ETCS Secure Data Distribution for Automated Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current procedures for initial data distribution, such as keys and certificates, in the ETCS train protection system are complex and require significant technical and organizational effort, especially for larger rail fleets, necessitating a more simplified and automated approach to manage cryptographic keys and certificates.

Innovation Solution

A procedure where data worth protecting is generated in a secure environment, packaged, and transmitted securely to ETCS devices, where it is stored in a protected area within the device, allowing for offline or online transmission and automated processing, reducing the need for a key manager and minimizing security requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the key manager procedure is used for initial distribution of sensitive data, then security requirements are met, but technical and organizational effort increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidtechnical and organizational effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the sensitive data distribution function from the complex key manager procedure. A separate secure data distribution system is created that handles only the initial distribution of sensitive data, while the key manager handles subsequent key management operations. This separation reduces the complexity and organizational effort required for initial distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure data distribution system as an intermediary between the key manager and ETCS devices. This intermediary handles the initial distribution of sensitive data using simplified procedures, reducing the burden on the key manager and lowering organizational effort while maintaining security through the use of secure communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the key manager procedure is used for initial distribution of sensitive data, then security requirements are met, but time required for initial commissioning increases

Engineering Contradiction:
ImprovesecurityVSAvoidtime required for initial commissioning
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by distributing sensitive data to multiple ETCS devices in advance through the secure data distribution system, before they are needed for operational key management. This allows devices to be pre-configured with necessary cryptographic material, significantly reducing the time required for initial commissioning while maintaining security through the use of secure communication channels.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by allowing ETCS devices to automatically receive and process sensitive data through the secure data distribution system without requiring manual intervention from key managers for each device. This automation reduces both the time required for initial commissioning and the organizational effort needed.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple ETCS devices need key installation, then security coverage is improved, but workload and personnel requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidworkload and personnel requirements
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the distribution of sensitive data to multiple ETCS devices into a single unified process through the secure data distribution system. Instead of requiring separate key manager operations for each device, the system can distribute sensitive data to multiple devices simultaneously or in sequence through automated processes, significantly reducing workload and personnel requirements while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal secure data distribution system that can serve multiple ETCS devices with different functions and requirements through a single infrastructure. This multi-functional system handles distribution to various device types (OBU, RBC, etc.) using standardized secure communication protocols, reducing the need for device-specific procedures and lowering overall workload.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4016918B1Method for initial distribution of protected data in an etcs train control system
Publication Date: 2025.01.29 SIEMENS MOBILITY GMBH
  • EP4016918B1 patent drawingFigure 1
  • EP4016918B1 patent drawingFigure 2
  • EP4016918B1 patent drawingFigure 3

AI summary

The invention relates to a method for the initial distribution of data requiring protection (9), such as at least one key, one certificate, or one password, in an ETCS train control system (4) between at least one data center (5) and at least one ETCS device (7), such as a vehicle-side on-board unit (OBU) or a trackside radio block center (RBC), wherein data requiring protection for the at least one ETCS device (7) is generated in a secure environment (11) in the data center (5), wherein at least one transport package (10) intended for the at least one ETCS device (7) is generated with the data requiring protection (9) in a secure environment (11), wherein the transport package (10) is secured in the secure environment (11), and wherein the secured transport package (10) is transmitted to the ETCS device (7).in which the secured transport package (10) is unlocked in a secure area (14) of the ETCS device (7) and the data requiring protection (9) is stored in the secure area (14) of the ETCS device (7). The method according to the invention improves the initial distribution of data requiring protection (9) in an ETCS train control system (4). The invention also relates to an ETCS train control system (4).