Railway Control Message Encryption via Sender-Side Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current railway control systems face challenges in ensuring communication safety and reliability due to complex architectures and limited use of Commercial Off-the-Shelf (COTS) components, which can lead to increased fault probabilities and reduced system availability.
Innovation Solution
The solution involves encrypting control messages using at least two private keys, with each apparatus generating, decrypting, and verifying messages, and then re-encrypting them for transmission, ensuring validation by multiple apparatuses, thereby ensuring safety and redundancy without transmitting plaintext information, and allowing the use of COTS components and distributed virtualization technologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundant architectures with Watchdog circuitry are used to ensure communication safety, then safety integrity level is improved, but device complexity increases and fault probability increases
Solution Approach 1:
The patent extracts the safety verification function from the message recipient and relocates it to the message sender. The sender apparatus now performs integrity verification and digital signature generation, removing the need for complex Watchdog circuitry at the recipient end. This extraction principle resolves the contradiction by simplifying the overall system architecture while maintaining SIL 4 safety requirements.
Solution Approach 2:
The patent introduces digital signature technology as an intermediary mechanism to establish trust between apparatuses. Instead of using complex redundant architectures with Watchdog circuitry, the system uses cryptographic signatures as a mediator to verify message authenticity and integrity. This intermediary approach achieves high safety integrity with simpler device architecture.
2Reliability
If redundant architectures with Watchdog circuitry are used to ensure communication safety, then safety integrity level is improved, but system availability decreases
Solution Approach 1:
By extracting the safety verification function from the recipient apparatus and placing it in the sender apparatus, the system eliminates the need for complex Watchdog circuitry that would otherwise limit system availability. This allows the use of COTS components with higher availability while maintaining SIL 4 safety requirements through the sender-side verification mechanism.
3Reliability
If intrinsic-safety circuitry is added to disable apparatuses on discordance detection, then safety integrity level is improved, but device complexity increases
Solution Approach 1:
The patent removes the need for intrinsic-safety circuitry by extracting the safety verification function to the sender apparatus. The sender performs integrity checks and digital signature generation, eliminating the requirement for additional safety circuitry at the recipient end that would increase device complexity while maintaining high safety integrity.
Solution Approach 2:
The patent replaces mechanical/intrinsic-safety circuitry with a cryptographic software-based solution. Instead of using hardware Watchdog circuits and intrinsic-safety mechanisms, the system uses digital signatures and cryptographic verification to achieve the same safety goals with simpler device architecture.
4Device complexity
If message verification is entrusted to recipients, then device complexity is reduced, but reliability of using COTS components decreases
Solution Approach 1:
The patent inverts the traditional verification approach by having the sender apparatus perform verification instead of the recipient. The sender validates message integrity and generates digital signatures, while the recipient simply verifies the signature. This inversion enables the use of COTS components with higher reliability while maintaining security, as the complex verification logic resides in the sender that controls the cryptographic keys.
Data Source
AI summary
The invention relates to an apparatus (1a) and a method for controlling a critical system (S), as well as to a device (3a,3b) and a method for the distribution of messages for controlling said critical system (S), wherein said apparatus (1a) is configured for encrypting a first control message by using the first private key, transmitting said first encrypted message to a second apparatus (1b), receiving a second encrypted message generated by a second apparatus (1b) and encrypted by said second apparatus (1b) by using a second private key, decrypting said second encrypted message by using a public key associated with said second private key, verifying the second decrypted message on the basis of said first message and, if the verification is successful, encrypting at least said second encrypted message with said first private key, thereby generating a third encrypted message, and transmitting said third encrypted message.


