Vehicle-ground safety transmission equipment and method

By integrating wireless modules and ARM into vehicle-to-ground security transmission equipment and using ARM to determine data filtering rules, the problem of increased cost of firewall equipment in the existing technology is solved, and secure data transmission and cost reduction are achieved.

CN120640291APending Publication Date: 2025-09-12CRRC TANGSHAN CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510947236.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-09
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

In existing train systems, firewall equipment needs to be purchased separately, which increases the installation cost.

Method used

By integrating wireless modules, reduced instruction set microprocessors ARM and backplane network modules into vehicle-to-ground secure transmission equipment, and using ARM to determine whether external and internal data conform to data filtering rules, secure data transmission is achieved, avoiding the need for additional firewall equipment.

Benefits of technology

It realizes the secure transmission of data between the train system and ground equipment, reduces the construction cost of the train system, and saves installation space.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120640291A_ABST
    Figure CN120640291A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides train-ground safety transmission equipment and method, and relates to the field of train network Ethernet firewalls and the like. The vehicle-ground safety transmission device comprises a wireless module, a reduced instruction set microprocessor ARM and a backboard network module. The wireless module is used for receiving external data sent by ground equipment and sending the external data to the ARM; the ARM is used for receiving external data; judging whether the external data conforms to a data filtering rule or not; and when the external data accords with the data filtering rule, sending the external data to the backboard network module. The wireless module is used for receiving the external data sent by the ground equipment, the ARM is used for judging the data filtering rule of the external data, and the external data is sent to the backboard network module when the external data meets the data filtering rule, so that the safety protection that the ground equipment sends the external data to the train system is realized; and additional firewall equipment is avoided, and the construction cost of a train system is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to fields such as train network Ethernet firewalls, and in particular to a vehicle-to-ground secure transmission device and method. Background Art

[0002] As trains become increasingly digitalized, the amount of external data sent by ground equipment to train systems becomes increasingly large, and the issue of security protection of external data becomes more prominent.

[0003] In related technologies, the train system includes vehicle-to-ground transmission equipment and firewall equipment. The firewall equipment receives external data sent by the ground equipment and determines whether the external data is safe. When the firewall equipment determines that the external data is safe, it sends the external data to the vehicle-to-ground transmission equipment to prevent the train system from being attacked by unsafe external data.

[0004] In the above-mentioned related technologies, it is usually necessary to purchase firewall equipment separately, which increases the cost of building the train system. Summary of the Invention

[0005] The embodiments of the present application provide train-to-ground safety transmission equipment and methods, which avoid the need to purchase firewall equipment separately, thereby reducing the cost of the train system.

[0006] In a first aspect, an embodiment of the present application provides a vehicle-to-ground safety transmission device, characterized in that it is applied to a train system, and the vehicle-to-ground safety transmission device includes: a wireless module, a reduced instruction set microprocessor ARM, and a backplane network module;

[0007] The wireless module is connected to the ARM; the ARM is connected to the backplane network module;

[0008] The wireless module is used to receive external data sent by ground equipment and send the external data to the ARM;

[0009] The ARM is used to receive the external data; determine whether the external data meets the data filtering rules; when the external data meets the data filtering rules, send the external data to the backplane network module; when the external data does not meet the data filtering rules, discard the external data.

[0010] In some embodiments, determining whether the external data complies with data filtering rules includes:

[0011] Passing the external data to a network protocol stack of a kernel in the ARM through a network interface driver running in the ARM, wherein the network protocol stack includes the data filtering rule;

[0012] Determine whether the external data complies with the data filtering rule through the network protocol stack.

[0013] In some embodiments, the ARM is further configured to:

[0014] When the external data does not comply with the data filtering rule, recording discard information of the external data;

[0015] The discard information of the external data includes at least one or more of the following:

[0016] The type of the external data;

[0017] The source Internet Protocol (IP) address of the external data;

[0018] The destination IP address of the external data; or

[0019] The port number of the external data.

[0020] In some embodiments, it is characterized in that

[0021] The ARM is further configured to receive internal data sent by the backplane network module; determine whether the internal data complies with the data filtering rules; send the internal data to the wireless module when the internal data complies with the data filtering rules; and discard the internal data when the internal data does not comply with the data filtering rules.

[0022] The wireless module is also used to receive the internal data and send the internal data to the ground equipment.

[0023] In some embodiments, determining whether the internal data complies with data filtering rules includes:

[0024] Passing the internal data to a network protocol stack of a kernel in the ARM through a network interface driver running in the ARM, wherein the network protocol stack includes the data filtering rule;

[0025] Determine whether the internal data complies with the data filtering rule through the network protocol stack.

[0026] In some embodiments, the ARM is further configured to:

[0027] When the internal data does not comply with the data filtering rule, recording discard information of the internal data;

[0028] The internal data discard information includes at least one or more of the following:

[0029] The type of the internal data;

[0030] The source IP address of the internal data;

[0031] The destination IP address of the internal data; or

[0032] The port number of the internal data.

