Railway signal system based on trusted computing security computing protection technology

By combining hardware trusted modules and a central trusted management platform with lightweight agents, a dynamic trusted protection framework for railway signaling systems is constructed. This solves the security and efficiency issues in the operation and maintenance process, realizes end-to-end trusted verification and hierarchical response, and improves the security and operation and maintenance efficiency of railway signaling systems.

CN122113178APending Publication Date: 2026-05-29CHINA STATE RAILWAY GRP CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA STATE RAILWAY GRP CO LTD
Filing Date
2026-01-30
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Railway signaling systems suffer from weak internal threat protection capabilities, lack of trusted verification across the entire operation and maintenance chain, insufficient lightweight and real-time capabilities, and disconnect from operation and maintenance scenarios during operation and maintenance. Existing security solutions are unable to effectively identify high-risk behaviors and achieve end-to-end trusted protection.

Method used

Using a hardware trusted module as the root of trust, the central trusted management platform performs trusted measurement and verification on the operation and maintenance terminals, communication links and equipment, builds a dynamic trusted benchmark model for equipment and operation and maintenance personnel, and uses a lightweight trusted agent to monitor the operation and maintenance process in real time and implement hierarchical response measures.

Benefits of technology

It achieves end-to-end trusted verification, improves the security and efficiency of the operation and maintenance process, reduces the false alarm rate, ensures the smoothness and security of the operation and maintenance process, and meets the requirements of railway signaling systems for high reliability and high availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122113178A_ABST
    Figure CN122113178A_ABST
Patent Text Reader

Abstract

The application discloses a kind of railway signal system security computing protection technology and system based on trusted computing.The application takes hardware trusted module as trust root, constructs the end-to-end trusted verification chain covering operation and maintenance terminal, communication link and destination device;Through the trusted management platform of center, the trust measurement and white list management of operation and maintenance tool are realized;Deeply integrate railway "window time" and standard operation process, construct device dynamic trusted benchmark model, and generate operation and maintenance personnel behavior trusted model based on historical behavior data;Deploy lightweight trusted agent to monitor operation and maintenance behavior in real time, and implement hierarchical response and authority control to behaviors deviating from the two models.The application realizes dynamic trusted protection in the whole operation and maintenance process, effectively improves the active defense capability against internal and external threats, balances safety strength and operation and maintenance efficiency, and provides business-aware security protection for railway signal system and key infrastructure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology for rail transit, and in particular to a secure computing protection technology and system for railway signaling systems based on trusted computing. Background Technology

[0002] As a core infrastructure ensuring safe train operation, the reliability and security of railway signaling systems are directly related to the nation's transportation lifeline and public safety. With the development of intelligent and networked railways, signaling systems are gradually adopting general-purpose computing platforms and IP-based communication architectures. While improving operational efficiency, this also presents increasingly severe cybersecurity threats. Currently, operational security protection mainly relies on traditional boundary protection technologies (such as firewalls and intrusion detection systems) and static access control mechanisms, which have the following prominent technical bottlenecks:

[0003] Weak internal threat protection: Existing solutions focus on network perimeter defense, lacking effective monitoring of misoperations, unauthorized operations, or malicious behavior by authorized maintenance personnel. In actual operation and maintenance, security incidents caused by backdoors implanted in maintenance tools, abnormal operation commands, or unplanned operations occur frequently, and traditional "username + password" authentication mechanisms are insufficient to identify behavioral risks.

[0004] The lack of trusted verification across the entire operation and maintenance chain: Existing trusted computing technologies mostly focus on static integrity measurements during the device startup phase (such as TPM / TCM measurements of BIOS and OS), but railway signaling system operation and maintenance involves multiple stages: "terminal → network → target device".

[0005] The trusted status of the operation and maintenance terminal cannot be dynamically verified (e.g., the system has been tampered with during operation).

[0006] Changes in the configuration of network devices in the communication link are difficult to detect in real time.

[0007] The lack of runtime verification mechanisms for the trustworthiness of operation and maintenance tools makes them easy targets for attacks.

[0008] Disconnected from railway operation and maintenance scenarios: Railway signaling system operation and maintenance is characterized by high timeliness (strictly limited "maintenance windows" from 00:00 to 04:00) and high process standardization (standard operating sequences), but existing security solutions have not established dynamic and reliable benchmarks coupled with business logic. For example, they cannot identify high-risk behaviors such as "configuration modifications outside of maintenance windows" or "abnormal operation command sequences," and also lack the ability to model and detect deviations from the historical behavior patterns of maintenance personnel.

