A network security isolation system based on rail transit vehicle network information processing
By establishing virtual transmission channels and configuring directional keys in the rail transit vehicle network, identifying and isolating atypical channels, and establishing directional regional networks and protocol sub-channels, the adaptability and specificity of network security isolation in the rail transit vehicle network are solved, achieving dynamic and comprehensive protection of information.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-21
- Publication Date
- 2026-03-31
AI Technical Summary
Existing network security isolation systems are unable to effectively prevent malicious attacks and threats from spreading laterally or vertically along communication channels in rail transit networks, leading to malicious tampering and unauthorized access to information, and thus failing to meet different types of network security isolation needs.
A virtual transmission channel is established between the train control terminal, the station communication terminal, and the ground transfer terminal. A directional key is configured, and the vehicle-to-network characteristics are extracted and converted into dynamic ciphertext through a key matching module. Isolation indicators of atypical channels are identified, an appropriate channel isolation mode is selected, and a directional local area network and a protocol sub-channel are established for dual isolation.
It enables dynamic and comprehensive analysis of network security isolation, improves the ability to identify and respond to unauthorized access, and ensures the security of information on the rail transit network.
Smart Images

Figure CN121585462B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and more specifically, to a network security isolation system based on rail transit vehicle network information processing. Background Technology
[0002] The rail transit vehicle network information system realizes real-time data interaction between the train control terminal, station communication terminal and ground data center, forming a complex mobile Internet of Things. However, the openness of cyberspace also makes the system face increasingly severe cybersecurity threats, such as unauthorized access, data eavesdropping, information tampering, denial-of-service attacks, etc. In order to avoid cybersecurity threats from affecting train operation safety and operational efficiency, it is necessary to isolate the rail transit vehicle network information for cybersecurity.
[0003] Reference patent application CN118784265A discloses a management method for onboard information security data of rail transit based on a cloud platform. The method includes encrypting the onboard network information security data using the AES128 encryption method provided by OpenSSL at the onboard network security device. The encrypted network security data is encapsulated in the TRDP protocol and transmitted in real time unidirectionally to the cloud access security agent of the cloud platform via the vehicle-to-ground wireless transmission channel using the TCP protocol. The onboard network security device consists of an onboard firewall and an onboard audit device. Each of the head car and tail car of the train is equipped with a set of onboard network security devices. The redundant configuration ensures the integrity of information security data transmission. After receiving the onboard network information security data, the backend completes the parsing and stores the parsed historical data in the Apache IoTDB time-series database.
[0004] Existing network security isolation systems typically focus on one-way isolation at network boundaries or simple internal network partitioning. However, within the rail transit network, once a device or channel is compromised by an external attack, malicious attacks and threats can easily spread irregularly horizontally or vertically along the communication channels within the network. This makes a single logical partition isolation method unable to meet different types of network security isolation needs, which can easily lead to malicious tampering and unauthorized access to rail transit network information, thus reducing the security of rail transit network information.
[0005] In view of this, the present invention proposes a network security isolation system based on rail transit vehicle network information processing to solve the above problems. Summary of the Invention
[0006] To overcome the aforementioned deficiencies of the prior art and to achieve the above objectives, the present invention provides the following technical solution: a network security isolation system based on rail transit vehicle network information processing, applied to a vehicle network cloud platform, comprising:
[0007] The key configuration module establishes a virtual transmission channel between the train control terminal, the station communication terminal, and the ground transfer terminal, defines the communication mechanism, and configures a directional key corresponding to the communication mechanism on the virtual transmission channel;
[0008] The key matching module extracts vehicle network features from the virtual transmission channel, converts the vehicle network features into dynamic ciphertext, and matches the dynamic ciphertext with the directional key to determine whether to perform network security isolation operation.
[0009] The mode selection module identifies atypical channels from the virtual transmission channels when performing network security isolation operations, collects isolation indicators for atypical channels, including the percentage of excessive access, the percentage of information delay, and the percentage of excessive traffic, calculates the isolation index, and selects the channel isolation mode that matches the isolation index.
[0010] The first isolation module, under the logical combination isolation mode, establishes a directional area network in the atypical channel and establishes an isolation fence at the boundary of the directional area network;
[0011] The second isolation module, in the protocol encryption isolation mode, constructs a protocol sub-channel within the atypical channel and configures encryption points on the protocol sub-channel.
[0012] Furthermore, the method for building a virtual transmission channel is as follows:
[0013] One channel node is set up at the train control terminal and one at the station communication terminal, and node one and node two are set up at the ground transfer terminal;
[0014] Taking the channel node at the train control end as the starting point and node number one as the ending point, a first channel is established between the starting point and the ending point. The bandwidth of the first channel is calculated by adding the bandwidth of the train control end and the bandwidth of the ground transfer end and averaging the results.
[0015] Using the channel node at the station communication end as the downlink starting point and node 2 as the downlink ending point, a second channel is established between the downlink starting point and the downlink ending point. The downlink bandwidth of the second channel is calculated by adding the bandwidth of the station communication end and the bandwidth of the ground relay end together and averaging the results.
