Balise Authenticity Verification via Cryptographic Hashing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The European Train Control System (ETCS) is vulnerable to intentional data manipulation, as cyclic redundancy checks do not protect against malicious alterations of safety-critical information transmitted by balises, which can compromise the authenticity and integrity of data received by rail vehicles.
Innovation Solution
A method is introduced where the authenticity of the balise identifier is verified by the rail vehicle, ensuring that only authenticated information is used for operation, employing cryptographic techniques such as hash functions and digital signatures to secure the transmission of data from balises to vehicle computers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic verification methods (hash functions, digital signatures) are implemented to verify balise authenticity, then data integrity and security are improved, but system complexity and processing time increase
Solution Approach 1:
The patent applies preliminary action by pre-storing reference hash values or digital signatures in the vehicle computer before the train reaches the balise. When the balise transmits data, the vehicle computer immediately compares the transmitted data's hash/s signature against the pre-stored reference, enabling rapid verification without complex real-time cryptographic computations.
Solution Approach 2:
The patent replaces complex cryptographic verification mechanisms with simpler hash function comparisons. Instead of implementing full digital signature verification protocols, the system uses hash functions to generate compact digital fingerprints of the balise data, which are then compared against pre-stored reference hashes, significantly reducing computational complexity while maintaining security.
2Reliability
If cryptographic verification methods are implemented to prevent data manipulation, then security against malicious attacks is improved, but transmission time and processing speed decrease
Solution Approach 1:
The patent extracts only the essential verification element (hash value or digital signature) from the complete cryptographic protocol and transmits it separately with the balise data. The vehicle computer then performs a simple comparison operation rather than executing the full cryptographic verification process, dramatically reducing transmission time while maintaining security.
Solution Approach 2:
The patent changes the verification parameter from complex cryptographic proofs to simplified hash value comparisons. By transforming the verification task into comparing compact hash fingerprints rather than executing full cryptographic protocols, the system achieves both security and speed requirements.
3Productivity
If balise data is used for train control decisions, then operational efficiency is improved, but vulnerability to data manipulation attacks increases
Solution Approach 1:
The patent introduces cryptographic hash functions and digital signatures as intermediary verification mechanisms between the balise and the vehicle computer. These intermediaries act as trusted mediators that certify the authenticity of balise data without interfering with the operational use of the data, allowing efficient train control while preventing manipulation attacks.
Solution Approach 2:
The patent applies preliminary anti-action by pre-securing the balise data through cryptographic hashing or digital signature generation before the data is used for train control decisions. This preliminary security measure prevents malicious manipulation by establishing an unalterable cryptographic reference that any tampering would immediately reveal.
Data Source
Figure 1~2
AI summary
The invention relates to checking the authenticity of a balise. For this purpose, an identifier is provided by the balise, which is transmitted as part of the telegram from the balise to the vehicle computer of the rail vehicle. The authenticity of the balise can be verified by the vehicle computer, based on the identifier. The identifier is advantageously transmitted in the ETCS packet 44 according to UNISIG. In addition, a hash value of a cryptographic hash function can be used as an identifier. Furthermore, it is advantageous that any tampering with the telegrams provided by the balise can be detected.