Projet “Europe’s Rail Joint Undertaking (ERJU) – Innovation Pillar – R2DATO”
Titre de la publication : D31.5 Use case YTSM model report
Date : 10.11.2023
Rôle : Leader
Lien vers la publication
Titre de la publication : D31.4 – Yard to station automatic movement system analysis
Date : 13.05.2025
Rôle : Leader
Lien vers la publication
Projet “Open CCS On-Board Architecture” (OCORA)
Titre de la publication : WP04 Train Display System – Modelling activities intermediate report
Date : 10.11.2023
Rôle : Leader
Lien vers la publication
Résumé
The ERTMS system allows the supervision and automatic control of trains. It is made up of sub-systems on
board the trains. Among them, the EVC (European Vital Computer) performs the calculations, and the TDS
(Train Display System) is a man-machine-interface which displays the information to the driver. These two
pieces of equipment communicate with each other.
The technical specification for interoperability defines a set of standards which specify the ERTMS system.
Some of these standards define the interface between two subsystems. Subset 121 specifies the interface
between the EVC and the TDS.
The model-based engineering approach aims to improve the quality of system design. Indeed, this method
relies on standards, processes and specific tools. It aims to obtain a formalized, structured and verifiable
definition of systems. It is applied throughout the development cycle. Thus, this approach compensates for the
weaknesses of the traditional approach of document specification written in natural language. This approach
is part of the wider systems engineering approach which includes configuration management, requirements
management, synthesis of the various specialities involved, and interface management. The specialities may
be technical (aeraulics, thermodynamics, etc.) or support (operating safety, cyber security, etc.). Thus, the
model-based engineering approach is interwoven with the system engineering approach, and these two
approaches feed off each other.
Matlab/Simulink is a development environment allowing the modelling of a system. Programming can be done
visually by using predefined blocks or by writing scripts. The structure of the system can be represented by
the definition of “subsystems”. The behaviour of the system is implemented and can be simulated. Toolboxes
contain ready-to-use functions dedicated to technical domains (automobiles, etc.), technologies (artificial
intelligence, etc.), techniques (signal analysis, code verification, proof of concept, etc.).
In addition to the definition provided by subset 121, it is proposed to develop a model under Matlab/Simulink.
The model implements the structure and behaviour specified in the subset. Test scenarios are used to
dynamically explain the expected behaviour.
The objective is to obtain a set of specifications, in the form of the subset and the model, which:
- Clarifies the behaviour
- Justifies the requirements by verifying the specification through the implementation of tests


Titre de la publication : Cybersecurity testing strategy
Date : 07.12.2022
Rôle : Leader
Lien vers la publication
Résumé
Cybersecurity testing aims to give confidence that the system under test reaches the requested level of security
performance.
The requested level of security is provided through the risk assessment process which conducts to identify the
requirement and additional protection that the system shall implement. The testing process aims to verify that
the system implements these requirements and provide confidence that the system can face the identified risk.
Cybersecurity testing is a cross domain which applies on all components of a system for which requirements
or protection are required (Security level SL ≥1)
Due to system complexity, tests are only a sample of all situations that the system can face. The coverage of
tests shall also consider the difference between testable and non-testable requirement and the clear distinction
between functional proof and penetration testing as a practical method to measure the resilience against cyber
attacks
The effort and the complexity of the tests have to be estimated and defined accordingly to the level of security
that is assessed and the level of confidence to be achieved.
As there is no formal method to demonstrate compliance, the tester is not subject to an obligation of results
but more to an obligation of means. The results of the tests are valid at the time they are executed according
to the level of threat and exposure of the system. But this must be challenged throughout the lifecycle of the
system.
The duration of penetration testing should be prioritized on the level of exposition for subsystem to an attack
and proportionally aligned with the resilience needs in front of an attack / with the security level target.
