Railway Safety Command Encryption via Mobile Confirmation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for issuing safety-critical operating commands in railway systems lack sufficient safety measures, particularly in preventing unauthorized operations and ensuring security across hardware and software components, despite requiring a high level of safety for a small proportion of operations.
Innovation Solution
A method utilizing commercially available hardware and encryption technology, where safety-critical operations are confirmed through a combination of a stationary operator station, a system component, and a receiving device, such as a smartphone, using encrypted two-dimensional codes or acoustic messages, ensuring that only authorized devices can execute commands and maintaining a secure communication channel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple confirmations are required for safety-critical operations, then system security is improved, but operational complexity increases
Solution Approach 1:
The confirmation process is segmented into distinct phases: first confirmation at the operator station, second confirmation at the receiving device, and system response verification. This segmentation distributes the security burden across multiple independent components, improving overall system security while maintaining clear operational procedures.
Solution Approach 2:
An encrypted communication channel acts as an intermediary between the operator station and the receiving device. The channel encrypts confirmations and system responses, ensuring secure transmission without requiring direct trust between all components, thus enhancing security while simplifying the interaction protocol.
2Reliability
If diverse hardware and encryption technology are used, then system security is improved, but manufacturing complexity increases
Solution Approach 1:
The system employs universally available hardware components (standard operator stations, smartphones with cameras) and general-purpose encryption technology rather than specialized custom hardware. This universality reduces manufacturing complexity while maintaining high security levels, as the same components can be used across different installations without requiring custom approval procedures.
Solution Approach 2:
The system uses encrypted copies of confirmations and responses that can be verified by any authorized device. The encryption mechanism creates verifiable copies that maintain security integrity while allowing flexible deployment across different hardware platforms, reducing the need for custom-manufactured security components.
3Reliability
If multiple confirmations are required, then unauthorized operations are prevented, but time consumption increases
Solution Approach 1:
The system establishes encrypted communication channels and pre-configures confirmation protocols before actual operations occur. This preliminary setup eliminates the need for time-consuming security configurations during operation, allowing rapid confirmations while maintaining strong security against unauthorized actions.
Solution Approach 2:
The system implements immediate feedback loops where system responses are encrypted and transmitted back to the operator station and receiving device. This rapid feedback mechanism allows operators to verify operations quickly without compromising security, reducing the time required for confirmations while preventing unauthorized operations through the same feedback channel.
Data Source
Figure 1~2
Figure 3
AI summary
In one embodiment, the method serves to input safety-critical operating commands (11) for a railway system and comprises the following steps: A) Inputting the operating command (11) into an operator station (2), B) Forwarding the operating command (11) from the operator station (2) to a system component (3) to be controlled, C) Generating an encrypted system response (12) in the system component (3), D) Sending the system response (12) from the system component (3) to the operator station (2), E) Transmitting the encrypted system response (12) from the operator station (2) directly to a mobile receiving device (4), and F) Decrypting the system response (12) in the receiving device (4) and confirming the operating command (11) at the receiving device (4) and sending an acknowledgment (13) for the operating command (11) to the system component (3).