Railway security system, security management system, and update control method
The railway security system addresses the challenge of unreliable wireless updates by implementing check code verification and data division techniques to ensure secure and reliable software updates, enhancing data integrity and reducing processing loads.
Patent Information
- Application Number
- JP2021161033
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-30
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-09-30
AI Technical Summary
Existing remote software update methods for railway security devices via general-purpose wireless communication face challenges in ensuring high reliability and security due to lower communication reliability and security compared to wired methods, necessitating measures to enhance data integrity and accuracy.
A railway security system employing a central control device, management device, and security devices that utilize check code verification and data division techniques to ensure reliable and secure wireless software updates, including transmission-side and reception-side check code calculations and collation to validate data integrity before updating.
Ensures high reliability and security in wireless software updates by validating data integrity through check code matching, reducing processing load on the central control device, and allowing parallel security control operations.
Smart Images

Figure 0007708633000001 
Figure 0007708633000002 
Figure 0007708633000003
Abstract
Description
Technical Field
[0001] The present invention relates to a railway security system and the like.
Background Art
[0002] Software (programs, data, etc.) stored in a security device, which is a component of a railway security system, may need to be updated, and no errors are allowed in the update. Therefore, as the main conventional update method, a method of directly connecting a PC (personal computer) storing update software to the security device to be updated with a cable, or a method of performing an update by attaching a storage medium such as a ROM (Read Only Memory) or a CF (Compact Flash) card storing update software to the security device to be updated has been adopted. In any method, it is necessary to go to the site where the security device to be updated is located, and the software update work for a large number of security devices is a laborious task.
[0003] Therefore, in recent years, a method of remotely updating software via a network without going to the site has been studied. For example, Patent Document 1 discloses a remote loading technology in which a loading instruction device storing update software and a plurality of loading target devices (corresponding to security devices) to be updated are connected on the same communication path, and the update software is transmitted from the loading instruction device to the loading target devices.
[0004] A method of remotely updating software using a dedicated network is highly secure, but there is a problem that it is necessary to construct a dedicated network and the equipment cost and maintenance cost are high. Therefore, for example, when the technology of Patent Document 2 is realized using general-purpose wireless, it is possible to reduce the equipment cost and maintenance cost of the network.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0006] However, communication via general-purpose wireless has a problem that the reliability and security of communication are lower than those of wired communication, and it is necessary to ensure the reliability and security of communication. That is, it is necessary to cope with data errors due to the superimposition of noise on the communication path.
[0007] The present invention has been made in view of the above circumstances, and an object thereof is to achieve high reliability and security when a security device receives and updates update software via wireless.
Means for Solving the Problems
[0008] A first invention for solving the above problems is a security device that performs a predetermined control operation based on stored software, a central control device that performs a predetermined security control related to train operation by communicating with the security device via wireless, a management device that can communicate with the security device via wireless and is communicatively connected to the central control device, a railway security system comprising: wherein the management device has update software transmission means (for example, the DB transmission unit 802 in FIG. 7) for transmitting update software to the security device, and transmission-side code transmission means (for example, the transmission-side code transmission unit 804 in FIG. 7) for transmitting a transmission-side check code for the update software calculated according to a predetermined calculation method for calculating a check code for given data to the central control device, and is provided with wherein the security device Update software receiving means (e.g., the DB receiving unit 502 in FIG. 6) for receiving the update software from the management device, Receiving-side code transmitting means (e.g., the receiving-side code transmitting unit 504 in FIG. 6) for calculating a receiving-side check code for the received update software according to the calculation method and transmitting it to the central control device, Update means (e.g., the update unit 506 in FIG. 6) for updating the software using the received update software when an update instruction is received from the central control device, Comprising, The central control device, Update instruction means (e.g., the update instruction unit 202 in FIG. 4) for transmitting the update instruction to the security device when the transmitted-side check code received from the management device matches the received-side check code received from the security device, Comprising, It is a railway security system.
