acceleration of the train; Step S8, determine the tracking interval time according to the real-time operating parameters; Step S9, generate and send control commands to the on-board equipment of the target train and its subsequent trains according to the tracking interval time.

[0028] The railway track traffic control and management method according to embodiments of the present invention employs a colored Petri net model to perform vulnerability and reachability analysis on the NTP protocol authentication process based on trusted certificates, determines and verifies the first and second dynamic keys, effectively preventing malicious attacks and unauthorized access, and providing a precise and unified time reference for the entire railway system. Based on this, a synchronization timestamp is generated, thereby accurately collecting real-time train operating parameters and improving the temporal reliability of these parameters. Determining the tracking interval based on the real-time operating parameters allows for maintaining a safe distance between trains, improving track utilization.

[0029] According to one embodiment of the present invention, in step S1, key equipment such as the signaling system, train control system, and communication system in the railway have high requirements for time synchronization. Therefore, it is necessary to establish a time synchronization network based on the NTP (Network Time Synchronization) protocol of the railway, with the first-level time node being the server and the second-level time node being the client.

[0030] According to an embodiment of the present invention, in step S2, a colored Petri net model is used to perform vulnerability state reachability analysis on the NTP protocol authentication process based on trusted certificates to determine whether the current protocol has vulnerabilities.

[0031] According to an embodiment of the present invention, step S2 includes: constructing a formal model, wherein the formal model includes a normal authentication process CPN (Colored Petri Net) model of the NTP protocol based on trusted certificates and an authentication process CPN model with man-in-the-middle intrusion added; through vulnerability state reachability analysis, verifying whether there is an insecure termination state in the protocol authentication process under man-in-the-middle attack, and if so, determining that the current protocol has a vulnerability.

[0032] According to an embodiment of the present invention, the construction of the formal model includes: establishing a normal authentication process CPN model between the first-level time node and the second-level time node based on the NTP protocol interaction sequence based on trusted certificates. The normal authentication process CPN model includes multiple libraries and transitions to describe the authentication process of cookie request, cookie response, time synchronization request, and time synchronization response. In the normal authentication process CPN model, a man-in-the-middle node is added to construct an authentication process CPN model with added man-in-the-middle intrusion. The man-in-the-middle node performs attack simulation on the protocol authentication process by intercepting, tampering with, and forwarding communication messages between the first-level time node and the second-level time node.

[0033] According to one embodiment of the present invention, Figure 2 An exemplary diagram illustrates the interaction process of the NTP protocol based on a trusted certificate according to an embodiment of the present invention. ServerB is the server, ClientA is the client, Assoc_Request is the association request, Assoc_Response is the association response, Cert_Request is the certificate request, Cert_Response is the certificate response, cookie_Request is the cookie request, cookie_Response is the cookie response, Syns_Request is the time synchronization request, Syns_Response is the time synchronization response, PK... A SK is the client's public key. B The server's private key, the NTP packet is a time synchronization request message, keyID is the key ID, and MAC address is the MAC address. asyn The message authentication code is 'NTP packet', and the time synchronization response message is 'NTP packet'. The specific steps are as follows: Initial association: The client and server exchange symmetric digest keys and hostnames. The initial association message contains a 32-bit state field and the symmetric digest key and hostname. The 32-bit state field contains the X.509 name and the encryption algorithm information used by the server and client. Certificate exchange: The client sends a certificate request message CERT_Request, containing the server name B obtained during the initial association process. Server B replies with a message CERT_Reponse containing a certificate, from which the client obtains the server's public key PK.B The client requests a cookie from the server. Using this cookie, the client verifies the server's identity and the integrity of data packets. The client also requests time synchronization from the server, sending a Syns_Request message (containing timestamp T1). Upon receiving this message, the server constructs a Syns_Response message (containing timestamps T1, T2, and T3) and sends it to the client. Upon receiving the response message (containing timestamp T4), the client calculates the NTP message's periodic delay and time deviation θ based on these four timestamps, and finally adjusts its local time accordingly. In other words, the client sends a message containing its public key (PK). A The server receives the cookie request message cookie_Request and first follows the first formula. Calculate the cookie, where ClientIP is the client's IP address, ServerIP is the server's IP address, and ServerSeed is a 32-bit random value, which is then used to perform a key-click operation using the public key sent by the client. A The calculated cookie is encrypted to obtain {cookie}PK. A Place it in the extended domain, using the server private key SK. B Encrypt the cookie to obtain the signature {cookie}SK B The server will PK {cookie} A and {cookie}SK B The data packet is sent to the client along with the server's public key obtained during the certificate exchange phase. Upon receiving the data packet, the client first uses the server's public key obtained during the certificate exchange phase to perform a PK test. B Verify the server signature, then use the client's own private key SK. A After decryption, the cookie is obtained. The client retrieves the secret cookie value from the server. Client A sends a Syns_Request message containing the keyID and MAC address. asyn And a time synchronization request NTP packet. The client uses the cookie obtained from the server and the keyID it chooses, using the second formula. Together, calculate the symmetric digest key, i.e., Autokey, where src_ip is the source IP address and dst_ip is the destination IP address. Then use the third formula... The calculated Autokey is combined with the NTP request message NTPpacket to calculate the MAC address. asynServer B receives a data packet from client A. Based on the key ID and cookie in the data packet, it calculates the symmetric digest key Autokey using the second formula, and then uses the third formula to calculate... This verifies the MAC address in the client data packet. asyn If the two match, server B sends a time synchronization response message (NTP packet) and simultaneously calculates the MAC address using the third formula. r_asyn After receiving the time response message from server B, client A calculates the Autokey and... Verify the MAC address in the server response message. r_asyn If the calculated With the MAC address in the message r_asyn If they match, it means that the cookies of the response server and the client are consistent, and it proves that the key ID in this time synchronization request message is the same as the key ID used to calculate the response MAC. At this time, the client adjusts its local time according to the timestamp in the reply message.

