A test system and method suitable for city regional railway CTCS key management

By constructing a test system suitable for CTCS key management in urban rail transit, the shortcomings of the existing test platform were addressed, and systematic and automated key management testing was achieved, ensuring the reliability and security of the system and reducing potential risks.

CN120639655BActive Publication Date: 2026-05-22SHANGHAI SHENTIE INVESTMENT CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANGHAI SHENTIE INVESTMENT CO LTD
Filing Date
2025-06-12
Publication Date
2026-05-22

Smart Images

  • Figure CN120639655B_ABST
    Figure CN120639655B_ABST
Patent Text Reader

Abstract

The application discloses a kind of test system and method suitable for city-region railway CTCS key management, the system includes: test control system and simulation test support system;Test control system is connected with real device;Test control system is composed of interface unit, test engine, simulation unit, password unit and operation terminal, with the test ability of virtual-real combination;Test control system is connected with real device interface through interface unit externally.Not only can the measured device be accessed into test system, but also other real devices can be accessed, to form a real device test environment, and the whole test process is controlled through the test system;Simulation test support system includes virtualization cloud platform and physical industrial computer, provides network environment and computing resource support for test control system.The application realizes the test verification work of city-region railway CTCS key management system device, and standardizes the test process, realizes the automatic test verification process, and provides a reliable test scheme.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of train operation control technology for high-speed railways and urban rail transit, and more specifically to a test system and method for CTCS key management in urban rail transit. Background Technology

[0002] The Chinese Train Control System (CTCS) is one of the core technologies ensuring railway transportation safety. The effective operation of the CTCS relies on reliable, secure, and efficient vehicle-to-ground data exchange. High-level CTCS systems achieve two-way information exchange through wireless networks, such as the CTCS-3 and CTCS-N systems which use GSM-R wireless networks, and potentially LTE or 5G wireless networks in the future. According to GB / T 24339.2 regarding security-related communication requirements in open transmission systems, systems based on open networks need to protect against damage and spoofing threats to ensure the authenticity and integrity of critical information exchanged between the vehicle and the ground. Ground and onboard signaling equipment employ encryption technology to guarantee the authenticity and integrity of messages exchanged between the two parties. Each time secure communication is established, both parties use an authentication key (KMAC) for authentication and generate a session key (KSMAC) based on the authentication key to symmetrically encrypt the vehicle-to-ground communication messages.

[0003] Currently, key management in China's CTCS system primarily relies on the Key Management Centre (KMC), which is responsible for generating and managing keys for all network security signaling equipment and distributing them offline. Offline key distribution is divided into two levels. Level 1 distribution involves sending the transmitted key and encrypted authentication key to the signaling vendors. This is done using offline removable media, and the authentication key is then decrypted using the vendors' respective key file generation tools. Level 2 distribution involves each vendor using its own dedicated key file generation tool to convert the authentication key into a key format file specific to their signaling equipment. The technology used in this level of transmission is equipment-specific. Most of the converted key format files are distributed in plaintext or a simple transformation of plaintext, with a few protected by the 3DES algorithm. The offline key distribution process carries the risk of key loss and leakage.

[0004] As a crucial component of urban agglomeration transportation, suburban railways require train control systems that balance the national railway CTCS standard with the specific needs of urban rail transit. To this end, the suburban railway CTCS key management system, based on the national railway standard, incorporates the key management concept of ETCS (European Train Control System) and combines it with commercial cryptographic algorithms to construct a system consisting of KMC (Knowledge Management Center), KMAC (Knowledge Management Controller) devices (such as TSRS, RBC, ATP / ATO), and Certificate Authority (CA) devices. The KMC manages the KMAC devices and KMAC according to the instructions of the key management personnel; the KMAC devices manage the KMAC according to the instructions of the KMC and perform train-to-ground communication; the CA devices manage the digital certificates of the KMC devices. The KMAC devices include a Temporary Speed ​​Restriction Server (TSRS), a Radio Block Centre (RBC), and Automatic Train Protection (ATP) / Automatic Train Operation (ATO) devices.

[0005] However, current research largely focuses on key generation and usage, lacking systematic support for testing and verifying key management functions. For example, key issues such as whether the key distribution process is compliant, whether the key storage capacity meets standards, and whether the system's resistance to attacks is sufficient all lack laboratory-level testing platforms and standardized testing methods.

[0006] Existing testing technologies have the following main problems:

[0007] 1. Offline testing relies on manual operation: The verification of the key management function requires manual configuration of the device and injection of the key, which is inefficient and prone to human error;

[0008] 2. Incomplete test coverage: The existing simulation platform focuses on verifying communication functions, ignoring the testing requirements for the entire lifecycle of key management (such as key destruction and status query);

[0009] 3. Insufficient security attack simulation: Lack of automated simulation capabilities for disguised attacks (such as man-in-the-middle attacks and DDoS attacks), making it difficult to assess the system's actual risk resistance.

