A method for online authorization of downloading down data

By using an online authorized download method and employing the standard TFTP protocol and DES encryption algorithm, remote downtime data download of railway signal control systems can be achieved, solving the problems of cumbersome offline downloads and high error rates, and ensuring data integrity and system security.

CN114003936BActive Publication Date: 2026-04-28CASCO SIGNAL LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CASCO SIGNAL LTD
Filing Date
2021-11-04
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

When existing railway signal control systems fail, offline downloading is cumbersome, prone to hardware damage, has a high error rate, and cannot fully retrieve historical failure information.

Method used

The system employs an online authorization download method, utilizing the standard TFTP protocol between the security control system and external devices to achieve automatic and manual communication authorization, ensuring the security and integrity of data transmission. It also uses the DES encryption algorithm to verify device identity and transmits downtime data through multiple channels.

Benefits of technology

It enables remote downloading of crash data without disassembling the device, reducing error rates, extending hardware lifespan, ensuring safe and reliable system operation, and improving the integrity and efficiency of data acquisition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114003936B_ABST
    Figure CN114003936B_ABST
Patent Text Reader

Abstract

A method for online authorization of download of down data, after restart of a down, a security control system adopts an automatic download communication authorization method to perform communication authorization with an external device, the security control system establishes a communication channel with the external device, and the security control system sends down data to the external device online. The present application enables the railway signal control system to have the ability of online acquisition of down information, ensures safe and reliable operation of the system, reduces the error rate, and prolongs the service life of hardware.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method for online authorized download of downtime data. Background Technology

[0002] The railway signaling safety platform is a general-purpose, fail-safe computer control system applied to key core equipment of railway signaling control systems. After a railway signaling control system is put into operation, unexpected downtime due to insufficient communication performance or software defects is inevitable. Backing up downtime information and saving fault data on-site is crucial for subsequent fault analysis. After data retention, normal equipment operation can be restored more quickly, minimizing the impact of downtime on on-site operations. Currently, the main method for downloading downtime information is offline downloading using a programmer by on-site personnel, which has the following problems:

[0003] 1. Offline downloading is cumbersome and affects device operation.

[0004] 2. Memory will be overwritten after a crash, and only the most recent crash information can be retrieved.

[0005] 3. Manual operation has an error rate and can easily cause damage to hardware pins.

[0006] 4. There are a large number of operating boards on site, and the cabinet space is limited, making it difficult to connect the programmer. Summary of the Invention

[0007] The purpose of this invention is to provide a method for online authorized download of downtime data, enabling railway signal control systems to acquire downtime information online, ensuring safe and reliable system operation, reducing error rates, and extending hardware lifespan.

[0008] To achieve the above objectives, the present invention provides a method for online authorization to download crash data. After a crash restart, the security control system uses an automatic download communication authorization method to perform communication authorization with external devices, establishes a communication channel between the security control system and the external devices, and sends crash data to the external devices online.

[0009] The communication authorization and data transmission between the security control system and the external device adopts the standard TFTP protocol.

[0010] The automatic download communication authorization method includes:

[0011] The security control system and external devices agree on the first and second data to be encrypted.

[0012] The security control system sends a read request to an external device. The file name corresponding to the read request contains a key, which is calculated from the first data to be encrypted using an encryption algorithm.

[0013] After receiving a read request from the security control system, the external device verifies the key value in the file name. If the verification is successful, it replies with a data packet calculated by the encryption algorithm from the second data to be encrypted.

[0014] After receiving a data packet from an external device, the safety control system verifies the correctness of the data. If the verification passes, it sends an acknowledgment packet to the external device.

[0015] The encryption algorithm used is DES encryption.

[0016] If the automatic communication authorization download method fails to grant communication authorization to external devices, the safety control system will then use the manual communication authorization download method to grant communication authorization to external devices.

[0017] The manual download communication authorization method includes:

[0018] The external device sends a read request to the security control system. After receiving the read request from the external device, the security control system replies with the authorization protocol version number to the external device.

