System and method for monitoring secure data network of railway train control system, device, and medium
Patent Information
- Application Number
- PCT/CN2025/129296
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-20
- Filing Date
- 2025-10-22
- Publication Date
- 2026-08-27
Smart Images

Figure CN2025129296_27082026_PF_FP_ABST
Abstract
Description
Railway train control system safety data network monitoring system, methods, equipment and media Technical Field
[0001] This application relates to the field of rail transit technology, and in particular to a railway train control system safety data network monitoring system, method, equipment and medium. Background Technology
[0002] As a critical facility of the railway train control system, the safety data network currently relies primarily on the network management system for operation and maintenance. This system maintains devices within the safety data network, such as switches, firewalls, and network management servers, including network topology, performance management, alarm management, security management, and log management, providing good support for the safety maintenance and fault diagnosis of the safety data network. However, the safety data network serves as the carrier for secure communication between safety devices within the train control system (Train Control Center TCC, interlocking, RBC, and TSRS). The network carries a large amount of data, and the interaction cycles between devices are very short, typically at the millisecond level. Any abnormal communication data (packet merging, packet loss, packet errors, etc.) can cause various communication anomalies in the communication sessions between devices. The existing network management system cannot accurately pinpoint the cause of these anomalies, nor can it completely record the communication data, increasing the difficulty for users and equipment manufacturers in analyzing faults. Summary of the Invention
[0003] To address the aforementioned issues, this application provides a railway train control system safety data network monitoring system, method, equipment, and medium, which features high sampling accuracy, strong security, and precise anomaly location. Furthermore, through intelligent analysis, it enables the transformation of safety data network operation and maintenance from fault repair to condition-based maintenance.
[0004] To achieve the above objectives, this application adopts the following technical solution:
[0005] In a first aspect, this application also provides a railway train control system safety data network monitoring system, including channel monitoring equipment and central maintenance equipment. The channel monitoring equipment is deployed on the station equipment and / or central equipment side of the railway train control system safety data network, and the channel monitoring equipment and the central maintenance equipment are independently networked to form a supervisory data network.
[0006] The channel monitoring equipment is used to collect channel communication data of station equipment and / or central equipment in the railway train control system safety data network in real time; it is also used to send the collected channel communication data to the central maintenance equipment through the monitoring data network.
[0007] The central maintenance equipment is used to receive real-time collected channel communication data, perform multi-dimensional processing on the channel communication data, and determine the results of anomaly analysis of the channel communication data.
[0008] Furthermore, the channel monitoring equipment is also used to collect channel communication data of railway train control system safety data network station equipment and / or central equipment by combining fiber optic split monitoring, Ethernet TAP monitoring, and port mirroring monitoring.
[0009] Furthermore, the central maintenance equipment is also used to receive real-time collected channel communication data, and to perform channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly check analysis on the channel communication data to determine the channel communication data anomalies of the railway train control system safety data network.
[0010] Furthermore, the central maintenance equipment includes network topology units, data analysis units, and channel warning units;
[0011] The network topology unit is used to receive real-time collected channel communication data and to parse and store the channel communication data.
[0012] The data analysis unit is used to perform channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly check analysis on channel communication data to determine the anomaly analysis results of channel communication data.
[0013] The channel warning unit is used to generate abnormal alarms based on the results of abnormal analysis of channel communication data and to display the abnormal alarms in a visual manner.
[0014] Furthermore, the network topology unit is also used to visualize the main line network topology of the secure data network, displaying channel session traffic ranking, channel IP traffic ranking, and channel port traffic ranking in list form.
[0015] Furthermore, the data analysis unit includes: a channel traffic analysis module, an RTT time anomaly early warning analysis module, and a communication connection group anomaly check analysis module;
[0016] The channel traffic analysis module is used to determine the anomaly analysis results of channel communication data based on the time series characteristics of the channel communication data and by using a real-time active anomaly detection algorithm.
[0017] The RTT time anomaly early warning and analysis module is used to determine the anomaly analysis results of the channel communication data based on the RTT time of the channel communication data and adopts an adaptive retransmission algorithm.
[0018] The communication connection group anomaly detection and analysis module is used to determine the anomaly analysis results of the channel communication data based on the IP information in the network layer IPv4 protocol messages in the channel communication data.
[0019] Furthermore, the channel warning unit is also used to receive real-time collected device alarm messages and perform incremental processing on the device alarm messages.
[0020] Secondly, this application provides a method for monitoring the safety data network of a railway train control system, including:
[0021] The channel monitoring equipment collects channel communication data of station equipment and / or central equipment in the railway train control system safety data network in real time, and sends the collected channel communication data to the central maintenance equipment through the supervision data network;
[0022] The central maintenance equipment receives real-time collected channel communication data and performs multi-dimensional processing on the channel communication data to determine the results of anomaly analysis.
