ITSO An overview March 2010.

Slides:



Advertisements
Similar presentations
Chapter 10 Encryption: A Matter of Trust. Awad –Electronic Commerce 1/e © 2002 Prentice Hall 2 OBJECTIVES What is Encryption? Basic Cryptographic Algorithm.
Advertisements

Four ways to give electronically 1. Making it easy for givers to give! 2.
ASYCUDA Overview … a summary of the objectives of ASYCUDA implementation projects and features of the software for the Customs computer system.
1 RFID and Telecommunication Services 25th May 2004 DATA BASE forum RFID and Your Phone Sebastian Nyström Nokia Ventures Organization.
Copyright © 2005 – Clickshare Service Corp. All rights reserved. Payment Aggregation & Affinity Management Clickshare for the Media Industry For more information.
CONFIDENTIAL DIGITAL WATERMARKING ALLIANCE. CONFIDENTIAL DIGITAL WATERMARKING ALLIANCE 2 Digital Watermarking Alliance Charter The Digital Watermarking.
Introduction Lesson 1 Microsoft Office 2010 and the Internet
SYNAPSE I.S. Ticket Sales & Management. SYNAPSE I.S. What is Olympia ? Olympia is NOT just another internet sales service. Olympia is a tool for the ticketing.
PaperCut MF Reseller Resource Material An Introduction to PaperCut MF.
1 Java Card Technology Prepared by:Ali Toyserkani Adopted from: Introduction to Java Card Technology C. Enrique Ortiz.
Eligibility, Benefits, and Pre-certifications
Estonian ICT Reducing administrative burden Indrek Vimberg.
Gareth Ellis Senior Solutions Consultant Session 5a Key and PIN Management.
Customer First : Strategic Context and Opportunities Rory Mair.
Multi-Application in Smart Card-based Devices Christophe Colas, Chief Software Architect August 2002.
©Tariff Check Services Ltd Questions ??? Are you in control of your mobile phone usage and expenditure? Are you getting the best rates from your.
Ecosystem Scenarios for Cloud-based NFC Payments
ITSO An Introduction.
Copyright Hub Software Engineering Ltd 2010All rights reserved Hub Workflow Product Overview.
SUOMEN PANKKI | FINLANDS BANK | BANK OF FINLAND e-SEPA - Where Do These Initiatives Stand? 21 March 2011 Harry Leinonen Harry Leinonen The views.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
E+e+ Presentation to the Smartcard Networking Forum 11 th April 2006 e-purse case study Jayne Ward Bracknell Forest Borough Council
University Multi-application Scheme using Desfire Contactless Cards Smartran Ltd Kevin Farquharson, Director Smartran Ltd
Scotland – Concessionary Travel and Smartcards Gordon Hanning Head of Concessionary Travel & Integrated Ticketing.
International Card Systems Skopje, Macedonia
Smart Ticketing: Reducing the barriers to Public Transport John Verity, Chief Advisor, ITSO Limited Chair, Smart Ticketing Alliance.
Southampton SmartCities scheme Peter Verrept
FIT3105 Smart card based authentication and identity management Lecture 4.
Creating a Secured and Trusted Information Sphere in Different Markets Giuseppe Contino.
Introduction to SAP R/3.
Credit Card And Prepaid Process Edward M. Kwang President.
“Electronic Payment System”
Riga’s e-Ticketing System
Philip is a subject matter expert in Accenture’s Payment practice with more than 30 years experience across payments, transaction processing, networks,
Introduction to ITSO April Introduction to ITSO  ITSO is an open Specification which belongs to the Crown. ITSO Limited is the guardian of this.
© SmartCard Networking Forum. NSCP Smart Card Scheme Design Workshop Introductory Session Prepared by Smartran Ltd Version 0.8 (08/04/05)
InterSwyft Technology presentation. Introduction InterSwyft brings secured encrypted transmission of SMS messages for internal and external devices such.
European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group.
Ministère de l'Écologie, du Développement durable, des Transports et du Logement Simplifying public transportation through.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
Smartcard Evaluation TM8104 – IT Security Evaluation Linda Ariani Gunawan.
© SmartCard Networking Forum 1 Introduction to Smartcards Workshop Prepared by Smartran Ltd for SCNF Version 1.3 (17/09/07)
US Workshop Sep 04 CEN TC 278 WG3 SG5 Interoperable Fare Management System Architecture David Sentinella Department for Transport David Sentinella Department.
Copyright © 2011 Accenture All Rights Reserved. Accenture, its logo, and High Performance Delivered are trademarks of Accenture. 1 January 18, 2011 The.
1 7 th CACR Information Workshop Vulnerabilities of Multi- Application Systems April 25, 2001 MAXIMUS.
Modernising Government Conference 29 October 2004 Mike Eastham Head of Technology ITSO Ltd.
The National Smartcard Project and the Citizen Experience Oliver Ferguson Workpackage Project Manager.
Bolton SMART Wendy Reddington – Bolton Council Adam Smith – Squidcard.
Smart Card Networking Forum English National Concessionary Travel Scheme 2008 Peter Laslett National Pass Delivery Team Concessionary Travel Division Cambridge.
3rd Forum for Sustainable Mobility and Metropolitan Development
Lewis Jones Business Transformation Through Technology.
How to Deliver a Citizen Card Scheme Ian Goodfellow Fares & Pricing Project Leader Metro RFID 30 September 2009.
Olive – The Realtime Integrated Payroll & HR Software.
The National Smartcard Project Vaughan Cooksey WP 10 & 11 Project Manager IDeA e-Champions 22nd January.
© SmartCard Networking Forum The LASSeO workshop Geoff Doggett & Mick Davies.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
Jason Kuo APSCA October 29, 2010 Convergence and cross usage of secure elements for mobile PKI and secure mobile contactless services.
RSPS3002 Mostafa Gulam Head of Technology ITSO Commercial Advisory Group 13 Nov 2013.
AGENDA Introduction Kind of information smart card contain
Problems – Technical Requirements
Definition: Pioneer; to take the lead in, be first to introduce.
Nils ZEINO-MAHMALAT Head of e-ticketing
EMV® 3-D Secure - High Level Overview
XinFin Blockchain for global Trade and Finance
NEW PRODUCT INTRODUCTION CONEKT™ Mobile Smartphone Access Control Identification Solution June 2018.
Conduent Fare Collection
E-Lock ProSigner ProSigner means “Professional Signer” signifying the software that can apply legally enforceable Advanced electronic signatures to electronic.
K!M SAA LOGICAL SECURITY Strong Adaptive Authentication
CEN/ISSS Workshop eURI
Presentation transcript:

