A 1553b pseudo terminal test device

By designing a 1553B pseudo-terminal test device including BC, RT, MT and spoofed nodes, and using FPGA and oscilloscope to monitor bus signals, the security problem of the 1553B bus system was solved, and the attack detection of spoofed nodes and the security verification of bus transmission were realized.

CN119788579BActive Publication Date: 2026-03-24CHINA ACADEMY OF SPACE TECHNOLOGY
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-02
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

The 1553B bus system lacks authentication, authorization, and encryption mechanisms, making it vulnerable to attacks that tamper with instructions, steal information, and block bus transmissions, leading to system chaos or paralysis.

Method used

Design a test device that includes BC nodes, RT nodes, MT nodes and dummy nodes. Utilize an FPGA and a configurable interface protocol chip to dynamically switch between BC and RT modes through dummy nodes, simulate attack behavior and monitor bus status, and combine an oscilloscope to detect signal waveforms.

Benefits of technology

It effectively verifies whether the bus has been spoofed by BC takeover and RT interference, ensures bus transmission security, detects potential system vulnerabilities, and prevents information leakage and system anomalies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788579B_ABST
    Figure CN119788579B_ABST
Patent Text Reader

Abstract

The application relates to a 1553B bus security test device which comprises a BC node, two RT nodes, an MT node and a camouflage node. The camouflage node accesses the bus, and the camouflage node can dynamically switch between a BC mode and an RT mode; in the BC mode, the camouflage node sends different data from normal BC nodes to initiate bus control behavior; in the RT mode, the address of the camouflage node is configured as an existing RT node address in the bus to simulate the RT node function to access the bus. The device can be used for 1553B bus protocol architecture security evaluation, detection of whether security loopholes exist in the 1553B bus, verification of whether malicious attack nodes can be embedded in the bus, and verification of whether key nodes in the bus can be maliciously used by attackers to cause key information leakage or system abnormality and other consequences.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a 1553B pseudo-terminal testing device, belonging to the field of aerospace component quality assurance and testing technology. Background Technology

[0002] The military standard data bus 1553B is widely used due to its high reliability and real-time performance. It uses shielded twisted-pair cables to interconnect three different terminal devices: bus controller (BC), remote terminal (RT), and bus monitor (MT), forming a half-duplex transmission network with bidirectional transmission capability and a speed of 1Mbps, which greatly improves the system's centralized control, distributed processing, and implementation response capabilities.

[0003] However, this bus architecture presents several typical security challenges for all nodes: Lack of authentication: A single legitimate address and message format are sufficient to establish a RT (Realist) and participate in bus communication. Lack of authorization: Without access control mechanisms, attackers can easily impersonate a BC (Breakpoint Controller) to gain system privileges, execute arbitrary functions, and access all devices. Lack of encryption: Addresses, commands, and data are transmitted in plaintext, making them easily captured and parsed, allowing attackers to readily understand the system's current state and control methods.

[0004] Based on the above issues, it is not difficult to see that the 1553B bus system may be vulnerable to attacks such as tampering with instructions to steal information and blocking bus transmission.

[0005] (1) Tampering with instructions to steal information leads to data transmission errors between subsystems, causing system chaos. If an unauthorized device has physical access to the bus, it can detect idle time when the bus is not occupied and initiate malicious information exchange during that time interval. Each subsystem device will assume that the communication on the bus is initiated by a legitimate BC, thereby responding with instructions that result in information leakage.

[0006] (2) Blocking bus transmission, leading to system paralysis. If an unauthorized device sets an existing RT address, its response to the command word periodically transmitted by the BC will cause a conflict with the original RT response. The BC may notice that communication is not possible on the bus and switch transmissions on redundant channels. However, if the unauthorized device can access each channel, it can attack each channel simultaneously. Summary of the Invention

[0007] The purpose of this invention is to overcome the shortcomings of the prior art and propose a 1553B pseudo-terminal testing device. The main problems to be solved are: verifying whether the bus can be seized by a fake BC and thus control the entire bus transmission; and verifying whether the bus transmission can be interfered with by a fake RT.

