Apparatus and method for controlling a critical system

The described method iteratively encrypts and verifies control messages using multiple private keys to ensure secure and reliable communication in railway systems, addressing the limitations of fault-tolerant architectures and enabling the use of COTS components for enhanced system availability and security.

JP7826588B2Active Publication Date: 2026-03-10HITACHI RAIL STS SPA
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-01
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing railway control systems face challenges in ensuring secure and reliable communication of critical messages due to the complexity of fault-tolerant architectures, which can lead to malfunctions and reduced system performance, and the limitations of using Commercial Off-the-Shelf (COTS) components in ensuring message integrity and redundancy.

Method used

An apparatus and method for iteratively encrypting control messages using at least two private keys, verifying the decrypted messages, and ensuring redundancy through multiple devices, allowing the use of COTS components and distributed virtualization technologies to enhance system availability and security.

Benefits of technology

This approach ensures secure and reliable message transmission by validating messages through multiple devices, reducing the risk of malfunctions and enhancing system availability, while enabling the use of COTS components suitable for distributed virtualization, thus improving control services in railway and other critical systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007826588000008
    Figure 0007826588000008
  • Figure 0007826588000009
    Figure 0007826588000009
  • Figure 0007826588000010
    Figure 0007826588000010
Patent Text Reader

Abstract

The present invention relates to an apparatus (1 a) and a method for controlling a critical system (S), as well as a device (3 a, 3 b) and a method for distribution of messages for controlling the critical system (S), wherein the apparatus (1 a) is configured to encrypt a first control message by using a first private key, send the first encrypted message to a second device (1 b), receive a second encrypted message generated by the second device (1 b) and encrypted by the second device (1 b) by using the second private key, decrypt the second encrypted message by using a public key associated with the second private key, verify the second decrypted message based on the first message, and if the verification is successful, encrypt at least the second encrypted message using the first private key, thereby generating a third encrypted message, and send the third encrypted message.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an apparatus and method for controlling a critical system and to a device and method for the distribution of messages for controlling said critical systems; in particular for controlling railway systems.

[0002] As is known, the development of railway networks that has taken place in the past decades has led to an increasing level of automation, particularly with regard to network and traffic control and monitoring. However, this increasing level of automation has also given rise to higher requirements in terms of the communication bandwidth needed to operate the control and monitoring equipment, and also with regard to the time intervals during which such equipment must remain available.

[0003] As specified by CENELEC EN50159 and subsequent standards, such equipment must operate at a Safety Integrity Level (SIL) of 4. One way to ensure compliance with such requirements is to use safety processing systems (Safe Calculators) that perform the tasks of collecting, processing, and communicating critical information and / or commands (necessary for the safe operation of the controlled railway network) in the form of time-varying communications protected by digital signatures. Such equipment is very often designed using a redundant architecture (2oo2), i.e., by using a pair of devices (also known as "replicas"), where each device must process information and jointly authenticate the transmission of valid critical messages. In this context, it is necessary to guarantee the security of such communications, i.e., to design the system so that it is not possible to transmit valid critical messages unless the replicas agree, which can be potentially dangerous. This task is usually delegated to a third device, an intrinsically safe circuit commonly referred to as a "watchdog," which performs the function of enabling or safely interrupting outbound communications. This device therefore allows disabling both units if any discrepancy between the replicas is detected; indeed, such a discrepancy is typically a symptom of a malfunction. In the railway field, disabling such units makes it possible to return the controlled transportation system (e.g., trains, points, signals, etc.) to a safe state, which is typically defined in the design phase, such as when signals are either off or red, train traffic is prohibited, points are set to avoid collisions between moving trains, etc.

[0004] The presence of this circuit often limits the performance of the system and increases the probability of a malfunction that will stop it from cycling, since the system is made up of many components that make it quite complex.

[0005] This problem is solved by Italian Patent Application No. 102016000116085 by HITACHI RAIL STS SpA, however, here the task of verifying the integrity of the messages is left to their recipient, thus limiting the possibility to use components that are already available on the market (known as "COTS components" - Commercial Off-the-Shelf Components) or even already installed along an operational railway network.

[0006] German Patent Application No. DE 10 2016 204 630 A1 describes a system that can enable the transmission of messages between railway system devices without requiring the provision of specific keys for such devices, e.g. in the form of authentication keys.

[0007] The present invention aims to solve these and other problems by providing an apparatus and method for generating messages for controlling a railway network according to the present invention.

[0008] The present invention aims to solve these and other problems by providing an apparatus and method for controlling critical systems.

[0009] Moreover, the present invention aims to solve these and other problems by also providing a device for the distribution of messages for controlling critical systems.

[0010] The basic idea of ​​the present invention is to iteratively encrypt control messages using at least two private keys, i.e., by configuring each device of at least one pair of devices according to the present invention to perform the following steps: - generating control messages, preferably using suitable control logic; - receiving an encrypted message from another device; - decrypting said encrypted message by using the public encryption key; - verifying the decrypted message by comparing it with the generated control message, and if the verification is successful, encrypting at least the second encrypted message using the first private encryption key, thereby generating a second encrypted message encrypted using at least two private keys; - sending said second encrypted message to a third device, to a message delivery device according to the invention, or to another recipient (eg, a controller, a signal, etc.).

[0011] This provides security in terms of protection of goods and / or people in that it is possible to verify that a message has been validated by at least two control devices and to ensure that the message will always travel in encrypted form, thus providing redundancy without transmitting any plaintext information.

[0012] As mentioned above and as will be further explained below, a third device may also be included that participates in the message verification process in series or in parallel with the other two devices to increase the system redundancy level.

[0013] It should be pointed out that the number of devices may be increased at will to meet the redundancy requirements of most critical systems.

