Communication method and communication system for operating a rail-bound vehicle

Secure communication in track-bound vehicles is achieved by implementing cryptographic methods at the OSI security layer, addressing integrity and authenticity issues through authentication servers and MACsec, facilitating standardized and adaptable communication.

DE102022200780B4Active Publication Date: 2025-09-25SIEMENS MOBILITY GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102022200780
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-01-25
Publication Date
2025-09-25
Estimated Expiration
2042-01-25

AI Technical Summary

Technical Problem

Existing communication methods for track-bound vehicles lack robust technical means to ensure integrity, confidentiality, and authenticity of data packets, particularly in dynamic scenarios involving vehicle coupling and mixed communication protocols, relying heavily on physical safety measures and insecure protocol combinations.

Method used

Implementing secure communication at the security layer of the OSI model using cryptographic methods, with authentication servers and MACsec standard to manage keys and adapt to vehicle composition changes, ensuring encryption and authentication across network components.

Benefits of technology

Enables standardized and secure communication across coupled vehicles, maintaining integrity and confidentiality while adapting to dynamic changes, enhancing security and interoperability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Communication method for operating a track-bound vehicle (3, 103, 203) with a communication network (2, 102, 202), characterized in that securing a communication via the communication network (2, 102, 202) by means of a terminal device (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) connected to the communication network (2, 102, 202) on the data link layer of the OSI model, wherein the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) is provided with authentication information (AI) for securing the communication of the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c), wherein the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) authenticates itself (E, J) to an authentication server (45a-b, 46a-b, 47a-b, 145a-b, 245a-b) which is connected to the communication network (2, 102, 202) by data technology, wherein the track-bound vehicle (3) has a consist network (15, 16, 17) extending over one or more carriages (5, 6, 7) forming a train (8), the track-bound vehicle (3) has a train network (11) which extends over the train, wherein the authentication server (45a-b, 46a-b, 47a-b) is part of a node device (25a-b, 26a-b, 27a-b)) which forms a transition between the consist network (15, 16, 17) and the train network (11), wherein the track-bound vehicle (103) comprises a plurality of node devices (125a, 125b), each having an authentication server (145a, 145b), wherein the authentication server (145a) of a leading node device (125a) is active, another track-bound vehicle (203) comprises a plurality of node devices (225a, 225b), each having an authentication server (245a, 245b), wherein the authentication server (245a) of a leading node device (225a) is active, wherein the track-bound vehicle (103) is coupled to the further track-bound vehicle (203) (G), wherein a node device is designated as the leading node device (125a) of the coupled vehicles (103, 203) (H) and wherein the terminals (135a-c, 235a-c) authenticate themselves (J) to the authentication server (145a) of the leading node device (125a) of the coupled vehicles.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a communication method and communication system for operating a track-bound vehicle with a communication network.

[0002] German patent application DE 10 2011 002 713 A1 describes a method and a device for providing cryptographic credentials (authorization credentials) for control units of a vehicle, wherein the control units are connected to a vehicle security management unit via a vehicle bus. The control units receive the credentials from the vehicle security management unit after the vehicle security management unit is authorized to do so by an immobilizer unit of the vehicle. The cryptographic credentials can be cryptographic keys. These cryptographic keys include, in particular, dynamically generated session keys, vehicle network keys for the entire network, and cryptographic security device keys or cryptographic security device group keys.Furthermore, the cryptographic credentials can be digital certificates or so-called security assertions.

[0003] Document WO 2019 / 123447 A1 discloses a system and method for tunnel-based malware detection. The system and method comprise a network with multiple devices connected via a communication link. An analyzer server is configured to analyze messages within the network and check them for malware or malware-related activities. A tunnel device redirects messages from the first device to the analyzer server.

[0004] The analyzer server performs an analysis process. If malware-related activity is detected, the analyzer server takes action to prevent the attack. An authentication mechanism ensures that devices are authenticated before communication. WO 2019 / 123447 A1 focuses in particular on secure communication between external networks and protected networks.

[0005] Against this background, it is the object of the invention to provide an improved communication method for operating a rail-bound vehicle.

[0006] This task is solved by a communication method for operating a track-bound vehicle with a communication network, in which communication via the communication network is secured by means of a terminal device connected to the communication network on the data link layer of the OSI model.

[0007] The invention is based on the recognition that secure communication within the communication network of the rail-bound vehicle, as well as between coupled rail-bound vehicles, is desirable. This has so far been primarily ensured by physical security measures. For example, the communication network is protected from attackers by physical inaccessibility. Furthermore, communication protocols are known that incorporate authentication safeguards. However, these supposedly secure communication protocols are often executed alongside unprotected protocols on the same network.

