{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T00:35:35Z","timestamp":1725842135306},"reference-count":54,"publisher":"Association for Computing Machinery (ACM)","issue":"4","funder":[{"name":"RFI - Rete Ferroviaria Italiana"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2023,10,31]]},"abstract":"\n The railway domain is regulated by rigorous safety standards to ensure that specific safety goals are met. Often, safety-critical systems rely on custom hardware-software components that are built from scratch to achieve specific functional and non-functional requirements. Instead, the (partial) usage of Commercial Off-The-Shelf (COTS) components is very attractive as it potentially allows reducing cost and time to market. Unfortunately, COTS components do not individually offer enough guarantees in terms of safety and security to be used in critical systems as they are. In such a context,\n RFI<\/jats:italic>\n (Rete Ferroviaria Italiana), a major player in Europe for railway infrastructure management, aims at equipping track-side workers with COTS devices to remotely and safely interact with the existing interlocking system, drastically improving the performance of maintenance operations. This paper describes the first effort to update existing (embedded) railway systems to a more recent cyber-physical system paradigm. Our Remote Worker Dashboard (RWD) pairs the existing safe interlocking machinery alongside COTS mobile components, making cyber and physical components cooperate to provide the user with responsive, safe, and secure service. Specifically, the RWD is a SIL4 cyber-physical system to support maintenance of actuators and railways in which COTS mobile devices are safely used by track-side workers. The concept, development, implementation, verification, and validation activities to build the RWD were carried out in compliance with the applicable CENELEC standards required by certification bodies to declare compliance with specific guidelines.\n <\/jats:p>","DOI":"10.1145\/3607193","type":"journal-article","created":{"date-parts":[[2023,7,4]],"date-time":"2023-07-04T13:37:28Z","timestamp":1688477848000},"page":"1-20","update-policy":"http:\/\/dx.doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Safe Maintenance of Railways using COTS Mobile Devices: The Remote Worker Dashboard"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"http:\/\/orcid.org\/0000-0001-9820-6047","authenticated-orcid":false,"given":"Tommaso","family":"Zoppi","sequence":"first","affiliation":[{"name":"Dept. of Mathematics and Informatics, University of Florence, Florence, Italy"}]},{"ORCID":"http:\/\/orcid.org\/0000-0002-5107-3897","authenticated-orcid":false,"given":"Innocenzo","family":"Mungiello","sequence":"additional","affiliation":[{"name":"R&D Department of Rete Ferroviaria Italiana - RFI, Afragola (Naples), Italy"}]},{"ORCID":"http:\/\/orcid.org\/0000-0002-2291-2428","authenticated-orcid":false,"given":"Andrea","family":"Ceccarelli","sequence":"additional","affiliation":[{"name":"Dept. of Mathematics and Informatics, University of Florence, Florence, Italy"}]},{"ORCID":"http:\/\/orcid.org\/0009-0001-2737-5801","authenticated-orcid":false,"given":"Alberto","family":"Cirillo","sequence":"additional","affiliation":[{"name":"R&D Department of Rete Ferroviaria Italiana - RFI, Afragola (Naples), Italy"}]},{"ORCID":"http:\/\/orcid.org\/0009-0003-7545-1674","authenticated-orcid":false,"given":"Lorenzo","family":"Sarti","sequence":"additional","affiliation":[{"name":"Dept. of Mathematics and Informatics, University of Florence, Florence, Italy"}]},{"ORCID":"http:\/\/orcid.org\/0009-0006-5246-5207","authenticated-orcid":false,"given":"Lorenzo","family":"Esposito","sequence":"additional","affiliation":[{"name":"R&D Department of Rete Ferroviaria Italiana - RFI, Afragola (Naples), Italy"}]},{"ORCID":"http:\/\/orcid.org\/0009-0005-0447-5446","authenticated-orcid":false,"given":"Giuseppe","family":"Scaglione","sequence":"additional","affiliation":[{"name":"R&D Department of Rete Ferroviaria Italiana - RFI, Osmannoro (Florence), Italy"}]},{"ORCID":"http:\/\/orcid.org\/0009-0007-1957-7941","authenticated-orcid":false,"given":"Sergio","family":"Repetto","sequence":"additional","affiliation":[{"name":"R&D Department of Rete Ferroviaria Italiana - RFI, Osmannoro (Florence), Italy"}]},{"ORCID":"http:\/\/orcid.org\/0000-0001-7366-6530","authenticated-orcid":false,"given":"Andrea","family":"Bondavalli","sequence":"additional","affiliation":[{"name":"Dept. of Mathematics and Informatics, University of Florence, Florence, Italy"}]}],"member":"320","published-online":{"date-parts":[[2023,10,14]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2004.2"},{"key":"e_1_3_2_3_2","unstructured":"International Electrotechnical Commission 2010 61508 functional safety of electrical\/electronic\/programmable electronic safety-related systems"},{"key":"e_1_3_2_4_2","unstructured":"CENELEC EN. 50159. Railway applications - Communication signalling and processing systems - Safety-related Communication in Transmission Part 2 (2011)."