[0008] The technical solution adopted in this invention is as follows:

[0009] A 1553B pseudo-terminal testing device includes: one BC node, two RT nodes, one MT node, and one spoofing node;

[0010] The BC node is used to master the bus and is responsible for initiating transactions when transmitting information. The RT nodes are commanded and controlled by the BC nodes. Each RT node is assigned a unique address for communication. The MT node does not respond to any commands, but is only used to monitor and record commands and data on the bus.

[0011] The surrogate node connects to the bus and can dynamically switch between BC mode and RT mode. In BC mode, the surrogate node sends different data than the normal BC node and initiates bus control behavior. In RT mode, the surrogate node address will be configured as the address of an existing RT node on the bus, simulating the function of an RT node to access the bus.

[0012] Furthermore, the BC node is the bus controller node, the RT node is the remote terminal node, and the MT node is the bus monitor node.

[0013] Furthermore, there can only be one BC node on one bus, and the data words sent and received by the BC node under normal circumstances are limited to two types: 0x1111 and 0x2222.

[0014] 4. The 1553B pseudo-terminal testing device according to claim 1, characterized in that: MT nodes do not need to be assigned addresses, and multiple MT nodes are mounted on the bus as needed.

[0015] Furthermore, the 1553B pseudo-terminal testing device uses an FPGA as the main control device, and the interface protocol chip adopts a circuit that supports configurable BC, RT, and MT modes.

[0016] Furthermore, the entire network adopts a transformer-coupled bus connection method, with BC nodes, RT nodes, MT nodes, and dummy nodes all connected to the bus via couplers.

[0017] Furthermore, when the spoofed terminal is dynamically configured to BC mode, it can seize bus control and transmit information with remote terminals on the bus when normal BC nodes are idle.

[0018] Furthermore, when the spoofed terminal is configured in RT mode, the spoofed terminal and the RT node with the same address being simulated simultaneously receive or respond to bus information.

[0019] Furthermore, it also includes an oscilloscope connected to the bus, which, together with the MT node, monitors the bus data status in real time. The MT node reflects the instructions and data information on the bus in real time, and the oscilloscope detects the signal waveform on the bus when the pseudo RT and the actual RT respond together.

[0020] Secondly,

[0021] This invention also proposes a testing method based on a 1553B pseudo-terminal testing device, comprising the following steps:

[0022] (1) Use a normal BC node to send a data word 0x1111 to the 1st sub-address of RT1 node; receive a data word 0x2222 from the 2nd sub-address of RT2 node; send the RT1-RT2 command to make RT1 node send the data word 0x1111 to RT2 node;

[0023] (2) The fake BC node implemented using a fake terminal attempts to send a data word 0x55AA to the 1# sub-address of RT1 node to corrupt the data in the 1# sub-address of RT1 node; attempts to receive a data word 0x2222 from the 2# sub-address of RT2 node to steal key information; observe whether the behavior initiated by the fake BC node is successfully responded to through the MT node and oscilloscope.

[0024] (3) If the attack in step (2) is successful, the fake BC node implemented by the fake terminal sends RT1-RT2 instructions again, so that the RT1 node sends the data word 0x55AA to the RT2 node, and observes whether it further damages the data in the RT2 node.

[0025] (4) Configure the fake terminal to RT mode and assign an existing RT address. Send commands using a normal BC node and observe whether the fake RT node implemented by the fake terminal will also respond.

[0026] (5) When the pseudo-RT node replies with a status word, observe whether the bus signals will overlap, leading to a bus conflict;

[0027] (6) Analyze the status word information replied by the normal RT node, invert it at the pseudo RT node end, and observe whether the bus level will be interfered with.

[0028] (7) If an abnormality occurs in the observation results in steps (2) to (6), it indicates that there is a vulnerability in the 1553B bus system.

