A train-ground communication method and system applied to a train control system
By obtaining verification messages between the on-board equipment and the ground equipment of the CTCS-3 train control system, determining whether the national secret algorithm is supported and corresponding encryption processing is carried out, the problem of insufficient security of vehicle-ground communication in the existing system is solved, efficient and secure wireless encrypted communication is achieved, and the reliability of train operation is improved.
Patent Information
- Application Number
- CN202510212988.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-02-26
AI Technical Summary
The existing CTCS-3 train control system has weak vehicle-ground communication security, and due to the huge system scale, it is difficult for software upgrades to achieve secure wireless encrypted communication between vehicles and ground.
Verification messages are obtained from the communication data between the on-board equipment and the ground equipment, and it is determined whether each other supports the national secret algorithm, so as to perform different encryption processing. The specific method includes using the security algorithm fields in the AU1 and AU2 messages to determine that the state-secret algorithm is supported, and the communication data is encrypted or decrypted, and communication is carried out through a protocol to realize wireless encrypted communication.
The function of wireless encrypted communication in the vehicle and the ground is realized, and the communication between one party is an encrypted device and the other party is an unencrypted device is supported, which reduces the operational efficiency reduction caused by software upgrades and improves the security and reliability of train operations.
Smart Images

Figure CN119729405B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of rail transit, and particularly relates to a vehicle-ground communication method and system applied to a train control system. Background Art
[0002] In recent years in the field of rail transit, with the innovation of technology, the speed of trains is steadily increasing. The CTCS3 (China Train Control System Level 3) train control system independently developed in China has been comprehensively promoted. This system can be divided into three parts: on-vehicle equipment for controlling train operation, ground equipment for issuing train operation permits and other information, and vehicle-ground communication equipment. If the information data transmitted by the communication equipment is not encrypted and has weak security, the security of vehicle-ground communication in the existing CTCS-3 train control system needs to be improved. Therefore, in order to improve the safe operation of trains, the encryption processing of corresponding wireless network data is urgent. In addition, since there are many types and quantities of vehicles to which this train control system is applied, it is faced with great difficulties to upgrade the software of such a large-scale system, and there will still be on-vehicle equipment or ground equipment that does not support the national cryptographic algorithm. Thus, how to achieve secure wireless encrypted communication between vehicles and the ground has increasingly become a technical problem to be solved urgently. Summary of the Invention
[0003] In view of the above problems, the present invention provides a vehicle-ground communication method and system applied to a train control system, which has strong compatibility, high communication efficiency, and is safe and reliable.
[0004] The purpose of the present invention is to provide a vehicle-ground communication method applied to a train control system, including,
[0005] The on-vehicle equipment obtains a second verification message from the communication data sent by the ground equipment, and the ground equipment obtains a first verification message from the communication data sent by the on-vehicle equipment;
[0006] The on-vehicle equipment and the ground equipment respectively judge whether each other supports the national cryptographic algorithm based on the obtained corresponding verification messages, so as to perform different processing on the communication data between the on-vehicle equipment and the ground equipment.
[0007] Further, it also includes that the on-vehicle equipment and the ground equipment communicate through a protocol, wherein,
[0008] the first verification message and the second verification message respectively adopt the AU1 message and the AU2 message in the protocol. The AU1 message and the AU2 message packets include a security algorithm field, wherein,
[0009] When the value of the security algorithm field in the first verification message and the second verification information message is the first numerical value, it indicates that the on-vehicle device and the ground device do not support the national cryptographic algorithm;
[0010] When the value of the security algorithm field in the first verification message and the second verification information message is the second numerical value, it indicates that the on-vehicle device and the ground device support the national cryptographic algorithm.
[0011] Furthermore, the on-vehicle device and the ground device respectively judge whether the other party supports the national cryptographic algorithm based on the obtained corresponding verification messages, so as to perform different processing on the communication data between the on-vehicle device and the ground device. Specifically, if it is judged that both support the national cryptographic algorithm, it includes,
[0012] The on-vehicle device fills the communication data other than the first verification message to be sent into an integer multiple of 16 bytes, and then performs national cryptographic encryption; and,
[0013] The on-vehicle device modifies the security algorithm field of the second verification message packet obtained to the first numerical value to obtain 3DES check data;
[0014] Perform national cryptographic decryption on the communication data other than the second verification message in the received non-3DES key data, and then remove the padding bytes.
[0015] Furthermore, if both support the national cryptographic algorithm, it also includes,
[0016] The ground device fills the communication data other than the second verification message to be sent into an integer multiple of 16 bytes, and then performs national cryptographic encryption; and,
[0017] The ground device modifies the security algorithm field of the first verification message packet obtained to the first numerical value to restore it to 3DES data;
[0018] Perform national cryptographic decryption on the communication data other than the first verification message in the received data, and then remove the padding bytes.
[0019] Furthermore, the on-vehicle device and the ground device respectively judge whether the other party supports the national cryptographic algorithm based on the obtained corresponding verification messages, so as to perform different processing on the communication data between the on-vehicle device and the ground device. It also includes that if it is judged that both do not support the national cryptographic algorithm, specifically including,
[0020] The on-vehicle device does not perform national cryptographic encryption on the communication data to be sent and does not perform national cryptographic decryption on the received communication data;
[0021] The ground device processes the received and sent communication data according to the preset algorithm logic.
