The hardware

Fourteen boxes. Zero exotic parts.

The network is the product — so every box is deliberately commodity, rail-certified where it must be, and identical across railways. Two radio SKUs cover the world's FRMCS spectrum; everything else is the same hardware from Secunderabad to Stockholm.

The radio

Two bands. One radio family.

FRMCS spectrum worldwide converges on a short list. We build exactly two RU SKUs against it — no per-customer radio zoo. The DU, the core and every application are identical in both variants; only the RF front-end changes.

BandRangeDuplexWhere it's requiredFRMCS.ai
n1011900–1910 MHzTDDEurope — the UIC / ECC (20)02 RMR FRMCS band — and markets following it. The primary FRMCS band worldwide; capacity-leaningSKU V1 — shipping design
n28700 MHzFDD (TDD-capable design)India's railway 700 MHz allocation and other low-band markets. Reach-leaning: ~8–10 km rural sites, deep cutting and tunnel penetrationSKU V2 — shipping design
n100900 MHz (RMR)FDDEuropean GSM-R refarm band alongside n101Roadmap — same DU, core and apps; RU front-end only
NTN bandsL/S/Ka via partnersSatellite tier everywherePartner constellation terminals — not an RU (see orbital tier)

4T4R · 4×40 W

One default radio configuration: four transmit, four receive, 40 W per branch — sized for along-track sectors, MIMO for capacity, headroom for high-speed Doppler.

Default RU · both SKUs

A carve-out is enough

5–10 MHz of railway spectrum carries every FRMCS traffic class — voice, signalling and telemetry are small and deterministic. CCTV bulk rides satellite and station Wi-Fi offload.

QoS plan · 3GPP 5QI 65/69/82–85

Open at the PHY

The O-DU speaks nFAPI (SCF 222/225) at the PHY boundary and the full O-RAN interface suite above it — pair our DU with any compliant L1/RU, or take the reference pairing.

O-RAN · SCF 222/225 nFAPI
The radio site

One cabinet, every corridor.

A tower site is a fixed bill of materials — identical for both band variants except the RU. Masts are standard 30 m lattice or existing structures; tunnels take leaky feeder or low-power repeaters fed from the portals.

Every site keeps its own time: GNSS-disciplined PTP with at least four hours of holdover, engineered per corridor for TDD phase discipline — not assumed.

  • O-RU: 4T4R 4×40 W, n101 or n28 SKU.
  • DU: 1U fanless x86 — Go control plane, C data path.
  • Timing: GNSS + PTP grandmaster (G.8275.1), OCXO holdover ≥ 4 h.
  • Transport: cell-site router, fibre preferred, microwave fallback, dual-homed where the line allows.
  • Antennas: along-track two-lobe sector panels, 4-port MIMO.
  • Power & housing: AC + 8 h battery (solar-hybrid option), IP55 cabinet, EN 50121-4 EMC, −33…+55 °C.
Compute — cloud to cabinet

Every function at the lowest tier that satisfies it. And no lower.

Vital transport terminates as close to the train as physics demands; learning and history live in the cloud where compute is cheap. That single placement rule shapes the whole estate.

Core cluster

3+ node x86 Kubernetes HA cluster, DPDK NICs for the UPF fast path, PostgreSQL + Valkey storage tiers, FIPS-class HSM pair for KMS/PKI roots, GPU pool for model training. Railway DC, sovereign cloud or hyperscaler — one GitOps release renders to all three.

H1 · control centre / cloud

Station edge

One or two 1U nodes per station: local 5G breakout so ETCS and voice stay regional even if the WAN dies, oneM2M mid-tier, CCTV archive cache, passenger Wi-Fi offload. Loses the cloud, keeps the railway running.

H8 · stations & depots

The moving edge

Every train carries its own compute: the TOBA gateway's NPU runs CCTV analytics, perception fusion and maintenance feature-extraction on board — features go up the radio, never raw video or waveforms.