[0029] The beneficial effects of this invention compared to the prior art are as follows:

[0030] (1) The device of the present invention can verify whether the bus will be hijacked by a fake BC and thus control the entire bus transmission; and verify whether the bus transmission will be interfered with by a fake RT.

[0031] (2) In this invention, a standard 1553B bus monitor (MT) will be deployed to monitor the bus status in real time. Simultaneously, a waveform monitoring point is also designed in this invention; by connecting it to a high-precision oscilloscope, the bus signal transmission waveform can be detected in real time. Attached Figure Description

[0032] Figure 1 This is a schematic diagram of the composition of a 1553B pseudo-terminal testing device. Detailed Implementation

[0033] To better understand the above technical solutions, the specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0034] This invention proposes a 1553B pseudo-terminal test device to verify whether the bus can be seized by a fake BC and thus control the entire bus transmission; and to verify whether the bus transmission can be interfered with by a fake RT.

[0035] Under normal circumstances, only one valid BC and multiple RTs can exist on the 1553B protocol bus. The BC controls all transactions on the entire bus, and each RT is assigned a unique address for node communication. In this invention, an attacker is simulated to launch an attack, controlling a node in the network to impersonate either the BC or an RT.

[0036] (1) Impersonating a BC. When the real BC is not occupying the bus, the fake terminal is configured as the BC. The fake BC is used to control the bus. The fake BC terminal is used to send BC-RT, RT-BC, and RT-RT commands to check whether the attack is successful.

[0037] (2) Impersonating a RT. Configure the pseudo-terminal address to an existing RT address in the network. Use a BC to send commands to this address and check whether both the pseudo-terminal and the corresponding normal terminal will respond. In addition, analyze the data words sent by the normal RT, invert the bits and use them as the data words of the pseudo-RT terminal, and check the bus status and waveform.

[0038] (3) Monitoring Function. This invention will deploy a standard 1553B bus monitor (MT) to monitor the bus status in real time. Simultaneously, this invention also includes waveform monitoring points; connecting a high-precision oscilloscope allows for real-time detection of the bus signal transmission waveform.

[0039] like Figure 1 As shown, the present invention proposes a 1553B pseudo-terminal testing device, comprising: one BC node, two RT nodes, one MT node, and one spoofing node;

[0040] The BC node is used to master the bus and is responsible for initiating transactions when transmitting information. The RT nodes are commanded and controlled by the BC node. Each RT node is assigned a unique address for communication. The MT node does not respond to any commands and is only used to monitor and record commands and data on the bus.

[0041] The surrogate node connects to the bus and can dynamically switch between BC mode and RT mode. In BC mode, the surrogate node sends different data than the normal BC node and initiates bus control behavior. In RT mode, the surrogate node address will be configured as the address of an existing RT node on the bus, simulating the function of an RT node to access the bus.

[0042] The Bus Controller (BC), Remote Terminal (RT), and Bus Monitor (MT) can perform the functions required by the 1553B bus; the spoofed terminal can be configured in BC mode to initiate bus control behavior; the spoofed terminal can be configured in RT mode to simulate RT function access to the bus; the bus monitor and oscilloscope can monitor bus signal transmission and signal waveforms in real time.

[0043] The BC controls the entire 1553B bus and is responsible for initiating information transmission and other tasks; the RT provides the interface between the relevant unit or subsystem and the 1553B bus, is controlled by the BC, and responds to BC commands; the MT does not respond to any commands, but only monitors and records commands and data on the bus.

[0044] The spoofed terminal can be dynamically configured to BC mode. When the normal BC is idle, it can preempt bus control and transmit information with remote terminals on the bus.

[0045] The spoofed terminal can be configured to RT mode, in which the spoofed terminal can be configured to an existing RT address in the network and can simultaneously receive or respond to bus information.

