A train network security architecture and train

By dividing the train network into six zones and defining pipelines, the problem of insufficient risk identification and protection strategies in train network security assessment was solved, thereby improving the security and stability of the train network.

CN117184173BActive Publication Date: 2026-01-30CRRC QINGDAO SIFANG ROLLING STOCK RESEARCH INSTITUTE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311182127.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-13
Publication Date
2026-01-30
Estimated Expiration
2043-09-13

AI Technical Summary

Technical Problem

In existing technologies, the risk identification and security assessment of train network security issues have not been effectively carried out, and there is a lack of scientific protection strategies, resulting in insufficient network security.

Method used

The train network is divided into six areas, including the train-level Ethernet area, the vehicle-level TCMS area, the vehicle-level OOS area, the local maintenance area, the remote maintenance area, and the vehicle-to-ground transmission area. Connecting pipelines are defined, and information transmission is ensured through security verification to improve network security.

Benefits of technology

By clearly defining the protection requirements and risk identification of the train network, the complexity of analysis is reduced, the security and stability of the network architecture are improved, and the safe operation of trains is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117184173B_ABST
    Figure CN117184173B_ABST
Patent Text Reader

Abstract

This invention relates to a train network security architecture and a train. The train network security architecture includes: a train-level Ethernet area, a vehicle-level TCMS area, a vehicle-level OOS area, a local maintenance area, a remote maintenance area, a vehicle-to-ground transmission area, and first to ninth channels connecting the various areas. The train network security architecture supports single-train and multi-train multiple-unit operation modes. By dividing the train network security areas and channels according to the architecture, component composition, and functional definitions of the train network, it helps to identify the importance of the assets contained in the train network, the communication interfaces and data flows within the train network, and their functional safety related aspects. This provides a solid foundation for the systemic security risk assessment of the train network, thereby enabling the formulation of corresponding network security protection strategies, improving the stability of the train network, and ensuring the safe operation of the train.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of rail vehicle technology, in particular to a train network security architecture and a train. BACKGROUND

[0002] With the application of Ethernet technology in the field of rail transit, the development of train informatization and intelligent system is promoted, and the train network control technology gradually transits from a closed special network to an open Ethernet fusion control network.

[0003] TCMS (Train Control and Monitoring System) is one of the core systems of rail transit vehicles, known as the "nerve system" of the train, and its main functions include vehicle control, state monitoring, fault diagnosis, etc. The train network control system mainly includes train-level switches, vehicle-level switches, central control units, remote input / output units, human-machine display units, etc. The network transmission of train control data must have high determinacy, real-time, reliability and security.

[0004] TCMS is generally divided into train-level networks and vehicle-level networks. Each marshalling communicates through a train-level switching unit to transmit vehicle control data, state data and fault diagnosis data. The internal devices of the marshalling are connected through a vehicle-level switching unit to realize data exchange between the vehicle controllers and the central control unit.

[0005] The OOS (Operator Oriented Service) system is a functional domain that provides auxiliary services for appropriate train operations, including train maintenance functions, PIS (Passenger Information System), etc. The goal of this functional domain is to improve the operational parameters of the train, such as maintenance costs and overall vehicle availability. Communication within the OOS system does not affect the functional safety of the train.

[0006] The OOS system supports communication between terminal devices within the same marshalling and between terminal devices in different marshalling, achieving maintenance information collection and device monitoring of on-board devices, and laying a technical foundation for intelligent maintenance of the train.

[0007] Due to the openness of Ethernet technology and its wide application in train networks, train network security issues have attracted increasing attention in the industry. How to scientifically and effectively identify risks and conduct safety assessments of train networks, and then develop network security protection strategies, has become a pressing problem.

[0008] Therefore, after a structured description of the rail vehicles and their related information, an initial security risk analysis is needed to identify systems and functional groups with similar protection requirements, and then classify them into the corresponding security zones. According to IEC 62443-3-2 and CLC / TS 50701 standards, when conducting cybersecurity risk management for the system under evaluation, the system needs to be divided into security zones and channels for inter-zone communication to support the definition of different security zones, risk analysis, and the development of protection strategies. Summary of the Invention

[0009] To address the shortcomings of related technologies, this invention provides a train network security architecture that further analyzes all possible attack routes of attackers based on each path that the protected object may be attacked, identifies risks related to IT security, and provides a solid foundation for the systemic security risk assessment of train networks.

