A railway mobile intelligent terminal security protection management platform and method

CN122602154APending Publication Date: 2026-08-18CHINA RAILWAY QINGHAI-TIBET GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610934400.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-26
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

(1)密钥生成静态化:传统国密算法(如SM4)采用固定密钥或简单随机数生成,密钥易被破解或泄露,一旦密钥泄露,加密链路即被攻破

Benefits of technology

本申请提供了一种铁路移动智能终端安全防护管理平台及方法,动态加密模块采用哈希算法根据环境感知模块实时采集的环境参数确定环境参数哈希值,并生成动态种子,同时将根密钥存储至本地根密钥库;采用国密算法运算基于临时密钥完成密钥生成和轮密钥扩展;物理防护模块在环境参数对应的数值超过预设阈值或者检测到物理拆解时,触发硬件熔断机制,并通过电流过载的方式烧毁本地根密钥库。此外,管理中心层根据密文确定对应的临时密钥,并还原国密算法运算轮密进行解密,以及判断是否环境适配;当出现连续多次环境不适配时,下发自毁指令至终端层,以实现终端安全防护。可见,本申请是基于环境参数的耦合加密和自毁式密钥保护(物理防护),旨在构建动态加密-环境适配-物理防护三位一体的纵深防御,保障移动智能终端在复杂环境下的数据安全性,并通过动态加密模块的动态密钥生成以及物理防护模块的物理安全防护机制,提升抗攻击能力。所以,本申请可提升数据安全性和设备可靠性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122602154A_ABST
    Figure CN122602154A_ABST
Patent Text Reader

Abstract

The application discloses a railway mobile intelligent terminal security protection management platform and method, and relates to the technical field of railway communication network security. A dynamic encryption module adopts a hash algorithm to determine an environment parameter hash value according to environment parameters and generates a dynamic seed, and meanwhile, stores a root key to a local root key library; a national secret algorithm is adopted to operate to complete key generation and round key expansion based on a temporary key; a network layer transmits ciphertext to a management center layer, the management center layer determines a corresponding temporary key according to the ciphertext, restores the national secret algorithm operation round key for decryption, and judges whether the environment is adapted; when continuous multiple environment maladaptations occur, a self-destruction instruction is issued to a terminal layer to realize terminal security protection; when the value corresponding to the environment parameter exceeds a preset threshold value or physical disassembly is detected, a hardware fuse mechanism is triggered, and the local root key library is burned by means of current overload. The application can improve data security and equipment reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of railway communication network security technology, and in particular to a railway mobile intelligent terminal security protection management platform and method. Background Technology

[0002] Railway mobile intelligent terminals are core equipment in railway transportation systems, enabling functions such as dispatching communication, equipment detection, and train operation control. Their security directly affects the reliability and confidentiality of railway operations. With the widespread application of 5G public network dedicated communication systems in the railway industry and the large-scale deployment of intelligent terminals, the environments in which these terminals operate are becoming increasingly complex (e.g., high altitudes, low temperatures, strong radiation, sandstorms), while simultaneously facing higher cybersecurity threats (e.g., communication data theft, terminal hijacking, hardware physical attacks). Currently known protection technologies mainly focus on network layer encryption and software layer protection, with insufficient consideration for dynamic environment awareness, hardware-level resilience, and joint protection against physical intrusion into the terminal. This makes it difficult to meet the high-security operation requirements of railway terminals in extreme environments under the 5G public network dedicated network background.

[0003] Currently, railway terminal encryption schemes based on Chinese national cryptographic algorithms use these algorithms as the core of encryption and employ a layered security system (encryption, key management, and access control) to encrypt system data. A key management system ensures secure transmission, achieving both data confidentiality and system stability. However, this approach relies on static keys for encryption, lacking dynamic parameters and making it vulnerable to key leakage risks after terminal hijacking.

[0004] Currently known 5G-R terminal security management systems adopt a three-tier architecture, covering the terminal, network, and management center. They construct a security system through technologies such as terminal legitimacy authentication, access control and behavior auditing, and mobile application management, demonstrating advancements in standardized security architecture and centralized management. However, they still suffer from insufficient environmental adaptability and a lack of physical protection.

[0005] Current general-purpose hardware designs for harsh environments have seen relatively mature research in physical hardening, environmental adaptability, and integration. They generally adopt the "design hardening" concept to enhance the physical protection capabilities of equipment. Through the selection of wide-temperature components and electromagnetic shielding technology, they ensure the normal operation of equipment in extreme temperature and strong electromagnetic interference environments. Embedded systems based on the ARM architecture have become mainstream. However, existing designs are relatively simple in function, with defects such as fragmented security functions and insufficient dynamic response. Currently, they only provide "passive defense" and cannot yet achieve "active adaptation."

