Railway signal system data security one-way ferry system and two-way and one-way interactive control method
By using a dedicated mobile security smart terminal and a collaborative architecture-based data security one-way transfer system, the data interaction security problem between the railway signaling system and mobile terminals has been solved. This system achieves secure one-way transmission of highly sensitive data and efficient transmission of low-sensitivity data, ensuring precise control and full lifecycle security management of terminals, and meeting the high security requirements of the railway signaling system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING DAOER TECH CO LTD
- Filing Date
- 2025-10-21
- Publication Date
- 2026-04-14
AI Technical Summary
The data interaction between railway signaling systems and mobile terminals suffers from insufficient security protection, lack of hierarchical data protection, weak terminal control capabilities, and imperfect traceability and auditing mechanisms. In particular, security vulnerabilities are easily formed in two-way data interaction, making it difficult to meet the high security requirements of railway signaling systems.
It employs a dedicated mobile security smart terminal, a mobile virtual private network, a hierarchical protection access subsystem, a one-way reinforcement bridging subsystem, and a scenario-based security management subsystem. The physical layer achieves one-way isolation through forward/reverse digital diodes in the one-way reinforcement bridging subsystem. Combined with SM4 encryption and hash value comparison in the one-way data verification module, the encryption strategy is dynamically adjusted to achieve hierarchical data protection and full lifecycle management. The scenario-based security management subsystem records the traceability chain and monitors the diode status.
It enables secure data transfer in railway signaling systems, ensuring that highly sensitive data is transmitted one-way without being tampered with, low-sensitivity data is transmitted efficiently, terminals are precisely controlled, and the entire lifecycle of security is managed, thus meeting the high availability and high security requirements of railway signaling systems.
Smart Images

Figure CN121357210B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of railway signaling system technology, specifically to a one-way data security shuttle system for railway signaling systems and methods for two-way and one-way interactive control. Background Technology
[0002] Railway signaling systems are core infrastructure ensuring the safety and efficiency of train operations. High-security systems such as TDCS (Train Dispatch Control System) and CTC (Centralized Dispatch System) undertake critical functions such as transmitting train dispatching instructions and monitoring operational status. The security of their data interaction is directly related to railway transportation safety. With the advancement of railway informatization, dedicated mobile security smart terminals are increasingly used in signaling system maintenance and dispatching instruction reception scenarios. There is an urgent need to establish secure and reliable data transmission channels to achieve compliant data interaction between mobile terminals and the signaling system.
[0003] In existing technologies, the data interaction between railway signaling systems and mobile terminals has the following problems:
[0004] 1. Insufficient security protection: Traditional data transmission mostly uses general network protocols and lacks dedicated protection mechanisms for railway signal scenarios, making it difficult to resist security threats such as targeted attacks and data tampering. In particular, it is prone to security vulnerabilities in two-way data interaction.
[0005] 2. Lack of data hierarchical protection: The signal system contains both highly sensitive data (such as dispatch instructions) and low-sensitivity data (such as equipment maintenance information). Existing technologies mostly adopt a unified encryption strategy, resulting in insufficient protection strength for highly sensitive data or low transmission efficiency for low-sensitivity data.
[0006] 3. Weak terminal control capabilities: The access status, location information and operation permissions of mobile terminals lack linkage control. Terminals may still interact with data after leaving the preset operation area, which poses a risk of data leakage.
[0007] 4. Inadequate traceability and auditing mechanisms: The data transmission process lacks full-link recording, making it difficult to trace the data source and transmission path once a security incident occurs. Furthermore, there is insufficient monitoring of the status of key equipment (such as one-way transmission components), making it impossible to respond to abnormal situations in a timely manner.
[0008] Therefore, in response to the high security requirements of railway signaling systems, designing a one-way shuttle system and control method that supports hierarchical data protection, precise terminal control, and full-link traceability has become a key requirement for ensuring the secure interaction of railway signaling data. Summary of the Invention
[0009] The purpose of this invention is to provide a one-way data security shuttle system for railway signaling systems and a two-way and one-way interactive control method to solve the problems of data interaction between existing railway signaling systems and mobile terminals mentioned in the background art.
[0010] To achieve the above objectives, the present invention provides the following technical solution: a one-way data security shuttle system for railway signaling systems, comprising a dedicated mobile security intelligent terminal, a mobile virtual private network, a hierarchical protection access subsystem, a one-way enhanced shuttle subsystem, and a scenario-based security management subsystem;
[0011] The dedicated mobile security smart terminal communicates with the hierarchical protection access subsystem via the mobile virtual private network. The hierarchical protection access subsystem communicates with the one-way enhanced shuttle subsystem. The one-way enhanced shuttle subsystem communicates with the railway signaling system. The one-way enhanced shuttle subsystem prioritizes adaptation to high-security-level systems, including but not limited to the TDCS system and the CTC system. The scenario-based security management subsystem is electrically connected to the dedicated mobile security smart terminal, the mobile virtual private network, the hierarchical protection access subsystem, and the one-way enhanced shuttle subsystem to achieve dedicated control in the one-way shuttle scenario.
[0012] The unidirectional reinforcement ferry subsystem includes a front-end unidirectional protocol interface unit, a forward digital diode, a reverse digital diode, a rear-end unidirectional protocol interface unit, and a unidirectional data verification module. The front-end unidirectional protocol interface unit only retains a unidirectional adapter port for receiving mobile side data and transmitting signal side data. The output of the front-end unidirectional protocol interface unit is connected to the input of the reverse digital diode. The input of the front-end unidirectional protocol interface unit is selectively connected to the output of the forward digital diode. The output of the reverse digital diode is connected to the rear-end unidirectional protocol interface unit. The unidirectional data verification module is connected in series between the reverse digital diode and the rear-end unidirectional protocol interface unit. The unidirectional data verification module is used to verify the integrity of the data transmitted from the signal system to the terminal.
[0013] The hierarchical protection access subsystem includes a basic protection layer, a deep protection layer, and an access protection layer, which are divided according to risk level. The basic protection layer is a firewall, the deep protection layer includes intrusion detection equipment and antivirus firewall, and the access protection layer is an access controller with terminal security status prediction function. Each protection layer cooperates in protection according to the logic of prioritizing unidirectional data transmission and secondary verification for bidirectional data transmission.
