Electronic fee collection - Secure monitoring for autonomous toll systems - Part 2: Trusted recorder

This document defines the requirements for the secure application module (SAM) used in the secure monitoring compliance checking concept. It specifies two different configurations of a SAM:
-   trusted recorder, for use inside an OBE;
-   verification SAM, for use in other EFC system entities.
This document describes
-   terms and definitions used to describe the two Secure Application Module configurations;
-   operation of the two Secure Application Modules in the secure monitoring compliance checking concept;
-   functional requirements for the two Secure Application Modules configurations, including a classification of different security levels;
-   the interface, by means of transactions, messages and data elements, between an OBE or front end and the trusted recorder;
-   requirements on basic security primitives and key management procedures to support Secure Monitoring using a trusted recorder.
This document is consistent with the EFC architecture as defined in EN ISO 17573-1 and the derived suite of standards and Technical Specifications, especially CEN/TS 16702-1 and CEN ISO/TS 19299.
The following is outside the scope of this document:
-   The life cycle of a Secure Application Module and the way in which this is managed;
-   The interface commands needed to get a Secure Application Module in an operational state;
-   The interface definition of the verification SAM;
-   Definition of a hardware platform for the implementation of a Secure Application Module.

Elektronische Gebührenerhebung - Sichere Überwachung von autonomen Mautsystemen - Teil 2: Zuverlässige Datenaufzeichnung

Perception de télépéage - Surveillance sécurisée pour systèmes autonomes de péage - Partie 2 : Enregistreur fiabilisé

Elektronsko pobiranje pristojbin - Varnostno spremljanje avtonomnih cestninskih sistemov - 2. del: Zaupanja vreden snemalnik

Ta dokument določa zahteve za modul varnega dostopa (SAM), ki se uporablja pri konceptu preverjanja skladnosti varnostnega spremljanja. Določa dve različni konfiguraciji modula varnega dostopa:
– zaupanja vreden snemalnik: za uporabo v opremi v vozilu (OBE);
– modul varnega dostopa za preverjanje: za uporabo v drugih entitetah sistema za elektronsko pobiranje pristojbin (EFC).
Ta dokument podaja:
– izraze in definicije, ki so uporabljeni za opis teh dveh konfiguracij modula varnega dostopa;
– delovanje teh dveh modulov varnega dostopa v konceptu preverjanja skladnosti varnostnega spremljanja;
– funkcionalne zahteve za ti dve konfiguraciji modula varnega dostopa, vključno z razvrstitvijo različnih varnostnih ravni;
– vmesnik, prek transakcij, sporočil in podatkovnih elementov, med opremo v vozilu ali čelnim delom in zaupanja vrednim snemalnikom;
– zahteve glede osnovnih varnostnih primitivov in ključnih postopkov upravljanja kot podpora varnostnemu spremljanju z uporabo zaupanja vrednega snemalnika.
Ta dokument je v skladu z arhitekturo za elektronsko pobiranje pristojbin, kot je določena s standardom FprEN ISO 17573-1 in skupino izpeljanih standardov in tehničnih specifikacij, še posebej FprCEN/TS 16702-1 in CEN ISO/TS 19299.
Naslednje ne spada na področje uporabe tega dokumenta:
– življenjska doba modula varnega dostopa in način, na katerega se to upravlja;
– ukazi vmesnika, ki so potrebni za zagon modula varnega dostopa;
– definicija vmesnika modula varnega dostopa za preverjanje;
– definicija platforme za strojno opremo za izvajanje modula varnega dostopa

General Information

Publication Date
Current Stage
9060 - Closure of 2 Year Review Enquiry - Review Enquiry
Start Date
Due Date
Completion Date


Buy Standard

Technical specification
TS CEN/TS 16702-2:2020
English language
54 pages
sale 10% off
sale 10% off
e-Library read for
1 day

Standards Content (Sample)

SIST-TS CEN/TS 16702-2:2015
Elektronsko pobiranje pristojbin - Varnostno spremljanje avtonomnih cestninskih
sistemov - 2. del: Zaupanja vreden snemalnik
Electronic fee collection - Secure monitoring for autonomous toll systems - Part 2:
Trusted recorder
Elektronische Gebührenerhebung - Sichere Überwachung von autonomen
Mautsystemen - Teil 2: Zuverlässige Datenaufzeichnung
Perception du télépéage - Surveillance sécurisée pour systèmes autonomes de péage -
Partie 2: Enregistreur fiabilisé
Ta slovenski standard je istoveten z: CEN/TS 16702-2:2020
03.220.20 Cestni transport Road transport
35.240.60 Uporabniške rešitve IT v IT applications in transport
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

CEN/TS 16702-2
January 2020
ICS 03.220.20; 35.240.60 Supersedes CEN/TS 16702-2:2015
English Version
Electronic fee collection - Secure monitoring for
autonomous toll systems - Part 2: Trusted recorder
Perception du télépéage - Surveillance sécurisée pour Elektronische Gebührenerhebung - Sichere
systèmes autonomes de péage - Partie 2 : Enregistreur Überwachung von autonomen Mautsystemen - Teil 2:
fiabilisé Zuverlässige Datenaufzeichnung
This Technical Specification (CEN/TS) was approved by CEN on 25 November 2019 for provisional application.