[0006] The disadvantages of the above technology are: (1) Static key generation: Traditional national cryptographic algorithms (such as SM4) use fixed keys or simple random numbers to generate keys. The keys are easy to crack or leak. Once the key is leaked, the encryption link is broken.

[0007] (2) Poor hardware environment adaptability: Existing TF password cards are prone to power fluctuations or chip failures in environments such as low temperature and high radiation, resulting in encryption interruption and affecting the continuity of key railway business.

[0008] (3) Weak physical protection mechanism: When the terminal is illegally disassembled, it relies on software to erase the key, which has a slow response speed and may be bypassed by side-channel attacks, and cannot completely erase sensitive data. Summary of the Invention

[0009] The purpose of this application is to provide a security protection management platform and method for railway mobile intelligent terminals, which can improve data security and equipment reliability.

[0010] To achieve the above objectives, this application provides the following solution: In a first aspect, this application provides a railway mobile intelligent terminal security protection management platform, comprising: a terminal layer, a network layer, and a management center layer; the terminal layer is connected to the network layer; the network layer is connected to the management center layer; the terminal layer includes an environment sensing module, a dynamic encryption module, and a physical protection module; the environment sensing module is connected to the dynamic encryption module; the physical protection module is connected to both the environment sensing module and the dynamic encryption module. The environmental sensing module is used to collect environmental parameters in real time. The dynamic encryption module is used for: A hash algorithm is used to determine the hash value of the environment parameters based on the environment parameters, and a dynamic seed is generated. At the same time, the root key Stored in the local root keystore; According to dynamic seeds With root key Generate temporary key The key generation and round key expansion are completed using the national cryptographic algorithm. According to dynamic seeds Determine the dynamic key identifier ; The network layer is used to transmit ciphertext to the management center layer; the ciphertext includes business data and a dynamic key identifier. And environmental parameter hash values; the network layer includes a dedicated virtual channel constructed using virtual private network technology; the dedicated virtual channel includes a 5G public network dedicated network, which is a data leased line encrypted and protected by a network cryptographic machine; the service data is in plaintext; The management center layer is used to determine the corresponding temporary key based on the ciphertext, and to perform decryption by restoring the national cryptographic algorithm and performing round-key operations. It also compares the decrypted dynamic seed with the hash value of the environment parameters to determine whether the environment is compatible. If multiple consecutive instances of environment incompatibility occur, a self-destruct command is sent to the terminal layer to achieve terminal security protection. The physical protection module is used to trigger a hardware fuse mechanism and burn out the local root key library by means of current overload when the value of the corresponding environmental parameter exceeds a preset threshold or when physical disassembly is detected.

[0011] In one embodiment, the dynamic encryption module uses a low-temperature resistant and radiation-resistant TF password card and integrates an adaptive power management module; the adaptive power management module automatically switches to a low-power mode in low-temperature environments; the low temperature corresponds to a temperature of -40℃; the low-power mode is an operating mode with power consumption lower than a preset value.

[0012] In one embodiment, the network layer further includes: the operator's public network and the site's private WiFi network.

[0013] In one embodiment, the physical protection module specifically includes: a detection module and a self-destruct execution module; The detection module includes a disassembly detection device and a signal detection device; the signal detection device is connected to the environmental perception module; both the disassembly detection device and the signal detection device are connected to the self-destruct execution module. The disassembly and detection device is used to monitor physical intrusion signals outside the terminal in real time; the physical intrusion signals include vibration intensity; The signal detection device is used to monitor signals corresponding to environmental parameters in real time; the environmental parameters include temperature, air pressure, and radiation intensity. The self-destruct execution module is used for: When the signal value corresponding to the environmental parameter exceeds the preset threshold, or when the physical intrusion signal exceeds the corresponding preset threshold, an unmaskable interrupt is triggered, and an interrupt trigger signal is output to the dynamic encryption module; at this time, the dynamic encryption module erases the key, achieving software-level destruction. Physical destruction is achieved by burning out the local root keystore through current overload.

[0014] In one embodiment, the response time for physical destruction based on the current overload method is less than 10 milliseconds.

[0015] In one embodiment, the TF password card includes: an encryption chip and a metal shielding layer; A metal shielding layer is provided around the encryption chip; the encryption chip internally employs redundant circuitry and CRC / ECC verification.