[0010] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0011] A train network security architecture for practical analysis and evaluation of the network security status of rail vehicles, including:

[0012] Vehicle-level TCMS area: includes a first ECNN switch and a TCMS device, wherein the TCMS device is connected to the first ECNN switch, and the first ECNN switch is connected to a group-level Ethernet to realize data exchange;

[0013] Vehicle-level OOS area: includes OOS devices and a second ECNN switch. The OOS devices are connected to the second ECNN switch, which is connected to a group-level Ethernet network to exchange data.

[0014] Maintenance area: includes maintenance equipment, which is connected to the TCMS device and the OOS device, and establishes communication and performs maintenance functions respectively;

[0015] Vehicle-to-ground transmission area: includes onboard wireless transmission devices for data exchange between the train and the ground system;

[0016] The fourth conduit connects the TCMS device and the OOS device and is used for data exchange via group-level Ethernet.

[0017] The seventh conduit connects the TCMS device and the vehicle-mounted wireless transmission device, and is used to exchange TCMS-related data with the ground system;

[0018] The ninth conduit connects the OOS device and the vehicle-mounted wireless transmission device, and is used to exchange OOS-related data with the ground system.

[0019] In some embodiments of the present invention, it further includes:

[0020] Train-level Ethernet area: including ETBN switches, used for communication between different train sets when multiple train sets are coupled together;

[0021] The first pipeline connects different train-level Ethernet areas when multiple train sets are reconnected, that is, it connects the ETBN switches of different train sets.

[0022] The second pipeline connects the ETBN switch and the first ECNN switch within the same train group and is used to exchange TCMS data via train-level Ethernet.

[0023] The third conduit, which connects the ETBN switch and the second ECNN switch within the same train group, is used to exchange OOS data via train-level Ethernet.

[0024] In some embodiments of the present invention, the TCMS device includes a functional safety TCMS device and a non-functional safety TCMS device;

[0025] The seventh conduit connects the non-functional safety TCMS device and the vehicle-mounted wireless transmission device.

[0026] The maintenance area includes:

[0027] Local maintenance area: includes a first maintenance device, which is connected to the functional safety TCMS device to establish communication and perform maintenance functions;

[0028] Remote maintenance area: includes a second maintenance device that is connected to the non-functional safety TCMS device and OOS device to establish communication and perform maintenance functions.

[0029] In some embodiments of the present invention, it further includes:

[0030] The fifth conduit connects the functional safety TCMS device and the first maintenance device, and is used to transmit maintenance data of the functional safety-related TCMS device.

[0031] The sixth conduit connects the non-functional safety TCMS device and the second maintenance device, and is used to transmit maintenance data of the non-functional safety related TCMS device;

[0032] The eighth pipe connects the OOS device and the second maintenance device and is used to transmit maintenance data of the OOS device.

[0033] In some embodiments of the present invention, the fifth, sixth, and eighth pipes are equipped with security verification during data communication.

[0034] In some embodiments of the present invention, at least two ETBN switches are provided in the same train formation and installed in the head car and tail car of the train formation;

[0035] The train-level Ethernet area also includes repeaters that connect the ETBN switches in the head car and the tail car of the same train group to ensure the communication quality of train-level Ethernet data.

[0036] In some embodiments of the present invention, multiple repeaters are provided, installed in each of the remaining carriages except the first and last carriages within the same train set. Repeaters in adjacent carriages are interconnected. The repeater adjacent to the first carriage is connected to the ETBN switch of the first carriage, and the repeater adjacent to the last carriage is connected to the ETBN switch of the last carriage for data transmission, forming a train-level Ethernet network.

[0037] In some embodiments of the present invention, the OOS device includes train maintenance equipment and PIS network equipment within the same trainset.

[0038] In some embodiments of the present invention, the OOS device and the TCMS device share a set of physical ECN networks.

[0039] In addition, the present invention also provides a train that applies the aforementioned train network security architecture.

[0040] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0041] 1. Based on the train network architecture, component composition, and functional definitions, this invention divides the train network into six areas, supporting single-unit and multi-unit multiple-unit operation modes. These areas include a train-level Ethernet area, a vehicle-level TCMS area, a vehicle-level OOS area, a local maintenance area, a remote maintenance area, and a vehicle-to-ground transmission area. This division confirms the different protection requirements of various parts of the railcar, facilitating risk identification and security assessment of the train network and the development of network security protection strategies.

