Railway Safety Command Encryption via Mobile Confirmation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for issuing safety-critical operating commands in railway systems lack sufficient safety measures, particularly in preventing unauthorized operations and ensuring security across hardware and software components, despite requiring a high level of safety for a small proportion of operations.

Innovation Solution

A method utilizing commercially available hardware and encryption technology, where safety-critical operations are confirmed through a combination of a stationary operator station, a system component, and a receiving device, such as a smartphone, using encrypted two-dimensional codes or acoustic messages, ensuring that only authorized devices can execute commands and maintaining a secure communication channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple confirmations are required for safety-critical operations, then system security is improved, but operational complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The confirmation process is segmented into distinct phases: first confirmation at the operator station, second confirmation at the receiving device, and system response verification. This segmentation distributes the security burden across multiple independent components, improving overall system security while maintaining clear operational procedures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An encrypted communication channel acts as an intermediary between the operator station and the receiving device. The channel encrypts confirmations and system responses, ensuring secure transmission without requiring direct trust between all components, thus enhancing security while simplifying the interaction protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If diverse hardware and encryption technology are used, then system security is improved, but manufacturing complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system employs universally available hardware components (standard operator stations, smartphones with cameras) and general-purpose encryption technology rather than specialized custom hardware. This universality reduces manufacturing complexity while maintaining high security levels, as the same components can be used across different installations without requiring custom approval procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses encrypted copies of confirmations and responses that can be verified by any authorized device. The encryption mechanism creates verifiable copies that maintain security integrity while allowing flexible deployment across different hardware platforms, reducing the need for custom-manufactured security components.

Inventive Principle:
Principle #26Copying

3Reliability

If multiple confirmations are required, then unauthorized operations are prevented, but time consumption increases

Engineering Contradiction:
Improvesecurity against unauthorized operationsVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system establishes encrypted communication channels and pre-configures confirmation protocols before actual operations occur. This preliminary setup eliminates the need for time-consuming security configurations during operation, allowing rapid confirmations while maintaining strong security against unauthorized actions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements immediate feedback loops where system responses are encrypted and transmitted back to the operator station and receiving device. This rapid feedback mechanism allows operators to verify operations quickly without compromising security, reducing the time required for confirmations while preventing unauthorized operations through the same feedback channel.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3753800B1Input method for safety-critical control commands and control system
Publication Date: 2023.10.11 SIEMENS MOBILITY GMBH DE
  • EP3753800B1 patent drawingFigure 1~2
  • EP3753800B1 patent drawingFigure 3

AI summary

In one embodiment, the method serves to input safety-critical operating commands (11) for a railway system and comprises the following steps: A) Inputting the operating command (11) into an operator station (2), B) Forwarding the operating command (11) from the operator station (2) to a system component (3) to be controlled, C) Generating an encrypted system response (12) in the system component (3), D) Sending the system response (12) from the system component (3) to the operator station (2), E) Transmitting the encrypted system response (12) from the operator station (2) directly to a mobile receiving device (4), and F) Decrypting the system response (12) in the receiving device (4) and confirming the operating command (11) at the receiving device (4) and sending an acknowledgment (13) for the operating command (11) to the system component (3).