[0016] Secondly, this application provides a railway mobile intelligent terminal security protection management method, which is implemented using the aforementioned railway mobile intelligent terminal security protection management platform; the railway mobile intelligent terminal security protection management method includes: Real-time collection of environmental parameters; A hash algorithm is used to determine the hash value of the environment parameters based on the environment parameters, and a dynamic seed is generated. At the same time, the root key Stored in the local root keystore; According to dynamic seeds With root key Generate temporary key The key generation and round key expansion are completed using the national cryptographic algorithm. According to dynamic seeds Determine the dynamic key identifier ; The corresponding temporary key is determined based on the ciphertext, and the national cryptographic algorithm is used for decryption. Furthermore, the decrypted dynamic seed is compared with the hash value of environmental parameters to determine environmental compatibility. The ciphertext includes business data and a dynamic key identifier. The data includes environmental parameter hash values; the business data is in plaintext; and when multiple consecutive environmental mismatches occur, a self-destruct command is sent to the terminal layer to achieve terminal security protection. When the value of the environmental parameter exceeds a preset threshold or physical disassembly is detected, the physical protection module triggers a hardware fuse mechanism and burns out the local root keystore by means of current overload.

[0017] In one implementation, based on dynamic seeds With root key Generate temporary key The key generation and round key expansion are completed using national cryptographic algorithms, specifically including: According to dynamic seeds With root key Generate temporary key ; The operation is performed using the national cryptographic algorithm and based on the temporary key. Perform key generation and round key expansion to generate 32 round keys. 128 people per round; ; in, This is the key expansion round number; Extend the round key.

[0018] In one implementation, based on dynamic seeds With root key Generate temporary key Specifically, it includes: ; in, This is an XOR operation.

[0019] In one implementation, dynamic seed The methods for determining this include: The environmental parameters are spliced ​​together to obtain spliced ​​data; The concatenated data is hashed using a hash algorithm to obtain the hash value of the environmental parameters; Extract the first 128 bits of the hash value of the environment parameters as the dynamic seed. .

[0020] According to the specific embodiments provided in this application, the following technical effects are disclosed: This application provides a security protection management platform and method for railway mobile intelligent terminals. The dynamic encryption module uses a hash algorithm to determine the hash value of environmental parameters based on real-time environmental parameters collected by the environmental sensing module, and generates a dynamic seed. Simultaneously, the root key is stored in a local root key library. National cryptographic algorithms are used to generate keys and expand round keys based on temporary keys. When the value of the corresponding environmental parameter exceeds a preset threshold or physical disassembly is detected, the physical protection module triggers a hardware fuse mechanism and burns out the local root key library through current overload. Furthermore, the management center layer determines the corresponding temporary key based on the ciphertext, restores the national cryptographic algorithm to perform round key decryption, and determines whether the environment is compatible. When multiple consecutive instances of environment incompatibility occur, a self-destruct command is issued to the terminal layer to achieve terminal security protection. Therefore, this application is based on coupled encryption of environmental parameters and self-destructive key protection (physical protection), aiming to build a three-in-one defense-in-depth system of dynamic encryption, environment adaptation, and physical protection to ensure the data security of mobile intelligent terminals in complex environments. The dynamic key generation of the dynamic encryption module and the physical security protection mechanism of the physical protection module enhance the anti-attack capability. Therefore, this application can improve data security and equipment reliability. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1This is a structural diagram of the railway mobile intelligent terminal security protection management platform; Figure 2 System architecture diagram of the railway mobile intelligent terminal security protection management platform; Figure 3 Flowchart for implementing encryption coupling of environmental parameters; Figure 4 A flowchart for the security protection and management method of railway mobile intelligent terminals; Figure 5 This is a flowchart for decryption and verification. Detailed Implementation

[0023] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0024] The purpose of this application is to provide a security protection solution that deeply integrates dynamic binding encryption of environmental parameters with anti-malicious hardware, to solve the core security problems faced by railway mobile intelligent terminals in extreme environments, and to improve data security and equipment reliability.

[0025] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0026] In one exemplary embodiment, such as Figure 1 As shown, a railway mobile intelligent terminal security protection management platform is provided, including: a terminal layer, a network layer, and a management center layer. The terminal layer is connected to the network layer; the network layer is connected to the management center layer; the terminal layer includes an environmental perception module, a dynamic encryption module, and a physical protection module; the environmental perception module is connected to the dynamic encryption module; the physical protection module is connected to both the environmental perception module and the dynamic encryption module.

[0027] The environmental sensing module is used to collect environmental parameters in real time.

[0028] The dynamic encryption module is used to determine the hash value of the environment parameters based on the environment parameters using a hash algorithm, and to generate a dynamic seed. At the same time, the root key Store in the local root keystore.

[0029] The dynamic encryption module is used to determine the dynamic seed. With root key Generate temporary key The key generation and round key expansion are completed using the national cryptographic algorithm.

[0030] The dynamic encryption module is also used to determine the dynamic seed. Determine the dynamic key identifier .

[0031] The network layer is used to transmit encrypted data to the management center layer; the encrypted data includes business data and dynamic key identifiers. The network layer includes environmental parameter hash values; it also includes dedicated virtual channels built using VPN technology; these dedicated virtual channels include 5G public network private networks, which are data leased lines encrypted and protected by network cryptographic machines. Service data is in plaintext. The network layer also includes: the operator's public network and the site's WiFi private network.