[0016] Uplink lock-in bits and downlink lock-in bits are established on the first channel and the second channel respectively, and the uplink lock-in bits and downlink lock-in bits are locked and synchronized to generate uplink and downlink channels.
[0017] Furthermore, the communication mechanism is as follows: a fixed node access method is used when the device is stationary, and a dynamic node access method is used when the device is in motion.
[0018] The configuration method for the directional key is as follows:
[0019] Bind the uplink and downlink channels of the lock synchronization into a synchronization channel, and query the speed of the train control terminal corresponding to the synchronization channel at the current moment.
[0020] When the speed of movement is less than the rated speed, the train control terminal is in a stationary state, and the wireless nodes inside the station communication terminal are recorded as fixed nodes and used as directional nodes.
[0021] When the speed of movement is greater than or equal to the calibrated speed, the train control terminal is in a moving state, and the wireless node in the response state is recorded as a dynamic node and the dynamic node is used as a directional node.
[0022] The directional node serves as the directional architecture for both the uplink and downlink channels. Asymmetric encryption algorithms are used to set the key body within the uplink and downlink locking bits, and the key body is embedded within the directional architecture to configure the directional key.
[0023] Furthermore, vehicle-to-everything (V2X) characteristics include network characteristics, service characteristics, and defense characteristics;
[0024] Network characteristics include communication protocols, security levels, and network deep coupling coefficients;
[0025] Business characteristics include encryption level, deep detection cycle, and determination of peak traffic;
[0026] Defense features include security defense level, maximum number of compatible numbers, control protocol, and maximum access permissions.
[0027] Furthermore, the method for converting dynamic ciphertext is as follows:
[0028] Establish a ciphertext layer with three wrapping structures and a circular distribution, and label the three ciphertext layers as inner layer, middle layer and outer layer in order from the inside out;
[0029] The basic model is trained into a ciphertext conversion model using deep learning technology, and engine conversion rules are configured on the ciphertext conversion model to enable the ciphertext conversion model to be converted into a ciphertext engine.
[0030] Network characteristics, business characteristics, and defense characteristics are sequentially input into the ciphertext engine to identify network ciphertext, business ciphertext, and defense ciphertext respectively. The network ciphertext, business ciphertext, and defense ciphertext are then imported into the inner, middle, and outer layers respectively, and timestamps and sequence numbers are applied simultaneously to convert the network ciphertext, business ciphertext, and defense ciphertext into dynamic ciphertext.
[0031] Furthermore, the method for determining whether to perform network security isolation operations is as follows:
[0032] The wireless node corresponding to the directional ciphertext is used as the central sensing point. The central sensing point is then used to expand the scene through simulation software to generate a matching scene.
[0033] Within the matching scenario, establish static matching bits and dynamic matching bits respectively, set up a matching channel with matching trigger points between the static matching bits and dynamic matching bits, and initialize the working mode of the matching trigger points to a silent state.
[0034] The directional key is imported into the static matching bit, and the dynamic ciphertext is imported into the dynamic matching bit. This drives the working mode of the matching trigger point to switch from the silent state to the prominent state, and sends a matching command to the matching channel to unlock and match the directional key and the dynamic ciphertext, generating a matching value.
[0035] If the matching value is greater than or equal to the standard matching threshold, it is determined that no network security isolation operation will be performed.
[0036] When the matching value is less than the standard matching threshold, a network security isolation operation is determined to be performed.
[0037] Furthermore, the method for collecting the percentage of excessive access is as follows:
[0038] The authentication system retrieves all access logs within the atypical channel, and logs with an authentication failure status are recorded as over-limit logs, resulting in A over-limit logs.
[0039] Count the number of times access requests underwent permission verification in each of the A over-limit logs, and record it as the verification value. Record the over-limit logs with a verification value greater than or equal to 3 as direct logs, and the over-limit logs with a verification value less than 3 as indirect logs.
[0040] The direct value is calculated by summing all the verification values in the direct log, and the indirect value is calculated by summing all the verification values in the indirect log.
[0041] The total value is obtained by summing the verification values in A over-limit logs. The direct value is multiplied by the calibrated verification coefficient and then added to the indirect value. The result is compared with the total value to calculate the over-limit access percentage.
[0042] Furthermore, the channel isolation modes include logical combination isolation mode and protocol encryption isolation mode;
[0043] The method for selecting the channel isolation mode is as follows:
[0044] When the isolation index is less than the isolation threshold, the logical combination isolation mode is selected;
[0045] When the isolation index is greater than or equal to the isolation threshold, select the protocol encryption isolation mode.
[0046] Furthermore, the method for establishing a targeted area network is as follows:
[0047] In the atypical channel, C independently distributed task regions are established, and a unique region identifier and security credential are assigned to each of the C task regions to generate region identities.
[0048] Set D spaced member base points on the boundary line of the task area, establish logical wall bases between two adjacent member base points, and expand the logical wall bases outward to generate local walls;
[0049] Connect adjacent partial walls end to end to form an isolation wall, set logical intersection points on the isolation wall, and annotate the area identity at the logical intersection point to construct a directional area network.
[0050] Furthermore, the method for establishing protocol sub-channels is as follows:
[0051] Based on the preset sub-bandwidth, the atypical channel is divided into E sub-channels, and the E sub-channels are arranged in a ring structure.
