GATEWAY AND METHOD FOR OPERATING A GATEWAY
20240007442 · 2024-01-04
Inventors
- Klaus Theuerkauf (Magdeburg, DE)
- Christian Reusch (Hannover, DE)
- Florian Neumann (Vechelde, DE)
- Jasper Hagenbuck (Braunschweig, DE)
Cpc classification
H04L63/029
ELECTRICITY
H04L12/66
ELECTRICITY
H04N7/035
ELECTRICITY
International classification
H04N7/035
ELECTRICITY
H04L12/66
ELECTRICITY
Abstract
A gateway for connection to a closed network of a railroad technical system has a network adapter for establishing a network connection to an external network. A video signal adapter can establish a video signal connection to the railroad technical system, and/or a device signal adapter can establish a device signal connection to the railroad technical system. At least one conversion facility is connected to both the network adapter and the video signal transmitter and/or the device signal adapter and converts the video or device signal connection data of the railroad technical system into external network data. The gateway thus provides particularly secure access to the closed network of the railroad technical system. There is also described a method for operating a gateway for connection to a closed network of a railroad technical system.
Claims
1. A gateway for connection to a closed network of a railroad technical system, the gateway comprising: a network adapter for establishing a network connection to a network that is external to the network of the railroad technical system; at least one signal adapter selected from the group consisting of: a video signal adapter for establishing a video signal connection to the railroad technical system; and a device signal adapter for establishing a device signal connection to the railroad technical system; and a conversion facility connected to both said network adapter and said at least one signal transmitter, said conversion facility being configured to convert at least one of video signal connection data or device signal connection data of the railroad technical system into external network data.
2. The gateway according to claim 1, wherein said conversion facility is also embodied to convert external network data into video signal connection data or device signal connection data of the railroad technical system.
3. The gateway according to claim 2, further comprising at least one key-operated switch configured to enable said conversion facility for converting external network data into video signal connection data and/or device signal connection data of the railroad technical system to be activated.
4. The gateway according to claim 1, further comprising at least one authentication facility configured to authenticate access on the part of said network adapter.
5. The gateway according to claim 1, further comprising at least one audit log facility configured to record access actions on the part of said network adapter.
6. The gateway according to claim 1, wherein the gateway is embodied as at least partially movable in a housing.
7. The gateway according to claim 1, which comprises: at least one first part to be connected to a user and at least one second part to be connected to the railroad technical system for establishing a signal connection by at least one of the device signal connection or the video signal connection; and wherein said at least one first part and said at least one second part are connected to one another by way of a network connection and are arranged remotely from one another.
8. The gateway according to claim 7, wherein the network connection between said first and second parts is a radio connection.
9. The gateway according to claim 8, wherein the network connection is an LTE connection.
10. A method for operating a gateway for connection to a closed network of a railroad technical system, the method comprising: providing the gateway according to claim 1; and receiving and converting at least one of video signal connection data or device signal connection data of the railroad technical system into external network data.
11. The method according to claim 10, which comprises also converting external network data into at least one of video signal connection data or device signal connection data of the railroad technical system.
12. The method according to claim 10, which comprises authenticating access of the network adapter.
13. The method according to claim 10, which comprises recording access activity on the part of the network adapter.
14. A computer program product with program instructions for performing the method according to claim 10.
15. A non-transitory program carrier for the computer program product according to claim 14, wherein the program carrier is configured to store and/or load the computer program product into a computer.
Description
BRIEF DESCRIPTION OF THE FIGURES
[0033]
[0034]
[0035]
DETAILED DESCRIPTION OF THE INVENTION
[0036] Referring now to the figures of the drawing in detail and first, in particular, to
[0037] The railroad technical system 2 comprises, for example, at least one subway train, street car, mainline train, freight train, i.e., a wide variety of rail vehicles together with their route network and a signaling system that is responsible for vehicle control or train control. As is common in all modern railroad technical systems, the railroad technical system 2 in
[0038] In order to ensure the security of the railroad technical system 2, the network 5 within the railroad technical system 2 is embodied as a closed network 5. It is, for example, set up as a Category 2 network according to the standard EN 50159, for which special requirements apply regarding isolation. Simple network access to the railroad technical system network 2 from outside is not desired with the exemplary embodiment in
[0039] Nevertheless, remote access of this kind by the user 4 by way of a computer 3 is still possible with the aid of the gateway 1 according to the invention, as described below. For the sake of simplicity, only the closed network of the railroad technical system 2 is shown in the figures.
