Subway vehicle network data security communication method, system, device and product

Through the combined hybrid encryption method and dynamic key management of the two-layer combination, the replay attack, man-in-the-middle attack and side channel attack problems faced by the subway vehicle network are solved, and efficient and secure transmission of vehicle control instructions and passenger information is realized, ensuring the safety and stability of subway operations.

CN120200844AInactive Publication Date: 2025-06-24CHENGDU SHUANGYANG RAIL TRANSIT EQUIPMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510589593.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-06-24
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The subway vehicle network is facing replay attacks, man-in-the-middle attacks and side channel attacks, which has caused the confidentiality of vehicle control instructions and passenger information to be threatened, seriously affecting the safety and stability of subway operations.

Method used

Using a two-layer hybrid encryption method, efficient and secure transmission of subway vehicle network data is achieved through data feature extraction and dynamic key management. The specific steps include: obtaining subway vehicle network communication data, performing feature extraction and plaintext data formation; generating keys and building symmetric encryption functions to encrypt plaintext data in blocks; encrypting the key based on the elliptic curve cryptographic system, and forming subway vehicle network transmission data; finally, conducting legality verification and key decryption to ensure the integrity and confidentiality of the data.

Benefits of technology

Effectively resist replay attacks, man-in-the-middle attacks and side channel attacks, ensure the confidentiality and integrity of vehicle control instructions and passenger information, and improve the safety and stability of subway operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200844A_ABST
    Figure CN120200844A_ABST
Patent Text Reader

Abstract

The invention provides a metro vehicle network data secure communication method, which comprises the following steps of: firstly, acquiring metro vehicle network communication data, and obtaining metro vehicle network communication characteristic data; then, plaintext data is formed, and a secret key is generated to construct a symmetric encryption function; signing the plaintext data to generate signature blocks, and performing block encryption processing on the plaintext data to form ciphertext data; then encrypting the key based on an elliptic curve cryptosystem to generate an encryption key block, and forming metro vehicle network transmission data; and finally, based on an elliptic curve cryptosystem, carrying out legality verification on the metro vehicle network transmission data, and decrypting the key so as to decrypt the ciphertext data, thereby obtaining metro vehicle network communication data. According to the secure communication method, replay attack, man-in-the-middle attack and side channel attack can be effectively resisted, and confidentiality and integrity of vehicle control instructions and passenger information are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of subway vehicle network data and secure communication, and particularly relates to a method, system, device and product for secure communication of subway vehicle network data. Background Art

[0002] In the context of the accelerating urbanization process today, the subway, as an efficient, convenient and high-capacity public transportation vehicle, has become the core pillar of the transportation networks of many cities. With the rapid progress of technology, the subway vehicle network technology has also witnessed rapid development. Various advanced control systems, sensors and information interaction devices have been widely applied to subway vehicles, realizing real-time monitoring of vehicle operation status, precise control and intelligent upgrade of passenger services. However, while the subway vehicle network is booming, the security threats faced by its communication data are becoming increasingly prominent. Among them, problems such as replay attacks, man-in-the-middle attacks and side-channel attacks are particularly severe, posing an unprecedented challenge to the confidentiality of vehicle control commands and passenger information, and seriously threatening the safety and stability of subway operation.

[0003] A replay attack is like a "ghost" hiding in the dark. The attacker intercepts legitimate communication data packets and then resends these data at a later time point, attempting to interfere with the normal operation of the subway vehicle. For example, the attacker may replay commands to control the acceleration or braking of the train, resulting in the loss of control of the train's operation state and triggering serious safety accidents. A man-in-the-middle attack is even more cunning. The attacker disguises as a legitimate communication node, establishes a "secret channel" between the sender and the receiver, intercepts, tampers with or even forges the communication data between the two parties. This may not only cause malicious tampering of vehicle control commands, affecting the normal operation of the train, but also leak passengers' personal information, posing great harm to passengers' privacy and safety. And side-channel attacks utilize the physical characteristics generated by subway vehicle network devices during operation, such as electromagnetic radiation, power consumption changes, etc., to steal sensitive information in communication data, further exacerbating the security risks.

