Train-mounted security gateway system and security protection method
By designing a firewall board and the chassis backplane in the train on-board system to achieve data access control, the problem of insufficient communication security defense in the train on-board system is solved, the stability and security of train operation are ensured, compatible with existing equipment and support multiple communication systems.
Patent Information
- Application Number
- CN202510409852.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-08-01
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When the existing train on-board system communicates with the ground train operation control system, the security defense capabilities are insufficient and the network threats are easily extended. The existing firewall design does not fully consider the application status of the train on-board system, which has a great impact.
Design a train on-board firewall board, which is connected in series between the train on-board communication module and the radio module through a communication interface, and combines the train on-board chassis backplane to realize data access control, including 5G communication modules, protocol analysis, threat library, boundary protection, real-time monitoring, security policy configuration and logging modules to ensure safe isolation of the system.
It realizes the secure isolation between the train's on-board system and the ground system, prevents the spread of network threats, ensures the stability and security of train operation, is compatible with existing equipment, supports 5G-R and GSM-R communication standards, and has dynamic policy configuration and real-time monitoring functions.
Smart Images

Figure CN120415775A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of train on-vehicle communication, and particularly to a train on-vehicle safety gateway system and a safety protection method. Background Art
[0002] With the increasing intensification of industrial control network security risks in recent years, the network security risks have extended from the external network to the vehicle-ground communication network between the train on-vehicle system and the ground train operation control system. In the process of the continuous deep integration of rail transit and informatization, more computer technology-based security risks have been brought to the vehicle-ground communication network, and the information security of the network system faces severe challenges.
[0003] Specifically, during vehicle-ground wireless communication, there may be network threats in the wireless communication network between the train on-vehicle system and the ground train operation control system, resulting in the extension of network security risks in the ground train operation control system to the train on-vehicle system; at the same time, the design of the existing firewall does not fully consider the application status of the existing train on-vehicle system, and has a greater impact on the existing equipment.
[0004] How to improve the security defense ability of the train on-vehicle system during communication with the ground train operation control system is a technical problem that needs to be solved urgently at present. Summary of the Invention
[0005] In view of this, the embodiments of the present disclosure provide a train on-vehicle safety gateway system and a safety protection method to solve the technical problem of insufficient security defense ability of the train on-vehicle system during communication with the ground train operation control system in the prior art.
[0006] To achieve the above object, the technical solution adopted by the present disclosure is:
[0007] In the first aspect of the embodiments of the present disclosure, a train on-vehicle safety gateway system is provided, including: a train on-vehicle firewall board, including an output power interface and a communication interface, the train on-vehicle firewall board can be connected in series between the train on-vehicle communication module and the train on-vehicle radio module through the communication interface for data access control between the train on-vehicle communication module and the train on-vehicle radio module; a train on-vehicle chassis backplane, including a first relay, the control end of the first relay is connected to the power interface, and the first signal end and the second signal end of the first relay are respectively connected to the train on-vehicle communication module and the train on-vehicle radio module.
[0008] In some embodiments, the train on-vehicle chassis backplane further includes a second relay, the control end of the second relay is connected to the power interface, and the first signal end and the second signal end of the second relay are respectively connected to the signal ground of the train on-vehicle communication module and the signal ground of the train on-vehicle radio module.
[0009] In some embodiments, the train on-vehicle firewall board card further includes a 5G communication module, and the 5G communication module can respectively establish communication connections with the train on-vehicle communication module and the train on-vehicle radio module by using the 5G interface protocol.
[0010] In some embodiments, the train on-vehicle firewall board card further includes a train communication protocol parsing module, and the train communication protocol parsing module can deeply parse communication data according to the train-specific protocol.
[0011] In some embodiments, the train on-vehicle firewall board card further includes a database module, and the database module is built-in with an updatable industrial control threat library and threat feature detection rules. The industrial control threat library includes a whitelist and a blacklist, and the database module can perform data filtering according to the threat feature detection rules, the whitelist and the blacklist.
[0012] In some embodiments, the train on-vehicle firewall board card further includes a boundary protection module, and the boundary protection module can prevent unauthorized external access and attacks from entering the train on-vehicle communication network.
