Abstract:
To satisfy the timeliness and security requirements for emergency troubleshooting of railway information system faults, this paper designs a secure and stable emergency access scheme based on key technologies including zero-trust security. The scheme establishes a three-layer defense system consisting of access layer, link layer and bastion host layer. The zero-trust security controller implements continuous identity authentication, user behavior monitoring and security auditing, and distributes security policies dynamically. In combination with practical operation and maintenance scenarios, full-process management covering emergency access, post-incident review and routine maintenance is standardized, which effectively guards against risks such as unauthorized access and data tampering. This scheme allows second-line operation and maintenance engineers and third-line manufacturer technicians to resolve faults remotely, safely and efficiently, and delivers solid support for the continuous operation of core railway transportation businesses.