[0034] According to one embodiment of the present invention, Figure 3 An exemplary CPN model of the normal authentication process of the NTP protocol based on trusted certificates according to an embodiment of the present invention is shown. Based on the NTP protocol authentication execution flow based on trusted certificates, a CPN model of the first-level and second-level time nodes in the railway time synchronization network during the normal authentication process is established. The color set represented by each library is C={c1, c2, ..., c9, c10}, where c1 is the color set obtained using PK. A The generated cookie_Request message contains c2 for the cookie and c3 for the {cookie}PK. A c4 is D{{cookie}PK A ,{cookie}SK B c5 is D{keyID, MAC asyn ,NTP message}, c6 is B{MAC r_asyn NTP response message}, c7 is AC (Accept), c8 is RE (Reject), c9 is {cookie}SK B c10 is the keyID. Here, D{.} indicates that the data elements within the parentheses are grouped together. In the NTP normal authentication CPN model under the trusted certificate authentication mechanism, the secondary time node A first uses its own public key PK. A A cookie request message a1 is generated and sent to the first-level time node via transition t1. After receiving the cookie request via transition t2, the first-level time node first calculates the cookie via transition t3, and then via transitions t4 and t5... 18 Using PK respectivelyA and SK B After encryption, the encrypted information is packaged by transition t5 and sent to the secondary time node via transition t6 as a cookie response message. Upon receiving the cookie response message via transition t7, the secondary time node first uses the PK via transition t8... B Verify the cookie signature information. After successful verification, then use SK. A The cookie is obtained by decrypting via transition t9. The obtained cookie, along with KeyID and NTP packets, is then used by transition t... 10 Calculate the Message Authentication Code (MAC) asyn At the same time, MAC asyn The KeyID and NTP messages are packaged together and sent as a time synchronization request message via a transition. 11 Sent to the primary time node. The primary time node undergoes a transition t. 12 After receiving, through the transition t 13 calculate Verify the integrity of the time request message. If the verification passes, reply with a message via NTP after the transition t. 14 Calculate MAC r_asyn And construct a time synchronization response message b8, and through transition t 15 Send to the second-level time node. The second-level time node is determined by transition t. 16 After receiving, through the transition t 17 calculate This verifies the integrity of the time synchronization response message. If the verification passes, the clock deviation is calculated and the local time is corrected based on the time information in the time synchronization response message. G is A using PK. A Generate a cookie request message. a1 is the cookie request message (cookie_Request) generated by A; a2 is the cookie_Response received by B from A; a3 indicates successful verification; a4 is the decrypted cookie; a5 is the time synchronization request message (Syns_Request) generated by A; a6 is the time synchronization response message (Syns_Response) received by A; a7 indicates successful verification; a8 indicates failed verification; a9 indicates failed verification; ch1 transmits the message A sends to B; ch2 transmits the message B sends to A; ch3 transmits the message A sends to B; ch4 transmits the message B sends to A; b1 is the cookie_Request received by B from A; b2 is the cookie calculated by A; b3 is the encrypted {cookie}PK. Ab4 is the cookie response message cookie_Response generated by B, b5 is the Syns_Request sent by A received by B, b6 indicates successful verification, b7 indicates unsuccessful verification, b8 is the time synchronization response message Syns_Response generated by B, and b9 is the encrypted {cookie}SK. B b10 is the keyID.

