Railway train-ground data secure transmission method and device and key management method

By combining the SM2, SM4, and SM3 algorithms, and utilizing BeiDou timing and device fingerprinting to generate dynamic SM2 curve parameters, predictive key material preparation and three-stage key negotiation are implemented. This solves the problem of key negotiation interruption in high-speed railway vehicle data transmission and achieves secure and efficient data transmission.

CN120979781APending Publication Date: 2025-11-18INST OF COMPUTING TECH CHINA ACAD OF RAILWAY SCI +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511281102.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In the high-speed rail environment, the onboard data transmission of EMU trains faces problems such as key negotiation interruption caused by frequent base station switching, strict time constraints, and high protocol complexity. Existing key negotiation and secure communication protocols cannot effectively cope with these issues, and there is a lack of secure transmission solutions adapted to high-speed mobile scenarios.

Method used

By combining the SM2 elliptic curve asymmetric encryption algorithm, the SM4 symmetric encryption algorithm, and the SM3 cryptographic hash algorithm, dynamic SM2 elliptic curve parameters are generated through BeiDou time synchronization and device fingerprinting. Predictive key material preparation and a three-stage key negotiation mechanism are implemented, and a three-level key derivation chain structure is established to achieve rapid connection recovery and key management.

Benefits of technology

It improves the system's resistance to attacks, ensures secure key distribution and management, reduces the complexity of key negotiation, enhances data transmission security and communication efficiency, and adapts to seamless key negotiation and secure data transmission in high-speed mobile scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979781A_ABST
    Figure CN120979781A_ABST
Patent Text Reader

Abstract

The invention discloses a railway train-ground data secure transmission method, and the method comprises the steps: generating a first key pair and a second key pair according to a preset rule in a ground data center and a vehicle-mounted end data center; the two parties map the standard curve to generate a dynamic curve, and select a random number according to communication quality switching; based on the first key pair, the second key pair and the random number, executing three-stage key negotiation on a dynamically generated dynamic curve, and calculating and safely transmitting a third key; based on the third key, the two parties form a three-level derived chain to adaptively derive a fourth key; and the service message is encrypted and decrypted by the fourth key drive, so that the safe transmission of the railway vehicle-mounted data is realized. According to the method and the system, predictive key preparation, quick connection recovery and key life cycle management are integrated, communication can be recovered through one-time handshake under the scene of high-speed movement and base station switching, and the safety, the real-time performance and the maintainability of data transmission are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of data communication and security processing of railway locomotives, in particular to a data security transmission method and device for high-speed moving and frequent base station switching scenarios of motor train units. BACKGROUND

[0002] Currently, the on-board data of the motor train unit includes the process and state information of multiple subsystems such as traction, braking, axle temperature, doors, air conditioning, etc., which has important research value for monitoring the fault state and running technical conditions of the motor train unit, and can be widely used in fault cause analysis, trend law prediction and operation state evaluation of various systems of the train. The on-board data of the motor train unit is divided into real-time and non-real-time data. Real-time data is collected by wireless on-board transmission equipment from train sensor networks and satellite navigation systems during train operation and transmitted to the ground data center in real time through 4G / 5G, 5G private network, etc. via a security platform, mainly including fault information and state information of the motor train unit. Non-real-time data is the full amount of data collected by the wireless on-board transmission equipment during train operation, which is transmitted to the motor train section server through WLAN.

[0003] The on-board transmission data of the motor train unit involves a large amount of sensitive information related to train operation, which is related to the safety and stability of train operation, so it puts forward very high requirements on the four dimensions of entity identity authenticity of the data transmission system, confidentiality and integrity of the on-board data, and non-repudiation of the transmission operation behavior. Not only should the on-board data of the motor train unit be prevented from being intercepted during transmission, but also the identity authenticity of the transmission data and the data content should be ensured not to be tampered with, etc., in order to protect the safety of the on-board data of the motor train unit.

[0004] Especially in the high-speed railway environment, the frequent base station switching problem caused by the high-speed movement of the motor train unit poses higher challenges to data security transmission. The current speed of the motor train unit can reach more than 350km / h, at this speed, the base station switching frequency is significantly increased, and the traditional key agreement mechanism faces the problems of key agreement interruption, strict time constraints, and high protocol complexity.

[0005] The current transmission of on-board data of the motor train unit mainly uses direct transmission, which lacks effective security measures to protect these sensitive information, and a perfect security equipment and management mechanism has not been established. Especially in the high-speed moving and frequent base station switching scenario, the existing key agreement and secure communication protocol shows obvious limitations and cannot effectively cope with various security challenges in such scenarios.

[0006] The prior art mainly adopts the following schemes: a pre-shared key (PSK) mode, a certificate authentication mode and a temporary key derivation mode. These schemes perform well in static or low-speed mobile scenarios, but in a high-speed mobile and frequent handover environment, there are obvious deficiencies such as long negotiation delay, high calculation complexity, and the like, and it is difficult to meet the real-time and secure transmission requirements in a high-speed mobile scenario of a train set.

[0007] In order to solve the above problems existing in the prior art, it is urgent to develop a key negotiation method suitable for a high-speed mobile environment and supporting seamless cooperation of double base stations, and a complete data security transmission scheme for a train set. SUMMARY

[0008] In order to solve the above-mentioned defects of the prior art, the present application provides a railway train-ground data security transmission method.

[0009] In a first aspect, the embodiments of the first aspect provide a railway train-ground data security transmission method, applied to railway data security transmission between a train-mounted data center and a ground data center, and the method comprises the following steps:

[0010] At the ground data center and the train-mounted data center, a first key pair and a second key pair are generated according to a preset rule;

[0011] The standard curve is mapped into a dynamic curve by both sides, and a random number is selected according to communication quality switching;

[0012] Based on the first key pair, the second key pair and the random number, a three-phase key negotiation is performed on the dynamically generated dynamic curve, a third key is calculated and transmitted;

[0013] Based on the third key, a three-level derivation chain is formed by both sides, and a fourth key is adaptively derived;

[0014] The fourth key is used to drive business packet encryption and decryption, and the security transmission of the railway train-mounted data is realized.

[0015] In the embodiments of the present application, the above-mentioned railway train-ground data security transmission method further comprises the following steps:

[0016] The received data packet is decrypted, identity confirmed and integrity verified;

[0017] After the communication base station switching or communication interruption, the connection is quickly recovered through a handshake.

[0018] In the embodiments of the present application, the above-mentioned generation of a first key pair and a second key pair at the ground data center and the train-mounted data center according to a preset rule comprises the following steps:

[0019] The ground data center is preset with an asymmetric first key pair, the vehicle-mounted data center is preset with an asymmetric second key pair and a public key of the first key pair, and identity confirmation is realized through encrypted communication of the public key of the first key pair.

[0020] In the embodiment of the application, the standard curve mapping is generated as a dynamic curve by the two parties, and the steps include:

[0021] The two parties synchronize time through Beidou time service and obtain train position information, combine the physical address of the vehicle-mounted equipment, adopt a hash modulation function, and jointly construct a dynamic elliptic curve parameter.

[0022] In the embodiment of the application, the random number is switched according to the communication quality, and the steps include:

[0023] The two parties measure the channel state of the train-ground wireless link at a certain time interval, and quantize the random number to form a channel state information random number cache pool;

[0024] When generating a data packet, the random number cache pool or a traditional random number is selected according to a channel state quality threshold.

[0025] In the embodiment of the application, the three-stage key negotiation includes:

[0026] The pre-switching time is calculated based on the train running track, and key material preparation is performed with the next base station in advance;

[0027] In the pre-negotiation stage, the vehicle-mounted end uses the second public key of the second key pair, and the ground end uses the first public key of the first key pair, to complete random number exchange and pre-distribution of third key encapsulation material on the dynamic curve when the current link is stable;

[0028] In the switching stage, the materials obtained in the pre-negotiation stage are directly used by the two parties at the moment when the physical link is switched to a new base station, and a complete handshake is not needed, so that communication is not interrupted.

