Safe nonvolatile data reading and storing method and vehicle-mounted signal system

By introducing a verification code calculation and verification comparison mechanism in the vehicle signal system, the problem of inability to ensure that all processing units acquire or write consistent data in the prior art is solved, and the security, integrity and consistency of system data are achieved, and the security and stability of the system are improved.

CN120011130APending Publication Date: 2025-05-16CASCO SIGNAL LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411864873.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-18
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The prior art cannot guarantee that in a two-by-two-two-to-two-on-two-to-two-on-vehicle system, all processing units can obtain or write secure, complete and consistent data at the same time, resulting in the system being unable to ensure consistency during data reading and writing.

Method used

By introducing a verification code calculation and verification comparison mechanism in the on-board signal system, it is ensured that when each main processing unit reads or writes data from the local storage medium, it performs verification comparison to ensure the consistency of the data. The specific steps include each main processing unit calculating the verification code of the data, comparing it with the verification code in the local storage medium, and if successful, it will be checked and compared with the main processing unit of the same subsystem and another subsystem, and finally output or write the data after the verification of all main processing units is successful.

Benefits of technology

It realizes the on-board system with two-by-two architecture, ensuring that all processing units can obtain or write safe, complete and consistent data at the same time, improving the security and stability of system operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120011130A_ABST
    Figure CN120011130A_ABST
Patent Text Reader

Abstract

The invention relates to a secure nonvolatile data reading and writing method, which comprises the following steps of: reading data from a local storage medium by a main processing unit, and verifying and comparing the data with the data of the local storage medium, the data read by the main processing unit of the same sub-system and the data read by the main processing unit of another sub-system; if verification succeeds, the read data are output to the outside; the writing sub-method comprises the following steps that: the main processing unit acquires external input data and a cyclic redundancy check code of the data, and performs check comparison; and checking and comparing the data with the data acquired by the main processing unit of the same sub-system, and if the checking is successful, writing the data into a local storage medium. Compared with the prior art, the vehicle-mounted signal system based on the double 2-vote-2 architecture has the advantages that the consistency and the correctness of the data are ensured in a mode of carrying out check code calculation on the data and executing check comparison under specific conditions, and safe data reading and writing functions in a local storage medium are realized, and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of rail transportation, and in particular to a method for reading and storing safe non-volatile data and a vehicle-mounted signal system. Background Art

[0002] The signal system in the field of rail transit is of great significance for ensuring the safety of train operation and improving transportation efficiency. The on-board system controls the operation of the train and is the hub of the entire signal system. Users have extremely high requirements for the safety of the on-board system. How to ensure that the processing unit can obtain the same, complete and correct data so that the system can clear and intercept abnormal data to ensure the safe operation of the system is an issue that system developers must focus on.

[0003] At present, the vehicle-mounted system based on the two-by-two-out-of-two architecture generally contains four main processing units, which are divided into two systems, the main and standby systems. Two processing units in each system form a two-out-of-two architecture. In order to ensure the operation of the system, it is necessary to ensure that the four processing units obtain the same security data when reading data. This requires that the processing units within a system and the processing units between systems must ensure data consistency. At the same time, it is also necessary to ensure that all processing units can obtain security data at the same time to ensure the timeliness of the data. When data needs to be updated, it is also necessary to ensure that the data written by the processing unit is consistent and correct.

[0004] After searching, the application publication number CN109240974A discloses a two-by-two-take-two system synchronization method and computer equipment, which specifically discloses: when the first subsystem determines that it is currently the main system, it sends a synchronization message through the first communication channel between the second subsystem; if the confirmation message returned by the second subsystem is obtained through the first communication channel, it is determined that the first subsystem and the second subsystem are in a synchronized state. Communication is carried out by utilizing the first communication channel between the first subsystem and the second subsystem in the system. However, this prior art only realizes the synchronization of the two subsystems, and does not guarantee the consistency of the actual read and write data.