[0046] Bus monitors and oscilloscopes can monitor bus signal transmission and signal waveforms in real time. The bus monitor (MT) can reflect the instructions and data information on the bus in real time, and the oscilloscope can detect the signal waveforms on the bus when the pseudo-RT and the actual RT respond together.

[0047] Example:

[0048] A 1553B pseudo-terminal testing device mainly consists of: 1. one BC node; 2. two RT nodes; 3. one MT node; and 4. one masquerading node. The functions and implementation methods of each part are described below:

[0049] A single BC node: Theoretically, there can only be one BC on a single bus. The BC acts as the master controller of the bus, initiating all transactions during information transmission. The RT (Relay Response) is controlled and regulated by the BC. This invention uses an FPGA and a 1553B bus interface circuit to construct the BC terminal. For ease of testing, the data words sent and received by the BC under normal circumstances are limited to 0x1111 and 0x2222.

[0050] Two RT nodes: RTs are general nodes in the 1553B bus. A single bus can accommodate 31 RTs, and each RT must be assigned a unique address to communicate. This invention uses an FPGA of the same model as the main control chip, configures the 1553B interface circuit as the RT terminal, and assigns a unique address to each RT terminal.

[0051] One MT node: The MT does not respond to any commands; it is only used to monitor and record commands and data on the bus. The MT does not require address allocation, and multiple MT nodes can be mounted as needed. In this invention, only one MT is implemented using a standard 1553B function board for test data monitoring.

[0052] A dummy node. The dummy node is the core of this invention. It connects to the bus like a normal node, but can dynamically switch between BC and RT modes. In BC mode, it sends data different from a normal BC; in RT mode, its address is configured to an existing RT address on the bus, achieving bus information security detection. This invention uses an FPGA as the main control device, and the interface protocol chip employs a circuit that supports configurable BC, RT, and MT modes.

[0053] The entire network uses a transformer-coupled bus connection method, with each terminal acting as a child node connected to the bus coupler. A high-precision oscilloscope is also connected to the bus to monitor the bus data status in real time, together with the MT (Transformer Mediator).

[0054] During testing, the testing method implemented by the 1553B pseudo-terminal testing device includes the following steps:

[0055] (1) Use a normal BC node to send a data word 0x1111 to the 1st sub-address of RT1 node; receive a data word 0x2222 from the 2nd sub-address of RT2 node; send the RT1-RT2 command to make RT1 node send the data word 0x1111 to RT2 node;

[0056] (2) The fake BC node implemented using a fake terminal attempts to send a data word 0x55AA to the 1# sub-address of RT1 node to corrupt the data in the 1# sub-address of RT1 node; attempts to receive a data word 0x2222 from the 2# sub-address of RT2 node to steal key information; observe whether the behavior initiated by the fake BC node is successfully responded to through the MT node and oscilloscope.

[0057] (3) If the attack in step (2) is successful, the fake BC node implemented by the fake terminal sends RT1-RT2 instructions again, so that the RT1 node sends the data word 0x55AA to the RT2 node, and observes whether it further damages the data in the RT2 node.

[0058] (4) Configure the fake terminal to RT mode and assign an existing RT address. Send commands using a normal BC node and observe whether the fake RT node implemented by the fake terminal will also respond.

[0059] (5) When the pseudo-RT node replies with a status word, observe whether the bus signals will overlap, leading to a bus conflict;

[0060] (6) Analyze the status word information replied by the normal RT node, invert it at the pseudo RT node end, and observe whether the bus level will be interfered with.

[0061] (7) If an abnormality occurs in the observation results in steps (2) to (6), it indicates that there is a vulnerability in the 1553B bus system.

[0062] The device of the present invention can be used for security evaluation of the 1553B bus protocol architecture, detect whether there are security vulnerabilities in the 1553B bus, verify whether malicious attack nodes can be embedded in the bus, and whether key nodes in the bus can be maliciously exploited by attackers, leading to consequences such as leakage of key information or system anomalies.

