Active safety based lightweight onboard trusted network system for railway vehicles
By constructing a lightweight onboard trusted network system for rail vehicles based on proactive safety, the problems of node device identification and trusted authentication in rail vehicle onboard networks are solved, thereby improving the real-time performance and security of the onboard network and making it suitable for proactive safety protection of rail vehicle onboard networks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NAT HIGH SPEED TRAIN QINGDAO TECH INNOVATION CENT
- Filing Date
- 2023-02-23
- Publication Date
- 2026-05-12
AI Technical Summary
Existing technologies are not effectively applicable to node device identity authentication, trusted authentication between node devices, and trusted authentication between networks in rail vehicle onboard networks. Furthermore, traditional trusted computing network architectures require recalculation when the environment changes, leading to increased computational load and reduced network real-time performance.
Design a lightweight onboard trusted network system for rail vehicles based on active safety. Through network node device access authentication mechanism, inter-subnet trusted authentication, and inter-device command interaction authentication, the system utilizes trusted cryptography module, trusted software base module, and trusted service module to realize identity authentication, measurement, and policy management, and builds a lightweight onboard trusted platform that is embedded in every layer of the onboard network system to ensure identity recognition and trusted verification between communicating parties.
It realizes the active safety function of the vehicle network, meets the real-time requirements of the train network, improves the network's active safety immunity, reduces safety hazards, is suitable for vehicle network scenarios, avoids large-scale modification, and improves system security and real-time performance.
Smart Images

Figure CN116346419B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of vehicle-mounted network information security technology, and relates to vehicle-mounted network technology for rail vehicles. Specifically, it relates to a lightweight, trusted vehicle-mounted network system for rail vehicles based on active safety. Background Technology
[0002] The rail vehicle network control system is one of the core systems of a train, often referred to as the train's brain and nervous system. Its main functions include overall vehicle control, status monitoring, and fault diagnosis. The train network primarily comprises the train control network, train maintenance network, and train signaling network. With the introduction of artificial intelligence and autonomous driving functions, train network control systems based on industrial Ethernet have been widely adopted. However, Ethernet's open communication protocol stack introduces significant security risks to the onboard communication network system. Onboard industrial Ethernet differs from traditional industrial Ethernet in its network protocols, architecture, and operating environment. For example, train networks use the real-time Ethernet protocol TRDP, while general industrial control systems mostly use standard industrial protocols. The topology and access devices of general industrial control networks and train networks also differ. Train networks have a higher degree of integration, with most devices using board-based architectures. The onboard network system contains various types of node devices, which are heterogeneous. Some nodes with weak security protection capabilities are vulnerable to security attacks. Similarly, because malicious terminal devices or computing devices may access the vehicle-to-ground wireless communication boundary, data security cannot be guaranteed.
[0003] Existing protection technologies are mainly divided into two levels: active protection and passive protection. Currently, facing ever-changing network threats, network security has evolved into an era of "intrinsic security," requiring the continuous growth of adaptive, autonomous, and self-evolving security capabilities through its own immune system. To this end, my country has formulated the "Information Security Technology Trusted Computing Specification Trusted Connection Architecture" standard. This standard adopts a three-element, three-layer, peer-to-peer, and centrally managed trusted connection architecture technology. Before a terminal connects to the target network, the trusted network authenticates its identity. If authentication is successful, the platform's trust status of the terminal is measured. If the measurement result meets the network connection security policy, the terminal is allowed to connect to the network; otherwise, access is denied. This is an active, bidirectional, and pre-emptive network connection method. However, this technology only provides a trusted connection scheme for terminal access to the network and cannot be applied to trusted authentication between networks. Therefore, experts and scholars have conducted a series of studies in this field.
