Train control system data encryption authentication method and device
By introducing security chips and encryption authentication modules into the train control system to authenticate and encrypt the rail-side equipment, the problems of insufficient security and flexibility of data transmission in the prior art are solved, and the flexibility and security of device identity identification and data protection are realized, and rapid adjustments are adapted to business needs.
Patent Information
- Application Number
- CN202510848713.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-24
AI Technical Summary
The data transmission methods in the existing train control systems are insufficient security, lack flexibility and scalability. Intranet data transmission is limited by the network topology structure. The transmission of series gateways increases system complexity and security risks. Illegal devices may access to steal or tamper with service data.
The security chip and encryption authentication module are used to authenticate the rail-side equipment, and the device is assigned a security identifier through the encryption authentication module, and the service data is encrypted and transmitted and decrypted. Data protection is used using national secret or international common encryption algorithms such as SM1, SM2, SM3, SM4, and supports initial power-on and power-off restart authentication, realizing the flexible off-rail device system of the data encryption authentication device.
It improves the security of rail-side equipment and flexibility of data transmission in the train control system, prevents illegal equipment access, ensures data security and integrity, supports rapid adjustment and upgrade, and adapts to changes in business needs.
Smart Images

Figure CN120358496A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security and confidentiality, and particularly relates to a method and device for data encryption and authentication of a train control system. Background Art
[0002] For a communication-based rail transit train control system, its on-vehicle controller communicates with the trackside system through a vehicle-ground wireless system to obtain information related to train operation control, and performs train control calculations to output train control commands. In the existing train control system, data transmission mainly adopts the intranet data transmission method, and this data transmission method has the following problems: 1. Limitations of intranet data transmission: By restricting intranet data transmission or cascading gateways for transmission, although data security can be guaranteed to a certain extent, this method is relatively limited and lacks flexibility. Intranet data transmission may be restricted by the network topology, affecting the efficiency and real-time performance of data transmission. Cascading gateway transmission increases the complexity and cost of the system, and may also introduce new security risks.
[0003] 2. Security of service data cannot be guaranteed: In the existing solutions, there is no restriction on device access, and the security of service data cannot be guaranteed. Illegal devices may access the train control system, steal or tamper with service data, posing a serious threat to the safe operation of the system.
[0004] 3. Lack of flexibility and scalability: The existing data encryption and authentication devices are usually tightly coupled with the service system, lacking flexibility and scalability. When service requirements change, it is difficult to quickly adjust and upgrade the device, affecting the adaptability and sustainable development ability of the system.
[0005] In summary, the existing intranet data transmission method has problems such as the inability to guarantee the security of service data, lack of flexibility and scalability. Summary of the Invention
[0006] In view of the deficiencies of the prior art, the present invention discloses a method and device for data encryption and authentication of a train control system.
[0007] The present invention is realized through the following technical solutions: In a first aspect, a method for data encryption and authentication of a train control system is applied to a data encryption and authentication device. The data encryption and authentication device includes a security chip and an encryption and authentication module. The security chip is communicatively connected to a service processing module through the encryption and authentication module. The data encryption and authentication device is integrated in a trackside device and is used for authenticating the identity of the trackside device and encrypting and transmitting data. The method includes: When the trackside device accesses the train control system, the security chip authenticates the identity of the trackside device; After successful authentication, the encryption authentication module assigns a security identifier to the trackside equipment; The security chip encrypts and decrypts the service data through the encryption authentication module.
[0008] In some embodiments, it further includes: When the trackside equipment does not require identity authentication and data encryption and decryption, the identity authentication and encryption and decryption functions of the trackside equipment are released by modifying the software configuration.
[0009] In some embodiments, the identity authentication includes initial power-on identity authentication and power-off restart identity authentication.
[0010] In some embodiments, the method for initial power-on identity authentication includes: When the trackside equipment first accesses the train control system, the service processing module starts the registration authentication process. The encryption authentication module combines the trackside equipment authentication identifier sent by the service processing module with the security chip authentication identifier sent by the security chip and constructs a registration authentication information message, and then sends it to the receiving end through the service processing module; The service processing module receives the authentication request data from the receiving end, then sends the authentication request data to the encryption authentication module for parsing, and then sends it to the security chip; The security chip processes the authentication request data, generates authentication response data and sends it to the encryption authentication module. The encryption authentication module constructs it into an authentication response message and then sends it to the service processing module; The service processing module sends the authentication response message to the receiving end; The receiving end returns the trackside equipment registration authentication result to the service processing module based on the authentication response message, sends the trackside equipment registration authentication result to the encryption authentication module. The encryption authentication module extracts the result information of the initial power-on and the formal key from it. The security chip judges the trackside equipment authentication result. If the authentication is successful, the security chip updates it with the extracted formal key and passes the authentication success information to the service processing module through the encryption authentication module. If the authentication fails, it returns a failure message to the service processing module through the encryption authentication module, and the service processing module re-launches the authentication process until the authentication is successful.
