Distributed Cryptographic Signatures for Railway Network Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current railway network control systems with redundant architectures face increased complexity and longer validation times due to the presence of watchdog circuitry, which can lead to delayed intervention in case of malfunctions or abnormal situations, as only one replica generates the integrity and authenticity verification, creating a functional difference that prolongs intervention times.
Innovation Solution
The system generates signatures for message authenticity and integrity using two independent apparatuses with distinct cryptographic keys, allowing each to generate pseudo-signatures and combine them to create a final signature, enabling each apparatus to independently control network portions and invalidate messages if anomalies are detected, thus reducing intervention time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If watchdog circuitry is added to ensure security of communications between replicas, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent extracts the security verification function from the centralized watchdog circuitry and distributes it to each replica. Each replica independently generates its own security code and verifies messages, removing the need for complex centralized watchdog intervention and reducing overall system complexity while maintaining security.
Solution Approach 2:
Each replica performs self-verification of message integrity and authenticity using its own security code and cryptographic keys. The system serves its own security needs without requiring external watchdog intervention, thereby simplifying the architecture while ensuring communication security.
2Reliability
If centralized watchdog circuitry is used to validate messages, then reliability is improved, but loss of time increases due to longer validation phase
Solution Approach 1:
The centralized security verification function is segmented and distributed to each replica. Each replica independently handles security code generation and message verification, eliminating the sequential dependency on centralized watchdog validation and significantly reducing the overall validation time.
Solution Approach 2:
Security codes are generated and stored in each replica in advance, before they are needed for message verification. This preliminary preparation eliminates the need for time-consuming real-time generation and validation through centralized watchdog circuitry.
3Device complexity
If only one replica generates security codes, then device complexity is reduced, but loss of time increases when intervention is needed
Solution Approach 1:
Each replica is equipped with the necessary cryptographic keys and security code generation capability locally, rather than relying on a single centralized component. This local empowerment enables immediate independent intervention by any replica that detects an abnormal situation, reducing intervention time.
Solution Approach 2:
The patent uses asymmetric cryptography where each replica has unique private keys but shares public verification keys. This asymmetric structure allows each replica to independently generate and verify security codes without requiring centralized coordination, reducing both complexity and intervention time.
Data Source
AI summary
An apparatus and method for generating and verifying secure messages between vital equipment for controlling a railway network, wherein the apparatus includes control and/or processing components configured to carry out the following steps: a) generating a message body including information that may change the state of the railway network; b) generating a first pseudo-signature on the basis of the message body and a first cryptographic key; c) transmitting the first pseudo-signature to a second apparatus; d) receiving a second pseudo-signature from the second apparatus; e) generating a message signature on the basis of the second pseudo-signature and the first cryptographic key; f) generating a message by combining the message body and the message signature; g) sending the message to a recipient.


