Distributed Cryptographic Signatures for Railway Network Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current railway network control systems with redundant architectures face increased complexity and longer validation times due to the presence of watchdog circuitry, which can lead to delayed intervention in case of malfunctions or abnormal situations, as only one replica generates the integrity and authenticity verification, creating a functional difference that prolongs intervention times.

Innovation Solution

The system generates signatures for message authenticity and integrity using two independent apparatuses with distinct cryptographic keys, allowing each to generate pseudo-signatures and combine them to create a final signature, enabling each apparatus to independently control network portions and invalidate messages if anomalies are detected, thus reducing intervention time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If watchdog circuitry is added to ensure security of communications between replicas, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity of communicationsVSAvoidcomplexity of system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security verification function from the centralized watchdog circuitry and distributes it to each replica. Each replica independently generates its own security code and verifies messages, removing the need for complex centralized watchdog intervention and reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Each replica performs self-verification of message integrity and authenticity using its own security code and cryptographic keys. The system serves its own security needs without requiring external watchdog intervention, thereby simplifying the architecture while ensuring communication security.

Inventive Principle:
Principle #25Self-service

2Reliability

If centralized watchdog circuitry is used to validate messages, then reliability is improved, but loss of time increases due to longer validation phase

Engineering Contradiction:
Improveintegrity and authenticity verificationVSAvoidduration of validation phase
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The centralized security verification function is segmented and distributed to each replica. Each replica independently handles security code generation and message verification, eliminating the sequential dependency on centralized watchdog validation and significantly reducing the overall validation time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security codes are generated and stored in each replica in advance, before they are needed for message verification. This preliminary preparation eliminates the need for time-consuming real-time generation and validation through centralized watchdog circuitry.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If only one replica generates security codes, then device complexity is reduced, but loss of time increases when intervention is needed

Engineering Contradiction:
Improvenumber of componentsVSAvoidintervention time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

Each replica is equipped with the necessary cryptographic keys and security code generation capability locally, rather than relying on a single centralized component. This local empowerment enables immediate independent intervention by any replica that detects an abnormal situation, reducing intervention time.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses asymmetric cryptography where each replica has unique private keys but shares public verification keys. This asymmetric structure allows each replica to independently generate and verify security codes without requiring centralized coordination, reducing both complexity and intervention time.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS11420662B2Device and method for the safe management of vital communications in the railway environment
Publication Date: 2022.08.23 HITACHI RAIL STS SPA
  • US11420662B2 patent drawing
  • US11420662B2 patent drawing
  • US11420662B2 patent drawing

AI summary

An apparatus and method for generating and verifying secure messages between vital equipment for controlling a railway network, wherein the apparatus includes control and/or processing components configured to carry out the following steps: a) generating a message body including information that may change the state of the railway network; b) generating a first pseudo-signature on the basis of the message body and a first cryptographic key; c) transmitting the first pseudo-signature to a second apparatus; d) receiving a second pseudo-signature from the second apparatus; e) generating a message signature on the basis of the second pseudo-signature and the first cryptographic key; f) generating a message by combining the message body and the message signature; g) sending the message to a recipient.