[0011] In some embodiments, the method for power-off restart identity authentication includes: After the trackside equipment is powered off and restarted, the service processing module automatically triggers the identity authentication process, receives the registration authentication result from the receiving end, and sends the registration authentication result to the encryption authentication module. The encryption authentication module extracts the result information of the power-on again after power-off from it; The secure chip determines the authentication result of the trackside device after power-off and power-on again. If the authentication is passed, the original official key and security identifier of the trackside device are maintained; otherwise, a failure message is returned and the authentication process is restarted until successful.
[0012] In some embodiments, the method of generating the security identifier includes digital signature and hash value.
[0013] In some embodiments, the encryption and transmission of service data by the encryption authentication module includes: The service processing module sends the service plaintext data to the secure chip through the encryption authentication module; The secure chip calls the cryptographic algorithm to encrypt the service plaintext data, obtains the service ciphertext data and sends it to the encryption authentication module; The encryption authentication module processes the service ciphertext data to obtain the secure encrypted data, sends the secure encrypted data to the service processing module, and the service processing module transmits the secure encrypted data to the receiving end.
[0014] In some embodiments, the decryption and transmission of service data by the encryption authentication module includes: The service processing module receives the secure encrypted data from the receiving end and sends it to the encryption authentication module; The encryption authentication module extracts the secure encrypted data to obtain the service ciphertext data, and then sends it to the secure chip; The secure chip calls the cryptographic algorithm to decrypt the service ciphertext data, obtains the service plaintext data, and then sends the service plaintext data to the service processing module through the encryption authentication module.
[0015] In some embodiments, the cryptographic algorithm includes a national cryptographic algorithm or an internationally common cryptographic algorithm; The national cryptographic algorithm includes SM1, SM2, SM3, and SM4. SM1 is a symmetric encryption algorithm, SM2 is an asymmetric encryption algorithm, SM3 is a hash algorithm, and SM4 is a symmetric encryption algorithm.
[0016] In a second aspect, a data encryption and authentication device for a train control system includes a secure chip and an encryption authentication module; The secure chip is used to authenticate the trackside device when the trackside device accesses the train control system, and to encrypt and decrypt service data; The encryption authentication module is used to transmit service data and assign a security identifier to the trackside device that has passed the identity authentication.
[0017] In some embodiments, the encryption authentication device is detached from the trackside device system by modifying the software configuration.
[0018] In some embodiments, the security chip includes a power-on identity authentication unit and a power-off restart identity authentication unit; The power-on identity authentication unit is configured to initiate a registration authentication process to the encryption authentication device through the service processing module when the trackside device first accesses the train control system; The power-off restart identity authentication unit is configured to automatically trigger an identity authentication process to the encryption authentication device by the service processing module after the trackside device is powered off and restarted.
[0019] In some embodiments, it further includes: A processor and a memory; The processor is configured to control the operation and data processing of the train control system data encryption authentication device; The memory is configured to store data and programs, including security identifiers, keys, and identity authentication logs.
[0020] In some embodiments, the security chip integrates a cryptographic algorithm and a key management function.
[0021] In some embodiments, the cryptographic algorithm includes a national cryptographic algorithm or an international general cryptographic algorithm; The national cryptographic algorithm includes SM1, SM2, SM3, and SM4. SM1 is a symmetric encryption algorithm, SM2 is an asymmetric encryption algorithm, SM3 is a hash algorithm, and SM4 is a symmetric encryption algorithm.
[0022] In some embodiments, the key management function uses hierarchical management, including a master key and a session key; The master key is used to protect the security of the session key, and the session key is used to encrypt and decrypt service data.