H5 · on-train NPU
  • Dispatcher positions: hardened workstations with MCX console, PTT panel + headset, group/priority select, REC initiate and receive.
  • Voice/data recorder: legal-grade REC and operational-voice recording, tamper-evident, policy-driven retention.
  • Video wall: decode nodes for on-train and wayside CCTV streams.
  • Incident desk: the Elastic Sky console — dock status, launch authorisation, incident-cell coverage, responder talkgroups.
  • ATC boundary: redundant gateways hand EuroRadio (Subset-037 over IP) to the RBC, interlocking and TMS — which remain vendor-certified vital equipment.
Control centre

Two estates, one room.

Ours is the communication estate: every controller position is just another FRMCS user — same identity, same services — so a backup control centre is configuration, not construction.

The signalling vendor's estate — RBC, interlocking, traffic management — stays certified and untouched. We carry ATC. We never are ATC.

On the train

Rail-certified, cab to last coach.

Everything on board is EN 50155 territory — temperature, shock, vibration and fire-rated (EN 45545). The vital train-control kit (EVC, ATO, TCMS) stays vendor-certified; we present FRMCS transport at the UIC reference points.

UnitSpecification
TOBA gatewayFanless EN 50155 x86, dual PSU, −25…+70 °C; 2× band modems (tower/drone diversity) + NTN modem + passenger APN module; edge NPU; the UIC TOBA multipath session terminates here
Roof antenna setBand MIMO ×2, NTN flat panel, GNSS — crash-rated radomes
Cab radio — on-board edge platformThe cab radio grown into an NVIDIA Jetson Orin edge computer — three jobs in one box: multi-bearer FRMCS gateway (5G primary · Wi-Fi 6/7 depot · Starlink remote, make-before-break failover), perception edge (camera + lidar + radar fused on the GPU), and LoRa IoT aggregation into oneM2M. Driver MCX terminal: PTT, group/priority select, guarded REC switch, DSD pedal tie-in
Crew panelGuard / train-crew position: MCX client, PIS/PA control, door-dispatch comms, REC access
Perception headMulti-modal forward camera head on the cab radio's Orin: high-speed global-shutter (~120 fps) + day/night WDR-IR + LWIR thermal, plus lidar and 77 GHz radar — TensorRT/DeepStream fusion; detections publish as FRMCS catalogue events with the right QoS
Bogie kitAxlebox vibration/temperature nodes, per-car concentrator, gearbox oil sensor — bogie health at the source
Coach LANPer-coach Ethernet backbone, VLAN-segmented: vital / CCTV / PIS+PA / passenger Wi-Fi — never sharing the vital slice; Wi-Fi 6 APs, saloon + cab cameras, PIS displays and PA
In people's hands

Every role, one identity model.

Drivers, guards, shunters, trackworkers, controllers — each is an FRMCS user with a device matched to the job. Same MCX services, same security, different form factor. The reference handheld is deliberately commodity; any 3GPP MCX-capable device with our client can substitute.

RolePrimary deviceWhat it carriesForm factor
DriverCab radioREC, voice, safety-device (DSD), advisory displayFixed in cab, guarded REC switch; handheld fallback off-train
Guard / crewCrew panel + handheldVoice, REC, PIS/PA control, door dispatchHandheld follows the crew through the train
ShunterRugged handheldLink-assured shunting groups, voiceGlove-usable, high-visibility, man-down
TrackworkerHandheld + wearableGeofenced approach warning, lone-worker, voiceWearable: GNSS + man-down IMU + haptic/audible alarm
ControllerFixed OCC positionAll voice/REC arbitration, incident consoleWorkstation-class
Incident commanderIncident kitEmergency talkgroups, drone-cell status, videoRuggedised case, pre-staged at dock stations and OCC
MaintenanceTablet + handheldTCMS/bogie dashboards, work orders, voiceDepot Wi-Fi + FRMCS dual-path
Elastic Sky hardware

A cell site that fits on a trailer.

