Train multi-network integration data transmission method, system and device and storage medium

The generation of shared keys in the train network through quantum random number generation technology solves the problem of insufficient security of data transmission in the train multi-service network, realizes non-cloned and non-eavesdropping data transmission, and improves the network's attack resistance and security.

CN120474792APending Publication Date: 2025-08-12CRRC TANGSHAN CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510694777.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In existing train multi-service networks, although the real-time data transmission is guaranteed, the security is insufficient, and different types of service networks may trigger cross-virtual LAN attacks and expose sensitive data when interacting.

Method used

Using quantum random number generation technology, the first device generates the first quantum random number as a private key, generates a public key, and adds a virtual LAN identifier to generate a shared key. The second device generates the second quantum random number for encryption, realizing the encryption and decryption of data transmission.

Benefits of technology

It has enhanced the anti-attack capability of multi-network converged networks, provided data transmission characteristics that are not cloned, not eavesdropped and undeciphered, and ensured long-term and stable protection of train networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474792A_ABST
    Figure CN120474792A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a train multi-network integration data transmission method, system and device and a storage medium, and relates to the technical field of rail transit. The method comprises the following steps: a first device generates a first quantum random number as a private key, generates a public key according to the private key, generates a shared key after adding a virtual local area network identifier to the public key, and sends the shared key to a second device; the second device generates a second quantum random number, encrypts the second quantum random number through the shared key and sends the second quantum random number to the first device; and the first device and the second device perform encryption and decryption of data transmission through the second quantum random number. According to the method, the network anti-attack capability after multi-network integration is enhanced through the quantum random number generation technology, the method has the advantages of being unclonable, uneavesdropped and undecoded, and long-term stable protection is provided for the train network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of rail transit technology, and in particular to a train multi-network integrated data transmission method, system, device and storage medium. Background Art

[0002] With the development of train communication systems, multi-network integration has become a key approach to improving train operational efficiency and intelligent management. However, this integration also presents new security challenges, particularly with regard to the security and integrity of data transmission. Quantum cryptography, as an emerging security measure, offers extremely high security and can effectively address the shortcomings of traditional encryption technologies.

[0003] After multi-network integration on trains, control data, video data, and maintenance data are transmitted on the same train backbone network. However, each type of data has different requirements for data volume, real-time performance, fault tolerance, security, and priority. Control data has extremely high security and real-time requirements; video data has moderate security and real-time requirements; and maintenance data is sporadic and has lower security and real-time requirements. Existing technology typically transmits data on trains via Ethernet.

[0004] However, the current train multi-service network only allocates bandwidth and priority based on data type, and does not take strict security encryption measures. Although it effectively guarantees the real-time nature of data, it cannot guarantee data security. In addition, when different types of service networks interact with each other, cross-VLAN attacks may occur, thereby exposing sensitive data. Summary of the Invention

[0005] In order to solve one of the above-mentioned technical defects, an embodiment of the present application provides a train multi-network fusion data transmission method, device and storage medium.

[0006] According to a first aspect of an embodiment of the present application, a train multi-network integrated data transmission method is provided, the method comprising:

[0007] The first device generates a first quantum random number as a private key, generates a public key based on the private key, adds a virtual local area network identifier to the public key to generate a shared key, and sends the shared key to the second device;

[0008] The second device generates a second quantum random number, encrypts it with the shared key, and sends the second quantum random number to the first device;

[0009] The first device and the second device perform encryption and decryption of data transmission through the second quantum random number.

[0010] In an optional embodiment of the present application, the first device generates a first quantum random number as a private key, generates a public key based on the private key, adds a virtual local area network identifier to the public key to generate a shared key, and sends the shared key to the second device further comprising:

[0011] The first device distributes the shared key in a logical address form.

[0012] In an optional embodiment of the present application, the first device generates a first quantum random number as a private key, generates a public key based on the private key, adds a virtual local area network identifier to the public key to generate a shared key, and sends the shared key to the second device further comprising:

[0013] The first device generates a first quantum random number in the form of injection, and distributes a shared key through a quantum key service platform.