[0033] In some embodiments, the ARM includes a data plane development kit DPDK, and the DPDK is pre-built with a vector packet processing VPP;

[0034] The VPP is controlled by a firewall application to burn data filtering rules into the ARM.

[0035] In some embodiments, the wireless module includes a fifth-generation mobile communication technology 5G wireless module and a wireless fidelity WiFi module;

[0036] The ARM includes a first interface and a second interface;

[0037] The ARM is connected to the 5G wireless module through a first interface;

[0038] The ARM is connected to the WiFi module via a second interface.

[0039] In some embodiments, the device includes a housing, the backplane network module is disposed on a first side of the housing, a front panel assembly is disposed on a second side of the housing, and the wireless module and the ARM are located inside the housing;

[0040] The front panel assembly includes a first coaxial connector, a second coaxial connector, a first rod antenna, and a second rod antenna;

[0041] The 5G wireless module is connected to the first coaxial connector via a first coaxial line; the WiFi module is connected to the second coaxial connector via a second coaxial line;

[0042] The first coaxial connector is connected to the first rod-shaped antenna; the second coaxial connector is connected to the second rod-shaped antenna.

[0043] In some embodiments, the ARM further includes a first gigabit network port and a second gigabit network port;

[0044] The ARM is connected to the front panel assembly via the first gigabit network port;

[0045] The ARM is connected to the backplane network module through the second gigabit network port.

[0046] An embodiment of the present application provides a vehicle-to-ground safety transmission device and method. By integrating a wireless module, an ARM and a backplane network module in the vehicle-to-ground safety transmission device, the wireless module is used to receive external data sent by the ground device, and the ARM performs data filtering rule judgment on the received external data. Based on the judgment result, it is decided to send the data to the backplane network module or discard the data, thereby realizing the safe transmission of data between the train system and the ground device, avoiding the addition of additional firewall equipment, and reducing the construction cost of the train system. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0048] Figure 1 Schematic diagram of the structure of a train system in the related art;

[0049] Figure 2 This is one of the structural diagrams of the vehicle-to-ground safety transmission equipment provided in an embodiment of the present application;

[0050] Figure 3 This is a flow chart of a method for secure vehicle-to-ground transmission provided in an embodiment of the present application;

[0051] Figure 4 This is a second structural diagram of the vehicle-to-ground safety transmission equipment provided in an embodiment of the present application;

[0052] Figure 5 The second flowchart of the vehicle-to-ground secure transmission method provided in an embodiment of the present application;

[0053] Figure 6 The third flowchart of the vehicle-to-ground secure transmission method provided in an embodiment of the present application;

[0054] Figure 7 This is the fourth flow chart of the vehicle-to-ground safe transmission method provided in an embodiment of the present application.

[0055] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0056] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0057] In the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and effects. For example, the first value and the second value are only used to distinguish different values, and do not limit their order. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different.

[0058] It should be noted that in the embodiments of the present application, words such as "exemplarily" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design described as "exemplarily" or "for example" in the present application should not be construed as more preferred or more advantageous than other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present relevant concepts in a specific manner.

[0059] In the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single (item) or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0060] The orientation or positional relationship indicated by terms such as "center", "longitudinal", "transverse", "upper", "lower", "left", "right", "front", "rear", etc. is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation to the present application.

[0061] The terms "connected" and "connect" should be interpreted broadly. For example, "connected" or "connected" in a circuit structure can refer not only to a physical connection, but also to an electrical connection or a signal connection. For example, it can be a direct connection, i.e., a physical connection, or an indirect connection through at least one intermediate component, as long as the circuit is interconnected. It can also refer to internal connectivity between two components. Signal connection can refer not only to signal connection through circuits but also to signal connection through media, such as radio waves. Those skilled in the art will understand the specific meanings of the above terms in this application on a case-by-case basis.

[0062] At present, as the degree of digitization of trains becomes higher and higher, the external data sent by ground equipment to the train system and the internal data sent by the train system to the ground equipment are becoming increasingly large, and the security protection issues of internal and external data are also becoming prominent.

[0063] In the prior art, a firewall device is added to the train system. The firewall device receives external and internal data and determines whether the data is safe. If the firewall device determines that the data is safe, the train-to-ground transmission device in the train system processes the data to prevent the train system from being attacked by unsafe data.

[0064] The following combination Figure 1 , the train system including the firewall device in the related art is explained.

[0065] Figure 1 FIG. 1 is a structural diagram of a train system in related art. Figure 1 As shown, the train system includes: train-to-ground transmission equipment and firewall equipment.

[0066] The vehicle-to-ground transmission equipment is connected to the firewall equipment.

