A vehicle-mounted data acquisition and transmission system based on a security mechanism and a working method thereof

By constructing a vehicle-mounted data acquisition and transmission system based on security mechanisms, the problems of complex and inadequate data transmission in subway vehicles have been solved, achieving concise data organization and efficient transmission, and ensuring data security and reliability.

CN119449847BActive Publication Date: 2025-11-04CRRC DALIAN R & D CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411521038.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-29
Publication Date
2025-11-04
Estimated Expiration
2044-10-29

AI Technical Summary

Technical Problem

The data transmission of the subway vehicle data acquisition system is complex and lacks security protection, resulting in difficulties in data parsing and insufficient security.

Method used

It employs data acquisition units, network security units, data encryption units, bus interface units, Ethernet switches, IO expansion units, and a central control unit to achieve data fusion, cleaning, encryption, and security monitoring, building a data protection defense line to ensure the security and simplicity of data transmission.

Benefits of technology

It simplifies data organization, improves the security and robustness of data transmission, facilitates analysis and processing by maintenance personnel, and reduces vehicle communication load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119449847B_ABST
    Figure CN119449847B_ABST
Patent Text Reader

Abstract

The application provides a kind of vehicle-mounted data acquisition and transmission system and working method based on security mechanism, comprising: data acquisition unit, network security unit, data encryption unit, bus interface unit, ethernet switch, IO expansion unit and central control unit, data acquisition unit obtains real-time fault data and normal operation data of subway vehicle through bus interface unit, carries out data fusion, cleaning and feature extraction processing to system state information and fault data, and stores;Network security unit is provided with redundancy measures and relay function, for protecting data acquisition unit, establishing data protection line;Data encryption unit carries out data transmission with data acquisition unit, for receiving and sending data;When receiving data, the received data is decrypted and then passed to the data acquisition unit;When sending data, the data of data acquisition unit is encrypted and then sent externally.The application improves the security of subway vehicle data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data communication, in particular, especially relates to a vehicle-mounted data acquisition and transmission system based on a security mechanism and a working method. BACKGROUND

[0002] As an important part of modern urban transportation, subway systems, people's understanding of their operation and passenger flow trends becomes increasingly important. In order to achieve efficient operation and intelligent management, data acquisition and transmission play a key role in subway systems. Subway system data acquisition involves various aspects, including vehicle operating conditions, station passenger flow, passenger travel time and location, etc. Through modern sensor technology and metering equipment, a large amount of data can be obtained in real time. Through the data transmission bus, internal data of each control device is obtained at a certain time period, forming ordered and certain density data.

[0003] The train network control system (TCMS) is a platform for data transmission of various subsystems of the subway vehicle, and is the central control unit for the control, monitoring and diagnosis of various subsystems of the vehicle control unit, which is equivalent to the brain of the subway vehicle. In order to ensure the safe, stable and efficient operation of the subway vehicle, the network control system will monitor the working state of each subsystem of the vehicle, diagnose the fault in time when the fault occurs, and feed back the fault information to the driver through the display unit. The organization and transmission of network control system data can seriously affect the performance of the subway vehicle.

[0004] The data transmission of the subway vehicle network control system mainly includes the physical layer, the data link layer, the application layer, etc., and the transmitted data mainly includes process data, message data and monitoring data. The current subway vehicle data acquisition system data transmission organization method is complex, which is not conducive to the analysis of the operation and maintenance personnel, and lacks network security protection measures, which cannot guarantee the safety of the vehicle data. Therefore, the field urgently needs a vehicle-mounted data acquisition and transmission system for subway vehicle data acquisition, which can solve the problems of lack of security protection and complex data analysis in the prior art based on a security mechanism. SUMMARY

[0005] According to the above technical problems, a vehicle-mounted data acquisition and transmission system based on a security mechanism and a working method are provided. The present application mainly uses a data acquisition unit, a network security unit, a data encryption unit, a bus interface unit, an Ethernet switch, an IO expansion unit and a central control unit to reduce the complexity of data and improve the safety of subway vehicle data transmission.