ITSO An overview March 2010

What is ITSO? ITSO is the UK Open Standard for integrated and interoperable smart ticketing, owned under Crown Copyright by the UK Government. The standard is supported and maintained by ITSO Ltd, a non-profit distributing organisation licensed by the UK Department for Transport. ITSO Ltd is owned by member organisations including: Central government, regional and local authorities; Bus operators; Train companies; and Suppliers to the industry.

The ITSO Interoperable Fare Management environment consists of: The ITSO Specification: an Open Specification available for downloading off the internet. Version 2.1.4 of the ITSO Specification was published in late February 2010 An ITSO Security Access Module (the ISAM) that resides in every Point of Service. The ISAM securely holds the keys to sign all transactions and verifies authenticity The ITSO Security Management Service (the ISMS) which generates, stores and securely distributes keys The method for showing Equipment Compliance The ‘Business Rules’ for inter-operability and Registration

ITSO supports the full interoperability of Customer Media between schemes and the compatibility of Equipment and Software. It is currently the responsibility of our suppliers and operators to: Provide other equipment (i.e. Ticketing posts, readers and gate machines) Process or hold Transaction Data Process or hold Customer Data (including usage) Handle payment or settlement

The ITSO Specification states . . . . . . that all Data Records must be: Free read Protected by a 3-DES seal that is diversified by a number of factors including: Date-time stamp ISAM identity Media identity Value Transaction number Thus ensuring personal data is protected and secure.