[0009] As another invention, The security management system in a railway security system comprising a security device that performs a predetermined control operation based on stored software and a security management system, A central control device that performs predetermined security control related to train operation by communicating with the security device via wireless, A management device that can communicate with the security device via wireless and is communicatively connected to the central control device, Comprising, When the security device receives given update software, it calculates a receiving-side check code for the update software according to a predetermined calculation method for calculating a check code for given data and transmits it to the central control device. When it receives an update instruction from the central control device, it has a function of updating the software using the received update software, The management device, Update software transmitting means for transmitting the update software to the security device, Transmission-side code transmission means for transmitting the transmission-side check code for the update software calculated according to the calculation method to the central control device; having, The central control device, update instruction means for transmitting the update instruction to the security device when the transmission-side check code received from the management device matches the reception-side check code received from the security device; having, may constitute a security management system.
[0010] As yet another invention, A security device that performs a predetermined control operation based on stored software, a central control device that performs a predetermined security control related to train operation by communicating with the security device via wireless, and a management device that can communicate with the security device via wireless and is communicatively connected to the central control device. In the software update control method in a railway security system comprising: An update software transmission step (for example, step S9 in FIG. 3) in which the management device transmits update software to the security device; A transmission-side code transmission step (for example, step S5 in FIG. 3) in which the management device transmits the transmission-side check code for the update software calculated according to a predetermined calculation method for calculating a check code for given data to the central control device; An update software reception step (for example, steps S11 to S17 in FIG. 3) in which the security device receives the update software from the management device; A reception-side code transmission step (for example, steps S19 to S21 in FIG. 3) in which the security device calculates a reception-side check code for the received update software according to the calculation method and transmits it to the central control device; An update step (for example, step S31 in FIG. 3) in which the security device updates the software using the received update software when an update instruction is received from the central control device; An update instruction step in which the central control device transmits the update instruction to the security device when the transmission - side check code received from the management device matches the reception - side check code received from the security device (for example, steps S23 - S29 in FIG. 3). An update control method including this may be configured.
[0011] According to the first invention etc., high reliability and security can be achieved when a security device receives and updates update software via wireless. That is, the management device transmits the update software to the security device and also transmits a transmission - side check code for the update software to the central control device. The security device calculates a reception - side check code for the received update software by the same calculation method as the transmission - side check code in the management device and transmits the calculated reception - side check code to the central control device. Then, the central control device collates the transmission - side check code and the reception - side check code, and when they match, transmits an update instruction for the software to the security device.
[0012] If the update software is received correctly in the security device, the transmission - side check code and the reception - side check code match. Also, since the central control device is communicatively connected to the management device, it can be said that the reliability and security of the transmission - side check code received by the central control device from the management device are high. Further, the central control device that performs security control is a fail - safe device, and the collation of the check code performed by the central control device which is a fail - safe device can be said to have high reliability and security. And when the check codes do not match by the collation, no update instruction is transmitted, so the software is not updated in the security device. Thereby, high reliability and security can be ensured when the security device receives and updates the update software via wireless.
[0013] In addition, the management device transmits the update software that imposes a heavy processing load. The central control device performs the collation of the check code with a lighter processing load as compared with the process related to the transmission of the update software. Thereby, the processing load of the central control device that performs the security control can be reduced.
[0014] A second invention is as follows in the first invention. The security device includes a target security device that is a target for updating the software stored in the security device, and a non-target security device that is not a target. The central control device notification means (for example, the notification unit 204 in FIG. 4) that notifies each of the management device and the target security device of an update start instruction including the designation of the target security device, further includes The update software transmission means transmits the update software to the target security device based on the update start instruction, The update software reception means receives the update software from the management device based on the update start instruction, The update instruction means transmits the update instruction to the target security device when the transmission-side check code received from the management device matches the reception-side check code received from the target security device. It is a railway security system.
[0015] According to the second invention, prior to the transmission of the update software, the central control device notifies each of the management device and the target security device of an update start instruction including the designation of the target security device. Thereby, only the target security device can update the software. Further, even when the update software is erroneously transmitted to a non-target security device, it is possible to avoid the software from being updated in the non-target security device.
[0016] A third invention is as follows in the first or second invention. The security device is an on-vehicle device mounted on a train or a level crossing control device. It is a railway security system.
