Intensive integrated train on-board network information security protection system
By integrating the design of the train's onboard network system into a unified system through intensive integrated design and software-defined networking technology, the safety protection equipment in the train's onboard network system is integrated into a unified system, which solves the problem of isolated operation of equipment in the existing technology, realizes efficient and collaborative safety protection, and improves the system's security and performance.
Patent Information
- Application Number
- CN202410254949.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-06
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-03-06
AI Technical Summary
The security protection devices in the existing train onboard network system work in isolation, which cannot achieve effective information sharing and collaborative protection. They lack initiative and the ability to predict attacks, making it difficult to deal with attacks that exploit logical flaws.
Adopting an integrated design, multiple dispersed network security protection devices are integrated into a unified system. Through management modules, policy distribution modules, and security protection control modules, and by utilizing software-defined networking (SDN) and virtualization slicing technology, security protection policies are dynamically bound to the CPU kernel, thereby achieving decoupling of security components and software-based deployment, and realizing efficient resource management and collaborative protection.
It improves the security and performance of the train's onboard network system, reduces the space and weight of the equipment, and enhances the response capability to network attacks and resource utilization.
Smart Images

Figure CN118381624B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of train safety protection technology, and in particular to an intensive integrated train on-board network information security protection system. BACKGROUND
[0002] The current network information security system mainly consists of a firewall, security audit and virus detection, referred to as the "old three". In the on-board network system, security protection is mainly achieved by deploying a firewall and security audit products, and each product works in isolation, cannot achieve effective information sharing, capacity sharing and collaborative work, and lacks initiative and prediction ability for attacks, making it difficult to deal with attacks using logical defects.
[0003] With the application of cloud computing, Internet of Things, mobile Internet and big data technologies, current network attacks have the characteristics of directionality, concealment, diversified attack means and diversified technologies. The number of connected devices inside the train is increasing. This provides more potential entry points for malicious attackers, and network attacks can cause train functions to be damaged, information to be leaked or operation to be interrupted. Protecting the security of the train on-board network helps to prevent unauthorized access and malicious operations, and maintains the normal operation of the train and the safety of passengers.
[0004] The intensive integrated linkage protection control system is organically combined with hardware devices and network defense systems. When an attack occurs, it does not rely on a single system to respond. By analyzing the attack behavior, it intelligently selects a reasonable defense means, and selects a hardware device that matches the attack type to stop the attack behavior. Through the means of linkage protection control, network resources can be protected to a greater extent, and network performance can be improved.
[0005] At present, the disadvantages of the security protection devices in the train on-board network system in the prior art include:
[0006] The security protection devices in the train on-board network system currently work in isolation, cannot achieve effective information sharing and collaborative linkage protection, and lack initiative and prediction ability for attacks, making it difficult to deal with attacks caused by logical defects.
[0007] The current network security protection devices, such as network isolation devices, intrusion detection devices, security audit devices, access control devices and data encryption devices, are designed independently, and each device uses separate hardware. The devices are relatively independent, and if deployed in the train on-board network system, they not only occupy space, but also increase the weight of the train itself. SUMMARY
[0008] The embodiments of the present application provide an intensive integrated train on-board network information security protection system to effectively improve the performance and security of the train on-board network system.
[0009] To achieve the above object, the present application adopts the following technical scheme.
[0010] An intensive integrated train on-board network information security protection system comprises a management module, a policy distribution module and a security protection control module.
[0011] The management module is used for managing the configuration, state and resources of the train on-board network information security protection system, providing a user with an operation interface of a security protection policy component, and receiving and managing a security protection policy dynamically customized by the user through the operation interface.
[0012] The policy distribution module is used for configuring the security protection policy into a programmable software module, dynamically binding the security protection policy with a CPU kernel of the intensive integrated train on-board network information security protection system, and dynamically deploying the security protection policy to a relevant hardware device according to a requirement.
[0013] The security protection control module is used for dividing a network security protection function into a plurality of independent security components by using a software defined network (SDN), decoupling the security components from the hardware device, configuring the security components into programmable software modules, deploying each security component in the form of a software module on the hardware device, setting a corresponding security protection policy for each security component, and executing the security protection policy on the security component of the hardware device.
[0014] Preferably, the system further comprises a calculation module, a rule library module, an authentication and authorization module, an encryption and decryption module, a scheduling module and an interface module.
[0015] The calculation module is used for processing a calculation task related to security protection, and monitoring various security events and threats in the system.
[0016] The rule library module is used for storing security rules and security protection policies of the train on-board network.
[0017] The authentication and authorization module is used for verifying and authorizing devices and users connected to the on-board network, and ensuring that only authorized devices and users can access the train on-board network.
[0018] The encryption and decryption module is used for performing a data encryption and decryption task.