[0063] The contents not described in detail in this specification are common knowledge to those skilled in the art.

Claims

1. A testing method based on a 1553B spoofing terminal testing device, used to test whether a 1553B bus system has vulnerabilities, characterized in that: The 1553B spoofing terminal testing device includes: one BC node, two RT nodes, one MT node, and one spoofing terminal; the BC node is used to master the bus and is responsible for initiating transactions when transmitting information, and the RT nodes are commanded and controlled by the BC node; each RT node is assigned a unique address for communication; the MT node does not respond to any commands, but is only used to monitor and record commands and data on the bus; The testing methods include: (1) Use a normal BC node to send a data word 0x1111 to the 1st sub-address of RT1 node; receive a data word 0x2222 from the 2nd sub-address of RT2 node; send the RT1-RT2 instruction to make RT1 node send the data word 0x1111 to RT2 node; (2) The fake BC node implemented using a fake terminal attempts to send a data word 0x55AA to the 1# sub-address of RT1 node to corrupt the data in the 1# sub-address of RT1 node; attempts to receive a data word 0x2222 from the 2# sub-address of RT2 node to steal key information; observe whether the behavior initiated by the fake BC node is successfully responded to through the MT node and oscilloscope. (3) If the attack in step (2) is successful, the fake BC node implemented by the fake terminal sends RT1-RT2 instructions again, so that the RT1 node sends the data word 0x55AA to the RT2 node, and observes whether it further damages the data in the RT2 node. (4) Configure the fake terminal to RT mode and assign an existing RT address. Send instructions using a normal BC node and observe whether the fake RT node implemented by the fake terminal will also respond. (5) When the pseudo-RT node replies with a status word, observe whether the bus signals will overlap, leading to a bus conflict; (6) Analyze the status word information replied by the normal RT node, invert it at the pseudo RT node end, and observe whether the bus level will be interfered with; (7) If an abnormality occurs in the observation results in steps (2) to (6), it indicates that there is a vulnerability in the 1553B bus system.

2. The test method according to claim 1, characterized in that: The fake terminal connects to the bus and can dynamically switch between BC mode and RT mode. In BC mode, the fake terminal sends data different from that of the normal BC node and initiates bus control behavior. In RT mode, the fake terminal address will be configured as the address of an existing RT node in the bus to simulate the function of an RT node to access the bus.

3. The test method according to claim 2, characterized in that: The BC node is the bus controller node, the RT node is the remote terminal node, and the MT node is the bus monitor node.

4. The test method according to claim 2, characterized in that: There can only be one BC node on a single bus, and the data words sent and received by the BC node under normal circumstances are limited to two types: 0x1111 and 0x2222.

5. The test method according to claim 2, characterized in that: MT nodes do not require address allocation; multiple MT nodes can be mounted on the bus as needed.

6. The test method according to claim 2, characterized in that: The 1553B spoofing terminal testing device uses an FPGA as the main control device, and the interface protocol chip adopts a circuit that supports configurable BC, RT, and MT modes.

7. The test method according to claim 2, characterized in that: BC nodes, RT nodes, MT nodes, and masquerading terminals are all connected to the bus via couplers.

8. The test method according to claim 2, characterized in that: When a fake terminal is dynamically configured to BC mode, it can seize bus control and transmit information with remote terminals on the bus when normal BC nodes are idle.

9. The test method according to claim 2, characterized in that: When the spoofed terminal is configured in RT mode, the spoofed terminal and the RT node with the same address being simulated simultaneously receive or respond to bus information.

10. The test method according to claim 2, characterized in that: It also includes an oscilloscope, which is connected to the bus and monitors the bus data status in real time together with the MT node. The MT node reflects the instructions and data information on the bus in real time, and the oscilloscope detects the signal waveform on the bus when the pseudo RT node and the actual RT respond together.

Citation Information

Patent Citations

  • Communication security verification method and device, equipment and storage medium

    CN113901478A