Urban rail transit communication safety system and method based on 5G public network access
By adopting a hybrid networking mode and multi-layered security mechanisms in rail transit, the network security challenges of 5G public networks in rail transit have been solved, achieving highly reliable and low-latency communication for the train operation control system and improving the system's security and protection capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-23
- Publication Date
- 2026-04-07
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In existing technologies, 5G public networks pose cybersecurity challenges in core rail transit operations, especially the security of train operation control systems, which are difficult to guarantee. They face challenges such as attack surface expansion, conflicting security strategies, and potential vulnerabilities, which may lead to lateral penetration after low-level systems are compromised, making it difficult to achieve the high reliability and low latency communication requirements.
Adopting a hybrid networking mode based on the 5G public network, and combining physical isolation and logical domain security architecture, a multi-layered security mechanism is built through unified authentication and access control, network slicing configuration, end-to-end encryption and key management, intrusion detection and prevention modules, and simulation testing platform. This enables physical isolation and end-to-end encryption of train control services, as well as dynamic protection and rapid response.
It has achieved secure and reliable communication for 5G public network access in rail transit, ensuring low latency and high reliability of train control services, improving the reliability and protection efficiency of terminal access, and providing a dynamic and controllable security protection system.
Smart Images

Figure CN121815255A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of rail transit communication security, specifically relating to an urban rail transit communication security system and method based on 5G public network access. Background Technology
[0002] With the rapid development of urban rail transit and the increasing demand for intelligent applications, rail transit systems are placing higher requirements on communication networks, such as low latency, high reliability, and high concurrency. 5G networks, with their enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (uRLLC), and massive machine-type communications (mMTC) characteristics, offer new possibilities for the informatization upgrade of urban rail transit. Several cities have already launched 5G+ smart rail transit pilot projects, and these applications demonstrate that 5G public network access offers high transmission rates, flexible deployment, and diverse security capabilities.
[0003] However, applying 5G public networks to core rail transit services (especially train operation control systems) also faces severe cybersecurity challenges. On the one hand, compared to traditional closed private networks, the openness and network interfaces of 5G public networks exponentially expand the attack surface: the number of public network base stations increases more than 200 times, and related attack incidents rise significantly. On the other hand, different rail transit services have varying security levels; for example, train control systems require Level 3 security protection, while video surveillance and maintenance require Level 2. When high-level train control services share the public network with low-level services, security policy conflicts may lead to lateral penetration of the train control system after the low-level system is compromised. Reports have shown that it only takes a few hours to penetrate the train control system through vulnerabilities in the passenger information system. Furthermore, 5G slicing mechanisms, network interfaces, and APIs themselves have potential vulnerabilities, which could allow attackers to bypass authentication and access core business data. Therefore, it is urgent to design a unified security architecture covering the physical layer to the application layer, organically integrating multiple mechanisms such as slice isolation, dynamic access control, and end-to-end encryption to meet the information security needs of rail transit under concurrent multi-service operation. Summary of the Invention
[0004] To address the problems existing in the prior art, this invention provides a 5G public network access-based urban rail transit communication security system and method. It adopts a hybrid networking mode that combines physical isolation and logical domain division, and uses a multi-layered security mechanism to ensure the reliability and security of vehicle-to-ground communication.
[0005] To achieve the above objectives, the present invention provides the following solution: A 5G public network access-based urban rail transit communication security system, the system comprising: a unified authentication and access control module, a network slicing configuration module, a physical isolation and logical domain security architecture, an end-to-end encryption and key management unit, an intrusion detection and prevention module, and a simulation test platform module; The unified authentication and access control module is used to implement a unified identity authentication and access control mechanism; The network slice configuration module is used to divide multiple network slices based on 5G core network slicing technology. The physical isolation and logical domain separation security architecture is used to achieve physical isolation of the column control business, while blocking cross-domain penetration attacks; The end-to-end encryption and key management unit is used to design end-to-end data encryption and differentiated protection strategies; The intrusion detection and prevention module is used to build an edge-center collaborative intrusion detection system. Lightweight traffic analysis and feature recognition components are deployed on MEC nodes to perform local real-time detection and early warning of access terminal data. Deep learning-driven AI-IDS is deployed on the central platform to centrally model and analyze the network traffic logs. The simulation test platform module is used to simulate tunnel multipath fading, high-speed train movement, and handover processes; it dynamically divides network slices for train control services through QoS policies, and integrates threat intelligence and AI anomaly detection through the Security Operations Center (SOC) to achieve automatic identification and response to injection attacks.
[0006] Preferably, the unified authentication and access control module is configured with a multi-factor authentication mechanism and device attribute authentication to achieve three-dimensional association authentication of "human-machine-environment"; The unified authentication and access control module is based on the attribute-driven access control ABAC engine. It implements dynamic authorization based on user identity, device status, access behavior, time and service type, and links with the intrusion detection system and boundary isolation policy to achieve a closed loop of "dynamic evaluation - immediate blocking - least privilege". The unified authentication and access control module also includes a Trusted Execution Environment (TEE) protection component, which is used to isolate critical applications and instructions in terminal devices and to evaluate the legality of device behavior in real time through terminal status monitoring. The unified authentication and access control module combines role-based access control (RBAC) with a zero-trust architecture. It integrates user identities and permissions across business systems through a unified authentication platform and deploys a zero-trust boundary agent at the access network boundary, ensuring that the train control system always operates in a controlled network environment.
