Data processing method and device, electronic equipment and storage medium

By using homomorphic encryption parameters for identity authentication in the train communication system, the problem of unauthorized train intrusion is solved, and communication security and efficiency are improved.

CN119942423APending Publication Date: 2025-05-06CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510203360.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art cannot effectively identify and prevent unauthorized trains from entering the group control system, resulting in poor communication security between trains and low communication efficiency and autonomy.

Method used

By obtaining the identity code of the current train when receiving the data processing request, and determining the encrypted identity code based on the homomorphic encryption parameters, identity authentication and communication processing are performed, ensuring that only authorized trains can communicate effectively.

Benefits of technology

It effectively prevents unauthorized trains from communicating with current trains, realizes identity identification of camouflage trains, and improves the safety, autonomy and efficiency of communication between trains.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119942423A_ABST
    Figure CN119942423A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing method and device, electronic equipment and a storage medium. According to the specific scheme, when a data processing request sent by a first train is received, the identity code of the current train is obtained, and the data processing request comprises homomorphic encryption parameters, a first encrypted identity code corresponding to the identity code of the first train and interaction data carrying train information of a train to be interacted; when the train information of the to-be-interacted train is consistent with the train information of the current train, determining a second encrypted identity code corresponding to the current train based on the identity code of the current train and the homomorphic encryption parameter; and based on the first encrypted identity code and the second encrypted identity code, a to-be-verified result is determined, and when the to-be-verified result meets a preset condition, feedback data, corresponding to the interaction data, of the first train is fed back. According to the invention, the communication efficiency between the trains is improved, and the communication safety and flexibility between the trains are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a data processing method, device, electronic equipment and storage medium. Background Art

[0002] Vehicle-to-vehicle communication is the core of the ad hoc group control system. Vehicle-to-vehicle communication within the group control system mainly relies on wireless communication. However, in the wireless communication scenario, unauthorized trains may disguise themselves as authorized trains to intrude into the group control system and communicate with authorized trains, causing malicious network attacks such as forged and tampered messages.

[0003] At present, the vehicle-to-vehicle communication protocols used in the group control system applied to rail transit are Railway Signal Safety Protocol_I (RSSP_I) or Railway Signal Safety Protocol_II (RSSP_II). At the same time, the ground system determines the train that initiates the communication request and the train that receives the communication request, and notifies the train that initiates the communication request and the train that receives the communication request to modify the corresponding communication configuration. However, the above method cannot identify the identity of unauthorized trains, and cannot prevent unauthorized trains from invading the group control system, resulting in poor communication security between trains. In addition, the method of determining the train that initiates the communication request and the train that receives the communication request between trains and notifying them through the ground system is not only inefficient, but also reduces the autonomy of communication between trains to a certain extent. Summary of the invention

[0004] The present invention provides a data processing method, device, electronic equipment and storage medium, which improve the efficiency of communication between trains and ensure the security and flexibility of communication between trains.

[0005] According to one aspect of the present invention, there is provided a data processing method, which is applied to data communication between a plurality of trains, and the plurality of trains belong to the same group, the method comprising:

[0006] Upon receiving a data processing request sent by the first train, obtaining an identity code of the current train, wherein the data processing request includes a homomorphic encryption parameter, a first encrypted identity code corresponding to the identity code of the first train, and interaction data carrying train information of the train to be interacted with;

[0007] When the train information of the train to be interacted is consistent with the train information of the current train, determining the second encrypted identity code corresponding to the current train based on the identity code and homomorphic encryption parameters of the current train;

[0008] Based on the first encrypted identity code and the second encrypted identity code, a result to be verified is determined, and when the result to be verified meets a preset condition, feedback data corresponding to the first train and the interaction data is fed back.

[0009] According to another aspect of the present invention, there is provided a data processing device for data communication between a plurality of trains, wherein the plurality of trains belong to the same group, the device comprising:

[0010] An identity code acquisition module, configured to acquire the identity code of the current train upon receiving a data processing request sent by the first train, wherein the data processing request includes a homomorphic encryption parameter, a first encrypted identity code corresponding to the identity code of the first train, and interaction data carrying train information of the train to be interacted with;

[0011] An identity code encryption module, used to determine a second encrypted identity code corresponding to the current train based on the identity code and homomorphic encryption parameters of the current train when the train information of the train to be interacted is consistent with the train information of the current train;

[0012] The data feedback module is used to determine the result to be verified based on the first encrypted identity code and the second encrypted identity code, and when the result to be verified meets the preset conditions, feedback data corresponding to the first train and the interaction data is fed back.

[0013] According to another aspect of the present invention, there is provided an electronic device, the electronic device comprising:

[0014] at least one processor; and

[0015] a memory communicatively connected to at least one processor; wherein,

[0016] The memory stores a computer program that can be executed by at least one processor. The computer program is executed by at least one processor so that the at least one processor can execute the data processing method of any embodiment of the present invention.