},{"key":"e_1_3_2_5_2","unstructured":"MISRA C:2012. Guidelines for the use of C in Critical Systems 978-1-906400-11-8 Motor Industry Research Association (2013)."},{"key":"e_1_3_2_6_2","unstructured":"International Electrotechnical Commission and Technical Committee 56. 2016. Hazard and operability studies (HA- Q6 641 ZOP studies): Application guide. IEC61882:2016."},{"key":"e_1_3_2_7_2","volume-title":"Failure Mode and Effect Analysis: FMEA from Theory to Execution","author":"Stamatis D. H.","year":"2003","unstructured":"D. H. Stamatis. 2003. Failure Mode and Effect Analysis: FMEA from Theory to Execution. ASQ Quality Press."},{"key":"e_1_3_2_8_2","unstructured":"CENELEC EN 50126. 2017. Railway applications - The specification and demonstration of Reliability Availability Maintainability and Safety (RAMS) \u2013 part 1 (2017)."},{"key":"e_1_3_2_9_2","unstructured":"CENELEC EN 50128. 2012. Railway applications - Communication signalling and processing systems - Software for railway control and protection systems. (2012)."},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1186\/s13173-021-00106-w"},{"key":"e_1_3_2_11_2","unstructured":"UNISIG ERTMS\/ETCS RBC-RBC Safe Communication Interface Subset-098 (2012)"},{"key":"e_1_3_2_12_2","unstructured":"UNISIG UNISIG ERTMS\/ETCS - Euroradio FIS Subset 037 (2016)"},{"key":"e_1_3_2_13_2","unstructured":"Joan Daemen and Vincent Rijmen. AES proposal: Rijndael. 1999."},{"key":"e_1_3_2_14_2","article-title":"The AES-CMAC algorithm","volume":"4493","author":"Song Junhyuk","year":"2006","unstructured":"Junhyuk Song et al. The AES-CMAC algorithm. RFC 4493, June, 2006.","journal-title":"RFC"},{"key":"e_1_3_2_15_2","unstructured":"RFI \u2013 Worker Dashboard RFI DTCDNSSS SR IS 14 000 C (07\/2013)."},{"issue":"5","key":"e_1_3_2_16_2","doi-asserted-by":"crossref","first-page":"545","DOI":"10.1016\/j.ress.2010.12.003","article-title":"Modeling safety instrumented systems with MooN voting architectures addressing system reconfiguration for testing","volume":"96","author":"Torres-Echeverr\u00eda Alejandro Carlos","year":"2011","unstructured":"Alejandro Carlos, Torres-Echeverr\u00eda, Sebasti\u00e1n Martorell, and H. A. Thompson. 2011. Modeling safety instrumented systems with MooN voting architectures addressing system reconfiguration for testing. Reliability Engineering & System Safety 96, 5 (2011), 545\u2013563.","journal-title":"Reliability Engineering & System Safety"},{"key":"e_1_3_2_17_2","volume-title":"Proc. 4th ICSE Workshop on Component-Based Software Engineering: Component Certification and System Prediction","author":"Popov P.","year":"2001","unstructured":"P. Popov, L. Strigini, S. Riddle, and A. Romanovsky. 2001. Protective wrapping of OTS components. In Proc. 4th ICSE Workshop on Component-Based Software Engineering: Component Certification and System Prediction, Toronto."},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2007.70210"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/EDCC-7.2008.26"},{"key":"e_1_3_2_20_2","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/RELDIS.1990.93957","volume-title":"Proceedings Ninth Symposium on Reliable Distributed Systems","author":"Di Giandomenico F.","year":"1990","unstructured":"F. Di Giandomenico and L. Strigini. 1990. Adjudicators for diverse-redundant components. In Proceedings Ninth Symposium on Reliable Distributed Systems. IEEE, 114\u2013123."},{"key":"e_1_3_2_21_2","unstructured":"RFI Specifica dei Requisiti del Terminale Operatore (TO) codifica RFI DTC STS SR SR SS40 001 A 2013."},{"key":"e_1_3_2_22_2","unstructured":"CEI EN50129 Railway applications - Communication signalling and processing systems - Safety related electronic systems for signalling. (2004)."},{"issue":"1","key":"e_1_3_2_23_2","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1109\/TII.2016.2610185","article-title":"Unified functional safety assessment of industrial automation systems","volume":"13","author":"Bhatti Zeeshan E.","year":"2016","unstructured":"Zeeshan E. Bhatti, Partha S. Roop, and Roopak Sinha. 