Safety application upgrade method and device for cloud train control system

By receiving upgrade requests, the target module and mode are determined using the device type code and upgrade mode bit. The upgrade can be performed online or offline to achieve hierarchical upgrade of the primary and backup systems. This solves the problems of limited upgrade timing and insufficient adaptability in existing technologies, and ensures data consistency and timeliness.

CN122308882APending Publication Date: 2026-06-30BEIJING HOLLYSYS
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING HOLLYSYS
Filing Date
2026-04-07
Publication Date
2026-06-30

AI Technical Summary

Technical Problem

The existing railway signaling system's safety application upgrades only support a single process and cannot adapt to the differentiated needs of different safety applications in the cloud train control system under operation/maintenance scenarios, resulting in limited upgrade opportunities and insufficient adaptability.

Method used

By receiving upgrade requests, the target upgrade module and mode are determined using the device type code and upgrade mode bit. The upgrade is carried out in an online or offline manner to achieve hierarchical upgrade of the primary and backup systems. Data consistency is ensured by reconstructing data consistency verification to avoid interruption of core functions.

Benefits of technology

It enables flexible adaptation to the upgrade needs of different security applications without relying on non-operational states, ensuring data consistency and timeliness during the upgrade process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122308882A_ABST
    Figure CN122308882A_ABST
Patent Text Reader

Abstract

This invention provides a method and apparatus for upgrading the security application of a cloud-based train control system, applied in the field of railway signaling technology. The method preprocesses the upgrade request to include an upgrade package, a device type code, and an upgrade mode bit. Upon receiving the upgrade request, the target upgrade module can be determined based on the device type code, and the upgrade mode can be determined based on the upgrade mode bit. If the upgrade mode is online upgrade, an online upgrade command is sent to the target upgrade module. During the online upgrade process using the upgrade package, the primary and backup systems of the target upgrade module are upgraded in a hierarchical manner, thus ensuring uninterrupted core functions. Furthermore, data consistency is guaranteed during the upgrade process through data consistency verification, eliminating the need to rely on non-operational states and effectively solving the problems of limited upgrade opportunities and poor adaptability in existing technologies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of railway signaling technology, and in particular to a method and apparatus for upgrading the safety application of a cloud-based train control system. Background Technology

[0002] Currently, upgrades to various safety-related applications in railway signaling systems only support a single upgrade process or require execution during non-operational periods, necessitating the shutdown of core equipment functions. Furthermore, they cannot adapt to the differentiated needs of various safety applications in cloud-based train control systems (such as Radio Block Centers (RBCs) and Temporary Speed ​​Restriction Servers (TSRSs)) under operational / maintenance scenarios, resulting in insufficient flexibility and timeliness. Summary of the Invention

[0003] In view of this, the present invention provides a method and apparatus for upgrading the security application of a cloud-based train control system, in order to solve the problems of limited upgrade opportunities and poor adaptability in existing technologies.

[0004] The first aspect of this invention provides a method for upgrading the security application of a cloud train control system, applied to a device for upgrading the security application of a cloud train control system, comprising:

[0005] Receive upgrade request: wherein the upgrade request includes an upgrade package and an upgrade control flow flag; the upgrade control flow flag includes a device type code and an upgrade mode bit; the upgrade package includes an upgrade file and a configuration file;

[0006] The target upgrade module is determined based on the device type code, and the upgrade mode is determined based on the upgrade mode bit.

[0007] If the upgrade mode is online upgrade, an online upgrade command is sent to the target upgrade module; wherein, after the backup system of the target upgrade module loads the upgrade file and the configuration file, it performs a data consistency check with the primary system of the target upgrade module. If the data consistency check passes, a first upgrade confirmation message is sent to the primary system of the target upgrade module. After the primary system of the target upgrade module receives the first upgrade confirmation message, the target upgrade module performs a primary / backup switch. After the backup system of the switched target upgrade module loads the upgrade file and the configuration file, it performs a data consistency check with the primary system of the switched target upgrade module. If the data consistency check passes, a second upgrade confirmation message is sent to the primary system of the switched target upgrade module. When the primary system of the switched target upgrade module receives the second upgrade confirmation message, an online upgrade success message is generated.