[0019] The scheduling module is used for assigning a task to different CPU kernels of the intensive integrated train on-board network information security protection system for execution, scheduling the task and allocating resources according to a binding policy and real-time requirements, and coordinating and managing the work of each module.
[0020] The interface module is used for providing an interface for the security protection system of the intensive integrated train on-board network information to interact with other systems and devices.
[0021] Preferably, the management module comprises a resource management module, a business scenario task and CPU binding module and a security protection policy component module.
[0022] The resource management module is used for managing the configuration, state and resources of the security protection system.
[0023] The business scenario task and CPU binding module is used for determining on which CPU core each business scenario task runs according to the system configuration and runtime performance index, dynamically determining the binding relationship between the business scenario task and the CPU core through the scheduling strategy and the application programming interface (API) provided by the operating system, and monitoring the change of the binding relationship between the business scenario task and the CPU core.
[0024] The security protection policy component module is used for configuring and managing the security protection policy component, wherein the security protection policy component comprises:
[0025] A policy controller is used for providing an operation interface for a user to dynamically customize the security protection policy of the train through the operation interface.
[0026] A dynamic policy analysis module is used for determining the security protection policy according to the task in the business scenario to be executed, querying whether the corresponding security protection policy is stored in a policy library, if yes, directly selecting the corresponding security protection policy from the policy library, otherwise, querying a component library, selecting various component information capable of being used to generate the security protection policy, the component information comprising the code and name information of the component, and sending a reconstruction message carrying the various component information to a reconstructor.
[0027] The reconstructor is used for reading the component information carried in the reconstruction message, activating the corresponding component in the component library according to the component information, and displaying the component in a tree type, a user directly selecting the corresponding component function on the tree type display of the component to generate a new security protection policy, and storing the generated security protection policy in the policy library.
[0028] The policy library is used for storing the security protection policy of the train in the form of a policy table.
[0029] The component library is used for storing various components used to generate the security protection policy of the train.
[0030] Preferably, the security protection control module comprises:
[0031] The security component generation module is configured to divide the network security protection function into various security components including an access control function, a packet filtering function, an intrusion detection function, a security audit function, a vulnerability scanning, a load balancing, an encryption and decryption function, an identity authentication function, a monitoring management function and a situation awareness function, decouple the security components from a traditional hardware device, configure the security components as programmable software modules, deploy and run each security component in the form of software on the hardware device, and add the security components according to the needs of the business.
[0032] The security protection policy execution module is configured to execute the security protection policy deployed on the security components, slices and hardware devices through the CPU core bound by the security protection policy, and the security protection policy execution and upgrade maintenance processes of the various security components and slices are independent of each other.
[0033] Preferably, the security component generation module is configured to set multiple security components for one security protection function, and store the correspondence between the security protection function and the security components. The corresponding security protection policy is set for each security component as needed, one security component and the corresponding security protection policy form a security protection unit; when a hardware device needs to implement a security protection function, a group of security protection units is set on the hardware device; when a hardware device needs to implement multiple security protection functions, multiple groups of security protection units are set on the hardware device.
[0034] The security protection policy execution module is configured to, when a certain security protection function needs to be performed, query the correspondence between the security protection function and the security components, select multiple security components corresponding to the certain security protection function, and then query the rule library module to configure the corresponding security protection policy for each selected security component as needed, set multiple security protection units for the certain security protection function, and realize dynamic redundant protection through intelligent linkage of the multiple security protection units.
[0035] Preferably, the policy distribution module includes:
[0036] The security protection policy decoupling module is configured to decouple the security protection policy from a traditional device based on SDN using a virtualization slicing technology, configure the security protection policy as a programmable software module, and dynamically bind the security protection policy with the CPU core of the security protection system of the intensive integrated train on-board network information, wherein the security protection policy includes a network isolation policy, an authentication and authorization policy, an encrypted communication policy and an update and vulnerability repair policy.
[0037] A network resource segmentation module is configured to logically abstract and multiplex network resources by using a virtualization slicing technology, divide the network resources into a plurality of virtual instances by using a virtualization software layer, each virtual instance corresponds to a slice, and configure a corresponding security protection strategy for each slice;
[0038] A security protection strategy deployment module is configured to dynamically bind the security protection strategy with a CPU core of a security protection system of the intensive integrated train onboard network information, dynamically configure and deploy the security protection strategy according to requirements, and deploy a corresponding security protection strategy for each security component, slice and hardware device.
[0039] Preferably, the security protection strategy decoupling module is configured to dynamically bind the security protection strategy with a CPU core of the security protection system of the intensive integrated train onboard network information at a hardware level and a software level. At the hardware level, the CPU has a plurality of physical cores and logical cores, each physical core has a cache and an execution unit, and the logical cores are implemented by a hyper-threading technology. At the software level, the operating system schedules tasks to be executed on different CPU cores, and dynamically binds specific business scenario tasks with the CPU cores by using a scheduling strategy and an API provided by the operating system.