[0023] Furthermore, the channel monitoring equipment adopts a combination of fiber optic split monitoring, Ethernet TAP monitoring, and port mirroring monitoring to collect channel communication data of railway train control system safety data network station equipment and / or central equipment in real time.
[0024] Furthermore, the central maintenance equipment receives real-time collected channel communication data and performs channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly check analysis on the channel communication data to determine the channel communication data anomalies of the railway train control system's safety data network.
[0025] Thirdly, this application also provides an electronic device, including: a processor and a memory;
[0026] The processor is coupled with the memory;
[0027] The processor is used to read and execute programs or instructions stored in the memory, causing the device to perform the method as described in the second aspect.
[0028] Fourthly, this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method as described in the second aspect.
[0029] The technical solution provided in this application has at least the following technical effects or advantages:
[0030] This application's solution deploys channel monitoring equipment within the railway train control system's safety data network at the station and / or central equipment levels, and independently networks it with the central maintenance equipment to form a supervisory data network for data collection. This achieves physical isolation from the main line network of the safety data network, ensuring strong security. Data collection is achieved through a combination of fiber optic splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring. Based on the characteristics of the different hardware devices used in these three methods, the solution can meet the needs of different application scenarios within the safety data network and ensure the sampling accuracy of the channel communication data collected. The central maintenance equipment receives the channel communication data and performs intelligent analyses such as channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly check analysis. This allows for precise identification of anomalies in the channel communication data, helping to promptly detect potential faults in the safety data network and thus enabling a shift in safety data network maintenance from fault repair to condition-based maintenance.
[0031] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures pointed out in the description, claims and drawings. Attached Figure Description
[0032] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0033] Figure 1 is a schematic diagram of the structure of a railway train control system safety data network monitoring system according to an embodiment of this application;
[0034] Figure 2 is a schematic diagram of the structure of a railway train control system safety data network monitoring system connected to the railway train control system safety data network in an embodiment of this application;
[0035] Figure 3 is a schematic diagram of the data processing flow of the network topology unit of the central maintenance device in this application;
[0036] Figure 4 is a flowchart illustrating the real-time active anomaly detection algorithm in the embodiments of this application;
[0037] Figure 5 is a schematic diagram of the adaptive retransmission algorithm in the embodiments of this application;
[0038] Figure 6 is a schematic diagram of the communication connection group anomaly check in an embodiment of this application;
[0039] Figure 7 is a flowchart illustrating a railway train control system safety data network monitoring method provided in an embodiment of this application;
[0040] Figure 8 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0041] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0042] Figure 1 is a schematic diagram of the structure of a railway train control system safety data network monitoring system according to an embodiment of this application; Figure 2 is a schematic diagram of the structure of a railway train control system safety data network monitoring system connected in series with the railway train control system safety data network according to an embodiment of this application.
[0043] As shown in Figures 1 and 2, the railway train control system safety data network monitoring system proposed in this application includes channel monitoring equipment and central maintenance equipment. The structure within the railway train control system safety data network is shown in Figure 1. The channel monitoring equipment is deployed on the side of station equipment (TCC or interlocking) and / or central equipment (RBC or TSRS) in the railway train control system safety data network, and is used to collect channel communication data of station equipment and / or central equipment in the railway train control system safety data network in real time. The channel monitoring equipment and the central maintenance equipment are independently networked, called a supervisory data network, which does not affect the normal communication of the main line of the railway train control system safety data network. The channel monitoring equipment sends the collected channel communication data to the central maintenance equipment through the supervisory data network. The central maintenance equipment receives the real-time collected channel communication data and performs multi-dimensional processing and analysis of the channel communication data to determine the results of anomaly analysis. Channel communication data refers to the communication data transmitted between devices in the railway train control system safety data network, including: channel physical status, communication service data, equipment alarm information, etc. The physical status of the channel includes physical quantities such as data flow, channel status, and optical power. Data flow refers to the number of bytes of communication data monitored per second (KB / s or MB / s); channel status refers to the communication status of the main line channel of the safety data network, which can be defined as an enumerated quantity, divided into normal, abnormal, and undetected, with abnormalities further divided into level one, level two, and level three. By statistically analyzing the multiple physical quantities included in the channel physical status, and combining them with the number of erroneous data packets and the number of dropped data packets over a period of time, the communication capability and communication quality of the channels within the railway train control system safety data network can be evaluated. Communication service data refers to the service interaction data between communication devices within the railway train control system safety data network, such as temporary speed limit commands from TSRS devices in frame format conforming to the RSSP safety protocol. For ease of description of the technical solution of this application, the railway train control system safety data network in this application can also be referred to as the safety data network.