[0019] An external device sends a write request to the security control system. The file name corresponding to the write request contains the license protocol version number. After receiving the write request from the external device, the security control system verifies whether the license protocol version number in the file name is correct. If the verification is successful, it replies with an acknowledgment packet to the external device.

[0020] After receiving the confirmation packet from the security control system, the external device sends a CPU identification number data packet to the security control system. After receiving the CPU identification number data packet from the external device, the security control system verifies whether the CPU identification number carried in the CPU identification number data packet is correct. If the verification is successful, the system replies with a confirmation packet to the external device, allowing the external device to establish communication with the security control system.

[0021] The method for establishing a communication channel between the security control system and external devices includes:

[0022] The external device sends a request to the security control system to read the channel number. After the target processor verifies the channel number, it replies to the external device with the channel number.

[0023] The external device sends a request to the target processor to read the download service version number, and the target processor replies with the download service version number.

[0024] The method for the safety control system to send downtime data to external devices online includes:

[0025] When the security control system receives a write request file for "initialization read" from an external device, it verifies the file information and saves the address and size data sent by the external device.

[0026] When the safety control system receives a read request file from an external device requesting the "acquire initialization read operation mode", it verifies the file information and replies with the initialization read operation mode to the external device. If the operation mode is available, the external device continues to execute subsequent steps.

[0027] When the security control system receives a "read data" request file from an external device, it verifies the file information and transmits the data according to the address and size sent by the external device.

[0028] The outage data includes electronic stamp information, outage flag, and outage information;

[0029] The electronic stamp information includes at least an error prevention code and CRC information;

[0030] The outage flag indicates whether an outage occurs.

[0031] The method for downloading the electronic stamp information includes:

[0032] An external device sends a write request to the security control system, requesting the starting address and size of the electronic stamp information to be written. The file name corresponding to the write request contains the download service version number and channel number. When the security control system receives the write request from the external device, if the verification is successful, it saves the written data and sends a confirmation packet back to the external device.

[0033] The external device sends a read request to the security control system, requesting to read the starting address and size of the electronic stamp information to be written and the operation mode. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the operation mode to the external device.

[0034] After receiving a response from the security control system indicating that the mode is available, the external device sends a read request to the security control system to read the electronic stamp information. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the electronic stamp information to the external device based on the starting address and size of the saved electronic stamp information.

[0035] The method for downloading the downtime flag includes:

[0036] An external device sends a write request to the security control system, requesting to write the starting address and size of the crash flag. The file name corresponding to the write request contains the download service version number and channel number. When the security control system receives the write request from the external device, if the verification is successful, it saves the written data and sends an acknowledgment packet back to the external device.

[0037] An external device sends a read request to the security control system, requesting to read the starting address and size of the operation mode for writing the crash flag. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the operation mode to the external device.

[0038] After receiving the mode availability reply from the security control system, the external device sends a read request to the security control system to read the crash flag. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the crash flag to the external device according to the starting address and size of the saved crash flag.

[0039] The method for downloading the downtime information includes:

[0040] An external device sends a write request to the security control system, requesting to write the starting address and size of the crash information. The file name corresponding to the write request contains the download service version number and channel number. When the security control system receives the write request from the external device, if the verification is successful, it saves the written data and sends a confirmation packet back to the external device.

[0041] An external device sends a read request to the security control system, requesting to read the starting address and size of the operation mode for writing down the crash information. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the operation mode to the external device.

[0042] After receiving a response from the security control system indicating that the mode is available, the external device sends a read request to the security control system to read the downtime information. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with downtime information to the external device based on the starting address and size of the saved downtime information.

[0043] After the data download is complete, the security control system cancels communication authorization with external devices.

[0044] The method for canceling communication authorization includes: after the security control system receives a cancellation authorization request from the external device, it cancels the communication authorization with the external device; or, if the security control system does not receive a cancellation authorization request from the external device within a set time, the security control system automatically cancels the communication authorization with the external device.

