Train Communication Security via Segmented Interfaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The European Train Control System (ETCS) is vulnerable to cyber attacks due to security gaps in GSM-based mobile radio networks, which can disrupt train traffic and compromise the integrity of safety-critical systems, despite end-to-end crypto security measures.
Innovation Solution
A communication arrangement is designed with cascaded interfaces forming three security zones: one including the mobile radio device and protective device, another including the communication computer, and a third including the vehicle computer, with each zone being individually protected, using distinct interfaces and potentially separate hardware or software implementations for the protective devices to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If direct connection between vehicle computer and mobile communication device is used, then device complexity is reduced, but security against cyber attacks deteriorates
Solution Approach 1:
The system is divided into three distinct security zones: the mobile communication device (first zone), the protective device (second zone), and the vehicle computer (third zone). Each zone is separated by different interfaces, with the protective device acting as an intermediary that segments the direct connection path, thereby enhancing security while maintaining manageable system complexity through modular architecture.
Solution Approach 2:
The protective device serves as an intermediary component positioned between the mobile communication device and the vehicle computer. It implements protocol conversion and security functions, acting as a mediator that protects the vehicle computer from direct exposure to potential attacks while enabling necessary communication functionality.
2Reliability
If multiple cascaded interfaces and security zones are implemented, then security is enhanced, but device complexity increases
Solution Approach 1:
The system architecture is segmented into three functional zones with distinct interfaces, allowing security functions to be distributed and specialized. This segmentation enables each component to focus on specific security tasks, making the overall complex system manageable through clear functional boundaries and responsibility separation.
Solution Approach 2:
Each interface and security zone is designed with specific local qualities and functions tailored to its security requirements. The protective device-side interface differs from the mobile device interface and computer-side interface, with each interface optimized for its specific security context, allowing targeted security measures rather than uniform complexity throughout the system.
3Reliability
If end-to-end cryptographic security is used, then data transmission security is protected, but protection against operational disruptions from cyber attacks deteriorates
Solution Approach 1:
The protective device acts as an intermediary that extends security beyond end-to-end cryptography. It monitors and controls data flows between the mobile communication device and vehicle computer, providing additional layers of protection against operational disruptions such as denial of service attacks and malware infiltration that cannot be prevented by cryptography alone.
Solution Approach 2:
The protective device performs preliminary security actions by filtering, validating, and monitoring communications before they reach the vehicle computer. This preliminary protection measures prevent potential disruptions before they can affect critical operations, complementing the end-to-end cryptographic security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates, inter alia, to a communication assembly (1) for a vehicle (100) for operating mobile radio communication with a track-mounted apparatus (300), the communication assembly (1) having a vehicle computer (10) and at least one mobile radio apparatus (41, 42) for a radio connection (F) to the track-mounted apparatus (300). According to the invention, the vehicle computer (10) and the mobile radio apparatus (41, 42) are not connected to each other directly, but rather by means of a communication computer (20) (NVC) and a protection apparatus (31, 32), the communication computer (20) is connected to the vehicle computer (10) by means of at least one computer-side interface (Sr) and to the protection apparatus (31, 32) by means of at least one protection-apparatus-side interface (Ss1, Ss2), and the protection apparatus (31, 32) is connected to the at least one mobile radio apparatus (41, 42) by means of a mobile radio device interface (Sm1, Sm2), the protection-apparatus-side interface (Ss1, Ss2) differing from the mobile radio device interface (Sm1, Sm2) or being operated differently than the mobile radio device interface and also differing from the computer-side interface (Sr) or being operated differently than the computer-side interface.