[0014] Preferably, the dedicated mobile security smart terminal has a built-in one-way data receiving module. The one-way data receiving module is only activated in one-way interaction mode. The one-way data receiving module is used to receive and parse highly sensitive data sent by the signal system. The highly sensitive data includes, but is not limited to, scheduling instructions from the TDCS system and the CTC system. The one-way data receiving module does not have a data return interface.
[0015] The dedicated mobile security smart terminal is also equipped with a de-segmentation data encryption unit, which is used to store one-way data that has not been processed in time after de-segmentation.
[0016] The encryption key is bound to the location of the dedicated mobile security smart terminal, and the data is automatically decrypted when the dedicated mobile security smart terminal returns to the work area.
[0017] Preferably, the dedicated mobile security smart terminal's one-way data receiving module has a read-only locking function. The highly sensitive data received by the one-way data receiving module only supports viewing operations and does not support copying, forwarding, or screenshot operations. Furthermore, the data viewing records will be synchronously uploaded to the scenario-based security management subsystem to achieve full lifecycle control of one-way data.
[0018] Preferably, the mobile virtual private network (MVPB) employs different encryption algorithms for encryption protection under different data sensitivity transmission scenarios, wherein:
[0019] The SM4 algorithm is used to encrypt highly sensitive data when transmitting it. The highly sensitive data includes TDCS system data and CTC system data, and the highly sensitive data corresponds to a one-way transmission scenario.
[0020] The SM3 algorithm is used to encrypt low-sensitivity data when transmitting it. The low-sensitivity data includes signal centralized monitoring and maintenance data, and the low-sensitivity data corresponds to a two-way transmission scenario.
[0021] The scenario-based security management subsystem automatically triggers the mobile virtual private network to switch to the corresponding encryption algorithm based on the current data interaction mode.
[0022] Preferably, the front-end unidirectional protocol interface unit of the unidirectional reinforcement ferry subsystem is equipped with a unidirectional protocol stripping module. The unidirectional protocol stripping module retains only the receiving and transmitting logic that matches the dedicated protocol of the signal system, such as the logic that matches the TSRS-CTC interface protocol, while removing redundant fields of general network protocols.
[0023] The unidirectional reinforcement ferry subsystem is equipped with a unidirectional protocol interface unit. The unidirectional protocol restoration module only restores the verified unidirectional data into a format that the signal system can recognize, and does not support reverse protocol conversion.
[0024] Preferably, the scenario-based security management subsystem includes a dedicated one-way ferry management module, which enables one-way data traceability and diode status monitoring, wherein:
[0025] Regarding one-way data traceability, the dedicated one-way ferry management module records relevant information for each piece of one-way data. This information includes the signal system data source address, one-way data verification result, receiving terminal identifier, and transmission timestamp. By recording this information, an immutable one-way data traceability chain is formed.
[0026] Regarding diode status monitoring, the unidirectional ferry dedicated management module monitors the on / off status of the forward and reverse digital diodes in real time. When the reverse digital diode is abnormally disconnected, the unidirectional ferry dedicated management module immediately triggers the hierarchical protection access subsystem to block all terminal access.
[0027] Preferably, the hierarchical protection access subsystem includes a mapping table of preset operating scenarios and protection strategies for the access protection layer, wherein:
[0028] When the dedicated mobile security smart terminal is used to receive data from the TDCS system and CTC system in one direction, the access verification item adds a matching degree verification between the terminal and the jurisdiction of the signal system;
[0029] When the dedicated mobile security smart terminal is used for bidirectional transmission of maintenance data, the access verification item is simplified to terminal hardening status verification in order to achieve scenario-based access control.
[0030] The data security two-way interactive control method based on the railway signaling system's data security one-way shuttle system includes the following steps:
[0031] S1) The dedicated mobile security smart terminal initiates a network access request. The mobile virtual private network first verifies the legality of the terminal's dual identifiers, which are the dedicated IoT card and the terminal serial number. This verification process is a one-time authentication by the operator.
[0032] S2) Terminal access hierarchical protection access subsystem, the access protection layer predicts the terminal security status. The prediction content includes the operating status of the hardening components and the matching degree between the current location and the preset work area. Only when the prediction result is low risk, the lightweight detection of the deep protection layer is triggered. This lightweight detection is a basic port scan. After the detection is passed, the platform side secondary access is completed.
[0033] The S3 scenario-based security management subsystem issues bidirectional mode commands to control the simultaneous activation of the forward and reverse digital diodes of the unidirectional enhanced ferry subsystem, and triggers the mobile virtual private network to switch the encryption level to the basic national cryptographic SM3.
[0034] S4) When data is transmitted bidirectionally, the hierarchical protection access subsystem performs additional format pre-verification and sensitive field filtering operations on the data sent from the mobile side to the signal side, and performs redundant information stripping operations on the data sent from the signal side to the mobile side.
[0035] S5) The scenario-based security management subsystem records associated logs during the bidirectional transmission process. The associated logs include data type, transmission duration, and terminal operator information, thereby forming a bidirectional data interaction traceability chain.
[0036] The data security one-way interactive control method based on the railway signaling system data security one-way shuttle system includes the following steps:
[0037] T1) The dedicated mobile security smart terminal initiates a network access request. The mobile virtual private network verifies the legality of the terminal's triple identification, which consists of the dedicated IoT card, the terminal serial number, and the operating permissions. This verification process is a one-time authentication by the operator.
[0038] T2) Terminal access hierarchical protection access subsystem, the access protection layer predicts the terminal security status, and only when the prediction result is no risk, the full detection of the deep protection layer is triggered. This full detection includes malicious code killing and abnormal process investigation. After the detection is passed, the platform side secondary access is completed.
[0039] T3) The scenario-based security management subsystem issues a one-way mode command to control the one-way enhanced ferry subsystem to turn on the reverse digital diode and lock the forward digital diode. At the same time, it triggers the one-way data verification module to enable dual verification, which is SM4 encryption and hash value comparison.
