A method for developing a security tool based on a double-chain mechanism and its application
By adopting the double-chain mechanism safety tool development method in the train control system, the problems of low timeliness and poor accuracy of data production are solved, and the efficient, reliable data production and system safety are achieved.
Patent Information
- Application Number
- CN202211189463.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-28
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-09-28
AI Technical Summary
In the prior art, in the train control system, data production has problems such as low timeliness, poor accuracy and easy to introduce safety hazards, making it difficult to effectively reduce the undetectable rate of errors.
The security tool development method based on the double-chain mechanism is adopted. By dividing configuration data from top to bottom according to the system level, the tools are independently developed and tested, and the third-party verification terminals are compared and accepted to ensure data accuracy and reliability.
It effectively reduces the undetectable rate of errors, improves the accuracy and reliability of data production, improves the security of the system, and improves the efficiency of data production and the cohesion of tools.
Smart Images

Figure CN115618420B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the data production technology of train control systems, and particularly to a safety tool development method based on a double-chain mechanism and its application. Background Art
[0002] The communication-based train control system (CBTC) is a continuous train automatic control system that realizes bidirectional vehicle-ground communication based on communication. This system mainly includes an automatic train control subsystem (ATC), an automatic train supervision subsystem (ATS), a computer interlocking subsystem (CI), a data transmission subsystem (DCS), and a maintenance support subsystem (MSS). In the CBTC system, in order to achieve precise and safe control of trains, each subsystem needs to know the position information of the train and the relevant equipment information of the track section in real time. The civil engineering line data, system design documents, etc. can be converted into line basic data and integrated into on-vehicle and trackside equipment. In order to ensure the continuity and accuracy of data production, the method of manually producing data not only has low timeliness and poor accuracy, but also easily leaves hidden dangers to system safety.
[0003] Therefore, how to effectively reduce the undetected rate of errors, improve the accuracy and reliability of data production, and thus contribute to enhancing the safety of the overall system has become a technical problem to be solved. Summary of the Invention
[0004] The purpose of the present invention is to overcome the defects of the above-mentioned existing technologies and provide a safety tool development method based on a double-chain mechanism and its application.
[0005] The purpose of the present invention can be achieved by the following technical solutions:
[0006] According to the first aspect of the present invention, a safety tool development method based on a double-chain mechanism is provided. The method includes the following steps:
[0007] Step A: Divide the configuration data required by the communication-based train control system from top to bottom according to the system level, and formulate calculation rules for the configuration data of each level;
[0008] Step B: The development terminals in the double-chain tool independently develop corresponding data preparation tools according to the calculation rules;
[0009] Step C: The test terminals in the double-chain tool respectively conduct software integration testing and validation testing on the tools in their respective chains in sequence;
[0010] Step D: The third-party verification terminal respectively obtains duplex tools, and through inputting the same input data, automatically compares, feeds back, and accepts the output data generated by the duplex tools;
[0011] Step E: The data preparation tools at each level sequentially complete software release.
[0012] As a preferred technical solution, the communication-based train control system in step A includes an automatic train control subsystem ATC, an automatic train supervision subsystem ATS, a computer interlocking subsystem CI, a data transmission subsystem DCS, and a maintenance support subsystem MSS. The automatic train control subsystem ATC includes on-vehicle equipment and trackside equipment;
[0013] The division of the configuration data required by the communication-based train control system in step A from top to bottom according to the system level is specifically as follows: it is sequentially divided into system data, subsystem data, and configuration data of each device in the subsystem.
[0014] As a preferred technical solution, the formulation of calculation rules for the configuration data at each level in step A is specifically as follows:
[0015] The original data of the communication-based train control system are system design files and civil engineering line equipment files in various formats. By making the calculation rules for system data, the original data is converted into XML-format system data that is convenient for each subsystem to identify and process, and is provided for each subsystem to use;
[0016] By making the calculation rules for subsystem data, the system data is further evolved into subsystem data that can be used by each device in the subsystem; by making the calculation rules for the configuration data of each device in the subsystem, the subsystem data is converted into binary-format burned configuration data.
