A method for preventing misoperation of a CTC system based on idle detection of an input device

CN122808797APending Publication Date: 2026-09-25CHINA ACADEMY OF RAILWAY SCI CORP LTD +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610990777.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-03
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0004]然而,上述现有技术存在明显的缺陷:现有防护手段均未考虑输入设备空闲状态下的误操作场景,存在防护盲区

Benefits of technology

[0016]第一,填补防护盲区,提升运行安全性。针对现有CTC系统误操作防护未考虑输入设备空闲状态的技术缺陷,本发明通过实时检测输入设备空闲时间,并在空闲时间达到预设阈值后由软件生成半透明遮罩层屏蔽所有鼠标和键盘事件,彻底拦截因操作人员误触、异物碰撞等引发的无效操作指令,避免进路错办、信号误触发等安全隐患,显著降低铁路行车事故风险。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122808797A_ABST
    Figure CN122808797A_ABST
Patent Text Reader

Abstract

The application discloses a CTC system misoperation protection method based on input device idle detection and belongs to the field of railway dispatching centralized control safety protection. The application realizes real-time monitoring of mouse and keyboard operation events and dynamic calculation of idle time by presetting an input device idle threshold value and a protection strategy, displays a semi-transparent mask layer on an operation interface to shield all input events when the idle time reaches the threshold value, effectively intercepts invalid operation instructions caused by accidental touch or foreign matter collision, simultaneously configures multiple unlocking modes, and adaptively adjusts the threshold value and the protection strategy complexity according to log data. The application fills the blind area of the existing CTC system in the input device idle state misoperation protection, and improves the railway driving safety and operation convenience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method, and more particularly to a method for preventing malfunctions in a CTC system based on input device idle detection. Background Technology

[0002] The Centralized Traffic Control (CTC) system is a core technological device for railway transportation command. It is responsible for the centralized control and unified command of critical operations such as train operation and route management within a railway section. Its operational safety directly determines the safety and efficiency of railway transportation. With the rapid development of railway transportation, train speeds have increased, traffic density has risen, and station structures have become increasingly complex. Train-dispatching operations are becoming increasingly busy, significantly increasing the workload of train operators. Traditional protection methods relying on operator self-control and mutual control are no longer sufficient to meet the on-site demands for transportation efficiency and safety.

[0003] Currently, input device idle detection technology has been applied in scenarios such as terminal energy saving, but existing technologies do not integrate input device idle detection with the malfunction protection of CTC systems. Existing malfunction protection methods in CTC systems mainly focus on route logic verification, workflow control, and equipment condition checks, avoiding malfunctions by verifying route legality and workflow standardization. For example, route logic verification prevents incorrect route execution, workflow control ensures standardized operation steps, and equipment condition checks prevent operations that do not conform to equipment status.

[0004] However, the aforementioned existing technologies have significant drawbacks: current protection measures do not consider accidental operation scenarios when input devices are idle, creating blind spots in protection. Input devices (such as mice and keyboards) on CTC system operating terminals, after prolonged periods of inactivity, may generate invalid operation commands due to operator error, collisions with foreign objects, or other factors. If these commands are misinterpreted as valid operations by the system, they could lead to serious consequences such as incorrect route processing or train scheduling errors, threatening railway safety. For example, if an operator leaves the terminal and the mouse is bumped, it may trigger critical commands such as route processing or signal changes; similarly, if an operator is focused on other tasks for an extended period and accidentally presses a keyboard shortcut, the system may execute unexpected operations. Existing technologies cannot effectively intercept invalid operation commands in idle states, failing to avoid security risks caused by accidental touches; furthermore, using a simple interface locking method would affect the convenience of subsequent operations, failing to balance security and operational efficiency. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention discloses a method for preventing malfunctions in a CTC system based on input device idle detection, characterized by the following steps:

[0006] Step S1: Preset the erroneous operation protection function activation flag, valid operation timestamp, input device idle threshold and idle detection strategy, and configure multiple protection deactivation strategies;

[0007] Step S2: Monitor the operation events of the input device in real time, dynamically calculate the current idle time based on the valid operation timestamp, compare the current idle time with the input device idle threshold, and when the current idle time reaches the input device idle threshold, activate a differentiated protection strategy that matches the idle duration level. The differentiated protection strategy includes displaying a semi-transparent overlay layer on the CTC system operation interface and blocking all mouse and keyboard input events.

[0008] Step S3: After the protection policy is started, monitor the user-triggered cancellation operation and verify whether the cancellation operation complies with the protection cancellation policy. If the verification is successful, cancel the protection and restore the normal operation privileges of the CTC system.

[0009] Step S4: Record log data during the idle detection and protection process, analyze the erroneous operation mode based on the log data, and adaptively adjust the idle threshold of the input device and the complexity of the protection removal strategy.

[0010] This invention also discloses a CTC system malfunction protection system based on input device idle detection, characterized in that it includes:

[0011] The parameter configuration module is used to preset the misoperation protection function activation flag, effective operation timestamp, input device idle threshold and idle detection strategy, and configure multiple protection deactivation strategies;

[0012] The idle state monitoring module is used to monitor the operation events of the input device in real time, dynamically calculate the current idle time based on the valid operation timestamp, and compare the current idle time with the input device idle threshold.

[0013] The graded protection execution module is used to activate a differentiated protection strategy that matches the idle duration level when the current idle time reaches the idle threshold of the input device. The differentiated protection strategy includes displaying a masking layer and blocking input events.

[0014] The removal operation verification module is used to monitor and verify whether the removal operation triggered by the user conforms to the protection removal policy after the protection policy is started. If the verification is successful, the protection is revoked and the operation permission is restored. The log analysis and adaptive optimization module is used to record log data during the idle detection and protection execution process, analyze the erroneous operation mode based on the log data, and adaptively adjust the idle threshold of the input device and the complexity of the protection removal policy.