[0017] According to another aspect of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data processing method of any embodiment of the present invention when executed.

[0018] According to another aspect of the present invention, there is provided a computer program product, comprising a computer program, wherein the computer program implements the data processing method according to any embodiment of the present invention when executed by a processor.

[0019] The technical solution of the embodiment of the present invention obtains the identity code of the current train when receiving the data processing request sent by the first train. When it is detected that the train information of the train to be interacted in the data processing request is consistent with the train information of the current train, the second encrypted identity code corresponding to the current train is determined according to the identity code of the current train and the homomorphic encryption parameters in the data processing request. According to the first encrypted identity code in the data processing request and the second encrypted identity code of the current train, the result to be verified is determined, so that when the result to be verified meets the preset conditions, the first train is determined to be a train in the group to which the current train belongs, and the feedback data corresponding to the interaction data in the data processing request of the first train is fed back to realize the communication processing between the first train and the current train. The identity authentication processing of the first train is performed through the homomorphic encryption parameters to determine that the first train is a train in the group to which the current train belongs, which effectively prevents unauthorized trains from communicating with the current train, realizes the identity identification of the disguised train, and ensures the security of the train communication within the group. Train identity authentication and communication between trains are performed by means of interactive encrypted identity coding between trains, which improves the autonomy and efficiency of communication between trains.

[0020] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0022] Figure 1 is a flow chart of a data processing method provided by an embodiment of the present invention;

[0023] Figure 2 is an example diagram of a train communication scenario provided by an embodiment of the present invention;

[0024] Figure 3 is a flow chart of a data processing method provided by an embodiment of the present invention;

[0025] Figure 4 is a structural schematic diagram of a data processing device provided by an embodiment of the present invention;

[0026] Figure 5 It is a structural schematic diagram of an electronic device for implementing the data processing method of an embodiment of the present invention. DETAILED DESCRIPTION

[0027] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0028] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0029] Embodiment 1

[0030] Figure 1 This is a flow chart of a data processing method provided in the first embodiment of the present invention. This embodiment can be applied to the situation where mutual communication between trains in a group corresponding to a group control system is realized based on homomorphic encryption, and is applied to data communication between multiple trains, and multiple trains belong to the same group. The method can be executed by a data processing device, which can be implemented in the form of hardware and / or software, and the data processing device can be configured in an electronic device such as a mobile phone, a computer or a server. Figure 1 As shown, the method includes:

[0031] S110. When receiving a data processing request sent by the first train, obtain the identity code of the current train, wherein the data processing request includes homomorphic encryption parameters, a first encrypted identity code corresponding to the identity code of the first train, and interaction data carrying train information of the train to be interacted.

[0032] The first encrypted identity code is determined based on the homomorphic encryption parameter, the identity code of the first train, and the preset encryption algorithm number corresponding to the train to be interacted, wherein the preset encryption algorithm number is determined based on the mapping relationship between the identity code and the encryption algorithm number and the identity code of the train to be interacted. The homomorphic encryption parameter can be a parameter determined based on the homomorphic encryption method. For example, if the homomorphic encryption method is an additive homomorphic encryption method, the homomorphic encryption function corresponding to the additive homomorphic encryption method can be expressed as:

[0033] E(m,r)=g m ·r n mod n 2

[0034] Among them, g and n are homomorphic encryption parameters, n represents the product of large prime numbers, and g is the modulus n 2 The generator under . m represents the plaintext information to be encrypted, and r represents a random number. It should be noted that for the above-mentioned additive homomorphic encryption function, it has the following properties: for two plaintexts m1 and m2, E(m1)·E(m2)=E(m1+m2)modn 2 . Optionally, the homomorphic encryption method can also be a fully homomorphic encryption method or a multiplicative homomorphic encryption method. Correspondingly, different homomorphic encryption methods have different corresponding homomorphic encryption parameters. For example, for a homomorphic encryption method based on discrete logarithms, the public key is (p, g, h), where p is a large prime number, g is a generator under the modulus p, and h = g x modp, x represents the private key. Then the corresponding homomorphic encryption function is expressed as follows: E(m) = (g k ,m,h k modp), where k represents a randomly selected key component. It should be noted that the above homomorphic encryption method has the following properties: for two plaintexts m1 and m2, if and but That is, E(m1)×E(m2)=E(m1·m2).

[0035] The first train can be understood as a train that needs to communicate data with the current train. The data processing request may include the first encrypted identity code corresponding to the identity code of the first train, homomorphic encryption parameters, and interactive data carrying train information of the train to be interacted. The identity code of the first train may be an identifier for uniquely representing the identity of the first train. The first encrypted identity code may be an encrypted identity code obtained by homomorphically encrypting the identity code of the first train based on the homomorphic encryption parameters. For the homomorphic encryption parameters corresponding to different homomorphic encryption methods, the encrypted identity codes obtained after homomorphic encryption of the identity code are different. It should be noted that a variety of homomorphic encryption methods can be designed, each homomorphic encryption method is bound to the identity code of the train, and a specific homomorphic encryption algorithm is used to communicate with a specific encoding device. If it is tampered with or is an illegal device, the correct result cannot be decrypted. In the data processing request, the first encrypted identity code corresponds to the homomorphic encryption parameter. The train to be interacted may be the train that the first train wants to communicate data with. The train information may be the train name, train identity code, and other information of the train to be interacted. The interactive data may be understood as the data information that needs to be interacted when the first train communicates data with the train to be interacted.

