• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

RDG planning 'Barcode 2.0' ticketing with cross-London support (+ ITSO on mobile)

Status
Not open for further replies.

CyrusWuff

Established Member
Joined
20 May 2013
Messages
5,474
Location
London
I'm never sure if cross-London tickets, if you could find one that was set up for ITSO fulfillment, would work on TfL barriers currently? I've never felt like risking it as TfL gateline staff would almost always be ill-equipped to examine a ticket held on a Smartcard if the barrier rejected it. I know Travelcards held on ITSO work fine on tube barriers. As I understand the job advert it's purely to do away with the need to issue the cards to people, by requisitioning the passenger's phone.
Cross-London and Single/Return tickets to LU/DLR zonal destinations aren't (currently) accepted on Smartcard at LU gatelines.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Edvid

Established Member
Joined
7 Feb 2008
Messages
2,544
Any further updates on Barcode 2.0 or the associated projects?
 

Edvid

Established Member
Joined
7 Feb 2008
Messages
2,544
Contracts for delivering ITSO on Mobile and compliance with the updated ITSO spec (v2.1.5) have been awarded to Cubic and Vix.


Reuses existing infrastructure - ITSO on Mobile will maximise the return on previous investments, avoiding costly hardware upgrades.

Easy to use - Contactless card usage by phone is already commonplace. ITSO on Mobile tickets will be the same - intuitive and quick. Customers will simply be able to use their smart device (phone or wearable) by holding it to the reader that is already on every automatic ticket gate in the country. On newer handsets, tickets will still work even if the device battery is flat.

Works first time - A recent study by RDG showed that contactless via a smart device is the fastest and most reliable ticketing interface at gatelines.

Fast - ITSO on Mobile will make use of Express Mode for Apple Pay and Google Wallet's Skip Device Unlock features, which means there will be no need to unlock the phone or open any apps at the gateline. Customers will just hold their device to the reader and go. Contactless ticketing is up to 40% faster than some barcode tickets.

Reduces fraud - ITSO on Mobile is designed to be a highly secure method of ticketing. The fraud prevention features of NFC ticketing are clearly evidenced in the event ticketing arena. Native Operating System (OS) commands allow fast, over-the-air cancellation of tickets if they are lost, stolen or refunded.

Commitment to support from Apple and Google - Following extensive investment and development, both organisations have now committed to supporting ITSO within native wallet, for a seamless customer fulfilment and usage experience.

ITSO on Mobile tickets can be deployed at pace and rolled out nationally as a software-only upgrade to the existing ITSO infrastructure, thus making ITSO on Mobile available everywhere that ITSO smartcards are accepted. With hardware to support ITSO already available across all rail stations nationally, as well as London Underground, buses and trams across the country, no new infrastructure is required.

Some content related to Cubic below, where it is noted inboundary readers (i.e. those within Zones 1-9) will stay on v2.1.4 for the time being.* I assume this is because of a freeze on software & base data changes for the remainder of the existing TfL Revenue Collection Contract.

[* With the possible exception of readers that aren't configured to validate Oyster cards, i.e. the Platform 1-4 gateline at London St Pancras (any others?)]

ITSO provides a smartcard standard in use across the UK public transport sector. The specification has been recently updated to version 2.1.5. Cubic's efforts are concentrated on delivering software and integration for all outboundary readers as a single, unified phase. These updates are required to achieve ITSO 2.1.5 specification compliance. This consolidated approach is enhanced by a vanguard period preceding the full rollout, facilitating early validation and refinement of the solution before network-wide implementation. Inboundary gates remain outside the scope at this stage.

Cubic will design, develop, test and deliver the Cubic gate reader and back office changes required to support the ITSO 2.1.5 and RSPS3002 specifications.

The work focuses on enabling ITSO 2.1.5 functionality across existing Cubic devices. No new hardware is introduced, and development will occur on the current infrastructure. As such, there are no proposed changes to the overall solution architecture. The impacted components include Reader Software, TR3 and IPV Software, and TOC back-office systems such as the BDP and DGC. Components such as the DPF, SCU, and SC remain unaffected.

