Visual of the Blog Post: How Secure Is Europe's Rail System? A Systematic Cybersecurity Risk Analysis of the ERTMS

How Secure Is Europe’s Rail System? A Systematic Cybersecurity Risk Analysis of the European Rail Traffic Management System (ERTMS)

The European Rail Traffic Management System (ERTMS) is designed to make Europe’s railways interoperable and safe. The system, which has been mandatory since 2002, combines standardized signaling, radio communication, and train control – but how well is it protected against cyberattacks? Using MoRA, our modular risk assessment approach, we systematically model the ERTMS and evaluate cybersecurity risks. We compare current and future configurations to identify the assets with the largest attack surface. Our overview of the entire system – from GSM-R, balises, FRMCS, ETCS levels, and ATO to key management – provides a concise preview of risk profiles and attack tree scenarios, and highlights practical countermeasures that significantly improve cybersecurity.

To promote the development and operation of international railways, the EU introduced the European Rail Traffic Management System (ERTMS) – with the goal of achieving interoperable signaling, communication, and train management systems. ERTMS enables standardized signaling, over-the-air (OTA) communication, and Automatic Train Operation (ATO). Mandatory for new high-speed networks since 2002 and for regular operations since 2004, its adoption varies widely: from full coverage in Belgium and Luxembourg to less than 1% in Germany.

ERTMS has even spread beyond the EU (including to Australia and Thailand), underscoring global confidence in the European Union Agency for Railways (ERA). The first draft specification dates back to 1996 and was most recently updated as “Baseline 4” (2023). This long history raises the question of to what extent cybersecurity was ever part of the standardization process.

Over the past decade, there have been attacks on rail infrastructure in several countries – mostly denial-of-service (DoS) attacks or data breaches. Older cyber-physical systems, in particular, are vulnerable to low-cost attacks: In 2023, Polish trains were stopped remotely via a radio-transmitted stop command. In addition to attacks carried out for personal gain or to cause targeted disruption, concerns about military exploitation are also growing in light of geopolitical tensions. The comparatively “aged” nature of ERTMS, given the rapid pace of cybersecurity development, calls for a closer look at the status quo.

Our Research Contribution

With this work, we aim to make two key contributions. First (Research Contribution 1), we adapt and apply a modular cybersecurity risk assessment approach to systematically model and evaluate ERTMS. Second (Research Contribution 2), we derive the risk profiles of current and future ERTMS configurations and compare them with one another to identify the assets that present the greatest attack surface.

Brief Overview of Related Work

Researchers and industry experts agree that the increasing digitization and networking of railway OT systems expand the attack surface of a strategically critical infrastructure. Existing cybersecurity analyses of ERTMS focus primarily on individual components or mechanisms – such as weak cryptography (3DES) in EuroRadio, DoS/jamming attacks against GSM-R, or the lack of integrity assurance in EuroBalises. From a standards perspective, CENELEC TS 50701 and the EU Rail System Pillar specifications provide lifecycle guidelines and basic requirements.

Our gap: Existing literature remains either very general or narrowly focused on specific technical issues. We close this gap by analyzing the entire ERTMS – from legacy GSM-R and EuroBalises to FRMCS and ATO – within a unified risk framework (MoRA) and by publishing explicit attack trees as well as detailed, system-wide risk profiles.

Technical Background

European Train Control System (ETCS): Within ERTMS, ETCS has the most direct impact on passenger safety; it ensures that no two trains travel on the same track section at the same time. ETCS defines four operating levels:

  • Level 0: No track-side ETCS
  • Level NTC: Legacy systems via Specific Transmission Modules (STM)
  • Level 1: Train monitoring using data from EuroBalises, EuroLoops, Radio Block Centers (RBCs), and Radio Infill Units (RIUs)
  • Level 2: Continuous radio communication with RBCs; EuroBalises primarily provide position data

The key parameter is the Movement Authority (MA), which allows a train to continue its journey up to an end/limit of authority. MAs can be extended but not revoked. Balise Linking triggers an emergency stop if expected balises are missing. The position is calculated primarily from odometry relative to balises; GNSS serves only as a time source.

GSM-R and FRMCS: Radio communication currently uses GSM-R. A Safety Layer supplements GSM with encryption and integrity protection using three symmetric keys (KTRANS, KMAC, KSMAC), with fresh session keys derived via 3DES. 3DES is an outdated encryption standard, though it has not yet been definitively cracked. The upcoming FRMCS will replace GSM-R with a 5G-based system featuring inherent authentication, encryption, and TLS-protected end-to-end communication.

Automatic Train Operation (ATO): Optional subsystem for (partially) autonomous operation. The ATO-OBU receives data exclusively via FRMCS and directly controls traction and braking. ETCS remains the safety authority and can override ATO by applying the brakes.

Key Management: ERTMS defines a distributed key management system via Key Management Centers (KMCs). Keys are distributed either offline out-of-band or online via a TLS-protected, PKI-based channel. With a full transition to FRMCS, a sector-wide PKI takes over all management.

