Railway vehicle on-board network secure communication method and railway vehicle

By using the software-defined boundary method, the network boundary is dynamically constructed using the onboard SDP control unit and gateway, which solves the problems of internal attacks and strong dependence on encryption algorithms in the existing onboard network security architecture of rail vehicles. This achieves network asset concealment and security, dynamically controls access permissions, and resists various network threats.

CN116489656BActive Publication Date: 2025-11-07NAT HIGH SPEED TRAIN QINGDAO TECH INNOVATION CENT
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310392424.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-13
Publication Date
2025-11-07
Estimated Expiration
2043-04-13

AI Technical Summary

Technical Problem

Existing onboard network security architectures for rail vehicles rely on network perimeter protection, which cannot effectively prevent internal attacks. Furthermore, their strong dependence on encryption algorithms affects real-time communication and makes them unsuitable for the security requirements of borderless network architectures.

Method used

By adopting the software-defined boundary approach, dynamic boundaries are realized through the vehicle-mounted SDP control unit and gateway. Based on authentication and authorization services, single-packet authorization authentication and two-way TLS encryption are used to dynamically build and reconstruct network boundaries, hide network resources, and achieve data confidentiality and integrity.

Benefits of technology

It achieves the concealment of in-vehicle network assets, prevents unauthorized access, dynamically controls access permissions, resists DDoS and man-in-the-middle attacks, and improves the security and real-time communication of the network system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116489656B_ABST
    Figure CN116489656B_ABST
Patent Text Reader

Abstract

The application relates to a rail vehicle on-board network secure communication method and a rail vehicle, wherein the method comprises the following steps: deploying and activating an on-board SDP control unit and an on-board SDP gateway in an on-board network; after deploying an SDP client component to a communication network node device of the on-board network and activating the SDP client component, the SDP client component is connected to the on-board SDP control unit to request authorization; after the SDP client component performs single packet authorization authentication on the authorized on-board SDP gateway and establishes encrypted communication, the node device communicates with the on-board network through the SDP client component and the on-board SDP gateway and executes control instructions of the rail vehicle. Based on software-defined deployment of a dynamic boundary of the on-board network, network and resources are hidden, unauthorized node devices are prevented from accessing, and data confidentiality and integrity of the whole process of on-board application interaction are realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of rail vehicle safety communication, in particular to a rail vehicle onboard network safety communication method based on software-defined boundary and a rail vehicle. BACKGROUND

[0002] The current rail vehicle onboard network protection system is a security architecture based on boundary protection and internal supervision and auditing. According to the physical position of the equipment in the network, the onboard network is divided into internal network and train-ground wireless communication network and other different areas. The internal and external networks are separated by a boundary. Firewalls are deployed at the network boundary, security audits are arranged at the internal core switch, corresponding strategies are configured, and a boundary security protection system is constructed.

[0003] For example, Chinese patent CN213213516U, the communication in this document is controlled by the router in the three-layer switch included in the switch and the firewall. The internal network and the external network are separated by a firewall as a network boundary. However, the security protection system based on the network boundary is not strict enough in terms of internal access security supervision. Once the attacker breaks through the protection boundary and enters the internal network, the original network security protection measure will fail, thus providing a clear attack target for the attacker. For example, Chinese patent CN115484085A discloses a network security control method for a motor train unit. The network security is improved by assigning public keys and private keys to onboard devices. However, the security of this method relies too much on the encryption algorithm. Once the encryption algorithm is broken, the network communication will no longer be secure, and the overhead of the encryption algorithm will affect the real-time performance of the train network communication.

[0004] In addition, with the application of new technologies such as automatic driving, artificial intelligence, and Internet of Things in the field of rail transportation, the onboard network system architecture is changing from "boundary" to "boundaryless". The traditional firewall-based boundary security passive defense technology cannot meet the security requirements of industrial control networks in special application scenarios.

[0005] At present, there is no effective solution to the boundary security protection needs of the new onboard network system architecture in the related art. SUMMARY

[0006] The embodiments of the present application provide a rail vehicle onboard network safety communication method based on software-defined boundary and a rail vehicle. The onboard network dynamic boundary is deployed based on software definition on demand, the network and resources are hidden, an identity-centered strategy model is adopted to prevent unauthorized node devices from accessing, and the data confidentiality and integrity of the entire process of onboard application interaction are realized.

[0007] In a first aspect, the embodiments of the present application provide a rail vehicle onboard network safety communication method, comprising:

[0008] a software-defined boundary construction step, deploying and activating a vehicle SDP control unit and a vehicle SDP gateway in the vehicle network, the vehicle SDP control unit starting an identity authentication and authorization service, and the vehicle SDP gateway connecting the vehicle SDP control unit in a secure manner; wherein the vehicle SDP gateway does not respond to communications from any other host (including the initiating host and the accepting host, i.e., the SDP client component and the vehicle SDP gateway) before authentication, nor does it respond to any unauthorized requests.

[0009] a node device onboarding step, deploying an SDP client component to a communication network node device of the vehicle network and activating the SDP client component, adding each initiating communication network node device to the SDP, the SDP client component connecting the vehicle SDP control unit to request authorization, and the vehicle SDP control unit outputting a gateway list and a permission list of the SDP client component after authentication;

[0010] a node device communication establishment step, after the SDP client component performs single-packet authorization authentication to the authorized vehicle SDP gateway according to the gateway list and the permission list and establishes encrypted communication, the node device communicates with the vehicle network through the SDP client component and the vehicle SDP gateway and executes control instructions of the rail vehicle;

[0011] wherein the gateway list and the permission list of the SDP client component are dynamically generated based on the rail vehicle control instructions to perform on-demand construction and dynamic reconstruction of the network boundary.