[0035] According to one embodiment of the present invention, Figure 4 An illustrative illustration of an authentication process CPN model incorporating a man-in-the-middle attack, according to an embodiment of the present invention, is provided. The specific steps of the NTP protocol authentication process based on trusted certificates being subjected to a man-in-the-middle attack are as follows: The client sends a document containing its public key (PK). A The cookie request message cookie_Request is intercepted by a man-in-the-middle attack, and the client's public key PK is stored. A Meanwhile, the man-in-the-middle masquerades as the client and uses its own public key to perform a key-click attack. M A cookie request message 'cookie_Request' is sent to the server. After receiving the cookie request message 'cookie_Request' from the man-in-the-middle, the server first calculates the cookie according to the first formula. Then, it uses the public key PK sent by the man-in-the-middle. M And using the server's private key SK B Encrypt the cookie to obtain the signature {cookie}SK B The server will PK {cookie} M and {cookie}SK B The constructed cookie response message 'cookie_Response' is sent to the man-in-the-middle. The man-in-the-middle intercepts 'cookie_Response' and uses its own private key SK. M Decrypt to obtain the client's cookie for this synchronization request. The man-in-the-middle uses the client's public key obtained in step 1 to PK. A Encrypt the cookie and obtain the {cookie}PK. A And the {cookie}SK in the intercepted cookie response message 'cookie_Response' B The reconstructed cookie_Response is sent to the client. Upon receiving the cookie_Response from the man-in-the-middle attack, the client uses the server's public key obtained during the certificate exchange phase to perform a key check. A Verify the server signature, then use the client's own private key SK. ADecrypting the cookie yields the cookie, thus the client also obtains it. The client sends a Syns_Request time request message, which contains the keyID, an NTP time synchronization request packet, and the MAC address. asyn The man-in-the-middle intercepts the message and forwards it to the server, while simultaneously saving the keyID. Upon receiving the Syns_Request, the server first calculates the symmetric digest key Autokey using the second formula, and then calculates the symmetric digest key Autokey using the third formula. This verifies the MAC address in the Syns_Request data packet. asyn If the two match, server B sends a time synchronization response message Syns_Request, which includes an NTP packet and a MAC address. r_asyn The man-in-the-middle intercepts the Syns_Response, uses the keyID intercepted in step 5 and the cookie obtained in step 3, recalculates the Autokey according to the second formula, and tampers with the time information of the NTP packet in the time reply message. M The MAC is calculated using Autokey. r_asyn_c , MAC r_asyn_c and NTP packets M The packet is reassembled into a Syns_Response and sent to the client. Upon receiving the Syns_Response, the client first calculates the Autokey using formula (3.2), and then calculates the MAC address using the third formula. r_asyn_c ', Compare MAC r_asyn_c ' and MAC r_asyn_c The client assumes it shares a cookie with the man-in-the-middle, and that the key ID in the current request message matches the key ID used for MAC calculation in the response message. Therefore, the client corrects its local time according to the time in the tampered NTP message, allowing the man-in-the-middle to manipulate the client's time arbitrarily. Based on the above attack steps, a colored Petri net model is established to incorporate man-in-the-middle intrusion into the NTP protocol authentication process between first-level and second-level time nodes. The color set is C = {c1, c2, ..., c9, c16}, where c11 is the cookie request 'cookie_Request' generated by the man-in-the-middle using PKM, and c12 is {cookie}PKM. M c13 is D{{cookie}PK M ,{cookie}SK B}, c14 is Autokey, c15 is D{MAC r_asyn_cThe tampered NTP reply message}, where c16 is the keyID. A man-in-the-middle node is added; this node intercepts the cookie request message sent from the second-level time node to the first-level time node via transition t2 and saves the key. A Then, it disguises itself as the client's IP address and uses the man-in-the-middle's own PK (player kill) attack. M A forged cookie request message i8 (i.e., cookie_Request') is sent to the first-level time node. Upon receiving the forged cookie request, the first-level time node mistakes it for a cookie request sent by the second-level time node, calculates the cookie, and simultaneously uses the man-in-the-middle public key to perform a key-click operation. M and your own private key SK at the first time node B Encrypt, and then PK the encrypted information {cookie}. M and {cookie}SK B After being reassembled via transition t9, the packet is sent to the man-in-the-middle node as a forged cookie response message (i.e., cookie_Response). The man-in-the-middle then uses transition t... 11 Intercepted and parsed, key information for first- and second-level time-point identity authentication was obtained from the cookie library i2, and the man-in-the-middle attack was detected through changes t. 12 Using the previously saved PK A Encrypt the cookie as {cookie}PK A Then through the transition t 13 PK {cookie} A and {cookie}SK B The packet is reassembled and sent as a cookie response message (cookie_Response) to the secondary time node. The secondary time node mistakenly believes this man-in-the-middle cookie_Response message originated from the primary time node, performs normal verification and parsing, and then sends the keyID and MAC address. asyn A time request message (i.e., Syns_Request) is formed by combining NTP messages. The man-in-the-middle transitions to t 20 The keyID is intercepted and saved, then forwarded to the primary time node. The primary time node receives and parses the message before sending a time synchronization response (Syns_Response). The man-in-the-middle then uses the transition t... 26 The message was intercepted, and the time information T2 and T3 in the NTP reply message were tampered with. Then, the MAC address was recalculated using the intercepted cookie from the tampered NTP message. r_asyn_c and MAC r_asyn_c And the altered NTP message after changes t 27The packet is reassembled into an i6 and sent to the secondary time node as a tampered time response message (i.e., Syns_Response). Upon receiving the tampered time response message, the secondary time node uses the leaked cookie for verification and mistakenly believes that the time response message came from the primary time node. Therefore, it corrects its local time based on the tampered time information in the message, allowing the man-in-the-middle to arbitrarily manipulate the time of the secondary time node.