Just a paragraph for Vix-specific stuff, which unlike the Cubic tasks include compliance with RSPS3016.

ITSO provides a smartcard standard in use across the UK public transport sector. The specification has recently been updated to version 2.1.5. The requirement expected from Vix will be to certify their software to ITSO 2.1.5 and against the RSPS3002, 3016 standards. The scope of the work describes changes to Vix applications in use across the UK National Rail estate that are required to achieve compliance.
 

Adam Williams

Established Member
Joined
2 Jan 2018
Messages
3,611
Location
Warks
Some content related to Cubic below, where it is noted inboundary readers (i.e. those within Zones 1-9) will stay on v2.1.4 for the time being.* I assume this is because of a freeze on software & base data changes for the remainder of the existing TfL Revenue Collection Contract.
This does seem like we're going to have even more of a fragmented mess before things get much better.

I am not convinced it's being done because it's a better user experience, it's simply because it doesn't require hardware changes.

Customers will just hold their device to the reader and go
Well hang on, what if they have more than one ticket in their wallet?

Native Operating System (OS) commands allow fast, over-the-air cancellation of tickets if they are lost, stolen or refunded.
What on earth is a Native Operating System command?
 

MrJeeves

Established Member
Associate Staff
Senior Fares Advisor
Joined
28 Aug 2015
Messages
4,715
Location
Burgess Hill
What on earth is a Native Operating System command?
I assume this is a very poorly phrased reference to the host card emulation of the ITSO spec within the native wallets, which must allow for remote cancellation of tickets...?
 

Adam Williams

Established Member
Joined
2 Jan 2018
Messages
3,611
Location
Warks
I assume this is a very poorly phrased reference to the host card emulation of the ITSO spec within the native wallets, which must allow for remote cancellation of tickets...?
I don't see that it has anything to do with the fact it's doing HCE underneath at all though, really? Would it not be the same for any ITSO stuff?

Yes, the Wallet Passes can be remotely updated but we both know there's no security in that at all. The products can presumably be hotlisted at the HOPS end which is where the actual protection comes from.
 

takno

Verified Rep - Traksy
Joined
9 Jul 2016
Messages
6,598
Well hang on, what if they have more than one ticket in their wallet?
Presumably you have to decide which of you wallet items is "on display", even if its being displayed via NFC rather than barcode.

I have to admit I don't really like turning NFC on, partly because I have no idea what it's going to do, and partly because it constantly mithers about the cards or passport that are in the same pocket or hand.
 

OscarH

Established Member
Joined
15 Sep 2020
Messages
1,290
Location
Crawley
It would seem to me that "barcodes 2.0" would be more use to everyone if it was actually about barcodes and getting operators and suppliers accepting and checking them properly
 

Wallsendmag

Established Member
Joined
11 Dec 2014
Messages
6,289
Location
Wallsend or somewhere on the ECML
It would seem to me that "barcodes 2.0" would be more use to everyone if it was actually about barcodes and getting operators and suppliers accepting and checking them properly
I've given up with seeing the end of CCST before I retire. We just seem to have meetings about it but there are only a couple of blockers which could be non problems if there was a will.
 

OscarH

Established Member
Joined
15 Sep 2020
Messages
1,290
Location
Crawley
I've given up with seeing the end of CCST before I retire. We just seem to have meetings about it but there are only a couple of blockers which could be non problems if there was a will.
Repeated meetings without ever having any progress is a feeling many of us in the retail side can relate to I think!
 

Starmill

Veteran Member
Joined
18 May 2012
Messages
27,327
Location
Bolton
It would seem to me that "barcodes 2.0" would be more use to everyone if it was actually about barcodes and getting operators and suppliers accepting and checking them properly
Some of us would say that should have been agreed before we adopted the technology widely. Sadly it wasn't, and it was predictable and predicted that these would be the consequences. It's very hypocritical to start saying at this stage there's a need to avoid "costly hardware upgrades" or "maximise previous investment".
 

MrJeeves

Established Member
Associate Staff
Senior Fares Advisor
Joined
28 Aug 2015
Messages
4,715
Location
Burgess Hill
I don't see that it has anything to do with the fact it's doing HCE underneath at all though, really? Would it not be the same for any ITSO stuff?