[0044] Depending on the method of access to the safety data network, the channel monitoring equipment employs three monitoring schemes to collect channel communication data of station equipment and / or central equipment in the railway train control system's safety data network in real time, ensuring the sampling accuracy of the collected channel communication data. The three monitoring schemes include: fiber optic splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring.
[0045] Fiber Optic Splitting Monitoring: Within the ring network of the safety data network, the intercom units are connected via optical fiber. A splitter is added on the side closest to the ring network to monitor physical quantities such as optical power within the safety data network. As shown in Figure 1, a splitter is connected in series within the safety data network communication line on the side closest to the station (TCC or interlocking) and / or central equipment (RBC or TSRS). A monitoring interface is then created through the splitter to connect to the channel monitoring equipment, enabling monitoring of physical quantities such as optical power within the safety data network. As a passive device, the splitter has a low failure rate and minimal impact on the normal communication of the main line of the safety data network. It also provides physical isolation between the main lines of the supervisory data network and the safety data network, ensuring strong security.
[0046] Ethernet TAP Monitoring: An Ethernet TAP device is added to the side of the safety data network closest to the ring network to fully monitor the channel communication data of the safety data network. As shown in Figure 1, the Ethernet TAP device is connected in series with the signal safety data network on the side closest to the station equipment (TCC or interlocking) and / or central equipment (RBC or TSRS). A monitoring interface is led out from the M port of the TAP device to connect to the channel monitoring device, realizing complete monitoring of the channel communication data of the safety data network. The TAP device can monitor devices within the local area network without filtering or discarding monitoring information, thus achieving complete monitoring of the channel communication data of the safety data network.
[0047] Port mirroring monitoring: On the side of the security data network closest to the ring network, port mirroring is used on existing switches within the security data network to forward data traffic from critical ports of the security network to the mirror port. By monitoring the mirror port, the channel communication data of the security data network can be monitored. As shown in Figure 1, on the side closest to the station equipment (TCC or interlocking) and / or the central equipment (RBC or TSRS), an existing switch within the security data network is used, with one of its spare ports serving as the mirror port. Data traffic from critical ports of the security data network is forwarded to the mirror port, which is then connected to a channel monitoring device to monitor the communication service data of the security data network. Port mirroring refers to forwarding data traffic from one or more source ports to a designated port on a switch to monitor network data. The designated port is called the "mirror port" or "destination port." Industrial switches typically have network data processing units and management processing units. Port mirroring is generally performed through the management processing unit, so enabling port mirroring will not affect the normal operation of the current switch.
[0048] The three monitoring schemes employ different hardware devices to collect channel communication data from the security data network. The characteristics of these different hardware devices can meet the needs of various application scenarios within the security data network and ensure the sampling accuracy of the collected channel communication data, while not affecting the communication quality of the main channel of the security data network. The hardware devices use dedicated high-time-accuracy acquisition chips, which can further meet the millisecond-level event resolution requirements of the security data network. The acquisition card and its driver software in the channel monitoring equipment convert the physical signals collected by the hardware into digital signals, facilitating processing by computer software. The converted digital signals are then used as channel communication data for the security data network and transmitted to the central maintenance equipment through the supervisory data network.
[0049] After establishing a connection with the channel monitoring equipment, the central maintenance equipment performs multi-dimensional processing on the channel communication data of station equipment and / or central equipment in the railway train control system safety data network, which is collected in real time by the channel monitoring equipment. This multi-dimensional processing includes real-time data reception, protocol parsing, data storage, data analysis, and anomaly warnings. The central maintenance equipment includes a network topology unit, a data analysis unit, and a channel warning unit. The network topology unit receives the real-time collected channel communication data, parses and stores the data, and also visualizes the main line network topology of the safety data network, displaying information such as channel session traffic ranking, channel IP traffic ranking, and channel port traffic ranking in a list format. The data analysis unit performs channel traffic analysis, RTT time anomaly warning analysis, and communication connection group anomaly check analysis on the channel communication data to determine the results of the channel communication data anomaly analysis. The channel alarm unit generates anomaly alarms based on the channel communication data anomaly analysis results and displays the alarms visually.