[0006] The technical means adopted by the present application are as follows:

[0007] A vehicle-mounted data acquisition and transmission system based on a security mechanism comprises a data acquisition unit, a network security unit, a data encryption unit, a bus interface unit, an Ethernet switch, an IO expansion unit and a central control unit, wherein:

[0008] The data acquisition unit acquires real-time fault data and normal operation data of a subway vehicle through the bus interface unit, performs data fusion, cleaning and feature extraction processing on system state information and fault data, and stores the data;

[0009] The network security unit is provided with a redundancy measure and a relay function for protecting the data acquisition unit and establishing a data protection line, and the redundancy measure is used to switch to a redundant device when a device fails to maintain normal operation of the system;

[0010] The data encryption unit transmits data with the data acquisition unit for receiving and sending data; when receiving data, the received data is decrypted and transmitted to the data acquisition unit; when sending data, the data of the data acquisition unit is encrypted and sent externally;

[0011] The bus interface unit is used for protocol conversion and configuration, and the data is transmitted in a transparent manner;

[0012] The Ethernet switch has a unique Ethernet communication transmission channel, and the network security unit ensures the security of data transmission;

[0013] The IO expansion unit includes a digital input module and a digital output module, wherein the digital input module is responsible for acquiring digital signals, and the digital output module is responsible for outputting voltage signals;

[0014] The central control unit is used for communication organization and management of the subsystems in the vehicle-mounted data acquisition and transmission system, and the subsystems include a traction system, a brake system, a door system and an air conditioning system.

[0015] The application also includes a working method of a vehicle-mounted data acquisition and transmission system based on a security mechanism, and the specific steps include:

[0016] S1, acquiring process data, message data and monitoring data of a subway vehicle during operation through the data acquisition unit, and performing data processing and storage;

[0017] S2, organizing the data in S1 into data messages using a communication protocol;

[0018] S3, communicating and managing the subsystems in the vehicle-mounted data acquisition and transmission system through the central control unit;

[0019] S4, the audit function in the vehicle data acquisition and transmission system is monitored and protected by the network security unit;

[0020] S5, the output data is encrypted by the data encryption unit and output to the external environment.

[0021] Further, the process data includes real-time vehicle position, current speed, ambient temperature, and running condition; the message data includes function message and service message, the function message is used for network control of the vehicle data acquisition and transmission system on the subsystem, and the service message is used for management of the vehicle data acquisition and transmission system; and the monitoring data is used for monitoring and checking the state of the subsystem equipment.

[0022] Further, the organization mode of the data packet is message header + type + message ID + subject content + reserved field + message tail.

[0023] The vehicle data acquisition and transmission system interacts with each unit through the MVB network to obtain the data of the data acquisition unit, organizes the data, and transmits the organized data to the ground operation and maintenance system in a train-ground wireless manner.

[0024] Further, the central control unit transmits data to the subsystem through the MVB network, configures a data transmission period according to the communication data requirement of the subsystem, and transmits the data to the brake system in a transparent manner and receives the data of the brake system for mapping.

[0025] Further, the audit function includes session access control, session monitoring, static routing, NAT, and global anti-DOS attack; the network security unit is provided with regional security protection and boundary protection, the regional security protection means that the equipment and data in each region are protected to different degrees, and the boundary protection means security measures taken at the boundary of the network or system to prevent unauthorized access and attacks.

[0026] Further, the data encryption unit uses a combination of asymmetric encryption and symmetric encryption algorithm to encrypt and decrypt the data, the symmetric encryption means that the same key is used for encryption and decryption by both parties, and the asymmetric encryption means that a pair of different keys are used for encryption and decryption.

[0027] Compared with the prior art, the present application has the following advantages:

[0028] The application provides a vehicle-mounted data acquisition and transmission system based on a security mechanism and a working method.

[0029] Based on the above reasons, the application can be widely promoted in the field of data communication. BRIEF DESCRIPTION OF DRAWINGS

[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0031] Figure 1 The figure is a structure diagram of the vehicle-mounted data acquisition and transmission system based on the security mechanism in the application. DETAILED DESCRIPTION

[0032] In order to make the person skilled in the art better understand the present application, the following will combine the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.