[0013] In some embodiments, the train on-vehicle firewall board card further includes a real-time event monitoring module, and the real-time event monitoring module can monitor and record network events, device events and platform events, and identify and block advanced persistent threat attacks according to the recorded content.
[0014] In some embodiments, the train on-vehicle firewall board card further includes a security policy configuration module, and the security policy configuration module can perform dynamic security policy configuration of the firewall according to the set security requirements.
[0015] In some embodiments, the train on-vehicle firewall board card further includes a log recording module, and the log recording module can record logs and upload the network attack behaviors in the logs to the server side.
[0016] In the second aspect of the embodiments of the present disclosure, there is provided a security protection method for a train on-vehicle security gateway system applying the first aspect of the embodiments of the present disclosure. The security protection method includes: after inserting the train on-vehicle firewall board card into the train on-vehicle chassis, the first relay on the backplane of the train on-vehicle chassis is attracted, so that the train on-vehicle firewall board card is connected in series between the train on-vehicle communication module and the train on-vehicle radio module through a communication interface, wherein the train on-vehicle firewall board card is used for performing data access control between the train on-vehicle communication module and the train on-vehicle radio module.
[0017] The beneficial effects of the embodiments of the present disclosure compared with the prior art are as follows: By designing the train on-vehicle firewall board and using it in cooperation with the train on-vehicle chassis backplane, the embodiments of the present disclosure can achieve data access control between the train on-vehicle communication module and the train on-vehicle radio module, realize the secure isolation and protection between the train on-vehicle system and the ground train operation control system, and ensure the stability and safety of train operation. Description of the Drawings
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0019] Figure 1 is a schematic structural diagram of the vehicle-ground communication network in the prior art;
[0020] Figure 2 is a schematic structural diagram of the train automatic protection system in the prior art;
[0021] Figure 3 is a schematic diagram of a train on-vehicle safety gateway system provided by the embodiments of the present disclosure;
[0022] Figure 4 is a schematic structural diagram of the train automatic protection system provided by the embodiments of the present disclosure;
[0023] Figure 5 is a schematic diagram of the front panel of the train on-vehicle firewall board provided by the embodiments of the present disclosure;
[0024] Figure 6 is a schematic structural diagram of the train on-vehicle firewall board provided by the embodiments of the present disclosure;
[0025] Figure 7 is a schematic diagram of the first relay provided by the embodiments of the present disclosure;
[0026] Figure 8 is a schematic diagram of the second relay provided by the embodiments of the present disclosure. Detailed Embodiments
[0027] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present disclosure more clearly understood, the present disclosure will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present disclosure and are not used to limit the present disclosure.
[0028] The technical solution of the embodiments of the present disclosure can be applied to the field of vehicle-ground wireless communication security protection of the high-speed railway CTCS-3 train operation control system. CTCS-3 is a train operation control system that transmits information wirelessly and uses track circuits and other methods to check train occupancy. The train on-board firewall board of the embodiments of the present disclosure is designed for the problem of insufficient security defense capabilities of the train on-board system when using the 5G-R (5G-Railway) network for vehicle-ground wireless communication.
[0029] Currently, the high-speed railway CTCS-3 train operation control system still uses the GSM-R (Global System for Mobile Communications-Railway) wireless communication system for communication between the vehicle-ground control systems. With the development of 5G (5th Generation Mobile Communication Technology), the 5G-R communication standard has gradually been applied to the CTCS-3 train control system and the high-speed rail ATO (Automatic Train Operation) system. However, neither the CTCS-3 train control system nor the high-speed rail ATO system comprehensively considers information security risks when the on-board ATP (Automatic Train Protection) communicates with the ground train operation control system. Only the RSSP-II protocol or the RSSP-I protocol is used for vehicle-ground wireless communication to protect against communication risks such as repetition, deletion, insertion, reordering, damage, delay, and spoofing specified in the EN50159 standard.
[0030] Therefore, a solution is needed to enhance the communication security between the CTCS-3 train on-board system and the ground train operation control system, so as to ensure network security without affecting the normal operation of the existing system when using 5G-R as the new communication standard.