[0050] The network topology units of the channel monitoring equipment and the central maintenance equipment interact with each other via a publish-subscribe mechanism (e.g., MQTT). The core of publish-subscribe is topic definition; based on pre-defined topics, the subscriber only accepts data related to those topics, making it a reliable remote communication protocol. The channel monitoring equipment performs preliminary protocol analysis on the real-time monitored channel communication data, marking different protocol data (identifying the protocol type) and placing them into relevant topics. The central maintenance equipment processes messages for different topics based on the subscribed topics (first determining the topic type, then distributing them to different processing programs). Upon receiving messages for different topics, the central maintenance equipment distributes them to different processing units. At this stage, the received channel communication data is raw and unprocessed (generally byte arrays), unsuitable for direct analysis and interface display. Therefore, the received channel communication data undergoes a data structure conversion based on the Railway Signal Safety Communication Protocol (RSSP), specifically a layered parsing process based on the RSSP protocol. The channel communication data primarily follows the Railway Signal Safety Communication Protocols RSSP-I and RSSP-II. The parsing process of the RSSP security protocol depends on the monitored data, unlike the sequential execution of typical application programs; it is an event-driven process. Therefore, the parsing of the aforementioned channel communication data conforming to the security protocol employs a finite state machine combined with a timer. The finite state machine includes several attributes: the current state (the current state of the state machine), the event (also called the condition), the action (the action executed after the condition is met. After the action is executed, the machine can transition to a new state or remain in the original state. Actions are not mandatory; when the condition is met, no action can be executed, and the machine can directly transition to a new state), and the next state (the new state to which the machine will transition after the condition is met. The "next state" is relative to the "current state," and once activated, it becomes the new "current state"). Timers are a frequently used technique in the field of RSSP security protocol communication technology, used to handle message timeouts during communication. During communication, under normal circumstances, after a data frame carrying information is sent, the receiver needs to send an acknowledgment message back to the sender to let the sender know that the data frame has been successfully received before continuing to send subsequent data frames. This is to ensure that the receiver receives messages in order and completely. However, if a message is not successfully received by the receiver (e.g., the data frame is lost during transmission, or garbled characters occur during transmission) or the receiver's acknowledgment message fails to reach the sender, without a time limit, the sender will wait indefinitely, causing the entire interaction process to be blocked.The timer's duration is usually pre-set (this may vary slightly depending on the device or manufacturer). If no acknowledgment is received within the timer's interval since the last data frame was sent, the previous data frame will be retransmitted until an acknowledgment is received or the retransmission limit is exceeded (at which point the connection between the two parties will be closed). The processing method, which combines a finite state machine with a timer, includes: layered parsing of each frame of received channel communication data; that is, parsing each frame of received channel communication data layer by layer based on the application layer, security layer, transport layer, network layer, link layer, and physical layer, generating message type events for the state machine within each layer's protocol; and processing the state machine within each layer's protocol in the order of physical layer - link layer - network layer - transport layer - security layer - application layer - security layer - transport layer - network layer - link layer - physical layer, allowing the state machine to transition from the current state to the next state, thereby obtaining the parsed channel communication data. When processing the state machine, it iterates through all current timer states and checks for timeouts. If a timeout occurs, a timeout event is generated, triggering message retransmission. In other words, if the acknowledgment time of a received message exceeds the set timeout period, a timeout event is generated, triggering the message retransmission mechanism.
[0051] The above-described layered parsing of channel communication data based on the RSSP (Railway Signal Safety Communication Protocol) protocol can be achieved by using Wireshark (a network protocol analysis tool) to capture data packets during network transmission and save them as pcap files. Wireshark performs detailed parsing on each captured data packet to obtain the corresponding protocol hierarchy and protocol field values. The parsed channel communication data is then depacketized, reassembled, and verified. Finally, the processed channel communication data is stored in a database. Due to the large volume of data, a snowflake algorithm is used to ensure data uniqueness when storing the channel communication data. The database used in this application can be a Redis database, or other high-performance key-value store databases or relational database repositories. Specific methods for storing data in the database are conventional techniques for those skilled in the art and will not be elaborated upon.
[0052] Figure 3 is a schematic diagram of the data processing flow of the network topology unit of the central maintenance device in this application embodiment.
[0053] As shown in Figure 3, before performing layered parsing of the channel communication data, the network topology unit of the central maintenance equipment also performs multi-dimensional processing such as channel session traffic ranking, channel IP traffic ranking, and channel port traffic ranking to obtain multi-dimensional ranking data of the channel communication data.
[0054] Channel session traffic ranking processing includes:
[0055] Step 1: Create a 5-tuple (source IP, source port, destination IP, destination port, protocol) traffic buffer;
[0056] Step 2: Set the cache to transfer data to the Redis database every second, and count the number of packets and the total number of bytes.
[0057] Step 3: Sort all quintuples according to the number of bytes counted per second, and arrange them from largest to smallest.
[0058] Step 4: Each time statistics are collected, it is checked whether a stop timer is set for the current line. The first time it is checked, there will be no stop timer. At this time, a new stop timer will be set. After that, each time statistics are collected, it is checked whether the timer is triggered (triggered means that the stop timer's countdown time meets the specified stop time). If triggered, the traffic buffer is cleared, the previous stop timer is cleared, and a new stop timer is set.