[0032] The management center layer is used to determine the corresponding temporary key based on the ciphertext, restore the national cryptographic algorithm to perform decryption, and compare the decrypted dynamic seed with the hash value of the environment parameters to determine whether the environment is compatible. When multiple consecutive instances of environment incompatibility occur, a self-destruct command is sent to the terminal layer to achieve terminal security protection.

[0033] The physical protection module is used to trigger a hardware fuse mechanism and burn out the local root keystore by means of current overload when the value of the corresponding environmental parameter exceeds the preset threshold or when physical disassembly is detected.

[0034] As an optional implementation, the dynamic encryption module uses a low-temperature resistant and radiation-resistant TF password card and integrates an adaptive power management module; the adaptive power management module automatically switches to a low-power mode in low-temperature environments; the low temperature corresponds to -40℃; the low-power mode is an operating mode with power consumption lower than the preset value.

[0035] The TF password card includes: an encryption chip and a metal shielding layer; the metal shielding layer is set around the encryption chip; the encryption chip uses redundant circuits and CRC / ECC verification.

[0036] The physical protection module specifically includes a detection module and a self-destruct execution module. The detection module includes a disassembly detection device and a signal detection device; the signal detection device is connected to the environmental sensing module; both the disassembly detection device and the signal detection device are connected to the self-destruct execution module.

[0037] The disassembly and detection device is used to monitor physical intrusion signals outside the terminal in real time; physical intrusion signals include vibration intensity. The signal detection device is used to monitor signals corresponding to environmental parameters in real time; environmental parameters include temperature, air pressure, and radiation intensity.

[0038] The self-destruct execution module is used to trigger an unmaskable interrupt when the signal value corresponding to the environmental parameter exceeds a preset threshold, or when the physical intrusion signal exceeds the corresponding preset threshold, and outputs an interrupt trigger signal to the dynamic encryption module; at this time, the dynamic encryption module erases the key to achieve software-level destruction.

[0039] The self-destruct execution module is also used to burn the local root keystore through current overload to achieve physical destruction.

[0040] The response time for physical destruction based on current overload is less than 10 milliseconds.

[0041] This application addresses dynamic encryption and hardware-level security protection technologies for railway mobile intelligent terminals in extreme environments such as high altitudes and high radiation levels. It combines national cryptographic algorithms, environmental parameter binding mechanisms, and robust hardware designs to enhance terminal data security and device reliability.

[0042] In other words, based on environmental parameter coupling encryption, hardware-level anti-malicious design and self-destruct key protection technology, it aims to build a three-in-one defense-in-depth system of "dynamic encryption - environment adaptation - physical protection" to ensure the data security of terminals in complex environments, and enhance the system's anti-attack capability through a dynamic key generation physical security protection mechanism.

[0043] like Figure 2 As shown, the railway mobile intelligent terminal security management platform of this application mainly includes three levels: railway dedicated mobile terminal (terminal layer), wireless access network (network layer), and terminal security service center (management center layer).

[0044] The railway-specific mobile terminal includes an environmental sensing module that integrates environmental sensors (temperature, air pressure, radiation), a dynamic encryption module (low-temperature resistant and radiation-resistant TF password card), and a physical protection module (self-destructing key protection module).

[0045] Wireless access networks include three wireless network scenarios: public operator networks, dedicated 5G public network networks, and dedicated station Wi-Fi networks. For information transmission, a dedicated virtual channel is constructed from the public operator network to the railway's external service network using Virtual Private Network (VPN) technology, and a dedicated data line is constructed from the railway's dedicated mobile smart terminal to the network cryptographic machine using network layer encryption.

[0046] The terminal security service center includes password management services, password status presentation services, network encryption services, terminal security control services, and trusted application security services. It monitors key status in real time and dynamically adjusts encryption strategies. The system architecture diagram of the railway mobile intelligent terminal security protection management platform is shown in Figure 2.

[0047] Dynamic encryption of environmental parameters: Real-time collection of environmental parameters (such as temperature, air pressure, radiation) of the smart terminal, generation of dynamic seeds through hash algorithm, and injection of dynamic seeds into the key expansion process of national cryptographic algorithms (such as SM4) to achieve "one environment, one key".

[0048] Harsh hardware design: It adopts low temperature resistant (temperature range -40℃-85℃) and radiation resistant TF password card hardware, and integrates an adaptive power management module to automatically switch to low power mode in low temperature environment to maintain core encryption function.

[0049] Self-destructing key protection: When physical disassembly or environmental parameters exceeding limits (such as excessive radiation) are detected, a hardware fuse mechanism is triggered, which instantly burns out the key storage unit (i.e., the local root key library) through current overload, thereby achieving the physical destruction of key data.