Methodology

The analysis follows four steps: (1) literature review, (2) system modeling, (3) risk analysis, and (4) validation against related work. We use MoRA (Modular Risk Assessment) as our framework – a method we developed at Fraunhofer AISEC and primarily use in the automotive domain (see our blog post on cybersecurity risk management in the automotive industry). Its iterative and modular nature is well-suited to the scope of ERTMS, as the level of granularity can be adjusted based on early findings.

The specific MoRA implementation includes:

  1. Creation of the Target of Evaluation (TOE): Formalization of the system model, including components, connections, technologies, and data flows
  2. Function mapping: Grouping data into functions based on purpose and impact
  3. Quantification of protection objectives: Assessment of confidentiality, integrity, and availability across four damage classes aligned with ISO/SAE 21434 (Safety, Financial, Legal, Operational).
  4. Threat identification: Application of a STRIDE subset (Spoofing, Tampering, Information Disclosure, DoS). Each threat is assessed using the Required Attack Potential (RAP) according to CEM (Basic to Beyond High).
  5. Definition of controls: Iterative identification of countermeasures, including those that undermine other controls.
  6. Attack trees: a recursive structure in which child nodes represent preparatory threats designed to weaken controls.
  7. Risk Assessment: Summing the paths and multiplying them by the damage levels of the compromised protection objectives yields the risk levels.
  8. Control Evaluation: Calculation of risks for various active control groups in comparison.

System Model

The components are divided into four categories:

  • On-Board (OB): The core is the ETCS OBU, connected to the DMI, ATO OBU, STM, On-Board Recording Device, EuroRadio module, and vehicle interface – all via a physical Ethernet network (PROFINET). The FRMCS functionality is integrated into EuroRadio.
  • Track-Side (TS): One instance each of EuroBalise, EuroLoop, RBC, and RIU. Transmission via induction (Balise/Loop) or GSM-R (RBC/RIU).
  • Internet: PKI, DNS resolver, and ATO-TS, connected via a gateway between the GSM-R network and the Internet.
  • Key Management (KM): local and external KMCs, connected redundantly via TCP and out-of-band.

Additionally, a GNSS component is included for some configurations.

Blogbeitrag Sebastian Peters und Lukas Lautenschlager; Abbildung 1: Systemmodell des ERTMS
Figure 1: System Model of the ERTMS

A total of 37 functions were derived from the specifications (including traction control, braking systems, MA, status messages, track information, key and certificate management, odometry, and emergency braking). The compromise of most safety objectives is rated as “Very High” or “High” – the consequences range from track closures to railroad crossing accidents resulting in injuries or fatalities. For example, a breach of the integrity of the MA causes “Very High” safety damage, as clearance into an occupied block can lead to collisions.

Controls and Threats

Threats are organized according to the underlying technology or interface. In accordance with the MoRA methodology, we first consider the baseline threats without any countermeasures. The impact of the individual controls is only gradually incorporated and evaluated in the subsequent steps.

Basic Threats: The easiest to attack is the magnetic induction used by EuroBalise and EuroLoop: A disruption requires only makeshift equipment (RAP: Basic), while spoofing via a fake balise or a replay attack requires expert knowledge and physical presence on the track (Moderate), and reflashing the firmware via debug interfaces requires the highest level of effort (High). For on-board Ethernet, cutting the cable (availability), sniffing, and Layer 2 spoofing are all trivial and remain at the Basic level. At the IP level, spoofing is also Basic, while sniffing requires an on-path position (Moderate) and DDoS – thanks to available “DDoS-as-a-Service” offerings – is classified as Enhanced-Basic. GSM-R is equally vulnerable to sniffing, jamming, and spoofing due to the widespread use of its hardware (all Basic). For GNSS, jamming is possible with just a few watts over long ranges (Basic), while spoofing requires a deep understanding of signal theory (Enhanced-Basic). Finally, we consider social engineering to be an overarching vector against offline key management: The attacker typically must infiltrate the operator’s organization (High; Moderate if repeated).

Controls:

  • Model-inherent: The absence of an ATO, exclusive ETCS Level 2 operation, and FRMCS (modeled as a control on GSM-R) elevate relevant RAPs to Beyond High.
  • Mandatory: PROFINET with a segmented network, largely TLS-secured IP communication, and the GSM-R Safety Layer (the outdated 3DES primitive raises the RAP only to Enhanced-Basic).
  • Optional: Balise Linking and Safe Radio Supervision convert safety-related incidents into delays (due to triggered emergency stops) without lowering the RAP.
  • Additional measures (literature & own suggestions): MAC-based telegram protection (according to Lim et al.), deactivation of offline key management and balise debug interfaces, GNSS-independent time measurement, DNSSEC, and an extended balise linking variant with authenticated Denial of Existence (DoE).

Additional threat: Balise linking can be circumvented by triggering the BMM track condition – for example, by distributing metallic masses along the tracks (RAP: Moderate). Furthermore, certain compromises break entire controls: a CMP violation breaks TLS, DNSSEC, and FRMCS; a KM violation breaks the GSM-R Safety Layer.