2016. Unified functional safety assessment of industrial automation systems. IEEE Transactions on Industrial Informatics 13, 1 (2016), 17\u201326.","journal-title":"IEEE Transactions on Industrial Informatics"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIE.2017.2674610"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3300179"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ress.2017.05.030"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3422369"},{"key":"e_1_3_2_28_2","doi-asserted-by":"crossref","unstructured":"Richard Bloomfield. 2006. Fundamentals of European rail traffic management system-ERTMS. (2006): 165\u2013184.","DOI":"10.1049\/ic.2006.0684"},{"key":"e_1_3_2_29_2","article-title":"Design and implementation of real-time wearable devices for a safety-critical track warning system","author":"Ceccarelli Andrea","year":"2012","unstructured":"Andrea Ceccarelli et al. 2012. Design and implementation of real-time wearable devices for a safety-critical track warning system. High-Assurance Systems Engineering (HASE), 14th Symp. on. IEEE.","journal-title":"High-Assurance Systems Engineering (HASE), 14th Symp. on"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.3390\/s140509153"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1016\/0950-5849(90)90100-6"},{"key":"e_1_3_2_32_2","volume-title":"Digital Watermarking","author":"Katzenbeisser S.","year":"2000","unstructured":"S. Katzenbeisser and F. A. P. Petitcolas. 2000. Digital Watermarking. Artech House, London."},{"key":"e_1_3_2_33_2","unstructured":"Exida Consulting LLC C\/C++ Coding Standard Recommendations for IEC 61508 Version V1 Revision R2 2011."},{"key":"e_1_3_2_34_2","unstructured":"Polyspace static analysis tool MATLAB (product description website) https:\/\/it.mathworks.com\/products\/polyspace.html."},{"issue":"1","key":"e_1_3_2_35_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3140240","article-title":"Improve the localization dependability for cyber-physical applications","volume":"3","author":"Wang T.","year":"2018","unstructured":"T. Wang, W. Wang, A. Liu, S. Cai, and J. Cao. 2018. Improve the localization dependability for cyber-physical applications. ACM Transactions on Cyber-Physical Systems 3, 1 (2018), 1\u201321.","journal-title":"ACM Transactions on Cyber-Physical Systems"},{"key":"e_1_3_2_36_2","unstructured":"Jill Britton. (PERFORCE) - Programming Research Which Software Quality Metrics Matter? Online at https:\/\/www.perforce.com\/resources\/qac\/which-software-quality-metrics-matter. Accessed 11\/7\/2023."},{"key":"e_1_3_2_37_2","unstructured":"Andy Greenberg. 2013. Hackers Reveal Nasty New Car Attacks-With Me Behind the Wheel (Video - online). https:\/\/bit.ly\/3lWRAIN."},{"issue":"1","key":"e_1_3_2_38_2","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1007\/s12198-019-00201-2","article-title":"Major incidents that shaped aviation security","volume":"12","author":"Klenka Michal","year":"2019","unstructured":"Michal Klenka. Major incidents that shaped aviation security. Journal of Transportation Security 12. 1-2 (2019), 39\u201356.","journal-title":"Journal of Transportation Security"},{"key":"e_1_3_2_39_2","unstructured":"Deutsche Bahn attacked by Wannacry (online) https:\/\/www.railtech.com\/digitalisation\/2017\/12\/11\/wannacry-virus-was-wake-up-call-for-railway-industry\/."},{"key":"e_1_3_2_40_2","unstructured":"Real Time Engineers Limited 2009 FreeRTOS reference manual: API functions and configuration options"},{"issue":"1","key":"e_1_3_2_41_2","first-page":"1","article-title":"NDN-GSM-R: A novel high-speed railway communication system via named data networking","volume":"2016","author":"Li Zhuo","year":"2016","unstructured":"Zhuo Li et al. 2016. NDN-GSM-R: A novel high-speed railway communication system via named data networking. EURASIP Journal on Wireless Communications and Networking 2016, 1 (2016), 1\u20135.","journal-title":"EURASIP Journal on Wireless Communications and Networking"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ress.2009.02.014"},{"key":"e_1_3_2_43_2","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/RELDIS.1990.93957","volume-title":"Proceedings Ninth Symposium on Reliable Distributed Systems","author":"Di Giandomenico F.","year":"1990","unstructured":"F. Di Giandomenico and L. Strigini. 1990. Adjudicators for diverse-redundant components. In Proceedings Ninth Symposium on Reliable Distributed Systems. IEEE, 114\u2013123."},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/26.103043"},{"key":"e_1_3_2_45_2","unstructured":"RFI \u2013 La Rete oggi (online) https:\/\/www.rfi.it\/it\/rete\/la-rete-oggi.html."