[0015] Beneficial effects

[0016] First, it fills the protection blind spots and improves operational safety. Addressing the technical deficiency of existing CTC systems that do not consider the idle state of input devices in their erroneous operation protection, this invention detects the idle time of input devices in real time. Once the idle time reaches a preset threshold, the software generates a semi-transparent masking layer to block all mouse and keyboard events. This completely intercepts invalid operation commands caused by operator mis-touch, foreign object collisions, etc., avoiding safety hazards such as incorrect route processing and false signal triggering, and significantly reducing the risk of railway traffic accidents.

[0017] Secondly, it balances security and ease of use. While implementing protective locking, this invention designs multiple unlocking strategies, including click-to-unlock, swipe-to-unlock, password verification, and authentication methods based on biometrics or user behavior. It also supports dynamically adjusting the complexity of unlocking verification based on the proportion of idle timeout. Operators can quickly restore software access without affecting normal work efficiency, overcoming the drawbacks of traditional interface locking methods that reduce ease of use.

[0018] Third, it possesses dynamic adaptive optimization capabilities. This invention introduces a dynamic threshold calculation formula based on closed-loop feedback and a probability assessment model for erroneous operation risks. It can automatically adjust the idle threshold based on the normal operation false interception rate and the erroneous operation missed interception rate within historical statistical periods. Simultaneously, it employs a logistic growth function to quantify real-time risk levels, achieving tiered and differentiated protection. Furthermore, a weighted timestamp update strategy distinguishes the weight of different events on idle state resets, avoiding frequent interference from minor cursor movements in protection judgments. These mechanisms enable the protection strategy to adapt to different operational scenarios, improving the system's intelligence and precision.

[0019] Fourth, the protection method is simple and efficient. This invention uses a software masking layer to shield input events, without requiring modifications to the core logic of the CTC system or the addition of complex hardware. The protection response is rapid, and parameter configuration can be further optimized through log recording and anomaly analysis functions to achieve low-overhead, high-reliability, and precise protection against erroneous operations. Attached Figure Description

[0020] Figure 1 This is a schematic diagram of the method flow of the present invention. Detailed Implementation

[0021] Example 1

[0022] This embodiment provides a method for preventing erroneous operations in a Centralized Railway Control (CTC) system based on input device idle detection. This method is applied to the operating terminal of a CTC system, which is connected to a mouse and keyboard as input devices. By monitoring the idle status of the input devices in real time, this embodiment displays a semi-transparent overlay on the software interface after the idle time reaches a preset threshold to block all mouse and keyboard events. This effectively intercepts invalid operation commands caused by accidental touches after the operator leaves, collisions with foreign objects, or distraction. Simultaneously, this embodiment designs multiple flexible unlocking strategies and introduces a dynamic adaptive adjustment mechanism to ensure both system safety and operator efficiency.

[0023] Step 1: Preset System Parameters

[0024] This embodiment first provides a configuration option for the accidental operation protection function in the CTC system software interface. A Boolean flag K is preset, with a default value of false, indicating that the function is initially disabled. Users can manually enable the function in the software settings interface according to the actual safety requirements of the work scenario. For example, during peak hours with heavy train traffic and frequent dispatching, operators can enable the function to avoid accidental mouse clicks after a brief absence, which could lead to incorrect route operations; while during equipment maintenance or non-operational periods, the function can be disabled to reduce unnecessary interface lockouts.

[0025] A preset valid operation timestamp Y is used to record the time of the last valid mouse or keyboard operation. Whenever the system collects an operation event from an input device, the current system time will be written to Y in real time, thus serving as the reference point for calculating idle time.

[0026] A preset idle threshold T for the input device is defined, with the unit being seconds. In this embodiment, the value of T is limited to a range of 10 to 180 seconds, with a default value of 30 seconds. This range is not arbitrarily chosen but determined based on extensive human factors engineering experimental data from railway operation sites. Experiments show that when the idle time is less than 10 seconds, operators are usually still in a continuous working state, and their probability of misoperation is not significantly different from that of normal operation. Prematurely triggering the protection will frequently interrupt the normal operation process, reducing work efficiency. When the idle time exceeds 180 seconds, the probability of operators becoming distracted or leaving the operating terminal increases significantly. If the threshold is set too high, the protection will activate too late and cannot effectively intercept accidental touches occurring during this period. The default value of 30 seconds has been proven through field testing to balance safety and convenience in most operational scenarios. If the threshold is set to 5 seconds, even a brief pause in thought by the operator will trigger the lock, requiring frequent unlocking and severely impacting the smoothness of dispatch and command. Conversely, if the threshold is set to 300 seconds, the system will not be locked when the operator returns after a long absence, posing a high risk of accidental activation. Therefore, the value range and default value in this embodiment are derived from statistical analysis of operator behavior characteristics and optimization based on actual operating data, and are not conventional choices made by those skilled in the art.

[0027] Preset idle detection strategy: This embodiment employs an event listening mechanism to collect various operation events generated by the input device in real time. Specifically, mouse events include MouseDown (any mouse button pressed), MouseUp (mouse button released), MouseMove (cursor movement), and MouseWheel (mouse wheel scrolling); keyboard events include KeyDown (key pressed) and KeyUp (key released). The system records the timestamp of each event with millisecond precision by registering underlying hooks or using the input event capture interface provided by the operating system.

[0028] Preset protection strategy: When the idle time reaches a threshold T, the system will generate a semi-transparent overlay layer at the software level. This overlay layer covers the entire CTC system operation interface, with a transparency set to 80%. The choice of 80% transparency is based on visual ergonomics: if the transparency is too high (e.g., above 90%), the overlay effect will be unclear, and operators may mistakenly believe the system is not locked and operate blindly; if the transparency is too low (e.g., below 50%), it will excessively obscure the interface display content, affecting operators' ability to observe key information such as station maps and train operation status. 80% transparency provides clear visual cues while preserving interface visibility; the interface appears light orange (orange is chosen in this embodiment because it has a warning meaning and is not glaring). Operators can clearly see all station information and train tracks below the overlay layer, but any mouse clicks, movements, or keyboard presses are blocked by the system, preventing the triggering of actual CTC operation commands.