[0017] According to the third invention, it is possible to ensure high reliability and safety when transmitting and updating update software wirelessly to an on-vehicle device or a level crossing control device mounted on a train.
[0018] The fourth invention is the same as the second invention, During the update of the software in the target safety device, the central control device executes the predetermined safety control based on communication with the non-target safety device that is not the update target of the software. It is a railway safety system.
[0019] According to the fourth invention, it is possible to execute safety control based on communication with a non-target safety device that is not the update target of the software and to transmit and update the update software to the target safety device in parallel.
[0020] The fifth invention is the same as any one of the first to fourth inventions, The update software transmission means adds additional information including the serial number of the division to each of a plurality of divided data obtained by dividing the update software into a predetermined data size and transmits the data. The update software reception means determines the reception success or failure for each of the divided data based on the additional information of the divided data. When it is determined by the update software reception means that the reception of all the divided data has been successful, the reception-side code transmission means calculates and transmits the reception-side check code. It is a railway safety system.
[0021] In wireless communication, since data is divided into predetermined data sizes, such as packets, and transmitted, on the receiving side, it is necessary to combine and reconstruct the divided data. For this reason, as in the fifth invention, the management device adds additional information including the serial number of the division to the divided data obtained by dividing the update software and transmits it. Then, based on the additional information added to the received divided data, the security device can determine missing divided data, reversal of the reception order, etc., and can reliably reconstruct the original update software. Thereby, it is possible to ensure high reliability and security when the security device receives and updates the update software via wireless communication.
Brief Description of the Drawings
[0022]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Embodiments for Carrying Out the Invention
[0023] Hereinafter, preferred embodiments of the present invention will be described with reference to the drawings. Note that the form to which the present invention is applicable is not limited to the following embodiments. Also, in the description of the drawings, the same reference numerals are given to the same elements.
[0024] [System Configuration] Figure 1 is a diagram showing a configuration example of the railway security system 1 of the present embodiment. As shown in Figure 1, the railway security system 1 of the present embodiment includes a central control device 3, a plurality of security devices 5, and a management device 7. The central control device 3 and the management device 7 are installed in a command post, an equipment room, etc., and are communicatively connected by a dedicated line such as an optical cable to constitute a security management system 10. Further, the central control device 3 and the management device 7 are also connected to the base station device 9 by a dedicated line, and can communicate with the security device 5 via the mobile wireless communication network N connected to the base station device 9. That is, communication is possible wirelessly between the central control device 3 and the management device 7 and the security device 5. The mobile wireless communication network N is a general-purpose wireless communication network operated by a communication carrier.
[0025] The central control device 3 is a fail-safe device, and performs predetermined security control related to train operation by communicating with the security device 5 via wireless using the mobile wireless communication network N. Examples of the security control include train control such as acquiring the train position from the on-vehicle device 5a by communicating wirelessly with the on-vehicle device 5a and the level crossing control device 5b which are the security devices 5, and transmitting train control information for performing speed control of each train to the on-vehicle device 5a based on the acquired train positions, and level crossing control such as transmitting level crossing control information for controlling level crossing facilities (level crossing warning devices, switches, etc.) to the level crossing control device 5b.
[0026] The security device 5 is a fail-safe device used for security control at the site, and is, for example, an on-vehicle device 5a mounted on a train, a level crossing control device 5b installed near a level crossing for controlling level crossing facilities, etc. In the railway security system 1, one or more on-vehicle devices 5a and level crossing control devices 5b are arranged respectively. Further, the security device 5 stores a database 602 related to security control. The database 602 is an example of software (programs and data), and has contents corresponding to the types and uses of the security devices 5 to be stored.
[0027] The management device 7 is a device for updating the database 602 stored in the security device 5. The management device 7 stores update databases 912 for each of the plurality of security devices 5, and in accordance with the control of the central control device 3, transmits the update database 912 corresponding to the designated security device 5 to the security device 5.