[0040] Preferably, the policy distribution module adopts a virtualization slicing technology, and the system includes a physical host, a virtual machine, a virtualization software and a management interface.
[0041] The physical host is configured to provide a physical server of a computing resource.
[0042] The virtual machine is configured to be an independent virtual instance running on the physical host, and each virtual machine has its own operating system and application program.
[0043] The virtualization software is configured to manage and control the creation, destruction, migration and monitoring of the virtual machine, one-to-one map the CPU core of the security protection system of the intensive integrated train onboard network information to a virtual machine vCPU by using a Docker application container engine, and dynamically bind the security protection strategy with the virtual machine vCPU.
[0044] The management interface is configured to be an interface for managing and configuring the virtual machine, and is operated by using a command line or a graphical interface.
[0045] Preferably, the network isolation strategy divides the onboard network in the train into different security areas, and each area is network-isolated by access control.
[0046] The authentication and authorization strategy implements an authentication and authorization mechanism, only verified users can access the vehicle-mounted network, and the access rights of the users are limited to ensure legal access.
[0047] The encryption communication strategy encrypts the communication in the train network, including data transmission encryption and identity authentication encryption.
[0048] The update and vulnerability repair strategy updates the software and operating system in the train network, and patches known vulnerabilities.
[0049] Preferably, the system is deployed at the vehicle-level switch of the train head car and the tail car.
[0050] As can be seen from the technical solutions provided by the above embodiments of the present application, the train-mounted network information security protection system of the present application integrates multiple dispersed network security protection devices into a unified system through intensive integrated design, improves efficiency, reduces cost, and enhances the security of train-mounted network information through centralized management and control.
[0051] Additional aspects and advantages of the present application will be described in the following description, which will become apparent from the following description, or will be learned by practice of the present application. BRIEF DESCRIPTION OF DRAWINGS
[0052] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0053] Figure 1 A structure diagram of an intensive integrated train-mounted network information security protection system provided by the embodiment of the present application;
[0054] Figure 2 A structure diagram of a management module provided by the embodiment of the present application;
[0055] Figure 3 A structure diagram of a security protection strategy component provided by the embodiment of the present application;
[0056] Figure 4 A structure diagram of a security protection control module provided by the embodiment of the present application;
[0057] Figure 5 A schematic diagram of setting one or more groups of security protection units on a hardware device provided by the embodiment of the present application;
[0058] Figure 6A structural diagram of a policy distribution module provided by an embodiment of the present application is provided.
[0059] Figure 7 A schematic diagram of binding of a security protection policy to a CPU core of an intensive integrated train on-board network information security protection system provided by an embodiment of the present application is provided.
[0060] Figure 8 A deployment position schematic diagram of an intensive integrated train on-board network information security protection system provided by an embodiment of the present application is provided. DETAILED DESCRIPTION
[0061] Embodiments of the present application are described in detail below with reference to the attached drawings, which show by way of example, embodiments in which like numerals indicate like elements or elements having the same or similar function throughout the several views. The embodiments described below are exemplary only and are not to be construed as limiting the present application.
[0062] It should be understood by those skilled in the art that the singular forms "a," "an," and "the" include plural referents unless the context clearly dictates otherwise. It should be further understood that the terms "comprises," "comprising," "includes," "including," "contains," "containing," "consists," "consisting," and "consisting essentially of" when used in the specification and claims, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we refer to one element being "connected" or "coupled" to another element, it can be directly connected or coupled to the other element or intervening elements can also be present. In addition, the use of "connection" or "coupling" herein also includes wireless connection or coupling. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0063] It should be understood by those skilled in the art that all terms used herein, including technical and scientific terms, have the same meaning as commonly understood by one of ordinary skill in the art to which the present application pertains, unless otherwise defined. It should also be understood that terms such as those defined in a general dictionary should be understood to have meanings consistent with those in the context of the present technology, and should not be interpreted in an idealized or overly formal sense unless otherwise defined as such.
[0064] For the sake of understanding the embodiments of the present application, further explanation and description will be made below with reference to the accompanying drawings in conjunction with several specific embodiments, and each embodiment does not constitute a limitation on the embodiments of the present application.
[0065] The embodiment of the present application provides an intensive integrated train on-board network information security protection system.
[0066] The structure of the intensive integrated train on-board network information security protection system provided by the embodiment of the present application is shown as Figure 1 The modules are as follows:
[0067] The management module is used for managing the configuration, state and resource of the whole train on-board network information security protection system, providing an operation interface of a security protection strategy component for a user, receiving and storing a security protection strategy dynamically customized by the user through the operation interface, being responsible for the binding relationship between a business scene task and a CPU core, determining the CPU core on which each business scene task should run according to system configuration and running time performance indexes, monitoring the change of the binding relationship between the business scene task and the CPU core and timely adjusting, and also including user permission management, system updating and maintenance.
