Safeguarding critical rail systems & operations

Security Gateway

Enforce secure segregation of critical rail networks and cut your exposure to cyber attack, on new and refurbished fleets.

Security Gateway product illustration
Overview

What it does

Security Gateway sits between key areas of the on-board network and enforces segregation, so train operators, builders and OEMs can manage secure zones and conduits without reliance on individual system suppliers.

It is a Layer 7 firewall with rail protocol support: it filters and inspects traffic crossing zone boundaries. For visibility inside each zone, pair it with Delta, which monitors devices and traffic within the zones. Deploy Security Gateway as an EN 50155 compliant hardware appliance, or as software on approved existing hardware.

Security Gateway is in service on new-build and retrofit rail programmes.

Benefits

Key benefits

Inspect traffic between zones

Deep packet inspection and Layer 7 rail-protocol filtering control what crosses each security boundary.

Combine security functions on one platform

Host Delta intrusion detection and other security applications as isolated modules alongside boundary enforcement.

Control configuration across the fleet

Configuration-as-code, controlled over-the-air updates and safeguarded rollback make changes easier to manage and audit.

Meet the operator’s specification

Select the deployment and filtering controls against the fleet architecture, risk assessment and OEM requirements.

Capabilities

Key capabilities

Network segregation

Separate on-board zones and control the traffic that crosses between them.

Protocol filtering

Apply Layer 7 inspection and rail-protocol filtering at zone boundaries.

Hardware or software deployment

EN 50155 compliant appliance, or software on approved existing hardware.

Central log aggregation

Syslog feeds into your SOC/SIEM for fleet-wide correlation.

Hardened application platform

Secure boot and disk encryption protect the platform, which can also host Delta as an isolated service module. Security Gateway is designed to stay in service for 15 years, with maintenance and updates throughout that period.

Configuration management

Configuration-as-code with selective over-the-air updates, A/B partitioning and safeguarded rollback.

Rugged modular Westermo on-board computer with M12 Ethernet, serial, USB, LTE and WLAN interfaces
Security Gateway runs on rugged Westermo rolling stock hardware: M12 Ethernet, serial, LTE and WLAN options. Also deployable as software on approved existing on-board hardware.
Role in The Secure Train

Enforce at the boundary

Security Gateway is the enforcement layer of The Secure Train: it separates onboard zones and filters the traffic that crosses between passenger, comfort, TCMS and safety-related environments.

See the full architecture
Operator SOC / SIEM CEF feeds · REST API · SOAR / CMDB RazorSecure Cloud · Dashboard Customer teams · optional analyst service Encrypted, prioritised store-and-forward On-board External interfaces Passenger Wi-Fi LTE / 5G · GSM-R Depot & shore Untrusted SECURITY GATEWAY Safety-critical CAN · MVB buses Delta · MVB IDS TCMS Train control & monitoring Delta Comfort CCTV · PIS · HVAC Delta Passenger Wi-Fi · infotainment Delta Passive monitoring plane: Delta detection & Echo asset status from every zone, no interference with train control Digital Maintenance Gateway: MFA · secure software updates Maintenance engineers: named users, agreed time windows

Plan your integration

A technical workshop pack covering interface, environmental and performance detail is available on request.

Request a technical workshop
Secure separation for critical on-board networks

Talk to our engineering team

Bring your programme requirements, fleet architecture and risk assessment, including any penetration-test findings. We help train builders meet their operators’ specifications and help operators plan security improvements to existing fleets.

Request a demo Explore products