Method and system for realizing LKJ data wireless reloading unique identification based on digital certificate

By initializing the digital certificate and binding the locomotive information before the LKJ data switching module is first installed on the train, and by combining the firewall and the operation and maintenance audit system, the problem of locomotive information recognition error in LKJ data wireless switching is solved, and higher security and reliability are achieved.

CN115913727BActive Publication Date: 2025-11-11HUNAN CRRC TIMES SIGNAL & COMM CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211484292.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-24
Publication Date
2025-11-11
Estimated Expiration
2042-11-24

AI Technical Summary

Technical Problem

The existing LKJ data wireless replacement method has the risk of incorrect or missed replacements due to errors in locomotive model, car number, and A/B section identification. Furthermore, the lack of a locomotive binding mechanism in the public mobile communication network leads to insecure and inefficient data transmission.

Method used

Digital certificates are used to forcibly bind and verify locomotive information before the on-board LKJ data replacement module is first installed on the vehicle. Combined with the vehicle-to-ground firewall and operation and maintenance audit system, unauthorized access is compared and blocked in real time to ensure the consistency of locomotive information. Changes are confirmed through the operation and maintenance audit process.

Benefits of technology

This improves the security and reliability of LKJ data wireless swapping, prevents incorrect and missed swaps, ensures the accuracy and efficiency of data transmission, and reduces the risk of human error.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913727B_ABST
    Figure CN115913727B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on digital certificate implementation LKJ data wireless recharging uniqueness identification method and system, the steps of the method include: using digital certificate, when digital certificate initialization is carried out before first time on vehicle LKJ data recharging module, complete locomotive information mandatory binding and audit;When establishing vehicle-ground communication with ground system after binding, when the locomotive information obtained by vehicle is inconsistent with the locomotive information bound by vehicle LKJ data recharging module, ground firewall adopts access prohibition strategy;Simultaneously, audit triggers the alarm information of the vehicle LKJ data recharging module changing locomotive, and the audit process change confirmation is carried out by ground management personnel;After confirming, pass through ground firewall and allow access again.The system is used to implement the above method.The application has the advantages of simple principle, better timeliness, higher security, better reliability and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention mainly relates to the field of train operation monitoring technology, specifically a method and system for wirelessly identifying the uniqueness of LKJ data based on digital certificates. Background Technology

[0002] Train operation monitoring devices (such as LKJ2000 and LKJ-15) are an important component and crucial piece of equipment in China's train operation control system. LKJ onboard data is the foundation for LKJ control functions and the basis for operational analysis; its accuracy and timeliness are prerequisites and guarantees for monitoring safe train operation. When track data changes due to construction, signal closures, flood prevention, or other reasons, it is necessary to update the onboard track data and perform data replacement operations.

[0003] Traditional manual data swapping methods are time-consuming, labor-intensive, and inefficient, posing various safety hazards in complex operational scenarios. While the wireless data swapping method based on mobile communication networks (5G / 4G / 3G) improves efficiency, it also introduces the risk of incorrect or missed swaps due to the need to swap the vehicle-mounted LKJ data swapping module (or its associated expansion unit) after the swapping process. Furthermore, when the LKJ wireless data swapping ground system communicates with the vehicle-mounted LKJ data swapping module via the wireless network, the model, vehicle number, and A / B sections of the locomotive to be swapped are retrieved from the LKJ host, which carries the possibility of human input errors, leading to the risk of incorrect swapping due to discrepancies between the locomotive to be swapped and the actual locomotive.

[0004] Traditional wireless data transfer methods for LKJ systems have some technical problems:

[0005] 1. The locomotive model + locomotive number + AB section are used as the unique identifier for locomotives. Currently, the unique identifier of the locomotive can only be obtained by manual input through the on-board DMI (LKJ human-machine interaction unit) of the LKJ device. There is no intelligent identification device, so there is a risk of incorrect input of the locomotive model, locomotive number and AB section. Once the input is incorrect, or the wrong locomotive is entered, there is a risk that the locomotive will be replaced by the wrong one or missed.

