Methods, devices, equipment and media for data security analysis of rail transit signaling systems
By establishing functional and data relationships among subsystems, interfaces, and peripheral systems within the rail transit signaling system, and combining top-level accident and guidance words, automated data safety analysis was achieved, solving the problem of low efficiency in existing technologies and improving analysis efficiency and accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TRAFFIC CONTROL TECH CO LTD
- Filing Date
- 2023-11-30
- Publication Date
- 2026-05-05
AI Technical Summary
In existing technologies, data security analysis of rail transit signaling systems is inefficient and prone to omissions, and manual analysis requires a huge amount of work.
By determining the functional relationships between subsystems, interfaces, and peripheral systems in the rail transit signaling system, and establishing data relationships, combined with top-level accident and guidance words, automated data security analysis can be achieved.
It has improved the efficiency and accuracy of data security analysis and enabled automated analysis of data security in rail transit signaling systems.
Smart Images

Figure CN117877134B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of rail transit technology, and in particular to a method, apparatus, equipment and medium for data security analysis of rail transit signaling systems. Background Technology
[0002] The amount of data transmitted between the various subsystems in a rail transit signaling system is enormous. This data is closely related to the realization of system functions and the safe implementation of system functions. Therefore, conducting security analysis on rail transit signaling system data is an important part of ensuring train operation safety.
[0003] In related technologies, security analysis of data in rail transit signaling systems is usually performed manually. However, due to the large amount of data in rail transit signaling systems, manual data security analysis is extremely labor-intensive, inefficient, and prone to omissions.
[0004] Therefore, how to achieve automated analysis of data security in rail transit signaling systems and improve the efficiency and accuracy of data security analysis has become a technical problem that the industry urgently needs to solve. Summary of the Invention
[0005] To address the problems existing in the prior art, the present invention provides a method, apparatus, equipment, and medium for data security analysis of rail transit signaling systems.
[0006] In a first aspect, the present invention provides a method for data security analysis of a rail transit signaling system, comprising:
[0007] Identify the subsystems, interfaces, and peripheral systems to be analyzed within the signaling system of rail transit;
[0008] Establish a first association relationship between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system; and establish a second association relationship between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the data of the interface.
[0009] Identify the top-level accident of the rail transit system and establish a third correlation between the top-level accident of the rail transit system, the pre-set guiding words of the top-level accident, and the functions of the subsystem.
[0010] Data security analysis is performed based on the first association, the second association, and the third association.
[0011] Among them, the top-level accidents of the rail transit include train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisonings.
[0012] The pre-set top-level incident prompts include: too early, too late, missing, error, too large, too small, on, and off.
[0013] Optionally, according to the data security analysis method for a rail transit signaling system provided by the present invention, the data security analysis based on the first correlation relationship, the second correlation relationship, and the third correlation relationship includes:
[0014] Based on the third association, a subset of hazards is established. The subset of hazards stores a first combination that can lead to a top-level accident of the rail transit. The first combination includes the top-level accident of the rail transit, the guiding words that can lead to the top-level accident, and the functions of the subsystem.
[0015] Based on the first association, the second association, and the subset of hazards, target data related to rail transit safety are determined;
[0016] Identify the lead words of the top-level incident associated with the target data, and determine whether the target data is security-side data based on the lead words of the top-level incident associated with the target data.
[0017] Optionally, according to the data security analysis method for rail transit signaling systems provided by the present invention, the step of determining the leading words of the top-level incident associated with the target data, and determining whether the target data is safety-side data based on the leading words of the top-level incident associated with the target data, includes:
[0018] A target data subset is established, which stores a second set of events that can lead to a top-level accident in the rail transit system. The second set of events includes the top-level accident in the rail transit system, a lead word for the top-level accident associated with the target data, and the target data itself.
[0019] Based on the target data subset, determine whether the target data is security-side data.