[0004] In the research of general-purpose trusted computing platforms: Shen Changxiang et al. proposed a trusted computing platform with a parallel dual-architecture architecture of computation and protection (application number: 201910195870.1). This trusted computing platform includes a parallel computation subsystem and a protection subsystem. The computation subsystem is used to complete computation tasks, and the protection subsystem is used to actively measure and control the computation subsystem according to a trusted policy through a trusted platform control module. Shen Changxiang et al. also proposed a construction method and a trusted computing platform with a dual-architecture architecture (application number: 201910610041.5). This method constructs computational resources to complete computation tasks; constructs trusted computing resources for actively measuring the computational resources and performing corresponding active control based on the results of the active measurement. Active measurement includes static and dynamic measurement; and configures the computational resources and trusted computing resources into a computer central processing unit (CPU) to obtain a dual-architecture trusted computing platform, which includes the CPU and other external resources. Wu Bangqiang et al. proposed a highly reliable integrated computer motherboard (application number: 201621426039.0). This motherboard includes the motherboard body and a Loongson 3A processor, northbridge chip, southbridge chip, PCIe switch chip, and trusted cryptographic module mounted on the motherboard body. Zhang Lingchen proposed a trusted network access method and system (application number: 201910673889.2). This method adopts a vertical information flow processing architecture, including a vertically decoupled data plane and defense plane. On the data plane, network packet rectification and transmission function calls are performed through interfaces to realize the sending and receiving of network packets. On the defense plane, security functions such as network packet encryption and decryption, integrity authentication, and key management are implemented. Xiao Zhengrong et al. proposed a method and system for network access authentication (application number: 202010408450.X). This method sends an access authentication request to the operator's core network system; receives a system-encrypted message generated and sent by the operator's core network system based on the access authentication request; and receives verification broadcast information sent by a second user terminal based on the user's legitimate broadcast information. The user then accesses the blockchain network based on the legitimate broadcast information and the verification broadcast information. Liu Siyao et al. proposed a trusted computing system and security protection system (application number: 202011588415.7). This system includes a trusted cryptographic module, a trusted platform control module, a trusted computing platform, a trusted BIOS platform, a trusted software module, trusted application software, and a network layer. Through a trusted computing system that combines computation and protection under secure and trusted policy control, it can effectively provide security protection for cyberspace in a big data environment.Sun Yu et al. proposed a trusted connection method for cloud environments (application number: 201911316415.9). This method intercepts external network requests through a cloud trusted boundary device, performs trusted connection authentication on external nodes, and after successful authentication, intercepts external network requests again through the virtual trusted boundary device of the tenant node, performing trusted connection authentication on external nodes. Dual authentication is required to establish a trusted connection between the external and internal cloud environments. Wang Fei et al. proposed a trusted network connection method based on near real-time state feedback (application number: 201610333356.6). This system includes a policy manager, a trusted connection management server, and multiple trusted terminals. During data transmission, even if the state of a trusted terminal changes, a trusted network connection can still be established according to the corresponding communication control policy after the change, improving the security of the trusted network and ensuring the real-time performance of data transmission.
[0005] In the research on active safety of onboard network systems for rail vehicles, He Yuehua et al. designed a secure access system and method for EMU network equipment (application number: 201810253117.9). The system includes an EMU network control system; several EMU subsystems connected to the EMU network control system; a wireless transmission device connected to the EMU network control system; and a ground server. When the life signal of an onboard network device is detected to be interrupted, the device is determined to be offline. When the device reconnects to the EMU network control system, it must be re-authenticated.
[0006] Gao Chunhai et al. proposed a rail transit information security protection system (application number: 201510825233.X), which monitors network data traffic in real time through intelligent monitoring equipment for communication networks, analyzes whether there are viruses or attacks on the network, and determines whether network information is secure. Zuo Zihui et al. proposed an access authentication method, device, equipment, and storage medium for railway services (application number: 202210164219.X), which realizes bidirectional access authentication between onboard business systems and ground authentication systems, thereby reducing the management complexity of onboard business systems. Zhu Li et al. proposed a trusted collaborative computing system for intelligent rail transit (application number: 202210456734.5), which includes onboard equipment, edge devices, cloud center equipment, and a blockchain system. This system solves the computing power dilemma caused by trust issues in the development of intelligent rail transit. Xu Yanfen et al. proposed an in-vehicle network security architecture and implementation method (application number: 202010299143.2). This architecture includes an in-vehicle security unit, a first train communication local area network (LAN), and a second train communication LAN. Using this architecture, data verified by the security unit can be transmitted between networks. Zheng Qiang et al. proposed an in-vehicle network security protection system and its application method (application number: 202110549799.X). This system includes a security engine module, an application programming interface (API) module, an authentication and authorization module, a secure communication module, a data encryption module, an attack protection module, an intrusion detection module, and a log system module. It is an in-vehicle network information security protection system for intelligent connected vehicles. Xu Chen proposed a train-mounted network security system and method based on quantum communication (application number: 202111442327.0). The system includes a communication network service station, a communication network, and carriage communication terminals. Each carriage is equipped with a communication network service station and several carriage communication terminals. The communication network service stations are interconnected through the communication network and establish data connections, which effectively improves data communication efficiency and reduces data packet loss rate.
[0007] Some of the aforementioned technical solutions belong to the field of general computer network information security technology, targeting host computer networks. Their information security protection for host computers mostly only provides trusted connection solutions for terminal network access. However, these information security protection technologies for general networks are not applicable to the information security protection of rail vehicle-mounted networks in specific scenarios. Other technical solutions belong to the field of vehicular network information security technology, but these information security protections for vehicular networks mostly lack proactive protection capabilities. Similarly, they are not applicable to node device identity authentication, trusted authentication between node devices, and trusted authentication between networks in the specific scenarios of rail vehicle-mounted networks. Furthermore, in traditional trusted computing network architectures, every time the host computing environment changes, a complete security scan must be performed again, and measurement data must be recalculated and stored, leading to increased computational load and reduced network real-time performance. Summary of the Invention
[0008] To address the aforementioned problems in existing technologies, this invention provides a lightweight onboard trusted network system for rail vehicles based on active safety. Through network node device access authentication mechanisms, inter-subnet trusted authentication, and inter-device command interaction authentication, it achieves active safety functions for the onboard network. This system can meet the real-time requirements of train networks and ensure the security of the onboard network system without the need for external defense tools, thereby improving the network's active safety immunity.