[0012] Based on this, the vehicle SDP gateway is used to divide the network virtual boundary, all business resources connected and controlled by the vehicle SDP gateway do not expose services or ports to the outside, only devices that have been verified and authorized can access the invisible SDP network resources, and the range of devices that can be accessed is dynamically developed and recycled based on control instructions, there are no fixed or permanent authorized node devices, and there are no fixed attack objects.

[0013] In some embodiments, the vehicle SDP control unit and the vehicle SDP gateway are connected to a vehicle-level Ethernet switch ECNN, and the node devices in the rail vehicle carriages communicate with the vehicle-level Ethernet through the SDP client component, the vehicle SDP control unit, and the vehicle SDP gateway in a hidden manner.

[0014] In some embodiments, in the software-defined boundary construction step, the vehicle SDP control unit and the vehicle SDP gateway are distributedly deployed,

[0015] the number of vehicle SDP gateways N Gconfigured: 2≤N G ≤ the number of rail vehicle carriages;

[0016] the number N of on-board SDP control units C configured: 2≤N C ≤ the number of rail vehicle carriages.

[0017] In some embodiments, the method further comprises:

[0018] The node device communication disestablishment step, when the single packet authorization authentication initiated by the SDP client component in the node device communication establishment step fails, the node device communication is completed, or the rail vehicle marshalling is reconnected, the on-board SDP control unit resets the gateway list, the permission list, and reconfigures the network boundary.

[0019] In some embodiments, the node device network access step further comprises:

[0020] The node device deployment step deploys the SDP client component to the node device, which is in communication connection with the on-board SDP control unit and sends authentication information to the on-board SDP control unit for identity verification;

[0021] The authorization list acquisition step, after identity verification, the on-board SDP control unit parses the control instructions of the rail vehicle to determine the gateway list and the permission list that the SDP client component needs to be authorized, and sends them to the SDP client component;

[0022] The covert communication pre-starting step, the on-board SDP control unit instructs the on-board SDP gateway in the gateway list to accept communication, and starts the control strategy required for encrypted communication.

[0023] In some embodiments, the node device communication establishment step further comprises:

[0024] The covert communication initiation step, the SDP client component of the node device initiates single packet authorization (SPA) to the authorized on-board SDP gateway according to the gateway list, creates a two-way encrypted communication after the authentication is passed, and the unauthorized on-board SDP gateway cannot perceive or access, to achieve covert communication; that is, the first data packet sent by the SDP client component of any node device to the on-board SDP control unit must be an authentication packet, and if other data packets are received, the device communication is disconnected for illegal connection. The two-way encrypted communication is a two-way TLS authentication. By using two-way TLS authentication and encryption technology, it can resist DDoS, man-in-the-middle attacks, supply chain attacks, and advanced persistent threats (APT) and zero-day vulnerability protection, etc., and achieve more fine-grained security control.

[0025] A control channel establishment step, the vehicle-mounted SDP control unit informs the vehicle-mounted SDP gateway of an SDP client component initiating a single package authorization authentication and its corresponding authorization policy, and establishes a control channel with the vehicle-mounted SDP gateway;

[0026] A data channel establishment step, the SDP client component acquires a vehicle-mounted SDP gateway with authority and its authorized resource control policy according to the permission list, establishes a bidirectional encrypted data channel between the SDP client component and the vehicle-mounted SDP gateway according to the resource control policy, and communicates with the vehicle-mounted network system through the vehicle-mounted SDP gateway.

[0027] Based on the above steps, the embodiment of the application realizes the separation of the control plane and the data plane, and realizes that the SDP client component of the node device can only connect to the vehicle-mounted SDP gateway and perform encrypted communication through the vehicle-mounted SDP gateway after authorization authentication. In known existing vehicle-mounted network service access processes, the client needs to first establish a network connection with the system and then perform authentication, which makes the vehicle-mounted network have to pre-develop a service port to the outside, increasing the attack risk. The embodiment separates the control plane and the data plane, and realizes network secure communication based on a single package authorization authentication mechanism.

[0028] In some embodiments, the SDP client component implements a deep trust evaluation mechanism and supports scoring the trust degree of the access node device. Specifically, the direct trust degree of the node device can be determined based on historical behavior data, the traffic trust degree can be calculated according to the traffic baseline of the access terminal and the behavior trust-based access decision agent, and the comprehensive trust degree can be calculated according to the direct trust degree and the traffic trust degree. The direct trust degree, the traffic trust degree and / or the comprehensive trust degree are configured with a trust threshold to determine whether it is abnormal information or can be accessed, and the minimum privilege required to complete a task is granted to perform business access interaction.

[0029] In some embodiments, the vehicle-mounted SDP control unit manages the authentication authorization policy and the resource control policy based on a deep learning technology. The deep learning technology is used to provide network models such as deep neural networks, convolutional neural networks, and recurrent neural networks to update the policy according to the network model, and the specific network model used by the deep learning technology is not limited in the application. The deep learning technology can dynamically discover new attack methods, allow learning from past events (such as distributed denial of service attacks DDoS, man-in-the-middle attacks, and replay attacks) to detect network anomalies, and increase the traceability of forensics.