[0033] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product or device.

[0034] As shown in Figure 1 The application provides a vehicle-mounted data acquisition and transmission system based on a security mechanism, comprising a data acquisition unit, a network security unit, a data encryption unit, a bus interface unit, an Ethernet switch, an IO expansion unit and a central control unit, wherein:

[0035] The data acquisition unit obtains real-time fault data and normal operation data of the subway vehicle through the bus interface unit, performs data fusion, cleaning and feature extraction processing on system state information and fault data, and stores data;

[0036] In implementation, the software architecture of the data acquisition unit mainly has four parts, which are a driver layer, a middleware, an application layer and an execution layer. Here, the driver layer mainly implements the driving function of the hardware interface; the middleware mainly provides interface functions and library files required for the host computer to run, and implements software communication protocols such as the Multifunction Vehicle Bus (MVB); the application layer mainly completes function functions, and interacts with the middleware by calling shared libraries during operation; and the execution layer mainly implements the related control logic of data processing, and completes the related configuration of the network port.

[0037] After the data acquisition unit is powered on, the system performs system initialization through an initialization function and performs initialization configuration. After completing system initialization, the application layer related tasks are created, mainly including: indicator light tasks, communication tasks, operation record tasks, and fault record tasks.

[0038] As shown in Table 1, the data acquisition unit uses an Intel processor as the core processor, which has the characteristics of high frequency and large memory, with a main frequency of 500 MHz and a memory of 256 MB; in terms of storage, an on-board 8 GB SSD is used to store the embedded system and data files, ensuring that the device has sufficient storage space; a power-off retention storage space is configured, which divides 1 MB of space to store the key parameters of the subway vehicle.

[0039] The data acquisition unit obtains real-time fault data and normal operation data of each subsystem of the subway vehicle through the Ethernet bus, and performs real-time data fusion, cleaning and feature extraction processing on the state information and fault data of each subsystem, and then saves the data.

[0040] Table 1 Technical parameters of the data acquisition unit

[0041]

[0042]

[0043] The network security unit is provided with redundancy measures and relay functions, which are used to protect the data acquisition unit and establish a data protection line. The redundancy measures are used to switch to a redundant device when the device fails, and maintain the normal operation of the system;

[0044] The metro vehicle network security unit is configured with a gigabit port and a hundred megabit port, wherein the hundred megabit port is up to 8, and the gigabit port is 2. The security monitoring protection function is set for the audit functions such as session access control, session monitoring, static route and NAT, global anti-DOS attack, etc., so that the device can ensure the safety of data when collecting data. The regional security protection and boundary protection are provided, the data protection line is established by protecting the data collection unit, the boundary security threat is resisted, and the device security protection is more intelligent. The design of the redundancy measure ensures the robustness of data transmission, and when the faulty device is switched to the redundant device, the network security unit can normally function. In order to ensure the normality of the redundancy switching, the network security unit has two-way By-Pass bypass relay function.

[0045] The technical parameters of the network security unit are shown in Table 2.

[0046] Table 2 Technical parameters of network security unit

[0047]

[0048] In implementation, the network security and protection adopts five-tuple based on the transmission layer protocol, source IP address, destination IP address, source port and destination port, the security policy adopts time definition package and MAC address filtering, and the access control uses the policy based on state detection technology. In the IPv6, IPv6 and IPv4 mixed network environment, ARP attack can be prevented, and IP / MAC address binding rule is adopted.

[0049] In order to strengthen the data security of metro vehicle, the on-board data collection device also protects the key data in network security and protection. By using the secure data protocol SDTv2 based on TRDP at the communication protocol level to transmit the key data, and using multiple check and handshake to process the important process data of the vehicle, the safety of on-board data is effectively guaranteed, and the data is avoided to be tampered in the transmission process.

[0050] The data encryption unit transmits data with the data collection unit, and is used for receiving and sending data; when receiving data, the received data is decrypted and transmitted to the data collection unit; when sending data, the data of the data collection unit is encrypted and sent externally;

[0051] In implementation, as shown in Table 3, the method of data transmission between the data encryption unit and the data collection unit is to design a communication interface on the backboard. Independent backboard Ethernet interface and RS485 interface are adopted to send and receive data.