[0067] The firewall device is used to receive external data sent by the ground device and determine whether the external data is safe. If the external data is safe, the firewall device sends the external data to the vehicle-ground transmission device.

[0068] The firewall device is also used to receive internal data sent by the vehicle-to-ground transmission device and determine whether the internal data is safe. If the internal data is safe, the firewall device sends the internal data to the ground device.

[0069] Alternatively, firewall devices can implement hardware-accelerated processing using specially designed application-specific integrated circuit (ASIC) chip logic. ASICs solidify instructions or computing logic within the chip, enabling extremely high processing capabilities. However, these chips lack flexibility and scalability. Once an ASIC chip is designed and finalized, it is difficult to modify or expand its functionality later.

[0070] Alternatively, firewall devices can use x86 architecture processors, paired with a general-purpose central processing unit (CPU) and peripheral component interconnect (PCI) bus interface, to implement security protection functions by running specific software on the processor. However, the x86 architecture's internal structure is complex and multi-layered, making optimization significantly more difficult. Most x86-based firewall devices rely on customized general-purpose operating systems, which means their security is closely linked to the security of the operating system itself. If the operating system has security vulnerabilities, the firewall device is also easily affected, exposing it to security risks.

[0071] Firewall equipment needs to be purchased on demand, which increases the cost of the train system.

[0072] In view of this, the present application proposes a vehicle-to-ground secure transmission device and method, the core of which is to achieve security protection of internal and external data through the ARM in the vehicle-to-ground secure transmission device, solving the problem of high cost of adding firewall equipment.

[0073] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0074] Figure 2 This is one of the structural diagrams of the vehicle-to-ground safety transmission equipment provided in the embodiment of the present application. For example, Figure 2 As shown in the figure, the vehicle-to-ground transmission equipment includes a wireless module, an Advanced RISC Machine (ARM) microprocessor, and a backplane network module. The wireless module is connected to the ARM, which is in turn connected to the backplane network module.

[0075] In some embodiments, the train-to-ground transmission equipment is arranged in a train system of a train.

[0076] In some embodiments, the train may also be a vehicle, a ship, or an aircraft.

[0077] When the train is a ship, the train can also be called: a ship, ship equipment, a marine vehicle, a marine transport vehicle, an aircraft, a marine transport equipment, a marine vehicle, etc.

[0078] When the train is an aircraft, the train can also be called: aircraft, airplane, aerial vehicle, aviation equipment, flight system, aviation transportation device, flight device, etc.

[0079] When a train is a vehicle, it can also be called: land vehicle, land transportation tool, traveler, land transportation equipment, transportation vehicle, etc.

[0080] The wireless module can receive external data sent by ground equipment.

[0081] In the embodiment of the present application, the wireless module is connected to the ARM, and external data can be sent to the ARM through the wireless module.

[0082] In an embodiment of the present application, the ARM is connected to the backplane network module, and external data can be sent to the backplane network module through the ARM.

[0083] Among them, ARM is also used to determine whether the received external data meets the data filtering rules. When the external data meets the data filtering rules, the external data is sent to the backplane network module. When the external data does not meet the data filtering rules, the external data is discarded.

[0084] Based on the above embodiment, the following example takes the wireless module as an example to receive external data sent by ground equipment. Figure 3 A vehicle-to-ground safe transmission method applicable to the above vehicle-to-ground safe transmission equipment is described in detail.

[0085] Figure 3 This is one of the flow charts of the vehicle-to-ground safe transmission method provided in the embodiment of the present application, such as Figure 3 As shown, the method includes:

[0086] S301. Ground equipment sends external data.

[0087] Correspondingly, the wireless module receives external data sent by the ground equipment.

[0088] Optionally, the ground equipment can be a traffic management center, a roadside base station, an intelligent traffic light, etc.

[0089] Optionally, the wireless module may include one or more of the following wireless modules: a third generation mobile communication technology (3G) wireless module, a fourth generation mobile communication technology (4G) wireless module, a fifth generation mobile communication technology (5G) wireless module, a sixth generation mobile communication technology (6G) wireless module, and a wireless fidelity (WiFi) module.

[0090] Through the above different wireless modules, the wireless module can support different communication protocols, including but not limited to: 3G communication protocol, 4G communication protocol, 5G communication protocol, 6G communication protocol, WiFi communication protocol. For example, the 4G wireless module in the wireless module can support 4G communication protocol

[0091] Optionally, the wireless module can switch between different wireless modules to receive external data sent by ground equipment based on one or more of the train's environmental signal strength, network stability, or external data transmission requirements. For example, when the train is in a city center with good coverage of surrounding WiFi hotspots, a small amount of external data transmission, and low real-time requirements, the wireless module will prioritize the WiFi module for receiving external data. When the train is traveling at high speed in a remote area with a strong 4G network signal, the wireless module will prioritize the 4G wireless module for receiving external data.

