A system protection method and device based on security genes

By extracting security genes independently and in association from subsystems in a complex system, a system gene library is formed, which solves the security protection conflicts and redundancy problems caused by the intersection between subsystems, and realizes effective monitoring and recovery of the stability and security of the overall system.

CN115906062BActive Publication Date: 2026-04-03SHENZHEN Y& D ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-02
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively protect the intersection between subsystems in complex systems, leading to security conflicts and redundancy.

Method used

By extracting security genes independently and in association from the subsystems within the overall system, a system gene library is formed, which is used to monitor and recover from anomalies in business operations and data.

Benefits of technology

It achieves effective security protection for the overall system and its subsystems, resolves conflicts and redundancy issues between subsystems, and ensures the stability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115906062B_ABST
    Figure CN115906062B_ABST
Patent Text Reader

Abstract

This invention discloses a system protection method and apparatus based on security genes. The system protection method includes: extracting independent security genes from subsystems within a main system; extracting associated security genes from subsystems within the main system; storing the independent and associated security genes in a system gene bank; and performing security monitoring and recovery of the main system's business and data based on the system gene bank. The beneficial effects of this invention are: achieving effective security protection and stability assurance for the main system and its subsystems' business and data, and resolving the problems of conflict and redundancy security protection between subsystems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information technology, and more specifically, to a system protection method and device based on security genes. Background Technology

[0002] With the development of information technology, existing systems have become increasingly complex, typically consisting of several subsystems. These subsystems often overlap in terms of business processes and data, leading to complex and intertwined security issues that hinder effective protection. For the security protection of complex systems, the intricate and intertwined structure makes it difficult to quickly determine a reasonable and effective global security protection method. Existing technologies generally start from individual subsystems, implementing security measures for each subsystem separately. However, addressing the intersections between subsystems can easily result in conflicting and redundant security measures. Summary of the Invention

[0003] This invention provides a system protection method and device based on security genes, which solves the problem of existing security protection technologies that are prone to conflicts and redundancy at the intersection of subsystems.

[0004] To address the above problems, this invention provides a system protection method based on security genes, comprising:

[0005] Independent safety gene extraction is performed on subsystems within the overall system;

[0006] Security genes are extracted from subsystems within the overall system.

[0007] Store independent and associated safety genes in the system gene bank;

[0008] Security monitoring and recovery of the overall system's business and data are performed based on the system's gene bank.

[0009] The independent and secure gene extraction of subsystems within the overall system includes:

[0010] Let the set of subsystems be S = {s1, s2, ...}, and the independent data set of the a-th subsystem be... The set of processing nodes for the a-th subsystem is: The set of normal independent services for the a-th subsystem is: in, Represented as in, express The j-th processing step of the business, Represented as in, express The operation of a processing node in the j-th processing step of the business. Represented as in, express A specific processing node in the j-th processing step of the business belongs to P(sa); express The set of data permissions corresponding to a specific processing node in the j-th processing step of the business is a subset of D(sa), denoted as... express The flow rule of a specific processing node in the j-th processing step of the business;

[0011] For specific processing nodes, data permission sets, flow rule extraction subsystems, there are independent data genes and independent business genes, among which independent security genes include independent business genes and independent data genes.

[0012] The extraction of associated security genes from subsystems within the overall system includes:

[0013] The most frequently shared identical data among the most subsystems is grouped into an associated data set, which is represented as... Where sa, sb, ... represent subsystems sharing related data; subsystems with related business are grouped into a set of related systems, denoted as C = {c1, c2, ...}, where the h-th related system is denoted as ch = (s'a, s'b, ...), h ∈ (1, 2, ...), s'a, s'b, ... represent subsystems with related business, and the related business of ch is... The xth related business Represented as express The y-th processing step of the business is expressed as: in, express The operation of the g-th processing node in the y-th processing step of the business is expressed as:

[0014] Based on the associated data set and associated systems, the associated business genes and associated data genes between subsystems are extracted. Among them, the associated security genes include associated business genes and associated data genes.