[0030] In some embodiments, the authentication data packet of the single package authorization authentication includes device fingerprint information, application fingerprint information, and authentication format information, the authentication format information includes a request code, a user identifier, a node device identifier ComID, a random number, a timestamp, and metadata, the request code includes a port and a protocol requested by the SDP client component to access, the user identifier includes user account information and login password information, which are pre-stored in the SDP client component file, and the random number is 32 bytes to avoid replay attacks. The device fingerprint is part of the function used in the SPA authentication data packet, and is the only encryption key for the vehicle-mounted SDP control unit to verify the identity of the vehicle-mounted network node device. Metadata, also known as intermediary data or relay data, is data about data, mainly information describing data properties, and is used to support functions such as indicating storage location, historical data, resource lookup, file recording, etc.

[0031] In some embodiments, the device fingerprint information is a string formed by digitizing, combining, and hashing encrypting a plurality of feature information, and the feature information includes a node device CPU unique identifier, node device CPU characteristic information, a network adapter MAC address, operating system features, peripheral interfaces, geographic location, operating services, and connection features.

[0032] The above authentication data packet encapsulates multi-factor identity information into the packet, realizes the stealth of vehicle-mounted network service resources and trusted access of node devices. It should be noted that the first data packet sent by the SDP client component of any node device to the vehicle-mounted SDP control unit must be an authentication data packet, otherwise the node device is not allowed to communicate for illegal connection. By integrating all necessary information into a single data packet, the knocking process is simplified, and the device and user identity are verified before allowing access to the network, thereby achieving "network stealth" and making it difficult for attackers to find service addresses and ports.

[0033] In some embodiments, based on the single package authorization authentication data packet as described above, after the SDP client component sends the authentication data packet of the single package authorization authentication, the vehicle-mounted SDP gateway performs unpacking, signature verification, and other operations on the received data packet, analyzes the information in the authentication data packet and confirms its validity, judges whether the authentication is successful, and the validity depends on whether the value registered in the vehicle-mounted SDP gateway matches the received value. The authentication data packet must be encrypted and authenticated and must include all necessary information, and individual data packets are not trusted and are not allowed to tamper with the original data packet. In the case of invalid data packet, the data packet is discarded without response. If it is a valid data packet, the SDP client component is notified of the successful authentication, and the establishment of TLS encrypted secure communication is controlled.

[0034] In some embodiments, the vehicle-mounted SDP control unit and the vehicle-mounted SDP gateway are arranged in the form of a 3U circuit board card. Specifically, the vehicle-mounted SDP control unit is inserted into the backplane slot of the CCU (Central Control Unit) chassis, and the interface is in the form of CPCI; the vehicle-mounted SDP gateway card is inserted into the backplane slot of the vehicle-level Ethernet switch ECNN chassis, and the interface is also in the form of CPCI.

[0035] In a second aspect, the embodiments of the present application provide a rail vehicle arranged with an Ethernet network using the rail vehicle vehicle-mounted network security communication method according to the first aspect described above.

[0036] Compared with the related art, the rail vehicle vehicle-mounted network security communication method and the rail vehicle based on software-defined boundaries provided by the embodiments of the present application realize the hiding of vehicle-mounted network assets, so that they are not directly exposed in the network, and the network assets and facilities are protected from external security threats. The minimum permission access control is centered on identity authentication, any node device inside and outside the network is not trusted by default through network stealth technology, security level assessment and dynamic access control are continuously performed, and the vehicle-mounted network system asset security is effectively protected.

[0037] The details of one or more embodiments of the present application are presented in the following drawings and description to make other features, objects and advantages of the present application more apparent. BRIEF DESCRIPTION OF DRAWINGS

[0038] The drawings described herein are intended to provide further understanding of the present application, and constitute a part of the present application. The illustrative embodiments of the present application and their description serve to explain the present application, and do not constitute an improper limitation of the present application. In the drawings:

[0039] Figure 1 is a network topology architecture diagram of a rail vehicle vehicle-mounted network according to the prior art;

[0040] Figure 2 is a rail vehicle vehicle-mounted network security communication method flowchart according to an embodiment of the present application;

[0041] Figure 3 is another rail vehicle vehicle-mounted network security communication method flowchart according to an embodiment of the present application;

[0042] Figure 4 is a rail vehicle vehicle-mounted network security communication method step S2 flowchart according to an embodiment of the present application;

[0043] Figure 5is a flow chart of the rail vehicle on-board network secure communication method according to the embodiment of the present application;

[0044] Figure 6 is a connection diagram of the on-board SDP control unit and the on-board SDP gateway according to the embodiment of the present application;

[0045] Figure 7 is a communication architecture diagram of the rail vehicle on-board network secure communication method according to the embodiment of the present application;

[0046] Figure 8 is a diagram of the authentication and authorization process of the rail vehicle on-board network secure communication method according to the embodiment of the present application;

[0047] Figure 9 is a diagram of the covert communication principle of the rail vehicle on-board network secure communication method according to the embodiment of the present application;

[0048] Figure 10 is a diagram of the SDP dynamic authorization strategy principle of the rail vehicle on-board network secure communication method according to the embodiment of the present application;

[0049] Figure 11 is a diagram of the attack resistance process of the rail vehicle on-board network secure communication method according to the embodiment of the present application. DETAILED DESCRIPTION

[0050] In order to make the objects, technical solutions and advantages of the present application clearer, the present application is described and explained below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application. Based on the embodiments provided by the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of the present application.

[0051] Obviously, the drawings in the following description are only some examples or embodiments of the present application, and for those of ordinary skill in the art, the present application can be applied to other similar scenarios without creative labor on the basis of these drawings. In addition, it can be understood that although the efforts made in this development process can be complex and lengthy, for those of ordinary skill in the art related to the content disclosed in the present application, some design, manufacture or production changes on the basis of the technical content disclosed in the present application are only routine technical means and should not be understood as insufficient disclosure of the present application.

[0052] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that is mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments without conflict.