[0014] In an optional embodiment of the present application, the step of the second device generating a second quantum random number, encrypting the second quantum random number using a shared key, and sending the second quantum random number to the first device further includes:

[0015] The first device has one and the second device has at least two. Each second device generates its own second quantum random number, so that each second device encrypts and decrypts data transmission with the first device through its own second quantum random number.

[0016] In an optional embodiment of the present application, the steps of encrypting and decrypting data transmission between the first device and the second device using the second quantum random number further include:

[0017] Data transmission between different second devices is forwarded by the first device.

[0018] In an optional embodiment of the present application, the first device and the second device belong to the same virtual local area network, the first device is a master device, and the second device is a terminal device.

[0019] In an optional embodiment of the present application, the first device and the second device belong to different virtual local area networks, and both the first device and the second device are master devices.

[0020] In an optional embodiment of the present application, the device address of the first device is smaller than that of the second device.

[0021] According to a second aspect of an embodiment of the present application, a train multi-network integrated data transmission system is provided, the system comprising a shared key generation module, a second quantum random number generation module and a data transmission module; wherein,

[0022] A shared key generation module, configured for the first device to generate a first quantum random number as a private key, generate a public key based on the private key, add a virtual local area network identifier to the public key to generate a shared key, and send the shared key to the second device;

[0023] A second quantum random number generation module is used for the second device to generate a second quantum random number, and to encrypt the second quantum random number with a shared key and send it to the first device;

[0024] The data transmission module is used for encrypting and decrypting data transmission between the first device and the second device using the second quantum random number.

[0025] According to a third aspect of an embodiment of the present application, a computer device is provided, comprising: a memory; a processor; and a computer program; wherein the computer program is stored in the memory and is configured to be executed by the processor to implement a train multi-network fusion data transmission method as described in any one of the first aspects of the embodiment of the present application.

[0026] According to the fourth aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program is stored; the computer program is executed by a processor to implement the train multi-network fusion data transmission method as described in any one of the first aspects of the embodiments of the present application.

[0027] The train multi-network integrated data transmission method provided in the embodiments of the present application has the following beneficial effects:

[0028] This application uses a quantum random number generator to generate true random numbers, and uses the true random numbers to generate session keys again through encryption operations. The quantum random number generation technology enhances the network's anti-attack capability after multi-network integration, and has the characteristics of being unclonable, uneavesdropped and undecipherable, providing long-term and stable protection for the train network. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0030] Figure 1 Flowchart of the train multi-network fusion data transmission method provided in an embodiment of the present application;

[0031] Figure 2 A schematic diagram of train multi-network fusion data transmission interaction provided in an embodiment of the present application;

[0032] Figure 3 A structural diagram of the train multi-network fusion data transmission system provided in an embodiment of the present application;

[0033] Figure 4 A schematic diagram of the computer device structure provided for one embodiment of the present application. DETAILED DESCRIPTION

[0034] In order to make the technical solutions and advantages of the embodiments of the present application more clearly understood, the exemplary embodiments of the present application are further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, and are not an exhaustive list of all the embodiments. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other unless they conflict.

[0035] In existing technology, train Ethernet serves as a control network, transmitting various control information for controlling train operation, including traction, braking, and other information. Train Ethernet serves as a maintenance network, allowing train network equipment and other subsystem control units with Ethernet interfaces to connect to each car's switch via an Ethernet bus to transmit data such as fault diagnosis, event logging, and display. Train Ethernet can also transmit video surveillance information (including car and pantograph video) and information system information. To prevent interference between various data types during Ethernet communication and ensure data transmission reliability and security, VLAN (Virtual Local Area Network) and IP address division are performed on each car's switch, and the switch port rate and data service priority are set.

[0036] However, existing train multi-service networks only allocate bandwidth and priority based on data type, without strict security encryption measures. While this effectively ensures real-time data delivery, it cannot guarantee data security. Furthermore, when different types of service networks interact with each other, cross-VLAN attacks can occur, exposing sensitive data.

[0037] Based on this, an embodiment of the present application provides a train multi-network integrated data transmission method to achieve secure information transmission.