[0020] Optionally, according to the data security analysis method for rail transit signaling systems provided by the present invention, the step of determining whether the target data is security-related data based on the target data subset includes:
[0021] Determine the data type of each of the target data;
[0022] Based on the data type of each target data and the subset of target data, determine whether the target data is security-side data.
[0023] Optionally, according to the data security analysis method for rail transit signaling systems provided by the present invention, the data types include functional switch parameter types, time and distance parameter types, and mode switch parameter types.
[0024] Optionally, according to the data security analysis method for a rail transit signaling system provided by the present invention, the subsystem includes at least one of the following: on-board subsystem VOBC, interlocking subsystem CI, area controller subsystem ZC, data communication subsystem DCS, automatic train monitoring subsystem ATS, and transponder subsystem;
[0025] The interface includes at least one of the following: the interface between the vehicle-mounted subsystem VOBC and the vehicle; the interface between the vehicle-mounted subsystem VOBC and the driving operation terminal of the train driver; the interface between the area controller subsystem ZC and the interlocking subsystem CI; and the interface between the vehicle-mounted subsystem VOBC and the transponder subsystem.
[0026] The peripheral system includes at least one of the following: an information security system, a train driver's operating terminal, a dispatching terminal, vehicles, doors, and platform doors.
[0027] Secondly, the present invention also provides a data security analysis device for a rail transit signaling system, comprising:
[0028] The determination module is used to identify the subsystems, interfaces, and peripheral systems to be analyzed within the signaling system of rail transit.
[0029] The first establishment module is used to establish a first association relationship between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system, and to establish a second association relationship between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the data of the interface;
[0030] The second module is used to determine the top-level accident of the rail transit and establish a third association between the top-level accident of the rail transit, the pre-set guiding words of the top-level accident, and the functions of the subsystem.
[0031] The security analysis module is used to perform data security analysis based on the first association relationship, the second association relationship, and the third association relationship;
[0032] Among them, the top-level accidents of the rail transit include train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisonings.
[0033] The pre-set top-level incident prompts include: too early, too late, missing, error, too large, too small, on, and off.
[0034] Thirdly, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the data security analysis method for rail transit signaling systems as described in the first aspect.
[0035] Fourthly, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the data security analysis method for rail transit signaling systems as described in the first aspect.
[0036] Fifthly, the present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the data security analysis method for rail transit signaling systems as described in the first aspect.
[0037] The present invention provides a method, apparatus, equipment, and medium for data security analysis of rail transit signaling systems. This method first identifies the subsystems, interfaces, and peripheral systems included in the rail transit signaling system to be analyzed. Then, it establishes a first correlation between the functions of the subsystems, interfaces, and peripheral systems, and a second correlation between the functions of the subsystems, interfaces, and peripheral systems and the data of the subsystems and interfaces. Simultaneously, it identifies the top-level accident of the rail transit system and establishes a third correlation between the top-level accident, pre-set guidance words for the top-level accident, and the functions of the subsystems. Data security analysis is then performed based on these three correlations, effectively achieving automated analysis of data security in rail transit signaling systems and improving the efficiency and accuracy of data security analysis. Attached Figure Description
[0038] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0039] Figure 1 This is a flowchart illustrating the data security analysis method for rail transit signaling systems provided by the present invention;
[0040] Figure 2 This is a schematic diagram illustrating the relationships between subsystems, interfaces, and peripheral systems provided by this invention;
[0041] Figure 3 This is a schematic diagram of the structure of the data security analysis device for rail transit signaling systems provided by the present invention;
[0042] Figure 4 This is a schematic diagram of the physical structure of the electronic device provided by the present invention. Detailed Implementation
[0043] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0044] It should be noted that in the description of this invention, the terms "first," "second," etc., are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, the first object can be one or more.
[0045] The following description, in conjunction with the accompanying drawings, provides an exemplary introduction to the data security analysis method, apparatus, equipment, and medium for rail transit signaling systems provided by the present invention.
