Train-to-ground communication method and apparatus, and device and storage medium

By establishing a key distribution center in the train communication system and using session keys and backup keys to manage train-to-ground communication, the security threat problem in train communication is solved, and more reliable and secure communication is achieved.

WO2025232156A1PCT designated stage Publication Date: 2025-11-13CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/134653
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-09
Filing Date
2024-11-26
Publication Date
2025-11-13

AI Technical Summary

Technical Problem

Communication between onboard equipment and ground equipment faces security threats, such as hacking, malware and signal interference. Existing technologies lack confidentiality protection for train-to-ground wireless communication messages, and using the same authentication key to generate session keys poses security risks.

Method used

By establishing a key distribution center, the train obtains a session key based on operation-related information before each run, and uses a backup key for encrypted communication when a session key is not obtained. The working key is used to perform consistency verification and encrypted communication with ground equipment.

Benefits of technology

This improved the reliability and security of train communication, ensuring the safe operation of trains.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024134653_13112025_PF_FP_ABST
    Figure CN2024134653_13112025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present invention are a train-to-ground communication method and apparatus, and a device and a storage medium. The method comprises: acquiring a preset master key and operation-related information of a train, and determining a working key on the basis of the preset master key and the operation-related information; encrypting the working key by means of the preset master key so as to generate working-key ciphertext, and sending the working-key ciphertext to a ground device, so as to acquire, on the basis of the working-key ciphertext, a confirmation message sent by the ground device, and generating a consistency check result on the basis of the confirmation message; and when the consistency check result indicates that the check is successful, communicating with the ground device by means of the working key. A key distribution center is established on the basis of train-to-ground wireless communication, so as to realize key management of the train-to-ground wireless communication; a train acquires a session key from the key distribution center on the basis of operation-related information, and uses the session key to perform encrypted communication; and when the session key is not acquired, a standby key is used for encrypted communication, thereby improving the communication reliability, and ensuring the operation safety of the train.
Need to check novelty before this filing date? Find Prior Art

Description

A vehicle-to-ground communication method, apparatus, device, and storage medium Technical Field

[0001] This invention relates to the field of train communication technology, and in particular to a train-to-ground communication method, apparatus, equipment, and storage medium. Background Technology

[0002] With the continuous development of railway transportation, communication between train-mounted equipment and ground equipment has become increasingly important. Train-mounted equipment needs to transmit information such as the train's location, speed, and operating status to ground equipment for monitoring and management. Simultaneously, ground equipment also needs to transmit control commands to the train-mounted equipment for appropriate train operations.

[0003] However, communication between onboard and ground equipment faces numerous security threats, such as hacking, malware, and signal interference. These threats can lead to tampering, falsification, or disruption of communication between the onboard and ground equipment, thereby affecting the safe operation of the train.

[0004] Existing technologies mainly use the 3DES algorithm to ensure the integrity of vehicle-to-ground wireless communication messages, but lack confidentiality protection for these messages. In addition, each vehicle-to-ground wireless communication uses the same authentication key to generate a session key through a key generation algorithm, which poses a security risk. Summary of the Invention

[0005] This invention provides a vehicle-to-ground communication method, apparatus, device, and storage medium to achieve security protection for vehicle-to-ground wireless communication networks.

[0006] According to one aspect of the present invention, a vehicle-to-ground communication method is provided, applied to an in-vehicle device, the method comprising:

[0007] Obtain the preset master key and vehicle operation-related information, and determine the working key based on the preset master key and operation-related information. The working key is either a backup key or a session key.

[0008] The working key is encrypted using a preset master key to generate working key ciphertext, and the working key ciphertext is sent to the ground equipment. The confirmation message sent by the ground equipment is obtained based on the working key ciphertext, and a consistency verification result is generated based on the confirmation message.

[0009] When the consistency verification result is successful, communication with ground equipment is achieved through the working key.

[0010] Optionally, the following steps are taken: obtaining a preset master key and vehicle operation-related information, including: reading the encrypted master key from the key distribution center through a secure transmission device, decrypting the encrypted master key using a pre-configured encryption algorithm to obtain the preset master key; obtaining the vehicle's current operating route, identifying the ground equipment connected to the vehicle, and identifying the equipment identifier corresponding to the ground equipment; and using the operating route and equipment identifier as operation-related information.