[0015] The security monitoring and recovery of the overall system's business and data based on the system's gene bank includes:

[0016] The business processes running in the overall system are extracted sequentially according to the processing flow.

[0017] Anomaly detection is performed on business flow characteristics based on business genes in independent security genes and associated security genes in the system gene library.

[0018] The security monitoring and recovery of the overall system's business and data based on the system gene bank also includes:

[0019] Anomaly monitoring of the overall system data is performed based on the data genes in the system's gene bank;

[0020] When data anomalies occur, the data is recovered based on independent and related data genes in the system's gene bank;

[0021] When a business operation encounters an anomaly, the system returns the previous processing step from the anomaly handling step based on the business gene in the system's gene bank to restore the business operation.

[0022] On the one hand, a system protection device based on security genes is provided, including:

[0023] An independent safety gene extraction module is used to extract independent safety genes from subsystems within the overall system.

[0024] The associated security gene extraction module is used to extract associated security genes from subsystems within the overall system.

[0025] The storage module is used to store independent and associated security genes into the system gene bank.

[0026] The monitoring and recovery module is used to perform security monitoring and recovery of the overall system's business and data based on the system's gene library.

[0027] The independent safe gene extraction module includes:

[0028] The independent security gene setting submodule is used to set the set of subsystems as S = {s1, s2, ...}, and the independent data set of the a-th subsystem is... The set of processing nodes for the a-th subsystem is: The set of normal independent services for the a-th subsystem is: in, Represented as in, express The j-th processing step of the business, Represented as in, express The operation of a processing node in the j-th processing step of the business. Represented as in, express A specific processing node in the j-th processing step of the business belongs to P(sa); express The set of data permissions corresponding to a specific processing node in the j-th processing step of the business is a subset of D(sa), denoted as... express The flow rule of a specific processing node in the j-th processing step of the business;

[0029] The independent security gene extraction submodule is used to extract independent data genes and independent business genes from specific processing nodes, data permission sets, and flow rules. Among them, the independent security genes include independent business genes and independent data genes.

[0030] The associated safety gene extraction module includes:

[0031] The associated security gene setting submodule is used to form an associated data set by sharing the most common data among the most subsystems. This associated data set is represented as... Where sa, sb, ... represent subsystems sharing related data; subsystems with related business are grouped into a set of related systems, denoted as C = {c1, c2, ...}, where the h-th related system is denoted as ch = (s'a, s'b, ...), h ∈ (1, 2, ...), s'a, s'b, ... represent subsystems with related business, and the related business of ch is... The xth related business Represented as express The y-th processing step of the business is expressed as: in, express The operation of the g-th processing node in the y-th processing step of the business is expressed as:

[0032] The associated security gene extraction submodule is used to extract associated business genes and associated data genes between subsystems based on the associated data set and associated systems. The associated security genes include associated business genes and associated data genes.

[0033] The monitoring and recovery module includes:

[0034] The business flow feature extraction submodule is used to extract business flow features from the business processes running in the overall system in sequence according to the processing flow.

[0035] The business anomaly detection submodule is used to perform anomaly detection on business flow characteristics based on business genes in independent security genes and associated security genes in the system gene library.

[0036] The data anomaly detection submodule is used to monitor the data of the entire system for anomalies based on the data genes in the system gene bank;

[0037] The data recovery submodule is used to recover data based on independent and related data genes in the system's gene library when data anomalies occur.

[0038] The data recovery submodule is used to recover the business when an anomaly occurs by returning the previous processing step from the anomaly handling step based on the business gene in the system gene library.

[0039] On the one hand, a computer-readable storage medium is provided, wherein a plurality of instructions are stored in the storage medium, the instructions being adapted to be loaded by a processor to execute the above-described system protection method based on security genes.