[0031] Currently, the widely used CTCS-3 train control system uses an on-board radio unit for vehicle-ground wireless communication via GSM-R. One of the interfaces between the CTCS-3 train control system and the GSM-R network is the IGSM-R interface, and one of the interfaces with the 5G network is the N6 interface. As Figure 1As shown in the figure, for the application scenarios of 5G-R, the train on-board system provides a two-way data transmission channel for IP (Internet Protocol) between the train control ground equipment through 5G-R at the IGSM-R interface and the N6 interface. When the CTCS-3 system adopts the 5G-R network, in order to be compatible with the existing GSM-R communication scenarios, the existing security connection mechanism and application message process need to be kept unchanged, and the form of the IGSM-R interface and other on-board existing equipment hardware need to be kept unchanged.
[0032] Each end of the ATP equipment of the train operation control system is equipped with two GSM-R / 5G-R dual-mode radios. Under both networks, the radio uses the IGSM-R interface to communicate with the ATP. Each radio has only one antenna interface, which is shared for GSM-R / 5G-R transceiver. When the radio works in the GSM-R mode and uses the GSM-R network, the train control data is transmitted through the circuit domain, and a reliable connection is established relying on the HDLC protocol, and the Subset037 protocol is used. When the radio works in the 5G-R mode, the train control data is transmitted through the packet domain, and a reliable connection is established relying on the TCP (Transmission Control Protocol), and the Subset037 protocol is used.
[0033] As Figure 2 shown, taking the 300S type on-board ATP system as an example, the radio unit consists of a chassis module, a power module, a radio module, a communication module, and a recording module. The radio module communicates with the interface board through the backplane using TTL (Transistor-Transistor Logic), and the communication interface conforms to the IGSM-R interface specification. The electrical characteristics adopt 5V TTL level. The communication module communicates with the wireless communication unit of the RIM company through a DB25 connector, the communication interface conforms to the IGSM-R interface specification, and the electrical characteristics adopt the RS-422 balanced mode.
[0034] The train on-board security gateway system and security protection method according to the embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0035] Figure 3 is a schematic diagram of a train on-board security gateway system provided by an embodiment of the present disclosure; Figure 4 is a schematic diagram of the structure of a train automatic protection system provided by an embodiment of the present disclosure; Figure 5 is a schematic diagram of the front panel of a train on-board firewall board provided by an embodiment of the present disclosure; Figure 6 is a schematic diagram of the structure of a train on-board firewall board provided by an embodiment of the present disclosure; Figure 7 is a schematic diagram of a first relay provided by an embodiment of the present disclosure; Figure 8It is a schematic diagram of the second relay provided by an embodiment of the present disclosure. The following will be combined with Figures 3 to 8 to describe the train on-vehicle safety gateway system and safety protection method provided by an embodiment of the present disclosure.
[0036] As Figure 3 shown, the train on-vehicle safety gateway system of an embodiment of the present disclosure includes:
[0037] The train on-vehicle firewall board 301 includes an output power interface and a communication interface. The train on-vehicle firewall board can be connected in series between the train on-vehicle communication module and the train on-vehicle radio module through the communication interface, and is used for data access control between the train on-vehicle communication module and the train on-vehicle radio module.
[0038] The train on-vehicle chassis backplane 302 includes a first relay. The control end of the first relay is connected to the power interface, and the first signal end and the second signal end of the first relay are respectively connected to the train on-vehicle communication module and the train on-vehicle radio module.
[0039] The technical solution of the embodiment of the present disclosure can be applied to the field of security protection of the vehicle-ground wireless communication network between the train on-vehicle system of rail transit and the ground train operation control system. When the CTCS-3 level train control system uses the 5G-R network for vehicle-ground wireless communication, it can prevent network threats to the wireless communication network between the train on-vehicle system and the ground train operation control system, and prevent network security risks in the ground system from extending to the train on-vehicle system; at the same time, the design of the train on-vehicle firewall board fully considers the application status of the existing CTCS-3 level train on-vehicle system, and minimizes the impact on the existing equipment.
[0040] In the embodiment of the present disclosure, to add an on-vehicle firewall function to the existing ATP system while maintaining the existing system architecture and minimizing the impact on the ATP system, it is necessary to add an on-vehicle firewall device, that is, the train on-vehicle firewall board, to each radio module in the radio unit, and at the same time, it is necessary to be compatible with the communication protocols related to the existing radio unit and the design of the chassis backplane to achieve zero impact on the existing on-vehicle ATP system.