[0046] Figure 1 This is a flowchart illustrating the data security analysis method for rail transit signaling systems provided by the present invention, as shown below. Figure 1 As shown, the method includes:
[0047] Step 100: Identify the subsystems, interfaces, and peripheral systems to be analyzed within the signaling system of the rail transit system;
[0048] Step 110: Establish a first association relationship between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system; and establish a second association relationship between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the data of the interface.
[0049] Step 120: Determine the top-level accident of the rail transit system and establish a third correlation between the top-level accident of the rail transit system, the pre-set guiding words of the top-level accident, and the functions of the subsystem.
[0050] Step 130: Perform data security analysis based on the first association, the second association, and the third association;
[0051] Among them, the top-level accidents of the rail transit include train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisonings.
[0052] The pre-set top-level incident prompts include: too early, too late, missing, error, too large, too small, on, and off.
[0053] It should be noted that the execution subject of the rail transit signaling system data security analysis method provided in this embodiment of the invention can be an electronic device, a component in the electronic device, an integrated circuit, or a chip. The electronic device can be a mobile electronic device or a non-mobile electronic device. For example, a mobile electronic device can be a mobile phone, tablet computer, laptop computer, PDA, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc., while a non-mobile electronic device can be a server, network attached storage (NAS), personal computer (PC), television (TV), ATM, or self-service machine, etc. This embodiment of the invention does not specifically limit the specific implementation of these methods.
[0054] The following example, using a computer executing the data security analysis method for a rail transit signaling system provided by this invention, illustrates the technical solution of this invention in detail.
[0055] Specifically, to overcome the shortcomings of manual data security analysis in rail transit signaling systems, which is labor-intensive, inefficient, and prone to omissions, this invention first identifies the subsystems, interfaces, and peripheral systems to be analyzed within the rail transit signaling system. Then, it establishes a first correlation between the functions of the subsystems, interfaces, and peripheral systems, and a second correlation between the functions of the subsystems, interfaces, and peripheral systems and the data of the subsystems and interfaces. Simultaneously, it identifies the top-level accident in the rail transit system and establishes a third correlation between the top-level accident, pre-set top-level accident indicators, and the functions of the subsystems. Finally, based on these first, second, and third correlations, data security analysis is performed, effectively achieving automated analysis of data security in rail transit signaling systems and improving the efficiency and accuracy of data security analysis.
[0056] Optionally, the subsystems, interfaces, and peripheral systems included in the signaling system of rail transit can be identified first, and then, based on the data security analysis requirements, the subsystems, interfaces, and peripheral systems to be analyzed can be determined from all the subsystems, interfaces, and peripheral systems.
[0057] Optionally, the subsystem includes at least one of the following: Vehicle On Board Controller (VOBC), Computer Interlocking (CI), Zone Controller (ZC), Data Communications System (DCS), Automatic Train Supervision (ATS), and Transponder Subsystem;
[0058] The interface includes at least one of the following: the interface between the vehicle-mounted subsystem VOBC and the vehicle; the interface between the vehicle-mounted subsystem VOBC and the driving operation terminal of the train driver; the interface between the area controller subsystem ZC and the interlocking subsystem CI; and the interface between the vehicle-mounted subsystem VOBC and the transponder subsystem.
[0059] The peripheral system includes at least one of the following: an information security system, a train driver's operating terminal, a dispatching terminal, vehicles, doors, and platform doors.
[0060] Optionally, the specifications of the subsystems, interfaces, and peripheral systems to be analyzed can be parsed to obtain the requirements of each subsystem, interface, and peripheral system, and to determine the functions of each subsystem, interface, and peripheral system.
[0061] Optionally, after obtaining the functions of each subsystem, interface, and peripheral system, a primary association relationship can be established between the functions of each subsystem, interface, and peripheral system.
[0062] Optionally, the first association may include: (1) the association between the function of each subsystem and the function of each interface and the function of each peripheral system, wherein the function of the subsystem needs to be connected to the function of the peripheral system through the interface function; (2) the association between the function of each subsystem and the function of the interface and the function of each subsystem, wherein the function of the subsystem needs to be connected to the function of the subsystem through the interface function.
