Railway technology device for a railway system and method for its operation
The railway technology device with a failure prediction system monitors key and main memory for impending failures, addressing the challenge of detecting errors in cryptographic key storage to prevent ETCS operational issues.
Patent Information
- Application Number
- EP2022155143
- Authority / Receiving Office
- EP · EP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-03-16
- Filing Date
- 2022-02-04
- Publication Date
- 2025-12-17
- Estimated Expiration
- 2042-02-04
AI Technical Summary
Existing railway technology systems face challenges in detecting potential failures in cryptographic key storage systems before they occur, which can lead to operational failures in the European Train Control System (ETCS), due to limited write cycles and the need for fault-tolerant, high-performance key storage with real-time error detection.
A railway technology device equipped with a failure prediction device that monitors key memory and volatile main memory for status information, generating warning signals when imminent failures are detected, using SMART-compatible queries and sensors to ensure timely maintenance.
The device effectively predicts and prevents failures in cryptographic key storage by issuing warning signals, allowing for proactive maintenance and ensuring the integrity of the ETCS system, thereby avoiding operational disruptions.
Smart Images

Figure IMGF0001 
Figure IMGF0002 
Figure IMGF0003
Abstract
Description
[0001] The invention relates to a railway technology device for a railway technology system with at least one computing unit and at least one key storage unit for storing cryptographic keys, which enable encrypted and / or cryptographically secured transmission of data between a railway vehicle and trackside facilities.
[0002] In SMITH J ET AL: "Security as a safety issue in rail communications", ADVANCES IN ONTOLOGIES, AUSTRALIAN COMPUTER SOCI-ETY, INC, PO BOX 319 DARLINGHURST, NSW 2010 AUSTRALIA, October 1, 2003 (2003-10-01), pages 79-88, a project is described in which safety-critical communication in a railway network is to be implemented.
[0003] In the field of railway technology, the safety-related data transmission via mobile networks for train control applications (ETCS - European Train Control System) relies on cryptographic methods. These methods use secret cryptographic keys to ensure the integrity and authenticity of the control data exchanged between trains and trackside control centers.
[0004] Since at least one key pair is usually used for each relationship between train and track control center, a large number of crypto keys are stored in the vehicles and track control centers, depending on the size of the rail network and the number of trains, especially if the crypto keys only have a time validity period.
[0005] Therefore, the systems communicating within ETCS require suitable key storage facilities that are supplied with the appropriate key material both offline and online. The key distribution procedures used for this purpose, as well as the actual train control protocol, are standardized at the European level (UNISIG Subsets 114 and 137).
[0006] The key storage systems of the ETCS instances are subject to special requirements regarding fault tolerance, performance, and integrity. For example, specific cryptographic keys must be selectable from thousands of keys within seconds based on various characteristics such as ETCS identity and current system time. Complex transactions, such as updating the validity of a large number of keys, must also be executed flawlessly. Furthermore, the integrity of the key storage system must be maintained even if a power outage interrupts ongoing transactions in an onboard computer at any given time. Finally, key storage systems implemented on flash hardware must be optimized with regard to their write cycles, as these storage systems are limited in the number of write accesses (flash cells can only perform between 3,000 (MLC 25 nm) and 100,000 (SLC) write operations).
[0007] Another requirement, arising both from the European standard (UNISIG Subset 137) and from the requirements of reliable ETCS train operations, is to disclose errors in the locally stored key data, as incorrect or unreadable crypto keys can lead to the failure of ETCS train operations and thus to significant operational problems.
[0008] To meet this requirement, the UNISIG specification includes error messages for cryptographic keys stored on the vehicles. To detect faulty cryptographic keys, key integrity can be monitored at the application level by, for example, storing a checksum for each specific cryptographic key and verifying it cyclically or before the key is used. However, this approach only detects problems after they have occurred and operates at the application level.
[0009] The invention is therefore based on the objective of providing an improved railway technology device with regard to the problem described above.
[0010] This problem is solved according to the invention by a railway technology device with the features according to device claim 1 and method claim 14. Advantageous embodiments of the railway technology device according to the invention are specified in the dependent claims.
