Non-security layer configuration method and device in RSSP-I security communication protocol stack

By obtaining the other party's communication node address ID, IP address and UDP port number during the communication process, the problem of large configuration workload and error-prone in the prior art is solved, and the non-security layer configuration is simplified and efficiency improvement is achieved.

CN120017734APending Publication Date: 2025-05-16CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510146491.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the prior art, the RSSP-I secure communication protocol stack needs to be configured with a large number of communication node address IDs, IP addresses and UDP port numbers before operation, resulting in large configuration workloads and error-prone.

Method used

The non-security layer configuration process is simplified by obtaining the other party's communication node address ID, IP address and UDP port number during the communication process. The specific method includes the communication sender initiates a secure connection request to the railway dedicated LAN through broadcast, and receives and records the IP address, UDP port number and communication node address ID in the secure connection response from the communication recipient.

Benefits of technology

This greatly simplifies the configuration work of non-security layers, reduces the possibility of configuration errors, and improves configuration efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017734A_ABST
    Figure CN120017734A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and provides a non-security layer configuration method and device in an RSSP-I security communication protocol stack, and the method comprises the steps: a communication sender configures a communication node address ID, an IP address and a UDP port number of the sender; the communication sender opens a UDP port according to the configured local IP address and the UDP port number; the communication sender uses the opened UDP port to initiate a secure connection request to the railway special local area network through broadcast; the communication sender receives the secure connection response from the communication receiver, and acquires and records the IP address, the UDP port number and the communication node address ID information of the communication receiver; and taking the recorded information as the configured IP address, UDP port number and communication node address ID of the opposite side communication. The address ID, the IP address and the UDP port number of the communication node of the opposite side are obtained in the communication process, so that the configuration work of a non-security layer can be simplified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure belongs to the field of communication technology, and in particular, relates to a method and device for configuring a non-security layer in an RSSP-I security communication protocol stack. Background Art

[0002] RSSP-I (Railway Signal Safety Protocol) safety communication protocol stack (hereinafter referred to as the "protocol stack") is a protocol used for communication between railway signal equipment applications. It can protect against the six communication risks specified in the EN50159 standard, and its safety integrity level can reach SIL4.

[0003] The protocol stack adopts a layered structure, such as Figure 1 As shown in the figure, it can be divided into a security layer and a non-security layer. The security layer assumes the security function and protects against communication risks. The non-security layer does not assume the security function and is mainly responsible for managing redundant channels and parameters related to the network transport layer such as IP addresses and UDP port numbers.

[0004] The application is the user of the protocol stack. The protocol stack provides an application adaptation layer. The application and the protocol stack transmit information to each other in the form of primitives. Each application has a unique communication node address ID, and the protocol stack distinguishes applications by the communication node address ID.

[0005] The protocol stack also provides a network adaptation layer and a system adaptation layer to adapt to different network transport layer communication methods and different operating environments. Usually, the network transport layer uses UDP.

[0006] Both communicating parties need to configure their own and the other party's communication node address ID, IP address and UDP port number in the non-security layer in advance. The communicating parties open the UDP port according to their own IP address and UDP (User Datagram Protocol) port number in the configuration. The applications of both communicating parties initiate (Real-time Safety Data) RSD messages. The receiving end must detect the RSD timing from the sending end in real time. If there is a timing error, the timing correction mechanism is triggered, and the RSD message is accepted only after the timing correction is restored. If the current timing is normal, it is only necessary to send RSD in real time in one direction without triggering the timing correction.

[0007] In the existing solution, the communication node address ID, IP address and UDP port number of the local party and all possible connection partners must be configured in the non-secure layer before the protocol stack runs. When there are hundreds or even thousands of possible connection partners, the problem of this solution is that the communication node address ID, IP address and UDP port number of all possible connection partners need to be configured, which is labor-intensive and error-prone. Summary of the invention

[0008] To solve the above problems, the present invention provides a method and device for configuring a non-security layer in an RSSP-I secure communication protocol stack, which obtains the communication node address ID, IP address and UDP port number of the other party during the communication process, thereby simplifying the configuration of the non-security layer.