[0038] like Figure 1 As shown, this application proposes a train multi-network fusion data transmission method, Figure 1 For a flow chart of the train multi-network fusion data transmission method provided in the embodiment of this application, please refer to Figure 1 :

[0039] S1: The first device generates a first quantum random number as a private key, generates a public key based on the private key, adds a virtual local area network identifier to the public key to generate a shared key, and sends the shared key to the second device.

[0040] S2: The second device generates a second quantum random number, encrypts it with the shared key, and sends the second quantum random number to the first device;

[0041] S3: The first device and the second device perform encryption and decryption of data transmission using the second quantum random number.

[0042] In a specific implementation, the first device and the second device are the two parties involved in the encrypted data transmission. The first device generates a first quantum random number as a private key and retains it for itself. The first quantum random number is encrypted again to generate a shared key for the session, which is then sent to the other party involved in the encrypted data transmission, namely the second device.

[0043] The second device generates a second quantum random number, encrypts it with the shared key, and sends it to the first device. After receiving it, the first device decrypts it with its own private key to obtain the second quantum random number. In subsequent data transmission, the two parties encrypt and decrypt data using the second quantum random number, as follows:

[0044] The first device encrypts the data to be sent to the second device using the second quantum random number, and then sends the encrypted data to the second device. After receiving the data, the second device decrypts the data using the second quantum random number to obtain the data.

[0045] The second device encrypts the data to be sent to the first device using the second quantum random number, and sends the encrypted data to the first device. After receiving the data, the first device decrypts the data using the second quantum random number to obtain the data.

[0046] The device in the embodiment of the present application uses quantum true random numbers as the "seed" for generating passwords. The quantum random number generation technology enhances the network's anti-attack capability after multi-network integration. It has the characteristics of being unclonable, non-eavesdropperable, and unbreakable, providing long-term and stable protection for the train network.

[0047] In some embodiments of the present application, the first device distributes the shared key in the form of a logical address.

[0048] In some embodiments of the present application, the first device generates a first quantum random number in the form of injection, and distributes a shared key through a quantum key service platform.

[0049] Specifically, the first device can send the shared key to the second device via a public logical address port. Based on this, the second device also sends it to the first device via its own logical address. Preferably, in this embodiment, the shared key can also be generated and distributed through a quantum key service platform and a filling method.

[0050] In some embodiments of the present application, there is one first device and at least two second devices, and each second device generates its own second quantum random number, so that each second device uses its own second quantum random number to encrypt and decrypt data transmission with the first device. In some embodiments of the present application, data transmission between different second devices is forwarded by the first device.

[0051] In a specific implementation, the present application provides an embodiment, proposing a method for data transmission in the same virtual local area network:

[0052] In some embodiments of the present application, the first device and the second device belong to the same virtual local area network, the first device is a master device, and the second device is a terminal device. In this embodiment:

[0053] The master device generates a first quantum random number as a private key (which it retains) and uses this private key to generate a public key shared by the same VLAN. The public key is then appended with a VLAN identifier, which serves as the shared key for data exchange within the same VLAN. Specifically, for the same VLAN, the VLAN identifier is 00x0.

[0054] Each terminal device generates its own quantum random number (i.e., the second quantum random number) and encrypts it with the shared key of the virtual local area network. Each terminal device sends the encrypted second quantum random number to the master device via its own logical address.

[0055] For the same virtual local area network data, the master device uses its own private key to decrypt the encrypted second quantum random number of each terminal device, obtaining the second quantum random number of each terminal device. This second quantum random number is then used to encrypt and transmit data transmitted on all logical ports associated with this terminal device. After receiving the data transmitted by the master device, the terminal device uses its previous second quantum random number to decrypt the data.

[0056] If the terminal device has data to send to the master device, the second quantum random number is used to encrypt the data. Other devices in the same virtual local area network are forwarded by the virtual local area network master device.

[0057] After receiving the data, the master device uses the previous second quantum random number to decrypt the data. If it needs to be forwarded to other devices, it matches the second quantum random number of the target terminal device for encryption and decryption operations.

