Transit ticketing and offline trust
All AmbiSecure engineering content tagged Transit, newest first. Newer entries reflect current thinking; earlier entries come from the engineering archive.
Transit fare systems are one of the largest deployments of contactless secure-element technology, moving millions of riders through gates in the sub-300-millisecond window a tap allows. They demand offline-capable validation, clonability resistance, and per-card key diversification — which is why DESFire and secure-element ticketing dominate closed-loop systems.
This category covers transit and ticketing engineering: DESFire-based fare media, closed-loop versus open-loop models, offline validation at the gate, EMV in transit, and the key management that keeps a large fare fleet secure. The recurring focus is meeting hard latency and connectivity constraints without weakening cryptographic assurance.
Articles tagged Transit
DESFire EV1 vs EV2 vs EV3
Designing Low-Latency Secure Transit Validators
Why SAMs Matter in Closed-Loop Transit
Understanding EMV certification In Public Transportation
Public Transport Ticketing System (Part-3)
Public Transport Ticketing System (Part-2)
Public Transport Ticketing System (Part-1)
Frequently asked questions
Why is DESFire common in transit?
DESFire offers fast contactless transactions, AES secure messaging, per-application keys, and clonability resistance — the combination fare systems need for high-throughput gates and large card fleets.
What is the difference between closed-loop and open-loop ticketing?
Closed-loop uses an operator-issued card (e.g., a DESFire transit card) validated offline; open-loop accepts general-purpose EMV bank cards. Many networks run both, with different trust and settlement models.
How do gates authenticate cards offline?
Gates hold diversified keys or trusted signatures and validate the card cryptographically on the spot, so a tap completes within the latency budget without an online round-trip.
What is account-based ticketing?
A model where the card identifies the rider and the fare is calculated centrally, rather than the balance being stored on the card. It adds flexibility but still needs a fast local decision at the gate.
Why is a stored-value card still used when phones can emulate cards?
Because cards need no battery, boot instantly and work for riders without a suitable phone. Phone emulation supplements the card rather than replacing it.