[0050] like Figure 3 As shown, to achieve the above security objectives and realize a "three-in-one" defense-in-depth approach, the technical solution process of this application is as follows: (1) System initialization phase: After the smart terminal is powered on, the hardware environment adaptation module is started, and the environmental sensor (environmental sensing module) is activated to detect the current temperature. air pressure ,radiation Parameters such as these.

[0051] The three 16-bit environment parameters are concatenated into a 48-bit environment parameter vector, where... It is a 48-bit binary vector. This is for splicing operations.

[0052] .

[0053] Subsequently, a SHA-256 hash operation is performed on the concatenated environmental parameters, and the first 128 bits are used as the dynamic key seed. ,in, This indicates that the first 128 bits are truncated and used as the dynamic seed. The last 8 bits serve as the dynamic key identifier. : .

[0054] Root key (128-bit, pre-programmed into the main control chip's secure storage area, i.e., the local root keystore) is unreadable. With root key Bitwise XOR operation to generate a temporary key. : .

[0055] Finally, the temporary key That is Input SM4 key expansion algorithm In the process, 32 round keys are generated. : .

[0056] Thus, dynamic seed generation, temporary key operation, and round key expansion are completed in the initialization phase, providing a key foundation for subsequent dynamic encryption.

[0057] (2) Data encryption and transmission stage: Business data is encrypted with SM4 dynamic key and includes a dynamic key identifier. Based on the hash value of environmental parameters, the data can be accessed via the operator's public network or a dedicated 5G public network on the wireless side. Encrypted data is then securely transmitted to the railway network via a VPN tunnel. After entering the dedicated railway network, all data is protected by a network cryptographic machine encryption tunnel before being transmitted to the management center. A dual-channel protection system, consisting of dynamic key encryption and a VPN / cryptographic machine two-layer link encryption, ensures that data transmission is tamper-proof. Let the plaintext block (plaintext) be... Business data is The ciphertext is The final transmitted data frame is denoted as key It has been expanded to RK0-RK 31 Then the dynamic encryption process can be represented as: .

[0058] (3) Decryption and verification stage of the management center: After receiving the ciphertext, the management center platform (management center layer) generates the corresponding temporary key based on the hash value of the attached environment parameters. It then executes the same SM4 key extension process as the terminal layer to generate a round key and completes data decryption; simultaneously, it verifies the hash value of the environment parameters. Consistency is required; if inconsistency is found, access is denied to prevent replay or offline attacks. Let... For data received directly, The relevant formulas are as follows for the recalculated data: .

[0059] The flowchart for decryption and verification is shown below. Figure 5 .

[0060] (4) Physical intrusion protection stage: If the terminal layer detects disassembly, high radiation, vibration or illegal intrusion signals, the self-destruct key protection module is immediately triggered by hardware interruption, the supercapacitor discharge fuse circuit is started, the key storage unit is physically burned and the chip power supply is disconnected, achieving an irreversible circuit breaker effect and realizing hardware-level active physical protection.

[0061] The triple protection mechanism in this application is not a simple combination of three functional modules, but rather a holistic design architecture that links "key-environment-physical" to achieve a proactive, layered defense logic of "sensing before encryption and detecting before destruction." The data (environmental parameters) collected by the environmental sensor (environmental sensing module) is first used to generate a dynamic key, which is the core of the dynamic encryption algorithm and the basis for the dynamic changes in the key. The same set of environmental parameters not only participates in encryption but is also used as the basis for judging security thresholds. When environmental parameters exceed limits or are abnormal, the judgment logic of the self-destruct module (self-destruct execution module) is directly triggered. The key generation process is strongly bound to current hardware environmental parameters such as temperature and radiation. When parameters exceed limits or intrusion is detected, the dynamic key immediately becomes invalid, blocking the continued encrypted transmission of the data link. The dynamic encryption module, the decryption module in the management center, and the self-destruct module on the terminal side all share a unified... and The control channel ensures that the encryption state, environmental state, and physical security state remain consistent, realizing a closed-loop, in-depth security mechanism that integrates key logic, environmental awareness, and physical protection.

[0062] Specifically, the execution process of the technical solution in this application is as follows: (a) Implementation of the dynamic encryption module coupled with environmental parameters.

[0063] The hardware mainly consists of an environmental sensor group (environmental perception module), a main control chip, an encryption chip (dynamic encryption module), and connection interfaces.