[0036] When homomorphically encrypting the identity code of the first train, the preset encryption algorithm number of the train to be interacted can be used for processing. The preset encryption algorithm number can be determined based on the identity code of the train to be interacted and the mapping relationship between the identity code and the encryption algorithm number. Calculating the first encrypted identity code by the preset encryption algorithm number can simplify the calculation and improve the calculation efficiency of the first encrypted identity code compared to directly calculating based on the identity code of the train to be interacted. For example, taking the homomorphic encryption parameter as the additive homomorphic encryption parameter as an example, the first encrypted identity code can be expressed as:

[0037] F(B)=E(i,k)=g i ·k n modn 2

[0038] Among them, F(B) represents the first encrypted identity code, F represents the additive homomorphic encryption method, and B represents the identity code of the first train. i represents the identity code of the first train, k represents the preset encryption algorithm number of the train to be interacted, g and n are homomorphic encryption parameters, n represents the product of large prime numbers, g is the modulus n 2 The following generator.

[0039] Specifically, when a data processing request sent by the first train is received, the data processing request is parsed to obtain homomorphic encryption parameters, a first encrypted identity code corresponding to the identity code of the first train, and interaction data carrying train information of the train to be interacted with, so as to determine whether the current train is the train communicating with the first train according to the train information of the train to be interacted with, and to perform identity authentication processing on the first train based on the first encrypted identity code to realize data communication with the first train.

[0040] For example, see Figure 2 ,exist Figure 2 The first train is train J in the group, and the current train is train I in the group. Train J in the group sends a data processing request to train I in the group, wherein the data processing request includes homomorphic encryption parameter A, the identity code of train J in the group encrypted by additive homomorphic encryption method F corresponding to homomorphic encryption parameter A, i.e., the first encrypted identity code B, and interaction data C carrying train information of the train to be interacted. That is, the data processing request includes A+F(B)+C.

[0041] S120. When the train information of the train to be interacted is consistent with the train information of the current train, determine the second encrypted identity code corresponding to the current train based on the identity code and homomorphic encryption parameters of the current train.

[0042] The second encrypted identity code can be determined based on the homomorphic encryption parameters and the identity code of the current train. For example, the homomorphic encryption parameters corresponding to the additive homomorphic encryption method are used as an example. F(D) = E(j, k) = g j ·k n modn 2 , where F(D) represents the second encrypted identity code, F represents the additive homomorphic encryption method, and B represents the identity code of the current train. j represents the identity code of the current train, k can be the identity code of the current train, or it can be the encryption algorithm number corresponding to the current train determined based on the mapping relationship between the identity code and the encryption algorithm number and the identity code of the current train. g and n are homomorphic encryption parameters, n represents the product of large prime numbers, g is the modulus n 2 It should be noted that when the train information of the current train is consistent with the train information of the train to be interacted, k can be understood as the identity code of the train to be interacted or the preset encryption algorithm number of the train to be interacted.

[0043] Specifically, when the train information of the train to be interacted is consistent with the train information of the current train, it means that the first train has not sent the wrong train, and the current train is the train that communicates data with the first train. Then, the identity code of the current train is homomorphically encrypted according to the homomorphic encryption parameters in the data processing request to obtain a second encrypted identity code, so as to perform identity authentication processing on the first train through the second encrypted identity code.

[0044] Exemplarily, in combination with the above example, when the train I in the group receives the data processing request sent by the train J in the group, it determines that the train J in the group has not sent the wrong train according to the train information of the train to be interacted in the data processing request. That is, the train I in the group is the train that performs data communication with the train J in the group. Then, according to the homomorphic encryption parameter and the identity code of the train I in the group, the second encrypted identity code of the train I in the group is determined.

[0045] S130. Determine the result to be verified based on the first encrypted identity code and the second encrypted identity code, and feed back feedback data corresponding to the first train and the interaction data when the result to be verified meets a preset condition.

[0046] The result to be verified may be a result obtained by multiplying the first encrypted identity code and the second encrypted identity code. The preset condition may be understood as a pre-set condition for determining whether the first train is a train in the group to which the current train belongs. The feedback data may be data information corresponding to the interaction data that is fed back after processing the interaction data when determining that the first train is a train in the group to which the current train belongs.