[0011] Optionally, the working key is determined based on a preset master key and operation-related information, including: generating a backup key application based on the preset master key; sending the backup key application to a key distribution center to obtain a backup key sent by the key distribution center based on the backup key application; encrypting operation-related information with the preset master key to generate a session key application; sending the session key application to the key distribution center and determining the sending time, and determining the working key based on the sending time.

[0012] Optionally, the working key is determined based on the sending time, including: when the sending time reaches a preset time, determining whether a session key has been obtained; if so, using the session key as the working key; otherwise, using the backup key as the working key.

[0013] Optionally, the working key ciphertext is sent to the ground equipment to obtain an acknowledgment message sent by the ground equipment based on the working key ciphertext, and a consistency verification result is generated based on the acknowledgment message. This includes: sending the working key ciphertext to the ground equipment; decrypting the working key ciphertext using a preset master key through the ground equipment to obtain the working key; generating an acknowledgment message based on the working key through the ground equipment, encrypting the acknowledgment message using the working key to generate an encrypted message, and returning the encrypted message to the vehicle-mounted equipment; decrypting the encrypted message using the working key to generate a decrypted message; and determining whether the decrypted message meets preset conditions. If so, the consistency verification result is determined to be successful; otherwise, the consistency verification result is determined to be unsuccessful.

[0014] Optionally, communication with ground equipment via a working key includes: acquiring communication data, encrypting the communication data using the working key to generate encrypted data, and sending the encrypted data to the ground equipment; and having the ground equipment decrypt the encrypted data using the working key to generate communication data, so as to conduct communication based on the communication data.

[0015] Optionally, the method also includes: generating a prompt message based on the confirmation message when the confirmation message does not meet the preset conditions; and triggering an alarm in a specified manner based on the prompt message.

[0016] According to another aspect of the present invention, a vehicle-to-ground communication device is provided, the device comprising:

[0017] The working key determination module is used to obtain the preset master key and vehicle operation-related information, and determine the working key based on the preset master key and operation-related information. The working key is either a backup key or a session key.

[0018] The key sending and confirmation module is used to encrypt the working key with a preset master key to generate working key ciphertext, and send the working key ciphertext to the ground equipment to obtain the confirmation message sent by the ground equipment based on the working key ciphertext, and generate a consistency verification result based on the confirmation message.

[0019] The vehicle-to-ground communication module is used to communicate with ground equipment via a working key when the consistency verification result is successful.

[0020] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0021] At least one processor; and

[0022] A memory communicatively connected to the at least one processor; wherein,

[0023] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to execute a vehicle-to-ground communication method according to any embodiment of the present invention.

[0024] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement a vehicle-to-ground communication method according to any embodiment of the present invention.

[0025] The technical solution of this invention establishes a key distribution center on the basis of vehicle-to-ground wireless communication to realize vehicle-to-ground wireless communication key management. Before each train operation, the train obtains a session key from the key distribution center based on operation-related information and uses the session key for encrypted communication. If the session key is not obtained, a backup key is used for encrypted communication, which improves the reliability of communication and ensures the safety of train operation.

[0026] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0027] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0028] Figure 1 is a flowchart of a vehicle-to-ground communication method according to Embodiment 1 of the present invention;

[0029] Figure 2 is a flowchart of another vehicle-to-ground communication method provided according to Embodiment 1 of the present invention;

[0030] Figure 3 is a flowchart of another vehicle-to-ground communication method provided according to Embodiment 2 of the present invention;

[0031] Figure 4 is a structural schematic diagram of a vehicle-to-ground communication device according to Embodiment 3 of the present invention;

[0032] Figure 5 is a schematic diagram of the structure of an electronic device that implements a vehicle-to-ground communication method according to an embodiment of the present invention. Detailed Implementation

[0033] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0034] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0035] Example 1

[0036] Figure 1 is a flowchart of a vehicle-to-ground communication method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where vehicle-mounted equipment and ground equipment communicate. The method can be executed by a vehicle-to-ground communication device, which can be implemented in hardware and / or software and can be configured in the vehicle-mounted equipment controller. As shown in Figure 1, the method includes:

[0037] S110. Obtain the preset master key and vehicle operation-related information, and determine the working key based on the preset master key and operation-related information, wherein the working key is either a backup key or a session key.