[0029] In the post-confirmation stage, the two parties each calculate and verify a label; if the signature verification is successful, the three-stage negotiation is completed.

[0030] In the embodiment of the application, the three-level key derivation structure includes:

[0031] The ground data center calculates the third key based on the first key pair and the second key pair according to the ID of the vehicle-mounted equipment based on a cryptographic hash algorithm, and the third key is encrypted and transmitted on the dynamic curve through the public key of the second key pair of the two parties and is signed.

[0032] Based on the third key, a three-level key derivation chain structure is established, wherein the three-level key derivation chain structure includes: the third key, a plurality of session keys generated based on the third key, and a corresponding fourth key generated for each session key.

[0033] In the embodiment of the present application, the service packet encryption and decryption driven by the fourth key comprises the following steps:

[0034] A one-packet-one-key strategy is adopted, the session key and the packet timestamp information are combined, and the fourth key unique to the vehicle-mounted packet is derived based on the encryption algorithm;

[0035] The vehicle-mounted data center encrypts the packet and encapsulates the packet using the fourth key driven mode, and realizes the secure transmission according to the vehicle-mounted transmission protocol;

[0036] The ground data center receives the encrypted packet, generates the fourth key according to the same encryption algorithm derivation rule using the session key and the packet header information, and decrypts the packet using the fourth key.

[0037] In the embodiment of the present application, the connection is restored through a handshake after the communication base station switching or communication interruption, and the steps comprise:

[0038] The vehicle-mounted client identifier, the base station server identifier, the session key and the current timestamp are used to generate a state token;

[0039] The vehicle-mounted end and the ground data center update the packet timestamp information based on the same timestamp rule, and the timestamp is synchronized with the Beidou time service system; and the local key value is updated based on the same algorithm;

[0040] According to the state token and the updated timestamp and local key, the communication connection is restored through a handshake;

[0041] The timestamp update rule is that a new timestamp information is generated after the last timestamp time elapses for a first time interval; the first time interval is dynamically adjusted according to the train running speed and the base station coverage range, and is re-synchronized when a switching event is detected.

[0042] In a second aspect, an embodiment of the present application provides a railway vehicle-ground data security transmission device, which comprises:

[0043] The data security module is used to generate a first key pair and a second key pair according to a preset rule;

[0044] The position prediction unit is used to calculate a pre-switching time based on the train running track, and to perform key material preparation with a next base station in advance;

[0045] The key derivation module is used to perform a three-stage key agreement on a dynamically generated dynamic curve, to calculate and securely transmit a third key; based on the third key, the vehicle-mounted end device and the ground data center form a three-stage derivation chain to adaptively derive a fourth key; the service packet encryption and decryption is driven by the fourth key to realize the security transmission of the railway vehicle-mounted data;

[0046] A verification module is configured to complete identity authentication and signature;

[0047] A fast connection recovery module is configured to recover the connection through a handshake after a base station switch or a communication interruption.

[0048] In a third aspect, an embodiment of the present aspect provides a key management method for railway on-board data security transmission, the method comprising: a multi-level key management mechanism for a first key pair, a second key pair, a third key, a session key, and a fourth key, and performing complete key life cycle management, wherein the key management mechanism further comprises: a multi-state key life cycle management, including a generation state, a pre-activation state, an activation state, an aging state, an archiving state, and a destruction state, and a prediction-based key update trigger mechanism, integrating time trigger, distance trigger, switch number trigger, and security risk trigger.

[0049] In a fourth aspect, an embodiment of the present aspect provides a computer-readable storage medium having a computer program stored thereon, the program being executed by a processor to implement the steps of the railway on-board data security transmission method described above.

[0050] In a fifth aspect, an embodiment of the present aspect provides a ground data center that adopts the railway on-board data security transmission method described above, the ground data center being configured to perform the steps of:

[0051] In the ground data center, a first key pair is generated according to a preset rule;

[0052] The ground data center receives a second private key signature message and a second public key sent by the on-board data center, verifies the second private key signature message, generates a third random number, decrypts the first random number using the first private key, encrypts the sum of the first random number and the third random number using the second public key, and calculates a third key;

[0053] The ground data center derives a fourth key based on the third key and an adaptive random number, and drives the business packet encryption and decryption using the fourth key to achieve the security transmission of the railway on-board data.

[0054] In a sixth aspect, an embodiment of the present aspect provides an on-board data center that adopts the railway on-board data security transmission method described above, the on-board data center being configured to perform the steps of:

[0055] In the on-board data center, a first key pair is generated according to a preset rule; and a second key pair is generated;

[0056] The on-board data center generates a first random number, encrypts the first random number using a first public key, encrypts a second private key signature message using a second private key signature, and sends the second private key signature message to the ground data center;

[0057] The vehicle-mounted data center receives the third key sent by the ground data center, and obtains the third key by decrypting the sum of the first random number and the third random number with the second private key;

[0058] The vehicle-mounted data center derives a fourth key based on the third key and the adaptive random number, and drives the encryption and decryption of the service packet with the fourth key to realize the secure transmission of the railway vehicle-mounted data.

[0059] Compared with the related prior art, the following outstanding beneficial effects are achieved:

[0060] (1) The method combines the SM2 elliptic curve asymmetric encryption algorithm, the SM4 symmetric encryption algorithm and the SM3 password hash algorithm, wherein the SM2 is used for identity authentication, digital signature and key agreement, the SM4 is used for data encryption protection, and the SM3 is used for sub-level key derivation, so that the advantages of high security of the SM2 and SM3 algorithms and the advantage of fast encryption and decryption of the SM4 algorithm are combined, and the safe and efficient transmission of the EMU vehicle-mounted data is realized;

[0061] (2) The method adopts a dynamic SM2 elliptic curve parameter generation mechanism based on Beidou timing and device fingerprint, and generates elliptic curve parameters through the formula (p', a', b') = H mod (p||a||b||MAC id ||T BDS ||GPS coord ), so that the curve parameters used by each device at different times and in different positions are different, and the attack resistance of the system is improved, and strong adaptability and security are provided for the special operation environment of high-speed rail

[0062] (3) The method innovatively proposes a predictive key material preparation mechanism and a three-stage key agreement mechanism of “pre-agreement-switch-post-confirmation”, solves the key agreement interruption problem caused by base station switching in the high-speed mobile scene, and realizes seamless key agreement and secure data transmission;

[0063] (4) The key management mechanism of the high-speed railway vehicle-mounted data transmits the key through vehicle-ground key agreement, offline distribution and online agreement of the sub-level key, ensures the safe distribution and management of the key, generates and distributes the master key through hierarchical key management, and reduces the exposure risk of the master key, provides a dynamic update function of the key, and effectively prevents security risks such as key leakage and key expiration. The vehicle-ground transmission system can flexibly and efficiently manage the key in different operation scenes, improve the security of data transmission, and ensure the consistency and effectiveness of the security of the key in long-term operation;

[0064] (5) The method establishes a three-level key derivation chain structure of the third key-session key-fourth key and a multi-state key life cycle management mechanism, reduces the complexity of key negotiation, and improves the efficiency and security of key management;

[0065] (6) The method designs a fast connection recovery protocol, optimizes the traditional three-way handshake to one-way handshake to recover the connection, significantly reduces the connection recovery delay during base station switching, and improves the communication efficiency of the system in a high-speed mobile scenario;

[0066] (7) The high-speed railway vehicle-mounted data encryption scheme is based on the vehicle-mounted equipment medium of the motor train unit and an independent secure transmission module, and through modular design, the existing hardware resources are fully utilized to improve the execution efficiency, and the flexibility and scalability of the secure transmission system are improved;