[0009] Insufficient lightweight and real-time performance: Signal field equipment (such as interlocking machines and train control centers) has limited computing resources, and existing trusted proxy modules are bulky and resource-intensive, making them difficult to deploy in embedded environments; at the same time, there is a lack of hierarchical response mechanisms for abnormal behavior (such as low-risk alarms and high-risk real-time blocking), resulting in an imbalance between security policies and operational efficiency.

[0010] While some research attempts to introduce trusted computing into industrial control systems (such as the IEC 62443 standard framework), their solutions have not been deeply adapted to the specific characteristics of railway signaling system operation and maintenance. They have neither constructed a two-dimensional dynamic trusted model based on "equipment operation benchmarks + personnel behavior benchmarks" nor achieved end-to-end trusted chain closed-loop verification from hardware trust roots to operational behavior. Therefore, there is an urgent need for a dynamic trusted security protection technology that deeply integrates railway operation and maintenance business logic, possesses lightweight real-time monitoring capabilities, and covers all elements of "terminal-link-tool-behavior" to break the current passive situation in railway signaling system operation and maintenance security protection. Summary of the Invention

[0011] This invention addresses the shortcomings of existing technologies by providing a secure computing protection technology for railway signaling systems based on trusted computing.

[0012] To achieve the above-mentioned objectives, the technical solution adopted by the present invention is as follows:

[0013] A trusted computing-based security computing protection technology for railway signaling systems includes the following steps:

[0014] Using a hardware trusted module as the hardware root of trust, trusted link verification is performed on the operation and maintenance terminal, communication link and destination device.

[0015] Trustworthy operation and maintenance tools are measured and verified through the Central Trusted Management Platform (CTMP).

[0016] Based on the characteristics of railway signaling system operation and maintenance, a dynamic and reliable benchmark model for equipment and a reliable model for the behavior of operation and maintenance personnel are constructed.

[0017] The lightweight trusted agent monitors the operation and maintenance process in real time. When the operation and maintenance operation or the behavior of the operation and maintenance personnel deviates from the dynamic trusted benchmark model of the device or the trusted model of the behavior of the operation and maintenance personnel, the access permissions and execution permissions are restricted or denied, and the measurement results and operation behavior are reported to the central trusted management platform (CTMP).

[0018] Furthermore, the hardware trusted module is a domestically produced trusted cryptographic module (TCM) or an international TPM 2.0 chip.

[0019] Furthermore, the trusted link verification for the operation and maintenance terminal includes:

[0020] Trusted boot chain metrics are performed through a hardware trusted module, including BIOS firmware hash, Bootloader hash, kernel and driver hash, terminal agent hash, and critical configuration file hash.

[0021] Extend the metric to the Platform Configuration Register (PCR) corresponding to the Trusted Module to generate the Platform Configuration Summary (PCS).

[0022] The trusted module signs the terminal's trusted credential, and only after successful verification can the terminal initiate an operation and maintenance access request.

[0023] Furthermore, the trusted verification of the communication link includes:

[0024] The trusted status of each network device on the operation and maintenance request communication link is verified by the central trusted management platform (CTMP).

[0025] Illegal configuration changes can be identified by comparing the runtime configuration data of network devices with pre-stored trusted baselines.

[0026] The runtime configuration data includes the device basic identifier, layer 3 parameters, layer 2 parameters, layer 2 security policy, MAC table, and ACL configuration.

[0027] Furthermore, the trust measurement and verification of the operation and maintenance tools includes:

[0028] Before the tool is released, the Central Trusted Management Platform (CTMP) calculates the hash value of the tool file and core code segment, performs digital signature, and enters it into the trusted tool whitelist.

[0029] When a tool is invoked, the lightweight trusted agent calculates its memory image hash value through the hardware trusted module, compares it with the trusted tool whitelist, and verifies the digital signature.

[0030] Furthermore, the device dynamic trust benchmark model includes a time benchmark and an operation sequence benchmark:

[0031] The time reference is set based on the railway signaling system maintenance window time setting;

[0032] The operation sequence benchmark is built based on historical operation and maintenance records, and defines the standard operation command sequence, parameter range and execution order for specific devices.