[0041] In view of the fact that the radio unit adopts a dual-channel redundant design, in the technical solution of the embodiment of the present disclosure, an additional train on-vehicle firewall board is added to each radio channel, that is, as Figure 4The firewalls 1 and 2 shown. A total of two train on-vehicle firewall boards need to be added to each radio unit. The communication logic position of the train on-vehicle firewall board should be between the radio module and the communication module, and access the IGSM-R interface through the backplane of the train on-vehicle chassis. Downlink data is received from the ground by the radio module, transmitted to the train on-vehicle firewall board through the TTL of the train on-vehicle chassis backplane, and then transmitted to the communication module by the train on-vehicle firewall board through the train on-vehicle chassis backplane. Uplink data communicates with the train on-vehicle firewall board through the train on-vehicle chassis backplane, and the train on-vehicle firewall board then communicates with the radio module. Among them, the communication module is the train on-vehicle communication module, and the radio module is the train on-vehicle radio module.
[0042] In the embodiment of the present disclosure, the train on-vehicle firewall board further includes a 5G communication module, and the 5G communication module can respectively establish communication connections with the train on-vehicle communication module and the train on-vehicle radio module by using the 5G interface protocol.
[0043] As Figure 5 shown, in consideration of adapting to the installation size of the radio chassis, the train on-vehicle firewall board complies with the 3U chassis standard and adopts a board-type design with a specification of 3U×6TE. The train on-vehicle firewall board consists of a functional module and related mechanical structural parts. It can use a circuit board with a size of 100mm*160mm, and the front panel adopts a 6TE design. The train on-vehicle firewall board is provided with 1 eight-core M12 interface, which can be converted into 1 USB and 1 console network device interface through a patch cord for downloading data and software debugging. The train on-vehicle firewall board is provided with a 100M Ethernet port in the form of a 4-core M12 connector for management and maintenance interfaces, and an online security audit interface is reserved. If the online security audit function is not enabled, no wiring is required on the front panel. The train on-vehicle firewall board is provided with a power Bypass (bypass) switch, and Bypass is achieved by controlling the power supply. When the board is in a power-off state, it defaults to Bypass, and the train on-vehicle firewall board can be system-isolated from the radio. The train on-vehicle firewall board is provided with power, module operation status, Bypass indication, MGMT port, and a total of 8 indicator lights for indicating the communication status of two pairs of input and output signals of service port 1 and service port 2. The board is connected to the chassis bottom plate of the train on-vehicle chassis through a 96-pin European connector on the train on-vehicle chassis backplane and is connected in series in the IGSM-R communication interface to complete the data filtering function.
[0044] The front panel of the train on-board firewall board uses LED indicators with a hole diameter of 2.00 mm and a hole pitch of 5.08 mm. The power indicator is green. When the power supply is normal, the power indicator is always on; when there is a power failure, the power indicator is off. The board status indicator is green, which indicates the GPIO signal, and is on when the GPIO signal is normal and off when the GPIO signal fails. The management network port indicator is green, which indicates the GMGT signal, and is on when the GMGT signal is normal and off when the GMGT signal fails. The Bypass indicator is green, which is on during serial port Bypass and off during non-Bypass. The serial port communication indicator is green, which blinks when data is being transmitted and received during RS422 communication on serial ports 1 and 2, and is off when there is no data.
[0045] The bottom plate of the train on-board chassis is responsible for power supply. It is designed with two 12V inputs to provide the presence signal and the slot signal. The presence signal is used by the bottom plate to determine whether the main board is present. The slot signal reserves the GPIO signal for the main board to determine which slot on the bottom plate it is inserted into, and the signal comes from the pre-defined bottom plate.