[0008] Due to the increasing interconnectedness and interoperability between different manufacturers of rail-bound vehicles, it is desirable to enforce integrity and confidentiality within the communication network using technical means, particularly by encrypting communication and ensuring the integrity and authenticity of data packets using cryptographic methods. Challenges such as dynamics (e.g., vehicle coupling) as well as the communication types used (e.g., multicast or broadcast communication) and protocols (e.g., a mix of standardized and proprietary protocols) must be taken into account.

[0009] The invention also recognized that the security of communication in previous communication methods for operating track-bound vehicles takes place on the network layer (layer 3) or the application layer (layer 7), for example with SSL (Secure Sockets Layer).

[0010] The inventive solution solves these problems by securing communication at the link layer of the OSI model. This makes it particularly easy to standardize communication security throughout the entire vehicle, as well as within coupled vehicles. The solution also allows for clever consideration of dynamics (vehicle coupling) to ensure security throughout the entire vehicle network (even after vehicle coupling).

[0011] The track-bound vehicle is preferably a rail vehicle, for example a multiple unit.

[0012] The communications network is preferably a local area network (LAN) and more preferably an Ethernet network. Network components of the communications network include, for example, Ethernet switches. The ports of the network components form, in particular, an input for receiving data and an output for transmitting data. The terminal device is connected, for example, to one of the ports of a network component for communication.

[0013] Security preferably refers to cryptographic security. This can serve the purpose of confidentiality (e.g., through encryption), integrity, authenticity, and / or binding nature. Confidentiality preferably refers to protection against unauthorized reading of data or unauthorized acquisition of information about the data content. Integrity preferably refers to proof that the data is complete and unaltered. Authenticity (also called protection against forgery) preferably refers to the unambiguous identification of the originator of the data or the sender of the message and the verifiability of their authorship.Binding nature (also called non-repudiation) preferably means that the originator of the data or sender of a message should not be able to deny his authorship, i.e. it should be possible to prove it to third parties.

[0014] Those skilled in the art understand the term "OSI model" to refer primarily to the ISO / OSI reference model (OSI: Open Systems Interconnection). The data link layer is often referred to as the data link layer, the link layer, the connection layer, or the procedure layer, particularly in English as the data link layer. This layer is also often referred to as Layer 2, i.e., above Layer 1 (physical layer) and below Layer 3 (network layer).

[0015] Furthermore, the invention provides that authentication information is made available to the terminal device to secure the communication of the terminal device.

[0016] The authentication information serves, for example, as an output for obtaining security information to secure communication. For example, the authentication information includes a so-called trust anchor.

[0017] The authentication information is added to the device's memory, for example, during device manufacturing. Alternatively, the authentication information can be added to the device's memory after manufacture and delivery as part of the device's configuration.

[0018] Furthermore, the invention provides that the terminal authenticates itself to an authentication server which is connected to the communication network by data technology.

[0019] The use of an authentication server provides a high degree of flexibility when authenticating multiple devices. Furthermore, key management can be improved and simplified, as the authentication server provides them centrally.

[0020] The authentication server, for example, is a so-called 802.1X EAPOL server. The authentication server can also be configured as a RADIUS server (RADIUS: Remote Authentication Dial-In User Service).

[0021] Preferably, the terminal device presents the authentication information to the authentication server in order to authenticate itself. The authentication information thus forms, for example, the basis for a key negotiation and / or a key exchange and / or a key distribution by the authentication server.

[0022] Furthermore, the invention provides that the rail-bound vehicle has a consist network extending across one or more cars forming a train. Furthermore, the rail-bound vehicle has a train network extending across the train. The authentication server is part of a node device that forms a transition between the consist network and the train network.

[0023] This further development, in which the authentication server is part of the node device, has the particular advantage that changes in the composition of the rail-bound vehicle can be particularly cleverly taken into account. This is because the node device adapts its operation when the composition of the rail-bound vehicle changes. For example, address translations are carried out by the node device depending on the composition of the vehicle. Thus, by providing the authentication server as part of the node device, the advantage arises that the management of keys by the authentication server can also be cleverly adapted to the composition. This is because it is at this point (namely at the node device) that the information relevant for determining the current composition is received, for example.

