Christoph Bonelli
Key Takeaways
- Evolit and Trafikverket, Sweden’s national infrastructure manager, are jointly developing a complete ETCS Key Management System (KMS).
- The KMS manages the lifecycle of the cryptographic keys used to secure communication between vehicles and trackside, and supports their automated online distribution.
- Cross-border key exchange with the key management systems of other infrastructure managers is also part of the solution.
- Evolit brings to this multi-year collaboration its experience from the ETCS Key Management Centre with online key exchange already delivered for ÖBB.
For ETCS to work reliably, the communication between vehicle and trackside must be properly protected. Cryptographic keys do that job: they allow the On-Board Unit (OBU) and the Radio Block Centre (RBC) to authenticate each other. As ETCS is rolled out step by step in Sweden, key management that securely generates, manages and distributes these keys and keeps their entire lifecycle traceable becomes all the more important.
That is why Evolit is developing a new ETCS Key Management System (KMS) together with Trafikverket. The focus is on automated processes, online key distribution, high cybersecurity requirements and interoperability with the systems of other European infrastructure managers. After the Key Management Centre (KMC) for ÖBB, it is the second European key management system to distribute keys online. It is also the first European online KMS to reach Security Level 3 – the second-highest security level in the 62443 series of standards.
Starting Point: ETCS Needs Modern, Reliable Key Management
As the national infrastructure manager, Trafikverket is responsible for Sweden’s state transport infrastructure and is driving the modernisation of the Swedish rail system with ETCS. As ETCS becomes more widespread, the number of cryptographic keys and of the systems involved grows with it. That increases the need for modern, automated key management that also allows keys to be exchanged online. These keys have to be generated, distributed securely, renewed and managed traceably across their entire lifecycle – a task that places high demands on cryptography and cyber security.
At the same time, the task does not stop at the national border: vehicles run internationally and therefore need keys from different infrastructure managers. A modern KMS must not only automate internal processes, but also enable secure, standardised exchange with other key management centres.
For Trafikverket, this creates an infrastructure component that has to work reliably for many years and remain maintainable in the long term.

Implementation: Online Key Management to UNISIG SUBSET-137
The KMS is being built in a multi-year joint undertaking by Trafikverket and Evolit. It is not just about the central application: the scope also covers the secured system environment, the interfaces to vehicles, trackside and other operators, and the operational processes that keep key management working in rail operations over the long term.
Evolit brings experience from developing ETCS key management systems to the project: an ETCS Key Management Centre with online key exchange has already been delivered for ÖBB. For Trafikverket, the work goes a step further – from a Key Management Centre to a complete Key Management System.
“Key management in ETCS is one of the most security-critical topics in digital rail operations. The fact that Trafikverket trusts us as a long-term partner here confirms what we set out to do: to combine the highest level of security and standards compliance with processes that work reliably in operation, year after year.”
Christoph Bonelli
Lead AI Innovation Group, Evolit
At the heart of the KMS is the Key Management Centre, which is conceptually similar to INFRA.KMC, the system Evolit developed for ÖBB. It generates, manages and distributes the cryptographic keys that protect radio communication between vehicles and trackside, and it automates secure key installation. The result is a central, traceable basis for key management between the ETCS components involved. The KMS also supports cross-border key exchange with the key management systems of other operators.
The solution is consistently aligned with the relevant European standards (UNISIG subsets of the ETCS specification, EN 50701 and ISO 62443) and relies on proven security mechanisms such as PKI, X.509 certificates, TLS and hardware security modules (HSM). It is embedded in an infrastructure model designed to ISO 62443. Architecture and development are geared throughout to Security Level 3, in other words to protection against targeted attacks using sophisticated means. A mandatory validation process ensures that the KMS meets the resulting requirements as a complete system.
Result: What the New KMS Is Designed to Deliver in Operation

As of September 2026, the KMS is in the development and test phase. The solution is designed to automate key management and, at the same time, to meet the high security and interoperability requirements of the ETCS environment. For Trafikverket, the following goals are central:
- Central key management: Cryptographic keys are generated, managed and traceably documented centrally across their entire lifecycle.
- Automated online distribution: Keys can be distributed securely via digital interfaces, which reduces manual process steps.
- Cross-border exchange: The KMS supports key exchange with the key management systems of other infrastructure managers.
- Standards-compliant implementation: The solution follows the relevant ETCS specifications and established cybersecurity requirements.
- Long-term operability: Architecture and processes are designed from the outset for years of use and further development in the rail environment.
- Operation as “home KMC as a service”: The KMS is also designed, in principle, to manage the keys for vehicle fleets as a service. As a result of the deregulation of the Swedish railway market, Trafikverket will not use “home KMC as a service” itself. Instead, Trafikverket will ensure that an interface is available upon completion of the project, when this service is introduced to the market.
Outlook: Part of a European Rail Network
Secure key management is not an end in itself – it is the basis of trust on which digital rail operations rest, and it enables efficient exchange via online interfaces. With the KMS for Trafikverket, Evolit is helping to keep ETCS in Sweden and in cross-border traffic secure, standards-compliant and operable in the long term. With Security Level 3, the KMS sets a new security benchmark across Europe.
The project is part of Evolit’s growing portfolio of security-related rail solutions for infrastructure managers across Europe – from adaptive rail operations and European real-time data platforms to secure digital infrastructure.
About Trafikverket
Trafikverket is the Swedish Transport Administration, responsible for the long-term planning of the transport infrastructure and for the construction, operation and maintenance of state roads and railways. In the rail sector, its responsibilities include the step-by-step introduction of ERTMS in Sweden.
More on "Mobility"
Mobility
Train Prediction with Graph Theory: A Research Project Makes Train Runs Computable
Train prediction with graph theory: how ÖBB-Infrastruktur AG and Evolit model train runs and compare forecasting methods on a shared data basis.
Mobility
Digital Train Preparation in Rail Freight: PORTHOS at ÖBB
With PORTHOS, ÖBB-Infrastruktur is digitalising the planning, dispatching and execution of train preparation – from train path ordering to automated train data reporting.
Mobility
Automatic Warning Systems: The Data Foundation for Safe Work on the Track
How Evolit modernised the data foundation of an automatic warning system in rail operations: a web application with versioning, SSO and RFID integration.