Balise Authenticity Verification via Cryptographic Hashing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The European Train Control System (ETCS) is vulnerable to intentional data manipulation, as cyclic redundancy checks do not protect against malicious alterations of safety-critical information transmitted by balises, which can compromise the authenticity and integrity of data received by rail vehicles.

Innovation Solution

A method is introduced where the authenticity of the balise identifier is verified by the rail vehicle, ensuring that only authenticated information is used for operation, employing cryptographic techniques such as hash functions and digital signatures to secure the transmission of data from balises to vehicle computers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic verification methods (hash functions, digital signatures) are implemented to verify balise authenticity, then data integrity and security are improved, but system complexity and processing time increase

Engineering Contradiction:
Improvedata integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-storing reference hash values or digital signatures in the vehicle computer before the train reaches the balise. When the balise transmits data, the vehicle computer immediately compares the transmitted data's hash/s signature against the pre-stored reference, enabling rapid verification without complex real-time cryptographic computations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex cryptographic verification mechanisms with simpler hash function comparisons. Instead of implementing full digital signature verification protocols, the system uses hash functions to generate compact digital fingerprints of the balise data, which are then compared against pre-stored reference hashes, significantly reducing computational complexity while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If cryptographic verification methods are implemented to prevent data manipulation, then security against malicious attacks is improved, but transmission time and processing speed decrease

Engineering Contradiction:
ImprovesecurityVSAvoidtransmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the essential verification element (hash value or digital signature) from the complete cryptographic protocol and transmits it separately with the balise data. The vehicle computer then performs a simple comparison operation rather than executing the full cryptographic verification process, dramatically reducing transmission time while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the verification parameter from complex cryptographic proofs to simplified hash value comparisons. By transforming the verification task into comparing compact hash fingerprints rather than executing full cryptographic protocols, the system achieves both security and speed requirements.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If balise data is used for train control decisions, then operational efficiency is improved, but vulnerability to data manipulation attacks increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoiddata manipulation vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces cryptographic hash functions and digital signatures as intermediary verification mechanisms between the balise and the vehicle computer. These intermediaries act as trusted mediators that certify the authenticity of balise data without interfering with the operational use of the data, allowing efficient train control while preventing manipulation attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary anti-action by pre-securing the balise data through cryptographic hashing or digital signature generation before the data is used for train control decisions. This preliminary security measure prevents malicious manipulation by establishing an unalterable cryptographic reference that any tampering would immediately reveal.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3137363B1Checking the authenticity of a balise
Publication Date: 2019.12.04 SIEMENS MOBILITY GMBH
  • EP3137363B1 patent drawingFigure 1~2

AI summary

The invention relates to checking the authenticity of a balise. For this purpose, an identifier is provided by the balise, which is transmitted as part of the telegram from the balise to the vehicle computer of the rail vehicle. The authenticity of the balise can be verified by the vehicle computer, based on the identifier. The identifier is advantageously transmitted in the ETCS packet 44 according to UNISIG. In addition, a hash value of a cryptographic hash function can be used as an identifier. Furthermore, it is advantageous that any tampering with the telegrams provided by the balise can be detected.