Yes, the Wallet Passes can be remotely updated but we both know there's no security in that at all. The products can presumably be hotlisted at the HOPS end which is where the actual protection comes from.
I was assuming ITSO on Mobile would also get the benefit of remotely removing a product from the emulated ITSO provided its host device had an internet connection, meaning you might also not have to rely on HOPS and validators being permanently connected to it because inevitably that can never be the case.
 

Adam Williams

Established Member
Joined
2 Jan 2018
Messages
3,611
Location
Warks
provided its host device had an internet connection
And was not rooted, and didn't have a VPN configured to interfere with remote commands...

Anything other than doing it properly via the HOPS is security theatre in my view :p

validators being permanently connected to it
I also reject that we should just accept this idea that this isn't possible and give up. Why shouldn't they be connected with 3 or 4 nines uptime?

Some of us would say that should have been agreed before we adopted the technology widely
Controversial view, but I think that would have basically slowed or almost entirely prevented progress in this area and we'd still be stuck with CCST across the board today given the pace of progress to date.

Today, Raileasy has managed nearly 90% E-Ticket fulfilment across all bookings. Customers overwhelmingly like them, they can be fulfilled almost instantly and displayed on a huge variety of devices. They've undoubtedly allowed for the industry to achieve much better protection of revenue.

Back when the E-Ticket specs were first being written, host card emulation (HCE) was nowhere near maturity and in fact Apple remained a hold out for a very, very long time. It might have been possible to do on some Android devices given the SDK was better for NFC from the start, but would've required every retailer providing it via their own app with no allowances for customers to just print out the tickets at home.

Why should all of that progress have been held back because of one operator in London?
 
Last edited:

MrJeeves

Established Member
Associate Staff
Senior Fares Advisor
Joined
28 Aug 2015
Messages
4,715
Location
Burgess Hill
I also reject that we should just accept this idea that this isn't possible and give up. Why shouldn't they be connected with 3 or 4 nines uptime?
Obviously they should, but how would an on board staff member travelling on SWR through the New Forest check HOPS with their mobile validator, if they're not on the single 444 unit with Starlink? :p
 

Adam Williams

Established Member
Joined
2 Jan 2018
Messages
3,611
Location
Warks
Obviously they should, but how would an on board staff member travelling on SWR through the New Forest check HOPS with their mobile validator, if they're not on the single 444 unit with Starlink? :p
Perhaps it would provide a good incentive for this country to actually have a proper go at investing in infrastructure, rather than just fiddling around the edges :p

Is there GSM-R coverage in the New Forest? I'm not suggesting that that network start being used for non-safety-critical data transfer, but it rather illustrates what's possible when the desire is there, I think.
 

Starmill

Veteran Member
Joined
18 May 2012
Messages
27,327
Location
Bolton
Why should all of that progress have been held back because of one operator in London?
There's a lot more going on than just that though isn't there. See also how most people's etickets aren't scanned on CrossCountry, or GTR installing readers on only some existing gates rather than all of them.

== Doublepost prevention - post automatically merged: ==

They've undoubtedly allowed for the industry to achieve much better protection of revenue.
Really? How does the medium of the tickets change that balance? You can use scan data to protect revenue but only against mischief introduced by the widespread adoption of mobile ticket selling. Northern and Merseyrail in the same area are no better or worse than one another despite the difference here. Ultimately revenue protection is just a function of how much relative ticket checking there is. Unless you are saying it's easier to buy a ticket now, which realistically is only a benefit when you get pay as you go, not when you get a mobile ticket sales channel.

== Doublepost prevention - post automatically merged: ==

I also reject that we should just accept this idea that this isn't possible and give up. Why shouldn't they be connected with 3 or 4 nines uptime?
I do find that attitude bizarre to be honest. Nearly every station will be able to plug into direct internet. It's hardly like we're talking about car parking machines in the West Highlands, we're overwhelmingly talking about urban railway stations.
 