[0011] According to the invention, the railway technology device is provided with a failure prediction device that can detect a potentially imminent failure of at least one component of the railway technology device and issue a warning signal indicating the potential failure.
[0012] A significant advantage of the railway technology device according to the invention lies in its ability to detect a potentially impending failure, i.e., a failure that has not yet occurred, using its failure prediction device, and to issue a timely warning signal indicating the possible failure. This allows operational restrictions to be avoided through timely maintenance or repair. In this way, errors in the ETCS key memory can be advantageously detected even before they occur, i.e., before any damaged or unusable keys need to be used for system operation.
[0013] According to the invention, the key memory is equipped with an internal memory monitoring device that can record status information relating to the key memory and output it upon query.
[0014] According to the invention, the failure prediction device is connected to the internal memory monitoring device and is designed to read at least one status information relating to the key memory from the internal memory monitoring device at regular or irregular intervals, to conclude on the basis of the at least one read-out status information a possible complete or partial failure of the key memory and to generate the warning signal on the basis of the at least one read-out status information.
[0015] In the latter variant, it is advantageous if the key memory comprises memory blocks used for storage as well as reserve blocks, which are used as replacements for failed memory blocks in the event of one or more failures, and if the failure prediction device reads the number of reserve blocks already in use from the internal memory monitoring device and generates the warning signal at least partly based on the number of reserve blocks already in use. Preferably, the warning signal is generated as soon as the memory monitoring device receives information that a predetermined number, preferably one, of reserve blocks has been used as a replacement for a failed memory block.
[0016] Alternatively or additionally, it can be advantageously provided that the failure prediction device reads the read error rate from the internal memory monitoring device when reading the key memory and generates the warning signal at least also on the basis of the read error rate, in particular generating the warning signal when the read error rate exceeds a predetermined maximum read error rate value.
[0017] Alternatively or additionally, it can be advantageously provided that the failure prediction device reads the erasure error rate from the internal memory monitoring device when erasing the key memory and generates the warning signal at least also on the basis of the erasure error rate, in particular generating the warning signal when the erasure error rate exceeds a predetermined maximum erasure error rate value.
[0018] Alternatively or additionally, it can be advantageously provided that the failure prediction device reads the number of uncorrectable errors of the key memory from the internal memory monitoring device and generates the warning signal at least also on the basis of the number of uncorrectable errors, in particular generating the warning signal when the number of uncorrectable errors exceeds a predetermined maximum value.
[0019] Alternatively or additionally, it can be advantageously provided that the failure prediction device reads the number of timeouts for commands to the key memory from the internal memory monitoring device and generates the warning signal at least also on the basis of the number of timeouts for commands, in particular generating the warning signal when the number of timeouts for commands to the key memory exceeds a predetermined maximum value.
[0020] Alternatively or additionally, it can be advantageously provided that the failure prediction device reads the number of unstable sectors of the key memory from the internal memory monitoring device, i.e., sectors that are temporarily or permanently unreadable, and generates the warning signal at least also on the basis of the number of unstable sectors, in particular generating the warning signal when the number of unstable sectors of the key memory exceeds a predetermined maximum value.
[0021] It is particularly advantageous if the failure prediction device is designed to read two or more status information items from the internal memory monitoring device at regular or irregular intervals, to infer a possible complete or partial failure of the key memory based on the two or more read status information items, and to generate the warning signal based on the two or more status information items.
[0022] The failure prediction device is preferably SMART-compatible (SMART: "Self-Monitoring, Analysis and Reporting Technology") and suitable for sending SMART-compatible queries to the internal memory monitoring device, evaluating SMART-compatible responses from the internal memory monitoring device, and generating the warning signal at least also on the basis of the SMART-compatible responses from the internal memory monitoring device.
[0023] The railway technology device is preferably suitable for receiving new cryptographic keys from a trackside key exchange device via a data transmission system and storing these as replacements for old keys previously stored in the key memory.