[0014] It is therefore possible to use railway control systems that are no longer based on dedicated fault-tolerant architectures (such as, for example, 2oo2 or similar architectures that assume the use of voting systems, watchdogs, etc.), but on COTS components (such as, for example, hardware and operating systems based on x86 or x64 architectures), which are well suited to the use of distributed virtualization technologies (the so-called "cloud"); indeed, the use of such technologies makes it possible to implement railway control systems in such a way as to increase their availability, thus advantageously improving the quality of the control services offered in the railway sector and in other sectors as well. In fact, the use of technologies such as virtualization makes it possible to (remotely) control critical systems (such as, for example, elevators, ropeways, subways, trams, trolleybuses, etc.) without having to install any control systems on-site, which, as is known, would take up space and require maintenance. Using the present invention, it is possible to centralize critical system control systems into a single server farm, which, due to large-scale hardware availability and virtualization technology, can guarantee longer uptime for the control systems, along with higher levels of physical security (e.g., against theft, damage, power outages, etc.) and logical security (e.g., against cyber attacks, degraded or defective mass storage units, etc.).

[0015] Further advantageous features of the invention are set out in the accompanying claims. [Brief explanation of the drawings]

[0016] These features and further advantages of the present invention will become more apparent in the light of the following description of preferred embodiments of the invention as illustrated in the accompanying drawings, which are given by way of non-limiting example only. [Figure 1] 1 is a diagram of a railway system comprising three devices according to the present invention; [Figure 2] 2 is a diagram illustrating the architecture of each of the devices in FIG. 1. FIG. [Figure 3] 2 is a block diagram illustrating the operation of the device of FIG. 1 as it executes a set of instructions implementing a method according to the present invention; DETAILED DESCRIPTION OF THE INVENTION

[0017] In this description, any reference to "one embodiment" will indicate that a particular configuration, structure, or feature is included in at least one embodiment of the present invention. Therefore, phrases such as "in one embodiment" that may appear in different parts of this description do not necessarily refer to the same embodiment. Moreover, any particular configuration, structure, or feature may be combined as deemed appropriate in one or more embodiments. Therefore, the following references are used for brevity only and are not intended to limit the scope of protection or extension of various embodiments.

[0018] Referring to FIG. 1, the following describes a critical system S, i.e., a railway system; the railway system S preferably comprises the following parts: - a railway line R, along which at least one train T can run; - Level crossing signal B with movable barrier; - a sensor M, for example an inductive, magnetic, etc. sensor, adapted to detect the presence of another vehicle V (for example a tram) involved in said crossing; - a message distribution system 2, in which the devices communicate with at least the signals B and the sensors M, preferably in an indirect way, i.e. via a yard controller C, which will be further described below; a system 0 for generating messages for controlling a critical system S, a first device 1a according to the invention, preferably in communication with a message delivery system 2; a second device 1b according to the invention, preferably in communication with the first device 1a and the message delivery system 2; System 0 Equipped with.

[0019] The devices 1a and 1b are configured to communicate with each other via a data communication network, preferably a private local area network, which, if the devices 1a, 1b are installed in separate locations, is preferably a public network, such as the Internet or a Multiprotocol Label Switching (MPLS) network.

[0020] It should be pointed out that reference in the following description is made to railroad crossings for illustrative purposes only, since the subject matter of the present invention is also applicable to other parts of a railway system that need to generate messages for controlling the railway network (e.g., railway vehicles, points, monitoring systems, etc.).

[0021] It should also be pointed out that system 0 may additionally comprise one or more further devices, as described above, that contribute to increasing the redundancy level of system 0. For greater clarity, this description will first present an exemplary embodiment envisaging an interaction between devices 1a and 1b, followed by an example in which a third device 1c (contained within system 0) interacts with the first two devices 1a, 1b.

[0022] As will be further explained below, the message delivery system 2 comprises at least one first message delivery device 3 a according to the present invention and optionally one or more second message delivery devices 3 b according to the present invention, wherein said devices 3 a and 3 b are configured to communicate with each other via a second data communication network, preferably a private local area network. If said devices 3 a, 3 b are installed in separate locations, the network is preferably a public network, for example the Internet or a Multiprotocol Label Switching (MPLS) network.

[0023] Also referring to FIG. 2, the following describes an apparatus 1 (designated by symbols 1a and 1b in FIG. 1); said apparatus 1 comprises the following components: - control and / or processing means 11 (for brevity also referred to as CPUs), such as one or more CPUs and / or microcontrollers and / or FPGAs and / or CPLDs, adapted to enable, preferably in a programmable manner, through the execution of appropriate instructions, the generation of messages for controlling the railway network; - memory means 12 in signal communication with the control and / or processing means 11, for example a random access memory (RAM) and / or flash memory and / or another type of memory, wherein said volatile memory means 12 preferably stores at least instructions implementing the method according to the invention, which can be read by the control and / or processing means 11 when the device 1 is in an operating condition; said memory means 12 may also contain a set of instructions implementing a control logic which will enable said device 1 to control a part of the railway network, preferably including an encryption key (as further explained below); - communication means 13 allowing the device 1 to communicate with other devices 1b and / or other elements, for example with the message distribution system 2 or with other devices included in the railway system S, preferably an interface operating according to one of the communication standards made possible by the ERTMS / ETCS system or one of the standards belonging to the IEEE 802.3 (also known as Ethernet), IEEE 802.11 (also known as WiFi) or 802.16 (also known as WiMax) families, or an interface to a GSM-R or GSM / GPRS / UMTS / LTE or TETRA data network; - input / output means (I / O) 14 that may be used, for example, to connect said device 1 to a programming terminal configured to write instructions (which the CPU 11 must then execute) into the memory means 12 and / or to enable the diagnosis of any faults suffered by said device 1; such input / output means 14 may include, for example, a USB, Firewire, RS232, IEEE1284, Ethernet, WiFi or Bluetooth adapter, etc.; a communication bus 17 allowing information to be exchanged between the control and / or processing means 11, the memory means 12, the communication means 13 and the input / output means 14; Equipped with.