[0006] 2. When LKJ2000 / LKJ-15 uses a public mobile communication network to conduct LKJ onboard data wireless replacement, the electrical engineering department, in conjunction with transportation, locomotive, and track maintenance departments, formulates an LKJ onboard data wireless replacement plan based on the railway's annual construction plan. This plan specifies key information such as the range of locomotives to be replaced, the LKJ onboard data version, the start / end time of the data replacement, and the data activation time. The LKJ data wireless replacement ground system establishes a communication connection with the onboard LKJ data replacement module based on the range of locomotives to be replaced. At the start time of the data replacement, it initiates the data transmission process, caching the LKJ onboard data file to the onboard LKJ data replacement module. When the data activation time arrives, the ground system or the onboard DMI (onboard human-machine interface unit) initiates a data activation command, updating the cached LKJ onboard data file to the LKJ host. The replacement result is returned to the ground system via the wireless network for closed-loop cancellation. However, when the data replacement process is in the data caching stage, if the onboard LKJ data replacement module is removed from the locomotive for maintenance or other reasons, it cannot be guaranteed that the module will be promptly transferred to that locomotive or to another locomotive. This means that the system needs to re-apply for train-to-ground transmission of data that was originally scheduled for replacement on the locomotive, depending on the caching status (whether it is cached and the cached data version), affecting the efficiency of LKJ data replacement. If there is no network signal at this time, and the data activation time arrives, activation cannot be completed, posing a risk of missed replacement. If the onboard LKJ data replacement module with cached data is transferred to a new locomotive (not within the scope of this replacement), it will trigger an alarm in the wireless replacement ground system, and the onboard DMI will incorrectly prompt the crew that the locomotive has a new version of cached data that needs to be replaced, posing a risk of incorrect replacement.

[0007] 3. The LKJ data wireless replacement system based on public mobile communication networks (5G / 4G / 3G) utilizes CA digital certificates to authenticate the vehicle-mounted LKJ data replacement module during vehicle-to-ground communication registration with the ground system. However, it is not bound to a locomotive. Authorized vehicle-mounted LKJ data replacement modules can communicate normally with the ground system from any locomotive. If the vehicle-mounted LKJ data replacement module is transferred to another railway bureau, and the certificate is not changed or cancelled in the current railway bureau's ground system, and the receiving railway bureau's ground system does not re-initialize the certificate, the access permission to the current railway bureau's ground system remains authorized.

[0008] 4. The LKJ data wireless replacement method using public mobile communication networks (5G / 4G / 3G) is adopted. The vehicle-mounted LKJ data replacement module is bound to the locomotive based on CA data certificates. When the vehicle-mounted LKJ data replacement module is changed to a different locomotive, an alarm is triggered through operation and maintenance audit to review the process and prevent the LKJ data on the locomotive from being replaced incorrectly or missing due to the replacement of the vehicle-mounted LKJ data replacement module. Summary of the Invention

[0009] The technical problem to be solved by this invention is: in view of the technical problems existing in the prior art, this invention provides a method and system for wirelessly identifying the uniqueness of LKJ data based on digital certificates, which is simple in principle, more timely, more secure, and more reliable.

[0010] To solve the above-mentioned technical problems, the present invention adopts the following technical solution:

[0011] A method for achieving unique identification of LKJ data wireless replacement based on digital certificates, comprising the following steps:

[0012] Using digital certificates, the locomotive information is forcibly bound and verified when the digital certificate is initialized before the vehicle-mounted LKJ data replacement module is first installed on the vehicle;

[0013] When establishing vehicle-to-ground communication with the ground system after binding, if the locomotive information obtained by the vehicle is inconsistent with the locomotive information bound to the vehicle-mounted LKJ data conversion module, the vehicle-to-ground firewall will adopt a policy of prohibiting access; at the same time, the audit will trigger the vehicle-mounted LKJ data conversion module to change the locomotive alarm information, and the ground management personnel will confirm the audit process change; after confirmation, access will be allowed again through the vehicle-to-ground firewall.

[0014] As a further improvement to the method of the present invention: the locomotive information includes the locomotive model, locomotive number, and sections A and B.

[0015] As a further improvement to the method of the present invention: the digital certificate initialization process includes:

[0016] The vehicle-mounted LKJ data conversion module is connected to the PC via a network cable;

[0017] The vehicle-mounted LKJ data replacement module is powered on and completes a self-test.