[0005] Therefore, how to design a data reading and storage method that can satisfy the consistency of data acquisition and writing by all processing units is a technical problem that needs to be solved. Summary of the invention

[0006] The purpose of the present invention is to provide a method for reading and storing secure non-volatile data and a vehicle-mounted signal system in order to overcome the defect of the prior art that all processing units cannot simultaneously acquire or write secure data.

[0007] The purpose of the present invention can be achieved by the following technical solutions:

[0008] According to one aspect of the present invention, a method for reading and writing secure non-volatile data is provided. The method is based on a vehicle signal system of a two-by-two-out-of-two architecture, wherein the signal system comprises a plurality of main processing units and a local storage medium, wherein the plurality of main processing units are divided into two subsystems; the method comprises a reading submethod and a writing submethod;

[0009] The reading sub-method includes: each main processing unit reads data from a local storage medium and performs verification and comparison; then each main processing unit verifies and compares the data read by the main processing unit of the same sub-system and the data read by the main processing unit of another sub-system; if all verifications are successful, the read data is output externally;

[0010] The writing sub-method includes: each main processing unit obtains external input data and performs verification and comparison; then each main processing unit verifies and compares the data read by the main processing unit of the same sub-system; if all verifications are successful, the data is written to the local storage medium.

[0011] As a preferred technical solution, the main processing unit calculates a checksum of the data after reading data from a local storage medium or obtaining external input data.

[0012] As a preferred technical solution, the check code is a 32-bit cyclic redundancy check code.

[0013] As a preferred technical solution, the reading sub-method is specifically:

[0014] Step S1, each main processing unit reads data and an existing check code from a local storage medium, and compares the calculated check code with the existing check code. If the check succeeds, step S2 is executed;

[0015] Step S2, each main processing unit is compared with the verification code of the main processing unit of the same sub-system, and if the verification is successful, step S3 is executed;

[0016] Step S3, verify and compare the verification code of each main processing unit with the verification code of the main processing unit of another sub-system, and if the verification is successful, execute step S4;

[0017] Step S4, each main processing unit sends the read data to other main processing units and receives the read data from other main processing units;

[0018] Step S5, each main processing unit verifies and compares the data read by all main processing units, and outputs the read data to the outside if all verifications are successful; otherwise, the data in the local storage medium is cleared.

[0019] As a preferred technical solution, if the compared check codes are consistent and both are not zero, the main processor unit sets the check result to success; otherwise, the check code of the current main processing unit is cleared and the check result is set to failure.

[0020] As a preferred technical solution, in step S4, a cycle is defined. In each cycle, if the main processing unit completes sending and receiving data, it is considered that all the main processing units have completed data reading.

[0021] As a preferred technical solution, the writing sub-method is specifically as follows:

[0022] Step S1, each main processing unit obtains external input data and existing data check codes, and compares the calculated check codes with the existing check codes. If the check succeeds, step S2 is executed;

[0023] Step S2, each main processing unit is compared with the verification code of the main processing unit of the same sub-system, and if the verification is successful, step S3 is executed;

[0024] Step S3: Each main processing unit writes the external input data and the verification code of the data into a local storage medium.

[0025] As a preferred technical solution, in step S1, if the compared check codes are consistent and both are not zero, the main processor unit sets the check result to success; otherwise, the check code of the current main processing unit is cleared and the check result is set to failure.

[0026] As a preferred technical solution, in step S2, if the compared check codes are consistent and both are not zero, the main processor unit sets the check result as successful; otherwise, the system is directed to the safety side.

[0027] According to another aspect of the present invention, there is provided an on-vehicle signal system for executing a method for reading and writing secure non-volatile data, comprising a plurality of main processing units and a local storage medium, wherein the main processing units and the local storage medium are communicatively connected; the plurality of main processing units are divided into two subsystems, and the number of main processing units in each subsystem is the same; the main processing units of the same subsystem are communicatively connected to each other via a universal asynchronous receiver-transmitter transmitter, and the main processing units of different subsystems are communicatively connected to each other via a time-sensitive network.