[0024] As an alternative to the communication bus 17, the control and / or processing means 11, memory means 12, communication means 13 and input / output means 14 may be connected using a star architecture.

[0025] Each of the devices 3a, 3b has an internal architecture that is similar to that of the apparatuses 1a, 1b. More specifically, said devices 3a, 3b comprise control and / or processing means (for example a CPU) and communication means (for example an Ethernet card or another type of card) for communicating with the signals B and the sensors M (the so-called yard equipment), preferably via a controller C that controls their operation; for this purpose said controller C comprises input / output means (I / O) that may for example comprise a board containing one or more relays capable of controlling the movement of a barrier of the signal B according to values ​​contained in control messages received from one or more of said devices 3a, 3b.

[0026] The devices 3a, 3b may be configured to be redundant with one another, or each of them may be connected to a separate controller that controls a separate set of yard devices. Moreover, as explained further below, the devices 3a, 3b may be configured to decode messages in the same way as the units 1, 1a, 1b to ensure the presence and proper operation of a given number (e.g., two or more) of such devices 3a, 3b.

[0027] Also referring to FIG. 3, the following describes a method for generating messages for controlling a railway network according to the present invention, wherein the method is implemented by a set of instructions that can be executed by each of devices 1a and 1b.

[0028] When each device 1a and 1b is in an operating condition, the control and / or processing means 11 executes a set of instructions implementing a message preparation phase P0a, P0b, during which the CPU 11 generates a first message, which is preferably determined based on the control logic stored in the memory means 12 and the state of the railway system S, and which may for example include data representative of sensor signals generated by the sensor M and / or by the signal B and received via the communication means 13.

[0029] Furthermore, the set of instructions executed by the control and / or processing means 11 (stored in the memory means 12) also implements a control method according to the invention; said method comprising at least the following phases: a. a first encryption phase P1a, P1b, in which said first message is encrypted by the control and / or processing means 11 using a first private encryption key, thereby generating a first encrypted message; b. a first transmission phase P2a, P2b, in which said first encrypted message is transmitted via the communication means 13 to the second device 1, 1a, 1b; c. a first reception phase P3a, P3b, in which a second encrypted message generated by the second device 1, 1a, 1b and encrypted by said second device 1, 1a, 1b using a second private encryption key is received via the communication means 13; d. a first decryption phase P4a, P4b, in which said second encrypted message is decrypted by the control and / or processing means 11 by using a public encryption key associated with said second private encryption key, thereby generating a second decrypted message; e. a first verification phase P5a, P5b, in which said second decrypted message is verified by the control and / or processing means 11 based on said first message (for example by performing a bit-by-bit comparison between the two messages or at least parts thereof so as to verify their equality), and if the verification fails, the control and / or processing means will preferably enter an error state ERR, in which the device 1a, 1b will preferably try to (re)combine with the other device 1a, 1b; f. a second encryption phase P6a, P6b, in which, if the verification phase is successful, said second encrypted message is encrypted by the control and / or processing means 11 using said first private encryption key, thereby generating a third encrypted message; g. A second transmission phase P7a, P7b, in which the third encrypted message is transmitted via communication means 13 to a recipient, e.g., the message delivery system 2 or a third device 1c (similar or equivalent to devices 1a, 1b, the operation of which is further described below). Equipped with.

[0030] It should be pointed out that the device 1 may be configured to execute these phases not strictly consecutively, i.e. phases c. and d. may start when phases a. and b. have not yet been completed.

[0031] When a device 3a, 3b is in an operational condition, the control and / or processing means of said device 2 execute a set of instructions stored in the memory means of said device 2, implementing a method for the distribution of messages for controlling a critical system according to the invention, said method comprising the following phases: a. a terminal reception phase, in which an encrypted message is received from at least one device 1, 1a, 1b via a communication means, wherein the message is encrypted using at least a first private encryption key and a second private encryption key; b. a terminal decryption phase, wherein said encrypted message is decrypted by the control and / or processing means using at least one public encryption key associated with said first private encryption key and / or said second private encryption key, thereby generating a first decrypted message (as further described below); c. Terminal transmission phase, in which the decrypted message is transmitted via a communication means to at least one device included in the critical system, such as a crossing signal B and / or a sensor M, preferably through a controller C controlling its operation. Equipped with.

[0032] It must be pointed out that if any one of the devices 1a, 1b does not execute the second encryption phase P6a, P6b (for example due to a failed first verification phase P5a, P5b), when a message signed by only one of the devices 1a, 1b reaches the device 3a, 3b, the terminal decryption phase will either fail or will anyway produce an invalid plaintext message, and therefore the security of the critical system S is ensured.

[0033] This ensures security in terms of the protection of goods and / or people in that it is possible to verify that a message has been validated by at least two control devices and to ensure that the message will always travel in encrypted form, thus providing redundancy without transmitting any cleartext information. It is therefore possible to use control systems based on COTS components, which are well suited to the use of distributed virtualization techniques.

[0034] The public and private cryptographic keys used by devices 1, 1a, 1b may be generated in pairs by using well-known cryptographic algorithms, such as RSA (Rivest-Shamir-Adleman), DSA (Digital Signature Algorithm), ECC (Elliptic Curve Cryptography), or similar other algorithms. As an alternative to these algorithms for the generation of the public and private key pairs, the following relationship may be used:

number

[0035] key pu i and PR i It should be emphasized that preferably has the same length, equal to the length of the message M. If the message is longer than the key, the bits comprising the key may be cyclically reused to obtain a (pseudo) key that is the same length as the message M in question.