[0064] The dynamic key generation process is as follows: (1) Environmental parameter acquisition: Initialize the environmental sensor, read the sensor data once per second to obtain the temperature value T, radiation value R, and air pressure value P (16-bit integer data). (2) Data hash fusion: Concatenate T, R, and P into 48-bit data in order from high to low bits, perform SHA-256 hash calculation on the concatenated data, and extract the first 128 bits as the dynamic seed, denoted as . (3) Dynamic key identifier: by The lower 8 bits are generated and appended to the ciphertext header to identify the version of the dynamic key used in the current block encryption, denoted as . The decryption end uses... The hash value of the environment parameter can be quickly matched to generate the corresponding round key, realizing dynamic key verification and decryption. (4) Temporary key generation: pre-made root key (128-bit, burned into the main control chip's secure storage area, i.e., the local root keystore), and according to... The temporary key is obtained by the bitwise XOR formula. (5) SM4 round key expansion: Input the SM4 key expansion algorithm to generate 32 round keys (128 bits per round), which will then participate in subsequent SM4 internal iterative encryption.

[0065] Encryption execution steps: (1) Plaintext grouping: Group the business data into 128-bit groups and pad with zeros if necessary; (2) Encryption initialization: The main control chip sends an initialization command to the TF cryptographic card via SPI; (3) Data encryption: Each group of plaintext is encrypted in SM4-CBC mode; (4) Ciphertext transmission: The ciphertext is transmitted over the network, and the header encapsulates the KeyID and the hash value of the environment parameters, which can be decrypted and verified by the service center.

[0066] (II) Hardware design of low temperature resistant / radiation TF password card.

[0067] The hardware mainly consists of a substrate material, a shielding layer, an encryption chip, a power management module, and a temperature sensor.

[0068] Low-temperature adaptive process: (1) Temperature monitoring: The temperature sensor monitors the internal temperature of the TF card in real time; (2) Mode switching: When the temperature is ≤-20℃, the power management module automatically switches to low-power mode, shuts down non-core circuits (such as debugging interfaces), and only maintains power supply to the encryption chip and power management module to ensure continuous and reliable operation of the encryption function. When the temperature returns to normal, the system automatically restores the full-function mode, thereby realizing dynamic environmental adaptation and core encryption function protection.

[0069] Radiation protection design: A metal shielding layer is set around the encryption chip to improve the protection against high-energy particles and electromagnetic interference; the chip uses redundant circuits and CRC / ECC verification of key data to ensure that the encryption function can still operate normally in the event of a single event upset or soft error, so as to achieve reliable operation of the chip in a high-radiation environment.

[0070] (III) Implementation of the self-destructing key protection module (physical protection module).

[0071] This module consists of a detection module and a self-destruct execution module. The detection module includes a disassembly detection device and a signal detection device (including a radiation detection device), used to monitor signals corresponding to external physical intrusion and environmental parameters in real time. Taking the radiation detection device as an example, it is used to monitor radiation intensity in real time. The self-destruct execution module includes an energy storage element (supercapacitor) and a fuse circuit (composed of a MOSFET switch and nickel-chromium alloy wires), used to quickly and physically destroy the key when the trigger conditions are met.

[0072] (1) Signal acquisition: The disassembly detection device detects the vibration intensity, and the radiation detection device monitors the radiation value in real time. When any signal exceeds the preset threshold, the GPIO level is pulled high; (2) Interrupt response: After the main control chip in the physical protection module detects the disassembly or radiation over-limit signal, it triggers an unmaskable interrupt to ensure that the safe operation is executed immediately; (3) Key erasure: After the interrupt is triggered, the main control chip sends a key erasure instruction to the encryption chip to perform software-level destruction; (4) Physical melting: The supercapacitor discharges instantaneously, causing the nickel-chromium alloy wire to melt and the key storage area circuit to be permanently disconnected. The data cannot be recovered through the physical probe, thus achieving complete physical destruction.

[0073] (iv) Decryption end environment verification and exception handling mechanism.

[0074] After receiving the encrypted message, the management center platform first parses the encrypted message header to extract... and And search for the root key with the binding bit in the local root keystore. Then generate the corresponding decryption process. Then, the SM4 round key is restored for decryption. After decryption, automatic comparison is performed. The system checks if the key is generated in the same environment as the current environment parameters of the terminal to determine if they match. If they do not match, the system will log an error and refuse the connection. If multiple environment mismatches occur consecutively, the system will proactively issue a key revocation notification and may also send a self-destruct command to the terminal, thereby improving overall consistency verification and intrusion prevention capabilities.

[0075] The benefits of this application are: 1. By using environmental parameters as a necessary factor in key generation, cracking requires obtaining both the key and real-time environmental parameters simultaneously. It also supports dynamic round key expansion using algorithms such as SM4, exponentially increasing the difficulty of cracking compared to traditional static key schemes. The dual-channel encryption scheme of "environment binding + network layer encryption" effectively resists man-in-the-middle attacks and replay attacks, significantly improving security.

