Railway Signal Encryption Interface Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Railway Signal Safety Protocol II (RSSP-II) lacks integration of the SM4 cryptographic algorithm, which is a national commercial secret algorithm in China, for security encryption, limiting its adaptability and security in railway signal communication.

Innovation Solution

A method and system for security encryption of railway signals that sets multiple security encryption interfaces corresponding to different encryption algorithms, including DES and SM4, on a Message Authentication Safety Layer (MASL), allowing selection of appropriate algorithms based on device types and applications, and executes these algorithms using connected encryption hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If only DES encryption algorithm is used in RSSP-II, then the system structure is simple, but the adaptability and security are limited

Engineering Contradiction:
Improveencryption algorithm adaptabilityVSAvoidencryption interface complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functionality by providing multiple security encryption interfaces (first security encryption interface for DES, second security encryption interface for SM4) within the same MASL layer. This allows the system to support both legacy DES algorithms and national SM4 algorithms, enabling adaptability across different device types and application scenarios while maintaining a unified interface structure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces dynamic selection capability where the system can choose different encryption algorithms based on device types and application requirements. The encryption selection unit dynamically determines which interface to use (DES or SM4) according to the communication partner's capabilities and security requirements, making the system flexible and adaptable rather than static.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple encryption algorithms are integrated, then the security and adaptability are improved, but the system complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidencryption interface complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption functionality into separate independent interfaces - a first security encryption interface for DES algorithms and a second security encryption interface for SM4 algorithms. Each interface is independently implemented and can be selected based on requirements. This segmentation allows multiple algorithms to coexist without creating a monolithic complex system, as each algorithm has its own dedicated interface module.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an encryption selection unit as an intermediary component that mediates between the upper layers and the different encryption interfaces. This selection unit receives encryption selection instructions and determines which interface to activate, simplifying the overall system architecture by providing a single point of control for algorithm selection rather than requiring complex decision logic throughout the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If legacy DES algorithm is used, then backward compatibility is maintained, but security protection is insufficient

Engineering Contradiction:
Improveencryption securityVSAvoidalgorithm selection flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic algorithm selection where the system can adaptively choose between DES and SM4 algorithms based on the communication scenario. When communicating with legacy devices, the system selects DES through the first security encryption interface to maintain compatibility. When communicating with modern devices requiring higher security, the system selects SM4 through the second security encryption interface, thus providing both backward compatibility and enhanced security capabilities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of encryption algorithm strength by providing both weak (DES) and strong (SM4) algorithm options. The system can adjust the encryption strength parameter according to the security requirements of different applications and the capabilities of communication partners, allowing flexible adaptation from legacy to modern security standards.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3713147B1Railway signal security encryption method and system
Publication Date: 2022.02.16 CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD
  • EP3713147B1 patent drawingFigure 1

AI summary

A method for security encryption of railway signal includes: setting a plurality of security encryption interfaces, wherein the plurality of security encryption interfaces respectively correspond to different encryption algorithms; selecting one security encryption interface from the plurality of security encryption interfaces; and encrypting data by using the encryption algorithm corresponding to the selected security encryption interface. The present disclosure further provides a system for security encryption of railway signal. The disclosed method and system for security encryption of railway signal fully consider different encryption algorithms, and can select different encryption algorithms according to different types of devices and applications, thereby improving security of communication.