[0009] To achieve the above objectives, the present invention provides a lightweight onboard trusted network system for rail vehicles, comprising a vehicle-to-ground wireless communication boundary domain, an onboard network domain, an onboard network node device domain, and an onboard trusted platform. The onboard trusted platform is embedded in each of the vehicle-to-ground wireless communication boundary domain, the onboard network domain, and the onboard network node device domain, and is used for onboard network authentication through identity authentication node devices, trusted communication authentication between different levels of subnets, and communication authentication between onboard network node devices.
[0010] Preferably, the vehicle-mounted trusted platform actively measures the trusted network system environment during the operation of the trusted network system, realizes the basic trusted environment of the vehicle-mounted trusted platform, and signs the measurement result report to identify the current trusted state of the vehicle-mounted trusted platform environment, thereby realizing the identification and trusted verification of the identities of the two communicating parties.
[0011] Preferably, the trusted in-vehicle platform includes:
[0012] The trusted cryptography module is used for identity authentication and inter-subnet authentication of vehicle network node devices, as well as the measurement, updating, and revocation of trust attributes between vehicle network node devices and maintenance terminal devices.
[0013] The trusted software base module is embedded in the operating system kernel of the vehicle network node device. It is used to implant measurement code in the operating system bootloader of the vehicle network node device, perform backtracking measurement on the integrity of the operating system boot program code under the CPU real mode drive, and complete the interception and policy management of vehicle network behavior.
[0014] The Trusted Service module centrally manages the trusted status, verifies and signs the trusted status reports reported by the vehicle network node devices, and authenticates and periodically synchronizes the currently maintained trusted status with the heartbeat packets of each vehicle network node device.
[0015] The trusted cryptography module includes:
[0016] A root of trust serves as the basis of trust in a trusted network system.
[0017] A domestically developed cryptographic algorithm engine is used to generate authentication keys, encrypt and decrypt data and instructions, sign node device status feature values and identity verification private keys, and calculate integrity metrics.
[0018] A random number generator is used to generate random numbers.
[0019] The storage module stores the node device status characteristics and the identity verification private key.
[0020] Preferably, the trusted authentication process for node devices in the vehicular network node device domain to access the vehicular network is as follows: Before accessing the vehicular network, the vehicular network node device needs to determine its trusted status according to the trusted device status list, and then decide whether to allow access; when the vehicular network node device accesses, the request command triggers an integrity verification handshake message, and the trusted service module submits a network access request after receiving the message; the trusted software base module obtains this access request through a hook function and notifies the trusted service module of the unique identifier ComID information of the vehicular network, and the trusted service module determines the trusted status of the corresponding system in the vehicle-to-ground wireless communication boundary domain; the trusted cryptographic module completes the authentication of the network access requester, then calculates the integrity metric value, and passes its authentication policy to the policy execution point to determine the open port of the policy execution point; if the trusted status of the corresponding system in the vehicle-to-ground wireless communication boundary domain meets the conditions, then connection to the vehicular network is allowed.
[0021] Preferably, the trusted communication authentication process between subnets of different levels is as follows: The first subnet periodically obtains the trusted status of all node devices in the vehicle network from the trusted service module and periodically reports the trusted status of the first subnet; the second subnet periodically obtains the trusted status of all node devices in the vehicle network from the trusted service module and periodically reports the trusted status of the second subnet; when the first subnet communicates with the second subnet, the first subnet queries the trusted status of the second subnet from its trusted status database, and the second subnet queries the trusted status of the first subnet from its trusted status database. Only after the first subnet completes the trusted status authentication with the second subnet can it initiate communication with the second subnet, and only after the second subnet completes the trusted status authentication with the first subnet can it initiate communication with the first subnet, thereby realizing trusted communication between subnets of different levels.
[0022] Preferably, the communication process between vehicle network node devices, i.e., the instruction-level reliable transmission authentication process, is as follows: Both vehicle network node devices send authentication requests. The trusted service module returns a random number for the authentication request. Upon receiving the response random number, the vehicle network node device calls the trusted cryptographic module to obtain the hash feature value of the random number. The trusted cryptographic module interacts with this information to obtain the required feature value and the corresponding measurement log. It signs the stored device status feature value with the identity verification private key to obtain the information identity authentication key. Both communicating parties decrypt the obtained ciphertext information to obtain the identity authentication key certificate. They then compare the identity authentication key certificate with the registered information to verify the identity authentication key certificate. After successful verification, they use the identity authentication key to verify the signature information to obtain the device status feature value and random number stored in the trusted cryptographic module. They verify whether it is consistent with the previously sent value. If they are consistent, they perform a hash operation on the trusted measurement log information and compare the resulting value with the device status feature value stored in the trusted cryptographic module. If the results are the same, the authentication is successful, and the two vehicle network node devices can then communicate.