[0092] Optionally, the external data includes but is not limited to the following types of data: train operation instruction data, road condition information data, real-time traffic signal status data, and passenger service data.

[0093] The train operation command data includes, for example, control commands such as acceleration, deceleration, turning, and stopping.

[0094] Traffic condition information data includes, for example, the location of the congested road section, the degree of congestion, and the estimated time to clear the road.

[0095] Real-time traffic signal status data includes, for example, the red and green status of traffic lights and countdown time.

[0096] Passenger service data includes, for example, hotel information push, restaurant information push, scenic spot information push, in-car temperature adjustment instructions, and in-car humidity adjustment instructions at the destination.

[0097] In some embodiments, the external data may further include one or more of the following: a source Internet Protocol (IP) address of the external data, a destination IP address of the external data, or a port number to be used by the external data.

[0098] S302: The wireless module sends external data to the ARM.

[0099] Correspondingly, ARM receives external data sent by the wireless module.

[0100] Optionally, during data transmission between the wireless module and the ARM, a data verification mechanism can be implemented between the wireless module and the ARM to ensure data integrity and accuracy. For example, the wireless module generates a checksum based on a specific algorithm for the external data to be transmitted. This checksum is sent to the ARM along with the external data. The ARM recalculates the checksum for the received external data using the same algorithm and compares the calculated checksum with the received checksum. If the two match, the external data was transmitted without error. If not, the ARM sends a retransmission request to the wireless module until the external data is correctly received.

[0101] Optionally, the algorithm is, for example, a cyclic redundancy check (CRC) algorithm, and the generated check code is a CRC code.

[0102] S303. ARM determines whether the external data complies with the data filtering rules.

[0103] Optionally, the data filtering rules include but are not limited to one or more of the following: source IP address rule, destination IP address rule, and port number rule.

[0104] Before determining whether external data conforms to the data filtering rules, ARM obtains the source IP address of the external data, the destination IP address of the external data, or the port number to be used by the external data based on the external data.

[0105] Example 1: When the data filtering rule includes a source IP address rule, the ARM determines whether the external data complies with the source IP address rule.

[0106] In some embodiments, the ARM determines whether external data complies with the source IP address rule can be described as the following example 1A or 1B.

[0107] Example 1A, ARM determines whether the external data complies with the source IP address rules. It can be understood that ARM determines whether the source IP address of the external data is within the legal source IP address range. If the source IP address of the external data is within the legal source IP address range, it is determined that the external data complies with the source IP address rules. If the source IP address of the external data is not within the legal source IP address range, it is determined that the external data does not comply with the source IP address rules.

[0108] For example, the legal source IP address range is 123.123.1.0 to 123.123.1.255, and the source IP address of the external data is 123.123.1.100, so it is determined that the external data complies with the source IP address rule.

[0109] Example 1B, ARM determines whether the external data complies with the source IP address rules. It can be understood that ARM determines whether the source IP address of the external data is included in the legal source IP address set. If the source IP address of the external data is included in the legal source IP address set, it is determined that the external data complies with the source IP address rules. If the source IP address of the external data is not included in the legal source IP address set, it is determined that the external data does not comply with the source IP address rules.

[0110] For example, the legal source IP address set includes: address 1, address 2, and address 3. The source IP address of the external data is address 2, so it is determined that the external data complies with the source IP address rule.

[0111] The legal source IP address may be the IP address of an authorized ground device.

[0112] Example 2: When the data filtering rule includes a destination IP address rule, the ARM determines whether the external data complies with the destination IP address rule.

[0113] In some embodiments, the ARM determines whether the external data complies with the destination IP address rule can be described as the following example 2A or 2B.

[0114] Example 2A, ARM determines whether the external data complies with the destination IP address rules. It can be understood that ARM determines whether the destination IP address of the external data is within the legal destination IP address range. If the destination IP address of the external data is within the legal destination IP address range, it is determined that the external data complies with the destination IP address rules. If the destination IP address of the external data is not within the legal destination IP address range, it is determined that the external data does not comply with the destination IP address rules.

[0115] Example 2B, ARM determines whether the external data complies with the destination IP address rules. It can be understood that ARM determines whether the destination IP address of the external data is included in the legal destination IP address set. If the destination IP address of the external data is included in the legal destination IP address set, it is determined that the external data complies with the destination IP address rules. If the destination IP address of the external data is not included in the legal destination IP address set, it is determined that the external data does not comply with the destination IP address rules.

[0116] The legal destination IP address can be the IP address of each module in the backplane network module.

[0117] Example 3: When the data filtering rule includes a port number rule, the ARM determines whether the external data complies with the port number rule.

[0118] ARM determines whether the external data complies with the port number rules. It can be understood that ARM determines whether the port number of the port used by the external data matches the port number of the port that the external data should use. If the port number of the port used by the external data matches the port number of the port that the external data should use, it is determined that the external data complies with the port number rules. If the port number of the port used by the external data does not match the port number of the port that the external data should use, it is determined that the external data does not comply with the port number rules.

