Cybersecurity 

Future-proofing networked and embedded security solutions from duagon 

Cybersecurity is now a key necessity for networked products and systems. In security and business-critical areas such as railway and medical technology or industrial automation, cyberattacks can lead to outages, data loss, or business interruptions. At the same time, regulatory requirements such as the Cyber Resilience Act (CRA) are increasing the pressure on manufacturers and operators to act. 

At duagon cybersecurity begins as early as the planning phase: Our experts accompany you along the entire product lifecycle – from new secure product developments to risk analysis and vulnerability watch for existing products. Our security solutions are tailor-made for embedded systems, communication platforms and networked devices.  To help you protect your project as effectively as possible against cyber threats while complying with regulatory requirements, we offer product-related cybersecurity services throughout the entire product lifecycle.

Cyber Resilience Act
Product Related Services

Security Certifications from duagon

The basis for the secure operation of networked systems is compliance with internationally recognized norms and security standards. In the railway industry, various cybersecurity standards apply to operators, system integrators, and product suppliers. As a product supplier, we also follow the development of standards that are important to our customers, to ensure that they meet their requirements. 

We meet relevant quality and security standards with the following certificates:  

Cybersecurity in railway transport

Networked control and communication systems are the basis of modern rail vehicles. Train Control Networks (TCN) and Ethernet Consist Networks (ECN) continuously exchange control, monitoring and status data that are essential for safe and reliable rail operations. At the same time, these networked structures create new points of attack for cyber threats. 

Our platforms and cybersecurity solutions reliably secure critical and non-critical on-board systems against unauthorized access and manipulation. With powerful capabilities to prevent, detect, and respond to cyberattacks, we support operators in developing and operating cybersecure vital TCNs and ECN-based systems.

Secure Products for Critical Applications

At duagon, we provide secure computing systems, I/O devices, security gateways, and network interface cards for railway transport, medical technology, and industrial use. Our expertise in CPU module design enables us to build security into our products from the very beginning. Combined with structured development processes and rigorous documentation, we ensure that security requirements are integrated, implemented, and verified throughout the entire development lifecycle.

 

Contact our team for more information

Enhanced media conversion gateways 

Our proven portfolio of gateways for media and protocol conversion has been enhanced with cybersecurity features. Secure configurations, comprehensive diagnostic functions, and a future-proof architecture help you reliably meet the growing demands of modern rail projects in terms of security, availability, and compliance with standards.

Flexible Protocol Translation

  • Versatile gateways to either connect a legacy bus (CAN/Serial/MVB) device to the ECN or an Ethernet-based device to MVB/CAN/Serial 

  • Support for Ethernet redundancy handling (dual homing) 

  • Standard mapping applications without the need to write a custom application  

  • Possibility for advanced mapping and services implementation based on customer requirements by our application engineering team or using our development library supporting process and message data

Secure Maintenance 

  • Role based user access with remote authentication services (e.g. Radius client) 

  • Software integrity checks and secure, certificate based, firmware update procedures 

  • Encrypted communication to our web services via sftp/ssh/https 

Configurable Hardware & Software Filters

Hard coded hardware filters 

  • Directly implemented in the FPGA without affecting the speed of data flow

  • Can be configured with a configuration file, e.g. a text file, to allow greater flexibility. Possibility of locking the memory once the configuration file has been loaded

NIOS softcore filtering CPU 

  • CPU implemented in the FPGA, solely dedicated to package filtering

  • Minimal influence on the package throughput

  • Can be user-programmed in C 

Properties 

  • Static, configurable filtering

  • Dynamic filtering in dedicated CPU

  • Up to 100 static filters, dynamic filter up to memory capacity

Our Secure Filters

DIN-Rail Secure Computing Platform

The MC50M is a computing platform for applications such as security gateways, wireless IoT gateways, predictive maintenance, ticketing systems, and diagnostic servers. In this configuration, it protects the vital train infrastructure from malicious traffic, viruses, and malware. The MC50M can be extended with serial ports, MVB or CAN bus interface or wireless communication interfaces such as LTE and WLAN. 

Features: 

  • Secure boot, measured boot, UEFI hardening for the pre-boot environment

  • 3 Separate Ethernet ports with three MAC addresses - supporting cybersecurity applications 

  • Intel Atom E3900 series 

  • Up to 8 GB DDR3 RAM with ECC 

  • Trusted Platform Module 

  • M.2 NVMe slot for storage 

  • Gb Ethernet, USB 3.2 Gen 1x1, RS232, RS485/422, DisplayPort 

  • As a service: custom specific product authentification

Secure Wake-Up Function

Secure web front-end (HTTPS), that can be used for diagnostic purposes and to upload and execute firmware updates. 