[0036] According to one embodiment of the present invention, the initial state M0 in the model is [0 ... T It is a 36-dimensional column vector, where each column represents a1~a9, ch1~ch4, i1~i9, ch5~ch8, b1~b 10 The initial states of 36 repositories are analyzed. The attack steps during the NTP protocol authentication process are analyzed, along with the insecure termination state M of the protocol. n =[0 0 AC 0 0 0 AC 0 0 0 0 0 0 0 0 0 0 0 00 0 0 0 0 0 0 0 0 0 0 0 AC 0 0 0 0] T Set the initial state M0 and the unsafe termination state M... n Substituting the state equations, in the CPN model of the authentication process with man-in-the-middle intrusion, the coefficient matrix D... T The rank is 31, and the augmented matrix (D) T M n The rank of the equation is also 31, and since both are the same, the equation has a solution. Further solving yields X = [1 ... T Therefore, the non-negative integer solution can be used to determine the attacker's attack sequence as: σ = t1t2t3t4t5t6t7t8t9t 10 t 11 t 12 t 13 t 14 t 15 t 16 t 17 t 18 t 19 t 20 t 21 t 22 t 23 t 24 t 25 t 26 t27 t 28 t 29 t 30 At this point, the unsafe termination state M can be confirmed. n Since the initial state is reachable, attacks targeting cookie requests during the NTP protocol authentication process can be achieved, thus indicating that the current protocol has a vulnerability.

[0037] According to an embodiment of the present invention, in step S3, if the current protocol is vulnerable, a first dynamic key and a second dynamic key are determined according to the key parameters of the NTP protocol authentication process, wherein the key parameters include a first-level time node public key, a first-level time node private key, and a second-level time node public key.

[0038] Figure 5 A flowchart illustrating the calculation of a first dynamic key and a second dynamic key according to an embodiment of the present invention is shown as an example.

[0039] According to an embodiment of the present invention, step S3 includes: step S31, obtaining network address identification information of a first-level time node and network address identification information of a second-level time node; step S32, obtaining a first-level random number generated by the first-level time node and a first-level timestamp when the random number is generated; step S33, obtaining a second-level random number generated by the second-level time node and a second-level timestamp when the random number is generated; step S34, determining a first dynamic key and a second dynamic key based on the key parameters, the network address identification information of the first-level time node, the network address identification information of the second-level time node, the first-level random number, the first-level timestamp, the second-level random number, and the second-level timestamp.

[0040] According to one embodiment of the present invention, a first-level time node public key is used for publicly disclosing encrypted information and verifying digital signatures. A second-level time node public key is used for receiving encrypted information and related verifications. The private key of the first-level time node is unique and confidential, possessed only by the first-level time node itself. Encryption via the private key ensures the trustworthiness and immutability of the information source. The first-level time node generates a first-level random number in its internal secure random number generator. This random number is unpredictable and unique, enhancing the security of key generation. The random number is updated once per second. Simultaneously, the first-level time node records the precise time of generating the random number, forming a first-level timestamp. The first-level timestamp serves as an important reference for time synchronization and security authentication, ensuring the traceability and verifiability of the random number generation time. The second-level time node generates a second-level random number through its own secure random number generator and records the precise time of generation, obtaining a second-level timestamp. The first and second dynamic keys are unique and secure, improving the communication security between the first and second-level time nodes.

[0041] According to an embodiment of the present invention, determining a first dynamic key and a second dynamic key based on the key parameters, the network address identification information of the first-level time node, the network address identification information of the second-level time node, the first-level random number, the first-level timestamp, the second-level random number, and the second-level timestamp includes: determining the first dynamic key according to formulas (1) and (2). Second dynamic key ,

[0042] (1),

[0043] (2),

[0044] in, For collision-resistant hash functions, This is the public key for the first-level time node. This is the public key for the second-level time node. This is a level 1 random number. It is a level 2 random number. This is a first-level timestamp. It is a second-level timestamp. This is the private key for the first-level time node. To obtain the x-coordinate of a point by performing a dot product operation on an elliptic curve, For bit string concatenation operations, This is a bitwise XOR operation.

[0045] According to an embodiment of the present invention, in formula (1), As a collision-resistant hash function, it can map input data of arbitrary length to output values ​​of fixed length and has collision resistance, meaning it is difficult to find two different inputs that produce the same output. It is often used to ensure the integrity and uniqueness of data. To concatenate the public key of the second-level time node, the public key of the first-level time node, the first-level random number, and the first-level timestamp into a new bit string, apply a collision-resistant hash function to the new bit string to obtain the first hash value. This first hash value is unique and unpredictable and can represent the characteristics of the information related to the first-level time node. To concatenate the first-level time node public key, the second-level time node public key, the second-level random number, and the second-level timestamp into a new bit string, a collision-resistant hash function is applied to obtain a second hash value. This second hash value represents the characteristics of the second-level time node information. A bitwise XOR operation is then performed on the first and second hash values. Bitwise XOR is reversible and cryptographic; only knowing the two hash values ​​can reconstruct the original result. Due to the collision resistance of the hash function, it is very difficult for attackers to deduce the first dynamic key from known information, thus ensuring the security of the first dynamic key. Simultaneously, the introduction of the timestamp makes each generated first dynamic key time-sensitive; even the same random number will generate different keys at different times, effectively resisting replay attacks.