[0119] The port number of the port used by the external data matches the port number of the port that the external data should use. This means that the port number of the port used by the external data is the same as the port number of the port that the external data should use.

[0120] The type of external data corresponds to the port that the external data should use. For example, port number 1 is used to transmit train operation instruction data, and port number 2 is used to transmit road condition information data. When the external data is train operation instruction data, the external data should use port number 1. If the port number used by the external data is 2, it is determined that the external data does not comply with the port number rule.

[0121] The above examples 1, 2, and 3 are not exhaustive and are merely illustrative of some embodiments and are not intended to limit the scope of protection of this application. For example, where there is no contradiction, examples 1, 2, and 3 may be combined in any manner. The rules in any one of these examples may be used for judgment, or the rules in multiple examples may be used simultaneously for simultaneous judgment.

[0122] S304a, ARM sends the external data to the backplane network module when the external data meets the data filtering rules.

[0123] Correspondingly, the backplane network module receives external data.

[0124] Optionally, the backplane network module may send the external data to a corresponding module in the backplane network module according to the destination IP address of the external data.

[0125] S304b. When the external data does not comply with the data filtering rules, the ARM discards the external data.

[0126] Optionally, when the external data does not comply with the data filtering rules, the ARM may also send abnormal information to the wireless module, for example, the source IP address of the external data does not comply with the rules.

[0127] exist Figure 3 In the secure train-to-ground transmission method provided in this embodiment, an ARM determines whether external data conforms to data filtering rules, enabling secure transmission of external data sent from ground equipment to the train. This prevents ground equipment from invading the train's bus or server via external data. This method enables secure protection of external data within the train system without the need for additional firewall equipment, avoiding the cost of additional firewall equipment, significantly reducing the cost of the train system, and saving installation space within the train system.

[0128] In some embodiments, the wireless module includes a fifth generation mobile communication technology (5G) wireless module and a wireless fidelity (WiFi) module.

[0129] exist Figure 2 Based on the following Figure 4 , further explains the vehicle-to-ground safety transmission equipment including wireless modules including 5G wireless modules and WiFi modules.

[0130] Figure 4 This is the second structural diagram of the vehicle-to-ground safety transmission equipment provided in the embodiment of the present application. For example, Figure 4 As shown, the vehicle-to-ground transmission equipment includes: a shell, a front panel assembly, a wireless module, an ARM and a backplane network module.

[0131] Optionally, the size of the housing is 3U 8HP size.

[0132] The wireless module and ARM are located inside the shell.

[0133] The wireless module includes a 5G wireless module and a WiFi module, and the ARM includes a first interface and a second interface.

[0134] ARM is connected to the 5G wireless module through the first interface, and ARM is connected to the WiFi module through the second interface.

[0135] Optionally, the first interface is a Universal Serial Bus (USB) 3.0 interface, and the second interface is a Peripheral Component Interconnect Express (PCIe) 3.0 interface.

[0136] ARM is also connected to the backplane network module.

[0137] The backplane network module is arranged on the first side of the shell, and the front panel assembly is arranged on the second side of the shell.

[0138] The second side is located opposite to the first side, the first side is the back panel of the shell, and the second side is the front panel of the shell.

[0139] The front panel assembly includes a first coaxial connector, a second coaxial connector, a first rod antenna, and a second rod antenna.

[0140] The 5G wireless module is connected to the first coaxial connector through a first coaxial line, and the first coaxial connector is connected to the first rod antenna.

[0141] The WiFi module is connected to the second coaxial connector via a second coaxial line, and the second coaxial connector is connected to the second rod antenna.

[0142] Optionally, the front panel assembly may further include: two layers of connectors, the first layer of connectors including: 4-way light emitting diode (LED) light pipes, two first antenna interfaces, and a third gigabit network port; the second layer of connectors including: four second antenna interfaces.

[0143] The antenna interface is the interface of the front panel corresponding to the module in the wireless module. The two first antenna interfaces are, for example, the antenna interfaces of the front panel corresponding to the two WIFI modules, and the four second antenna interfaces are, for example, the antenna interfaces of the front panel corresponding to the four 5G wireless modules.

[0144] Optionally, the first coaxial line and the second coaxial line are both I-PEX to SMA coaxial lines, and the first coaxial connector and the second coaxial connector are both SubMiniature version A (SMA) connectors.

[0145] Optionally, a Nano Subscriber Identity Module (Nano SIM) card is configured in the 5G wireless module.

[0146] The ARM also includes a first gigabit network port and a second gigabit network port. The ARM is connected to the front panel assembly via the first gigabit network port, and the ARM is connected to the backplane network module via the second gigabit network port.