[0076] Dynamic Seeds Derived from real-time environmental parameters (48 bits concatenated and then hashed), these parameters serve as input for key expansion, making the expansion process time-dependent and unpredictable. This is because key generation depends not only on... Furthermore, it relies on instantaneous environmental parameters, which is equivalent to introducing additional random entropy into the SM4 128-bit key space, making the comprehensive search space theoretically close to 2^(128+48). Therefore, compared with static key systems, the brute-force attack difficulty of the dynamic key generation process in this application is significantly increased, and replay attacks are unlikely to succeed.

[0077] 2. Enhanced environmental adaptability ensures hardware stability under low temperature and radiation conditions, reducing bit error rate; the adaptive power management module automatically switches in low temperature environments to optimize energy consumption and extend battery life.

[0078] By using low-temperature resistant electronic components and adjusting the power supply mode through real-time temperature feedback, the system can maintain encryption operations without power loss in extreme environments of -40℃, while reducing the power consumption of non-core modules, thus achieving the hardware's "adaptive survivability".

[0079] 3. The self-destruct mechanism responds several times faster than traditional software erasure, physically destroys the key storage area, and achieves 100% complete destruction, completely blocking the risk of data leakage.

[0080] By using a supercapacitor to instantly fuse the wire during overcurrent, irreversible fuse breaking is achieved at the hardware level. The self-destruct response time is usually less than 10 milliseconds, eliminating the problem that software erasure may still be bypassed and read, thus achieving active physical-level protection.

[0081] In one exemplary embodiment, a railway mobile intelligent terminal security protection management method is provided, which is implemented using a railway mobile intelligent terminal security protection management platform.

[0082] like Figure 4 As shown, the railway mobile intelligent terminal security protection management method includes: Step 100: Collect environmental parameters in real time.

[0083] Step 200: Use a hash algorithm to determine the hash value of the environment parameters based on the environment parameters, and generate a dynamic seed. At the same time, the root key Store in the local root keystore.

[0084] Step 300: Based on the dynamic seed With root key Generate temporary key The key generation and round key expansion are completed using the national cryptographic algorithm.

[0085] Step 400: Based on the dynamic seed Determine the dynamic key identifier .

[0086] Step 500: Determine the corresponding temporary key based on the ciphertext, perform decryption using the national cryptographic algorithm, and compare the decrypted dynamic seed with the environment parameter hash value to determine environment compatibility. The ciphertext includes business data and the dynamic key identifier. The system includes environment parameter hash values; business data is in plaintext; and when multiple consecutive instances of environment incompatibility occur, a self-destruct command is sent to the terminal layer to achieve terminal security protection.

[0087] Step 600: When the value of the corresponding environmental parameter exceeds the preset threshold or physical disassembly is detected, the physical protection module triggers the hardware fuse mechanism and burns out the local root key library through current overload.

[0088] In one embodiment, based on dynamic seeds With root key Generate temporary key The key generation and round key expansion are completed using national cryptographic algorithms, specifically including: According to dynamic seeds With root key Generate temporary key .

[0089] The operation is performed using the national cryptographic algorithm and based on the temporary key. Perform key generation and round key expansion to generate 32 round keys. 128 people per round.

[0090] .

[0091] in, This is the key expansion round number; Extend the round key.

[0092] According to dynamic seeds With root key Generate temporary key Specifically, it includes: .

[0093] in, This is an XOR operation.

[0094] Dynamic Seeds The methods for determining this include: The environmental parameters are concatenated to obtain concatenated data; a hash algorithm is used to perform SHA-256 hash calculation on the concatenated data to obtain the hash value of the environmental parameters; the first 128 bits of the hash value of the environmental parameters are extracted as the dynamic seed. .

[0095] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0096] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A railway mobile intelligent terminal security protection management platform, characterized in that, include: The system comprises a terminal layer, a network layer, and a management center layer; the terminal layer is connected to the network layer; the network layer is connected to the management center layer; the terminal layer includes an environment sensing module, a dynamic encryption module, and a physical protection module; the environment sensing module is connected to the dynamic encryption module; and the physical protection module is connected to both the environment sensing module and the dynamic encryption module. The environmental sensing module is used to collect environmental parameters in real time. The dynamic encryption module is used for: A hash algorithm is used to determine the hash value of the environment parameters based on the environment parameters, and a dynamic seed is generated. At the same time, the root key Stored in the local root keystore; According to dynamic seeds With root key Generate temporary key The key generation and round key expansion are completed using the national cryptographic algorithm. According to dynamic seeds Determine the dynamic key identifier ; The network layer is used to transmit ciphertext to the management center layer; the ciphertext includes business data and a dynamic key identifier. And environmental parameter hash values; the network layer includes a dedicated virtual channel constructed using virtual private network technology; the dedicated virtual channel includes a 5G public network dedicated network, which is a data leased line encrypted and protected by a network cryptographic machine; the service data is in plaintext; The management center layer is used to determine the corresponding temporary key based on the ciphertext, and to perform decryption by restoring the national cryptographic algorithm and performing round-key operations. It also compares the decrypted dynamic seed with the hash value of the environment parameters to determine whether the environment is compatible. If multiple consecutive instances of environment incompatibility occur, a self-destruct command is sent to the terminal layer to achieve terminal security protection. The physical protection module is used to trigger a hardware fuse mechanism and burn out the local root key library by means of current overload when the value of the corresponding environmental parameter exceeds a preset threshold or when physical disassembly is detected.