[0047] Specifically, the first encrypted identity code and the second encrypted identity code are multiplied to obtain a result to be verified. When the result to be verified meets the preset condition, it means that the first train is a train in the group to which the current train belongs, that is, the identity authentication of the first train is passed, and the interaction data is processed, and feedback data corresponding to the interaction data is fed back to the first train to realize communication between the first train and the current train.

[0048] In an embodiment of the present invention, the method of conducting data feedback with the first train may be: multiplying the first encrypted identity code and the second encrypted identity code to obtain a result to be verified; determining the code addition result based on the identity code corresponding to the target communication train and the identity code corresponding to the current train, wherein the target communication train is a train in the group to which the current train belongs that conducts data communication with the current train; determining the standard result based on the code addition result, the identity code corresponding to the current train, and the homomorphic encryption parameters; when the result to be verified is consistent with the standard result, determining that the first train and the current train belong to the same group, and sending feedback data corresponding to the interaction data to the first train.

[0049] The target communication train may be a train in the group to which the current train belongs that performs data communication with the current train. In order to prevent the first train from forging the identity of the target communication train and performing data communication with the current train, the identity of the first train may be authenticated according to the result to be verified and the standard result. The coding sum result may be the result obtained by adding the identity code of the target communication train and the identity code of the current train. The standard result may be determined based on the coding sum result, the identity code of the current train, and the homomorphic encryption parameters.

[0050] Specifically, the first encrypted identity code and the second encrypted identity code are multiplied to obtain a result to be verified. The identity code of the target communication train and the identity code of the current train are added to obtain a coded sum result. The coded sum result and the identity code of the current train are processed according to the homomorphic encryption parameters to obtain a standard result. When the result to be verified is consistent with the standard result, it means that the first train is the target communication train, that is, the first train and the current train belong to the same group. The interactive data is processed to obtain feedback data, and the feedback data is sent to the first train.

[0051] Exemplarily, in combination with the above example, the result to be checked is F(B)×F(D). The standard result may be E(i'+j,j)=g i ' +j ·j n modn 2 , where i' represents the identity code of the target communication train, j represents the identity code of the current train, g and n are homomorphic encryption parameters, n represents the product of large prime numbers, and g is the modulus n 2 Generator under. When the result to be verified is F(B)×F(D)=E(i,k)×E(j,k)=E(i'+j,j), that is, i=i'. It can be understood that the first train is the target communication train, and the identity verification of the first train is passed, then the feedback data corresponding to the interaction data of the first train is fed back to the first train. Figure 2 In the example, train I in the group is the current train, and train J in the group is the first train. When it is determined through the above method that the first train is indeed train J in the group, the corresponding feedback data can be fed back to train J in the group to realize communication between train I in the group and train J in the group.

[0052] The technical solution of this embodiment is to obtain the identity code of the current train when receiving the data processing request sent by the first train. When it is detected that the train information of the train to be interacted in the data processing request is consistent with the train information of the current train, the second encrypted identity code corresponding to the current train is determined according to the identity code of the current train and the homomorphic encryption parameters in the data processing request. According to the first encrypted identity code in the data processing request and the second encrypted identity code of the current train, the result to be verified is determined, so that when the result to be verified meets the preset conditions, the first train is determined to be a train in the group to which the current train belongs, and the feedback data corresponding to the interactive data in the data processing request of the first train is fed back to realize the communication processing between the first train and the current train. The identity authentication processing of the first train is performed through the homomorphic encryption parameters to determine that the first train is a train in the group to which the current train belongs, which effectively prevents unauthorized trains from communicating with the current train, realizes the identity identification of the disguised train, and ensures the security of the communication between trains in the group. Train identity authentication and communication between trains are performed by means of interactive encrypted identity codes between trains, which improves the autonomy and efficiency of communication between trains.

[0053] Embodiment 2

[0054] Figure 3 This is a flow chart of a data processing method provided by the second embodiment of the present invention. This embodiment is based on the above embodiment. When the result to be verified does not meet the preset conditions, that is, when the result to be verified is inconsistent with the standard result, data communication can also be established with the first train outside the group by sending a communication connection request. The specific implementation method can refer to the technical solution of this embodiment. Among them, the technical terms that are the same or corresponding to the above embodiment are not repeated here. Figure 3 As shown, the method includes:

[0055] S210. When receiving a data processing request sent by the first train, obtain the identity code of the current train, wherein the data processing request includes homomorphic encryption parameters, a first encrypted identity code corresponding to the identity code of the first train, and interaction data carrying train information of the train to be interacted.

[0056] S220. When the train information of the train to be interacted is consistent with the train information of the current train, determine the second encrypted identity code corresponding to the current train based on the identity code and homomorphic encryption parameters of the current train.

[0057] S230. Determine the result to be verified based on the first encrypted identity code and the second encrypted identity code, and send a communication connection request to the first train when the result to be verified is inconsistent with the standard result.

[0058] The communication connection request carries a third encrypted identity code, which is determined based on homomorphic encryption parameters, the identity code of the current train, and the identity code of the first train. The communication connection request may be a request sent to the first train for establishing data communication.

