首页> 外国专利> METHOD OF OPERATING A COMPUTER-CONTROLLED DEVICE FOR ESTABLISHING A SECURE DATA COMMUNICATION IN A DISTRIBUTED CONTROL SYSTEM OF A PASSENGER TRANSPORTATION ARRANGEMENT

METHOD OF OPERATING A COMPUTER-CONTROLLED DEVICE FOR ESTABLISHING A SECURE DATA COMMUNICATION IN A DISTRIBUTED CONTROL SYSTEM OF A PASSENGER TRANSPORTATION ARRANGEMENT

机译:操作计算机控制设备的方法,用于在乘客运输布置的分布式控制系统中建立安全数据通信

摘要

A method of operating a computer-controlled first device (15) for establishing a secure data communication (23) between the computer-controlled first device (15) and a computer-controlled second device (17) in a distributed control system (27) of a passenger transportation arrangement (1) is proposed. The method comprises: (i) generating an encryption key including e.g. a key pair with a public and a private key; (ii) creating credentials in form of a certificate such as an X509 certificate based on the generated encryption key; (iii) preparing a certificate signing request CSR and dispatching the CSR to a certificate authority CA (21) via a secured data communication path (25), wherein the CA (21) is based on a public key infrastructure PKI (19) operated by an operator of the passenger transportation arrangement (1); (iv) receiving the certificate back from the CA (21), wherein the received certificate is signed by the CA (21) with a signature using a private key being a secret held by the operator of the passenger transportation arrangement (1); (v) establishing the secure data communication (23) with the computer-controlled second device (17) by transmitting the credentials to the second device (17), wherein the second device (17) accepts establishing the secure data communication (23) upon verification of the signature of the credentials, wherein the verification of the signature of the credentials is executed using a public key of the operator of the passenger transportation arrangement (1).
机译:一种操作计算机控制的第一设备(15)的方法,用于在分布式控制系统(27)中的计算机控制的第一设备(15)和计算机控制的第二设备(17)之间建立安全数据通信(23)提出了乘客运输安排(1)。该方法包括:(i)生成加密密钥,包括例如。与公共和私钥的密钥对; (ii)以证书的形式创建凭据,例如基于生成的加密密钥的X509证书; (iii)准备证书签名请求CSR并通过安全的数据通信路径(25)将CSR发送到证书颁发机构CA(21),其中CA(21)基于由此操作的公钥基础设施PKI(19)。乘客运输安排的运营商(1); (iv)从CA(21)收到证书,其中收到的证书由CA(21)签署了使用私钥的签名,作为客运安排的运营商(1)的秘密; (v)通过将凭证发送到第二设备(17),利用计算机控制的第二设备(17)建立安全数据通信(23),其中第二设备(17)接受建立安全数据通信(23)验证凭证的签名,其中使用乘客运输布置(1)的操作员的公钥来执行凭证的签名。

著录项

  • 公开/公告号WO2021160542A1

    专利类型

  • 公开/公告日2021-08-19

    原文格式PDF

  • 申请/专利权人 INVENTIO AG;

    申请/专利号WO2021EP52900

  • 发明设计人 COLOMBANO CLAUDIO;

    申请日2021-02-08

  • 分类号B66B1/34;B66B19;

  • 国家 EP

  • 入库时间 2022-08-24 20:43:42

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号