Last edited:

Adam Williams

Established Member
Joined
2 Jan 2018
Messages
3,611
Location
Warks
Really? How does the medium of the tickets change that balance?
CCST really has very few security features comparatively, and the measures that do exist aren't really very good. They reflect the time that the format was designed. There a variety of things you could potentially do with a CCST ticket that would be much more difficult or almost impossible to do with E-Tickets. There is far too much faith placed in stock control, and bad actors not doing things that they could do.

You are right that E-Tix (and more generally, online mobile purchasing) by their nature allow for novel types of misuse, but the standards have generally been well-designed with these risks in mind - e.g. buying after departure is very easy to spot. I don't think the comparison is even vaguely close.
 

Starmill

Veteran Member
Joined
18 May 2012
Messages
27,327
Location
Bolton
CCST really has very few security features comparatively, and the measures that do exist aren't really very good. They reflect the time that the format was designed. There a variety of things you could potentially do with a CCST ticket that would be much more difficult or almost impossible to do with E-Tickets. There is far too much faith placed in stock control, and bad actors not doing things that they could do.

You are right that E-Tix (and more generally, online mobile purchasing) by their nature allow for novel types of misuse, but the standards have generally been well-designed with these risks in mind - e.g. buying after departure is very easy to spot. I don't think the comparison is even vaguely close.
The standard itself was great if you wanted to prevent a problem that never existed, like someone making fake London to Manchester advance tickets on CCST, and was and remains dreadful at preventing short faring, such that it propogated an enormous rise in fraud which only now has come back under control. It's still trivially easy to say board at Cattal with no ticket, buy a Burley Park to Leeds when the train is at Headingley and then travel undetected having paid a fraction of what you should. Nobody can do that on Merseyrail.

Now that's not a reason not to use a significantly better format for customer experience reasons, but unfortunately the implementation of it in an uncontrolled way caused a lot of new problems that then had to be solved.
 

alistairlees

Established Member
Joined
29 Dec 2016
Messages
4,416
The standard itself was great if you wanted to prevent a problem that never existed, like someone making fake London to Manchester advance tickets on CCST, and was and remains dreadful at preventing short faring, such that it propogated an enormous rise in fraud which only now has come back under control. It's still trivially easy to say board at Cattal with no ticket, buy a Burley Park to Leeds when the train is at Headingley and then travel undetected having paid a fraction of what you should. Nobody can do that on Merseyrail.

Now that's not a reason not to use a significantly better format for customer experience reasons, but unfortunately the implementation of it in an uncontrolled way caused a lot of new problems that then had to be solved.
It is also trivially easy to check that passengers on trains have tickets, no?
 

Starmill

Veteran Member
Joined
18 May 2012
Messages
27,327
Location
Bolton
It is also trivially easy to check that passengers on trains have tickets, no?
Precisely so. Revenue protection is overwhelmingly a function of doing the ticket check. Not of using one fulfilment method over another.
 

saismee

Established Member
Joined
20 Oct 2023
Messages
1,747
Location
UK
I think one of the main problems with revenue protection of eTickets is that there's no immediate or obvious consequence for buying an invalid ticket... or just silently refunding it without a scan. You aren't taking something physical so it feels cheeky rather than criminal, and the anonymity of an online retailer means you don't have to speak to a real person every time. Mass refunding at a ticket office would be quite obvious, in comparison.
 

Haywain

Veteran Member
Joined
3 Feb 2013
Messages
24,824
This is, presumably, why the Conditions of Travel appear to be changing to restrict the right to a refund on the day of travel.
 

Sonic1234

Member
Joined
25 Apr 2021
Messages
795
Location
Croydon
and the anonymity of an online retailer means you don't have to speak to a real person every time.
Exactly this. It's the depersonalisation of the buying and refund process which enables it.

Even things like refunding an Advance you can't use any more as "disruption" when the train is only a couple of minutes late, which arguably is legitimate. There's no way someone would go to a ticket office and claim a disruption refund, but sending a form off into the ether is a different matter.
 

SynthD

Established Member
Joined
4 Apr 2020
Messages
2,055
Location
UK
I've given up with seeing the end of CCST before I retire. We just seem to have meetings about it but there are only a couple of blockers which could be non problems if there was a will.
Are there known solutions that a specific organisation doesn’t have the will to implement?
 
Status
Not open for further replies.

Top