[0068] The security protection control module is used for executing a security protection strategy, controlling and scheduling a network security protection function in real time, automatically optimizing and configuring the network security protection function according to network demand, and ensuring the stability and reliability of the network.
[0069] In actual application, the corresponding security protection strategy can be set for each security component, the corresponding security configuration and protection measure can be taken for each security component, the isolation and protection between resources are realized, the upgrade and maintenance of each security component are independent, the upgrade of a certain security component does not affect the operation of other security components, each security component is uniformly managed and single sign-on, the security component is flexibly added and the corresponding security protection strategy is flexibly set for the security component along with the rapid change of the business, the customized security protection measure is provided, the security risk is reduced, the risk of being attacked is reduced, and the security of network resources is protected.
[0070] The resources in the network are divided into multiple independent slices according to security requirements and levels. In actual application, a corresponding security protection strategy can be set for each slice, and different security protection strategies are configured to realize flexible management of each slice and isolation and protection between resources.
[0071] The policy distribution module is used to distribute the preset security protection strategy to related devices and nodes to ensure the safety of the train onboard network. Based on SDN, the security protection strategy is decoupled from the traditional device by using the virtualization slicing technology, and the security protection strategy is configured as a programmable software module. The security protection strategy is dynamically bound with the CPU (Central Processing Unit) core of the safety protection system of the intensive integrated train onboard network information, and the security protection strategy is dynamically configured and deployed according to the requirements to improve the system performance and resource utilization.
[0072] The above-mentioned computing module is used to process the computing tasks related to security protection, monitor various security events and threats in the system, such as intrusion detection, abnormal behavior detection, etc., and analyze these security events in real time to identify threats and respond accordingly.
[0073] The above-mentioned rule base module is used to store the security rules and security protection strategies of the train onboard network for reference and use by other modules.
[0074] The authentication and authorization module is used to verify and authorize devices and users connected to the onboard network to ensure that only authorized devices and users can access the train network.
[0075] The encryption and decryption module is used to perform data encryption and decryption tasks. When transmitting sensitive data or storing sensitive information, it can use encryption algorithms to protect the data from being accessed and tampered with by unauthorized personnel.
[0076] The scheduling module is used to assign tasks to different CPU cores of the safety protection system of the intensive integrated train onboard network information for execution. According to the binding strategy and real-time requirements, the task scheduling and resource allocation are performed to maximize the system performance and resource utilization. The module coordinates and manages the work of each module to ensure the normal operation and collaborative operation of the system, schedules the protection strategies including access control, traffic filtering, permission management, etc. to ensure the safety of the system and its related resources.
[0077] The interface module is used to provide an interface for the safety protection system of the intensive integrated train onboard network information to interact with other systems and devices, including interacting with the train control system and various security protection modules to realize information sharing and data transmission.
[0078] The structure of the management module provided by the embodiment of the application is shown in Figure 2 and comprises a resource management module, a business scenario task and CPU binding module and a security protection policy component module.
[0079] The resource management module is used for managing the configuration, state and resources of the security protection system.
[0080] The business scenario task and CPU binding module is used for determining, according to the system configuration and runtime performance index, on which CPU core of the intensive integrated train on-board network information security protection system each business scenario task runs, dynamically determining the binding relationship between the business scenario task and the CPU core through the scheduling strategy and the application programming interface (API) provided by the operating system, and monitoring the change of the binding relationship between the business scenario task and the CPU core.
[0081] The business scenario task and CPU binding of the embodiment of the application involves two levels: a hardware level and a software level.
[0082] At the hardware level, the CPU of the intensive integrated train on-board network information security protection system has a plurality of physical cores and logical cores. Each physical core has a cache and an execution unit and can independently execute instructions. The logical core is realized through the super-threading technology, a plurality of virtual cores are created on the physical core, and higher degree parallel processing is realized.
[0083] At the software level, the operating system is responsible for scheduling tasks to different CPU cores for execution. By binding a specific business scenario task to a CPU core, core resources can be effectively utilized, and resource competition and performance bottlenecks can be avoided.
[0084] The business scenario task and CPU binding mode adopts a dynamic binding mode, according to the real-time protection business scenario task demand of the on-board network security, dynamically allocates tasks to appropriate CPU cores. Control is performed through the scheduling strategy and the API (Application Programming Interface) provided by the operating system.
[0085] The advantage of dynamic binding is that resources can be flexibly allocated according to actual conditions.
[0086] The security protection policy component module is used for configuring and managing the security protection policy component. The structure of the security protection policy component provided by the embodiment of the application is shown in Figure 3 and comprises the following modules:
[0087] The policy controller is used for providing an operation interface for a user, and the user can dynamically customize the security protection policy of the train through the operation interface.