[0040] T4) Data is transmitted only along a specific path, which is the railway signaling system sequentially passing through the rear one-way protocol interface machine, one-way data verification module, reverse digital diode, front one-way protocol interface machine, hierarchical protection access subsystem, mobile virtual private network, and finally transmitted to a dedicated mobile security smart terminal. The mobile virtual private network simultaneously upgrades the encryption level to the advanced national cryptographic SM4.
[0041] T5) If the terminal exceeds the preset operating area, the scenario-based security management subsystem first triggers the mobile virtual private network to disconnect the link, and then instructs the terminal to encrypt and store the received one-way data locally. The encryption key is dynamically issued by the security management subsystem, and a linkage log is generated at the same time. The linkage log contains information related to the out-of-area, link disconnection and encryption.
[0042] Preferably, in step T4, the dual verification process of the one-way data verification module is as follows:
[0043] T41) First, the data sent by the railway signaling system is encrypted using the SM4 algorithm to generate encrypted data packets;
[0044] T42) Then calculate the hash value of the generated encrypted data packet;
[0045] T43) transmits the encrypted data packet along with the calculated hash value to a dedicated mobile secure smart terminal;
[0046] After receiving the encrypted data packet and hash value, the T44 dedicated mobile security smart terminal first verifies the consistency of the hash value. After the hash value is verified, it uses a dedicated key to decrypt the encrypted data packet. This process ensures that the data sent from the railway signaling system to the dedicated mobile security smart terminal has not been tampered with.
[0047] Compared with existing technologies, this invention achieves secure data transfer in railway signaling systems by constructing a collaborative architecture that includes a dedicated mobile security intelligent terminal, a mobile virtual private network, a hierarchical protection access subsystem, a one-way enhanced transfer subsystem, and a scenario-based security management subsystem, combined with bidirectional and one-way interactive control methods. This has the following beneficial effects:
[0048] 1) This invention achieves physical layer unidirectional isolation through forward / reverse digital diodes in the unidirectional reinforced ferry subsystem. Combined with the SM4 encryption and hash value comparison dual verification mechanism of the unidirectional data verification module, it eliminates the risk of highly sensitive data being tampered with or transmitted in reverse from both hardware and algorithmic levels. The dedicated unidirectional data receiving module of the mobile security smart terminal has a read-only locking function, supporting only the viewing of highly sensitive data and prohibiting operations such as copying and forwarding. Combined with off-site data encryption storage and location-bound key mechanisms, it ensures secure management of data throughout its entire lifecycle. The multi-layered protection strategy (firewall + intrusion detection + access control) and scenario-based verification rules of the graded protection access subsystem further block unauthorized terminal access and abnormal data transmission, forming a defense-in-depth system.
[0049] 2) This invention dynamically adjusts the encryption strategy based on data sensitivity and transmission scenario: highly sensitive data (such as TDCS / CTC scheduling instructions) is encrypted using the SM4 algorithm and transmitted through a one-way channel, while low-sensitivity data (such as maintenance information) is encrypted using the SM3 algorithm to support bidirectional interaction. This satisfies the protection requirements of high-security data while improving the transmission efficiency of low-sensitivity data. The protocol stripping and restoration module of the one-way enhanced ferry subsystem retains only the core logic of signal system-specific protocols (such as the TSRS-CTC interface protocol), eliminates redundant fields of general protocols, reduces the attack surface while improving protocol adaptability, and ensures compatibility with different types of railway signaling systems.
[0050] 3) The scenario-based security management subsystem records the source address, verification result, terminal identifier, and timestamp of each piece of data through a one-way data traceability function, forming an immutable traceability chain to meet security audit requirements. The diode status monitoring function monitors the status of key components in real time, immediately blocking terminal access in case of anomalies, enabling rapid risk response. In the two-way and one-way interactive control methods, terminal access requires dual authentication from both the operator and platform sides, combined with location information and operation permission verification, to ensure that the terminal's identity is legitimate, its status is secure, and its operation is compliant. All interaction processes generate associated logs, providing a basis for fault diagnosis and responsibility determination.
[0051] 4) This invention supports secure access and data interaction for mobile terminals within a preset work area. When a terminal exceeds the work area, a linkage mechanism involving mobile virtual private network (MVPB) disconnection and local data encryption storage prevents data leakage. The hierarchical protection access subsystem's work scenario-to-protection strategy mapping table can dynamically adjust access verification rules according to the terminal's purpose (one-way reception / two-way transmission), adapting to diverse railway signaling work scenarios. The dynamic encryption level switching and dual-mode communication support of the mobile MVPB ensure the continuity and stability of data transmission, providing reliable support for the mobile operation and maintenance of railway signaling systems. Attached Figure Description
[0052] Figure 1 This is a flowchart of the data security two-way interactive control method of this application;
[0053] Figure 2 This is a flowchart of the data security one-way interactive control method of this application;
[0054] Figure 3 This is a flowchart of the dual verification process for the one-way data verification module of this application. Detailed Implementation
[0055] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0056] In the description of the invention, it should be noted that the terms "upper," "lower," "inner," "outer," "front end," "rear end," "both ends," "one end," and "the other end," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.
[0057] In the description of the invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installed," "equipped with," "connected," etc., should be interpreted broadly. For example, "connection" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be a connection within two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0058] In the description of the invention, it should be noted that the execution order of the steps is not limited by the sequence number. The possible changes in the order of some steps, the synchronous execution of steps, and the split execution of steps are all within the scope of protection of this application.
[0059] Please see Figure 1-3 The present invention provides a technical solution: a one-way data security shuttle system for railway signaling systems, including a dedicated mobile security intelligent terminal, a mobile virtual private network, a hierarchical protection access subsystem, a one-way enhanced shuttle subsystem, and a scenario-based security management subsystem;
[0060] The dedicated mobile security smart terminal communicates with the hierarchical protection access subsystem via a mobile virtual private network. The hierarchical protection access subsystem communicates with the one-way enhanced shuttle subsystem. The one-way enhanced shuttle subsystem communicates with the railway signaling system. The one-way enhanced shuttle subsystem is preferentially adapted to high-security-level systems, including but not limited to the TDCS system and the CTC system. The scenario-based security management subsystem is electrically connected to the dedicated mobile security smart terminal, the mobile virtual private network, the hierarchical protection access subsystem, and the one-way enhanced shuttle subsystem to achieve dedicated control in one-way shuttle scenarios.