[0022] Further, the in-vehicle device and the ground device respectively determine whether they support the national cryptographic algorithm based on the obtained corresponding verification messages, so as to perform different processing on the data communicated between the in-vehicle device and the ground device. It further includes that if it is determined that the in-vehicle device supports the national cryptographic algorithm and the ground device does not support the national cryptographic algorithm, specifically including,
[0023] The in-vehicle device does not perform national cryptographic encryption on the communicated data to be sent, and does not perform national cryptographic decryption on the received communicated data;
[0024] The ground device modifies the security algorithm field of the obtained first verification message packet to a first value and restores it to 3DES data;
[0025] Processes the communicated data other than the first verification message received according to a preset algorithm logic; and,
[0026] The ground device processes the communicated data to be sent according to a preset algorithm logic.
[0027] Further, the in-vehicle device and the ground device respectively determine whether they support the national cryptographic algorithm based on the obtained corresponding verification messages, so as to perform different processing on the data communicated between the in-vehicle device and the ground device. It further includes that if it is determined that the in-vehicle device does not support the national cryptographic algorithm and the ground device supports the national cryptographic algorithm, specifically including,
[0028] The in-vehicle device does not perform national cryptographic encryption on the communicated data to be sent, and does not perform national cryptographic decryption on the received communicated data;
[0029] The ground device processes the communicated data received and to be sent according to a preset algorithm logic.
[0030] Further, both the first verification message and the second verification message are transmitted in plain text.
[0031] Further, it further includes that if the communicated data transmitted inside the in-vehicle device is a 3DES key, the in-vehicle device directly receives it.
[0032] Further, the in-vehicle device internally transmits data using a preset transmission protocol, and the preset transmission protocol includes Link Protocol and Serial_Link transmission protocol.
[0033] The object of the present invention also lies in providing a vehicle-ground communication system applied to a train control system, including an in-vehicle device and a ground device. The in-vehicle device includes an in-vehicle secure communication unit, and the ground device includes a communication network. An encryption management module is further provided in the communication network, wherein,
[0034] A vehicle-mounted security communication unit is used to obtain a second verification message from the communication data sent by a ground device, and determine whether the ground device supports the national cryptographic algorithm based on the obtained second verification message, so as to perform different processing on the data communicated between the vehicle-mounted device and the ground device;
[0035] An encryption management module is used to obtain a first verification message from the communication data sent by the vehicle-mounted device, and determine whether the vehicle-mounted device supports the national cryptographic algorithm based on the obtained second verification message, so as to perform different processing on the data communicated between the vehicle-mounted device and the ground device.
[0036] Further, the ground device further includes a security communication server, and the security communication server is connected to the encryption management module through a switch. When both the vehicle-mounted device and the ground device support the national cryptographic algorithm, the security communication server is used to perform national cryptographic encryption on the communication data filled to an integer multiple of 16 bytes other than the second verification message sent by the communication network; and perform national cryptographic decryption on the communication data sent by the received vehicle-mounted device other than the first verification message.
[0037] Further, the communication between the vehicle-mounted device and the ground device is through a protocol, wherein,
[0038] the first verification message and the second verification message respectively adopt the AU1 message and the AU2 message in the protocol. The AU1 message and the AU2 message are transmitted in plain text, and the AU1 message and the AU2 message packets include a security algorithm field, wherein,
[0039] When the value of the security algorithm field in the first verification message and the second verification information packet is the first value, it indicates that the vehicle-mounted device and the ground device do not support the national cryptographic algorithm;
[0040] When the value of the security algorithm field in the first verification message and the second verification information packet is the second value, it indicates that the vehicle-mounted device and the ground device support the national cryptographic algorithm.
[0041] Further, the vehicle-mounted device further includes a main control unit, a communication control unit, a communication encryption unit, and a radio station. Among them, the vehicle-mounted security communication unit is arranged between the communication control unit and the communication encryption unit, and exchanges communication data with the communication control unit and the communication encryption unit respectively according to the Link Protocol and the Serial_Link transmission protocol.
[0042] Further, the ground device further includes a radio block center, and the radio block center is connected to the communication network.
[0043] The communication method of the present invention realizes the function of vehicle-ground wireless encrypted communication, and also supports communication where one party is an encrypted device and the other party is a non-encrypted device, that is, it supports cross-communication between vehicle-mounted devices without national cryptography function and vehicle-mounted devices with national cryptography function and ground devices without national cryptography and ground devices with national cryptography function respectively, reduces the problem of reduced operation efficiency caused by encrypting existing upgraded software, improves vehicle-ground communication efficiency, and improves the safety and reliability of train operation.
[0044] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained by the structure pointed out in the specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0046] Figure 1 It shows a schematic flowchart of a vehicle-ground communication method applied to a train control system in an embodiment of the present invention;
[0047] Figure 2 It shows a kind in an embodiment of the present invention Schematic diagram of the interaction process of the protocol;
[0048] Figure 3 It shows a schematic structural diagram of a vehicle-ground communication system applied to a train control system in an embodiment of the present invention;
[0049] Figure 4 It shows a schematic structural diagram of a vehicle-mounted device in an embodiment of the present invention;
[0050] Figure 5 It shows a schematic structural diagram of a ground device in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0052] As Figure 1 shown, in the embodiment of the present invention, a vehicle-ground communication method applied to a train control system is introduced, which realizes the function of vehicle-ground wireless encrypted communication and supports communication where one party is an encrypted device and the other party is a non-encrypted device. The method includes: First, the on-vehicle device obtains a second verification message from the communication data sent by the ground device, and the ground device obtains a first verification message from the communication data sent by the on-vehicle device; Then, the on-vehicle device and the ground device respectively judge whether each other supports the national cryptographic algorithm based on the obtained corresponding verification messages, so as to perform different processing on the communication data between the on-vehicle device and the ground device. The above method realizes vehicle-ground wireless encrypted communication, and is compatible with cross-communication between on-vehicle devices without national cryptographic function and on-vehicle devices with national cryptographic function and between ground devices without national cryptographic function and ground devices with national cryptographic function respectively, reduces the problem of reduced operation efficiency caused by encrypting the existing upgraded software, improves the vehicle-ground communication efficiency, and improves the safety and reliability of train operation.