[0033] Furthermore, the construction of the trustworthy behavior model for operations and maintenance personnel includes:

[0034] Clean the historical operation records of operations and maintenance personnel, and remove incomplete, erroneous or test data;

[0035] Perform aggregated analysis of operational behaviors based on operation and maintenance task modules;

[0036] For the "person-object-task" combination, operation commands, sequence features, time intervals and access paths are extracted, and a behavioral baseline is generated through sequence pattern mining algorithm.

[0037] Furthermore, the lightweight trusted proxy includes:

[0038] Trusted Root Service Layer: Provides a hardware abstraction interface, compatible with multiple types of trusted modules;

[0039] Data Acquisition and Measurement Layer: Performs multi-dimensional data acquisition and real-time reliable measurement;

[0040] Strategy and Model Execution Layer: Parses and executes the strategy and model files issued by the Central Trusted Management Platform (CTMP);

[0041] Interface and Communication Layer: Establish a secure communication channel based on the key distributed by the Central Trusted Management Platform (CTMP).

[0042] Furthermore, when an operation or maintenance action is detected to deviate from the device's dynamic trusted baseline model or the operation and maintenance personnel's trusted behavior model, the system implements a tiered response based on the degree of deviation:

[0043] Low risk: Log security information and trigger alerts;

[0044] Medium risk: Requires enhanced identity authentication;

[0045] High risk: Real-time interruption of operation and maintenance sessions and freezing of related account permissions.

[0046] This invention also discloses a railway signaling system based on trusted computing for secure computation protection, used to implement the aforementioned secure computation protection technology, comprising:

[0047] A lightweight trusted agent is deployed on the maintained equipment to schedule the hardware trusted module to perform runtime trust measurement and evidence collection.

[0048] The Central Trusted Management Platform (CTMP) is deployed in the security operations and maintenance management area for policy management, trusted verification, behavior analysis, dynamic access control, and audit log management.

[0049] The hardware trusted module, integrated into the motherboard of the terminal device, provides a hardware-level root of trust and supports security measurement, signature and key protection functions.

[0050] Compared with the prior art, the advantages of the present invention are as follows:

[0051] With trusted hardware modules as the root of trust, the system connects the entire link of "operation and maintenance terminal - communication link - operation and maintenance tools - target device" with trusted verification, extending security protection from the network boundary to the end of operation and maintenance behavior, effectively resisting complex security threats such as external attacks and internal unauthorized access and misoperation, and significantly enhancing the system's defense-in-depth capabilities.

[0052] This innovative approach integrates the unique "maintenance window" constraints of railway signaling systems with standard operating procedures to construct a dynamic and reliable benchmark model for equipment. Simultaneously, it establishes a personalized behavioral reliability model based on the historical behavioral characteristics of maintenance personnel. The synergistic effect of these two approaches ensures a high degree of alignment between safety strategies and business scenarios, significantly improving the accuracy of abnormal behavior identification, substantially reducing false alarms, and guaranteeing smooth and efficient normal operation and maintenance processes.

[0053] The trusted agent adopts a modular, layered architecture and a hardware abstraction layer design, resulting in extremely low resource consumption and seamless deployment on signal field equipment with limited computing resources. While continuously performing trusted measurements and behavior monitoring, it does not affect the real-time performance and stability of the core signal system operations, meeting the stringent requirements for high reliability and high availability in the rail transit sector.

[0054] The system intelligently determines the risk level based on the degree of behavioral deviation and flexibly adopts differentiated handling measures such as logging, enhanced authentication, and session blocking. This avoids operational interruptions caused by excessive protection while enabling rapid and accurate intervention in high-risk operations, effectively balancing the intensity of security control with on-site operational efficiency, and improving personnel compliance and system acceptance.

[0055] Implement dual verification of pre-release signatures and runtime for operation and maintenance tools to eliminate the risk of tool contamination at the source; retain tamper-proof measurement evidence, operation behavior and handling records throughout the process to form a complete and credible audit chain, providing solid support for security incident tracing, responsibility determination and national cybersecurity compliance requirements.