[0038] In this context, "onboard equipment" refers to electronic devices installed on the train to enable intelligent and information-based operation of the vehicle. Onboard equipment can interact and communicate with the outside world via network connections. A pre-set master key is a pre-configured key used to protect the security of vehicle-to-ground communication. Vehicle operation-related information may include the vehicle's current operating route and the device number of the ground equipment. Ground equipment refers to the ground communication equipment corresponding to the onboard equipment, used for communication and interaction with it. Ground equipment may include base stations, servers, and control consoles, which can transmit data and communicate with the onboard equipment via wireless communication technology. The main function of the ground equipment is to receive and send information from the onboard equipment, and to process and analyze this information to achieve vehicle monitoring and management. The working key can be a backup key or a session key, depending on the communication status of the onboard equipment.

[0039] Figure 2 is a flowchart of a vehicle-to-ground communication method provided in Embodiment 1 of the present invention. Step S110 mainly includes the following steps S111 to S115:

[0040] S111. Obtain the preset master key and vehicle operation-related information.

[0041] The pre-set master key is used by the vehicle-mounted device to apply for the vehicle-to-ground wireless communication session key from the key distribution center. Specifically, it can include a vehicle-mounted pre-set master key and a ground-based pre-set master key.

[0042] Optionally, the following steps are taken: obtaining a preset master key and vehicle operation-related information, including: reading the encrypted master key from the key distribution center through a secure transmission device, decrypting the encrypted master key using a pre-configured encryption algorithm to obtain the preset master key; obtaining the vehicle's current operating route, identifying the ground equipment connected to the vehicle, and identifying the equipment identifier corresponding to the ground equipment; and using the operating route and equipment identifier as operation-related information.

[0043] Specifically, the vehicle-mounted device can obtain a pre-set master key from the key distribution center. The key distribution center can then use secure transmission equipment and a transmission key to encrypt and transmit the pre-set master key. The vehicle-mounted device can decrypt the read encrypted master key using a pre-configured encryption algorithm. Through decryption, the pre-set master key can be obtained. The pre-set master key is a crucial key used to protect vehicle-to-ground communication and is used for subsequent encryption and decryption operations. For example, a user can obtain an encrypted master key encrypted using the SM4 algorithm from the key distribution center using a secure USB drive. The vehicle-mounted device can copy the encrypted master key from the secure USB drive and directly decrypt it using the decryption key corresponding to the SM4 algorithm to obtain the pre-set master key. Similarly, ground equipment can obtain the pre-set master key in the same way. It is important to note that the pre-set master key needs to be updated regularly to ensure the security of communication between the vehicle-mounted device, ground equipment, and the key distribution center.

[0044] Furthermore, after obtaining the pre-set master key, it is necessary to identify the ground equipment connected to the vehicle. This can be achieved through the communication protocol between the vehicle and the ground equipment or other methods. Then, the device identifier corresponding to the ground equipment needs to be determined. The device identifier can be a unique number, identifier, or other form of identification. The vehicle's current operating route also needs to be obtained. This can be obtained through the vehicle's positioning system, sensors, or other data sources. Finally, the obtained vehicle operating route and device identifier can be combined as operational information.

[0045] S112. Generate a backup key application based on the preset master key.

[0046] Specifically, the vehicle-mounted device generates a backup key application based on the preset master key to request a backup key from the key distribution center. The backup key application contains some key-related information, such as the type of backup key requested and its validity period.

[0047] S113. Send the backup key request to the key distribution center to obtain the backup key sent by the key distribution center based on the backup key request.

[0048] Specifically, the generated backup key request is sent to the key distribution center. The key distribution center is the central organization responsible for managing and distributing keys, with functions including full lifecycle management of keys such as generation, storage, distribution, use, backup and recovery, archiving, and destruction. Upon receiving the backup key request, the key distribution center generates a backup key based on the request's requirements and relevant policies, and sends it to the vehicle-mounted device. This backup key can be used for communication or other specific operations in emergency situations.

[0049] It is important to note that after the backup key is used, the on-board equipment must immediately update it with the key distribution center to ensure the security of vehicle-to-ground wireless encrypted communication.

[0050] S114. Encrypt the relevant information for operation using a preset master key to generate a session key application.

[0051] Specifically, in addition to the backup key, a session key also needs to be generated to protect the actual data communication. Based on the route information for this operation, the on-board equipment obtains the equipment identifiers of the route and the ground equipment involved, as operation-related information, and generates a session key application based on the pre-set master key and the operation-related information.

[0052] S115. Send the session key application to the key distribution center and determine the sending time, and determine the working key based on the sending time.