[0046] The train on-board chassis backplane provides 2 channels of 5V TTL level UART signals, namely signals A29-COM1_Rx, A30-COM1_Tx, B29-COM2_Rx, and B30-COM2_Tx. When 2-channel serial port Bypass occurs, the train on-board chassis backplane will connect A29-COM1_Rx to B30-COM2_Tx, connect A30-COM1_Tx to B29-COM2_Rx, and at the same time isolate the connection of the signal ground to ensure direct passage of external signals. The power-off bypass design can ensure that the vehicle-ground network can still communicate normally in case of power failure or abnormal conditions of the device.
[0047] The train on-board firewall board uses a 96-pin European standard connector and is equipped with 2 serial ports with TTL level, which are used for communication between the DCE (Data Circuit-terminating Equipment) and the interface board where the train on-board communication module is located, and between the DTE (Data Terminal Equipment) and the radio board where the train on-board radio module is located respectively. It is in the Bypass state during the power-off state and the power-on process, and the 2 serial ports adopt a direct connection design. The power interface obtains power from the train on-board chassis backplane. The maximum power of a single board does not exceed 20W, and the average power does not exceed 10W.
[0048] The train on-vehicle firewall board is responsible for the communication adaptation between the communication board of the on-vehicle equipment communication unit and the radio module. Each train on-vehicle firewall board is only responsible for the communication between one communication board and the radio module and does not belong to the functional safety-level equipment. Therefore, a single CPU (Central Processing Unit) structure can be adopted. Considering the low-power consumption requirements of train on-vehicle equipment, the train on-vehicle firewall board uses an industrial-grade embedded chip to adapt to various extreme weather conditions during train operation. At the same time, it adopts a design that supports multiple buses to adapt to the communication rates of different buses and ensure that the data packet throughput meets the requirements. The schematic diagram of the hardware logic structure of the train on-vehicle firewall board is as shown in Figure 6 shown below.
[0049] As Figure 7 shown, the first relay on the train on-vehicle chassis backplane has control terminals B2 and B3. The first signal terminal and the second signal terminal of the first relay are respectively connected to the train on-vehicle communication module and the train on-vehicle radio module. Among them, the first relay has two groups of first signal terminals and second signal terminals. The second signal terminal ADAPTER_CT103_IN of the first group is connected to the train on-vehicle communication module to receive the signal sent by the train on-vehicle communication module, and the first signal terminal MT_CT103_OUT is connected to the train on-vehicle radio module to send a signal to the train on-vehicle radio module. The first signal terminal MT_CT104_IN of the second group is connected to the train on-vehicle radio module to receive the signal sent by the train on-vehicle radio module, and the second signal terminal ADAPTER_CT104_OUT is connected to the train on-vehicle communication module to send a signal to the train on-vehicle communication module.
[0050] The radio module transmits data to the train on-vehicle firewall board through two 5V TTL signals CT103_IN and CT104_IN on the train on-vehicle chassis backplane. The train on-vehicle firewall board also transmits data to the communication module through two 5V TTL signals CT103_OUT and CT104_OUT on the train on-vehicle chassis backplane. When the train on-vehicle firewall board is not inserted, for the CT103 and CT104 signal data, the radio module can be directly connected to the communication module. When the train on-vehicle firewall board is inserted, for the CT103 and CT104 signal data, the radio module data is first filtered by the train on-vehicle firewall board and then transmitted to the communication module. The backplane needs to use a relay with a 5V coil voltage. The coil is connected to B2 / B3, and the two normally closed contacts are connected to CT103 and CT104. When the train on-vehicle firewall board is not inserted, the normally closed contacts of the relay are closed, and the CT103 and CT104 signals between the radio module and the communication module are normally conducted. When the train on-vehicle firewall board is inserted, the normally closed contacts of the relay are disconnected, and the train on-vehicle firewall board performs data forwarding.
[0051] Considering the isolation of the input and output signals of the on-train firewall board, it is necessary to switch the signal ground. For example, Figure 8 As shown, the backplane of the on-train chassis further includes a second relay. The control terminals B2 and B3 of the second relay are connected to the power interface. The first signal terminal ADAPTER_SGND and the second signal terminal MT_SGND of the second relay are respectively connected to the signal ground of the on-train communication module and the signal ground of the on-train radio module.
[0052] In the embodiments of the present disclosure, the relay coils of the first relay and the second relay are both driven by the 5V power supply output by the on-train firewall board at the same time.
