Train Control Security Segmentation for Defense-in-Depth

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information security protection methods for train control and monitoring systems are inadequate, primarily relying on firewalls for simple isolation, failing to address the increasing threat of malicious network attacks, which can compromise train operations and safety.

Innovation Solution

A multi-dimensional information security protection system integrating region boundary, communication network, and terminal device security, employing firewalls, safety monitoring, and response modules to prevent attacks, with distributed and centralized security analysis to ensure secure communication and device integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If only firewall is used for simple isolation protection, then device complexity is reduced, but security reliability is insufficient to defend against malicious network attacks

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the train control network into multiple security zones (control zone, information zone, maintenance zone) with different security levels. Each zone is protected by dedicated security devices including firewalls, intrusion detection systems, and safety monitoring modules. This segmentation allows comprehensive security protection without requiring a single complex system, thereby improving security reliability while managing device complexity through modular deployment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multi-dimensional security protection system is implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improveinformation security protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-dimensional security protection by adding security layers at different network dimensions: region boundary security (zone isolation), communication network security (protocol validation, intrusion detection), and terminal device security (device authentication, access control). This multi-dimensional approach comprehensively addresses security threats while organizing complexity across different operational dimensions rather than concentrating it in a single system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The security system employs a nested architecture where security devices are deployed at multiple hierarchical levels: zone boundary firewalls, network-level intrusion detection systems, and device-level security modules. Each layer nests within and supports the others, creating a defense-in-depth structure that provides comprehensive protection while distributing system complexity across hierarchical levels.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If region boundary security protection is implemented by deploying safety protection device at regional boundary, then security reliability is improved, but device complexity and cost increase

Engineering Contradiction:
Improveregion boundary securityVSAvoidboundary protection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by tailoring security measures to specific regional boundaries based on their security requirements. The control zone boundary uses stringent protection with safety monitoring modules and protocol validation, while the information zone boundary employs standard firewall and intrusion detection. This localized approach optimizes security reliability at each boundary while avoiding uniform over-protection that would increase overall device complexity and cost.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12448015B2Information security protection method and apparatus
Publication Date: 2025.10.21 ZHUZHOU CSR TIMES ELECTRIC CO LTD
  • US12448015B2 patent drawing
  • US12448015B2 patent drawing
  • US12448015B2 patent drawing

AI summary

The invention relates to an information security protection method and apparatus, and a computer-readable storage medium. The information security protection method comprises the steps of: allocating a train control and monitoring system to an intranet region, and performing region boundary security protection on the train control and monitoring system; performing communication network security protection on the train control and monitoring system; and performing terminal device security protection on the train control and monitoring system. The invention deeply integrates an application service of a train control and monitoring system, and defence-in-depth is performed on the train control and monitoring system from a plurality of dimensions such as region boundary security, communication network security and terminal device security, such that attacks initiated from an intranet and an extranet of the system can be effectively handled, and thus, the information security protection capability of the train control and monitoring system is improved.