[0053] Optionally, the working key is determined based on the sending time, including: when the sending time reaches a preset time, determining whether a session key has been obtained; if so, using the session key as the working key; otherwise, using the backup key as the working key.

[0054] Specifically, after sending the session key request to the key distribution center, the sending time needs to be determined. The sending time is used to determine the timeliness of the session key request. The vehicle-mounted device continuously monitors the sending time to determine if a preset time has been reached. The preset time can be set by the user in advance; for example, the preset time could be 3 seconds. When 3 seconds have passed, the vehicle-mounted device will determine whether it has successfully obtained the session key. If the session key has been successfully obtained, the vehicle-mounted device will use it as the working key. The session key will be used in subsequent communication processes to encrypt and decrypt vehicle-to-ground wireless communication messages, ensuring data confidentiality and integrity. If the session key is not obtained, it may be due to some reason that the generation or distribution of the session key failed. For example, there may be a communication failure between the vehicle-mounted device and the key distribution center. In this case, the vehicle-mounted device will use a backup key as the working key.

[0055] S120. The working key is encrypted using a preset master key to generate working key ciphertext, and the working key ciphertext is sent to the ground equipment to obtain the confirmation message sent by the ground equipment based on the working key ciphertext, and a consistency verification result is generated based on the confirmation message.

[0056] Specifically, to protect the security of the working key, the onboard equipment uses a preset master key to encrypt it, generating working key ciphertext. This ciphertext is an encrypted working key that can only be decrypted with the correct preset master key. The ciphertext is then sent to the ground equipment. Upon receiving the ciphertext, the ground equipment can decrypt it using the preset master key to obtain the working key.

[0057] Optionally, the working key ciphertext is sent to the ground equipment to obtain an acknowledgment message sent by the ground equipment based on the working key ciphertext, and a consistency verification result is generated based on the acknowledgment message. This includes: sending the working key ciphertext to the ground equipment; decrypting the working key ciphertext using a preset master key through the ground equipment to obtain the working key; generating an acknowledgment message based on the working key through the ground equipment, encrypting the acknowledgment message using the working key to generate an encrypted message, and returning the encrypted message to the vehicle-mounted equipment; decrypting the encrypted message using the working key to generate a decrypted message; and determining whether the decrypted message meets preset conditions. If so, the consistency verification result is determined to be successful; otherwise, the consistency verification result is determined to be unsuccessful.

[0058] In one specific implementation, after receiving the working key ciphertext, the ground equipment decrypts it using a preset master key and verifies the validity of the working key. If the working key is valid, the ground equipment encrypts the confirmation message using the working key to generate an encrypted message and returns the encrypted message to the vehicle-mounted equipment. The vehicle-mounted equipment decrypts the encrypted message using the working key to generate a decrypted message, and then further determines whether the decrypted message meets preset conditions. Only when the conditions are met is the consistency verification result confirmed as passed.

[0059] S130. When the consistency verification result is successful, communicate with the ground equipment through the working key.

[0060] Specifically, when the onboard equipment determines that the consistency verification result is successful, it indicates that the working key has been verified and can be used to communicate securely with the ground equipment.

[0061] Optionally, the method also includes: generating a prompt message based on the confirmation message when the confirmation message does not meet the preset conditions; and triggering an alarm in a specified manner based on the prompt message.

[0062] Specifically, when the onboard device's verification confirmation message does not meet preset conditions, it will generate a corresponding prompt message based on the confirmation message. This prompt message will be presented to the vehicle driver or relevant personnel in a specified manner. That is, based on the generated prompt message, the onboard device will issue an alarm in a specified way. The alarm method can be set according to actual conditions, such as an audible alarm, visual warning, or vibration alert. This ensures that the driver or relevant personnel are promptly aware that the confirmation message does not meet the preset conditions. The purpose of the alarm is to attract the attention of the driver or relevant personnel and prompt them to take appropriate action. Possible actions include checking the status of the onboard device, verifying the accuracy of the confirmation message, taking necessary corrective measures, or contacting technical support personnel. In this way, the onboard device can promptly detect situations where the confirmation message does not meet preset conditions and remind relevant personnel to take appropriate action through an alarm, thereby ensuring the safety and normal operation of the vehicle.

