Train control on-board equipment distributed health state assessment method and related device

By employing a distributed health status assessment method and utilizing lightweight models and privacy computing technology, high-precision assessment and secure transmission of train control onboard equipment have been achieved. This has solved the problems of data privacy and "data silos," improved assessment accuracy and early warning capabilities, and promoted the transformation of rail transit operation and maintenance models.

CN121691402APending Publication Date: 2026-03-17EAST CHINA JIAOTONG UNIVERSITY

Patent Information

Application Number
CN202610178535.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-09
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing technologies pose risks of data security and privacy leaks and "data silos" in the health assessment of train control onboard equipment, resulting in limited assessment accuracy and early warning capabilities, and making it impossible to learn common fault modes across regions and vehicle models.

Method used

A distributed health status assessment method is adopted, which independently collects data and generates local assessment results through vehicle edge nodes. It uses a lightweight health assessment model and privacy computing technology to generate encrypted assessment information, establishes an encrypted vehicle-to-ground connection, and performs secure aggregation calculations on the central cloud platform to generate an anonymized global health status assessment report.

Benefits of technology

This has improved the accuracy and early warning capabilities of health status assessment while ensuring data privacy and security compliance, promoted the transformation of rail transit operation and maintenance mode from passive response to proactive prevention, and improved operation and maintenance efficiency and safety control capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121691402A_ABST
    Figure CN121691402A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed health state assessment method for train control on-board equipment and a related device, and relates to the technical field of intelligent operation and maintenance of rail transit, and each train control on-board equipment is used as an on-board edge node and is connected with a central cloud platform through an encrypted train-ground communication network. The vehicle-mounted edge node independently collects multi-source vehicle-mounted operation data, and generates a local health assessment result by using a lightweight health assessment model; generating encryption evaluation information for the result by applying a privacy computing technology, and uploading the encryption evaluation information to a central cloud platform; and the central cloud platform performs security aggregation on the encrypted evaluation information after verification, generates a desensitization global health state evaluation report and distributes the report to each node and a ground operation and maintenance scheduling center for adjusting the early warning level and formulating an operation and maintenance strategy. According to the scheme, local retention of original data is realized, data privacy and compliance are guaranteed through multi-protection of federated learning, privacy calculation and anonymization transmission, a data island is broken, and health state assessment accuracy is improved through global collaborative assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent operation and maintenance technology for rail transit, and in particular to a distributed health status assessment method and related device for train control onboard equipment. Background Technology

[0002] Accurate health assessment of train control onboard equipment relies on the fusion and analysis of massive amounts of multi-source operational data, including highly sensitive information such as train location, trajectory, and equipment serial numbers. Traditional centralized architectures upload data to a central platform for processing, which easily leads to the leakage of trade secrets and infringement of passenger privacy, violating data security and personal information protection regulations. While localized assessments can protect privacy, the "data silo" problem prevents models from learning common fault patterns across regions and train models, limiting assessment accuracy and early warning capabilities. Existing privacy-preserving computing technologies such as federated learning or homomorphic encryption have been explored in general scenarios, but a feasible, end-to-end distributed health assessment system has not yet been established specifically for the high security, real-time, and high reliability characteristics of rail transit. Therefore, a new distributed architecture and privacy protection mechanism are urgently needed to achieve high-precision health status assessment through multi-party collaboration without allowing raw data to leave the train, balancing the dual goals of data value release and security compliance. Summary of the Invention

[0003] The purpose of this application is to provide a distributed health status assessment method and related device for train control on-board equipment, which can improve the accuracy of health status assessment through global collaborative assessment, while fully protecting data privacy and compliance.

[0004] To achieve the above objectives, this application provides the following solution: Firstly, this application provides a distributed health status assessment method for train control on-board equipment, wherein each train control on-board device acts as an on-board edge node and establishes an encrypted connection with the central cloud platform through a vehicle-to-ground communication network, including the following steps: For any vehicle edge node, multi-source vehicle operation data is collected independently, and a local health assessment result is generated through a lightweight health assessment model. The lightweight health assessment model is a model obtained through a one-time federated learning process. The lightweight health assessment model takes the multi-source vehicle operation data of the vehicle edge node as input and the local health assessment result of the vehicle edge node as output.

[0005] Privacy computing technology is applied to the local health assessment results to generate corresponding encrypted assessment information, and the encrypted assessment information, along with the anonymized identifier of the vehicle edge node, is uploaded to the central cloud platform through the vehicle-to-ground communication network.