[0007] Preferably, the network slicing configuration module, based on 5G core network slicing technology, divides the network slices into: train operation control slice, video surveillance slice, and Internet of Things slice, and reserves corresponding resources and priorities for each slice; The network slice configuration module also establishes a mapping relationship between various services and slices, and adopts an on-demand scheduling strategy to ensure the performance of critical services.
[0008] Preferably, the physical isolation and logical domain-based security architecture adopts a hybrid networking mode of "physical private network + virtual slicing". A virtual private network (UPF) is deployed on the operator network side, and a UPF is deployed on the rail transit side to achieve physical isolation of train control services. At the same time, firewalls, multi-level security gateways and security operations centers (SOCs) are deployed at the network layer to block cross-domain penetration attacks through shared threat intelligence and user plane integrity protection mechanisms.
[0009] Preferably, the end-to-end encryption and key management unit encrypts and protects the entire vehicle-to-ground communication data. It encrypts high-security business data that meets preset requirements by introducing national cryptographic algorithms, and implements hierarchical key management for different security levels of business, including periodic rotation, dynamic distribution and automatic revocation of high-level keys. Combined with the zero-trust on-demand authorization principle, it only opens access to encrypted data when the terminal identity and context are valid, thereby achieving "minimum data visibility".
[0010] Preferably, the simulation test platform module includes: a 5G network constructed from a real 5G public network and software radio, a sinking edge MEC node, an actual train control system, and simulated train control auxiliary equipment. The platform loads actual line and train parameters to realize a realistic train-to-ground communication scenario; at the same time, it integrates attack simulation devices and multi-level security protection equipment to construct an attack and defense confrontation environment.
[0011] This invention also provides a method for ensuring communication security in urban rail transit based on 5G public network access. The method is implemented through the aforementioned system and includes: On the rail transit side, MEC edge computing nodes, multi-level firewalls, IDS / IPS, and security gateways are deployed; on the operator network side, a hybrid mode of physical private network plus virtual slicing is used to connect to the urban rail transit system. The unified identity authentication management center is used to implement multi-factor authentication for all access terminals and to perform remote integrity verification during the access process; Multiple network slices are created in the 5G network based on service type and priority, and computing, network and radio resources are reserved for each slice according to 5QI, resource type and service priority; The entire chain of train control operations and critical data is encrypted, using national cryptographic algorithms and hierarchical key management strategies, and a zero-trust on-demand authorization mechanism is combined to dynamically open decryption access during data transmission. Lightweight intrusion detection modules are deployed at the edge of rail transit systems to perform real-time analysis of terminal traffic and issue local alerts; AI-IDS is deployed at the central side to perform deep learning analysis on aggregated traffic logs; the system shares threat intelligence through the Security Operations Center (SOC) to quickly block DDoS and APT attacks. The system's protection effectiveness was verified by loading a real train control system and network environment model onto the simulation test platform and using DDoS attacks, fake base station man-in-the-middle attacks, and protocol fuzzing attacks. The system's performance was then evaluated using key indicators.
[0012] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention achieves dual physical and logical isolation between the 5G public network and rail transit services. It utilizes slicing technology and a downlinked UPF to ensure priority for train control services; multi-factor authentication, ABAC, and TEE technologies ensure trusted terminal access; end-to-end national cryptographic encryption and dynamic key management provide strong security guarantees; AI-driven multi-layered intrusion detection improves protection efficiency; and a comprehensive simulation testing platform provides a realistic and controllable environment for verifying system performance and security mechanisms. Compared to existing technologies, this invention constructs a unified security architecture and testing system covering the end-to-cloud, achieving secure and reliable communication for 5G access in urban rail transit. Attached Figure Description
[0013] To more clearly illustrate the technical solution of the present invention, the drawings used in the embodiments are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This is a diagram of the 5G network architecture for urban rail transit according to an embodiment of the present invention; Figure 2 This is a schematic diagram illustrating identity authentication and access control based on a zero-trust architecture according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the data encryption process according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the intrusion detection process according to an embodiment of the present invention; Figure 5 This is a schematic diagram of a slice security isolation mechanism for multiple services in urban rail transit according to an embodiment of the present invention; Figure 6 This is a schematic diagram of the test platform architecture in an embodiment of the present invention. Detailed Implementation
[0015] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0016] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0017] Example 1 This invention combines technologies such as 5G network slicing, zero-trust access control, encrypted transmission, and intrusion detection to provide a secure and reliable public network access solution for urban rail transit services (such as train operation control, video surveillance, and passenger information). Specifically: This invention provides a communication security system for 5G public network access in urban rail transit, comprising the following modules: The unified authentication and access control module is configured with a multi-factor authentication mechanism and device attribute authentication to achieve three-dimensional association authentication of "human-machine-environment". The module is based on the attribute-driven access control (ABAC) engine, which implements dynamic authorization based on context information such as user identity, device status, access behavior, time and service type, and links with the intrusion detection system and boundary isolation strategy to achieve a closed loop of "dynamic evaluation-instant blocking-least authorization". The network slicing configuration module, based on 5G core network slicing technology, divides the network into multiple slices, including at least: train operation control slices (latency ≤ 50ms, reliability ≥ 99.999%), video surveillance slices (uplink bandwidth ≥ 100Mbps), and IoT slices (high connection density), reserving corresponding resources and priorities for each slice. The module also establishes a dynamic mapping relationship between various services and slices, and implements on-demand scheduling based on a joint optimization model of service attributes and network status to ensure the performance and security of critical services such as train control. During the slice allocation phase, the system allocates slices according to service type... Characteristic parameters (including latency requirements) Reliability requirements and security level Calculate the overall priority function: ; in, For business Scheduling priority; , , These are the latency, reliability, and security weighting coefficients corresponding to different service types. This formula establishes a differentiated priority order for the performance requirements of different types of services, thereby achieving precise scheduling.
