期刊文献+

高速铁路信号系统网络安全与统一管控 被引量:21

Analysis of Network Security for Chinese High-Speed Railway Signal Systems and Proposal of Unified Security Control
下载PDF
导出
摘要 为了保障我国高速铁路信号系统的网络安全,从高速铁路信号系统的整体架构出发,对系统所面临的网络安全问题进行了全面的分析,涵盖了分散自律调度集中系统、列车运行控制系统、集中监测系统和GSM-R无线通信系统等.在此基础上,提出了基于软件定义网络(SDN)的高速铁路信号系统网络安全统一管控方案,把分散自律调度集中网络、信号安全数据网和集中监测网络通过软件定义的方式进行管控和隔离,实现了对网络流量的精细控制和统一管理,利用逻辑上统一的控制器实现全局的设备注册管理、安全通信访问控制和网络数据的追踪溯源,从而提高了网络的安全性,减小了网络管理的复杂性.通过分析可知,本文所提出的架构具有逻辑集中管控、统一安全策略、网络可编程等特点,相对于分散管理的网络更适用于高铁信号系统专网的网络安全管理,可以解决我国高速铁路信号系统不同安全等级网络互联和复杂网络安全管控的问题. In order to ensure the network security of China's high-speed railway signal system, the network security issues including the central traffic control (CTC) system, train control system, centralized signal monitoring system and the GSM-R system were analyzed generally. Subsequently a unified network security control and management strategy was proposed based on the software-defined networking (SDN) architecture. The centralized management and unified security policies are achieved in one physical network, and the original control logics between sub-networks including CTC network, train control network and centralized signal monitoring network are all software-defined in the control plane, which enables the finer and unified control of the whole network. Using the logically centralized controller, the unified device register control, communication control and packet traceability are all achieved, thus improving the network security and reducing the management complexity. According to the analysis, the proposed architecture is centrally managed, network programmable and unified of the security policy. The proposed strategy is better than the distributed control network for the managementof China's high-speed railway signal system network security and can solve the complex management of networks' intereonnection of different security levels.
出处 《西南交通大学学报》 EI CSCD 北大核心 2015年第3期478-484,503,共8页 Journal of Southwest Jiaotong University
基金 国家自然科学基金资助项目(61401377) 铁道部重大项目(2012X004-A) 教育部重大项目(313049)
关键词 高速铁路 信号系统 网络安全 软件定义网络 下一代铁路信号系统网络 CTCS-3 high-speed railway signal systems network security software-defined networking next generation network of Chinese high-speed railway signal system CTCS-3
  • 相关文献

参考文献16

  • 1MARTIN C, MICHAEL J, JUSTIN P, et al. Ethane: taking control of the enterprise[J]. ACM SIGCOMM Computer Communication Review, 2007, 37 (4) : 1- 12.
  • 2中华人民共和国铁道部.运基通信[2006]185号GSM—R与CTC系统接口规范[S/OL].(2006-06一08)12014-08-051http://wenku.baidu.com/link?url:Ojz—WTidYAHvmsH8GHDIpiOPeTMLBl4Fv8WzmqKFgyUgsaZLk_Z1mJoUoK9AdgcKVrD6kdumiROkLgli8weleb4jv9P17Qi0V——R12HmdnMi.
  • 3LI S F, YAN L S, XING H L, et al. Enhanced robustness of control network for chinese train control system level 3 (CTCS-3) facilitated by software defined networking [ J ]. International Journal of Rail Transportation, 2014, 2(4) : 239-252.
  • 4BREWER R. Advanced persistent threats: minimising thedamaged[J]. Network Security, 2014, 2014(4): 5-9.
  • 5中华人民共和国铁道部.运基信号[2009]223号客运专线信号系统安全数据网技术方案V2.0[s/OL].(2010—11—12)[2014-08-05].http://wenku.baidu.com/link?url=8TJbHyzuhblxjG3n—yuHBlwiiorh3M55dV2elXl—njji—DQ—fKeGG—POi—R1emfjXzM89sH2pMojpnOKJG2hWM7pFev2UB45zLAvhDOJsqe.
  • 6刘大为,郭进,王小敏,陈建译,杨扬.中国铁路信号系统智能监测技术[J].西南交通大学学报,2014,49(5):904-912. 被引量:42
  • 7中华人民共和国铁道部.科技运[2004]15号分散自律调度集中系统技术条件[S/OL].(2004-02-12)[2014-08-05].http://www.cqvip.com/QK/7l135X/201107/15210729.html.
  • 8中华人民共和国铁道部.科技运[2008]34号CTCS一3级列控系统总体技术方案[S].北京:中国铁道出版社,2008.
  • 9NICK M, ANDERSON T, BALAKRISHNAN H, et al. OpenFlow: enabling innovation in campus networks [ J ]. ACM Sigcomm Computer Communication Review, 2008, 38(2): 69-74.
  • 10SHERWOOD R, GIBB G, YAP K K, et al. Carving research slices out of your production networks with OpenFlow [ J ]. ACM Sigcomm Computer Communication Review, 2010, 40( 1 ) : 129-130.

二级参考文献26

共引文献41

同被引文献153

引证文献21

二级引证文献84

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部