[0006] The central cloud platform receives and verifies the encrypted assessment information uploaded by each vehicle edge node, performs secure aggregation calculations on the verified encrypted assessment information, and generates a de-identified global health status assessment report based on the secure aggregation results.

[0007] The global health status assessment report is distributed to each vehicle edge node and the ground operation and maintenance dispatch center through the vehicle-to-ground communication network. The global health status assessment report is used by the vehicle edge nodes to adjust the warning level and by the ground operation and maintenance dispatch center to formulate operation and maintenance strategies.

[0008] Optionally, the multi-source on-board operating data includes braking core data, speed core data, and communication auxiliary data; braking core data includes brake cylinder pressure and braking command response data; speed core data includes real-time speed and target speed deviation data; communication auxiliary data includes message integrity and link status data; the local health assessment result is a four-dimensional probability vector, which includes the probability that the train control on-board equipment is in a healthy state, a slightly abnormal state, a seriously abnormal state, and a fault state, and the sum of the probability values ​​in the four-dimensional probability vector is 1.

[0009] Optionally, the privacy computing technology is homomorphic encryption or differential privacy technology; When privacy computing technology employs homomorphic encryption, it generates corresponding encrypted evaluation information, specifically including: The probability values ​​in the local health assessment results are quantized into integers, and each quantized probability value is independently encrypted using a public key pre-distributed by the central cloud platform to obtain encrypted assessment information in the form of a ciphertext vector.

[0010] When privacy computing technology employs differential privacy technology, it generates corresponding encrypted evaluation information, specifically including...

[0011] Based on a preset privacy budget, the scale of the Laplace noise is determined, and Laplace noise of the corresponding scale is added to the local health assessment results to obtain encrypted assessment information in the form of noisy plaintext vectors.

[0012] Optionally, when performing secure aggregation calculations, if the encrypted evaluation information is in the form of a ciphertext vector, the addition homomorphic property of homomorphic encryption technology is used to add all ciphertext vectors element by element without decryption to obtain an encrypted global vector. The encrypted global vector is then decrypted using a threshold decryption mechanism to obtain a secure aggregation result in the form of a plaintext global vector. If the encrypted evaluation information is in the form of a noisy plaintext vector, the arithmetic average of all noisy plaintext vectors is calculated to obtain a secure aggregation result in the form of a plaintext global vector.

[0013] Optionally, the period for the vehicle edge node to collect multi-source vehicle operation data is 100ms, and the window for generating local health assessment results through the lightweight health assessment model is 1 second; the default frequency for uploading encrypted assessment information is once every 5 minutes, and when the probability of a serious abnormal state or fault state in the local health assessment results exceeds a preset threshold, the encrypted assessment information is uploaded immediately.

[0014] Optionally, the overall health status assessment report includes statistics on the distribution of population health status, analysis of high-risk factors, and general maintenance recommendations; the overall health status assessment report does not contain any train identification information.

[0015] Secondly, this application provides a distributed health status assessment system for train control onboard equipment, in which each train control onboard device acts as an onboard edge node and establishes an encrypted connection with the central cloud platform through a vehicle-to-ground communication network.

[0016] The vehicle-mounted edge node includes: a data acquisition module, a model loading module, a local evaluation module, a privacy protection module, a secure upload module, and a policy application module.

[0017] The data acquisition module is used to independently collect multi-source vehicle operation data.

[0018] The model loading module is used to load the lightweight health assessment model. The lightweight health assessment model is a model obtained through a one-time federated learning process. The lightweight health assessment model takes multi-source vehicle operation data of the vehicle edge node as input and outputs the local health assessment results of the vehicle edge node.

[0019] The local assessment module is used to generate local health assessment results based on multi-source vehicle operation data using a lightweight health assessment model.

[0020] The privacy protection module is used to apply privacy computing technology to the local health assessment results and generate corresponding encrypted assessment information.

[0021] The secure upload module is used to upload encrypted evaluation information, along with the anonymized identifier of the vehicle-mounted edge node, to the central cloud platform via the vehicle-to-ground communication network.

[0022] The strategy application module is used to adjust the warning level based on the global health status assessment report issued by the central cloud platform.

[0023] The central cloud platform includes: a receiving and verification module, a security aggregation module, a report generation module, and a feedback distribution module.

[0024] The receiving and verification module is used to receive and verify the encrypted evaluation information uploaded by each vehicle edge node in the central cloud platform.