[0067] (8) The high-speed railway vehicle-mounted data encryption uses the OFB mode of the SM4 block cipher algorithm to process data encryption, optimizes the encryption and decryption calculation efficiency, is suitable for fast implementation on resource-limited vehicle-mounted equipment, so that the system can process and transmit a large amount of data in the operation of the motor train unit in real time, without affecting the normal operation of the motor train unit and information circulation. BRIEF DESCRIPTION OF DRAWINGS

[0068] The drawings described herein are used to provide further understanding of the present application, constitute a part of the present application, the illustrative embodiments of the present application and the description thereof are used to explain the present application, and do not constitute an improper limitation on the present application. In the drawings:

[0069] Figure 1 The flowchart of the railway train-ground data security transmission method of the present application;

[0070] Figure 2 The architecture diagram of the motor train unit vehicle-mounted data security transmission system of the embodiment of the present application;

[0071] Figure 3 The flowchart of the three-stage negotiation method of the embodiment of the present application;

[0072] Figure 4 The vehicle-mounted data frame encryption format schematic diagram of the embodiment of the present application;

[0073] Figure 5 The expansion schematic diagram of the vehicle-mounted data transmission protocol of the embodiment of the present application;

[0074] Figure 6 The module diagram of the railway train-ground data security transmission device of the embodiment of the present application;

[0075] Figure 7 The vehicle-mounted data security transmission key management hierarchy diagram of the embodiment of the present application;

[0076] Figure 8 is a schematic diagram of a medium structure of a vehicle-mounted data security transmission device according to an embodiment of the present application;

[0077] Figure 9 is a schematic diagram of an encryption and decryption process according to an embodiment of the present application. DETAILED DESCRIPTION

[0078] It should be noted that the processor of the present application is the control center of the electronic device, which can be one processor or a plurality of processing elements. For example, it can be one or more central processing units (CPUs), application specific integrated circuits (ASICs), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0079] Optionally, the processor can execute various functions of the electronic device by running or executing software programs stored in the memory and calling data stored in the memory.

[0080] In a specific implementation, as an embodiment, the processor can include one or more CPUs. Each of these processors can be a single core processor or a multi-core processor. The processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions). The electronic device can include a server, a desktop computer, a notebook computer, a smart phone, a tablet computer, an embedded computer, etc., wherein the embedded computer includes vehicles and robots, etc.

[0081] The memory is used to store software programs for implementing the present application, and is controlled by the processor to execute. The specific implementation can refer to the above method embodiments, which will not be described here.

[0082] It should be noted that the structure of the electronic device shown in the drawings of the present application does not constitute a limitation, and the actual knowledge structure recognition device can include more or fewer components than shown, or combine certain components, or different component arrangements.

[0083] The above-described embodiments can be implemented in whole or in part by software, hardware (e.g., circuitry), firmware, or any combination thereof. When implemented in software, the above-described embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are wholly or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center through wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. containing one or more available medium collections. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. The semiconductor medium can be a solid-state disk.

[0084] It should also be understood that the term "and / or" used herein is merely an association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. In addition, the character " / " herein generally represents an "or" relationship between the associated objects before and after it, but it can also represent an "and / or" relationship, which can be understood in the context before and after it.

[0085] In the present application, "at least one" means one or more, and "multiple" means two or more. "At least one of the following" or the like means any combination of the items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.

[0086] It should also be understood that in various embodiments of the present application, the size of the sequence number of the above-described processes does not mean the order of execution, and the execution order of the processes should be determined by their functions and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0087] In several embodiments provided by the present application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other manners. For example, the embodiments of the apparatus described above are merely schematic. For example, the division of the units is only a logical function division. There can be another division manner for the actual implementation. For example, a plurality of units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0088] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.

[0089] In addition, each functional unit in the various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.

[0090] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the present application that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0091] In order to make the above features and effects of the present application more clear and easy to understand, the following embodiments are specifically described below with reference to the accompanying drawings. The present specification discloses one or more embodiments containing the features of the present application. The disclosed embodiments are only for illustration. The protection scope of the present application is not limited to the disclosed embodiments, and the present application is defined by the appended claims.

[0092] The following is a system embodiment corresponding to the above method embodiment. The present embodiment can be implemented in cooperation with the above embodiments. The related technical details mentioned in the above embodiments are still valid in the present embodiment. In order to reduce repetition, they will not be described here. Correspondingly, the related technical details mentioned in the present embodiment can also be applied in the above embodiments.

[0093] The method aims to provide a railway vehicle-ground data security transmission method and device. It includes: the vehicle-mounted end and the ground end map the national standard curve SM2 to a dynamic curve E' based on Beidou timing and equipment fingerprint, perform three-stage key negotiation of "pre-negotiation-switch-confirmation" on E', and securely transfer the third key; both sides use SM3 to form a three-level derivation chain of "third key-session key-fourth key". The system generates a true random number cache pool by periodically measuring the vehicle-ground channel state information, takes the channel state information random number when the communication is good, automatically switches the random number when the condition is poor, and adaptively derives the fourth key; the business message is driven by the SM4-OFB encryption and decryption key. The device modularly integrates predictive key preparation, fast connection recovery, and key life cycle management, can recover communication through one handshake in the high-speed mobile and base station switching scene, and improves the security, real-time performance, and maintainability of data transmission.

[0094] The method aims to provide a railway vehicle-ground data security transmission method and device. It includes: the vehicle-mounted end and the ground end map the national standard curve SM2 to a dynamic curve E' based on Beidou timing and equipment fingerprint, perform three-stage key negotiation of "pre-negotiation-switch-confirmation" on E', and securely transfer the third key; both sides use SM3 to form a three-level derivation chain of "third key-session key-fourth key". The system generates a true random number cache pool by periodically measuring the vehicle-ground channel state information, takes the channel state information random number when the communication is good, automatically switches the random number when the condition is poor, and adaptively derives the fourth key; the business message is driven by the SM4-OFB encryption and decryption key. The device modularly integrates predictive key preparation, fast connection recovery, and key life cycle management, can recover communication through one handshake in the high-speed mobile and base station switching scene, and improves the security, real-time performance, and maintainability of data transmission.

[0095] The present application embodiment provides a railway vehicle-ground data security transmission method, which is applied to a railway, especially a dynamic train or high-speed railway vehicle-mounted device, a ground access node, and a dynamic train-ground network transmission system of a ground data center. Based on the existing dynamic train vehicle-mounted data transmission system, according to the dynamic train vehicle-mounted data transmission requirements, the dynamic train vehicle-mounted data center encrypts the vehicle-mounted data through a local data security module, and then transmits the encrypted data to the national railway group external / internal service network through the 4G / 5G Internet or the 5G private network via the ground data center for decryption, analysis, and application, and provides data sharing services for dynamic train manufacturing enterprises.

[0096] The following will be described in detail in combination with specific embodiments.

[0097] Embodiment one

[0098] As Figure 1 shown, Figure 1 The railway vehicle-ground data security transmission method disclosed by the embodiment of the application is applied to railway data security transmission between a vehicle-mounted data center and a ground data center, and the method comprises the following steps:

[0099] Step 101: At the ground data center and the vehicle-mounted data center, a first key pair and a second key pair are generated according to preset rules.

[0100] Step 102: The standard curve is mapped into a dynamic curve by both sides, and a random number is selected according to communication quality switching.

[0101] Step 103: Based on the first key pair, the second key pair and the random number, three-phase key negotiation is performed on the dynamically generated dynamic curve, and a third key is calculated and transmitted.

[0102] Step 104: Based on the third key, a three-level derivative chain is formed by both sides, and a fourth key is adaptively derived.

[0103] Step 105: The fourth key is used to drive business packet encryption and decryption, and the security transmission of railway vehicle-mounted data is realized.