[0046] According to an embodiment of the present invention, in formula (2), the elliptic curve dot product operation has unidirectional and nonlinear characteristics and is often used in key exchange and encryption algorithms in cryptography. To obtain a point on an elliptic curve, the dot product operation is performed using the private key of a first-level time node and the public key of a second-level time node, and the x-coordinate value of that point is taken. Elliptic curve dot product has a one-way property: given the private and public keys, it is easy to calculate the dot product result, but given the dot product result, it is difficult to derive the private key. That is, even if an attacker intercepts random numbers during communication, they cannot derive the x-coordinate value because they cannot solve the discrete logarithm problem of the elliptic curve, thus ensuring the security of the core key material. To concatenate the first-level random number, the second-level random number, the network address identifier information of the first-level time node, and the network address identifier information of the second-level time node into a single bit string, a collision-resistant hash function is used to calculate a third hash value. This third hash value combines the random number and network address information, further increasing the randomness of the key and its correlation with the network environment. The x-coordinate value obtained from the elliptic curve dot product operation is then XORed with the third hash value to obtain the second dynamic key, improving its security, dynamism, and unpredictability.

[0047] In this way, by using the timestamp as a key parameter in the generation of the first dynamic key and fusing the information of both parties through an XOR operation, the forward and backward security of the first dynamic key is improved, reducing the risk of the key being completely cracked due to the leakage of random numbers by one party. By introducing elliptic curve dot product, the second dynamic key is strongly bound to both parties, realizing the integration of identity authentication and key negotiation. No third party can calculate the key without possessing the private key of the communicating party, which greatly improves the security of authentication.

[0048] According to one embodiment of the present invention, in step S4, verification is performed based on the first dynamic key and the second dynamic key.

[0049] Figure 6 A flowchart of the verification process according to an embodiment of the present invention is shown as an example.

[0050] According to an embodiment of the present invention, step S4 includes: step S41, the secondary time node sends a time synchronization request message to the primary time node, wherein the time synchronization request message includes a first message authentication code generated based on the first dynamic key; step S42, the primary time node receives the time synchronization request message, verifies the first message authentication code based on the first dynamic key, and after successful verification, generates a time synchronization response message, wherein the time synchronization response message includes a second message authentication code generated based on a second dynamic key; step S43, the secondary time node receives the time synchronization response message and verifies the second message authentication code based on the second dynamic key.

[0051] According to one embodiment of the present invention, in a railway track traffic time synchronization network, a secondary time node prepares to send a time synchronization request message to a primary time node. To ensure the integrity and authenticity of the request message, the secondary time node uses a first dynamic key and a specific message authentication code generation algorithm (e.g., HMAC algorithm based on hash functions) to calculate key information (e.g., timestamp) in the time synchronization request message, thereby generating a first message authentication code. The secondary time node appends the generated first message authentication code to the time synchronization request message and transmits the time synchronization request message containing the first message authentication code to the primary time node via the network. Upon receiving the time synchronization request message sent by the secondary time node, the primary time node first performs preliminary parsing of the message, extracting the key information and the first message authentication code. The primary time node then recalculates the extracted key information in the time synchronization request message using the same first dynamic key as the secondary time node and the same message authentication code generation algorithm. The calculated result is compared with the received first message authentication code. If they match, the time synchronization request message has not been tampered with during transmission and originates from a legitimate secondary time node possessing the first dynamic key; verification passes. If they do not match, it indicates the message may have been tampered with or the sender is an illegitimate node; verification fails, and the primary time node discards the message without further time synchronization processing. After verifying the first message authentication code, the primary time node generates a time synchronization response message based on its precise time information. This response message contains accurate time synchronization data to help the secondary time node calibrate its local time. Using the second dynamic key and the same message authentication code generation algorithm as the one used to generate the first message authentication code, the primary time node calculates the key information in the time synchronization response message to generate the second message authentication code. The primary time node appends the generated second message authentication code to the time synchronization response message and transmits the message containing the second message authentication code to the secondary time node over the network. The secondary time node receives the time synchronization response message sent by the primary time node, which contains the second message authentication code. The secondary time node performs preliminary parsing of the message, extracting key information and the second message authentication code. Using the same second dynamic key as the primary time node and the same message authentication code generation algorithm, the secondary time node recalculates the key information in the extracted time synchronization response message. The calculated result is compared with the received second message authentication code. If they match, the time synchronization response message has not been tampered with during transmission and originates from a legitimate primary time node possessing the second dynamic key; verification passes. If they do not match, it indicates the message may have been tampered with or the sender is an illegitimate node; verification fails, and the secondary time node discards the message without using its time synchronization data for local time calibration.