[0052] Table 3 Encryption board technical index

[0053]

[0054] The bus interface unit is used for conversion and configuration of relevant protocols, and the data is transmitted in a transparent manner; in implementation, in order to enable the vehicle-mounted data acquisition and transmission system to acquire more detailed data of the subway vehicle, the bus interface unit is configured to convert relevant protocols, and the data is transmitted in a transparent manner.

[0055] The Ethernet switch has a unique Ethernet communication transmission channel, and the safety of data transmission is ensured through the network security unit; in implementation, the vehicle-mounted data acquisition and transmission system has only one transmission channel for external Ethernet communication, so that the network security unit is ensured as the only Ethernet data input channel, and the safety of data transmission is ensured.

[0056] The IO expansion unit includes a digital input module and a digital output module, wherein the digital input module is responsible for acquiring 110V digital signals, and the digital output module is responsible for outputting 110V voltage signals.

[0057] The central control unit is used for communication organization and management of the subsystems in the vehicle-mounted data acquisition and transmission system, and the subsystems include a traction system, a brake system, a door system and an air conditioning system.

[0058] In implementation, the traction system refers to a system for traction of the vehicle through power or other ways during operation of the subway train. The brake system refers to a system for brake control of the vehicle during operation of the subway train. The door system refers to a system for control of opening and closing of the vehicle door during operation of the subway train. The air conditioning system can realize multiple functions such as air cooling, air heating and ventilation, and meets the comfort requirement of passengers in travel life.

[0059] In implementation, the vehicle-mounted data acquisition and transmission system based on the safety mechanism further includes a power supply unit, the power supply unit adopts DC 110V input and DC 5V output, the input interface is located on the front panel, the output interface is located on the back plate connector of the power supply board, and power supply is output to other circuit boards through the back plate.

[0060] The application further includes a working method of the vehicle-mounted data acquisition and transmission system based on the safety mechanism, and the specific steps include:

[0061] S1, acquiring process data, message data and monitoring data of the subway vehicle during operation through the data acquisition unit, and performing data processing and storage;

[0062] In particular implementation, as the preferred embodiment of the present application, the process data includes: real-time position of the vehicle, current speed, ambient temperature, running condition; the message data includes: function message and service message, the function message is used for network control of the vehicle data acquisition and transmission system to the subsystem, and the service message is used for management of the vehicle data acquisition and transmission system; and the monitoring data is used for monitoring and checking the state of the subsystem equipment.

[0063] S2, organizing the data in S1 into data messages by using a communication protocol;

[0064] In particular implementation, as the preferred embodiment of the present application, as shown in Table 4, the organization mode of the data message is: message header + type + message ID + subject content + reserved field + message tail.

[0065] Table 4 Data packet format

[0066] Message Header Type Message ID Subject Content Reserved Field Message Trailer 3 bytes 1 byte 4 bytes N bytes 2 bytes 3 bytes

[0067] The message header is fixedly filled with 0xAA, 0xAB and 0xAC; the type is fixedly filled with 0x01; the message ID is the number of the message, the number starts from 0, and is increased by 1 every time a new message is sent, and is accumulated until the maximum value is reached and then circulates; the data area is filled with state data and fault data, and fixed size areas are divided for the state data and the fault data. The reserved field is fixedly filled with 0x00 and 0x00; and the message tail is fixedly filled with 0xBA, 0xBB and 0xBC.

[0068] The vehicle data acquisition and transmission system obtains the data of the data acquisition unit through the MVB network and each unit, organizes the data, and transmits the organized data to the ground operation system in a vehicle-ground wireless manner.

[0069] S3, the central control unit is used for communication organization and management of the subsystem in the vehicle data acquisition and transmission system;

[0070] In particular implementation, as the preferred embodiment of the present application, the central control unit transmits data to the subsystem through the MVB network, configures a data transmission period according to the communication data requirement of the subsystem, and transmits the data to the brake system in a transparent transmission mode, and receives the data of the brake system for mapping.

