Train Protection Key Distribution via Route-Specific Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing key distribution methods for train protection systems, particularly in cross-domain scenarios, are complex, error-prone, and inefficient, requiring permanent connections between key management centers for exchanging communication keys.

Innovation Solution

A method and system for automatically generating and distributing communication keys based on a planned train route, where a central key allocation office creates route-specific keys that can be shared among involved domains, allowing for targeted and tamper-proof communication between rail vehicles and route control centers, with the option to limit key validity by location and time, and using key derivation methods to generate route center-specific keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual key distribution is used between key management centers of different domains, then communication keys can be exchanged between route centers, but the process becomes complex, error-prone, and requires permanent connections between KMCs

Engineering Contradiction:
Improvekey distribution reliabilityVSAvoidkey distribution system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a home KMC as an intermediary that centralizes key management for mobile units. Instead of requiring permanent connections between all KMCs across domains, the home KMC acts as a mediator that generates keys locally and distributes them to route centers on-demand based on planned routes, eliminating the need for complex inter-KMC connection infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the key generation function from the distributed KMCs and concentrates it in the home KMC. This extraction allows the home KMC to independently generate communication keys without requiring connections to other KMCs, thereby simplifying the overall system architecture while maintaining key distribution reliability

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If domain-specific communication keys are manually installed on the train's control computer before starting the journey, then the train can communicate securely with route centers, but the process is time-consuming and requires permanent connections between KMCs

Engineering Contradiction:
Improvecommunication securityVSAvoidkey installation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-generating communication keys in the home KMC before the train's journey. The keys are prepared in advance based on the planned route and automatically distributed to the train's control computer and relevant route centers, eliminating the need for time-consuming manual key installation processes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing the train's control computer to automatically receive and install communication keys through automated interfaces. The home KMC automatically provides the necessary keys based on the planned route, eliminating manual intervention and reducing key installation time while maintaining security

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If communication keys are distributed to all route centers for a rail vehicle's route, then secure communication is enabled across domains, but the key distribution plan becomes complex and error-prone

Engineering Contradiction:
Improvecross-domain communication capabilityVSAvoidkey distribution plan complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by distributing keys selectively to only those route centers that are actually needed for the train's specific planned route. Each route center receives keys locally relevant to its domain, rather than all route centers receiving all keys. This localized approach reduces key distribution plan complexity while maintaining cross-domain communication capability

Inventive Principle:
Principle #3Local quality

4Extent of automation

If a central key allocation office generates communication keys based on planned routes, then key distribution is simplified and automated, but the system requires coordination between multiple key allocation offices in different domains

Engineering Contradiction:
Improvekey distribution automationVSAvoidinter-office coordination complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent implements universality by designing the home KMC with multi-functional capabilities that allow it to serve as both a key generation center and a key distribution hub for multiple domains. The home KMC can generate keys for the mobile unit and automatically distribute them to route centers in different domains without requiring complex coordination protocols with other KMCs, thereby achieving automation while minimizing coordination complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2658764B1Key management system and method for a train protection system
Publication Date: 2017.08.30 SIEMENS AG
  • EP2658764B1 patent drawingFigure 1A~2C
  • EP2658764B1 patent drawingFigure 3A~4C
  • EP2658764B1 patent drawingFigure 5A~6

AI summary

The invention relates to a method for distributing communication keys (6) for the encryption of traffic control messages of a rail vehicle protection system, having the steps of generating a communication key (6) at a first key allocation point (1a) of a first track operator as a function of a planned route of a rail vehicle (4), making available the communication key (6) to a second key allocation point (1b) of a second track operator, making available the communication key (6) to the rail vehicle (4) by means of the first key allocation point, and encrypting traffic control messages of the rail vehicle (4) with the communication key (6) in order to permit tamper-proof communication of the rail vehicle (4) with operation control centres (3) of the first track operator and with operational control centres (3) of the second track operator.