[0147] Specifically, the external devices in the front panel assembly are connected to ARM through the third gigabit network port of the front panel assembly and the first gigabit network port of ARM, so that the network interface driver and firewall application can run in ARM, and network port debugging and verification, as well as connection to firewall devices, can be realized.

[0148] Specifically, the ARM sends external data to the backplane network module and receives internal data sent by the backplane network module through the second gigabit network port.

[0149] Optionally, the first gigabit network port and the second gigabit network port are both native gigabit Ethernet ports.

[0150] In some embodiments, the vehicle-to-ground safety transmission device further includes: a first 4-pin pin header connector and a second 4-pin pin header connector, and the ARM processor further includes: a first serial port (Debug_UART serial port), a second serial port (SCU_UART serial port) and a third interface.

[0151] Debug_UART can be the UART0 interface.

[0152] The first serial port is connected to the first 4-pin pin header connector, and the second serial port is connected to the second 4-pin pin header connector.

[0153] The first serial port and the second serial port are used to debug the ARM processor.

[0154] The third interface is used to program or debug data filtering rules.

[0155] Specifically, the data filtering rules are burned into the ARM through the third interface.

[0156] The third interface is, for example, a USB 2.0 interface.

[0157] Optionally, the ARM processor can also include a third Gigabit Ethernet port. This port connects to the Ethernet switch chip in the Prognostics and Health Management (PHM) chassis, enabling data exchange with other devices within the PHM chassis and implementing prognostics and health management for vehicle-to-ground safety transmission equipment. For example, the ARM processor can collect device operating data from sensors within the PHM chassis for further analysis and processing, and can also transmit the processed data to other devices via the Ethernet switch chip, enabling data sharing and remote monitoring.

[0158] Optionally, the vehicle-to-ground wireless transmission device further includes a single-chip microcomputer, wherein the single-chip microcomputer is connected to the ARM via the ARM's third serial port (UART serial port). The single-chip microcomputer can be used to manage the vehicle-to-ground wireless transmission device.

[0159] Figure 5 The second flow chart of the vehicle-to-ground safe transmission method provided in the embodiment of the present application is as follows: Figure 5 As shown, the method includes:

[0160] S501. Ground equipment sends external data.

[0161] Correspondingly, the wireless module receives external data sent by the ground equipment.

[0162] S502: The wireless module sends external data to the ARM.

[0163] Correspondingly, ARM receives external data sent by the wireless module.

[0164] S503 : The ARM transmits the external data to the network protocol stack of the kernel in the ARM through the network interface driver running in the ARM, wherein the network protocol stack includes data filtering rules.

[0165] In some embodiments, ARM includes a Data Plane Development Kit (DPDK) with Vector Packet Processing (VPP) pre-built into the DPDK.

[0166] In some embodiments, the VPP is controlled by a firewall application to burn data filtering rules into the ARM.

[0167] In some embodiments, the VPP is controlled by a firewall application to change data filtering rules in the ARM.

[0168] Specifically, the external device is connected to the ARM via the third interface, so that the external device can operate the firewall application and control the VPP to burn the data filtering rules into the ARM, that is, into the network protocol stack of the kernel.

[0169] Optionally, the firewall application calls the underlying VPP binary application programming interface (VPP binary API) through a preset interface to control the VPP.

[0170] Optionally, the preset interface may be GoVPP, or may be another interface capable of calling the underlying VPP binary API to implement control over the VPP.

[0171] Optionally, the network interface driver and the firewall application program can be run through a communication connection between an external device and the vehicle-to-ground wireless transmission device, wherein the connection can be a wired communication connection or a wireless communication connection.

[0172] S504. ARM determines whether the external data complies with the data filtering rules through the network protocol stack of the kernel.

[0173] Specifically, the execution method of S504 is similar to that of S303 and will not be repeated here.

[0174] S505a, ARM sends the external data to the backplane network module when the external data meets the data filtering rules.

[0175] Correspondingly, the backplane network module receives external data.

[0176] S505b. When the external data does not comply with the data filtering rules, the ARM discards the external data and records the discarding information of the external data.

[0177] In some embodiments, the discarding information of the external data includes at least one or more of the following:

[0178] The type of external data;

[0179] The source IP address of the external data;

[0180] The destination IP address of the external data; or

[0181] The port number for external data.

[0182] The port number of the external data includes the port number that the external data should use and the port number currently used by the external data.

[0183] Optionally, the discarding information of the external data may further include: the discarding time of the external data, the size of the external data, the discarding reason of the external data, etc.

[0184] exist Figure 5 In the vehicle-to-ground security transmission method provided in the embodiment, the network interface driver in the ARM controls the transmission of external data to the kernel's network protocol stack, thereby controlling the on / off of external data transmission. The coordinated operation of DPDK and VPP enables the data filtering rules to be burned into the kernel's network protocol stack in the ARM through the firewall application, enabling the ARM to filter data according to the data filtering rules. This means that in the train system, security protection functions can be implemented without the need for additional firewall equipment, avoiding the cost investment caused by the addition of firewall equipment and significantly reducing the cost of the train system. In addition, data filtering rules can also be changed through the firewall application to meet the different scenario requirements of ground equipment and train transmission.