[0004] Therefore, based on the above deficiencies, how to provide a secure communication method for subway vehicle network data that can effectively resist replay attacks, man-in-the-middle attacks and side-channel attacks and ensure the confidentiality of vehicle control commands and passenger information has become an urgent problem to be solved. Summary of the Invention

[0005] The purpose of the present invention is to provide a method, system, device and product for secure communication of subway vehicle network data to solve the problems of the security of subway vehicle network data communication and the long scanning time existing in the prior art.

[0006] To achieve the above purpose, the present invention adopts the following technical solutions:

[0007] In a first aspect, the present invention provides a method for secure communication of subway vehicle network data, which includes:

[0008] Obtain subway vehicle network communication data, and perform feature extraction on the subway vehicle network communication data to obtain subway vehicle network communication feature data;

[0009] Form plaintext data based on the subway vehicle network communication feature data, and generate a key to construct a symmetric encryption function;

[0010] Sign the plaintext data to generate a signature block, and perform block encryption on the plaintext data using the symmetric encryption function to form ciphertext data;

[0011] Encrypt the key based on the elliptic curve cryptosystem to generate an encrypted key block, and form subway vehicle network transmission data based on the signature block, the ciphertext data, and the encrypted key block;

[0012] Based on the elliptic curve cryptosystem, perform legality verification on the subway vehicle network transmission data, and decrypt the key to decrypt the ciphertext data using the key to obtain the subway vehicle network communication data.

[0013] In a possible design, obtaining subway vehicle network communication data and performing feature extraction on the subway vehicle network communication data to obtain subway vehicle network communication feature data includes:

[0014] Obtain subway vehicle network communication data, including vehicle status data, passenger information data, and control instruction data;

[0015] Perform time-domain analysis on the subway vehicle network communication data;

[0016] Calculate the redundancy information density of the subway vehicle network communication data at the network edge to obtain the frequency distribution of the subway vehicle network communication data at the vehicle network edge nodes;

[0017] Based on the frequency distribution of the subway vehicle network communication data at the vehicle network edge nodes, perform filtering on the subway vehicle network communication data using a discrete function to filter out redundant noise in the subway vehicle network communication data;

[0018] Based on the subway vehicle network communication data after filtering out redundant noise, extract the feature vectors of the subway vehicle network communication data to form subway vehicle network communication feature data.

[0019] In a possible design, forming plaintext data based on the subway vehicle network communication feature data includes:

[0020] Divide the subway vehicle network communication characteristic data into multiple data blocks;

[0021] Based on the subway vehicle network communication characteristic data, construct a plaintext space in combination with the node metrics of the subway vehicle network communication, and form plaintext data;

[0022] Correspondingly, generate a key to construct a symmetric encryption function, including:

[0023] Dynamically generate a key according to the running state of the subway vehicle train;

[0024] Based on the key, use a symmetric encryption algorithm to construct a symmetric encryption function.

[0025] In a possible design, sign the plaintext data to generate a signature block, including:

[0026] Use a hash function to generate a fixed-length plaintext data digest for the plaintext data;

[0027] Use the key to sign the plaintext data digest to generate a signature block;

[0028] Correspondingly, use the symmetric encryption function to perform block encryption processing on the plaintext data to form ciphertext data, including:

[0029] Use the symmetric encryption function to define a ciphertext space;

[0030] Use the key to perform block encryption processing on the plaintext data and map it to the ciphertext space to form ciphertext data.

[0031] In a possible design, encrypt the key based on the elliptic curve cryptosystem to generate an encrypted key block, including:

[0032] Obtain a preset standard elliptic curve, generate a standard elliptic curve equation, and randomly generate a recipient private key;

[0033] Based on the standard elliptic curve equation, calculate the recipient public key using the recipient private key;

[0034] Obtain a randomly generated temporary key, and calculate a shared point based on the randomly generated temporary key and the recipient public key;

[0035] Use the shared point to encrypt the key and generate an encrypted key block.