[0024] The failure prediction device preferably transmits the warning signal to the key exchange device when a possible or imminent failure of the key storage is detected.
[0025] The railway technology device is preferably designed to transmit a positive acknowledgment signal to the key exchange device after successful replacement of old keys with new keys.
[0026] The railway technology device is preferably designed to transmit a negative acknowledgment signal to the key exchange device after each unsuccessful exchange of old keys with new keys.
[0027] The failure prediction device is preferably designed to transmit the warning signal to the key exchange device together with, or as part of, the respective acknowledgment signal when a possible or imminent failure of the key storage is detected.
[0028] In an advantageous embodiment, the railway technology device is a vehicle control unit, in particular an ETCS-compatible (ETCS: European Train Control System) vehicle control unit, which stores cryptographic information non-volatilely.
[0029] In another advantageous embodiment, the railway technology device is a stationary trackside device, in particular an ETCS-compatible trackside device, or a trackside key distribution device.
[0030] It is advantageous if the railway technology device has a volatile main memory in addition to the key memory.
[0031] The failure prediction device is preferably designed to detect a possible or imminent failure of the volatile main memory and to issue a warning signal indicating the possible failure of the main memory.
[0032] The failure prediction device is preferably designed to detect parity errors in the main memory and to generate a warning signal indicating a possible or imminent failure of the main memory based on the parity errors.
[0033] It is also advantageous if the computing device has at least one sensor, in particular a temperature sensor, which can record at least one piece of status information relating to the computing device, in particular the temperature of the computing device, by forming a sensor measurement value.
[0034] The failure prediction device is preferably designed in such a way that it generates a warning signal indicating a possible or imminent failure of the computing device, at least also on the basis of the sensor measurement value.
[0035] The invention further relates to a railway engineering system. According to the invention, the system is provided to include a railway engineering device as described above.
[0036] Regarding the advantages and advantageous embodiments of the system according to the invention, reference is made to the above statements in connection with the railway technology device according to the invention and its advantageous embodiments.
[0037] The invention further relates to a vehicle, in particular a rail vehicle. According to the invention, the vehicle is provided to have a railway technology device as described above.
[0038] Regarding the advantages and advantageous embodiments of the vehicle according to the invention, reference is made to the above statements in connection with the railway technology device according to the invention and its advantageous embodiments.
[0039] The invention further relates to a method according to claim 14 for operating a railway technology device equipped with at least one computing unit and at least one key storage unit for storing cryptographic keys that enable encrypted and / or cryptographically secured transmission of data between the railway vehicle and trackside equipment. According to the invention, the railway technology device is monitored for a possible failure of at least one component of the railway technology device, and a warning signal indicating a possible or impending failure is issued if a monitoring result suggests a possible failure.
[0040] Regarding the advantages and advantageous embodiments of the method according to the invention, reference is made to the above statements in connection with the railway technology device according to the invention and its advantageous embodiments.
[0041] The invention is explained in more detail below with reference to exemplary embodiments; these show, by way of example, Figure 1 shows an embodiment of a section of a railway installation according to the invention, which is traversed by an embodiment of a rail vehicle according to the invention; Figure 2 shows an embodiment of a railway device according to the invention for the installation and the rail vehicle. Figure 1 Figure 3 shows a further embodiment of a railway technology device according to the invention for the plant and the rail vehicle according to Figure 1and Figure 4 shows a further embodiment for a section of a railway technical installation according to the invention, which is traversed by an embodiment for a rail vehicle according to the invention.
[0042] For the sake of clarity, the same reference symbols are always used in the figures for identical or comparable components.
[0043] The Figure 1 shows a section of a railway technical installation 10. A rail vehicle 20 can be seen traveling along a track 30 in the direction of an arrow P.
[0044] The railway technical system 10 is equipped with a key exchange device 40 for transmitting cryptographic keys to other devices of the railway technical system 10. In the exemplary embodiment shown, the key exchange device 40 is located Figure 1 connected to a trackside communication device 50.
[0045] The trackside communication device 50 is in turn connected to a vehicle-side communication device 21 of the rail vehicle 20. The vehicle-side communication device 21 and the trackside communication device 50 thus both form components of a data transmission system 60 of the railway technical system 10.