[0088] a dynamic policy analysis module, configured to determine a security protection policy according to a task in a service scenario to be executed, query whether the corresponding security protection policy is stored in a policy library, if yes, directly select the corresponding security protection policy from the policy library, otherwise, query a component library, select various component information capable of being used to generate the security protection policy, the component information including coding and name information of the component, and send a reconstruction message carrying the various component information to a reconstructor.
[0089] the reconstructor, configured to read the component information carried in the reconstruction message, activate corresponding components in the component library according to the component information, and display the components in a tree type, so that a user can directly select corresponding component functions in the form of the tree type display to generate a new security protection policy, and store the generated security protection policy in the policy library.
[0090] The policy library stores the security protection policy of the train in the form of a policy table. The update of the policy library can be manually added by an administrator, or the policy generated by the dynamic customization can be automatically added to the policy library after being evaluated by the evaluation component, to complete the update of the policy library.
[0091] The component library stores various components capable of being used to generate the security protection policy of the train.
[0092] The security protection policy component includes:
[0093] a policy controller, configured to provide an operation interface for a user to dynamically customize the security protection policy of the train;
[0094] the dynamic policy analysis module, configured to determine a security protection policy according to a task in a service scenario to be executed, query whether the corresponding security protection policy is stored in a policy library, if yes, directly select the corresponding security protection policy from the policy library, otherwise, query a component library, select various component information capable of being used to generate the security protection policy, the component information including coding and name information of the component, and send a reconstruction message carrying the various component information to a reconstructor;
[0095] the reconstructor, configured to read the component information carried in the reconstruction message, activate corresponding components in the component library according to the component information, and display the components in a tree type, so that a user can directly select corresponding component functions in the form of the tree type display to generate a new security protection policy, and store the generated security protection policy in the policy library.
[0096] the policy library, configured to store the security protection policy of the train in the form of a policy table;
[0097] The component library is configured to store various components capable of being used to generate the security protection policy of the train.
[0098] A structural diagram of a security protection control module provided by an embodiment of the present application is shown in Figure 4 The security protection control module comprises the following modules:
[0099] A security component generation module is configured to divide network security protection functions into security components including access control functions, packet filtering functions, intrusion detection functions, security audit functions, vulnerability scanning, load balancing, encryption and decryption functions, identity authentication functions, monitoring management functions and situation awareness functions by using SDN, decouple the security components from traditional hardware devices, configure the security components as programmable software modules, deploy and run each security component in the form of software on the hardware devices, and add security components according to the needs of a business.
[0100] Multiple security components can be set for one security protection function, and the correspondence between the security protection function and the security components is stored in the security protection control module. A corresponding security protection policy is set for each security component as needed, and one security component and the corresponding security protection policy constitute a security protection unit. Therefore, multiple security protection units can be set for one security protection function, and when one hardware device needs to implement one security protection function, a group of security protection units is set on the hardware device. When one hardware device needs to implement multiple security protection functions, multiple groups of security protection units are set on the hardware device. Figure 5 A schematic diagram of setting one group or multiple groups of security protection units on one hardware device is provided by the embodiment of the present application. The multiple security protection units achieve redundant protection through intelligent linkage, comparison between the security protection units, efficient, dynamic and redundant protection of the train-borne network system, and intelligent joint defense and control and active defense. The above-mentioned intensive integrated train-borne network information security protection system combines network devices and network defense systems organically. When an attack behavior occurs, the attack behavior is analyzed, and multiple groups of security protection units and hardware device schemes are intelligently selected to form multiple different defense means. Thus, the attack behavior is prevented, and not only a single security protection unit is relied on to respond. Through the means of linkage protection control, network resources can be protected to a greater extent, and network performance can be improved.
[0101] A security protection policy execution module is configured to execute the security protection policy deployed on the security components, slices and hardware devices by the CPU core of the intensive integrated train-borne network information security protection system bound by the security protection policy, and the security protection policy execution and upgrade maintenance processes of each security component and slice are independent of each other.
[0102] When a certain security protection function needs to be performed, such as protection of intrusion detection, the security protection control module queries the correspondence between the security protection function and the security component, and selects a plurality of security components corresponding to the security protection function. Then, the rule library module is queried, and a corresponding security protection strategy is configured for each selected security component as needed. Therefore, a plurality of security protection units are set for the certain security protection function, and the plurality of security protection units can protect network resources to a greater extent through the means of linkage protection control.
[0103] A structural diagram of a policy distribution module provided by an embodiment of the present application is shown in Figure 6 The policy distribution module comprises the following modules:
[0104] A security protection strategy decoupling module is configured to decouple the security protection strategy from a traditional device based on SDN using a virtualization slicing technology, configure the security protection strategy as a programmable software module, and dynamically bind the security protection strategy with a CPU core, wherein the security protection strategy comprises a network isolation strategy, an authentication and authorization strategy, an encrypted communication strategy, and an update and vulnerability repair strategy.
