A hot standby encrypted wireless transmission device for urban rail transit based on public network

Through the management of multi-wireless access terminal ad hoc network and communication interface server, the problem of bandwidth limitation and insufficient security of special networks in urban rail transit is solved, efficient and secure diversified data transmission is achieved, and network construction costs are reduced.

CN116017359BActive Publication Date: 2025-08-12CHINA ACADEMY OF RAILWAY SCI CORP LTD +3
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211729548.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2025-08-12
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

The bandwidth limitation of the private network of urban rail transit cannot support the large-capacity service data carrying under redundant links. The security of public wireless transmission equipment is insufficient, and the equipment operation and maintenance efficiency is low. The uneven network coverage of multiple operators leads to limited redundancy capabilities.

Method used

Multi-wireless access terminals are adopted to implement multiple hot standby transmission channels through communication interface server management, and data encryption and decryption are carried out, combining geographic information monitoring to improve network status and reduce network construction costs.

Benefits of technology

Break through the bandwidth limitation of dedicated networks, provide large-capacity real-time transmission channels, improve transmission stability and security, reduce network construction costs, and achieve diversified application needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116017359B_ABST
    Figure CN116017359B_ABST
Patent Text Reader

Abstract

The present invention discloses a hot standby encrypted wireless transmission device for urban rail transit based on the public network. On the one hand, it breaks through the bandwidth limitation of the private network of urban rail transit and provides a large-capacity real-time transmission channel. Moreover, the transmission scheme based on the public network expands the server location limitation of urban rail transit data transmission, which can meet more diversified application needs. On the other hand, it uses a multi-wireless terminal access method to provide multiple hot standby transmission channels, which ensures the reliability of transmission. Moreover, the design of periodic key update improves the security of vehicle-ground data transmission. At the same time, the wireless status monitoring technology based on geographic information combines wireless status information and geographic information, provides rich network status monitoring elements, and improves the efficiency of wireless network optimization. In addition, the whole set of equipment has a wide range of applications based on the public network, and can realize the replacement of the public network for the private network in the vehicle-ground wireless data interaction application of some urban rail transit lines, greatly reducing the network construction cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of rail transit technology, and in particular to a public network-based urban rail transit hot standby encrypted wireless transmission device. Background Art

[0002] Currently, urban rail transit uses the LTE-M system in the 1785MHz to 1805MHz frequency band to build dedicated wireless networks. However, this system has significant bandwidth limitations and cannot support the comprehensive carrying of high-capacity service data under redundant link conditions. With the increasing improvement of 4G / 5G public network signal coverage in cities, full public network coverage for urban rail transit is becoming a reality. Furthermore, 4G / 5G technologies offer high-speed mobility and high bandwidth capabilities, making it feasible to use 4G / 5G technology to carry data transmission for high-speed moving urban rail transit trains. Using the public network and public frequency bands to transmit train-to-ground wireless communication data can significantly reduce construction costs and effectively improve the train-to-ground wireless transmission capabilities of urban rail transit. Urban rail transit data transmission requires security and redundancy. Existing public network wireless transmission equipment generally uses transparent transmission, which cannot guarantee data security and lacks the ability to connect to multiple operator networks to provide redundant data transmission channels.

[0003] There are currently two main types of solutions:

[0004] Solution 1: Use wireless transparent transmission devices for transmission. Vehicle-mounted devices use wireless transparent transmission devices as routers, communicating directly with the internet via NAT (Network Address Translation) technology. However, when using wireless transparent transmission devices outside of a dedicated network, the vehicle-mounted device application must consider features such as encrypted transmission and redundant transmission. This requires the addition of additional software or hardware communication control modules in front of the wireless transparent transmission devices, which introduces inconvenience in practical applications. Furthermore, wireless transparent transmission devices are generally black-box devices, making effective network monitoring impossible. Equipment operation and maintenance rely on third-party equipment, resulting in low efficiency.

[0005] Solution 2: Online redundant transmission technology. Urban rail transit dedicated control networks require network redundancy. In dedicated networks, two sets of wireless access terminals are generally used to access the ground network at different frequencies and operate simultaneously to ensure redundant data transmission. However, in public networks, wireless communication networks are generally built by operators, and there are base stations from multiple operators and different manufacturers in the area, resulting in uneven coverage and possible areas of weak coverage. In addition, simultaneous transmission by two sets of equipment can only cover two operators, and redundancy is limited. Moreover, using multiple sets of transmission equipment for simultaneous transmission will increase the data processing pressure on ground servers exponentially, placing higher requirements on the processing performance of ground equipment and increasing equipment costs.

[0006] In view of the various problems existing in the existing technology, the development of a redundant encrypted wireless transmission solution based on public network transmission is of great significance to promoting the intelligent and information-based development of urban rail transportation. Summary of the Invention

[0007] The purpose of the present invention is to provide a hot-standby encrypted wireless transmission device for urban rail transit based on the public network, which can improve the bandwidth of the vehicle-to-ground transmission network, improve transmission stability and security, conveniently realize network monitoring, and reduce network construction costs.

[0008] The purpose of the present invention is achieved through the following technical solutions:

[0009] An urban rail transit hot standby encrypted wireless transmission device based on a public network, comprising: a wireless access terminal and a communication interface server; wherein:

[0010] The wireless access terminals are deployed on train ends, and each train end is deployed with multiple independently working wireless access terminals. Different wireless access terminals access the public networks of different operators and simultaneously communicate with the communication interface server, receiving data from the communication interface server and sending wireless quality monitoring data based on geographic information. Only one of the multiple independently working wireless access terminals is in an active state and can send and receive encrypted service data to the communication interface server.

[0011] The communication interface server is deployed on the ground side, receives wireless quality monitoring data based on geographic information sent by each wireless access terminal, periodically sends updated keys to each wireless access terminal for the wireless access terminal to perform data encryption and decryption, forwards the encrypted business data sent by the wireless access terminal to the corresponding ground device through device addressing, and forwards the encrypted business data from the ground device to the corresponding wireless access terminal through device addressing.