[0018] During resource allocation, the system constructs an optimization model with the goal of maximizing the utility of high-priority business operations: ; in, For business At any moment Use slices The resource utilization efficiency at that time reflects the comprehensive performance of slice bandwidth, latency, and reliability. The constraints are: ; in, For business The amount of resources required, For slices Total resource capacity Indicates business Assign to slice (Value can be 0 or 1).
[0019] When the system detects network anomalies or security threats, the Security Operations Center (SOC) updates the security posture coefficient in real time. Adjust business priorities: ; in, This indicates the impact of security posture on scheduling. When an attack or link anomaly is detected, a higher value is taken, thereby increasing the scheduling priority of critical services. Unlike existing scheduling methods based on static QoS parameters, the scheduling mechanism proposed in this module achieves dynamic resource optimization through a three-dimensional linkage of "service type - network status - security posture". It can complete slice reallocation and priority adjustment in milliseconds, ensuring the stable operation of train control services.
[0020] A physical isolation and logical domain-based security architecture is adopted, further including a security domain-based mechanism based on quantifiable isolation. The system employs a hybrid networking mode of "physical private network + virtual slicing," deploying Virtual Private User Plane Function (UPFc) on the operator's core network side and deploying a dedicated rail transit UPFe at the lower level to achieve physical isolation of train control services on the data plane. To quantitatively characterize the security isolation effect between different network domains, a cross-domain leakage probability model is introduced: ; in, This indicates the probability of potential information leakage between the public network and the private network; For the first Security vulnerability coefficient of class interface (calculated by combining protocol exposure surface and access frequency); Frequency of interface security events; This is the isolation strength factor, reflecting the comprehensive isolation capabilities of firewall rules, access control, and routing domain division policies between UPFs. The system improves this by... (For example, strengthening the integrity protection of the N9 interface and deploying a dual-layer security gateway) can enable This reduces the security level by an order of magnitude, thus achieving both physical and logical security for train control operations. Simultaneously, at the logical layer, the system implements dynamic threat control through multi-level firewalls, intrusion prevention systems (IDS / IPS), and a Security Operations Center (SOC). The SOC updates security posture parameters based on real-time threat intelligence. And adjust the domain protection strength through a security trust index calculation model: ; in, The current overall security and trustworthiness of the system; , These are the structure and situation weighting coefficients. When the system detects... Below the preset threshold When this occurs, a cross-domain blocking mechanism is automatically triggered to restrict the data interaction channel between the core UPF and the edge UPF, achieving dynamic security domain segmentation. Through the aforementioned quantifiable isolation model and security trust feedback mechanism, this module differs from existing static isolation-based designs, forming a physical-logical integrated protection system that can be evaluated in real time and adaptively strengthened, significantly improving the security resilience and verifiability of 5G public network access to rail transit services.
[0021] The end-to-end encryption and key management unit encrypts and protects the data of the entire vehicle-to-ground communication link. The unit introduces national cryptographic algorithms to encrypt high-security business data such as train control, and implements hierarchical key management for different security levels of business, including regular rotation, dynamic distribution and automatic revocation of high-level keys; combined with the zero-trust on-demand authorization principle, it only opens access to encrypted data when the terminal identity and context are valid, and achieves "minimum data visibility"; The intrusion detection and prevention module of this invention establishes a hierarchical collaborative detection mechanism between MEC edge nodes and the central AI platform. The edge side performs real-time feature extraction and initial anomaly screening using a lightweight traffic analysis model, while the central side performs comprehensive judgment based on a deep temporal learning model. To achieve a balance between detection efficiency and accuracy, a "temporal feature weighted detection model" is proposed, whose detection judgment function is defined as: ; in, For a moment The overall abnormality score; Indicates the first Class characteristics (such as packet rate, protocol field distribution, session duration, etc.); For feature normalization function; The feature weights are dynamically adjusted based on the type of rail transit business (e.g., train control business has the highest weight); This indicates the time-series prediction bias (difference between actual traffic patterns and prediction patterns) output by the central AI-IDS. The center correction factor. When When the threshold is determined by the system's self-learning, the system determines that abnormal behavior exists and triggers automatic defense. The edge MEC node first performs local blocking and isolation, and then uploads the feature summary to the central SOC to achieve a closed-loop defense of "edge detection - central confirmation - joint response". Unlike existing IDS that only rely on feature matching or single-point detection, this module combines a time-series prediction bias and a dynamic feature weight adjustment mechanism, which can maintain a high recognition rate (>99%) and a low false alarm rate (<1%) in complex attack scenarios such as DDoS, APT and slow penetration. The simulation test platform module includes: a 5G network constructed from a real 5G public network and software-defined radio, a sinking edge MEC node, an actual train control system (Zone Controller, Vehicle Controller, and Vehicle Controller), and simulated train control auxiliary equipment (computer interlocking, ATS equipment). The platform loads actual line and train parameters (such as line length, station information, train model, operating speed, and passenger capacity) to achieve a realistic train-to-ground communication scenario. It also integrates attack simulation devices (DDoS traffic generator, fake base station, protocol fuzzing testing tool) and multi-level security protection equipment (IPsec / SSL tunnel security gateway, traffic behavior analysis IDS, blockchain evidence storage platform, and dynamic identity authentication component) to construct an attack and defense environment. This test platform can simulate environmental conditions such as high-speed train movement, tunnel fading, multipath interference, and handover failure, and dynamically inject attack events. It provides protection for train control services through high-reliability, low-latency slicing to verify the system's performance in terms of throughput, latency, reliability (≥99.999% availability), and anti-attack capabilities.