[0061] The one-way reinforcement ferry subsystem includes a front-end one-way protocol interface unit, a forward digital diode, a reverse digital diode, a rear-end one-way protocol interface unit, and a one-way data verification module. The front-end one-way protocol interface unit only retains one-way adapter ports for receiving data from the mobile side and transmitting data from the signal side. The output of the front-end one-way protocol interface unit is connected to the input of the reverse digital diode. The input of the front-end one-way protocol interface unit is selectively connected to the output of the forward digital diode. The output of the reverse digital diode is connected to the rear-end one-way protocol interface unit. The one-way data verification module is connected in series between the reverse digital diode and the rear-end one-way protocol interface unit. The one-way data verification module is used to verify the integrity of the data transmitted from the signal system to the terminal.
[0062] The graded protection access subsystem includes a basic protection layer, a deep protection layer, and an access protection layer, which are divided according to risk level. The basic protection layer is a firewall, the deep protection layer includes intrusion detection equipment and antivirus firewall, and the access protection layer is an access controller with terminal security status prediction function. Each protection layer cooperates to protect according to the logic of prioritizing unidirectional data transmission and secondary verification for bidirectional data transmission.
[0063] Specifically, through a complete architecture comprising a dedicated mobile security smart terminal, a mobile virtual private network, a hierarchical protection access subsystem, a one-way enhanced transfer subsystem, and a scenario-based security management subsystem, the system lays the foundation for secure transfer of railway signal data at the system composition level, solving the core problems of fragmented protection and lack of coordinated control in the interaction between traditional signal systems and mobile terminals. From a structural design perspective, the one-way enhanced transfer subsystem achieves physical layer one-way isolation through a combination of front / rear one-way protocol interface units and forward / reverse digital diodes. This meets the rigid requirements of high-security systems such as TDCS and CTC for one-way data transmission, while also allowing for flexible switching of interaction modes via diode on / off control, accommodating low-sensitivity bidirectional data transmission scenarios. The hierarchical protection access subsystem, divided according to risk level, comprises a basic protection layer (firewall), a deep protection layer (intrusion detection + antivirus firewall), and an access protection layer (access controller with state prediction). This breaks the limitations of traditional single protection devices, forming a layered defense chain of boundary interception, deep detection, and precise access control, effectively resisting external intrusions and unauthorized access. From the perspective of collaborative management and control, the electrical connection design of the scenario-based safety management subsystem and its components enables centralized management and control of terminals, networks, and subsystems, providing architectural support for subsequent data hierarchical protection and precise terminal management, and ensuring that the system as a whole meets the high availability and high security requirements of railway signals.
[0064] The dedicated mobile security smart terminal has a built-in one-way data receiving module. The one-way data receiving module is only activated in one-way interaction mode. The one-way data receiving module is used to receive and parse highly sensitive data sent by the signal system. The highly sensitive data includes, but is not limited to, scheduling instructions from the TDCS system and CTC system. The one-way data receiving module does not have a data return interface.
[0065] The dedicated mobile security smart terminal is also equipped with a data encryption unit for off-site data, which is used to store one-way data that has not been processed in time after off-site data is removed.
[0066] The encryption key is bound to the location of the dedicated mobile security smart terminal. When the dedicated mobile security smart terminal returns to the work area, the data is automatically decrypted.
[0067] Specifically, this application addresses the shortcomings of traditional mobile terminals in protecting highly sensitive data and the vulnerability of data to leakage after being removed from the designated work area, thus strengthening the first line of defense for data security at the terminal level. On one hand, the one-way interactive mode activation design of the dedicated one-way data receiving module is activated only when receiving highly sensitive data such as TDCS and CTC scheduling instructions, and explicitly lacks a data return interface, eliminating the possibility of reverse transmission of highly sensitive data from a hardware perspective and preventing core data leakage due to terminal misoperation or malicious attacks. On the other hand, the combination of the off-site data encryption unit and the location-bound key solves the data storage security problem after the terminal leaves the preset work area. Traditionally, off-site data is often stored in plaintext or with fixed keys, posing a risk of theft. In this application, the encryption key is bound to the terminal's location and automatically decrypts upon returning to the work area, ensuring that data cannot be illegally read during off-site operation without affecting data usage efficiency during normal operation. Furthermore, this application deeply integrates terminal functions with railway signaling operation scenarios. For example, for the reception of highly sensitive data such as dispatch instructions, the application enables on-demand activation and dedicated use of the terminal through module function limitations. This aligns with the railway signaling system's operational and maintenance management standards, which emphasize clear functions and responsibilities, thereby enhancing the security and compliance of terminal use.
[0068] The dedicated one-way data receiving module of the mobile security smart terminal has a read-only locking function. Highly sensitive data received by this module can only be viewed; copying, forwarding, or screenshotting is not supported. Furthermore, data viewing records are synchronously uploaded to the scenario-based security management subsystem to achieve full lifecycle control of one-way data. Specifically, this application solves the problems of uncontrolled viewing of highly sensitive data and untraceable operation records in traditional terminals, achieving full lifecycle security control of data. The read-only locking function of the one-way data receiving module directly prohibits copying, forwarding, and screenshotting of highly sensitive data, blocking the possibility of secondary data dissemination at the operational level. While traditional terminals can receive sensitive data, they cannot restrict users' subsequent processing of the data, easily leading to risks of data leakage such as screenshotting and file copying. This application extends data control to the viewing stage through function locking, ensuring that highly sensitive data (such as TDCS / CTC scheduling instructions) can only be viewed by authorized personnel in authorized scenarios. Meanwhile, the design of the scenario-based security management subsystem that synchronously uploads data viewing records fills the gap of data viewing without auditing in traditional systems. Every viewing operation of highly sensitive data is recorded. In the event of a data breach, the operator and operation time can be traced through the audit logs, providing key evidence for liability determination and security incident tracing. This meets the security management requirements of railway signaling systems for traceability and auditability, and further strengthens the security control of data usage.
[0069] Mobile Virtual Private Networks (MVPBs) employ different encryption algorithms for encryption protection when transmitting data of varying sensitivity, including:
[0070] The SM4 algorithm is used to encrypt highly sensitive data when transmitting it. The highly sensitive data includes TDCS system data and CTC system data, and the highly sensitive data corresponds to a one-way transmission scenario.