[0036] In a possible design, based on the elliptic curve cryptosystem, verify the legitimacy of the subway vehicle network transmission data and decrypt the key, including:

[0037] Receive the subway vehicle network transmission data, and separate the signature block, the ciphertext data, and the encrypted key block;

[0038] Verify the legality of the signature block. If the verification fails, discard the subway vehicle network transmission data and issue an alarm;

[0039] Decrypt the encrypted key block based on the shared point and the recipient's private key to obtain the key;

[0040] Correspondingly, decrypt the ciphertext data with the key to obtain the subway vehicle network communication data, which includes:

[0041] Use the key to decrypt the ciphertext data in blocks to obtain plaintext data;

[0042] Restore the subway vehicle network communication feature data corresponding to the plaintext data to the subway vehicle network communication data, and verify the integrity of the subway vehicle network communication data.

[0043] In a possible design, after obtaining the subway vehicle network communication data, it further includes:

[0044] Obtain the subway vehicle network status indicators, and obtain the subway vehicle network fluctuation rating according to the subway vehicle network status indicators;

[0045] Update the key based on the subway vehicle network fluctuation rating and optimize the symmetric encryption function;

[0046] Use the updated key and the optimized symmetric encryption function to perform a new round of encryption on the plaintext data.

[0047] In a second aspect, the present invention provides a subway vehicle network data security communication system, which includes:

[0048] A data acquisition unit, configured to acquire subway vehicle network communication data, and extract features from the subway vehicle network communication data to obtain subway vehicle network communication feature data;

[0049] An encryption function generation unit, configured to form plaintext data based on the subway vehicle network communication feature data, and generate a key to construct a symmetric encryption function;

[0050] A first-layer encryption unit, configured to sign the plaintext data to generate a signature block, and perform block encryption processing on the plaintext data using the symmetric encryption function to form ciphertext data;

[0051] A two - layer encryption unit, which is used to encrypt the key based on the elliptic curve cryptosystem to generate an encrypted key block, and form subway vehicle network transmission data based on the signature block, the ciphertext data, and the encrypted key block;

[0052] A data decryption unit, which is used to perform legality verification on the subway vehicle network transmission data based on the elliptic curve cryptosystem, decrypt the key, and decrypt the ciphertext data with the key to obtain subway vehicle network communication characteristic data corresponding to the plaintext data.

[0053] In a third aspect, the present invention provides an electronic device, including a memory, a processor, and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the subway vehicle network data security communication method as described in the first aspect or any one of the possible designs in the first aspect.

[0054] In a fourth aspect, the present invention provides a storage medium, on which instructions are stored. When the instructions are run on a computer, the subway vehicle network data security communication method as described in the first aspect or any one of the possible designs in the first aspect is executed.

[0055] In a fifth aspect, the present invention provides a computer program product containing instructions. When the instructions are run on a computer, the computer is made to execute the subway vehicle network data security communication method as described in the first aspect or any one of the possible designs in the first aspect.

[0056] Beneficial effects:

[0057] The present invention discloses a method for secure communication of subway vehicle network data. First, subway vehicle network communication data is acquired, and feature extraction is performed on the subway vehicle network communication data to obtain subway vehicle network communication feature data. Then, plaintext data is formed based on the subway vehicle network communication feature data, and a key is generated to construct a symmetric encryption function. Next, the plaintext data is signed to generate a signature block, and the plaintext data is encrypted in blocks using the symmetric encryption function to form ciphertext data. After that, the key is encrypted based on the elliptic curve cryptosystem to generate an encrypted key block, and subway vehicle network transmission data is formed based on the signature block, the ciphertext data, and the encrypted key block. Finally, based on the elliptic curve cryptosystem, the subway vehicle network transmission data is verified for legality, and the key is decrypted to decrypt the ciphertext data using the key to obtain the subway vehicle network communication data. The secure communication method disclosed by the present invention realizes the efficient and secure transmission of subway vehicle network data through a two-layer combined hybrid encryption, combined with data feature extraction and dynamic key management. By using the steps of data preprocessing, hybrid encryption, signature encapsulation, and decryption verification, it can effectively resist replay attacks, man-in-the-middle attacks, and side-channel attacks, ensuring the confidentiality and integrity of vehicle control instructions and passenger information. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 It is a schematic flowchart of the steps of the method for secure communication of subway vehicle network data provided by an embodiment of the present invention;