[0046] The vehicle-side communication device 21 is connected to a vehicle control unit 22, which is connected to a device in the Figure 1 The key storage, which is not shown in detail for clarity, is suitable for storing cryptographic keys. The cryptographic keys enable encrypted and / or cryptographically secured data transmission between the rail vehicle 20 and trackside equipment, for example, the trackside communication equipment 50, as described in [reference to relevant document]. Figure 1 .
[0047] The trackside key exchange device 40 serves to transmit new cryptographic keys via the data transmission system 60, for example to the vehicle control unit 22 of the rail vehicle 20, so that these can be stored as replacements for old keys previously stored in the key memory of the rail vehicle 20 and used in the future.
[0048] The vehicle control unit 22 of the rail vehicle 20 is designed such that, after a successful exchange of old keys for new keys, it sends a positive confirmation signal QS to the key memory (not shown) or, in the case of a failed exchange, a negative confirmation signal. QS transmitted to the key exchange facility 40.
[0049] Furthermore, the vehicle control unit 22 is equipped with a [unclear] in the Figure 1For the sake of clarity, the key is also equipped with a failure prediction device, which, upon detection of a possible or imminent failure of the key storage, transmits a warning signal WS together with the aforementioned positive or negative acknowledgment signal or as part of the respective acknowledgment signal to the key exchange device 40.
[0050] The Figure 2 Figure 1 shows an embodiment of a railway technology device 100 according to the invention, which can be used as a vehicle control unit 22 in the rail vehicle 20. The railway technology device 100 is preferably ETCS-compatible.
[0051] The railway technology device 100 comprises a computing unit 110, a key memory 120, a volatile main memory 130, and a software memory 140 in which a railway technology software module SPM is stored. The railway technology software module SPM serves to ensure the operation of the railway technology device 100 when executed by the computing unit 110, in this case, its operation as an ETCS-compatible vehicle control unit 22.
[0052] In addition, the software memory 140 contains a failure prediction module AVM, which, when executed by the railway technology device 100, forms a failure prediction device.
[0053] The failure prediction module AVM, or rather the failure prediction device formed by it, is connected to both the key memory 120 and the volatile main memory 130. The failure prediction module AVM, or rather the failure prediction device formed by it, serves to monitor the functionality of both the key memory 120 and the volatile main memory 130.
[0054] In order to enable or simplify this monitoring of the key storage 120, the key storage 120 is equipped with an internal storage monitoring device 121, which can record status information ZI relating to the key storage 120 and output it on request.
[0055] The failure prediction module AVM, or the failure prediction device it forms, communicates with the internal memory monitoring device 121 and is designed to read at least one status information ZI relating to the key memory 120 from the internal memory monitoring device 121 at regular or irregular intervals. It evaluates the at least one read status information ZI and, if necessary, concludes that the key memory 120 has failed completely or partially. Subsequently, it may generate the warning signal WS based on the evaluation of the at least one read status information ZI.
[0056] It is advantageous if the key memory 120 has memory blocks used for storage as well as reserve blocks that are used as replacements for failed memory blocks in the event of one or more failures. In this case, the failure prediction module AVM, or the failure prediction device formed by it, can read the number of reserve blocks already in use from the internal memory monitoring device 121 and generate the warning signal WS, at least in part, based on the number of reserve blocks already in use. For example, the failure prediction module AVM, or the failure prediction device formed by it, will generate the warning signal WS as soon as the memory monitoring device 121 provides information that a first reserve block has been used as a replacement for a failed memory block.Alternatively, it can also generate the warning signal WS only when a predetermined maximum number greater than one of reserve blocks has been used.
[0057] Alternatively or additionally, the failure prediction module AVM or the failure prediction device formed by it can read the read error rate when reading the key memory 120 from the internal memory monitoring device 121 and generate the warning signal WS at least also on the basis of the read error rate, in particular generate the warning signal WS if the read error rate exceeds a predetermined maximum read error rate value.