[0063] It should be noted that the connection between the functions of two peripheral systems is not within the scope of the system; if a connection is made, an error message will be displayed.
[0064] Optionally, the established first association can be checked, and if a connection error is found, an error connection message can be displayed.
[0065] Optionally, data from the subsystem to be analyzed and data from the interface to be analyzed can be obtained.
[0066] Optionally, after obtaining the data of each subsystem to be analyzed and the data of each interface to be analyzed, a second correlation relationship can be established between the functions of each subsystem, the functions of each interface, the functions of each peripheral system, and the data of each subsystem and each interface.
[0067] Optionally, the second association may include: (1) the association between the function of the subsystem and the data of the subsystem; (2) the association between the function of the subsystem and the data of the interface; (3) the association between the function of the interface and the data of the interface; (4) the association between the function of the interface and the data of the subsystem; (5) the association between the function of the peripheral system and the data of the interface; and (6) the association between the function of the peripheral system and the function of the interface.
[0068] It should be noted that the relationship between functions and data can be one function associated with one piece of data, or one function associated with multiple pieces of data.
[0069] It should be noted that the relationships between functions are directional. For example, the relationship between the function of a subsystem and the function of an interface is different from the relationship between the function of an interface and the function of a subsystem.
[0070] It should be noted that the relationship between data and function is not directional, and the relationship between data is not directional either.
[0071] It should be noted that the functions of a subsystem need to complete a closed loop of relationships, that is, starting from the functions of a certain subsystem, the connection needs to be completed so that the final relationship points to the functions of that subsystem. The functions of the peripheral systems do not need to complete a closed loop.
[0072] It should be noted that both the functions of the subsystem and the functions of the interface require corresponding data connections.
[0073] For example, Figure 2 This is a schematic diagram illustrating the relationships between subsystems, interfaces, and peripheral systems provided by the present invention. Figure 2 For example, the connection relationship of subsystem A's functions forms a closed loop connection, and the connection of subsystem B's functions also forms a closed loop connection. Interface functions A, B, and C all have corresponding data connections, that is, interface functions A are connected to interface A's data, interface functions B are connected to interface B's data, and interface functions C are connected to interface C's data.
[0074] Optionally, top-level accidents of rail transit can be obtained, including but not limited to: train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisonings.
[0075] Optionally, pre-set prompts that may lead to top-level accidents can be obtained, including but not limited to: too early, too late, missing, error, too large, too small, open, closed.
[0076] Optionally, after obtaining the top-level accident data, the leading words of the top-level accident data, and the functions of each subsystem of the rail transit system, a third correlation relationship can be established between the top-level accident data, the leading words of the top-level accident data, and the functions of each subsystem of the rail transit system.
[0077] Optionally, data security analysis of the rail transit signaling system can be conducted based on the first correlation between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system; the second correlation between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the interface; and the third correlation between the top-level accident of the rail transit, the guiding words of the top-level accident, and the functions of each subsystem.
[0078] The data security analysis method for rail transit signaling systems provided by this invention first identifies the subsystems, interfaces, and peripheral systems included in the rail transit signaling system. Then, it establishes a first correlation between the functions of the subsystems, interfaces, and peripheral systems, and a second correlation between the functions of the subsystems, interfaces, and peripheral systems and the data of the subsystems and interfaces. Simultaneously, it identifies the top-level accident of the rail transit system and establishes a third correlation between the top-level accident, pre-set guidance words for the top-level accident, and the functions of the subsystems. Data security analysis is then performed based on these first, second, and third correlations, effectively achieving automated analysis of data security in rail transit signaling systems and improving the efficiency and accuracy of data security analysis.
[0079] Optionally, the data security analysis based on the first association, the second association, and the third association includes:
[0080] Based on the third association, a subset of hazards is established. The subset of hazards stores a first combination that can lead to a top-level accident of the rail transit. The first combination includes the top-level accident of the rail transit, the guiding words that can lead to the top-level accident, and the functions of the subsystem.