[0059] Figure 2 It is a schematic functional structure diagram of the subway vehicle network data secure communication system provided by an embodiment of the present invention;

[0060] Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0061] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the present invention in combination with the drawings and the description of the embodiments or the prior art. Obviously, the following description of the drawing structure is only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. It should be noted here that the description of these embodiment modes is used to help understand the present invention, but does not constitute a limitation to the present invention.

[0062] It should be understood that although terms such as first and second may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, the first unit may be referred to as the second unit, and similarly, the second unit may be referred to as the first unit, without departing from the scope of the exemplary embodiments of the present invention.

[0063] It should be understood that for the term "and / or" that may appear herein, it is merely an association relationship describing associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, B exists alone, and both A and B exist simultaneously; for the term " / and" that may appear herein, it is a description of another associated object relationship, indicating that two relationships may exist. For example, A / and B may represent: A exists alone, and both A and B exist; in addition, for the character " / " that may appear herein, generally it represents that the associated objects before and after are in an "or" relationship.

[0064] Embodiment:

[0065] See Figure 1 As shown, the subway vehicle network data security communication method provided in this embodiment, through a hybrid encryption method combining the encryption of plaintext data and the encryption of the symmetric encryption function key, combined with data feature extraction and dynamic key update management, realizes the efficient and secure transmission of subway vehicle network data, and based on the steps of data preprocessing, hybrid encryption, signature encapsulation, and decryption verification, can effectively resist replay attacks, man-in-the-middle attacks, and side-channel attacks, ensuring the confidentiality and integrity of vehicle control instructions and passenger information; among them, for example, this method can but is not limited to running on the subway vehicle network data security communication system side. It can be understood that the foregoing execution subject does not constitute a limitation on the embodiments of the present application. Correspondingly, the running steps of this method can but are not limited to the following steps S1 to S5.

[0066] S1. Obtain subway vehicle network communication data, and perform feature extraction on the subway vehicle network communication data to obtain subway vehicle network communication feature data;

[0067] Among them, in step S1, in a possible design, obtaining subway vehicle network communication data and performing feature extraction on the subway vehicle network communication data to obtain subway vehicle network communication feature data includes:

[0068] S11. Obtain subway vehicle network communication data, including vehicle status data, passenger information data, and control instruction data;

[0069] S12. Perform time-domain analysis on the subway vehicle network communication data;

[0070] S13. Calculate the redundancy information density of the subway vehicle network communication data at the network edge to obtain the frequency distribution of the subway vehicle network communication data at the vehicle network edge node;

[0071] S14. Based on the frequency distribution of the subway vehicle network communication data at the vehicle network edge node, use a discrete function to filter the subway vehicle network communication data to screen out redundant noise in the subway vehicle network communication data;

[0072] S15. Based on the subway vehicle network communication data after screening out redundant noise, extract the feature vectors of the subway vehicle network communication data to form subway vehicle network communication feature data.

[0073] It should be noted that the discrete function can be a discrete wavelet function; and, the process of feature extraction further includes: optimizing the decomposition scale of the discrete transform based on the energy characteristics of the subway vehicle network nodes to reduce computational energy consumption.

[0074] S2. Based on the subway vehicle network communication feature data, form plaintext data and generate a key to construct a symmetric encryption function;

[0075] Among them, in step S2, in a possible design, forming plaintext data based on the subway vehicle network communication feature data includes:

[0076] S21. Divide the subway vehicle network communication feature data into multiple data blocks;

[0077] S22. Based on the subway vehicle network communication feature data, combine the node indicators of the subway vehicle network communication to construct a plaintext space and form plaintext data;

[0078] Correspondingly, generating a key to construct a symmetric encryption function includes:

[0079] S23. Dynamically generate a key according to the running state of the subway vehicle train;

[0080] S24. Based on the key, use a symmetric encryption algorithm to construct a symmetric encryption function.