[0185] In an embodiment of the present application, the ARM is connected to the backplane network module, and the backplane network module can also send internal data to the ARM.

[0186] In an embodiment of the present application, the wireless module is connected to the ARM, and the ARM can also send internal data to the wireless module.

[0187] The wireless module can also send internal data to ground equipment.

[0188] Among them, ARM is also used to determine whether the received internal data meets the data filtering rules. When the internal data meets the data filtering rules, the internal data is sent to the wireless module. When the internal data does not meet the data filtering rules, the internal data is discarded.

[0189] Based on the above embodiment, the following example takes the wireless module as an example to send internal data to the ground equipment. Figure 6 A vehicle-to-ground safe transmission method applicable to the above vehicle-to-ground safe transmission equipment is described in detail.

[0190] Figure 6 The third flow chart of the vehicle-to-ground safe transmission method provided in the embodiment of the present application is as follows: Figure 6 As shown, the method includes:

[0191] S601. The backplane network module sends internal data to the ARM.

[0192] Correspondingly, ARM receives internal data sent by the backplane network.

[0193] Optionally, the backplane network module includes multiple modules, including but not limited to: an on-board navigation module, a train fault diagnosis module, and a passenger service module.

[0194] Internal data includes, for example, the train's current position and route planning data generated by the on-board navigation module, the train status data detected by the train fault diagnosis module, and the passenger demand-related data generated by the passenger service module.

[0195] In some embodiments, the internal data may further include one or more of the following: a source IP address of the internal data, a destination IP address of the internal data, or a port number that the internal data should use.

[0196] The source IP addresses of the internal data correspond one-to-one to the multiple modules in the backplane network module.

[0197] S602: ARM determines whether the internal data complies with the data filtering rules.

[0198] Specifically, the execution method of S602 is similar to the execution method of S303 and will not be described in detail here.

[0199] Optionally, the internal data may also include emergency information. ARM may also determine whether the internal data contains emergency information before determining whether the internal data complies with the data filtering rules. If the internal data contains emergency information, it will prioritize determining whether the internal data complies with the data filtering rules. If it complies with the data filtering rules, it will prioritize sending the data to the wireless module and then sending it to the ground equipment through the wireless module.

[0200] Optionally, the data filtering rules may further include external data filtering rules and internal data filtering rules, and the ARM is used to determine whether the external data complies with the external data filtering rules and whether the internal data complies with the internal data filtering rules.

[0201] S603a, when the internal data meets the data filtering rules, the ARM sends the internal data to the wireless module.

[0202] Correspondingly, the wireless module receives internal data.

[0203] The wireless module may include one or more of the following wireless modules: 3G wireless module, 4G wireless module, 5G wireless module, 6G wireless module, and WiFi module.

[0204] Optionally, the ARM may send the internal data to each wireless module in the wireless module according to one or more of the signal strength of the train's environment, network stability, or the transmission requirements of the internal data.

[0205] S603b. When the internal data does not comply with the data filtering rules, the ARM discards the internal data.

[0206] S604: The wireless module sends internal data to the ground equipment.

[0207] Optionally, after receiving the internal data, the wireless module switches to different wireless modules to send the internal data to the ground equipment according to one or more of the signal strength of the train's environment, network stability, or the transmission requirements of the internal data.

[0208] exist Figure 6 In the train-to-ground security transmission method provided in the embodiment, ARM is used to determine whether the internal data meets the data filtering rules, thereby realizing the secure transmission of internal data from the train to the ground equipment. This method realizes the security protection of internal data in the train system without the need for additional firewall equipment, avoiding the cost investment caused by the addition of firewall equipment, significantly reducing the cost of the train system, and saving the installation space of the train system in the train.

[0209] Figure 7The fourth flow chart of the vehicle-to-ground safe transmission method provided in the embodiment of the present application is as follows: Figure 7 As shown, the method includes:

[0210] S701. The backplane network module sends internal data to the ARM.

[0211] Correspondingly, ARM receives internal data sent by the backplane network.

[0212] S702 : The ARM transmits internal data to a network protocol stack of a kernel in the ARM through a network interface driver running in the ARM, wherein the network protocol stack includes data filtering rules.

[0213] Specifically, the execution method of S702 is similar to the execution method of S403 and will not be described in detail here.

[0214] S703. ARM determines whether the internal data complies with the data filtering rules through the network protocol stack.

[0215] Specifically, the execution method of S703 is similar to that of S404 and will not be repeated here.