[0022] In this embodiment, the urban rail transit 5G public network architecture design aims to improve network reliability and meet the requirements of the train operation control system. The invention proposes a 5G-based redundant A / B dual-network for vehicle-to-ground communication. The A / B dual-network transmits train control services via wired networks. Network A comprehensively carries all urban rail transit services, including train control, trunking communication, and video surveillance, while network B only carries train control services. The train control system uses two physically independent 5G TAUs, each carrying data from networks A and B respectively. Because network A comprehensively carries many services, including a large amount of streaming media data, and the volume of streaming media data is increasing, the urban rail transit ground 5G network solution adopts a leaky cable-based transmission architecture. The trackside access is via a 5G RRU connected to the leaky cable, and the 5G BBU is connected to the 5G core network via fiber optic cable. The 5G core network is co-located with the subway dispatch center in a single equipment room. The 5G-based ground and in-vehicle 5G A / B network architecture is as follows: Figure 1 As shown.
[0023] To improve the reliability of non-train-controlled services during integrated A-network transport, a redundant backup scheme for onboard TAUs was designed. Specifically, two 5G TAUs are used for primary / backup redundancy on the vehicle for A-network integrated transport media streams. If one TAU fails, the system switches to the other, thus further improving the reliability of all services without increasing traffic volume. The redundant networking on the onboard TAU LAN (local area network) side adopts the VRRP (Virtual Router Redundancy Protocol) protocol. Typically, onboard network equipment needs to be configured with a default route (i.e., gateway) to achieve communication with external networks.
[0024] For details: see Figure 1 In this embodiment, the security system includes the operator's 5G network and urban rail transit-side equipment. The operator side deploys a 5G core network (including AMF, SMF, UDM, etc.) and a slice management unit; the urban rail transit side deploys an MEC edge computing platform (including a downlink UPF), multi-level firewalls, IDS / IPS, secure access gateways, and a security operations center. Terminal equipment includes onboard 5G-TAU base stations, train cluster dispatch consoles, handheld terminals, and trackside sensors, some of which have biometric authentication or a Trusted Execution Environment (TEE). The system adopts a hybrid networking mode of "physical private network + virtual slice," where train control services are transmitted through the operator's "premium mode" physical slices, and the user plane function (UPF) is downlinked to the rail transit side for local data processing, achieving physical isolation of critical services; video surveillance and operation and maintenance services are assigned to independent virtual slices. To achieve performance assurance and security monitoring under multi-slice collaboration, the system establishes a slice dynamic scheduling and flow control model, whose performance constraints can be expressed as: ; in, For slices End-to-end latency, Based on propagation delay, Indicates business arrival rate With service speed The ratio (i.e., slice load factor). The system adjusts in real time. (i.e., bandwidth allocation) and routing paths, ensuring that critical service slices remain on... Within the stable range, the system ensures that the train control service latency is ≤ 50ms. At the encrypted transmission level, the system employs a symmetric encryption mechanism, the security strength of which can be expressed as: ; in, To calculate the probability of a successful brute-force attack. The encryption key length (in bits) under the AES-256 algorithm. It meets the Level 3 protection requirements of the Cybersecurity Classified Protection 2.0. Through the joint design of the above performance scheduling and encryption strength model, this invention achieves secure isolation and dynamic situational control across slice services while ensuring low latency and high reliability of train control communication.
[0025] In this embodiment, as Figure 2 As shown, all terminals and users accessing the rail transit 5G network must be authenticated by a unified identity authentication center. The authentication process employs multi-factor authentication, including digital certificates, passwords, biometrics, and terminal software integrity verification. This "human-machine-environment" three-dimensional authentication approach enhances authentication credibility. After successful access, the access control engine performs real-time evaluation of the session based on the ABAC strategy, determining whether to authorize access to the corresponding service slice based on factors such as user role, terminal type, access time, and service type. Simultaneously, the system deploys zero-trust proxies and multi-layered firewalls at the network boundary to ensure that critical services such as train operation control always operate in a trusted network environment. If abnormal behavior is detected (such as communication anomalies or unauthorized access), the intrusion detection system will trigger blocking policies in real time, forming a closed-loop control mechanism of "dynamic evaluation - immediate blocking - minimum authorization."
