Train Communication Security via Segmented Interfaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The European Train Control System (ETCS) is vulnerable to cyber attacks due to security gaps in GSM-based mobile radio networks, which can disrupt train traffic and compromise the integrity of safety-critical systems, despite end-to-end crypto security measures.

Innovation Solution

A communication arrangement is designed with cascaded interfaces forming three security zones: one including the mobile radio device and protective device, another including the communication computer, and a third including the vehicle computer, with each zone being individually protected, using distinct interfaces and potentially separate hardware or software implementations for the protective devices to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If direct connection between vehicle computer and mobile communication device is used, then device complexity is reduced, but security against cyber attacks deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system is divided into three distinct security zones: the mobile communication device (first zone), the protective device (second zone), and the vehicle computer (third zone). Each zone is separated by different interfaces, with the protective device acting as an intermediary that segments the direct connection path, thereby enhancing security while maintaining manageable system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The protective device serves as an intermediary component positioned between the mobile communication device and the vehicle computer. It implements protocol conversion and security functions, acting as a mediator that protects the vehicle computer from direct exposure to potential attacks while enabling necessary communication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple cascaded interfaces and security zones are implemented, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system architecture is segmented into three functional zones with distinct interfaces, allowing security functions to be distributed and specialized. This segmentation enables each component to focus on specific security tasks, making the overall complex system manageable through clear functional boundaries and responsibility separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each interface and security zone is designed with specific local qualities and functions tailored to its security requirements. The protective device-side interface differs from the mobile device interface and computer-side interface, with each interface optimized for its specific security context, allowing targeted security measures rather than uniform complexity throughout the system.

Inventive Principle:
Principle #3Local quality

3Reliability

If end-to-end cryptographic security is used, then data transmission security is protected, but protection against operational disruptions from cyber attacks deteriorates

Engineering Contradiction:
Improvedata transmission securityVSAvoidoperational disruptions
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The protective device acts as an intermediary that extends security beyond end-to-end cryptography. It monitors and controls data flows between the mobile communication device and vehicle computer, providing additional layers of protection against operational disruptions such as denial of service attacks and malware infiltration that cannot be prevented by cryptography alone.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The protective device performs preliminary security actions by filtering, validating, and monitoring communications before they reach the vehicle computer. This preliminary protection measures prevent potential disruptions before they can affect critical operations, complementing the end-to-end cryptographic security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3603011B1Apparatuses and method for operating mobile radio communication with a track-mounted apparatus
Publication Date: 2023.03.22 SIEMENS MOBILITY GMBH
  • EP3603011B1 patent drawingFigure 1
  • EP3603011B1 patent drawingFigure 2
  • EP3603011B1 patent drawingFigure 3

AI summary

The invention relates, inter alia, to a communication assembly (1) for a vehicle (100) for operating mobile radio communication with a track-mounted apparatus (300), the communication assembly (1) having a vehicle computer (10) and at least one mobile radio apparatus (41, 42) for a radio connection (F) to the track-mounted apparatus (300). According to the invention, the vehicle computer (10) and the mobile radio apparatus (41, 42) are not connected to each other directly, but rather by means of a communication computer (20) (NVC) and a protection apparatus (31, 32), the communication computer (20) is connected to the vehicle computer (10) by means of at least one computer-side interface (Sr) and to the protection apparatus (31, 32) by means of at least one protection-apparatus-side interface (Ss1, Ss2), and the protection apparatus (31, 32) is connected to the at least one mobile radio apparatus (41, 42) by means of a mobile radio device interface (Sm1, Sm2), the protection-apparatus-side interface (Ss1, Ss2) differing from the mobile radio device interface (Sm1, Sm2) or being operated differently than the mobile radio device interface and also differing from the computer-side interface (Sr) or being operated differently than the computer-side interface.