[0081] It should be noted that for the symmetric encryption function, encryption constraint conditions can be set, where the encryption constraint conditions can be expressed as:

[0082]

[0083] In the above formula (1), γ[M(X)] is used to represent the encryption constraint condition, and M(X) represents the symmetric encryption function. represents the quadratic coefficient for encrypting the subway vehicle network communication feature data, S represents the range parameter of the symmetric encryption function, and q represents the key transformation coefficient.

[0084] The setting of the encryption constraint conditions can provide reliability guarantee for the secure encryption of computer network communication data to avoid the communication data from being invaded by the outside world.

[0085] S3. Sign the plaintext data to generate a signature block, and use the symmetric encryption function to perform block encryption processing on the plaintext data to form ciphertext data;

[0086] Among them, in step S3, in a possible design, signing the plaintext data to generate a signature block includes:

[0087] S31. Use a hash function to generate a fixed-length plaintext data digest for the plaintext data;

[0088] S32. Use the key to sign the plaintext data digest to generate a signature block;

[0089] Correspondingly, using the symmetric encryption function to perform block encryption processing on the plaintext data to form ciphertext data includes:

[0090] S33. Use the symmetric encryption function to define a ciphertext space;

[0091] S34. Use the key to perform block encryption processing on the plaintext data and map it to the ciphertext space to form ciphertext data.

[0092] It should be noted that the encryption of the plaintext data is the first encryption in this embodiment and the first layer of encryption in the secure communication method of this embodiment, forming stable and basic encrypted data and efficiently protecting the content of the plaintext data to ensure the confidentiality of real-time communication.

[0093] Among them, using the key to sign the plaintext data digest forms an end-to-end digital signature. The sender uses the key to sign the plaintext data digest, and the receiver uses the key to verify the signature when receiving. When an attacker eavesdrops on and tampers with the communication data of the subway vehicle network and impersonates a legitimate node, tampers with the data or forges an identity, the signature verification of the receiver will fail at this time, completing the resistance to the attack.

[0094] S4. Encrypt the key based on the elliptic curve cryptosystem to generate an encrypted key block, and form the subway vehicle network transmission data based on the signature block, the ciphertext data, and the encrypted key block;

[0095] Among them, in step S4, in a possible design, encrypting the key based on the elliptic curve cryptosystem to generate an encrypted key block includes:

[0096] S41. Obtain a preset standard elliptic curve, generate a standard elliptic curve equation, and randomly generate a recipient private key;

[0097] S42. Based on the standard elliptic curve equation, calculate the recipient public key using the recipient private key;

[0098] S43. Obtain a randomly generated temporary key, and calculate a shared point based on the randomly generated temporary key and the recipient public key;

[0099] S44. Use the shared point to encrypt the key and generate an encrypted key block.

[0100] It should be noted that the encryption of the key is the secondary encryption in this embodiment and the second layer of encryption in the secure communication method of this embodiment to securely distribute the key and solve the security problem of key transmission. This secondary hybrid encryption method generates a temporary key each time for communication to ensure the uniqueness of each session key. Therefore, if an attacker replays an old data packet, the decryption will fail because the original temporary key has expired, which can be used to resist replay attacks on subway vehicle network communication.

[0101] By encrypting the key, even if an attacker intercepts the subway vehicle network transmission data and obtains the encrypted key block, they will not be able to obtain the real key because they cannot crack the second layer of encryption. Based on this, it can also largely cope with the man-in-the-middle attack of the attacker on the subway vehicle network communication.

[0102] S5. Based on the elliptic curve cryptosystem, perform a legitimacy verification on the subway vehicle network transmission data, decrypt the key, and decrypt the ciphertext data with the key to obtain the subway vehicle network communication data.