[0025] The security aggregation module is used to perform secure aggregation calculations on the verified encrypted evaluation information.

[0026] The report generation module is used to generate anonymized global health status assessment reports based on secure aggregation results.

[0027] The feedback distribution module is used to distribute the global health status assessment report to each vehicle edge node and the ground operation and maintenance dispatch center through the vehicle-to-ground communication network; the global health status assessment report is used by the ground operation and maintenance dispatch center to formulate operation and maintenance strategies.

[0028] Thirdly, this application provides a computer device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the distributed health status assessment method for train control on-board equipment described above.

[0029] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the distributed health status assessment method for train control on-board equipment described above.

[0030] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the distributed health status assessment method for train control on-board equipment described above.

[0031] According to the specific embodiments provided in this application, the following technical effects are disclosed: This application provides a distributed health status assessment method and related apparatus for train control onboard equipment. In this method, each train control onboard device acts as an onboard edge node, establishing an encrypted connection with the central cloud platform through a vehicle-to-ground communication network. This ensures the security of vehicle-to-ground data transmission, prevents the leakage of sensitive information during transmission, and strictly complies with the safety and compliance requirements of rail transit scenarios. The method includes the following steps: independently collecting multi-source onboard operation data at each onboard edge node, with the raw data stored locally onboard throughout the process and not transmitted externally, thus ensuring the privacy and security of sensitive data such as train position and trajectory from the source; and generating local health assessment results through a lightweight health assessment model; applying privacy computing technology to de-identify the local health assessment results to prevent attackers from deducing the precise status information of a single train from the assessment results, further strengthening privacy protection; and the central cloud platform receiving and verifying the encrypted assessment information uploaded by each onboard edge node. To ensure the legality and integrity of uploaded data and prevent malicious data from interfering with the accuracy of the overall assessment results, the system performs secure aggregation calculations on verified encrypted assessment information without decrypting the original assessment results. This enables collaborative value mining of multi-party data, protecting privacy and integrating massive data resources across trains and lines. Finally, the overall health status assessment report is distributed to each onboard edge node and the ground operation and maintenance dispatch center via the vehicle-to-ground communication network. On the one hand, this allows onboard edge nodes to adjust warning levels, combining local conditions with global patterns, upgrading them from "passive diagnosis" to "proactive prevention," and improving the foresight of single-train fault warnings. On the other hand, it provides the ground operation and maintenance dispatch center with data-driven basis for formulating operation and maintenance strategies, prioritizing maintenance, allocating spare parts, and optimizing timetables. This promotes the transformation of rail transit operation and maintenance models from passive response to proactive prevention, improving the operation and maintenance efficiency and safety control capabilities of the entire network. Attached Figure Description

[0032] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0033] Figure 1 This is a flowchart illustrating a distributed health status assessment method for train control onboard equipment provided in one embodiment of this application.

[0034] Figure 2 This is a schematic diagram of the functional modules of a distributed health status assessment system for train control onboard equipment provided in an embodiment of this application.

[0035] Figure 3 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0036] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0037] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, this application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0038] This application provides a distributed health status assessment method for train control on-board equipment. In one exemplary embodiment, the method is applied to a train network system, which consists of N (N≥2) train control on-board devices deployed on different trains and a central cloud platform located in the railway bureau's data center. Each train control on-board device acts as an on-board edge node, establishing an encrypted connection with the central cloud platform through a vehicle-to-ground communication network, such as... Figure 1 As shown, it includes the following steps: A1. For any vehicle edge node, independently collect multi-source vehicle operation data and generate local health assessment results through a lightweight health assessment model. The lightweight health assessment model is a model obtained through a one-time federated learning process. The lightweight health assessment model takes the multi-source vehicle operation data of the vehicle edge node as input and the local health assessment results of the vehicle edge node as output.

[0039] In an exemplary embodiment, the multi-source vehicle operation data collected in the vehicle edge node includes braking core data, speed core data, and communication auxiliary data; the braking core data includes brake cylinder pressure and braking command response data; the speed core data includes real-time speed and target speed deviation data; and the communication auxiliary data includes message integrity and link status data.

[0040] During train operation, the judicial recording unit collects three types of data (braking core data, speed core data, and communication auxiliary data) from the on-board train control system at a period of 100ms and stores them in each on-board edge node.