[0053] Unless otherwise defined, the technical or scientific terms used in this application shall have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms “a,” “an,” “an,” “the,” and similar words used in this application do not indicate quantity limitation and may indicate singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may also include steps or units not listed, or may include other steps or units inherent to these processes, methods, products, or devices. The terms “connected,” “linked,” “coupled,” and similar words used in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. “Multiple” used in this application refers to two or more. “And / or” describes the relationship between related objects, indicating that three relationships may exist; for example, “A and / or B” can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following objects are in an "or" relationship. The terms "first," "second," and "third" used in this application are merely to distinguish similar objects and do not represent a specific ordering of the objects.

[0054] The software-defined perimeter described in the present application is pointed out by the National Institute of Standards and Technology (NIST) in the Zero Trust Architecture (draft) that the zero trust architecture is an end-to-end method of network and data security, focusing on identity, credentials, access management, operations, endpoints, host environments and interconnected infrastructure. Zero trust is based on identity-based access control, and software-defined perimeter (SDP) is a form of zero trust architecture implementation. SDP enables applications to deploy security boundaries when needed to isolate network communication services from insecure networks. SDP only allows access and access to the network after device verification and identity verification, is identity-centric, targets business and data protection, and implements continuous verification, dynamic authorization and business access through secure access control policies to achieve secure access to resources, and implements unified identity authentication, continuous trust assessment, dynamic access control and minimum access authorization criteria to resist external vehicle network attacks.

[0055] In recent years, the network attacks on the rail transit vehicle network system have shown an upward trend. The inventors have also conducted a series of researches on software-defined perimeter networks. On the one hand, it is adapted to the change of the rail transit vehicle network system architecture and the security requirements, and on the other hand, it is targeted at the threats caused by the upgrading of current network attack means and the diversification of attacker identity attributes. In combination with the characteristics of the rail vehicle vehicle network and the application scene of the zero trust protection mechanism, the present application proposes a rail vehicle vehicle network security communication method based on software-defined perimeter.

[0056] Figure 1 The network topology architecture of the prior art rail vehicle vehicle network is shown in the figure. The present embodiment takes this network structure as an example but is not limited to application in the network architecture shown in the figure, and reference is made to Figure 1 Figure 1 ​As shown in the prior vehicle-mounted Ethernet network system, the motor train unit adopts eight-vehicle marshalling, and the eight-vehicle marshalling is divided into two traction units, the first to fourth cars form a first traction unit, the fifth to eighth cars form a second traction unit, and the remaining cars are sequentially connected between the first car and the eighth car. The train level backbone network ETB bus is used to realize the dynamic configuration of the train, which can adapt to the dynamic configuration of a sixteen-vehicle marshalling recombined train composed of two eight-vehicle marshalling motor train units. Four train level Ethernet nodes ETBN are arranged on the train level backbone network ETB bus (Ethernet Train Backbone, ETB), the vehicle marshalling Ethernet ECN bus (Ethernet Consist Network, ECN) is used in the traction unit, the central control unit CCU and each subsystem are connected, used for obtaining and transmitting communication data of various devices in the traction unit, and data exchange and interoperation between devices are realized. The vehicle marshalling Ethernet ECN is used in the traction unit, and vehicle level Ethernet switches ECNN are arranged in the front and rear half traction units, respectively. Redundant vehicle level Ethernet switches ECNN are arranged in the car, and a linear double Ethernet line vehicle marshalling Ethernet ECN bus architecture is formed by using link aggregation. The single-car interior takes a single vehicle level Ethernet switch ECNN as the center to access each subsystem device to the vehicle level Ethernet switch ECNN. The subsystem devices in the diagram at least include input and output modules IOM, human-machine interface units HMI, train data recording units ERM, door control units EDCU, passenger information systems PIS, smoke and fire alarm systems FAS, pantograph controllers PCU, traction control units DCU, brake control units BCU, air conditioning control units HVAC and other onboard devices, and each device realizes communication through the vehicle level Ethernet switch ECNN.

[0057] Figure 2 The flowchart of the rail vehicle onboard network security communication method according to the embodiment of the present application is shown in FIG. 1, which includes the following steps: Figure 2

[0058] ​The software-defined boundary construction step S1 deploys and activates the vehicle SDP control unit and the vehicle SDP gateway in the vehicle network, the vehicle SDP control unit starts the identity authentication and authorization service, and the vehicle SDP gateway communicates with the vehicle SDP control unit in a secure manner; wherein, the vehicle SDP gateway will not respond to communications from any other host (including the initiating host and the accepting host, that is, the SDP client component and the vehicle SDP gateway) before authentication, nor will it respond to any unauthorized requests. Specifically, the vehicle SDP control unit and the vehicle SDP gateway are communicatively connected to the vehicle-level Ethernet switch ECNN, and the node devices in the rail vehicle compartment communicate with the vehicle-level Ethernet through the SDP client component, the vehicle SDP control unit and the vehicle SDP gateway, wherein the node devices communicate with the SDP client component based on the TRDP protocol.

[0059] The node device network access step S2 deploys the SDP client component to the communication network node device of the vehicle network and activates the SDP client component, adds each initiating communication network node device to the SDP, and the SDP client component is communicatively connected to the vehicle SDP control unit to request authorization, and the vehicle SDP control unit is used to output the gateway list and the permission list of the authorized SDP client component after authentication;

[0060] The node device communication establishment step S3, after the SDP client component performs single packet authorization authentication to the authorized vehicle SDP gateway according to the gateway list and the permission list and establishes encrypted communication, the node device communicates with the vehicle network through the SDP client component and the vehicle SDP gateway and executes the control instruction of the rail vehicle, such as Figure 7 As shown in the figure, the dashed line between the vehicle SDP control unit and the vehicle SDP gateway indicates the control flow; the straight line between the vehicle network node device and the vehicle SDP gateway indicates the data flow; by way of example but not limitation, the control instruction can be from the vehicle TCMS network (Train Control and Management System, Train Control and Management System), ATC network (Automatic Train Control, vehicle signal system) or PIS network, and the control instruction includes traction instruction, braking instruction, marshalling instruction, etc.