[0071] The SM3 algorithm is used to encrypt low-sensitivity data when transmitting it. Low-sensitivity data includes signal centralized monitoring and maintenance data, and the low-sensitivity data corresponds to bidirectional transmission scenarios.
[0072] The scenario-based security management subsystem automatically triggers the mobile virtual private network to switch to the corresponding encryption algorithm based on the current data interaction mode.
[0073] Specifically, traditional technologies often employ a uniform encryption algorithm, such as a single SM3 or SM4, to process all signal data. This results in insufficient protection for highly sensitive data, such as TDCS / CTC data, or for less sensitive data, such as centralized signal monitoring and maintenance data. Over-encryption can lead to increased transmission delays. In contrast, this application dynamically switches encryption algorithms based on data sensitivity and transmission scenario: highly sensitive data transmitted in one direction uses the stronger SM4 algorithm to ensure core data is not compromised; less sensitive data transmitted in two directions uses the more efficient SM3 algorithm, improving transmission speed while meeting basic security requirements. Furthermore, the scenario-based security management subsystem automatically triggers encryption level switching, avoiding errors caused by manual intervention. Traditional encryption strategy switching relies on manual judgment of the interaction mode and manual adjustment, which is prone to operational errors. This application, through the linkage between the management subsystem and the interaction mode, achieves automatic identification and switching of encryption strategies. This reduces the workload of maintenance personnel and ensures accurate matching of encryption strategies with data transmission scenarios, meeting the high reliability and low manual intervention requirements of railway signaling systems.
[0074] The front-end unidirectional protocol interface unit of the unidirectional reinforcement ferry subsystem is equipped with a unidirectional protocol stripping module. The unidirectional protocol stripping module retains only the receiving and transmitting logic that matches the dedicated protocol of the signal system, such as the logic that matches the TSRS-CTC interface protocol, while removing redundant fields of general network protocols.
[0075] The unidirectional reinforcement ferry subsystem's rear unidirectional protocol interface unit is equipped with a unidirectional protocol restoration module. The unidirectional protocol restoration module only restores the verified unidirectional data into a format that the signal system can recognize, and does not support reverse protocol conversion.
[0076] Specifically, by enhancing the protocol processing capabilities of the one-way enhanced ferry subsystem, the problems of poor protocol compatibility and security risks introduced by redundant fields in traditional systems are solved, improving the system's adaptability and security with railway signaling-specific protocols. The one-way protocol stripping module of the front-end one-way protocol interface machine retains only the receiving / transmitting logic matching the signaling system's specific protocol (such as the TSRS-CTC interface protocol), eliminating redundant fields from general network protocols. This is because traditional protocol processing often retains complete fields of general protocols, and these redundant fields may contain vulnerabilities or attack points that can be exploited by attackers. This application reduces invalid information in data transmission through protocol stripping, thereby reducing data transmission volume, improving efficiency, and reducing the attack surface, avoiding security threats caused by vulnerabilities in general protocols. The one-way protocol restoration module of the rear-end one-way protocol interface machine only restores the verified one-way data to a format recognizable by the signaling system, and explicitly does not support reverse protocol conversion. This ensures at the protocol level that data can only be transmitted unidirectionally from the signaling system to the mobile terminal, eliminating the possibility of reverse data interaction, especially suitable for the one-way data inflow requirements of high-security systems such as TDCS and CTC. Furthermore, this design achieves secure conversion between general network protocols and railway signaling-specific protocols through a protocol processing flow of stripping and restoration, ensuring secure interoperability between the general network environment of the mobile virtual private network and the dedicated protocol environment of the signaling system, thus solving the problems of protocol incompatibility and data unrecognition in traditional cross-protocol interactions.
[0077] The scenario-based safety management subsystem includes a dedicated management module for one-way ferry connections. This module enables one-way data traceability and diode status monitoring.
[0078] In terms of one-way data traceability, the dedicated management module for one-way ferry records relevant information for each piece of one-way data. The information includes the data source address of the signal system, the one-way data verification result, the receiving terminal identifier, and the transmission timestamp. By recording this information, an immutable one-way data traceability chain is formed.
[0079] Regarding diode status monitoring, the one-way ferry dedicated management module monitors the on / off status of the forward and reverse digital diodes in real time. When the reverse digital diode is abnormally disconnected, the one-way ferry dedicated management module immediately triggers the hierarchical protection access subsystem to block all terminal access.
[0080] Specifically, regarding one-way data traceability, the dedicated one-way ferry management module records the signal system data source address, one-way data verification result, receiving terminal identifier, and transmission timestamp for each piece of one-way data, forming an immutable traceability chain. Traditional signal system data transmission often lacks full-link recording; once data tampering or leakage occurs, it is impossible to trace the data source and transmission path. This application, however, through the construction of a traceability chain, can accurately locate the flow process of each piece of highly sensitive data, providing a basis for security auditing and incident investigation. Regarding diode status monitoring, the module monitors the on / off status of forward / reverse digital diodes in real time. When a reverse digital diode abnormally disconnects, it immediately triggers the hierarchical protection access subsystem to block all terminal access. Specifically, the digital diode is a core component of one-way transmission; its abnormal status (such as accidental disconnection) can lead to interruption of highly sensitive data transmission or security vulnerabilities. Traditional systems lack real-time monitoring of such critical components and cannot detect anomalies in a timely manner. This application, through status monitoring and a linkage blocking mechanism, can quickly cut off terminal access when a diode malfunctions, avoiding security risks caused by component failure and ensuring the continuous reliability of the one-way transmission channel.
[0081] A mapping table between preset operating scenarios and protection strategies for the access control layer of the graded protection access subsystem, wherein:
[0082] When a dedicated mobile security smart terminal is used to receive data from the TDCS system and the CTC system in one direction, the access verification item adds a matching degree verification between the terminal and the jurisdiction of the signal system.
[0083] When a dedicated mobile security smart terminal is used for bidirectional transmission of maintenance data, the access verification item is simplified to terminal hardening status verification in order to achieve scenario-based access control.