[0036] During the encryption phases P1a and P1b, the encryption operation (i-th private encryption key PR i (using) is preferably performed by executing, via the control and / or processing means 11, a set of instructions that implements the following relationships:

number

[0037] During the first decryption phase P4a, P4b, the encrypted message (MC) received during the first reception phase P3a, P3b is encrypted using the i-th public encryption key PU. i The operation of decoding (using) is preferably performed via the control and / or processing means 11 by executing a set of instructions which implement the following relationship:

number

number

[0038] During the terminal decryption phase performed by the devices 3a and 3b, at least two private keys (PR i ,PR j ) is preferably performed by executing, via the control and / or processing means 11, a set of instructions that implements the following relationship (which is similar to relationship 3 above, as explained further below):

number

number

[0039] This approach reduces the complexity of the decryption operations and advantageously (in addition to the computational complexity) also reduces the number of failure modes that can occur during the execution of the message distribution method according to the invention, leading to improved security in terms of the protection of objects and / or people, since it is possible to verify that the message has been validated by at least two control devices and to ensure that the message will always travel in encrypted form, thus ensuring redundancy without transmitting any plaintext information. As a result, it becomes possible to use control systems based on COTS components, which are well suited to the use of distributed virtualization techniques.

[0040] Due to the very advantages explained above, it is also advantageously possible for the devices 1, 1a, b to be configured to use (during the second decryption phase of the control method according to the invention) a public encryption key associated with said second private encryption key and said third private encryption key, wherein said public encryption key is the result of a combination between at least said second public encryption key and said third public encryption key.

[0041] In addition to the above, the first device 1a and / or the second device 1b may be configured to send (during a second transmission phase P7a, P7b) a second encrypted message to the third device 1. This makes it possible to obtain an additional validation of the control message by another control device, thereby increasing the redundancy level of the entire system S. To this end, the control method according to the invention, which is executed by all three devices 1, 1a, 1b, preferably also comprises the following steps: h. a second receiving phase, in which a fourth encrypted message generated by the third device 1c using a third private encryption key starting from a message (already) encrypted (by at least the second device 1b) using at least the second private encryption key is received via the communication means 13; i. a second decryption phase, wherein said fourth encrypted message is decrypted by the control and / or processing means 11 using at least one public encryption key associated with said second private encryption key and / or said third private encryption key, thereby obtaining (e.g., relation 5 (where D(MCC,PU ij ,n), where n=2) by executing a set of instructions that implements the fourth decrypted message; j. a second verification phase, in which said fourth decrypted message is verified by the control and / or processing means 11 based on said first message (e.g. by performing a bit-wise comparison between the two messages or at least parts thereof so as to verify their equality); k. A third encryption phase, where if the verification phase is successful, said fourth encrypted message is encrypted by the control and / or processing means 11 using a first private encryption key, thereby obtaining (e.g. relation 4(where E(M,PR i ), a fifth encrypted message is generated by executing a set of instructions that implements), which is), MCC); l. A third transmission phase, in which said fifth encrypted message is transmitted via communication means 13 to a recipient, for example device 3a, 3b (if the verification process has been completed) or to a fourth apparatus 1 (if an additional level of redundancy is required).

[0042] During the terminal decryption phase, the public encryption key used by the device 3 a, 3 b is obtained by (arithmetically) combining the first, second and third public encryption keys, for example by executing (preferably asynchronously (offline) with respect to the execution of the message delivery method according to the invention) a set of instructions that implements the following relationship:

number

[0043] It must be emphasized that, similar to the second encryption phase P6a, P6b, if any one of the devices 1, 1a, 1b has not performed the third encryption phase (for example due to a failed second verification phase), when a message signed by only one or two of the devices 1a, 1b reaches the device 3a, 3b, the terminal decryption phase will either fail or will anyway produce an invalid plaintext message, and therefore the security of the critical system S will be ensured.

[0044] By observing relations 6 and 7, it can be seen that this approach can be extended to any number of keys, advantageously increasing the level of redundancy without increasing the computational load on devices 3a, 3b.

[0045] In practice, it should be pointed out that depending on the context of the particular application in which the invention is to be used, the level of redundancy can be increased at will (to meet the requirements of the particular application context) by sending messages to one or more additional devices 1.

[0046] This advantageously provides an increased level of redundancy and makes it possible to improve security in terms of the protection of goods and / or people in that it is possible to verify that a message has been validated by at least three control devices and to ensure that the message will always travel in encrypted form, thus ensuring redundancy without transmitting any plaintext information. It is therefore possible to use control systems based on COTS components, which are well suited to the use of distributed virtualization techniques.

[0047] If two or more devices 3a, 3b are used, it is possible to ensure that a given number of such devices 3a, 3b are properly operational by configuring each device 3a, 3b to perform the following sub-phases during the terminal decryption phase: - decrypting the encrypted message by using at least a first public encryption key associated with at least the first private encryption key, thereby generating a first semi-decrypted, i.e., partially decrypted and still ciphertext, message; - transmitting said first partially decrypted message via the communication means of said device to preferably another (second) device 3a, 3b; - receiving, via the communication means of the devices 3a, 3b, a second semi-decrypted (i.e. partially decrypted) message, wherein the second decrypted message has been decrypted using at least one fourth public encryption key associated with at least the second private encryption key; - decrypting, by the control and / or processing means, said second partially decrypted message by using at least said first public encryption key associated with said first private encryption key, thereby producing a plaintext message, e.g. by executing a set of instructions that implements relation 3.

[0048] This advantageously makes it possible to prevent the encrypted message from being decrypted if at least two (or more) of said devices 3a, 3b are not operational.