[0059] Specifically, the first encrypted identity code and the second encrypted identity code are multiplied to obtain a result to be verified. When the result to be verified does not meet the preset condition, that is, when the result to be verified is inconsistent with the standard result, it means that the first train is not a train in the group to which the current train belongs. The received first encrypted identity code is decrypted to obtain the identity code corresponding to the first train, and a data communication request is sent to the first train based on the identity code of the first train to establish data communication between the current train and the first train.

[0060] For example, see Figure 2 , the current train is train I in the group. When the result to be verified is inconsistent with the standard result, it means that the first train is not a train in the group to which the current train belongs. That is, the first train is a train outside the group. Train I in the group sends a communication connection request to the train outside the group, so that the train outside the group is added to the group to which train I in the group belongs based on the communication connection request.

[0061] In an embodiment of the present invention, before sending a communication connection request to the first train, the first encrypted identity code is decrypted based on the homomorphic encryption parameters to obtain the identity code corresponding to the first train; the identity code corresponding to the first train and the identity code corresponding to the current train are added to obtain the code to be processed; and the third encrypted identity code is determined based on the code to be processed, the identity code corresponding to the first train and the homomorphic encryption parameters.

[0062] The code to be processed may be obtained by adding the identity code of the first train and the identity code of the current train. The third encrypted identity code may be obtained by processing the code to be processed and the identity code of the first train based on the homomorphic encryption parameters. For example, the homomorphic encryption parameters corresponding to the additive homomorphic encryption method are used as an example for explanation. The third encrypted identity code may be determined by the following function.

[0063] F(N)=E(j+i,k')=g i+j ·k' n mod n 2

[0064] Wherein, F(N) represents the third encrypted identity code, i represents the identity code of the first train, j represents the identity code of the current train, and i+j represents the code to be processed. k' represents the identity code of the first train, or it can be the encryption algorithm number corresponding to the first train determined based on the mapping relationship between the identity code and the encryption algorithm number and the identity code of the first train. g and n are homomorphic encryption parameters, n represents the product of large prime numbers, g is the modulus n 2 The following generator.

[0065] Specifically, when it is determined that the first train is not a train in the group to which the current train belongs, a communication connection request can be sent to the first train. The communication connection request carries a third encrypted identity code. The specific method for determining the third encrypted identity code can be: decrypting the first encrypted identity code according to the homomorphic encryption parameters to obtain the identity code corresponding to the decrypted first train. The identity code of the first train and the identity code of the current train are added to obtain a code to be processed. The identity code of the first train and the code to be processed are processed using the homomorphic encryption parameters to obtain the third encrypted identity code, so as to send the communication connection request carrying the third encrypted identity code to the first train to establish data communication between the first train and the current train.

[0066] S240. When receiving the fourth encrypted identity code corresponding to the communication connection request fed back by the first train, parse the fourth encrypted identity code, and when the parsing result meets the train joining condition, add the first train to the group to which the current train belongs.

[0067] The fourth encrypted identity code is obtained by multiplying the first encrypted identity code by the third encrypted identity code. For example, in combination with the above example, when the first encrypted identity code is F(B) and the third encrypted identity code is F(N), the fourth encrypted identity code may be F(B)×F(N). The parsing result may be the parsed identity code of the first train and the identity code of the current train. The train joining condition may be a condition for determining that the first train meets the conditions for joining the group to which the current train belongs.

[0068] Specifically, a communication connection request carrying a third encrypted identity code is sent to the first train, so that the first train performs multiplication processing based on the third encrypted identity code and its corresponding first encrypted identity code to obtain a fourth encrypted identity code, and feeds it back to the current train. After receiving the fourth encrypted identity code fed back by the first train, the fourth encrypted identity code is parsed to obtain the parsed identity code of the first train and the identity code of the current train. Based on the properties of the homomorphic encryption method corresponding to the homomorphic encryption parameters, it is determined whether the parsed identity code of the first train and the encrypted identity code corresponding to the identity code of the current train are consistent with the fourth identity code. If they are consistent, it means that the first train meets the train joining conditions, and the first train is added to the group to which the current train belongs.

[0069] In an embodiment of the present invention, a method for determining whether the first train joins the group to which the current train belongs may be: parsing the fourth encrypted identity code to obtain a parsing result, wherein the parsing result includes the identity code of the current train and the identity code of the first train; performing homomorphic encryption processing on the parsed identity code of the current train and the identity code of the first train based on homomorphic encryption parameters to obtain a result to be verified corresponding to the parsing result; when the result to be verified is consistent with the fourth encrypted identity code, adding the first train to the group to which the current train belongs.

[0070] Among them, the result to be verified can be the result obtained after homomorphic encryption processing of the identity code of the first train and the identity code of the current train based on the homomorphic encryption parameters. For example, in combination with the above example, if the fourth encrypted identity code F(N)×F(B) is parsed, and the parsed identity code is homomorphically encrypted, the result to be verified F(N+B) is obtained. If F(N)×F(B)=F(N+B), the first train meets the train joining condition, and the first train is added to the group to which the current train belongs.