[0081] Based on the first association, the second association, and the subset of hazards, target data related to rail transit safety are determined;
[0082] Identify the lead words of the top-level incident associated with the target data, and determine whether the target data is security-side data based on the lead words of the top-level incident associated with the target data.
[0083] Specifically, in this embodiment of the invention, in order to perform data security analysis based on the first association relationship, the second association relationship, and the third association relationship, a subset of hazards can first be established based on the third association relationship. This subset of hazards stores a first combination that can lead to a top-level accident in rail transit. The first combination includes a top-level accident in rail transit, a guide word that can lead to a top-level accident, and the function of a subsystem. Then, based on the first association relationship, the second association relationship, and the subset of hazards, target data related to rail transit safety is determined, and then the guide word of the top-level accident associated with the target data is determined. Based on the guide word of the top-level accident associated with the target data, it is determined whether the target data is safety-side data.
[0084] It should be noted that the established hazard source subset includes the complete set of combinations of top-level accidents, top-level accident prompts, and subsystem functions. The complete set includes all top-level accidents, top-level accident prompts, and subsystem functions. Based on prior experience, it is possible to determine whether top-level accident prompts and subsystem functions will lead to top-level accidents, thereby obtaining the first combination that can lead to top-level accidents.
[0085] It is understood that the embodiments of the present invention establish a subset of hazards through a third association relationship, and then determine target data related to rail transit safety based on the first association relationship, the second association relationship and the subset of hazards. In addition, the top-level accident guidance words associated with the target data are determined, and based on the top-level accident guidance words associated with the target data, it is determined whether the target data is safety-side data. This effectively realizes the automated analysis of data safety of rail transit signaling system, and the algorithm is simple and easy to implement.
[0086] Optionally, determining the lead word of the top-level incident associated with the target data, and judging whether the target data is security-side data based on the lead word of the top-level incident associated with the target data, includes:
[0087] A target data subset is established, which stores a second set of events that can lead to a top-level accident in the rail transit system. The second set of events includes the top-level accident in the rail transit system, a lead word for the top-level accident associated with the target data, and the target data itself.
[0088] Based on the target data subset, determine whether the target data is security-side data.
[0089] Specifically, in this embodiment of the invention, a target data subset can be established, which stores a second set that can lead to a top-level accident in rail transit. The second set includes a top-level accident in rail transit, a leading word of the top-level accident associated with the target data, and the target data. Then, based on the target data subset, it is determined whether each target data is safety-side data.
[0090] Understandably, based on the first correlation between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system, the second correlation between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the interface, as well as the aforementioned hazard source subset, data related to the hazard source subset can be identified, namely, target data related to rail transit safety. Then, a target data subset can be established, which contains all the guiding words and target data of top-level accidents. Based on prior experience, it can be determined whether the guiding words of top-level accidents and the data related to the hazard source subset will lead to top-level accidents, thereby obtaining a second combination that can lead to top-level accidents.
[0091] It is understood that the embodiments of the present invention establish a target data subset, which stores a second combination that can lead to a top-level accident in rail transit. The second combination includes the top-level accident in rail transit, the leading words of the top-level accident associated with the target data, and the target data. Based on this target data subset, it is determined whether each target data is safety-side data, which effectively realizes the automated analysis of data security of rail transit signaling system. Moreover, the algorithm is simple and easy to implement.
[0092] Optionally, determining whether the target data is security-side data based on the target data subset includes:
[0093] Determine the data type of each of the target data;
[0094] Based on the data type of each target data and the subset of target data, determine whether the target data is security-side data.
[0095] Specifically, in this embodiment of the invention, in order to determine whether target data is security data based on a subset of target data, the data type of each target data can be determined first, and then the data type and subset of target data can be used to determine whether each target data is security data.
[0096] Optionally, the data type includes function switch parameter type, time and distance parameter type, and mode switch parameter type.