[0052] One by one, establish transmission nodes with encryption bars on each of the E sub-channels, and use an asymmetric encryption algorithm to perform asymmetric encryption on the transmission nodes, thereby causing the transmission nodes to be converted into encryption points.
[0053] Based on the transmission of one type of vehicle network information through a sub-channel, a transmission mechanism is set in the encryption field, and a real-time triggered security protocol is applied to the sub-channel to generate a protocol sub-channel.
[0054] The technical advantages of the network security isolation system based on rail transit vehicle network information processing of this invention are as follows:
[0055] (1): This invention extracts vehicle network features from the virtual transmission channel and converts the vehicle network features into dynamic ciphertext for unlocking and matching. It can analyze and judge the network security situation in the virtual transmission channel from multiple different dimensions, ensuring that the network security situation can continuously change dynamically with the timeline. This avoids the limitations of network security analysis in a static state or at a fixed time point, and achieves a dynamic, comprehensive and accurate analysis effect of network security isolation.
[0056] (2): By identifying the isolation index of atypical channels and selecting isolation methods accordingly, this invention can adapt to the actual isolation requirements, improving the adaptability and pertinence of network security isolation operations. At the same time, by combining the dual isolation methods of directional area network and protocol sub-channel, it can achieve the dual effect of horizontal protection within the area and vertical protection within the channel for vehicle network information, thereby effectively preventing the phenomenon of malicious tampering and illegal access to the vehicle network information of rail transit, improving the identification ability and response speed of illegal access, and ensuring the security of rail transit vehicle network information. Attached Figure Description
[0057] Figure 1 This is a schematic diagram of the architecture of a network security isolation system based on rail transit vehicle network information processing, provided in Embodiment 1 of the present invention.
[0058] Figure 2 This is a schematic diagram of the vehicle network cloud platform provided in Embodiment 1 of the present invention. Detailed Implementation
[0059] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0060] Example 1: Please refer to Figures 1-2 As shown in this embodiment, a network security isolation system based on rail transit vehicle network information processing is applied to a vehicle network cloud platform, including:
[0061] The key configuration module establishes a virtual transmission channel between data terminals, defines the communication mechanism of the data terminals, and configures a directional key corresponding to the communication mechanism on the virtual transmission channel.
[0062] The data terminal refers to the vehicle network information used to send and receive information from rail transit. As the overall object for achieving network security isolation, by determining the communication mechanism of the data terminal, the transmission and security of vehicle network information from different data terminals can be established, ensuring the accuracy of subsequent network security isolation.
[0063] In this embodiment, the data terminal includes a train control terminal, a station communication terminal, and a ground relay terminal; the train control terminal is a port used to send and receive a series of train network information; the station communication terminal is a port used to send and receive relevant information between the platform and the train; and the ground relay terminal is used to transmit and interact with the train network information bidirectionally between the train control terminal and the station communication terminal.
[0064] The virtual transmission channel is a virtual data channel used to realize the free, bidirectional and stable transmission of vehicle network information between the train control terminal, station communication terminal and ground transfer terminal, which can ensure the free transmission effect of rail transit vehicle network information at the virtual level.
[0065] Specifically, the virtual transmission channel includes an uplink channel and a downlink channel; the uplink channel is used to facilitate uplink data transmission between the train control terminal and the ground transfer terminal, while the downlink channel is used to facilitate downlink data transmission between the station communication terminal and the ground transfer terminal.
[0066] The method for setting up a virtual transmission channel is as follows:
[0067] One channel node is set up at the train control terminal and one at the station communication terminal, and two relay nodes are set up at the ground relay terminal. The two relay nodes are designated as Node 1 and Node 2, respectively. The channel node and the relay node are the ports of the data transmission channels on different data terminals, and serve as the input and output ports of the vehicle network information.
[0068] The first channel is established between the channel node at the train control terminal as the starting point and the first node as the ending point.
[0069] The uplink bandwidth is calculated by adding the bandwidth of the train control terminal and the bandwidth of the ground transfer terminal, and then using the uplink bandwidth as the bandwidth of the first channel.
[0070] A second channel is established between the station's communication terminal's channel node as the downlink starting point and node number two as the downlink ending point.
[0071] The downlink bandwidth is calculated by adding the bandwidth of the station communication terminal and the bandwidth of the ground relay terminal, and then using the downlink bandwidth as the bandwidth of the second channel.
[0072] Uplink and downlink lock bits are established on the first and second channels respectively, and these lock bits are synchronized to convert the first and second channels into uplink and downlink channels. Lock bit synchronization is used to bind the locking operations of the uplink and downlink lock bits in sync, ensuring that the uplink and downlink lock bits remain consistent.
[0073] It should be noted that the number of uplink channels and downlink channels is not unique; it varies adaptively depending on the number of wireless nodes in the ground relay station. However, the number of uplink channels and downlink channels is the same, that is, one uplink channel corresponds to one downlink channel.