[0056] Breaking through the limitations of traditional trusted computing, which is confined to static startup verification, this technology achieves dynamic and continuous trusted protection for business scenarios for the first time, promoting the deep integration of the three elements of "hardware trust root, business rules, and personnel behavior." This technical framework can be extended to critical fields with stringent security and timeliness requirements, such as rail transit, smart grids, and industrial control, providing a reusable technical paradigm and practical path for the construction of the national critical information infrastructure security system. Attached Figure Description

[0057] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0058] Figure 1 This is a schematic diagram of the system architecture of an embodiment of the present invention;

[0059] Figure 2 This is a schematic diagram illustrating the principle of trust measurement during the operation of software maintenance tools in this embodiment of the invention. Detailed Implementation

[0060] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0061] The railway signaling system based on trusted computing security computing protection technology provided in this embodiment of the invention includes the following steps:

[0062] Using a hardware trusted module as the hardware root of trust, trusted link verification is performed on the operation and maintenance terminal, communication link and destination device.

[0063] The central trusted management platform is used to perform trusted measurement and verification of operation and maintenance tools.

[0064] Based on the characteristics of railway signaling system operation and maintenance, a dynamic and reliable benchmark model for equipment and a reliable model for the behavior of operation and maintenance personnel are constructed.

[0065] The lightweight trusted agent monitors the operation and maintenance process in real time. When the operation and maintenance operation or the behavior of the operation and maintenance personnel deviates from the dynamic trusted benchmark model of the device or the trusted model of the behavior of the operation and maintenance personnel, the access permissions and execution permissions are restricted or denied, and the measurement results and operation behavior are reported to the central trusted management platform.

[0066] like Figure 1 As shown, the detailed implementation steps of the present invention are as follows:

[0067] I. Building a Trusted Chain

[0068] (1) Terminal / Server Trust Measurement: When the device boots up, the following measurement chain is executed through the hardware trust module: BIOS firmware hash, Bootloader hash, kernel and driver hash, terminal agent program hash, and key configuration file (such as host, database configuration, business software, etc.) hash. All measurement values ​​are extended to the Platform Configuration Register (PCR) corresponding to the trust module. This register has read-only and tamper-proof characteristics and is the core carrier for the trust module to implement integrity measurement and trust verification. Its data can only be updated through dedicated instructions. Finally, a Platform Configuration Summary (PCS) is generated, which is signed by the trust module and used as the "terminal trust credential". If any measurement value is inconsistent with the pre-stored baseline when the device starts up (such as the BIOS being flashed or the maintenance tools being replaced), the PCS verification fails and the terminal cannot initiate an access request.

[0069] (2) Trustworthiness Measurement of Communication Link Devices: After the terminal initiated by the maintenance team passes the trust verification, it sends a trustworthiness verification request for the communication link to CTMP. CTMP verifies the trustworthiness of the network devices (switches / routers) traversed on the communication link of this maintenance request. The network topology of the railway signaling system is usually very stable, and the connection relationships between devices rarely change. Therefore, CTMP can collect, learn, and record the runtime configuration data of each network device in advance as a data fingerprint. The selected configuration data includes, but is not limited to, the following common data, which can be adjusted according to the site conditions:

[0070] Basic device identifiers: hostname, device model, system software version, device serial number (SN);

[0071] Layer 3 parameters: IPv4 / IPv6 address, subnet mask, gateway configuration;

[0072] Layer 2 parameters: Interface VLAN mode (Access / Trunk / Hybrid), list of VLANs allowed through Trunk;

[0073] Layer 2 security: Port security (MAC address binding, maximum number of accesses), storm control (broadcast / multicast / unknown unicast rate limiting);

[0074] MAC table: Static MAC address binding, MAC address aging time configuration;

[0075] ACL configuration: ACL number / name, rule matching conditions (source / destination IP, port, protocol), action (allow / deny).

[0076] (3) After CTMP verifies the trustworthiness of the device and communication link, it issues a one-time session key to the maintenance terminal and the target device to establish an end-to-end encrypted channel between the maintenance terminal and the target maintenance device. At the same time, it issues the trusted baseline model of the device and the behavior model of the maintenance personnel to the trusted agent of the target device for subsequent real-time monitoring.

[0077] (4) Trust Measurement of Software Operation and Maintenance Tools: Before release, all operation and maintenance software, scripts, firmware upgrade tools, etc., are subject to CTMP calculation of the hash value and digital signature of the tool file itself, as well as the core software code segment, i.e., the binary executable instructions generated after software compilation, including function calls, arithmetic operations, logical judgments, etc. (e.g., the .text (code segment) that will be divided after C program compilation), and read-only data segments (e.g., all const-modified constants, string literals, enumeration constants, etc. in C / C++), and are entered into a whitelist. When a tool is invoked, the trusted agent calculates the hash value of its memory image in real time through the interface provided by the hardware trusted module, compares it with the whitelist, and verifies the digital signature to ensure that the tool has not been tampered with. Figure 2 ).