[0040] The beneficial effects of this invention are: classifying normal business and data between subsystems according to independence and correlation, extracting independent security genes and related security genes, and performing security monitoring and recovery on the overall system based on security genes, thereby achieving effective security protection and stability assurance for the business and data of the overall system and its subsystems, and solving the problem of conflict and redundancy security protection between subsystems. Attached Figure Description

[0041] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0042] Figure 1 This is a flowchart of a system protection method based on security genes provided in an embodiment of the present invention. Detailed Implementation

[0043] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0044] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicating orientation or positional relationships based on the orientation or positional relationships shown in the accompanying drawings, are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more features. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0045] In this invention, the term "exemplary" is used to mean "serving as an example, illustration, or description." Any embodiment described as "exemplary" in this invention is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is provided to enable any person skilled in the art to make and use the invention. Details are set forth in the following description for purposes of explanation. It should be understood that those skilled in the art will recognize that the invention can be made without using these specific details. In other instances, well-known structures and processes will not be described in detail to avoid obscuring the description of the invention with unnecessary detail. Therefore, the invention is not intended to be limited to the embodiments shown, but is consistent with the broadest scope of the principles and features disclosed herein.

[0046] See Figure 1 , Figure 1 This is a flowchart of a system protection method based on security genes according to an embodiment of the present invention. The system protection method based on security genes includes steps S1-S4:

[0047] S1. Independently extract safe genes from subsystems within the overall system; Step S1 includes steps S11-S12:

[0048] S11. Set the set of subsystems as S = {s1, s2, ...}, and the independent data set of the a-th subsystem is... The set of processing nodes for the a-th subsystem is: The set of normal independent services for the a-th subsystem is: in, Represented as in, express The j-th processing step of the business, Represented as in, express The operation of a processing node in the j-th processing step of the business. Represented as in, express A specific processing node in the j-th processing step of the business belongs to P(sa); express The set of data permissions corresponding to a specific processing node in the j-th processing step of the business is a subset of D(sa), denoted as... express The flow rule of a specific processing node in the j-th processing step of the business.

[0049] In this embodiment, a typical overall system consists of several subsystems, which may overlap in terms of business and resources. First, independent security features are extracted from each subsystem. The subsystem set S = {s1, s2, ...}, and the a-th subsystem sa is an independent data set. Subsystem sa processing node set Normal independent business set A business process can be viewed as a series of sequential processing steps, represented as... express The j-th processing step of a business can be viewed as an operation of at least one processing node, denoted as: express The operation of a specific processing node in the j-th processing step of the business is represented as: express A specific processing node in the j-th processing step of the business belongs to P(sa); express The set of data permissions corresponding to a specific processing node in the j-th processing step of the business is a subset of D(sa), denoted as... express The flow rule of a specific processing node in the j-th processing step of the business; The flow rule in the operation of the nth processing step of the business, which is the final processing step, is empty.

[0050] S12. For specific processing nodes, data permission sets, flow rule extraction subsystems, independent data genes and independent business genes, among which, independent security genes include independent business genes and independent data genes.

[0051] In this embodiment, the independent security genes of the subsystem include independent security genes of business and data. On the one hand, all independent data genes of the subsystem are extracted, and on the other hand, all normal independent business genes of the subsystem are extracted. Specifically, for a single normal independent business, the processing node, node data permissions, and node pointer are extracted. The processing node is equivalent to the functional module of the subsystem, which is the processing that needs to be performed in the business process.