[0071] Specifically, when the fourth encrypted identity code fed back by the first train is received, the fourth encrypted identity code is parsed to obtain the identity code of the current train and the identity code of the first train. The identity code of the current train and the identity code of the first train obtained by parsing are homomorphically encrypted using homomorphic encryption parameters to obtain a result to be verified. When the result to be verified is consistent with the fourth encrypted identity code, the first train is added to the group to which the current train belongs.

[0072] Exemplarily, in combination with the above example, when the train outside the group receives a communication connection request carrying the third encrypted identity code F(N), the fourth encrypted identity code of the train I in the group is fed back, that is, F(B)×F(N). The fourth encrypted identity code is parsed to obtain the identity code of the train I in the group and the identity code of the train outside the group. And based on the homomorphic encryption parameters, the parsed identity code of the train I in the group and the identity code of the train outside the group are homomorphically encrypted to obtain the result to be verified F(N+B). When F(B)×F(N)=F(N+B), the train outside the group is added to the group to which the train I in the group belongs.

[0073] In an embodiment of the present invention, after adding the first train to the group to which the current train belongs, the method further includes: assigning an encryption algorithm number corresponding to the identity code to the first train based on the homomorphic encryption method corresponding to the homomorphic encryption parameters, so as to perform homomorphic encryption communication processing with the first train based on the encryption algorithm number.

[0074] The homomorphic encryption method may be an encryption method corresponding to a homomorphic encryption parameter. For example, if the homomorphic encryption parameter is an additive homomorphic encryption parameter, the homomorphic encryption method is an additive homomorphic encryption method. The encryption algorithm number may be determined based on a mapping relationship between the identity code and the encryption algorithm number and the identity code of the first train.

[0075] Specifically, according to the homomorphic encryption method corresponding to the homomorphic encryption parameter, an encryption algorithm number corresponding to the identity code of the first train is assigned to perform homomorphic encryption communication with the first train based on the encryption algorithm number.

[0076] Exemplarily, in combination with the above example, according to the additive homomorphic encryption method, an encryption algorithm number is assigned to the train outside the group, so that the train I in the group or the train in the group to which the train I in the group belongs can communicate with the first train through the encryption algorithm number. It should be noted that if the encryption algorithm number is not assigned to the train outside the group, the train I in the group or the train in the group to which the train I in the group belongs cannot communicate with the train outside the group.

[0077] The technical solution of this embodiment is to obtain the identity code of the current train when receiving the data processing request sent by the first train. When it is detected that the train information of the train to be interacted in the data processing request is consistent with the train information of the current train, the second encrypted identity code corresponding to the current train is determined according to the identity code of the current train and the homomorphic encryption parameters in the data processing request. According to the first encrypted identity code in the data processing request and the second encrypted identity code of the current train, the result to be verified is determined, so that when the result to be verified is inconsistent with the standard result, the first train is determined to be a train outside the group to which the current train belongs, and a communication connection request is sent to the first train. By verifying whether the result to be verified is consistent with the standard result, the identity authentication of the first train can be realized, and forged messages, malicious messages and tampered messages when communicating between trains under the group control system can be avoided, thereby ensuring the security group of train communication. When the fourth encrypted identity code corresponding to the communication connection request fed back by the first train is received, the fourth encrypted identity code is parsed, so that when the parsing result meets the train joining condition, the first train is added to the group to which the current train belongs. Based on the above four communications, it can be determined whether the first train is a train that applies to join the group to which the current train belongs, and a two-way verification can be realized. In the above manner, the present invention can autonomously determine whether the first train is a train requesting to join the group to which the current train belongs, without the need for confirmation by the ground system, which not only improves the autonomy of communication between trains, but also can be used when the train-ground communication is interrupted. In addition, while improving the security, autonomy and efficiency of communication between trains, the present invention does not require the transmission of public keys, thus avoiding the risk of key leakage.

[0078] Embodiment 3

[0079] Figure 4 Schematic diagram of the structure of a data processing device provided by Embodiment 3 of the present invention. Figure 4 As shown, the device includes: an identity code acquisition module 310 , an identity code encryption module 320 and a data feedback module 330 .

[0080] The identity code acquisition module 310 is used to obtain the identity code of the current train when receiving the data processing request sent by the first train, wherein the data processing request includes homomorphic encryption parameters, the first encrypted identity code corresponding to the identity code of the first train, and interaction data carrying the train information of the train to be interacted; the identity code encryption module 320 is used to determine the second encrypted identity code corresponding to the current train based on the identity code of the current train and the homomorphic encryption parameters when the train information of the train to be interacted is consistent with the train information of the current train; the data feedback module 330 is used to determine the result to be verified based on the first encrypted identity code and the second encrypted identity code, and when the result to be verified meets the preset conditions, feedback data corresponding to the first train and the interaction data are fed back.