[0058] Based on this, for data exchange within the same virtual local area network (VLAN), each terminal device generates its own second quantum random number, which is encrypted using a shared key generated by the VLAN master device. The VLAN master device then retrieves the second quantum random number. The second quantum random number is then used to encrypt and decrypt transmitted data. This improves both the efficiency and security of device interaction within the VLAN.

[0059] In a specific implementation, the present application provides an embodiment, proposing a method for transmitting data across a virtual local area network:

[0060] In some embodiments of the present application, the first device and the second device belong to different virtual local area networks, and both the first device and the second device are master devices. In some embodiments of the present application, the device address of the first device is smaller than that of the second device. In this embodiment:

[0061] The master device with the smaller device address generates a first quantum random number as a private key for data exchange across the virtual local area network. Optionally, asymmetric encryption technology (including but not limited to RSA and elliptic curve algorithms) is used to generate a public key for use across the virtual local area network based on this private key.

[0062] The public key is added with a virtual LAN identifier and used as a shared key for data interaction across virtual LANs: for data interaction across two virtual LANs, the virtual LAN identifier is y0x0.

[0063] The master device with the smaller device address distributes the shared key (4-bit VLAN ID + 128-bit public key) with the VLAN ID to all terminal devices in the VLAN through the master device's public logical address port. The master device with the larger device address distributes the shared key it generates for its own VLAN through the public logical address of its VLAN.

[0064] For cross-virtual LAN data, the master device with a larger device address generates a quantum random number, encrypts it with the cross-virtual LAN shared key generated by the master device with a smaller device address, and sends it to the master device with a smaller device address. The two master devices encrypt and decrypt the cross-virtual LAN data for transmission.

[0065] Based on this, for cross-VLAN data interaction scenarios, two master devices use quantum random numbers to encrypt and decrypt cross-VLAN data, improving both the efficiency of cross-VLAN device interaction and the security of data interaction.

[0066] The embodiment of the present application integrates virtual LAN identification technology. Only when data is interacted across virtual LANs will the encryption and decryption mechanism between different virtual LAN master devices be triggered, ensuring both the real-time and security of data interaction. By assigning a unique identifier to each virtual LAN, the virtual LAN to which the data belongs can be accurately identified, thereby ensuring that the data always maintains its integrity and confidentiality during transmission. During the encryption process, advanced encryption algorithms are used to process the data, making it impossible for the data to be illegally intercepted or tampered with when transmitted across virtual LANs. In the decryption stage, only the master device of the target virtual LAN can decrypt with the correct key and identifier to obtain the original data.

[0067] See Figure 2 This application provides an example of data interaction between a train brake system control unit (Brake Electronic Control Unit, BECU) and a traction control unit (Emergency Driving Control Unit, EDCU) on the same virtual local area network:

[0068] The Central Control Unit (CCU) is the master device of this virtual local area network. All the above devices are in VLAN 10.

[0069] The master device (CCU) (i.e., the first device) generates a first quantum random number as a private key and uses this private key to calculate a public key shared by VLAN 10. The public key is then appended with the VLAN 10 identifier to generate a shared key for data exchange within the same VLAN. The master device (CCU) distributes this shared key (4-bit VLAN identifier + 128-bit public key) with the VLAN identifier to all end devices (i.e., the second device) in VLAN 10 via the master device's public logical address 0x468.

[0070] The brake control unit (BECU) and traction control unit (EDCU) each generate their own second quantum random number and encrypt it using the shared key of VLAN 10. The BECU and traction control unit (EDCU) then send the encrypted second quantum random number to the master device (CCU) via their respective logical addresses.

[0071] The master device CCU uses its own retained private key to decrypt the second quantum random number encrypted by the braking system control unit BECU and the traction control unit EDCU, and obtains the second quantum random number of the braking system control unit BECU and the traction control unit EDCU.

[0072] The second quantum random number generated by the braking system control unit BECU is used to encrypt and transmit the logical port transmission data related to the braking system equipment; the second quantum random number generated by the traction control unit EDCU is used to encrypt and transmit the logical port transmission data related to the traction system equipment.

[0073] After the braking system control unit BECU receives the data transmitted by the main device, it uses the previous second quantum random number to decrypt the data; after the traction control unit EDCU receives the data transmitted by the main device, it uses the previous second quantum random number to decrypt the data.

