Data Relay Cascade for Secure Automated Railway Data Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for updating data in computing systems, especially in railway technology, require manual intervention and lack secure verification processes, particularly in Category 2 networks where DMZs are cumbersome to manage and ALG approvals are difficult to verify.
Innovation Solution
A computing system with an input data path featuring data relays and buffer memory that allows data to be temporarily stored and verified by an intermediate authority before forwarding, ensuring authorized data sources and correct checksums are used, utilizing a relay cascade with intermediate computing devices for secure data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual data transfer methods are used, then data can be transferred to computing systems, but manual intervention by maintenance personnel is required and the process is time-consuming
Solution Approach 1:
The system enables automated data transfer where the computing system itself performs data reception and verification operations without requiring manual intervention. The interface device automatically receives data, stores it in buffer memory, and the computing system autonomously verifies checksums and cryptographic signatures, eliminating the need for maintenance personnel to physically intervene in the data transfer process.
2Reliability
If DMZ with multiple firewalls and ALG is used, then data exchange can be achieved, but the system complexity increases and regular updates and verification are required
Solution Approach 1:
The invention extracts the essential security verification functions (checksum verification and cryptographic signature verification) from the complex DMZ architecture and implements them directly in the computing system's data processing path. This eliminates the need for separate firewalls and ALG components while maintaining security requirements, thereby reducing system complexity while preserving data exchange security.
3Reliability
If ALG is used for data exchange, then data can be forwarded, but the assurance of ALG property cannot be directly proven or verified in railway networks
Solution Approach 1:
The invention introduces cryptographic signatures as an intermediary verification mechanism that provides provable authentication of data sources. Instead of relying on ALG approval status which cannot be directly verified, the system uses cryptographic signatures that can be mathematically verified to prove the authenticity and integrity of data, providing direct and measurable assurance of data source authorization.
4Ease of operation
If direct data access is allowed, then data transfer is simple, but security verification and authorization checks cannot be performed
Solution Approach 1:
The system performs security verification operations (checksum verification and cryptographic signature verification) as preliminary actions before allowing data access. The interface device receives data and performs initial verification, storing verified data in buffer memory. Only after successful verification does the system enable direct data access, ensuring that security checks are completed beforehand without complicating the actual data transfer operation.
Data Source
AI summary
A computing system includes a computing device and an input data path connecting an interface device to the computing device. The input data path has at least two data relays and at least one buffer memory temporarily storing data. Each of the data relays has first and second terminals and a central terminal and selectively interconnects the first and central terminals or the second and central terminals and leaves the first and second terminals constantly separated from each other. The first terminal of a first relay is connected to the interface device, and the second terminal is connected to the computing device. The central terminal of the first data relay is connected to the buffer memory. The intermediate buffer memory is selectively connected by the first data relay solely to the interface device or the second terminal of the first data relay, but not to both simultaneously.