[0045] The security control system includes multiple target processors, each of which performs communication authorization with multiple external devices, establishes communication channels, and downloads data.

[0046] The target processor simultaneously establishes multiple communication channels with external devices.

[0047] The present invention has the following advantages:

[0048] 1. The remote control method allows external devices to download downtime information through the external network port reserved on the security control system without disassembling the highly enclosed equipment, making it highly versatile.

[0049] 2. Automatic download mode ensures proactive backup of data after each system crash, preventing the loss of important information.

[0050] 3. Downloading downtime information remotely online via the network does not affect secure data communication and ensures the safe and reliable operation of the system, which is more convenient and reliable than obtaining information offline when the system is shut down.

[0051] 4. No manual intervention is required in the field, reducing the error rate, extending the lifespan of hardware, and saving hardware costs. Attached Figure Description

[0052] Figure 1 This is a flowchart of a method for online authorized download of downtime data in an embodiment of the present invention.

[0053] Figure 2 This is a flowchart for selecting an online communication authorization method for communication authorization.

[0054] Figure 3 This is a flowchart of the method for downloading downtime information online. Detailed Implementation

[0055] The following is based on Figures 1-3 The preferred embodiments of the present invention will be described in detail below.

[0056] like Figure 1 As shown, in one embodiment of the present invention, a method for online authorized download of downtime data is provided, comprising six stages: a first stage of requesting communication authorization; a second stage of requesting to open a channel; a third stage of requesting electronic stamp information; a fourth stage of requesting a downtime flag; a fifth stage of requesting downtime information; and a sixth stage of canceling communication authorization.

[0057] In the first phase, an authorization service based on the standard TFTP protocol is provided. The TFTP message format is opcod|sourcefile|type, where opcod is for read requests and write requests, source file is the filename, and type uses octet (the value of the type field in the TFTP message). There are two communication authorization methods: manual download authorization (external devices (PCs) request authorization) and automatic download authorization (the safety control system (i.e., the "railway signal control system") requests authorization).

[0058] After a system crashes and restarts, the safety control system first uses an automatic download method to send crash information to external devices and save the crash information immediately. If the automatic download method fails, a manual download method is used.

[0059] like Figure 2 As shown, selecting a communication authorization method for communication authorization includes the following steps:

[0060] Step 1: The safety control system first performs system initialization;

[0061] Step 2: The safety control system checks if there is a crash setting. If yes, proceed to Step 3; otherwise, proceed to Step 6.

[0062] Step 3: The security control system checks whether automatic download has been executed. If yes, proceed to step 6; otherwise, proceed to step 4.

[0063] Step 4: The security control system automatically downloads communication authorization;

[0064] Step 5: The security control system verifies the identity of the external device by checking whether the encryption algorithm passes the verification, thereby determining whether the automatic download communication authorization is successful. If yes, the second stage can be carried out; otherwise, proceed to step 6.

[0065] Step 6: The security control system performs other communication tasks, and then proceeds to Step 7;

[0066] Step 7: The security control system determines whether it has received an authorization request from an external device. If yes, proceed to step 8; otherwise, proceed to step 6.

[0067] Step 8: External devices perform manual download communication authorization;

[0068] Step 9: The security control system verifies whether the TFTP request sent by the external device is correct, thereby determining whether the manual download communication authorization is successful. If yes, the second stage can proceed; otherwise, proceed to step 6.

[0069] In step 4, the automatic download method is initiated by the security control system. To ensure communication security, the security control system verifies the identity of the external device using an encryption algorithm before requesting communication authorization. In this embodiment, the encryption algorithm is DES encryption. The method to verify the identity is whether the encryption algorithm has passed the verification. If it has passed, it means that the other party is a secure and trustworthy device.