[0010] 4. Lack of performance indicator verification: Key performance parameters such as key storage limit and device management scale lack quantitative testing methods.

[0011] The aforementioned issues prevented the CTCS key management system for urban railways from being fully verified for reliability and security before deployment, potentially leading to significant security risks such as key leakage and communication interruptions. Therefore, there is an urgent need for a verification platform and methodology that supports both virtual and physical testing and is automated, to comprehensively cover the testing requirements for key management functions, performance, and security. Summary of the Invention

[0012] In view of this, the present invention provides a testing system and method for CTCS key management in urban rail transit, aiming to fill the technical gap in the field of testing and verification of CTCS key management system in urban rail transit, and to provide technical support for the efficient deployment and secure operation of the system.

[0013] To achieve the above objectives, the present invention adopts the following technical solution:

[0014] In a first aspect, the present invention provides a testing system for CTCS key management in urban rail transit, comprising: a test control system and a simulation test support system; the test control system is connected to real equipment; the real equipment includes a key management center, a certificate authorization device, a temporary speed limit server, a wireless block center, and automatic train protection equipment and automatic train operation equipment;

[0015] The test control system includes:

[0016] The interface unit is configured to establish communication connections between the simulation unit and the real device through multiple interfaces, and to provide interface data to the test engine.

[0017] The test engine connects to the interface unit and calls the cryptographic unit; it is used to execute the test logic control, network data monitoring, and key synchronization operations of the entire test system.

[0018] The simulation unit communicates with the real device through the interface unit to generate a virtual KMAC device and perform protocol-consistent interaction with the real device module, supporting fault injection.

[0019] The cryptographic unit is called by the test engine and simulation unit to implement key generation, secure storage encryption / decryption functions, and secure communication encryption / decryption functions.

[0020] The operating terminal provides a human-computer interaction interface and supports test sequence management, log recording, and test result display.

[0021] The simulation test support system includes a virtualization cloud platform and a physical industrial control computer, providing network environment and computing resource support for the test control system.

[0022] Furthermore, the interface unit includes:

[0023] Ethernet interface module, used to connect real devices and virtual ground devices, and to provide a monitoring interface between the test engine and the Ethernet environment;

[0024] The wireless network interface module is used for the wireless network interface between the internal network environment and the external network environment, including the GSM-R network interface between the real ATP / ATO and the virtual ground equipment in the simulation unit, the GSM-R network interface between the virtual ATP / ATO and the real ground equipment, and the monitoring interface of the test engine for the GSM-R network environment.

[0025] The offline interface module is configured to perform key injection operations via USB storage media.

[0026] Furthermore, the testing engine includes:

[0027] The test control module is used to enable the test engine to control the test process. It issues instructions to the corresponding devices according to the progress of the test sequence, drives the test to proceed, determines the data that needs to be monitored, and judges whether the test is completed.

[0028] The data capture module is used to monitor and capture data required for testing in the network environment and analyze it, providing analysis results of the test data, or capturing, intercepting, and tampering with the data to achieve fault injection;

[0029] The cryptographic unit calling module is used to call the functional interface of the cryptographic unit to implement the encryption and decryption functions of the ciphertext;

[0030] The key synchronization module is used to synchronize and store the keys distributed by the key management system to each device, and to decrypt them after capturing ciphertext data.

[0031] Furthermore, the cryptographic unit includes:

[0032] The key generation module is used to generate the keys required for secure communication.

[0033] The secure storage encryption / decryption module is used to perform encrypted storage and decryption reading operations on key data in the storage medium.

[0034] The secure communication encryption / decryption module is used for encrypting and decrypting ciphertext during vehicle-to-ground communication.

[0035] Furthermore, the operating terminal includes:

[0036] The human-computer interface module is used to provide a way for testers to interact with the test platform, and to provide interfaces for testers' operations and the display of various data.

[0037] The test equipment management module is used to manage the test equipment connected to the test platform, including various real and simulated devices, and to add and delete real and simulated devices.

[0038] The test sequence query module is used to store and display test sequences that conform to the test cases of the urban railway CTCS key management system, so that testers can select the required test sequences and execute them.

[0039] The logging module is used to record operations performed on the testing platform, including operation time, operation content, and operation results.