[0009] In a first aspect, a method for configuring a non-security layer in an RSSP-I secure communication protocol stack is provided, the method comprising:

[0010] The communication sender configures its own communication node address ID, IP address and UDP port number;

[0011] The communication sender opens the UDP port according to the configured IP address and UDP port number;

[0012] The communication sender uses the open UDP port to initiate a secure connection request to the railway dedicated LAN through broadcasting;

[0013] The communication sender receives a secure connection response from the communication receiver, obtains and records the communication receiver's IP address, UDP port number, and communication node address ID;

[0014] The recorded communication recipient's IP address, UDP port number, and communication node address ID are used as the configured other party's communication IP address, UDP port number, and communication node address ID.

[0015] Furthermore, the method further comprises:

[0016] Monitor the status of the security connection of each communication recipient;

[0017] When it is detected that the security connection is in a disconnected state, the IP address, UDP port number and communication node address ID of the communication receiver are cleared.

[0018] In a second aspect, a method for configuring a non-security layer in an RSSP-I secure communication protocol stack is provided, the method comprising:

[0019] The communication receiver configures its own communication node address ID, IP address and UDP port number;

[0020] The communication receiver uses the configured UDP port number to receive the secure connection response from the communication sender, obtains and records the communication receiver's IP address, UDP port number and communication node address ID;

[0021] The communication receiver uses the recorded IP address, UDP port number and communication node address ID of the communication receiver as the configured IP address, UDP port number and communication node address ID of the other party;

[0022] The communication receiver sends a secure connection response to the communication sender so that the communication sender can obtain and record the IP address, UDP port number and communication node address ID of the communication receiver.

[0023] Furthermore, the method further comprises:

[0024] Monitor the status of the security connection of each communication sender;

[0025] When it is detected that the security connection is disconnected, the IP address, UDP port number and communication node address ID of the communication sender are cleared.

[0026] In a third aspect, a non-security layer configuration device in an RSSP-I security communication protocol stack is provided, the device comprising: a configuration unit, a sending unit, a receiving unit and a processing unit; wherein:

[0027] A configuration unit, used to configure the communication node address ID, IP address and UDP port number of the party;

[0028] The sending unit is used to open the UDP port according to the configured local IP address and UDP port number; and initiate a secure connection request to the railway dedicated LAN by broadcasting using the opened UDP port;

[0029] A receiving unit, configured to receive a secure connection response from a communication receiving party;

[0030] The processing unit is used to obtain and record the IP address, UDP port number and communication node address ID of the communication recipient; and use the recorded IP address, UDP port number and communication node address ID of the communication recipient as the configured IP address, UDP port number and communication node address ID of the other party.

[0031] Furthermore, the device also includes:

[0032] A monitoring unit, used to monitor the status of the security connection of each communication recipient;

[0033] The processing unit is also used to clear the IP address, UDP port number and communication node address ID of the communication receiver when it is detected that the security connection is in a disconnected state.

[0034] In a fourth aspect, a non-security layer configuration device in an RSSP-I security communication protocol stack is provided, the device comprising: a configuration unit, a receiving unit, a processing unit and a sending unit; wherein:

[0035] A configuration unit, used to configure the communication node address ID, IP address and UDP port number of the party;

[0036] A receiving unit, used for receiving a secure connection response from a communication sender using a configured UDP port number;

[0037] The processing unit is used to obtain and record the IP address, UDP port number and communication node address ID of the communication recipient; the communication recipient uses the recorded IP address, UDP port number and communication node address ID of the communication recipient as the configured IP address, UDP port number and communication node address ID of the other party;

[0038] The sending unit is used to send a secure connection response to the communication sender so that the communication sender can obtain and record the IP address, UDP port number and communication node address ID of the communication receiver.

[0039] Furthermore, the device further comprises:

[0040] A monitoring unit, used to monitor the status of the security connection of each communication sender;

[0041] The processing unit is also used to clear the IP address, UDP port number and communication node address ID of the communication sender when it is detected that the security connection is in a disconnected state.

[0042] In a fifth aspect, an electronic device is provided, comprising at least one processor and at least one storage medium electrically connected; the storage medium is connected to the processor bus; wherein,

[0043] The storage medium stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the above-mentioned non-security layer configuration method in the RSSP-I security communication protocol stack.