[0074] A directional key is used to lock and encrypt the same set of uplink and downlink channels, ensuring that the train network information between the train control terminal and the station communication station can be communicated bidirectionally in a secure and encrypted manner. When configuring a directional key, the specific form of the directional key needs to be determined according to the communication mechanism of the data terminal.
[0075] Since the objects that generate and receive vehicle network information in the data terminal are the train control terminal and the station communication terminal, the communication mechanism needs to restrict both the train control terminal and the station communication terminal to ensure the stable and reliable transmission of vehicle network information.
[0076] Specifically, the communication mechanism is as follows: a fixed node access method is used when the device is stationary, and a dynamic node access method is used when the device is in motion.
[0077] It should be noted that the stationary state refers to the relatively stationary state where the train's speed is less than the rated speed, and the moving state refers to the relatively moving state where the train's speed is greater than or equal to the rated speed; the node refers to the wireless node included in the ground transfer terminal. In this embodiment, the wireless node includes, but is not limited to, base stations, wireless gateways, etc. installed on the station or track.
[0078] The configuration method for the directional key is as follows:
[0079] Bind the uplink and downlink channels corresponding to the uplink and downlink lock positions of the lock position synchronization to generate a synchronization channel, and query the speed of the train control terminal corresponding to the synchronization channel at the current moment.
[0080] When the speed of movement is less than the calibrated speed, it means that the train control terminal is stationary at the current moment. The wireless node inside the station communication terminal is recorded as a fixed node and the fixed node is used as a directional node.
[0081] When the speed of movement is greater than or equal to the calibrated speed, it indicates that the train control terminal is in a moving state at the current moment. The wireless node that is in a response state at the current moment is recorded as a dynamic node, and the dynamic node is used as a directional node.
[0082] The directional node serves as the directional architecture for both the uplink and downlink channels. Asymmetric encryption algorithms are used to set the key body within the uplink and downlink locking bits, and the key body is embedded within the directional architecture to configure the directional key.
[0083] It should be noted that the directed architecture and the key body are two components in constructing a directed key. The directed architecture is used to provide the overall protection architecture for the key, while the key body is used to provide the substantive content of the key and ensure the secure transmission of relevant data information within the virtual transmission channel.
[0084] The key matching module extracts vehicle network features from the virtual transmission channel, converts the vehicle network features into dynamic ciphertext, and matches the dynamic ciphertext with the directional key to determine whether to perform network security isolation operation.
[0085] Vehicle network characteristics are the content characteristics of vehicle network information transmitted by the train control terminal, station communication terminal and ground transfer terminal through the uplink and downlink channels. They can concisely and accurately represent the real situation of vehicle network information in the uplink and downlink channels, and serve as the basis for subsequent network security isolation operations.
[0086] Specifically, vehicle-to-everything (V2X) characteristics include network characteristics, service characteristics, and defense characteristics;
[0087] Network characteristics are used to represent the real content of vehicle network information at the communication network layer, and serve as the basis for determining whether virtual transmission channels need to be isolated at the communication network layer.
[0088] In this embodiment, network characteristics include, but are not limited to, communication protocols, security levels, and network deep coupling coefficients. Network characteristics can serve as the skeleton and blood vessels of rail transit vehicle network information, and also determine the physical path and basic rules of data flow in vehicle network information.
[0089] Business characteristics are used to represent the actual content of the vehicle network information related to the business logic layer, and serve as the basis for determining whether the virtual transmission channel needs to be isolated at the business logic layer;
[0090] In this embodiment, the business characteristics include, but are not limited to, encryption level, deep detection period, and determination of traffic peaks; the business characteristics can serve as the lifeblood and mission of rail transit vehicle network information, and also determine the nature of the data that needs to be transmitted and processed.
[0091] Defense features are used to represent the actual content of vehicle network information regarding security defense, and serve as the basis for determining whether virtual transmission channels need to be isolated at the security defense level.
[0092] In this embodiment, the defense features include, but are not limited to, security defense level, maximum compatibility, control protocol, maximum access permissions, etc.; the defense features can serve as the immune system and health system of rail transit vehicle network information, and also determine the difficulty of the external challenges that need to be faced.
[0093] After obtaining the vehicle network characteristics, the vehicle network characteristics can be converted into ciphertext, so that the vehicle network characteristics can be converted into dynamic ciphertext corresponding to the directional key, thereby effectively integrating vehicle network characteristics of different types and dimensions to generate direct evidence that meets the subsequent network security isolation judgment.
[0094] In this embodiment, the dynamic ciphertext is a data set generated based on vehicle network features and using a data fusion algorithm as a carrier for targeted key matching analysis.
[0095] Specifically, the method for converting dynamic ciphertext is as follows:
[0096] Establish a ciphertext layer with three wrapping structures and a circular distribution, and label the three ciphertext layers as inner layer, middle layer and outer layer in order from the inside out;
[0097] A base model is trained into a ciphertext conversion model using deep learning technology. Engine conversion rules are then configured on the ciphertext conversion model to convert it into a ciphertext engine. The ciphertext conversion model is an artificial intelligence model obtained through iterative training based on deep learning technology, enabling it to possess deep learning capabilities. The training logic of the ciphertext conversion model is consistent with the training logic of machine learning models in existing technologies, and will not be elaborated here. The engine conversion rules are used to impose deep learning conversion constraints on the ciphertext engine, ensuring that the ciphertext conversion model can be converted into a ciphertext engine.