[0041] The local health assessment result generated based on multi-source on-board operation data is a four-dimensional probability vector. The four-dimensional probability vector includes the probability that the train control on-board equipment is in a healthy state, a slightly abnormal state, a seriously abnormal state, and a fault state, and the sum of the probability values ​​in the four-dimensional probability vector is 1.

[0042] During federated learning, the central cloud platform, acting as the coordinator, distributes an initial global model to all participating onboard edge nodes. Each edge node fine-tunes this global model using its local historical data, calculating the update gradients for the model parameters. These gradients (not the original data) are then encrypted and uploaded to the central cloud platform. The central cloud platform aggregates all gradients, updates the global model, and distributes the new global model. This process iterates several times until the global model converges. Ultimately, each onboard edge node possesses a high-performance, lightweight health assessment model adapted to its local data distribution, and throughout the entire process, no original onboard data leaves the train.

[0043] The evaluation engine of the vehicle edge node performs feature engineering (such as calculating the sliding average of speed deviation and the rate of change of braking pressure) on the collected multi-source vehicle operation data in a 1-second window, forming a feature vector. This feature vector is input into the loaded lightweight health assessment model, which outputs a local health assessment result. In this embodiment, the local health assessment result is defined as a four-dimensional probability vector. , representing the probabilities of the train control onboard equipment being in one of four states: "Healthy (H)", "Minor Abnormality (MA)", "Severe Abnormality (SA)", and "Fault (F)", respectively, and this vector satisfies .

[0044] A2. Apply privacy computing technology to the local health assessment results to generate corresponding encrypted assessment information, and upload the encrypted assessment information, along with the anonymized identifier of the vehicle edge node, to the central cloud platform through the vehicle-to-ground communication network.

[0045] As a scalable implementation, this method supports two mainstream privacy protection modes in this step, which can be configured according to actual security needs and computing resources. The privacy computing technology can be homomorphic encryption or differential privacy technology; this embodiment defaults to homomorphic encryption (HE) mode because it provides stronger cryptographic security.

[0046] When privacy computing technology employs homomorphic encryption, it generates corresponding encrypted evaluation information, specifically including: The probability values ​​in the local health assessment results are quantized into integers, and each quantized probability value is independently encrypted using a public key pre-distributed by the central cloud platform to obtain encrypted assessment information in the form of a ciphertext vector.

[0047] Specifically, the vehicle-mounted edge node has a built-in high-efficiency homomorphic encryption library (Microsoft SEAL), and the edge node possesses a globally unique public key that will not change within a certain period. However, to ensure security, the public key is changed periodically every three months. (This is related to the generation process.) Then, the nodes use the public key (PK) pre-distributed by the central cloud platform to independently encrypt each probability value in the vector. Since the probability values ​​are floating-point numbers, they must first be quantized into integers. The encrypted result is a ciphertext vector. . This refers to the encrypted assessment information used with privacy protection.

[0048] When privacy computing technology employs differential privacy technology, it generates corresponding encrypted evaluation information, specifically including...

[0049] Based on a preset privacy budget, the scale of the Laplace noise is determined, and Laplace noise of the corresponding scale is added to the local health assessment results to obtain encrypted assessment information in the form of noisy plaintext vectors.

[0050] When using differential privacy technology, the on-board edge nodes no longer encrypt the data, but instead use the local evaluation results. Add Laplace noise. The scale of the noise is determined by the privacy budget. ε Control. For example, for a sensitivity of... Average number of queries, ( DP ≤ N The added noise is In this way, each edge node uploads a noisy plaintext vector. .

[0051] Subsequently, the vehicle-mounted edge node will use the secure channel established by the protocol to... Along with its own anonymized identifier (such as a randomly generated UUID that updates with each session, rather than the actual vehicle number), it is uploaded to the central cloud platform. The default frequency for uploading encrypted assessment information is once every 5 minutes, depending on the probability of a severe abnormal or faulty state in the local health assessment results. or If the value exceeds a preset threshold (e.g., 0.5), the encrypted evaluation information will be uploaded immediately.

[0052] A3. Receive and verify the encrypted assessment information uploaded by each vehicle edge node in the central cloud platform, perform secure aggregation calculation on the verified encrypted assessment information, and generate a de-identified global health status assessment report based on the secure aggregation result.

[0053] The central cloud platform continuously monitors upload requests from each edge node. It receives one... The platform first verifies the legitimacy of its source (by verifying the digital signature) and checks whether its format is correct. Once the verification is successful, the ciphertext vector is stored in the processing queue.

