Standardisation and Immunity Tests regarding · 6 Product Standards • The weakest link for the...
Transcript of Standardisation and Immunity Tests regarding · 6 Product Standards • The weakest link for the...
Standardisation and Immunity Tests regarding IEMI
Véronique Beauvois ULG
SECRET Final conference - Lille 2015 10 29
2
ERTMS: European Railway Traffic Management System
GSM-R: Global System for Mobiles-Railways European Railway radio system for voice and data communication
EUROBALISE
GSM-R
MODEM
CONTROLCENTRE
EUROBALISE
GSM-R
MODEM
CONTROLCENTRE
Train detection, location information
Data and voice transmissions
SECRET Final conference - Lille 2015 10 29
ERTMS = Unique signalling standards throughout Europe
3
EM attacks: definitions
SECRET Final conference - Lille 2015 10 29
IEMI: Intentional EM Interferences
HPEM sources: High Power EM sources
HEMP: High-altitude ElectroMagnetic Pulse
Any system of emission unauthorized or not, available on public domain: Jammer, remote control, emission and amplifier components, EMP Guns…..
Scope of the SECRET project Impact of these systems on the radio links
involved on the railway operational
Especially GSM-R transmissions
4
SECRET is concerned by jamming = intentional signal
vs
Railway EMC immunity standards performed on electronic equipment are based on unintentional disturbances.
SECRET Final conference - Lille 2015 10 29
EMC Standards
5
Product Standards • Railway applications.
• EMC product standards are EN standards, series EN 50121-x.
• EN 50121-4 Railway applications – EMC – Emission & Immunity of signalling and telecommunication apparatus in railway applications.
• EN 50121-3-2 Railway applications – EMC – Rolling stock – Apparatus
• …
SECRET Final conference - Lille 2015 10 29
EMC Standards for Railway
6
Product Standards • The weakest link for the jamming attack is the communication (GSM-R,
TETRA, Eurobalise). • EMC product standards are ETSI standards, series EN 301 489-x for radio
equipments and services. • EN 301 489-1 • EN 301 489-7 for GSM and DCS mobile equipments • EN 301 489-8 for GSM base stations • EN 301 489-18 for TETRA equipments • … • GSM-R? with exclusion bands (vs. jamming in the useful band).
SECRET Final conference - Lille 2015 10 29
7
Immunity Standards • EMC product standards are based on basic immunity standards
EN 61000-4-x series (TC77).
• As we are concerned by radiated fields, EN 61000-4-3*
• 80 MHz to 1 GHz – 1.4 GHz to 2.7 GHz (sinusoidal)
• AM modulation 1 kHz 80 %
• Level 3 V/m
• Exclusion bands around transceiver nominal frequency.
* The other basic standards mentioned in the previously mentioned product standards concerned mainly conducted tests.
SECRET Final conference - Lille 2015 10 29
EMC Standards
8
Immunity Standards • EMC product standards are based on basic immunity
standards EN 61000-4-x series (TC77).
• Only SC77C develops basic immunity standards on intentional phenomena.
• SC 77C : High-power transient phenomena, including IEMI (Intentional) (high power conditions = incident E fields > 100 V/m).
• e.g. IEC 61000-4-36: IEMI Immunity Test Methods for Equipment and Systems (project 77C/222/CD)
• Annex G including jammers
SECRET Final conference - Lille 2015 10 29
EMC Standards
SECRET Final conference - Lille 2015 10 29 9
GSM-R Susceptibility Measurements
Ref: S. Dudoyer , V. Deniau et al., "Study of the Susceptibility of the GSM-R Communications Face to the Electro - magnetic Interferences of the Rail Environment," IEEE Transactions on Electromagnetic Compatibility, vol.54, no.3, pp.667-676, June 2012
BTS Simulator
Jamming Signal
Immunity Test Setup evaluates the impact of jamming signal on GSM-R transmissions measuring RXQual
Tests in Lab
Parameters: 1) Jamming waveform 2) Repetition Rate 3) GSM-R signal power level
Conclusions
Today, none standard concerning the vulnerability of systems involving radio links regarding jamming signals.
The vulnerability is real and jamming signals can have major consequences on the railway system.
The vulnerability of the radio link is depending on the power level of the communication signal. So, how can we specify the test configuration?
The time characteristics of the jamming signal impact significantly the test results. So, how can we define a reference jamming signal?
Can we perform immunity tests dedicated to jamming signal?
SECRET Final conference - Lille 2015 10 29
Conclusions
Can we perform immunity tests dedicated to jamming signal?
Today, tests to jamming signals should not be considered with an immunity
level to verify … but can be indicative and permit to the railway operators to check in case
of evolution of the communication solution the vulnerability increases of decreases.
More generally, the communication solutions applied to critical
infrastructure should be able to monitor itself the presence of jamming signal…
and in that case, test to jamming signal should permit to check the efficiency of the monitoring solution
SECRET Final conference - Lille 2015 10 29
Thank you for attention
http://www.secret-project.eu
12 SECRET Final conference - Lille 2015 10 29