[0024] The node device preferably functions as an ETB node (ETB: Ethernet Train Backbone) as defined by IEC 61375-2-5. For example, the node device forwards data packets originating from a consistent network for transmission on the train network. Conversely, the node device forwards data packets received via the train network to the consistent network. The train network, for example, is an ETB as defined by IEC 61375-2-5.

[0025] Furthermore, the invention provides that the rail-bound vehicle comprises a plurality of node devices, each having an authentication server, wherein the authentication server of a leading node device is active. Another rail-bound vehicle comprises a plurality of node devices, each having an authentication server, wherein the authentication server of a leading node device is active. The rail-bound vehicle is coupled to the other rail-bound vehicle. One node device is designated as the leading node device of the coupled vehicles. The terminal devices authenticate themselves against the authentication server of the leading node device of the coupled vehicles.

[0026] Preferably, the leading node device of the track-bound vehicle or the leading node device of the coupled track-bound vehicles is a node device located at the front of the track-bound vehicle or of the coupled track-bound vehicles in the traversing direction. However, the traversing direction does not have to coincide with the operational direction of travel.

[0027] The wording that the authentication server of the leading node device is active should preferably be understood to mean that the authentication servers of the non-leading node devices are in standby mode.

[0028] The coupling of the rail-bound vehicle with the other rail-bound vehicle preferably comprises a mechanical coupling as well as a data coupling in which the communication networks of the rail-bound vehicles are connected to one another.

[0029] Further preferably, the authentication server of the leading node device of the coupled vehicles is active, while the authentication servers of the non-leading node devices of the coupled vehicles are in standby mode.

[0030] According to a preferred embodiment of the communication method according to the invention, the security is carried out on the media access control layer using the MACsec standard.

[0031] The Media Access Control layer is often referred to as sublayer 2a of layer 2 (data link layer).

[0032] The use of the MACsec standard has the particular advantage that protocols above the data link layer are transparently encapsulated and therefore not changed.

[0033] The expert understands the MACsec standard to be the so-called “IEEE Standard for Local and metropolitan area networks - Media Access Control (MAC) Security”, which is listed under the number IEEE 802.1AE.

[0034] The invention further relates to a computer program comprising instructions which, when the program is executed by a computing device, cause the computing device to carry out the communication method of the type described above.

[0035] The invention further relates to a computer program product comprising instructions which, when the program is executed by a computing device, cause the computing device to carry out the communication method of the type described above.

[0036] The invention further relates to a provision device for the computer program or computer program product of the type described above, wherein the provision device stores and / or provides the computer program or computer program product. The provision device is, for example, a storage unit that stores and / or provides the computer program or computer program product. Alternatively and / or additionally, the provision device is, for example, a network service, a computer system, a server system, in particular a distributed, for example cloud-based, computer system and / or virtual computer system, which stores and / or provides the computer program or computer program product, preferably in the form of a data stream.

[0037] The provision takes place in the form of a program data block as a file, in particular as a download file, or as a data stream, in particular as a download data stream, of the computer program. This provision can, for example, take place as a partial download consisting of multiple parts. Such a computer program is, for example, read into a system using the provisioning device, so that the communication method according to the invention is executed on a computer. The computer is, for example, a computing device of the terminal device, the node device, and / or network component.

[0038] The invention further relates to a communication system for operating a rail-bound vehicle. The communication system comprises a communication network and a terminal device connected to the communication network. The terminal device is configured to secure communication via the communication network at the link layer of the OSI model.

[0039] The invention further relates to a rail-bound vehicle with a communication system of the type described above.

[0040] The track-bound vehicle is preferably a rail vehicle, for example a multiple unit.

[0041] For advantages, embodiments and design details of the computer program product or computer program according to the invention, the provision device according to the invention, the communication system according to the invention and the track-bound vehicle according to the invention, reference can be made to the above description of the corresponding features of the communication method according to the invention.

[0042] Embodiments of the invention are explained with reference to the drawings. They show: Fig. 1 schematically shows the sequence of an embodiment of a communication method according to the invention, Fig. 2 schematically shows the structure of an embodiment of a communication system according to the invention, Fig. 3 schematically shows the sequence of a further embodiment of a communication method according to the invention and Fig. 4 schematically shows the structure of another embodiment of a communication system according to the invention.

[0043] Fig. 1 shows a schematic flow diagram illustrating the sequence of an embodiment of the communication method according to the invention.

[0044] Fig. 2 shows a schematic representation of a communication system 1 with a communication network 2, which is shown in relation to a rail-bound vehicle 3 and is physically installed on the rail-bound vehicle 3.

