Skip to content

Physical and logical safeguards against unauthorised access

Description

Protection of high-speed EMU equipment and control means against unauthorised access by third parties. Restriction of access to control organs, technical condition monitoring, and service information interfaces, including for information security.

Goals and objectives

Ensuring access to high-speed EMU monitoring and control interfaces depending on user rights and role.

Characteristics

1. Access depending on user rights and role:

  • "passenger" — access to equipment that satisfies the passenger's request for comfortable and safe presence inside the EMU;
  • "train crew personnel" — access to equipment and control organs that enable control to create comfortable and safe conditions for people inside the EMU;
  • "locomotive crew personnel" — access to equipment and control organs that enable EMU control;
  • "service personnel" — access to equipment and control organs that enable maintenance and repair.

2. Access restriction is based on the principle of least privilege. This means the user receives access only to the interfaces and control organs necessary to perform assigned tasks; everything else remains inaccessible. This approach substantially reduces the risk of unsafe and unreliable operation of the high-speed EMU.

3. Depending on installation location and purpose, the design of technical means provides protection against unauthorised access to control elements (physical, virtual, implemented in software), and service interfaces.

Applied technologies

1. Access restriction is ensured by comprehensive measures implemented through various technologies:

  • physical protection of access to equipment and control organs. Doors and hatches of electrical and technical cabinets, containers, and equipment niches are fitted with mechanical locking devices to secure them in the closed position. Access to equipment service ports is protected against unauthorised access and records access events;
  • software protection of access to data. Software applications and services, as well as associated access ports, can be disabled or blocked; unused data transmission interfaces are disabled or blocked.

2. Implementation of data access restriction:

  • authorisation and authentication systems;
  • data encryption;
  • traffic filtering;
  • use of virtualisation and containerisation means.

3. Management of passwords, code sequences, and security keys:

  • change;
  • policy configuration to achieve minimum complexity level.

4. For operating systems used as part of hardware means, access to the system area is restricted for unauthorised external processes and users.

5. Security events are recorded and stored (events recorded in processed form indicating possible violation of information integrity, availability, and/or confidentiality, as well as failure of an information protection means or function, or another situation that may be significant for information security).

6. Software is developed using:

  • programming languages: C, C++, Python;
  • development tools: Visual Studio, Code::Blocks, Eclipse, NetBeans, and specialised integrated environments for embedded microcontroller software (IAR, Keil, CubeIDE);
  • source code management tools: SVN, Git;
  • requirements management tools: T-FLEX RM.
Physical and logical safeguards against unauthorised access