[0103] Among them, in step S5, in a possible design, based on the elliptic curve cryptosystem, performing a legitimacy verification on the subway vehicle network transmission data and decrypting the key includes:

[0104] S5. Receive the subway vehicle network transmission data, and separate the signature block, the ciphertext data, and the encrypted key block;

[0105] S5. Perform a legitimacy verification on the signature block. If the verification fails, discard the subway vehicle network transmission data and issue an alarm;

[0106] S5. Decrypt the encrypted key block based on the shared point and the recipient's private key to obtain the key;

[0107] Correspondingly, decrypt the ciphertext data with the key to obtain the subway vehicle network communication data, which includes:

[0108] S5. Use the key to decrypt the ciphertext data in blocks to obtain plaintext data;

[0109] S5. Restore the subway vehicle network communication feature data corresponding to the plaintext data to the subway vehicle network communication data, and perform integrity verification on the subway vehicle network communication data.

[0110] In a possible design, after steps S1 - S5, after obtaining the subway vehicle network communication data, it further includes:

[0111] Obtain subway vehicle network status indicators, and obtain a subway vehicle network fluctuation rating based on the subway vehicle network status indicators;

[0112] Update the key based on the subway vehicle network fluctuation rating, and optimize the symmetric encryption function;

[0113] Use the updated key and the optimized symmetric encryption function to perform a new round of encryption on the plaintext data.

[0114] It should be noted that by obtaining the subway vehicle network status indicators in real time, the encryption parameters can be dynamically adjusted according to the subway vehicle network status indicators, and according to the subway vehicle network fluctuation rating, the key can be updated (randomly switch the key length (such as switching from 256 bits to 128 bits)), and the symmetric encryption function can be optimized (optimize the encryption mode) to increase the attacker's modeling difficulty. To a great extent, it resists side-channel attacks on the subway vehicle network.

[0115] Thus, through the subway vehicle network data security communication method detailed in the foregoing steps S1 - S5, the embodiments of the present invention implement efficient and secure transmission of subway vehicle network data through a hybrid encryption method combining encryption of plaintext data and encryption of the symmetric encryption function key, combined with data feature extraction and dynamic key update management, and based on the steps of data preprocessing, hybrid encryption, signature encapsulation, and decryption verification, can effectively resist replay attacks, man-in-the-middle attacks, and side-channel attacks, ensuring the confidentiality and integrity of vehicle control instructions and passenger information.

[0116] As Figure 2 shown, the second aspect of this embodiment provides a hardware system for implementing the subway vehicle network data security communication method described in the first aspect of the embodiment, including:

[0117] A data acquisition unit, configured to acquire subway vehicle network communication data and perform feature extraction on the subway vehicle network communication data to obtain subway vehicle network communication feature data;

[0118] An encryption function generation unit, configured to form plaintext data based on the subway vehicle network communication feature data and generate a key to construct a symmetric encryption function;

[0119] A first-layer encryption unit, configured to sign the plaintext data to generate a signature block and perform block encryption processing on the plaintext data by using the symmetric encryption function to form ciphertext data;

[0120] A second-layer encryption unit, configured to encrypt the key based on the elliptic curve cryptosystem to generate an encrypted key block, and form subway vehicle network transmission data based on the signature block, the ciphertext data, and the encrypted key block;

[0121] A data decryption unit, configured to perform legality verification on the subway vehicle network transmission data based on the elliptic curve cryptosystem, decrypt the key, and decrypt the ciphertext data by using the key to obtain the subway vehicle network communication feature data corresponding to the plaintext data.

[0122] For the working process, working details and technical effects of the subway vehicle network data security communication system provided in this embodiment, reference may be made to the first aspect of the embodiment, which will not be elaborated herein.

[0123] As Figure 3 shown, a third aspect of this embodiment provides an electronic device, including: a memory, a processor, and a transceiver that are communicatively connected in sequence, where the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the subway vehicle network data security communication method as described in the first aspect of the embodiment.

[0124] Specifically, the memory may include, but is not limited to, random access memory (RAM), read only memory (ROM), flash memory, first input first output (FIFO) memory, and / or first in last out (FILO) memory, etc.; specifically, the processor may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor may be implemented in at least one of the following hardware forms: digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). At the same time, the processor may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the central processing unit (CPU); the coprocessor is a low-power processor used to process data in the standby state.