[0012] It can be seen from the technical solution provided by the above-mentioned present invention that, on the one hand, it breaks through the bandwidth limitation of the private network of urban rail transit and provides a large-capacity real-time transmission channel. Moreover, the transmission solution based on the public network expands the server location limitation of urban rail transit data transmission, which can realize more diversified application needs; on the other hand, the use of multiple wireless terminals to access the network provides multiple hot standby transmission channels, which ensures the reliability of transmission, and the design of periodic key updates improves the security of vehicle-ground data transmission; at the same time, the wireless status monitoring technology based on geographic information combines wireless status information and geographic information, provides rich network status monitoring elements, and improves the efficiency of wireless network optimization; in addition, the entire set of equipment is based on a wide range of public network applications, and can realize the replacement of public network for private network in vehicle-ground wireless data interaction applications of some urban rail transit lines, greatly reducing network construction costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0014] Figure 1 A schematic diagram of a public network-based urban rail transit hot standby encrypted wireless transmission device according to an embodiment of the present invention;

[0015] Figure 2 A schematic diagram of a transport layer protocol provided by an embodiment of the present invention;

[0016] Figure 3 A schematic diagram of an embodiment of the present invention providing a method for implementing data transmission between ground equipment and vehicle-mounted equipment using a wireless access terminal and a communication interface server;

[0017] Figure 4 A diagram showing the structure of a wireless access terminal device provided in an embodiment of the present invention;

[0018] Figure 5 A flowchart of wireless access terminal software initialization provided by an embodiment of the present invention;

[0019] Figure 6 A flowchart of wireless access terminal network access control provided by an embodiment of the present invention;

[0020] Figure 7 A flow chart of data transmission from a wireless access terminal according to an embodiment of the present invention;

[0021] Figure 8 A flowchart of a wireless access terminal data transmission thread provided by an embodiment of the present invention;

[0022] Figure 9 A flow chart of data reception by a wireless access terminal provided in an embodiment of the present invention;

[0023] Figure 10 A flowchart of integrity protection provided by an embodiment of the present invention;

[0024] Figure 11 The wireless access terminal activation state initialization process provided by the embodiment of the present invention;

[0025] Figure 12 A flowchart of a wireless access terminal broadcast monitoring provided by an embodiment of the present invention;

[0026] Figure 13 A flow chart of initializing a communication interface server provided in an embodiment of the present invention;

[0027] Figure 14 A flow chart of ground data addressing provided by an embodiment of the present invention;

[0028] Figure 15 A flowchart of vehicle data addressing provided by an embodiment of the present invention;

[0029] Figure 16 This is a flow chart of wireless server data reception provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0030] The following is a clear and complete description of the technical solutions in the embodiments of the present invention, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0031] First, the following terms may be used in this article:

[0032] The term “and / or” means that either or both of them can be realized at the same time. For example, X and / or Y includes both “X” or “Y” and “X and Y”.

[0033] The terms "include," "comprises," "contains," "has," or other similar expressions should be interpreted as non-exclusive. For example, "including certain technical features (such as raw materials, components, ingredients, carriers, dosage forms, materials, dimensions, parts, components, mechanisms, devices, steps, procedures, methods, reaction conditions, processing conditions, parameters, algorithms, signals, data, products, or manufactured articles, etc.) should be interpreted as including not only the technical features explicitly listed, but also other technical features known in the art that are not explicitly listed.

[0034] Unless otherwise specified or limited, the terms "mounted," "connected," "connect," and "fixed" should be interpreted broadly. For example, they can refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediary; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in this document based on specific circumstances.

[0035] The following is a detailed description of a public network-based urban rail transit hot standby encrypted wireless transmission device provided by the present invention. Any content not described in detail in the embodiments of the present invention belongs to the prior art known to professionals in this field. Where specific conditions are not specified in the embodiments of the present invention, the process shall be carried out in accordance with conventional conditions in the field or the conditions recommended by the manufacturer. The components used in the embodiments of the present invention, where the manufacturer is not specified, are all conventional products that can be purchased commercially.

[0036] The embodiment of the present invention provides a public network-based urban rail transit hot standby encrypted wireless transmission device, such as Figure 1 As shown, it mainly includes: wireless access terminal and communication interface server.

[0037] 1. Wireless access terminal.

[0038] The wireless access terminal is deployed at the train end, and each train end is deployed with multiple independently working wireless access terminals. Different wireless access terminals access the public networks of different operators and communicate with the communication interface server at the same time, receiving data from the communication interface server and sending wireless quality monitoring data based on geographic information. Only one of the multiple independently working wireless access terminals is in an active state and can send and receive encrypted business data to the communication interface server.

[0039] In the embodiment of the present invention, each train terminal can deploy three independently working wireless access terminals to access the public networks of different operators (China Mobile, China Telecom, and China Unicom).

[0040] 1) Wireless transmission technology.

[0041] In the embodiment of the present invention, a hot standby wireless transmission technology solution based on the public network is used: multiple wireless access terminals are connected to the communication interface server in an ad hoc network manner to provide transmission channels, thereby completing the hot standby of the transmission channels without generating redundant data and increasing the server burden.

[0042] 2) Hardware composition.

[0043] In an embodiment of the present invention, the train end uses a device platform that complies with the CPCI bus interface standard to integrate all wireless access terminals; the device platform that complies with the CPCI bus interface standard includes: a CPCI backplane, a power supply board, multiple wireless access terminal line network card boards, and a CPU board. The power supply board, multiple wireless access terminal line network card boards, and the CPU board are all fixed to corresponding slots on the CPCI backplane.

[0044] 3) Internal composition of wireless access terminal.

[0045] In an embodiment of the present invention, the wireless access terminal includes: an activation management module, a first data analysis module, a network status collection module, two wireless clients, a network access control module, a first log storage module, and a first parameter configuration module; wherein:

[0046] The first parameter configuration module is used to configure various parameters of the wireless access terminal during operation;

[0047] The first log storage module is used to store log data of the wireless access terminal;

[0048] The network access control module is used to realize automatic network access of wireless access terminals and automatic network access recovery when network anomalies occur;

[0049] The network status acquisition module is used to collect wireless quality monitoring data based on geographic information and send it to the communication interface server through the wireless client;

[0050] The two wireless clients are configured to interact with a communication interface server, receive data from the communication interface server, and send data to the communication interface server; the data received from the communication interface server includes delay measurement data, key synchronization data, and encrypted service data; the data sent to the communication interface server includes wireless quality monitoring data based on geographic information, delay measurement data, and encrypted service data; specifically, one of the wireless clients is responsible for transmitting the encrypted service data (wireless client 2), and the other wireless client (wireless client 1) is responsible for transmitting other data; the other data includes wireless quality monitoring data based on geographic information, delay measurement data, and key synchronization data;

[0051] The first data analysis module is used to receive encrypted business data from the communication interface server and then perform data analysis; the data analysis includes: data decryption and integrity protection.

[0052] The activation management module manages the status of the wireless access terminal through a self-organized device activation process, and the status includes: an activated state and an inactivated state.

[0053] 4) Data sending process.