[0023] Compared with the prior art, the present invention has the following advantages: 1. There are many trackside devices in the train control system and they are widely distributed. To ensure the security and stability of the system, it is necessary to authenticate the trackside devices to prevent illegal devices from accessing the system; 2. The trackside devices are securely identified so that the legitimacy and security of the devices can be quickly identified during the operation of the system; 3. The data transmission distance between the train control center and the trackside devices is relatively long, and it is vulnerable to external attacks and interference during transmission. Therefore, it is necessary to encrypt and protect the data to ensure the security and integrity of the data; 4. The data encryption authentication device can be separated from the trackside device system without affecting its performance, so as to facilitate the processing of a large amount of data.
[0024] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or be understood by implementing the present use information. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0026] Figure 1 This is a flow chart of a train control system data encryption and authentication method according to this embodiment.
[0027] Figure 2 It is a schematic diagram of the information flow of the trackside equipment in this embodiment registering and authenticating the request through the security chip.
[0028] Figure 3 Schematic diagram of the process of parsing authentication request information in this embodiment.
[0029] Figure 4 This is a schematic diagram of the flow of sending the authentication request data of this embodiment through the encryption authentication module to the security chip for parsing.
[0030] Figure 5 It is a schematic diagram of the process flow of the encryption authentication device of this embodiment obtaining the registration authentication result of the trackside equipment based on the authentication response data.
[0031] Figure 6 This is a schematic diagram of the key update process for trackside information that has passed identity authentication in this embodiment.
[0032] Figure 7 It is a schematic diagram of the bypass decryption and transmission process of business data by the trackside equipment of this embodiment after identity authentication.
[0033] Figure 8 It is a schematic diagram of the bypass encryption transmission process of business data by the trackside equipment of this embodiment after identity authentication.
[0034] Figure 9 It is a flow chart of the identity authentication removal function of the trackside equipment in this embodiment.
[0035] Figure 10 It is a schematic diagram of the process of turning on or off the encryption and decryption transmission of business data by the trackside equipment of this embodiment. DETAILED DESCRIPTION
[0036] The accompanying drawings are only for illustrative purposes and should not be construed as limiting the present invention; for better illustrating the embodiments, some components in the drawings may be omitted, enlarged or reduced, which does not represent the size of the actual product; for those skilled in the art, it is understandable that some well-known structures and their descriptions in the drawings may be omitted. The positional relationships described in the drawings are only for illustrative purposes and should not be construed as limiting the present invention.
[0037] In some embodiments, such as Figure 1 A method for data encryption and authentication of a train control system as shown is applied to a data encryption and authentication device. The data encryption and authentication device includes a security chip and an encryption and authentication module. The security chip is communicatively connected to a service processing module through the encryption and authentication module. The data encryption and authentication device is integrated in a trackside device and is used for authenticating the identity of the trackside device and encrypting and transmitting data. The service processing module is integrated in the trackside device. The method includes: S1. When the trackside device accesses the train control system, authenticate the identity of the trackside device through the security chip; S2. After the authentication is passed, the encryption and authentication module assigns a security identifier to the trackside device; S3. The security chip encrypts and decrypts the transmission of service data through the encryption and authentication module.
[0038] Specifically, the trackside device integrates a security chip, an encryption and authentication module, and a service processing module. When the trackside device accesses the train control system, the identity authentication process is divided into initial power-on authentication and power-off restart authentication, including the trackside device registering authentication request information through the integrated security chip, the integrated service processing module sending authentication request data to the security chip through the encryption and authentication module integrated in the trackside device, the security chip verifying the parsed authentication request data using a key, the security chip judging the authentication result of the trackside device, and updating the key for the trackside information that passes the identity authentication.
[0039] Further, the trackside device registers authentication request information through the security chip as Figure 2 shown. The trackside device goes online and accesses the train control system, enters the trackside device registration authentication process through its integrated service processing module, combines the trackside device authentication identifier and the security chip authentication identifier through the encryption and authentication module integrated in the trackside device and encapsulates them to construct a registration authentication information message, which is transmitted to the service processing module and then sent by the service processing module to the receiving end, and the receiving end is the central server of the train control system.
[0040] Further, parsing the authentication request information as Figure 3As shown, after receiving the registration authentication information message, the receiving end initiates an authentication request to the business processing module, sends the authentication request data to the encryption authentication module for parsing, and the encryption authentication module then sends the authentication request data to the security chip, such as Figure 4 As shown, the security chip receives and processes the authentication request data, generates authentication response data and sends it to the encryption authentication module, constructs the authentication response data into an authentication response message through the encryption authentication module, and then sends the authentication response message to the receiving end through the business processing module.
