Top Banner
Role Based Access Controls Applied to Electronic Toll Collection November 2016
29

Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Mar 31, 2018

Download

Documents

trinhcong
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Role Based Access Controls

Applied to Electronic Toll

Collection

November 2016

Page 2: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

01/ Presentation main goals

02/ Toll Collection Systems

03/ Transactions and data access

04/ External requests for information

05/ Next Steps

Index

Page 3: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Presentation

main goals

01/ Presentation main goals

Page 4: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

A/ The Tolling Systems and its security

framework

B/ Management of accesses to the toll

information

C/ Assurance of the principle of the least

privilege in information access

Role Based Access Controls Applied to Electronic

Toll Collection in Ascendi

01/ Presentation Main Goals

Page 5: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

02/ Toll Collection Systems

Toll Collection Systems

Page 6: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Significant experience and know-how

in toll collection

AET (MLFF)

Toll collection systems enabling

traffic free flow

Traditional

Toll Collection

Open or closed systems,

manual and electronic

02/ Toll Collection Systems

Page 7: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

6 contracts under operation

(130 tolling points)

Operation under independent contracts

between Ascendi O&M and Infraestruturas

de Portugal (Portuguese Road Agency)

Costa de Prata, Grande Porto, Beiras

Litoral e Alta, Interior Norte, Pinhal Interior,

Tunel do Marão

AET | All Electronic Tolling

02/ Toll Collection Systems

Page 8: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Norte and Grande Lisboa Concessions

21 Toll plazas (closed system)

3 Toll plazas (open system)

134 Manual lanes

83 Electronic single lanes free flow

Traditional Toll Collection

02/ Toll Collection Systems

Page 9: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

02/ Toll Collection Systems

https://www.youtube.com/watch?v=6Kiwrdyy_ts

Page 10: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Systems - Architecture

02/ Toll Collection Systems

Page 11: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

OPERATIONAL BACK-OFFICE (OBO)

COMMERCIAL BACK-OFFICE (CBO)

ROAD SIDE EQUIPMENT (RSE)

Integrates all tolling operations

• Account Management

• Contact and Walk-in centre

• CRM

• Billing and notice issuing

• Dunning management

• Payment processing

• External Interface (links)

Integrates all tolling operations

• Prepared for technologies from

different vendors (DSRC, RFID)

• Transaction validation

• Second level OCR

• Image review

• Trip aggregation engine

• Price calculation

• Mobile enforcement BO

02/ Toll Collection Systems

Systems - Architecture

•Detection of the passage of thevehicle

•Classification of vehicle usingits volumetry figures (height, width, lenght, trail)

•Read of OBU

•Capture of front, rear andcontext images

•Automatic License PlateRecognision

•Data correlation of the varioussubsystems

Page 12: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

NATIONAL VEHICLESDirect Collection (without

surcharges):

• Fully electronic payment through

OBU issuer (debit card)

• Pre-payment with client

identification

• Anonymous pre-payment supported

Post Payment Collection (with

surcharges):

• Anonymous post-payment using

license plate - available for payment at

postal offices, Payshop network and

internet.

FOREIGNVEHICLES• Interoperability with Spain

(vehicles equipped with OBU)

• “Easy-Toll” system (automatic

registration at the borders,

using credit card account)

• TollService (pre-paid title for

light vehicles for 3 days or pre-

-determined trips)

• TollCard (“on the shelf” pre paid

card, activated by SMS)

• Temporary Via Verde tag

(rent-a-tag)

ENFORCED COLLECTION• Enforced Collection for non

payment

• Mobile enforcement

• Tax authority (with fines

treated as fiscal offense)

• Internet

AET | Payment Methods (Portugal)

02/ Toll Collection Systems

Page 13: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

European

Standards

• EN 15509 – Electronic Free

Collection – Interoperability

Application profile for DSCR

• Security features and mechanisms

based on the general security

framework defined in 7.1.4 in EN

ISO 14906:2004.

• Image Security: attribute

adaptations according to CEN/TS

16439 (EFC - Security Framework).