[0053] In the physical layer communication design between the on-train firewall board and other modules, the electrical specifications between the on-train firewall board and the radio module are a 5V TTL interface, the baud rate is 9600bps, and it adopts a bidirectional synchronous transmission mode without a transmission cycle; the electrical specifications between the on-train firewall board and the communication module are a 5V TTL interface, the baud rate is 9600bps, and it adopts a bidirectional synchronous transmission mode without a transmission cycle.
[0054] The on-train firewall board is powered by the backplane of the on-train chassis, with a working voltage of DC12V ± 5% 830mA max and having a short-circuit protection function. The backplane of the on-train chassis provides 2 channels of TTL-level UART signals; 2 channels of TTL outputs, signal isolation, 1 group of Bypass; 1 group of in-position signals, 1 group of slot signals. The input / output voltage range of TTL is -0.5V - 6V, the output current is ±15mA, the high and low level ranges are >4.2V and <0.4V, and the waveform state is a square wave.
[0055] The on-train firewall board in the embodiments of the present disclosure can be installed through the chassis guide rail. A pull assist device can be set on the front panel of the on-train firewall board to facilitate the insertion and removal of the on-train firewall board. In addition, the backplane of the on-train chassis adopts an anti-mixing pin design.
[0056] At the software function level, the on-train firewall board aims to achieve the secure isolation and protection between the on-train system and the ground train operation control system, avoid unauthorized access and attacks, reduce the risk of the spread of network storms, attack behaviors, viruses, etc. in the ground service system to the train, and ensure the stability and security of train operation; at the same time, it monitors the activities of the on-train network in real time, records and analyzes network traffic, discovers abnormal behaviors and potential security threats in a timely manner, adds intrusion detection and intrusion prevention functions, and discovers and blocks unauthorized intrusion behaviors. In addition, considering that the application scenario of the on-train firewall board is different from that of a conventional ground traditional firewall, the on-train firewall board is designed with the following multiple modules that meet the requirements of the on-train system.
[0057] In an embodiment of the present disclosure, the train on-vehicle firewall board card further includes a train communication protocol parsing module, which can deeply parse communication data according to the train-specific protocol. Specifically, it can deeply parse the RSSP-I and RSSP-II train-specific protocols to ensure the legality of the data content.
[0058] In an embodiment of the present disclosure, the train on-vehicle firewall board card further includes a database module, which internally stores an updatable industrial control threat library and threat feature detection rules. The industrial control threat library includes a whitelist and a blacklist, and the database module can filter data according to the threat feature detection rules, the whitelist, and the blacklist. The database module internally stores an updatable professional industrial control threat library and threat feature detection rules, supports self-learning of service traffic, and automatically constructs industrial control protocol whitelist rules.
[0059] In an embodiment of the present disclosure, the train on-vehicle firewall board card further includes a boundary protection module, which can prevent unauthorized external access and attacks from entering the train on-vehicle communication network. Specifically, the train on-vehicle firewall board card can implement different configuration schemes such as boundary protection, area protection, and terminal protection, and accurately identify key operation behaviors and give alarms.
[0060] In an embodiment of the present disclosure, the train on-vehicle firewall board card further includes a real-time event monitoring module, which can monitor and record network events, device events, and platform events, and identify and block advanced persistent threat attacks according to the recorded content. Specifically, it can provide a comprehensive event monitoring and security protection mechanism, monitor and record network security events, device management operations, and platform system events in real time, and give alarms and block APT attacks and abnormal behaviors.
[0061] In an embodiment of the present disclosure, the train on-vehicle firewall board card further includes a security policy configuration module, which can perform dynamic security policy configuration of the firewall according to the set security requirements. It has flexible security policy configuration capabilities and can be dynamically adjusted according to different security requirements.
[0062] In an embodiment of the present disclosure, the train on-vehicle firewall board card further includes a log recording module, which can record logs and upload the network attack behaviors in the logs to the server side. It has a complete log recording function, can record any attack behavior and remotely transmit it to the server side for later analysis.
[0063] Specifically, the on-train firewall board card of the train is connected in series between the communication module and the radio module, and only processes the two data transceiver signals of sending data and receiving data of the IGSM-R interface. The remaining signals such as request to send, ready to send, ready to set up, data terminal ready, and data channel receive link signal detector are directly controlled by the communication module and the radio module for communication, without affecting the existing control logic.
