Security Device Bank for CBTC Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current urban rail communication-based train control (CBTC) systems face challenges in ensuring secure and efficient data communication between trusted and untrusted networks, which is critical for safe train operations, particularly in maintaining reliability and preventing collisions and misaligned rail switches.

Innovation Solution

The implementation of a data communication system that includes trusted and untrusted fiber optic networks, security device banks acting as gateways between these networks, and security devices that provide strong authentication and encryption using IPSec protocols to establish secure communication tunnels and ensure scalability and redundancy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security devices are deployed to provide strong authentication and encryption between trusted and untrusted networks, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple security devices are consolidated into a single security device bank that manages multiple security functions. The security device bank integrates authentication, encryption, and communication management into one unified system, reducing the complexity of deploying and managing multiple separate security devices while maintaining strong security protocols between trusted and untrusted networks.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security device bank is designed as a multi-functional system that can handle various security operations including authentication, encryption key management, and communication tunnel establishment. This universal design allows a single device to perform multiple security functions that would otherwise require separate devices, thereby improving security without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple security devices are used to ensure scalability and redundancy, then system capability is improved, but device complexity increases

Engineering Contradiction:
ImprovescalabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security device bank is segmented into multiple independent security devices that can be individually managed and scaled. Each security device within the bank can be deployed, removed, or replaced without affecting the entire system, enabling scalability while maintaining manageable complexity through modular architecture. The segmentation allows the system to adapt to varying security needs without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A controller acts as an intermediary between the security devices and the rest of the CBTC system, managing the complexity of multiple security devices. The controller coordinates communication between security devices, handles authentication requests, and manages encryption keys, thereby enabling scalability and redundancy without requiring each individual security device to be overly complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security device banks are implemented as gateways between trusted and untrusted networks, then communication integrity is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication integrityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security device bank serves as an intermediary gateway between trusted and untrusted networks, establishing secure communication tunnels through the untrusted network. This intermediary position allows the system to maintain communication integrity by filtering and validating data packets, while the controller manages the complexity of tunnel establishment and maintenance automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Manual security management processes are replaced with automated cryptographic mechanisms. The security device bank uses automated key exchange protocols, digital certificates, and encryption algorithms to establish secure communications without requiring manual intervention. This substitution of mechanical management with automated cryptographic systems improves communication integrity while reducing operational complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9166952B2Security device bank and a system including the and SD security device bank
Publication Date: 2015.10.20 HITACHI RAIL GTS CANADA INC
  • US9166952B2 patent drawing
  • US9166952B2 patent drawing
  • US9166952B2 patent drawing

AI summary

In some embodiments, a system includes a trusted network, an untrusted network, on-board equipment on-board a moving object, one or more first security devices on-board the moving object and communicatively connecting the on-board equipment and the untrusted network, and a security device bank communicatively connecting the trusted network and the untrusted network. The security device bank includes a common bus or the local network and one or more second security devices connected to the common bus or the local network.