[0071] In implementation, the brake system needs to directly acquire original data of the metro vehicle traction system. The brake system exchanges data with the on-board data acquisition and transmission system in the form of an MVB bus, but the on-board data acquisition and transmission system only serves as a medium for data transmission and does not perform logical control on the data, but adopts a transparent transmission mode to transmit the data to the brake system. The central control unit receives the MVB network data of the brake system and maps the data, and the MVB network central control unit, the man-machine interface unit and the brake system receive and process the data. There is data interaction between the traction system and the central control unit and the brake system.

[0072] S4, the audit function in the on-board data acquisition and transmission system is monitored and protected by the network security unit.

[0073] In specific implementation, as a preferred embodiment of the present application, the audit function includes session access control, session monitoring, static routing and NAT and global anti-DOS attack; the network security unit is provided with regional security protection and boundary protection, the regional security protection means that the devices and data in each region are protected to different degrees, and the boundary protection means security measures taken at the boundary of the network or system to prevent unauthorized access and attacks.

[0074] In implementation, the session access control refers to the control of the session between the server and the client, and the judgment of who the two parties of the session are; the session monitoring refers to the monitoring of the content of the session; the static routing refers to a way of routing, which is manually configured. Static NAT refers to a technology of mapping network addresses during network address translation. Global anti-DOS attack refers to establishing a comprehensive security system from the network infrastructure to multiple protection measures at the application level.

[0075] S5, the data encryption unit is used to encrypt the output data and output to the external environment.

[0076] In specific implementation, as a preferred embodiment of the present application, the data encryption unit adopts an algorithm combining asymmetric encryption and symmetric encryption to encrypt and decrypt the data. Symmetric encryption means that the same key is used for encryption and decryption by both the sender and the receiver, and asymmetric encryption means the process of using a pair of different keys for encryption and decryption.

[0077] In implementation, the data encryption unit adopts an algorithm combining the two to take advantage of the characteristics of asymmetric encryption and symmetric encryption. By combining the two algorithms, the security of the key during transmission is ensured, and the rapid encryption of large data packets is ensured, and the advantages are complementary.

[0078] The above embodiment numbers of the present application are only for description, and do not represent the advantages and disadvantages of the embodiments.

[0079] In the above-described embodiments of the present application, the description of each embodiment focuses on different aspects, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0080] In several embodiments provided in the present application, it should be understood that the disclosed technical contents can be implemented by other ways. Among them, the above-described device embodiments are only schematic, for example, the division of units can be a logical function division, and actual implementation can have another division way, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or modules shown or discussed can be indirect coupling or communication connection through some interfaces, units or modules, which can be electrical or other forms.

[0081] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place or distributed to multiple units. Part or all of the units can be selected to achieve the purpose of the embodiment scheme according to actual needs.

[0082] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit.

[0083] If the integrated unit is realized in the form of software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the whole or part of the technical solutions that make essential contributions to the prior art can be embodied in the form of software product, which is stored in a storage medium and includes a plurality of instructions for making a computer device (which can be a personal computer, a server or a network device, etc.) execute all or part of the steps of the embodiments of the present application. The foregoing storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and various program code storage media.