[0018] Start the certificate processing platform on the PC, call the certificate interface of the vehicle-mounted LKJ data replacement module, read the relevant information in the module, generate a certificate request file and extract it.

[0019] On the PC, edit the certificate request file, enter the railway bureau number, vehicle type, car number, and A / B section information, and submit it to the CA certificate server.

[0020] As a further improvement to the method of the present invention: the process of binding the digital certificate to the locomotive includes:

[0021] The CA certificate server obtains the edited certificate request file, triggers the association and binding review process between the vehicle-mounted LKJ data replacement module and the locomotives belonging to the railway bureau, and submits it to the operation and maintenance audit server;

[0022] The process of linking and binding information of the vehicle-mounted LKJ data replacement module is reviewed through the operation and maintenance audit platform, and then submitted to the CA certificate server after the review is completed.

[0023] The CA certificate server generates digital certificates based on the audit results;

[0024] Check the certificate application status on the certificate processing platform on your PC, and download the generated digital certificate to your local PC.

[0025] On the PC, the certificate processing platform calls the certificate import interface in the vehicle-mounted LKJ data replacement module to import the certificate into the vehicle-mounted LKJ data replacement module, thus completing the association and binding of the digital certificate of the vehicle-mounted LKJ data replacement module with the locomotive.

[0026] As a further improvement to the method of the present invention, it also includes a process for changing the association and binding of the vehicle-mounted LKJ data replacement module:

[0027] When conducting vehicle-to-ground communication based on a public mobile communication network, the on-board LKJ data conversion module establishes a VPN connection with the vehicle-to-ground firewall.

[0028] The vehicle model, license plate number, and A / B section information are obtained from the application layer of the vehicle-mounted LKJ data replacement module, and the module's own digital certificate is sent to the ground system's vehicle-to-ground firewall.

[0029] The vehicle-to-ground firewall obtains real-time locomotive information and compares it with the locomotive information associated in the module digital certificate. When the comparison matches, a normal communication connection is established without any association changes. When the comparison does not match, the vehicle-to-ground firewall blocks the vehicle-to-ground communication link in real time and sends the comparison result to the ground system CA certificate server.

[0030] The ground system CA certificate server receives comparison results from the vehicle-to-ground firewall. When a change occurs, it triggers the module-locomotive association change process review and pushes the review information to the ground system operation and maintenance audit server.

[0031] The process of reviewing the associated change information of the vehicle-mounted LKJ data replacement module is carried out through the operation and maintenance audit platform, and then submitted to the CA certificate server after the review is completed.

[0032] The ground system CA certificate server determines the audit result; if the audit fails, the vehicle-mounted LKJ data replacement module is prohibited from use on the current locomotive, the vehicle-to-ground firewall blocks it, and a normal communication link cannot be established. Only by restoring it to the original associated locomotive can a normal communication link be restored; when the audit is approved, the operation and maintenance audit platform binds the current locomotive where the module is located and regenerates a new digital certificate.

[0033] The ground system vehicle-to-ground firewall queries the certificate change status. When a new digital certificate is available after the change, the certificate file is downloaded to the local machine. By calling the certificate import interface of the vehicle-mounted LKJ data replacement module, the new digital certificate after the change of locomotive binding relationship is imported into the vehicle-mounted LKJ data replacement module, and a normal communication link is established.

[0034] This invention further provides a system for wirelessly identifying the uniqueness of LKJ data through digital certificates, comprising:

[0035] The vehicle-mounted LKJ data replacement module has a digital certificate running in its FLASH memory. The certificate contains a public key and a private key, which are used for the legitimacy detection and identification of the locomotive's access to the ground and for the encryption of transmitted data.

[0036] The vehicle-to-ground firewall is used for network boundary protection of the LKJ data wireless replacement ground system, and performs protection and blocking against network behaviors such as unauthorized access and malicious attacks.

[0037] The CA certificate server is used to provide services such as authorization, modification, and cancellation for clients (locomotive-mounted LKJ data replacement module) and vehicle-to-ground firewalls.