[0070] The method for automatically downloading communication authorization includes the following steps:

[0071] The target processor in the security control system agrees with the external device on two 8-byte data to be encrypted. The security control system sends a read request to the external device. The file name corresponding to the read request is "download_mode" + "CPU identifier" + "key". Here, "download_mode" indicates the download mode, which is used to distinguish between manual download and automatic download. The "key" is calculated by the data to be encrypted 1 using the DES encryption algorithm. The data to be encrypted 1 is determined through negotiation between the two communicating parties (i.e., the target processor and the external device).

[0072] After receiving a read request from the security control system, the external device verifies the key value in the file name. If the verification is successful, it replies with a data packet calculated by the DES encryption algorithm from the data to be encrypted 2. The data to be encrypted 2 is determined through negotiation between the two communicating parties (i.e., the target processor and the external device).

[0073] After receiving a data packet from an external device, the safety control system verifies the correctness of the data. If the verification passes, it sends an acknowledgment packet to the external device; otherwise, it sends an error packet.

[0074] The method for manually downloading communication authorization includes the following steps:

[0075] An external device sends a read request to the target processor (CPU) in the security control system. The file name corresponding to the read request is "atr_information". After receiving the read request from the external device, the target processor replies with an authorization protocol version number to the external device. The authorization protocol version number is used as part of the file name of the subsequent authorization request from the external device. Its purpose is to ensure the authenticity and reliability of the external device and prevent authorization from being granted to unauthorized devices.

[0076] An external device sends a write request to the target processor. The filename corresponding to the write request is "atr_vxxx_authorize", where vxxx is the version number of the authorization protocol. After receiving the write request from the external device, the target processor verifies whether the filename is correct. If the verification is successful, it replies with an acknowledgment packet to the external device.

[0077] After receiving the acknowledgment packet from the target processor, the external device sends a CPU identification number data packet to the target processor. The target processor then sends a verification message to check whether the CPU identification number carried in the CPU identification number data packet matches the target processor. If the check passes, the external device replies with an acknowledgment packet, allowing the external device to establish communication with the security control system. If the check fails, an error packet is sent to the external device.

[0078] Each CPU in the security control system manages a certain number of different external device requests for authorization. If the number exceeds this limit, the newly requested external device replaces the originally requested external device to improve resource utilization.

[0079] In the second phase, the method for requesting to open a channel includes the following steps:

[0080] An external device sends a request to the target processor in the security control system to read the channel number. After the target processor verifies the channel number, it replies with the channel number "channelID" to the external device. The channel number is used as part of the file name in subsequent request requests and is used by the security platform to verify the identity of the remote external device to ensure the security of data transmission. The target processor can open multiple channels simultaneously to download downtime information and other security information, thereby expanding functionality and improving communication efficiency.

[0081] An external device sends a request to the target processor to read the download service version number, and the target processor replies with the download service version number "vxxx"; the download service version number "vxxx" is used as part of the filename requested by the external device in subsequent requests.

[0082] The security control system only downloads crash information after authorizing external devices to communicate, preventing the leakage of security information and ensuring the security of data communication. Both parties agree on the memory address and size to be read, and use the TFTP protocol for chunked transmission. Compared to traditional UDP communication, the TFTP protocol ensures data integrity in large-capacity communication scenarios, avoids invalid downloads due to errors during the download process, and improves transmission stability.

[0083] After successful authorization and opening of the communication channel, the download process begins, including the third, fourth, and fifth stages. The flowchart for each stage is shown below. Figure 3 As shown, the online download method for downtime information includes the following steps:

[0084] Step 1: When the target processor in the security control system receives a write request file for "initialization read" sent by an external device, it verifies the file information and saves the data sent by the external device, including the read address and size.

[0085] Step 2: When the target processor in the security control system receives a read request file from an external device to "obtain the initialization read operation mode", it verifies the file information and replies with the current operation mode. If the current operation mode is available, the external device can continue to execute subsequent steps.

[0086] Step 3: When the target processor in the security control system receives a "read data" request file from an external device, it verifies the file information and performs data transmission according to the address and size saved in Step 1.