[0061] The gateway list and the permission list authorized by the SDP client component are dynamically generated based on the rail vehicle control instruction, so as to perform on-demand construction and dynamic reconstruction of the network boundary, and the on-board SDP gateway is connected to the service resource side to access the application service. Taking train traction as an example, when the train is in traction, the power is introduced to the vehicle from the catenary through the pantograph and then connected to the traction inverter, the traction inverter supplies power to the traction motor, thereby controlling the vehicle to run, at this time, in the traction instruction, the devices that need to be responded to include but are not limited to the pantograph controller PCU and the traction control unit DCU, then the SDP client component parses and generates the gateway list and the permission list of the pantograph controller PCU and the traction control unit DCU according to the traction instruction demand; only the train traction working condition is taken as an example to illustrate the instruction basis for dynamically and on-demand generating the gateway list and the permission list, and correspondingly, other working conditions such as train braking control / emergency braking control, fire hazard early warning, train marshalling reconnection and the like are the same, and will not be repeated here.

[0062] In some embodiments, reference is made to Figure 4 As shown in the figure, the node device network access step S2 further includes:

[0063] The node device deployment step S201 deploys the SDP client component to the node device, the SDP client component is in communication connection with the on-board SDP control unit and sends verification information to the on-board SDP control unit for identity authentication, so as to form a trusted user identity authentication with the on-board SDP control unit, the on-board SDP control unit detects and checks the verification information of the accessed SDP client component, and realizes terminal security baseline scanning; wherein the verification information includes but is not limited to user information and network environment information, the user information at least includes: username, password, terminal information, and the network environment information at least includes: hardware ID, local antivirus software version, local patch update situation, IP address, address location, thereby helping the user to comprehensively understand the security of the running environment of the accessed node device and realizing security access control, and ensuring the reliability of the accessed node device. Optionally, the SDP client component is embedded in the node device in the form of the SDP client component.

[0064] The authorized list obtaining step S202, after the identity authentication is passed, the on-board SDP control unit parses the control instruction of the rail vehicle to determine the gateway list and the permission list that the SDP client component needs to be authorized, and sends to the SDP client component;

[0065] The covert communication pre-starting step S203, the on-board SDP control unit instructs the on-board SDP gateway in the gateway list to accept communication, and starts the control strategy required for encrypted communication.

[0066] Based on this, the network virtual boundary is divided by using the vehicle-mounted SDP gateway. All service resources controlled by the vehicle-mounted SDP gateway are not exposed to the outside, and only the authorized devices can access the hidden SDP network resources. Moreover, the range of the accessible devices is dynamically developed and recycled based on the control instructions, and there is no fixed or permanent authorized node device, so there is no fixed attack object.

[0067] In some embodiments, the node device communication establishment step S3 further includes: Figure 5

[0068] The hidden communication initiation step S301 includes that the SDP client component of the node device initiates single packet authorization (SPA) to the authorized vehicle-mounted SDP gateway according to the gateway list, and creates a bidirectional encrypted communication after the authorization is passed. The unauthorized vehicle-mounted SDP gateway cannot perceive or access, so as to realize the hidden communication, as shown in FIG. 3. Figure 8 That is, the first data packet sent by the SDP client component of any node device to the vehicle-mounted SDP control unit must be an authentication packet. If other data packets are received, the device communication is disconnected for illegal connection. The bidirectional encrypted communication is a bidirectional TLS authentication. The bidirectional TLS authentication and encryption technology are adopted to resist DDoS, man-in-the-middle attack, supply chain attack, advanced persistent threat (APT) and zero-day vulnerability protection, and to realize more fine-grained security control, as shown in FIG. 4. Figure 9

[0069] The control channel establishment step S302 includes that the vehicle-mounted SDP control unit informs the SDP client component initiating the single packet authorization and the corresponding authorization strategy of the vehicle-mounted SDP gateway, and establishes a control channel with the vehicle-mounted SDP gateway.

[0070] The data channel establishment step S303 includes that the SDP client component obtains the vehicle-mounted SDP gateway with the right and the authorized resource control strategy according to the permission list, establishes a bidirectional encrypted data channel with the vehicle-mounted SDP gateway with the right according to the resource control strategy, and communicates with the vehicle-mounted network system through the vehicle-mounted SDP gateway.

[0071] ​​Based on the above steps, the embodiment of the application realizes the separation of the control plane and the data plane, and realizes that the SDP client component of the node device can only connect to the vehicle-mounted SDP gateway and perform encrypted communication through the vehicle-mounted SDP gateway after authorization authentication. It is known that in the existing vehicle-mounted network service access process, the client needs to first establish a network connection with the system and then perform authentication, so that the vehicle-mounted network has to pre-develop a service port for direct transmission of signal instructions, increasing the risk of attack. The embodiment realizes network security communication through the separation of the control plane and the data plane and based on a single packet authorization authentication mechanism. Compared with the existing situation in which the vehicle control instruction is directly transmitted based on the firewall boundary, the network boundary of the application always maintains untrusted node device identifiers and node device IP addresses. Each node device must be verified before communicating with the vehicle-mounted network system to ensure that each node is allowed to intervene, thereby realizing trust evaluation and permission granting of resource access, hiding vehicle-mounted network device assets in a software-defined boundary continuous verification and on-demand dynamic authorization manner, preventing unauthorized network nodes from accessing, and protecting against external security threats, realizing hidden communication of the vehicle-mounted network system, and ensuring the safety of the vehicle-mounted network system.