[0053] In the embodiment of the present invention, the communication between the on-vehicle device and the ground device is carried out through a protocol, where, as Figure 2 shown, the The interaction process of the protocol. When establishing a secure connection between safety layers, when the Sa-CONNECT.request primitive requests a secure connection, the safety layer requests the establishment of a transport connection through the TCONN.req service primitive, and this service primitive includes the first message (AU1 SaPDU) of the peer entity authentication process as user data; among them, SaPDU (Session Activation Packet Data Unit) refers to the session activation packet unit, and SaPDU is the packet unit used to activate the session during the communication process. If the receiving party accepts this request and has informed the corresponding user of the secure connection establishment through TCONN.ind, then it will respond to the TC (Transport Connection) establishment request through the T-CONN.resp service primitive, which includes the second message (AU2 SaPDU) of the peer entity authentication protocol as user data. After successfully establishing the transport connection, the calling transport entity uses the TCONN.conf service primitive to notify the safety layer and forwards the AU2 SaPDU as user data to the safety layer. The safety entity then generates an AU3 SaPDU containing the third message of the authentication protocol and forwards this message to the transport layer using the T-DATA.request service primitive. The receiving transport entity uses the T-DATA.ind service primitive to forward the AU3 SaPDU as user data to the safety layer, and the safety entity evaluates the AU3 SaPDU. If the AU3 SaPDU evaluation is successful, the safety entity forwards the Sa-CONN.ind service primitive to the safety user. If the safety user accepts the secure connection establishment request, it will respond using the Sa-CONN.resp service primitive. The safety entity verifies the response and generates an AR SaPDU containing the third message of the authentication protocol and forwards this message to the safety layer using the T-DATA.req service primitive. The receiving transport entity uses the T-DATA.ind service primitive to forward the AR SaPDU as user data to the safety layer. After successfully establishing the transport connection, the calling transport entity uses the TCONN.conf service primitive to notify the safety layer.
[0054] In the embodiment of the present invention, on the basis of the messages (i.e., communication data) such as AU1, AU2, AU3, AR, DT, and DI specified in the above protocol, the national cryptography encryption and decryption function is added, specifically including, The message is filled to an integer multiple of 16 bytes before encryption, and after corresponding decryption, the padding bytes are removed according to the following rules. First, the padding bytes are located before the message code stream (corresponding communication data). Second, the first padding byte is as shown in Table 1.
[0055] Table 1 The first padding byte of the message
[0056]
[0057] The values of the remaining padding bytes other than the first padding byte are 0.
[0058] Furthermore, bits 1 to 5 represent the number of padding bytes. Among them, The relationship between the remainder of the length of the message divided by 16 and the padding byte data is shown in Table 2,
[0059] Table 2 The relationship between the remainder of the length of the message divided by 16 and the padding byte data
[0060]
[0061] By modifying the existing protocol, it supports the scenario where on-vehicle devices with / without national cryptography functions and ground devices with / without national cryptography functions communicate simultaneously. This method has strong applicability and improves the reliability of vehicle-ground communication.
[0062] In the embodiments of the present invention, the first verification message and the second verification message respectively adopt the AU1 message and the AU2 message in the protocol. The security algorithm fields indicating whether to support the national cryptography algorithm are included in the AU1 message and the AU2 message. Among them, the value of the security algorithm field in the first verification message and the second verification message is the first numerical value, indicating that the on-vehicle device and the ground device do not support the national cryptography algorithm; the value of the security algorithm field in the first verification message and the second verification message is the second numerical value, indicating that the on-vehicle device and the ground device support the national cryptography algorithm. Preferably, the first numerical value is 1 and the second numerical value is 2. Exemplarily, the values of the SaF field in the AU1 message content and the AU2 message content shown in Tables 3 and 4 are both 1, that is, both the on-vehicle device and the ground device do not support the national cryptography algorithm.
[0063] Table 3 AU1 message content
[0064]
[0065] Among them, the ETY: field is used to identify the ETCS (European Train Control System) ID type, which involves SA (Security Authority), RBC (Radio Block Center) engine, Balise (a trackside device), and entities related to key management and interlocking. MTI: Message Type Identifier, here it is AU1, indicating that this is a message of type AU1. DF: Direction Flag, '0' indicates that the message is sent to the responder. SA: The ETCS ID of the calling party, occupying 2 to 4 octets. SaF: Security Algorithm Field, which is used in the embodiments of the present invention to indicate whether the national cryptography algorithm is supported. Here, it is specified to use single DES (Data Encryption Standard) with the modified MAC algorithm 3, and all other values are reserved. Ra: The random number Ra of the first authentication message, occupying 6 to 13 octets.