[0008] Optionally, the cloud-based train control system security application upgrade method further includes:

[0009] If the upgrade mode is offline upgrade, an offline upgrade command is sent to the target upgrade module; wherein, the primary system and the backup system of the target upgrade module stop running after receiving the offline upgrade command;

[0010] When the primary system and the backup system of the target upgrade module are offline, a primary system upgrade command is sent to the primary system of the target upgrade module; wherein, after receiving the primary system upgrade command, the primary system of the target upgrade module loads the upgrade file and the configuration file, initializes and starts up, and then enters the primary system running state;

[0011] When the primary system of the target upgrade module is detected to enter the primary system running state, a backup system upgrade command is sent to the backup system of the target upgrade module; wherein, after receiving the backup system upgrade command, the backup system of the target upgrade module loads the upgrade file and the configuration file, initializes and starts up, and then enters the backup system running state;

[0012] Once the backup system of the target upgrade module is detected to have entered the backup system operation state, an offline upgrade success message is generated.

[0013] Optionally, the upgrade package is obtained by preprocessing the original upgrade package using the SM4 algorithm for encryption and the SM2 algorithm for digital signature.

[0014] Optionally, after receiving the upgrade request, the method further includes:

[0015] The integrity of the upgrade package is verified, and the integrity verification result is obtained.

[0016] Optionally, after receiving the upgrade request, the method further includes:

[0017] The correctness of the device type code and the upgrade mode bit is verified to obtain the correctness verification result.

[0018] A second aspect of the present invention provides a security application upgrade device for a cloud-based train control system, comprising:

[0019] A receiving unit is configured to receive an upgrade request, wherein the upgrade request includes an upgrade package and an upgrade control flow flag; the upgrade control flow flag includes a device type code and an upgrade mode bit; and the upgrade package includes an upgrade file and a configuration file.

[0020] The upgrade module determination unit is used to determine the target upgrade module based on the device type code.

[0021] An upgrade mode determination unit is used to determine an upgrade mode based on the upgrade mode bit.

[0022] An upgrade command sending unit is configured to send an online upgrade command to the target upgrade module if the upgrade mode is online upgrade; wherein, after the backup system of the target upgrade module loads the upgrade file and the configuration file, it performs a data consistency check with the primary system of the target upgrade module. If the data consistency check passes, it sends a first upgrade confirmation message to the primary system of the target upgrade module. After receiving the first upgrade confirmation message, the primary system of the target upgrade module performs a primary / backup switch. After the backup system of the switched target upgrade module loads the upgrade file and the configuration file, it performs a data consistency check with the primary system of the switched target upgrade module. If the data consistency check passes, it sends a second upgrade confirmation message to the primary system of the switched target upgrade module. When the primary system of the switched target upgrade module receives the second upgrade confirmation message, it generates an online upgrade success message.

[0023] Optionally, the cloud-based train control system security application upgrade device further includes:

[0024] The upgrade command sending unit is further configured to send an offline upgrade command to the target upgrade module if the upgrade mode is offline upgrade; wherein the primary system and the backup system of the target upgrade module stop running after receiving the offline upgrade command;

[0025] The primary system upgrade command sending unit is used to send a primary system upgrade command to the primary system of the target upgrade module when the primary system and the backup system of the target upgrade module are in an offline state; wherein, after receiving the primary system upgrade command, the primary system of the target upgrade module loads the upgrade file and the configuration file, initializes and starts up, and then enters the primary system running state;

[0026] The backup system upgrade command sending unit is used to send a backup system upgrade command to the backup system of the target upgrade module after detecting that the primary system of the target upgrade module has entered the primary system running state; wherein, after receiving the backup system upgrade command, the backup system of the target upgrade module loads the upgrade file and the configuration file, initializes and starts up, and then enters the backup system running state;

[0027] The generation unit is used to generate an offline upgrade success message when it detects that the primary system of the target upgrade module has entered the standby system operation state.

[0028] Optionally, the upgrade package is obtained by preprocessing the original upgrade package using the SM4 algorithm for encryption and the SM2 algorithm for digital signature.

[0029] Optionally, the cloud-based train control system security application upgrade device further includes:

[0030] The integrity verification unit is used to perform integrity verification on the upgrade package and obtain the integrity verification result.

[0031] Optionally, the cloud-based train control system security application upgrade device further includes:

[0032] The correctness verification unit is used to verify the correctness of the device type code and the upgrade mode bit, and obtain the correctness verification result.

[0033] A third aspect of the present invention provides an electronic device, comprising:

[0034] One or more processors;

[0035] A storage device on which one or more programs are stored;

[0036] When the one or more programs are executed by the one or more processors, the one or more processors implement the cloud train control system security application upgrade method as described in any one of the first aspects.

[0037] A fourth aspect of the present invention provides a computer storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the cloud train control system security application upgrade method as described in any one of the first aspects.