[0098] The network characteristics, business characteristics, and defense characteristics are sequentially input into the ciphertext engine to identify the network ciphertext, business ciphertext, and defense ciphertext respectively, and then the network ciphertext, business ciphertext, and defense ciphertext are imported into the inner layer, middle layer, and outer layer respectively.
[0099] Timestamps and sequence numbers are applied synchronously to the inner, middle, and outer layers, causing network ciphertext, business ciphertext, and defense ciphertext to be converted into dynamic ciphertext.
[0100] It should be noted that dynamic ciphertext is not static. As the relative positions between the train control terminal and the station communication terminal change, and as the timeline changes, the dynamic ciphertext at each moment is unique, thus achieving the real-time and dynamic nature of dynamic ciphertext.
[0101] Once the dynamic ciphertext is obtained, it can be decrypted and matched with the directional key. Based on the result of the decryption and matching, it can be determined whether to perform network security isolation operations, thereby providing a basis for judging the network security isolation of the rail transit vehicle network processing system.
[0102] Unlock matching is an operation used to analyze and compare the degree of compatibility between dynamic ciphertext and directed key, and to determine whether to perform network security isolation operation based on the final result of unlock matching.
[0103] Specifically, the method for determining whether to perform network security isolation operations is as follows:
[0104] The wireless node corresponding to the directional ciphertext is used as the central sensing point. The central sensing point is then diffused into the scene using simulation software to generate a matching scene. The matching scene is a simulated virtual environment provided for the unlocking and matching of dynamic ciphertext and directional key, ensuring that the unlocking and matching of dynamic ciphertext and directional key can remain fast and efficient.
[0105] Within the matching scenario, establish static and dynamic matching positions respectively. Set up a matching channel with a matching trigger point between the static and dynamic matching positions, and initialize the working mode of the matching trigger point to a silent state. The matching channel is the direct location for unlocking the matching, and the matching trigger point is the node used to control whether the matching channel is working, ensuring that the matching channel can be opened when there is a need to unlock the matching.
[0106] The directional key is imported into the static matching bit, and the dynamic ciphertext is imported into the dynamic matching bit. This drives the working mode of the matching trigger point to switch from the silent state to the prominent state, and sends a matching command to the matching channel to unlock and match the directional key and the dynamic ciphertext, generating a matching value.
[0107] The matching value is compared with the standard matching threshold in the database. When the matching value is greater than or equal to the standard matching threshold, it indicates that the degree of unlocking match between the dynamic ciphertext and the directed key is high, and it is determined that no network security isolation operation will be performed.
[0108] When the matching value is less than the standard matching threshold, it indicates that the degree of unlocking match between the dynamic ciphertext and the directed key is low, and a network security isolation operation is performed.
[0109] It should be noted that the standard matching threshold is the critical value of the degree of overlap between the dynamic ciphertext pre-stored in the database and the targeted key after unlocking, and it serves as the data basis for determining whether to perform network security isolation operations.
[0110] The mode selection module, when performing network security isolation operations, identifies atypical channels from the virtual transmission channel, collects the isolation indicators of the atypical channels, calculates the isolation index of the atypical channels, and selects a channel isolation mode that matches the isolation index. The channel isolation modes include logical combination isolation mode and protocol encryption isolation mode.
[0111] When network security isolation operations are performed, it indicates that there are abnormal train network information such as malicious attacks or unauthorized access in the uplink or downlink channels between the train control terminal, station communication terminal and ground transfer terminal. This makes the train network information in the virtual transmission channel easy for unauthorized users to eavesdrop on and access, and thus easy for the train network information to be maliciously tampered with. Therefore, it is necessary to analyze the virtual transmission channel and identify atypical channels with abnormalities.
[0112] In this embodiment, when identifying atypical channels from within the virtual transmission channel, the identification is based on the result of matching the dynamic ciphertext with the directional key unlocking. Specifically, uplink and downlink channels with matching values less than the standard matching threshold are recorded as atypical channels.
[0113] It should be noted that as time goes by, the number of uplink and downlink channels between the train control terminal, station communication terminal and ground transfer terminal will continue to increase. However, at any given moment, the number of atypical channels can only be one or two of the uplink and downlink channels.
[0114] Isolation metrics are comprehensive indicators used to describe the degree of abnormal danger of vehicle network information in atypical channels in network security. They serve as the data basis for subsequent isolation operations in network security within atypical channels. Based on the calculation of isolation metrics, an isolation index representing the rigor and abnormality of the isolation operation is calculated.
[0115] In this embodiment, the isolation indicators include the percentage of excessive access, the percentage of information delay, and the percentage of excessive traffic.
[0116] The percentage of excessive access refers to the ratio of the number of external access requests with abnormal permissions received in the atypical channel to the total number of requests. It can be used to represent the degree of unreasonable access requests in the atypical channel.
[0117] The method for collecting the percentage of excessive access is as follows:
[0118] The authentication system retrieves all access logs within the atypical channel, and logs with an authentication failure status are recorded as over-limit logs, resulting in A over-limit logs.
