Security Device Bank for CBTC Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current urban rail communication-based train control (CBTC) systems face challenges in ensuring secure and efficient data communication between trusted and untrusted networks, which is critical for safe train operations, particularly in maintaining reliability and preventing collisions and misaligned rail switches.
Innovation Solution
The implementation of a data communication system that includes trusted and untrusted fiber optic networks, security device banks acting as gateways between these networks, and security devices that provide strong authentication and encryption using IPSec protocols to establish secure communication tunnels and ensure scalability and redundancy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security devices are deployed to provide strong authentication and encryption between trusted and untrusted networks, then security and reliability are improved, but device complexity increases
Solution Approach 1:
Multiple security devices are consolidated into a single security device bank that manages multiple security functions. The security device bank integrates authentication, encryption, and communication management into one unified system, reducing the complexity of deploying and managing multiple separate security devices while maintaining strong security protocols between trusted and untrusted networks.
Solution Approach 2:
The security device bank is designed as a multi-functional system that can handle various security operations including authentication, encryption key management, and communication tunnel establishment. This universal design allows a single device to perform multiple security functions that would otherwise require separate devices, thereby improving security without proportionally increasing device complexity.
2Adaptability or versatility
If multiple security devices are used to ensure scalability and redundancy, then system capability is improved, but device complexity increases
Solution Approach 1:
The security device bank is segmented into multiple independent security devices that can be individually managed and scaled. Each security device within the bank can be deployed, removed, or replaced without affecting the entire system, enabling scalability while maintaining manageable complexity through modular architecture. The segmentation allows the system to adapt to varying security needs without requiring complete system redesign.
Solution Approach 2:
A controller acts as an intermediary between the security devices and the rest of the CBTC system, managing the complexity of multiple security devices. The controller coordinates communication between security devices, handles authentication requests, and manages encryption keys, thereby enabling scalability and redundancy without requiring each individual security device to be overly complex.
3Reliability
If security device banks are implemented as gateways between trusted and untrusted networks, then communication integrity is improved, but device complexity increases
Solution Approach 1:
The security device bank serves as an intermediary gateway between trusted and untrusted networks, establishing secure communication tunnels through the untrusted network. This intermediary position allows the system to maintain communication integrity by filtering and validating data packets, while the controller manages the complexity of tunnel establishment and maintenance automatically.
Solution Approach 2:
Manual security management processes are replaced with automated cryptographic mechanisms. The security device bank uses automated key exchange protocols, digital certificates, and encryption algorithms to establish secure communications without requiring manual intervention. This substitution of mechanical management with automated cryptographic systems improves communication integrity while reducing operational complexity.
Data Source
AI summary
In some embodiments, a system includes a trusted network, an untrusted network, on-board equipment on-board a moving object, one or more first security devices on-board the moving object and communicatively connecting the on-board equipment and the untrusted network, and a security device bank communicatively connecting the trusted network and the untrusted network. The security device bank includes a common bus or the local network and one or more second security devices connected to the common bus or the local network.


