Railway Signal Encryption Interface Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Railway Signal Safety Protocol II (RSSP-II) lacks integration of the SM4 cryptographic algorithm, which is a national commercial secret algorithm in China, for security encryption, limiting its adaptability and security in railway signal communication.
Innovation Solution
A method and system for security encryption of railway signals that sets multiple security encryption interfaces corresponding to different encryption algorithms, including DES and SM4, on a Message Authentication Safety Layer (MASL), allowing selection of appropriate algorithms based on device types and applications, and executes these algorithms using connected encryption hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If only DES encryption algorithm is used in RSSP-II, then the system structure is simple, but the adaptability and security are limited
Solution Approach 1:
The patent implements multi-functionality by providing multiple security encryption interfaces (first security encryption interface for DES, second security encryption interface for SM4) within the same MASL layer. This allows the system to support both legacy DES algorithms and national SM4 algorithms, enabling adaptability across different device types and application scenarios while maintaining a unified interface structure.
Solution Approach 2:
The patent introduces dynamic selection capability where the system can choose different encryption algorithms based on device types and application requirements. The encryption selection unit dynamically determines which interface to use (DES or SM4) according to the communication partner's capabilities and security requirements, making the system flexible and adaptable rather than static.
2Reliability
If multiple encryption algorithms are integrated, then the security and adaptability are improved, but the system complexity increases
Solution Approach 1:
The patent segments the encryption functionality into separate independent interfaces - a first security encryption interface for DES algorithms and a second security encryption interface for SM4 algorithms. Each interface is independently implemented and can be selected based on requirements. This segmentation allows multiple algorithms to coexist without creating a monolithic complex system, as each algorithm has its own dedicated interface module.
Solution Approach 2:
The patent introduces an encryption selection unit as an intermediary component that mediates between the upper layers and the different encryption interfaces. This selection unit receives encryption selection instructions and determines which interface to activate, simplifying the overall system architecture by providing a single point of control for algorithm selection rather than requiring complex decision logic throughout the system.
3Reliability
If legacy DES algorithm is used, then backward compatibility is maintained, but security protection is insufficient
Solution Approach 1:
The patent implements dynamic algorithm selection where the system can adaptively choose between DES and SM4 algorithms based on the communication scenario. When communicating with legacy devices, the system selects DES through the first security encryption interface to maintain compatibility. When communicating with modern devices requiring higher security, the system selects SM4 through the second security encryption interface, thus providing both backward compatibility and enhanced security capabilities.
Solution Approach 2:
The patent changes the parameter of encryption algorithm strength by providing both weak (DES) and strong (SM4) algorithm options. The system can adjust the encryption strength parameter according to the security requirements of different applications and the capabilities of communication partners, allowing flexible adaptation from legacy to modern security standards.
Data Source
Figure 1
AI summary
A method for security encryption of railway signal includes: setting a plurality of security encryption interfaces, wherein the plurality of security encryption interfaces respectively correspond to different encryption algorithms; selecting one security encryption interface from the plurality of security encryption interfaces; and encrypting data by using the encryption algorithm corresponding to the selected security encryption interface. The present disclosure further provides a system for security encryption of railway signal. The disclosed method and system for security encryption of railway signal fully consider different encryption algorithms, and can select different encryption algorithms according to different types of devices and applications, thereby improving security of communication.