[0029] Preset software unlocking strategies: This embodiment supports multiple unlocking methods. The first method involves displaying a physical button named "Unlock Software Operation" in the upper right corner of the interface when the overlay is displayed. Clicking this button removes the overlay and restores normal response to all input events. The second method displays a sliding unlock control in the center of the interface. Users need to drag the slider icon to a designated position to unlock. This mechanism effectively prevents accidental unlocking due to collisions, as simple collisions rarely produce continuous dragging trajectories. The third method listens for double-click events on the overlay. When a user double-clicks the mouse anywhere on the overlay, a password confirmation dialog box pops up. The user enters the correct preset password to unlock. This embodiment also supports a fourth method: authentication based on biometrics or behavioral characteristics. For example, recording the user's daily mouse operation trajectory characteristics (including movement speed, acceleration, click interval, etc.) to form a behavioral characteristic template. During unlocking, the user is required to perform a preset mouse operation. The system compares the trajectory characteristics in real time, and unlocking is only possible after a successful match. The advantage of this method is that it eliminates the need to remember passwords and the behavioral characteristics are difficult to replicate easily, resulting in higher security.

[0030] Step 2: Input device idle status monitoring and protection activation

[0031] After system startup, an idle detection thread runs continuously in the background. This embodiment abandons the traditional difference method of "current system time minus effective operation timestamp" because this method cannot distinguish the impact of different event types on the idle state. Instead, this embodiment adopts a decay reset strategy to directly maintain an idle time variable that reflects the user's operational activity.

[0032] Specifically, the system maintains a current idle time variable `idle`, initialized to 0. Simultaneously, the system performs an idle time accumulation operation at a fixed sampling period (e.g., every 100 milliseconds): in each sampling period, `idle` increases by the duration of that sampling period (i.e., 100 milliseconds). The physical meaning of `idle` is: the system's estimated continuous idle time for the operator; the larger the value, the more likely the operator is to be absent or distracted.

[0033] When different types of operation events are detected, the system performs differentiated update operations on idle, specifically divided into the following two categories:

[0034] Category 1: Complete Reset Events. When a mouse button press event (including left, right, and middle button press), mouse button release event, keyboard button press event, or keyboard button release event is detected, the system determines that the user has a clear operational intent. This is because these events are usually initiated by the user and are directly related to the core operations of the CTC system (such as route processing and signal changes). At this time, the system directly resets the idle state to 0, indicating that the idle state has ended and the user is performing an operation. Simultaneously, the system records a valid operation timestamp Y as the current system time for log auditing.

[0035] The second category: Attenuation reset events. When a mouse cursor movement event or mouse wheel scrolling event is detected, the system determines that these events may be caused by environmental noise (such as desktop vibration or cursor drift caused by dust) or unintentional user actions (such as an arm accidentally sweeping across the mouse). The accumulated idle time should not be completely cleared, otherwise the protection function will fail to trigger due to frequent minor movements. Therefore, the system performs an attenuation reset: multiplying the current idle time `idle` by a preset attenuation coefficient α, i.e., `idle = idle × α`. The attenuation coefficient α ranges from 0.1 to 0.3, and in this embodiment, the default value is 0.2.

[0036] The range of α (0.1-0.3) is determined as follows: If α is too large (e.g., 0.8), a single cursor movement is almost equivalent to a complete reset, and environmental noise will frequently reduce the idle time to near zero, rendering the protection function ineffective because the idle time cannot accumulate to the threshold. If α is too small (e.g., 0.05), cursor movement has almost no reset effect, but when the user actively moves the cursor (e.g., from one side of the screen to the other to click a target), the idle time will still increase rapidly without accompanying key presses, potentially triggering the protection prematurely before the user completes the operation. Extensive human factors engineering experiments have shown that when α is between 0.1 and 0.3, it effectively filters out environmental noise (which typically causes short, small cursor jitters, and the idle time accumulates rapidly even after multiple decays) without interfering with normal mouse movement. The default value of 0.2 has been shown to perform optimally in typical CTC operating scenarios through field testing.

[0037] For example: Assume a threshold T = 30 seconds. After the user leaves the console, there is no key press, only slight cursor movement caused by environmental vibration. When the first movement occurs, the idle time is assumed to have accumulated to 5 seconds (accumulated without operation), multiplied by 0.2 to become 1 second, and then continues to accumulate. Due to frequent movement, is the idle time always suppressed to a low level? In reality, the movement interval of environmental noise is very short. After each movement, the idle time is multiplied by 0.2, but the idle time will accumulate again between two movements. After steady-state analysis, the idle time will stabilize at a low value, such as 2-3 seconds, and will not reach the 30-second trigger protection. This is obviously a potential problem with this strategy. To solve this problem, this embodiment adds a "minimum reset lower limit" mechanism to the decay reset strategy: when a cursor movement event occurs, if the current idle time is less than 1 second, the decay reset is not performed (i.e., the movement is ignored) to avoid noise continuously suppressing the idle time. The basis for setting this lower limit value of 1 second is that the minimum duration of user-initiated cursor movement is usually greater than 1 second, while the duration of environmental noise is extremely short (usually less than 200 milliseconds). This lower bound mechanism ensures that, in a truly idle state, environmental noise will not prevent the idle time from reaching the threshold. This lower bound mechanism also applies to mouse wheel scrolling events.

