A systematic development of a secure architecture for the European Rail Traffic Management System

A systematic development of a secure architecture for the European Rail Traffic Management System
复制标题

DOI:
--
复制
发表时间:
2019-07
期刊:
--
影响因子:
--
通讯作者:
Richard J. Thomas
Richard J. Thomas
中科院分区:
其他
文献类型:
--
作者:
Richard J. Thomas

文献摘要

相似文献

欧洲铁路交通管理系统(ERTMS)是一种新的信号系统,正在全球范围内实施,目的是改善互操作性和跨境运营。它也是工业控制系统的一个例子,这是一个安全关键的系统,近年来受到了许多攻击和威胁。在这些系统中,安全是系统设计者最关心的问题,而安全有时是事后才想到的。因此,确保当前和未来威胁的安全是谨慎的,这些威胁可能会影响铁路的安全运营。在本文中,我们对ERTMS标准的部分内容进行了系统的安全性分析,首先使用ProVerif工具回顾了ERTMS中使用的协议所提供的安全性。然后,我们将评估平台使用的自定义MAC算法,找出每个ERTMS协议层中存在的问题,并针对这些问题提出解决方案。我们还确定了将ERTMS引入国家基础设施管理者围绕密钥管理带来的挑战,其中我们还提出了一种新的密钥管理方案Traks,它降低了其复杂性。然后,我们为资产所有者定义了一个整体流程,以对其架构进行自己的安全评估,并考虑工业控制系统带来的独特挑战,以及如何缓解这些挑战以确保这些系统的安全。从这些分析中得出结论,我们引入了“安全架构”的概念,并审查了ERTMS目前对这一定义的遵守情况,确定了为使其现在和将来都有一个安全架构所需的改变。
The European Rail Traffic Management System (ERTMS) is a new signalling scheme that is being implemented worldwide with the aim of improving interoperability and cross-border operation. It is also an example of an Industrial Control System, a safety-critical system which, in recent years, has been subject to a number of attacks and threats. In these systems, safety is the primary concern of the system designers, whilst security is sometimes an afterthought. It is therefore prudent to assure the security for current and future threats, which could affect the safe operation of the railway. In this thesis, we present a systematic security analysis of parts of the ERTMS standard, firstly reviewing the security offered by the protocols used in ERTMS using the ProVerif tool. We will then assess the custom MAC algorithm used by the platform and identify issues that exist in each of the ERTMS protocol layers, and aim to propose solutions to those issues. We also identify a challenge presented by the introduction of ERTMS to National Infrastructure Managers surrounding key management, where we also propose a novel key management scheme, TRAKS, which reduces its complexity. We then define a holistic process for asset owners to carry out their own security assessments for their architectures and consider the unique challenges that are presented by Industrial Control Systems and how these can be mitigated to ensure security of these systems. Drawing conclusions from these analyses, we introduce the notion of a `secure architecture' and review the current compliance of ERTMS against this definition, identifying the changes required in order for it to have a secure architecture, both now and also in the future.