Secure ETH connection (ssh)

> Receiving wake-up trigger 

< Confirm wake-up state 

Secure communication protocols like HTTPS web server, SFTP file transfer, SSH CLI 

  • Authentication by password, public key or host based 

  • 2 digital outputs (24-110 V); bi-directional solid state relay output with current limitation 

  • 2 digital inputs (24-110 V); state, PWM or frequency input 

  • 2x2 analog inputs; voltage, current, resistance 

Secure boot - software integrity check

Ensures software authenticity at startup using cryptographic signatures, protecting your system from unauthorized or tampered code while allowing customer-specific key management. 

  • A private key is used to create a signature of each software package (OS, drivers, application) 

  • With the corresponding public key, the authenticity of the software is checked before it is booted or executed 

  • Keyhandling methods enable customer to make use of an own set of keys, independent from keys created by manufacturer (platform key, key exchange key) 

Secure Network Interface Cards

Protects data exchange between vital and non-vital networks by monitoring, filtering, and controlling network traffic, helping prevent unauthorized access and reduce cyber threats.

Access Control and User Access Management (UAM):

  • Role-based access control (RBAC), using centralized access control by supporting a RADIUS client (according to RFC 2865) for managing authentication via a remote server

  • The anti-brute force mechanism provides an account lockout or time delay for local accounts to mitigate brute-force attacks

  • The UAM tracks user sessions by assigning a random identifier

Security Auditing and Logging:

  • Security events are sent as syslog data over UDP (RFC 5426)

  • Security events are sent to up to two syslog servers which can be configured from the device command line interface

Find out how to protect your critical infrastructure

Our sales team provides detailed information on our hardware, software expertise, required standards, and cybersecurity best practices. They also collaborate with our engineers to create the best solution for your application. 

 

Contact us

Frequently Asked Questions (FAQ) - Cybersecurity

Who can support me with my cybersecurity requirements?

Staying cyber secure is an ongoing process. Organizations that embed security throughout the product lifecycle are better positioned to reduce risk, maintain compliance, and deliver resilient products to their customers. 

duagon offers a comprehensive set of services throughout the entire product lifecycle. The evaluation of a project with cybersecurity requirements follows similar process steps like a standard customization project for duagon products. The process for an individual project can be accelerated when train builder specific security concepts have been pre-defined. 

  • At the beginning of your project, duagon will help to define an appropriate security level for your specific use case, offer general cybersecurity consultancy, as well as initial threat & risk analysis. 
  • The design process follows IEC 62443-4-1 and makes use of our duagon secure product development platforms which include secure coding, product hardening, penetration tests, user access management, setup & maintenance of Public Key Infrastructure (PKI), security documentation, and the setup of vulnerability watch. 
  • Production will take place in duagon’s in-house factories. 
  • The delivery of your products will be secured by tamper detection through software integrity checks. You will also receive a security manual. 
  • Once your product is put into operation, duagon’s vulnerability watch will monitor the security status of all 3rd party components and detected issues in own components. Depending on the feature package implemented, various services help maintain a secure operation like security audit logging, centralized user management or secure firmware update and firewall functionality. Additionally, duagon offers software security updates to close known security vulnerabilities. 
  • At the end of your product’s lifecycle, duagon will take care of secure and verifiable deletion of sensitive data and disposal of hardware according to environmental regulations. 
Which security levels can duagon cover?

The IEC 62443 standard defines security levels on a five-point scale (0, 1, 2, 3 and 4), each of which represents an incremental level in terms of cybersecurity measures. 

  • SL1 can be covered by the duagon Cybersecurity Basic Package elements 
  • SL2 can be covered by the duagon Cybersecurity Extended Package elements 
  • SL3 can be covered by the duagon Cybersecurity Advanced Package elements with customizations 
  • SL4 may be offered in the scope of a customer specific project 
What are cybersecurity services for embedded and connected products?

Cybersecurity services for embedded and connected products help manufacturers identify, reduce, and manage cyber risks throughout the product lifecycle. They can include risk assessments, threat modelling, secure software development, security testing, vulnerability management, SBOM creation, PSIRT setup, and incident support.

These services are particularly relevant for industrial systems, rail applications, medical devices, edge computers, gateways, and other products with digital elements.

What is product cybersecurity?

Product cybersecurity is the protection of a connected product, its software, interfaces, data, and communications against cyber threats. It covers the complete lifecycle, from development and production to operation, maintenance, updates, and end of support.

For embedded and industrial products, product cybersecurity may include secure boot, authentication, encryption, hardening, secure remote access, vulnerability management, and security monitoring.

Why do industrial and embedded products need cybersecurity?

Industrial and embedded products are increasingly connected to networks, cloud services, maintenance tools, and other devices. This connectivity can create attack surfaces that may affect availability, integrity, confidentiality, safety, operations, and business continuity.

Cybersecurity helps manufacturers and operators protect devices, networks, software, and data from unauthorized access, manipulation, malware, and service disruption.

