ISO 19299:2020 PDF
Electronic fee collection — Security framework
Electronic fee collection — Security framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 129
- Дата публикации:
- 13 августа 2020 г.
- Издание:
- ISO IS 19299 edition 1 version 1
- ICS:
- 03.220.20
This document defines an information security framework for all organizational and technical entities of an EFC scheme and for the related interfaces, based on the system architecture defined in ISO 17573-1. The security framework describes a set of security requirements and associated security measures. Annex D contains a list of potential threats to EFC systems and a possible relation to the defined security requirements. These threats can be used for a threat analysis to identify the relevant security requirements for an EFC system. The relevant security measures to secure EFC systems can then be derived from the identified security requirements.
Abstract
Overview
ISO 19299:2020 - Electronic fee collection - Security framework defines an information security framework for Electronic Fee Collection (EFC) systems. Based on the system architecture in ISO 17573-1, the standard sets out security requirements, associated security measures, and guidance for implementing trust and key management across all organizational and technical entities of an EFC scheme. It also includes annexes with threat analysis, security profiles, conformance templates, and privacy recommendations (including GDPR considerations).
Key topics and technical requirements
- Trust model: Defines stakeholder trust relations and technical trust architectures (e.g., TC - Toll Charger, TSP - Toll Service Provider, interoperability management).
- Security requirements: High-level and component-specific requirements for information security management, communication interfaces, data storage, toll chargers, toll service providers and interoperability management.
- Security measures / countermeasures: Concrete protections for interfaces and end‑to‑end security covering DSRC-EFC, CCC, LAC, ICC, front-end/back-end components, and roadside equipment (RSE).
- Key management: Lifecycle, generation, exchange, protection and use of asymmetric and symmetric keys, session key handling and certificate processes (issuance, revocation, CRLs).
- Interface specifications: Security specifications for interoperable interfaces and recommended signature/hash algorithm use, plus profiles for on-board equipment (OBE) and RSE.
- Threat analysis & privacy: Annex D lists potential threats and maps them to security requirements; Annex G offers privacy-focused implementation guidance aligned with GDPR.
Practical applications and who uses ISO 19299:2020
ISO 19299:2020 is used to design, evaluate and certify secure EFC systems and implementations. Typical users include:
- Toll operators and national authorities setting security policies for tolling and EETS (European Electronic Toll Service).
- Toll Service Providers (TSPs) and system integrators implementing back-end and front-end components.
- Vendors of on‑board equipment (OBE), roadside equipment (RSE) and interoperable interface products.
- Security architects, risk assessors and compliance officers conducting threat analysis and deriving security measures.
- Certification bodies and test labs using the Implementation Conformance Statement (ICS) proforma and security profiles.
Related standards
- ISO 17573-1 (EFC system architecture) - referenced as the architectural basis.
- ISO/TS 21193 - common payment media guidance referenced in the 2020 revision.
- Other ITS and cryptographic guidance relevant to interface and key management decisions.
ISO 19299:2020 delivers a practical, standards-based security framework for interoperable and privacy-aware EFC deployments, helping stakeholders reduce risk and implement robust, auditable security controls.
Технические детали
- Технический комитет
- ISO/TC 204 - Intelligent transport systems
- SKU
- ISO 19299:2020
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
SIST EN ISO 17573-1:2019
ДействующийElectronic fee collection - System architecture for vehicle related tolling - Part 1: Reference model (ISO 17…
Overview EN ISO 17573-1:2019 - "Electronic fee collection - System architecture for vehicle-related tolling - Part 1: Reference model" defines a high-level architecture and common language for electr…
PD ISO/TS 21193:2019
ОтменёнElectronic fee collection. Requirements for EFC application interfaces on common media
What is ISO/TS 21193- Requirements for EFC application interfaces on common media about? ISO/TS 21193 defines requirements to support information exchanges among related entities of a common payment…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…