[0042] 2. The present invention also includes pipelines connected to each security zone. When conducting security risk assessment of the train network, the definition and identification of pipelines can reduce the complexity of the analysis. When transmitting information in some pipelines, security verification is required at the pipeline. Only information that has passed the verification can cross the boundary and enter the next security zone, which further improves the security of the network architecture.

[0043] 3. The division of train network areas and pipelines helps to identify the assets included in the train network, the communication interfaces and data flows within the train network and their functional safety-related importance, identify assets with common safety requirements, and provide a solid foundation for the systemic safety risk assessment of the train network. This ensures the integrity and reliability of the safety risk assessment, facilitates the implementation of safety measures to mitigate network security risks, improves the stability of the train network, and ensures the safe operation of trains. Attached Figure Description

[0044] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0045] Figure 1 This is a schematic diagram of a train network security architecture model according to an embodiment of the present invention;

[0046] Figure 2 This is a schematic diagram of the network security zone and pipeline division of a train when multiple train sets are coupled together, according to an embodiment of the present invention. Detailed Implementation

[0047] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0048] The terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first," "second," or "third" may explicitly or implicitly include one or more of that feature.

[0049] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "joining" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal communication between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0050] As attached Figure 1 and attached Figure 2 As shown, in an exemplary embodiment of a train network security architecture according to the present invention, it includes:

[0051] Train-level Ethernet area: including ETBN switches, used for communication between different train sets when multiple train sets are coupled together;

[0052] Vehicle-level TCMS area: includes a first ECNN switch and TCMS equipment. The TCMS equipment is connected to the first ECNN switch, which is connected to a group-level Ethernet network to achieve data exchange.

[0053] Vehicle-level OOS area: includes OOS devices and a second ECNN switch. The OOS devices are connected to the second ECNN switch, which is connected to the group-level Ethernet and enables data exchange.

[0054] Vehicle-to-ground transmission area: includes onboard wireless transmission devices for data exchange between the train and the ground system;

[0055] Local maintenance area: includes the first maintenance device, which is connected to the functional safety TCMS device to establish communication and perform maintenance functions;

[0056] Remote maintenance area: includes a second maintenance device that connects to the non-functional safety TCMS device and OOS device to establish communication and perform maintenance functions.

[0057] The first pipeline connects different train-level Ethernet areas when multiple train sets are reconnected, that is, it connects the ETBN switches of different train sets.

[0058] The second pipeline connects the ETBN switch and the first ECNN switch within the same train group and is used to exchange TCMS data via train-level Ethernet.

[0059] The third pipeline connects the ETBN switch and the second ECNN switch within the same train group and is used to exchange OOS data via train-level Ethernet.

[0060] The fourth channel connects the TCMS and OOS devices and is used for data exchange via grouped Ethernet.

[0061] The fifth conduit connects the functional safety TCMS device and the first maintenance device, and is used to transmit maintenance data of the functional safety-related TCMS device.

[0062] The sixth conduit connects the non-functional safety TCMS device and the second maintenance device, and is used to transmit maintenance data of the non-functional safety related TCMS device.

[0063] The seventh conduit connects the non-functional safety TCMS device and the vehicle-mounted wireless transmission device, and is used to exchange TCMS-related data with the ground system;

[0064] The eighth pipe connects the OOS device and the second maintenance device, and is used to transmit maintenance data of the OOS device;

[0065] The ninth conduit connects the OOS equipment and the vehicle-mounted wireless transmission device, and is used to exchange OOS-related data with the ground system.

[0066] To comply with the IEC 62443-3-2-2020 standard, the first to ninth pipelines can be further defined as follows: C1 Train-level Ethernet area to train-level Ethernet area pipeline, C2 Train-level Ethernet area to vehicle-level TCMS area pipeline, C3 Train-level Ethernet area to vehicle-level OOS area pipeline, C4 Vehicle-level TCMS area to vehicle-level OOS area pipeline, C5 Vehicle-level TCMS area to local maintenance area pipeline, C6 Vehicle-level TCMS area to remote maintenance area pipeline, C7 Vehicle-level TCMS area to vehicle-to-ground transmission area pipeline, C8 Vehicle-level OOS area to remote maintenance area pipeline, and C9 Vehicle-level OOS area to vehicle-to-ground transmission area pipeline.