[0038] The safety supervision and operation and maintenance audit unit is used to support the process audit when binding and associating the vehicle-mounted LKJ data replacement module with the locomotive.

[0039] As a further improvement to the system of the present invention: when applied to the LKJ-15 system, the vehicle-mounted LKJ data conversion module is built into the LKJ expansion unit; when applied to the LKJ2000 system, it is an independent LKJ data conversion device.

[0040] As a further improvement to the system of the present invention: before the vehicle-mounted LKJ data replacement module is first deployed on the vehicle, it is initialized and authenticated in the ground certificate system and bound to the locomotive information to be connected. After initialization, the vehicle-mounted LKJ data replacement module has a unique digital certificate number. After the bound locomotive is reviewed by the operation and maintenance system, the digital certificate number and the locomotive information are associated one-to-one. Only when the digital certificate is valid and the associated locomotive is valid will the vehicle-to-ground firewall allow the locomotive to access.

[0041] As a further improvement to the system of the present invention: the vehicle-to-ground firewall stores server certificates, root certificates, public keys and private keys issued by the certificate system; the vehicle-to-ground firewall detects the legitimacy of access from the locomotive on-board LKJ data switching module in real time through the root certificate, and blocks illegal access and triggers an alarm to be submitted to the security supervision and operation and maintenance audit unit.

[0042] As a further improvement to the system of the present invention: when the digital certificate of the vehicle-mounted LKJ data replacement module is initialized, a binding association is formed between the digital certificate number and the locomotive information. Only after the administrator approves the application in the operation and maintenance audit system can the module be used normally on the associated locomotive. When the vehicle-mounted LKJ data replacement module of the associated locomotive is changed and re-registered for communication with the ground system, the vehicle-to-ground firewall blocks the communication in real time and triggers an alarm in the operation and maintenance audit system. This generates an association review process for the current vehicle-mounted LKJ data replacement module to rebind to the locomotive. The administrator reviews and confirms the process. After approval, the vehicle-mounted LKJ data replacement module re-establishes its association with the locomotive, enabling normal use on the associated locomotive.

[0043] Compared with the prior art, the advantages of the present invention are as follows:

[0044] 1. The method and system for wireless LKJ data replacement based on digital certificates of the present invention are simple in principle, have better timeliness, higher security, and better reliability. Based on digital certificates, combined with operation and maintenance auditing and firewall technology, while ensuring the security and reliability of LKJ data transmission over mobile public networks, the method uses digital certificates to forcibly bind and verify the locomotive (locomotive model + locomotive number + AB section) during the digital certificate initialization before the vehicle-mounted LKJ data replacement module is first installed on the vehicle. After binding, when establishing vehicle-to-ground communication with the ground system, the locomotive (locomotive model + AB section) obtained by the vehicle-mounted system is used for identification. When the locomotive number (car number + AB sections) information is inconsistent with the locomotive (locomotive model + locomotive number + AB sections) information bound to the onboard LKJ data replacement module, the vehicle-to-ground firewall adopts an access prohibition policy. At the same time, the audit triggers the locomotive change alarm information of the onboard LKJ data replacement module. The ground management personnel conduct an audit process change confirmation. After confirmation, access is allowed again through the vehicle-to-ground firewall. This effectively prevents the risk of incorrect or missed replacement during the wireless replacement of LKJ data after the onboard LKJ data replacement module changes the locomotive or the onboard LKJ device manually enters the locomotive information (locomotive model + locomotive number + AB sections).

[0045] 2. The method and system for unique identification of LKJ data wireless replacement based on digital certificates of the present invention can use digital certificates based on national cryptographic standards, combined with firewall, operation and maintenance audit and other technologies. The digital certificate is dynamically bound to the locomotive (railway bureau, locomotive model, locomotive number, A and B sections) as the unique identity identifier of the on-board LKJ data replacement module. On the basis of the original system using digital certificates for vehicle-to-ground communication identity authentication, a dynamic condition judgment and triggering review and confirmation mechanism for binding the on-board LKJ data replacement module to the locomotive is added. This effectively avoids the mis-replacement or omission of LKJ on-board data wireless replacement caused by incorrect locomotive information input in the LKJ system or the swapping of on-board LKJ data replacement modules between different locomotive workshops due to inspection, maintenance and other operations. It plays a key role in the prevention and control of daily safety production risks of LKJ data replacement in the railway signaling field. Attached Figure Description

[0046] Figure 1 This is a schematic diagram illustrating the composition principle of the system of the present invention in a specific application.