[0084] Specifically, the access protection layer uses a pre-defined mapping table of operational scenarios to protection strategies, setting differentiated verification rules for different terminal uses: when a terminal is used to receive highly sensitive TDCS / CTC data unidirectionally, a matching verification between the terminal and the signal system's jurisdiction is added to ensure that the terminal can only access the signal system within its jurisdiction, avoiding the leakage of highly sensitive data due to unauthorized cross-regional access; when a terminal is used to transmit maintenance data bidirectionally, the verification is simplified to terminal hardening status verification, improving access efficiency while meeting basic security requirements. Traditional access control often uses uniform verification rules (such as only verifying terminal identity), which cannot distinguish the differences in security requirements of operational scenarios, resulting in insufficient verification in highly sensitive data scenarios or redundant verification in low-sensitive data scenarios, affecting efficiency. In addition, this design deeply integrates access rules with railway signal operation processes. For example, when signal personnel use a terminal to receive dispatch instructions, the terminal's jurisdiction needs to be verified additionally to ensure that dispatch instructions are only issued to terminals responsible for that area, complying with the railway signal system's zoning management and corresponding rights and responsibilities operation and maintenance specifications, improving the accuracy and compliance of access control.
[0085] According to another aspect of this application, a data security two-way interactive control method based on a railway signaling system data security one-way shuttle system is also provided, comprising the following steps:
[0086] S1) The dedicated mobile security smart terminal initiates a network access request. The mobile virtual private network first verifies the legality of the terminal's dual identifiers, which are the dedicated IoT card and the terminal serial number. This verification process is a one-time authentication by the operator.
[0087] S2) Terminal access hierarchical protection access subsystem, the access protection layer predicts the terminal security status. The prediction content includes the operating status of the hardening components and the matching degree between the current location and the preset work area. Only when the prediction result is low risk, the lightweight detection of the deep protection layer is triggered. This lightweight detection is a basic port scan. After the detection is passed, the platform side secondary access is completed.
[0088] The S3 scenario-based security management subsystem issues bidirectional mode commands to control the simultaneous activation of the forward and reverse digital diodes of the unidirectional enhanced ferry subsystem, and triggers the mobile virtual private network to switch the encryption level to the basic national cryptographic SM3.
[0089] S4) When data is transmitted bidirectionally, the hierarchical protection access subsystem performs additional format pre-verification and sensitive field filtering operations on the data sent from the mobile side to the signal side, and performs redundant information stripping operations on the data sent from the signal side to the mobile side.
[0090] S5) The scenario-based security management subsystem records associated logs during the bidirectional transmission process. The associated logs include data type, transmission duration, and terminal operator information, thereby forming a bidirectional data interaction traceability chain.
[0091] Specifically, the two-way interactive control method addresses the security interaction scenarios of low-sensitivity data (such as signal centralized monitoring and maintenance data), solving the problems of weak authentication mechanisms, unfiltered data processing, and lack of traceability in traditional two-way transmission, thus achieving secure and efficient interaction of low-sensitivity data. Regarding terminal access authentication, a dual mechanism of one-time authentication (dual identifier verification) on the operator side and two-time access control (security status prediction and lightweight detection) on the platform side verifies both the legitimacy of the terminal SIM card and serial number, and verifies the terminal's hardening status and location compliance, avoiding the risk of legitimate terminals being hijacked and illegally accessing the system due to traditional single authentication (such as only verifying the SIM card). In terms of data transmission processing, the hierarchical protection access subsystem performs format pre-verification and sensitive field filtering on data sent from the mobile side to the signal side, preventing illegally formatted data or data containing sensitive information from entering the signal system; it also strips redundant information from data sent from the signal side to the mobile side, reducing data transmission volume and improving efficiency, solving the problems of unfiltered data and easy carrying of redundant / sensitive information in traditional two-way transmission. In terms of interactive traceability, the scenario-based safety management subsystem records data types, transmission durations, and associated logs of terminal operators, forming a two-way data interaction traceability chain. This ensures that every two-way data interaction is auditable, meeting the traceability and controllability requirements of railway signaling systems. It also provides data support for equipment maintenance and fault diagnosis (such as analyzing data transmission stability through transmission duration).
[0092] According to another aspect of this application, a data security one-way interactive control method based on a railway signaling system data security one-way shuttle system is also provided, comprising the following steps:
[0093] T1) The dedicated mobile security smart terminal initiates a network access request. The mobile virtual private network verifies the legality of the terminal's triple identification, which consists of the dedicated IoT card, the terminal serial number, and the operating permissions. This verification process is a one-time authentication by the operator.
[0094] T2) Terminal access hierarchical protection access subsystem, the access protection layer predicts the terminal security status, and only when the prediction result is no risk, the full detection of the deep protection layer is triggered. This full detection includes malicious code killing and abnormal process investigation. After the detection is passed, the platform side secondary access is completed.
[0095] T3) The scenario-based security management subsystem issues a one-way mode command to control the one-way enhanced ferry subsystem to turn on the reverse digital diode and lock the forward digital diode. At the same time, it triggers the one-way data verification module to enable dual verification, which is SM4 encryption and hash value comparison.
[0096] T4) Data is transmitted only along a specific path, which is the railway signaling system sequentially passing through the rear one-way protocol interface machine, one-way data verification module, reverse digital diode, front one-way protocol interface machine, hierarchical protection access subsystem, mobile virtual private network, and finally transmitted to a dedicated mobile security smart terminal. The mobile virtual private network simultaneously upgrades the encryption level to the advanced national cryptographic SM4.
[0097] T5) If the terminal exceeds the preset operating area, the scenario-based security management subsystem first triggers the mobile virtual private network to disconnect the link, and then instructs the terminal to encrypt and store the received one-way data locally. The encryption key is dynamically issued by the security management subsystem, and a linkage log is generated at the same time. The linkage log contains information related to the out-of-area, link disconnection and encryption.