[0067] The first and second maintenance devices are service devices with maintenance applications and authentication access permissions, such as laptops. The first maintenance device can be directly connected to TCMS devices related to functional safety, while the second maintenance device can be connected to TCMS devices and OOS devices related to non-functional safety via the train network. The local and remote maintenance areas mainly realize maintenance functions such as reading diagnostic information, reading and writing configuration parameters, and downloading software from the connected devices.

[0068] Specifically, in implementing local maintenance functions, the first maintenance device (such as a laptop) acts as the client. The maintenance device sends communication requests via the DNS protocol, and the ETBN switch in the train network acts as the server. The ETBN switch receives the client's communication requests, which include the target device's domain name. Based on the target device's domain name, it determines the target device's dynamic IP address (the target device's global IP). This dynamic IP address is then sent to the client via the DNS protocol. Upon receiving the dynamic IP address, the client uses it to communicate with the target device.

[0069] The TCMS includes functional safety features such as control functions related to traction and braking, and non-functional safety features such as maintenance and display functions. In some embodiments, the functional and non-functional safety devices of the TCMS can be set according to the actual conditions of the train.

[0070] In this embodiment, to reduce the impact of cybersecurity issues on the safe operation of the train, communication between the TCMS functional safety equipment and the remote maintenance area and the train-to-ground transmission area is prohibited.

[0071] In this embodiment, a two-level bus topology is adopted, consisting of a train bus and a vehicle-level bus. The train bus and vehicle-level bus utilize the ECN vehicle network, namely the ETB train-level bus and the ECN vehicle-level bus. System devices with Ethernet interfaces are directly connected to the ECN vehicle network. Specifically, the ETB train-level bus consists of a train-level Ethernet switch (ETBN) and Ethernet train lines; the ECN vehicle-level bus consists of an ECNN vehicle-level Ethernet switch and terminal devices with Ethernet interfaces. All sub-devices are connected to the vehicle-level Ethernet switch (ECNN) in a dual-homing structure, and the switches between each car are interconnected to form a ring-redundant train-level Ethernet network.

[0072] In single-unit formations, communication within the same formation is provided through a vehicle-level Ethernet switch (ECNN) to enable vehicle-level communication between onboard equipment. Cross-formation communication is provided through a train-level Ethernet switch (ETBN) to enable communication between onboard equipment in multiple-unit formations.

[0073] When multiple train sets are coupled together, vehicle control, status and diagnostic data are transmitted between the train-level Ethernet switches (ETBN), and the equipment within the train sets exchanges data between the vehicle controllers and the central control unit (CCU) through the vehicle-level Ethernet switches (ECNN).

[0074] In some embodiments, ETBN and ECNN have fault bypass capabilities and support link aggregation.

[0075] In some embodiments, the train-level Ethernet uses Gigabit Ethernet to ensure effective transmission of data throughout the vehicle.

[0076] In some embodiments, since the maximum communication distance of Ethernet cannot exceed 100 meters, and the ETBN switches between subunits in a train may exceed this distance, the ETB train-level bus also includes an Ethernet repeater to regenerate electronic signals and ensure the communication quality of train-level Ethernet data in order to guarantee communication within the train network system. The ETBN and the repeater are connected using link aggregation technology.

[0077] In this embodiment, at least two ETBN switches are provided in the same train formation, installed in the first and last cars of the train formation; multiple repeaters are provided, installed in each of the remaining cars in the same train formation except for the first and last cars. Repeaters in adjacent cars are interconnected. The repeater adjacent to the first car is connected to the ETBN switch in the first car, and the repeater adjacent to the last car is connected to the ETBN switch in the last car, for data transmission, forming a train-level Ethernet network.

[0078] Specifically, taking an eight-car train as an example, the ETBN switch is set in the first and eighth cars, and the repeaters are set in the second to seventh cars. The repeaters near the first and last cars are connected to the nearest ETBN switch, and adjacent repeaters are interconnected.

[0079] In some embodiments, the Ethernet switch configures a separate 100 Mbps M12 Ethernet interface for each terminal device, and network hardware (CCU, IOM, HMI, WTS, ER, etc.) and other subsystem control units with Ethernet interfaces can be connected to the Ethernet switch of each vehicle via an Ethernet bus.

[0080] In some embodiments, the OOS equipment includes train maintenance equipment and PIS network equipment within the same trainset. Both the maintenance equipment and the PIS network equipment are connected to the ECNN switch in the same carriage and transmit data to the vehicle-level Ethernet.

[0081] In some embodiments, the OOS device and the TCMS device share a physical ECN network.