[0049] In practice, it is possible to prevent message decryption by generating the public keys such that each of the public keys is related only to a portion of the private key used to encrypt the message. For example, if a message was encrypted using four private keys (i.e., generated using four devices 1, 1a, 1b, 1c), a first public key can be generated based on the public key associated with the first and third private keys, and a fourth public key can be generated based on the public key associated with the second and third private keys, preferably by executing instructions that implement relationship 7 above.

[0050] It is therefore possible to advantageously increase the number of failure modes of the critical system S that can be eliminated, thereby increasing safety in terms of the protection of objects and / or people, while also ensuring redundancy without transmitting any plaintext information.

[0051] Of course, the examples described above may be subject to many variations.

[0052] In a first variant, when there are at least three devices according to the invention, instead of performing a first verification phase P5a, P5b and a second verification phase, the devices only perform a single verification phase in which all verification operations are concentrated.

[0053] More specifically, the control and / or processing means 11 are adapted to carry out the phases of the method according to the invention as follows: - during a sending phase, said first encrypted message is sent (via the communication means 13) to a second device and also to a third device; - during the first receiving phase, at least one fourth encrypted message is also received (via the communication means 13), which message was generated by a third device and encrypted by said third device using a third private encryption key; - during a decryption phase, the fourth encrypted message is similarly decrypted by using a public encryption key associated with the third private encryption key, thereby generating a third decrypted message; - during a first verification phase, also at least said third decrypted message is verified based on the (first) message generated by said control and / or processing means 11 as described with reference to the main embodiment; - during the second encryption phase, if the first verification phase is successful, at least said second encrypted message and said fourth encrypted message are encrypted using said first private encryption key, thereby generating a third encrypted message, which is then to be transmitted as described with reference to the main embodiment.

[0054] It should be pointed out that during the second encryption phase, the second encrypted message and the third encrypted message are combined together (e.g., combined according to relationship 4 above), so that with a single encryption operation it is possible to confirm successful verification of all messages generated by other devices. This advantageously allows the number of such devices to be increased without significantly increasing the length of the operations required to verify the messages.

[0055] It is therefore possible to verify that the message has been validated by at least three control devices and ensure that the message will always travel in encrypted form, thereby increasing security in terms of the protection of objects and / or people and providing redundancy without transmitting any plaintext information.

[0056] In a further variant, the message prepared and sent by the device according to the invention (i.e. by the message generation system 0, see FIG. 1) is not sent to the message delivery system 2 but is sent directly to a controller C or a signal S, wherein the controller C or the signal S is configured to perform the phases of the method for delivery of messages according to the invention.

[0057] This makes it possible to manage situations where the message delivery system 2 is broken or non-existent, without transmitting any plaintext information, thereby increasing the level of redundancy and therefore the level of safety in terms of the protection of objects and / or people.