[0052] S2. Extract associated safety genes from subsystems within the overall system; Step S2 includes steps S21-S22:

[0053] S21. Form an associated data set from the most frequently shared identical data among the most subsystems, wherein the associated data set is represented as... Where sa, sb, ... represent subsystems sharing related data; subsystems with related business are grouped into a set of related systems, denoted as C = {c1, c2, ...}, where the h-th related system is denoted as ch = (s'a, s'b, ...), h ∈ (1, 2, ...), s'a, s'b, ... represent subsystems with related business, and the related business of ch is... The xth related business Represented as express The y-th processing step of the business is expressed as: in, express The operation of the g-th processing node in the y-th processing step of the business is expressed as:

[0054] In this embodiment, the most shared identical data among the most subsystems forms an associated data set, which is represented as: The brackets in D represent specific subsystems that share related data, belonging to the subsystem set S. Subsystems with related business operations form a related system, denoted as C = {c1, c2, ...}. One related system is denoted as ch = (sa, sb, ...), h ∈ (1, 2, ...). The brackets in ch represent specific subsystems with related business operations, and the related business operations of the related system ch are... A related business The representation method is the same as the above independent services, and can be regarded as multiple sequential processing steps, represented as follows: express The y-th processing step of a business can be viewed as an operation of at least one processing node, denoted as: express The operation of a specific processing node in the y-th processing step of the business is represented as:

[0055] S22. Based on the associated data set and associated systems, extract the associated business genes and associated data genes between subsystems, whereby the associated security genes include associated business genes and associated data genes.

[0056] In this embodiment, the normal related business and related data genes between subsystems are extracted; on the one hand, the data shared between subsystems are extracted, and on the other hand, the normal business across subsystems is extracted.

[0057] S3. Store the independent safety genes and associated safety genes in the system gene bank.

[0058] S4. Perform security monitoring and recovery of the overall system's business and data based on the system's gene bank. Step S4 includes steps S41-S44:

[0059] S41. Extract business flow features for the business processes running in the overall system in sequence according to the processing flow.

[0060] In this embodiment, the business processes of the overall system are processed sequentially according to the processing flow, which is similar to the business gene extraction mentioned above. That is, in each processing step of the business process, all processing nodes, node data permissions corresponding to each processing node, and node flow rule judgment results corresponding to each processing node are extracted.

[0061] S42. Perform anomaly detection on business flow characteristics based on the business genes in the independent security genes and associated security genes in the system gene library.

[0062] S43. Monitor the overall system data for anomalies based on the data genes in the system gene bank.

[0063] S44. When data anomalies occur, the data is restored based on the independent data genes and related data genes in the system gene bank.

[0064] S45. When a business operation encounters an anomaly, the system returns the previous processing step from the anomaly handling step based on the business gene in the system gene bank to restore the business operation.

[0065] The system protection device based on security genes provided in this case includes:

[0066] An independent safety gene extraction module is used to extract independent safety genes from subsystems within the overall system.

[0067] The associated security gene extraction module is used to extract associated security genes from subsystems within the overall system.

[0068] The storage module is used to store independent and associated security genes into the system gene bank.

[0069] The monitoring and recovery module is used to perform security monitoring and recovery of the overall system's business and data based on the system's gene library.

[0070] The independent safe gene extraction module includes:

[0071] The independent security gene setting submodule is used to set the set of subsystems as S = {s1, s2, ...}, and the independent data set of the a-th subsystem is... The set of processing nodes for the a-th subsystem is: The set of normal independent services for the a-th subsystem is: in, Represented as in, express The j-th processing step of the business, Represented as in, express The operation of a processing node in the j-th processing step of the business. Represented as in, express A specific processing node in the j-th processing step of the business belongs to P(sa); express The set of data permissions corresponding to a specific processing node in the j-th processing step of the business is a subset of D(sa), denoted as... express The flow rule of a specific processing node in the j-th processing step of the business;

[0072] The independent security gene extraction submodule is used to extract independent data genes and independent business genes from specific processing nodes, data permission sets, and flow rules. Among them, the independent security genes include independent business genes and independent data genes.

