US 12,107,873 B2
Blockchain-based intrusion detection system for railway signals
Qichang Li, Beijing (CN); Ran Zhao, Beijing (CN); Bingyue Lin, Beijing (CN); Hua Zhang, Beijing (CN); Gang Li, Beijing (CN); Yingying Cui, Beijing (CN); Lin Wang, Beijing (CN); Deji Fu, Beijing (CN); Fei Wang, Beijing (CN); Zibiao Fu, Beijing (CN); Fei Wang, Beijing (CN); Yazhou Kou, Beijing (CN); Jiali Zhao, Beijing (CN); Qiang Gao, Beijing (CN); Xianfeng Luan, Beijing (CN); Hui Zhang, Beijing (CN); Gang Zhao, Beijing (CN); Shi Yan, Beijing (CN); Hao Chang, Beijing (CN); Chaoping Zhu, Beijing (CN); Zhenzhen Liu, Beijing (CN); Zhiduo Xie, Beijing (CN); Yong Yang, Beijing (CN); Yuan Ma, Beijing (CN); and Qizheng Hu, Beijing (CN)
Assigned to Signal and Communication Research Institute, China Academy of Railway Sciences Corporation Ltd., Beijing (CN); China Academy of Railway Sciences Corporation Ltd., Beijing (CN); Beijing Huatie Information Technology Corporation Ltd., Beijing (CN); and Beijing Ruichi Guotie ITS Eng. & Tech. Ltd., Beijing (CN)
Filed by Signal and Communication Research Institute, China Academy of Railway Sciences Corporation Ltd., Beijing (CN); China Academy of Railway Sciences Corporation Ltd., Beijing (CN); Beijing Huatie Information Technology Corporation Ltd., Beijing (CN); and Beijing Ruichi Guotie ITS Eng.&Tech. Ltd., Beijing (CN)
Filed on Dec. 30, 2023, as Appl. No. 18/401,368.
Claims priority of application No. 202310138551.3 (CN), filed on Feb. 20, 2023.
Prior Publication US 2024/0283801 A1, Aug. 22, 2024
Int. Cl. H04L 67/12 (2022.01); H04L 9/40 (2022.01)
CPC H04L 63/1416 (2013.01) [H04L 67/12 (2013.01)] 15 Claims
OG exemplary drawing
 
1. A blockchain-based intrusion detection system for railway signal, comprising:
a plurality of intrusion detection components that are distributed across hardware processors of various business devices within a railway signaling system and a core network, wherein each intrusion detection component functions as an intrusion detection node within a blockchain, a hash value of a system log from the railway signaling system and a hash value of alarm information output by the intrusion detection node are both uploaded to the blockchain; wherein:
each intrusion detection node incorporates an intrusion detection model, the intrusion detection model is employed to conduct intrusion detection on the system log within a business device or the core network where the intrusion detection node is situated, the alarm information output indicates whether there is an external attack;
a trust evaluation program is established by combining intrusion detection precision of each intrusion detection node, the intrusion detection node chosen by the trust evaluation program employs a consensus program to verify the alarm information and achieve a unified representation of intrusion detection results;
wherein the trust evaluation program comprises: a node reward and punishment program and a node trust blacklist program;
wherein the node reward and punishment program is used to reward and penalize the intrusion detection node based on the intrusion detection precision thereof, that is, adjusts a trust weight of the intrusion detection node, and combines the trust weight with the node trust blacklist program to categorize intrusion detection nodes into trusted nodes and untrusted nodes, and a trusted node is the intrusion detection node selected by the trust evaluation program.