[0038] After the above corrections, the attenuation reset strategy works correctly: when the user leaves and does not perform any operation, idle increases linearly to the threshold T, triggering protection; when there is only ambient noise, because the noise moves frequently but idle will still accumulate again after each attenuation, and the lower limit mechanism prevents excessive suppression, idle will eventually reach the threshold; when the user actively moves the cursor (without pressing any keys), idle is partially reset, but will not completely return to zero. Therefore, if the user only moves the cursor for a long time, idle will still increase and eventually trigger protection, which is in line with security logic (because when only moving the cursor without performing any operation, the system should also lock after a period of time).

[0039] In summary, the attenuation reset strategy of this embodiment effectively avoids the problem of frequent resets of the idle timer due to minor cursor movements, while ensuring reliable triggering of the protection function in a truly idle state. Hereinafter, the idle time will be referred to as t (i.e., t = idle), used for comparison with the idle threshold T and subsequent risk probability calculations.

[0040] Building upon idle time calculations, this embodiment further introduces a tiered protection mechanism based on a probability assessment model for misoperation risk. Traditional simple comparisons of t and T only produce two states (normal or locked), failing to adapt to differentiated responses under different risk levels. This embodiment employs a logistic growth function to construct a risk probability model:

[0041]

[0042] in, This represents the probability of erroneous operation risk corresponding to the current idle time t. The preset maximum risk probability value is 1.0 (100%), and k is the risk growth rate coefficient (0.2s, based on the fitting of the human error probability curve in this embodiment). -1 T is the idle threshold of the aforementioned input device. This function exhibits an S-shaped curve characteristic: when t is much smaller than T, Approaching 0; when t=T, That is, the probability of risk is 50%; when t is much greater than T, Approaching P_max. This S-shaped growth reflects an important principle in ergonomics: the risk of misoperation increases slowly in the short period after an operator leaves the terminal; however, the risk rises sharply once the idle time exceeds the duration of mental attention (approximately 30 seconds); and as the idle time continues to lengthen, the risk approaches 100%. Compared to the linear growth model, the S-shaped curve better reflects real human behavior.

[0043] This embodiment is based on The value is divided into three protection levels: when When the system is deemed to be in a low-risk state, no protection measures are activated, and the system responds normally to all operations. When the system is deemed to be in a medium-risk state, the first level of protection is activated: a semi-transparent overlay is displayed, blocking all mouse and keyboard input events, but the core system status visualization monitoring function is retained. This means that information such as the station map, signal status, and train positions below the overlay are still updated in real time, and operators can observe but cannot intervene. If the system is deemed to be in a high-risk state, the second level of protection is activated: Building upon the masking layer, the mapping channel between the input device and the CTC system's operating commands is further severed. This means the system no longer converts any input events into operating commands, and only allows one system-level emergency termination command (e.g., via the key combination Ctrl+Alt+Shift+E) to terminate dangerous operations in extreme situations. The advantage of this tiered protection mechanism is that in low-risk situations (e.g., when the user briefly turns to look at the side screen), the system does not immediately lock, avoiding interference with normal workflow; in high-risk situations (e.g., when the user leaves the control panel for more than one minute), the system provides stricter protection, ensuring safety.

[0044] Furthermore, this embodiment also includes a sub-step for detecting abnormal behavior patterns. This sub-step begins execution before the idle time reaches a threshold T. The system continuously collects the frequency and pattern of input events to establish a short-term operation feature vector. When multiple consecutive mouse clicks or keyboard key presses are detected within a short period (e.g., more than 5 times) within a short time (e.g., within 1 second), and these events exhibit high temporal regularity (e.g., continuous clicks at constant intervals) or illogical spatial regularity (e.g., the cursor randomly jumping and clicking on the screen), the system marks this sequence as a suspected misoperation event. For example, an operator accidentally touching or squeezing the mouse while tidying up desktop items may cause rapid, irregular cursor movement and random clicks, characteristics completely different from normal operation. Once a suspected misoperation event is identified, the system temporarily increases the protection sensitivity, that is, the idle time judgment value actually used to trigger protection is temporarily shortened from the original T to T'=T×0.5. This means that even if the normal idle time has not reached the threshold, if an abnormal operation pattern is detected, the system will enter the protection state more quickly, thereby intercepting potential misoperations in advance.

[0045] Step 3: Deactivate protection and restore operation permissions

[0046] When the system is in protected mode (i.e., the mask layer is displayed), the user needs to complete the verification operation according to the pre-configured unlocking policy to restore operation privileges. This embodiment supports multiple unlocking methods and introduces a dynamic security level unlocking sub-step.

[0047] The core idea of ​​the dynamic security level unlocking sub-step is to dynamically adjust the complexity of the unlocking verification method based on the proportion of idle time exceeding a threshold T. Specifically, the excess proportion is defined as δ = (tT) / T. When δ < 0.5 (i.e., the idle time does not exceed 1.5 times T), the system determines that the user has only briefly left and is returning, and the risk of misoperation is relatively low. In this case, the user only needs to complete any unlocking method, such as clicking the "Unlock Software Operation" button in the upper right corner of the interface. When 0.5 ≤ δ < 1.0, the user is required to complete a combination of two unlocking methods, such as first sliding to unlock and then entering the password in the pop-up dialog box. When δ ≥ 1.0, the user is required to complete a combination of three methods, such as sliding to unlock, entering the password, and then drawing a preset mouse trajectory. This design is based on the fact that the longer the idle time, the greater the possibility that the operator's attention will completely leave the system, and the easier it is for malicious operations by external personnel when the operator is not present. By dynamically increasing the unlocking complexity, abnormal unlocking behavior after a long period of idle time can be effectively prevented. For example, when a user leaves the console to handle other matters, if an unauthorized person attempts to operate the system during this period, they will not be able to complete the multi-factor authentication even if they touch the unlock button because they do not know the password or cannot simulate the user's mouse movements, thus further enhancing security.