[0045] The track-bound vehicle 3 is a rail vehicle 4, for example, a multiple unit train, with several carriages 5, 6, and 7. Cars 5 and 7 are end cars. Car 6 is located between end cars 5 and 7.

[0046] The communication network 2 comprises several consist networks 15, 16, 17, each of which is located in one of the cars 5, 6, and 7. The cars 5, 6, and 7 together form a train 8.

[0047] The respective consist network 15, 16, and 17 each comprises two node devices 25a, b, 26a, b, and 27a, b, respectively, which are physically and data-technically connected to each other via a train-wide train network 11. The node devices 25a, b, 26a, b, and 27a, b each have a so-called ETB node (ETB: Ethernet Train Backbone).

[0048] Several terminal devices 35a-c, 36a-c, and 37a-c are connected to the respective consist network 15, 16, and 17. In particular, the terminal devices 35a-c, 36a-c, and 37a-c are connected to network components (not shown), such as Ethernet switches. The network components are interconnected in a ring structure 13.

[0049] In a method step A, authentication information AI is made available to the respective terminal device 35a-c, 36a-c, and 37a-c. This authentication information AI is added to a memory of the terminal device 35a-c, 36a-c, or 37a-c in a method step B1 during the manufacture of the terminal device. Alternatively, the authentication information AI is added to the memory of the terminal device 35a-c, 36a-c, or 37a-c in a method step B2 after manufacture and delivery as part of the configuration of the terminal device.

[0050] The authentication information AI, for example, is a so-called trust anchor. This enables the terminal devices 35a-c, 36a-c, and 37a-c to mutually verify their authenticity in a process step C when acting as authentication clients.

[0051] In addition to their function as ETB nodes, the node devices 25a, b, 26a, b, and 27a, b each have an authentication server 45a, b, 46a, b, and 47a, b. Authentication servers 45a, b, 46a, b, and 47a, b are, for example, so-called 802.1X EAPOL servers. Furthermore, the authentication servers can be configured as RADIUS servers (RADIUS: Remote Authentication Dial-In User Service).

[0052] The node device 25a is designated as the leading node device in a method step D within the framework of a naming procedure. This leading node device 25a is a node device 25a arranged at the front in the naming direction 21. The authentication server 45a is active at this leading node device 25a, while the other authentication servers 45b, 46a, b, and 47a, b are in standby mode.

[0053] In a method step E, the terminals 35a-c to 37a-c authenticate themselves to the active authentication server 45a using the authentication information AI.

[0054] Based on authentication E, the end devices, in their role as authentication clients, receive additional security information that can be used for upcoming secure communication, for example, between two end devices. The security information is, for example, key information for encrypting the communication in a process step F.

[0055] The security of communications passing through communication network 2 is implemented at the link layer of the OSI model. Specifically, the security is implemented at the Media Access Control layer using the MACsec standard according to IEEE 802.1AE.

[0056] Securing communication involves, for example, encryption according to process step F, but also authentication according to process step E.

[0057] Fig. 3 shows a schematic representation of a communication system 101 with a communication network 102, which is shown in relation to a rail-bound vehicle 103 and is physically installed on the rail-bound vehicle 103, and with a communication network 202, which is shown in relation to a rail-bound vehicle 203 and is physically installed on the rail-bound vehicle 203.

[0058] The communication networks 102 and 202 are similar to that in Fig. 2 shown communication network 2. Identical and functionally identical components are provided with identical or analogous reference numerals.

[0059] The communication network 102 has node devices 125a and 125b and terminal devices 135a-c. The communication network 202 has node devices 225a and 225b and terminal devices 235a-c. The respective node device 125a, b or 225a, b has an authentication server 145a, b or 245a, b.

[0060] In the Fig. 3 shown further embodiment of the communication system 101 according to the invention, the Fig. 1 The method steps A to F described above are carried out analogously before coupling the vehicles 103 and 203.

[0061] After coupling the vehicles 103 and 203 in a method step G, a naming is performed in a method step H, in which the node device 125a is naming as the leading node device of the coupled vehicle 103, 203. The authentication server 145a is active in this leading node device 125a, while the other authentication servers 145b, 245a, b are in standby mode.

[0062] All terminal devices 135a-c and 235a-c can now authenticate themselves in a method step J to the active authentication server 145a using the authentication information AI.