[0023] Preferably, the trusted cryptographic module uses ComID based on the TRDP protocol as the unique identifier of the node device data structure for identity authentication. ComID, source IP address and destination IP address are combined to form a unique identifier for vehicle network communication for inter-network communication authentication. Process data uses the UDP protocol and the destination communication port is fixed at 17224. Message data uses the UDP or TCP protocol and the destination port is fixed at 17225.
[0024] Preferably, the root of trust is used to verify all additional software loaded on the trusted network system. The root of trust is hardware-based and immutable, and cannot be tampered with.
[0025] Furthermore, during the operation of the trusted network system, all vehicle-mounted network node devices periodically report their own trusted status, while also updating the trusted status of all terminals in the network from the security management platform. When the status of one of the communicating parties changes, emergency measures are taken.
[0026] Preferably, the vehicle-to-ground wireless communication boundary domain includes the vehicle-to-ground wireless communication control system, data exchange system, and 4G / 5G wireless communication system; the on-board network domain includes the ETB train backbone network system and the ECN train formation network system; the on-board network node equipment domain mainly includes the bogie system, motor system, electric drive system, braking system, air conditioning system, door control system, high voltage system, train control system, entertainment system, monitoring system, and auxiliary systems.
[0027] Compared with the prior art, the advantages and positive effects of the present invention are as follows:
[0028] (1) The vehicle-mounted trusted network system of the present invention constructs a vehicle-mounted network communication trusted mechanism based on active security. Through access authentication mechanism, trusted authentication between subnets, and instruction interaction authentication between devices, the active security function of the vehicle-mounted network is realized. It can not only meet the real-time requirements of the train network, but also combine trusted computing technology with vehicle-mounted network access control. It formulates trusted network security policies in close combination with business scenarios. Only node devices that meet the policies can access the network, which isolates terminals that may cause malicious attacks from the network, greatly reduces security risks, and improves the intrinsic security active immunity capability of the rail vehicle vehicle-mounted network.
[0029] (2) The vehicle-mounted trusted network system of the present invention takes into account the characteristics of its own network environment, application environment and physical environment of the vehicle-mounted network system based on real-time industrial Ethernet, and combines the service characteristics of the vehicle-mounted network system node devices to carry out a lightweight design. Through centralized management of trusted status, the trusted status reports reported by the vehicle-mounted network node devices are verified and signed, and the trusted status is authenticated with the heartbeat packets of each node device and synchronized with the currently maintained trusted status on a regular basis, thereby improving the real-time performance of the network.
[0030] (3) The vehicle-mounted trusted network system of the present invention clearly defines the identity and status authentication between the vehicle-mounted network node device and the trusted third-party manager, which is more secure and more suitable for vehicle-mounted network scenarios.
[0031] (4) The in-vehicle trusted network system of the present invention does not require modification of business programs, logic, and system resources, avoiding large-scale transformation of the existing business system, which is conducive to the implementation of the technology and engineering applications. Compared with the currently common trusted computing technology implementation methods, the in-vehicle network trusted computing platform pushes the starting point of measurement from the operating system to the operating system bootloader, thereby significantly improving system security. Attached Figure Description
[0032] Figure 1 This is a structural block diagram of the lightweight on-board network system for rail vehicles based on active safety, as described in an embodiment of the present invention.
[0033] Figure 2 This is a flowchart illustrating the authentication process for accessing the vehicle network in a lightweight onboard network system for rail vehicles based on active safety, as described in an embodiment of the present invention.
[0034] Figure 3 This is a flowchart illustrating the trusted communication authentication process between different levels of subnets in the lightweight onboard network system for rail vehicles based on active safety, as described in an embodiment of the present invention.
[0035] Figure 4 This is a flowchart illustrating the communication authentication process between onboard network node devices in the lightweight onboard network system for rail vehicles based on active safety, as described in an embodiment of the present invention.
[0036] Figure 5 This is a schematic diagram of the trusted transmission process of the lightweight on-board network system for rail vehicles based on active safety, as described in an embodiment of the present invention.
[0037] Figure 6 This is a schematic diagram illustrating the interface call method of the lightweight on-board network system module for rail vehicles based on active safety, as described in an embodiment of the present invention. Detailed Implementation
[0038] The present invention will now be described in detail through exemplary embodiments. However, it should be understood that, without further description, elements, structures, and features in one embodiment may be advantageously incorporated into other embodiments.