[0026] The unified authentication and access control module further introduces a dynamic trust calculation mechanism based on a Trusted Execution Environment (TEE) to achieve real-time legitimacy assessment and access decision-making for terminal behavior. The system runs an independent identity authentication agent within the terminal's TEE, performs encrypted measurement of the execution status of key instructions, and calculates a comprehensive trust value based on device operating status, geographical location, and behavioral characteristics. The trust assessment function is defined as follows: ; in, For end users At any moment Trust score; This is a device integrity metric (calculated from the TEE metric register, with a value of 0-1). For compliance with historical access requirements; Real-time behavior deviation (probability of abnormal terminal commands detected by AI model); Weighting coefficients (satisfying) The system only... Access to the train control system or critical control interfaces is permitted only when permitted; otherwise, TEE isolation and re-authentication are automatically triggered. Furthermore, the unified authentication platform combines Role-Based Access Control (RBAC) and Zero Trust Architecture (ZTA) to dynamically authorize cross-system identities and permissions. Let the set of user access requests be... Its access authorization matrix is defined as follows: ; in, Indicates user Resources Whether access is granted (1 for allow, 0 for deny). This matrix is dynamically maintained by the zero-trust boundary agent on the access network side, and ensures that critical services such as the train control system always operate in a controlled and trusted environment through continuous verification and the least privilege policy.
[0027] Unlike traditional static RBAC, the zero-trust dynamic authorization mechanism based on TEE trust scoring proposed in this invention can achieve millisecond-level access decision adjustment, avoiding the terminal from maintaining a high-privilege state for a long time after being compromised, thereby significantly improving the security resilience and adaptive defense capability of 5G public network access to rail transit systems.
[0028] In this embodiment, in the physical isolation and logical domain security architecture, a dedicated physical network (UPF) in the operator's "premium mode" is used for high-security services such as train operation control, while secondary services such as video surveillance and passenger information systems are carried by independent virtual slices. The system achieves high availability and tamper-proof capability for critical data and control commands through technologies such as dual-machine hot standby, link redundancy and blockchain notarization.
[0029] In this embodiment, the end-to-end encryption and key management unit employs different encryption protocols for data at different service levels: train control services use high-strength symmetric encryption algorithms (such as AES-256) or national cryptographic algorithms; video services use TLS 1.3 and SRTP protocol link encryption; and critical control instructions are stored on the blockchain to ensure integrity and immutability. Specifically, a full-link data encryption and differentiated protection strategy is designed. End-to-end encryption is used for critical rail transit data transmitted over the 5G public network, prioritizing the introduction of national cryptographic algorithms to ensure high-strength security and compliance of the encryption system. During the link access phase, the onboard terminal and MEC negotiate a temporary session key using public-key encryption technology (such as SM2). The onboard terminal first randomly generates a temporary private key. With its own public key The ciphertext is generated using SM2 encryption and sent to the MEC node. The SM2 encryption process formula is as follows: ; in, This is a temporary random number; It is the base point of the elliptic curve; The recipient's public key; The plaintext data to be encrypted; Represents a hash function (such as the SM3 hash function); the symbol " " indicates a bitwise XOR operation;" This indicates a message concatenation operation. The formula means: first, concatenate the random number... Multiply by base point Generate temporary public key Then use the recipient's public key With random numbers Generate shared points Then through a hash function Derived keystream, for plaintext Perform an XOR operation to obtain the ciphertext. And calculate the integrity check code. MEC nodes utilize private keys Complete the ciphertext decryption and establish a temporary session key with the vehicle terminal. The collaboration ensures the confidentiality and integrity of the key exchange process.
[0030] After the session key is established, the data transmission phase employs a symmetric encryption algorithm (such as SM4) to encrypt the business data blocks. The SM4 encryption process formula is as follows: ; in, For plaintext data blocks, The symmetric key generated for temporary negotiation. This is an SM4 encryption function; the encrypted output is ciphertext. Furthermore, the SM4 algorithm is a block cipher algorithm with a 128-bit block length, a 128-bit key length, and 32 rounds of iteration. Its core round function is defined as follows: ; in, For each round of input, four 32-bit words are entered. This is the output result for this round. For the first The wheel key. The wheel function. Defined as: ; Among them, the symbol " " indicates bitwise XOR operation; function It is a composite function that includes S-box substitution and linear transformation, where S-box substitution achieves nonlinear mapping and linear transformation guarantees key diffusion properties; For the first The wheel key (generated by the key expansion algorithm).
[0031] The SM4 algorithm enables high-performance block encryption and decryption, and is suitable for data protection of high-frequency services such as train control data and video stream data. It is particularly suitable for deployment in terminal chips or MEC edge nodes for rapid hardware acceleration.
[0032] Figure 3The process of the SM2 / SM4 hybrid encryption communication mechanism was demonstrated. The onboard terminal first sends a random number and public key information to the MEC node using SM2 encryption to complete key negotiation. Then, the terminal uses the negotiated symmetric key to encrypt the service data using the SM4 algorithm before sending it to the MEC node, which then decrypts and processes the data. Through this phased, algorithm-based encryption system design, end-to-end protection of rail transit service data from the access point to the platform is achieved, effectively improving data security in the public network communication environment of rail transit.