[0017] As a preferred technical solution, the duplex tools in step B are two independent and different tools. Each chain tool is equipped with a development terminal and a test terminal. Among them, independence means that the two tools each have their own development processes and maintain zero communication with each other. The difference means that the two tools use different software development languages and are in different compilation environments. Due to the duplex independence, the software designs are also different.
[0018] As a preferred technical solution, the development terminals in the duplex tools in step B respectively and independently develop the corresponding data preparation tools according to the calculation rules, which means that the calculation rules at each level are the basis of software requirements. The development terminals carry out software design and coding work based on this, and the development terminals of the duplex tools work independently of each other.
[0019] As a preferred technical solution, step C: The test terminals in the double-chain tool respectively perform software integration testing and validation testing on the tools in their respective chains specifically as follows:
[0020] It is determined by the development process of the waterfall V1 model adopted by each of the double-chain tools. Among them, software integration testing is the confirmation of software design, and software validation testing is the confirmation of software requirements. The test terminals in the double-chain tools perform independently.
[0021] As a preferred technical solution, the third-party verification terminals in step D respectively obtain the double-chain tools and input the same input data, specifically as follows:
[0022] For the system data preparation tool, its input data is system design files in various formats; for the subsystem data preparation tool, its input data is system data; for the data preparation tools of each device in the subsystem, its input data is subsystem data.
[0023] As a preferred technical solution, the third-party verification terminals in step D compare, feedback, and accept the output data generated by the double-chain tools specifically as follows:
[0024] The third-party verification terminal determines the data differences generated by the double-chain, and feeds back the problems to the chain with calculation errors. It compares the modified tool again, and repeats this process until the data generated by the double-chain is compared and consistent, so as to ensure that the double-chain realizes the same calculation function.
[0025] As a preferred technical solution, after the data preparation tools at each level in step E are released, configuration data is prepared for the systems at each level according to the top-down structure.
[0026] According to the second aspect of the present invention, an application method of the security tool development method using the double-chain mechanism is provided. This application method includes the following steps:
[0027] Step S1: Develop the CBTC system data preparation tool with the double-chain;
[0028] Step S2: Release the CBTC system data;
[0029] Step S3: Develop the ATC subsystem data preparation tool with the double-chain;
[0030] Step S4: Generate the line map data SGD, ZC and LC data in Par format;
[0031] Step S5: Develop the data preparation tools for on-vehicle equipment and trackside equipment with the double-chain;
[0032] Step S6: Generate the binary burn files for on-vehicle equipment and trackside equipment.
[0033] According to a third aspect of the present invention, there is provided an electronic device, including a memory and a processor, where a computer program is stored on the memory, and when the processor executes the program, the method described above is implemented.
[0034] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described above is implemented.
[0035] Compared with the prior art, the present invention has the following advantages:
[0036] 1) The present invention adopts a double-chain development, testing, and third-party comparison mode, effectively reducing the undetected error rate, improving the accuracy and reliability of data production, and thus contributing to enhancing the security of the overall system.
[0037] 2) The present invention divides the configuration data required for the communication-based train control system from top to bottom according to the system hierarchy, making the data structure clearer, condensing the data at the same level, and avoiding duplicate data production.
[0038] 3) The present invention calculates the original data in the form of a development tool, improving the production efficiency of the target configuration data and allowing for multiple repeated uses.