[0041] Further, the receiving end returns the registration authentication result of the trackside equipment to the business processing module based on the authentication response message, such as Figure 5 As shown, the registration authentication result of the trackside equipment is extracted through the encryption authentication module, including the initial power-on result information and its formal key, and the power-off and power-on result information, and then sent to the security chip by the encryption authentication module to determine whether the trackside equipment authentication is passed. If the authentication fails, the authentication failure information is returned, otherwise the authentication success information is returned, and the formal key is updated for the initial power-on authentication.
[0042] Furthermore, the key is updated for the trackside information that has passed identity authentication, such as Figure 6 As shown, after the wayside equipment is authenticated, the security chip completes the key update. If the wayside equipment is powered on for the first time, the security chip sends a formal key update confirmation message to the encryption authentication module. The encryption authentication module encapsulates the formal key update confirmation message into an authentication pass information message and sends it to the business processing module. The business processing module sends the authentication pass information message and the unique security identifier of the wayside equipment identity authentication assigned by the encryption authentication module to the receiving end. After the security identifier is assigned to the wayside equipment that has passed the identity authentication, it is stored in the security equipment management library and logged. If the identity authentication fails, the wayside equipment authentication process continues until the authentication passes.
[0043] Furthermore, the security identification is generated in a manner including a digital signature or a hash value, and is used to quickly identify the legitimacy and security of the trackside equipment, including verifying whether the digital signature matches the characteristic information of the trackside equipment or recalculating the hash value based on the characteristic data of the trackside equipment and comparing it with the security identification to ensure consistency.
[0044] Furthermore, the security chip integrates cryptographic algorithms and key management functions.
[0045] Furthermore, the keys are managed in a hierarchical manner, including a master key and a session key. The master key is used to protect the security of the session key, and the session key is used to encrypt and decrypt business data. In addition, the generation, storage, distribution and update of the keys comply with security policies to ensure the security and reliability of the keys.
[0046] Specifically, the cryptographic algorithm includes a national cryptographic algorithm or an internationally common cryptographic algorithm. The national cryptographic algorithms include SM1, SM2, SM3, and SM4. Among them, SM1 is a symmetric encryption algorithm, SM2 is an asymmetric encryption algorithm, SM3 is a hashing algorithm, and SM4 is a symmetric encryption algorithm. Different encryption algorithms are selected for combined use according to different application scenarios and security requirements.
[0047] Further, after the trackside equipment passes the identity authentication, it performs bypass decryption transmission and encryption transmission on the service data. The decryption is as Figure 7 shown. The receiving end sends the secure encrypted data to the service processing module. The service processing module sends the secure encrypted data to the encryption authentication module. The encryption authentication module extracts the service ciphertext data from the secure encrypted data and then sends it to the security chip. The service ciphertext data is processed by invoking the decryption function of the security chip to obtain the service plaintext data. The service plaintext data is sent to the service processing module of the trackside equipment through the encryption authentication module.
[0048] Further, the encryption is as Figure 8 shown. The service processing module of the trackside equipment sends the service plaintext data to the security chip through the encryption authentication module, invokes the encryption function of the security chip to encrypt the service plaintext data, obtains the service ciphertext data and sends it to the encryption authentication module. The encryption authentication module processes the service ciphertext data to form secure encrypted data, and then sends the secure encrypted data to the receiving end through the service processing module.
[0049] In some embodiments, the encryption authentication module adopts standard interfaces including USB, PCIe, and SPI, or is customized and developed according to the requirements of the service processing module. In addition, to ensure the security of the interfaces, security protection measures are taken, including data encryption, access control, data integrity verification, and identity authentication. The data encryption encrypts and protects the data transmitted through the interfaces to prevent the data from being stolen or tampered with; the access control can limit the access permissions to the interfaces, and only authorized devices and users can access the interfaces; the identity authentication can authenticate the devices connected to the interfaces to ensure the legality and security of the devices.
[0050] In some embodiments, when the trackside equipment does not need to perform identity authentication and encryption / decryption, the identity authentication and encryption / decryption functions are removed by modifying the configuration, so that the data encryption authentication device is completely separated from the trackside equipment system.
[0051] Specifically, when the trackside equipment is not powered on, the initialization configuration file is written into the initial configuration information parameters required by the business processing module. When the trackside equipment is powered on, the configuration file is read and parsed for the first time, and the parameters are modified to control whether the authentication and encryption and decryption functions are enabled, such as 1 for on and 0 for off.