[0054] In an embodiment of the present invention, the process of a wireless client sending data to a communication interface server includes:

[0055] Determine the current state based on the state machine of the wireless client;

[0056] If it is in the connected or connecting state, the data is directly put into the queue; if it is in the idle state, the connection thread is started to initiate a connection with the communication interface server and put the data into the queue; after the data is put into the queue, the semaphore is activated and waits for the sending thread to process;

[0057] When the connection thread is successfully connected to the communication interface server, the sending thread and the receiving thread are started to start the wireless transmission of data.

[0058] 5) Sending thread process and receiving thread process.

[0059] In an embodiment of the present invention, after the sending thread is started, it always waits for the semaphore for data transmission; when the semaphore is generated, if it is currently in a connected state and the key is synchronized, the data is encrypted and integrity protected and then sent to the communication interface server.

[0060] In an embodiment of the present invention, if a connection is found to be closed in a receiving thread, the receiving thread is closed. If the receiving thread is in a connected state, a delay measurement, key synchronization, and decryption process is performed according to the data type based on the data packet content obtained after integrity protection. Specifically, when the received data type is delay measurement data, data is returned based on the wireless client status in the data packet and the status of the wireless server in the communication interface server. When the wireless client and the wireless server respectively record two of their own timestamps, both parties can calculate the two-way delay in the network. When the received data type is key synchronization data, the current key is first backed up, and then the key is synchronized to the key required by the wireless server. When the received data type is encrypted service data, the service data is decrypted. If decryption fails using the current key, decryption is performed using the backup key.

[0061] 6) Activation management.

[0062] In this embodiment, a self-organizing device activation process is adopted, including:

[0063] Each wireless access terminal maintains a broadcast status table containing the broadcaster ID, last broadcast time, current status, MAC address, delay, and accumulated delay limit;

[0064] Each wireless access terminal monitors multiple broadcast cycles. If it does not receive a status broadcast from an active device, it sets its broadcaster ID to 0 or the maximum broadcast device ID + 1, enters the active state, and then periodically sends status broadcasts containing its own status information. If it receives a status broadcast from an active device, it sets its broadcaster ID to the maximum broadcast device ID + 1 and enters the inactive state. All devices continue to send status broadcasts, except that the current status byte in the broadcast information of the active device is 1, while that of other devices is 0.

[0065] When the latency of an active device exceeds the limit or the wireless network is interrupted, the device with the smallest latency and the smallest MAC address in the broadcast state table is selected as the active device and a successor broadcast is issued.

[0066] When the wireless access terminal does not receive a status broadcast for multiple consecutive periods or receives a broadcast with a target ID (broadcaster ID) that is inherited from the current wireless access terminal, it directly enters the active state; when the broadcaster ID of the device receiving the status broadcast is the same as the current wireless access terminal, whether to change the broadcaster ID of the current wireless access terminal is determined based on the MAC address; if the current wireless access terminal is in the active state but the status broadcast message received from other devices contains a status broadcast from an activated device, the evaluation value of the other wireless access terminal and the current wireless access terminal is determined based on the priority of the three values: the smaller cumulative delay limit, the smaller delay, and the smaller MAC address. When the evaluation value of the other wireless access terminal is higher than the evaluation value of the current wireless access terminal, the current wireless access terminal state is changed to the inactive state.

[0067] This section considers the scenario of a device being powered on, unplugged, and then plugged in. When the device is disconnected from the network and doesn't receive status broadcasts from other devices, it automatically sets itself to active. However, after plugging in the network, if it detects other active devices on the LAN, it determines whether it should remain active based on cumulative delays, latency, and MAC address. Specifically, when the cumulative delay exceeds the set threshold, the count increases by 1; latency refers to the average latency over a period of 10 seconds; and the MAC address refers to the physical network address of the device's wired port.

[0068] The evaluation value is evaluated using the priority. Consider wireless access terminal A and wireless access terminal B.

[0069] 1) When the cumulative number of over-limits of wireless access terminal A is less than that of wireless access terminal B, and the difference is greater than or equal to a first threshold (for example, 3), then the evaluation value of wireless access terminal A is higher; if the number of over-limits of wireless access terminal B is greater than or equal to the first threshold, then the evaluation value of wireless access terminal B is higher; otherwise, it is necessary to evaluate based on the delay.

[0070] 2) When the latency of wireless access terminal A is smaller than that of wireless access terminal B, and the difference is greater than a second threshold (e.g., 20ms), then the evaluation value of wireless access terminal A is higher; if the latency of wireless access terminal B is smaller than that of wireless access terminal A, and the difference is greater than the second threshold, then the evaluation value of wireless access terminal B is higher; otherwise, it is necessary to evaluate based on the device MAC address.

[0071] 3) When the MAC address of wireless access terminal A is smaller than the MAC address of wireless access terminal B, the evaluation value of wireless access terminal A is higher; otherwise, the evaluation value of wireless access terminal B is higher.

[0072] 2. Communication interface server.

[0073] The communication interface server is deployed on the ground side, receives wireless quality monitoring data based on geographic information sent by each wireless access terminal, periodically sends updated keys to each wireless access terminal for the wireless access terminal to perform data encryption and decryption, forwards the encrypted business data sent by the wireless access terminal to the corresponding ground device through device addressing, and forwards the encrypted business data from the ground device to the corresponding wireless access terminal through device addressing.

[0074] 1) Internal composition of the communication interface server.

[0075] In the embodiment of the present invention, the communication interface server mainly includes: a second data parsing module, a device number addressing module, a wireless quality monitoring module, two wireless service terminals, a second log storage module and a second parameter configuration module.

[0076] in:

[0077] The second parameter configuration module is used to configure various parameters when the communication interface server is working;

[0078] The second log storage module is used to store log data of the communication interface server;

[0079] The wireless quality monitoring module is used to perform wireless quality monitoring based on wireless quality monitoring data based on geographic information;

[0080] The second data parsing module is used to receive the encrypted business data from the sender and perform data parsing to obtain the receiver ID and the sender ID; the data parsing includes: data decryption and integrity protection;

[0081] The device number addressing module is used to perform device addressing according to the receiver ID and the sender ID, wherein the receiver and the sender are two vehicle-mounted devices, each connected to a different wireless access terminal; wherein one of the receiver and the sender is a vehicle-mounted device and the other is a ground device;

[0082] The two wireless service terminals are used to interact with the wireless access terminal, receive data from the wireless access terminal, and send data to the wireless access terminal. The data received from the wireless access terminal includes: wireless quality monitoring data based on geographic information, delay measurement data, and encrypted business data. The data sent to the wireless access terminal includes: delay measurement data, key synchronization data, and encrypted business data. Specifically, one of the wireless service terminals (wireless service terminal 2) is responsible for transmitting the encrypted business data, and the other wireless service terminal (wireless service terminal 1) is responsible for transmitting the wireless quality monitoring data based on geographic information. Both wireless service terminals need to be responsible for transmitting the delay measurement data and the key synchronization data.