[0038] As can be seen from the above solutions, the present invention provides a method and apparatus for upgrading the security application of a cloud-based train control system. This method preprocesses the upgrade request to include an upgrade package, a device type code, and an upgrade mode bit. Upon receiving the upgrade request, the target upgrade module can be determined based on the device type code, and the upgrade mode can be determined based on the upgrade mode bit. If the upgrade mode is online upgrade, an online upgrade command is sent to the target upgrade module. During the online upgrade process using the upgrade package, the primary and backup systems of the target upgrade module are upgraded in a hierarchical manner, thus ensuring that core functions are not interrupted. Furthermore, data consistency is guaranteed during the upgrade process through data consistency verification, without relying on non-operational states. This effectively solves the problems of limited upgrade opportunities and poor adaptability in existing technologies. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0040] Figure 1 A flowchart illustrating a method for upgrading the security application of a cloud-based train control system, as provided in an embodiment of the present invention;

[0041] Figure 2 A flowchart illustrating a method for upgrading the security application of a cloud-based train control system, as provided in another embodiment of the present invention;

[0042] Figure 3 This is a schematic diagram of a cloud-based train control system security application upgrade device provided in another embodiment of the present invention. Detailed Implementation

[0043] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0044] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0045] It should be noted that the information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this invention are all information and data authorized by the user or fully authorized by all parties.

[0046] It should be noted that the concepts of "first" and "second" mentioned in this invention are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0047] It should be noted that the terms "a" and "a plurality of" used in this invention are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0048] This invention provides a method for upgrading the security application of a cloud-based train control system, such as... Figure 1 As shown, the specific steps include:

[0049] S101, the cloud train control system security application upgrade device receives the upgrade request.

[0050] The upgrade request includes an upgrade package and upgrade control flow flags; the upgrade control flow flags include a device type code and an upgrade mode bit; the upgrade package includes an upgrade file and a configuration file.

[0051] In the actual application of this invention, the upgrade mode bit can occupy one byte, for example: 0x55 for online upgrade, 0xAA for offline upgrade; the device type code occupies one byte, for example: 0x11 for Radio Block Center (RBC), 0x22 for Temporary Speed ​​Restriction Server (TSRS), 0x33 for Train Control Center and Interlocking Integrated System (TIS), 0x44 for Computer Based Interlocking (CBI), 0x55 for Train Control Center (TCC), etc., and is not limited here.

[0052] This invention achieves precise compatibility between the upgrade package and different train control devices such as RBC and TSRS by upgrading the "device type code" in the control flow flag, thus avoiding version incompatibility issues.

[0053] In practical applications of this invention, equipment manufacturers can establish a connection with the cloud-based train control system security application upgrade device using specialized tools; this is not limited here. Furthermore, for security reasons, identity verification can be performed before establishing the connection; this is also not limited here.

[0054] In the practical application of this invention, the upgrade file can be the entire application, which can be directly replaced to complete the upgrade, or it can be a differential package (comparing the differences between the old and new versions of the file and extracting only the changed parts to generate a "differential package"), which is used to upgrade the historical application by patching. There is no limitation here.

[0055] Optionally, in another embodiment of the present invention, the upgrade package can be preprocessed, such as by using SM4 algorithm encryption and SM2 algorithm digital signature to preprocess the original upgrade package, which is not limited here.

[0056] This invention addresses the challenge of insufficient security protection through a multi-layered security system: the upgrade package preprocessing employs SM4 national cryptographic algorithm encryption + SM2 national cryptographic algorithm digital signature, coupled with a dedicated control flow flag containing device type code and upgrade mode bits, forming a triple protection of "encryption-signature-flag verification". Compared to the single verification or general encryption of existing technologies, the national cryptographic algorithm is more in line with domestic rail transit safety standards, and the dedicated flag enables precise matching between the device and the upgrade mode, resisting the risk of tampering and forgery from the source.

[0057] It is understandable that if the SM4 national cryptographic algorithm is used for encryption, the cloud-based train control system security application upgrade device will use the corresponding SM4 national cryptographic algorithm to decrypt the request after receiving it.

[0058] Optionally, in another embodiment of the present invention, after receiving the upgrade request, the integrity of the upgrade package can be verified to obtain the integrity verification result.

[0059] Integrity verification can be, but is not limited to, cyclic redundancy check (CRC) verification, etc., and is not limited here.

[0060] Optionally, in another embodiment of the present invention, after receiving the upgrade request, the correctness of the device type code and upgrade mode bit can also be verified to obtain the correctness verification result.

[0061] For example: the upgrade mode bit occupies one byte, 0x55 is for online upgrade, 0xAA is for offline upgrade, and other values ​​are illegal; the device type code occupies one byte, 0x11 is for RBC, 0x22 is for TSRS, 0x33 is for TIS, 0x44 is for CBI, 0x55 is for TCC, etc., and other undefined values ​​are illegal.