[0066] Table 4 AU2 Message Packet Content
[0067]
[0068] ETY: field is used to identify the ETCS (European Train Control System) ID type, which involves SA (Security Authority), radio padding unit, engine, RBC (Radio Block Center), Balise (a trackside device), and entities related to key management and interlocking. MTI: Message Type Identifier, here it is AU2, indicating that this is a message of type AU2. DF: Direction Flag, '1' indicates that the message is sent to the initiator. SA: The ETCS ID of the responder, occupying 2 to 4 octets. SaF is used to indicate whether the national cryptography algorithm is supported. Here, it is specified to use single DES (Data Encryption Standard) with the modified MAC algorithm 3, and all other values are reserved. R A : The random number R of the second authentication message, occupying 6 to 13 octets. MAC (Message Authentication Code) field: Message Authentication Code field, occupying 14 to 21 octets, calculated according to the rules of the peer entity and message source authentication procedure.
[0069] In the embodiments of the present invention, the vehicle-mounted device and the ground device respectively determine whether they support the national cryptographic algorithm based on the obtained corresponding verification messages, including that the vehicle-mounted device determines whether the ground device supports the national cryptographic algorithm based on the obtained second verification message, and the ground device determines whether the vehicle-mounted device supports the national cryptographic algorithm based on the obtained first verification message.
[0070] Specifically, the vehicle-mounted device determines whether the ground device supports the national cryptographic algorithm based on the obtained second verification message, including making a determination before sending communication data to the ground device and when receiving communication data sent by the ground device, and then performing different processing on the communication data based on the determination result. In addition, the vehicle-mounted device forwards data using a preset transmission protocol internally, and the preset transmission protocol includes the Link Protocol and the Serial_Link transmission protocol. Further, when the vehicle-mounted device determines whether the ground device supports the national cryptographic algorithm based on the second verification message before sending communication data to the ground device and performs different processing on the communication data between the vehicle-mounted device and the ground device according to the determination result, it includes the following processing procedures:
[0071] First, obtain the data to be sent to the ground device based on the Link Protocol and the Serial_Link transmission protocol.
[0072] Second, do not perform national cryptographic encryption on its own AU1 message (the first verification message), do not add padding bytes, and transmit it in plain text. Among them, if the vehicle-mounted device supports the national cryptographic algorithm, change the SaF field (security algorithm field) of the AU1 message packet from 1 to 2 to indicate support for the national cryptographic algorithm.
[0073] Then, analyze the obtained AU2 message (the second verification message) sent by the ground device. Among them, if the SaF field of the AU2 message packet is 1 and the ground device does not support the national cryptographic algorithm, the data sent to the ground device is not encrypted using the national cryptographic algorithm, and then new data is obtained according to the Link Protocol and the Serial_Link transmission protocol and sent to the ground device. If the SaF field of the AU2 message packet is 2 and the ground device supports the national cryptographic algorithm, padding data is added to the data other than the AU1 message, and then it is encrypted using the national cryptographic algorithm. After obtaining the encrypted data, new data is obtained according to the Link Protocol and the Serial_Link transmission protocol, and then it is sent to the ground device.
[0074] Further, when the vehicle-mounted device determines whether the ground device supports the national cryptographic algorithm before receiving the communication data from the ground device and performs different processing on the communication data between the vehicle-mounted device and the ground device according to the determination result, it includes the following processing procedures:
[0075] Determine whether the communication data is 3DES key data. Preferably, the 3DES key data is the data for internal communication of the vehicle-mounted device, rather than the communication data between the vehicle-mounted device and the ground device.
[0076] If it is 3DES key data, directly receive it; if it is non-3DES key data, it includes the following processing procedures:
[0077] First, obtain the data sent by the ground device according to the Link Protocol and Serial_Link transmission protocols.
[0078] Then, obtain the second verification message sent by the ground device. Among them, if the SaF field of the AU2 message packet is 1, it means that the ground device does not support the national cryptographic algorithm, and then the data of the ground device received subsequently will not be decrypted using the national cryptographic algorithm and will be directly received.
[0079] If the SaF field of the AU2 message packet is 2, it means that the ground device supports the national cryptographic algorithm. First, change the SaF field of the AU2 message packet with a value of 2 to 1, and then obtain only the 3DES check data. Then, obtain the new data according to the Link Protocol and Serial_Link transmission protocols for reception. In addition, for the data other than the AU2 message, perform national cryptographic decryption, delete the padding data, and finally obtain the new data according to the Link Protocol and Serial_Link transmission protocols for reception.
[0080] Furthermore, the ground device determines whether the vehicle-mounted device supports the national cryptographic algorithm based on the obtained AU1 message, including making the determination before sending communication data to the vehicle-mounted device and when receiving the communication data sent by the vehicle-mounted device, and then performing different processing on the communication data based on the determination result. Even further, the ground device includes a ground device that does not support the national cryptographic algorithm and a ground device that supports the national cryptographic algorithm.
[0081] When the ground device does not support the national cryptographic algorithm, the ground device determines whether the vehicle-mounted device supports the national cryptographic algorithm before sending communication data to the vehicle-mounted device and performs different processing on the communication data between the vehicle-mounted device and the ground device according to the determination result, including the following processing procedures:
[0082] The AU1 message sent by the vehicle-mounted device is transmitted in plain text, and the SaF field of its packet is 1, indicating that the vehicle-mounted device does not support the national cryptographic algorithm. Then, the ground device processes the communication data of the vehicle-mounted device received according to the preset algorithm logic and sends it to the Radio Block Center (RBC) in the ground device, and also processes the RBC data received according to the preset algorithm logic and sends it to the vehicle-mounted device; the preset algorithm logic processing includes, but is not limited to, processing through the 3DES (Triple Data Encryption Standard) algorithm (a symmetric encryption algorithm).