The period of validity of this CEN/TS is limited initially to three years. After two years the members of CEN will be requested to
submit their comments, particularly on the question whether the CEN/TS can be converted into a European Standard.

CEN members are required to announce the existence of this CEN/TS in the same way as for an EN and to make the CEN/TS
available promptly at national level in an appropriate form. It is permissible to keep conflicting national standards in force (in
parallel to the CEN/TS) until the final decision about the possible conversion of the CEN/TS into an EN is reached.

CEN members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia,
Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway,
Poland, Portugal, Republic of North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and
United Kingdom.


CEN-CENELEC Management Centre: Rue de la Science 23, B-1040 Brussels
© 2020 CEN All rights of exploitation in any form and by any means reserved Ref. No. CEN/TS 16702-2:2020 E
worldwide for CEN national Members.

Contents Page
European foreword . 4
Introduction . 5
1 Scope . 7
2 Normative references . 7
3 Terms and definitions . 8
4 Symbols and abbreviations . 12
5 SAM concept and scenarios . 13
5.1 General . 13
5.2 The concepts of TR and verification SAM . 13
5.3 Scenarios for a trusted recorder. 15
5.3.1 General . 15
5.3.2 Real-Time Freezing without using a Trusted Time Source . 15
5.3.3 Real-Time Freezing using a Trusted Time Source . 16
5.4 Scenarios for a verification SAM . 16
5.4.1 General . 16
5.4.2 MAC verification . 16
5.5 General Scenarios . 17
5.5.1 General . 17
5.5.2 Assigning a Toll Domain Counter . 17
5.5.3 Obtaining SAM Information . 18
6 Functional requirements. 19
6.1 General . 19
6.1.1 SAM options . 19
6.1.2 Presentation of requirements . 20
6.2 Basic requirements . 20
6.3 Key management . 21
6.4 Cryptographic functions . 21
6.5 Real-time freezing . 22
6.6 Verification SAM . 23
6.7 Toll Domain Counter . 23
6.8 Trusted time source . 24
6.9 Security protection level . 25
7 Interface requirements . 26
7.1 General . 26
7.2 Calculate MAC for real-time freezing . 26
7.2.1 General . 26
7.2.2 Calculation of MAC . 27
7.2.3 Coding of request . 27
7.2.4 Coding of response. 28
7.3 Calculate digital signature for real-time freezing . 28
7.3.1 General . 28
7.3.2 Calculation of digital signature . 29
7.3.3 Coding of request . 29
7.3.4 Coding of response . 29
7.4 Get device information . 30
7.4.1 General . 30
7.4.2 Coding of request . 30
7.4.3 Coding of response . 31
7.5 Get toll domain counter information. 31
7.5.1 General . 31
7.5.2 Coding of request . 31
7.5.3 Coding of response . 32
7.6 Get key information . 32
7.6.1 General . 32
7.6.2 Coding of request . 33
7.6.3 Coding of response . 33
7.7 Error handling . 34
Annex A (normative) Data type specification . 35
Annex B (normative) Implementation Conformance Statement (ICS) proforma . 36
Annex C (informative) Trusted Time Source implementation issues. 49
Annex D (informative) Use of this document for the EETS . 51
Bibliography . 53

European foreword
This document (CEN/TS 16702-2:2020) has been prepared by Technical Committee CEN/TC 278
“Intelligent transport systems”, the secretariat of which is held by NEN.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN shall not be held responsible for identifying any or all such patent rights.
This document supersedes CEN/TS 16702-2:2015.
The CEN/TS 16702 series, Electronic fee collection – Secure monitoring for autonomous toll systems, is
composed with the following parts:
— Part 1: Compliance checking;
— Part 2: Trusted recorder.
This document about the trusted recorder is the second part of the CEN/TS 16702 series about the secure
monitoring for autonomous toll systems. The overall concept of secure monitoring is defined in
CEN/TS 16702-1.
This second edition will supersede the first edition (CEN/TS 16702-2:2015), which was technically
revised. The main changes compared to the previous edition are as follows:
— references to underlaying standards updated to latest version;
— updated terminology;
— slight restructuring.
This document has been prepared under a mandate given to CEN by the European Commission and the
European Free Trade Association.
According to the CEN/CENELEC Internal Regulations, the national standards organisations of the
following countries are bound to announce this Technical Specification: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Pol

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.