[0125] In some embodiments, the processor may be integrated with a graphics processing unit (GPU). The GPU is responsible for rendering and drawing the content to be displayed on the display screen. For example, the processor may not be limited to using a microprocessor of the STM32F105 series, a reduced instruction set computer (RISC) microprocessor, a processor with an X86 architecture, or a processor integrated with a neural-network processing unit (NPU); the transceiver may include, but is not limited to, a wireless fidelity (WIFI) wireless transceiver, a Bluetooth wireless transceiver, a general packet radio service (GPRS) wireless transceiver, a ZigBee wireless transceiver (a low-power local area network protocol based on the IEEE802.15.4 standard), a 3G transceiver, a 4G transceiver, and / or a 5G transceiver, etc. In addition, the device may also include, but is not limited to, a power module, a display screen, and other necessary components.

[0126] For the working process, working details, and technical effects of the electronic device provided in this embodiment, reference may be made to the first aspect of the embodiment, which will not be elaborated here.

[0127] The fourth aspect of this embodiment provides a storage medium storing instructions for the subway vehicle network data security communication method described in the first aspect of the embodiment, that is, instructions are stored on the storage medium, and when the instructions run on a computer, the subway vehicle network data security communication method described in the first aspect of the embodiment is executed.

[0128] Among them, the storage medium refers to a carrier for storing data, and may include, but is not limited to, floppy disks, optical discs, hard disks, flash memories, USB flash drives, and / or memory sticks, etc. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.

[0129] For the working process, working details, and technical effects of the storage medium provided in this embodiment, reference may be made to the first aspect of the embodiment, which will not be elaborated herein.

[0130] The fifth aspect of this embodiment provides a computer program product containing instructions, which, when running on a computer, causes the computer to execute the subway vehicle network data security communication method described in the first aspect of the embodiment. Among them, the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.

[0131] Finally, it should be noted that the above are only preferred embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for secure communication of subway vehicle network data, characterized in that: include: Acquiring subway vehicle network communication data, and performing feature extraction on the subway vehicle network communication data to obtain subway vehicle network communication feature data; Based on the subway vehicle network communication characteristic data, plaintext data is formed and a key is generated to construct a symmetric encryption function; Signing the plaintext data to generate a signature block, and performing block encryption processing on the plaintext data using the symmetric encryption function to form ciphertext data; Encrypting the key based on elliptic curve cryptography to generate an encryption key block, and forming subway vehicle network transmission data based on the signature block, the ciphertext data and the encryption key block; Based on the elliptic curve cryptography system, the legitimacy of the subway vehicle network transmission data is verified, and the key is decrypted to decrypt the ciphertext data through the key to obtain the subway vehicle network communication data.

2. The subway vehicle network data security communication method according to claim 1 is characterized in that: Acquiring subway vehicle network communication data and performing feature extraction on the subway vehicle network communication data to obtain subway vehicle network communication feature data, including: Obtaining subway vehicle network communication data, including vehicle status data, passenger information data, and control command data; Performing time domain analysis on the subway vehicle network communication data; Calculating the redundant information density of the subway vehicle network communication data at the network edge to obtain the frequency distribution of the subway vehicle network communication data at the vehicle network edge node; Based on the frequency distribution of the subway vehicle network communication data at the vehicle network edge node, the subway vehicle network communication data is filtered using a discrete function to filter out redundant noise in the subway vehicle network communication data; Based on the subway vehicle network communication data after redundant noise is screened out, a feature vector of the subway vehicle network communication data is extracted to form subway vehicle network communication feature data.

3. The subway vehicle network data security communication method according to claim 1 is characterized in that: The plaintext data is formed based on the subway vehicle network communication characteristic data, including: Dividing the subway vehicle network communication characteristic data into a plurality of data blocks; Based on the subway vehicle network communication characteristic data, a plaintext space is constructed in combination with the node index of the subway vehicle network communication, and plaintext data is formed; Accordingly, generating a key to construct a symmetric encryption function includes: Dynamically generate keys based on the running status of subway vehicles and trains; Based on the key, a symmetric encryption function is constructed using a symmetric encryption algorithm.