[0119] Count the number of times access requests underwent permission verification in each of the A over-limit logs, and record it as the verification value. Record the over-limit logs with a verification value greater than or equal to 3 as direct logs, and the over-limit logs with a verification value less than 3 as indirect logs.
[0120] The direct value is calculated by summing all the verification values in the direct log, and the indirect value is calculated by summing all the verification values in the indirect log.
[0121] After summing the verification values in A over-limit logs, the total value is calculated. The direct value is multiplied by the calibrated verification coefficient and then added to the indirect value. This is then compared with the total value to calculate the over-limit access percentage.
[0122] The formula for calculating the percentage of excessive access is:
[0123] ;
[0124] In the formula, This refers to the percentage of users who exceeded the access limit. For direct values, The calibration verification coefficients are as follows. Indirect values, This refers to the total value.
[0125] Information delay ratio refers to the proportion of vehicle network information with transmission delays and congestion in atypical channels to the total number of such information, which can be used to represent the smoothness of vehicle network information transmission in atypical channels.
[0126] The method for collecting the information delay percentage is as follows:
[0127] Using the same interval as a standard, B data packets are randomly captured from the data inlet of the atypical channel using a packet capture tool, and the sending time of the B data packets is queried.
[0128] Query the transmission status of B data packets one by one, and query the moment when the transmission status of the data packets first changes to "received", thus obtaining B receiving moments.
[0129] The duration between B sending times and B receiving times is recorded as the transmission duration. Data packets whose transmission duration exceeds the peak value of the calibrated duration are recorded as abnormal packets, and the number of abnormal packets is counted. The peak value of the calibrated duration refers to the minimum transmission duration corresponding to the data packets recorded as abnormal packets, to ensure the accuracy of the abnormal packet identification results.
[0130] The information delay percentage is calculated by comparing the number of abnormal packets with the number of data packets.
[0131] The percentage of data traffic exceeding the standard in a single transmission in an atypical channel refers to the proportion of the total number of data transmissions that exceed the standard data traffic in the atypical channel. It can be used to represent the degree of data traffic exceeding the standard in an atypical channel.
[0132] In this embodiment, the percentage of traffic exceeding the limit is obtained by querying through a traffic monitoring tool.
[0133] The isolation index is a numerical representation of the degree of abnormality in vehicle-to-network information transmission within atypical channels, and serves as the basis for selecting channel isolation modes for vehicle-to-network information within atypical channels.
[0134] Specifically, the formula for calculating the isolation index is:
[0135] ;
[0136] In the formula, For the isolation index, The percentage of information delays. For the percentage of traffic exceeding the limit, , , These are the percentages of excessive access, information delay, and excessive traffic, respectively. , , The sum of is 1.
[0137] The channel isolation mode is a specific mode used to perform network security isolation operations on vehicle network information in atypical channels, providing different isolation operations for vehicle network information with different levels of abnormal danger;
[0138] Channel isolation modes include logical combination isolation mode and protocol encryption isolation mode. Logical combination isolation mode refers to the method of dividing a logically independent security area on a shared atypical channel through various technical means, while protocol encryption isolation mode refers to the method of dividing a logically independent security area through various control protocols and encryption algorithms.
[0139] Specifically, the method for selecting the channel isolation mode is as follows:
[0140] The isolation index is compared with the isolation threshold; the isolation threshold is the critical value of the isolation index used to distinguish between logical combination isolation and protocol encryption isolation, thereby ensuring that the selected logical combination isolation and protocol encryption isolation can be adapted to atypical channels.
[0141] When the isolation index is less than the isolation threshold, it indicates that the degree of anomaly in the atypical channel is relatively mild, so the logical combination isolation mode is selected.
[0142] When the isolation index is greater than or equal to the isolation threshold, it indicates that the degree of anomaly in the atypical channel is relatively severe, and the protocol encryption isolation mode should be selected.
[0143] The first isolation module, under the logical combination isolation mode, establishes a directional area network in the atypical channel and sets up an isolation wall at the boundary of the directional area network to ensure the independent security of vehicle network information in the atypical channel;
[0144] In the logical combination isolation mode, a directional area network needs to be established in atypical channels so that the directional area network can provide an independent task network area for each vehicle network information access request and data transmission.
[0145] An isolation fence refers to a virtual protective fence set up at the boundary of a qualitative area network. It can protect the vehicle network information in the directional area network from leakage and ensure the independent security of vehicle network information in each qualitative area network within the atypical channel.
[0146] Specifically, the method for establishing a targeted area network is as follows:
[0147] Within the atypical channel, C independently distributed task regions are established, and each of the C task regions is assigned a unique region identifier and security credential to generate a region identity. The task region is a local network constructed within the atypical channel to perform lateral isolation of vehicle network information.
[0148] D spaced member base points are set on the boundary line of the task area. Logical wall bases are established between two adjacent member base points, and the logical wall bases are expanded outward to generate local walls. Local walls are the basic units that make up the isolation walls and serve as the data transmission protection protocol between two adjacent member base points.