[0083] 2) Device addressing method.

[0084] In an embodiment of the present invention, the communication interface server implements device addressing in the following manner:

[0085] The communication interface server stores a static ID-IP table and a dynamic ID-IP table; the device addressing work is performed through the static ID-IP table and the dynamic ID-IP table;

[0086] The static ID-IP table is generated by the ground server configuration data. If only one network ID-IP table is configured, the device addressing is performed for one network and ground devices (that is, the ground device addressing is performed using the ID-IP table of this network). If two network ID-IP tables are configured, the device addressing is performed for both networks and ground devices (that is, the ground device addressing is performed using the ID-IP tables of the two networks respectively). The same ID corresponds to one or more IPs plus ports.

[0087] The dynamic ID-IP table generation process is dynamically generated and managed by the server-side parsing encrypted business data; after the TCP connection accessed by the server correctly parses the application data packet, it obtains the receiver ID and sender ID, and then the ID corresponding to the address and port of the accessed TCP connection is considered to be the receiver ID; when the on-board device dynamically changes its ID, the server will also dynamically change its ID; among them, one of the receiver and sender is the on-board device, and the other is the ground device.

[0088] In this section, since it is a TCP connection and the address of the wireless access terminal is assigned according to the operator's rules, the IP address of the wireless access terminal cannot be determined; there is a sender ID in the communication protocol, so after receiving the service data sent by the wireless access terminal, you can check whether the dynamic ID-IP table has a corresponding wireless access terminal. If not, it will be added to the dynamic ID-IP table. If so, the time of the latest data received will be updated. When the ground equipment sends service data to the wireless access terminal, the destination device ID number needs to be written on the data packet so that the communication interface server can determine the specific wireless access terminal based on the device ID number. When the entry in the dynamic ID-IP table is disconnected from TCP or there is no data interaction for a period of time (for example, 10 seconds), the corresponding entry will be deleted from the table.

[0089] 3) Data receiving process.

[0090] In the embodiment of the present invention, the process of receiving data by the wireless server includes:

[0091] After reading the configuration, the TCP server is initialized and then the listening queue is used to wait for data to be received.

[0092] When the SOCKET of the data received is the handle of the server, it means that a wireless client is received, and the SOCKET of the corresponding wireless client is also added to the listening queue;

[0093] When the data receiving socket is a wireless client socket, it is first determined whether the connection is abnormal or closed. If so, the client socket is removed from the listening queue. If not, after receiving the data, the data content is obtained after integrity protection, and latency measurement and service data decryption are performed according to the data type.

[0094] After decryption, the business data can be parsed into the receiver ID and sender ID. The sender ID identifies the network address and port corresponding to the wireless client SOCKET, and the receiver ID is used for device addressing. After the business data completes the ID addressing, data processing is completed according to the wireless data processing flow.

[0095] In order to more clearly demonstrate the technical solution and technical effects provided by the present invention, a public network-based urban rail transit hot standby encrypted wireless transmission device provided by the present invention is described in detail below with reference to a specific embodiment.

[0096] 1. Transmission method

[0097] like Figure 2Figure 2 shows the transport layer protocol. The transport layer protocol for application layer data between devices uses either UDP or TCP, depending on the channel characteristics. The onboard device and wireless access terminal are connected via the onboard wired network, using UDP. The ground server and communication interface server are connected via a dedicated ground wired network, using UDP. The wireless access terminal and communication interface server are connected via a public network, using TCP.

[0098] like Figure 3 Figure 1 shows a schematic diagram of data transmission between ground and vehicle devices using a wireless access terminal and a communication interface server. Device A (wireless access terminal) and devices B, C, D, E, and F (ground devices) all send data to the wireless access terminal and the communication interface server. The data is then addressed to the device based on the device ID in the data and the ID-IP table in the communication interface server.

[0099] The wireless access terminal includes activation management, primary data analysis, network status collection, two wireless clients, network access control, primary log storage, and primary parameter configuration, totaling seven modules and eight components. The communication interface server includes secondary data analysis, device addressing, wireless quality monitoring, two wireless servers, secondary log storage, and secondary parameter configuration, totaling six modules and seven components and seven components.

[0100] The dotted line shows the user data flow. When device A needs to send data to device B, the data must flow through the first data parsing module and wireless client of the wireless access terminal, then through the transmission system to the wireless service end of the communication interface server, the device number addressing module, and the second data parsing module before reaching device B. The data flow of device B sending data to device A is the opposite.

[0101] In the embodiment of the present invention, the data transmission format (application data transmission protocol) between the vehicle-mounted device and the ground device is shown in Table 1.

[0102] Table 1: Application data transmission protocols

[0103]

[0104] The device number addressing module in the communication interface server performs device addressing through the receiver ID and sender ID in the above-mentioned application data transmission protocol.

[0105] 2. Wireless access terminal.

[0106] Urban rail transit data transmission requires high real-time and stability, and wireless access terminals must possess autonomous recovery and redundant backup capabilities. This invention employs three wireless access terminals with autonomous recovery capabilities to simultaneously connect to the three major carriers: China Telecom, China Mobile, and China Unicom. By applying the activation management method proposed in this invention, these three wireless access terminals achieve automatic networking and autonomous decision-making regarding active and standby operating states.

[0107] 1. Hardware composition.

[0108] like Figure 4 The figure shows the wireless access terminal device configuration. This device platform uses the CPCI (Compact PCI) bus interface standard. It integrates a power supply, wireless access terminal, wired network card board, and CPU board. Slot 1 is an 8HP power module, which provides ±12V, 5V, and 3.5V power to the CPCI backplane. Boards 2, 3, and 4 are 4HP in size and serve as three wireless access terminals. Board 6 is a 4HP wired network card. Board 7 is an 8HP CPU board. The three wireless access terminals operate independently. It supports 4G / 5G networks from China Telecom, China Mobile, and China Unicom; it has four Ethernet interfaces; and it supports BeiDou / GPS.

[0109] It should be noted that Figure 4 The number of slots and their positional relationships shown are only examples and can be adjusted by the user based on actual conditions.

[0110] 2. Workflow.

[0111] In the embodiment of the present invention, the wireless access terminal is composed of a first parameter configuration, a first log storage, a network access control, a first data analysis, a network status collection and a wireless client, and an activation management module; its initialization process is as follows Figure 5 As shown in the figure, the local application service processing thread receives data from the directly connected vehicle and sends it to the communication interface server; it also receives data from the communication interface server and sends it to the vehicle device. The local management service thread allows users to query the status of wireless terminal devices. It has four management commands: wireless status query command, device restart command, device shutdown command, and current working status (activation / inactivation) query command.