[0073] The associated safety gene extraction module includes:

[0074] The associated security gene setting submodule is used to form an associated data set by sharing the most common data among the most subsystems. This associated data set is represented as... Where sa, sb, ... represent subsystems sharing related data; subsystems with related business are grouped into a set of related systems, denoted as C = {c1, c2, ...}, where the h-th related system is denoted as ch = (s'a, s'b, ...), h ∈ (1, 2, ...), s'a, s'b, ... represent subsystems with related business, and the related business of ch is... The xth related business Represented as express The y-th processing step of the business is expressed as: in, express The operation of the g-th processing node in the y-th processing step of the business is expressed as:

[0075] The associated security gene extraction submodule is used to extract associated business genes and associated data genes between subsystems based on the associated data set and associated systems. The associated security genes include associated business genes and associated data genes.

[0076] The monitoring and recovery module includes:

[0077] The business flow feature extraction submodule is used to extract business flow features from the business processes running in the overall system in sequence according to the processing flow.

[0078] The business anomaly detection submodule is used to perform anomaly detection on business flow characteristics based on business genes in independent security genes and associated security genes in the system gene library.

[0079] The data anomaly detection submodule is used to monitor the data of the entire system for anomalies based on the data genes in the system gene bank;

[0080] The data recovery submodule is used to recover data based on independent and related data genes in the system's gene library when data anomalies occur.

[0081] The data recovery submodule is used to recover the business when an anomaly occurs by returning the previous processing step from the anomaly handling step based on the business gene in the system gene library.

[0082] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by instructions, or by instructions controlling related hardware. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor. Therefore, embodiments of the present invention provide a storage medium storing multiple instructions that can be loaded by a processor to execute the steps in any of the security gene-based system protection methods provided in the embodiments of the present invention.

[0083] The storage medium may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0084] Since the instructions stored in the storage medium can execute the steps of any of the security gene-based system protection methods provided in the embodiments of the present invention, the beneficial effects that any of the security gene-based system protection methods provided in the embodiments of the present invention can achieve can be realized, as detailed in the preceding embodiments, and will not be repeated here.

[0085] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A system protection method based on security genes, characterized in that, include: Independent safety gene extraction is performed on subsystems within the overall system; Security genes are extracted from subsystems within the overall system. Store independent and associated safety genes in the system gene bank; Security monitoring and recovery of the overall system's business and data are based on the system's gene library; The independent and secure gene extraction of subsystems within the overall system includes: Let the set of subsystems be S = {s1, s2, ...}, and the independent data set of the a-th subsystem be D(sa) = { , ,......}, the set of processing nodes of the a-th subsystem is P(sa)={ , ,......}, the set of normal independent services of the a-th subsystem is W(sa)={ , ,......, },in, Represented as ,in, express The j-th processing step of the business, Represented as ,in, express The operation of a processing node in the j-th processing step of the business. Represented as ( , , ),in, express A specific processing node in the j-th processing step of the business belongs to P(sa); express The set of data permissions corresponding to a specific processing node in the j-th processing step of the business is a subset of D(sa), denoted as ( , , ......); express The flow rule of a specific processing node in the j-th processing step of the business; For specific processing nodes, data permission sets, flow rule extraction subsystems, independent data genes and independent business genes, among which, independent security genes include independent business genes and independent data genes; The extraction of associated security genes from subsystems within the overall system includes: The most frequently shared identical data among the most subsystems is formed into an associated data set, denoted as D(sa,sb,......)={ , ,......}, where sa, sb,...... represent subsystems sharing related data; subsystems with related business are formed into a related system, the set of related systems is represented as C={c1,c2,......}, where the h-th related system is represented as ch=(s'a,s'b,......), h∈(1,2,......), s'a,s'b,...... represent subsystems with related business, and the related business of ch is W(ch)={ , ,......}, the xth related business Represented as , express The y-th processing step of the business is expressed as: ,in, express The operation of the g-th processing node in the y-th processing step of the business is expressed as ( , , ); Based on the associated data set and associated systems, the associated business genes and associated data genes between subsystems are extracted. Among them, the associated security genes include associated business genes and associated data genes.