[0063] The technical solution of this invention establishes a key distribution center on the basis of vehicle-to-ground wireless communication to realize vehicle-to-ground wireless communication key management. Before each train operation, the train obtains a session key from the key distribution center based on operation-related information and uses the session key for encrypted communication. If the session key is not obtained, a backup key is used for encrypted communication, which improves the reliability of communication and ensures the safety of train operation.

[0064] Example 2

[0065] Figure 3 is a flowchart of a vehicle-to-ground communication method provided in Embodiment 2 of the present invention. This embodiment adds a specific process for communicating with ground equipment through a working key based on Embodiment 1. The specific content of steps S210-S220 is largely the same as steps S110-S120 in Embodiment 1, and therefore will not be repeated in this embodiment. As shown in Figure 3, the method includes:

[0066] S210. Obtain the preset master key and vehicle operation-related information, and determine the working key based on the preset master key and operation-related information, wherein the working key is either a backup key or a session key.

[0067] Optionally, the following steps are taken: obtaining a preset master key and vehicle operation-related information, including: reading the encrypted master key from a specified address, decrypting the encrypted master key using a pre-configured encryption algorithm to obtain the preset master key; identifying the ground equipment connected to the vehicle and determining the corresponding device identifier; obtaining the vehicle's current operating route and using the operating route and device identifier as operation-related information.

[0068] Optionally, the working key is determined based on a preset master key and operation-related information, including: generating a backup key application based on the preset master key; sending the backup key application to a key distribution center to obtain a backup key sent by the key distribution center based on the backup key application; encrypting operation-related information with the preset master key to generate a session key application; sending the session key application to the key distribution center and determining the sending time, and determining the working key based on the sending time.

[0069] Optionally, the working key is determined based on the sending time, including: when the sending time reaches a preset time, determining whether a session key has been obtained; if so, using the session key as the working key; otherwise, using the backup key as the working key.

[0070] S220. The working key is encrypted using a preset master key to generate working key ciphertext, and the working key ciphertext is sent to the ground equipment to obtain the confirmation message sent by the ground equipment based on the working key ciphertext, and generate a consistency verification result based on the confirmation message.

[0071] Optionally, the working key ciphertext is sent to the ground equipment to obtain the confirmation message sent by the ground equipment based on the working key ciphertext, including: sending the working key ciphertext to the ground equipment; decrypting the working key ciphertext using a preset master key by the ground equipment to obtain the session key; and generating a confirmation message based on the session key by the ground equipment.

[0072] S230. When the consistency verification result is successful, acquire the communication data, encrypt the communication data using the working key to generate encrypted data, and send the encrypted data to the ground equipment.

[0073] Specifically, the train's onboard equipment can acquire communication data through various sensors, monitoring systems, and other means. For example, communication data can include the train's position, speed, status information, and communication content with other devices.

[0074] Furthermore, to ensure the security of communication data, the onboard equipment uses a working key to encrypt the data. The encrypted data exists in ciphertext form, and only ground equipment with the correct working key can decrypt it. Once the onboard equipment has completed encrypting the communication data, it transmits the encrypted data to the ground equipment via a wireless communication link or other suitable transmission method. During transmission, the encrypted data remains encrypted to prevent unauthorized third parties from accessing and deciphering the communication data.

[0075] S240. The ground equipment uses a working key to decrypt the encrypted data to generate communication data, and then uses the communication data to conduct communication.

[0076] Specifically, after receiving encrypted data, the ground equipment decrypts it using the same working key. During decryption, the ground equipment uses the working key to convert the encrypted data back into the original communication data. In this way, the ground equipment can obtain the original communication data transmitted with the vehicle-mounted equipment.

[0077] Furthermore, based on the decrypted communication data, ground equipment can perform various communication operations, such as train monitoring, control, and scheduling. Ground equipment can make corresponding decisions and operations based on the content of the communication data, achieving effective communication and interaction with the onboard equipment. In this way, the communication data between the train's onboard equipment and ground equipment can be protected, preventing unauthorized third parties from obtaining and tampering with the communication content. The use of a working key ensures that only legitimate devices can perform encryption and decryption operations, thereby improving the security and reliability of communication.

[0078] Optionally, the method also includes: generating a prompt message based on the confirmation message when the confirmation message does not meet the preset conditions; and triggering an alarm in a specified manner based on the prompt message.

[0079] The technical solution of this invention establishes a key distribution center on the basis of vehicle-to-ground wireless communication to realize vehicle-to-ground wireless communication key management. Before each train operation, the train obtains a session key from the key distribution center based on operation-related information and uses the session key for encrypted communication. If the session key is not obtained, a backup key is used for encrypted communication, which improves the reliability of communication and ensures the safety of train operation.