[0059] Step 5: Repeat steps 2-4 to obtain the channel session traffic ranking data of the channel communication data.
[0060] Channel IP traffic ranking processing includes:
[0061] Step 1: Create a channel IP traffic buffer;
[0062] Step 2: Set the cache to transfer data to the Redis database every second, and count the number of packets and the total number of bytes.
[0063] Step 3: Sort all channel IPs according to the number of bytes counted per second, and arrange them from largest to smallest.
[0064] Step 4: Each time statistics are collected, it is checked whether a stop timer is set for the current line. The first time it is checked, there will be no stop timer. At this time, a new stop timer will be set. After that, each time statistics are collected, it is checked whether the timer is triggered (triggered means that the stop timer's countdown time meets the specified stop time). If triggered, the traffic buffer is cleared, the previous stop timer is cleared, and a new stop timer is set.
[0065] Step 5: Repeat steps 2-4 to obtain the channel IP traffic ranking data of the channel communication data.
[0066] Channel port traffic ranking processing includes:
[0067] Step 1: Create a channel port traffic buffer;
[0068] Step 2: Set the cache to transfer data to the Redis database every second, and count the number of packets and the total number of bytes.
[0069] Step 3: Sort all channel ports according to the number of bytes counted per second, and arrange them from largest to smallest.
[0070] Step 4: Each time statistics are collected, it is checked whether a stop timer is set for the current line. The first time it is checked, there will be no stop timer. At this time, a new stop timer will be set. After that, each time statistics are collected, it is checked whether the timer is triggered (triggered means that the stop timer's countdown time meets the specified stop time). If triggered, the traffic buffer is cleared, the previous stop timer is cleared, and a new stop timer is set.
[0071] Step 5: Repeat steps 2-4 to obtain the channel port traffic ranking data for channel communication data.
[0072] The network topology unit of the central maintenance equipment analyzes and logs the stored channel communication data, and reconstructs the interaction process according to the business logic interaction logic and the communication sequence of the channel communication data. It also displays the network topology diagram of the main line of the security data network in a visual way. Based on the multi-dimensional ranking data of the obtained channel communication data, it displays the corresponding ranking information in the form of a list, namely, channel session traffic ranking, channel IP traffic ranking, channel port traffic ranking, etc.
[0073] The data analysis unit of the central maintenance equipment performs channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly check analysis on the monitored channel communication data to determine the channel communication data anomaly analysis results; the channel communication data anomaly analysis results can be presented in a visual way.
[0074] Channel traffic analysis:
[0075] Based on the time-series characteristics of the acquired channel communication data, a real-time active anomaly detection algorithm is used to determine the anomaly analysis results. The real-time active anomaly detection algorithm consists of three stages: a buffering stage, a training stage, and a verification stage. The buffering stage refers to the period from the start of the real-time active anomaly detection algorithm until the set buffering time length. The training stage refers to the stage after the buffering stage, where the channel communication data sequence corresponding to the specified training time length acquired in the buffering stage is used as the channel communication data training set for the machine learning model to train the model and predict the channel communication data at the next time step. The verification stage refers to the stage after the training stage, where anomalies are detected in the real-time channel communication data acquired at the next time step.
[0076] Specifically, as shown in Figure 4, during the buffering stage, initialize the model parameters and the buffering time length of a machine learning model (such as a Long Short-Term Memory (LSTM) model); since the number of channel communication data obtained at the beginning of the active anomaly detection algorithm does not meet the minimum dataset size for training and model training cannot be performed, during the stage from the start of the real-time active anomaly detection algorithm to the set buffering time length, continuously obtain channel communication data and save the channel communication data. After the buffering stage ends, during the training stage, obtain the channel communication data sequence corresponding to the specified training time length as the channel communication data training set for the machine learning model. The specified training time length is usually the same as the buffering time length. Use the channel communication data training set to train the machine learning model. During the training process, introduce an evaluation metric - Average Absolute Relative Error (AARE) that quantifies the difference between the real-time channel communication data and the predicted channel communication data at the same moment. Each time real-time channel communication data is obtained, train the machine learning model. After each training, predict the channel communication data for the next moment, obtain the predicted channel communication data corresponding to the next moment, and cache the predicted channel communication data until the real-time channel communication data for the next moment is obtained, then calculate and save the AARE value of the real-time channel communication data and the predicted channel communication data. After the training stage ends, during the verification stage, adopt a dual-strategy anomaly detection mechanism with secondary judgment to determine the channel traffic anomaly analysis result; the dual-strategy anomaly detection mechanism with secondary judgment includes a first detection mechanism and a second detection mechanism; the first detection mechanism includes: when obtaining the real-time channel communication data, calculate the first difference evaluation metric AARE of the difference between the real-time channel communication data at the current moment t and the corresponding predicted channel communication data t ; calculate the mean and standard deviation