[0039] 4) The present invention develops corresponding data preparation tools according to the system hierarchy, making each tool have the characteristics of high cohesion and low coupling. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 is a specific flowchart of the security tool opening method based on the double-chain mechanism of the present invention;
[0041] Figure 2 is a specific flowchart of the double-chain development mechanism of the present invention;
[0042] Figure 3 is a schematic diagram of the tool development process (waterfall V1 model) of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0044] The CBTC data preparation process is to convert system design files in various formats into data formats that can be recognized by devices in each subsystem. The present invention provides a method for developing a security tool based on a double-chain mechanism. In an embodiment of the present invention, the development process of configuration data is divided according to the CBTC system level, the ATC subsystem level, and the on-vehicle and trackside devices in the subsystem, as Figure 1 shown, and includes the following steps:
[0045] Step S1: Develop a CBTC system data preparation tool using a double-chain;
[0046] Step S2: Release CBTC system data;
[0047] Step S3: Develop an ATC subsystem data preparation tool using a double-chain;
[0048] Step S4: Generate line map data SGD, ZC and LC data in Par format;
[0049] Step S5: Develop on-vehicle and trackside data preparation tools using a double-chain;
[0050] Step S6: Generate on-vehicle and trackside binary burn files;
[0051] The said Step S1: Develop a CBTC system data preparation tool using a double-chain. This tool mainly includes functions such as implementing relevant data entry, deriving data generation, data integration, comparison, and acceptance, releasing subsystem data, interface data, and floor plan data, and engineering project data management.
[0052] The said Step S2: Release CBTC system data. This data is the basic data for project implementation, mainly including the release of data of each subsystem such as ATC, CI, ATS, and MSS, interface data, and MD5 checksum. Each subsystem itself cannot modify the released system data.
[0053] The said Step S3: Develop an ATC subsystem data preparation tool using a double-chain. This tool is an integration of a group of data preparation tools, mainly including: a static electronic map (SGD) generation tool, an SGD.CSV.XML generation tool, a Par generation tool for the zone controller (ZC), a Par generation tool for the data storage unit (DSU) / line controller (LC), a Beacon generation tool, and an InterCSV generation tool.
[0054] The said Step S4: Generate line map data SGD, ZC and LC data in Par format. It takes the system data released in Step S2 as input, and at the same time, according to the rule file and parameter file, uses the ATC subsystem tools in Step S3 to generate an SGD file in XML format and ZC and LC files in Par format.
[0055] Step S5: Develop on-vehicle and wayside data preparation tools for double-chain. The on-vehicle preparation tools mainly include train automatic protection (ATP) and train automatic operation (ATO) tools; the wayside preparation tools mainly include ZC and LC tools.
[0056] Step S6: Generate on-vehicle and wayside programming files. Take the SGD data generated in Step S4 as input, and through the on-vehicle preparation tools in Step S5, generate on-vehicle programming files in binary format; take the Par files generated in Step S4 as input, and through the wayside data preparation tools in Step S5, generate wayside programming files in binary format.
[0057] As Figure 2 shown, Steps S1 and S2 are the processes of inputting and calculating the system design files to generate system data. Through the system data preparation tools, various formats of system files (such as vehicle attributes, civil engineering data, system configuration files, train operation rules, etc.) are input and calculated to be converted into system data and interface data between each subsystem, and are published to each subsystem such as ATC, CI, ATS, MSS, etc. for each subsystem to use;
[0058] As Figure 2 shown, Steps S3 and S4 are the processes of generating ATC subsystem data based on the system data. Through the ATC data preparation tools, the system data published in Step S2 is used to generate line electronic map data SGD and Par format ZC and LC data according to the project files and parameter configuration files;
[0059] As Figure 2 shown, Steps S5 and S6 are the processes of generating on-vehicle and wayside binary data based on the ATC subsystem data. Through the on-vehicle data preparation tools, the XML format SGD data generated by the ATC tools is calculated to generate binary data that can be recognized by the on-vehicle online software. Through the wayside data preparation tools, the Par format ZC and LC generated by the ATC tools are calculated and converted into binary data that can be recognized by the wayside online software.