[0081] The technical solution of this embodiment is to obtain the identity code of the current train when receiving the data processing request sent by the first train. When it is detected that the train information of the train to be interacted in the data processing request is consistent with the train information of the current train, the second encrypted identity code corresponding to the current train is determined according to the identity code of the current train and the homomorphic encryption parameters in the data processing request. According to the first encrypted identity code in the data processing request and the second encrypted identity code of the current train, the result to be verified is determined, so that when the result to be verified meets the preset conditions, the first train is determined to be a train in the group to which the current train belongs, and the feedback data corresponding to the interactive data in the data processing request of the first train is fed back to realize the communication processing between the first train and the current train. The identity authentication processing of the first train is performed through the homomorphic encryption parameters to determine that the first train is a train in the group to which the current train belongs, which effectively prevents unauthorized trains from communicating with the current train, realizes the identity identification of the disguised train, and ensures the security of the communication between trains in the group. Train identity authentication and communication between trains are performed by means of interactive encrypted identity codes between trains, which improves the autonomy and efficiency of communication between trains.

[0082] Based on the above embodiment, optionally, the first encrypted identity code is determined based on the homomorphic encryption parameters, the identity code of the first train and the preset encryption algorithm number corresponding to the train to be interacted, wherein the preset encryption algorithm number is determined based on the mapping relationship between the identity code and the encryption algorithm number and the identity code of the train to be interacted.

[0083] Optionally, a data feedback module is used to multiply the first encrypted identity code and the second encrypted identity code to obtain a result to be verified; determine the code addition result based on the identity code corresponding to the target communication train and the identity code corresponding to the current train, wherein the target communication train is a train in the group to which the current train belongs that communicates data with the current train; determine the standard result based on the code addition result, the identity code corresponding to the current train, and the homomorphic encryption parameters; when the result to be verified is consistent with the standard result, determine that the first train and the current train belong to the same group, and send feedback data corresponding to the interaction data to the first train.

[0084] Optionally, the device also includes a train joining group module, which includes: a communication connection request sending unit, used to send a communication connection request to the first train, wherein the communication connection request carries a third encrypted identity code, and the third encrypted identity code is determined based on homomorphic encryption parameters, the identity code of the current train, and the identity code of the first train; a train joining group unit, used to parse the fourth encrypted identity code when receiving the fourth encrypted identity code corresponding to the communication connection request fed back by the first train, and when the parsing result meets the train joining condition, add the first train to the group to which the current train belongs, wherein the fourth encrypted identity code is obtained by multiplying the first encrypted identity code by the third encrypted identity code.

[0085] Optionally, the train joining group module also includes: a third encrypted identity code determination unit, which is used to decrypt the first encrypted identity code based on the homomorphic encryption parameters to obtain the identity code corresponding to the first train; add the identity code corresponding to the first train and the identity code corresponding to the current train to obtain the code to be processed; determine the third encrypted identity code according to the code to be processed, the identity code corresponding to the first train and the homomorphic encryption parameters.

[0086] Optionally, a train joins a group unit, which is used to parse the fourth encrypted identity code to obtain a parsing result, wherein the parsing result includes the identity code of the current train and the identity code of the first train; based on the homomorphic encryption parameters, the parsed identity code of the current train and the identity code of the first train are homomorphically encrypted to obtain a result to be verified corresponding to the parsing result; when the result to be verified is consistent with the fourth encrypted identity code, the first train is added to the group to which the current train belongs.

[0087] Optionally, the train joining group module also includes: an encryption algorithm number allocation unit, which is used to allocate an encryption algorithm number corresponding to the identity code to the first train based on the homomorphic encryption method corresponding to the homomorphic encryption parameters, so as to perform homomorphic encryption communication processing with the first train based on the encryption algorithm number.

[0088] The data processing device provided in the embodiment of the present invention can execute the data processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0089] Embodiment 4

[0090] Figure 51 is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0091] like Figure 5 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0092] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0093] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs the various methods and processes described above, such as a data processing method.

[0094] In some embodiments, the data processing method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data processing method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to perform the data processing method in any other appropriate manner (e.g., by means of firmware).

[0095] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0096] The computer program for implementing the data processing method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program can be executed entirely on the machine, partially on the machine, partially on the machine as a stand-alone software package and partially on a remote machine, or entirely on a remote machine or server.

[0097] Embodiment 5

[0098] Embodiment 5 of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to cause a processor to execute a data processing method, the method comprising:

[0099] Upon receiving a data processing request sent by the first train, the identity code of the current train is obtained, wherein the data processing request includes homomorphic encryption parameters, a first encrypted identity code corresponding to the identity code of the first train, and interaction data carrying train information of the train to be interacted with; when the train information of the train to be interacted with is consistent with the train information of the current train, based on the identity code of the current train and the homomorphic encryption parameters, the second encrypted identity code corresponding to the current train is determined; based on the first encrypted identity code and the second encrypted identity code, a result to be verified is determined, and when the result to be verified meets a preset condition, feedback data corresponding to the first train and the interaction data is fed back.