[0040] Secondly, the present invention also provides a testing method for CTCS key management in urban rail transit, using a testing system for CTCS key management in urban rail transit as described in any one of the first aspects, comprising:

[0041] S1. Connect the real KMC device, real CA device and KMAC device to the test control system via Ethernet and wireless network, and jointly establish a test environment based on the simulation test support system;

[0042] S2. Select a test sequence, including a system function test sequence, a performance test sequence, or an interface test sequence; or perform a spoofing attack test on KMC;

[0043] S3. Based on the test engine, execute automated test processes for the selected test sequences;

[0044] S4. Based on the testing requirements, inject fault test vectors; monitor and capture data packets and key changes during the testing process, and generate test data;

[0045] S5. Analyze the test data and generate a comprehensive test report that includes key synchronization status, response time, and attack defense capabilities.

[0046] Furthermore, in step S3, the system function test includes:

[0047] The key lifecycle management verification steps sequentially perform closed-loop tests on key generation, storage, distribution, use, and destruction; including fault injection operations; the fault injection operations include: tampering with data packet content, intercepting data packets, or modifying the key validity period;

[0048] The permission management verification process involves testing the operation permission management isolation function through multi-level user accounts.

[0049] The log audit verification process checks the completeness of operation logs and the compliance of their storage cycle.

[0050] Furthermore, in step S3, the system performance test includes: the upper limit of key storage, the upper limit of the number of devices managed, and the response time of the automated test key management system device.

[0051] Furthermore, in step S3, the system interface testing includes:

[0052] Verify the communication interface data between devices in the key management system;

[0053] In the system interface test sequence, the test engine captures the corresponding data packets in the network and compares them with the data format specified in the technical conditions or specifications.

[0054] Furthermore, in step S3, the anti-counterfeiting attack test includes:

[0055] Generating fake devices and unauthorized access: The simulation unit generates a virtual KMAC device carrying an illegal certificate and initiates a connection request to the KMC under test;

[0056] Man-in-the-middle attack simulation: The fake device establishes a communication link with both the KMC and the real KMAC device simultaneously, tampering with or stealing the interaction data;

[0057] DDoS attack simulation: Multiple fake devices are generated through a virtualized cloud platform to send high-frequency connection requests to KMC to test the system's stress resistance;

[0058] Attack result determination: Check whether illegal connections are blocked through the KMC maintenance interface, and analyze the completeness of the attack events recorded in the logs.

[0059] As can be seen from the above technical solution, compared with the prior art, the present invention has the following technical advantages:

[0060] This invention enables the testing and verification of CTCS key management system equipment for urban railways, standardizes the testing process, and automates the testing and verification process, providing a reliable testing solution for the CTCS key management system for urban railways. Attached Figure Description

[0061] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0062] Figure 1 This is a schematic diagram of the overall architecture of the CTCS key management system for urban rail transit.

[0063] Figure 2This is a test system architecture diagram for CTCS key management in urban rail transit provided by the present invention.

[0064] Figure 3 The present invention provides a test system module interaction diagram for CTCS key management in urban rail transit.

[0065] Figure 4 The system function testing flowchart provided by this invention.

[0066] Figure 5 The system performance testing flowchart provided by this invention.

[0067] Figure 6 The system interface testing flowchart provided for this invention.

[0068] Figure 7 The flowchart for anti-spoofing attack testing provided by this invention. Detailed Implementation

[0069] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0070] First, the technical terms involved in this invention are explained as follows:

[0071] CTCS (Chinese Train Control System): China's train operation control system;

[0072] KMS (Key Management System): Key Management System;

[0073] KMAC (Key Management Authentication Center): The key management authentication center is responsible for key generation, distribution, and identity authentication.

[0074] KSMAC (Session Key for Message Authentication Code): A session key used for integrity verification and encryption of vehicle-to-ground communication messages;

[0075] KMC (Key Management Centre): The key management center is responsible for the entire lifecycle management of keys;

[0076] CA (Certificate Authority): A certificate authorization device responsible for issuing and managing digital certificates;

[0077] TSRS (Temporary Speed ​​Restriction Server): A temporary speed limiting server.

[0078] RBC (Radio Block Centre): Radio Block Centre;

[0079] ATP (Automatic Train Protection): Train overspeed protection equipment;

[0080] ATO (Automatic Train Operation): Automatic train operation equipment;

[0081] DDoS (Distributed Denial of Service): A distributed denial-of-service attack.

[0082] like Figure 1 As shown, the CTCS key management system for urban rail transit uses KMC to centrally manage the keys of urban rail transit train control equipment (KMAC equipment), including key generation, online / offline distribution, addition, deletion, modification and query functions; it uses CA to manage the network access credentials of KMS equipment (including KMC and KMAC equipment), including digital certificate generation, distribution and verification functions; KMAC equipment establishes a secure connection with the corresponding equipment based on the key distributed by KMC to realize secure data interaction of the train control system.