[0047] Figure 2 This is a schematic diagram illustrating the process of binding and associating modules with locomotives in a specific application example of the present invention.

[0048] Figure 3 This is a schematic diagram of the module and locomotive binding change process in a specific application example of the present invention. Detailed Implementation

[0049] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0050] In the description of this application, it should be understood that:

[0051] LKJ data replacement refers to the changes in LKJ onboard data caused by factors such as the construction and renovation of existing lines, the commissioning of new lines, and changes in train operation. The corresponding change and upgrade work is simply referred to as LKJ data replacement.

[0052] LKJ data wireless swapping is based on public mobile communication networks and uses a wireless remote method to send LKJ vehicle data files to the vehicle LKJ system.

[0053] A digital certificate is an electronic document issued by a CA (Certificate Authority) that is a string of numbers that can identify a network user and provides a way to verify the identity of a network user on a computer network.

[0054] Public mobile communication networks, fifth / fourth / third / second generation mobile communication systems (2G / 3G / 4G / 5G).

[0055] like Figure 1 As shown, the method for wireless identification of LKJ data based on digital certificates according to the present invention includes:

[0056] To ensure the security and reliability of LKJ data transmission over mobile public networks, digital certificates are used. When the digital certificate is initialized before the LKJ data replacement module is first installed on the vehicle, the locomotive (locomotive model + locomotive number + A and B sections) is forcibly bound and verified.

[0057] When establishing vehicle-to-ground communication with the ground system after binding, if the locomotive (locomotive model + locomotive number + AB sections) information obtained by the vehicle is inconsistent with the locomotive (locomotive model + locomotive number + AB sections) information bound to the vehicle-mounted LKJ data conversion module, the vehicle-to-ground firewall will implement an access prohibition policy. At the same time, the audit will trigger the vehicle-mounted LKJ data conversion module to change locomotive alarm information, and the ground management personnel will confirm the audit process change. After confirmation, access will be allowed again through the vehicle-to-ground firewall. This effectively prevents the risk of incorrect or missed replacements during the wireless replacement of LKJ data after the vehicle-mounted LKJ data conversion module changes the locomotive or the vehicle-mounted LKJ device manually enters the locomotive information (locomotive model + locomotive number + AB sections).

[0058] See Figure 2 In specific application examples, the digital certificate initialization of the vehicle-mounted LKJ data replacement module and the process of binding and associating it with the locomotive include:

[0059] The vehicle-mounted LKJ data conversion module is connected to the PC via a network cable;

[0060] The vehicle-mounted LKJ data replacement module is powered on and completes a self-test.

[0061] Start the certificate processing platform on the PC, call the certificate interface of the vehicle-mounted LKJ data replacement module, read the relevant information in the module, generate a certificate request file and extract it.

[0062] On the PC, edit the certificate request file, enter the railway bureau number, vehicle type, car number, and A / B section information, and submit it to the CA certificate server;

[0063] The CA certificate server obtains the edited certificate request file, triggers the association and binding review process between the vehicle-mounted LKJ data replacement module and the locomotives belonging to the railway bureau, and submits it to the operation and maintenance audit server;

[0064] The administrator reviews the association and binding information of the vehicle-mounted LKJ data replacement module through the operation and maintenance audit platform, and submits it to the CA certificate server after the review is completed.

[0065] The CA certificate server generates digital certificates based on the audit results;

[0066] Check the certificate application status on the certificate processing platform on your PC, and download the generated digital certificate to your local PC.

[0067] On the PC, the certificate processing platform calls the certificate import interface in the vehicle-mounted LKJ data replacement module to import the certificate into the vehicle-mounted LKJ data replacement module, completing the initialization of the digital certificate of the vehicle-mounted LKJ data replacement module and its association and binding with the locomotive.