[0104] In the embodiment of the application, the railway vehicle-ground data security transmission method further comprises the following steps:

[0105] Step 106: The received data packet is decrypted, identity confirmed and integrity checked.

[0106] Step 107: After communication base station switching or communication interruption, the connection is quickly recovered through a handshake.

[0107] Specifically, the railway vehicle-ground data security transmission method in the embodiment of the application can be applied to a motor train unit or a high-speed railway, but the application is not limited to this, and can also be applied to other vehicle-mounted data security transmission methods, and the method specifically comprises the following steps:

[0108] The ground data center pre-sets an asymmetric first key pair based on an SM2 algorithm; the vehicle-mounted data center pre-sets an asymmetric second key pair based on the SM2 algorithm and a first key pair public key; the ground data center and the vehicle-mounted end synchronize time and obtain position information through a Beidou timing system; both sides dynamically generate an SM2 elliptic curve parameter set E' by using an SM3 hash modulation function according to a vehicle-mounted device identifier, a Beidou timing timestamp and position information; a three-stage key negotiation of 'pre-negotiation-switching-post-confirmation' is performed on the curve E'; the ground data center calculates a third key by using SM3 on the vehicle-mounted device identifier and safely transmits the third key to the vehicle-mounted end; both sides use SM3 to derive a session key and a fourth key according to a three-level derivation chain structure of the third key-session key-fourth key, and locally use the SM3 to derive the session key;

[0109] The vehicle-mounted end and the ground end measure vehicle-ground wireless channel state information according to a preset period, quantize the channel state information into random numbers and store the random numbers into a channel state information random number cache pool;

[0110] When the communication condition is good, the random numbers are extracted from the CSI random number cache pool; when the communication condition is poor or the channel state information is invalid, the random numbers output by the random number generator are switched to;

[0111] Both sides adaptively calculate the fourth key according to the random numbers, the vehicle-mounted end drives SM4-OFB mode to encrypt a data packet and sends the data packet by using the fourth key, and the ground end synchronously calculates the fourth key, decrypts the received data packet, confirms the identity and performs integrity check.

[0112] In the specific embodiment of the application, the method further includes a fast connection recovery protocol, and the connection can be recovered through one handshaking, and the state token is generated in the following manner: StateToken=SM3(Client id ||Server id ||K session ||T c ), wherein Client id is a vehicle-mounted client identifier, Server id is a base station server identifier, K session is a current session key, and T c is a current timestamp.

[0113] Specifically, the train-mounted end and the ground data center adopt a unified quantization rule for timing information and position information, the unified quantization rule is that the time is rounded down to 1 second, and the coordinates are rounded down to 1*10 -4度 . The quantized timestamp is updated after a configurable first time interval from the last timestamp; the first time interval is dynamically adjusted according to the train speed and the base station coverage range.

[0114] Wherein, the vehicle-mounted data center and the ground data center adopt the same synchronization algorithm, and when a base station switching event is detected, a re-synchronization quantization operation is triggered.

[0115] Specifically, in the embodiment of the present application, the specific steps of the three-stage key agreement mechanism are as follows:

[0116] Pre-agreement stage: the vehicle-mounted terminal exchanges necessary key materials with the target base station before base station switching;

[0117] Switching stage: the pre-agreement key is used immediately after the communication link is switched;

[0118] Post-confirmation stage: the validity of the key is verified after the switching is completed, and the parameters are adjusted as needed.

[0119] Specifically, in the embodiment of the present application, the dynamic SM2 elliptic curve parameter generation algorithm is as follows: (p', a', b') = H mod (p||a||b||MAC id ||T BDS ||GPS coord ), wherein (p', a', b') is the dynamically generated elliptic curve parameter, (p, a, b) is the standard SM2 elliptic curve parameter, MAC id is the physical address of the vehicle-mounted device, T BDS is the Beidou time stamp, GPS coord is the current GPS coordinate of the train, H mod is the SM3 hash modulation function.

[0120] In the embodiment of the present application, the first key pair and the second key pair are generated according to the preset rules at the ground data center and the vehicle-mounted data center, and step 101 includes:

[0121] The ground data center presets an asymmetric first key pair, the vehicle-mounted data center presets the public key of the asymmetric second key pair and the first key pair, and the two parties realize identity confirmation through encrypted communication using the public key of the first key pair.

[0122] In the embodiment of the present application, the two parties map the standard curve to a dynamic curve, and step 102 includes:

[0123] The two parties synchronize the time through Beidou and obtain the train position information, combine the physical address of the vehicle-mounted device, and use a hash modulation function to jointly construct dynamic elliptic curve parameters.

[0124] In the embodiment of the present application, the random number is selected according to the communication quality, and step 102 includes:

[0125] Both sides measure the channel state of the train-ground wireless link at a certain time interval, and quantify the random number to form a channel state information random number cache pool;

[0126] When generating a data packet, a random number cache pool or a traditional random number is selected according to a channel state quality threshold.

[0127] In the embodiment of the application, the three-stage key negotiation includes the following steps:

[0128] The pre-switching time is calculated based on the train operation trajectory, and the key material is prepared in advance with the next base station;

[0129] Pre-negotiation stage: when the current link is stable, the train-mounted end uses the second public key of the second key pair, and the ground end uses the first public key of the first key pair to complete random number exchange and pre-distribution of third key packaging material on a dynamic curve;

[0130] Switching stage: at the moment when the physical link is switched to a new base station, both sides directly use the material obtained in the pre-negotiation stage without re-hello, thereby ensuring uninterrupted communication.

[0131] Post-confirmation stage: after switching is completed, both sides calculate and verify the label respectively; if the signature verification is successful, the three-stage negotiation is completed.

[0132] In the embodiment of the application, the three-stage key derivation structure includes the following steps:

[0133] The ground data center calculates the third key based on the first key pair and the second key pair based on the password hash algorithm according to the train-mounted equipment ID, and transmits and signs the third key through the public key of the second key pair on the dynamic curve;

[0134] Based on the third key, a three-stage key derivation chain structure is established, wherein the three-stage key derivation chain structure includes: the third key, a plurality of session keys generated based on the third key, and a corresponding fourth key generated for each session key.

[0135] In the embodiment of the application, the fourth key is used to drive the encryption and decryption of the service packet, and the step 105 includes the following steps:

[0136] A one-packet-one-encryption strategy is adopted, and a unique fourth key is derived for the train-mounted data packet based on the encryption algorithm in combination with the session key and the data packet timestamp information;

[0137] The train-mounted data center uses the fourth key driven mode to encrypt and package the data packet, and realizes secure transmission according to the train-mounted transmission protocol;

[0138] The ground data center receives the encrypted data packet, generates the fourth key according to the same encryption algorithm derivation rule using the session key and the data packet header information, and decrypts the data packet using the fourth key.

[0139] In the embodiment of the present application, the step 107 of restoring the connection by one handshaking after the communication base station switching or communication interruption includes:

[0140] The vehicle-mounted client identifier, the base station server identifier, the session key and the current timestamp are used to generate a state token;

[0141] The vehicle-mounted terminal and the ground data center update the packet timestamp information based on the same timestamp rule, and the timestamp is synchronized with the Beidou timing system; and the value of the local key is updated based on the same algorithm;

[0142] According to the state token and the updated timestamp and local key, the communication connection is restored by one handshaking.

[0143] The timestamp update rule is that a new timestamp information is generated after the last timestamp time elapses a first time interval; the first time interval is dynamically adjusted according to the train running speed and the base station coverage range, and is re-synchronized when a switching event is detected.

