Reduced Case Study
Reduced Case Study
System boundaries Description: STIMS is composed by at least two TID on-board devices per train and one TIS on-ground.
Initial system architecture
Logical and physical network plans TID (Train Integrity Device): continuously acquires its position and communicates it to TIS. It shall be
installed in head-unit and in tail wagon. The TID has the following main blocks:
For the scope of our example, the first three o Localization block based on a GNSS (Global Navigation Satellite System) receiver. This receiver
inputs of this phase (System boundaries, Initial could use Galileo, GPS, Glonass or Beidou technology.
system architecture, Logical and physical o Wireless communication block based on a single or multiple Modem (Gateway). This modem
network plans) are represented by figures and could use 2G, 3G, 4G, 5G or GSM-R/GPRS-R technology.
associated descriptions. o Driver Interface block placed on the driver desk. This TID HMI could be a simple set of LED
and switches, or a touch-screen monitor.
o TID computing block. This is the elaboration unit based on a microcontroller, microprocessor,
FPGA, RAM based memory, Flash based memory and some interfaces.
o Optional Wi-Fi communication block able to allow the interaction of the TID with a laptop,
tablet or smartphone. This block could be based on Wi-Fi, BlueTooth or other wireless short-
range technology.
TIS (Train Integrity Service): continuously collects TID data, computes train length and notifies
alarms in case of anomalies. A TIS has the following main blocks:
o TIS DCS (Train Integrity Service Data Collection Server): provides communications services to
collect and process data from on-board TID devices
o TIS WEB (Train Integrity Service Web Application): provides centralized configuration,
analysis and management services to STIMS operators
- On board
o Get application specific essential train run
X X YES
Essential functions data from TCMS: EVN, Composition.
Acceptable
Asset Impact Likelihood Risk N°
? Type Including Risk
zone/conduit
TID HMI B 3 Significant NO
Z1 Zone Head TID, Head GNSS Loc Significant
Head TID B 3 Significant NO Z2 Zone Tail TID, Tail GNSS Loc High
Head GNSS Loc C 4 Significant NO Z3 Zone TID HMI Significant
Tail to Head
B 2 Medium YES Z4 Zone TIS DCS Low
Communication
Tail TID B 5 High NO
Z5 Zone TIS WEB Medium
Tail GNSS Loc C 5 High NO
Train to Ground C1 Conduit Tail to Head Comm. Medium
B 3 Significant NO
Communication
TIS DCS B 1 Low YES C2 Conduit Train to Ground Comm. Significant
TIS WEB D 4 Medium YES
External System C3 Conduit External System Comm. Significant
C 4 Significant NO
Communication
Train to Ground
Communication
C2
ON-BOARD SYSTEM
Poor auth.,
Command and
T.MaliciousActivity External Cybercrime
Control
Z1, Z2, Z3 Unpatched
components
T.Legal External - - - -
Significant interruption of minor safety implications, typically leading to Loss of non-security relevant data, data are Marginal business impact
operation of a line or station or a injuries without hospitalization not under data protection; attacker can make
D few vehicles for a significant time commercial use of the data by combing with
other information
typically, no influence typically, no safety implications Loss of non-security relevant data, data are Negligible business impact
E not under data protection
SL 1 casual or
coincidental
FR = Foundational Requirement
SR = System Requirement
RE = Requirement Enhancement
Application of FprTS 50701
ENISA-ERA Conference: Cybersecurity in Railways
16 March 2021 35
Phase 4 – Selection of countermeasures
FprTS 50701 - Table 5: System Security Requirements and Foundational Classes
(derived from IEC 62443-3-3:2019)
FR = Foundational Requirement
SR = System Requirement
RE = Requirement Enhancement
Application of FprTS 50701
ENISA-ERA Conference: Cybersecurity in Railways
16 March 2021 36