[0039] See Figure 1 This invention provides a lightweight onboard trusted network system for rail vehicles based on active safety. The system includes a vehicle-to-ground wireless communication boundary domain, an onboard network domain, an onboard network node device domain, and an onboard trusted platform. The onboard trusted platform is embedded in each of these domains and is used for onboard network authentication via identity authentication node devices, trusted communication authentication between different levels of subnets, and communication authentication between onboard network node devices. Specifically, the vehicle-to-ground wireless communication boundary domain includes a vehicle-to-ground wireless communication control system, a data exchange system, and a 4G / 5G wireless communication system; the onboard network domain includes an ETB train backbone network system and an ECN train formation network system; and the onboard network node device domain mainly includes a bogie system, a motor system, an electric drive system, a braking system, an air conditioning system, a door control system, a high-voltage system, a train control system, an entertainment system, a monitoring system, and auxiliary systems. During the operation of the trusted network system, the vehicle-mounted trusted platform actively measures the trusted network system environment to realize the basic trusted environment of the vehicle-mounted trusted platform. It also signs the measurement result report to identify the current trusted state of the vehicle-mounted trusted platform environment, thereby realizing the identification and trusted verification of the identities of the two communicating parties.
[0040] In the vehicle network system described in this embodiment of the invention, the vehicle trusted platform is embedded on the motherboard of each system, establishing a foundation of trust at the bottom layer of each system. The trust relationship of the vehicle trusted platform is transmitted from the root of trust to the motherboard and BIOS layers, and finally to the operating network layer, thereby ensuring the security of each system from multiple levels.
[0041] Specifically, in one embodiment of the present invention, the vehicle-mounted trusted platform includes:
[0042] The trusted cryptography module is used for identity authentication and inter-subnet authentication of vehicle network node devices, as well as the measurement, updating, and revocation of trust attributes between vehicle network node devices and maintenance terminal devices.
[0043] The trusted software base module is embedded in the operating system kernel of the vehicle network node device. It is used to implant measurement code in the operating system bootloader of the vehicle network node device, perform backtracking measurement on the integrity of the operating system boot program code under the CPU real mode drive, and complete the interception and policy management of vehicle network behavior.
[0044] The Trusted Service module centrally manages the trusted status, verifies and signs the trusted status reports reported by the vehicle network node devices, and authenticates the heartbeat packets of each vehicle network node device and periodically synchronizes the currently maintained trusted status.
[0045] The trusted cryptography module includes:
[0046] A root of trust serves as the basis of trust in a trusted network system.
[0047] A domestically developed cryptographic algorithm engine is used to generate authentication keys, encrypt and decrypt data and instructions, sign node device status feature values and identity verification private keys, and calculate integrity metrics.
[0048] A random number generator is used to generate random numbers.
[0049] The storage module stores the node device status characteristics and the identity verification private key.
[0050] Specifically, domestically developed cryptographic algorithm engines include:
[0051] SM2 engine: generates SM2 key pairs and performs SM2 encryption / decryption and signature operations;
[0052] SM3 engine: performs hash operations;
[0053] SM4 engine: Performs SMS4 symmetric cryptographic operations;
[0054] HMAC Engine: Calculates message authentication codes based on the SM3 engine.
[0055] The SM2 engine involves cryptographic algorithms including system parameters, key pair generation, digital signature algorithms, key exchange protocols, and encryption algorithms, all based on elliptic curve cryptography. The digital signature algorithm verifies message integrity by generating a digital signature on the node device status characteristic value and the identity verification private key stored in the storage module, enabling verification of the integrity of these two values at any later time. The key exchange protocol establishes a shared secret key through negotiation between two users, determining its value. The encryption algorithm involves the sender encrypting the information into ciphertext using the receiver's public key; conversely, the receiver decrypts the received ciphertext using their private key to restore the original information.
[0056] The SM3 engine uses a cryptographic hash algorithm. For a given message length, the cryptographic hash algorithm generates a hash value through padding, iterative compression, and pruning. It should be noted that the hash value generated by the cryptographic hash algorithm is the integrity measure value.
[0057] The SM4 engine uses symmetric cryptography algorithms, which are block ciphers. They consist of encryption and decryption algorithms with identical structures, but the round keys are used in reverse order. The decryption round key is the reverse of the encryption round key.
[0058] The HMAC engine uses a message verification code algorithm, which generates a message verification code of length t bytes for a given message and the secret information shared by both parties.
[0059] In one specific implementation, the trusted cryptographic module uses ComID based on the TRDP protocol as the unique identifier of the node device data structure for identity authentication. ComID, source IP address and destination IP address are combined to form a unique identifier for vehicle network communication and to perform inter-network communication authentication. Process data uses the UDP protocol and the destination communication port is fixed at 17224. Message data uses the UDP or TCP protocol and the destination port is fixed at 17225.