[0082] In this embodiment, the Ground Passenger Information Service System (PIS) is connected to the Ethernet via a standard gigabit Ethernet interface. Because the Ground Passenger Information Service System (PIS) and the vehicle-to-ground large-capacity data transfer system require a large amount of bandwidth to transmit video and other data, the Ethernet provides a standard gigabit Ethernet physical interface for the Ground Passenger Information Service System (PIS). In addition, the TCMS will upload all data on the vehicle, including control, fault, and status data, to the Ethernet to provide a basis for health diagnosis.

[0083] In some embodiments, critical network devices are designed with redundancy, including train-level Ethernet switches, vehicle-level Ethernet switches, central control units, input / output modules, human-machine interface displays, and wireless transmission devices.

[0084] Based on IEC 62443-3-2 and CLC / TS 50701 standards, the above exemplary embodiments are further defined to include the physical and logical boundaries, functional safety descriptions, physical and logical access points, data flows, connected areas and pipelines, and assets of each train network area and each pipeline, in order to conduct risk analysis and formulate protection strategies.

[0085] Specifically, the train network area is defined as follows:

[0086] 1. Train-level Ethernet area

[0087] (1) Physical and logical boundaries: Train-level Ethernet spans the entire train and all its network devices, including train-level switches, repeaters, connectors, cables, etc. The devices in this area are located in locked cabinets and can only be accessed by authorized personnel.

[0088] (2) Functional safety description: Data exchange between functional safety related equipment in different groups.

[0089] (3) Physical and logical access points: The interfaces include the interface from ETBN to ECN and the interface from ETB to terminal equipment.

[0090] (4) Data flow: Functional safety and non-functional safety data exchanged via train-level Ethernet.

[0091] (5) Connected areas and pipes: C1, C2, C3.

[0092] (6) Assets: ETBN, repeaters, connectors, Ethernet cables.

[0093] 2. Vehicle-level TCMS area

[0094] (1) Physical and logical boundaries: The devices in this area include functional safety and non-functional safety related devices of TCMS within a group. The devices in this area are located in locked cabinets and can only be accessed by authorized personnel.

[0095] (2) Functional safety description: related to important functional safety.

[0096] (3) Physical and logical access points: including the interface from ECN to TCMS terminal equipment.

[0097] (4) Data flow: Functionally safe and non-functionally safe data exchanged via grouped Ethernet.

[0098] (5) Connected areas and pipes: C2, C4, C5, C6, C7.

[0099] (6) Assets: ECNN, TCMS terminal equipment, connectors, Ethernet cables.

[0100] 3. Vehicle-level OOS area

[0101] (1) Physical and logical boundaries: The devices in this area include devices in a group of OOS devices. The devices in this area are located in locked cabinets and can only be accessed by authorized personnel.

[0102] (2) Functional safety description: No functional safety is involved.

[0103] (3) Physical and logical access points: including the interface from ECN to OOS terminal equipment.

[0104] (4) Data flow: Non-functional safety-related OOS data exchanged via group-level Ethernet.

[0105] (5) Connected areas and pipes: C3, C4, C8, C9, C10.

[0106] (6) Assets: ECNN, OOS terminal equipment, connectors, Ethernet cables.

[0107] 4. Local maintenance area

[0108] (1) Physical and logical boundaries: This area includes service equipment with maintenance applications that are directly connected to TCMS equipment related to functional safety.

[0109] (2) Functional safety description: Functional safety related.

[0110] (3) Physical and logical access points: physical interfaces (e.g., Ethernet ports or USB ports).

[0111] (4) Data flow: Read diagnostic information, read and write configuration parameters, and download software.

[0112] (5) Connected areas and pipes: C5.

[0113] (6) Assets: Service devices with authentication access permissions, such as laptops.

[0114] 5. Remote maintenance area

[0115] (1) Physical and logical boundaries: This area includes service equipment with maintenance applications, which are connected to non-functional safety related TCMS and OOS devices via the train network.

[0116] (2) Functional safety description: This does not involve functional safety. Remote maintenance is prohibited for TCMS devices related to functional safety.

[0117] (3) Physical and logical access points: physical interfaces (e.g., Ethernet ports or USB ports) are used to connect to non-functional safety-related TCMS devices and OOS devices and establish secure communication with the devices.

[0118] (4) Data flow: Read diagnostic information, read and write configuration parameters, and download software.

[0119] (5) Connected areas and pipes: C6, C8.