[0040] In the exemplary embodiment in
[0041] On the other hand, the gateway 1 according to the invention is connected to the user's 4 computer 3 by a network connection 13. Herein, the network connection 13 is connected to the network adapter 6 of the gateway 1. The network connection 13 is part of a non-illustrated external network embodied externally to the network 5 of the railroad technical system 2. The computer 3 also comprises a commercially available network adapter (not shown) to which the network connection 13 is connected. The user's 4 computer 3 is a commercially available computer such as, for example, a laptop with which a network connection 13 is possible. The network connection 13 can be wired, for example, via Ethernet, or can also be at least partially wireless via WLAN and Internet.
[0042] The gateway 1 according to the invention provides the user 4 with remote access to the network 5 of the railroad technical system 2 via the computer. However, there is no direct connection between the computer 3 and the network 5 of the railroad technical system 2. Rather, there is a protocol break in the gateway 1 so that the connection from the computer 3 could be described as indirect and in any case as having no repercussions for the network 5. This ensures a high level of security for the network 5 and the railroad technical system 2.
[0043] In the video signal adapter 7 of the gateway 1, video signals from the network 5 of the railroad technical system 2 arrive in the gateway 1 via the HDMI line 11. Since the conversion facility 9 is connected to the network adapter 6, the device signal adapter 8 and also the video signal adapter 7, the video signals from the network 5 are transmitted to the conversion facility 9.
[0044] The conversion facility 9 now converts the video signals, i.e., the data from the video signal connection with the network 5, into data that can be fed in the network connection 13 via the network adapter 6. This conversion of the data formats in the conversion facility 9 is performed by a microprocessor contained in the conversion facility 9. Herein, first the video signals from the network 5 are analyzed and then converted into data in a data format of the external network of the network connection 13. This could also be referred to as a translation. This conversion is necessary because the data format of the video signal connection at the video signal adapter 7 is different from the data format at the network adapter 6. This conversion of the data formats includes the protocol break that ensures security for the railroad technical system 2. Data from the network adapter 6 cannot be automatically fed into the network 5 by the video signal adapter 7 because the data formats are different. Thus, it would not be possible to transmit data without the conversion facility 9.
[0045] After the conversion of the data formats by the conversion facility 9, the video information from the network 5 can be transmitted via the network connection 13 to the computer 3 and displayed there. In this way, video information that would otherwise only be visible on display facilities within the network 5 of the railroad technical system is displayed to the user 4 on the computer 3, in particular on the monitor of the computer 3. Here, the selected connection between the video signal adapter 7 and the network 5 is, for example, the HDMI line 11 because this is common at the present time. Obviously, the connection can also be implemented with other video signal connections.
[0046] In particular, to enable the user 4 to make entries in the network 5 of the railroad technical system, the gateway 1 is also embodied to convert device signals. These device signals are generated in the usual way on the computer 3 by the user 4, for example in the form of keyboard entries or mouse movements or the like. These device signals are routed via the network connection 13 to the gateway 1 and in particular to the network adapter 6. These device signals are analyzed in the conversion facility 9 and converted by the conversion facility 9 into the appropriate data format for the device signal adapter 8. Here, another protocol break takes place, so that there is no direct connection to the network. In the exemplary embodiment 1 in
[0047] These translated device signals are fed into the network 5 of the railroad technical system 2 via the USB line 12. In this way, the entries made by the user 4 reach the network 5 of the railroad technical system 2 via the gateway 1 according to the invention as if the user 4 were acting directly within the railroad technical system 2. Therefore, the conversion facility 9 of the gateway 1 according to the invention emulates the operating actions of the user 4 as performed on the remote computer 3. As a result, the operating actions of the user 4 appear as if they had been performed within the network 5.
[0048] In the exemplary embodiment in
[0049] In the exemplary embodiment in
[0050] The authentication facility 16 is embodied to authenticate access to the network adapter 6 of the gateway 1. As a result, the user 4 has to be authenticated by means of a personal certificate so that it is possible to trace who has access to the network adapter 6.
[0051] The audit log facility 17 is embodied to record access actions on the part of the network adapter thereby providing increased security. The audit log facility records who has gained access to the network adapter 6. This is advantageous because it means that any subsequent access to the gateway according to the invention is also recorded. The protocol data generated by the audit log facility 17 can also be transmitted to a separate external location for storage.
[0052] In the exemplary embodiment in
[0053] In the exemplary embodiment in
[0054] In the following, the invention will be described with reference to the exemplary embodiment in
[0055] In the exemplary embodiment in
[0056] In the exemplary embodiment in
[0057] In the embodiment in
[0058] In the following, the invention is described with reference to the further exemplary embodiments in
[0059] In contrast to the embodiment in