[0054] Once the queue accumulates encrypted evaluation information from M (M≤N) different vehicle edge nodes (e.g., M=1000), the central cloud platform initiates an aggregation task. Utilizing the additive homomorphic property of homomorphic encryption, the platform can directly add all ciphertext vectors element-wise without decryption, as shown in the following equation: .

[0055] Right now, This process continues until an encrypted vector representing the sum of all M samples is obtained. ,include , , and These are probability vectors corresponding to the four states: "Health (H)", "Minor Abnormality (MA)", "Severe Abnormality (SA)" and "F" respectively.

[0056] Specifically, in this embodiment, when performing secure aggregation calculations, if the encrypted evaluation information is in the form of a ciphertext vector, the addition homomorphic property of homomorphic encryption technology is used to add all ciphertext vectors element by element without decryption to obtain an encrypted global vector. In order to avoid the single point of trust problem, the encrypted global vector is decrypted through a threshold decryption mechanism to obtain a secure aggregation result in the form of a plaintext global vector.

[0057] The central cloud platform itself holds a portion of the private key, while the other two portions are held by independent, regulated third-party institutions. Decryption can only be completed when at least two portions operate in concert. The resulting plaintext vector is then obtained. .

[0058] The central cloud platform will The sum of all terms in the vector is divided by M to obtain the average probability vector. This represents the overall health status distribution of the M train group currently participating in the assessment.

[0059] If the encrypted evaluation information is in the form of noisy plaintext vectors, then the arithmetic average of all noisy plaintext vectors is calculated to obtain a secure aggregation result in the form of a global plaintext vector. When using differential privacy technology, the central cloud platform directly receives all... The vector is used to calculate its arithmetic mean, which is calculated using the following formula: .

[0060] Since the expectation of Laplace noise is 0, when the denominator DP When large enough, It will be very close to reality. ,Right now This approach simultaneously satisfies ε-differential privacy. While computationally inefficient, making it ideal for resource-constrained scenarios, its privacy protection is weaker than homomorphic encryption and requires a larger sample size. DP Only then can accuracy be guaranteed.

[0061] The aforementioned limitations on the application of privacy-preserving computation techniques describe the processing steps for privacy-preserving computation using homomorphic encryption or differential privacy techniques. In certain high-security scenarios, a hybrid approach may be adopted. For example, regarding the most critical "fault (F)" probability... Homomorphic encryption is used to ensure absolute security. For other non-critical metrics, differential privacy is used to balance performance. This flexible policy configuration capability allows this solution to adapt to diverse business needs.

[0062] A4. The global health status assessment report is distributed to each onboard edge node and the ground operation and maintenance dispatch center via the vehicle-to-ground communication network. The global health status assessment report is used by the onboard edge nodes to adjust the warning level and by the ground operation and maintenance dispatch center to formulate operation and maintenance strategies. The global health status assessment report includes statistics on the distribution of group health status, analysis of high-risk factors, and general maintenance recommendations; the global health status assessment report does not contain any train identification information.

[0063] The average probability vector has been obtained in step A3. Based on this, the platform's analytics engine will perform in-depth analysis, if... or If the value is significantly higher than the historical baseline, a Level 1 warning will be generated: "Group Risk Alert". The central cloud platform will then aggregate all anonymized UUIDs used in this aggregation along with their corresponding metadata such as route, vehicle type, and ambient temperature (this metadata is uploaded...). (The information provided has been anonymized) Association analysis was conducted to identify high-risk factors. For example, it was found that "in East China, with the CR380 model, and under ambient temperatures >35℃..." "40% higher than other conditions."

[0064] The final global health status assessment report is strictly anonymized and does not contain any individual train information. It only includes the overall health status distribution, risk factor analysis and general maintenance recommendations (such as "It is recommended to strengthen the heat dissipation inspection of the braking system for CR380 models operating in the high-temperature season in East China").

[0065] After receiving the global health status assessment report, each vehicle edge node's local intelligent engine compares the global insights with its own local status. For example, if the global report indicates that a certain type of brake valve is prone to problems at high temperatures, and the vehicle happens to be equipped with that model and the current ambient temperature is high, then even if the vehicle's local assessment result is still normal ( Even at a lower risk level, the system will raise the internal warning level and display a message on the human-machine interface to the driver: "Attention: The current environment matches a known high-risk scenario. Please pay attention to the braking system status." This represents an upgrade from "passive diagnosis" to "active prevention."