The disaster-recovery and rapid-deployment tier is two units: a dock station and a tethered drone. Docks are fixed at strategic points along the corridor, plus a road-trailer pool that can drive to any incident.

The dock's controller can execute a launch autonomously — the one site class designed to act even when the network around it is gone.

  • Dock station: shelter, winch + tether management, charger, SBC controller, optional NTN backhaul for docks beyond tower coverage.
  • Airframe: tethered multirotor, 80–120 m operating height, rain/wind envelope per certification.
  • Payload: micro-RU with fronthaul over the tether, edge compute, perception pod (camera/radar/lidar).
  • Tether: HV power up, fibre down — unlimited endurance, aircraft physically secured over railway land.
  • Reserve power: on-board battery for controlled descent on tether loss.
Wayside IoT fleet

Cheap, battery-frugal, everywhere.

Beneath the 5G network sits the sensing fabric: ESP32-class nodes on LoRa and Wi-Fi HaLow, IP67, years on battery or solar — reporting to a Raspberry Pi-class station gateway. Nothing on this layer is vital; everything on it is replaceable in minutes with a screwdriver.

Node familyRadioPowerMeasures
Track monitorLoRaBattery / solarVibration RMS · peak · dominant frequency, rail temperature, strain, tilt, train-pass events
Level crossingLoRaLine + batteryBarrier state, approach signal, audio alarm, motor current, vehicle count
Signal lightLoRaLineAspect, lamp current / voltage / temperature, burn hours, fault flag
Axle counterLoRaLineSection occupancy, axle count, last-train speed / direction / weight
Catenary monitorHaLowLine (25 kV env.)Voltage, current, wire tension, contact wear, arcing, icing
Bridge strainLoRaBattery / solar3× strain gauges, tilt, displacement, deck temperature, train load
Predictive maintenanceHaLowLine (depot)Bearing temperatures, gearbox oil, wheel-flat signature, health score

Station gateway

Raspberry Pi-class SBC, DIN-rail IP54, PoE or 12–48 V DC. Three receivers: LoRa (SX1276) for km-reach battery nodes, Wi-Fi HaLow for waveform-class payloads, HTTP for the bench.

H9 · oneM2M uplink

The radio rule

LoRa for tiny periodic payloads at kilometre reach on batteries; HaLow where the payload is a waveform — catenary electricals, vibration features — and line power exists.

LoRa · 802.11ah HaLow

Wayside guardians

The perception exception: camera (+ lidar at high-risk sites) with an edge NPU at crossings, portals, platform ends and slip zones. Detections — not video — ride the FRMCS network; these are 5G devices, not LoRa nodes.

H12 · anti-collision tier
Certified where it counts

The standards each box answers to.

WherePowerBackupEnvironment / certification
Core clusterDC feed, dual PDUUPS + generatorData-centre class; HSM FIPS 140-3
Radio siteAC8 h battery, solar-hybrid optionIP55 cabinet, EN 50121-4 EMC, −33…+55 °C
Station edgeAC/DC4 h batteryETSI EN 300 019 indoor/cabinet
Dock + droneLineside AC / tether HVLaunch-and-hold battery; descent reserveOutdoor shelter, self-heating; airframe certification envelope
On-train estateTrain battery busTrain-nativeEN 50155 (temp/shock/vibration), EN 45545 fire
Handhelds / wearablesBatteryShift-length + hot-swapIP67, drop-rated, glove UI
IoT nodesBattery / solarYears-scale duty cycleIP67, lineside

Simulator = hardware contract. Every field device has a simulator that emits the exact wire format of the real firmware — so software never waits for hardware, and a new corridor is tested end-to-end before the first cabinet ships.

Want the full bill of materials, spec by spec?

The design document goes one level deeper — every unit, every interface, every certification target, from the RU front-end to the axlebox sensor.