Transaction speed is key ITSO Transactions by Points of Service are benchmarked for both “simple” and “complex” transactions: Java, DESfire and Calypso: 300mSec max Low Memory media: 200mSec max For off-line bus and hand held equipment, an allowance of 2x and 3x the maximum is made Speeds achieved through the rigorous testing and compliance processes are recorded on the equipment Certificate of Compliance

The ITSO Specification has the following parts: Part 0: General Introduction Part 1: Terminology, References Part 2: Customer Media (CM) Part 3: Point of Service Terminals (POSTs) Part 4: Host Operator Processing Systems (HOPS) including Asset Management (AMS) Part 5: Data Record Definitions on Customer Media Part 6: Message Data Part 7: Security Sub-system Part 8: Security Management System Part 9: Communications Part 10: Customer Media Types

International Standards, the EU and ITSO ITSO complies with and supports the development of the following International Standards: Media: ISO/IEC 14443 File Structure: ISO/IEC 7816 Architecture: EN ISO 24014-1 (IFM) Applications: EN 15320 (IOPTA) Data Elements: EN 1545 ISAM Security: ISO 15408 (Protection Profile PP9911) And in doing so anticipates compliance with the proposed EU-IFM Specification

ITSO supports the following Customer Media: CMD1: Mifare® Classic standard 1K CMD2: Generic Micro-processor (Java) CMD3: Mifare® Classic standard 4K CMD4: Mifare® ultra light CMD5: Innovision Jewel – 0301/70 CMD7: Mifare® DESfire CMD8: Calypso Of these, the Mifare Classic family are being phased out, and ITSO is looking to further enhance the CMD2 definition to embrace Global Platform and comply with the EU-IFM definition of a Secure Element.

SE Unique Identifier (eg MCRN) The ITSO solution supports Multi-Application use, can exist alongside EMV Payment or NFC Applications and has its own ITSO Stored Value proposition Secure Element (SE) Issuer SE Unique Identifier (eg MCRN) Secure Element layer (eg smartcard, USB key, NFC phone etc) Directory ITSO Shell Environment EMV ??? ITSO Shell (Application) Application layer Directory ID STR Tickets ??? Credit/ Debit Product layer IPE layer

ITSO supports the following Product Types: TYP0: Private Application TYP2: Stored Value TYP3,17: Loyalty TYP4,5: Charge to Account TYP14,16: Entitlement and ID TYP22,23,24: Pre-defined Tickets TYP25: Voucher TYP26: Tolling TYP27,28,29: Space-saving Tickets TYP34: Transient Ticket

The ITSO TYP0, Private Application, allows Operators to use the ITSO Security to protect a local Application such as Library Card, or a Leisure or Event Ticket. The ITSO Stored Value Product supports: Different currencies and currency change Multiple Stored Value Products on same Media (including EMV) Auto top-up Journey legs and cumulative fare Receipt printing (when available) ITSO Products are suitable for remote downloading using Secure Messaging.

. Current ITSO Implementations cover*: 20,000+ Points of Service (ISAMs) connected into the Security System; more than 12 million ITSO Customer Media covering all of Scotland and Wales, and 23 PTA in England (on both, bus and rail, for concessionary and commercial ticketing. These figures are expected to double over the next 5 years in order to meet the UK Government Smart and Integrated Ticketing strategy. These developments will include ITSO operating in Greater London alongside TfL’s Oyster product before the 2012 Olympics. ITSO is currently being considered by a number of other countries. * As of March 2010 .

For more information: E-mail info@itso.org.uk Or call ITSO on +44 (0)121 634 3700 Or visit www.itso.org.uk