[0144] More specifically, in the embodiment of the present application, the railway vehicle-ground data security transmission method is as follows:

[0145] The ground data center is preset with a first asymmetric key pair based on the SM2 algorithm, and the vehicle-mounted terminal data center is preset with a second asymmetric key pair based on the SM2 algorithm and a first key pair public key, and the two parties realize identity confirmation through encrypted communication through the public key. The two parties synchronize the time through the Beidou timing and obtain the train position information, combine the vehicle-mounted device physical address (MAC id ), and jointly construct a dynamic SM2 elliptic curve parameter (p', a', b'), and the specific generation method is as follows:

[0146] (p', a', b') = H mod (p || a || b || MAC id || T BDS || GPS coord ), wherein (p', a', b') is the dynamically generated elliptic curve parameter, (p, a, b) is the standard SM2 elliptic curve parameter, MAC id is the vehicle-mounted device physical address, T BDS is the Beidou timing timestamp, GPS coord is the real-time coordinate of the train, H mod is the SM3 hash modulation function.

[0147] The vehicle-mounted terminal data center calculates the pre-switching time based on the train running track and real-time position and speed information, and uses a three-stage key agreement mechanism of pre-negotiation-switching-post-confirmation to prepare key materials with the next base station in advance, and the pre-switching time calculation formula is: Tpre = (D r / v) x η s , where T pre is the pre-handoff preparation advance, D r is the train distance to the next base station boundary, v is the real-time speed of the train, and η s is a safety factor.

[0148] Pre-negotiation phase: When the current link is still stable, the on-board end uses the second public key, and the ground end uses the first public key to complete the pre-distribution of materials such as random number exchange, third key encapsulation on the dynamic curve E'.

[0149] Switching phase: At the moment when the physical link is switched to the new base station, the materials obtained by pre-negotiation are directly used by both parties without the need for a complete handshake again, thereby ensuring uninterrupted communication.

[0150] Post-confirmation phase: After the switching is completed, both parties calculate and verify the tag respectively:

[0151] Tag = SM3(K m || ID bn || T c )

[0152] where K m is the third key, ID bn is the identification of the new base station, and T c is the current timestamp.

[0153] If the signature verification is successful, the three-phase negotiation is completed; otherwise, immediately fall back to the standard curve E, discard all key materials of this session, and re-enter the key negotiation phase to ensure security consistency.

[0154] The ground data center calculates the third key based on the SM3 cryptographic hash algorithm based on the on-board device ID, and transmits and signs it through the public keys of both parties on the dynamic curve E'.

[0155] Based on the third key, a three-level key derivation chain structure (third key-session key-fourth key) is established to achieve efficient key derivation and management. The session key derivation function is:

[0156] K session = SM3(K m , ID bs || T s || T e )

[0157] where K session is the session key, ID bs is the identification of the current base station, and T s and T e are the valid time windows of the session.

[0158] The vehicle-mounted data center decrypts and verifies the message, obtains the third key, and verifies the consistency of the random number. If the consistency is correct, the identity confirmation is successful, otherwise the message is discarded.

[0159] Both sides measure the channel state information of the vehicle-ground wireless link at certain time intervals, quantify the 256-bit random number, and cache it for 10 minutes to form a "channel state information random number cache pool". When the vehicle-mounted device generates a data packet each time, a random number is selected according to the channel state information quality threshold:

[0160]

[0161] Wherein, CSI rand is the random number value taken from the channel state information cache pool, RNG rand is the traditional random number, and k is the set channel state information threshold.

[0162] Then a one-packet-one-encryption strategy is adopted, a unique fourth key is derived for the vehicle-mounted data packet based on the SM3 algorithm combined with the session key and the data packet timestamp, and the fourth key derivation function is:

[0163] K comm = SM3(K session || Seq || T c || Rand)

[0164] Wherein, K comm is the fourth key, Seq is the sequence number, and T c is the current timestamp.

[0165] The vehicle-mounted data center uses the fourth key K comm to drive the SM4-OFB mode to encrypt the data packet and encapsulate it, and realizes secure transmission according to the vehicle-mounted transmission protocol.

[0166] The ground data center receives the encrypted data packet, uses the session key and the data packet header information, generates the fourth key according to the same SM3 password hash algorithm derivation rule, and uses the key to decrypt the data packet. After decryption, the system verifies the identity of the decrypted data through the SM2 algorithm authentication mechanism. If the verification is passed, the entity identity of the data packet is not tampered with, otherwise the data packet is discarded; further compare the decrypted data with the original data, if the data content is consistent, the confidentiality of the data packet is guaranteed, otherwise the data packet is discarded.

[0167] To solve the problem of connection interruption caused by frequent base station switching, the method also includes a fast connection recovery protocol, which can recover the connection through a handshake, and the state token generation method is:

[0168] StateToken = SM3(Clientid ||Server id ||k session ||T c )

[0169] wherein Client id is the vehicle client identity, Server id is the base station server identity, k session is the session key, and T c is the current timestamp.

[0170] In the method, the vehicle end and the ground data center update the packet timestamp information based on the same rule, and the timestamp is synchronized with the Beidou timing system.

[0171] The timestamp update rule is that a new timestamp information is generated after the previous timestamp time elapses a first time interval; the first time interval is dynamically adjusted according to the train running speed and the base station coverage range, and is re-synchronized when a switching event is detected.

[0172] The vehicle end and the ground data center update the value of the local key based on the same algorithm.

[0173] Preferably, the following takes the example of the dynamic train set vehicle data security transmission as an example, as shown in Figure 2 , the network architecture of the dynamic train set vehicle data security transmission system provided by the present application is provided. For the sake of convenience, only the parts related to the present embodiment are listed.

[0174] In the embodiments of the present disclosure, the dynamic train set vehicle data security transmission system adopts a method combining SM2, SM3 and SM4 encryption algorithms. The security transmission system involves a sender, a transmission channel and a receiver. According to the characteristics of the dynamic train set vehicle data transmission system, the use method of the cryptographic algorithm is as follows:

[0175] a) The asymmetric cryptographic algorithm uses the SM2 elliptic curve cryptographic algorithm, which is used for identity authentication, digital signature, key agreement, etc. Based on Beidou timing and device fingerprint, the curve parameters are dynamically generated to enhance the anti-precomputation and replay ability.

[0176] b) The symmetric cryptographic algorithm uses the SM4 block cipher algorithm OFB mode, which is used for encryption protection of vehicle data. The SM4 algorithm is used for encryption protection of key agreement data.

[0177] c) The cryptographic hash algorithm uses the SM3 cryptographic hash algorithm, which is used for key derivation, state token and verification tag generation at all levels.

[0178] d) The random number generator and the channel state information random number jointly provide key entropy.

[0179] AsFigure 3 As shown, the embodiment of the present disclosure provides a motor train unit on-board data security transmission method, and the specific method is as follows:

[0180] Firstly, the standard parameters (p, a, b, G, n) of the algorithm elliptic curve in SM2 are defined, wherein the meanings of the elements are as follows:

[0181] p: a large prime number, defining the finite field F p .

[0182] a and b: coefficients in the elliptic curve equation y 2 = x 3 + ax + b.

[0183] G: the base point on the elliptic curve, serving as the basis for all key generation and encryption calculation.

[0184] n: the order of the base point G, the smallest positive integer n is selected to make nG = 0, wherein O is the infinite point.

[0185] Based on the Beidou timing and the device fingerprint, the system dynamically generates the curve parameters in the following manner:

[0186] (p', a', b') = H mod (p||a|||b||MAC id ||T BDS ||GPS coord )

[0187] Wherein, (p', a', b') is the dynamically generated elliptic curve parameter, (p, a, b) is the standard SM2 elliptic curve parameter, MAC id is the device physical address, T BDS is the Beidou timing timestamp, GPS coord is the current GPS coordinate of the train, H mod is the SM3 hash modulation function. The base point G and the order n remain unchanged to ensure the basic cryptographic properties.