[0072] Based on the above steps, the vehicle-mounted network security communication of the embodiment of the application avoids the vulnerability of the firewall itself through a connection mode of first authorization and then authentication based on the software-defined boundary SDP, forms network stealth through a single packet authorization authentication mechanism, hides the vulnerabilities of the system and application program, and is invisible to unauthorized users, effectively reducing the attack surface, alleviating or completely eliminating multiple security threats, risks, and vulnerabilities, resisting DDoS, man-in-the-middle attacks, supply chain attacks, and advanced persistent threats (APT) and zero-day vulnerability protection, and realizing more fine-grained security control to realize business asset avoidance of known or unknown attack threats.

[0073] In some embodiments, the authentication data packet of the single packet authorization authentication includes device fingerprint information, application fingerprint information, and authentication format information, the authentication format information includes a request code, a user identifier, a node device identifier ComID, a random number, a timestamp, and metadata, the request code includes a port and a protocol requested by the SDP client component to access, the user identifier includes user account information and login password information, which are pre-stored in the SDP client component file, and the random number is 32 bytes to avoid replay attacks. The device fingerprint is part of the function used in the single packet authorization authentication SPA authentication data packet, and is the only encryption key for the vehicle-mounted SDP control unit to verify the identity of the vehicle-mounted network node device. The metadata, also known as intermediary data or relay data, is data about data, mainly information describing data properties, and is used to support functions such as indicating storage location, historical data, resource search, file record, etc.

[0074] In some embodiments, the device fingerprint information is a string formed by digitizing, combining, and hashing encrypting a plurality of feature information, the feature information includes a node device CPU unique identifier, node device CPU characteristic information, a network adapter MAC address, operating system features, peripheral interfaces, geographic location, operation services, and connection features, and the digitization can use ASCII encoding, Chinese national standard code, etc. The application fingerprint information is specifically the version number of the application program software installed on the node device.

[0075] The above authentication data packet encapsulates multi-factor identity information into the packet, realizes the stealth of vehicle-mounted network service resources and trusted access of node devices. It should be noted that the first data packet sent by the SDP client component of any node device to the vehicle-mounted SDP control unit must be an authentication data packet, otherwise, the node device is not allowed to communicate for illegal connection. By integrating all necessary information in a single data packet, the knocking process is simplified, and the device and user identity are verified before allowing access to the network, thereby achieving "network stealth" and making it difficult for attackers to find service addresses and ports.

[0076] In some embodiments, based on the single packet authorization authentication data packet as above, the vehicle-mounted SDP gateway unpacks, verifies and the like the received data packet, analyzes and confirms the validity of the information in the authentication data packet, judges whether the authentication is successful, the validity depends on whether the registered value in the vehicle-mounted SDP gateway matches the received value, the authentication data packet must be encrypted and authenticated and must include all necessary information, a single data packet is not trusted and the original data packet is not allowed to be tampered with. In the case of invalid data packet, the data packet is discarded without response. If it is a valid data packet, the SDP client component is notified that the authentication is successful, and the establishment of the TLS encrypted secure communication is controlled.

[0077] In some embodiments, in the software-defined boundary construction step, the vehicle-mounted SDP control unit and the vehicle-mounted SDP gateway are distributedly deployed, the number N of vehicle-mounted SDP gateways G is configured to: 2≤N G < the number of rail vehicle carriages; the number N of vehicle-mounted SDP control units C is configured to: 2≤N C < the number of rail vehicle carriages. Optionally, the head car and the tail car of the rail vehicle consist are respectively provided with vehicle-mounted SDP gateways, and the intermediate vehicles are optionally provided with vehicle-mounted SDP gateways corresponding to the number of vehicles or less than the number of vehicles. When the number of vehicle-mounted SDP gateways is less than the total number of vehicles, the node device of each carriage can select the vehicle-mounted SDP gateway for communication based on the principle of proximity. In summary, the number of vehicle-mounted SDP gateways can be flexibly set according to the network load and the real-time demand of network communication, but at least the communication demand of the head car and the tail car should be met. The number of vehicle-mounted SDP control units is preferably set to be the same as the number of vehicle-mounted SDP gateways, but it is not excluded that it can also be set to be different. The node device of each carriage can also select the vehicle-mounted SDP control unit based on the principle of proximity.

[0078] Figure 6 is a connection diagram of the vehicle-mounted SDP control unit and the vehicle-mounted SDP gateway according to the embodiments of the present application. As shown in Figure 6 , the vehicle-mounted SDP control unit and the vehicle-mounted SDP gateway are provided in the form of a 3U circuit board card. Specifically, the vehicle-mounted SDP control unit is inserted into the backboard slot of the CCU (Central Control Unit) case, and the interface is in the form of CPCI; the vehicle-mounted SDP gateway card is inserted into the backboard slot of the vehicle-level Ethernet switch ECNN case, and the interface is also in the form of CPCI. The 3U circuit board card refers to the size matched with 3U devices, and U is a unit of abbreviation for unit, and the detailed size is determined by the American Electronics Industry Association (EIA) as an industry group.