[0087] Specifically, in the third stage, the method for requesting electronic stamp information includes the following steps:

[0088] Step 301: The external device sends a write request of “dld_vxxx_w” + “channelID” + “PAL” to the target processor, requesting the starting address and size of the electronic stamp information to be written. Upon receiving the request, the target processor checks the correctness of the request and data. If the verification passes, it saves the written data and replies with an acknowledgment packet; otherwise, it ends the download.

[0089] Step 302: The external device sends a read request of “dld_vxxx_m” + “channelID” to the target processor to request to read the operation mode of step 301. The target processor replies with the operation mode, and the status values ​​are Initialize, Enable, Disable, and Error.

[0090] Initialize indicates initialization, Enable indicates that the next request can be sent, and Disable indicates that the request needs to be resent. If it is still unusable after a certain number of resentments (which can be set by the user, with a default of 3), an Error will be returned and the sending of subsequent requests will be terminated.

[0091] Step 303: The external device sends a read request of “dld_vxxx_u” + “channelID” to the target processor to read the electronic stamp information. The target processor replies with the target processor electronic stamp information according to the starting address and size saved in step 301.

[0092] The electronic stamp contains hardware information such as error prevention codes and CRC, achieving separation of hardware and software storage areas and improving read efficiency. Downloading the electronic stamp information allows for analysis of hardware status, and combining this with crash information can help analyze hardware-related faults.

[0093] In the fourth stage, the method for requesting the crash flag specifically includes the following steps:

[0094] Step 401: The external device sends a write request to the target processor containing "dld_vxxx_w" + "channelID" + "SRL", requesting the writing of the starting address and size of a crash flag, which indicates whether crash information exists. Upon receiving the request, the target processor checks the correctness of the request and data. If the verification passes, it saves the written data and replies with an acknowledgment packet; otherwise, the download ends.

[0095] Step 402: The external device sends a read request of “dld_vxxx_m” + “channelID” to the target processor to request to read the status of the operation in step 401. The target processor replies with the operation status value.

[0096] Step 403: The external device sends a read request of "dld_vxxx_u" + "channelID" to the target processor, requesting to read the crash flag. The target processor replies with its own crash flag based on the starting address and size saved in step 401. The crash flag determines whether subsequent stages proceed; obtaining the crash flag during this stage improves the efficiency of the download process.

[0097] In the fifth stage, the method for requesting downtime information specifically includes the following steps:

[0098] Step 501: The external device sends a write request to the target processor containing "dld_vxxx_w" + "channelID" + "MEM", requesting the starting address and size of the crash information to be written. The target processor saves the written data and replies with an acknowledgment packet. The crash information includes the software stack information of the target processor at the time of the crash.

[0099] Step 502: The external device sends a read request of “dld_vxxx_m” + “channelID” to the target processor to request to read the status of the operation in step 501. The target processor replies with the operation status value.

[0100] Step 503: The external device sends a read request of “dld_vxxx_u” + “channelID” to the target processor to request to read the crash information. The target processor replies with the target processor crash information according to the starting address and size saved in step 501.

[0101] Due to the large amount of crash information data, it is transmitted in segments. Each segment is a maximum of 0x4000 bytes, and each packet is a maximum of 512 bytes. The block number of the data packet ensures data integrity. The first 2 bytes of each segment store a flag indicating whether the crash information segment is complete, ensuring the validity of the data during each download process. After a segment of data transmission is completed, if the transmission is not finished, proceed to step 501, and increment the starting address by 0x4000.

[0102] In this context, "dld" is an abbreviation for download service, PAL, SRL, and MEM are memory regions, and w, m, and u represent different operations.

[0103] By analyzing downtime information, the fault point caused by software can be located, thereby discovering and fixing software defects and ensuring the normal operation of the safety control system.

[0104] After the download process is complete, the communication authorization should be revoked. Besides the external device initiating the revocation, the security control system can also automatically revoke the external device's communication authorization by setting a timer. This provides dual protection for system security when automatic downloading is used or when no revocation request is received from the external device within a certain timeframe.