[0033] This invention employs differentiated encryption strategies to protect data security for different communication services. In the train control system, all communication data is encrypted using high-strength national cryptographic algorithms (such as SM4 / AES-256). For CBTC train control services, key hierarchy and lifecycle management are also implemented: high-level key management requirements are set, and keys are periodically rotated, dynamically distributed, and automatically revoked to ensure key security. In services such as video surveillance, TLS 1.3 and SRTP protocols are used to encrypt video streams, preventing eavesdropping and interception attacks. The encryption process incorporates the zero-trust principle, granting decryption permissions only when the terminal and user context are legitimate, achieving "minimum data visibility" and avoiding boundary leaks.
[0034] like Figure 5 As shown, regarding network resource isolation, three typical slices are configured according to the different QoS requirements of vehicle and ground services: the train control slice guarantees uplink / downlink latency ≤50ms and reliability ≥99.999%, and reserves resource blocks (RBs); the video slice guarantees uplink bandwidth ≥100Mbps and reserves sufficient spectrum; the IoT slice supports high connection density. On the core network side, SDN / NFV technology is used to orchestrate computing, storage, and forwarding resources to ensure end-to-end isolation between slices. In addition, data plane isolation is achieved by deploying VPNs, virtual LANs, or Layer 2 isolation mechanisms between slices to prevent lateral penetration.
[0035] In this embodiment, the AI-IDS engine of the intrusion detection and prevention module combines a hybrid detection method, integrating rule matching, behavior modeling, and protocol analysis. The system establishes a multi-dimensional behavioral indicator probability map, sets dynamic threshold alarms for abnormal behaviors, and supports red-blue team exercises to verify response timeliness (response time ≤ 30 seconds). Specifically, to comprehensively monitor potential abnormal behaviors during 5G public network communication in urban rail transit, a Gaussian distribution anomaly detection model is introduced to probabilistically model terminal communication behavior and service data flow characteristics in the rail transit network, identifying abnormal events that deviate from the normal pattern. In actual deployment, the system will collect features such as communication frequency, session duration, transmission rate, and protocol usage frequency of various terminals to form a multi-dimensional behavioral dataset, and use a Gaussian distribution to model the probability density distribution of each feature under normal conditions. Let a certain behavioral feature variable be... Under normal circumstances, it follows a univariate Gaussian distribution, and its probability density function is: ; in, This represents the mean of the normal sample. For variance; For observation values The probability of occurrence.
[0036] The system uses normal communication behaviors collected over a period of time as training samples to estimate the performance of each feature dimension. and During the real-time detection phase, if the probability density function values of a certain communication behavior sample are lower than a set threshold in multiple dimensions... If so, the behavior can be determined to be abnormal: ; Figure 4 This document details the intrusion detection design mechanism, illustrating the complete process from data acquisition to feature extraction, anomaly detection, and response handling. The data acquisition section comprises two sub-modules: an edge traffic probe and a terminal data collector, enabling functions such as collecting onboard terminal logs and capturing southbound / northbound traffic from edge MEC nodes. The feature extraction section extracts behavioral characteristics such as communication frequency, packet size, protocol type distribution, and session duration for anomaly detection. The anomaly detection section employs Gaussian distribution modeling and anomaly analysis, using a probability density function to determine abnormal behavior. If the Gaussian model determines an anomaly, the response handling section is executed. First, an alarm log is generated, and then the alarm information is pushed to the rail transit operator's safety command center. The command center may manually confirm or process the alarm automatically. Then, based on the security center's decision, an instruction is sent to the SDN controller to forward the abnormal terminal to a closed area for protection and isolation. Finally, according to the policy settings, the abnormal traffic is migrated to a honeypot area for further observation of attack behavior.
[0037] Intrusion detection uses behavior recognition algorithms trained on deep learning models (such as CNN+LSTM) to receive log data from edge nodes, build a temporal model of terminal behavior, and identify high-order threats such as slow attacks, privilege abuse, and lateral movement. Deep neural networks (DNNs) are used in intrusion detection to identify complex attack patterns. Their structure includes an input layer, multiple hidden layers, and an output layer. The model's output can be represented as: ; in, This represents the predicted category probability distribution; , For the first Layer weights and biases; For the first The output of the layer.
[0038] This model is able to effectively learn from network traffic and identify anomalous behavior.
[0039] This invention also deploys honeypot systems in insecure systems to lure attackers into traps, extracting attack behavior characteristics to feed back into model training. Once high-risk behavior is detected, the system will trigger a linkage response mechanism, working in conjunction with the access control policy engine to immediately revoke the current session token and block its network path through the SDN controller, achieving an automatic response effect of "detection-identification-linkage-blocking".
[0040] This invention deploys an intrusion detection module at the edge of the rail transit system and a deep analysis engine at the center. The edge IDS can analyze the traffic generated by the UE side in real time, quickly detecting traffic anomalies or protocol anomalies. The AI-IDS on the core network side continuously collects network-wide traffic logs and analyzes them using deep learning and time-series behavioral models to identify covert attack patterns. For example, dynamic alarm thresholds are set for communication frequency anomalies and Modbus protocol anomalies through multi-dimensional behavioral indicator maps. When a threat is detected, the system coordinates with the security operations center to link the firewall and IDS, automatically blocking the attack chain and initiating tracing. Red team / blue team exercises have shown that this embodiment can initiate response measures within ≤30 seconds after an attack occurs.