[0062] S102, the cloud train control system security application upgrade device determines the target upgrade module based on the equipment type code and the upgrade mode based on the upgrade mode bit.

[0063] Assuming the upgrade mode bit occupies one byte, with 0x55 for online upgrade and 0xAA for offline upgrade, then when the upgrade mode bit in the upgrade control flow flag is 0x55, the upgrade mode is determined to be online upgrade; when the upgrade mode bit in the upgrade control flow flag is 0xAA, the upgrade mode is determined to be offline upgrade.

[0064] Assuming the device type code occupies one byte, with 0x11 for RBC, 0x22 for TSRS, 0x33 for TIS, 0x44 for CBI, and 0x55 for TCC, then when the device type code in the upgrade control flow flag is 0x11, the device type is determined to be RBC.

[0065] Assume we have 12 main control modules. During power-on initialization, main control modules numbered 1 and 2 form a primary-backup system, carrying the security application RBC; main control modules numbered 3 and 4 form a primary-backup system, carrying the security application TSRS; and main control modules numbered 5 and 6 form a primary-backup system, carrying the security application CBI. The remaining 6 main control modules are redundant main control modules.

[0066] If a request to update the security application RBC is received, assuming that the master control module number 1 is the master system of the security application RBC, then the master system of the target upgrade module is the master control module number 1, and the backup system of the target upgrade module is the master control module number 2; assuming that the master control module number 2 is the master system of the security application RBC, then the master system of the target upgrade module is the master control module number 2, and the backup system of the target upgrade module is the master control module number 1.

[0067] It should be noted that there can be multiple target upgrade modules. For example, there are 6 main control modules A, B, C, D, E, and F corresponding to type RBC. Among them, A, B, and C are the main systems of RBC, and D, E, and F are the backup systems of RBC. Then the main systems of the target upgrade modules are the main control modules numbered A, B, and C. The main systems and backup systems of all target upgrade modules will be upgraded in the future.

[0068] This invention automatically triggers online or offline upgrade processes by upgrading the "upgrade mode bit" in the control flow flag. In online mode, the primary and backup systems are upgraded in a tiered manner without interrupting core functions; in offline mode, the primary and backup systems are started and stopped in stages according to their order, adapting to maintenance scenarios. It does not rely on non-operational states and can dynamically switch according to the actual operating needs of the equipment, effectively solving the problems of limited upgrade opportunities and poor adaptability in existing technologies.

[0069] S103. If the upgrade mode is online upgrade, the cloud train control system security application upgrade device sends an online upgrade command to the backup system of the target upgrade module.

[0070] In the practical application of this invention, the cloud train control system security application upgrade device can first send an online upgrade command to the primary system of the target upgrade module. After receiving the online upgrade command, the primary system of the target upgrade module forwards it to the backup system of the target upgrade module. Alternatively, the cloud train control system security application upgrade device can directly send the online upgrade command to the backup system of the target upgrade module; this is not limited here. Currently Figure 1 This example illustrates how the cloud-based train control system security application upgrade device directly sends online upgrade commands to the backup system of the target upgrade module.

[0071] S104. After the backup system of the target upgrade module loads the upgrade file and configuration file, it performs a data consistency check with the primary system of the target upgrade module.

[0072] The reconstructed data consists of global variable values ​​set in various security applications, which are usually critical variables. When the primary system discovers that the status of the backup system is inconsistent with the status of its stored critical variables, the primary system will send the status of these critical variables to the backup system to maintain consistency between the primary and backup systems.

[0073] In the actual application of this invention, after loading the upgrade file and configuration file, the backup system of the target upgrade module will initialize and be in standby state. At this time, it sends a request to reconstruct data to the primary system of the target upgrade module and waits for the primary system of the target upgrade module to return the reconstructed data. The backup system of the target upgrade module verifies the consistency of the reconstructed data structure and completes the reconstructed data consistency verification.

[0074] Specifically, the security application pre-configures the structure version and data version of the reconstructed data, adding two fields, structure version and data version, to the reconstructed data transmission packet. The backup system verifies that the structure version and data version in the reconstructed data packet are consistent with its own configured structure version and data version. If they are consistent, it indicates that online upgrade is possible, and the backup system responds to the primary system with an online upgrade confirmation message (first upgrade confirmation message); if they are inconsistent, it indicates that online upgrade is not possible, and the backup system responds to the primary system with an online upgrade error message.

[0075] S105. If the data consistency verification of the reconstructed data passes, the backup system of the target upgrade module sends the first upgrade confirmation message to the primary system of the target upgrade module.