[0105] In the sixth phase, the method for revoking communication authorization includes the following steps:

[0106] Step 601: The external device sends a write request to the target processor, with the corresponding file name being "atr_vxxx_unauthorize", where vxxx is the license agreement version number in the manual download method. After receiving the write request, the target processor verifies whether the file name is correct, and replies with an acknowledgment packet after the verification is successful.

[0107] Step 602: After receiving the confirmation packet sent by the target processor, the external device sends the CPU identifier to the target processor. The target processor verifies the message and replies with the confirmation packet, thus canceling the communication between the external device and the security control system.

[0108] The present invention has the following advantages:

[0109] 1. The remote control method allows external devices to download downtime information through the external network port reserved on the security control system without disassembling the highly enclosed equipment, making it highly versatile.

[0110] 2. Automatic download mode ensures proactive backup of data after each system crash, preventing the loss of important information.

[0111] 3. Downloading downtime information remotely online via the network does not affect secure data communication and ensures the safe and reliable operation of the system, which is more convenient and reliable than obtaining information offline when the system is shut down.

[0112] 4. No manual intervention is required in the field, reducing the error rate, extending the lifespan of hardware, and saving hardware costs.

[0113] It should be noted that, in the embodiments of the present invention, the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," "counterclockwise," "axial," "radial," and "circumferential," etc., indicating the orientation or positional relationship, are based on the orientation or positional relationship shown in the accompanying drawings and are only for the convenience of describing the embodiments. They do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0114] In this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0115] Although the present invention has been described in detail through the preferred embodiments above, it should be understood that the above description should not be considered as a limitation of the present invention. Various modifications and substitutions to the present invention will be apparent to those skilled in the art after reading the above description. Therefore, the scope of protection of the present invention should be defined by the appended claims.

Claims

1. A method for online authorized download of downtime data, characterized in that, After a system crash and restart, the safety control system uses an automatic download communication authorization method to grant communication authorization to external devices. The safety control system establishes a communication channel with the external devices and sends crash data to the external devices online. If the automatic communication authorization download method fails to grant communication authorization to external devices, the safety control system will then use the manual communication authorization download method to grant communication authorization to external devices. The automatic download communication authorization method includes: The security control system and external devices agree on the first and second data to be encrypted. The security control system sends a read request to an external device. The file name corresponding to the read request contains a key, which is calculated from the first data to be encrypted using an encryption algorithm. After receiving a read request from the security control system, the external device verifies the key value in the file name. If the verification is successful, it replies with a data packet calculated by the encryption algorithm from the second data to be encrypted. After receiving a data packet from an external device, the safety control system verifies the correctness of the data. If the verification passes, it sends an acknowledgment packet to the external device. The manual download communication authorization method includes: The external device sends a read request to the security control system. After receiving the read request from the external device, the security control system replies with the authorization protocol version number to the external device. An external device sends a write request to the security control system. The file name corresponding to the write request contains the license protocol version number. After receiving the write request from the external device, the security control system verifies whether the license protocol version number in the file name is correct. If the verification is successful, it replies with an acknowledgment packet to the external device. After receiving the confirmation packet from the security control system, the external device sends a CPU identification number data packet to the security control system. After receiving the CPU identification number data packet from the external device, the security control system verifies whether the CPU identification number carried in the CPU identification number data packet is correct. If the verification is successful, the system replies with a confirmation packet to the external device, allowing the external device to establish communication with the security control system.

2. The method for online authorized download of downtime data as described in claim 1, characterized in that, The communication authorization and data transmission between the security control system and the external device adopts the standard TFTP protocol.

3. The method for online authorized download of downtime data as described in claim 1, characterized in that, The encryption algorithm used is DES encryption.

4. The method for online authorized download of downtime data as described in claim 1, characterized in that, The method for establishing a communication channel between the security control system and external devices includes: The external device sends a request to the security control system to read the channel number. After the target processor verifies the channel number, it replies to the external device with the channel number. The external device sends a request to the target processor to read the download service version number, and the target processor replies with the download service version number.