[0083] The CTCS key management system for urban railways contains numerous new technologies and equipment related to key management functions, necessitating testing and verification of the overall functionality of the key management system. As a full lifecycle management system encompassing key generation, storage, distribution, verification, use, querying, backup, recovery, deletion, destruction, and archiving, the key management system plays a crucial role in the key function modules. Related equipment must undergo thorough testing and verification to prove its ability to meet functional requirements and performance indicators before being put into application.

[0084] Therefore, embodiments of the present invention provide a test system suitable for CTCS key management in urban rail transit, referring to... Figure 2 As shown, it includes: a test control system and a simulation test support system. The test control system is connected to the real equipment. The real equipment includes a Key Management Center (KMC), a Certificate Authority (CA), a Temporary Speed ​​Limiting Server (TSRS), a Radio Block Center (RBC), and an onboard KMAC device (real ATP / ATO).

[0085] The test control system consists of an interface unit, a test engine, a simulation unit, a cryptographic unit, and an operation terminal, possessing the capability for both virtual and physical testing. The functions of each component are as follows:

[0086] The interface unit includes an Ethernet interface module, a wireless network interface module, and an offline interface module. The Ethernet interface module provides the Ethernet interface between the platform's internal and external network environments, including the Ethernet interface between the real ground devices (KMC, CA, TSRS, and RBC) and the virtual ground devices (TSRS and RBC) in the simulation unit, as well as the test engine's monitoring interface for the Ethernet environment. The wireless network interface module provides the wireless network interface between the platform's internal and external network environments, including the GSM-R network interface between the real ATP / ATO and the virtual ground devices in the simulation unit, and between the virtual ATP / ATO and the real ground devices, as well as the test engine's monitoring interface for the GSM-R network environment. The offline interface is a USB interface, providing access via key or digital certificate storage media and manual injection. The interface unit is responsible for the entire platform's interface functions, enabling information exchange with external devices, connecting external real devices with the platform's internal simulation devices, and fulfilling the interface requirements of the test environment. Simultaneously, the interface unit is also responsible for providing interface data to the test engine for test control and execution.

[0087] The test engine is the core unit of the test control system's test logic, responsible for implementing the core test logic of the entire test system and controlling the test execution process. The test engine includes: a test control module, a data capture module, a cryptographic unit invocation module, and a key synchronization module. The test control module controls the test process, issuing commands to relevant devices according to the progress of the test sequence, driving the test forward, determining the data to be monitored, and judging whether the test is complete. The data capture module monitors and captures the data required for testing in the network environment and analyzes it, providing analysis results, or capturing, intercepting, and tampering with data to achieve fault injection. The cryptographic unit invocation module calls the functional interfaces of the cryptographic units to achieve functions such as encryption and decryption of ciphertext. The key synchronization module synchronizes and stores the keys distributed to each device by the key management system, and uses them for decryption after capturing ciphertext data. The test engine performs the corresponding tests according to commands from the operation terminal and returns the test process and results to the operation terminal. The test engine connects to the interface unit and calls the cryptographic unit, possessing functions such as random number generation, key generation, encryption, decryption, signing, signature verification, data capture, random number analysis, and key synchronization.

[0088] The simulation unit is responsible for the operation of virtual train control equipment (TSRS, RBC) and virtual onboard equipment (ATP / ATO). It simulates the KMAC device's access to the system under test, implementing the virtual device portion of the simulation platform's test environment. It also features fault injection capabilities to simulate device malfunctions, such as incorrect storage keys. According to testing requirements, virtual devices do not need to interface with each other; they only interface with external real devices. The communication protocol is the same as that between real devices, complying with relevant technical conditions and specifications for urban rail transit. By adding virtual KMAC devices to the simulation unit, system stress testing, performance testing, and spoofing testing of the key management system can be achieved. The simulation unit also needs to call the cryptographic unit to perform data encryption and decryption.

[0089] The cryptographic unit employs commercially certified hardware cryptographic modules or devices, including a key generation module, a secure storage encryption / decryption module, and a secure communication encryption / decryption module. The key generation module generates the keys required for secure communication; the secure storage encryption / decryption module stores ciphertext data or keys, requiring encryption protection, thus necessitating encryption and decryption operations via the cryptographic unit during storage and retrieval; the secure communication encryption / decryption module handles the encryption and decryption of ciphertext during communication. The cryptographic unit is invoked by the test engine and simulation unit to implement key generation, secure storage encryption / decryption, and secure communication encryption / decryption functions, serving as the core unit for the test system's key processing capabilities.