[0028] In the present embodiment, the central control device 3 performs security control by communicating wirelessly with each of a plurality of security devices 5 (hereinafter referred to as "non-target security devices") that are not targets for updating the database 602, and in parallel, for the security devices 5 (hereinafter referred to as "target security devices") that are targets for updating the database 602, controls the transmission of the update database 912 and the update of the database 602. In other words, during the update of the database 602 in the security device 5 (target security device) that is the update target of the database 602, security control can be performed based on communication with other security devices 5 (non-target security devices) that are not the update targets of the database 602. For example, if the target security device is the on-vehicle device 5a, when the work of the vehicle equipped with the on-vehicle device 5a is completed and the vehicle is placed in a garage or the like, the update database 912 is transmitted and the database 602 is updated. At this time, since security control for vehicles and level crossing control devices other than the vehicle can be continued, security control related to normal train operation can be performed. Also, if the target security device is the level crossing control device 5b, the update database 912 is transmitted and the database 602 is updated at night after the operation ends.
[0029] [Transmission Procedure] Figures 2 and 3 are diagrams for explaining the transmission procedure of the update database 912 to the security device 5. Figure 2 is a diagram focusing on the instructions and data transmitted and received between devices, and Figure 3 is a diagram focusing on the processing flow of each device.
[0030] First, the management device 7 receives an update operation instruction to specify a security device 5 (target security device 5X) to be updated in the database 602 from among a plurality of security devices 5 (step S1). Then, the management device 7 notifies the central control device 3 of the acceptance of the update of the database 602 specifying the target security device 5X (step S3). Further, the management device 7 transmits a check code (hereinafter referred to as the "transmission-side check code") for the update database 912 corresponding to the target security device 5X (step S5). This transmission-side check code for the update database 912 is calculated in advance by a predetermined calculation method and stored in the management device 7 in association with the update database 912.
[0031] Then, the central control device 3 notifies each of the management device 7 and the target security device 5X of an update start instruction including the specification of the target security device 5X (step S7). By this notification of the update start instruction, the target security device 5X recognizes that it is the target for updating the database 602 and receives the update database 912 transmitted from the management device 7. That is, the security device 5 receives the update database 912 only when the notification of the update start instruction designating the device itself as the target security device 5X is given. Since the non-target security device 5Y is not notified of the update start instruction designating the device itself, it does not receive the update database 912. For this reason, the update of the database 602 by the non-target security device 5Y is avoided.
[0032] Then, the management device 7 transmits the update database 912 to the target security device 5X (step S9). Since the transmission of the update database 912 is performed wirelessly via the mobile wireless communication network N, it is divided by a communication device that controls communication via the mobile wireless communication network N and transmitted as packets. To avoid the division of the update database 912 by this communication device, the management device 7 previously divides the update database 912 into a data size that can fit into one packet even with additional information added, and sequentially transmits the transmission data with additional information added to the divided data (hereinafter referred to as "divided data"). The additional information is information including the sequence number and total number of divisions. The transmission data is transmitted to the target security device 5X as one packet with error detection codes such as encryption and CRC (Cyclic Redundancy Check) added.
[0033] The target security device 5X sequentially receives the packets sequentially transmitted from the management device 7. The received packets are first determined whether they are normally received by performing error detection by a communication device that controls communication via the mobile wireless communication network N using error detection codes such as decryption and CRC. If the packet is normally received, the target security device 5X further determines the reception success or failure of the divided data based on the additional information added to the received divided data (step S11). Specifically, if it is received within a certain time from the reception of the immediately preceding divided data and is the sequence number following the immediately preceding received divided data, it is determined as reception success, otherwise it is determined as reception failure. Then, the target security device 5X transmits a reception response including the reception success or failure of the divided data and a retransmission request for the corresponding divided data in case of reception failure to the management device 7 (step S13).
[0034] When the target security device 5X successfully receives all the divided data (step S15: YES), it combines the divided data in the order according to the serial number and reconstructs the update database 604 (step S17). Subsequently, the target security device 5X calculates the check code of the received update database 604 (hereinafter referred to as the "received-side check code") (step S19), and transmits the calculated received-side check code to the central control device 3 (step S21). Here, the received-side check code calculated by the target security device 5X is calculated by the same calculation method as the transmitted-side check code for the update database 912 stored in the management device 7. The calculation method of the check code is arbitrary. For example, any error detection code such as a checksum or CRC can be used.