[0068] See Figure 3 In a specific application example, the present invention further includes a process for changing the association and binding of the vehicle-mounted LKJ data replacement module:

[0069] When conducting vehicle-to-ground communication based on a public mobile communication network, the on-board LKJ data conversion module establishes a VPN connection with the vehicle-to-ground firewall.

[0070] The module obtains real-time vehicle model, license plate number, and A / B section information (from the vehicle LKJ system settings) from the application layer of the vehicle-mounted LKJ data replacement module, and sends the module's own digital certificate to the ground system's vehicle-to-ground firewall.

[0071] The vehicle-to-ground firewall obtains real-time locomotive information (model, car number, A and B sections) and compares it with the locomotive information associated with the module's digital certificate. When the comparison matches, a normal communication connection is established without requiring any association changes; when the comparison does not match, the vehicle-to-ground firewall blocks the vehicle-to-ground communication link in real time and simultaneously sends the comparison result to the ground system's CA certificate server.

[0072] The ground system CA certificate server receives comparison results from the vehicle-to-ground firewall. When a change occurs, it triggers the module-locomotive association change process review and pushes the review information to the ground system operation and maintenance audit server.

[0073] The administrator reviews the associated change information of the vehicle-mounted LKJ data replacement module through the operation and maintenance audit platform, and submits it to the CA certificate server after the review is completed.

[0074] The ground system CA certificate server determines the verification result. If the verification fails, the vehicle-mounted LKJ data replacement module is prohibited from use on the current locomotive, the vehicle-to-ground firewall blocks it, and a normal communication link cannot be established. Only by restoring it to the original associated locomotive can a normal communication link be restored. When the verification is approved, the operation and maintenance audit platform binds the current locomotive where the module is located and regenerates a new digital certificate.

[0075] The ground system vehicle-to-ground firewall queries the certificate change status. When a new digital certificate is available after the change, the certificate file is downloaded to the local machine. By calling the certificate import interface of the vehicle-mounted LKJ data replacement module, the new digital certificate after the change of locomotive binding relationship is imported into the vehicle-mounted LKJ data replacement module, and a normal communication link is established.

[0076] This invention further provides a system for wirelessly identifying the uniqueness of LKJ data through digital certificates, comprising:

[0077] The vehicle-mounted LKJ data replacement module has a digital certificate running in its FLASH memory. The certificate contains a public key and a private key, which are used for the legitimacy detection and identification of the locomotive's access to the ground and for the encryption of transmitted data.

[0078] The vehicle-to-ground firewall is used for network boundary protection of the LKJ data wireless replacement ground system, and performs protection and blocking against network behaviors such as unauthorized access and malicious attacks.

[0079] The CA certificate server is used to provide services such as authorization, modification, and cancellation for clients (locomotive-mounted LKJ data replacement module) and vehicle-to-ground firewalls.

[0080] Safety supervision and operation and maintenance auditing are used to support the process review when binding and associating the vehicle-mounted LKJ data replacement module with the locomotive.

[0081] In specific application examples, when applied to the LKJ-15 system, the vehicle-mounted LKJ data conversion module is built into the LKJ expansion unit; when applied to the LKJ2000 system, it is an independent LKJ data conversion device.

[0082] In specific application examples, before the vehicle-mounted LKJ data replacement module is first deployed on the vehicle, it undergoes initial authentication in the ground certificate system and completes the binding with the locomotive to be installed (locomotive model + locomotive number + AB section). After initialization, the vehicle-mounted LKJ data replacement module has a unique digital certificate number. After the bound locomotive is reviewed by the operation and maintenance system, the digital certificate number and the locomotive (locomotive model + locomotive number + AB section) are associated one-to-one. Only when the digital certificate is valid and the associated locomotive is valid will the vehicle-ground firewall allow the locomotive to access.

[0083] In a specific application example, the vehicle-to-ground firewall stores server certificates, root certificates, public keys, and private keys issued by the certificate system. The firewall uses the root certificate to detect the legitimacy of access from clients (locomotive-mounted LKJ data conversion modules) in real time (client identity verification and unique association between the client and its locomotive). When unauthorized access is detected, it is blocked, and an alarm is triggered and submitted to the operation and maintenance audit system.