[0076] If the data consistency verification fails, an online upgrade error message is sent and the system is set to a fault state. The master system of the target upgrade module sends an upgrade error message to the cloud train control system security application upgrade device and sets the system to a fault state. The cloud train control system security application upgrade device sends an upgrade failure message to the special tool and indicates that the failure message indicates that the data structure consistency is incorrect.

[0077] S106. After the primary system of the target upgrade module receives the first upgrade confirmation message, the target upgrade module performs a primary / backup system switch.

[0078] Specifically, after the primary system of the target upgrade module receives the first upgrade confirmation message, it switches to the standby system and sends a message to the standby system of the target upgrade module to upgrade it to the primary system.

[0079] In the actual application of this invention, after the backup system of the target upgrade module receives the message of being upgraded to the primary system, it can, but is not limited to, determine whether it has been downgraded to the backup system based on the primary / backup system field in the periodic status information broadcast by the primary system of the target upgrade module. If it is found that the primary system of the target upgrade module has been downgraded to the backup system, the backup system of the target upgrade module switches to the primary system, thereby completing the primary / backup system switch.

[0080] S107. After the backup system of the target upgrade module loads the upgrade file and configuration file, it performs a data consistency check with the primary system of the target upgrade module after the switch.

[0081] It is understandable that the backup system of the target upgrade module after the switch is the primary system of the target upgrade module in the above example, and the primary system of the target upgrade module after the switch is the backup system of the target upgrade module in the above example.

[0082] It should be noted that the specific implementation of step S107 can be referred to the specific implementation of step S104, and will not be repeated here.

[0083] S108. If the data consistency verification of the reconstructed data passes, the backup system of the target upgrade module after the switch sends a second upgrade confirmation message to the primary system of the target upgrade module after the switch.

[0084] It should be noted that the specific implementation of step S109 can refer to the specific implementation of step S105, and will not be repeated here.

[0085] S109. When the primary system of the target upgrade module after the switch receives the second upgrade confirmation message, an online upgrade success message is generated.

[0086] In the actual application of this invention, after generating the online upgrade success message, the online upgrade success message is sent to the cloud train control system security application upgrade device, and the cloud train control system security application upgrade device then sends the online upgrade success message to the dedicated tool.

[0087] Optionally, in another embodiment of the present invention, one implementation of the cloud train control system security application upgrade method is as follows: Figure 2 As shown, it includes:

[0088] S201, The cloud train control system security application upgrade device receives an upgrade request.

[0089] The upgrade request includes an upgrade package and upgrade control flow flags; the upgrade control flow flags include a device type code and an upgrade mode bit; the upgrade package includes an upgrade file and a configuration file.

[0090] S202, the cloud train control system security application upgrade device determines the target upgrade module based on the equipment type code and the upgrade mode based on the upgrade mode bit.

[0091] It should be noted that the specific implementation methods of steps S201 and S202 can be referred to the specific implementation methods of steps S101 and S102 respectively, and will not be repeated here.

[0092] S203. If the upgrade mode is offline upgrade, the cloud train control system security application upgrade device sends an offline upgrade command to the master system of the target upgrade module.

[0093] S204. If the upgrade mode is offline upgrade, the cloud train control system security application upgrade device sends an offline upgrade command to the backup system of the target upgrade module.

[0094] The primary and backup systems of the target upgrade module stop operating after receiving the offline upgrade command.

[0095] It should be noted that steps S203 and S204 can be performed simultaneously, or step S203 can be executed first and then step S204, or step S204 can be executed first and then step S203. No limitation is made here. Currently... Figure 2 This example illustrates the concept of executing step S203 first and then step S204.

[0096] S205. When the primary system and backup system of the target upgrade module are in an offline state, the cloud train control system security application upgrade device sends a primary system upgrade command to the primary system of the target upgrade module.

[0097] In the actual application of this invention, it is possible, but not limited to, to determine whether the target upgrade module is in an offline state based on the status field in the periodic status information broadcast by the primary and backup systems. This is not limited here.

[0098] S206. After receiving the main system upgrade command, the target upgrade module loads the upgrade file and configuration file, initializes and starts the main system into the running state.

[0099] S207. When the primary system of the target upgrade module is detected to enter the primary system operation state, the cloud train control system security application upgrade device sends a backup system upgrade command to the backup system of the target upgrade module.

[0100] In the actual application of this invention, it is possible, but not limited to, to determine whether the target upgrade module has entered the main system running state based on the status field in the periodic status information broadcast by the main system. This is not limited here.

[0101] S208. After receiving the backup system upgrade command, the backup system of the target upgrade module loads the upgrade file and configuration file, initializes and starts up, and then enters the backup system running state.