[0035] The central control device 3 collates the transmitted-side check code received from the management device 7 with the received-side check code received from the target security device 5X (step S23). If they match (step S25: YES), it transmits an update instruction for the database 602 to the target security device 5X (step S29). If the check codes do not match (step S25: NO), it notifies the management device 7 that the transmission of the update database 912 has failed (transmission error) (step S27).
[0036] When the target security device 5X receives the update instruction from the central control device 3, it updates the stored database 602 using the received update database 604 (step S31). When the update of the database 602 is completed, it notifies the central control device 3 of the update completion (step S33). Thereafter, the central control device 3 notifies the management device 7 of the update completion of the database 602 of the target security device 5X (step S35). The update of the database 602 in the security device 5 is performed as described above.
[0037] [Functional Configuration] (A) Central Control Device FIG. 4 is a diagram showing the functional configuration of the central control device 3 and shows the functional units according to the present embodiment. According to FIG. 4, the central control device 3 includes an operation unit 102, a display unit 104, a communication unit 106, a processing unit 200, and a storage unit 300, and is configured by a fail-safe computer system.
[0038] The operation unit 102 is realized by an input device such as a button switch, a touch panel, a keyboard, etc., and outputs an operation signal corresponding to the performed operation to the processing unit 200. The display unit 104 is realized by a display device such as an LCD (Liquid Crystal Display) or a touch panel, and performs various displays according to the display signal from the processing unit 200. The communication unit 106 is realized by a wired or wireless communication device, and communicates with external devices such as the management device 7 and the base station device 9 via a dedicated line.
[0039] The processing unit 200 is realized by an arithmetic device such as a CPU (Central Processing Unit), etc., and based on programs, data, etc. stored in the storage unit 300, gives instructions and transfers data to each part constituting the central control device 3, and performs overall control of the central control device 3. Further, the processing unit 200 has an update instruction unit 202 and a notification unit 204 as functional units according to the present embodiment. However, these functional units can also be configured as independent arithmetic circuits by an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), etc.
[0040] When the transmission-side check code received from the management device 7 matches the reception-side check code received from the target security device 5X, the update instruction unit 202 transmits an update instruction to the target security device 5X (steps S23 to S29 in FIG. 3).
[0041] The notification unit 204 notifies the management device 7 and each of the target security devices 5X of the update start instruction including the designation of the target security device 5X (step S7 in FIG. 3). For example, it is assumed that the management device 7 accepts an update operation designating the target security device 5X, and in accordance with the notification indicating that this update operation from the management device 7 has been accepted, the update start notification can be notified.
[0042] The storage unit 300 is implemented by a storage device such as a hard disk, ROM (Read Only Memory), or RAM (Random Access Memory), and stores programs, data, etc. for the processing unit 200 to integrally control the central control device 3. Further, the storage unit 300 is used as a work area for the processing unit 200, and temporarily stores calculation results executed by the processing unit 200 according to various programs, input data via the operation unit 102 or the communication unit 106, etc. In the present embodiment, DB update management information 310 is stored in the storage unit 300.
[0043] FIG. 5 is a diagram showing an example of the DB update management information 310. The DB update management information 310 is information for managing the update of the database 602 in the security device 5, and is generated for each update. One piece of DB update management information 310 stores, in association with the security device ID of the target security device 5X, the update date and time, the transmission-side check code received from the management device 7, the reception-side check code received from the target security device 5X, and the collation result of the transmission-side check code and the reception-side check code made by the update instruction unit 202.
[0044] (B) Security device FIG. 6 is a diagram showing the functional configuration of the security device 5, and shows the functional units according to the present embodiment. According to FIG. 6, the security device 5 includes an operation unit 402, a display unit 404, a wireless communication unit 406, a processing unit 500, and a storage unit 600, and is configured by a computer system having fail-safe property.
[0045] The operation unit 402 is implemented by an input device such as a button switch, a touch panel, a keyboard, etc., and outputs an operation signal corresponding to the performed operation to the processing unit 500. The display unit 404 is implemented by a display device such as an LCD (Liquid Crystal Display) or a touch panel, and performs various displays according to the display signal from the processing unit 500. The wireless communication unit 406 is implemented by a wireless communication device, connects to the mobile wireless communication network N, and communicates wirelessly with external devices such as the central control device 3 and the management device 7.