[0052] According to one embodiment of the present invention, in step S5, if the verification passes, it indicates that the source of the response message is legitimate and has not been tampered with. The synchronization time signal is then corrected based on the timestamp information in the time synchronization response message. For example, the timestamp information of the extracted first-level time node is compared with the local current time to calculate the time difference between the two. When the time difference is small and within an acceptable range of slow adjustment, a smooth adjustment method is used to gradually correct the local time. For example, at 5-millisecond intervals, a small portion of the time difference is adjusted each time to gradually synchronize the local time with the standard time over a period of time. When the time difference is large and the system can withstand instantaneous time changes, an instantaneous adjustment method is used to directly set the local time to the standard time represented by the timestamp of the first-level time node.

[0053] According to one embodiment of the present invention, in step S6, the timestamp is transmitted to various subsystems or modules that require the information, such as the train operation monitoring system, the train dispatching system, and the train safety protection system, based on the business requirements of the train system. During the transmission process, each system can obtain accurate and consistent synchronization timestamp information, thereby ensuring the normal operation and collaborative work of the target train system.

[0054] According to one embodiment of the present invention, in step S7, the target track section where the train is currently located is determined using the train's positioning system (e.g., a positioning device based on a global navigation satellite system, track circuit positioning, transponder positioning, etc.), i.e., the length of a block section. In any case, the next train can only enter after a train has completely left a block section. Based on the calibrated time, data from sensor devices for the train's instantaneous speed and instantaneous acceleration are collected; that is, the real-time operating parameters include the train's instantaneous speed and instantaneous acceleration.

[0055] According to one embodiment of the present invention, in step S8, the tracking interval time is determined based on the real-time operating parameters.

[0056] Figure 7 A flowchart illustrating the calculation of the tracking interval time according to an embodiment of the present invention is shown as an example.

[0057] According to an embodiment of the present invention, step S8 includes: step S81, obtaining the first length of the target train and the second length of the target track section; step S82, setting the short-term prediction duration and the basic safety tracking time margin; step S83, obtaining the maximum speed limit of the target track section; and step S84, determining the tracking interval time based on the real-time operating parameters, the first length, the second length, the short-term prediction duration, the basic safety tracking time margin, and the maximum speed limit of the track.

[0058] According to one embodiment of the present invention, the first length information of the target train is obtained through the vehicle parameter database carried by the train itself, and the second length of the target track section is obtained through the track map. The short-term prediction duration can be set to 5 seconds, and the basic safe tracking time margin represents the maximum safe time that needs to be maintained under extreme low-speed conditions (e.g., when the train is just starting or stopping at a station), which can be set to 10 seconds. The maximum speed limit information of the target track section is extracted from the track geographic information database. The tracking interval time allows the following train to maintain a sufficient safe distance while tracking the preceding train, and can take timely braking measures to avoid collision even in the event of an emergency.

[0059] According to an embodiment of the present invention, determining the tracking interval time based on the real-time operating parameters, the first length, the second length, the short-term prediction duration, the basic safety tracking time margin, and the line maximum speed limit includes: determining the tracking interval time according to formula (3). ,

[0060] (3),

[0061] in, The first length, For the second length, The instantaneous speed of the train For the instantaneous acceleration of the train, For short-term prediction duration, Based on the margin of safety tracking time, This is the maximum speed limit for the line.

[0062] According to one embodiment of the present invention, in formula (3), The sum of the first and second lengths represents the minimum physical distance that the following vehicle must maintain from the vehicle in front. To approximate the velocity increment related terms based on the displacement formula for uniformly accelerated linear motion (considering the impact of uniformly accelerated motion on the average velocity from a velocity perspective within a short-term prediction period). The approximate increment of train speed within the short-term prediction period is calculated. This is an approximation of the train's instantaneous speed plus an increment, representing the change in the train's speed over a short prediction period. It is the ratio between the minimum physical distance and the train's speed change within a short-term prediction period. This ratio represents the most basic operating interval duration of the target train's current motion trend. This represents the ratio of the train's instantaneous speed to the line's maximum speed limit. When the train's instantaneous speed is low, The smaller, The closer the value is to 1, the closer the train's instantaneous speed is to the line's maximum speed limit. The closer to 1, The smaller. This refers to the dynamic adjustment of the basic safety tracking time margin, also known as the dynamic safety margin. For example, when the train's instantaneous speed is 0, the dynamic safety margin equals the basic safety tracking time margin. In low-speed, complex operating conditions (e.g., station operations), a more conservative strategy is tended. As the train speed approaches the maximum speed limit, the dynamic safety margin decreases. For instance, in high-speed, high-efficiency mainline operating sections, the safety margin can be intelligently compressed while ensuring safety, thereby increasing the line's throughput capacity. and Adding these together, we can obtain the tracking interval time. This tracking interval time allows the following train sufficient time to deal with various situations while tracking the preceding train, ensuring the safety and stability of train operation.

