Summary
Key results
Secure startup ensured that only trusted software could run on the onboard rail communication system
Encrypted, failure-resistant software updates aligned with rail and regional cybersecurity requirements
New rail cybersecurity rules created a compliance gap
Alstom’s onboard communication gateway connects rail systems with other onboard components and external environments, making secure startup and software updates critical throughout the device lifecycle.
Changes in rail cybersecurity requirements, including updates to CENELEC standards and the broader impact of the Cyber Resilience Act, meant that the existing software loading and update processes did not meet the required cybersecurity standards. Alstom needed a production-ready approach that would allow only trusted software to run, reduce the risk of failed updates leaving the device unable to boot, and support the continued development and sale of the gateway devices.
The work required specialist low-level embedded expertise that was not available internally, so Alstom engaged Sii to deliver the solution end to end.
Secure startup and update capabilities for the onboard gateway
Sii assembled a team combining embedded engineering, solution architecture, test automation, documentation, and project management competencies to deliver the product end to end. The scope covered platform adaptation, secure startup, protected software updates, automated validation, documentation, and integration support.
The main technical challenge was integrating TF-A and U-Boot 2024 with the NXP LS1046A-based platform while preserving correct hardware initialization, existing client-specific configurations, and repeatable startup behavior. The team also had to ensure that the new security mechanisms did not affect system performance, security, or quality.
The scope of work included:
- Secure startup – enabling the gateway to run only trusted software components
- Protected software updates – introducing an encrypted, failure-resistant update mechanism that reduced the risk of interrupted or failed updates leaving the device unable to start
- Automated validation – creating repeatable tests for startup and update scenarios, including negative paths
- Documentation and handover – providing the solution description, procedures, and test assets needed for integration, maintenance, and future releases
After delivery, Sii supported Alstom in integrating the product into the target environment and resolving related issues.
Specialist delivery without building the capability internally
Sii delivered the project as a complete product and took responsibility for time, cost, and quality. This allowed Alstom to close a specialist embedded cybersecurity gap without building the required expertise and tooling internally.
The documentation, procedures, test assets, and post-delivery support gave Alstom a basis for integrating, maintaining, and developing the product further, while reducing dependency on individual experts.
Key results
- Restricting gateway operation to trusted software
- Meeting rail and regional cybersecurity requirements through encrypted updates
- Reducing the risk of leaving the device unable to boot through failure-resistant update logic
- Enabling repeatable validation of future releases through automated regression testing