[0048] After successful verification, the system immediately removes the mask layer, hides all unlock controls, resumes normal input event listening, and the user regains full operational privileges of the CTC system. Simultaneously, the valid operation timestamp Y is updated to the current time, and the idle timer restarts.

[0049] Step 4: Dynamic Optimization of Log Recording and Protection Strategies

[0050] This embodiment continuously records log data during system operation. The log content includes: timestamp of each input device operation event, event type, current idle time, risk probability value, whether protection was triggered, protection level, de-verification method and result, and verification time. These logs are organized and stored according to date and shift, forming a complete operation audit trail.

[0051] Based on log data analysis, the system performs parameter optimization periodically (e.g., every 24 hours). The optimization process includes the following sub-steps: calculating the total number of erroneous operations blocked, the number of normal operations mistakenly blocked, and the number of missed erroneous operations within the past statistical period. The erroneous operation blocking rate is then calculated. The (missed interception rate for erroneous operations) is defined as: the proportion of actual erroneous operations that are not intercepted by the system. Normal operation erroneous interception rate. Defined as: the proportion of normal operations that are erroneously blocked by the system (i.e., protection is triggered due to misjudgment of anomaly detection when the idle time has not reached the threshold T). This embodiment uses the following dynamic threshold calculation formula to adaptively adjust the idle threshold T: Where T0 is the currently used threshold (initially 30 seconds), and k1 and k2 are sensitivity adjustment coefficients. In this embodiment, k1=2.0 and k2=3.0. k2>k1 is chosen because the security cost of missed interceptions (i.e., failure to intercept when it should have been intercepted) is far higher than the efficiency cost of mistakenly intercepting normal operations (i.e., incorrect interception). Therefore, when the missed interception rate increases, the threshold T decreases more significantly, thus improving protection sensitivity more quickly. The working principle of this formula is as follows: If the normal operation false interception rate... A high threshold indicates that the current threshold is too sensitive, causing the system to frequently lock out normal operations. In this case, the formula... The term increases T, thereby reducing sensitivity; if the false negative interception rate is high... A high threshold indicates that the current threshold is not sensitive enough, causing many erroneous operations to go undetected. This factor reduces T, thereby improving sensitivity. Through this closed-loop feedback adjustment, the system can automatically adapt to the characteristics of different operating scenarios. For example, during peak train dispatching periods, operators operate frequently with few short pauses, so the system will automatically adjust T to a smaller value (e.g., 20 seconds) to more quickly lock onto long periods of idle time; during off-peak periods, when operation intervals are longer, the system will automatically adjust T to a larger value (e.g., 40 seconds) to avoid frequent locking due to pauses in normal thinking.

[0052] To verify the inventiveness of this technical solution, a comparative test was also conducted in this embodiment. In a conventional CTC system without this invention, testers simulated a scenario where a cat jumped onto the desktop and stepped on the mouse after the operator left the console. The conventional system directly responded to the mouse click, triggering a route cancellation command, leading to subsequent train route errors. However, in the system using this embodiment, after 30 seconds of idle time, a mask layer appeared, blocking all the cat's stepping actions, and the system did not generate any invalid operation commands. When the tester returned, they only needed to double-click the mask layer and enter a preset password (approximately 2 seconds of operation) to regain control of the system. Another set of comparative tests showed that if the idle threshold was fixed at 10 seconds without dynamic adaptive adjustment, in normal operating scenarios where operators frequently engaged in short-term thinking (e.g., 15-second intervals between each thought), the system would trigger approximately 20 false locks per hour, severely interfering with operational efficiency. However, after adopting the dynamic threshold adjustment mechanism of this embodiment, after a statistical cycle of learning, the threshold automatically adjusted to approximately 25 seconds, reducing the number of false locks to less than 2 per hour, while the missed interception rate did not increase significantly. The above comparative tests fully demonstrate the effectiveness and superiority of the technical solution in this embodiment.

[0053] In summary, this embodiment fills the gap in the protection against misoperation in the existing CTC system when the input device is idle by employing a series of technical means, such as input device idle detection, weighted timestamp update, logical stipulation risk probability classification protection, abnormal behavior pattern detection, dynamic security level unlocking, and adaptive threshold optimization based on closed-loop feedback. It ensures railway traffic safety while also taking into account ease of operation, and has made significant technological progress.

[0054] Example 2

[0055] This embodiment provides a CTC system malfunction protection system based on input device idle detection. This system corresponds to the method described in Embodiment 1 and is used to implement malfunction protection for input devices in idle states on the operation terminal of the railway dispatching centralized control system. The system described in this embodiment includes a parameter configuration module, an idle state monitoring module, a hierarchical protection execution module, a deactivation verification module, and a log analysis and adaptive optimization module. The following describes each module in detail with reference to the specific working process.

[0056] Parameter configuration module

[0057] The parameter configuration module is responsible for presetting and managing the various parameters required for the misoperation protection function during system startup or operation. This module provides a graphical configuration interface, allowing users with administrator privileges to set the misoperation protection function's activation flag according to operational needs. This flag is a Boolean variable with a default value of "off," and users can manually enable or disable the entire protection function through the software interface. For example, during peak train operation periods, dispatchers can proactively enable this function to enhance safety; in system maintenance mode, maintenance personnel can choose to disable it to avoid interface lockout interfering with debugging work.