[0060] Specifically, the root of trust is used to verify all additional software loaded on a trusted network system. The root of trust is hardware-based and immutable, and cannot be tampered with.
[0061] In one specific implementation, see Figure 2 The trusted authentication process for node devices in the vehicular network node device domain to access the vehicular network is as follows: Before accessing the vehicular network, the vehicular network node device needs to determine its trusted status according to the trusted device status list before deciding whether to allow access; when the vehicular network node device accesses, the request command triggers an integrity audit handshake message, and the trusted service module submits a network access request after receiving the message; the trusted software base module obtains this access request through a hook function and notifies the trusted service module of the unique identifier ComID information of the vehicular network; the trusted service module determines the trusted status of the corresponding system in the vehicle-to-ground wireless communication boundary domain; the trusted cryptographic module completes the authentication of the network access requester, then calculates the integrity metric value, and passes its authentication policy to the policy execution point to determine the open port of the policy execution point; if the trusted status of the corresponding system in the vehicle-to-ground wireless communication boundary domain meets the conditions, then connection to the vehicular network is allowed.
[0062] Specifically, taking the Central Control Unit (CCU) and the Vehicle-to-Ground Wireless Communication Device (WTD) as an example: Before accessing the vehicle network, the vehicle network node device needs to determine its trust status based on the trusted device status list before deciding whether to allow access. When the vehicle network node device accesses the network, the request command triggers an integrity verification handshake message. After receiving the message, the trusted service module submits a network access request. The trusted software base module obtains this access request through a hook function and notifies the trusted service module of the vehicle network's unique identifier, ComID. The trusted service module determines the trust status of the vehicle WTD. The trusted cryptographic module completes the authentication of the network access requester, then calculates the integrity metric and passes its authentication policy to the policy execution point to determine the open port of the policy execution point. If the trust status of the vehicle WTD meets the conditions, it is allowed to connect to the vehicle network.
[0063] In a specific real-time mode, see Figure 3 The trusted communication authentication between different levels of subnets is the trusted connection authentication process between the vehicle control network, the passenger information system network, and the operation and maintenance network: The first subnet periodically obtains the trusted status of all node devices in the vehicle network from the trusted service module and periodically reports the trusted status of the first subnet; the second subnet periodically obtains the trusted status of all node devices in the vehicle network from the trusted service module and periodically reports the trusted status of the second subnet; when the first subnet communicates with the second subnet, the first subnet queries the trusted status of the second subnet from its trusted status database, and the second subnet queries the trusted status of the first subnet from its trusted status database. Only after the first subnet completes the trusted status authentication with the second subnet can it initiate communication with the second subnet, and only after the second subnet completes the trusted status authentication with the first subnet can it initiate communication with the first subnet, thereby realizing trusted communication between different levels of subnets.
[0064] Specifically, taking the communication between the vehicle control network subnet VN1 and the passenger information system network subnet VN2 as an example, the vehicle control network subnet VN1 periodically obtains the trusted status of all node devices in the vehicle network from the trusted service module of the on-board CCU, and periodically reports the trusted status of the vehicle control network subnet VN1; similarly, the passenger information system network subnet VN2 periodically obtains the trusted status of all node devices in the vehicle network from the trusted service module of the on-board CCU, and periodically reports the trusted status of its own passenger information system network subnet VN2; when the vehicle control network subnet VN1 and the passenger information system network subnet VN2 communicate, the vehicle control network... Subnet VN1 queries the trusted state of passenger information system network subnet VN2 from its trusted state database, while passenger information system network subnet VN2 queries the trusted state of vehicle control network subnet VN1 from its trusted state database. Only after completing trusted state authentication with passenger information system network subnet VN2 can vehicle control network subnet VN1 initiate communication with passenger information system network subnet VN2. Similarly, passenger information system network subnet VN2 can only initiate communication with vehicle control network subnet VN1 after completing trusted state authentication with vehicle control network subnet VN1, thereby realizing trusted communication between two subnets of different levels.
[0065] In one specific implementation, see Figure 4 The communication process between vehicular network node devices, i.e., the instruction-level reliable transmission authentication process, is as follows: Both vehicular network node devices send authentication requests. The trusted service module returns a random number for the authentication request. Upon receiving the response random number, the vehicular network node device calls the trusted cryptographic module to obtain the hash feature value of the random number. The trusted cryptographic module interacts with this information to obtain the required feature value and the corresponding measurement log. It signs the stored device status feature value with the identity verification private key to obtain the information identity authentication key. Both communicating parties decrypt the obtained ciphertext information to obtain the identity authentication key certificate. They then compare the identity authentication key certificate with the registered information to verify the identity authentication key certificate. After successful verification, they use the identity authentication key to verify the signature information to obtain the device status feature value and random number stored in the trusted cryptographic module. They verify whether it is consistent with the previously sent value. If they are consistent, they perform a hash operation on the trusted measurement log information and compare the resulting value with the device status feature value stored in the trusted cryptographic module. If the results are the same, the authentication is successful, and the two vehicular network node devices can then communicate.