[0052] Furthermore, when the trackside equipment is powered on, a command is issued to the trackside equipment. After receiving the command, the trackside equipment calls the security chip to complete the switching of the identity authentication function and the encryption and decryption function. The process is as follows: Figure 9 and Figure 10 As shown, the deauthentication function includes: the receiving end initiates a trackside equipment key recovery or update request to the business processing module, the encryption authentication module processes the key recovery or update request to obtain key recovery or update data, and sends it to the security chip, calls the security chip key recovery or update setting function, performs corresponding key recovery or update according to the key recovery or update data, and returns the key recovery or update authentication result to the encryption authentication module, the encryption authentication module encapsulates the key recovery or update confirmation information into a message and sends it to the business processing module, and then transmits the message to the receiving end through the business processing module.
[0053] Furthermore, releasing the encryption and decryption function includes: the receiving end initiates a request to turn on or off the encryption and decryption function of the trackside equipment to the business processing module; the encryption authentication module obtains the encryption and decryption turn-on or turn-off data based on the encryption and decryption turn-on or turn-off request data, and sends it to the security chip, thereby calling the security chip to turn on or off the encryption and decryption function; the encryption and decryption function is turned on or off according to the encryption and decryption turn-on or turn-off data, and the authentication encryption and decryption turn-on or turn-off data is sent to the business processing module through the encryption authentication module to turn on or off the encryption and decryption transmission of the business data.
[0054] In some embodiments, the trackside equipment has no operating system environment. The host computer software sends instructions to the trackside equipment, and the encryption authentication module of the encryption authentication device drives the call of various functions of the security chip to complete the trackside equipment identity authentication, data encryption and business logic processing, thereby facilitating centralized management of multiple trackside equipment.
[0055] In some embodiments, a train control system data encryption authentication device includes a security chip, a processor, a memory and an encryption authentication module. The security chip is used for key storage, key update and execution of encryption and decryption algorithms. The processor is used for the operation and data processing of the train control system data encryption authentication device. The memory is used to store data and programs. The encryption authentication module is used for data interaction between the security chip and the business processing module.
[0056] Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A data encryption and authentication method for a train control system, characterized in that Applied to a data encryption authentication device, the data encryption authentication device includes a security chip and an encryption authentication module, the security chip is connected to the business processing module through the encryption authentication module, the data encryption authentication device is integrated in the trackside equipment, and is used to perform identity authentication and data encryption transmission on the trackside equipment, the business processing module is integrated in the trackside equipment, and the method includes: When the trackside equipment is connected to the train control system, the trackside equipment is authenticated through the security chip; After the authentication is passed, the encryption authentication module assigns a safety identification to the trackside equipment; The security chip encrypts and decrypts the business data for transmission through the encryption authentication module.
2. The method for encrypting and authenticating train control system data according to claim 1, wherein Also includes: When the trackside equipment does not need identity authentication and data encryption and decryption, the identity authentication and encryption and decryption functions of the trackside equipment are released by modifying the software configuration.
3. The data encryption authentication method of the train control system according to claim 1, characterized in that: The identity authentication includes initial power-on identity authentication and power-off restart identity authentication.
4. The method for encrypting and authenticating train control system data according to claim 3, wherein The initial power-on identity authentication includes: When the trackside equipment is connected to the train control system for the first time, the business processing module starts the registration and authentication process. The encryption authentication module combines the trackside equipment authentication identifier sent by the business processing module with the security chip authentication identifier sent by the security chip and constructs a registration and authentication information message, which is then sent to the receiving end through the business processing module. The business processing module receives the authentication request data from the receiving end, then sends the authentication request data to the encryption authentication module for parsing, and then sends it to the security chip; The security chip processes the authentication request data, generates authentication response data and sends it to the encryption authentication module, which constructs it into an authentication response message and then sends it to the business processing module; The business processing module sends the authentication response message to the receiving end; The receiving end returns the registration authentication result of the trackside equipment to the business processing module based on the authentication response message, and sends the registration authentication result of the trackside equipment to the encryption authentication module. The encryption authentication module extracts the result information of the initial power-on and the formal key therefrom. The security chip determines the authentication result of the trackside equipment. If the authentication is successful, the security chip is updated using the extracted formal key, and the authentication pass information is transmitted to the business processing module through the encryption authentication module. If the authentication fails, the failure information is returned to the business processing module through the encryption authentication module, and the business processing module re-initiates the authentication process until the authentication is successful.