[0041] In this embodiment, the simulation test platform includes a wireless channel simulator in the simulated environment, which can simulate tunnel multipath fading, high-speed train movement, and handover processes. The platform dynamically allocates high-reliability, low-latency network slices for train control services through QoS policies, and integrates threat intelligence and AI anomaly detection through the Security Operations Center (SOC) to achieve automatic identification and response to injection attacks. Specifically, a 5G security simulation test platform for urban rail transit is built. This platform integrates real equipment and a simulation environment, including a real 5G network (operator public network and software radio platform), a downlink MEC, an actual train control system (Zone Control Center, Vehicle Control Center, VOBC), and simulated interlocking / ATS equipment. The platform loads actual line, train, and CBTC control logic data to simulate train-to-ground communication scenarios. For security attack and defense, it integrates two-way facilities: attackers deploy DDoS traffic generators, fake base stations, and protocol fuzzing testing tools; defenders deploy multi-level IPsec / SSL encrypted tunnels, IDS based on traffic behavior analysis, blockchain notarization, and dynamic authentication mechanisms. The test environment can simulate complex channel conditions such as high-speed train movement, multipath fading, and handover failure, dynamically inject attack events, and ensure the transmission of train control services through high-reliability, low-latency slicing.
[0042] like Figure 6 As shown, this embodiment establishes a simulation test platform to verify the feasibility and performance of the security solution. The platform hardware includes a real operator's 5G base station, a software-defined radio 5G simulator, an MEC server, and a vehicle-to-ground communication protocol simulator. The train control system is partially connected to a real Zone Controller (ZC) and Vehicle Controller (VOBC), supplemented by simulated computer interlocking and ATS equipment, loading actual line parameters (kilometers, station distribution) and train parameters (train formation, speed, passenger capacity, etc.). The security attack and defense modules include a DDoS flooding traffic generator, a fake base station man-in-the-middle device, and a protocol fuzzing testing tool on the attack side, and a multi-level security gateway (establishing an IPsec / SSL encrypted tunnel), behavioral analysis IDS, a blockchain evidence storage platform, and a multi-factor authentication system on the defense side. During testing, complex scenarios such as train movement, tunnel environment fading, and frequent switching can be simulated, and abnormal events such as DDoS, wireless hijacking, and protocol attacks can be injected. The platform is configured with high-reliability, low-latency slices specifically to carry train control services, and integrates threat intelligence and AI detection under the monitoring of the security operations center to achieve end-to-end attack identification and emergency response.
[0043] In this embodiment, as Figure 6As shown, comprehensive security testing was conducted on the simulation platform for different business layers. For example, the effectiveness of blocking unauthorized access and the integrity of video encryption were verified for Level 2 services (CCTV, PIS, etc.); for Level 3 services (train control system), the robustness of the protocol and the integrity protection of control commands were tested. The train control system test adopted two-factor authentication (U-Key + biometrics) and a blockchain evidence storage platform to verify the anti-tampering capability of control commands during communication. In addition, fuzz testing tools were used to attack CBTC and Modbus / TCP protocols to determine the self-healing time of the terminal protocol stack (≤30 seconds in this embodiment) and the filtering efficiency of the security gateway. In terms of overall performance, the system needs to meet the requirements of encrypted throughput ≥1Gbps, inter-slice isolation ≥30dB, and ensure the reliability of train control services ≥99.999% under multi-service concurrency and attack conditions.
[0044] Example 2 This invention also provides a communication security method for 5G public network access in urban rail transit, comprising the following steps: a) Deploy a security architecture: Deploy MEC edge computing nodes (including core network functions such as UPF, AMF, SMF, and UDM) and security devices such as multi-level firewalls, IDS / IPS, and security gateways on the rail transit side; on the operator network side, a hybrid mode of physical private network plus virtual slicing is used to connect to the urban rail transit system; b) Terminal access authentication: Utilize a unified identity authentication management center to implement multi-factor authentication for all access terminals, including digital certificates, device fingerprints, biometrics, etc., and perform remote integrity verification during the access process; c) Slice resource scheduling: Create multiple network slices in the 5G network based on service type and priority, and reserve computing, network and radio resources for each slice according to 5QI, resource type and service priority; d) Encrypted data transmission: Full-link encryption is applied to train control operations and critical data, using national cryptographic algorithms and hierarchical key management strategies, and a zero-trust on-demand authorization mechanism is used to dynamically open decryption access during data transmission; e) Operation monitoring and detection: Deploy lightweight intrusion detection modules at the edge of rail transit to perform real-time analysis of terminal traffic and issue local warnings; deploy AI-IDS at the central side to perform deep learning analysis on aggregated traffic logs; the system shares threat intelligence through the Security Operations Center (SOC) to quickly block DDoS, APT and other attacks. f) Simulation testing and verification: Load real train control system and network environment models on the simulation test platform, including vehicle-to-ground communication protocols (such as CBTC, Modbus / TCP) and complex channel simulation. Verify the system protection effect through attack methods such as DDoS attacks, fake base station man-in-the-middle attacks, and protocol fuzzing tests. Evaluate the system performance through key indicators (throughput ≥1Gbps, availability ≥99.999%, response latency ≤50ms, etc.).
[0045] This invention constructs a complete security architecture and verification platform suitable for 5G public network access in urban rail transit by coordinating multiple security technologies, and realizes an efficient and feasible communication security solution.
[0046] The embodiments described above are merely preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Various modifications and improvements made to the technical solutions of the present invention by those skilled in the art without departing from the spirit of the present invention should fall within the protection scope defined by the claims of the present invention.