[0149] Connect adjacent partial walls end to end to form an isolation wall, set logical intersection points on the isolation wall, and add the area identity to the logical intersection point to convert the task area into a targeted area network.
[0150] It should be noted that the logical intersection point is equivalent to the data transmission intersection node on the isolation wall. That is, a channel for information exchange between the internal and external vehicle networks can be opened on the isolation wall, thereby achieving the effect of dynamic opening and closing control of the qualitative area network.
[0151] The second isolation module, in the protocol encryption isolation mode, establishes protocol sub-channels within atypical channels and configures encryption points on the protocol sub-channels to ensure one-to-one correspondence of vehicle network information within atypical channels.
[0152] In the protocol encryption isolation mode, it is necessary to establish a protocol sub-channel for separate transmission of vehicle network information in the atypical channel, so that the protocol sub-channel can transmit vehicle network information in a separate and complete form.
[0153] When establishing a protocol sub-channel, in order to ensure the independence of vehicle network information within the protocol sub-channel and to prevent the loss or tampering of vehicle network information, encryption points need to be set on the protocol sub-channel to encrypt and protect it.
[0154] Specifically, the method for establishing a protocol sub-channel is as follows:
[0155] Based on the preset sub-bandwidth, the atypical channel is divided into E sub-channels, and the E sub-channels are arranged in a ring structure. The ring structure arrangement can ensure that the sub-channels are closely connected, minimize the negative transmission interference caused by irregular arrangement, and also be used for longitudinal isolation of vehicle network information. The preset sub-bandwidth refers to the bandwidth of the sub-channel that is set in advance.
[0156] One by one, establish transmission nodes with encryption bars on each of the E sub-channels, and use an asymmetric encryption algorithm to perform asymmetric encryption on the transmission nodes, thereby causing the transmission nodes to be converted into encryption points.
[0157] Based on the transmission of vehicle network information through a sub-channel, a transmission mechanism is set in the encryption field of the encryption point, and a real-time triggered security protocol is applied to the sub-channel to cause the sub-channel to be converted into a protocol sub-channel.
[0158] It should be noted that the transmission mechanism is used to restrict and require the secure transmission of vehicle-to-everything (V2X) information within the protocol sub-channel, ensuring that a protocol sub-channel can only transmit one type of V2X information at a time. The security protocol provides the core kernel for secure transmission of the protocol sub-channel, ensuring that the transmission of V2X information by the protocol sub-channel remains independent and secure at any time. Through real-time triggered state settings, the protocol sub-channel can always maintain an encrypted and secure state when exchanging V2X information.
[0159] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.
Claims
1. A network security isolation system based on rail transit vehicle network information processing, applied to a vehicle network cloud platform, characterized in that, include: The key configuration module establishes a virtual transmission channel between the train control terminal, the station communication terminal, and the ground transfer terminal, defines the communication mechanism, and configures a directional key corresponding to the communication mechanism on the virtual transmission channel; The key matching module extracts vehicle network features from the virtual transmission channel, converts the vehicle network features into dynamic ciphertext, and matches the dynamic ciphertext with the directional key to determine whether to perform network security isolation operation. The mode selection module identifies atypical channels from the virtual transmission channels when performing network security isolation operations, collects isolation indicators for atypical channels, including the percentage of excessive access, the percentage of information delay, and the percentage of excessive traffic, calculates the isolation index, and selects the channel isolation mode that matches the isolation index. Channel isolation modes include logical combination isolation mode and protocol encryption isolation mode; The method for selecting the channel isolation mode is as follows: When the isolation index is less than the isolation threshold, the logical combination isolation mode is selected; When the isolation index is greater than or equal to the isolation threshold, the protocol encryption isolation mode is selected; The first isolation module, under the logical combination isolation mode, establishes a directional area network in the atypical channel and establishes an isolation fence at the boundary of the directional area network; The method for establishing a targeted area network is as follows: In the atypical channel, C independently distributed task regions are established, and a unique region identifier and security credential are assigned to each of the C task regions to generate region identities. Set D spaced member base points on the boundary line of the task area, establish logical wall bases between two adjacent member base points, and expand the logical wall bases outward to generate local walls; Connect adjacent partial walls end to end to form an isolation wall, set logical intersection points on the isolation wall, and annotate the area identity on the logical intersection point to construct a directional area network; The second isolation module, in the protocol encryption isolation mode, constructs a protocol sub-channel within the atypical channel and configures encryption points on the protocol sub-channel; The method for establishing a protocol subchannel is as follows: Based on the preset sub-bandwidth, the atypical channel is divided into E sub-channels, and the E sub-channels are arranged in a ring structure. One by one, establish transmission nodes with encryption bars on each of the E sub-channels, and perform asymmetric encryption on the transmission nodes using an asymmetric encryption algorithm to convert the transmission nodes into encryption points. Based on the transmission of one type of vehicle network information through a sub-channel, a transmission mechanism is set in the encryption field, and a real-time triggered security protocol is applied to the sub-channel to generate a protocol sub-channel.