[0120] (6) Assets: Service devices with authentication access permissions, such as laptops.

[0121] 6. Vehicle-to-ground transmission area

[0122] (1) Physical and logical boundaries: This area includes assets that ensure secure communication between the train and ground systems. The equipment in this area is located in locked cabinets and can only be accessed by authorized personnel.

[0123] (2) Functional safety description: No functional safety is involved.

[0124] (3) Physical and logical access points: Interfaces from the vehicle-mounted wireless transmission device to the group-level Ethernet.

[0125] (4) Data stream: Train operation data related to non-functional safety in TCMS and OOS, such as diagnostic information.

[0126] (5) Connected areas and pipes: C7, C9.

[0127] (6) Assets: Vehicle-mounted wireless transmission device.

[0128] The train network pipeline is defined as follows:

[0129] 1. C1: Train-level Ethernet zone to train-level Ethernet zone inter-pipeline

[0130] (1) Physical and logical boundaries: This conduit connects different train-level Ethernet areas when multiple train sets are reconnected. The equipment in this conduit is located in a locked cabinet and can only be accessed by authorized personnel.

[0131] (2) Functional Safety Description: The initial operation function of the train and the data exchange between TCMS devices related to functional safety between different train formations are functional safety related. The data exchange between TCMS devices and OOS devices that are not related to functional safety between different train formations does not involve functional safety.

[0132] (3) Physical and logical access points: Interfaces include connection interfaces between different ETBNs.

[0133] (4) Data flow: Functional safety and non-functional safety data exchanged via train-level Ethernet.

[0134] (5) Connected areas and pipes: Train-level Ethernet area.

[0135] (6) Assets: ETBN train-level interface, connectors, Ethernet cables.

[0136] 2. C2: Pipeline between train-level Ethernet area and vehicle-level TCMS area

[0137] (1) Physical and logical boundaries: This conduit connects the train-level Ethernet area and the vehicle-level TCMS area. The equipment in this conduit is located in a locked cabinet and can only be accessed by authorized personnel.

[0138] (2) Functional safety description: Functional safety related.

[0139] (3) Physical and logical access points: Interfaces include the interface from ETBN to ECN and the interface from ECN to TCMS device.

[0140] (4) Data stream: Functional safety and non-functional safety TCMS data exchanged via train-level Ethernet.

[0141] (5) Connected areas and pipelines: train-level Ethernet area, vehicle-level TCMS area.

[0142] (6) Assets: ETBN vehicle-grade interface, ECNN interface, TCMS device interface, connectors, Ethernet cables.

[0143] 3. C3: Pipeline between train-level Ethernet area and vehicle-level OOS area

[0144] (1) Physical and logical boundaries: This conduit connects the train-level Ethernet area and the vehicle-level OOS area. The equipment in this conduit is located in a locked cabinet and can only be accessed by authorized personnel.

[0145] (2) Functional safety description: No functional safety is involved.

[0146] (3) Physical and logical access points: Interfaces include the interface from ETBN to ECN and the interface from ECN to OOS device.

[0147] (4) Data stream: OOS data exchanged via train-level Ethernet.

[0148] (5) Connected areas and pipes: train-level Ethernet area, vehicle-level OOS area.

[0149] (6) Assets: ETBN vehicle-grade interface, ECNN interface, OOS device interface, connectors, Ethernet cables.

[0150] 4. C4: Pipeline between vehicle-level TCMS area and vehicle-level OOS area

[0151] (1) Physical and logical boundaries: This conduit connects the vehicle-level TCMS area and the vehicle-level OOS area within the same group. The equipment in this conduit is located in a locked cabinet and can only be accessed by authorized personnel.

[0152] (2) Functional safety description: No functional safety is involved.

[0153] (3) Physical and logical access points: Interfaces include the interface from ECN to TCMS and the interface from ECN to OOS devices.

[0154] (4) Data flow: Non-functional safety-related data exchanged between TCMS devices and OOS devices via intra-group Ethernet.

[0155] (5) Connected areas and pipes: vehicle-level TCMS area, vehicle-level OOS area.

[0156] (6) Assets: ECNN interface, TCMS device interface, OOS device interface, connectors, Ethernet cables.

[0157] 5. C5: Piping between vehicle-level TCMS area and local maintenance area

[0158] (1) Physical and logical boundaries: This pipeline connects the vehicle-level TCMS area functional safety related equipment and the service equipment with maintenance applications directly connected to the equipment.