[0102] S209. When the backup system of the target upgrade module is detected to enter the backup system operation state, the cloud train control system security application upgrade device generates an offline upgrade success message.

[0103] In the actual application of this invention, it is possible, but not limited to, to determine whether the target upgrade module has entered the backup system operation state based on the status field in the periodic status information broadcast by the backup system. This is not limited here.

[0104] In the practical application of this invention, after generating an offline upgrade success message, the cloud train control system security application upgrade device sends the offline upgrade success message to a dedicated tool.

[0105] This invention requires dual confirmation of the offline and operational status of the primary and backup systems during offline upgrades before executing the next instruction. Existing technologies often rely on single status checks, which are prone to upgrade failures due to misjudgments. This invention effectively improves the reliability of offline upgrades.

[0106] In the actual application of this invention, the dedicated tool receives an offline upgrade success message or an online upgrade success message and completes the upgrade process archiving; if a failure message is received, staff can investigate the problem based on the feedback of the fault cause (such as inconsistent reconstructed data or failure of compatibility verification) and then re-initiate the upgrade process to solve the defects of insufficient adaptability and inefficient fault handling of existing technologies.

[0107] As can be seen from the above scheme, the present invention provides a method for upgrading the security application of a cloud-based train control system. By preprocessing the upgrade request to include an upgrade package, a device type code, and an upgrade mode bit, the target upgrade module can be determined based on the device type code and the upgrade mode can be determined based on the upgrade mode bit upon receiving the upgrade request. If the upgrade mode is online upgrade, an online upgrade command is sent to the target upgrade module. During the online upgrade process using the upgrade package, the primary and backup systems of the target upgrade module are upgraded in a hierarchical manner, thereby ensuring that the core functions are not interrupted. Furthermore, data consistency is guaranteed during the upgrade process by reconstructing data consistency verification, without relying on non-operational states. This effectively solves the problems of limited upgrade opportunities and poor adaptability in existing technologies.

[0108] Another embodiment of the present invention provides a security application upgrade device for a cloud train control system, such as... Figure 3 As shown, it specifically includes:

[0109] The receiving unit 301 is used to receive upgrade requests.

[0110] The upgrade request includes an upgrade package and upgrade control flow flags; the upgrade control flow flags include a device type code and an upgrade mode bit; the upgrade package includes an upgrade file and a configuration file.

[0111] The upgrade module determination unit 302 is used to determine the target upgrade module based on the device type code.

[0112] The upgrade mode determination unit 303 is used to determine the upgrade mode based on the upgrade mode bit.

[0113] The upgrade command sending unit 304 is used to send an online upgrade command to the target upgrade module if the upgrade mode is online upgrade.

[0114] In this process, after the backup system of the target upgrade module loads the upgrade file and configuration file, it performs a data consistency check with the primary system of the target upgrade module. If the data consistency check passes, it sends a first upgrade confirmation message to the primary system of the target upgrade module. After receiving the first upgrade confirmation message, the primary system of the target upgrade module performs a primary-backup switch. After the backup system of the target upgrade module loads the upgrade file and configuration file, it performs a data consistency check with the primary system of the target upgrade module. If the data consistency check passes, it sends a second upgrade confirmation message to the primary system of the target upgrade module. When the primary system of the target upgrade module receives the second upgrade confirmation message, it generates an online upgrade success message.

[0115] For details on the specific operation of the units disclosed in the above embodiments of the present invention, please refer to the corresponding method embodiments, such as... Figure 1 As shown, it will not be elaborated further here.

[0116] Optionally, in another embodiment of the present invention, one implementation of the cloud train control system security application upgrade device further includes:

[0117] The upgrade command sending unit is also used to send an offline upgrade command to the target upgrade module if the upgrade mode is offline upgrade.

[0118] The primary and backup systems of the target upgrade module stop operating after receiving the offline upgrade command.

[0119] The primary system upgrade command sending unit is used to send a primary system upgrade command to the primary system of the target upgrade module when the primary system and the backup system of the target upgrade module are in an offline state.

[0120] After receiving the main system upgrade command, the target upgrade module loads the upgrade file and configuration file, initializes and starts the main system, and then enters the main system running state.

[0121] The backup system upgrade command sending unit is used to send a backup system upgrade command to the backup system of the target upgrade module after detecting that the primary system of the target upgrade module has entered the primary system operation state.

[0122] When the backup system of the target upgrade module receives the backup system upgrade command, it loads the upgrade file and configuration file, initializes and starts up, and then enters the backup system running state.