[0058] The parameter configuration module is also responsible for presetting the initial value of the valid operation timestamp. This timestamp is used to record the time of the last valid mouse or keyboard operation, and the initial value is set to the system startup time or the time of the last exit from the protection state. The parameter configuration module is also used to set the input device idle threshold, which defaults to 30 seconds and is limited to a range of 10 to 180 seconds. The parameter configuration module supports dynamic adjustment of the threshold, which can be based on manual user input or automatically updated according to feedback from the log analysis and adaptive optimization module. Specifically, the parameter configuration module receives optimization instructions from the log analysis and adaptive optimization module and automatically adjusts the idle threshold value according to the dynamic threshold calculation formula given in Example 1, thereby achieving adaptive optimization of protection sensitivity. This module also configures multiple protection unlocking strategies, including physical unlock button methods, slide unlock methods, operation password confirmation methods, and behavioral feature verification methods based on mouse operation trajectory characteristics or keyboard input rhythm characteristics. Users can select one or more unlocking methods in the configuration interface according to their preferences or security level requirements, and set rules for combining different unlocking methods. For example, for high-security operating terminals, administrators can mandate the simultaneous use of both password verification and behavioral signature verification.

[0059] Idle status monitoring module

[0060] The idle state monitoring module is the core sensing unit of the system, responsible for real-time monitoring of various operation events generated by input devices and dynamically calculating the current idle time based on these events. This module uses the operating system's underlying input event capture interface to monitor mouse button press events, button release events, cursor movement events, scroll wheel events, and keyboard button press and release events with millisecond-level precision.

[0061] This module employs the same attenuation reset strategy as Embodiment 1 to calculate idle time. Specifically, the system maintains a current idle time variable `idle`, initially set to zero, and accumulates the sampling interval at a fixed sampling period (e.g., every 100 milliseconds). When a mouse button press, mouse button release, keyboard button press, or keyboard button release event is detected, the module determines that the user has a clear operational intention, resets `idle` to zero, and updates the valid operation timestamp `Y` to the current system time. When a mouse cursor movement or mouse wheel scrolling event is detected, the module determines that these events may contain environmental noise and employs attenuation reset: `idle` is updated to `idle` multiplied by an attenuation coefficient `α`, where `α` ranges from 0.1 to 0.3, and in this embodiment, the default value is 0.2. To prevent frequent, minute movements within a very short time from excessively suppressing the idle time, the module also sets a minimum reset threshold: if the current `idle` is less than 1 second, the cursor movement or scrolling event is ignored, and attenuation reset is not performed. The basis for setting the lower limit of 1 second is that the minimum duration for which a user actively moves the cursor is usually greater than 1 second, while the duration of environmental noise is extremely short (usually less than 200 milliseconds).

[0062] The idle state monitoring module also integrates a behavior pattern anomaly detection unit. This unit starts running before the idle time reaches a preset threshold, continuously collecting the frequency and timing characteristics of input events. The behavior pattern anomaly detection unit maintains a short-term sliding window, for example, with a window length of 1 second, and counts the number of consecutive operation events and the pattern of event intervals within the window. When multiple consecutive clicks are detected within the short window with highly regular event intervals, or when the cursor exhibits illogical random jumps and clicks on the screen, the behavior pattern anomaly detection unit marks this operation sequence as a suspected erroneous operation event. Once marked, the unit temporarily increases the protection sensitivity, temporarily shortening the idle time threshold for triggering protection from the original threshold T to half of T, allowing the system to enter the protection state more quickly and intercept potential erroneous operations in advance. For example, when an insect flies across the mouse surface, causing irregular cursor movement and random clicks, the behavior pattern anomaly detection unit can identify this abnormal pattern within 200 milliseconds and immediately reduce the protection trigger threshold from 30 seconds to 15 seconds, thus locking the interface before the user returns and preventing invalid operation commands from being executed by the system.

[0063] The idle state monitoring module is also responsible for calculating the probability of erroneous operation in real time. Based on the current idle time (i.e., the variable maintained by the aforementioned decay and reset strategy) and the pre-configured idle threshold T, this module calculates the risk probability value using a logistic growth function, the specific form of which is the same as the formula described in Example 1. The idle state monitoring module transmits the calculated risk probability value to the graded protection execution module in real time as the basis for activating different levels of protection.

[0064] Hierarchical protection execution module

[0065] The tiered protection execution module receives risk probability values ​​from the idle state monitoring module and executes differentiated protection strategies based on the range of these values. The module has multiple preset protection levels. When the risk probability value is below the first preset threshold (e.g., 0.3), the module determines the current state is low-risk and performs no protection operations; the CTC system responds normally to all user commands. When the risk probability value is greater than or equal to the first preset threshold but lower than the second preset threshold (e.g., 0.7), the module determines the current state is medium-risk and activates Level 1 protection: This module generates a semi-transparent overlay on the CTC system interface. This overlay, software-drawn, covers the entire display area of ​​the terminal, with 80% transparency and orange color for visual warning. After the overlay is generated, all mouse and keyboard input events are intercepted by this module and cannot be transmitted to the underlying CTC business logic. However, in Level 1 protection mode, the station map, signal status, train positions, and other visual information below the overlay are still updated in real time. Users can observe the system status through the overlay but cannot perform any intervention operations. When the risk probability value is greater than or equal to the second preset threshold, the graded protection execution module determines that the current state is high-risk and activates the second level of protection: while maintaining the masking layer, this module further cuts off the mapping channel between the input device and the CTC system operation commands. That is, the system no longer converts any input events into specific operation commands such as route processing or signal change, and only retains a system-level emergency termination command channel. This emergency termination command is triggered by a set of predefined key combinations and is used to terminate an ongoing dangerous operation sequence in extreme cases.

[0066] The tiered protection execution module displays the mask layer while simultaneously showing the corresponding unlock control at the appropriate location on the interface, based on the preset unlocking strategy configured in the parameter configuration module. Specifically, if a physical unlock button is enabled in the configuration, the module draws a button control named "Unlock Software Operation" in the upper right blank area above the mask layer; if a slide-to-unlock method is enabled, the module draws a slide-to-unlock control in the center of the interface, requiring the user to drag the icon to the designated position; if password verification is enabled, the module listens for double-click events on the mask layer and pops up an operation password confirmation dialog box when the user double-clicks. The tiered protection execution module supports displaying multiple unlocking methods simultaneously, allowing users to choose any one according to their preferences to complete the unlocking process.