[0058] Alternatively or additionally, the failure prediction module AVM or the failure prediction device formed by it can read the deletion error rate from the internal memory monitoring device 121 when deleting the key memory 120 and generate the warning signal WS at least also on the basis of the deletion error rate, in particular generate the warning signal WS if the deletion error rate exceeds a predetermined maximum deletion error rate value.
[0059] Alternatively or additionally, the failure prediction module AVM or the failure prediction device formed by it can read the number of uncorrectable errors of the key memory 120 from the internal memory monitoring device 121 and generate the warning signal WS at least also on the basis of the number of uncorrectable errors, in particular generate the warning signal WS if the number of uncorrectable errors exceeds a specified maximum value.
[0060] Alternatively or additionally, the failure prediction module AVM or the failure prediction device formed by it can read the number of timeouts for commands to the key memory 120 from the internal memory monitoring device 121 and generate the warning signal WS at least also on the basis of the number of timeouts for commands, in particular generate the warning signal WS if the number of timeouts for commands to the key memory 120 exceeds a predefined maximum value.
[0061] Alternatively or additionally, the failure prediction module AVM or the failure prediction device formed by it can read the number of unstable sectors of the key memory 120 from the internal memory monitoring device 121, i.e., sectors that are temporarily or permanently unreadable, and generate the warning signal WS at least also on the basis of the number of unstable sectors, in particular generating the warning signal WS if the number of unstable sectors of the key memory 120 exceeds a predetermined maximum value.
[0062] The failure prediction module AVM, or the failure prediction device formed by it, and the internal memory monitoring device 121 are preferably SMART-compatible. This means that the failure prediction module AVM, or the failure prediction device formed by it, can send SMART-compatible queries to the internal memory monitoring device 121, and the internal memory monitoring device 121 can generate SMART-compatible responses. The failure prediction module AVM, or the failure prediction device formed by it, evaluates the SMART-compatible responses from the internal memory monitoring device 121 and generates the warning signal WS, at least in part, based on the SMART-compatible responses from the internal memory monitoring device 121.
[0063] Furthermore, the failure prediction module AVM is designed to monitor the volatile main memory 130 with regard to its functionality. Specifically, when executed by the computing unit 110, the failure prediction module AVM will detect a possible or imminent failure of the volatile main memory 130 and generate a warning signal WS indicating the possible failure of the main memory 120 if parity errors are detected in the main memory 130.
[0064] The Figure 3 shows a further embodiment of a railway technology device 100, which is used as a vehicle control unit 22 in the rail vehicle 20 according to Figure 1 can be used. Unlike the railway technology device 100 according to Figure 2 is in the railway technology device 100 according to Figure 3An additional sensor 150 is provided, which monitors at least one physical property of the computing device 110. For example, the sensor 150 can be a temperature sensor that detects status information relating to the computing device 110 in the form of its temperature, generates a corresponding sensor measurement value M, and transmits this value to the failure prediction module AVM.
[0065] If the failure prediction module AVM receives status information from sensor 150 indicating that a failure of the computing unit 110 is to be expected, for example due to overheating, the failure prediction module AVM will generate a corresponding warning signal WS on its output side and transmit it to the nearest communication device 50 on the trackside according to Figure 1 to transmit so that the relevant failure information is available on the route side in a timely manner.
[0066] The Figure 4Figure 1 shows a further embodiment of a railway technical system 10 in which a rail vehicle 20 travels on a track system 30. In contrast to the embodiment according to Figure 20, the embodiment shown is further illustrated in Figure 20. Figure 1 The trackside communication equipment 50 is also equipped with a railway technology device 100, as exemplified in connection with the Figure 2 and 3 This has been explained. Regarding the design of the railway technology device 100 according to Figure 4 Therefore, refer to the above statements in connection with the Figure 2 and 3 referred.