[0080] Example 3

[0081] Figure 4 is a schematic diagram of a vehicle-to-ground communication device provided in Embodiment 3 of the present invention. As shown in Figure 4, the device includes: a working key determination module 310, used to obtain a preset master key and vehicle operation-related information, and determine a working key based on the preset master key and operation-related information, wherein the working key is a backup key or a session key;

[0082] The key sending and confirmation module 320 is used to encrypt the working key with a preset master key to generate working key ciphertext, and send the working key ciphertext to the ground equipment to obtain the confirmation message sent by the ground equipment based on the working key ciphertext, and generate a consistency verification result based on the confirmation message.

[0083] The vehicle-to-ground communication module 330 is used to communicate with the ground equipment via a working key when the consistency verification result is successful.

[0084] Optionally, the working key determination module 310 specifically includes: a master key and operation-related information acquisition unit, used to: read the encrypted master key from the key distribution center through a secure transmission device, decrypt the encrypted master key using a pre-configured encryption algorithm to obtain a preset master key; obtain the current operating route of the vehicle, determine the ground equipment connected to the vehicle, and determine the equipment identifier corresponding to the ground equipment; and use the operating route and equipment identifier as operation-related information.

[0085] Optionally, the working key determination module 310 specifically includes: a backup key application generation unit, used to: generate a backup key application based on a preset master key; a backup key acquisition unit, used to: send the backup key application to a key distribution center to obtain a backup key sent by the key distribution center based on the backup key application; a session key application generation unit, used to: encrypt operation-related information using a preset master key to generate a session key application; and a working key determination unit, used to: send the session key application to the key distribution center and determine the sending time, and determine the working key based on the sending time.

[0086] Optionally, the working key determination unit is specifically used to: when the transmission time reaches a preset time, determine whether the session key has been obtained; if so, use the session key as the working key; otherwise, use the backup key as the working key.

[0087] Optionally, the key sending and confirmation module 320 specifically includes: a confirmation message acquisition unit, used for: sending the working key ciphertext to the ground equipment; decrypting the working key ciphertext using a preset master key through the ground equipment to obtain the working key; generating a confirmation message based on the working key through the ground equipment, encrypting the confirmation message using the working key to generate an encrypted message, and returning the encrypted message to the vehicle-mounted equipment; decrypting the encrypted message using the working key to generate a decrypted message; determining whether the decrypted message meets preset conditions, and if so, determining that the consistency verification result is successful; otherwise, determining that the consistency verification result is unsuccessful.

[0088] Optionally, the vehicle-to-ground communication module 330 specifically includes: a vehicle-to-ground communication unit, used to: acquire communication data, encrypt the communication data using a working key to generate encrypted data, and send the encrypted data to the ground equipment; and use the ground equipment to decrypt the encrypted data using a working key to generate communication data, so as to conduct communication based on the communication data.

[0089] Optionally, the device further includes: a confirmation failure alarm module, used to generate a prompt message based on the confirmation message when the confirmation message does not meet preset conditions; and to trigger an alarm in a specified manner based on the prompt message.

[0090] The technical solution of this invention establishes a key distribution center on the basis of vehicle-to-ground wireless communication to realize vehicle-to-ground wireless communication key management. Before each train operation, the train obtains a session key from the key distribution center based on operation-related information and uses the session key for encrypted communication. If the session key is not obtained, a backup key is used for encrypted communication, which improves the reliability of communication and ensures the safety of train operation.

[0091] The vehicle-to-ground communication device provided in this embodiment of the invention can execute a vehicle-to-ground communication method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of executing the method.

[0092] Example 4

[0093] Figure 5 illustrates a schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0094] As shown in Figure 5, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer programs stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0095] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0096] Processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, central processing unit (CPU), graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as a vehicle-to-ground communication method. That is: obtaining a preset master key and vehicle operation-related information; determining a working key based on the preset master key and operation-related information, wherein the working key is a backup key or a session key; encrypting the working key with the preset master key to generate working key ciphertext, and sending the working key ciphertext to the ground equipment to obtain an acknowledgment message sent by the ground equipment based on the working key ciphertext; generating a consistency verification result based on the acknowledgment message; when the consistency verification result is successful, communicating with the ground equipment through the working key.