[0046] The processing unit 500 is implemented by an arithmetic device such as a CPU (Central Processing Unit), etc., and based on programs, data, etc. stored in the storage unit 600, gives instructions and transfers data to each part constituting the security device 5, and performs overall control of the security device 5. Further, the processing unit 500 has, as functional units according to this embodiment, a DB reception unit 502, a reception-side code transmission unit 504, and an update unit 506. However, these functional units can also be configured as independent arithmetic circuits by an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), etc.
[0047] The DB reception unit 502 receives the update database 912 from the management device 7 based on the update start instruction from the central control device 3. Since the update database 912 is sequentially transmitted in units of divided data obtained by dividing the update database 912, for each received divided data, the reception success or failure is determined based on the additional information of the divided data, and the determination result is transmitted to the management device 7 as a reception response. The reception success or failure of the divided data is determined as reception success if it is received within a certain time from the reception of the immediately preceding divided data and the sequence number following the immediately preceding received divided data, and as reception failure otherwise. Then, when the reception of all the divided data is successful, the divided data is combined based on the additional information of the divided data, and the received update database 604 is reconstructed (steps S11 to S17 in FIG. 3).
[0048] When it is determined by the DB reception unit 502 that the reception of all the divided data is successful, the reception-side code transmission unit 504 calculates a reception-side check code for the reception update database 604 according to a predetermined calculation method and transmits it to the central control device 3 (steps S19 to S21 in FIG. 3). The calculation method of the reception-side check code is the same as the calculation method of the transmission-side check code for the update database 912 stored in the management device 7.
[0049] When the update unit 506 receives an update instruction from the central control device 3, it updates the stored database 602 using the received update database 604 (step S31 in FIG. 3).
[0050] The storage unit 600 is realized by a storage device such as a hard disk, ROM (Read Only Memory), or RAM (Random Access Memory), and stores programs, data, etc. for the processing unit 500 to integrally control the security device 5. Further, the storage unit 600 is used as a work area of the processing unit 500, and temporarily stores calculation results obtained by the processing unit 500 executing according to various programs, input data via the operation unit 402 or the wireless communication unit 406, etc. In the present embodiment, the storage unit 600 stores the database 602, the update database 604 received from the management device 7, and the reception-side check code 606 for the update database 604 calculated by the reception-side code transmission unit 504.
[0051] (C) Management device FIG. 7 is a diagram showing the functional configuration of the management device 7, and shows the functional units according to the present embodiment. According to FIG. 7, the management device 7 includes an operation unit 702, a display unit 704, a communication unit 706, a processing unit 800, and a storage unit 900, and can be configured as a kind of computer system.
[0052] The operation unit 702 is implemented by an input device such as a button switch, a touch panel, a keyboard, etc., and outputs an operation signal corresponding to the performed operation to the processing unit 800. The display unit 704 is implemented by a display device such as an LCD (Liquid Crystal Display) or a touch panel, and performs various displays according to the display signal from the processing unit 800. The communication unit 706 is implemented by a wired or wireless communication device, and communicates with external devices such as the central control device 3 and the base station device 9 via a dedicated line.
[0053] The processing unit 800 is implemented by an arithmetic device such as a CPU (Central Processing Unit), and based on programs, data, etc. stored in the storage unit 900, issues instructions and transfers data to each part constituting the management device 7, and performs overall control of the management device 7. Further, the processing unit 800 has a DB transmission unit 802 and a transmission-side code transmission unit 804 as functional units according to this embodiment. However, these functional units can also be configured as independent arithmetic circuits by an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), etc.
[0054] The DB transmission unit 802 transmits the update database 912 to the target security device 5X based on the update start instruction from the central control device 3. The transmission of the update database 912 is performed by adding additional information including the serial number of the division to each of a plurality of divided data obtained by dividing the update database 912 into a predetermined data size and then transmitting the data. Specifically, the transmission data 913 that has been generated and prepared in advance in the corresponding update DB management information 910 is sequentially transmitted (step S9 in FIG. 3).