[0123] The generation unit is used to generate an offline upgrade success message after detecting that the backup system of the target upgrade module has entered the backup system operation state.

[0124] For details on the specific operation of the units disclosed in the above embodiments of the present invention, please refer to the corresponding method embodiments, such as... Figure 2As shown, it will not be elaborated further here.

[0125] Optionally, in another embodiment of the present invention, the upgrade package is obtained by preprocessing the original upgrade package through SM4 algorithm encryption and SM2 algorithm digital signature.

[0126] The specific working process of the units disclosed in the above embodiments of the present invention can be found in the corresponding method embodiments, and will not be repeated here.

[0127] Optionally, in another embodiment of the present invention, one implementation of the cloud train control system security application upgrade device further includes:

[0128] The integrity verification unit is used to perform integrity verification on the upgrade package and obtain the integrity verification result.

[0129] The specific working process of the units disclosed in the above embodiments of the present invention can be found in the corresponding method embodiments, and will not be repeated here.

[0130] Optionally, in another embodiment of the present invention, one implementation of the cloud train control system security application upgrade device further includes:

[0131] The correctness verification unit is used to verify the correctness of the device type code and upgrade mode bit, and obtain the correctness verification result.

[0132] The specific working process of the units disclosed in the above embodiments of the present invention can be found in the corresponding method embodiments, and will not be repeated here.

[0133] As can be seen from the above solution, the present invention provides a cloud-based train control system security application upgrade device. By preprocessing the upgrade request to include an upgrade package, a device type code, and an upgrade mode bit, the target upgrade module can be determined based on the device type code and the upgrade mode can be determined based on the upgrade mode bit upon receiving the upgrade request. If the upgrade mode is online upgrade, an online upgrade command is sent to the target upgrade module. During the online upgrade process using the upgrade package, the primary and backup systems of the target upgrade module are upgraded in a hierarchical manner, thereby ensuring that the core functions are not interrupted. Furthermore, data consistency is guaranteed during the upgrade process by reconstructing data consistency verification, without relying on non-operational states. This effectively solves the problems of limited upgrade opportunities and poor adaptability in existing technologies.

[0134] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field-Programmable Gate Array (FPGA), Application-Specific Integrated Circuit (ASIC), Application-Specific Standard Product (ASSP), System on a Chip (SOC), Complex Programmable Logic Device (CPLD), and so on.

[0135] Another embodiment of the present invention provides an electronic device, comprising:

[0136] One or more processors.

[0137] A storage device on which one or more programs are stored.

[0138] When the one or more programs are executed by the one or more processors, the one or more processors implement the cloud train control system security application upgrade method as described in the above embodiments.

[0139] Another embodiment of the present invention provides a computer storage medium storing a computer program thereon, wherein when the computer program is executed by a processor, it implements the cloud train control system security application upgrade method as described in the above embodiments.

[0140] In the context of this invention, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0141] It should be noted that the computer-readable medium described above in this invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0142] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0143] Another embodiment of the present invention provides a computer program product, which, when executed, is used to perform the above-described cloud train control system security application upgrade method.

[0144] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, it performs the functions defined in the methods of the embodiments of the present invention.

[0145] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in this invention is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely exemplary forms for implementing the invention.

[0146] While several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of the invention. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0147] The above description is merely a preferred embodiment of the present invention and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention is not limited to the specific combination of the above-described technical features, but also includes other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the inventive concept. For example, technical solutions formed by substituting the above-described features with technical features of the present invention (but not limited to) that have similar functions.

Claims

1. A method for upgrading the security application of a cloud-based train control system, characterized in that, A security application upgrade device for a cloud-based train control system, wherein the security application upgrade method for the cloud-based train control system includes: Receive upgrade request: wherein the upgrade request includes an upgrade package and an upgrade control flow flag; the upgrade control flow flag includes a device type code and an upgrade mode bit; the upgrade package includes an upgrade file and a configuration file; The target upgrade module is determined based on the device type code, and the upgrade mode is determined based on the upgrade mode bit. If the upgrade mode is online upgrade, an online upgrade command is sent to the target upgrade module; wherein, after the backup system of the target upgrade module loads the upgrade file and the configuration file, it performs a data consistency check with the primary system of the target upgrade module. If the data consistency check passes, a first upgrade confirmation message is sent to the primary system of the target upgrade module. After the primary system of the target upgrade module receives the first upgrade confirmation message, the target upgrade module performs a primary / backup switch. After the backup system of the switched target upgrade module loads the upgrade file and the configuration file, it performs a data consistency check with the primary system of the switched target upgrade module. If the data consistency check passes, a second upgrade confirmation message is sent to the primary system of the switched target upgrade module. When the primary system of the switched target upgrade module receives the second upgrade confirmation message, an online upgrade success message is generated.