[0078] II. Principles of Dynamic Reliability Benchmark Modeling for Signal Equipment

[0079] Common maintenance scenarios for railway signaling systems are as follows: maintenance operations are permitted during maintenance windows, but prohibited at other times. For example, a maintenance task might be to perform a software upgrade on the centralized signal monitoring station equipment during a maintenance window [00:00, 04:00]. Maintenance personnel would typically perform the following sequence of operations on the station equipment:

[0080] 1. Remotely log in to the station machine using a dedicated maintenance terminal → 2. Remotely upload the upgrade software file to the station machine's temporary directory → 3. Close the running station machine software → 4. Enter the software's directory → 5. Back up the old software → 6. Obtain the upgrade software file from the station machine's temporary directory to the station machine's software directory → 7. Start the station machine software → 8. Perform relevant tests on the software according to the signal system specifications → 9. Complete the maintenance operation within the scheduled time (usually within 2 hours).

[0081] Within a certain railway management scope, the software upgrade operation sequence and time for centralized monitoring station equipment usually do not exceed the above range; if they do, an anomaly may have occurred.

[0082] In view of the characteristics of railway signaling equipment operation and maintenance, this invention utilizes time series analysis and sequence pattern mining algorithms in machine learning to perform in-depth analysis of historical audit logs.

[0083] Model inputs: Operation and maintenance time, operation and maintenance personnel ID, source terminal device, target device, operation command sequence, parameters, operation time.

[0084] Model output: A series of "trustworthy pattern rules" are formed.

[0085] For example: Rule A: Person P, within the time window [00:00, 04:00], executes the operation sequence {O1, O2, O3} on server S from terminal T. The total time taken is within the range of [3600s, 14400s], which is a trusted mode.

[0086] Dynamic updates: The model will periodically and in a controlled manner update itself as the operation and maintenance practices are fine-tuned (such as the addition of new equipment or the optimization of operation and maintenance processes), avoiding frequent false alarms caused by normal process changes.

[0087] III. Trustworthy Modeling of Operations and Maintenance Personnel Behavior

[0088] The system collects and analyzes the operational behavior characteristics of each operations and maintenance personnel, constructing a dynamic and personalized "behavioral fingerprint" to verify "whether he is still himself, and whether his behavior conforms to his historical habits and current task expectations." This addresses risks such as session hijacking, account impersonation, or malicious operations by internal personnel that may occur after identity authentication is successful.

[0089] 1. Data preprocessing and task allocation:

[0090] Filter the historical operation information of operation and maintenance personnel to remove incomplete, incorrect or test operation records.

[0091] Based on the operation and maintenance logs, the operations performed by operation and maintenance personnel on specific target objects (such as a certain server) are divided and aggregated according to operation and maintenance task modules. For example, all "database backup" operations are grouped into one task module, and all "firewall policy updates" are grouped into another module.

[0092] 2. Feature Extraction and Model Generation: For each "person-object-task" combination, the aforementioned multi-dimensional behavioral features are extracted from the preprocessed data. A machine learning sequence pattern mining algorithm is used for training to generate a baseline behavioral model for the person performing the task. This model includes common operational commands, command sequences, time intervals, access paths, and other habitual patterns. Finally, the generated behavioral model is bound to the specific target person and target object to form a personalized behavioral profile.

[0093] 3. Real-time behavior measurement and anomaly detection mechanism:

[0094] Real-time behavior sequence matching: The system aggregates and analyzes the current operation flow of the operation and maintenance personnel in real time, and matches it with the similarity calculation results of multi-dimensional features such as operation sequence, object, and time series with the bound behavior model.

[0095] Anomaly Detection and Response: Based on the matching results, the system calculates the deviation of the current behavior from the baseline model. When the deviation exceeds a preset threshold, it is determined to be abnormal behavior. Anomalies may manifest as: executing dangerous commands rarely used within its scope of responsibility, executing task steps in an abnormal order, performing sensitive operations outside of working hours, or operation time being significantly inconsistent with historical patterns, etc.