[0058] Although some of the possible variations of the present invention have been described above, it will be clear to those skilled in the art that other embodiments in which some elements may be replaced by other technically equivalent elements may also be implemented in practice. The present invention is therefore not limited to the illustrative examples described above, but is susceptible to various modifications, improvements, equivalent parts and substitutions of elements, as specified in the following claims, without departing from the basic inventive concept. [Other possible items] [Item 1] A device (1, 1a, 1b, 1c) for controlling a critical system (S), - memory means (12) containing at least one first private cryptographic key; - communication means (13) adapted to communicate with a second device (1, 1a, 1b, 1c), - control and / or processing means (11) in communication with said memory means (12) and said communication means (13), wherein said control and / or processing means (11) is configured to generate a first message containing information capable of changing the state of said critical system (S). Equipped with The control and / or processing means (11) - encrypting the first message by using the first private encryption key, thereby generating a first encrypted message; - transmitting said first encrypted message to at least said second device (1, 1a, 1b, 1c) via said communication means (13); - receiving, via said communication means (13), at least one second encrypted message generated by said second device (1, 1a, 1b, 1c) and encrypted by said second device (1, 1a, 1b, 1c) using a second private encryption key; - decrypting the second encrypted message by using a public encryption key associated with the second private encryption key, thereby generating a second decrypted message; - verifying at least the second decrypted message based on the first message, and if the verification is successful, encrypting at least the second encrypted message using the first private encryption key, thereby generating a third encrypted message; - sending said third encrypted message to a recipient via said communication means (13); The apparatus is configured to also perform the following: [Item 2] The control and / or processing means (11) - receiving, via said communication means (13), a fourth encrypted message generated by a third device (1, 1a, 1b, 1c) using a third private encryption key starting from a message encrypted using at least said second private encryption key; - decrypting the fourth encrypted message by using at least a second public encryption key associated with the second private encryption key and / or the third private encryption key, thereby generating a fourth decrypted message; - verifying the fourth decrypted message based on the first message, and if the verification is successful, encrypting the fourth encrypted message using the first private encryption key, thereby generating a fifth encrypted message; - transmitting the fifth encrypted message via the communication means (13). Item 1. The device (1, 1a, 1b, 1c) according to item 1, configured to also perform [Item 3] The second public encryption key associated with the second private encryption key and the third private encryption key is at least - a fourth public encryption key associated with said second private encryption key; and - a third public cryptographic key associated with said third private cryptographic key; Item 2. The device according to part of item 2, which is the result of a combination between (1, 1a, 1b, 1c). [Item 4] The control and / or processing means (11) - transmitting said first encrypted message to a third device (1, 1a, 1b, 1c) via said communication means (13); - also receiving, via said communication means (13), at least one fourth encrypted message generated by said third device (1, 1a, 1b, 1c) and encrypted by said third device (1, 1a, 1b, 1c) using a third private encryption key, - similarly decrypting the fourth encrypted message by using a fifth public encryption key associated with the third private encryption key, thereby generating a third decrypted message; - similarly verifying at least the third decrypted message based on the first message, and if the verification is successful, encrypting at least the second encrypted message and the fourth encrypted message using the first private encryption key, thereby generating the third encrypted message. The device (1, 1a, 1b, 1c) according to item 1, further comprising: [Item 5] A system (0) for the generation of messages for controlling said critical system (S), - a first device (1a) according to any one of items 1 to 4, and - a second device (1b) according to any one of items 1 to 4 wherein the first device (1a) and the second device (1b) are configured to communicate with each other via a data communication network. [Item 6] 1. A method for controlling a critical system (S) through at least one first message containing information capable of changing the state of said critical system (S), comprising: - a first encryption phase (P1a, P1b), in which said first message is encrypted by the control and / or processing means (11) using a first private encryption key, thereby generating a first encrypted message; - a first transmission phase (P2a, P2b), in which said first encrypted message is transmitted via a communication means (13) to at least one second device (1, 1a, 1b, 1c); - a first reception phase (P3a, P3b), in which at least one second encrypted message generated by said second device (1, 1a, 1b, 1c) and encrypted by said second device (1, 1a, 1b, 1c) using a second private encryption key is received via said communication means (13); - a first decryption phase (P4a, P4b), in which the second encrypted message is decrypted by the control and / or processing means (11) by using a public encryption key associated with the second private encryption key, thereby generating a second decrypted message; - a first verification phase (P5a, P5b), in which at least said second decrypted message is verified by said control and / or processing means (11) on the basis of said first message; - a second encryption phase (P6a, P6b), in which, if the first verification phase is successful, at least the second encrypted message is encrypted by the control and / or processing means (11) using the first private encryption key, thereby generating a third encrypted message; - a second transmission phase (P7a, P7b), during which said third encrypted message is transmitted to a recipient via said communication means (13). A method comprising: [Item 7] a second reception phase, in which a fourth encrypted message generated by a third device (1, 1a, 1b, 1c) using a third private encryption key starting from a message encrypted using at least said second private encryption key is received via said communication means (13); - a second decryption phase, in which the fourth encrypted message is decrypted by the control and / or processing means (11) using at least one second public encryption key associated with the second private encryption key and / or the third private encryption key, thereby generating a fourth decrypted message; - a second verification phase, in which the fourth decrypted message is verified by the control and / or processing means (11) based on the first message; - a third encryption phase, in which, if the verification phase is successful, the fourth encrypted message is encrypted by the control and / or processing means (11) using the first private encryption key, thereby generating a fifth encrypted message; - a third transmission phase, in which said fifth encrypted message is transmitted via said communication means (13). Item 7. The method of item 6, further comprising: [Item 8] During the second decryption phase, the second public encryption key associated with the second private encryption key and the third private encryption key is at least - a fourth public encryption key associated with said second private encryption key; and - a third public cryptographic key associated with said third private cryptographic key; 8. The method according to claim 7, wherein the method is the result of a combination between: [Item 9] - during said transmission phase, said first encrypted message is also transmitted to a third device (1, 1a, 1b, 1c), - during said first receiving phase, at least one fourth encrypted message is also received, said fourth encrypted message having been generated by said third device (1, 1a, 1b, 1c) and encrypted by said third device (1, 1a, 1b, 1c) using a third private encryption key; - during the decryption phase, the fourth encrypted message is also decrypted by using a fifth public encryption key associated with the third private encryption key, thereby generating a third decrypted message; - during the first verification phase, at least the third decrypted message is also verified based on the first message; - during the second encryption phase, if the first verification phase is successful, at least the second encrypted message and the fourth encrypted message are encrypted using the first private encryption key, thereby generating the third encrypted message; The method according to item 6. [Item 10] A device (3a, 3b) for the distribution of messages for controlling a critical system (S), - memory means containing at least one first public cryptographic key; - communication means adapted to communicate with at least one device (1, 1a, 1b, 1c) according to any one of items 1 to 4, - control and / or processing means in communication with said memory means and said communication means; Equipped with wherein said control and / or processing means receiving, via said communication means, an encrypted message from said at least one device (1, 1a, 1b, 1c), wherein said message is encrypted using at least a first private encryption key and a second private encryption key; decrypting the encrypted message by using at least the first public encryption key associated with at least the first private encryption key and / or the second private encryption key, thereby generating a plaintext message; transmitting said plaintext message via said communication means to at least one device included in said critical system (S); A device configured to perform the following: [Item 11] Item 11. The device (3a, 3b) according to item 10, wherein the received encrypted message is also encrypted by using a third private encryption key. [Item 12] The first public encryption key comprises at least - a second public encryption key associated with at least said first private encryption key; and - a third public cryptographic key associated with at least said second private cryptographic key; 12. The device (3a, 3b) according to item 10 or 11, which is the result of a combination between: [Item 13] said control and / or processing means - decrypting the encrypted message by using at least the first public encryption key associated with at least the first private encryption key, thereby generating a first partially decrypted message; - transmitting said first partially decrypted message via said communication means; - receiving via said communication means a second partially decrypted message, wherein said second partially decrypted message has been decrypted using at least one fourth public encryption key associated with at least said second private encryption key; - decrypting, by said control and / or processing means, said second partially decrypted message by using said first public encryption key associated with at least said first private encryption key, thereby generating said plaintext message. 13. The device (3a, 3b) according to any one of items 10 to 12, configured to decrypt the encrypted message by executing [Item 14] A message distribution system (2) that controls the critical system (S), - a first device (3a) according to any one of items 10 to 13, and - a second device (3b) according to any one of items 10 to 13 wherein the first device (3a) and the second device (3b) are configured to communicate with each other via a data communication network. [Item 15] A method for distribution of messages for controlling a critical system (S), comprising: - a terminal reception phase, in which an encrypted message is received from at least one device (1, 1a, 1b, 1c) via a communication means, wherein the message is encrypted using at least a first private encryption key and a second private encryption key; - a terminal decryption phase, in which the encrypted message is decrypted by the control and / or processing means using at least one first public encryption key associated with the first private encryption key and / or the second private encryption key, thereby generating a plaintext message; a terminal transmission phase, in which said plaintext message is transmitted via said communication means to at least one device included in said critical system (S); A method comprising: [Item 16] Item 6. The method according to item 5, wherein the message received during the terminal reception phase is also encrypted by using a third private encryption key. [Item 17] During the first terminal decryption phase, the first public encryption key is - a second public encryption key associated with at least said first private encryption key; and - a third public cryptographic key associated with at least said second private cryptographic key; 17. The method according to item 15 or 16, wherein the method is the result of a combination between: [Item 18] The following substeps: - decrypting, by said control and / or processing means, said encrypted message by using at least said first public encryption key associated with at least said first private encryption key, thereby generating a first partially decrypted message; - transmitting said first partially decrypted message via said communication means; - receiving via said communication means a second partially decrypted message, wherein said second partially decrypted message has been decrypted using at least one fourth public encryption key associated with at least said second private encryption key; - decrypting, by said control and / or processing means, said second partially decrypted message by using said first public encryption key associated with at least said first private encryption key, thereby generating said plaintext message. 18. The method according to any one of items 15 to 17, wherein the is executed during the terminal decryption phase. [Item 19] A computer program product that can be loaded into the memory of an electronic computer and that comprises portions of software code for performing the phases of the method according to any one of items 6 to 9 or 15 to 18.