[0090] The operating terminal includes a human-machine interface (HMI) module, a test equipment management module, a test sequence query module, and a log recording module. The HMI module provides an interface for testers to interact with the test system, facilitating operations and data display. The test equipment management module manages the test equipment connected to the system, including various real and simulated devices, allowing for the addition and deletion of such devices. The test sequence query module stores and displays test sequences conforming to the CTCS key management system for urban railways, allowing testers to select and execute desired sequences. The log recording module records operations performed on the test system, including operation time, content, and results, such as device addition / deletion time, added / deleted test equipment, results of device addition / deletion, test sequence query time, test sequence execution time, and test sequence execution results. The operating terminal provides human-machine interaction, featuring an HMI interface, and is responsible for test equipment management, test sequence query, test process and result display, and test log recording. It serves as the entry point for testers to operate the test system. Testers can control the key management system testing process through the terminal, observe the testing process and results in real time, and query historical test results.

[0091] The test system control system interfaces with real devices (TSRS, RBC, ATP / ATO, KMC, CA) through interface units. It can connect not only the device under test (DUT) to the test system, but also other real devices, creating a realistic device testing environment and controlling the entire testing process through the test system.

[0092] The simulation test support system provides underlying support for the platform's operation and testing. It provides the software runtime environment through a virtualized cloud platform and physical industrial control computers, and the network environment required for testing through a local area network (LAN), switches, and GSM-R networks. The virtualized cloud platform provides a stable, reliable, and hot-standby virtual machine runtime environment through multiple servers. Simulation devices and various software can run on virtual machines and communicate with external networks through the virtual LAN within the servers and the interface units of the test system. The physical industrial control computers provide a usable environment for software that must be deployed on real machines (such as maintenance terminals and human-machine interfaces). The LAN, switches, and GSM-R networks together provide the wired and wireless network environments required by the real devices and the test system.

[0093] The CTCS key management testing system for urban rail transit provided by this invention consists of a test control system and a simulation test support system. The test engine controls the core logic of the testing process, ensuring its secure, efficient, and automated execution. This testing system has the function of testing and verifying key management devices, including but not limited to device management functions, digital certificate management functions, key management functions (including key generation, storage, query and verification, destruction, deletion, use, distribution, archiving, and key status management), access control functions, log recording, and auditing functions. The testing system has the function of testing the system interfaces, performance indicators, security, and certificate management systems of the devices. It also has a device spoofing function, capable of simulating active attack tests on the key management system.

[0094] The interaction flow of each module in the test system is as follows: Figure 3 As shown. In the information exchange during the testing process, the interface unit is responsible for completing the information exchange between the platform and the real device / simulation unit, which is responsible for assembling the testing equipment and simulation environment, and the cryptographic unit is responsible for the calculation of cryptographic-related functions. The information flow between the modules within these parts and the functions related to the testing system is relatively simple, so they are described as a whole. The interaction flow of each module in a complete testing process is as follows:

[0095] (1) Testers can add all the devices that need to be connected for testing in the test equipment management module through the human-machine interface.

[0096] (2) Testers can use the human-machine interface to search for and select the required test sequence in the test sequence query interface to execute.

[0097] (3) The operation terminal sends the test sequence to be executed to the test engine.

[0098] (4) The test control module informs the data capture module of the data packets to be captured based on the monitoring targets set in the test sequence to be executed.

[0099] (5) The test control module sends a fault injection command to the target simulation device and an operation command to the target device according to the requirements of the test sequence to be executed.

[0100] (6) Business data is exchanged between each real device and the simulation device. During this process, the simulation unit calls the cryptographic unit to realize secure communication encryption / decryption between each simulation device.

[0101] (7) The data capture module continuously monitors the data packets in the interface unit, captures the required data packets for parsing, and calls the cryptographic unit through the cryptographic unit to call the cryptographic unit's secure communication encryption / decryption and other cryptographic-related functions.

[0102] (8) If the data interaction between devices involves a change in the key, the data capture module will send the relevant data to the key synchronization module. The key synchronization module enables the test engine to synchronously modify and store the changed key.

[0103] (9) The data capture module returns the analysis results of the data packets that need to be monitored during the test to the test control module.

[0104] (10) The test control module returns the test results to the operation terminal based on the data monitoring results returned by the data capture module, and the log recording module records them.

[0105] (11) Testers can query the test results of the selected test sequence through the human-computer interface.

[0106] The test system for CTCS key management in urban railways provided by this invention can be used for laboratory environment verification testing of the system. It helps to verify the functionality of the key management system equipment, ensures that the equipment can meet the functional requirements of technical conditions and specifications, and can reduce potential risks before the equipment is put into use to a certain extent, thereby achieving better economic and social benefits.