[0096] Tiered response strategy: Once an anomaly is detected, the system should take different response measures according to the level of risk, for example:

[0097] Low-risk alert: Logs and issues security alerts to notify the security administrator.

[0098] Intervention for medium-risk situations: Requires secondary identity verification.

[0099] High-risk blocking: Suspicious operation and maintenance sessions are interrupted in real time, and related accounts are frozen.

[0100] Evidence solidification: All behavior logs and abnormal events should be fully recorded. Key operation records (such as commands, time, and operators) should be hashed and reported to the central storage.

[0101] IV. Lightweight Trusted Proxy

[0102] The trusted proxy is isolated from the original business processes of the device, containing only the most essential basic measurement functions such as process hash calculation, system call monitoring, and network connectivity. It communicates with the central platform through a secure internal channel. The proxy includes: a trusted root service layer, a data collection and measurement layer, a policy and model execution layer, and an interface and communication layer.

[0103] 1. Trusted Root Service Layer:

[0104] To ensure compatibility with different hardware platforms, this layer is designed with a hardware abstraction layer. The services of this layer rely on the core cryptographic functions (such as secure key generation, storage and management, as well as hashing, signing and other operations) provided by the hardware trusted module, and provide a unified interface (such as calculating PCR extensions, signing, and key management) to the upper layer.

[0105] 2. Data Acquisition and Measurement Layer:

[0106] This layer is responsible for multi-dimensional data collection:

[0107] (1) Calculate the hash value of the protected object (such as system files, critical configuration files, and trusted operation and maintenance tool binary files) and compare it with the baseline whitelist issued by CTMP.

[0108] (2) When the system is running, perform a trust measurement on the software operation and maintenance tools in real time.

[0109] (3) On the operation and maintenance terminal equipment, capture all operation commands, parameters, and target objects of the operation and maintenance personnel in real time, and analyze the time series, intervals, and frequencies of the operations. Dynamically compare the above real-time data stream with the personalized behavior model of the operation and maintenance personnel issued by CTMP, and calculate the deviation between the current behavior and the model.

[0110] (4) On the target maintenance device, capture the operation sequence of the maintenance process on the device in real time, compare it with the maintenance trust model of the device issued by CTMP, and calculate the deviation of the current behavior from the model.

[0111] 3. Strategy and Model Execution Layer:

[0112] Securely receive and parse policy and model files from CTMP, converting them into internally executable rules. Execute tiered responses based on metrics and comparison results. For example:

[0113] Critical system files have been tampered with, causing measurement failure: An alarm is triggered immediately, and the system can be prevented from starting or switched to a safe state based on the policy.

[0114] Changes to the code and data segments of the operation and maintenance software: interrupt the process and trigger an alarm.

[0115] Behavioral sequence deviation: Different measures are taken depending on the deviation level. Minor deviations may only log and issue an alert; moderate deviations require secondary authentication; severe deviations (such as attempting to execute high-risk commands or completely abnormal sequences) will immediately block the current operation and terminate the operation session.

[0116] 4. Interface and Communication Layer:

[0117] Communication with CTMP is established using an encrypted communication key issued by CTMP. All communication content is encrypted and end-to-end authentication can be performed using a hardware root of trust to prevent man-in-the-middle attacks. The communication uses a lightweight protocol to minimize bandwidth and latency.

[0118] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0119] In another embodiment, a trusted computing-based security computing protection system for railway signaling systems is provided, which corresponds one-to-one with the security computing protection technology in the above embodiments. Detailed descriptions of each functional module are as follows:

[0120] A lightweight trusted agent is deployed on the maintained equipment to schedule the hardware trusted module to perform runtime trust measurement and evidence collection.

[0121] The Central Trusted Management Platform (CTMP) is deployed in the security operations and maintenance management area for policy management, trusted verification, behavior analysis, dynamic access control, and audit log management.

[0122] The hardware trusted module, integrated into the motherboard of the terminal device, provides a hardware-level root of trust and supports security measurement, signature and key protection functions.