[0216] S704a, ARM sends the internal data to the wireless module when the internal data meets the data filtering rules.

[0217] Correspondingly, the wireless module receives internal data.

[0218] S704b. When the internal data does not comply with the data filtering rules, the ARM discards the internal data and records the discarding information of the external internal and external data.

[0219] In some embodiments, the discard information of the internal data includes at least one or more of the following:

[0220] The type of internal data;

[0221] Source IP address of internal data;

[0222] The destination IP address of the internal data; or

[0223] The port number for internal data.

[0224] The port number of the internal data includes the port number that the internal data should use and the port number currently used by the internal data.

[0225] Optionally, the discarding information of the internal data may further include: the discarding time of the internal data, the size of the internal data, the discarding reason of the internal data, etc.

[0226] S705. The wireless module sends internal data to the ground equipment.

[0227] exist Figure 7 In the vehicle-to-ground safe transmission method provided in the embodiment, the network interface driver in ARM controls the transmission of internal data to the kernel's network protocol stack, thereby controlling the on / off of internal data transmission. The coordinated operation of DPDK and VPP enables the burning of data filtering rules into the kernel's network protocol stack in ARM through a firewall application, so that ARM has the ability to filter data according to data filtering rules. This means that in the train system, security protection functions can be implemented without the need for additional firewall equipment, thus avoiding the cost investment caused by the addition of firewall equipment and significantly reducing the cost of the train system.

[0228] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.

Claims

1. A vehicle-to-ground safety transmission device, characterized in that: Applied to train systems, the vehicle-ground security transmission equipment includes: a wireless module, a reduced instruction set microprocessor ARM and a backplane network module; The wireless module is connected to the ARM; the ARM is connected to the backplane network module; The wireless module is used to receive external data sent by ground equipment and send the external data to the ARM; The ARM is used to receive the external data; determine whether the external data meets the data filtering rules; when the external data meets the data filtering rules, send the external data to the backplane network module; when the external data does not meet the data filtering rules, discard the external data.

2. The device according to claim 1, characterized in that The determining whether the external data complies with the data filtering rules includes: Passing the external data to a network protocol stack of a kernel in the ARM through a network interface driver running in the ARM, wherein the network protocol stack includes the data filtering rule; Determine whether the external data complies with the data filtering rule through the network protocol stack.

3. The device according to claim 1 or 2, characterized in that The ARM is also used to: When the external data does not comply with the data filtering rule, recording discard information of the external data; The discard information of the external data includes at least one or more of the following: The type of the external data; The source Internet Protocol (IP) address of the external data; The destination IP address of the external data; or The port number of the external data.

4. The device according to claim 1, characterized in that The ARM is further configured to receive internal data sent by the backplane network module; determine whether the internal data complies with the data filtering rules; send the internal data to the wireless module when the internal data complies with the data filtering rules; and discard the internal data when the internal data does not comply with the data filtering rules. The wireless module is also used to receive the internal data and send the internal data to the ground equipment.

5. The device according to claim 4, characterized in that The determining whether the internal data complies with the data filtering rules includes: Passing the internal data to a network protocol stack of a kernel in the ARM through a network interface driver running in the ARM, wherein the network protocol stack includes the data filtering rule; Determine whether the internal data complies with the data filtering rule through the network protocol stack.

6. The device according to claim 4 or 5, characterized in that The ARM is also used to: When the internal data does not comply with the data filtering rule, recording discard information of the internal data; The internal data discard information includes at least one or more of the following: The type of the internal data; The source IP address of the internal data; The destination IP address of the internal data; or The port number of the internal data.

7. The device according to any one of claims 1 to 6, characterized in that The ARM includes a data plane development kit DPDK, in which a vector packet processing VPP is pre-built; The VPP is controlled by a firewall application to burn the data filtering rules into the ARM.

8. The device according to claim 1, characterized in that The wireless module includes a fifth-generation mobile communication technology 5G wireless module and a wireless fidelity WiFi module; The ARM includes a first interface and a second interface; The ARM is connected to the 5G wireless module through a first interface; The ARM is connected to the WiFi module via a second interface.

9. The device according to claim 8, characterized in that The device includes a housing, the backplane network module is arranged on a first side of the housing, a front panel assembly is arranged on a second side of the housing, and the wireless module and the ARM are located inside the housing; The front panel assembly includes a first coaxial connector, a second coaxial connector, a first rod antenna, and a second rod antenna; The 5G wireless module is connected to the first coaxial connector via a first coaxial line; the WiFi module is connected to the second coaxial connector via a second coaxial line; The first coaxial connector is connected to the first rod antenna; The second coaxial connector is connected to the second rod antenna.

10. The device according to claim 9, characterized in that The ARM further includes a first gigabit network port and a second gigabit network port; The ARM is connected to the front panel assembly via the first gigabit network port; The ARM is connected to the backplane network module through the second gigabit network port.