Railway Control Message Encryption via Sender-Side Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current railway control systems face challenges in ensuring communication safety and reliability due to complex architectures and limited use of Commercial Off-the-Shelf (COTS) components, which can lead to increased fault probabilities and reduced system availability.

Innovation Solution

The solution involves encrypting control messages using at least two private keys, with each apparatus generating, decrypting, and verifying messages, and then re-encrypting them for transmission, ensuring validation by multiple apparatuses, thereby ensuring safety and redundancy without transmitting plaintext information, and allowing the use of COTS components and distributed virtualization technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redundant architectures with Watchdog circuitry are used to ensure communication safety, then safety integrity level is improved, but device complexity increases and fault probability increases

Engineering Contradiction:
Improvesafety integrity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the safety verification function from the message recipient and relocates it to the message sender. The sender apparatus now performs integrity verification and digital signature generation, removing the need for complex Watchdog circuitry at the recipient end. This extraction principle resolves the contradiction by simplifying the overall system architecture while maintaining SIL 4 safety requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces digital signature technology as an intermediary mechanism to establish trust between apparatuses. Instead of using complex redundant architectures with Watchdog circuitry, the system uses cryptographic signatures as a mediator to verify message authenticity and integrity. This intermediary approach achieves high safety integrity with simpler device architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If redundant architectures with Watchdog circuitry are used to ensure communication safety, then safety integrity level is improved, but system availability decreases

Engineering Contradiction:
Improvesafety integrity levelVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By extracting the safety verification function from the recipient apparatus and placing it in the sender apparatus, the system eliminates the need for complex Watchdog circuitry that would otherwise limit system availability. This allows the use of COTS components with higher availability while maintaining SIL 4 safety requirements through the sender-side verification mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If intrinsic-safety circuitry is added to disable apparatuses on discordance detection, then safety integrity level is improved, but device complexity increases

Engineering Contradiction:
Improvesafety integrity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent removes the need for intrinsic-safety circuitry by extracting the safety verification function to the sender apparatus. The sender performs integrity checks and digital signature generation, eliminating the requirement for additional safety circuitry at the recipient end that would increase device complexity while maintaining high safety integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces mechanical/intrinsic-safety circuitry with a cryptographic software-based solution. Instead of using hardware Watchdog circuits and intrinsic-safety mechanisms, the system uses digital signatures and cryptographic verification to achieve the same safety goals with simpler device architecture.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Device complexity

If message verification is entrusted to recipients, then device complexity is reduced, but reliability of using COTS components decreases

Engineering Contradiction:
Improvedevice complexityVSAvoidreliability of COTS components
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent inverts the traditional verification approach by having the sender apparatus perform verification instead of the recipient. The sender validates message integrity and generates digital signatures, while the recipient simply verifies the signature. This inversion enables the use of COTS components with higher reliability while maintaining security, as the complex verification logic resides in the sender that controls the cryptographic keys.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS20240039717A1Appratus and method for controlling a critical system
Publication Date: 2024.02.01 HITACHI RAIL STS SPA
  • US20240039717A1 patent drawing
  • US20240039717A1 patent drawing
  • US20240039717A1 patent drawing

AI summary

The invention relates to an apparatus (1a) and a method for controlling a critical system (S), as well as to a device (3a,3b) and a method for the distribution of messages for controlling said critical system (S), wherein said apparatus (1a) is configured for encrypting a first control message by using the first private key, transmitting said first encrypted message to a second apparatus (1b), receiving a second encrypted message generated by a second apparatus (1b) and encrypted by said second apparatus (1b) by using a second private key, decrypting said second encrypted message by using a public key associated with said second private key, verifying the second decrypted message on the basis of said first message and, if the verification is successful, encrypting at least said second encrypted message with said first private key, thereby generating a third encrypted message, and transmitting said third encrypted message.