of the difference metrics of the difference between the channel communication data sequence from the start of the training stage to the current moment t and the corresponding predicted channel communication data, and according to the 3-σ criterion in statistics, determine the anomaly threshold thd1 of the difference evaluation metric of the difference between the real-time channel communication data at the current moment t and the corresponding predicted channel communication data; compare the first difference evaluation metric AARE t at the current moment t with the anomaly threshold thd1 of the difference evaluation metric. If AARE t < thd1, the real-time channel communication data at the current moment t is normal data; if AARE t ≥ thd1, use the channel communication data sequence during the nearest training time length at the current moment t as the training set to retrain the machine learning model, then predict the real-time channel communication data at the current moment t, and recalculate the second difference evaluation metric AARE' of the difference between the real-time channel communication data at the current moment t and the corresponding predicted channel communication datat The second difference evaluation index AARE′ at the current time t t Compared with the anomaly threshold thd1 of the difference evaluation index, if AARE′ t If the difference between the real-time channel communication data at time t is greater than or equal to thd1, then the real-time channel communication data at the current time t is considered abnormal data. The second detection mechanism is similar to the first, except that in the second mechanism, when determining the abnormal threshold thd1 for the difference evaluation index between the real-time channel communication data at the current time t and the corresponding predicted channel communication data, both the channel communication data sequence used from the start of the training phase to the current time t and the corresponding predicted channel communication data are considered normal data. The above channel traffic analysis results can be displayed visually.
[0077] RTT Time Anomaly Warning Analysis:
[0078] Based on the RTT (Relative Tolerance Time) of channel communication data, an adaptive retransmission algorithm is used to determine the anomaly analysis results of channel communication data. In a secure data network, when secure devices communicate with each other, the transmission time of channel communication data in the network is called the RTT. The time elapsed between the sending device sending data and the receiving device responding or replying is called the RTT. Because communication between secure devices faces a complex data network, the RTT is variable. The adaptive retransmission algorithm updates the estimated RTT of the channel communication data in real time and compares this estimated RTT with a set threshold to determine the anomaly analysis results of the channel communication data's RTT. Figure 5 is a schematic flowchart of the adaptive retransmission algorithm in an embodiment of this application.
[0079] Specifically, as shown in Figure 5, when the adaptive retransmission algorithm starts executing, it initializes the parameter α for calculating the estimated RTT time of the channel communication data. This parameter is a smoothing factor, typically ranging from 0 to 1, and can be set to 0.125. It then specifies the channel to be analyzed, the target device IP, and the source device IP. From the received channel communication data, it extracts the transmit / receive data pairs between the target device IP and the source device IP and calculates the RTT time of these pairs. If this is the first time the RTT time of a transmit / receive data pair is calculated, it is recorded as SampleRTT and used as the estimated RTT time of the channel communication data (EstimatedRTT). If this is not the first time the RTT time of a transmit / receive data pair is calculated... For time-related calculations, the estimated RTT time of the channel communication data is recalculated by combining the RTT time of the first calculation of the transmitted and received data pair, the estimated RTT time of the channel communication data (EstimatedRTT), and the parameter α used in the estimation. This estimated RTT time is then compared to a set threshold. If it exceeds the threshold, the RTT time of the channel communication data is considered abnormal; otherwise, it is considered normal. This process is repeated to calculate the estimated RTT time of newly received channel communication data, thus identifying any abnormalities. An anomaly alarm is triggered when the RTT time of the channel communication data is abnormal.
[0080] Communication connection group anomaly check and analysis:
[0081] The communication connection group of the safety data network refers to two independent ring networks, divided into a left ring network and a right ring network. The interface IP addresses of the application devices in both ring networks are configured such that the left ring network uses odd-numbered network segments, and the right ring network uses even-numbered network segments. Each channel monitoring device in the safety data network monitors only one ring network. The IP network segment of this ring network is pre-set. The source and destination IP addresses carried in the network layer IPv4 protocol messages in the channel communication data monitored in real time by the channel monitoring device must be within the IP network segment of the ring network and comply with the standard "Railway Signal Safety Data Network (TB / T 3547)". The two ring networks are physically isolated, and the IP addresses used by the safety devices in the two networks are generally not in the same network segment. Messages sent from other network segments should not appear in an independent ring network. To prevent concatenation of ring networks that could lead to message chaos in the safety data network, anomaly checks are performed on the communication connection group. The network layer data stored after real-time protocol parsing of channel communication data is acquired. Based on the provisions of the "Railway Signal Safety Data Network (TB / T 3547)" standard, the IP information in the network layer IPv4 protocol is judged to determine whether there is a series anomaly in the independent ring network, and thus determine the channel communication data anomaly of the safety data network. Figure 6 is a schematic diagram of the communication connection group anomaly check in an embodiment of this application.