[0084] In specific application examples, when initializing the digital certificate of the vehicle-mounted LKJ data replacement module, a binding association is formed between the digital certificate number and the locomotive (model, car number, A / B sections). Only after the administrator approves the binding in the operation and maintenance audit system can the module be used normally on the associated locomotive. When the vehicle-mounted LKJ data replacement module of the associated locomotive is changed and re-registered for communication with the ground system, the vehicle-to-ground firewall blocks the communication in real time and triggers an alarm in the operation and maintenance audit system. This generates an association review process for the current vehicle-mounted LKJ data replacement module to rebind to the locomotive. The administrator reviews and confirms the process. After approval, the vehicle-mounted LKJ data replacement module re-establishes its association with the locomotive, enabling normal use on the associated locomotive.

[0085] The above are merely preferred embodiments of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should be considered within the scope of protection of the present invention.

Claims

1. A method for achieving unique identification of LKJ data wireless swapping based on digital certificates, characterized by the following steps: include: Using digital certificates, the locomotive information is forcibly bound and verified when the digital certificate is initialized before the vehicle-mounted LKJ data replacement module is first installed on the vehicle; When establishing vehicle-to-ground communication with the ground system after binding, if the locomotive information obtained by the vehicle is inconsistent with the locomotive information bound to the vehicle-mounted LKJ data conversion module, the vehicle-to-ground firewall will adopt an access prohibition policy; at the same time, the audit will trigger the vehicle-mounted LKJ data conversion module to change the locomotive alarm information, and the ground management personnel will confirm the audit process change; after confirmation, the vehicle-to-ground firewall will allow access again; This also includes the process for changing the association and binding of the vehicle-mounted LKJ data replacement module: When conducting vehicle-to-ground communication based on a public mobile communication network, the on-board LKJ data conversion module establishes a VPN connection with the vehicle-to-ground firewall. The vehicle model, license plate number, and A / B section information are obtained from the application layer of the vehicle-mounted LKJ data replacement module, and the module's own digital certificate is sent to the ground system's vehicle-to-ground firewall. The vehicle-to-ground firewall obtains real-time locomotive information and compares it with the locomotive information associated in the module digital certificate. When the comparison matches, a normal communication connection is established without any association changes. When the comparison does not match, the vehicle-to-ground firewall blocks the vehicle-to-ground communication link in real time and sends the comparison result to the ground system CA certificate server. The ground system CA certificate server receives comparison results from the vehicle-to-ground firewall. When a change occurs, it triggers the module-locomotive association change process review and pushes the review information to the ground system operation and maintenance audit server. The process of reviewing the associated change information of the vehicle-mounted LKJ data replacement module is carried out through the operation and maintenance audit platform, and then submitted to the CA certificate server after the review is completed. The ground system's CA certificate server determines the verification result. If the audit fails, the vehicle-mounted LKJ data replacement module will be prohibited from use on the current locomotive. The vehicle-to-ground firewall will block it, and a normal communication link cannot be established. Only by restoring it to the original associated locomotive can a normal communication link be restored. Once the audit is approved, the operation and maintenance audit platform will bind the current locomotive where the module is located and regenerate a new digital certificate. The ground system vehicle-to-ground firewall queries the certificate change status. When a new digital certificate is available after the change, the certificate file is downloaded to the local machine. By calling the certificate import interface of the vehicle-mounted LKJ data replacement module, the new digital certificate after the change of locomotive binding relationship is imported into the vehicle-mounted LKJ data replacement module, and a normal communication link is established.

2. The method for wireless identification of LKJ data based on digital certificates according to claim 1, characterized in that, The locomotive information includes the locomotive model, locomotive number, and sections A and B.

3. The method for achieving unique identification of LKJ data wireless clothing replacement based on digital certificates according to claim 1 or 2, characterized in that, The digital certificate initialization process includes: The vehicle-mounted LKJ data conversion module is connected to the PC via a network cable; The vehicle-mounted LKJ data replacement module is powered on and completes a self-test. Start the certificate processing platform on the PC, call the certificate interface of the vehicle-mounted LKJ data replacement module, read the relevant information in the module, generate a certificate request file and extract it. On the PC, edit the certificate request file, enter the railway bureau number, vehicle type, car number, and A / B section information, and submit it to the CA certificate server.