[0188] Dynamic parameter verification steps:

[0189] 1. Verify that p' is a prime number and meets the specific length requirement;

[0190] 2. Verify that the curve equation y 2 = x 3 + a'x + b'(mod p') defines a valid elliptic curve;

[0191] 3. Verify that the base point G is still valid on the new curve;

[0192] 4. Verify that the nG = O relationship still meets the requirement under the new parameters,

[0193] Step two, key pre-setting and predictive preparation, the ground data center pre-sets a pair of SM 2 asymmetric first key pair (PA, SA), and pre-sets the first public key PA into the vehicle-mounted data center device.

[0194] Further, the ground data center randomly selects a positive integer SA∈[1, n-1] as the first private key of the ground data center, calculates the first public key PA=SA·G according to SA and the base point G, wherein · is the scalar multiplication operation on the elliptic curve.

[0195] The vehicle-mounted data center generates a pair of asymmetric SM 2 second key pair (PB, SB), and generates a random number for identity authentication by a true random number generator locally.

[0196] Further, the vehicle-mounted data center randomly selects a positive integer SB∈[1, n-1] and SB≠SA as the second private key of the vehicle-mounted data center, calculates the second public key PB=SB·G according to SB and the base point G, wherein · is the scalar multiplication operation on the elliptic curve.

[0197] Further, the vehicle-mounted data center encrypts {PB, R device} on the dynamic curve E' using the first public key PA, wherein R device is the vehicle-mounted random number, and transmits the encrypted result to the ground data center, and the ground data center decrypts and verifies the random number using the first private key SA after receiving the information, to realize vehicle-mounted identity confirmation.

[0198] To adapt to the high-speed mobile scene, the system realizes a predictive key material preparation mechanism:

[0199] 1. Based on the known train running track, combined with real-time position and speed information, the pre-switching time T pre is calculated:

[0200] T pre =(D r / v)×η s

[0201] Wherein, D r is the distance of the train to the next base station boundary, v is the real-time speed of the train, and η s is the safety factor.

[0202] 2. When the system detects that the train is about to enter the coverage range of the next base station (after the current time + T pre ), the pre-key negotiation process with the next base station is triggered.

[0203] Step three, three-stage key negotiation mechanism, the vehicle-ground key negotiation adopts a three-stage mechanism (pre-negotiation-switching-post-confirmation), and the specific process is as follows:

[0204] The first stage: pre-negotiation, the vehicle-mounted data center generates a random number N1 by a random number generator, encrypts the message N2 on the dynamic curve E' using the first public key PA, generates a message (ID || PA(N1) || PB || SB(N2)), and sends it to the ground data center associated with the current base station. At the same time, when the prediction system triggers a pre-negotiation request, the vehicle-mounted terminal sends a pre-negotiation message (ID || PA(N1) + PB + T est ) to the next base station, wherein T est is the predicted arrival time.

[0205] After the ground data center receives the message, it decrypts the message using the first private key SA to obtain the random number N1 and the message N2. If the decryption is successful, the correctness of the second public key PB of the vehicle-mounted terminal is passed, otherwise the message is discarded. The ground data center locally generates a random number N3 by a random number generator, encrypts the message N2 on the dynamic curve E' using the second public key PB According to the vehicle-mounted device ID, the third key K m is calculated using the SM3 cryptographic hash algorithm, N1 is encrypted using K m , and a message is constructed and sent back to the vehicle-mounted data center.

[0206] After the next base station receives the pre-negotiation request, it prepares the corresponding key material, pre-calculates the third key K m+1 = SM3(ID || N 3,n+1 ) with the vehicle-mounted device, and returns a confirmation message to the vehicle-mounted terminal.

[0207] After the vehicle-mounted data center receives the message, it decrypts to obtain N3 using the second private key SB, and then obtains the third key K m . The consistency of N1 is verified. If the consistency is passed, the key negotiation is successful. At the same time, the vehicle-mounted terminal saves the key material pre-negotiated by the next base station for switching, otherwise the message is discarded.

[0208] The second stage: switching, when the train moves from the current base station coverage area to the next base station coverage area, the following process is triggered:

[0209] 1. Detecting the change of communication signal, immediately start base station switching;

[0210] 2. The vehicle-mounted terminal immediately initiates the first communication using the pre-negotiated key K m+1 ;

[0211] 3. The next base station (now changed to the current base station) uses the pre-stored corresponding key material to process the request;

[0212] 4. Due to the pre-negotiation mechanism, there is no need to perform complete key negotiation, and a one-time handshake can establish a secure connection

[0213] Third stage: Post-confirmation, after the switch is completed, the new current base station will inform the ground data center of the communication establishment, and the vehicle-mounted terminal and the new base station will calculate respectively:

[0214] Tag=SM3(K m ||ID bn ||T c )

[0215] If the tags of both parties match, the negotiation is completed, otherwise, it will be rolled back to the standard curve E, the session key material will be discarded and re-entered into the pre-negotiation stage.

[0216] Further, the key negotiation of the embodiment includes two distribution methods: offline distribution and online negotiation, wherein:

[0217] 1. Offline distribution method, the vehicle-mounted device obtains the third key K m in advance through physical distribution method.

[0218] 2. Online negotiation method, in the real-time transmission process, the vehicle-ground system generates the third key K m through step three key negotiation and then transmits it through a secure channel.

[0219] Step four, three-level key derivation chain structure, the embodiment adopts a three-level key derivation chain structure, i.e. the third key (K m ), the session key (K session ) and the fourth key (K comm ), which reduces the complexity of key negotiation and improves security:

[0220] 1. After the vehicle-mounted terminal data center obtains the third key K m , the session key is derived:

[0221] K session =SM3(K m ,ID bs ||T s ||T e )

[0222] Wherein ID bs is the base station identifier, T s and T e are the session valid time window.

[0223] 2. The vehicle-ground parties measure the channel state information every other time interval, quantify the 256-bit random number and cache for 10 minutes to form a channel state information random number cache pool.

[0224] 3. When sending a data packet, a random number is selected according to the threshold value k:

[0225]

[0226] 4. Derive a unique fourth key for each data packet based on the session key and the random number:

[0227] K comm = SM3(K session || Seq || T c || Rand)

[0228] where Seq is the sequence number, T c is the current timestamp, and Rand is the random number.

[0229] The on-board device generates data packets based on the on-board operation state data of the motor train unit at regular intervals and transmits them in order. To ensure transmission efficiency, the on-board device encapsulates the on-board data according to the TJ / CL441-2022 specification.

[0230] In the embodiments of the present disclosure, the ground data center and the on-board terminal maintain the same key derivation rules.

[0231] Step five, fast connection recovery protocol: To solve the communication interruption problem in base station handover, the present embodiment designs a fast connection recovery protocol:

[0232] 1. State token generation:

[0233] StateToken = SM3(Client id || Server id || Session key || T c )

[0234] where Client id is the on-board client identifier, and Server id is the base station server identifier.

[0235] 2. Connection recovery process:

[0236] a. When handover or interruption occurs, the on-board terminal sends a recovery request containing the StateToken;

[0237] b. The base station verifies the validity of the StateToken. If valid, it directly recovers the connection state;

[0238] c. One handshaking can complete connection recovery without the need for complete key agreement.

[0239] Step six, on-board data encryption: The on-board data security module adopts a one-packet-one-encryption strategy, uses the fourth key K comm to perform encryption operations on data packets through the SM4 algorithm OFB mode, encapsulates according to the on-board transmission protocol, and transmits through a secure channel.

[0240] In this embodiment, the data is encrypted and encapsulated in a data frame format and transmitted, and an example of a vehicle-mounted data frame encryption format is shown in Figure 4

[0241] Step seven, vehicle-mounted data secure transmission, vehicle-mounted encrypted data is transmitted to the ground data center through 4G / 5G or 5G private network, and the data is received by the access node of the ground data center, and after receiving, the local data security gateway decrypts the data according to the third key K m According to the data packet header information, the fourth key K comm is calculated in real time, and the data packet is decrypted and processed, and the decrypted data can be provided to different application systems for analysis, transmission and application.