4. The subway vehicle network data security communication method according to claim 1, characterized in that: Signing the plaintext data to generate a signature block includes: Using a hash function to generate a plaintext data digest of a fixed length for the plaintext data; Using the key, signing the plaintext data digest to generate a signature block; Correspondingly, using the symmetric encryption function to perform block encryption processing on the plaintext data to form ciphertext data includes: Using the symmetric encryption function, a ciphertext space is defined; The plaintext data is encrypted in blocks using the key and mapped to the ciphertext space to form ciphertext data.

5. The subway vehicle network data security communication method according to claim 1 is characterized in that: Encrypting the key based on the elliptic curve cryptography to generate an encrypted key block, including: Obtain a preset standard elliptic curve, generate a standard elliptic curve equation, and randomly generate a recipient's private key; Based on the standard elliptic curve equation, the recipient's public key is calculated using the recipient's private key; Obtaining a randomly generated temporary key, and calculating a sharing point based on the randomly generated temporary key and the recipient's public key; Using the shared point, the key is encrypted and an encrypted key block is generated.

6. The subway vehicle network data security communication method according to claim 5 is characterized in that: Based on the elliptic curve cryptography system, the legitimacy of the subway vehicle network transmission data is verified and the key is decrypted, including: Receiving the subway vehicle network transmission data, and separating the signature block, the ciphertext data and the encryption key block; Performing a legitimacy verification on the signature block, and if the verification fails, discarding the subway vehicle network transmission data and issuing an alarm; Decrypting the encrypted key block based on the shared point and the recipient private key to obtain the key; Correspondingly, decrypting the ciphertext data by using the key to obtain the subway vehicle network communication data includes: Using the key, decrypting the ciphertext data in blocks to obtain plaintext data; The subway vehicle network communication characteristic data corresponding to the plaintext data is restored to the subway vehicle network communication data, and the integrity of the subway vehicle network communication data is verified.

7. The subway vehicle network data security communication method according to claim 1, characterized in that: After obtaining the subway vehicle network communication data, the method further includes: Obtaining a subway vehicle network status indicator, and obtaining a subway vehicle network fluctuation rating according to the subway vehicle network status indicator; updating the key based on the subway vehicle network fluctuation rating and optimizing the symmetric encryption function; A new round of encryption is performed on the plaintext data using the updated key and the optimized symmetric encryption function.

8. A subway vehicle network data security communication system, characterized in that: include: A data acquisition unit, used to acquire subway vehicle network communication data and perform feature extraction on the subway vehicle network communication data to obtain subway vehicle network communication feature data; An encryption function generating unit, used to form plaintext data based on the subway vehicle network communication characteristic data, and generate a key to construct a symmetric encryption function; A layer of encryption unit, used to sign the plaintext data to generate a signature block, and use the symmetric encryption function to perform block encryption processing on the plaintext data to form ciphertext data; A second-layer encryption unit, used for encrypting the key based on an elliptic curve cryptography system to generate an encryption key block, and forming subway vehicle network transmission data based on the signature block, the ciphertext data and the encryption key block; The data decryption unit is used to verify the legitimacy of the subway vehicle network transmission data based on the elliptic curve cryptography system, and decrypt the key to decrypt the ciphertext data through the key to obtain the subway vehicle network communication characteristic data corresponding to the plaintext data.

9. An electronic device, characterized in that: include: A memory, a processor and a transceiver which are sequentially connected in communication, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the subway vehicle network data security communication method as described in any one of claims 1 to 7.

10. A computer program product comprising instructions, characterized in that When the instructions are executed on a computer, the computer is caused to execute the subway vehicle network data security communication method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Electric power data privacy communication method based on hybrid encryption algorithm

    CN112511304A

  • Information encryption transmission method and device based on block chain

    CN113806772A

  • Vehicle-mounted data wireless downloading method and system based on hybrid encryption and decryption algorithm

    CN117135624A

  • Techniques for secure data exchange

    US20140195804A1