Efficient & secure digital maintenance

Digital Maintenance Gateway

Secure local and remote maintenance access through one audited route, with individual authentication and a common credential store across the fleet.

Digital Maintenance Gateway product illustration
Overview

What it does

Digital Maintenance Gateway (DMG) improves security and efficiency when updating on-board and wayside systems by eliminating the need for dedicated service laptops and USBs. It provides a secure, managed point of access for existing maintenance applications.

Engineers use a familiar and consistent working environment. Local and remote access use individual authentication and can use multi-factor authentication, with the same audit trail. A common credential store across the fleet replaces shared per-vehicle accounts. Every session starts in a clean state and every action is attributable and auditable.

DMG supports controlled maintenance workflows across multiple units without exposing on-board systems directly to service laptops.

Benefits

Key benefits

Reduce maintenance cost

Free skilled staff from managing service laptops with controlled distribution of firmware and configuration files. One engineer can update multiple units in a single shift, instead of one engineer per train per night.

Control access

Give named engineers controlled access to systems that cannot provide individual authentication themselves. This compensating control supports access-control evidence without modifying the underlying system.

Audit activity & monitoring

Full traceability of maintenance activity for compliance and fast diagnosis.

Close off common attack paths

Isolate insecure service laptops and remove USB transfer entirely.

Capabilities

Key capabilities

Secure remote access & authentication

Time-bound access is limited to specific assets and named engineers. MFA supports local and remote access, with a common audit trail.

Secure digital environment

A clean-state desktop session around your existing maintenance applications.

Controlled file distribution

Production, authorisation, installation, verification and monitoring form a controlled update workflow. A wayside repository supports code-signed software distribution, with synchronisation to the train and validation of the software. Separate production and authorisation roles control release.

Protects on-board systems

Isolates service laptops from on-board systems, removes USB transfer and prevents unauthorised applications from being added through the managed environment.

Session recording & audit

Recorded sessions support diagnosis and audit.

Works with wayside too

One maintenance approach across vehicles and infrastructure.

Train cutaway diagram showing the Digital Maintenance Gateway connected to train control, IT network, passenger interface and comfort systems
One audited access path to every maintainable system on the vehicle: train control, IT network, passenger interfaces and comfort systems.
Role in The Secure Train

Control maintenance access

Digital Maintenance Gateway is the maintenance layer of The Secure Train: named users, multi-factor authentication, controlled update workflows and full audit records replace unmanaged service laptops.

See the full architecture
Operator SOC / SIEM CEF feeds · REST API · SOAR / CMDB RazorSecure Cloud · Dashboard Customer teams · optional analyst service Encrypted, prioritised store-and-forward On-board External interfaces Passenger Wi-Fi LTE / 5G · GSM-R Depot & shore Untrusted SECURITY GATEWAY Safety-critical CAN · MVB buses Delta · MVB IDS TCMS Train control & monitoring Delta Comfort CCTV · PIS · HVAC Delta Passenger Wi-Fi · infotainment Delta Passive monitoring plane: Delta detection & Echo asset status from every zone, no interference with train control Digital Maintenance Gateway: MFA · secure software updates Maintenance engineers: named users, agreed time windows

Plan your integration

A maintenance workflow and deployment workshop is available on request.

Request a technical workshop
Every maintenance session authenticated & audited

Talk to our engineering team

Bring your programme requirements, fleet architecture and risk assessment, including any penetration-test findings. We help train builders meet their operators’ specifications and help operators plan security improvements to existing fleets.

Request a demo Explore products