[0242] Further, the embodiment extends the vehicle-mounted data transmission protocol based on Q / CR 675-2022 Appendix B, which is used for third key online negotiation and ground data center decryption exception response, and the protocol extension is shown in Figure 5

[0243] As described above, the method of the present application can be better implemented.

[0244] Compared with the prior art, the method of the present application proposes a secure transmission method supporting predictive key material preparation, three-stage key negotiation, dynamic SM2 curve parameter generation based on Beidou timing and device fingerprint, periodic measurement of channel state information and establishment of a random number cache pool, an adaptive fourth key derivation mechanism, and fast connection recovery, which solves the key negotiation interruption and security transmission efficiency problem in the high-speed mobile scene.

[0245] Embodiment two

[0246] As shown in Figure 6 The embodiment of the present application provides a railway train-ground data secure transmission device, which comprises:

[0247] The data security module 61 is used to generate a first key pair and a second key pair according to a preset rule; wherein the vehicle-mounted data security module is also responsible for the encrypted transmission of vehicle-mounted data;

[0248] The position prediction unit 62 is used to calculate a pre-switching time based on the train operation trajectory, and to perform key material preparation with the next base station in advance;

[0249] The verification module 63 is used to complete identity authentication and signature; specifically, in the embodiment of the present application, identity authentication and signature are completed based on SM2 in E';

[0250] ​​The key derivation module 64 is used to perform three-stage key agreement on a dynamically generated dynamic curve, calculate and securely transmit a third key, and form a three-stage derivation chain based on the third key to adaptively derive a fourth key between the vehicle-mounted device and the ground data center; the fourth key is used to drive the encryption and decryption of service packets to achieve secure transmission of railway vehicle-mounted data.

[0251] The data encryption module 65 derives a three-stage key structure including the third key, the session key and the fourth key for the EMU and the vehicle-mounted device according to the EMU model, the vehicle-mounted device ID, the Beidou time stamp and the location information, respectively.

[0252] The fast connection recovery module 66 is used to recover the connection through a handshake after base station switching or communication interruption.

[0253] The sending module 67 is used to send the encrypted service data.

[0254] The device further comprises a data encryption program running on the vehicle-mounted device to implement the encryption method of the EMU vehicle-mounted data according to the first aspect.

[0255] In the device, the data security module is responsible for updating the time stamp information, and the updating is completed before data generation and encryption according to the previous time stamp time and a preset time interval.

[0256] The device further comprises a time interval calculation module, which is internally provided with an algorithm for adjusting the first time interval and sends the time interval value generated according to the algorithm to the vehicle-mounted data security module.

[0257] Embodiment Three

[0258] As shown in Figure 7 The present application provides a key management mechanism for secure transmission of EMU vehicle-mounted data, which is arranged in a ground data center to maintain a multi-stage key management mechanism and a multi-state key life cycle management, and the mechanism comprises:

[0259] The first key pair and the second key pair are used for identity authentication and key agreement between the ground data center and the EMU vehicle-mounted device;

[0260] The third key is generated based on the first key pair and the second key pair to realize derivation of a session key;

[0261] The session key is derived from the third key and is associated with a base station to realize security at the session level;

[0262] The fourth key is adaptively derived from the session key in combination with a random number to realize encryption of data packets.

[0263] The multi-state key life cycle management includes a generation state, a pre-activation state, an activation state, an aging state, an archiving state and a destruction state.

[0264] The mechanism further includes generation, distribution, update and destruction rules of the keys, which improves the security and management efficiency of the keys in their life cycle.

[0265] The mechanism also includes a predicted key update triggering mechanism based on time triggering, distance triggering, switching number triggering and security risk triggering.

[0266] In particular, the key management mechanism for safe transmission of data on board of a motor train unit provided by the embodiment of the application covers a first key pair of a ground data center, a second key pair of a data center on board, a third key K m , a session key K session , a fourth key K comm and other multi-level key management mechanisms, as shown in the hierarchical structure Figure 5 , for management in a complete life cycle.

[0267] The state conversion of the key life cycle includes:

[0268] Generation state: the initial generation stage of the key, which is generated by a security module

[0269] Pre-activation state: the key material has been prepared but not yet put into use (applicable to pre-negotiation scenarios)

[0270] Activation state: the key is in use and can be used for encryption and decryption operations

[0271] Aging state: the key is close to the effective period, and the system starts to prepare a replacement key

[0272] Archiving state: the key is no longer used for encryption, but can be used for decryption of historical data

[0273] Destruction state: the key is completely deleted from the system

[0274] The key management requirements are shown in Table 1 as follows:

[0275] Table 1

[0276]

[0277]

[0278] The function of the predicted key update triggering mechanism is as follows:

[0279]

[0280] Wherein, T m is the maximum time period, and D thresholdis a distance threshold value, N handoff is a switching times threshold value, L threshold is a risk level threshold value.

[0281] Embodiment Four

[0282] As Figure 8 shown, the embodiments of the present application provide a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the steps of the railway train-ground data security transmission method described above.

[0283] Specifically, the disclosure provides a motor train unit on-board data security transmission device medium, as shown in Figure 8 the device medium can include a storage medium 71, an on-board device 72, a data security transmission device 73 and an external device 74, wherein the storage medium 71, the on-board device 72, the data security transmission device 73 and the external device 74 can be connected to realize communication through a bus or other ways, Figure 7 taking the bus connection as an example.

[0284] In the device medium, the storage medium 71 as a kind of computer readable storage medium, it can be used to store software programs, executable programs, etc., such as the corresponding encryption program instruction in the embodiments of the present application, to execute the data encryption method described in the embodiments.

[0285] In the device medium, the on-board device 72 as the data acquisition and processing device of the on-board end, is used to generate raw data packet messages. The on-board device 72 obtains the running state data of the motor train unit and converts it into data frames for subsequent encryption transmission. The on-board device 72 transmits the collected data to the data security transmission device 73 through communication with the data security transmission device 73 to complete the encryption and packaging of the data.

[0286] In the device medium, the data security transmission device 73 can include the above-mentioned device modules to call the encryption program instructions and keys in the storage medium 71 to execute the encryption processing of the motor train unit on-board data. At the same time, the device has the functions of verification and decryption to verify the data integrity.

[0287] In the device medium, the external device 74 can include a display device, a data storage server or other data interface device, which is used for external communication. The external device 74 can communicate with the on-board device 72 and the data security transmission device 73 through the bus to realize the visualization processing and management of the data, or to provide further analysis of the received encrypted data.

[0288] Embodiment Five

[0289] As Figure 9As shown, this application embodiment provides a ground data center that employs the above-described railway vehicle-to-ground data secure transmission method. The ground data center is configured to execute the following steps:

[0290] In the ground data center, the first key pair is generated according to preset rules;

[0291] The ground data center receives the second private key signature message and the second public key sent by the vehicle-mounted data center, verifies the second private key signature message, generates a third random number, decrypts the first random number using the first private key, encrypts the sum of the first random number and the third random number using the second public key, and calculates and generates the third key.

[0292] The ground data center derives a fourth key based on the third key and an adaptive random number; the fourth key drives the encryption and decryption of business messages, enabling secure transmission of railway vehicle data.

[0293] Example 6

[0294] like Figure 9 As shown, this embodiment of the invention provides an on-board data center, employing the railway vehicle-to-ground data security transmission method described above. The on-board data center is configured to execute the following steps:

[0295] In the vehicle-mounted data center, a first key pair is generated according to preset rules; a second key pair is then automatically generated.

[0296] The vehicle-mounted data center generates a first random number, encrypts the first random number using a first public key, signs the encrypted message using a second private key, and sends it to the ground data center.