[0112] 1) Parameter configuration.

[0113] Configuration parameters include the following: server address and port, local binding address and port, local data processing address and port, local location information service address and port, local management and maintenance address and port, logging mode, local log storage path, local log binding address and port, and remote log server address and port. Table 2 shows a complete configuration file example.

[0114] Table 2: Configuration file example

[0115]

[0116] When no local configuration file is found during program execution, the program will automatically generate a default configuration file according to the format to prevent the program from being unable to be restored and reconfigured after the user deletes the configuration file.

[0117] 2) Network access control.

[0118] In order to separate network access control from application layer communication, the method of opening different threads is adopted to drive the wireless network card to complete the functions of automatic network access and automatic recovery.

[0119] like Figure 6 The figure below illustrates the wireless access terminal network access control process. First, the wireless network card is controlled to access the network according to AT commands. After successful access, periodic monitoring is initiated to ensure timely network recovery in the event of an anomaly. Tables 3 and 4 illustrate the network access and monitoring processes.

[0120] Table 3: Network access process

[0121]

[0122]

[0123] Table 4: Monitoring process

[0124]

[0125]

[0126] 3) Network status collection.

[0127] In the embodiment of the present invention, the wireless status monitoring technology based on geographic information combines wireless status information with geographic information, provides a rich set of network status monitoring elements, and improves the efficiency of wireless network optimization. The application data of the network status collection content is shown in Table 5.

[0128] Table 5: Application data of network status collection content

[0129]

[0130] If the device is in a tunnel, the longitude and latitude positioning of the device information cannot be used. The "segment + offset" method provided by the urban rail transit train control system interface can be used to locate the device to achieve uninterrupted data monitoring.

[0131] 4) Wireless client principle.

[0132] The wireless client starts the workflow by sending data. The design idea of the present invention is to perform TCP connection and queue sending functions according to the current wireless client status when sending data. At the same time, an asynchronous processing mechanism is designed to achieve a congestion-free data sending process.

[0133] like Figure 7 The figure shows the data transmission process of the wireless client. When a user requests to send data, the wireless client's state machine is first used to determine the current state. If it is in the connected state or connected, the data is directly placed in the queue. Otherwise, the connection thread is started to initiate a TCP connection with the peer server, the sent data is placed in the queue, and the semaphore is activated.

[0134] When the connection thread is successfully connected to the peer server, the sending thread and receiving thread are started to start wireless data transmission. Figure 8 Figure 1 shows the data sending thread process for a wireless access terminal. The sending thread constantly waits for a semaphore to signal data transmission. When the semaphore is generated, if the terminal is currently connected and synchronized, the data is encrypted and integrity-protected before being sent to the peer server. If the connection is lost, the sending thread terminates.

[0135] like Figure 9 Figure 1 shows the data receiving thread process for a wireless access terminal. If the connection is closed in the receiving thread, the receiving thread is terminated. Otherwise, latency measurement, key synchronization, and decryption are performed based on the data type based on the integrity-protected data packet content.

[0136] In the embodiment of the present invention, it is considered that TCP transmission is in the form of a data stream. The sender of TCP sends out packets of data separately. In the present invention, each packet of data is called a frame. However, the data received by the receiver of TCP may be a combination of multiple data packets, such as 1.2 packets, 1.5 packets, 3 packets, 4.5 packets, etc. The present invention designs a method to recover a complete packet of data from any data, specifically by introducing three special state control data to parse the received data into complete data packets. The data integrity protection function provides a data packet parsing method for converting the user data packet sending mode into the data stream sending mode, and on the other hand, it provides a certain protection capability for the data.

[0137] Corresponding to the encapsulation and parsing of integrity protection. Define four states A, B, C, D and three special state control markers BOF (start of frame marker), COF (control frame marker), EOF (end of frame marker). Among them, the three special state control data can be any characters, but once selected, these characters become special characters. For example, the start frame marker BOF can be selected as 0xBF, the control frame marker COF can be selected as 0xBC, and the end frame marker EOF can be selected as 0xBE. First, add the start frame marker BOF to the target data array; then, add the original data (that is, the data to be sent) to the target data array in sequence. If the original data added to the target data array is state control data, then add the control frame marker COF before adding it; if the data ends, add the end frame marker EOF. During integrity protection, the received target data array is restored to a complete data packet form based on the three special state control markers.

[0138] For example, if BOF is 0xAA, COF is 0xCC, and EOF is 0xEE, data is encapsulated before transmission. If the data packet contains these control characters, COF is added before them. For example, when sending 0xaabbccddeeff, it becomes 0xAACCaabbCCccddCCeeffEE. First, add 0xAA and 0xEE to the first and last bits of the data, and add 0xCC before 0xaa and other bits in the data. During parsing, the state machine can decode 0xaabbccddeeff. When receiving two or three frames of data superimposed (data stream), three special state control flags can be used to reconstruct them into three data frames.

[0139] like Figure 10The figure shows the state machine transitions during data reception during the integrity protection process. States A, B, C, and D are custom states used for parsing integrity-protected packets. These states transition from the start to the end of a connection. When receiving data, the state machine initially enters State A. In State A, if the Start of Frame (BOF) is not present, the state remains in State A; otherwise, it enters State B. While in State B, if a Control Frame (COF) is received, the state enters State C; otherwise, it enters State D. While in State D, if a Start of Frame (BOF) is received, the state enters State B; if a Control Frame (COF) is received, the state enters State C; otherwise, it enters State D. In State D, if a Control Frame (EOF) is received, the state enters State A and completes the data packet; otherwise, it remains in State D. State B represents the start bit of the data; after recording the application data, the state enters State D. State D continuously records data and increments the data length. When the data contains status control data, the state enters State C, following the Control Frame (COF) + Control Data pattern added when establishing data integrity. After adding the control status data to the service data and increasing the length, the state enters State D.

[0140] When the received data type is delay measurement, the client status and server status of the data packet are measured according to the timestamps shown in Table 6, and the data is returned. When the client and server respectively record their own timestamps, both parties can calculate the two-way delay in the network.

[0141] Table 6: Timestamp measurement data packet

[0142]

[0143] When the received data type is key synchronization information, the current key is first backed up, and then the key is synchronized to the key required by the server. The key data synchronization package is shown in Table 7.