[0079] It should be noted that the software-defined boundary SDP adopts a dynamic authorization strategy. After verifying the identity of the node device in the initial stage, the context of the access is also continuously monitored, such as whether the state of the node device is safe and whether the user access behavior is abnormal, to comprehensively evaluate the continuous trustworthiness of the access. When an exception is found, authorization degradation is performed, and the permission list is adjusted, such as initiating secondary authentication, requiring the node device to provide stronger identity proof to indicate its trustworthiness, and processing according to the security requirements before the access to the business resource can continue, such as Figure 10 .

[0080] The embodiment also provides a rail vehicle on-board network secure communication method. Figure 3 The flowchart of the rail vehicle on-board network secure communication method according to the embodiment of the application is shown in Figure 3 , and the difference between the flowchart and the above embodiment is that the flowchart further includes the following steps:

[0081] The node device communication canceling step S4 is that when the single packet authorization authentication initiated by the SDP client component in the node device communication establishing step S3 fails, the node device communication is completed, or the rail vehicle marshalling is reconnected, the on-board SDP control unit resets the gateway list and the permission list, and reconfigures the network boundary.

[0082] In combination with the above embodiment, the distributed on-board SDP control unit of the application is mainly used for dynamically authenticating and authorizing the on-board network terminal node device, dynamically adjusting the access communication permission of the network node device, verifying the access permission of the node device where the SDP client component is located, building a zero-trust identity security boundary, ensuring bidirectional encrypted communication, realizing asset hiding and controlling the hidden communication network, and opening resources on demand according to the priority;

[0083] The on-board SDP gateway is mainly used for dividing the virtual boundary of the on-board network, can accept and control connections, grant limited-time access permissions, and all backend resources connected and controlled by the on-board SDP gateway have no exposed services or ports. Only the devices that pass the verification and are authorized can access the hidden network resources, and the range is strictly controlled and dynamically opened and recycled. Conversely, the on-board SDP gateway rejects all unauthorized connection requests. Only after the on-board SDP control unit issues an authentication and authorization strategy, the connection of the specified SDP client component is dynamically accepted, the data communication of the SDP client component and the application is proxy by the encrypted transmission, and the communication process is managed according to the resource control strategy issued by the on-board SDP control unit. The on-board SDP control unit and the on-board SDP gateway cooperate to realize intelligent automatic routing of the gateway where the rail vehicle control instruction related application is executed.

[0084] In the communication of the vehicle-mounted network node device, the real domain name and address are not exposed throughout, only the authorized nodes can reliably access, and the unauthorized users cannot communicate and service. Before the SDP client component of the network node device completes the single packet authorization authentication, the vehicle-mounted SDP control unit and the vehicle-mounted SDP gateway do not respond to any connection of any client.

[0085] In addition, in some embodiments, the SDP client component implements a deep trust evaluation mechanism and supports scoring the trust degree of the access node device. Specifically, the direct trust degree of the node device can be determined based on historical behavior data, the traffic trust degree can be calculated according to the traffic baseline of the access terminal and the behavior trust-based access decision agent, and the comprehensive trust degree can be calculated according to the direct trust degree and the traffic trust degree. The trust threshold is configured for the direct trust degree, the traffic trust degree and / or the comprehensive trust degree to determine whether it is abnormal information or can be accessed, and the minimum permission required to complete the task is granted to perform business access interaction, such as Figure 11 as shown.

[0086] In some embodiments, the vehicle-mounted SDP control unit manages the authentication authorization strategy and the resource control strategy based on a deep learning technology. The deep learning technology is used to provide network models such as deep neural network, convolutional neural network, and recurrent neural network to update the strategy according to the network model, and the specific network model used by the deep learning technology is not limited by the present application. The deep learning technology can dynamically discover new attack methods, allow learning from past events (such as distributed denial of service attack DDoS, man-in-the-middle attack, replay attack, etc.) to detect network anomalies, and increase the traceability of forensics.

[0087] It should be noted that the steps shown in the above flow or the flowchart of the accompanying drawings can be executed in a computer system such as a group of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from here.

[0088] In addition, the embodiment of the present application provides a railway vehicle arranged with an Ethernet network adopting the railway vehicle network security communication method as described above.

[0089] In summary, the rail vehicle on-board network security communication method based on the software-defined boundary and the rail vehicle provided by the embodiments of the present application, by the rail vehicle on-board network security communication method based on the software-defined boundary, compared with the traditional on-board network system, the on-board network assets are hidden, so as not to be directly exposed in the network, so that the network assets and facilities are immune to external security threats. The minimum permission access control is carried out based on identity authentication, any node device inside and outside the network is not trusted by default through the network stealth technology, the security level assessment and dynamic access control are continuously carried out, and the on-board network system asset security is effectively protected.

[0090] Based on the above step S3, the separation of the control plane and the data plane is realized, and the SDP client component of the node device can only connect the on-board SDP gateway and perform encrypted communication through the on-board SDP gateway after authorized authentication;

[0091] The network stealth is formed through the single packet authorization authentication mechanism, the vulnerabilities of the system and the application program are hidden, and the unauthorized users cannot see it, which can effectively reduce the attack surface, alleviate or completely eliminate multiple security threats, risks and vulnerabilities, resist DDoS, man-in-the-middle attacks, supply chain attacks and advanced persistent threats (APT) and zero-day vulnerability protection, and realize more fine-grained security control to realize business asset avoidance of known or unknown attack threats.

[0092] The technical features of the above embodiments can be combined arbitrarily, in order to make the description simple, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.

[0093] The above embodiments only express several implementation manners of the present application, the description is more specific and detailed, but it should not be understood as the limitation of the patent scope of the present application. It should be pointed out that, for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which all belong to the protection scope of the present application. Therefore, the patent protection scope of the present application should be subject to the appended claims.