[0066] Upon receiving the report, the ground operations and maintenance center can take the following actions based on the current situation. These actions include, but are not limited to: adding high-risk vehicles or lines to the priority maintenance list; pre-allocating relevant spare parts to key stations based on predicted failure modes; adjusting train schedules or speed limit policies in extreme weather or special sections; and using the new patterns discovered in this aggregation as prior knowledge for the model initialization of the next round of federated learning, forming a continuously evolving intelligent closed loop.

[0067] The above embodiments of this application provide a distributed health status assessment method for train control on-board equipment. Each train control on-board device acts as an on-board edge node, establishing an encrypted connection with the central cloud platform through a vehicle-to-ground communication network. This ensures the security of vehicle-to-ground data transmission, prevents the leakage of sensitive information during transmission, and strictly complies with the safety and compliance requirements of rail transit scenarios. In this method: First, for any onboard edge node, multi-source onboard operation data is independently collected, and the raw data is stored locally onboard throughout the process without being transmitted externally. This ensures the privacy and security of sensitive data such as train location and trajectory from the source, and maintains data sovereignty. Then, a lightweight health assessment model is used to generate local health assessment results. The lightweight health assessment model is a model obtained through a one-time federated learning process. During the training process, only the model gradient is transmitted instead of the raw data. This breaks the limitation of "data silos" and allows the model to fully learn common fault modes across regions and vehicle models. It also avoids the leakage of raw data, balances privacy protection and model generalization ability, and significantly improves the accuracy of local health assessment results.

[0068] Subsequently, privacy computing technology is applied to the local health assessment results to generate corresponding encrypted assessment information. In this embodiment, homomorphic encryption or differential privacy technology is used to desensitize the assessment results to prevent attackers from deducing the precise status information of a single train from the assessment results, thereby further strengthening privacy protection. The encrypted assessment information, along with the anonymized identifier of the on-board edge node, is uploaded to the central cloud platform through the vehicle-to-ground communication network. The anonymized identifier prevents the leakage of the identity information of a single train. This dual protection eliminates the operator's concerns about the leakage of sensitive data and increases the willingness to participate in collaborative assessment.

[0069] Subsequently, the encrypted assessment information uploaded by each vehicle-mounted edge node is received and verified in the central cloud platform to ensure the legality and integrity of the uploaded data and prevent malicious data from interfering with the accuracy of the global assessment results. Without decrypting the original assessment results, the verified encrypted assessment information is securely aggregated and calculated to achieve collaborative value mining of multi-party data. This not only protects privacy and security but also integrates massive data resources across trains and lines. Based on the secure aggregation results, a desensitized global health status assessment report is generated, which does not contain any identification information traceable to a single train. At the same time, it can present the patterns of group health status and high-risk factors, providing macro-level data support for the operation and maintenance of the entire railway network.

[0070] Finally, the global health status assessment report is distributed to each onboard edge node and the ground operation and maintenance dispatch center through the vehicle-to-ground communication network. The global health status assessment report is used to allow onboard edge nodes to adjust the warning level, realize the combination of local status and global patterns, upgrade the onboard edge nodes from "passive diagnosis" to "proactive prevention", improve the foresight of single train fault warning, and provide the ground operation and maintenance dispatch center with data-driven basis for formulating operation and maintenance strategies, such as priority maintenance, spare parts allocation, and operation schedule optimization. This promotes the transformation of rail transit operation and maintenance mode from passive response to proactive prevention, and improves the operation and maintenance efficiency and safety control capabilities of the entire network.

[0071] Based on the same inventive concept, this application also provides a system for implementing the distributed health status assessment method for train control on-board equipment described above. The solution provided by this system is similar to the implementation scheme described in the above method. In an exemplary embodiment, such as... Figure 2 As shown, a distributed health status assessment system for train control onboard equipment is provided. Each onboard device acts as an onboard edge node, establishing an encrypted connection with the central cloud platform via a vehicle-to-ground communication network. The onboard edge node includes: a data acquisition module, a model loading module, a local assessment module, a privacy protection module, a secure upload module, and a policy application module. The central cloud platform includes: a receiving and verification module, a secure aggregation module, a report generation module, and a feedback distribution module.

[0072] The data acquisition module is used to independently collect multi-source vehicle operation data.