2. The network security isolation system based on rail transit vehicle network information processing according to claim 1, characterized in that, The method for setting up a virtual transmission channel is as follows: One channel node is set up at the train control terminal and one at the station communication terminal, and node one and node two are set up at the ground transfer terminal; Taking the channel node at the train control end as the starting point and node number one as the ending point, a first channel is established between the starting point and the ending point. The bandwidth of the first channel is calculated by adding the bandwidth of the train control end and the bandwidth of the ground transfer end and averaging the results. Using the channel node at the station communication end as the downlink starting point and node 2 as the downlink ending point, a second channel is established between the downlink starting point and the downlink ending point. The downlink bandwidth of the second channel is calculated by adding the bandwidth of the station communication end and the bandwidth of the ground relay end together and averaging the results. Uplink lock-in bits and downlink lock-in bits are established on the first channel and the second channel respectively, and the uplink lock-in bits and downlink lock-in bits are locked and synchronized to generate uplink and downlink channels.
3. A network security isolation system based on rail transit vehicle network information processing according to claim 2, characterized in that, The communication mechanism is as follows: a fixed node access method is used when the device is stationary, and a dynamic node access method is used when the device is in motion. The configuration method for the directional key is as follows: Bind the uplink and downlink channels of the lock synchronization into a synchronization channel, and query the speed of the train control terminal corresponding to the synchronization channel at the current moment. When the speed of movement is less than the rated speed, the train control terminal is in a stationary state, and the wireless nodes inside the station communication terminal are recorded as fixed nodes and used as directional nodes. When the speed of movement is greater than or equal to the calibrated speed, the train control terminal is in a moving state, and the wireless node in the response state is recorded as a dynamic node and the dynamic node is used as a directional node. The directional node serves as the directional architecture for both the uplink and downlink channels. Asymmetric encryption algorithms are used to set the key body within the uplink and downlink locking bits, and the key body is embedded within the directional architecture to configure the directional key.
4. A network security isolation system based on rail transit vehicle network information processing according to claim 3, characterized in that, Vehicle-to-everything (V2X) characteristics include network characteristics, service characteristics, and defense characteristics; Network characteristics include communication protocols, security levels, and network deep coupling coefficients; Business characteristics include encryption level, deep detection cycle, and determination of peak traffic; Defense features include security defense level, maximum number of compatible numbers, control protocol, and maximum access permissions.
5. A network security isolation system based on rail transit vehicle network information processing according to claim 4, characterized in that, The method for converting vehicle network features into dynamic ciphertext is as follows: Establish a ciphertext layer with three wrapping structures and a circular distribution, and label the three ciphertext layers as inner layer, middle layer and outer layer in order from the inside out; The basic model is trained into a ciphertext conversion model using deep learning technology, and engine conversion rules are configured on the ciphertext conversion model to enable the ciphertext conversion model to be converted into a ciphertext engine. Network characteristics, business characteristics, and defense characteristics are sequentially input into the ciphertext engine to identify network ciphertext, business ciphertext, and defense ciphertext respectively. The network ciphertext, business ciphertext, and defense ciphertext are then imported into the inner, middle, and outer layers respectively, and timestamps and sequence numbers are applied simultaneously to convert the network ciphertext, business ciphertext, and defense ciphertext into dynamic ciphertext.
6. A network security isolation system based on rail transit vehicle network information processing according to claim 5, characterized in that, The method for determining whether to perform network security isolation operations is as follows: The wireless node corresponding to the directional ciphertext is used as the central sensing point. The central sensing point is then used to expand the scene through simulation software to generate a matching scene. Within the matching scenario, establish static matching bits and dynamic matching bits respectively, set up a matching channel with matching trigger points between the static matching bits and dynamic matching bits, and initialize the working mode of the matching trigger points to a silent state. The directional key is imported into the static matching bit, and the dynamic ciphertext is imported into the dynamic matching bit. This drives the working mode of the matching trigger point to switch from the silent state to the prominent state, and sends a matching command to the matching channel to unlock and match the directional key and the dynamic ciphertext, generating a matching value. If the matching value is greater than or equal to the standard matching threshold, it is determined that no network security isolation operation will be performed. When the matching value is less than the standard matching threshold, a network security isolation operation is determined to be performed.
7. A network security isolation system based on rail transit vehicle network information processing according to claim 6, characterized in that, The method for collecting the percentage of excessive access is as follows: The authentication system retrieves all access logs within the atypical channel, and logs with an authentication failure status are recorded as over-limit logs, resulting in A over-limit logs. Count the number of times access requests underwent permission verification in each of the A over-limit logs, and record it as the verification value. Record the over-limit logs with a verification value greater than or equal to 3 as direct logs, and the over-limit logs with a verification value less than 3 as indirect logs. The direct value is calculated by summing all the verification values in the direct log, and the indirect value is calculated by summing all the verification values in the indirect log. The total value is obtained by summing the verification values in A over-limit logs. The direct value is multiplied by the calibrated verification coefficient and then added to the indirect value. The result is compared with the total value to calculate the over-limit access percentage.
Citation Information
Patent Citations
Rail transit vehicle-mounted information safety data management method based on cloud platform
CN118784265A
Unmanned sweeper and cloud platform data interaction system based on hybrid encryption
CN120264270A
Rail transit vehicle-ground security encryption control method and device based on national secret algorithm
CN120980522A