[0144] Table 7: Key data synchronization package

[0145] name Length (Byte) scope illustrate Data Type 4 0xFFEFFDDE: Key synchronization Key seed 4 0x0-0xFFFFFFFF Key

[0146] During key consolidation, in multi-threaded programming, it's inevitable that keys may be synchronized but data may still be encrypted using the backup key. Therefore, if data received fails to be decoded using the current key, the backup key will be used. If both attempts fail, the data packet will be discarded. Keys are updated at regular intervals to ensure data encryption and prevent third-party decryption.

[0147] 5) Activation management.

[0148] The activation management module implements a self-organizing device activation process. The design concept is to use device broadcasts to exchange information about wireless terminals connected to different carriers' networks. Each device can automatically negotiate its device ID, and each device selects an active device based on its own status and the status of other devices.

[0149] Each wireless terminal needs to maintain a broadcast status table (status broadcast protocol) as shown in Table 8, which includes the broadcaster ID, receiver ID (fixed to 0xFFFFFFFF), last broadcast time, current status, MAC address, delay, and delay limit accumulation.

[0150] Table 8: Broadcast status table

[0151] name Length (Byte) scope illustrate Broadcaster ID 4 0x0-0xFFFFFFFF Dynamic acquisition Recipient ID 4 0x0-0xFFFFFFFF 0xFFFFFFFF: All devices Broadcast Type 2 0x0-0xFFFFFFFF 0x0: Status broadcast Broadcast Time 8 Current device time Current Status 2 0 / 1 1 is active, 0 is inactive MAC address 6 MAC address of the device's network card Latency 2 0x0-0xFFFF Measure latency in milliseconds Delay Exceeding Accumulation 2 0x0-0xFFFF Number of times the delay exceeds the threshold consecutively

[0152] Table 9 is the inheritance broadcast table. When the delay of the activated device exceeds the accumulated limit or the wireless network is interrupted, the device with the smallest accumulated delay and the smallest MAC address is selected as the activated device according to the broadcast status table and sends the inheritance information.

[0153] Table 9: Inherited broadcast table

[0154] name Length (Byte) scope illustrate Broadcaster ID 4 0x0-0xFFFFFFFF Dynamic acquisition Recipient ID 4 0x0-0xFFFFFFFF Inherit the broadcaster ID of the device in the active state Broadcast Type 2 0x0-0xFFFFFFFF 0x1: Inherited broadcast

[0155] like Figure 11 The figure shows the initialization process for the wireless access terminal's activation state. When a device comes online, it has no information about its own broadcaster ID and status. Therefore, it monitors multiple (for example, three) broadcast cycles. If it does not receive a status broadcast from an activated device, it sets its broadcaster ID to 0 or the maximum broadcaster ID + 1, enters the activated state, and then periodically broadcasts its status. If it receives a status broadcast from an activated device, it directly sets its broadcaster ID to the maximum broadcaster ID + 1, and enters the inactive state.

[0156] like Figure 12 As shown, the broadcast monitoring process of the wireless access terminal is demonstrated. When the device does not receive broadcast information for multiple (for example, 3) consecutive cycles or receives a broadcast whose target ID is inherited from the current device, it directly enters the activated state. When the broadcaster ID of the device receiving the status broadcast is the same as that of the local device, it is decided whether to change the broadcaster ID of the current device based on the MAC address. When the local device is an activated device and the status broadcast includes the activated device, the evaluation value of the other device and the local device is determined based on the priority comparison of the three values: smaller cumulative delay limit, smaller delay and smaller MAC address. When the evaluation value of the other device is higher than the evaluation value of the local device, the status of the local device is changed to an inactive state.

[0157] 3. Communication interface server.

[0158] In the embodiment of the present invention, the communication interface server is mainly composed of a second parameter configuration, a second log storage, a second data analysis, a wireless quality monitoring and device number addressing and a wireless service end module. The initialization process of the communication interface server is as follows: Figure 13 As shown in the figure, the server processing thread cyclically monitors the TCP server socket and the TCP client socket; it processes TCP connection requests, wireless network status information, service data, and latency measurement data sent by the TCP client; the local management service thread provides management and query services for devices connected to the ground LAN. Queries include dynamic ID-IP table queries, traffic queries, rate queries, access client information queries, and server CPU memory usage queries; control commands include shutdown, program restart, system restart, and time synchronization commands.

[0159] 1. Parameter configuration.

[0160] Parameter configuration includes the following aspects: logging mode, local log storage path, local log binding address and port, remote log server address and port, local TCP binding address and port, communication port and address between the local server and private network A, communication port and address with private network B, and the wayside_a / b ID-IP mapping table. Table 10 shows a complete configuration file example. Private network A and private network B refer to two different private networks.

[0161] Table 10: Configuration file example

[0162]

[0163]

[0164] When no local configuration file is found during program execution, the program will automatically generate a default configuration file according to the format to prevent the program from being unable to be restored and reconfigured after the user deletes the configuration file.

[0165] 2. Device number addressing.

[0166] The device number addressing process uses the static ID-IP table on the server side and the dynamic ID-IP table of the TCP connection to address the device. The devices included in the static ID-IP table are ground devices that are on the same ground LAN as the communication interface server. Each device is assigned an ID corresponding to the IP of each device. The dynamic ID-IP is because the IP address of the train will change, so it is necessary to establish a dynamic ID-IP table at any time based on the ID information in the application data protocol. The dynamic ID-IP table is the on-board device table, and the static ID-IP table is the ground device table. The specific addressing process is as follows:

[0167] The static ID-IP table is generated from the ground server configuration data and provides device addressing functionality for both networks. If only one network's static ID-IP table is configured, device addressing is performed for both networks and ground devices. If two networks' static ID-IP tables are configured, device addressing is performed for both networks and ground devices. The same ID can be mapped to multiple IP addresses and ports.

[0168] The communication interface server has three network ports: one for the public network, one for private network A, and one for private network B. The public network port is responsible for transmitting and receiving data with wireless access terminals; the port for private network A transmits and receives data with devices on ground private network A; and the port for private network B transmits and receives data with devices on ground private network B. Since trains communicate with devices on both private network A and B simultaneously, redundancy is also a key consideration. If the control system on ground private network A fails, troubleshooting can still be achieved through private network B. There are two static ID-IP tables: one for devices on private network A and one for devices on private network B. For example, if the central control server on private network A has a primary and backup server, and the central control server on private network B also has a primary and backup server, then the central control server's device ID can correspond to the IP addresses of four devices. When the communication interface server receives a message with the device ID of this central control server as its destination, it sends the message to the primary and backup systems via private network A and to the primary and backup systems via private network B, resulting in four copies of the data. At the same time, since the central control server contains a master and a backup machine, the master and backup machine IDs are the same, but the IPs are different.