5. The method for encrypting and authenticating train control system data according to claim 3, wherein, The power-off restart identity authentication comprises: After the trackside equipment is powered off and restarted, the business processing module automatically triggers the identity authentication process, receives the registration authentication result from the receiving end, and sends the registration authentication result to the encryption authentication module, which extracts the result information of the power-off and power-on again; The security chip determines the authentication result of the trackside equipment after power-off and power-on. If the authentication is successful, the original official key and security identification of the trackside equipment are maintained. Otherwise, a failure message is returned and the authentication process is re-initiated until it succeeds.
6. The data encryption authentication method of the train control system according to claim 1, characterized in that: The methods for generating the security identifier include digital signature and hash value.
7. The method for encrypting and authenticating train control system data according to claim 1, wherein, The encrypted transmission of service data by the encryption authentication module includes: The service processing module sends the service plaintext data to the security chip through the encryption authentication module; The security chip calls the cryptographic algorithm to encrypt the service plaintext data to obtain service ciphertext data and sends it to the encryption authentication module; The encryption authentication module processes the service ciphertext data to obtain secure encrypted data, sends the secure encrypted data to the service processing module, and the service processing module transmits the secure encrypted data to the receiving end.
8. The method for encrypting and authenticating train control system data according to claim 1, wherein The decrypted transmission of service data by the encryption authentication module includes: The service processing module receives the secure encrypted data from the receiving end and sends it to the encryption authentication module; The encryption authentication module extracts the secure encrypted data to obtain service ciphertext data and then sends it to the security chip; The security chip calls the cryptographic algorithm to decrypt the service ciphertext data to obtain service plaintext data, and then sends the service plaintext data to the service processing module through the encryption authentication module.
9. The method for encrypting and authenticating train control system data according to claim 8, characterized in that The cryptographic algorithm includes a national cryptographic algorithm or an internationally common cryptographic algorithm; The national cryptographic algorithm includes SM1, SM2, SM3, and SM4. SM1 is a symmetric encryption algorithm, SM2 is an asymmetric encryption algorithm, SM3 is a hashing algorithm, and SM4 is a symmetric encryption algorithm.
10. A data encryption and authentication device for a train control system, characterized in that, It includes a security chip and an encryption authentication module; The security chip is used to authenticate the identity of the trackside equipment when the trackside equipment accesses the train control system, and to encrypt and decrypt service data; The encryption authentication module is used to transmit service data and allocate a security identifier to the trackside equipment that has passed the identity authentication.
11. The train control system data encryption and authentication device according to claim 10, characterized in that The encryption authentication device is detached from the trackside equipment system by modifying the software configuration.
12. The train control system data encryption and authentication device according to claim 10, wherein The security chip includes an initial power-on identity authentication unit and a power-off restart identity authentication unit; The initial power-on identity authentication unit is used to initiate a registration authentication process to the encryption authentication device through the service processing module when the trackside equipment first accesses the train control system; The power-off restart identity authentication unit is used to automatically trigger an identity authentication process to the encryption authentication device by the service processing module after the trackside equipment is powered off and restarted.
13. The train control system data encryption and authentication device according to claim 10, characterized in that, It further includes: A processor and a memory; The processor is used to control the operation and data processing of the train control system data encryption and authentication device; The memory is used to store data and programs, including security identifiers, keys, and identity authentication logs.
14. The train control system data encryption and authentication device according to claim 10, characterized in that The security chip integrates a cryptographic algorithm and a key management function.
15. The train control system data encryption and authentication device according to claim 14, characterized in that The cryptographic algorithm includes a national cryptographic algorithm or an internationally common cryptographic algorithm; The national cryptographic algorithms include SM1, SM2, SM3, and SM4. SM1 is a symmetric encryption algorithm, SM2 is an asymmetric encryption algorithm, SM3 is a hashing algorithm, and SM4 is a symmetric encryption algorithm.
16. The data encryption and authentication device for the train control system according to claim 14, characterized in that the key management function uses hierarchical management, including a master key and a session key; the master key is used to protect the security of the session key, and the session key is used to encrypt and decrypt service data.
Citation Information
Patent Citations
Access authentication and key agreement protocol and method of special network for space-aeronautics-vehicle-ground tracks
CN107204847A
Internet of Things terminal security authentication method based on security chip
CN110545285A
Secure communication method based on security chip
CN114244505A
Railway vehicle operation intelligent mobile terminal safety protection system
CN119364360A
Chinese national cryptographic algorithm-based identity authentication and data encryption method for coap
WO2025000590A1