[0083] The AU1 message sent by the in-vehicle device is transmitted in plain text. If the SaF field of its message is 2, it means that the in-vehicle device supports the national cryptographic algorithm. Then the ground device changes the SaF field of the AU1 message from 2 to 1, restores it to 3DES data, and sends it to the RBC in the ground device. Then the RBC host considers the data received from the in-vehicle device as 3DES verification data.
[0084] The ground device does not modify the received AU2 message sent by the RBC, maintains the SaF field of the AU2 message as 1, indicating 3DES data, and then sends it to the in-vehicle device. After that, the remaining messages sent by the RBC in the ground device are all processed in the preset 3DES data manner. At the same time, the in-vehicle device does not perform national cryptographic encryption when sending data. Further, the preset 3DES data manner is the 3DES algorithm.
[0085] In the embodiment of the present invention, when the ground device supports the national cryptographic algorithm, before sending communication data to the in-vehicle device, the ground device determines whether the in-vehicle device supports the national cryptographic algorithm and performs different processing on the communication data between the in-vehicle device and the ground device according to the judgment result, including the following processing procedures:
[0086] The AU1 message sent by the in-vehicle device is transmitted in plain text. If the SaF field of its message is 1, it means that the in-vehicle device does not support the national cryptographic algorithm. Then the ground device processes the communication data received from the in-vehicle device according to the preset algorithm logic and sends it to the Radio Block Center (RBC) in the ground device, and also processes the received RBC data according to the preset algorithm logic and sends it to the in-vehicle device.
[0087] The AU1 message sent by the in-vehicle device is transmitted in plain text. If the SaF field of its message is 2, it means that the in-vehicle device supports the national cryptographic algorithm, and the following processing is performed in sequence:
[0088] First, the ground device changes the SaF field of the AU1 message from 2 to 1, restores it to 3DES data, and sends it to the RBC in the ground device. Then the RBC host considers the data received from the in-vehicle device as 3DES verification data.
[0089] Then, the ground device changes the SaF field of the received AU2 message from the RBC from 1 to 2, indicating support for the national cryptographic algorithm. Among them, for the AU2 message, no padding data is added, and no national cryptographic encryption is performed, and it is directly sent to the in-vehicle device.
[0090] Finally, for other data except the AU1 and AU2 messages, the following processing is performed:
[0091] The ground equipment decrypts the data of the on-vehicle equipment received with national cryptography, removes the padding data, and then sends it to the RBC host.
[0092] The ground equipment adds padding data to the data sent by the RBC received, encrypts it with national cryptography, and then sends it to the on-vehicle equipment.
[0093] In the above method, when at least one of the on-vehicle equipment and the ground equipment does not support the national cryptography algorithm, the on-vehicle equipment and the ground equipment do not perform national cryptography encryption and decryption on the corresponding data, and execute according to the preset algorithm logic. The preset algorithm logic can be processed in accordance with the existing 3DES data method, but is not limited thereto, and other data processing methods are applicable to the present invention. In addition, the national cryptography algorithms include but are not limited to SM1, SM2, SM3, SM4, SM7, SM9 algorithms, etc.
[0094] The above method supports cross-communication between on-vehicle equipment without national cryptography function and on-vehicle equipment with national cryptography function and between ground equipment without national cryptography and ground equipment with national cryptography function, adopts different data encryption processing methods for different situations, improves the efficiency of vehicle-ground communication, and improves the safety and reliability of train operation.
[0095] As Figure 3 shown, an embodiment of the present invention introduces a vehicle-ground communication system applied to a train control system that can execute the above method. The system includes on-vehicle equipment and ground equipment. The on-vehicle equipment includes an on-vehicle secure communication unit, and the ground equipment includes a communication network. An encryption management module is also provided in the communication network. Among them, the on-vehicle secure communication unit is used to obtain a second verification message from the communication data sent by the ground equipment, and based on the obtained second verification message, determine whether the ground equipment supports the national cryptography algorithm, so as to perform different processing on the data communicated between the on-vehicle equipment and the ground equipment; the encryption management module is used to obtain a first verification message from the communication data sent by the on-vehicle equipment, and based on the obtained second verification message, determine whether the on-vehicle equipment supports the national cryptography algorithm, so as to perform different processing on the data communicated between the on-vehicle equipment and the ground equipment.
[0096] In an embodiment of the present invention, the ground equipment further includes a secure communication server. The secure communication server is connected to the encryption management module through a switch, and is used to perform national cryptography encryption on the communication data filled with an integer multiple of 16 bytes except the second verification message received from the communication network when both the on-vehicle equipment and the ground equipment support the national cryptography algorithm; and perform national cryptography decryption on the communication data sent by the on-vehicle equipment except the first verification message. The secure communication server is a ground secure communication server.
