SUBSET-038 — Off-line Key Management FIS
Legally binding: EU law, a TSI-mandated specification or international treaty law.
Issuing body: UNISIG / ERA · Version: v4.0.0 · Published: 2023-07-10
ETCS baseline: CCS TSI 2023 Annex A: v4.0.0 (ETCS Baseline 4)
Link verified August 5, 2026
Scope
The Functional Interface Specification for off-line key management: how the cryptographic keys (KMAC) that authenticate EuroRadio communication between ETCS on-boards and radio block centres are generated, distributed, installed, updated and revoked across entities.
ETCS Level 2 safety rests on authenticated radio sessions, and authenticated sessions rest on key management: SUBSET-038 specifies the off-line processes and interfaces by which Key Management Centres issue and distribute the triple-DES KMAC keys, how keys are allocated to specific on-board/RBC relationships, their validity handling, and the operational procedures for installation and revocation. It pairs with SUBSET-114, which standardises the KMC-to-ETCS-entity interface, and both are mandatory at v4.0.0 under Annex A of the 2023 CCS TSI. Every ETCS L2 deployment — and every cross-border service crossing KMC domains — operates these processes; national KMCs, infrastructure managers, railway undertakings and on-board suppliers are the daily users, and the domain is evolving as FRMCS and on-line key management mature.
Related documents
- Cited by:
- TSI-CCS