[0169] The dynamic ID-IP table generation process is dynamically generated and managed by the server parsing the application data. After the server's accessed TCP connection correctly parses the application data packet, it obtains the receiver ID and sender ID, and then the ID corresponding to the address and port of the accessed TCP connection is considered to be the receiver ID. From this method, it can be seen that when the vehicle-mounted device dynamically changes its ID, the server will also dynamically change its ID. The dynamic ID-IP table can avoid the impact of IP changes caused by network hardware replacement on the communication system in the public network.

[0170] like Figure 14 Figure 1 shows the ground data addressing flow chart. When data is received from private network A / B, the dynamic ID-IP table is first traversed. If a corresponding ID exists, the data is sent via TCP. If not, the data received from network A / B is returned to the sender, indicating that the addressing failed.

[0171] like Figure 15Figure 2 shows the in-vehicle data addressing flow chart. Upon receiving data from the public network, the system first searches the static ID-IP table corresponding to private network A / B. If a corresponding ID exists, the data is sent via UDP. If not, the data is returned to the sending device via the public network, indicating that the addressing failed. This feature demonstrates that when an in-vehicle device selects an ID that does not exist in the system for data transmission, it can be used to measure round-trip latency.

[0172] 3. Wireless server.

[0173] The workflow of the wireless server is as follows: Figure 16 As shown. First, the TCP server is initialized after reading the configuration, and then the listening queue is used to wait for data reception. When the SOCKET (socket) for data reception is the handle of the server, it indicates that a client has been received, and the SOCKET of the client is also added to the listening queue. When the SOCKET for data reception is a client SOCKET, it is first determined whether the connection is abnormal or closed, and the client SOCKET is removed from the listening queue. Then, after integrity protection, the application data content is obtained, and delay measurement and business data decryption are performed according to the data type. After decryption, the business data can be parsed into the receiver ID and sender ID. The sender ID can identify the network address and port corresponding to the client SOCKET, and the receiver ID is used for device addressing. After the business data completes ID addressing, data processing is completed according to the processing flow of wireless data. Figure 16 The set ID at the bottom refers to the ID of the vehicle-mounted device corresponding to the TCP connection, that is, the ID in the dynamic ID-IP table. This ID is also the destination ID in the data content sent by the ground device to the communication interface server. Through this ID, the TCP client socket can be found, and the data can be sent to the vehicle-mounted device through the socket.

[0174] The wireless data processing flow mainly includes: 1) updating the dynamic ID-IP table; 2) accumulating the transmission traffic, which is only used as a record; 3) calculating the transmission rate, which is in units of 2 seconds, which is only used as a record; 4) storing data summary, which only stores the application data packet header.

[0175] The integrity protection, delay measurement, and key decryption processes are the same as those of wireless access terminals. The wireless server's key is updated regularly at a fixed time period (e.g., 1 minute), and after the update, all connected wireless access terminals are synchronized.

[0176] The above solution provided by the embodiment of the present invention mainly achieves the following beneficial effects:

[0177] 1. Increased bandwidth for train-to-ground transmission networks. This overcomes the bandwidth limitations of dedicated urban rail transit networks and provides high-capacity, real-time transmission channels. Furthermore, this public network-based transmission solution extends the server location limitations of urban rail transit data transmission, enabling a wider range of application needs.

[0178] 2. Improved transmission stability and security. Using a multi-wireless terminal ad hoc network, multiple hot standby transmission channels are provided to ensure transmission reliability. Furthermore, the design of integrity protection and periodic key updates enhances the security of vehicle-to-ground data transmission.

[0179] 3. Convenient network monitoring. Geographic information-based wireless status monitoring technology combines wireless status information with geographic information, providing a rich set of network status monitoring elements and improving the efficiency of wireless network optimization.

[0180] 4. Reduce network construction costs. This equipment has a wide range of applications based on the public network. It can replace the public network with the private network in some urban rail transit lines in the application of wireless data interaction between vehicles and the ground, greatly reducing network construction costs.

[0181] Those skilled in the art will clearly understand that for the convenience and brevity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the system can be divided into different functional modules to complete all or part of the functions described above.

[0182] The above description is merely a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A public network-based urban rail transit hot standby encrypted wireless transmission device, characterized in that: include: Wireless access terminal and communication interface server; wherein: The wireless access terminal is deployed at the train end, and each train end is deployed with multiple independently working wireless access terminals. Different wireless access terminals access the public networks of different operators and communicate with the communication interface server at the same time, receive data from the communication interface server and send wireless quality monitoring data based on geographic information. Only one of the multiple independently working wireless access terminals is in an activated state and can send and receive encrypted business data to the communication interface server; the wireless access terminal includes: an activation management module, a first data parsing module, a network status acquisition module, two wireless clients, a network access control module, a first log storage module and a first parameter configuration module; wherein: the first parameter configuration module is used to configure various parameters when the wireless access terminal is working; the first log storage module is used to store log data of the wireless access terminal; the network access control module is used to realize automatic network access of the wireless access terminal and automatic network abnormality. Automatic restoration of network access; the network status acquisition module is used to collect wireless quality monitoring data based on geographic information and send it to the communication interface server through the wireless client; the two wireless clients are used to interact with the communication interface server, receive data from the communication interface server, and send data to the communication interface server; the data received from the communication interface server includes: delay measurement data, key synchronization data and encrypted business data; the data sent to the communication interface server includes: wireless quality monitoring data based on geographic information, delay measurement data and encrypted business data; the first data parsing module is used to receive the encrypted business data from the communication interface server and then perform data parsing; the data parsing includes: data decryption and integrity protection; the activation management module manages the status of the wireless access terminal through a self-organized device activation process, and the status includes: activation state and inactivation state; The communication interface server is deployed on the ground side, receives wireless quality monitoring data based on geographic information sent by each wireless access terminal, periodically sends updated keys to each wireless access terminal for the wireless access terminal to perform data encryption and decryption, forwards the encrypted business data sent by the wireless access terminal to the corresponding ground device through device addressing, and forwards the encrypted business data from the ground device to the corresponding wireless access terminal through device addressing.

2. The urban rail transit hot standby encrypted wireless transmission device based on the public network according to claim 1 is characterized in that: The train end uses a device platform with CPCI bus interface standard to integrate all wireless access terminals; the device platform with CPCI bus interface standard includes: a CPCI backplane, a power board, multiple wireless access terminal line network card boards and a CPU board, and the power board, multiple wireless access terminal line network card boards and CPU board are all fixed on corresponding slots on the CPCI backplane.