[0098] Specifically, in terms of terminal access control, a triple identification verification (dedicated IoT card, terminal serial number, and job permissions) and full-scale detection (malicious code detection and abnormal process investigation) are adopted. Compared with the dual identification and lightweight detection of two-way interaction, this further raises the terminal access threshold, allowing only terminals with job permissions and no security risks to access the system, preventing unauthorized or infected terminals from obtaining highly sensitive data. In terms of data transmission control, physical layer unidirectional isolation is achieved through the activation of reverse digital diodes and the blocking of forward digital diodes. Combined with SM4 advanced encryption of the mobile virtual private network, data can only flow from the signal system to the terminal and cannot be transmitted in reverse, solving the problem that traditional unidirectional transmission relies on software control and is easily breached. In terms of abnormal response, when a terminal exceeds the preset job area, the scenario-based security management subsystem triggers a combination mechanism of link disconnection, local encrypted storage, and linkage logs. This not only cuts off the data transmission link to prevent subsequent data leakage, but also protects the received data through encrypted storage, while generating logs for easy traceability. This solves the risk that traditional terminals can continue to receive data after going out of the zone or that received data is stored in plaintext, comprehensively ensuring the security of unidirectional transmission of highly sensitive data.
[0099] In step T4, the dual verification process of the one-way data verification module is as follows:
[0100] T41) First, the data sent by the railway signaling system is encrypted using the SM4 algorithm to generate encrypted data packets;
[0101] T42) Then calculate the hash value of the generated encrypted data packet;
[0102] T43) transmits the encrypted data packet along with the calculated hash value to a dedicated mobile secure smart terminal;
[0103] After receiving the encrypted data packet and hash value, the T44 dedicated mobile security smart terminal first verifies the consistency of the hash value. After the hash value is verified, it uses a dedicated key to decrypt the encrypted data packet. This process ensures that the data sent from the railway signaling system to the dedicated mobile security smart terminal has not been tampered with.
[0104] Specifically, the dual verification process of the one-way data verification module combines SM4 encryption and hash value comparison to form a complete protection chain: encryption before transmission, carrying a verification value during transmission, and verification before decryption upon receipt. First, the data sent by the railway signaling system is encrypted with SM4 to ensure that even if intercepted during transmission, the data cannot be decrypted. Then, the hash value of the encrypted data packet is calculated, and both are transmitted together, avoiding the problem of undetectable data tampering in traditional single encryption. Specifically, after receiving the data, the terminal must first verify the consistency of the hash value to confirm that the data has not been tampered with before decryption, ensuring that the finally received data is completely consistent with the data sent by the signaling system. Compared to traditional methods that only use single encryption or single verification, this process protects data from two dimensions: confidentiality (SM4 encryption) and integrity (hash value comparison), making it particularly suitable for scenarios with extremely high requirements for data accuracy, such as TDCS / CTC dispatch instructions (tampering with dispatch instructions could lead to train operation accidents). Meanwhile, the process clearly defines the operating entities for each step (signal system encryption, verification module hash value calculation, and terminal verification and decryption), with clear boundaries of responsibility. This meets the management requirements of traceable operation and verifiable responsibility for railway signaling systems, further enhancing the reliability and security of one-way transmission of highly sensitive data.
[0105] Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A one-way data security shuttle system for railway signaling systems, characterized in that, It includes a dedicated mobile security smart terminal, a mobile virtual private network, a hierarchical protection access subsystem, a one-way enhanced transfer subsystem, and a scenario-based security management subsystem; The dedicated mobile security smart terminal communicates with the hierarchical protection access subsystem via the mobile virtual private network. The hierarchical protection access subsystem communicates with the one-way enhanced shuttle subsystem. The one-way enhanced shuttle subsystem communicates with the railway signaling system. The one-way enhanced shuttle subsystem prioritizes adaptation to high-security-level systems, including but not limited to the TDCS system and the CTC system. The scenario-based security management subsystem is electrically connected to the dedicated mobile security smart terminal, the mobile virtual private network, the hierarchical protection access subsystem, and the one-way enhanced shuttle subsystem to achieve dedicated control in the one-way shuttle scenario. The unidirectional reinforcement ferry subsystem includes a front-end unidirectional protocol interface unit, a forward digital diode, a reverse digital diode, a rear-end unidirectional protocol interface unit, and a unidirectional data verification module. The front-end unidirectional protocol interface unit only retains a unidirectional adapter port for receiving mobile side data and transmitting signal side data. The output of the front-end unidirectional protocol interface unit is connected to the input of the reverse digital diode. The input of the front-end unidirectional protocol interface unit is selectively connected to the output of the forward digital diode. The output of the reverse digital diode is connected to the rear-end unidirectional protocol interface unit. The unidirectional data verification module is connected in series between the reverse digital diode and the rear-end unidirectional protocol interface unit. The unidirectional data verification module is used to verify the integrity of the data transmitted from the signal system to the terminal. The hierarchical protection access subsystem includes a basic protection layer, a deep protection layer, and an access protection layer, which are divided according to risk level. The basic protection layer is a firewall, the deep protection layer includes intrusion detection equipment and antivirus firewall, and the access protection layer is an access controller with terminal security status prediction function. Each protection layer cooperates in protection according to the logic of prioritizing unidirectional data transmission and secondary verification for bidirectional data transmission.
2. The railway signaling system data security one-way shuttle system according to claim 1, characterized in that, The dedicated mobile security smart terminal has a built-in one-way data receiving module. The one-way data receiving module is only activated in one-way interaction mode. The one-way data receiving module is used to receive and parse highly sensitive data sent by the signal system. The highly sensitive data includes, but is not limited to, scheduling instructions from the TDCS system and CTC system. The one-way data receiving module does not have a data return interface. The dedicated mobile security smart terminal is also equipped with a de-segmentation data encryption unit, which is used to store one-way data that has not been processed in time after de-segmentation. The encryption key is bound to the location of the dedicated mobile security smart terminal, and the data is automatically decrypted when the dedicated mobile security smart terminal returns to the work area.
3. The railway signaling system data security one-way shuttle system according to claim 1, characterized in that, The dedicated mobile security smart terminal's one-way data receiving module has a read-only locking function. The highly sensitive data received by the one-way data receiving module can only be viewed and cannot be copied, forwarded, or screenshotted. Furthermore, the data viewing records will be synchronously uploaded to the scenario-based security management subsystem.