[0073] The model loading module is used to load the lightweight health assessment model. The lightweight health assessment model is a model obtained through a one-time federated learning process. The lightweight health assessment model takes multi-source vehicle operation data of the vehicle edge node as input and outputs the local health assessment results of the vehicle edge node.

[0074] The local assessment module is used to generate local health assessment results based on multi-source vehicle operation data using a lightweight health assessment model.

[0075] The privacy protection module is used to apply privacy computing technology to the local health assessment results and generate corresponding encrypted assessment information.

[0076] The secure upload module is used to upload encrypted evaluation information, along with the anonymized identifier of the vehicle-mounted edge node, to the central cloud platform via the vehicle-to-ground communication network.

[0077] The strategy application module is used to adjust the warning level based on the global health status assessment report issued by the central cloud platform.

[0078] The receiving and verification module is used to receive and verify the encrypted evaluation information uploaded by each vehicle edge node in the central cloud platform.

[0079] The security aggregation module is used to perform secure aggregation calculations on the verified encrypted evaluation information.

[0080] The report generation module is used to generate anonymized global health status assessment reports based on secure aggregation results.

[0081] The feedback distribution module is used to distribute the global health status assessment report to each vehicle edge node and the ground operation and maintenance dispatch center through the vehicle-to-ground communication network; the global health status assessment report is used by the ground operation and maintenance dispatch center to formulate operation and maintenance strategies.

[0082] certainly, Figure 2 The architecture shown is merely exemplary; it can be omitted as needed when implementing different functionalities. Figure 2 One or at least two components of the system shown.

[0083] In one exemplary embodiment, a computer device is provided, which may be a server or a terminal, and its internal structure diagram may be as follows. Figure 3 As shown, the computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it can implement the distributed health status assessment method for train control on-board equipment provided in the above embodiment.

[0084] Those skilled in the art will understand that Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0085] In one exemplary embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.

[0086] In one exemplary embodiment, a computer-readable storage medium is provided storing a computer program that, when executed by a processor, implements the steps in the above-described method embodiments.

[0087] In one exemplary embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above-described method embodiments.

[0088] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use and processing of the relevant data are carried out in compliance with the relevant data protection laws and policies of the country where the location is located, and with the authorization granted by the owner of the corresponding device.

[0089] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM).

[0090] The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0091] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0092] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A distributed health state evaluation method for train control on-board equipment, characterized in that, Each train control on-board equipment as an on-board edge node, establishes an encrypted connection with the center cloud platform through a train-ground communication network, including: For any on-board edge node, independently collecting multi-source on-board operation data, and generating a local health assessment result through a lightweight health assessment model; the lightweight health assessment model is a model obtained through a one-time federated learning process, and the lightweight health assessment model takes the multi-source on-board operation data of the on-board edge node as input and takes the local health assessment result of the on-board edge node as output; Applying a privacy computing technology to the local health assessment result to generate corresponding encrypted assessment information, and uploading the encrypted assessment information together with the anonymized identifier of the on-board edge node to the center cloud platform through the train-ground communication network; Receiving and verifying the encrypted assessment information uploaded by each on-board edge node in the center cloud platform, performing secure aggregation calculation on the encrypted assessment information that passes the verification, and generating a desensitized global health state assessment report based on the secure aggregation result; Distributing the global health state assessment report to each on-board edge node and the ground operation and dispatching center through the train-ground communication network; the global health state assessment report is used for the on-board edge node to adjust the warning level and the ground operation and dispatching center to formulate operation and maintenance strategies.

2. The method according to claim 1, wherein, The multi-source on-board operation data includes braking core data, speed core data and communication auxiliary data; the braking core data includes brake cylinder pressure and brake instruction response data; the speed core data includes real-time speed and target speed deviation data; the communication auxiliary data includes message integrity and link state data; the local health assessment result is a four-dimensional probability vector, the four-dimensional probability vector includes the probabilities of the train control on-board equipment being in a healthy state, a slight abnormal state, a serious abnormal state and a failure state, and the sum of each probability value in the four-dimensional probability vector is 1.

3. The method according to claim 1, wherein, The privacy computing technology is a homomorphic encryption technology or a differential privacy technology; When the privacy computing technology adopts the homomorphic encryption technology, the corresponding encrypted assessment information is generated, specifically including: Quantifying the probability values in the local health assessment result into integers, and independently encrypting each quantified probability value through the public key pre-distributed by the center cloud platform to obtain the encrypted assessment information in the form of a ciphertext vector; When the privacy computing technology adopts the differential privacy technology, the corresponding encrypted assessment information is generated, specifically including: Determining the scale of the Laplace noise based on a preset privacy budget, adding the Laplace noise of the corresponding scale in the local health assessment result to obtain the encrypted assessment information in the form of a noisy plaintext vector.