Evaluation

A total of 191 risks were identified. The distribution across the various control groups is as follows:

Blogartikel Sebastian Peters und Lukas Lautenschlager; Abbildung 2: Evaluation der Risiken des ERTMS über verschiedene Control-Gruppen
Figure 2: Evaluation of ERTMS Risks Across Various Control Groups

Key observations:

  • A large portion of the very-high risks stems from the vulnerability of EuroBalises (spoofing, tampering, jamming) as well as threats to GSM-R and OB-Ethernet.
  • With all optional ERTMS controls (including FRMCS), only OB-Ethernet and GSM-R spoofing are completely mitigated. While Balise Linking and Safe Radio Supervision prevent the catastrophic safety consequences of jamming, they come at the cost of operational disruptions, as the system responds by applying the brakes.
  • The transition to “ETCS Level 2 only” brings the most drastic improvement, as the role of EuroBalises is greatly reduced. Nine very-high risks remain – primarily jamming and DDoS, which can disrupt operations with relatively little effort.
  • ATO increases the attack surface only minimally: Since ETCS can intervene at any time by applying the brakes and thereby override ATO, and since all ATO data is TLS-encrypted, this results in only one additional high-risk scenario.

Discussion

A minimal ERTMS implementation has several vulnerabilities that could lead to fatalities. While additional security measures – including the upcoming FRMCS – have a clearly positive effect, significant concerns remain regarding DoS attacks and EuroBalise tampering. The ERTMS standard itself appears to be the weakest link in cyber defense, which we attribute to the slow pace of OT standardization. Even with academic countermeasures, reliability remains vulnerable to remote DoS attacks – consistent with real-world incidents. Further defensive measures are needed to ensure uninterrupted operation: single points of failure should be avoided through redundant communication, decentralized control systems, and vehicle-to-vehicle communication.

Conclusion and Outlook

We conducted a risk analysis of the ERTMS standards family by systematically translating the specifications into an abstract system model and assessing the risks using MoRA. Legacy components – particularly Eurobalises and GSM-R – are the primary source of risk. A complete transition to ETCS Level 2 and the deployment of FRMCS significantly improve the cybersecurity posture. Jamming and DDoS remain among the highest risks due to low RAPs.

We identified several limitations in applying the MoRA methodology to the railway domain, including: (1) Risks are often classified at the highest level due to their direct relevance to safety; (2) Damage conversion often does not lower the classification when the RAP is low; (3) Some risks are only downgraded to “Moderate,” even though the attacks are no longer possible. A rail-centric risk matrix addresses these issues as a natural next step. Further work includes extending the model beyond ERTMS, achieving finer granularity for individual subsystems (e.g., the attack surface of FRMCS), and experimentally validating the identified risks.

Learn more: The complete paper, including detailed tables of results (all 191 risks per control group), can be found in the extended version on arXiv. The paper has also been accepted for presentation at ARES 2026 CPRA [link will be availabe soon]. 

Authors

Most Popular

Never Miss a Post:

 
Bitte füllen Sie das Pflichtfeld aus.
Bitte füllen Sie das Pflichtfeld aus.
Bitte füllen Sie das Pflichtfeld aus.

* Mandatory

* Mandatory

By filling out the form you accept our privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Other Articles

Fault Attacks on ECC Signature Verification

Digital signatures used in embedded systems are often based on elliptic curve cryptography (ECC) thanks to its performance and low memory profile. In secure boot processes they provide the cryptographic foundation for guaranteeing the authenticity of a firmware image. At the same time, these resource-constraints and the physical exposure of such devices makes them prime targets for fault attacks. Prior work studied faults on signature generation in depth, yet nobody had systematically asked how vulnerable signature verification is to fault attacks combined with carefully crafted signature inputs. That is exactly the gap we set out to close.

Read More »
Visual of the Blog Post: How Secure Is Europe's Rail System? A Systematic Cybersecurity Risk Analysis of the ERTMS

How Secure Is Europe’s Rail System? A Systematic Cybersecurity Risk Analysis of the European Rail Traffic Management System (ERTMS)

The European Rail Traffic Management System (ERTMS) is designed to make Europe’s railways interoperable and safe. The system, which has been mandatory since 2002, combines standardized signaling, radio communication, and train control – but how well is it protected against cyberattacks? Using MoRA, our modular risk assessment approach, we systematically model the ERTMS and evaluate cybersecurity risks. We compare current and future configurations to identify the assets with the largest attack surface. Our overview of the entire system – from GSM-R, balises, FRMCS, ETCS levels, and ATO to key management – provides a concise preview of risk profiles and attack tree scenarios, and highlights practical countermeasures that significantly improve cybersecurity.

Read More »
Viisual for blog post: Codyze: Automated Analysis of Cybersecurity Requirements in Software

Codyze: Automated Analysis of Cybersecurity Requirements in Software

Manually verifying compliance with requirements such as the Cyber Resilience Act is not scalable. Our code analysis tool, Codyze, translates product-centric regulatory requirements into verifiable rules and automatically assesses whether the product’s source code fulfills them – across languages and microservices. Codyze makes all analysis results transparent to developers, security teams, and auditors.

Read More »
WordPress Cookie Plugin by Real Cookie Banner