2. The railway mobile intelligent terminal security protection management platform according to claim 1, characterized in that, The dynamic encryption module uses a low-temperature resistant and radiation-resistant TF password card and integrates an adaptive power management module; the adaptive power management module automatically switches to a low-power mode in low-temperature environments; the low temperature corresponds to a temperature of -40℃; the low-power mode is an operating mode with power consumption lower than the preset value.

3. The railway mobile intelligent terminal security protection management platform according to claim 1, characterized in that, The network layer also includes: the operator's public network and the station's private WiFi network.

4. The railway mobile intelligent terminal security protection management platform according to claim 1, characterized in that, The physical protection module specifically includes: a detection module and a self-destruct execution module; The detection module includes a disassembly detection device and a signal detection device; the signal detection device is connected to the environmental perception module; both the disassembly detection device and the signal detection device are connected to the self-destruct execution module. The disassembly and detection device is used to monitor physical intrusion signals outside the terminal in real time; the physical intrusion signals include vibration intensity; The signal detection device is used to monitor signals corresponding to environmental parameters in real time; the environmental parameters include temperature, air pressure, and radiation intensity. The self-destruct execution module is used for: When the signal value corresponding to the environmental parameter exceeds the preset threshold, or when the physical intrusion signal exceeds the corresponding preset threshold, an unmaskable interrupt is triggered, and an interrupt trigger signal is output to the dynamic encryption module; at this time, the dynamic encryption module erases the key, achieving software-level destruction. Physical destruction is achieved by burning out the local root keystore through current overload.

5. The railway mobile intelligent terminal security protection management platform according to claim 4, characterized in that, The response time for physical destruction based on the aforementioned current overload method is less than 10 milliseconds.

6. The railway mobile intelligent terminal security protection management platform according to claim 2, characterized in that, The TF password card includes: an encryption chip and a metal shielding layer; A metal shielding layer is provided around the encryption chip; the encryption chip internally employs redundant circuitry and CRC / ECC verification.

7. A method for security protection and management of railway mobile intelligent terminals, characterized in that, The railway mobile intelligent terminal security protection management method is implemented using the railway mobile intelligent terminal security protection management platform described in any one of claims 1-6; The railway mobile intelligent terminal security protection management method includes: Real-time collection of environmental parameters; A hash algorithm is used to determine the hash value of the environment parameters based on the environment parameters, and a dynamic seed is generated. At the same time, the root key Stored in the local root keystore; According to dynamic seeds With root key Generate temporary key The key generation and round key expansion are completed using the national cryptographic algorithm. According to dynamic seeds Determine the dynamic key identifier ; The corresponding temporary key is determined based on the ciphertext, and the national cryptographic algorithm is used for decryption. Furthermore, the decrypted dynamic seed is compared with the hash value of the environment parameters to determine environmental compatibility. The ciphertext includes business data and a dynamic key identifier. The data includes environmental parameter hash values; the business data is in plaintext; and when multiple consecutive environmental mismatches occur, a self-destruct command is sent to the terminal layer to achieve terminal security protection. When the value of the environmental parameter exceeds a preset threshold or physical disassembly is detected, the physical protection module triggers a hardware fuse mechanism and burns out the local root keystore by means of current overload.

8. The railway mobile intelligent terminal security protection management method according to claim 7, characterized in that, According to dynamic seeds With root key Generate temporary key The key generation and round key expansion are completed using national cryptographic algorithms, specifically including: According to dynamic seeds With root key Generate temporary key ; The operation is performed using the national cryptographic algorithm and based on the temporary key. Perform key generation and round key expansion to generate 32 round keys. 128 people per round; ; in, This is the key expansion round number; Extend the round key.

9. The railway mobile intelligent terminal security protection management method according to claim 8, characterized in that, According to dynamic seeds With root key Generate temporary key Specifically, it includes: ; in, This is an XOR operation.

10. The railway mobile intelligent terminal security protection management method according to claim 7, characterized in that, Dynamic Seeds The methods for determining this include: The environmental parameters are spliced ​​together to obtain spliced ​​data; The concatenated data is hashed using a hash algorithm to obtain the hash value of the environmental parameters; Extract the first 128 bits of the hash value of the environment parameters as the dynamic seed. .