Train-to-Train Secure Key Exchange via Central Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing train-to-train communication systems are vulnerable to man-in-the-middle attacks, where malicious actors can intercept and modify communications, compromising the security and authenticity of messages between trains, especially in complex track networks.

Innovation Solution

A computer-implemented method and system for secure train-to-train key exchange, involving the generation of secret random numbers and public keys, authentication using digital signatures, and the establishment of a shared secret key to secure communication channels, preventing man-in-the-middle attacks by ensuring the identity and trustworthiness of communicating trains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If train-to-train communication is implemented in a complex track network, then train control and safety operation are improved, but vulnerability to man-in-the-middle attacks increases

Engineering Contradiction:
Improvetrain control safetyVSAvoidcyber security vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a central office server as an intermediary that acts as a trusted third party to facilitate secure key exchange between trains. The server distributes authentication information and coordinates the establishment of secure communication channels, preventing malicious actors from directly compromising train-to-train communications without detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and key exchange actions before actual train-to-train communication begins. Authentication information is pre-distributed by the central office server, and secure communication channels are established in advance, ensuring that when communications occur, they are already protected against man-in-the-middle attacks.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If public keys and two-factor authentication mechanisms are used, then authentication capability is improved, but they are insufficient to certify message source against sophisticated MITM attacks

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsource identification information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms where the central office server continuously monitors and verifies authentication exchanges between trains. The server provides feedback confirmation that validates the authenticity of exchanged keys and messages, creating a closed-loop security system that can detect and prevent MITM attacks that would otherwise bypass standard authentication protocols.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent adds another dimension to authentication by introducing a hierarchical structure with the central office server at a higher level, above the train-to-train communication layer. This dimensional addition allows the system to verify not just the immediate communication partners but also the legitimacy of the authentication process itself, providing multi-layered source certification.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11153077B2Secure vehicle to vehicle communication
Publication Date: 2021.10.19 WESTINGHOUSE AIR BRAKE TECH CORP
  • US11153077B2 patent drawing
  • US11153077B2 patent drawing
  • US11153077B2 patent drawing

AI summary

A system and method for a secure key exchange between two trains operating within a track network may include generating a first or second public key based on a secret random number, generating a shared secret key based on the first or second public key, authenticating one or more key exchange communications by a remote server based on a digital signature established with an on-board key associated with the first train, authenticating a communication by a remote server based on the digital signature of the second train signed with an on-board key associated with the second train, and establishing secure train-to-train communication between the two trains by generating a shared secret key based on a public key received from the other train, the secure key exchange protecting the two trains from a man-in-the-middle attack.