Back to results

Queens University

Security of Communication-Based Train Control Systems

Abstract

dc:description.abstract

Communication-Based Train Control (CBTC) systems are automatic train control systems that rely on bidirectional communications between trains and wayside units to exchange train status information and operational commands. Introducing wireless technologies changed train control systems to cyber-physical systems vulnerable to cyber attacks. Therefore, it is crucial to protect the security of CBTC systems. This thesis provides a comprehensive solution to secure CBTC communications. Its contributions represent solutions to detect attacks, mitigate their impacts, and securely manage communication session keys. It offers TrainSec, an open-source simulation framework for CBTC networks. TrainSec implements the functional requirements defined in IEEE 1474.1, the standard for CBTC performance and functional requirements. CBTCset is an open-source dataset, provided to detect misbehavior attacks in CBTC networks. The thesis then presents Train-CaDet, a novel context-aware framework for intrusion detection systems (IDSs) that use machine learning (ML) to detect attacks on train-to-wayside (T2W) communications. It facilitates the development of adaptive ML-based IDSs responsive to changes in the dynamic environmental context. The experimental results show that context awareness improves detection performance by increasing accuracy and decreasing false positive rates. Furthermore, deploying train-to-train (T2T) communication links besides T2W links reduces the latency and end-to-end delays of CBTC communications. The security of T2T-CBTC systems is addressed by presenting two resilient control strategies that mitigate the impacts of jamming attacks on their communications. The strategies are based on multi-agent deep reinforcement learning and contribute to achieving convergence and reaching a stable state faster than existing strategies. Train-DGKMS is a decentralized group key management system (DGKMS) proposed to manage group session keys for virtually-coupled train sets. It uses blockchain with smart contracts to ensure tamper-proof and automatic management of group session keys. The experimental results show that Train-DGKMS reduces the communication and computation overhead and the gas costs of smart contract functions compared to existing works in the literature.

Degree

thesis:*
Department dc:contributor.department
Computing
Year dc:date.issued
2025

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Fakhereldine, Amin
Advisor dc:contributor.supervisor
  • Zulkernine, Mohammad

Subjects

dc:subject × 10

Rights

dc:rights
Statement dc:rights
  • Attribution-NonCommercial-NoDerivatives 4.0 International
Language dc:language.iso
eng

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/1974/34285
OAI identifier oai:identifier
oai:queensu.scholaris.ca:1974/34285

Chain of custody

source
Harvested from
Queens University
Base URL
qspace.library.queensu.ca/server/oai/request
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
citation

Fakhereldine, Amin. Security of Communication-Based Train Control Systems. 2025. https://hdl.handle.net/1974/34285