[0060] As Figure 2As shown, the double-chain development method adopted in steps S1, S3, and S5 is developed by two specific and independent development terminals with differences. The double-chain independence means that each chain has independent development and testing terminals, and they belong to different organizations and projects, with zero communication between the two chains. Moreover, each chain has an independent CQ and CC library, and there should be no test cases for comparing the consistency of the two chains in the testing of each chain. The double-chain difference means that the two development teams use different programming languages and compilers. According to the data structure and form of the CBTC system, the double-chain usually adopts an object-oriented development language. For example, one chain uses the Java language and the other chain uses the C# language.
[0061] As Figure 2 shown, the data at each level generated in steps S2, S4, and S6 is compared and verified for the double-chain by a third-party verification terminal outside the double-chain open team. If the data comparison generated by the double-chain tool is inconsistent, the verification terminal will determine the difference. If it is a problem with the development tool, the problem will be fed back to the developer of the faulty chain. If there is a problem with the rules provided by the product, the product will adjust the rules, and the double-chain will perform secondary development based on the modification of the rules. The third-party verification terminal will compare the data generated by the double-chain tool again, and so on, until the double-chain comparison is consistent, so as to ensure that the functions finally realized by the double-chain are the same. Due to the independence and difference of the double-chain development mechanism in steps S1, S3, and S5, the third-party verification terminal compares the data generated by the double-chain, which can significantly reduce the undetected error rate, thereby effectively improving the correctness and reliability of data production.
[0062] As Figure 3 shown, the data preparation tool in steps S1, S3, and S5 adopts a structured, top-down software development method based on the waterfall V1 model, mainly including the software requirements stage, the software design stage, the coding stage, the integration testing stage, and the validation testing stage. The integration testing stage is a process of verifying the software design, and the validation testing stage is a process of verifying the software requirements. According to the independence and difference of the double-chain mechanism, each chain development team has its own testing team to form two independent waterfall V1 processes. Moreover, V&V (Verification&Validation) personnel will verify and validate the double-chain development process respectively, verifying the coverage of requirements by the double-chain development team and the coverage of code implementation requirements.
[0063] The above is the introduction of the method embodiment. The following further illustrates the solution of the present invention through the embodiments of the electronic device and the storage medium.
[0064] The electronic device of the present invention includes a central processing unit (CPU), which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) or computer program instructions loaded from a storage unit into a random access memory (RAM). In the RAM, various programs and data required for device operation can also be stored. The CPU, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.
[0065] Multiple components in the device are connected to the I / O interface, including: an input unit, such as a keyboard, a mouse, etc.; an output unit, such as various types of displays, speakers, etc.; a storage unit, such as a magnetic disk, an optical disc, etc.; and a communication unit, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit allows the device to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0066] The processing unit executes the various methods and processes described above, such as the method of the present invention. For example, in some embodiments, the method of the present invention can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as a storage unit. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device via the ROM and / or the communication unit. When the computer program is loaded into the RAM and executed by the CPU, one or more steps of the method of the present invention described above can be executed. Alternatively, in other embodiments, the CPU can be configured to execute the method of the present invention by any other suitable means (e.g., by means of firmware).
[0067] The functions described above herein can be at least partially performed by one or more hardware logic components. For example, by way of non-limitation, exemplary types of hardware logic components that can be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and so on.
[0068] The program code for implementing the method of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine and partially on a remote machine as an independent software package, or executed entirely on a remote machine or server.