[0097] Optionally, for target data of function switch parameter type, if the top-level fault initiator of the target data of function switch parameter type is determined to be "on", then the off function parameter is recorded as safety side data; if the top-level fault initiator of the target data of function switch parameter type is determined to be "off", then the on function parameter is recorded as safety side data; if the top-level fault initiator of the target data of function switch parameter type is determined to be neither "on" nor "off", then the system records a fault.
[0098] Optionally, for target data of time and distance parameter types, if the top-level fault indicator for the target data of this time and distance parameter type is determined to be "too large", then data less than the critical parameter is determined to be safe-side data; if the top-level fault indicator for the target data of this time and distance parameter type is determined to be "too small", then data greater than the critical parameter is determined to be safe-side data; if the top-level fault indicator for the target data of this time and distance parameter type is determined to be neither "too large" nor "too small", then the system records a fault.
[0099] Optionally, for target data of the mode switch parameter type, the security requirements in the security requirements library can be selected as the security requirements of the target data of the mode switch parameter type, and the security requirements of the target data of the mode switch parameter type can be determined as security side data.
[0100] It should be noted that the security requirements library can be obtained in advance, and it contains the security requirements that can be used.
[0101] Optionally, after the target data is analyzed, a subset of security-side data and system fault information can be obtained and output.
[0102] It is understood that the embodiments of the present invention effectively realize the automated analysis of data security of rail transit signaling systems by performing security-side judgments on target data according to different data types and forming security analysis results. Moreover, the algorithm is simple and easy to implement.
[0103] It should be noted that the purpose of this invention is to rapidly analyze safety-related data of rail transit signaling systems and to make safety-side determinations on the safety data. The core idea includes: identifying the subsystems, interfaces, and peripheral systems involved in the signaling system; based on the involved subsystems, interfaces, and peripheral systems, determining the relevant data of the subsystems and interfaces, and establishing the correlation between the functions of the subsystems and interfaces and the data; determining the safety side of the data based on the correlation between the functions of the subsystems and interfaces and the data; and forming the results of the safety analysis based on the above results. This invention can quickly locate safety-related data of rail transit signaling systems, improve the efficiency and accuracy of safety analysis, reduce the workload of manual safety analysis, reduce omissions in safety analysis, and facilitate the determination of the scope of impact of subsequent function and data changes.
[0104] The data security analysis method for rail transit signaling systems provided by this invention first identifies the subsystems, interfaces, and peripheral systems included in the rail transit signaling system. Then, it establishes a first correlation between the functions of the subsystems, interfaces, and peripheral systems, and a second correlation between the functions of the subsystems, interfaces, and peripheral systems and the data of the subsystems and interfaces. Simultaneously, it identifies the top-level accident of the rail transit system and establishes a third correlation between the top-level accident, pre-set guidance words for the top-level accident, and the functions of the subsystems. Data security analysis is then performed based on these first, second, and third correlations, effectively achieving automated analysis of data security in rail transit signaling systems and improving the efficiency and accuracy of data security analysis.
[0105] The following describes the data security analysis device for rail transit signaling systems provided by the present invention. The data security analysis device for rail transit signaling systems described below can be referred to in correspondence with the data security analysis method for rail transit signaling systems described above.
[0106] Figure 3 This is a schematic diagram of the structure of the data security analysis device for rail transit signaling systems provided by the present invention, as shown below. Figure 3 As shown, the device includes: a determination module 310, a first establishment module 320, a second establishment module 330, and a security analysis module 340; wherein:
[0107] The determination module 310 is used to determine the subsystems, interfaces, and peripheral systems to be analyzed included in the signaling system of rail transit;
[0108] The first establishment module 320 is used to establish a first association relationship between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system, and to establish a second association relationship between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the data of the interface;
[0109] The second establishment module 330 is used to determine the top-level accident of the rail transit and establish a third association relationship between the top-level accident of the rail transit, the pre-set top-level accident guide words and the functions of the subsystem;
[0110] The security analysis module 340 is used to perform data security analysis based on the first association relationship, the second association relationship, and the third association relationship;
[0111] Among them, the top-level accidents of the rail transit include train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisonings.