[0082] Specifically, as shown in Figure 6, the system acquires the network layer data stored after protocol parsing of the channel communication data in real time; it retrieves the source IP address and destination IP address from the IPv4 protocol message structure from the network layer data; it compares whether the network segment where the IP address is located in the IPv4 protocol message structure is the same as the network segment of the ring network where the security device is located. If they are different, it determines whether there is a series anomaly in the independent ring network, and then determines that the channel communication data of the security data network is abnormal, and provides a prompt for the anomaly; the above steps are executed repeatedly to perform communication connection group anomaly check and analysis on the newly received channel communication data.
[0083] The channel alarm unit of the central maintenance equipment generates abnormal alarms based on the above-mentioned abnormal analysis results of channel communication data and displays the abnormal alarms in a visual manner.
[0084] The channel monitoring equipment and the channel alarm unit of the central maintenance equipment interact with each other through subscription and publication (such as MQTT). The channel monitoring equipment monitors the station (TCC or interlocking) and / or central equipment in real time, identifies anomalies and generates equipment alarm messages, and publishes the identified equipment alarm messages as incremental alarm information. The channel alarm unit of the central maintenance equipment subscribes to the incremental alarm information published by the channel monitoring equipment and performs incremental processing on the equipment alarm messages.
[0085] Specifically, the channel alarm unit of the central maintenance equipment subscribes to incremental alarm information released by the channel monitoring equipment and obtains the channel monitoring equipment ID from the incremental alarm information; it then retrieves a pre-stored set of all channel monitoring equipment IDs and determines whether the set contains the channel monitoring equipment ID from the incremental alarm information. If it does, the process ends and the incremental alarm information is not processed; if it does, it determines whether the incremental alarm information is a new alarm or an alarm recovery based on the recovery time in the incremental alarm information; if the recovery time in the incremental alarm information is empty, the incremental alarm information is a new alarm, and the preset alarm filtering rule table in the database is queried, and the incremental alarm is processed accordingly. The system retrieves the corresponding alarm filtering rule set from the channel monitoring device ID in the information, polls the rule set, and masks incremental alarm information based on the alarm occurrence time and alarm type in the incremental alarm information. If a rule is matched during the polling, the incremental alarm information is masked and not processed, i.e., it is not written to the database or displayed on the front-end interface. If no rule is matched during the polling, the system checks the database for the existence of the incremental alarm information based on the channel monitoring device ID in the incremental alarm information. If it exists, the same alarm is displayed; otherwise, an alarm is displayed, and the incremental alarm information is written to the database. If the recovery time in the incremental alarm information is not empty, the incremental alarm information is considered alarm recovered. The system checks the database for the existence of the incremental alarm information based on the channel monitoring device ID in the incremental alarm information. If it exists, the alarm status of the corresponding incremental alarm information in the database is updated to recovered; otherwise, no processing is performed.
[0086] The channel alarm unit of the central maintenance equipment can query historical alarm information using criteria such as line code, station code, equipment ID, alarm type, alarm level, alarm status, and time from incremental alarm information. This information is then displayed on a visual front-end interface. Query criteria can be set through the front-end interface, and the system can retrieve historical alarm information from the cache or database of all devices in the security data network based on these criteria.
[0087] The technical solutions in this application have at least the following technical effects or advantages:
[0088] This application's solution deploys channel monitoring equipment within the railway train control system's safety data network at the station and / or central equipment sides, and independently networks it with the central maintenance equipment to form a supervisory data network for data collection. This achieves physical isolation from the main line network of the safety data network, ensuring strong security. Data collection is achieved through a combination of fiber optic splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring. Based on the characteristics of the different hardware devices used in these three methods, the solution can meet the needs of different application scenarios within the safety data network and ensure the sampling accuracy of the channel communication data collected. The central maintenance equipment receives the channel communication data and performs intelligent analyses such as channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly check analysis. This allows for precise identification of anomalies in the channel communication data, facilitating the timely detection of potential faults in the safety data network and enabling a shift in safety data network maintenance from fault repair to condition-based maintenance.
[0089] Figure 7 is a flowchart illustrating a railway train control system safety data network monitoring method provided in an embodiment of this application. As shown in the figure, the method includes:
[0090] The channel monitoring equipment collects channel communication data of station equipment and / or central equipment in the railway train control system safety data network in real time, and sends the collected channel communication data to the central maintenance equipment through the supervision data network;
[0091] The central maintenance equipment receives real-time collected channel communication data and performs multi-dimensional processing on the channel communication data to determine the results of anomaly analysis.
