Railway Display Protection via Encrypted Data Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for displaying data about system components in railway installations lack reliability and require expensive reference systems, especially for secure displays that need to maintain low error rates.
Innovation Solution
A method involving the selection of states by an operator, generation of encrypted test data sets, and their comparison using a test computer, with only the secure system components acting as reference, eliminating the need for additional reference systems and ensuring security through a combination of operator station, receiving device, and test computer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a reference system is added to ensure secure display with low error rates, then reliability is improved, but device complexity and cost increase
Solution Approach 1:
The patent creates a virtual copy of the secure system's state data through encrypted test data sets. Instead of adding a physical reference system, the method generates encrypted representations of system states that can be transmitted and verified through multiple channels, achieving reference functionality through data copying rather than hardware duplication
Solution Approach 2:
The patent introduces a test computer as an intermediary that receives encrypted test data sets from the operator station and secure system, performs decryption and comparison, then generates result data sets. This intermediary handles the complex reference system functions centrally, avoiding the need for each operator station to have its own reference system
2Reliability
If encryption and multiple data channels are used for secure transmission, then security is improved, but device complexity increases
Solution Approach 1:
The test computer serves multiple functions: receiving encrypted test data sets from different sources, decrypting them using stored keys, comparing the decrypted data, generating result data sets, and transmitting results back. This multi-functional approach consolidates security operations into a single device rather than distributing complexity across multiple components
Solution Approach 2:
The method creates encrypted copies of system state data that can be transmitted through multiple data channels. These encrypted test data sets contain all necessary information for verification without requiring the receiving devices to process complex security protocols, moving the encryption/decryption complexity to the test computer
3Measurement precision
If encrypted test data sets are transmitted through multiple channels and compared, then measurement precision is improved, but loss of time increases
Solution Approach 1:
The operator station and secure system generate and transmit the encrypted test data sets in advance, before the actual verification is needed. The test computer stores these encrypted data sets and their corresponding decryption keys, so when verification is required, the decryption and comparison can proceed quickly without delay
Data Source
Figure 1
Figure 2~3
AI summary
The procedure serves for generic display monitoring in a railway installation and comprises: A) Selecting a state to be checked (10), B) Generating an encrypted first and second test data set (12) by an operator station (2) for each state (10), C) Sending the first test data set (11) to a receiver (4) with a first data channel (31), D) Sending the second test data set (12) to the receiver (4) with a second data channel (32), E) Sending the test data sets (11, 12) to a test computer (6), F) Decrypting the test data sets (11, 12) in the test computer (6) and comparing the test data sets (11, 12) with each other, G) Generating a first and a second result data set (21, 22) from a result of the comparison and sending the result data sets to the receiver (4), H) Forwarding and decrypting the first result data set (21) at the operator station (2) and decrypting the second result data set (22) in the receiving device (4),and I) Comparing the two decrypted result data sets (21, 22).,