[0112] The pre-set top-level incident prompts include: too early, too late, missing, error, too large, too small, on, and off.
[0113] The rail transit signaling system data security analysis device provided by this invention first identifies the subsystems, interfaces, and peripheral systems included in the rail transit signaling system to be analyzed. Then, it establishes a first correlation between the functions of the subsystems, interfaces, and peripheral systems, and a second correlation between the functions of the subsystems, interfaces, and peripheral systems and the data of the subsystems and interfaces. Simultaneously, it identifies the top-level accident of the rail transit system and establishes a third correlation between the top-level accident, pre-set guidance words for the top-level accident, and the functions of the subsystems. Data security analysis is then performed based on the first, second, and third correlations, effectively realizing automated analysis of rail transit signaling system data security and improving the efficiency and accuracy of data security analysis.
[0114] It should be noted that the rail transit signal system data security analysis device provided in this embodiment of the invention can implement all the method steps implemented in the above-mentioned rail transit signal system data security analysis method embodiment, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0115] Figure 4 This is a schematic diagram of the physical structure of the electronic device provided by the present invention, such as... Figure 4As shown, the electronic device may include: a processor 410, a communication interface 420, a memory 430, and a communication bus 440, wherein the processor 410, the communication interface 420, and the memory 430 communicate with each other via the communication bus 440. The processor 410 can call logical instructions in the memory 430 to execute the rail transit signaling system data security analysis method provided by the above methods, which includes:
[0116] Identify the subsystems, interfaces, and peripheral systems to be analyzed within the signaling system of rail transit;
[0117] Establish a first association relationship between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system; and establish a second association relationship between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the data of the interface.
[0118] Identify the top-level accident of the rail transit system and establish a third correlation between the top-level accident of the rail transit system, the pre-set guiding words of the top-level accident, and the functions of the subsystem.
[0119] Data security analysis is performed based on the first association, the second association, and the third association.
[0120] Among them, the top-level accidents of the rail transit include train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisonings.
[0121] The pre-set top-level incident prompts include: too early, too late, missing, error, too large, too small, on, and off.
[0122] Furthermore, the logical instructions in the aforementioned memory 430 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0123] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions, wherein when the program instructions are executed by a computer, the computer is able to execute the rail transit signaling system data security analysis method provided by the above methods, the method comprising:
[0124] Identify the subsystems, interfaces, and peripheral systems to be analyzed within the signaling system of rail transit;
[0125] Establish a first association relationship between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system; and establish a second association relationship between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the data of the interface.
[0126] Identify the top-level accident of the rail transit system and establish a third correlation between the top-level accident of the rail transit system, the pre-set guiding words of the top-level accident, and the functions of the subsystem.
[0127] Data security analysis is performed based on the first association, the second association, and the third association.
[0128] Among them, the top-level accidents of the rail transit include train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisonings.
[0129] The pre-set top-level incident prompts include: too early, too late, missing, error, too large, too small, on, and off.
[0130] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the aforementioned rail transit signaling system data security analysis methods, the method comprising:
[0131] Identify the subsystems, interfaces, and peripheral systems to be analyzed within the signaling system of rail transit;
[0132] Establish a first association relationship between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system; and establish a second association relationship between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the data of the interface.
[0133] Identify the top-level accident of the rail transit system and establish a third correlation between the top-level accident of the rail transit system, the pre-set guiding words of the top-level accident, and the functions of the subsystem.
[0134] Data security analysis is performed based on the first association, the second association, and the third association.
[0135] Among them, the top-level accidents of the rail transit include train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisonings.
[0136] The pre-set top-level incident prompts include: too early, too late, missing, error, too large, too small, on, and off.