[0105] A network resource segmentation module is configured to logically abstract and multiplex network resources using a virtualization slicing technology, divide the network resources into a plurality of virtual instances using a virtualization software layer, and configure each slice with a corresponding security protection strategy.
[0106] A security protection strategy deployment module is configured to dynamically bind the security protection strategy with a CPU core of the security protection system of the intensive integrated train onboard network information, dynamically configure and deploy the security protection strategy according to requirements, and deploy a corresponding security protection strategy for each security component, slice, and hardware device. Figure 7 A schematic diagram of the binding of the security protection strategy with the CPU core of the security protection system of the intensive integrated train onboard network information is provided by an embodiment of the present application.
[0107] Specifically, the security protection strategy decoupling module separates the network security control plane from the data forwarding plane using the SDN architecture paradigm. In a traditional network architecture, hardware devices contain control logic and data forwarding functions, resulting in complex network management and configuration. SDN, however, centralizes network control logic in one or more controllers, enabling centralized control and management of the entire network. This separated architecture makes the network more programmable and flexible, allowing dynamic configuration and optimization of network traffic according to application requirements. SDF technology implements network functions as software, which can be deployed and run on hardware devices, reducing the number of physical devices and maintenance costs. At the same time, SDF technology can dynamically deploy and configure network functions according to requirements, improving the customizability and flexibility of network services.
[0108] The network resource segmentation module divides network resources into multiple logical slices using virtualization slicing technology, and each slice can have an independent security protection policy.
[0109] Virtualization slicing technology is a technology that logically abstracts and multiplexes physical resources (such as computing, storage, and network). It divides physical resources into multiple virtual instances by using a virtualization software layer (such as a virtual machine monitor or container engine), allowing each instance to be independently run and managed.
[0110] Virtualization slicing technology is a technology that logically isolates and manages computing resources, which can divide physical resources (such as processors, memory, storage, etc.) into multiple independent virtual instances, making each instance appear as a complete and independent system. Each virtual network has an independent logical topology and control. This virtualization technology enables better sharing and utilization of network resources, improving network flexibility and scalability. It can be dynamically adjusted according to actual needs to improve resource utilization and system performance.
[0111] The virtualization slicing technology system consists of:
[0112] (1) Physical host (Host): A physical server that provides computing resources (such as processors, memory, storage, etc.).
[0113] (2) Virtual machine (Virtual Machine, VM): An independent virtual instance running on a physical host, each virtual machine has its own operating system and applications.
[0114] (3) Virtualization software (Hypervisor): Also known as virtual machine monitor (VMM), responsible for managing and controlling the creation, destruction, migration, and monitoring of virtual machines. Through the Docker application container engine, the CPU cores of the intensive integrated train onboard network information security protection system are one-to-one mapped to virtual machine vCPUs, and the security protection policy is dynamically bound to the virtual machine vCPU.
[0115] (4) Management interface: An interface for managing and configuring virtual machines, which can be operated through a command line or graphical interface.
[0116] The above security protection policy includes network isolation policy, authentication and authorization policy, encrypted communication policy, and update and vulnerability repair policy.
[0117] The network isolation policy divides the onboard network in the train into different security areas, and each area is isolated by access control to prevent security incidents from spreading throughout the network.
[0118] Authentication and authorization policy implements authentication and authorization mechanisms, only verified users can access the vehicle network, and the access rights of users are limited to ensure legal access.
[0119] Encrypted communication policy encrypts communication in the train network, including data transmission encryption and identity authentication encryption, to prevent unauthorized personnel from accessing sensitive information or eavesdropping and tampering with communication.
[0120] Update and vulnerability repair policy can update software and operating system in train network in time, and repair known vulnerabilities to reduce potential security risks.
[0121] The intensive integrated train vehicle network information security protection system of the embodiment of the application integrates multiple security components, is simple to deploy, and is convenient to manage. The deployment position of the above-mentioned intensive integrated train vehicle network information security protection system is as shown in Figure 8 The system can be deployed at the vehicle-level switch of the train head car and the tail car. The switch configuration needs to configure the static lacp type eth-thrunk to let the opposite end send lacp message to detect the link state. Once an exception occurs, it can be automatically switched.
[0122] The intensive integrated train vehicle network information security protection system of the embodiment of the application realizes efficient, dynamic and redundant protection of the vehicle network system through multi-level intensive integrated security design and comparison between each component. Intelligent joint defense and control and active defense are realized. Principle: The intensive integrated joint protection control system is organically combined with network equipment and network defense system. When an attack behavior occurs, not only a single system is relied on to respond. Through analysis of the attack behavior, a reasonable defense means is intelligently selected, and network equipment suitable for the attack type is selected to prevent the attack behavior. Through the means of joint protection control, network resources can be protected to a greater extent, and network performance can be improved.