[0063] In this way, the operational status of a target train can be understood within a short-term prediction period, thereby ensuring a safe distance between trains. The tracking interval can be dynamically adjusted according to different track conditions, enabling trains to operate safely and efficiently in various track environments.

[0064] According to one embodiment of the present invention, in step S9, the type of control command to be generated is determined based on the tracking interval time and the train's operating status. Common control command types include speed adjustment commands, stop commands, and start commands. For example, if the tracking interval time is less than a safety threshold (e.g., 10 seconds), a speed reduction command may be generated to slow down subsequent trains and increase the interval with the preceding train. If the preceding train has reached the terminal station and the interval between subsequent trains is too large, a start command may be generated to accelerate subsequent trains.

[0065] The railway track traffic control and management method according to embodiments of the present invention employs a colored Petri net model to perform vulnerability and reachability analysis on the NTP protocol authentication process based on trusted certificates, determines and verifies the first and second dynamic keys, effectively preventing malicious attacks and unauthorized access, and providing a precise and unified time reference for the entire railway system. Based on this, a synchronization timestamp is generated, thereby accurately collecting real-time train operating parameters and improving the temporal reliability of these parameters. Determining the tracking interval based on the real-time operating parameters ensures a safe distance between trains, improving track utilization. In determining the first and second dynamic keys, the timestamp is used as a key parameter for generating the first dynamic key, and information from both parties is fused through an XOR operation, improving the forward and backward security of the first dynamic key and reducing the risk of complete key cracking due to random number leakage from one party. By introducing elliptic curve multiplication, the second dynamic key is strongly bound to both parties, achieving a fusion of identity authentication and key negotiation. No third party can calculate the key without possessing the private key of the communicating party, greatly enhancing authentication security. When determining the tracking interval, short-term predictions can be used to understand the target train's operation within that timeframe, thus ensuring a safe distance between trains. The tracking interval can be dynamically adjusted based on different track conditions, enabling trains to operate safely and efficiently in various track environments.

[0066] Figure 8An exemplary block diagram of a railway track traffic control and management system according to an embodiment of the present invention is shown. The system includes: a time synchronization network module for establishing a time synchronization network based on the railway NTP protocol, wherein the time synchronization network includes at least one primary time node and at least one secondary time node; a judgment module for performing vulnerability state reachability analysis on the NTP protocol authentication process based on trusted certificates using a colored Petri net model to determine whether the current protocol has vulnerabilities; and a dynamic key module for determining a first dynamic key and a second dynamic key based on key parameters of the NTP protocol authentication process if the current protocol has vulnerabilities, wherein the key parameters include a primary time node public key, a primary time node private key, and a secondary time node public key. The system includes: a verification module for verifying the target train based on the first dynamic key and the second dynamic key; a correction module for correcting the synchronization time signal based on the timestamp information in the time synchronization response message if the verification is successful; a synchronization timestamp module for generating a synchronization timestamp for the target train based on the synchronization time signal; a real-time operating parameter module for collecting the real-time operating parameters of the target train on the target track section based on the synchronization timestamp, wherein the real-time operating parameters include the instantaneous speed and instantaneous acceleration of the train; a tracking interval time module for determining the tracking interval time based on the real-time operating parameters; and a control command module for generating and issuing control commands to the onboard equipment of the target train and its subsequent trains based on the tracking interval time.

[0067] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.

[0068] Those skilled in the art should understand that the embodiments of the present invention described above and shown in the accompanying drawings are merely examples and do not limit the present invention. The objectives of the present invention have been fully and effectively achieved. The functions and structural principles of the present invention have been demonstrated and explained in the embodiments, and any modifications or variations of the embodiments of the present invention may be made without departing from the stated principles.

Claims

1. A railway track traffic control and management method, characterized in that, include: A railway-based NTP protocol time synchronization network is established, comprising at least one primary time node and at least one secondary time node. A colored Petri net model is used to perform vulnerability and reachability analysis on the NTP protocol authentication process based on trusted certificates to determine if the current protocol has vulnerabilities. If the current protocol has vulnerabilities, a first dynamic key and a second dynamic key are determined based on the key parameters of the NTP protocol authentication process, wherein the key parameters include the primary time node public key, the primary time node private key, and the secondary time node public key. Verification is performed based on the first dynamic key and the second dynamic key. If the verification passes, the synchronization time signal is corrected based on the timestamp information in the time synchronization response message. A synchronization timestamp is generated for the target train based on the synchronization time signal. Based on the synchronization timestamp, real-time operating parameters of the target train in the target track section are collected, wherein the real-time operating parameters... The data includes the train's instantaneous speed and instantaneous acceleration; based on the real-time operating parameters, the tracking interval time is determined; based on the tracking interval time, control commands are generated and sent to the onboard equipment of the target train and its subsequent trains; if the current protocol has vulnerabilities, the first dynamic key and the second dynamic key are determined based on the key parameters of the NTP protocol authentication process, including: obtaining the network address identification information of the first-level time node and the network address identification information of the second-level time node; obtaining the first-level random number generated by the first-level time node and the first-level timestamp when the random number is generated; obtaining the second-level random number generated by the second-level time node and the second-level timestamp when the random number is generated; based on the key parameters, the network address identification information of the first-level time node, the network address identification information of the second-level time node, the first-level random number, the first-level timestamp, the second-level random number, and the second-level timestamp, the first dynamic key and the second dynamic key are determined, including: based on the formula: , Determine the first dynamic key Second dynamic key ,in, For collision-resistant hash functions, This is the public key for the first-level time node. This is the public key for the second-level time node. This is a level 1 random number. It is a level 2 random number. This is a first-level timestamp. It is a second-level timestamp. This is the private key for the first-level time node. To obtain the x-coordinate of a point by performing a dot product operation on an elliptic curve, Network address identification information for the first-level time node. Network address identification information for secondary time nodes, For bit string concatenation operations, This is a bitwise XOR operation.