[0028] Compared with the prior art, the present invention has the following beneficial effects:

[0029] 1) The vehicle signal system based on the two-by-two-out-of-two architecture of the present invention ensures the consistency and correctness of data by calculating the check code of the data and performing the check comparison under specific conditions, and realizes the function of reading and writing secure data in the local storage medium; realizes software reuse, and is suitable for the secure interaction of non-real-time data of the vehicle signal system under the two-by-two-out-of-two architecture;

[0030] 2) The present invention not only ensures the security of data, but also ensures the consistency of data output on all main processing units in the time dimension, thereby improving the security and stability of system operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 A flow chart of a method for reading secure non-volatile data according to the present invention;

[0032] Figure 2 A flow chart of a method for writing secure non-volatile data according to the present invention;

[0033] Figure 3 It is a schematic diagram of the connection structure of multiple main processing units of the present invention. DETAILED DESCRIPTION

[0034] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0035] Example 1

[0036] like Figure 1 As shown, the present invention provides a method for reading secure non-volatile data, which is as follows:

[0037] 1) The main processing unit (CPU) reads data from the local storage medium and calculates the 32-bit cyclic redundancy check code (CRC check code) of the data, and compares it with the check code stored in the local storage medium. If they are inconsistent, the calculated check code is cleared;

[0038] 2) After the CPU completes the local data verification, it compares it with the verification code calculated by the CPU of the same subsystem. If the CPU verification code is non-zero and consistent, the verification passes and the reading result is set as successful. Otherwise, the local verification code is cleared and the reading result is set as failed.

[0039] 3) After completing the data verification in the same subsystem, the CPU sends the processed verification code to the CPU of another subsystem. After receiving the verification code sent by any CPU of another subsystem, it compares it with the local verification code. If it is non-zero and consistent, the verification is passed and the reading result is set to success. Otherwise, the local verification code is cleared and the reading result is set to failure.

[0040] 4) After obtaining the read result, the CPU sends the locally read data to other CPUs every cycle. When the read results of all other CPUs are received within one cycle and the local read result has been sent, it means that all CPUs have completed the reading;

[0041] 5) The CPU compares the reading results of all four CPUs. Only when the reading results of the four CPUs are successful can the security data be output externally, otherwise it will not be output and the data in the local storage medium will be cleared.

[0042] Example 2

[0043] like Figure 2 As shown, the present invention provides a method for writing secure non-volatile data, which is as follows:

[0044] 1) After the main processing unit (CPU) obtains the external input data and data check code, it calculates the 32-bit cyclic redundancy check code (CRC check code) of the data and compares it with the external input check code. If the two CRC check codes are non-zero and consistent, it means that the check is passed, otherwise the calculated check code is cleared;

[0045] 2) The CPU sends the verification code processed locally to another CPU in the same subsystem. After receiving the verification code from the other CPU in the same subsystem, it compares it with the local verification code. If the two verification codes are non-zero and consistent, the verification passes. Otherwise, the system returns to the safe side.

[0046] 3) After the data verification in the subsystem is passed, the data verification code and the data are written into the local storage medium together.

[0047] Example 3

[0048] like Figure 3 As shown, the present invention provides a vehicle-mounted signal system, including multiple main processing units and a local storage medium, the main processing unit (CPU) and the local storage medium are communicatively connected; the multiple main processing units are divided into two subsystems (i.e., forming two microprocessing units MPU), and the number of main processing units in each subsystem is the same; the main processing units of the same subsystem are communicatively connected to each other through a universal asynchronous receiver-transmitter (UART), and the main processing units of different subsystems are communicatively connected to each other through a time-sensitive network (TSN).

[0049] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed by the present invention, and these modifications or replacements should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be based on the protection scope of the claims.