[0107] Based on the same inventive concept, this invention also provides a testing method suitable for CTCS key management in urban rail transit, using the testing system for CTCS key management in urban rail transit as described in the above embodiments. The method includes:

[0108] S1. Connect the real KMC device, real CA device and KMAC device to the test control system via Ethernet and wireless network, and jointly establish a test environment based on the simulation test support system;

[0109] S2. Select a test sequence, including a system function test sequence, a performance test sequence, or an interface test sequence; or perform a spoofing attack test on KMC;

[0110] S3. Based on the test engine, execute automated test processes for the selected test sequences;

[0111] S4. Based on the testing requirements, inject fault test vectors; monitor and capture data packets and key changes during the testing process, and generate test data;

[0112] S5. Analyze the test data and generate a comprehensive test report that includes key synchronization status, response time, and attack defense capabilities.

[0113] In this embodiment, the testing method involves testers selecting appropriate test sequences. The specific testing procedures vary depending on the test items. The device under test (DUT) can be tested in three aspects: system functionality, system performance, and system interfaces. Employing a combination of virtual and real testing methods, it provides testers with comprehensive automated testing covering all system requirements, standardizing the testing process and simplifying operations. Furthermore, it can perform spoofing attack testing, providing testers with a way to verify the DUT's anti-spoofing attack capabilities. Based on the testing system described in the above embodiment, this method is simple to implement, does not require a large number of real devices, and saves resources needed for the testing environment.

[0114] 1. System functional testing includes:

[0115] The key lifecycle management verification steps sequentially perform closed-loop tests on key generation, storage, distribution, use, and destruction; including fault injection operations; the fault injection operations include: tampering with data packet content, intercepting data packets, or modifying the key validity period;

[0116] The permission management verification process involves testing the operation permission management isolation function through multi-level user accounts.

[0117] The log audit verification process checks the completeness of operation logs and the compliance of their storage cycle.

[0118] Specific system function testing procedures, such as Figure 4As shown, the system functions include basic key management functions, key generation, key storage, key query and verification, key destruction, key usage, key distribution, key deletion, key archiving, key status management, as well as user permission management, log recording, and auditing functions. Testing these functions requires direct user operation. Users need to issue corresponding commands through the KMC device's maintenance interface and observe the response of each device in the key management system after issuing commands, or view various data through the maintenance interface. After the user selects a system function test sequence and issues an execution command, the test system opens the relevant device maintenance interface for the test sequence and prompts the user with the test content and required operations. Simultaneously, the test system monitors the interface data status and captures corresponding data packets on the network. If the test sequence requires fault injection (e.g., tampering with KMAC key information, key identifiers, validity period format, etc.), the captured data packets are modified accordingly and sent to the original target device.

[0119] Fault injection operations mainly include three categories:

[0120] (1) Tampering with the contents of data packets, such as tampering with the key information in KMAC, such as the key owner's KMC device ID, key serial number, device IDs of both communicating parties, key validity period, key content, key length, etc.

[0121] (2) Intercept data packets to prevent the operation commands of the device under test from being sent normally, or to prevent the device under test from receiving the acknowledgments of the operation commands;

[0122] (3) Send a fault injection command to the simulation device to cause a certain function of the simulation device to fail or malfunction, such as instructing the simulation device to modify the validity period of the key it uses. Finally, the user checks the response of each device to confirm the final test results.

[0123] 2. System performance testing includes: the maximum key storage capacity, maximum number of devices managed, and response time of the automated test key management system devices.

[0124] System performance testing process as follows Figure 5As shown. System performance testing primarily tests the response time, storage capacity, and interface device capacity of the key management system devices (including KMC, CA, and KMAC devices). After the user selects a system performance test sequence and issues an execution command, the test system automatically executes operations according to the test sequence requirements to test system performance. Taking the KMC storage key quantity limit test as an example, the test system automatically issues key generation operation commands to the KMC device until the required number is reached. Then, the operation terminal opens the KMC device remote maintenance interface for the user, who checks the number of stored keys and confirms the test results. Taking the KMC management device quantity limit test as another example, the test system's simulation unit automatically generates simulated TSRS, simulated RBC, and simulated ATP / ATO, and adds KMAC devices to the KMC device until the required number is reached. Then, the operation terminal opens the KMC device remote maintenance interface for the user, who confirms the number of KMAC devices managed by the KMC device. This process is automatically executed by the test system, eliminating the need for manual operation by testers, thus saving testers' time in situations requiring a large number of operations. The specific performance parameters of each device in the CTCS key management system for urban railways are shown in Table 1.

[0125] Table 1. Specific parameters of the CTCS key management system equipment performance indicators for urban railways.