Claims

1. An apparatus for controlling a critical system (S), comprising: memory means containing at least one first private cryptographic key; communication means adapted to communicate with a second device; - control and / or processing means in communication with said memory means and said communication means, wherein said control and / or processing means are adapted to generate a first message containing information capable of modifying the state of said critical system (S). Equipped with said control and / or processing means - encrypting said first message by using said first private encryption key, thereby generating a first encrypted message; - transmitting said first encrypted message to at least said second device via said communication means; receiving, via said communication means, at least one second encrypted message generated by said second device and encrypted by said second device using a second private encryption key; - decrypting the second encrypted message by using a public encryption key associated with the second private encryption key, thereby generating a second decrypted message; - verifying at least the second decrypted message based on the first message, and if the verification is successful, encrypting at least the second encrypted message using the first private encryption key, thereby generating a third encrypted message; - sending said third encrypted message to a recipient via said communication means; The apparatus is configured to also perform

2. said control and / or processing means receiving, via said communication means, a fourth encrypted message generated by a third device using a third private encryption key starting from a message encrypted using at least said second private encryption key; decrypting the fourth encrypted message by using at least a second public encryption key associated with the second private encryption key and / or the third private encryption key, thereby generating a fourth decrypted message; verifying the fourth decrypted message based on the first message, and if the verification is successful, encrypting the fourth encrypted message using the first private encryption key, thereby generating a fifth encrypted message; - transmitting said fifth encrypted message via said communication means. The apparatus of claim 1 , further configured to:

3. The control and / or processing means receiving, via said communication means, a fourth encrypted message generated by a third device using a third private encryption key starting from a message encrypted using at least said second private encryption key; decrypting the fourth encrypted message by using at least a second public encryption key associated with the second private encryption key and the third private encryption key, thereby generating a fourth decrypted message; verifying the fourth decrypted message based on the first message, and if the verification is successful, encrypting the fourth encrypted message using the first private encryption key, thereby generating a fifth encrypted message; - transmitting said fifth encrypted message via said communication means. It is also configured to The second public encryption key associated with the second private encryption key and the third private encryption key is at least a fourth public encryption key associated with said second private encryption key; and a third public encryption key associated with said third private encryption key; The apparatus of claim 1 , wherein the combination is the result of:

4. said control and / or processing means - transmitting said first encrypted message via said communication means to a third device as well; - receiving, via said communication means, at least one fourth encrypted message generated by said third device and encrypted by said third device using a third private encryption key; - similarly decrypting the fourth encrypted message by using a fifth public encryption key associated with the third private encryption key, thereby generating a third decrypted message; - similarly verifying at least the third decrypted message based on the first message, and if the verification is successful, encrypting at least the second encrypted message and the fourth encrypted message using the first private encryption key, thereby generating the third encrypted message. The apparatus of claim 1 , further comprising:

5. A system (0) for the generation of messages for controlling said critical system (S), a first device, which is a device according to any one of claims 1 to 4, and a second device, which is a device according to any one of claims 1 to 4, wherein the first device and the second device are configured to communicate with each other over a data communications network.

6. 1. A method for controlling a critical system (S) through at least one first message containing information capable of changing the state of said critical system (S), comprising: a first encryption phase, in which said first message is encrypted by the control and / or processing means using a first private encryption key, thereby generating a first encrypted message; a first transmission phase, in which said first encrypted message is transmitted via a communication means to at least one second device; a first receiving phase, in which at least one second encrypted message generated by said second device and encrypted by said second device using a second private encryption key is received via said communication means; a first decryption phase, in which said second encrypted message is decrypted by said control and / or processing means by using a public encryption key associated with said second private encryption key, thereby generating a second decrypted message; a first verification phase, in which at least said second decrypted message is verified by said control and / or processing means on the basis of said first message; a second encryption phase, in which, if said first verification phase is successful, at least said second encrypted message is encrypted by said control and / or processing means using said first private encryption key, thereby generating a third encrypted message; a second transmission phase, in which said third encrypted message is transmitted to a recipient via said communication means; A method comprising:

7. a second reception phase, in which a fourth encrypted message generated by a third device using a third private encryption key is received via said communication means, starting from a message encrypted using at least said second private encryption key; a second decryption phase, in which said fourth encrypted message is decrypted by said control and / or processing means using at least one second public encryption key associated with said second private encryption key and / or said third private encryption key, thereby generating a fourth decrypted message; a second verification phase, in which said fourth decrypted message is verified by said control and / or processing means on the basis of said first message; a third encryption phase, in which, if the second verification phase is successful, the fourth encrypted message is encrypted by the control and / or processing means using the first private encryption key, thereby generating a fifth encrypted message; a third transmission phase, in which said fifth encrypted message is transmitted via said communication means; The method of claim 6 further comprising: a second receiving phase, in which a fourth encrypted message generated by a third device using a third private encryption key starting from a message encrypted using at least said second private encryption key is received via said communication means; a second decryption phase, in which said fourth encrypted message is decrypted by said control and / or processing means using at least one second public encryption key associated with said second private encryption key and said third private encryption key, thereby generating a fourth decrypted message; a second verification phase, in which said fourth decrypted message is verified by said control and / or processing means on the basis of said first message; a third encryption phase, in which, if the second verification phase is successful, the fourth encrypted message is encrypted by the control and / or processing means using the first private encryption key, thereby generating a fifth encrypted message; a third transmission phase, in which said fifth encrypted message is transmitted via said communication means; Further provided with During the second decryption phase, the second public encryption key associated with the second private encryption key and the third private encryption key is at least a fourth public encryption key associated with said second private encryption key; and a third public encryption key associated with said third private encryption key; 7. The method of claim 6, wherein the method is the result of a combination between:

9. During the first transmission phase, the first encrypted message is also transmitted to a third device; during said first receiving phase, at least one fourth encrypted message is also received, said fourth encrypted message having been generated by said third device and encrypted by said third device using a third private encryption key; during the first decryption phase, the fourth encrypted message is also decrypted by using a fifth public encryption key associated with the third private encryption key, thereby generating a third decrypted message; during said first verification phase, at least said third decrypted message is also verified based on said first message; during the second encryption phase, if the first verification phase is successful, at least the second encrypted message and the fourth encrypted message are encrypted using the first private encryption key, thereby generating the third encrypted message; The method of claim 6.

10. A device for the distribution of messages for controlling a critical system (S), comprising: memory means containing at least one first public cryptographic key; - communication means adapted to communicate with at least one device, the device being a device according to any one of claims 1 to 4; control and / or processing means in communication with said memory means and said communication means; Equipped with wherein said control and / or processing means receiving, via said communication means, an encrypted message from said at least one device, wherein said message is encrypted using at least a first private encryption key and a second private encryption key; decrypting the encrypted message by using at least the first public encryption key associated with at least the first private encryption key and / or the second private encryption key, thereby generating a plaintext message; transmitting said plaintext message via said communication means to at least one device comprised in said critical system (S); A device that is configured to:

11. 11. The device of claim 10, wherein the received encrypted message is also encrypted using a third private encryption key.

12. The first public encryption key comprises at least a second public encryption key associated with at least said first private encryption key; and a third public encryption key associated with at least said second private encryption key; 12. The device according to claim 10 or 11, which is the result of a combination between:

13. said control and / or processing means - decrypting the encrypted message by using at least said first public encryption key associated with at least said first private encryption key, thereby generating a first partially decrypted message; - transmitting said first partially decrypted message via said communication means; receiving, via said communication means, a second partially decrypted message, wherein said second partially decrypted message has been decrypted using at least one fourth public encryption key associated with at least said second private encryption key; - decrypting, by said control and / or processing means, said second partially decrypted message by using said first public encryption key associated with at least said first private encryption key, thereby generating said plaintext message.

13. A device according to any one of claims 10 to 12, configured to decrypt the encrypted message by executing:

14. A message distribution system that controls the critical system (S), a first device, which is a device according to any one of claims 10 to 13, and a second device, which is a device according to any one of claims 10 to 13; wherein the first device and the second device are configured to communicate with each other over a data communications network.

15. A method for the distribution of messages for controlling a critical system (S), comprising: a terminal reception phase, in which an encrypted message is received from at least one device via a communication means, wherein said message is encrypted using at least a first private encryption key and a second private encryption key; a terminal decryption phase, in which the encrypted message is decrypted by the control and / or processing means using at least one first public encryption key associated with the first private encryption key and / or the second private encryption key, thereby generating a plaintext message; a terminal transmission phase, in which said plaintext message is transmitted via said communication means to at least one device included in said critical system (S). A method comprising:

16. 16. The method of claim 15, wherein the message received during the terminal reception phase is also encrypted by using a third private encryption key.

17. During the terminal decryption phase, the first public encryption key is at least a second public encryption key associated with at least said first private encryption key; and a third public encryption key associated with at least said second private encryption key; 17. The method of claim 15 or 16, which is the result of a combination between:

18. The following substeps: - decrypting, by said control and / or processing means, said encrypted message by using at least said first public encryption key associated with at least said first private encryption key, thereby generating a first partially decrypted message; - transmitting said first partially decrypted message via said communication means; receiving, via said communication means, a second partially decrypted message, wherein said second partially decrypted message has been decrypted using at least one fourth public encryption key associated with at least said second private encryption key; - decrypting, by said control and / or processing means, said second partially decrypted message by using said first public encryption key associated with at least said first private encryption key, thereby generating said plaintext message. The method according to any one of claims 15 to 17, wherein during the terminal decryption phase,

19. A computer program product loadable into the memory of an electronic computer and comprising software code for carrying out the phases of the method of any one of claims 6 to 9 or 15 to 18.

Citation Information

Patent Citations

  • Device and Method for the Safe Management of Vital Communications in the Railway Environment

    US20190351924A1

  • Communications system, communications device used in same, management device, and information terminal

    WO2018003919A1