[0069] In the context of the present invention, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0070] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A method for developing a security tool based on a double-chain mechanism, characterized in that The method includes the following steps: Step A: Divide the configuration data required by the communication-based train control system from top to bottom according to the system hierarchy, and formulate calculation rules for the configuration data at each level; Step B: The development terminals in the double-chain tool independently develop the corresponding data preparation tools according to the calculation rules; Step C: The test terminals in the double-chain tool sequentially perform software integration testing and validation testing on the tools in their respective chains; Step D: The third-party verification terminals respectively obtain the double-chain tool, and by inputting the same input data, automatically compare, feedback, and accept the output data generated by the double-chain tool; Step E: The data preparation tools at each level sequentially complete software release; The double-chain tool in Step B is composed of two independent and different tools. Each chain tool is equipped with a development terminal and a test terminal. The independence means that the two tools have their own development processes and maintain zero communication with each other. The difference means that the two tools use different software development languages and different compilation environments. Due to the double-chain independence, the software designs are also different; The development terminals in the double-chain tool in Step B independently develop the corresponding data preparation tools according to the calculation rules, which means that the data calculation rules at each level are the basis of software requirements. The development terminals carry out software design and coding work based on this, and the development terminals of the double-chain tool work independently; Step C: The specific process of the test terminals in the double-chain tool sequentially performing software integration testing and validation testing on the tools in their respective chains is as follows: It is determined by the development process of the waterfall V1 model adopted by each double-chain tool. Among them, software integration testing is the confirmation of software design, and software validation testing is the confirmation of software requirements. The test terminals in the double-chain tool work independently; 2. The method for developing a security tool based on a double-chain mechanism according to claim 1, wherein, The communication-based train control system in Step A includes an automatic train control subsystem ATC, an automatic train supervision subsystem ATS, a computer interlocking subsystem CI, a data transmission subsystem DCS, and a maintenance support subsystem MSS. The automatic train control subsystem ATC includes on-vehicle equipment and trackside equipment; The specific process of dividing the configuration data required by the communication-based train control system from top to bottom in Step A is as follows: sequentially divide it into system data, subsystem data, and configuration data of each device in the subsystem; 3. A security tool development method based on a double-chain mechanism according to claim 1, characterized in that, The specific process of formulating calculation rules for the configuration data at each level in Step A is as follows: The original data of the communication-based train control system is system design files and civil engineering line equipment files in various formats. By formulating the calculation rules for system data, the original data is converted into XML-format system data that is convenient for each subsystem to identify and process, and provided for each subsystem to use; By formulating the calculation rules for subsystem data, the system data is further evolved into subsystem data that can be used by each device in the subsystem; by formulating the calculation rules for the configuration data of each device in the subsystem, the subsystem data is converted into binary-format burn-in configuration data.
4. A method for developing a security tool based on a double-chain mechanism according to claim 1, characterized in that The third-party verification terminals in step D respectively obtain dual-chain tools and input the same input data, specifically: For the system data preparation tool, its input data is system design files in various formats; for the subsystem data preparation tool, its input data is system data; for the data preparation tools of each device in the subsystem, its input data is subsystem data.
5. A method for developing a security tool based on a double-chain mechanism according to claim 1, characterized in that, The third-party verification terminals in step D compare, feedback, and accept the output data generated by the dual-chain tools, specifically: The third-party verification terminal determines the data differences generated by the dual-chains, and feedbacks the problems to the chain with calculation errors, and compares the modified tools again. Repeat this process until the data generated by the dual-chains is compared and consistent, so as to ensure that the dual-chains achieve the same calculation function.
6. A method for developing a security tool based on a double-chain mechanism according to claim 1, characterized in that After the data preparation tools at each level in step E are released, configure data for the systems at each level according to the top-down structure.
7. An application of the method for developing a security tool based on a double-strand mechanism according to any one of claims 1-6, characterized in that, This application includes the following steps: Step S1: Develop dual-chain CBTC system data preparation tools; Step S2: Release CBTC system data; Step S3: Develop dual-chain ATC subsystem data preparation tools; Step S4: Generate line map data SGD, ZC and LC data in Par format; Step S5: Develop dual-chain data preparation tools for on-vehicle equipment and trackside equipment; Step S6: Generate binary burn files for on-vehicle equipment and trackside equipment.
8. An electronic device, comprising a memory and a processor, wherein a computer program is stored on the memory, characterized in that, When the processor executes the program, it implements the method described in any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method described in any one of claims 1 to 6.
Citation Information
Patent Citations
Heterogeneous double-chain automatic data validation method
CN107562808A
Software automation test verification method
CN112631918A