2. The railway track traffic control and management method according to claim 1, characterized in that, A colored Petri net model is used to perform vulnerability state reachability analysis on the NTP protocol authentication process based on trusted certificates to determine whether the current protocol has vulnerabilities. This includes: constructing a formal model, wherein the formal model includes a normal authentication process CPN model for the NTP protocol based on trusted certificates and an authentication process CPN model with a man-in-the-middle attack; through vulnerability state reachability analysis, verifying whether there is an insecure termination state in the protocol authentication process under a man-in-the-middle attack. If so, the current protocol is determined to be vulnerable.

3. The railway track traffic control and management method according to claim 2, characterized in that, The formal model construction includes: establishing a normal authentication process CPN model between primary and secondary time nodes based on the NTP protocol interaction sequence based on trusted certificates. The normal authentication process CPN model includes multiple libraries and transitions to describe the authentication process of cookie requests, cookie responses, time synchronization requests, and time synchronization responses. In the normal authentication process CPN model, a man-in-the-middle node is added to construct an authentication process CPN model with added man-in-the-middle intrusion. The man-in-the-middle node simulates an attack on the protocol authentication process by intercepting, tampering with, and forwarding communication messages between primary and secondary time nodes.

4. The railway track traffic control and management method according to claim 1, characterized in that, Verification based on the first dynamic key and the second dynamic key includes: a secondary time node sending a time synchronization request message to a primary time node, wherein the time synchronization request message contains a first message authentication code generated based on the first dynamic key; the primary time node receiving the time synchronization request message, verifying the first message authentication code based on the first dynamic key, and generating a time synchronization response message after successful verification, wherein the time synchronization response message contains a second message authentication code generated based on the second dynamic key; and the secondary time node receiving the time synchronization response message and verifying the second message authentication code based on the second dynamic key.

5. The railway track traffic control and management method according to claim 1, characterized in that, The tracking interval time is determined based on the real-time operating parameters, including: obtaining the first length of the target train and the second length of the target track section; setting the short-term prediction duration and the basic safe tracking time margin; obtaining the maximum speed limit of the target track section; and determining the tracking interval time based on the real-time operating parameters, the first length, the second length, the short-term prediction duration, the basic safe tracking time margin, and the maximum speed limit of the track.

6. The railway track traffic control and management method according to claim 5, characterized in that, Based on the real-time operating parameters, the first length, the second length, the short-term prediction duration, the basic safety tracking time margin, and the maximum speed limit of the line, the tracking interval time is determined, including: according to the formula: Determine the tracking interval ,in, The first length, For the second length, The instantaneous speed of the train For the instantaneous acceleration of the train, For short-term prediction duration, Based on the margin of safety tracking time, This is the maximum speed limit for the line.

7. A railway track traffic control and management system, used to execute the railway track traffic control and management method as described in any one of claims 1-6, characterized in that, include: A time synchronization network module is used to establish a time synchronization network for the railway-based NTP protocol, wherein the time synchronization network includes at least one primary time node and at least one secondary time node; a judgment module is used to perform vulnerability state reachability analysis on the NTP protocol authentication process based on trusted certificates using a colored Petri net model to determine whether the current protocol has vulnerabilities; a dynamic key module is used to determine a first dynamic key and a second dynamic key based on key parameters of the NTP protocol authentication process if the current protocol has vulnerabilities, wherein the key parameters include the primary time node public key, the primary time node private key, and the secondary time node public key; a verification module is used to verify the first dynamic key and the... The second dynamic key is used for verification; a correction module is used to correct the synchronization time signal according to the timestamp information in the time synchronization response message if the verification is successful; a synchronization timestamp module is used to generate a synchronization timestamp for the target train according to the synchronization time signal; a real-time operating parameter module is used to collect the real-time operating parameters of the target train in the target track section according to the synchronization timestamp, wherein the real-time operating parameters include the instantaneous speed and instantaneous acceleration of the train; a tracking interval time module is used to determine the tracking interval time according to the real-time operating parameters; and a control command module is used to generate and issue control commands to the on-board equipment of the target train and its subsequent trains according to the tracking interval time.

Citation Information

Patent Citations

  • Method and system for determining operation interval of collinear operation path

    CN115959174A