[0137] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0138] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0139] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A data security analysis method for rail transit signaling systems, characterized in that, include: Identify the subsystems, interfaces, and peripheral systems to be analyzed within the signaling system of rail transit; Establish a first association relationship between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system; and establish a second association relationship between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the data of the interface. Identify the top-level accident of the rail transit system and establish a third correlation between the top-level accident of the rail transit system, the pre-set guiding words of the top-level accident, and the functions of the subsystem. Data security analysis is performed based on the first association, the second association, and the third association. Among them, the top-level accidents of the rail transit include train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisoning accidents. The pre-set top-level incident prompts include: too early, too late, missing, error, too large, too small, on, and off.
2. The data security analysis method for rail transit signaling systems according to claim 1, characterized in that, The data security analysis based on the first association, the second association, and the third association includes: Based on the third association, a subset of hazards is established. The subset of hazards stores a first combination that can lead to a top-level accident of the rail transit. The first combination includes the top-level accident of the rail transit, the guiding words that can lead to the top-level accident, and the functions of the subsystem. Based on the first association, the second association, and the subset of hazards, target data related to rail transit safety are determined; Identify the lead words of the top-level incident associated with the target data, and determine whether the target data is security-side data based on the lead words of the top-level incident associated with the target data.
3. The data security analysis method for rail transit signaling systems according to claim 2, characterized in that, The step of determining the lead word of the top-level incident associated with the target data, and determining whether the target data is security-side data based on the lead word of the top-level incident associated with the target data, includes: A target data subset is established, which stores a second set of events that can lead to a top-level accident in the rail transit system. The second set of events includes the top-level accident in the rail transit system, a lead word for the top-level accident associated with the target data, and the target data itself. Based on the target data subset, determine whether the target data is security-side data.
4. The data security analysis method for rail transit signaling systems according to claim 3, characterized in that, The step of determining whether the target data is security-side data based on the target data subset includes: Determine the data type of each of the target data; Based on the data type of each target data and the subset of target data, determine whether the target data is security-side data.
5. The data security analysis method for rail transit signaling systems according to claim 4, characterized in that, The data types include function switch parameter types, time and distance parameter types, and mode switch parameter types.
6. The data security analysis method for rail transit signaling systems according to claim 1, characterized in that, The subsystem includes at least one of the following: onboard subsystem VOBC, interlocking subsystem CI, area controller subsystem ZC, data communication subsystem DCS, automatic train monitoring subsystem ATS, and transponder subsystem; The interface includes at least one of the following: the interface between the vehicle-mounted subsystem VOBC and the vehicle; the interface between the vehicle-mounted subsystem VOBC and the driving operation terminal of the train driver; the interface between the area controller subsystem ZC and the interlocking subsystem CI; and the interface between the vehicle-mounted subsystem VOBC and the transponder subsystem. The peripheral system includes at least one of the following: an information security system, a train driver's operating terminal, a dispatching terminal, vehicles, doors, and platform doors.
7. A data security analysis device for a rail transit signaling system, characterized in that, include: The determination module is used to identify the subsystems, interfaces, and peripheral systems to be analyzed within the signaling system of rail transit. The first establishment module is used to establish a first association relationship between the functions of the subsystem, the functions of the interface, and the functions of the peripheral system, and to establish a second association relationship between the functions of the subsystem, the functions of the interface, the functions of the peripheral system, and the data of the subsystem and the data of the interface; The second module is used to determine the top-level accident of the rail transit and establish a third association between the top-level accident of the rail transit, the pre-set guiding words of the top-level accident, and the functions of the subsystem. The security analysis module is used to perform data security analysis based on the first association relationship, the second association relationship, and the third association relationship; Among them, the top-level accidents of the rail transit include train-to-train collisions, train-to-obstacle collisions, train derailments, injuries to passengers caused by train doors and platform screen doors, electric shocks, and poisoning accidents. The pre-set top-level incident prompts include: too early, too late, missing, error, too large, too small, on, and off.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the data security analysis method for rail transit signaling systems as described in any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the data security analysis method for rail transit signaling systems as described in any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the data security analysis method for rail transit signaling systems as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Risk coupling analysis method of high-speed train control system complex operation scene
CN108920846A
Equipment full-life-cycle resume tracking and fault correlation analysis method and device
CN114091696A