[0126] Performance indicators Specific parameters Number of keys stored in the key management system >100,000 Number of digital certificates stored in the key management system >100,000 Number of KMAC devices that the key management system can manage >1000 Key management system certificate concurrency >100 Log storage time saved by the key management system >180 days Maximum number of keys stored in an in-vehicle KMAC device >200 Maximum number of keys stored in a ground-based KMAC device >1000 KMAC device log storage time >90 days

[0127] 3. System interface testing includes:

[0128] Verify the communication interface data between devices in the key management system;

[0129] In the system interface test sequence, the test engine captures the corresponding data packets in the network and compares them with the data format specified in the technical conditions or specifications.

[0130] The system interface testing process is as follows: Figure 6 As shown, the system interface test mainly checks the communication interface data between various devices in the key management system. In the system interface test sequence, the operating platform automatically performs operations such as key generation, and the test engine captures the corresponding data packets in the network, compares them with the data format specified in the technical conditions or specifications, and returns the comparison results to the operating terminal for display. Finally, the operating terminal directly displays to the user whether the captured data packet format is compliant and automatically displays the test results.

[0131] 4. Anti-counterfeiting attack testing includes:

[0132] Generating fake devices and unauthorized access: The simulation unit generates a virtual KMAC device carrying an illegal certificate and initiates a connection request to the KMC under test;

[0133] Man-in-the-middle attack simulation: The fake device establishes a communication link with both the KMC and the real KMAC device simultaneously, tampering with or stealing the interaction data;

[0134] DDoS attack simulation: Multiple fake devices are generated through a virtualized cloud platform to send high-frequency connection requests to KMC to test the system's stress resistance;

[0135] Attack result determination: Check whether illegal connections are blocked through the KMC maintenance interface, and analyze the completeness of the attack events recorded in the logs.

[0136] As the core device of the CTCS key management system for urban rail transit, the KMC is responsible for the entire lifecycle management of the KMAC and needs to possess a certain level of anti-spoofing attack capability. The testing system provides corresponding testing methods to test the anti-spoofing attack capability of the KMC device. One test sequence flow is as follows: Figure 7 As shown. The real KMC device under test is connected to the test system network via Ethernet and connects to the virtual device generated in the simulation unit. After the user executes the anti-masking attack test sequence, the simulation unit will start generating fake KMAC devices to attempt to connect to the KMC device. The fake KMAC devices use self-signed certificates, expired or revoked certificates, etc., to attempt to impersonate legitimate devices and communicate with the KMC device, or use forged certificates to communicate with the tested KMC device and other real KMAC devices simultaneously, realizing a man-in-the-middle attack. The test engine monitors the data packets in the network in real time, and judges the anti-masking capability of the tested device based on whether the KMC responds to the fake devices and the results of the data packet parsing, such as whether communication is established and whether business data interaction has occurred. In addition, the simulation unit generates a large number of fake devices to initiate high-frequency and large-volume connection requests to the tested device, simulating a DDoS attack on the real tested device. The test system has dedicated virtual machines on a virtualization cloud platform or uses dedicated physical industrial control computers to provide a running environment for the large number of fake devices generated in this sequence. The virtual machines and industrial control computers used have undergone load testing, and their configurations are capable of handling the required number of spoofed devices for a sufficient testing duration. Through the KMC device's maintenance interface, the device's operating status and key management functions can be verified, providing test results on the tested device's anti-attack capabilities and comprehensively evaluating its anti-spoofing attack capabilities.

[0137] The testing method for CTCS key management in urban railways provided by this invention can standardize the equipment testing process, reduce the workload of testers, improve testing efficiency, and reduce testing errors caused by human factors.

[0138] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.

[0139] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A test system suitable for CTCS key management in urban rail transit, characterized in that, include: Test control system and simulation test support system; The test control system is connected to the actual equipment; The actual equipment includes a Key Management Center (KMC), a Certificate Authority (CA), a Temporary Speed ​​Limiting Server (TSRS), a Radio Block Center (RBC), and an onboard KMAC device. The onboard KMAC device includes an Automatic Train Protection (ATP) device and an Automatic Train Operation (ATO) device. The test control system includes: The interface unit is configured to establish communication connections between the simulation unit and the real device through multiple interfaces, and to provide interface data to the test engine. The interface unit includes: an Ethernet interface module for connecting the real device and the virtual ground device, and providing a monitoring interface between the test engine and the Ethernet environment; a wireless network interface module for wireless network interfaces between the internal and external network environments, including a GSM-R network interface between the real ATP / ATO and the virtual ground device in the simulation unit, a GSM-R network interface between the virtual ATP / ATO and the real device, and a monitoring interface between the test engine and the GSM-R network environment; and an offline interface module configured to perform key injection operations via a USB storage medium. The test engine connects to the interface unit and calls the cryptographic unit; it is used to execute the test logic control, network data monitoring, and key synchronization operations of the entire test system. The simulation unit communicates with the real device through the interface unit to generate a virtual KMAC device and perform protocol-consistent interaction with the real device, supporting fault injection. The cryptographic unit, invoked by the test engine and simulation unit, implements key generation, secure storage encryption, secure storage decryption, secure communication encryption, and secure communication decryption functions. The cryptographic unit includes: a key generation module for generating keys required for secure communication; a secure storage encryption and decryption module for performing encryption storage and decryption reading operations on key data in the storage medium; and a secure communication encryption and decryption module for encrypting and decrypting ciphertext during vehicle-to-ground communication. The operating terminal provides a human-computer interaction interface and supports test sequence management, log recording, and test result display. The simulation test support system includes a virtualized cloud platform and a physical industrial control computer, which provide network environment and computing resource support for the test control system. The test system, when executing the test method, includes a fault injection operation, which includes tampering with data packet content, intercepting data packets, or modifying the key validity period.