[0097] In an embodiment of the present invention, the on-vehicle equipment and the ground equipment communicate through a protocol, where
[0098] The first verification message and the second verification message respectively adopt the AU1 message and the AU2 message in the protocol. The AU1 message and the AU2 message are transmitted in plain text. The AU1 message and the AU2 message packets include a security algorithm field. Among them,
[0099] when the value of the security algorithm field in the first verification message and the second verification information packet is the first value, it indicates that the on-vehicle device and the ground device do not support the national cryptography algorithm;
[0100] when the value of the security algorithm field in the first verification message and the second verification information packet is the second value, it indicates that the on-vehicle device and the ground device support the national cryptography algorithm.
[0101] As Figure 4 shown, the on-vehicle device further includes a main control unit, a communication control unit (STUV-V unit), a communication encryption unit (STUV-N unit), and a radio. Among them, the on-vehicle security communication unit is arranged between the communication control unit and the communication encryption unit, is connected through TCP / IP (Transmission Control Protocol / Internet Protocol), and interacts and communicates data with the communication control unit and the communication encryption unit respectively according to the Link Protocol and the Serial_Link transmission protocol. The Link Protocol (link protocol) and the Serial_Link (serial link) transmission protocol are both application layer protocols.
[0102] Furthermore, the main control unit is a C3 main control unit and is connected to the STUV-V unit through MVB (Multifunction Vehicle Bus). The C3 main control unit is the main logic processing unit of the on-vehicle device and is used for train control. The STUV-V unit (the Vital unit of the STU-V device, that is, the communication control unit) is responsible for processing key-related functions. The STUV-N (the Non-Vital unit of the STU-V device, that is, the communication encryption unit) unit is responsible for the communication function with the radio. The STUV-N module is connected to the MT radio through a serial port. The MT radio (Motive Power Transceiver Radio) sends and receives vehicle-ground data. Furthermore, the STUV-V unit and the STUV-N unit are generally used for wired data encryption. An on-vehicle security communication unit is added on the on-vehicle device side. Thus, the on-vehicle security communication unit processes the data sent from the STUV_V unit to the STUV-N unit in sequence as follows:
[0103] ① Obtain the data to be encrypted using the national cryptographic algorithm (i.e., the data sent by the STUV_V unit) according to the Link Protocol and Serial_Link transmission protocols;
[0104] ② Do not perform national cryptographic encryption on the AU1 message and do not add padding bytes, and transmit it as plaintext. Among them, if the vehicle-mounted device supports the national cryptographic algorithm, change the SaF field of the AU1 message packet from 1 to 2 to indicate support for the national cryptographic algorithm.
[0105] ③ Analyze the AU2 message sent by the RBC. If the SaF field of the AU2 message packet is 1 and the RBC does not support the national cryptographic algorithm, then the data sent to the RBC will no longer be encrypted using the national cryptographic algorithm. Only the data obtained by the STUV-V unit according to the LinkProtocol and Serial_Link transmission protocols is sent to the STUV-N unit, and the subsequent steps are not executed. If the RBC supports the national cryptographic algorithm, execute ④.
[0106] ④ For the data to be encrypted using the national cryptographic algorithm, except for the AU1 message, add padding data, and obtain the data encrypted using the national cryptographic algorithm through the vehicle-mounted security communication unit.
[0107] ⑤ Send the encrypted data to the STUV-N unit after obtaining new data according to the Link Protocol and Serial_Link transmission protocols.
[0108] Furthermore, the vehicle-mounted security communication unit processes the data sent by the STUV-N unit to the STUV_V unit as follows:
[0109] 1) Receive the 3DES key of the STUV_N and forward it to the STUV-V unit. Among them, the 3DES key data is the internal communication data between the STUV-N unit and the STUV_V unit, not the communication data between the ATP and the RBC.
[0110] 2) For non-3DES key data, perform the following processing in sequence:
[0111] ① Obtain the data sent by the RBC according to the Link Protocol and Serial_Link transmission protocols;
[0112] ② When receiving the AU2 message sent by the RBC, if the SaF field of the AU2 message packet is 1, indicating that the RBC does not support the national cryptographic algorithm, then the subsequent data sent by the RBC received will not be decrypted using the national cryptographic algorithm and will be directly forwarded to the STUV-V unit, and the subsequent steps will not be executed.
[0113] ③ When receiving the AU2 message sent by the RBC, if the SaF field in the AU2 message packet is 2, it indicates that the RBC supports the national cryptography algorithm. After changing the value of the SaF field in the AU2 message from 2 to 1, the data including only 3DES verification is obtained, and the new data is sent to the STUV-V unit according to the Link Protocol and Serial_Link transmission protocols.
[0114] For communication data other than AU2, after decrypting the data by the national cryptography of the on-vehicle security communication unit, the padding data is deleted, and then the new data is sent to the STUV-N unit according to the Link Protocol and Serial_Link transmission protocols.
[0115] In the embodiment of the present invention, the protocol data preset by the on-vehicle device and the ground device is 3DES data, and the national cryptography algorithm is a layer of packaging on the basis of the 3DES algorithm.
[0116] As Figure 5 shown, the ground device further includes a radio block center, and the radio block center is connected to the communication network through a switch. Preferably, the communication device further includes a plurality of communication networks. Further, the communication network is ISDN (Integrated Services Digital Network). Among them, ISDN includes an ISDN that supports the national cryptography algorithm and an ISDN that does not support the national cryptography algorithm. Among them, the ISDN that does not support the national cryptography algorithm performs the following steps:
[0117] The AU1 message sent by the ATP (i.e., the on-vehicle device) is transmitted in plain text. If the SaF field in its message is 1, it indicates that the ATP does not support the national cryptography. Then the ISDN processes the received ATP data (data sent by the on-vehicle device) according to the preset algorithm logic of the ISDN server software and sends it to the RBC, and processes the received RBC data according to the preset algorithm logic and then sends it to the ATP.