[0100] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0101] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0102] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0103] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0104] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0105] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A data processing method, characterized in that: Applicable to data communication between multiple trains, and the multiple trains belong to the same group, including: Upon receiving a data processing request sent by a first train, obtaining an identity code of the current train, wherein the data processing request includes a homomorphic encryption parameter, a first encrypted identity code corresponding to the identity code of the first train, and interaction data carrying train information of a train to be interacted with; When the train information of the train to be interacted is consistent with the train information of the current train, determining a second encrypted identity code corresponding to the current train based on the identity code of the current train and the homomorphic encryption parameter; Based on the first encrypted identity code and the second encrypted identity code, a result to be verified is determined, and when the result to be verified meets a preset condition, feedback data corresponding to the first train and the interaction data is fed back.

2. The method according to claim 1, characterized in that The first encrypted identity code is determined based on the homomorphic encryption parameters, the identity code of the first train and the preset encryption algorithm number corresponding to the train to interact, wherein the preset encryption algorithm number is determined based on the mapping relationship between the identity code and the encryption algorithm number and the identity code of the train to interact.

3. The method according to claim 1, characterized in that The determining the result to be verified based on the first encrypted identity code and the second encrypted identity code, and feeding back feedback data corresponding to the first train and the interaction data when the result to be verified meets a preset condition, includes: Multiplying the first encrypted identity code and the second encrypted identity code to obtain a result to be verified; Determine a code sum result based on an identity code corresponding to a target communication train and an identity code corresponding to the current train, wherein the target communication train is a train in a group to which the current train belongs that performs data communication with the current train; Determine a standard result according to the coded sum result, the identity code corresponding to the current train and the homomorphic encryption parameter; When the result to be verified is consistent with the standard result, it is determined that the first train and the current train belong to the same group, and feedback data corresponding to the interaction data is sent to the first train.

4. The method according to claim 3, characterized in that When the result to be verified is inconsistent with the standard result, the method further includes: Sending a communication connection request to the first train, wherein the communication connection request carries a third encrypted identity code, and the third encrypted identity code is determined based on the homomorphic encryption parameter, the identity code of the current train, and the identity code of the first train; Upon receiving the fourth encrypted identity code corresponding to the communication connection request fed back by the first train, the fourth encrypted identity code is parsed, and when the parsing result meets the train joining condition, the first train is added to the group to which the current train belongs, wherein the fourth encrypted identity code is obtained by multiplying the first encrypted identity code by the third encrypted identity code.

5. The method according to claim 4, characterized in that Before sending the communication connection request to the first train, the method further includes: Based on the homomorphic encryption parameters, decrypting the first encrypted identity code to obtain an identity code corresponding to the first train; Adding the identity code corresponding to the first train and the identity code corresponding to the current train to obtain a code to be processed; A third encrypted identity code is determined according to the code to be processed, the identity code corresponding to the first train, and the homomorphic encryption parameters.

6. The method according to claim 4, characterized in that The parsing of the fourth encrypted identity code and, when the parsing result satisfies a train joining condition, adding the first train to the group to which the current train belongs includes: Parsing the fourth encrypted identity code to obtain a parsing result, wherein the parsing result includes the identity code of the current train and the identity code of the first train; Based on the homomorphic encryption parameter, homomorphic encryption is performed on the identity code of the current train and the identity code of the first train obtained by parsing, so as to obtain a result to be verified corresponding to the parsing result; When the result to be verified is consistent with the fourth encrypted identity code, the first train is added to the group to which the current train belongs.

7. The method according to claim 4, characterized in that After adding the first train to the group to which the current train belongs, the method further includes: Based on the homomorphic encryption method corresponding to the homomorphic encryption parameters, an encryption algorithm number corresponding to the identity code is assigned to the first train, so as to perform homomorphic encryption communication processing with the first train based on the encryption algorithm number.

8. A data processing device, characterized in that: Applicable to data communication between multiple trains, and the multiple trains belong to the same group, including: an identity code acquisition module, configured to acquire the identity code of the current train upon receiving a data processing request sent by the first train, wherein the data processing request includes a homomorphic encryption parameter, a first encrypted identity code corresponding to the identity code of the first train, and interaction data carrying train information of the train to be interacted with; An identity code encryption module, used to determine a second encrypted identity code corresponding to the current train based on the identity code of the current train and the homomorphic encryption parameter when the train information of the train to be interacted is consistent with the train information of the current train; A data feedback module is used to determine a result to be verified based on the first encrypted identity code and the second encrypted identity code, and to feed back feedback data corresponding to the first train and the interaction data when the result to be verified meets a preset condition.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the data processing method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data processing method according to any one of claims 1 to 7 when executed.