[0159] (2) Functional safety description: Functional safety related.

[0160] (3) Physical and logical access points: Interfaces include interfaces from functional safety-related TCMS devices to service devices.

[0161] (4) Data flow: Read diagnostic information, read and write configuration parameters, and download software.

[0162] (5) Connected areas and pipelines: vehicle-level TCMS area, local maintenance area.

[0163] (6) Assets: TCMS device interfaces and service device interfaces related to functional safety.

[0164] 6. C6: Piping between vehicle-level TCMS area and remote maintenance area

[0165] (1) Physical and logical boundaries: This pipeline connects non-functional safety-related equipment in the vehicle-level TCMS area to service equipment with maintenance applications connected to the equipment via the train network.

[0166] (2) Functional safety description: No functional safety is involved.

[0167] (3) Physical and logical access points: Interfaces include the interface from ECN to non-functional safety related TCMS devices and the interface from ECN to service devices.

[0168] (4) Data flow: Read diagnostic information, read and write configuration parameters, and download software.

[0169] (5) Connected areas and pipelines: vehicle-level TCMS area, remote maintenance area.

[0170] (6) Assets: ECNN interface, non-functional safety related TCMS device interface, service device interface, connectors, Ethernet cable.

[0171] 7. C7: Pipeline between vehicle-level TCMS area and vehicle-to-ground transmission area

[0172] (1) Physical and logical boundaries: This pipeline connects non-functional safety-related equipment and vehicle-mounted wireless transmission devices in the same group via group-level Ethernet connection in the vehicle-level TCMS area.

[0173] (2) Functional safety description: No functional safety is involved.

[0174] (3) Physical and logical access points: The interfaces include the interface from ECN to TCMS and the interface from ECN to the wireless transmission device.

[0175] (4) Data stream: Non-functional safety related TCMS train operation data, such as diagnostic information.

[0176] (5) Connected areas and pipelines: vehicle-level TCMS area, vehicle-to-ground transmission area.

[0177] (6) Assets: ECNN interface, non-functional safety related TCMS device interface, wireless transmission device interface, connectors, Ethernet cables.

[0178] 8. C8: Pipeline between vehicle-level OOS area and remote maintenance area

[0179] (1) Physical and logical boundaries: This pipeline connects vehicle-level OOS area equipment and service equipment with maintenance applications connected to the equipment via the train network.

[0180] (2) Functional safety description: No functional safety is involved.

[0181] (3) Physical and logical access points: Interfaces include the interface from ECN to OOS and the interface from ECN to service devices.

[0182] (4) Data flow: Read diagnostic information, read and write configuration parameters, and download software.

[0183] (5) Connected areas and pipelines: vehicle-level OOS area, remote maintenance area.

[0184] (6) Assets: ECNN interface, OOS device interface, service device interface, connectors, Ethernet cables.

[0185] 9. C9: Pipeline between vehicle-level OOS area and vehicle-to-ground transmission area

[0186] (1) Physical and logical boundaries: This pipeline connects vehicle-level OOS area devices and vehicle-mounted wireless transmission devices within the same group via group-level Ethernet.

[0187] (2) Functional safety description: No functional safety is involved.

[0188] (3) Physical and logical access points: The interfaces include the interface from ECN to OOS and the interface from ECN to wireless transmission devices.

[0189] (4) Data stream: Diagnostic information and video streams from OOS devices that need to be transmitted between the vehicle and the ground.

[0190] (5) Connected areas and pipelines: vehicle-level OOS area, vehicle-to-ground transmission area.

[0191] (6) Assets: ECNN interface, OOS device interface, wireless transmission device interface, connectors, Ethernet cables.

[0192] By defining physical and logical boundaries and access points, the communication boundaries of each area and conduit in the train network are identified, facilitating attack path identification and enabling scientific and effective vulnerability and risk analysis of the train network. Functional safety specifications define the correlation between each area and conduit in the train network and train functional safety, facilitating the identification of the functional safety importance of each area and conduit, the potential serious impact and consequences of an attack, and thus determining higher levels of network security requirements and strengthening security protection measures. Data flow defines the data information of each area and conduit, facilitating the identification of the specific functions implemented by each area and conduit. Assets define the equipment information contained in each area and conduit, identifying assets in different security domains of the train network.