[0118] The AU1 message sent by the ATP is transmitted in plain text. If the SaF field in its message is 2, it indicates that the ATP supports the national cryptography. Then the ISDN changes the SaF field of the AU1 message from 2 to 1, obtains the 3DES data and sends it to the RBC, and the RBC host considers that the received ATP data is 3DES verification data;
[0119] The ISDN does not modify the received AU2 sent by the RBC, maintains the SaF field of the AU2 message packet as 1, indicating 3DES data, and sends it to the ATP. After that, the ISDN processes the remaining communication messages in the existing 3DES data manner (3DES algorithm) (it should be noted that when the ISDN does not support the national cryptography algorithm, the communication data sent by the ATP is also not encrypted by the national cryptography).
[0120] The ISDN supporting national cryptographic algorithms performs the following steps:
[0121] The AU1 message sent by ATP is transmitted in plaintext. If the SaF field of its message is 1, indicating that ATP does not support national cryptography, then the ISDN processes the received ATP data according to the preset algorithm logic and sends it to the RBC, and processes the received RBC data according to the preset algorithm logic and then sends it to ATP. The preset algorithm logic processing includes but is not limited to the 3DES algorithm.
[0122] The AU1 message sent by ATP is transmitted in plaintext. The SaF field of its message is 2, indicating that ATP supports national cryptography, and it is processed in the following order.
[0123] ① For the AU1 message, the ISDN changes the SaF field of the AU1 message from 2 to 1, restores it to 3DES data and sends it to the RBC, then the RBC host considers the received ATP data as 3DES verification data.
[0124] ② After receiving the AU2 message from the RBC, change the SaF field of the AU2 message from 1 to 2 to indicate the message supporting national cryptographic algorithms, do not add padding data, do not perform national cryptography encryption, and send it directly to ATP.
[0125] ③ For other messages (communication data) except AU1 and AU2, the following processing is performed:
[0126] For the data sent by ATP to the RBC, the ISDN sends it to the ground safety communication server according to the communication protocol and then receives the data decrypted by national cryptography (that is, the ground safety communication server decrypts the data by national cryptography), removes the padding data, and sends it to the RBC host according to the protocol between the RBC host and the ISDN server.
[0127] For the data sent by the RBC to ATP, after the ISDN adds padding data, it sends it to the ground safety communication server according to the communication protocol and then receives the data encrypted by national cryptography (that is, the ground safety communication server encrypts the data by national cryptography), and then sends it to ATP in the original processing method (wireless communication method).
[0128] In the above system, a vehicle-mounted safety communication unit is added to the vehicle-mounted device, a safety communication server is added to the ground device, and an encryption and decryption module is set in the ISDN, so as to perform encryption and decryption relying on hardware devices, getting rid of the limitation of relying on software encryption. Thus, while realizing the wireless encryption communication function between the vehicle-mounted device and the ground device, it also supports the cross-communication between the vehicle-mounted devices without national cryptography function and the vehicle-mounted devices with national cryptography function and the ground devices without national cryptography and the ground devices with national cryptography function respectively, greatly improving the data security.
[0129] Furthermore, an external encryption device is added to perform encryption and decryption through hardware. Without modifying in-vehicle software and with minimal modification to ground software, it supports communication between encrypted vehicles and encrypted ground devices, as well as communication between encrypted vehicles and non-encrypted ground devices, and upgrades the device to the greatest extent while ensuring operational efficiency.
[0130] Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A vehicle-to-ground communication method applied to a train control system, characterized in that: include, The on-board device obtains the second verification message from the communication data sent by the ground device, and the ground device obtains the first verification message from the communication data sent by the on-board device; The vehicle-mounted equipment and the ground equipment are connected through Protocol for communication, where The first verification message and the second verification message are respectively The AU1 message and AU2 message in the protocol, wherein the AU1 message and AU2 message message include a security algorithm field, wherein when the security algorithm field of the first verification message and the second verification information message takes a first value, it indicates that the on-board device and the ground device do not support the national encryption algorithm; when the security algorithm field of the first verification message and the second verification information message takes a second value, it indicates that the on-board device and the ground device support the national encryption algorithm; The vehicle-mounted device and the ground device respectively determine whether each other supports the national secret algorithm based on the corresponding verification message obtained, so as to perform different processing on the communication data between the vehicle-mounted device and the ground device, including if it is determined that both support the national secret algorithm, specifically including: The vehicle-mounted device fills the communication data sent except the first verification message into an integer multiple of 16 bytes, and then performs national secret encryption; and, The vehicle-mounted device modifies the security algorithm field of the obtained second verification message to the first value, and obtains 3DES verification data; Decrypt the received non-3DES key data except the second verification message using the national secret code, and then remove the padding bytes; The ground equipment fills the communication data sent except the second verification message to an integer multiple of 16 bytes, and then performs national secret encryption; and, The ground device modifies the security algorithm field of the acquired first verification message to the first value and restores it to 3DES data; The received communication data except the first verification message is decrypted with national secret, and then the padding bytes are removed.