2. The system protection method according to claim 1, characterized in that, The security monitoring and recovery of the overall system's business and data based on the system's gene bank includes: The business processes running in the overall system are extracted sequentially according to the processing flow. Anomaly detection is performed on business flow characteristics based on business genes in independent security genes and associated security genes in the system gene library.

3. The system protection method according to claim 2, characterized in that, The security monitoring and recovery of the overall system's business and data based on the system gene bank also includes: Anomaly monitoring of the overall system data is performed based on the data genes in the system's gene bank; When data anomalies occur, the data is recovered based on independent and related data genes in the system's gene bank; When a business operation encounters an anomaly, the system returns the previous processing step from the anomaly handling step based on the business gene in the system's gene bank to restore the business operation.

4. A system protection device based on security genes, characterized in that, include: An independent safety gene extraction module is used to extract independent safety genes from subsystems within the overall system. The associated security gene extraction module is used to extract associated security genes from subsystems within the overall system. The storage module is used to store independent and associated security genes into the system gene bank. The monitoring and recovery module is used to perform security monitoring and recovery of the overall system's business and data based on the system's gene library. The independent safe gene extraction module includes: The independent security gene setting submodule is used to set the set of subsystems as S={s1,s2,......}, and the independent data set of the a-th subsystem is D(sa={ , ,......}, the set of processing nodes of the a-th subsystem is P(sa)={ , ,......}, the set of normal independent services of the a-th subsystem is W(sa)={ , ,......, },in, Represented as ,in, express The j-th processing step of the business, Represented as ,in, express The operation of a processing node in the j-th processing step of the business. Represented as ( , , ),in, express A specific processing node in the j-th processing step of the business belongs to P(sa); express The set of data permissions corresponding to a specific processing node in the j-th processing step of the business is a subset of D(sa), denoted as ( , , ......); express The flow rule of a specific processing node in the j-th processing step of the business; The independent security gene extraction submodule is used to extract the independent data genes and independent business genes of the subsystem for specific processing nodes, data permission sets, and flow rules. The independent security genes include independent business genes and independent data genes. The associated safety gene extraction module includes: The associated security gene setting submodule is used to form an associated data set by sharing the most common data among the most subsystems. This associated data set is represented as D(sa, sb, ... ) = { , ,......}, where sa, sb,...... represent subsystems sharing related data; subsystems with related business are formed into a related system, the set of related systems is represented as C={c1,c2,......}, where the h-th related system is represented as ch=(s'a,s'b,......), h∈(1,2,......), s'a,s'b,...... represent subsystems with related business, and the related business of ch is W(ch)={ , ,......}, the xth related business Represented as , express The y-th processing step of the business is expressed as: ,in, express The operation of the g-th processing node in the y-th processing step of the business is expressed as ( , , ); The associated security gene extraction submodule is used to extract associated business genes and associated data genes between subsystems based on the associated data set and associated systems. The associated security genes include associated business genes and associated data genes.

5. The system protection device according to claim 4, characterized in that, The monitoring and recovery module includes: The business flow feature extraction submodule is used to extract business flow features from the business processes running in the overall system in sequence according to the processing flow. The business anomaly detection submodule is used to perform anomaly detection on business flow characteristics based on business genes in independent security genes and associated security genes in the system gene library. The data anomaly detection submodule is used to monitor the data of the entire system for anomalies based on the data genes in the system gene bank; The data recovery submodule is used to recover data based on independent and related data genes in the system's gene library when data anomalies occur. The data recovery submodule is used to recover the business when an anomaly occurs by returning the previous processing step from the anomaly handling step based on the business gene in the system gene library.

6. A computer-readable storage medium, characterized in that, The storage medium stores multiple instructions, which are adapted to be loaded by a processor to execute the system protection method based on security genes as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Security and protection system based on chemical industrial park

    CN106597966A

  • Integrated monitoring system and method for safe operation of train and fault diagnosis instrument

    CN110606106A