2. The test system for CTCS key management in urban rail transit according to claim 1, characterized in that, The testing engine includes: The test control module is used to control the test process by the test engine. It issues instructions to the corresponding devices according to the progress of the test sequence, drives the test to proceed, determines the test data that needs to be monitored, and judges whether the test is completed. The data capture module is used to monitor and capture the test data in the network environment and analyze it, provide the analysis results of the test data, or capture, intercept and tamper with the test data to achieve fault injection; The cryptographic unit calling module is used to call the functional interface of the cryptographic unit to implement the encryption and decryption functions of the ciphertext; The key synchronization module is used to synchronize and store the keys distributed by the key management system to each device, and to decrypt them after capturing ciphertext data.

3. A test system for CTCS key management in urban rail transit according to claim 1, characterized in that, The operating terminal includes: The human-machine interface module is used to provide a way for testers to interact with the test control system, and to provide an interface for testers' operations and various data transmissions; The test equipment management module is used to manage the test equipment connected to the test control system, including various real and virtual devices, and to add and delete real and virtual devices. The test sequence query module is used to store and display test sequences that conform to the test cases of the urban railway CTCS key management system, so that testers can select the required test sequences and execute them. The log recording module is used to record operations on the test and control system, including operation time, operation content, and operation results.

4. A testing method suitable for CTCS key management in urban rail transit, characterized in that, The test system for CTCS key management of urban rail transit as described in any one of claims 1-3 includes: S1. Connect the real KMC device, real CA device, and virtual KMAC device to the test control system via Ethernet and wireless network, and jointly establish a test environment based on the simulation test support system; S2. Select a test sequence, including system function test sequence, performance test sequence, interface test sequence, or anti-spoofing attack test sequence; S3. Based on the test engine, execute automated test processes for the selected test sequences; S4. Based on the testing requirements, inject fault test vectors; monitor and capture data packets and key changes during the testing process, and generate test data; S5. Analyze the test data and generate a comprehensive test report that includes key synchronization status, response time, and attack defense capabilities.

5. A testing method for CTCS key management in urban rail transit according to claim 4, characterized in that, In step S3, the system function test includes: The key lifecycle management verification steps sequentially perform closed-loop tests on key generation, storage, distribution, use, and destruction; including fault injection operations; the fault injection operations include: tampering with data packet content, intercepting data packets, or modifying the key validity period; The permission management verification process involves testing the operation permission management isolation function through multi-level user accounts. The log audit verification process checks the completeness of operation logs and the compliance of their storage cycle.

6. A testing method for CTCS key management in urban rail transit according to claim 4, characterized in that, In step S3, the system performance test includes: the upper limit of key storage, the upper limit of the number of devices managed, and the response time of the automated test key management system device.

7. A testing method for CTCS key management in urban rail transit according to claim 4, characterized in that, In step S3, the system interface testing includes: Check and verify the communication interface data between devices in the key management system; In the system interface test sequence, the test engine captures the corresponding data packets in the network and compares them with the data format specified in the technical conditions or specifications.

8. A testing method for CTCS key management in urban rail transit according to claim 4, characterized in that, In step S2, the testing process for the anti-spoofing attack test sequence includes the following steps: Generating fake devices and unauthorized access: The simulation unit generates a virtual KMAC device carrying an illegal certificate and initiates a connection request to the real KMC device; Man-in-the-middle attack simulation: The fake device establishes communication links with both the real KMC and real KMAC devices simultaneously, tampering with or stealing the interactive data; DDoS attack simulation: Multiple fake devices are generated through a virtualized cloud platform to send high-frequency connection requests to real KMC devices to test the system's stress resistance. Attack result determination: Check whether illegal connections are blocked through the KMC maintenance interface, and analyze the completeness of the attack events recorded in the logs.