2. The vehicle-to-ground communication method applied to a train control system according to claim 1, characterized in that: The vehicle-mounted device and the ground device respectively determine whether each other supports the national secret algorithm based on the corresponding verification message obtained, so as to perform different processing on the data communicated between the vehicle-mounted device and the ground device, and also include if it is determined that neither of them supports the national secret algorithm, specifically including: The vehicle-mounted equipment does not encrypt the communication data sent, and does not decrypt the communication data received; The ground equipment processes the received and sent communication data according to the preset algorithm logic.
3. The vehicle-to-ground communication method applied to a train control system according to claim 1, characterized in that: The vehicle-mounted device and the ground device respectively determine whether each other supports the national secret algorithm based on the corresponding verification message obtained, so as to perform different processing on the data communicated between the vehicle-mounted device and the ground device. It also includes if it is determined that the vehicle-mounted device supports the national secret algorithm, but the ground device does not support the national secret algorithm, specifically including: The vehicle-mounted equipment does not encrypt the communication data sent, and does not decrypt the communication data received; The ground device modifies the security algorithm field of the acquired first verification message to the first value and restores it to 3DES data; Processing the received communication data except the first verification message according to a preset algorithm logic; as well as, The ground equipment processes the sent communication data according to the preset algorithm logic.
4. The vehicle-to-ground communication method applied to a train control system according to claim 1, characterized in that: The vehicle-mounted device and the ground device respectively determine whether each other supports the national secret algorithm based on the corresponding verification messages obtained, so as to perform different processing on the data communicated between the vehicle-mounted device and the ground device. It also includes if it is determined that the vehicle-mounted device does not support the national secret algorithm, and the ground device supports the national secret algorithm, specifically including: The vehicle-mounted equipment does not encrypt the communication data sent, and does not decrypt the communication data received; The ground equipment processes the received and sent communication data according to the preset algorithm logic.
5. The vehicle-to-ground communication method applied to a train control system according to any one of claims 1-2, characterized in that: The first verification message and the second verification message are both transmitted in plain text.
6. The vehicle-to-ground communication method applied to a train control system according to claim 5, characterized in that: It also includes that if the communication data transmitted inside the vehicle-mounted device is a 3DES key, the vehicle-mounted device directly receives it.
7. The vehicle-to-ground communication method applied to a train control system according to claim 6, characterized in that: The vehicle-mounted device internally adopts a preset transmission protocol to transmit data, and the preset transmission protocol includes Link Protocol and Serial_Link transmission protocol.
8. A vehicle-to-ground communication system applied to a train control system, characterized in that: It includes vehicle-mounted equipment and ground equipment. The vehicle-mounted equipment includes a vehicle-mounted safety communication unit. The ground equipment includes a communication network. The communication network is also provided with an encryption management module. The vehicle-mounted security communication unit is used to obtain a second verification message from the communication data sent by the ground device, and to determine whether the ground device supports the national encryption algorithm based on the obtained second verification message, so as to perform different processing on the data communicated between the vehicle-mounted device and the ground device, including, if it is determined that both support the national encryption algorithm, specifically including: The vehicle-mounted device fills the communication data sent except the first verification message into an integer multiple of 16 bytes, and then performs national secret encryption; and, The vehicle-mounted device modifies the security algorithm field of the obtained second verification message to the first value, and obtains 3DES verification data; Decrypt the received non-3DES key data except the second verification message using the national secret code, and then remove the padding bytes; The encryption management module is used to obtain a first verification message from the communication data sent by the vehicle-mounted device, and to determine whether the vehicle-mounted device supports the national encryption algorithm based on the obtained second verification message, so as to perform different processing on the data communicated between the vehicle-mounted device and the ground device, including if it is determined that both support the national encryption algorithm, specifically including: The ground equipment fills the communication data sent except the second verification message to an integer multiple of 16 bytes, and then performs national secret encryption; and, The ground device modifies the security algorithm field of the acquired first verification message to the first value and restores it to 3DES data; Decrypt the received communication data except the first verification message using the national secret code, and then remove the padding bytes; The first verification message and the second verification message are respectively The AU1 message and AU2 message in the protocol are transmitted in plain text, and the AU1 message and AU2 message include a security algorithm field, wherein: When the security algorithm field value of the first verification message and the second verification information message is the first value, it indicates that the vehicle-mounted device and the ground device do not support the national encryption algorithm; When the security algorithm field of the first verification message and the second verification information message takes the second value, it indicates that the on-board device and the ground device support the national encryption algorithm.
9. The vehicle-to-ground communication system applied to a train control system according to claim 8, characterized in that: The ground equipment also includes a secure communication server, which is connected to the encryption management module through a switch and is used to perform national encryption on the communication data padded with an integer multiple of 16 bytes received from the communication network except for the second verification message when both the vehicle-mounted equipment and the ground equipment support the national encryption algorithm; and to perform national encryption on the communication data received from the vehicle-mounted equipment except for the first verification message.
10. The vehicle-to-ground communication system applied to a train control system according to claim 9, characterized in that: The vehicle-mounted device also includes a main control unit, a communication control unit, a communication encryption unit and a radio station, wherein the vehicle-mounted safety communication unit is arranged between the communication control unit and the communication encryption unit, and exchanges communication data with the communication control unit and the communication encryption unit respectively according to the Link Protocol and Serial_Link transmission protocols.
11. The vehicle-to-ground communication system applied to a train control system according to claim 9, characterized in that: The ground equipment also includes a radio block center, which is connected to the communication network.
Citation Information
Patent Citations
Data transmission method and device, electronic equipment and storage medium
CN118802218A