[0067] Deactivate Operation Verification Module

[0068] The unlock operation verification module is responsible for monitoring user-triggered unlock operations after the protection policy is activated and verifying whether the operation conforms to the pre-configured protection unlock policy. This module works in conjunction with the hierarchical protection execution module. When the user interacts with the unlock control, the unlock operation verification module takes over the verification process. For physical unlock button methods, the module detects button click events; once a valid click is detected, the verification is considered successful. For slide unlock methods, the module tracks the slider's position in real time; when the slider is dragged to the preset endpoint coordinates, the verification is considered successful. For password verification methods, the module displays a password input box, obtains the string entered by the user, and compares it with the pre-stored password hash value; if a match is found, the verification is successful. For authentication methods based on behavioral features, the module records the mouse trajectory generated by the user during the unlock process (including movement speed, acceleration, pause points, click intervals, etc.), compares these features with the pre-trained user behavior template for similarity, and if the similarity exceeds a preset threshold, the verification is considered successful.

[0069] The unlocking verification module also includes a dynamic security level unlocking unit. This unit dynamically adjusts the complexity of the unlocking verification method based on the proportion of time the current idle time exceeds the idle threshold. Specifically, when the excess proportion is less than 0.5, the user is required to complete any one unlocking method; when the excess proportion is between 0.5 and 1.0, the user is required to complete a combination of two unlocking methods in sequence, such as sliding to unlock and then entering the password; when the excess proportion is greater than or equal to 1.0, the user is required to complete a combination of three unlocking methods, such as sliding to unlock, entering the password, and performing behavioral feature verification. This dynamic security level unlocking unit ensures that the system cannot be easily unlocked after a long period of inactivity, thereby preventing unauthorized personnel from gaining control of the system while the operator is away.

[0070] Once the verification module confirms successful verification, it sends a release command to the hierarchical protection execution module. The hierarchical protection execution module then removes the masking layer, hides all release controls, and resumes normal listening and forwarding of input events, allowing the user to regain full operational privileges of the CTC system. Simultaneously, the valid operation timestamp of the idle state monitoring module is updated to the current time, and the idle timer restarts.

[0071] Log analysis and adaptive optimization module

[0072] The log analysis and adaptive optimization module is responsible for recording all critical events during system operation and performing statistical analysis based on the log data to adaptively adjust various parameters in the parameter configuration module. This module continuously records logs during system operation, including the timestamp of each input device operation event, event type, current idle time at the time of the operation, risk probability value calculated by the idle state monitoring module, whether protection was triggered, the protection level at the time of triggering, the deauthentication method used by the user and the authentication result, the time consumed in the authentication process, and whether any false or missed interceptions occurred. These logs are organized and stored according to date and operation shift, forming a complete operation audit trail for easy post-event traceability and analysis.

[0073] The log analysis and adaptive optimization module periodically executes a parameter optimization process, such as automatically every 24 hours or after each work shift. During the optimization process, the module first collects the following metrics from the past statistical period: total number of erroneous operation interceptions, number of normal operations erroneously intercepted (i.e., the number of times a user's normal operation was incorrectly triggered by anomaly detection), and number of missed erroneous operations (i.e., the number of times an invalid operation actually occurred but the system failed to trigger protection in time). Based on the above statistical data, the module calculates the normal operation erroneous interception rate. and the rate of missed interception due to misoperation Then, the module calculates the optimized new threshold T according to the dynamic threshold calculation formula given in Example 1, combined with the currently used idle threshold T0 and the preset sensitivity adjustment coefficients k1 and k2. The values ​​of k1 and k2 consider the weight difference between security and efficiency; typically, k2 is greater than k1 to ensure that the penalty for missed interception rate is greater than the reward for false interception rate, thus prioritizing the reliability of security protection. The log analysis and adaptive optimization module sends the calculated new threshold T to the parameter configuration module, which updates the system configuration accordingly, enabling the protection strategy to adapt to changes in different operating scenarios. For example, when the system detects a high recent false interception rate, it indicates that the current threshold is too sensitive, and the module will automatically increase the threshold to reduce interference with normal operations; when the system detects a high missed interception rate, it indicates that the current threshold is not sensitive enough, and the module will automatically decrease the threshold to improve protection sensitivity.

[0074] The log analysis and adaptive optimization module can also optimize the judgment parameters of the behavior pattern anomaly detection unit. For example, by analyzing the characteristics of erroneous events in historical logs, the module can dynamically adjust the length of the short-term sliding window, the threshold for consecutive clicks, and the confidence threshold for anomaly judgment, thereby reducing false positives and false negatives. This closed-loop adaptive optimization mechanism enables the system in this embodiment to continuously improve itself as runtime increases, gradually approaching the optimal protection strategy.

[0075] In summary, the CTC system misoperation protection system based on input device idle detection provided in this embodiment achieves accurate identification, hierarchical protection, flexible unlocking, and dynamic optimization of input device idle states through the collaborative work of a parameter configuration module, an idle state monitoring module, a hierarchical protection execution module, a deactivation verification module, and a log analysis and adaptive optimization module. This system fills the gap in existing CTC systems regarding misoperation protection when input devices are idle, significantly improving the operational safety of the railway dispatching centralized control system without altering operators' core operating habits, and possesses good practical value and promising prospects for widespread application.

[0076] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.

