arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

SecDT:一种用于TRDP通信的基于配置文件的安全层

SecDT: A Profile-Based Security Layer for TRDP Communications

Erlantz Alonso, Igor Lopez, Jasone Astorga

arXiv 2609.03133首次发表:更新:

发表机构

University of the Basque Country (EHU); CAF S.A.(巴斯克大学; CAF公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对TRDP协议原生密码保护不足及组播流量配置文件带来的挑战,提出基于现代密码算法的轻量级安全层SecDT,依赖OKMS实现安全配置协商与密钥管理,原型开销可控,适配轨道车辆实时通信需求。

AI 中文摘要

列车实时数据协议(Train Real-time Data Protocol,TRDP)广泛应用于轨道车辆,但它原生提供的密码学保护支持有限。此外,TRDP过程数据中用于车载子系统间交换关键信息的组播流量配置文件,使密码学保护的引入成为一项挑战。本文提出一种用于安全TRDP通信的轻量级安全层,该安全层实现了一系列基于现代密码算法构建的安全配置文件。该附加层依赖车载密钥管理系统(On-board Key Management System,OKMS)完成安全配置文件协商、动态密钥分发和密钥生命周期管理。安全配置文件支持密码 agility(敏捷性)与灵活性,涵盖从简单认证到带关联数据的认证加密(Authenticated Encryption with Associated Data,AEAD)算法的多种方案。安全配置文件协商流程保证同一通信ID(Communication ID,ComID)下的所有TRDP终端设备(End Devices,ED)共享相同的安全配置文件,从而能够处理彼此的消息。本文开发了基于mbedTLS和Arm平台安全架构(Arm Platform Security Architecture,PSA)的原型实现并进行评估,实验结果表明其开销可控,适用于轨道车辆上的实时和时间敏感型通信。

英文摘要

The Train Real-time Data Protocol (TRDP) is widely used on rolling stock but it provides limited native support for cryptographic protection. Furthermore, the multicast traffic profile used in TRDP Process Data to exchange critical information between onboard subsystems makes the introduction of cryptographic protection a challenge. This paper presents a lightweight security layer for secure TRDP communication that implements a number of security profiles built around modern cryptographic algorithms. This additional layer relies on an On-board Key Management System (OKMS) for both security profile negotiation, dynamic key distribution and key lifecycle management. The security profiles allow for cryptographic agility and flexibility, ranging from simple authentication to Authenticated Encryption with Associated Data (AEAD) algorithms. The security profile negotiation procedure guarantees all TRDP End Devices (ED) on a common Communication ID (ComID) share the same security profile and can therefore process each other's messages. A prototype implementation based on mbedTLS and Arm Platform Security Architecture (PSA) was developed and evaluated. Experimental results demonstrate manageable overhead, suitable for the real-time and time-sensitive communication found on rolling stock.

CommentsSubmitted to IEEE Future Networks World Forum 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