Industry Professional

Metro Proof

Securing the Amsterdam Metro Underground

The Amsterdam Metro is a mixed rapid transit and light rail system in Amsterdam and its surrounding municipalities: Amstelveen, Diemen and Ouder-Amstel in the Netherlands. The network is owned by the city of Amsterdam and operated by the Gemeentelijk Vervoerbedrijf (GVB), the company that also operates trams, ferries and local buses.

Underground Lock System

The lock system of the Amsterdam underground is quite extensive and includes 2,574 cylinders. GVB was able to find and implement a system that solved their key issues as well as environmental issues. We will take a look at the challenge Amsterdam Metro is facing, the CyberLock system, the solution, and finally, how CyberLock’s system benefit Amsterdam Metro. In the Amsterdam underground, a cylinder has a lot to endure.

It must be resistant to burglary attempts, vandalism, manipulation, corrosion and rough handling. Even if it’s strong enough to withstand all of these, the life of a lock can be severely shorted if a vital key gets lost.

“We used to have a mechanical lock system, but we were constantly facing problems with lost keys,” said Frank de Vries, security manager of the Amsterdam underground stations. “Since replacing all cylinders would be a rather costly affair, we only replaced those that the lost key could open. In doing so, we eventually ended up with huge key rings.”

Key-centric Solution

CyberLock is a key-centric access control solution. The power is completely in the key. Each key contains a unique ID that cannot be changed or duplicated. These keys have the ability to store thousands of access events such as lock ID, date and time and event type.

The keys carry access schedules for the specific key holder and retain encrypted access codes that bind the key to a specific system. Each key contains a specific list of authorized locks and a schedule of when they may be accessed. For example, a key can be programmed to allow access to one or several locks from 8 a.m. to 6 p.m. on weekdays and 10 a.m. to 4 p.m. on Saturdays.

If presented outside of this schedule it is denied access. As for key expirations, keys can be assigned a start date and an expiration date which means keys can be issued before they become active, and can be set to expire on a regular basis in the future. Key holders must reauthorize keys before access will be granted again. Setting shortterm expiration dates is an excellent way to minimize risk due to lost or stolen keys.

When a key first makes contact, the key energizes the lock. A split second exchange of information determines if a key is at an approved lock within an authorized time frame. Access is then either granted or denied and that action, along with a date and time stamp, is recorded to the memories of both the key and the lock. These features were crucial in Amsterdam Metro’s need to get rid of the huge key rings the employees were carrying around and with the programmability and expiration date of the keys, re-keying will never be in the Amsterdam Metro vocabulary.

Hardware Interface

Because diversity of communication was necessary for Amsterdam Metro, the devices they selected served as an interface between the hardware and software. Key holders were given access privileges as needed. An audit trail also could be downloaded from the key while simultaneously uploading new schedules, permissions and system information. The system is able to keep track of keep track of remote and on ground employees.

The GVB decided to look for another way to protect its station entrances and restrict access to equipment rooms. Under consideration were various alternatives, including electronic access systems and remote card readers; however, these solutions were not resistant to water, frost or vandalism. GVB felt the diversity of electronic cylinder locks made it easy for GVB to convert all locks by retrofitting all their existing hardware on site. Access privileges are distributed to key holders via communicators. These devices are linked to the software over a local area network or securely over the Internet.

Met with some skepticism from some managers, GVB officials held firm to their decision.

“Initially, this system was received with some skepticism; there were a few complaints from managers who were no longer able to open certain doors—doors they should not have been able to open to begin with,” de Vries said. “Within a month, all cylinders had been replaced, including those in doors with very uncommon profiles. We have not had to adjust a single lock, and the installation of the cylinders was easily done by our own locksmith.”

Since re-keying was a costly option, and CyberLock’s electronic cylinders were installed without wiring, Amsterdam Metro was able to stay in budget, as the price for a lock is one-tenth the cost for a hardwired system. Since the implementation of CyberLock at the GVB, de Vries has received visits from colleagues of nearly all Dutch transport companies wanting to learn more about the system that has been such a huge success for Amsterdam Metro.

This article originally appeared in the August 2017 issue of Security Today.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3