5. The method for online authorized download of downtime data as described in claim 1, characterized in that, The method for the safety control system to send downtime data to external devices online includes: When the security control system receives a write request file for "initialization read" from an external device, it verifies the file information and saves the address and size data sent by the external device. When the safety control system receives a read request file from an external device requesting "get initialization read operation mode", it verifies the file information and replies with the initialization read operation mode to the external device. If the operation mode is available, the external device continues to execute subsequent steps. When the security control system receives a "read data" request file from an external device, it verifies the file information and transmits the data according to the address and size sent by the external device.

6. The method for online authorized download of downtime data as described in claim 5, characterized in that, The outage data includes electronic stamp information, outage flag, and outage information; The electronic stamp information includes at least an error prevention code and CRC information; The outage flag indicates whether an outage occurs.

7. The method for online authorized download of downtime data as described in claim 6, characterized in that, The method for downloading the electronic stamp information includes: An external device sends a write request to the security control system, requesting the starting address and size of the electronic stamp information to be written. The file name corresponding to the write request contains the download service version number and channel number. When the security control system receives the write request from the external device, if the verification is successful, it saves the written data and sends a confirmation packet back to the external device. The external device sends a read request to the security control system, requesting to read the starting address and size of the electronic stamp information to be written and the operation mode. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the operation mode to the external device. After receiving a response from the security control system indicating that the mode is available, the external device sends a read request to the security control system to read the electronic stamp information. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the electronic stamp information to the external device based on the starting address and size of the saved electronic stamp information.

8. The method for online authorized download of downtime data as described in claim 6, characterized in that, The method for downloading the downtime flag includes: An external device sends a write request to the security control system, requesting to write the starting address and size of the crash flag. The file name corresponding to the write request contains the download service version number and channel number. When the security control system receives the write request from the external device, if the verification is successful, it saves the written data and sends an acknowledgment packet back to the external device. An external device sends a read request to the security control system, requesting to read the starting address and size of the operation mode for writing the crash flag. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the operation mode to the external device. After receiving the mode availability reply from the security control system, the external device sends a read request to the security control system to read the crash flag. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the crash flag to the external device according to the starting address and size of the saved crash flag.

9. The method for online authorized download of downtime data as described in claim 6, characterized in that, The method for downloading the downtime information includes: An external device sends a write request to the security control system, requesting to write the starting address and size of the crash information. The file name corresponding to the write request contains the download service version number and channel number. When the security control system receives the write request from the external device, if the verification is successful, it saves the written data and sends a confirmation packet back to the external device. An external device sends a read request to the security control system, requesting to read the starting address and size of the operation mode for writing down the crash information. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with the operation mode to the external device. After receiving a response from the security control system indicating that the mode is available, the external device sends a read request to the security control system to read the downtime information. The file name corresponding to the read request contains the download service version number and channel number. The security control system replies with downtime information to the external device based on the starting address and size of the saved downtime information.

10. The method for online authorized download of downtime data as described in any one of claims 1-9, characterized in that, After the data download is complete, the security control system cancels communication authorization with external devices.

11. The method for online authorized download of downtime data as described in claim 10, characterized in that, The method for canceling communication authorization with external devices includes: after the security control system receives a cancellation authorization request from the external device, it cancels the communication authorization with the external device; or, if the security control system does not receive a cancellation authorization request from the external device within a set time, the security control system automatically cancels the communication authorization with the external device.

12. The method for online authorized download of downtime data as described in claim 11, characterized in that, The security control system includes multiple target processors, each of which performs communication authorization with multiple external devices, establishes communication channels, and downloads data.

13. The method for online authorized download of downtime data as described in claim 12, characterized in that, The target processor simultaneously establishes multiple communication channels with external devices.

Citation Information

Patent Citations

  • Method and system for processing television outage

    CN102622254A

  • Initializing and reconfiguring a secure network interface

    US6073172A