Claims
1. A 5G public network access-based urban rail transit communication safety system, characterized in that, The system includes: a unified authentication and access control module, a network slicing configuration module, a physical isolation and logical domain security architecture, an end-to-end encryption and key management unit, an intrusion detection and prevention module, and a simulation testing platform module; The unified authentication and access control module is used to implement a unified identity authentication and access control mechanism; The network slice configuration module is used to divide multiple network slices based on 5G core network slicing technology. The physical isolation and logical domain separation security architecture is used to achieve physical isolation of the column control business, while blocking cross-domain penetration attacks; The end-to-end encryption and key management unit is used to design end-to-end data encryption and differentiated protection strategies; The intrusion detection and prevention module is used to build an edge-center collaborative intrusion detection system. Lightweight traffic analysis and feature recognition components are deployed on MEC nodes to perform local real-time detection and early warning of access terminal data. Deep learning-driven AI-IDS is deployed on the central platform to centrally model and analyze the network traffic logs. The simulation test platform module is used to simulate tunnel multipath fading, high-speed train movement, and handover processes; it dynamically divides network slices for train control services through QoS policies, and integrates threat intelligence and AI anomaly detection through the Security Operations Center (SOC) to achieve automatic identification and response to injection attacks.
2. The system according to claim 1, characterized in that, The unified authentication and access control module is configured with a multi-factor authentication mechanism and device attribute authentication to achieve three-dimensional "human-machine-environment" association authentication; The unified authentication and access control module is based on the attribute-driven access control ABAC engine. It implements dynamic authorization based on user identity, device status, access behavior, time and service type, and links with the intrusion detection system and boundary isolation policy to achieve a closed loop of "dynamic evaluation - immediate blocking - least privilege". The unified authentication and access control module also includes a Trusted Execution Environment (TEE) protection component, which is used to isolate critical applications and instructions in terminal devices and to evaluate the legality of device behavior in real time through terminal status monitoring. The unified authentication and access control module adopts a combination of role-based access control (RBAC) and zero-trust architecture, and integrates user identity and permissions across business systems through a unified authentication platform. Furthermore, a zero-trust boundary agent is deployed at the access network boundary to ensure that the train control system always operates in a controlled network environment.
3. The system according to claim 1, characterized in that, The network slicing configuration module, based on 5G core network slicing technology, divides network slices into: train operation control slice, video surveillance slice, and Internet of Things slice, and reserves corresponding resources and priorities for each slice; The network slice configuration module also establishes a mapping relationship between various services and slices, and adopts an on-demand scheduling strategy to ensure the performance of critical services.
4. The system according to claim 1, characterized in that, The physical isolation and logical domain-based security architecture adopts a hybrid networking mode of "physical private network + virtual slicing". A virtual private network (UPF) is deployed on the operator network side and a UPF is deployed on the rail transit side to achieve physical isolation of train control services. At the same time, firewalls, multi-level security gateways and security operations centers (SOCs) are deployed at the network layer to block cross-domain penetration attacks through shared threat intelligence and user plane integrity protection mechanisms.
5. The system according to claim 1, characterized in that, The end-to-end encryption and key management unit encrypts and protects the data of the entire vehicle-to-ground communication link. It introduces national cryptographic algorithms to encrypt high-security business data that meet preset requirements, and implements hierarchical key management for different security levels of business, including regular rotation, dynamic distribution and automatic revocation of high-level keys. Combining the zero-trust on-demand authorization principle, encrypted data access is only granted when the terminal identity and context are valid, thus achieving "minimum data visibility".
6. The system according to claim 1, characterized in that, The simulation test platform module includes: a 5G network constructed from a real 5G public network and software radio, a sinking edge MEC node, an actual train control system, and simulated train control auxiliary equipment. The platform loads actual line and train parameters to realize a realistic train-to-ground communication scenario; at the same time, it integrates attack simulation devices and multi-level security protection devices to construct an attack and defense confrontation environment.
7. A method for ensuring communication security in urban rail transit based on 5G public network access, wherein the method is implemented using the system described in any one of claims 1-6, characterized in that, The method includes: On the rail transit side, MEC edge computing nodes, multi-level firewalls, IDS / IPS, and security gateways are deployed; on the operator network side, a hybrid mode of physical private network plus virtual slicing is used to connect to the urban rail transit system. The unified identity authentication management center is used to implement multi-factor authentication for all access terminals and to perform remote integrity verification during the access process; Multiple network slices are created in the 5G network based on service type and priority, and computing, network and radio resources are reserved for each slice according to 5QI, resource type and service priority; The entire chain of train control operations and critical data is encrypted, using national cryptographic algorithms and hierarchical key management strategies, and a zero-trust on-demand authorization mechanism is combined to dynamically open decryption access during data transmission. Lightweight intrusion detection modules are deployed at the edge of rail transit systems to perform real-time analysis of terminal traffic and issue local alerts; AI-IDS is deployed at the central side to perform deep learning analysis on aggregated traffic logs; the system shares threat intelligence through the Security Operations Center (SOC) to quickly block DDoS and APT attacks. The system's protection effectiveness was verified by loading a real train control system and network environment model onto the simulation test platform and using DDoS attacks, fake base station man-in-the-middle attacks, and protocol fuzzing attacks. The system's performance was then evaluated using key indicators.