[0066] Specifically, during the operation of the trusted network system, all vehicle-mounted network nodes periodically report their own trusted status and simultaneously update the trusted status of all terminals in the network from the security management platform. When the status of either party in the communication changes, emergency measures are taken. There are various emergency measures, such as: linking with the protection policies in the network system to control the sending and receiving of terminal data packets; or directly interrupting the execution of illegal programs through the trusted software base module.
[0067] See Figure 5 The trusted transmission process of the lightweight onboard trusted network system for rail vehicles described in this invention is as follows: The onboard network trusted transmission process utilizes cryptographic algorithms to establish a trust chain. Starting from the root of trust, system control is sequentially transferred from the trusted BIOS to the trusted operating system loader, from the trusted operating system loader to the trusted operating system, and then from the trusted operating system to the trusted application, thereby transferring trust from the local domain to the network domain. Upper layers can only operate normally after acquiring the trust of the lower layers. The root of trust determines whether the authenticity and integrity of its next-level executable code have been tampered with. If not, the system transfers operational control to the next-level trusted executable code, expanding the system's trusted scope from the root of trust to the next level of functionality. Similarly, this continuous transfer of system operational code control enables the establishment and transmission of the trust chain, ultimately extending the system's trusted scope. If tampering occurs, the system is passed to the security policy controller for judgment and the implementation of corresponding security rules. Access control is executed based on the generated and received access policies, thereby achieving a trusted connection.
[0068] See Figure 6 The interface calling methods for the trusted network system module are as follows: When a trusted application accesses the underlying trusted hardware, a dynamic link library is used between the application and the trusted service provider layer. The trusted service provider layer communicates with the trusted computing core service using local or remote procedure calls, and space is automatically allocated according to the interface description language definition. The interface between the trusted computing core service and the device driver library also uses a dynamic link library calling method. The interface between the driver library and the device driver uses the standard interface for accessing driver programs under the operating system.
[0069] The lightweight onboard trusted network system for rail vehicles described in this invention embodiment, based on proactive safety, considers the characteristics of the onboard network system's own network environment, application environment, and physical environment based on real-time industrial Ethernet. It can achieve trusted terminal network access (i.e., trusted authentication for node devices accessing the onboard network), trusted inter-network communication connection (i.e., trusted connection authentication between the vehicle control network, passenger information system network, and operation and maintenance network), and reliable transmission authentication for communication between onboard network node devices (i.e., instruction-level reliable transmission). It establishes a secure and trusted system with trusted onboard network access devices, trusted communication between network devices, trusted operational behavior, trusted data storage, and trusted policy management, comprehensively improving the proactive safety immunity capability of the onboard network system.
[0070] The above embodiments are used to explain the present invention, but not to limit the present invention. Any modifications and changes made to the present invention within the spirit and scope of the claims shall fall within the protection scope of the present invention.
Claims
1. A lightweight onboard trusted network system for rail vehicles based on active safety, characterized in that, It includes a vehicle-to-ground wireless communication boundary domain, a vehicle network domain, a vehicle network node device domain, and a vehicle trusted platform. The vehicle trusted platform is embedded in each system of the vehicle-to-ground wireless communication boundary domain, the vehicle network domain, and the vehicle network node device domain, and is used for accessing the vehicle network authentication through identity authentication node devices, trusted communication authentication between different levels of subnets, and communication authentication between vehicle network node devices. In-vehicle trusted platforms include: The trusted cryptography module is used for identity authentication and inter-subnet authentication of vehicle network node devices, as well as the measurement, updating, and revocation of trust attributes between vehicle network node devices and maintenance terminal devices. The trusted software base module is embedded in the operating system kernel of the vehicle network node device. It is used to implant measurement code in the operating system bootloader of the vehicle network node device, perform backtracking measurement on the integrity of the operating system boot program code under the CPU real mode drive, and complete the interception and policy management of vehicle network behavior. The Trusted Service module centrally manages the trusted status, verifies and signs the trusted status reports reported by the vehicle network node devices, and authenticates the heartbeat packets of each vehicle network node device and periodically synchronizes the currently maintained trusted status.
2. The lightweight onboard trusted network system for rail vehicles based on active safety as described in claim 1, characterized in that, During the operation of the trusted network system, the vehicle-mounted trusted platform actively measures the trusted network system environment to realize the basic trusted environment of the vehicle-mounted trusted platform. It also signs the measurement result report to identify the current trusted state of the vehicle-mounted trusted platform environment, thereby realizing the identification and trusted verification of the identities of the two communicating parties.