[0074] If the brake control unit (BECU) has data to send to the traction control unit (EDCU), the data is encrypted using the second quantum random number and sent to the master device. After receiving the data, the master device uses the second quantum random number from the brake control unit (BECU) to decrypt the data and uses the second quantum random number from the traction control unit (EDCU) to encrypt the data.

[0075] After the traction control unit EDCU receives the data transmitted by the main device, it uses its previous second quantum random number to decrypt the data.

[0076] Based on this, this embodiment uses a quantum random number generator to generate true random numbers, which are then used to generate session keys through encryption. In train network communications, the CCU is the master device, and other terminal devices establish independent and different session keys with the master device.

[0077] Please continue to see Figure 2 This application provides an example of data interaction between a train driver's cab human-machine interaction system (HMI) and a passenger information system (PIS) control host in a passenger compartment across a virtual local area network:

[0078] The central control unit CCU is the master device in VLAN 10, and the PIS control host in the driver's cab is the master device in VLAN 20. The central control unit CCU is the master device with the smallest device address among all the master devices.

[0079] The master device (CCU) with the smaller device address generates a first quantum random number as a private key for cross-VLAN data exchange. Based on this private key, it generates a public key for cross-VLAN use. The public key is appended with the cross-VLAN identifier 2010 and serves as a shared key for cross-VLAN data exchange.

[0080] The master device CCU sends the shared key (4-bit virtual LAN identifier + 128-bit public key) with VLAN10 identifier to all terminal devices in VLAN10 through the public logical address port 0x478 of the master device; the shared key with VLAN2010 identifier is sent to the master device driver's room PIS control host in VLAN20.

[0081] The driver's room PIS control host sends the independently generated VLAN20 shared key to the passenger room PIS host through the public logical address 0x488 port of its virtual LAN.

[0082] Each terminal device generates its own second quantum random number and encrypts the quantum random number with the shared key of its own virtual local area network: the HMI encrypts the second quantum random number it generates with the VLAN10 shared key; the guest room PIS host encrypts the second quantum random number it generates with the VLAN20 shared key.

[0083] Each terminal device sends the encrypted second quantum random number to the master device via its own logical address. The device uses its own private key to decrypt each terminal device's encrypted second quantum random number, obtaining the quantum random number for each terminal device. The CCU, the master device in VLAN 10, decrypts the second quantum random number obtained by the HMI; the PIS, the master device in the driver's cab, decrypts the second quantum random number obtained by the PIS in the passenger compartment. This second quantum random number is then used to encrypt and transmit data transmitted across all logical ports associated with this terminal device.

[0084] After the terminal device receives the data transmitted by the main device, it uses the previous second quantum random number to decrypt the data.

[0085] If a terminal device has data to send across virtual local area networks (VLANs), the master device of each VLAN uses the second quantum random number generated by the master device with the larger device address for encryption and decryption. The CCU, the master device with the smaller device address, obtains the second quantum random number from the PIS host in the driver's cab of the master device with the larger device address for encryption and decryption of data across VLANs.

[0086] It should be understood that, although the various steps in the flowchart are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps may be performed in other orders. Moreover, at least a portion of the steps in the figure may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but may be performed at different times. The execution order of these sub-steps or stages is not necessarily to be performed in sequence, but may be performed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0087] See Figure 3 One embodiment of the present application provides a train multi-network integrated data transmission system, which includes a shared key generation module 10, a second quantum random number generation module 20 and a data transmission module 30; wherein,

[0088] A shared key generation module 10 is configured to generate a first quantum random number as a private key on the first device, generate a public key based on the private key, add a virtual local area network identifier to the public key to generate a shared key, and send the shared key to the second device;

[0089] A second quantum random number generation module 20 is used for the second device to generate a second quantum random number, and to encrypt the second quantum random number with a shared key and send it to the first device;

[0090] The data transmission module 30 is used for encrypting and decrypting data transmission between the first device and the second device using the second quantum random number.