Claims

1. A method for secure communication of an onboard network of a rail vehicle, characterized in that, Comprise: Software-defined boundary construction step, deploying and activating vehicle-mounted SDP control unit and vehicle-mounted SDP gateway in vehicle-mounted network, the vehicle-mounted SDP control unit starts identity authentication and authorization service, and the vehicle-mounted SDP gateway is communicatively connected with the vehicle-mounted SDP control unit; Node device network access step, deploying SDP client to the communication network node device of the vehicle-mounted network and activating SDP client component, the SDP client component is communicatively connected with the vehicle-mounted SDP control unit to request authorization, and the vehicle-mounted SDP control unit is used to output the gateway list and the permission list authorized by the SDP client component after authentication; Node device communication establishment step, after the SDP client component performs single packet authorization authentication to the authorized vehicle-mounted SDP gateway according to the gateway list and the permission list and establishes encrypted communication, the node device communicates with the vehicle-mounted network through the SDP client component, vehicle-mounted SDP gateway and executes control instruction of the rail vehicle; Wherein, the gateway list and the permission list authorized by the SDP client component are dynamically generated based on the rail vehicle control instruction, so as to construct and dynamically reconstruct the network boundary on demand; Wherein, the vehicle-mounted SDP control unit and the vehicle-mounted SDP gateway are communicatively connected with vehicle-level Ethernet switch ECNN, the node device in the rail vehicle carriage performs hidden communication with the vehicle-level Ethernet through the SDP client component, vehicle-mounted SDP control unit and vehicle-mounted SDP gateway, the node device communicates with the SDP client component based on TRDP protocol, and the first data packet sent by the SDP client component of any node device to the vehicle-mounted SDP control unit must be authentication data packet, otherwise, the node device is not allowed to communicate for illegal connection; The network boundary always keeps untrusted to node device identifier and node device ID address, each node device must be verified before communicating with the vehicle-mounted network system, to ensure that each node is allowed to intervene, so as to realize trust evaluation and permission granting of resource access, and to hide vehicle-mounted network device assets in a way of continuously verifying and dynamically authorizing on demand by software-defined boundary.

2. The method of claim 1, wherein, In the software-defined boundary construction step, the vehicle-mounted SDP control unit and the vehicle-mounted SDP gateway are distributedly deployed, Number of on-board SDP gateways N G Configured as: 2 ≤ N G ≤ number of rail vehicle carriages; Number N of on-board SDP control units C Configured such that: 2 ≤ N C ≤ number of rail vehicle carriages.

3. The method of claim 2, wherein, Further comprise: Node device communication removal step, when the single packet authorization authentication initiated by the SDP client component in the node device communication establishment step fails, the node device communication is completed or the rail vehicle is reconnected, the vehicle-mounted SDP control unit resets the gateway list and the permission list, and the network boundary is reset.

4. The method of claim 1, wherein, The node device network access step further comprises: Node device deployment step, deploying SDP client component to the node device, the SDP client component is communicatively connected with the vehicle-mounted SDP control unit and sends authentication information to the vehicle-mounted SDP control unit for identity authentication; The authorization list obtaining step, after the identity authentication is passed, the vehicle-mounted SDP control unit analyzes the control instruction of the rail vehicle to determine the gateway list and the permission list that the SDP client component needs to be authorized, and sends to the SDP client component; The covert communication pre-starting step, the vehicle-mounted SDP control unit instructs the vehicle-mounted SDP gateway in the gateway list to accept communication, and starts the control strategy required for encrypted communication.

5. The method of claim 4, wherein, The node device communication establishing step further comprises: The covert communication initiating step, the SDP client component of the node device initiates single packet authorization authentication to the authorized vehicle-mounted SDP gateway according to the gateway list, and creates bidirectional encrypted communication after the authentication is passed; The control channel establishing step, the vehicle-mounted SDP control unit informs the SDP client component initiating single packet authorization authentication and its corresponding authorization strategy to the vehicle-mounted SDP gateway, and establishes a control channel with the vehicle-mounted SDP gateway; The data channel establishing step, the SDP client component obtains the vehicle-mounted SDP gateway with permission and its authorized resource control strategy according to the permission list, establishes a bidirectional encrypted data channel between the SDP client component and the vehicle-mounted SDP gateway according to the resource control strategy, and communicates with the vehicle-mounted network system through the vehicle-mounted SDP gateway.

6. The method of secure communication for onboard network of a rolling stock according to claim 5, characterized in that, The authentication data packet of the single packet authorization authentication comprises device fingerprint information, application fingerprint information and authentication format information, and the authentication format information comprises a request code, a user identifier, a node device identifier ComID, a random number, a timestamp and metadata.

7. The method of secure communication for onboard network of a rolling stock according to claim 6, characterized in that, The device fingerprint information is a string formed by digitalizing, combining and hash encrypting a plurality of feature information, and the feature information comprises a node device CPU unique identifier, node device CPU characteristic information, a network adapter MAC address, an operating system feature, a peripheral interface, a geographic location, an operation service and a connection feature.

8. The rail vehicle onboard network secure communication method according to any one of claims 1-7, characterized in that, The vehicle-mounted SDP control unit and the vehicle-mounted SDP gateway are arranged in the form of a 3U circuit board card.

9. A rail vehicle, characterized by The rail vehicle is arranged with an Ethernet network adopting the rail vehicle vehicle-mounted network security communication method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Motor train unit network security control method, device and equipment and readable storage medium

    CN115484085A

  • Ethernet network for diagnosing railway vehicle and railway vehicle

    CN213213516U

  • Resource access method, system and device and storage medium

    CN115333840A