[0064] At the link layer, the on-train firewall board card of the train supports AT protocol recognition and transparently forwards the AT control commands between the on-vehicle device and the dual-mode communication module, so as to enable the configuration and control of the dual communication module by the on-vehicle device; it can process the received AT command packets, circuit domain HDLC data packets, and packet domain PPP data packets respectively. It supports PPP protocol recognition and transparently forwards the LCP protocol and NCP protocol of the PPP protocol, so as to enable the PPP link negotiation of the dual-mode communication module by the on-vehicle device; it supports the recognition of PPP protocol IP data and performs security detection on the TCP / IP (Transmission Control Protocol / Internet Protocol) data carried by the PPP protocol.
[0065] At the network layer, the on-train firewall board card of the train supports security policies based on five-tuples, including partial or all combinations of source IP address, destination IP address, source port, destination port, and protocol type; it supports access control based on state detection technology; it supports setting the maximum concurrent session number for a single IP and rejecting TCP connections exceeding the maximum concurrent session number; it supports global anti-DoS (Denial of Service) attacks.
[0066] At the application layer, the on-train firewall board card of the train supports the protocol format specification check of the ALE (Automatic Link Establishment) protocol, prohibits communications that do not conform to the protocol specification, and prevents ALE protocol logic defect attacks; it supports application layer security detection and illegal data interception based on parameters such as ALE protocol type, data elements, and range.
[0067] In terms of log management, the on-train firewall board card of the train only allows authorized administrators to access the logs; it provides a log viewing tool with the ability to retrieve audit events based on conditions such as date, time, source IP address, and destination IP address, and only allows authorized administrators to use the viewing tool.
[0068] The technical solution of the disclosed embodiments improves the network security of the train's onboard system by adding an onboard firewall card, enhancing its ability to resist unknown attacks while ensuring the safety and stability of train operations. Furthermore, the onboard firewall card includes a reserved expansion interface, enabling the development of future security audit systems and increasing system scalability.
[0069] The train-mounted firewall board of the disclosed embodiment can be seamlessly integrated into the existing CTCS-3 train-mounted system without changing the existing train-mounted system communication architecture, thereby increasing the firewall function of the on-board system. It is compatible with the bottom plate design and communication design of the existing radio unit chassis of 300S, 300H, 400H and other train-mounted systems, and meets the requirements of EN50155 and GB / T24338.4 on-board product standards, and supports train-to-ground wireless communication under both GSM-R and 5G-R communication standards.
[0070] The train-mounted firewall board in this disclosed embodiment is pre-designed with a 4-core M12 100M Ethernet port, which allows for subsequent expansion and connection to the onboard network security audit system, enhancing the scalability of the network. Furthermore, the train-mounted firewall board features global bypass and fully transparent, uninterrupted deployment, preventing single points of failure during line deployment from causing network failures. In the event of a device failure, the hardware bypass function is automatically enabled, allowing data traffic to pass normally without being affected by the failure, ensuring business continuity.
[0071] The train-mounted firewall board of the disclosed embodiment adopts a relay design with a 5V coil voltage, which can automatically adapt to whether the train-mounted firewall board is configured, so as to be compatible with application scenarios of both GSR-R and 5G-R communication standards. When the train-mounted firewall board is not inserted, the signal between the radio module and the communication module can be conducted normally; when the train-mounted firewall board is inserted, the train-mounted firewall board performs data forwarding. The train-mounted firewall board has a dynamic policy library management function, supports policy library updates, local encrypted storage of policy libraries, and push updates of emergency rules, and performs data integrity verification and data encryption on the update transmission process of the policy library to ensure data integrity and confidentiality.
[0072] According to the train-mounted security gateway system provided by the embodiment of the present disclosure, by designing a train-mounted firewall board and using it in conjunction with the train-mounted chassis backplane, data access control between the train-mounted communication module and the train-mounted radio module can be achieved, and the safe isolation and protection of the train-mounted system and the ground train operation control system can be achieved, thereby ensuring the stability and safety of the train operation.