[0055] The transmission-side code transmission unit 804 transmits the transmission-side check code for the update database 912 calculated according to a predetermined calculation method for calculating the check code for given data to the central control device 3. Specifically, it transmits the transmission-side check code 914 that has been calculated and prepared in advance in the corresponding update DB management information 910 (step S5 in FIG. 3).
[0056] The storage unit 900 is realized by a storage device such as a hard disk, ROM (Read Only Memory), or RAM (Random Access Memory), and stores programs, data, etc. for the processing unit 800 to integrally control the management device 7. Further, the storage unit 900 is used as a work area for the processing unit 800, and temporarily stores calculation results obtained by the processing unit 800 executing according to various programs, input data via the operation unit 702 and the communication unit 706, etc. In this embodiment, the update DB management information 910 is stored in the storage unit 900.
[0057] FIG. 8 is a diagram showing an example of the update DB management information 910. The update DB management information 910 is information for managing the update database 912 to be transmitted to the security device 5, and is prepared for each security device 5. One piece of update DB management information 910 stores the update database 912, the transmission data 913, and the transmission-side check code 914 in association with the security device ID 911 of the corresponding security device 5. The transmission data 913 is data for dividing and transmitting the update database 912, and is prepared for each of a plurality of divided data obtained by dividing the update database 912 into a predetermined data size. One piece of transmission data 913 includes the corresponding divided data, and the division number and the total number of divisions of the divided data, which are additional information. The transmission-side check code 914 is a check code calculated for the update database 912 by a predetermined calculation method.
[0058] [Operation and Effect] According to this embodiment, high reliability and security can be achieved when the security device 5 receives the update database 912 via wireless communication and updates the database 602. That is, the management device 7 transmits the update database 912 to the target security device 5X, which is the security device 5 to be updated in the database 602, and transmits the transmission-side check code for the update database 912 to the central control device 3. The target security device 5X calculates the reception-side check code for the received update database 912 using the same calculation method as the transmission-side check code in the management device 7, and transmits the calculated reception-side check code to the central control device 3. Then, the central control device 3 collates the transmission-side check code and the reception-side check code, and when they match, transmits an update instruction for the database 602 to the target security device 5X.
[0059] If the update database 912 is received without error in the target security device 5X, the transmission-side check code and the reception-side check code will match. Also, since the central control device 3 is communicatively connected to the management device 7 via a dedicated line, it can be said that the reliability and security of the transmission-side check code received by the central control device 3 from the management device 7 are high. Further, the central control device 3 that performs security control is a fail-safe device, and the collation of the check code performed by the central control device 3, which is a fail-safe device, can be said to have high reliability and security. And when the check codes do not match due to the collation, no update instruction is transmitted, so the software in the target security device 5X is not updated. Thereby, high reliability and security can be ensured when the target security device 5X receives and updates the update database 912 via wireless communication.
[0060] In addition, the management device 7 transmits the update database 912 with a heavy processing load, and the central control device 3 performs collation of check codes with a lighter processing load compared to the processing related to the transmission of the update database 912. Thereby, the processing load on the central control device 3 that performs security control can be reduced. And since the processing load on the central control device 3 is light, the central control device 3 can execute security control based on communication with the non-target security device 5Y that is not the update target of the database 602 and transmit the update database 912 to the target security device 5X and update the database 602 in parallel.
[0061] Note that the applicable embodiments of the present invention are not limited to the above-described embodiments, and it goes without saying that they can be appropriately changed without departing from the spirit of the present invention.
[0062] For example, in the above-described embodiment, an example in which software is used as a database has been described, but other software such as a program (for example, a predetermined program of the security device 5) instead of a database may be used.