4. The railway signaling system data security one-way shuttle system according to claim 1, characterized in that, The mobile virtual private network (MVNO) employs different encryption algorithms for encryption protection under different data sensitivity transmission scenarios, wherein: The SM4 algorithm is used to encrypt highly sensitive data when transmitting it. The highly sensitive data includes TDCS system data and CTC system data, and the highly sensitive data corresponds to a one-way transmission scenario. The SM3 algorithm is used to encrypt low-sensitivity data when transmitting it. The low-sensitivity data includes signal centralized monitoring and maintenance data, and the low-sensitivity data corresponds to a two-way transmission scenario. The scenario-based security management subsystem automatically triggers the mobile virtual private network to switch to the corresponding encryption algorithm based on the current data interaction mode.
5. The railway signaling system data security one-way shuttle system according to claim 1, characterized in that, The front-end unidirectional protocol interface unit of the unidirectional reinforcement ferry subsystem is equipped with a unidirectional protocol stripping module. The unidirectional protocol stripping module retains only the receiving and sending logic that matches the dedicated protocol of the signal system, while removing redundant fields of the general network protocol. The unidirectional reinforcement ferry subsystem is equipped with a unidirectional protocol interface unit. The unidirectional protocol restoration module only restores the verified unidirectional data into a format that the signal system can recognize, and does not support reverse protocol conversion.
6. The railway signaling system data security one-way shuttle system according to claim 1, characterized in that, The scenario-based safety management subsystem includes a dedicated one-way ferry management module, which enables one-way data traceability and diode status monitoring, wherein: Regarding one-way data traceability, the dedicated one-way ferry management module records relevant information for each piece of one-way data. This information includes the signal system data source address, one-way data verification result, receiving terminal identifier, and transmission timestamp. By recording this information, an immutable one-way data traceability chain is formed. Regarding diode status monitoring, the unidirectional ferry dedicated management module monitors the on / off status of the forward and reverse digital diodes in real time. When the reverse digital diode is abnormally disconnected, the unidirectional ferry dedicated management module immediately triggers the hierarchical protection access subsystem to block all terminal access.
7. The railway signaling system data security one-way shuttle system according to claim 1, characterized in that, The hierarchical protection access subsystem's access control layer includes a mapping table of preset operating scenarios and protection strategies, where: When the dedicated mobile security smart terminal is used to receive data from the TDCS system and CTC system in one direction, the access verification item adds a matching degree verification between the terminal and the jurisdiction of the signal system; When the dedicated mobile security smart terminal is used for bidirectional transmission of maintenance data, the access verification item is simplified to terminal hardening status verification in order to achieve scenario-based access control.
8. A data security bidirectional interactive control method for a railway signaling system data security one-way shuttle system as described in claim 1, characterized in that, Includes the following steps: S1) The dedicated mobile security smart terminal initiates a network access request. The mobile virtual private network first verifies the legality of the terminal's dual identifiers, which are the dedicated IoT card and the terminal serial number. This verification process is a one-time authentication by the operator. S2) Terminal access hierarchical protection access subsystem, the access protection layer predicts the terminal security status. The prediction content includes the operating status of the hardening components and the matching degree between the current location and the preset work area. Only when the prediction result is low risk, the lightweight detection of the deep protection layer is triggered. This lightweight detection is a basic port scan. After the detection is passed, the platform side secondary access is completed. The S3 scenario-based security management subsystem issues bidirectional mode commands to control the simultaneous activation of the forward and reverse digital diodes of the unidirectional enhanced ferry subsystem, and triggers the mobile virtual private network to switch the encryption level to the basic national cryptographic SM3. S4) When data is transmitted bidirectionally, the hierarchical protection access subsystem performs additional format pre-verification and sensitive field filtering operations on the data sent from the mobile side to the signal side, and performs redundant information stripping operations on the data sent from the signal side to the mobile side. S5) The scenario-based security management subsystem records associated logs during the bidirectional transmission process. The associated logs include data type, transmission duration, and terminal operator information, thereby forming a bidirectional data interaction traceability chain.
9. A data security one-way interactive control method for a railway signaling system data security one-way shuttle system as described in claim 1, characterized in that, Includes the following steps: T1) The dedicated mobile security smart terminal initiates a network access request. The mobile virtual private network verifies the legality of the terminal's triple identification, which consists of the dedicated IoT card, the terminal serial number, and the operating permissions. This verification process is a one-time authentication by the operator. T2) Terminal access hierarchical protection access subsystem, the access protection layer predicts the terminal security status, and only when the prediction result is no risk, the full detection of the deep protection layer is triggered. This full detection includes malicious code killing and abnormal process investigation. After the detection is passed, the platform side secondary access is completed. T3) The scenario-based security management subsystem issues a one-way mode command to control the one-way enhanced ferry subsystem to turn on the reverse digital diode and lock the forward digital diode. At the same time, it triggers the one-way data verification module to enable dual verification, which is SM4 encryption and hash value comparison. T4) Data is transmitted only along a specific path, which is the railway signaling system sequentially passing through the rear one-way protocol interface machine, one-way data verification module, reverse digital diode, front one-way protocol interface machine, hierarchical protection access subsystem, mobile virtual private network, and finally transmitted to a dedicated mobile security smart terminal. The mobile virtual private network simultaneously upgrades the encryption level to the advanced national cryptographic SM4. T5) If the terminal exceeds the preset operating area, the scenario-based security management subsystem first triggers the mobile virtual private network to disconnect the link, and then instructs the terminal to encrypt and store the received one-way data locally. The encryption key is dynamically issued by the security management subsystem, and a linkage log is generated at the same time. The linkage log contains information related to the out-of-area, link disconnection and encryption.
10. The one-way interactive control method according to claim 9, characterized in that, In step T4, the dual verification process of the one-way data verification module is as follows: T41) First, the data sent by the railway signaling system is encrypted using the SM4 algorithm to generate encrypted data packets; T42) Then calculate the hash value of the generated encrypted data packet; T43) transmits the encrypted data packet along with the calculated hash value to a dedicated mobile secure smart terminal; After receiving the encrypted data packet and hash value, the T44 dedicated mobile security smart terminal first verifies the consistency of the hash value. After the hash value is verified, it then uses a dedicated key to decrypt the encrypted data packet.
Citation Information
Patent Citations
Electric marketing mobile application safe protection system
CN104184735A
Peripheral ferry device and system thereof
CN115065498A