What is a cybersecurity risk assessment?

A cybersecurity risk assessment identifies relevant assets, threats, vulnerabilities, attack paths, and potential business or operational impacts. It helps determine which security measures are appropriate for a product, system, or application.

For connected products, the assessment should consider the device, embedded software, interfaces, supply chain, user roles, communications, update mechanisms, and expected operating environment.

What is threat modelling?

Threat modelling is a structured method for identifying how a product or system could be attacked, and which controls are needed to reduce risk. It is usually carried out during the design and development phase.

A threat model documents assets, trust boundaries, interfaces, potential attackers, attack scenarios, and security requirements. It supports secure-by-design development and provides evidence for product-security and compliance activities.

What is vulnerability management for connected products?

Vulnerability management is the ongoing process of identifying, assessing, prioritizing, remediating, and communicating security vulnerabilities in products and software.

For connected products, it includes monitoring vulnerability sources, assessing the affected product versions, coordinating fixes, providing security updates where appropriate, publishing advisories, and maintaining documentation across the supported product lifecycle.

How does IEC 62443 support industrial cybersecurity?

IEC 62443 is a family of international standards for cybersecurity in industrial automation and control systems. It provides guidance for operators, integrators, service providers, and product manufacturers.

The standards address areas such as secure development lifecycle practices, security levels, risk assessment, system architecture, component security, and operational security. The applicable parts depend on the organization’s role and the specific product or system.

How can railway systems be protected against cyber threats?

Railway cybersecurity requires a risk-based approach that protects rolling stock, signalling, trackside infrastructure, communication networks, maintenance interfaces, and passenger-facing systems.

Typical measures include security architecture reviews, network segmentation, secure remote access, hardening, intrusion detection, vulnerability management, monitoring, incident response planning, and alignment with relevant rail cybersecurity requirements such as TS 50701 where applicable.

Cybersecurity Glossary

ATC Automatic train control 
CIA (Triad)Confidentiality, Integrity, and Availability: The three core principles of cybersecurity: protecting information from unauthorized disclosure, preventing unauthorized modification, and ensuring reliable access when needed.
CVE Common Vulnerability & Exposure 
CVSS Common Vulnerability Scoring System 
Cyber Attack attack by hackers/cyber criminals against a computer or network to steal data, disrupt systems or maliciously damage or deactivate computers. 
Cybersecurity The protection of on-board computer systems (in general on-board-units (OBU), vehicle control units (VCU), etc.) from theft of or damage to their hardware, software or electronic data, as well as from disruption or misdirection of the services they provide.
DC Data Confidentiality 
DoS Denial of Service: The hacker attempts to prevent legitimate users from accessing the service by flooding the service with with superfluous requests 
ECN Ethernet Consist Networks 
EoP Elevation of Privilege: User group / profile manipulation 
ETB Ethernet train backbone 
ETBN Ethernet Train Backbone Node 
HB-IDS Host based intrusion detection system 
IAC Identification & Authentication Control 
IDD Intrusion Detection Device 
IDS Intrusion Detection System 
IEC 62443 Industry standard: defines security levels on a five-point scale (0, 1, 2, 3 and 4), each of which represents an incremental level in terms of cybersecurity measures. 
ISO 27001 International standard: managing information security 
Malware Malware is any software that brings harm to a computer system 
MVB Multifunction Vehicle Bus 
NIDSNetwork Intrusion Detection System
NIS2 Update to the Network and Information Security (NIS) Directive that establishes cybersecurity and incident reporting requirements for essential and important entities. EU-wide legislation aiming to strengthen cybersecurity across the EU. 
NVD National Vulnerability Database 
NW-IDS Network based intrusion detection system 
PEN test Penetration testing, an authorized security assessment in which specialists simulate realistic attack methods to identify exploitable weaknesses. 
PIS Personal Information Systems 
PKI Public Key Infrastructure 
PSIRT Product Security Incident Response Team, a process an organization uses to receive, analyze, remediate, and publicly disclose security vulnerabilities in its products or services. 
RA Resource Availability 
RDF Restricted Data Flow 
SED Secure end device system controller 
SGW Security Gateway between networks 
SI System Integrity 
SL Security Level 
Spoofing Denial-of-service attacks often use IP spoofing to overload networks and devices with packets that appear to be from legitimate source IP addresses. 
SRIOM Secure Remote I/O Device 
Tampering Malware / ransomware injection, change of hidden fields in web applications, change of parameters in URLs 
TBN Train Backbone Node 
TCN Train Communication Network 
TCS Train Control System 
Threat Modeling A procedure for optimizing network security by identifying objectives and vulnerabilities, and then defining countermeasures to prevent, or mitigate the effects of, threats to the system 
TRA Threat and risk analysis 
TRE Timely Response to Events 
UC Use Control 
WTB Wire Train Bus