4. The distributed health state evaluation method for train control on-board equipment according to claim 3, characterized in that, When performing secure aggregation calculation, if the encrypted assessment information is in the form of a ciphertext vector, the additive homomorphic property of the homomorphic encryption technology is used to add all ciphertext vectors element by element without decryption to obtain an encrypted global vector, and the encrypted global vector is decrypted through a threshold decryption mechanism to obtain a secure aggregation result in the form of a plaintext global vector; if the encrypted assessment information is in the form of a noisy plaintext vector, an arithmetic average calculation is performed on all noisy plaintext vectors to obtain a secure aggregation result in the form of a plaintext global vector.

5. The method according to claim 2, wherein, The periodicity of the vehicle-mounted edge node collecting multi-source vehicle-mounted operation data is 100 ms, and the window for generating a local health assessment result by a lightweight health assessment model is 1 second; the default frequency of uploading encrypted evaluation information is once every 5 minutes; when the probability of a serious abnormal state or a failure state in the local health assessment result exceeds a preset threshold, the encrypted evaluation information is immediately uploaded.

6. The method of claim 1, wherein, The global health state assessment report includes group health state distribution statistics, high-risk factor analysis, and universal maintenance recommendations. The global health state assessment report does not contain any train identification information.

7. A distributed health state evaluation system for train control on-board equipment, characterized in that, Each train control vehicle-mounted device serves as a vehicle-mounted edge node and establishes an encrypted connection with the center cloud platform through a train-ground communication network; The vehicle-mounted edge node includes a data acquisition module, a model loading module, a local assessment module, a privacy protection module, a secure upload module, and a strategy application module; The data acquisition module is configured to independently acquire multi-source vehicle-mounted operation data; The model loading module is configured to load a lightweight health assessment model; the lightweight health assessment model is a model obtained through a one-time federated learning process and collaborative training, and the lightweight health assessment model takes multi-source vehicle-mounted operation data of the vehicle-mounted edge node as input and takes a local health assessment result of the vehicle-mounted edge node as output; The local assessment module is configured to generate a local health assessment result by the lightweight health assessment model according to the multi-source vehicle-mounted operation data; The privacy protection module is configured to apply a privacy computing technology to the local health assessment result to generate corresponding encrypted evaluation information; The secure upload module is configured to upload the encrypted evaluation information to the center cloud platform through the train-ground communication network together with an anonymized identifier of the vehicle-mounted edge node; The strategy application module is configured to adjust an early warning level according to a global health state assessment report issued by the center cloud platform; The center cloud platform includes a receiving and verifying module, a secure aggregation module, a report generation module, and a feedback distribution module; The receiving and verifying module is configured to receive and verify encrypted evaluation information uploaded by each vehicle-mounted edge node in the center cloud platform; The secure aggregation module is configured to perform secure aggregation calculation on the encrypted evaluation information that passes verification; The report generation module is configured to generate a desensitized global health state assessment report based on the secure aggregation result; The feedback distribution module is configured to distribute the global health state assessment report to each vehicle-mounted edge node and a ground operation and maintenance dispatching center through the train-ground communication network; the global health state assessment report is used for the ground operation and maintenance dispatching center to formulate an operation and maintenance strategy.

8. A computer device comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that the processor executes the computer program to implement the train control vehicle-mounted device distributed health state assessment method of any one of claims 1-6.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the train control vehicle-mounted device distributed health state assessment method of any one of claims 1-6.

10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the train control vehicle-mounted device distributed health state assessment method of any one of claims 1-6.

Citation Information

Patent Citations

  • Elevator intelligent management system based on edge computing and computing network integration

    CN119059385A

  • System for realizing unified monitoring, operation and maintenance management based on multiple edge cloud platforms

    CN120676037A

  • Traffic engineering facility safety state monitoring system and method based on Internet of Things

    CN121393082A

  • Heat dissipation fault early warning and monitoring system based on edge calculation

    CN121434865A

  • Distributed bridge group health diagnosis and early warning method and system

    CN121456737A

Cited By

  • Train control on-board equipment health monitoring method and equipment based on D-S evidence theory, medium and product

    CN121977865A