[0123] For specific limitations regarding a railway signaling system based on trusted computing for secure computation protection, please refer to the limitations of secure computation protection technology mentioned above, which will not be repeated here. Each module in the above system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0124] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A security computing protection technology for railway signaling systems based on trusted computing, characterized in that, Includes the following steps: Using a hardware trusted module as the hardware root of trust, trusted link verification is performed on the operation and maintenance terminal, communication link and destination device. The central trusted management platform is used to perform trusted measurement and verification of operation and maintenance tools. Based on the characteristics of railway signaling system operation and maintenance, a dynamic and reliable benchmark model for equipment and a reliable model for the behavior of operation and maintenance personnel are constructed. The lightweight trusted agent monitors the operation and maintenance process in real time. When the operation and maintenance operation or the behavior of the operation and maintenance personnel deviates from the dynamic trusted benchmark model of the device or the trusted model of the behavior of the operation and maintenance personnel, the access permissions and execution permissions are restricted or denied, and the measurement results and operation behavior are reported to the central trusted management platform.

2. The secure computing protection technology according to claim 1, characterized in that, The hardware trusted module is either a domestically produced trusted cryptographic module or an international TPM 2.0 chip.

3. The secure computing protection technology according to claim 1, characterized in that, The trusted link verification for the operation and maintenance terminal includes: Trusted boot chain metrics are performed through a hardware trusted module, including BIOS firmware hash, Bootloader hash, kernel and driver hash, terminal agent hash, and critical configuration file hash. Extend the metric to the platform configuration register corresponding to the trusted module to generate a platform configuration summary; The trusted module signs the terminal's trusted credential, and only after successful verification can the terminal initiate an operation and maintenance access request.

4. The secure computing protection technology according to claim 1, characterized in that, The trusted verification of the communication link includes: The central trusted management platform verifies the trusted status of each network device on the operation and maintenance request communication link; Illegal configuration changes can be identified by comparing the runtime configuration data of network devices with pre-stored trusted baselines. The runtime configuration data includes the device basic identifier, layer 3 parameters, layer 2 parameters, layer 2 security policy, MAC table, and ACL configuration.

5. The secure computing protection technology according to claim 1, characterized in that, The trust measurement and verification of operation and maintenance tools includes: Before the tool is released, the central trusted management platform calculates the hash value of the tool file and core code segment, performs digital signature, and enters it into the trusted tool whitelist. When a tool is invoked, the lightweight trusted agent calculates its memory image hash value through the hardware trusted module, compares it with the trusted tool whitelist, and verifies the digital signature.

6. The secure computing protection technology according to claim 1, characterized in that, The device dynamic reliable baseline model includes a time baseline and an operation sequence baseline: The time reference is set based on the railway signaling system maintenance window time setting; The operation sequence benchmark is built based on historical operation and maintenance records, and defines the standard operation command sequence, parameter range and execution order for specific devices.

7. The secure computing protection technology according to claim 1, characterized in that, The construction of the trustworthy behavior model for operations and maintenance personnel includes: Clean the historical operation records of operations and maintenance personnel, and remove incomplete, erroneous or test data; Perform aggregated analysis of operational behaviors based on operation and maintenance task modules; For the "person-object-task" combination, operation commands, sequence features, time intervals and access paths are extracted, and a behavioral baseline is generated through sequence pattern mining algorithm.

8. The secure computing protection technology according to claim 1, characterized in that, The lightweight trusted proxy includes: Trusted Root Service Layer: Provides a hardware abstraction interface, compatible with multiple types of trusted modules; Data Acquisition and Measurement Layer: Performs multi-dimensional data acquisition and real-time reliable measurement; Strategy and Model Execution Layer: Parses and executes the strategy and model files issued by the central trusted management platform; Interface and Communication Layer: Establish a secure communication channel based on the key distributed by the central trusted management platform.

9. The secure computing protection technology according to claim 1, characterized in that, When an operation or behavior deviates from the dynamic trusted baseline model of the device or the trusted model of the operation and maintenance personnel behavior, the system implements a graded response based on the degree of deviation: Low risk: Log security information and trigger alerts; Medium risk: Requires enhanced identity authentication; High risk: Real-time interruption of operation and maintenance sessions and freezing of related account permissions.

10. A railway signaling system based on trusted computing for secure computational protection, characterized in that, To implement the secure computing protection technology according to any one of claims 1 to 9, it includes: A lightweight trusted agent is deployed on the maintained equipment to schedule the hardware trusted module to perform runtime trust measurement and evidence collection. The central trusted management platform is deployed in the security operations and maintenance management area and is used for policy management, trusted verification, behavior analysis, dynamic access control and audit log management. The hardware trusted module, integrated into the motherboard of the terminal device, provides a hardware-level root of trust and supports security measurement, signature and key protection functions.