Claims
1. Railway engineering device (100) for a railway engineering installation (10) with at least one computing facility (110) and at least one keystore (120) for storing cryptographic keys, which enable an encrypted and / or cryptographically secured transfer of data between the rail vehicle (20) and trackside facilities (50), wherein the railway engineering device (100) is equipped with a failure prediction facility (AVM), which can establish a potentially impending failure of at least one component of the railway engineering device (100) and can output a warning signal (WS) indicating the possible failure, wherein - the keystore (120) is equipped with an internal storage monitoring facility (121), which can capture status information (ZI) relating to the keystore (120) and can output it on request, and characterised in that - the failure prediction facility (AVM) is connected to the internal storage monitoring facility (121) and is embodied to read out at least one item of status information (ZI) relating to the keystore (120) from the internal storage monitoring facility (121) at regular or irregular intervals, to infer a possible full or partial failure of the keystore (120) on the basis of the at least one item of status information (ZI) that is read out, and to generate the warning signal (WS) on the basis of the at least one item of status information (ZI) that is read out.
2. Railway engineering device (100) according to claim 1, characterised in that - the keystore (120) has storage blocks that are used for storage purposes, as well as reserve blocks that are used when one or more storage blocks fail, as a replacement for the failed storage blocks, and - the failure prediction facility (AVM) reads out the number of reserve blocks that have already been used from the internal storage monitoring facility (121) and generates the warning signal (WS) at least also on the basis of the number of reserve blocks that have already been used, in particular generates the warning signal (WS) as soon as the storage monitoring facility (121) receives the information that a predefined number, preferably amounting to one, of reserve blocks has been used as a replacement for a failed storage block.
3. Railway engineering device (100) according to one of the preceding claims 1 to 2, characterised in that the failure prediction facility (AVM) is embodied to read out two or more items of status information (ZI) from the internal storage monitoring facility (121) at regular or irregular intervals, to infer a possible full or partial failure of the keystore (120) on the basis of the two or more items of status information (ZI) that are read out, and to generate the warning signal (WS) on the basis of the two or more items of status information (ZI).
4. Railway engineering device (100) according to one of the preceding claims 1 to 3, characterised in that the failure prediction facility (AVM) - reads out the read error rate during reading of the keystore (120) from the internal storage monitoring facility (121) and generates the warning signal (WS) at least also on the basis of the read error rate, in particular generates the warning signal (WS) if the read error rate exceeds a predefined maximum value for the read error rate, and / or - reads out the delete error rate during deletion of the keystore (120) from the internal storage monitoring facility (121) and generates the warning signal (WS) at least also on the basis of the delete error rate, in particular generates the warning signal (WS) if the delete error rate exceeds a predefined maximum value for the delete error rate, and / or - reads out the number of uncorrectable errors in the keystore (120) from the internal storage monitoring facility (121) and generates the warning signal (WS) at least also on the basis of the number of uncorrectable errors, in particular generates the warning signal (WS) if the number of uncorrectable errors exceeds a predefined maximum value, and / or - reads out the number of timeouts for commands to the keystore (120) from the internal storage monitoring facility (121) and generates the warning signal (WS) at least also on the basis of the number of timeouts for commands, in particular generates the warning signal (WS) if the number of timeouts for commands to the keystore (120) exceeds a predefined maximum value, and / or - reads out the number of unstable sectors, i.e. those which temporarily or permanently are no longer readable, of the keystore (120) from the internal storage monitoring facility (121) and generates the warning signal (WS) at least also on the basis of the number of unstable sectors, in particular generates the warning signal (WS) if the number of unstable sectors of the keystore (120) exceeds a predefined maximum value.
5. Railway engineering device (100) according to one of the preceding claims 1 to 4, characterised in that the failure prediction facility (AVM) is S.M.A.R.T.-compatible and is suitable - for directing S.M.A.R.T.-compatible requests to the internal storage monitoring facility (121) and - for evaluating S.M.A.R.T.-compatible responses by the internal storage monitoring facility (121) and generating the warning signal (WS) at least also on the basis of the S.M.A.R.T.-compatible responses by the internal storage monitoring facility (121).
