Calypso HCE Scheme Creation and Operation

Author
Regulations

Transport operator security requirements

Calypso Networks Association (CNA) is a global open standards body for smart ticketing. In 2024, the Calypso standard is deployed in 29 countries worldwide.  CNA defined the Calypso HCE transport solution to operate on the existing NFC validation terminals.  Transport networks such as Île-de-France Mobilités requested to strengthen confidence in Calypso HCE solutions. For hardware-based solutions CNA relies on Common Criteria certification, but had no experience on mobile security or the definition of a security certification program.

Client / Project Need

Objectives & drivers

Create and operate a dedicated security certification scheme for Calypso HCE that reassures transport authorities, prevents fraud, and preserves trust in the existing hardware-based Calypso ecosystem. Île-de-France Mobilités was the first transport network to require this Calypso-HCE certification, as part of its ticketing modernisation plan led by Conduent, on a mobile solution supplied by HID Global.

Challenge

Key hurdles

Designing a tailored certification program for mobile HCE solutions with two fundamental security objectives: not weakening the existing hardware-based Calypso ecosystem, and preventing fraud, while remaining acceptable for vendors, transport operators and evaluation labs.

Approach

What we did

01

Created state-of-the-art security requirements for Calypso HCE, building on established mobile security programs.

02

Defined the evaluation and certification scheme adapted to mobile HCE solutions.

03

Set up and operated the certification body, including governance and processes.

04

Coordinated evaluation labs and provided certification guidance to vendors.

05

Combined desk-work with working-group sessions to align CNA members and stakeholders.

Key outcomes

Impact delivered

Lessons learned

What we took away

C-suite takeaway: extending a trusted hardware ecosystem to mobile requires a dedicated security scheme, not a reuse of hardware certification.  Early definition of security objectives, governance and lab coordination is what turns a new technology into a bankable, fraud-resistant service at scale.

Related materials

Keep exploring

ODSI: A Building-Block Approach to Secure Isolation

Read case study →

2IdO: Securing the Industrial Internet of Things

Read case study →

SECREDAS

SECREDAS: Building Trustworthy Automated Systems Across Critical Industries

Read case study →

Contact us

Request this document

We’ll send you access by email.