4. The method for achieving unique identification of LKJ data wireless clothing change based on digital certificates according to claim 3, characterized in that, The process of binding the digital certificate to the locomotive includes: The CA certificate server obtains the edited certificate request file, triggers the association and binding review process between the vehicle-mounted LKJ data replacement module and the locomotives belonging to the railway bureau, and submits it to the operation and maintenance audit server; The process of linking and binding information of the vehicle-mounted LKJ data replacement module is reviewed through the operation and maintenance audit platform, and then submitted to the CA certificate server after the review is completed. The CA certificate server generates digital certificates based on the audit results; Check the certificate application status on the certificate processing platform on your PC, and download the generated digital certificate to your local PC. On the PC, the certificate processing platform calls the certificate import interface in the vehicle-mounted LKJ data replacement module to import the certificate into the vehicle-mounted LKJ data replacement module, thus completing the association and binding of the digital certificate of the vehicle-mounted LKJ data replacement module with the locomotive.

5. A system for implementing the method of any one of claims 1-4, based on a digital certificate, to achieve unique identification of LKJ data wireless clothing replacement, characterized in that, include: The vehicle-mounted LKJ data conversion module uses a digital certificate stored in its FLASH memory. This certificate contains a public and private key, used for verifying the legitimacy of the locomotive's ground access and encrypting transmitted data. The vehicle-to-ground firewall is used for network boundary protection of the LKJ data wireless switching ground system, and performs protection and blocking against unauthorized access and malicious network attacks. The CA certificate server is used to authorize, modify, and revoke services for clients and vehicle-to-ground firewalls; the client includes a locomotive-mounted LKJ data replacement module. The safety supervision and operation and maintenance audit unit is used to support the process audit when binding and associating the vehicle-mounted LKJ data replacement module with the locomotive.

6. The system for wireless identification of LKJ data based on digital certificates according to claim 5, characterized in that, When applied to the LKJ-15 system, the vehicle-mounted LKJ data conversion module is built into the LKJ expansion unit; when applied to the LKJ2000 system, it is an independent LKJ data conversion device.

7. The system for wireless identification of LKJ data based on digital certificates according to claim 5, characterized in that, Before the vehicle-mounted LKJ data replacement module is deployed on the vehicle for the first time, it undergoes initial authentication in the ground certificate system and completes the binding with the locomotive information to be connected. After initialization, the vehicle-mounted LKJ data replacement module has a unique digital certificate number. After the bound locomotive is reviewed by the operation and maintenance system, the digital certificate number and the locomotive information are associated one-to-one. Only when the digital certificate is valid and the associated locomotive is valid will the vehicle-to-ground firewall allow the locomotive to access.

8. The system for wireless identification of LKJ data based on digital certificates according to claim 5, characterized in that, The vehicle-to-ground firewall stores server certificates, root certificates, public keys, and private keys issued by the certificate system. The vehicle-to-ground firewall uses the root certificate to detect the legitimacy of access from the locomotive's onboard LKJ data switching module in real time. When an unauthorized access is detected, it is blocked, and an alarm is triggered and submitted to the security supervision and operation and maintenance audit unit.

9. The system for wireless identification of LKJ data based on digital certificates according to any one of claims 5-8, characterized in that, When the digital certificate of the vehicle-mounted LKJ data replacement module is initialized, a binding association is formed between the digital certificate number and the locomotive information. Only after the administrator approves the registration in the operation and maintenance audit system can the module be used normally on the associated locomotive. When the vehicle-mounted LKJ data replacement module of the associated locomotive is changed and re-registered for communication with the ground system, the vehicle-to-ground firewall blocks the communication in real time and triggers an alarm in the operation and maintenance audit system. This generates an association review process for the current vehicle-mounted LKJ data replacement module to be re-bound to the locomotive. The administrator reviews and confirms the process. After approval, the vehicle-mounted LKJ data replacement module re-establishes its association with the locomotive, enabling normal use on the associated locomotive.

Citation Information

Patent Citations

  • Safety protection system and method of data wireless reloading of train monitoring device

    CN108040058A

  • Vehicle-mounted unit information changing method and device based on ETC antenna

    CN112991561A