2. The cloud train control system security application upgrade method according to claim 1, characterized in that, Also includes: If the upgrade mode is offline upgrade, an offline upgrade command is sent to the target upgrade module; wherein, the primary system and the backup system of the target upgrade module stop running after receiving the offline upgrade command; When the primary system and the backup system of the target upgrade module are offline, a primary system upgrade command is sent to the primary system of the target upgrade module; wherein, after receiving the primary system upgrade command, the primary system of the target upgrade module loads the upgrade file and the configuration file, initializes and starts up, and then enters the primary system running state; When the primary system of the target upgrade module is detected to enter the primary system running state, a backup system upgrade command is sent to the backup system of the target upgrade module; wherein, after receiving the backup system upgrade command, the backup system of the target upgrade module loads the upgrade file and the configuration file, initializes and starts up, and then enters the backup system running state; Once the backup system of the target upgrade module is detected to have entered the backup system operation state, an offline upgrade success message is generated.

3. The cloud-based train control system security application upgrade method according to claim 1, characterized in that, The upgrade package is obtained by preprocessing the original upgrade package using the SM4 algorithm for encryption and the SM2 algorithm for digital signature.

4. The cloud-based train control system security application upgrade method according to claim 1, characterized in that, After receiving the upgrade request, the process also includes: The integrity of the upgrade package is verified, and the integrity verification result is obtained.

5. The cloud-based train control system security application upgrade method according to claim 1, characterized in that, After receiving the upgrade request, the process also includes: The correctness of the device type code and the upgrade mode bit is verified to obtain the correctness verification result.

6. A security application upgrade device for a cloud-based train control system, characterized in that, include: A receiving unit is configured to receive an upgrade request, wherein the upgrade request includes an upgrade package and an upgrade control flow flag; the upgrade control flow flag includes a device type code and an upgrade mode bit; and the upgrade package includes an upgrade file and a configuration file. The upgrade module determination unit is used to determine the target upgrade module based on the device type code. An upgrade mode determination unit is used to determine an upgrade mode based on the upgrade mode bit. An upgrade command sending unit is configured to send an online upgrade command to the target upgrade module if the upgrade mode is online upgrade; wherein, after the backup system of the target upgrade module loads the upgrade file and the configuration file, it performs a data consistency check with the primary system of the target upgrade module. If the data consistency check passes, it sends a first upgrade confirmation message to the primary system of the target upgrade module. After receiving the first upgrade confirmation message, the primary system of the target upgrade module performs a primary / backup switch. After the backup system of the switched target upgrade module loads the upgrade file and the configuration file, it performs a data consistency check with the primary system of the switched target upgrade module. If the data consistency check passes, it sends a second upgrade confirmation message to the primary system of the switched target upgrade module. When the primary system of the switched target upgrade module receives the second upgrade confirmation message, it generates an online upgrade success message.

7. The cloud-based train control system security application upgrade device according to claim 6, characterized in that, Also includes: The upgrade command sending unit is further configured to send an offline upgrade command to the target upgrade module if the upgrade mode is offline upgrade; wherein the primary system and the backup system of the target upgrade module stop running after receiving the offline upgrade command; The primary system upgrade command sending unit is used to send a primary system upgrade command to the primary system of the target upgrade module when the primary system and the backup system of the target upgrade module are in an offline state; wherein, after receiving the primary system upgrade command, the primary system of the target upgrade module loads the upgrade file and the configuration file, initializes and starts up, and then enters the primary system running state; The backup system upgrade command sending unit is used to send a backup system upgrade command to the backup system of the target upgrade module after detecting that the primary system of the target upgrade module has entered the primary system running state; wherein, after receiving the backup system upgrade command, the backup system of the target upgrade module loads the upgrade file and the configuration file, initializes and starts up, and then enters the backup system running state; The generation unit is used to generate an offline upgrade success message when it detects that the primary system of the target upgrade module has entered the standby system operation state.

8. The cloud train control system security application upgrade device according to claim 6, characterized in that, The upgrade package is obtained by preprocessing the original upgrade package using the SM4 algorithm for encryption and the SM2 algorithm for digital signature.

9. The cloud train control system security application upgrade device according to claim 6, characterized in that, Also includes: The integrity verification unit is used to perform integrity verification on the upgrade package and obtain the integrity verification result.

10. The cloud train control system security application upgrade device according to claim 6, characterized in that, Also includes: The correctness verification unit is used to verify the correctness of the device type code and the upgrade mode bit, and obtain the correctness verification result.