[0297] The vehicle-mounted data center receives the third key sent by the ground data center, and uses the second private key to decrypt the sum of the first and third random numbers to obtain the third key;

[0298] The on-board data center derives a fourth key based on a third key and an adaptive random number; the fourth key drives the encryption and decryption of business messages, thereby achieving secure transmission of railway on-board data.

[0299] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0300] The above-described embodiments are merely illustrative of several embodiments of the present application, which are described in more detail and in a specific and detailed manner, but should not be construed as limiting the scope of the patent. It should be noted that for those skilled in the art, several modifications and improvements can be made without departing from the concept of the present application, and these are all within the scope of the present application. Therefore, the scope of protection of the patent of the present application should be subject to the appended claims.

Claims

1. A railway vehicle-ground data secure transmission method, characterized in that, The method is applied to railway data security transmission between a vehicle-mounted data center and a ground data center, and comprises the following steps: At both the ground data center and the vehicle-mounted data center, a first key pair and a second key pair are generated according to preset rules; Both sides generate a dynamic curve by mapping a standard curve, and select random numbers according to communication quality; Based on the first key pair, the second key pair and the random numbers, three-phase key negotiation is performed on the dynamically generated dynamic curve to calculate and transfer a third key; Based on the third key, both sides form a three-level derived chain to adaptively derive a fourth key; The fourth key is used to drive business packet encryption and decryption to realize safe transmission of railway vehicle-mounted data.

2. The method of claim 1, wherein, The method further comprises the following steps: Decrypted, identity-confirmed and integrity-verified data packets are received; After communication base station switching or communication interruption, a handshake is performed to quickly recover the connection.

3. The method of claim 1 or 2, wherein, At both the ground data center and the vehicle-mounted data center, a first key pair and a second key pair are generated according to preset rules, which comprises the following steps: The ground data center presets an asymmetric first key pair, and the vehicle-mounted data center presets an asymmetric second key pair and a public key of the first key pair, and both sides perform encrypted communication through the public key of the first key pair to realize identity confirmation.

4. The method of claim 1 or 2, wherein, Both sides generate a dynamic curve by mapping a standard curve, which comprises the following steps: Both sides synchronize time through Beidou timing and obtain train position information, combine the physical address of the vehicle-mounted device, use a hash modulation function, and jointly construct a dynamic elliptic curve parameter.

5. The method of claim 1 or 2, wherein, Both sides measure the channel state of the train-ground wireless link every certain time interval, quantify random numbers, and form a channel state information random number cache pool; When generating a data packet, a random number cache pool or a traditional random number is selected according to a channel state quality threshold. The three-phase key negotiation comprises the following steps:

6. The method of claim 1 or 2, wherein, Based on the train running track, a pre-switching time is calculated, and key materials are prepared with the next base station in advance; Pre-negotiation stage: when the current link is stable, the vehicle-mounted end uses a second public key of the second key pair, and the ground end uses a first public key of the first key pair to complete random number exchange and pre-distribution of third key packaging materials on the dynamic curve; Switching stage: at the moment when the physical link is switched to a new base station, both sides directly use the materials obtained in the pre-negotiation stage without re-complete handshaking, thereby ensuring uninterrupted communication; Post-confirmation stage: after switching is completed, both sides calculate and verify labels respectively; if the signature verification is successful, the three-phase negotiation is completed. The three-level key derivation structure comprises the following steps:

7. The method of claim 1 or 2, wherein, The ground data center calculates a third key based on the first key pair and the second key pair according to a password hash algorithm based on the ID of the vehicle-mounted device, and the third key is encrypted and transmitted and signed on the dynamic curve through the public key of the second key pair of both sides; Based on the third key, a three-level key derivation chain structure is established, wherein the three-level key derivation chain structure comprises: the third key, a plurality of session keys generated based on the third key, and a corresponding fourth key generated for each session key. The fourth key is used to drive business packet encryption and decryption, which comprises the following steps:

8. The method of claim 1 or 2, wherein, ​ Adopting one package one secret strategy, combining session key and data packet timestamp information, based on encryption algorithm to derive unique fourth key for vehicle data packet; The vehicle data center uses fourth key driven mode to encrypt and package data packets, and realizes safe transmission according to vehicle transmission protocol; The ground data center receives encrypted data packets, uses session key and data packet header information, generates fourth key according to the same encryption algorithm algorithm derivation rule, and uses the fourth key to decrypt the data packets.

9. The method of claim 2, wherein, The method further includes key generation, distribution, update and destruction rules, which improve the security and management efficiency of the key in its life cycle; The method further includes a predicted key update trigger mechanism based on a predicted key update trigger mechanism, which integrates time trigger, distance trigger, switching times trigger and security risk trigger multiple trigger conditions. The program is executed by the processor to realize the steps of the railway vehicle-ground data security transmission method in any one of claims 1-9. The device comprises: A data security module for generating a first key pair and a second key pair according to a preset rule; 10. A railway vehicle-to-ground data security transmission device, characterized in that, A location prediction unit for calculating a pre-switching time based on a train running track and preparing key materials with a next base station in advance; A key derivation module for performing three-stage key agreement on the dynamically generated dynamic curve, calculating and securely transmitting a third key; based on the third key, the vehicle end device and the ground data center form a three-level derivation chain to adaptively derive a fourth key; the fourth key is used to drive business message encryption and decryption to realize safe transmission of railway vehicle data; A verification module for completing identity authentication and signature; A fast connection recovery module for recovering connection through a handshake after base station switching or communication interruption. The method includes multi-state key life cycle management: First key pair, second key pair: used for identity authentication and key agreement between ground data center and vehicle end of motor train unit; 11. A key management method for secure transmission of data on board of a railway vehicle, characterized in that, Third key: generated based on the first key pair and the second key pair, used to realize session key derivation root; Session key: derived from the third key, associated with the base station, used for session level security; Fourth key: adaptively derived from the session key combined with random number, used to realize data packet encryption; The multi-state key life cycle management includes: generation state, pre-activation state, activation state, aging state, archiving state and destruction state; The method further includes key generation, distribution, update and destruction rules to improve the security and management efficiency of the key in its life cycle; The method further includes a predicted key update trigger mechanism based on a predicted key update trigger mechanism, which integrates time trigger, distance trigger, switching times trigger and security risk trigger multiple trigger conditions. The program is executed by the processor to realize the steps of the railway vehicle-ground data security transmission method in any one of claims 1-9. ​ 12. A computer readable storage medium having stored thereon a computer program, characterized in that, ​ 13. A ground data center, characterized by, The railway vehicle-ground data security transmission method according to any one of claims 1-9, wherein the ground data center is configured to perform the following steps: The ground data center generates a first key pair according to a preset rule; The ground data center receives a second private key signature message and a second public key sent by the vehicle-mounted data center, verifies the second private key signature message, generates a third random number, decrypts the first random number using the first private key, encrypts the sum of the first random number and the third random number using the second public key, and calculates a third key; The ground data center derives a fourth key based on the third key and an adaptive random number; The fourth key is used to drive the encryption and decryption of service packets, thereby realizing the secure transmission of railway vehicle-mounted data.

14. A vehicle-mounted data center, comprising: The railway vehicle-ground data security transmission method according to any one of claims 1-9, wherein the vehicle-mounted data center is configured to perform the following steps: The vehicle-mounted data center generates a first key pair according to a preset rule; and generates a second key pair; The vehicle-mounted data center generates a first random number, encrypts the first random number using a first public key, encrypts a second private key signature message using a second private key signature, and sends the second private key signature message to the ground data center; The vehicle-mounted data center receives a third key sent by the ground data center, decrypts the sum of the first random number and a third random number using the second private key, and obtains the third key; The vehicle-mounted data center derives a fourth key based on the third key and an adaptive random number; and uses the fourth key to drive the encryption and decryption of service packets, thereby realizing the secure transmission of railway vehicle-mounted data.