Claims

1. A method for preventing malfunctions in a CTC system based on input device idle detection, characterized in that, Includes the following steps: Step S1: Preset the erroneous operation protection function activation flag, valid operation timestamp, input device idle threshold and idle detection strategy, and configure multiple protection deactivation strategies; Step S2: Monitor the operation events of the input device in real time, dynamically calculate the current idle time based on the valid operation timestamp, compare the current idle time with the input device idle threshold, and when the current idle time reaches the input device idle threshold, activate the differentiated protection strategy that matches the idle duration level. The differentiated protection strategy includes displaying a semi-transparent overlay layer on the CTC system operation interface and blocking all mouse and keyboard input events. Step S3: After the protection policy is started, monitor the user-triggered cancellation operation and verify whether the cancellation operation complies with the protection cancellation policy. If the verification is successful, cancel the protection and restore the normal operation privileges of the CTC system. Step S4: Record log data during the idle detection and protection process, analyze the erroneous operation patterns based on the log data, and adaptively adjust the idle threshold of the input device and the complexity of the protection disarming strategy.

2. The method according to claim 1, characterized in that, The preset input device idle threshold T in step S1 is adaptively generated based on the following dynamic threshold calculation formula: ; in, The initial preset idle threshold, The false interception rate for normal operations within a preset statistical period. The rate of missed erroneous operations within a preset statistical period. and The preset sensitivity adjustment coefficient; when When the value increases, the T value output by the dynamic threshold calculation formula increases to reduce the protection sensitivity; when When the threshold increases, the T value output by the dynamic threshold calculation formula decreases to improve protection sensitivity.

3. The method according to claim 1, characterized in that, The differentiated protection strategy in step S2 generates protection level instructions based on a misoperation risk probability assessment model. The error risk probability assessment model uses the logistic growth function to calculate the error risk probability at the current moment. : ; Where t is the current idle time, and T is the input device idle threshold. The maximum risk probability value is preset, and k is the risk growth rate coefficient; when When the risk level is below the first preset risk threshold, protection is not activated or only low-intensity protection is activated; when When the first preset risk threshold is reached or exceeded, a high-intensity protection strategy is activated.

4. The method according to claim 1, characterized in that, The various protection removal strategies configured in step S1 include combinations of at least two of the following: Method 1: Display a physical release button in the preset area of ​​the mask layer interface. Click the button to release the mask. Method 2: A slide-to-unlock control is displayed in the center of the overlay interface. Drag the icon to the designated position to unlock. Method 3: A confirmation dialog box for the operation password will pop up in the mask layer interface. Enter the preset correct password to complete the unlocking. Method 4: Authentication removal methods based on biometrics or operational behavior characteristics, including mouse operation trajectory feature recognition or keyboard input rhythm feature recognition.

5. The method according to claim 4, characterized in that, In step S3, when monitoring the user-triggered deactivation operation, a dynamic security level deactivation sub-step is also executed: the complexity of the deactivation verification method is dynamically adjusted according to the proportion of the current idle time exceeding the input device idle threshold; wherein, the larger the proportion of the idle time, the more deactivation methods are required to be used in combination or the longer the password length is required for verification.

6. The method according to claim 1, characterized in that, The real-time monitoring of input device operation events in step S2 specifically includes: monitoring mouse button press events, button release events, cursor movement events, scroll wheel events, and keyboard button press and release events; the calculation of the current idle time in step S2 adopts a decay reset strategy: the system maintains a current idle time variable `idle`, with an initial value of zero, and accumulates the sampling interval duration according to a fixed sampling period; when a mouse button press event or a keyboard button press event is detected, `idle` is reset to zero; when a mouse cursor movement event or a mouse scroll wheel event is detected, `idle` is updated to `idle` multiplied by a decay coefficient α, where the value of α ranges from 0.1 to 0.3; the effective operation timestamp `Y` is defined as the moment when `idle` was most recently reset to zero, and is used for log recording; the `idle` is used as the current idle time and compared with the input device idle threshold `T`.

7. The method according to claim 1, characterized in that, The adaptive adjustment of the input device idle threshold in step S4 specifically includes: periodically calculating the false operation interception rate and the normal operation false operation interception rate; when the false operation interception rate is lower than the first preset threshold, automatically reducing the input device idle threshold to improve protection sensitivity; when the normal operation false operation interception rate is higher than the second preset threshold, automatically increasing the input device idle threshold to reduce interference with normal operation.

8. The method according to claim 1, characterized in that, Step S2 also includes a behavior pattern anomaly detection sub-step: when the current idle time has not reached the input device idle threshold but continuous and high-frequency atypical operation events are detected from the input device, the operation event is marked as a suspected misoperation event, and the protection sensitivity is temporarily increased, shortening the idle time judgment value that actually triggers protection.

9. A CTC system malfunction protection system based on input device idle detection, characterized in that, include: The parameter configuration module is used to preset the misoperation protection function activation flag, effective operation timestamp, input device idle threshold and idle detection strategy, and configure multiple protection deactivation strategies; The idle status monitoring module is used to monitor the operation events of the input device in real time, dynamically calculate the current idle time based on the valid operation timestamp, and compare the current idle time with the input device idle threshold. The graded protection execution module is used to activate a differentiated protection strategy that matches the idle duration level when the current idle time reaches the input device idle threshold. The differentiated protection strategy includes displaying a masking layer and blocking input events. The removal operation verification module is used to monitor and verify whether the removal operation triggered by the user complies with the protection removal policy after the protection policy is started. If the verification is successful, the protection is revoked and the operation permission is restored. The log analysis and adaptive optimization module records log data during the idle detection and protection process, analyzes erroneous operation patterns based on log data, and adaptively adjusts the idle threshold of input devices and the complexity of protection disarming strategies.

10. The system according to claim 9, characterized in that, The idle state monitoring module also includes a behavior pattern anomaly detection unit, which is used to mark the operation event as a suspected misoperation event and temporarily increase the protection sensitivity when the current idle time has not reached the input device idle threshold but the input device generates continuous and high-frequency atypical operation events. The graded protection execution module also includes a dynamic security level deactivation unit, which is used to dynamically adjust the complexity of the deactivation verification method according to the proportion of the current idle time exceeding the input device idle threshold.