[0097] In some embodiments, a vehicle-to-ground communication method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the vehicle-to-ground communication method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform a vehicle-to-ground communication method by any other suitable means (e.g., by means of firmware).

[0098] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0099] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0100] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0101] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0102] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0103] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0104] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0105] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A vehicle-to-ground communication method, characterized in that, Applications in vehicle-mounted equipment, including: Obtain a preset master key and vehicle operation-related information, and determine a working key based on the preset master key and the operation-related information, wherein the working key is a backup key or a session key; The working key is encrypted using the preset master key to generate working key ciphertext, and the working key ciphertext is sent to the ground equipment to obtain the confirmation message sent by the ground equipment based on the working key ciphertext, and generate a consistency verification result based on the confirmation message. When the consistency verification result is successful, communication is established with the ground equipment through the working key.

2. The method according to claim 1, characterized in that, The acquisition of the preset master key and vehicle operation-related information includes: The encrypted master key is read from the key distribution center through a secure transmission device, and the encrypted master key is decrypted using a pre-configured encryption algorithm to obtain the preset master key; Obtain the current operating route of the vehicle, identify the ground equipment connected to the vehicle, and determine the equipment identifier corresponding to the ground equipment; The operating line and the equipment identifier are used as the operating-related information.

3. The method according to claim 1, characterized in that, The process of determining the working key based on the preset master key and the operation-related information includes: A backup key application is generated based on the preset master key; The backup key request is sent to the key distribution center to obtain the backup key sent by the key distribution center based on the backup key request; The operation-related information is encrypted using the preset master key to generate a session key application; The session key request is sent to the key distribution center and the sending time is determined. The working key is determined based on the sending time.

4. The method according to claim 3, characterized in that, The step of determining the working key based on the sending time includes: When the sending time reaches the preset time, it is determined whether the session key has been obtained. If so, the session key is used as the working key. Otherwise, the backup key shall be used as the working key.

5. The method according to claim 1, characterized in that, The step of sending the working key ciphertext to the ground equipment, obtaining the acknowledgment message sent by the ground equipment based on the working key ciphertext, and generating a consistency verification result based on the acknowledgment message includes: The working key ciphertext is sent to the ground equipment; The working key is obtained by decrypting the ciphertext of the working key using a preset master key through the ground equipment; The ground equipment generates a confirmation message based on the working key, encrypts the confirmation message using the working key to generate an encrypted message, and returns the encrypted message to the vehicle-mounted equipment. The encrypted message is decrypted using the working key to generate a decrypted message; Determine whether the decrypted message meets the preset conditions; if so, determine that the consistency verification result is successful. Otherwise, the consistency verification result is determined to be a failure.

6. The method according to claim 1, characterized in that, The communication with the ground equipment via the working key includes: The system acquires communication data, encrypts the communication data using the working key to generate encrypted data, and sends the encrypted data to the ground equipment. The ground equipment uses a working key to decrypt the encrypted data to generate communication data, and then uses this communication data to conduct communication.

7. The method according to claim 1, characterized in that, The method further includes: When the confirmation message does not meet the preset conditions, a prompt message is generated based on the confirmation message; An alarm will be triggered in the specified manner according to the provided prompt.

8. A vehicle-to-ground communication device, characterized in that, include: The working key determination module is used to obtain a preset master key and vehicle operation-related information, and determine a working key based on the preset master key and the operation-related information, wherein the working key is a backup key or a session key; The key sending and confirmation module is used to encrypt the working key with the preset master key to generate working key ciphertext, and send the working key ciphertext to the ground equipment, so as to obtain the confirmation message sent by the ground equipment based on the working key ciphertext, and generate a consistency verification result based on the confirmation message; The vehicle-to-ground communication module is used to communicate with the ground equipment through the working key when the consistency verification result is successful.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-7.

10. A computer storage medium, characterized in that, The computer storage medium stores computer instructions that are used to cause a processor to execute the method of any one of claims 1-7.

Citation Information

Patent Citations

  • Message encryption method and device, message decryption method and device and storage medium

    CN115277219A

  • Internet of vehicles information encryption method and device, computer equipment and storage medium

    CN115766244A

  • Session key generation method, communication network system, storage medium and electronic equipment

    CN116055033A

  • Method, gateway and system for protecting communication data through quantum encryption

    CN117640084A

  • Unmanned aerial vehicle encryption communication method and device based on national cryptographic algorithm, and medium

    CN117715027A