Explanation of Reference Numerals
[0063] 1... Railway security system 3... Central control device 200... Processing unit 202... Update instruction unit 204... Notification unit 300... Storage unit 310... DB update management information 5... Security device 500... Processing unit 502... DB reception unit 504... Reception-side code transmission unit 506... Update unit 600... Storage unit 602... Database 604... Update database 606... Reception-side check code 7... Management device 800... Processing unit 802... DB transmission unit 804... Transmission-side code transmission unit 900… Memory section 910… Update DB management information 912… Update database 9… Base station device N… Mobile radio communication network
Claims
1. A security device that performs a predetermined control operation based on stored software, A central control device that performs a predetermined security control related to train operation by communicating with the security device via wireless, A management device that can communicate with the security device via wireless and is communicatively connected to the central control device, A railway security system comprising: The management device: Update software transmission means for transmitting update software to the security device, Transmission-side code transmission means for transmitting a transmission-side check code for the update software calculated according to a predetermined calculation method for calculating a check code for given data to the central control device, Comprising: The security device: Update software reception means for receiving the update software from the management device, Reception-side code transmission means for calculating a reception-side check code for the received update software according to the calculation method and transmitting it to the central control device, Update means for updating the software using the received update software when an update instruction is received from the central control device, Comprising: The central control device: Update instruction means for transmitting the update instruction to the security device when the transmission-side check code received from the management device and the reception-side check code received from the security device match, Comprising: A railway security system.
2. In the security device, there are a target security device that is a target for updating the software stored in the security device and a non-target security device that is not a target, The central control device: Notification means for notifying each of the management device and the target security device of an update start instruction including designation of the target security device, Further comprising: The update software transmission means transmits the update software to the target security device based on the update start instruction, The update software reception means receives the update software from the management device based on the update start instruction, The update instruction means transmits the update instruction to the target security device when the transmission-side check code received from the management device and the reception-side check code received from the target security device match, The railway security system according to Claim 1.
3. The security device is an on-vehicle device mounted on a train or a level crossing control device. The railway security system according to claim 1 or 2.
4. During the update of the software in the target security device, the central control device executes the predetermined security control based on communication with the non-target security devices that are not the software update targets. The railway security system according to claim 2.
5. The software update transmission means adds additional information including the serial number of the split to each of a plurality of split data obtained by splitting the software update into a predetermined data size and transmits the data. The software update reception means determines the success or failure of reception for each of the split data based on the additional information of the split data. When it is determined that all of the split data have been successfully received by the software update reception means, the reception-side code transmission means calculates and transmits the reception-side check code. The railway security system according to any one of claims 1 to 4.
6. The security management system in a railway security system including a security device that performs a predetermined control operation based on stored software and a security management system, A central control device that performs predetermined security control related to train operation by communicating with the security device via radio, A management device that can communicate with the security device via radio and is communicatively connected to the central control device, Comprising, When the security device receives given software for update, it calculates a reception-side check code for the software for update according to a predetermined calculation method for calculating a check code for given data and transmits it to the central control device. When it receives an update instruction from the central control device, it has a function of updating the software using the received software for update. The management device, Software update transmission means for transmitting the software for update to the security device, Transmission-side code transmission means for transmitting a transmission-side check code for the software for update calculated according to the calculation method to the central control device, Having, The central control device, Update instruction means for transmitting the update instruction to the security device when the transmission-side check code received from the management device and the reception-side check code received from the security device match, Having, Security management system.
7. A security device that performs a predetermined control operation based on stored software, a central control device that performs a predetermined security control related to train operation by communicating with the security device via wireless, and a management device that can communicate with the security device via wireless and is communicatively connected to the central control device. A method for updating control of the software in a railway security system, comprising: An update software transmission step in which the management device transmits update software to the security device; A transmission-side code transmission step in which the management device transmits a transmission-side check code for the update software calculated according to a predetermined calculation method for calculating a check code for given data to the central control device; An update software reception step in which the security device receives the update software from the management device; A reception-side code transmission step in which the security device calculates a reception-side check code for the received update software according to the calculation method and transmits it to the central control device; An update step in which the security device updates the software using the received update software when an update instruction is received from the central control device; An update instruction step in which the central control device transmits the update instruction to the security device when the transmission-side check code received from the management device matches the reception-side check code received from the security device; An update control method including the above steps.
Citation Information
Patent Citations
Mobile object information management system
JP1997187072A
Update information management system, program and method
JP2007272750A
Train control system
JP2009234527A
Wireless data-updating method for database of on-vehicle device
JP2015196422A
Railroad security system
JP2018036975A