[0044] In a sixth aspect, a computer storage medium is provided, wherein the storage medium stores instructions that can be executed by at least one processor; the instructions are executed by the at least one processor so that the at least one processor can execute the above-mentioned non-security layer configuration method in the RSSP-I secure communication protocol stack.

[0045] Compared with the prior art, the present invention has the following advantages:

[0046] The communicating parties do not need to configure each other's communication node address ID, IP address and UDP port number. Instead, they obtain them during the communication process, which greatly simplifies the configuration of the non-security layer.

[0047] Other features and advantages of the present disclosure will be described in the following description, and partly become apparent from the description, or be understood by implementing the present disclosure. The purpose and other advantages of the present disclosure can be realized and obtained by the structures pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0049] Figure 1 The hierarchical structure of the protocol stack is shown;

[0050] Figure 2 A schematic diagram of a method for configuring a non-security layer in an RSSP-I secure communication protocol stack according to an embodiment of the present disclosure is shown;

[0051] Figure 3 A schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0052] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.

[0053] Figure 2 A schematic diagram of a method for configuring a non-security layer in an RSSP-I secure communication protocol stack according to an embodiment of the present disclosure is shown. Figure 2 The communication nodes 1 and 2 are included in the communication. The communication node 1 is the communication sender and the communication node 2 is the communication receiver. Figure 2 As shown, the non-security layer configuration method in the RSSP-I security communication protocol stack of the embodiment of the present disclosure is applied to the following steps:

[0054] Step (1): Communication node 1 configures its own communication node address ID, IP address and UDP port number; Communication node 2 configures its own communication node address ID, IP address and UDP port number;

[0055] In this step (1), the non-security layer of the protocol stack of the communicating parties does not need to configure the communication node address ID, IP address and UDP port number of the other party, but only needs to configure the communication node address ID, IP address and UDP port number of their own party.

[0056] Step (2): Communication node 1 opens the UDP port according to the local IP address and UDP port number in the configuration. Communication node 2 opens the UDP port according to the local IP address and UDP port number in the configuration.

[0057] Specifically, you can open the UDP port number by setting the socket and opening the socket. In short, it is to enable the network.

[0058] Step (3): Communication node 1 uses the opened UDP port to initiate a secure connection request to the railway dedicated local area network through broadcasting. The secure connection request carries the IP address, UDP port number and communication node address ID of communication node 1;

[0059] Specifically, the secure connection request message is an RSD message;

[0060] Step (4): Each communication node 2 in the railway dedicated LAN receives the RSD message sent by the communication node 1, parses the received security connection request, obtains the IP address, UDP port number and communication node address ID of the communication node 1 and records them;

[0061] Step (5): Each communication node 2 in the railway dedicated LAN replies to the security connection request and sends a security connection response to the communication node 1. The security connection response carries the IP address, UDP port number and communication node address ID of the communication node 2.

[0062] Specifically, each communication node 2 detects the RSD timing from the communication node 1 in real time. If there is a timing error, an SSE message is sent to the communication node 1; if the timing is correct, an RSD message is sent; the SSE message sent to the communication node 1 and the RSD message contain the IP address, UDP port number and communication node address ID of the communication node 2;

[0063] Step (6): Communication node 1 receives the security connection response from each communication node 2, parses the received security connection response, and obtains the IP address, UDP port number and communication node address ID of communication node 2.

[0064] Specifically, communication node 1 receives the RSD message or the SSE message, parses the received RSD message or the SSE message, and obtains the IP address, UDP port number, and communication node address ID of communication node 2.

[0065] At this point, the non-secure layer connection is successful.

[0066] The secure layer then continues to exchange other messages through the non-secure layer, ultimately establishing a secure connection. Applications can send and receive application data through the secure connection.

[0067] Figure 2 In the process, after the connection is successful, step (7) of periodic communication is performed. Figure 2 In the diagram, solid lines with arrows represent control flow, and dashed lines with arrows represent data flow.

[0068] It can be seen from this that communication node 1 establishes a secure connection with each communication node 2 by broadcasting, and each communication node 2 can obtain the IP address, UDP port number and communication node address ID of communication node 1. Communication node 2 only needs to record and save them without configuring the IP address, UDP port number and communication node address ID of communication node 1; further, communication node 1 receives the secure connection response of each communication node 2, and can accurately obtain the IP address, UDP port number and communication node address ID of each communication node 2 without any configuration.