Claims

1. A method for reading and writing secure non-volatile data, characterized in that: The method is based on a vehicle signal system of a two-by-two-take-two architecture, the signal system comprising a plurality of main processing units and a local storage medium, the plurality of main processing units being divided into two subsystems; the method comprising a reading submethod and a writing submethod; The reading sub-method includes: each main processing unit reads data from a local storage medium and performs verification and comparison; then each main processing unit verifies and compares the data read by the main processing unit of the same sub-system and the data read by the main processing unit of another sub-system; if all verifications are successful, the read data is output externally; The writing sub-method includes: each main processing unit obtains external input data and performs verification and comparison; then each main processing unit verifies and compares the data read by the main processing unit of the same sub-system; if all verifications are successful, the data is written to the local storage medium.

2. A method for reading and writing secure non-volatile data according to claim 1, characterized in that: The main processing unit calculates the checksum of the data after reading data from the local storage medium or obtaining external input data.

3. A method for reading and writing secure non-volatile data according to claim 2, characterized in that: The check code is a 32-bit cyclic redundancy check code.

4. A method for reading and writing secure non-volatile data according to claim 2, characterized in that: The reading sub-method is specifically as follows: Step S1, each main processing unit reads data and an existing check code from a local storage medium, and compares the calculated check code with the existing check code. If the check succeeds, step S2 is executed; Step S2, each main processing unit is compared with the verification code of the main processing unit of the same sub-system, and if the verification is successful, step S3 is executed; Step S3, verify and compare the verification code of each main processing unit with the verification code of the main processing unit of another sub-system, and if the verification is successful, execute step S4; Step S4, each main processing unit sends the read data to other main processing units and receives the read data from other main processing units; Step S5, each main processing unit verifies and compares the data read by all main processing units, and outputs the read data to the outside if all verifications are successful; otherwise, the data in the local storage medium is cleared.

5. A method for reading and writing secure non-volatile data according to claim 4, characterized in that: If the compared check codes are consistent and both are not zero, the main processor unit sets the check result as success; otherwise, the check code of the current main processor unit is cleared and the check result is set as failure.

6. A method for reading and writing secure non-volatile data according to claim 4, characterized in that: In the step S4, a cycle is defined. In each cycle, if the main processing unit completes sending and receiving data, it is considered that all the main processing units have completed data reading.

7. A method for reading and writing secure non-volatile data according to claim 2, characterized in that: The writing sub-method is specifically as follows: Step S1, each main processing unit obtains external input data and existing data check codes, and compares the calculated check codes with the existing check codes. If the check succeeds, step S2 is executed; Step S2, each main processing unit is compared with the verification code of the main processing unit of the same sub-system, and if the verification is successful, step S3 is executed; Step S3: Each main processing unit writes the external input data and the verification code of the data into a local storage medium.

8. A method for reading and writing secure non-volatile data according to claim 7, characterized in that: In step S1, if the compared check codes are consistent and both are not zero, the main processor unit sets the check result as successful; otherwise, the check code of the current main processor unit is cleared and the check result is set as failed.

9. A method for reading and writing secure non-volatile data according to claim 7, characterized in that: In step S2, if the compared check codes are consistent and both are not zero, the main processor unit sets the check result as successful; otherwise, the system is directed to the safety side.

10. A vehicle signal system for executing the method for reading and writing secure non-volatile data according to any one of claims 1 to 9, characterized in that: It includes multiple main processing units and local storage media, and the main processing units and local storage media are communicatively connected; the multiple main processing units are divided into two subsystems, and the number of main processing units in each subsystem is the same; the main processing units in the same subsystem are communicatively connected to each other through a universal asynchronous receiver-transmitter transmitter, and the main processing units in different subsystems are communicatively connected to each other through a time-sensitive network.

Citation Information

Patent Citations

  • Two-by-two two-by-two system synchronization method and computer equipment

    CN109240974A