},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3234513"},{"issue":"1","key":"e_1_3_2_47_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3349584","article-title":"Modeling adversarial physical movement in a railway station: Classification and metrics","volume":"4","author":"Cheh Carmen","year":"2019","unstructured":"Carmen Cheh et al. 2019. Modeling adversarial physical movement in a railway station: Classification and metrics. ACM Transactions on Cyber-Physical Systems 4, 1 (2019), 1\u201325.","journal-title":"ACM Transactions on Cyber-Physical Systems"},{"key":"e_1_3_2_48_2","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1109\/IWCMC.2017.7986268","volume-title":"2017 13th International Wireless Communications and Mobile Computing Conference (IWCMC)","author":"Banerjee S.","year":"2017","unstructured":"S. Banerjee, M. Hempel, and H. Sharif. 2017. A review of workspace challenges and wearable solutions in railroads and construction. In 2017 13th International Wireless Communications and Mobile Computing Conference (IWCMC). IEEE, 91\u201396."},{"key":"e_1_3_2_49_2","unstructured":"Network Rail Urged to Eliminate \u201cVictorian Methods of Protection\u201d (online) https:\/\/rail.nridigital.com\/future_rail_oct19\/getting_on_track_with_safety_for_railway_workers."},{"key":"e_1_3_2_50_2","volume-title":"SPE Middle East Health, Safety, Environment & Sustainable Development Conference and Exhibition","author":"Alam M. M.","year":"2014","unstructured":"M. M. Alam and E. Ben Hamida. 2014. Advances in wearable sensor technology and its applications in mobile workforce's health monitoring and safety management. In SPE Middle East Health, Safety, Environment & Sustainable Development Conference and Exhibition. Society of Petroleum Engineers."},{"key":"e_1_3_2_51_2","first-page":"012012","volume-title":"IOP Conference Series: Materials Science and Engineering","volume":"985","author":"Kliuiev S.","year":"2020","unstructured":"S. Kliuiev, I. Medvediev, and N. Khalipova. 2020. Study of railway traffic safety based on the railway track condition monitoring system. In IOP Conference Series: Materials Science and Engineering. IOP Publishing 985, 1 (2020), 012012."},{"key":"e_1_3_2_52_2","first-page":"517","volume-title":"Proceedings of the Institution of Mechanical Engineers, Part F: Journal of Rail and Rapid Transit","volume":"227","author":"Noorudheen N.","year":"2013","unstructured":"N. Noorudheen, M. McClanachan, Y. Toft, and G. Dell. 2013. Keeping track workers safe: A socio-technical analysis of emerging systems and technology. Proceedings of the Institution of Mechanical Engineers, Part F: Journal of Rail and Rapid Transit 227, 5 (2013), 517\u2013528."},{"key":"e_1_3_2_53_2","doi-asserted-by":"crossref","DOI":"10.1108\/01425450610661234","article-title":"Off the rails: Factors affecting track worker safety in the rail industry","author":"Baldry C.","year":"2006","unstructured":"C. Baldry and J. Ellison. 2006. Off the rails: Factors affecting track worker safety in the rail industry. Employee Relations.","journal-title":"Employee Relations"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1080\/13669870701715550"},{"key":"e_1_3_2_55_2","doi-asserted-by":"crossref","first-page":"638","DOI":"10.1109\/IROS.2013.6696418","volume-title":"2013 IEEE\/RSJ International Conference on Intelligent Robots and Systems","author":"Mosberger R.","year":"2013","unstructured":"R. Mosberger, H. Andreasson, and A. J. Lilienthal. 2013. Multi-human tracking using high-visibility clothing for industrial safety. In 2013 IEEE\/RSJ International Conference on Intelligent Robots and Systems. IEEE, 638\u2013644."}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3607193","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,14]],"date-time":"2023-10-14T12:06:45Z","timestamp":1697285205000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3607193"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,14]]},"references-count":54,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,10,31]]}},"alternative-id":["10.1145\/3607193"],"URL":"https:\/\/doi.org\/10.1145\/3607193","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"value":"2378-962X","type":"print"},{"value":"2378-9638","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,10,14]]},"assertion":[{"value":"2022-08-02","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-06-29","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-10-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}