[0069] Through the solution of the embodiments of the present disclosure, the communicating parties do not need to configure their own communication node address ID, IP address and UDP port number, but can obtain them during the communication process, which greatly simplifies the configuration work of the non-security layer.

[0070] When communication node 1 and communication node 2 detect that the security connection is disconnected, for example, there is no data for more than a set period of time, the communicating parties clear the communication node address ID, IP address and UDP port number of the other party.

[0071] In addition, if the other party's communication node address ID, IP address or port number changes, there is no need to shut down to modify the protocol stack configuration or re-run the protocol stack. Communication node 1 can re-establish a secure connection by broadcasting a secure connection request to the railway-specific LAN where it is located, and regain the IP address, UDP port number and communication node address ID of each communication node 2.

[0072] Based on the above method, the embodiment of the present disclosure also provides a device corresponding to the above method, including: a configuration unit, a sending unit, a receiving unit and a processing unit; wherein:

[0073] A configuration unit, used to configure the communication node address ID, IP address and UDP port number of the party;

[0074] The sending unit is used to open the UDP port according to the configured local IP address and UDP port number; and initiate a secure connection request to the railway dedicated LAN by broadcasting using the opened UDP port;

[0075] A receiving unit, configured to receive a secure connection response from a communication receiving party;

[0076] The processing unit is used to obtain and record the IP address, UDP port number and communication node address ID of the communication recipient; and use the recorded IP address, UDP port number and communication node address ID of the communication recipient as the configured IP address, UDP port number and communication node address ID of the other party.

[0077] Furthermore, the device also includes:

[0078] A monitoring unit, used to monitor the status of the security connection of each communication recipient;

[0079] The processing unit is also used to clear the IP address, UDP port number and communication node address ID of the communication receiver when it is detected that the security connection is in a disconnected state.

[0080] Based on the above method, the embodiment of the present disclosure further provides another device corresponding to the above method, including: a configuration unit, a receiving unit, a processing unit and a sending unit; wherein:

[0081] A configuration unit, used to configure the communication node address ID, IP address and UDP port number of the party;

[0082] A receiving unit, used for receiving a secure connection response from a communication sender using a configured UDP port number;

[0083] The processing unit is used to obtain and record the IP address, UDP port number and communication node address ID of the communication recipient; the communication recipient uses the recorded IP address, UDP port number and communication node address ID of the communication recipient as the configured IP address, UDP port number and communication node address ID of the other party;

[0084] The sending unit is used to send a secure connection response to the communication sender so that the communication sender can obtain and record the IP address, UDP port number and communication node address ID of the communication receiver.

[0085] Furthermore, the above another device also includes:

[0086] A monitoring unit, used to monitor the status of the security connection of each communication sender;

[0087] The processing unit is also used to clear the IP address, UDP port number and communication node address ID of the communication sender when it is detected that the security connection is in a disconnected state.

[0088] Based on the same inventive concept as the above disclosed content, the present disclosure also provides an electronic device. Figure 3 As shown, the electronic device of the embodiment of the present disclosure includes at least one electrically connected processor and at least one memory, wherein the memory is electrically connected to the processor, wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the non-security layer configuration method in the RSSP-I secure communication protocol stack as described above.

[0089] It should be noted that the electrical connection between the above-mentioned units does not necessarily mean the connection between lines. An indirect connection method can be applied to the embodiments of the present disclosure as long as the purpose of the present disclosure is achieved.

[0090] Based on the same inventive concept, the present disclosure also provides a computer storage medium storing instructions executable by the at least one processor, the instructions being executed by the at least one processor so that the at least one processor can execute the non-security layer configuration method in the RSSP-I secure communication protocol stack as described above. Although the present disclosure is described in detail with reference to the aforementioned embodiments, a person of ordinary skill in the art should understand that the technical solutions described in the aforementioned embodiments can still be modified, or some of the technical features thereof can be replaced by equivalents; and these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present disclosure.