[0092] Figure 8 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. As shown in the figure, the electronic device includes a processor and a memory.
[0093] The processor is used to read and execute programs and instructions stored in the memory, causing the electronic device to perform the above-described method embodiments.
[0094] It should be noted that, for ease of explanation, Figure 8 only shows the main components of the electronic device. In actual applications, the electronic device may also include components or parts not shown in the figure.
[0095] This application also provides a computer-readable storage medium storing a program or instructions that, when read and executed by a computer, cause the computer to perform the above-described method embodiments.
[0096] Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A railway train control system safety data network monitoring system, characterized in that, This includes channel monitoring equipment and central maintenance equipment. The channel monitoring equipment is deployed on the station equipment and / or central equipment side of the railway train control system safety data network. The channel monitoring equipment and the central maintenance equipment are independently networked as a supervisory data network. The channel monitoring equipment is used to collect channel communication data of station equipment and / or central equipment in the railway train control system safety data network in real time; it is also used to send the collected channel communication data to the central maintenance equipment through the monitoring data network. The central maintenance equipment is used to receive real-time collected channel communication data, perform multi-dimensional processing on the channel communication data, and determine the results of anomaly analysis of the channel communication data.
2. The railway train control system safety data network monitoring system according to claim 1, characterized in that, The channel monitoring equipment is also used to collect channel communication data of railway train control system safety data network station equipment and / or central equipment in real time by combining fiber optic split monitoring, Ethernet TAP monitoring and port mirroring monitoring.
3. The railway train control system safety data network monitoring system according to claim 1, characterized in that, The central maintenance equipment is also used to receive real-time collected channel communication data, and to perform channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly check analysis on the channel communication data to determine the channel communication data anomalies of the railway train control system safety data network.
4. The railway train control system safety data network monitoring system according to claim 3, characterized in that, The central maintenance equipment includes a network topology unit, a data analysis unit, and a channel warning unit; The network topology unit is used to receive real-time collected channel communication data and to parse and store the channel communication data. The data analysis unit is used to perform channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly check analysis on channel communication data to determine the anomaly analysis results of channel communication data. The channel warning unit is used to generate abnormal alarms based on the results of abnormal analysis of channel communication data and to display the abnormal alarms in a visual manner.
5. The railway train control system safety data network monitoring system according to claim 4, characterized in that, The network topology unit is also used to visualize the main line network topology of the secure data network, displaying channel session traffic ranking, channel IP traffic ranking, and channel port traffic ranking in a list format.
6. The railway train control system safety data network monitoring system according to claim 4, characterized in that, The data analysis unit includes: a channel traffic analysis module, an RTT time anomaly early warning analysis module, and a communication connection group anomaly check analysis module; The channel traffic analysis module is used to determine the anomaly analysis results of channel communication data based on the time series characteristics of the channel communication data and by using a real-time active anomaly detection algorithm. The RTT time anomaly early warning and analysis module is used to determine the anomaly analysis results of the channel communication data based on the RTT time of the channel communication data and adopts an adaptive retransmission algorithm. The communication connection group anomaly detection and analysis module is used to determine the anomaly analysis results of the channel communication data based on the IP information in the network layer IPv4 protocol messages in the channel communication data.
7. The railway train control system safety data network monitoring system according to claim 4, characterized in that, The channel warning unit is also used to receive real-time collected device alarm messages and perform incremental processing on the device alarm messages.
8. A method for monitoring the safety data network of a railway train control system, characterized in that, include: The channel monitoring equipment collects channel communication data of station equipment and / or central equipment in the railway train control system safety data network in real time, and sends the collected channel communication data to the central maintenance equipment through the supervision data network; The central maintenance equipment receives real-time collected channel communication data and performs multi-dimensional processing on the channel communication data to determine the results of anomaly analysis.
9. The railway train control system safety data network monitoring method according to claim 8, characterized in that, The channel monitoring equipment uses a combination of fiber optic splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring to collect channel communication data of railway train control system safety data network station equipment and / or central equipment in real time.
10. The railway train control system safety data network monitoring method according to claim 8, characterized in that, The central maintenance equipment receives real-time collected channel communication data and performs channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly check analysis on the channel communication data to determine the channel communication data anomalies of the railway train control system's safety data network.
11. An electronic device, characterized in that, include: Processor and memory; The processor is coupled to the memory; The processor is configured to read and execute the program or instructions stored in the memory, causing the device to perform the method as described in any one of claims 8-10.
12. A computer-readable storage medium, characterized in that, The device contains a computer program that, when executed by a processor, implements the method as described in any one of claims 8-10.