3. The lightweight onboard trusted network system for rail vehicles based on active safety as described in claim 1 or 2, characterized in that, The trusted cryptographic module includes: A root of trust serves as the basis of trust in a trusted network system. A domestically developed cryptographic algorithm engine is used to generate authentication keys, encrypt and decrypt data and instructions, sign node device status feature values and identity verification private keys, and calculate integrity metrics. A random number generator is used to generate random numbers. The storage module stores the node device status characteristics and the identity verification private key.
4. The lightweight onboard trusted network system for rail vehicles based on active safety as described in claim 3, characterized in that, The trusted authentication process for node devices in the vehicular network node device domain to access the vehicular network is as follows: Before accessing the vehicular network, the vehicular network node device needs to determine its trusted status according to the trusted device status list, and then decide whether to allow access. When a vehicle-mounted network node device connects, the request command triggers an integrity verification handshake message. After receiving the message, the trusted service module submits a network access request. The trusted software base module obtains this access request through the hook function and notifies the trusted service module of the unique identifier ComID of the vehicle network. The trusted service module then determines the trusted status of the corresponding system in the vehicle-to-ground wireless communication boundary domain. The trusted cryptographic module completes the authentication of the network access requester, then calculates the integrity metric value, and passes its authentication policy to the policy enforcement point to determine the open port of the policy enforcement point; if the trusted state of the corresponding system in the vehicle-to-ground wireless communication boundary domain meets the conditions, then connection to the vehicle network is allowed.
5. The lightweight onboard trusted network system for rail vehicles based on active safety as described in claim 3, characterized in that, Trusted communication authentication process between different subnets: The first subnet periodically obtains the trusted status of all node devices in the vehicle network from the trusted service module and periodically reports the trusted status of the first subnet; the second subnet periodically obtains the trusted status of all node devices in the vehicle network from the trusted service module and periodically reports the trusted status of the second subnet; when the first subnet communicates with the second subnet, the first subnet queries the trusted status of the second subnet from its trusted status database, and the second subnet queries the trusted status of the first subnet from its trusted status database. Only after the first subnet completes trusted status authentication with the second subnet can it initiate communication with the second subnet, and only after the second subnet completes trusted status authentication with the first subnet can it initiate communication with the first subnet, thereby realizing trusted communication between subnets of different levels.
6. The lightweight onboard trusted network system for rail vehicles based on active safety as described in claim 3, characterized in that, The communication process between vehicular network node devices, i.e., the instruction-level reliable transmission authentication process, is as follows: Both vehicular network node devices send authentication requests. The trusted service module returns a random number for the authentication request. Upon receiving the response random number, the vehicular network node device calls the trusted cryptographic module to obtain the hash feature value of the random number. The trusted cryptographic module interacts with this information to obtain the required feature value and corresponding measurement log. It signs the stored device status feature value with the identity verification private key to obtain the information identity authentication key. Both communicating parties decrypt the obtained ciphertext information to obtain the identity authentication key certificate. They then compare the identity authentication key certificate with the registered information to verify the identity authentication key certificate. After successful verification, they use the identity authentication key to verify the signature information to obtain the device status feature value and random number stored in the trusted cryptographic module. They verify whether it is consistent with the previously sent value. If they are consistent, they perform a hash operation on the trusted measurement log information and compare the resulting value with the device status feature value stored in the trusted cryptographic module. If the results are the same, the authentication is successful, and the two vehicular network node devices can then communicate.
7. The lightweight onboard trusted network system for rail vehicles based on active safety as described in claim 3, characterized in that, The trusted cryptography module uses ComID based on the TRDP protocol as the unique identifier of the node device data structure for identity authentication. ComID, source IP address and destination IP address are combined to form a unique identifier for vehicle network communication and to perform inter-network communication authentication. Process data uses the UDP protocol and the destination communication port is fixed at 17224. Message data uses the UDP or TCP protocol and the destination port is fixed at 17225.
8. The lightweight onboard trusted network system for rail vehicles based on active safety as described in claim 3, characterized in that, The root of trust is used to verify all additional software loaded on a trusted network system. The root of trust is hardware-based and immutable, and cannot be tampered with.
9. The lightweight onboard trusted network system for rail vehicles based on active safety as described in claim 1, characterized in that, During the operation of the trusted network system, all vehicle-mounted network node devices periodically report their own trusted status and also update the trusted status of all terminals in the network from the security management platform. When the status of one of the communicating parties changes, emergency measures are taken.
10. The lightweight onboard trusted network system for rail vehicles based on active safety as described in claim 1, characterized in that, The vehicle-to-ground wireless communication boundary domain includes the vehicle-to-ground wireless communication control system, data exchange system, and 4G / 5G wireless communication system; the on-board network domain includes the ETB train backbone network system and the ECN train formation network system; the on-board network node equipment domain mainly includes the bogie system, motor system, electric drive system, braking system, air conditioning system, door control system, high voltage system, train control system, entertainment system, monitoring system, and auxiliary systems.