Claims

1. A method for configuring a non-safety layer in an RSSP-1 safety communication protocol stack, characterized in that: The method comprises: The communication sender configures its own communication node address ID, IP address and UDP port number; The communication sender opens the UDP port according to the configured IP address and UDP port number; The communication sender uses the open UDP port to initiate a secure connection request to the railway dedicated LAN through broadcasting; The communication sender receives a secure connection response from the communication receiver, obtains and records the communication receiver's IP address, UDP port number, and communication node address ID; The recorded communication recipient's IP address, UDP port number, and communication node address ID are used as the configured other party's communication IP address, UDP port number, and communication node address ID.

2. The method according to claim 1, characterized in that The method further comprises: Monitor the status of the security connection of each communication recipient; When it is detected that the security connection is in a disconnected state, the IP address, UDP port number and communication node address ID of the communication receiver are cleared.

3. A method for configuring a non-safety layer in an RSSP-1 safety communication protocol stack, characterized in that: The method comprises: The communication receiver configures its own communication node address ID, IP address and UDP port number; The communication receiver uses the configured UDP port number to receive the secure connection response from the communication sender, obtains and records the communication receiver's IP address, UDP port number and communication node address ID; The communication receiver uses the recorded IP address, UDP port number and communication node address ID of the communication receiver as the configured IP address, UDP port number and communication node address ID of the other party; The communication receiver sends a secure connection response to the communication sender so that the communication sender can obtain and record the IP address, UDP port number and communication node address ID of the communication receiver.

4. The method according to claim 3, characterized in that The method further comprises: Monitor the status of the security connection of each communication sender; When it is detected that the security connection is disconnected, the IP address, UDP port number and communication node address ID of the communication sender are cleared.

5. A non-security layer configuration device in RSSP-I security communication protocol stack, characterized in that: The device comprises: a configuration unit, a sending unit, a receiving unit and a processing unit; wherein: A configuration unit, used to configure the communication node address ID, IP address and UDP port number of the party; The sending unit is used to open the UDP port according to the configured local IP address and UDP port number; and initiate a secure connection request to the railway dedicated LAN by broadcasting using the opened UDP port; A receiving unit, configured to receive a secure connection response from a communication receiving party; The processing unit is used to obtain and record the IP address, UDP port number and communication node address ID of the communication recipient; and use the recorded IP address, UDP port number and communication node address ID of the communication recipient as the configured IP address, UDP port number and communication node address ID of the other party.

6. The device according to claim 5, characterized in that The device also includes: A monitoring unit, used to monitor the status of the security connection of each communication recipient; The processing unit is also used to clear the IP address, UDP port number and communication node address ID of the communication receiver when it is detected that the security connection is in a disconnected state.

7. A non-security layer configuration device in RSSP-I security communication protocol stack, characterized in that: The device comprises: a configuration unit, a receiving unit, a processing unit and a sending unit; wherein: A configuration unit, used to configure the communication node address ID, IP address and UDP port number of the party; A receiving unit, used for receiving a secure connection response from a communication sender using a configured UDP port number; The processing unit is used to obtain and record the IP address, UDP port number and communication node address ID of the communication recipient; the communication recipient uses the recorded IP address, UDP port number and communication node address ID of the communication recipient as the configured IP address, UDP port number and communication node address ID of the other party; The sending unit is used to send a secure connection response to the communication sender so that the communication sender can obtain and record the IP address, UDP port number and communication node address ID of the communication receiver.

8. The device according to claim 7, characterized in that The device also includes: A monitoring unit, used to monitor the status of the security connection of each communication sender; The processing unit is also used to clear the IP address, UDP port number and communication node address ID of the communication sender when it is detected that the security connection is in a disconnected state.

9. An electronic device, characterized in that: The invention comprises at least one processor and at least one storage medium which are electrically connected; the storage medium is connected to the processor bus; wherein, The storage medium stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the non-security layer configuration method in the RSSP-I security communication protocol stack as described in any one of claims 1-4.

10. A computer storage medium, characterized in that: The storage medium stores instructions that can be executed by at least one processor; the instructions are executed by the at least one processor so that the at least one processor can execute the non-security layer configuration method in the RSSP-I secure communication protocol stack as described in any one of claims 1-4.