[0123] In summary, the embodiment of the application is based on software-defined function and virtualization slicing technology. Network security protection policy can be decoupled from traditional devices and configured as a programmable software module. This method allows flexible configuration and management of network security protection policy according to specific needs and scenarios without relying on specific hardware devices.
[0124] Through software-defined function, the functions of each component of the network can be virtualized and managed as a software module. In this way, network security protection policy can be independent of hardware devices and can be dynamically adjusted and configured as needed.
[0125] Virtualization slicing technology allows network resources to be divided into multiple logical slices, each of which can have its own network security protection policy. This method can provide better isolation and flexibility, so that different network deployments and applications can have different security policies, while avoiding interference with each other.
[0126] In general, based on the decoupling and programmability of network security protection policies based on software-defined functions and virtualization slicing technology, security protection policy linkage is achieved, and higher flexibility, scalability and management efficiency can be provided.
[0127] Those skilled in the art can understand that the modules or flows in the drawings are not necessarily required to implement the present application.
[0128] From the above description of the embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software and the necessary network device platform. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, server, or network device, etc.) execute the methods described in various embodiments or some parts of the embodiments.
[0129] Each embodiment in the specification is described in a progressive manner, and the same or similar parts of each embodiment can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device or system embodiment, since it is basically similar to the method embodiment, it is described more simply, and the relevant parts can be referred to the part of the method embodiment. The above-described device and system embodiments are only illustrative, and the units described as separate components can be or can not be physically separated, and the components displayed as units can be or can not be physical units, i.e. they can be located in one place or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the present embodiment scheme according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0130] The above is only the preferred specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or replacements within the technical range disclosed by the present application can be easily thought of by those skilled in the art, and should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An intensive integrated train on-board network information security protection system, characterized in that, The application relates to a security protection system for an intensive integrated train onboard network information, which comprises a management module, a policy distribution module and a security protection control module. The management module is used for managing the configuration, state and resource of the security protection system of the train onboard network information, providing an operation interface of a security protection policy component for a user, receiving and managing a security protection policy dynamically customized by the user through the operation interface. The policy distribution module is used for configuring the security protection policy into a programmable software module, dynamically binding the security protection policy with a CPU kernel of the security protection system of the intensive integrated train onboard network information, and dynamically deploying the security protection policy on a related hardware device according to requirements. The security protection control module is used for dividing a network security protection function into a plurality of independent security components by using a software defined network (SDN), decoupling the security components from the hardware device, configuring the security components into programmable software modules, deploying each security component in the form of a software module on the hardware device, setting a corresponding security protection policy for each security component, and executing the security protection policy on the security component of the hardware device. The management module comprises a resource management module, a business scenario task and CPU binding module and a security protection policy component module. The resource management module is used for managing the configuration, state and resource of the security protection system. The business scenario task and CPU binding module is used for determining on which CPU kernel each business scenario task runs according to system configuration and runtime performance indexes, dynamically determining the binding relationship between the business scenario task and the CPU kernel through a scheduling strategy and an application programming interface (API) provided by an operating system, and monitoring the change of the binding relationship between the business scenario task and the CPU kernel. The security protection policy component module is used for configuring and managing a security protection policy component, and the security protection policy component comprises a policy controller, a dynamic policy analysis module and a reconfigurer. The policy controller is used for providing an operation interface for a user, and the user dynamically customizes a security protection policy of a train through the operation interface. The dynamic policy analysis module is used for determining a security protection policy according to a task in a required business scenario, inquiring whether corresponding security protection policies are stored in a policy library, selecting corresponding security protection policies from the policy library if the corresponding security protection policies exist, otherwise, inquiring a component library, selecting various component information capable of being used to generate the security protection policy, the component information comprising coding and name information of components, and sending a reconfiguration message carrying the various component information to the reconfigurer. The reconfigurer is used for reading the component information carried in the reconfiguration message, activating corresponding components in the component library according to the component information, and displaying the components in a tree type, a user directly selecting corresponding component functions on the tree type display, generating a new security protection policy, and storing the generated security protection policy in the policy library. The policy library is used for storing the security protection policy of the train in the form of a policy table. The component library is used for storing various components used to generate the security protection policy of the train. The security protection control module comprises a security protection policy component module, a policy distribution module and a resource management module. The security component generation module is configured to divide network security protection functions into security components including access control functions, packet filtering functions, intrusion detection functions, security audit functions, vulnerability scanning, load balancing, encryption and decryption functions, identity authentication functions, monitoring management functions and situation awareness functions by using SDN, decouple the security components from hardware