6. Railway engineering device (100) according to one of the preceding claims, characterised in that - the railway engineering device (100) is suitable for receiving new cryptographic keys from a trackside key exchange facility (40) via a data transfer system (60), and for storing these as replacements for old keys previously stored in the keystore (120), and - the failure prediction facility (AVM) transmits the warning signal (WS) to the key exchange facility (40) when a possible or impending failure of the keystore (120) is established.
7. Railway engineering device (100) according to claim 6, characterised in that - the railway engineering device (100) is embodied to transmit a positive acknowledgement signal (QS) to the key exchange facility (40) in each case after successfully exchanging old keys with new keys, and - the failure prediction facility (AVM) is embodied to transmit the warning signal (WS), together with the or as a constituent part of the acknowledgement signal (QS), to the key exchange facility (40) when a possible or impending failure of the keystore (120) is established.
8. Railway engineering device (100) according to claim 6 or 7, characterised in that - the railway engineering device (100) is embodied to transmit a negative acknowledgement signal (QS) to the key exchange facility (40) in each case after unsuccessfully exchanging old keys with new keys, and - the failure prediction facility (AVM) is embodied to transmit the warning signal, together with the or as a constituent part of the acknowledgement signal (QS), to the key exchange facility (40) when a possible or impending failure of the keystore (120) is established.
9. Railway engineering device (100) according to one of the preceding claims, characterised in that the railway engineering device (100) - is a vehicle control device, in particular an ETCS-compatible vehicle control device, which stores cryptographic information in a non-volatile manner, or - is a stationary trackside device (50), in particular an ETCS-compatible trackside device, which stores cryptographic information in a non-volatile manner, or is a trackside key distribution facility (40).
10. Railway engineering device (100) according to one of the preceding claims, characterised in that - the railway engineering device (100) has a volatile main memory (130) in addition to the keystore (120), and - the failure prediction facility (AVM) is embodied to identify a possible or impending failure of the volatile main memory (130) and to output a warning signal (WS) indicating the possible failure of the main memory (130).
11. Railway engineering device (100) according to claim 10, characterised in that the failure prediction facility (AVM) is embodied to identify parity errors in the main memory (130) and to generate a warning signal (WS) indicating the possible or impending failure of the main memory (130) on the basis of the parity errors.
12. Railway engineering device (100) according to one of the preceding claims, characterised in that - the computing facility (110) has at least one sensor (150), in particular temperature sensor, which can capture at least one item of status information (ZI) relating to the computing facility (110), in particular the temperature of the computing facility (110), with the formation of a sensor measurement value (M), and - the failure prediction facility (AVM) is embodied in such a manner that it generates a warning signal (WS) indicating a possible or impending failure of the computing facility (110) at least also on the basis of the sensor measurement value (M) of the sensor (150).
13. Railway engineering installation (10) or rail vehicle (20) for a railway engineering installation (10), characterised in that the railway engineering installation (10) or the rail vehicle (20) is equipped with a railway engineering device (100) according to one of the preceding claims,14. Method for operating a railway engineering device (100), which is equipped with at least one computing facility (110) and at least one keystore (120) for storing cryptographic keys, which enable an encrypted and / or cryptographically secured transfer of data between the rail vehicle (20) and trackside facilities (50), wherein the railway engineering device (100) is monitored for a possible failure of at least one component of the railway engineering device (100) and a warning signal (WS) indicating the possible or impending failure is output if a monitoring result of the monitoring indicates a possible failure, wherein - the keystore (120) is equipped with an internal storage monitoring facility (121), which can capture status information (ZI) relating to the keystore (120) and can output it on request, and characterised in that - the failure prediction facility (AVM) is connected to the internal storage monitoring facility (121) and is embodied to read out at least one item of status information (ZI) relating to the keystore (120) from the internal storage monitoring facility (121) at regular or irregular intervals, to infer a possible full or partial failure of the keystore (120) on the basis of the at least one item of status information (ZI) that is read out, and to generate the warning signal (WS) on the basis of the at least one item of status information (ZI) that is read out.
Citation Information
Patent Citations
Method for predicting a failure of a sensor
EP3459810A1
Generating tags for data allocation
WO2021006940A1