Key Management Module for Secure ETCS Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing method for securing the distribution of authentication keys in the European Train Control System (ETCS) level 2 or 3 is vulnerable due to reliance on human procedures for initialization and updates, which can lead to potential weaknesses and degradation of security over time.

Innovation Solution

A method and key management module that utilize asymmetric cryptographic techniques, including the generation and remote distribution of transportation keys using a certification authority module, to securely initialize and update authentication keys for communication modules, eliminating the need for human intervention and ensuring continuous high security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If human procedures are used for initialization and update of transportation keys, then the key distribution can be performed, but the security level degrades over time and potential weaknesses arise

Engineering Contradiction:
Improvesecurity levelVSAvoidtime for key update
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated key management where the key management module autonomously generates, distributes, and updates transportation keys without human intervention. The module self-manages the entire key lifecycle including generation using cryptographic algorithms, secure transmission to communication modules, and periodic renewal, eliminating the need for manual procedures that degrade security over time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key management module performs preliminary actions by pre-generating transportation keys and securely storing them before they are needed. The system proactively manages key distribution schedules and automatically initiates key updates before expiration, ensuring continuous security without requiring reactive human intervention.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If human procedures are used for key distribution, then key management can be performed, but the procedure becomes heavy and constraining

Engineering Contradiction:
Improveease of key distributionVSAvoidcomplexity of key management procedure
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical procedures with automated electronic systems. The key management module uses cryptographic algorithms and automated transmission protocols to distribute keys electronically, substituting human operators and manual processes with machine-to-machine communication that is both simpler to execute and more secure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The key management module acts as an intermediary between the central authority and communication modules, automating the key distribution process. It handles key generation, secure transmission, and management operations, simplifying the overall system by centralizing and automating what would otherwise require complex coordinated human procedures across multiple entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If automated key distribution is implemented, then security level is maintained, but cryptographic operations are required

Engineering Contradiction:
Improvesecurity levelVSAvoidcomplexity of cryptographic operations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key management module is designed as a universal component that integrates multiple cryptographic functions including key generation, encryption, decryption, and secure transmission. By consolidating these diverse cryptographic operations into a single multi-functional module, the system maintains high security while managing complexity through functional integration rather than separate specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3219575B1Method for securing the exchange of authentication keys and associated key management module
Publication Date: 2020.11.04 ALSTOM TRANSPORT TECH SAS
  • EP3219575B1 patent drawingFigure 1
  • EP3219575B1 patent drawingFigure 2~3

AI summary

This method (100) comprises a step (130) of transmitting an authentication key to at least one communication module among a first and a second communication modules, the transmission being performed by a symmetric data encryption communication between a key server and said communication module, using a transportation key known by said communication module, The method further comprises a preliminary step (120) of transmitting the transportation key to said communication module, the preliminary transmission being performed by an asymmetric data encryption communication between the key server and said communication module using a public key generated by said communication module.