devices, configure the security components as programmable software modules, and deploy and run each security component in the form of software on the hardware devices according to the needs of the business; A plurality of security components are set for one security protection function, the corresponding relationship between the security protection function and the security components is stored in the security protection control module, the corresponding security protection policy is set for each security component as needed, one security component and the corresponding security protection policy constitute a security protection unit, a plurality of security protection units are set for one security protection function, when one hardware device needs to implement one security protection function, a group of security protection units are set on the hardware device, when one hardware device needs to implement a plurality of security protection functions, a plurality of groups of security protection units are set on the hardware device, the plurality of security protection units realize redundant protection through intelligent linkage, comparison is performed between the security protection units, redundant protection of the train network system is realized, intelligent joint defense and control and active defense are realized; when an attack behavior occurs, the attack behavior is analyzed, and a plurality of groups of security protection units and hardware device schemes are intelligently selected to form a plurality of different defense means; The security protection policy execution module, The CPU core of the security protection system of the intensive integrated train on-board network information executes the security protection policy deployed on the security components, slices and hardware devices through the security protection policy binding, and the security protection policy execution and upgrade maintenance processes of each security component and slice are independent of each other; When a certain security protection function is needed, the security protection control module queries the corresponding relationship between the security protection function and the security components, selects a plurality of security components corresponding to the security protection function, and then queries the rule library module to configure the corresponding security protection policy for each selected security component as needed; The policy distribution module includes: The security protection policy decoupling module is configured to decouple the security protection policy from the traditional device based on SDN by using the virtualization slicing technology, configure the security protection policy as a programmable software module, and dynamically bind the security protection policy with the CPU core of the security protection system of the intensive integrated train on-board network information, wherein the security protection policy includes a network isolation policy, an authentication and authorization policy, an encrypted communication policy, and an update and vulnerability repair policy. The network resource segmentation module is configured to logically abstract and multiplex network resources by using a virtualization slicing technology, divide the network resources into a plurality of virtual instances by using a virtualization software layer, each virtual instance corresponds to a slice, and configure a corresponding security protection strategy for each slice. The security protection strategy deployment module is configured to dynamically bind the security protection strategy with a CPU core of the intensive integrated train onboard network information security protection system, dynamically configure and deploy the security protection strategy according to requirements, and deploy a corresponding security protection strategy for each security component, slice and hardware device.
2. The system of claim 1, wherein, The system further comprises a computing module, a rule library module, an authentication and authorization module, an encryption and decryption module, a scheduling module and an interface module. The computing module is configured to process security protection-related computing tasks and monitor various security events and threats in the system. The rule library module is configured to store security rules and security protection strategies of the train onboard network. The authentication and authorization module is configured to verify and authorize devices and users connected to the onboard network, and ensure that only authorized devices and users can access the train onboard network. The encryption and decryption module is configured to perform data encryption and decryption tasks. The scheduling module is configured to assign tasks to different CPU cores of the intensive integrated train onboard network information security protection system for execution, perform task scheduling and resource allocation according to binding strategies and real-time requirements, and coordinate and manage the work of each module. The interface module is configured to provide an interface for the intensive integrated train onboard network information security protection system to interact with other systems and devices.
3. The system of claim 1, wherein, The security protection strategy decoupling module is configured to dynamically bind the security protection strategy with the CPU core of the intensive integrated train onboard network information security protection system at the hardware and software levels.
4. The system of claim 3, wherein, The policy distribution module uses the virtualization slicing technology, and the system comprises a physical host, a virtual machine, a virtualization software and a management interface. The physical host is configured to provide a physical server of computing resources. The virtual machine is configured to be an independent virtual instance running on the physical host, and each virtual machine has its own operating system and application program. The virtual machine is configured to be an independent virtual instance running on the physical host, and each virtual machine has its own operating system and application program. The virtualization software is used for managing and controlling creation, destruction, migration and monitoring of virtual machines, CPU cores of the intensive integrated train on-board network information security protection system are one-to-one mapped to virtual machine vCPUs through a Docker application container engine, and security protection policies are dynamically bound to the virtual machine vCPUs. The management interface is used for managing and configuring the virtual machine, and is operated through a command line or a graphical interface.
5. The system of claim 1, wherein, The network isolation strategy divides the on-board network in the train into different security areas, and network isolation is performed between each area through access control. The authentication and authorization strategy implements an authentication and authorization mechanism, only a user who has passed verification can access the on-board network, and access rights of the user are limited, so that legal access is ensured. The encrypted communication strategy performs encryption processing on communication in the train network, including data transmission encryption and identity authentication encryption. The update and vulnerability repair strategy updates software and an operating system in the train network, and patches known vulnerabilities.
6. The system of claim 1, wherein, The system is deployed at vehicle-level switches of a train head car and a tail car.
Citation Information
Patent Citations
Network security cooperative protection method and system
CN108965289A
Method and apparatus for network security andmanagement
KR1020040094985A