[0063] Based on authentication J, the end devices, in their role as authentication clients, receive additional security information that can be used for upcoming secure communication, for example, between two end devices. The security information is, for example, key information for encrypting the communication in a process step K. In other words: As soon as authentication J is completed, communication between end devices (or between an end device and a server) can take place securely in a process step K. The security of the communication running over the communication network 2 occurs at the link layer of the OSI model. In particular, the security occurs at the Media Access Control layer using the MACsec standard according to IEEE 802.1AE.

[0064] Securing communication involves, for example, encryption according to process step K, but also authentication according to process step J.

[0065] Although the invention has been illustrated and described in detail by the preferred embodiment, the invention is not limited to the disclosed examples and other variations may be derived therefrom by those skilled in the art without departing from the scope of the invention.

Claims

[1] Communication method for operating a track-bound vehicle (3, 103, 203) with a communication network (2, 102, 202), characterized by , that securing a communication via the communication network (2, 102, 202) by means of a terminal device (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) connected to the communication network (2, 102, 202) on the data link layer of the OSI model, wherein the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) is provided with authentication information (AI) for securing the communication of the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c), wherein the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) authenticates itself (E, J) to an authentication server (45a-b, 46a-b, 47a-b, 145a-b, 245a-b) which is connected to the communication network (2, 102, 202) by data technology, wherein the track-bound vehicle (3) has a consist network (15, 16, 17) extending over one or more carriages (5, 6, 7) forming a train (8), the track-bound vehicle (3) has a train network (11) which extends over the train, wherein the authentication server (45a-b, 46a-b, 47a-b) is part of a node device (25a-b, 26a-b, 27a-b)) which forms a transition between the consist network (15, 16, 17) and the train network (11), wherein the track-bound vehicle (103) comprises a plurality of node devices (125a, 125b), each having an authentication server (145a, 145b), wherein the authentication server (145a) of a leading node device (125a) is active, another track-bound vehicle (203) comprises a plurality of node devices (225a, 225b), each having an authentication server (245a, 245b), wherein the authentication server (245a) of a leading node device (225a) is active, wherein the track-bound vehicle (103) is coupled to the further track-bound vehicle (203) (G), wherein a node device is designated as the leading node device (125a) of the coupled vehicles (103, 203) (H) and wherein the terminals (135a-c, 235a-c) authenticate themselves (J) to the authentication server (145a) of the leading node device (125a) of the coupled vehicles. [2] Communication method according to claim 1, characterized by that security is provided at the Media Access Control layer using the MACsec standard. [3] Computer program comprising instructions which, when executed by a computing device, cause the computing device to carry out the communication method according to at least one of the preceding claims 1 to 2. [4] A provision device for the computer program according to claim 3, wherein the provision device stores and / or provides the computer program. [5] Communication system for operating a track-bound vehicle (3, 103, 203), comprehensive - a communication network (2, 102, 202) and - a terminal device (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) connected to the communication network (2, 102, 202) for data purposes, wherein the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) is arranged to secure a communication via the communication network (2, 102, 202) on the link layer of the OSI model, wherein the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) is provided with authentication information (AI) for securing the communication of the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c), wherein the terminal (35a-c, 36a-c, 37a-c, 135a-c, 235a-c) authenticates itself (E, J) to an authentication server (45a-b, 46a-b, 47a-b, 145a-b, 245a-b) which is connected to the communication network (2, 102, 202) by data technology, wherein the track-bound vehicle (3) has a consist network (15, 16, 17) extending over one or more carriages (5, 6, 7) forming a train (8), the track-bound vehicle (3) has a train network (11) which extends over the train, wherein the authentication server (45a-b, 46a-b, 47a-b) is part of a node device (25a-b, 26a-b, 27a-b)) which forms a transition between the consist network (15, 16, 17) and the train network (11), wherein the track-bound vehicle (103) comprises a plurality of node devices (125a, 125b), each having an authentication server (145a, 145b), wherein the authentication server (145a) of a leading node device (125a) is active, another track-bound vehicle (203) comprises a plurality of node devices (225a, 225b), each having an authentication server (245a, 245b), wherein the authentication server (245a) of a leading node device (225a) is active, wherein the track-bound vehicle (103) is coupled to the further track-bound vehicle (203) (G), wherein a node device is designated as the leading node device (125a) of the coupled vehicles (103, 203) (H) and wherein the terminals (135a-c, 235a-c) authenticate themselves (J) to the authentication server (145a) of the leading node device (125a) of the coupled vehicles. [6] Rail-bound vehicle (3, 103, 203) with a communication system (1) according to claim 5.

Citation Information

Patent Citations

  • System and method for tunnel-based malware detection

    WO2019123447A1