• Monitored datacenters

(heat, fire, power, air

conditioning, cctv)

• Restricted physical

Access

• Network segmentation

• Public Key

Infrastructure (PKI),

FTPS, HTTPS for

webmail, SSL VPN,

Ipsec Tunnel Private-to-

private Network

Network Security

Protocols

Systems - Security Features

Datacenters

02/ Toll Collection Systems

Page 14: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Business Continuity

Systems - Security Features

• Secure Infraestruture - Virtualization and

High Availability for Core Systems

• Centralized enterprise backup and

recovery, disaster recovery and endpoint

data protection

• Disaster Recovery Site for OBO

and CBO;

• Business Continuity Plan;

Organization

• Security policies and procedures

• Skilled Technical resources

• Non-disclosure agreement concerning

personal, proprietary information and

good practices using IT systems

02/ Toll Collection Systems

Page 15: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

DIMENSION

• Largest Europeanprivate operator of amulti-vehicle categoryAET (MLFF);

• High speedmotorways - DSRC

Technology;

• More than 99,99%

system availability;

• 99,80% of vehicles

detection (no speed

restriction);

• more than 96% of

ALPR (multiple

libraries);

FEASIBILITY

• Electronic Tollingusing OBU

identification; or

• Video Tolling, using

ALPR in association

with 2º level OCR

engines;

OPERATIONALFLEXIBILITY

• Unitary transactions ofa journey aggregated

into a single

transaction, where:

o Customer able to

check travelled journey;

o Optimized transaction

costs;

TRANSACTIONAGGREGATION

AET | Main Features (Portugal)

02/ Toll Collection Systems

Page 16: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

TransactionsandData

Access

03/ Transactions and data access

Page 17: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

700K Transactions

processed daily

Transaction mode: 80%

ETC, 11% VTC, 9%

Manual

Facts and Figures

1.7M customer

accounts managed

5.2M km (aggregate

distance travelled by all

users) charged per day

Invoices/notices:

42.5k processed per

week

More than 160 users

of the systems

03/ Transactions and data access

> 500K images

per day

Page 18: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Customer Care Organization

Technical team

• 6 Supervision areas

• 10 Operational teams

Macro-areas

03/ Transactions and data access

Coordination &

Technical Support

Invoice-Manual

Validation

& QC

Document

Management

& Receivables

Customer

Care (walk-in

+ call center)

Customer

Care (written +

online)

Litigation &

Corporate

• Invoicing

• Clients and Operations

Page 20: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Access Profiles are defined per application module

Permission Matrix

• By system

• Read Only / Read & Write

03/ Transactions and data access

Page 21: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Segregation by function

• Overall containment of information access

• Rigid boundaries

• Team defined access

• Different degrees of access inside the boundaries

• Almost atomic granularity of permissions

Segregated by Area of responsibility

Access Profiles are defined per application module

03/ Transactions and data access

Page 22: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

All requests for change refer to

this matrix AND ALL PREVIOUS

VERSIONS ARE AUDITABLE

Versioning

03/ Transactions and data access

Page 23: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Internet Access

• Access controlled

through the use of white-

lists

• Internet access only

allowed via proxy

• Active Directory user

groups determine the

Internet access

Email

• Email is only allowed

internally for Manual

Toll-Operator team

• All Client interaction

teams use an unified

account (mono account

per channel)

• All email sent to Clients

by the unified accounts

is duplicated to a read-

only mailbox

(traceability)

Workstations \ Mobile Devices

• Predefined software image for

workstations

• Standard GPO enforced restrictions

on USB drives and other media

• Locked down baseline according to

Center for Internet Security

benchmarks

(https://www.cisecurity.org/)

• Firewall rules restrict access to local

addresses only (http proxy is local)

• Software update via SCCM (security,

critical, antivirus and malware )

Workstation | Restrictions and controls

Data Loss Prevention

03/ Transactions and data access

Page 24: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Requestsfor

Information

04/ External requests for Information

Page 25: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Available information

• Client must show personal identification andvehicles documentation

• Data is verified with historic ownership data

Client requests

By Clients

• Non paid transactions

• Travel information

• Photographic evidence – license plate ONLY

Requests for Information

04/ External requests for Information

Page 26: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

By Public Authorities

Request for Information

• Requires criminal proceeding (not civil)

• Requires an associated court order

• Non paid transactions

• Travel information

• Photographic evidence – license plate ONLY

04/ External requests for Information

Request by legal enforcement Entities

Available information

Page 27: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Next Steps

05/ Next Steps

Page 28: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

05/ Next Steps

Next Steps and Challenges

Security Audits

New data protection rules

Perimeter reinforcement

Revise polices, procedures

and rules

Evaluate CERT Team

Page 29: Role Based Access Controls Applied to Electronic Toll ...Role Based Access Controls Applied to Electronic ... (DSRC, RFID) • Transaction ... • Secure Infraestruture - Virtualization

Thank You!

Questions ?www.ascendi.pt