[0073] The embodiments of the present disclosure further provide a security protection method for a train on-vehicle safety gateway system applying the above technical solution. The security protection method includes: after inserting the train on-vehicle firewall board into the train on-vehicle chassis, the first relay on the backplane of the train on-vehicle chassis is attracted, so that the train on-vehicle firewall board is connected in series between the train on-vehicle communication module and the train on-vehicle radio module through the communication interface, wherein the train on-vehicle firewall board is used to perform data access control between the train on-vehicle communication module and the train on-vehicle radio module.
[0074] According to the security protection method for the train on-vehicle safety gateway system provided by the embodiments of the present disclosure, by designing the train on-vehicle firewall board and using it in cooperation with the backplane of the train on-vehicle chassis, data access control between the train on-vehicle communication module and the train on-vehicle radio module can be realized, and the security isolation and protection between the train on-vehicle system and the ground train operation control system can be achieved, ensuring the stability and security of train operation.
[0075] The above are only the preferred embodiments of the present disclosure and are not intended to limit the present disclosure. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. A train on-vehicle safety gateway system, characterized in that, The train on-vehicle safety gateway system includes: A train on-vehicle firewall board, which includes an output power interface and a communication interface. The train on-vehicle firewall board can be connected in series between the train on-vehicle communication module and the train on-vehicle radio module through the communication interface, and is used for data access control between the train on-vehicle communication module and the train on-vehicle radio module; A train on-vehicle chassis backplane, which includes a first relay. The control end of the first relay is connected to the power interface, and the first signal end and the second signal end of the first relay are respectively connected to the train on-vehicle communication module and the train on-vehicle radio module.
2. The train on-vehicle safety gateway system according to claim 1, characterized in that, The train on-vehicle chassis backplane further includes a second relay. The control end of the second relay is connected to the power interface, and the first signal end and the second signal end of the second relay are respectively connected to the signal ground of the train on-vehicle communication module and the signal ground of the train on-vehicle radio module.
3. The train on-vehicle safety gateway system according to claim 1, characterized in that, The train on-vehicle firewall board further includes a 5G communication module, and the 5G communication module can communicate with the train on-vehicle communication module and the train on-vehicle radio module respectively by using the 5G interface protocol.
4. The train on-vehicle safety gateway system according to claim 1, characterized in that The train on-vehicle firewall board further includes a train communication protocol parsing module, and the train communication protocol parsing module can deeply parse communication data according to the train-specific protocol.
5. The train on-vehicle safety gateway system according to claim 1, wherein The train on-vehicle firewall board further includes a database module. The database module has a built-in updatable industrial control threat library and threat feature detection rules. The industrial control threat library includes a whitelist and a blacklist, and the database module can filter data according to the threat feature detection rules, the whitelist and the blacklist.
6. The train on-vehicle safety gateway system according to claim 1, characterized in that The train on-vehicle firewall board further includes a boundary protection module, and the boundary protection module can prevent unauthorized external access and attacks from entering the train on-vehicle communication network.
7. The train on-vehicle safety gateway system according to claim 1, characterized in that, The train on-vehicle firewall board further includes a real-time event monitoring module, and the real-time event monitoring module can monitor and record network events, device events and platform events, and identify and block advanced persistent threat attacks according to the recorded content.
8. The train on-vehicle safety gateway system according to claim 7, characterized in that, The train on-vehicle firewall board further includes a security policy configuration module, and the security policy configuration module can perform dynamic security policy configuration of the firewall according to the set security requirements.
9. The train on-vehicle safety gateway system according to claim 1, characterized in that The train on-vehicle firewall board further includes a log recording module, and the log recording module can record logs and upload the network attack behaviors in the logs to the server side.
10. A safety protection method for a train on-vehicle safety gateway system according to any one of claims 1 to 9, characterized in that, After the train on-vehicle firewall board is inserted into the train on-vehicle chassis, the first relay on the train on-vehicle chassis backplane is energized, so that the train on-vehicle firewall board is connected in series between the train on-vehicle communication module and the train on-vehicle radio module through the communication interface, wherein the train on-vehicle firewall board is used for data access control between the train on-vehicle communication module and the train on-vehicle radio module.