3. The urban rail transit hot standby encrypted wireless transmission device based on the public network according to claim 1 is characterized in that: The process of a wireless client sending data to a communication interface server includes: Determine the current state based on the state machine of the wireless client; If it is in the connected or connecting state, the data is directly put into the queue; if it is in the idle state, the connection thread is started to initiate a connection with the communication interface server and put the data into the queue; after the data is put into the queue, the semaphore is activated and waits for the sending thread to process; When the connection thread is successfully connected to the communication interface server, the sending thread and the receiving thread are started to start the wireless transmission of data; After the sending thread is started, it always waits for the semaphore of data sending; when the semaphore is generated, if it is currently in a connected state and the key is synchronized, the data is encrypted and integrity protected and then sent to the communication interface server.

4. The urban rail transit hot standby encrypted wireless transmission device based on the public network according to claim 3 is characterized in that: In the receiving thread, if the connection is found to be closed, the receiving thread is closed; If the connection is established, the delay measurement, key synchronization, and decryption process are performed based on the data type according to the data packet content obtained after integrity protection. When the received data type is delay measurement data, the data is returned based on the wireless client status in the data packet and the wireless server status in the communication interface server. When the wireless client and wireless server each record their own timestamps, both parties can calculate the two-way delay in the network. When the received data type is key synchronization data, the current key is backed up first, and then the key is synchronized to the key required by the wireless server; When the received data type is encrypted business data, the business data is decrypted. If the decryption fails using the current key, the backup key is used for decryption.

5. The urban rail transit hot standby encrypted wireless transmission device based on the public network according to claim 1 is characterized in that: The self-organizing device activation process includes: Each wireless access terminal maintains a broadcast status table containing the broadcaster ID, last broadcast time, current status, MAC address, delay, and accumulated delay limit; Each wireless access terminal monitors multiple broadcast cycles. If it does not receive a status broadcast from an active device, it sets its broadcaster ID to 0 or the maximum broadcaster ID + 1, enters the active state, and then periodically sends status broadcasts. If it receives a status broadcast from an active device, it sets its broadcaster ID to the maximum broadcaster ID + 1 and enters the inactive state. When the latency of an active device exceeds the limit or the wireless network is interrupted, the device with the smallest latency and the smallest MAC address in the broadcast state table is selected as the active device and a successor broadcast is issued. When the wireless access terminal does not receive a status broadcast for multiple consecutive periods or receives a broadcast whose target ID is inherited from the current wireless access terminal, it directly enters the active state; when the broadcaster ID of the device receiving the status broadcast is the same as the current wireless access terminal, it decides whether to change the broadcaster ID of the current wireless access terminal based on the MAC address; if the current wireless access terminal is in the active state but the status broadcast message received from other devices contains a status broadcast from an activated device, the evaluation value of the other wireless access terminal and the current wireless access terminal is determined based on the priority of the three values: the smaller cumulative delay limit, the smaller delay, and the smaller MAC address. When the evaluation value of the other wireless access terminal is higher than the evaluation value of the current wireless access terminal, the current wireless access terminal state is changed to the inactive state.

6. The urban rail transit hot standby encrypted wireless transmission device based on the public network according to claim 1 is characterized in that: The communication interface server includes: a second data parsing module, a device number addressing module, a wireless quality monitoring module, two wireless service terminals, a second log storage module and a second parameter configuration module The second parameter configuration module is used to configure various parameters when the communication interface server is working; The second log storage module is used to store log data of the communication interface server; The wireless quality monitoring module is used to perform wireless quality monitoring based on wireless quality monitoring data based on geographic information; The second data parsing module is used to receive the encrypted business data from the sender and perform data parsing to obtain the receiver ID and the sender ID; the data parsing includes: data decryption and integrity protection; The device number addressing module is used to perform device addressing according to the receiver ID and the sender ID, wherein the receiver and the sender are two vehicle-mounted devices, each connected to a different wireless access terminal; wherein one of the receiver and the sender is a vehicle-mounted device and the other is a ground device; The two wireless service terminals are used to interact with the wireless access terminal, receive data from the wireless access terminal, and send data to the wireless access terminal; the data received from the wireless access terminal includes: wireless quality monitoring data based on geographic information, delay measurement data and encrypted business data; the data sent to the wireless access terminal includes: delay measurement data, key synchronization data and encrypted business data.

7. The urban rail transit hot standby encrypted wireless transmission device based on the public network according to claim 1 or 6, characterized in that: The communication interface server implements device addressing in the following manner: The communication interface server stores a static ID-IP table and a dynamic ID-IP table; the device addressing work is performed through the static ID-IP table and the dynamic ID-IP table; The static ID-IP table is generated by the ground server configuration data. If only one network ID-IP table is configured, the device addressing is performed for one network and the ground device. If two network ID-IP tables are configured, the device addressing is performed for both networks and the ground device. The same ID corresponds to one or more IPs and ports. The dynamic ID-IP table generation process is dynamically generated and managed by the server-side parsing encrypted business data; after the TCP connection accessed by the server correctly parses the application data packet, it obtains the receiver ID and sender ID, and then the ID corresponding to the address and port of the accessed TCP connection is considered to be the receiver ID; when the on-board device dynamically changes its ID, the server will also dynamically change its ID; among them, one of the receiver and sender is the on-board device, and the other is the ground device.

8. The urban rail transit hot standby encrypted wireless transmission device based on the public network according to claim 6 is characterized in that: The process of receiving data on the wireless server includes: After reading the configuration, the TCP server is initialized and then the listening queue is used to wait for data to be received. When the SOCKET of the data received is the handle of the server, it means that a wireless client is received, and the SOCKET of the corresponding wireless client is also added to the listening queue; When the data receiving socket is a wireless client socket, it is first determined whether the connection is abnormal or closed. If so, the client socket is removed from the listening queue. If not, after receiving the data, the data content is obtained after integrity protection, and latency measurement and service data decryption are performed according to the data type. After decryption, the business data can be parsed into the receiver ID and sender ID. The sender ID identifies the network address and port corresponding to the wireless client SOCKET, and the receiver ID is used for device addressing. After the business data completes the ID addressing, data processing is completed according to the wireless data processing flow.

9. The urban rail transit hot standby encrypted wireless transmission device based on a public network according to claim 1, 3, 6 or 8, characterized in that: The integrity protection refers to parsing the received data into a complete data packet by introducing three state control data, the three state control marks include: start frame mark BOF, control frame mark COF, end frame mark EOF; first, add the start frame mark BOF to the target data array; then add the original data to the target data array in sequence. If the original data added to the target data array is state control data, then add the control frame mark COF before adding; if the original data ends, add the end frame mark EOF; during integrity protection, the received target data array is restored to the form of a complete data packet according to the three state control marks.

Citation Information

Patent Citations

  • System and method for configuring train-ground wireless communication authentication key of urban mass transit system

    CN105142137A