[0193] The segmentation of train network areas and pipelines helps identify the assets included in the train network, the communication interfaces and data flows within the train network, and their functional safety-related importance, identifying assets with common safety requirements. This provides a solid foundation for systemic safety risk assessment of the train network, thereby ensuring the integrity and reliability of the safety risk assessment, facilitating the implementation of safety measures to mitigate cybersecurity risks, improving the stability of the train network, and ensuring the safe operation of trains.

[0194] In addition, the present invention also provides a train that applies the above-described train network security architecture.

[0195] Finally, it should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0196] The above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them; although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications can still be made to the specific implementation of the present invention or equivalent substitutions can be made to some technical features without departing from the spirit of the technical solutions of the present invention, and all such modifications and substitutions should be covered within the scope of the technical solutions claimed in the present invention.

Claims

1. A train network security architecture, characterized by, A method for analyzing and evaluating the network security status of a rail vehicle, comprising: a vehicle-level TCMS area including a first ECNN switch and a TCMS device connected to the first ECNN switch, the first ECNN switch being connected to a consist-level Ethernet and realizing data exchange; a vehicle-level OOS area including an OOS device and a second ECNN switch, the OOS device being connected to the second ECNN switch, the second ECNN switch being connected to the consist-level Ethernet and realizing data exchange; a maintenance area including a maintenance device connected to the TCMS device and the OOS device to respectively establish communication and perform maintenance functions; a train-ground transmission area including a vehicle-mounted wireless transmission device for data exchange between the train and a ground system; a fourth pipeline connecting the TCMS device and the OOS device for data exchange through the consist-level Ethernet; a seventh pipeline connecting the TCMS device and the vehicle-mounted wireless transmission device for exchanging TCMS-related data with the ground system; a ninth pipeline connecting the OOS device and the vehicle-mounted wireless transmission device for exchanging OOS-related data with the ground system; a train-level Ethernet area including an ETBN switch for communication between different consist trains during multi-consist reconnection; a first pipeline connecting different train-level Ethernet areas during multi-consist reconnection, i.e., connecting ETBN switches of different consists; a second pipeline connecting ETBN switches and the first ECNN switch within the same consist for exchanging TCMS data through the train-level Ethernet; a third pipeline connecting ETBN switches and the second ECNN switch within the same consist for exchanging OOS data through the train-level Ethernet.

2. The train network security architecture of claim 1, wherein, The TCMS device includes a functional safety TCMS device and a non-functional safety TCMS device; the seventh pipeline connects the non-functional safety TCMS device and the vehicle-mounted wireless transmission device; the maintenance area includes: a local maintenance area including a first maintenance device connected to the functional safety TCMS device to establish communication and perform maintenance functions; a remote maintenance area including a second maintenance device connected to the non-functional safety TCMS device and the OOS device to establish communication and perform maintenance functions.

3. The train network security architecture of claim 2, wherein, Further comprising: a fifth pipeline connecting the functional safety TCMS device and the first maintenance device for transmitting maintenance data of the functional safety-related TCMS device; a sixth pipeline connecting the non-functional safety TCMS device and the second maintenance device for transmitting maintenance data of the non-functional safety-related TCMS device; an eighth pipeline connecting the OOS device and the second maintenance device for transmitting maintenance data of the OOS device.

4. The train network security architecture of claim 3, wherein, The fifth, sixth, and eighth pipelines are provided with security verification when performing data communication.

5. The train network security architecture of claim 1, wherein, In the same consist train, the ETBN switch is provided with at least two, installed in the head car and tail car of the consist train; The train-level Ethernet area further comprises a repeater connected to the ETBN switch of the head car and the ETBN switch of the tail car of the same consist, for ensuring the communication quality of the train-level Ethernet data.

6. The train network security architecture of claim 5, wherein, The repeater is provided in multiple, installed in each of the remaining cars in the same consist except the head car and the tail car, the repeaters of adjacent cars are connected to each other, the repeater adjacent to the head car is connected to the ETBN switch of the head car, and the repeater adjacent to the tail car is connected to the ETBN switch of the tail car, forming a train-level Ethernet network.

7. The train network security architecture of claim 1, wherein, The OOS device comprises train maintenance devices and PIS network devices in the same consist.

8. The train network security architecture of claim 1, wherein, The OOS device and the TCMS device share a set of physical ECN networks.

9. A train characterised by A train network security architecture according to any one of claims 1-8.

Citation Information

Patent Citations

  • Train network architecture based on Ethernet deep fusion

    CN116389531A