ETCS Secure Data Distribution for Automated Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current procedures for initial data distribution, such as keys and certificates, in the ETCS train protection system are complex and require significant technical and organizational effort, especially for larger rail fleets, necessitating a more simplified and automated approach to manage cryptographic keys and certificates.
Innovation Solution
A procedure where data worth protecting is generated in a secure environment, packaged, and transmitted securely to ETCS devices, where it is stored in a protected area within the device, allowing for offline or online transmission and automated processing, reducing the need for a key manager and minimizing security requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the key manager procedure is used for initial distribution of sensitive data, then security requirements are met, but technical and organizational effort increases significantly
Solution Approach 1:
The patent extracts the sensitive data distribution function from the complex key manager procedure. A separate secure data distribution system is created that handles only the initial distribution of sensitive data, while the key manager handles subsequent key management operations. This separation reduces the complexity and organizational effort required for initial distribution.
Solution Approach 2:
The patent introduces a secure data distribution system as an intermediary between the key manager and ETCS devices. This intermediary handles the initial distribution of sensitive data using simplified procedures, reducing the burden on the key manager and lowering organizational effort while maintaining security through the use of secure communication channels.
2Reliability
If the key manager procedure is used for initial distribution of sensitive data, then security requirements are met, but time required for initial commissioning increases
Solution Approach 1:
The patent implements preliminary action by distributing sensitive data to multiple ETCS devices in advance through the secure data distribution system, before they are needed for operational key management. This allows devices to be pre-configured with necessary cryptographic material, significantly reducing the time required for initial commissioning while maintaining security through the use of secure communication channels.
Solution Approach 2:
The patent enables self-service by allowing ETCS devices to automatically receive and process sensitive data through the secure data distribution system without requiring manual intervention from key managers for each device. This automation reduces both the time required for initial commissioning and the organizational effort needed.
3Reliability
If multiple ETCS devices need key installation, then security coverage is improved, but workload and personnel requirements increase
Solution Approach 1:
The patent merges the distribution of sensitive data to multiple ETCS devices into a single unified process through the secure data distribution system. Instead of requiring separate key manager operations for each device, the system can distribute sensitive data to multiple devices simultaneously or in sequence through automated processes, significantly reducing workload and personnel requirements while maintaining comprehensive security coverage.
Solution Approach 2:
The patent creates a universal secure data distribution system that can serve multiple ETCS devices with different functions and requirements through a single infrastructure. This multi-functional system handles distribution to various device types (OBU, RBC, etc.) using standardized secure communication protocols, reducing the need for device-specific procedures and lowering overall workload.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for the initial distribution of data requiring protection (9), such as at least one key, one certificate, or one password, in an ETCS train control system (4) between at least one data center (5) and at least one ETCS device (7), such as a vehicle-side on-board unit (OBU) or a trackside radio block center (RBC), wherein data requiring protection for the at least one ETCS device (7) is generated in a secure environment (11) in the data center (5), wherein at least one transport package (10) intended for the at least one ETCS device (7) is generated with the data requiring protection (9) in a secure environment (11), wherein the transport package (10) is secured in the secure environment (11), and wherein the secured transport package (10) is transmitted to the ETCS device (7).in which the secured transport package (10) is unlocked in a secure area (14) of the ETCS device (7) and the data requiring protection (9) is stored in the secure area (14) of the ETCS device (7). The method according to the invention improves the initial distribution of data requiring protection (9) in an ETCS train control system (4). The invention also relates to an ETCS train control system (4).