[0091] The specific limitations of the aforementioned train multi-network converged data transmission system can be found in the aforementioned limitations of the train multi-network converged data transmission method and will not be further elaborated here. Each module in the aforementioned train multi-network converged data transmission system can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the aforementioned modules can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a computer device memory in software form, allowing the processor to call and execute the corresponding operations of each of the aforementioned modules.

[0092] In one embodiment, a computer device is provided. The internal structure diagram of the computer device can be as follows: Figure 4As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the above-mentioned train multi-network fusion data transmission method is implemented. It includes: a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the above-mentioned train multi-network fusion data transmission method is implemented.

[0093] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned train multi-network fusion data transmission method can be implemented.

[0094] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code. The scheme in the embodiment of the present application can be implemented in various computer languages, for example, C language, VHDL language, Verilog language, object-oriented programming language Java, and directly interpreted scripting language JavaScript, etc.

[0095] The present application is described with reference to the flowcharts and / or block diagrams of the systems and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0096] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0097] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0098] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.

[0099] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A train multi-network integrated data transmission method, characterized in that: include: The first device generates a first quantum random number as a private key, generates a public key based on the private key, adds a virtual local area network identifier to the public key to generate a shared key, and sends the shared key to the second device; The second device generates a second quantum random number, encrypts the second quantum random number using the shared key, and sends the second quantum random number to the first device; The first device and the second device perform encryption and decryption of data transmission using the second quantum random number.

2. The train multi-network fusion data transmission method according to claim 1, characterized in that: The first device generates a first quantum random number as a private key, generates a public key based on the private key, adds a virtual local area network identifier to the public key to generate a shared key, and sends the shared key to the second device further comprising: The first device distributes the shared key in a logical address form.

3. The train multi-network fusion data transmission method according to claim 1, characterized in that: The first device generates a first quantum random number as a private key, generates a public key based on the private key, adds a virtual local area network identifier to the public key to generate a shared key, and sends the shared key to the second device further comprising: The first device generates the first quantum random number in a filling form, and distributes the shared key through the quantum key service platform.

4. The train multi-network fusion data transmission method according to claim 1, characterized in that: The step of the second device generating a second quantum random number, encrypting the second quantum random number using the shared key, and sending the second quantum random number to the first device further includes: There is one first device and at least two second devices, and each second device generates its own second quantum random number, so that each second device encrypts and decrypts data transmission with the first device through its own second quantum random number.

5. The train multi-network fusion data transmission method according to any one of claims 1 to 4, characterized in that: The step of encrypting and decrypting data transmission between the first device and the second device using the second quantum random number further includes: Data transmission between different second devices is forwarded through the first device.

6. The train multi-network fusion data transmission method according to claim 5, characterized in that: The first device and the second device belong to the same virtual local area network, the first device is a main device, and the second device is a terminal device.

7. The train multi-network integrated data transmission method according to any one of claims 1 to 3, characterized in that: The first device and the second device belong to different virtual local area networks, and both the first device and the second device are master devices.

8. The train multi-network integrated data transmission method according to claim 7, characterized in that: The device address of the first device is smaller than that of the second device.

9. A train multi-network integrated data transmission system, characterized in that: include: Shared key generation module, second quantum random number generation module and data transmission module; wherein, a shared key generation module, configured to generate a first quantum random number as a private key on the first device, generate a public key based on the private key, add a virtual local area network identifier to the public key to generate a shared key, and send the shared key to the second device; a second quantum random number generation module, configured for the second device to generate a second quantum random number, and to encrypt the second quantum random number using the shared key and send the second quantum random number to the first device; A data transmission module is used for encrypting and decrypting data transmission between the first device and the second device using the second quantum random number.

10. A computer device, characterized in that: include: Memory; processor; as well as computer programs; The computer program is stored in the memory and is configured to be executed by the processor to implement the train multi-network integration data transmission method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that A computer program is stored thereon; the computer program is executed by a processor to implement the train multi-network fusion data transmission method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Wireless Local Area Network (WLAN) access point equipment, system and related method

    CN102869012A

  • Method, device and system for data transmission

    CN102907040A

  • Method, device and equipment for realizing secure communication between equipment

    CN115694804A