[0084] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit the present application; although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions recorded in the above embodiments can be modified, or some or all of the technical features can be replaced by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A vehicle-mounted data acquisition and transmission system based on a security mechanism, characterized in that, include: The system comprises a data acquisition unit, a network security unit, a data encryption unit, a bus interface unit, an Ethernet switch, an I / O expansion unit, and a central control unit, wherein: The data acquisition unit acquires real-time fault data and normal operation data of the subway vehicle through the bus interface unit, performs data fusion, cleaning and feature extraction processing on the system status information and fault data, and stores the data. The software architecture of the data acquisition unit mainly consists of four parts: driver layer, middleware, application layer, and execution layer. The driver layer mainly implements the driver function of the hardware interface; the middleware mainly provides the interface functions and library files required for the host computer to run, and implements the multi-functional vehicle bus software communication protocol; the application layer mainly completes the function functions and interacts with the middleware by calling the shared library during the operation; the execution layer mainly implements the relevant control logic for data processing and completes the relevant configuration of the network port. The network security unit is equipped with redundancy measures and relay functions to protect the data acquisition unit and establish a data protection defense line. The redundancy measures are used to switch to redundant devices in the event of equipment failure to maintain normal system operation. Critical data is transmitted using the TRDP-based Security Data Protocol SDTv2 at the communication protocol level, and important vehicle process data is processed using multiple checksums and handshakes. The data encryption unit transmits data with the data acquisition unit for receiving and sending data; when receiving data, it decrypts the received data and then transmits it to the data acquisition unit; when sending data, it encrypts the data from the data acquisition unit and then sends it out. The bus interface unit is used for converting and configuring relevant protocols and transmitting data in a transparent manner. The Ethernet switch has a unique Ethernet communication transmission channel, and the security of data transmission is ensured by a network security unit. The IO expansion unit includes a digital input module and a digital output module, wherein the digital input module is responsible for acquiring digital signals and the digital output module is responsible for outputting voltage signals; The central control unit is used for communication organization and management of the subsystems, including the traction system, braking system, door system and air conditioning system; The central control unit transmits data to the subsystem via an MVB network and configures the data transmission cycle according to the communication data requirements of the subsystem. The central control unit transmits data to the braking system in a transparent manner and receives data from the braking system for mapping.

2. A method for vehicle data acquisition and transmission based on a security mechanism, implemented using the vehicle data acquisition and transmission system based on the security mechanism described in claim 1, characterized in that: The specific steps include: S1. Collect process data, message data, and monitoring data of the subway vehicle during operation through the data acquisition unit, and process and store the data; S2. Organize the data in S1 into data packets using a communication protocol; S3. The central control unit organizes and manages the communication of subsystems in the vehicle data acquisition and transmission system. S4. The auditing function of the vehicle data acquisition and transmission system is monitored and protected through the network security unit; S5. Use the data encryption unit to encrypt the output data and then output it to the external environment.

3. The working method of the vehicle-mounted data acquisition and transmission system based on a security mechanism according to claim 2, characterized in that, The process data includes: real-time vehicle location, current speed, ambient temperature, and operating status; the message data includes: functional messages and service messages, wherein the functional messages are used for network control of the subsystem by the vehicle data acquisition and transmission system, and the service messages are used for managing the vehicle data acquisition and transmission system; the monitoring data is used for monitoring and verifying the status of the subsystem equipment.

4. The working method of the vehicle-mounted data acquisition and transmission system based on a security mechanism according to claim 2, characterized in that, The data message is organized as follows: message header + type + message ID + subject content + reserved fields + message footer; The vehicle-mounted data acquisition and transmission system interacts with various units through the MVB network to obtain data from the data acquisition units, organizes the data, and then transmits the organized data to the ground operation and maintenance system via vehicle-to-ground wireless communication.

5. The working method of the vehicle-mounted data acquisition and transmission system based on a security mechanism according to claim 2, characterized in that, The central control unit transmits data to the subsystem via an MVB network and configures the data transmission cycle according to the communication data requirements of the subsystem. The central control unit transmits data to the braking system in a transparent manner and receives data from the braking system for mapping.

6. The working method of the vehicle-mounted data acquisition and transmission system based on a security mechanism according to claim 2, characterized in that, The auditing functions include: session access control, session monitoring, static routing and NAT, and global anti-DoS attack; the network security unit is equipped with regional security protection and boundary protection. Regional security protection means that devices and data in each region are protected to different degrees, and boundary protection means that security measures are taken at the boundary of the network or system to prevent unauthorized access and attacks.

7. The working method of the vehicle-mounted data acquisition and transmission system based on a security mechanism according to claim 2, characterized in that, The data encryption unit uses an algorithm that combines asymmetric and symmetric encryption to encrypt and decrypt data. The symmetric encryption means that both the sender and receiver use the same key, while the asymmetric encryption means that a pair of different keys are used for encryption and decryption.

Citation Information

Patent Citations

  • Train networking control system

    CN111262888A

  • Subway engineering vehicle vehicle-mounted device and system integrating operation monitoring and protection functions

    CN115848441A