Navigation

Get in touch
Logo
News

Industries / Transportation

Connect mobility. Secure systems.

Securely integrate fleets, connected vehicles and digital payment systems.

Consulting. Integration. Operations.

parked trucks — illustrative image

Built around your industry.

  • Transit associations and public transport operators
  • Rail and infrastructure operators
  • Logistics providers, ports and airports
  • Vehicle manufacturers and suppliers

Your priorities

Understand the challenge. Shape the solution.

We bring fleet and traffic data together in data platforms, secure connected vehicles with PKI and hardware security modules, and build ticketing and booking platforms with high availability.

01

Fleet and traffic data platform

Data platform connected to telematics, control system and workshop

More on this
02

Ticketing, booking and payment under PCI DSS

Cloud-native ticketing and booking platform with load test report

More on this
03

Integrating dispatch, maintenance and billing

Integration architecture with interface catalog and data contracts

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01Fleet and traffic data platformApache Kafka · MQTT · Lakehouse

Our approach

Telematics, vehicle sensors, traffic control systems and workshop data deliver readings continuously, but they only become usable for dispatch and planning in a shared data platform. We build this platform with streaming ingestion, a common time reference and a data catalog, and on it we train models for predictive maintenance, utilization forecasts and vehicle scheduling. Every model gets version control, monitoring and documentation under the EU AI Act, and location data of drivers and passengers is processed in pseudonymized form.

Full scope
  • Ingestion of telematics, CAN bus data, traffic control systems and workshop systems via Apache Kafka and MQTT
  • Lakehouse with data catalog, data quality rules and a common time reference across all sources
  • Models for predictive maintenance, utilization forecasts and vehicle scheduling, validated against historical failures
  • Dashboards for control center, workshop and planning with Grafana and documented metrics
  • Model operations with MLflow, data drift monitoring and documentation under the EU AI Act and the GDPR

A bus operator brings together telematics, workshop orders and timetable data; the workshop spots impending failures of brakes and doors in the operating data before a vehicle breaks down on the route.

What you get

  • Data platform connected to telematics, control system and workshop
  • Versioned models with model card and monitoring
  • Data protection concept with pseudonymization of location data
Discuss this topic
02Connected vehicles and V2X certificates with HSM-backed PKIThales Luna Network HSM · Utimaco u.trust GP HSM Se-Series · Entrust nShield 5c

Our approach

Connected vehicles need a unique identity, encrypted connections to the backend, signed software updates and, for V2X communication, short-lived certificates that authenticate messages to other vehicles and to the infrastructure. We design the vehicle PKI with root CA, issuing CAs and enrollment for electronic control units and place the keys of the CAs and the signing services in hardware security modules. Issuance, renewal and revocation are logged, and the documents feed into the cybersecurity management system that UNECE R155 requires from the manufacturer.

Full scope
  • PKI architecture with root CA, issuing CAs, enrollment via EST or SCEP and revocation lists for control units and backends
  • V2X certificates under IEEE 1609.2 and ETSI TS 103 097 with connection to the European C-ITS trust infrastructure
  • Signing service for software updates with keys in the HSM, four-eyes approval and a log per release
  • HSM selection and integration, for example Thales Luna Network HSM, Utimaco u.trust GP HSM Se-Series or Entrust nShield 5c, with key ceremonies
  • Threat analysis under ISO/SAE 21434 and documents for the CSMS under UNECE R155

A commercial vehicle manufacturer moves the signing of its control unit updates from a build server into an HSM with an approval process; the vehicle PKI issues certificates per control unit and revocation becomes possible for the first time.

What you get

  • PKI architecture with certificate policy and key ceremony records
  • Signing service for software updates with HSM protection and approval process
  • CSMS documents and threat analysis for type approval
Discuss this topic
03Ticketing, booking and payment under PCI DSSKubernetes · PostgreSQL · Apache Kafka

Our approach

Ticketing, booking and freight portals must stay available at peak times and protect payment and customer data without every change triggering a PCI assessment. We develop and modernize these applications as cloud-native services, keep card data out of your own systems through tokenization and payment providers and tie passenger data to a deletion and authorization concept under the GDPR. On request we take over operations, monitoring and further development as an application service with agreed service levels.

Full scope
  • Architecture for ticketing and booking with load balancing, queues and automatic scaling on Kubernetes
  • Payment integration via payment providers with tokenization, EMV 3-D Secure and a defined PCI DSS scope
  • Connection to eTicket Deutschland under VDV-KA and to sales partners via versioned interfaces
  • Load tests, failover tests and a release process before timetable changes and fare changes
  • Operations with monitoring, on-call duty, security updates and a deletion and authorization concept under the GDPR

A transit association moves card payment in its ticket app to a payment provider with tokenization; its own platform leaves the PCI scope and sales stay stable during the timetable change.

What you get

  • Cloud-native ticketing and booking platform with load test report
  • Payment integration with tokenization and PCI scope definition
  • Operations manual with monitoring, on-call duty and deletion concept
Discuss this topic
04Control and signaling systems under IEC 62443IEC 62443 · CLC/TS 50701 · OPSWAT MetaDefender

Our approach

Interlockings, traffic control centers, tunnel control systems and operations control systems direct traffic and stay in service for decades, often without security updates. We divide these systems into zones and conduits under the IEC 62443 series for industrial automation, separate control systems from the administrative network, set up monitored remote maintenance and detect anomalies in the control network with passive OT monitoring. For railway applications we add the requirements of CLC/TS 50701, and all measures are planned so that operations continue during implementation.

Full scope
  • Inventory and risk analysis of control systems under IEC 62443-3-2 with zones, conduits and security levels
  • Segmentation with firewalls, data diodes and security gateways in front of legacy systems that cannot be hardened themselves
  • Remote maintenance via jump servers with multi-factor authentication, session recording and time-limited access
  • Passive OT monitoring connected to the SIEM and reporting processes under the BSI Act and NIS2
  • Inspection of maintenance laptops and removable media with OPSWAT MetaDefender, security processes under CLC/TS 50701 for railway systems

A rail infrastructure operator separates its interlocking systems from the administrative network and routes vendor remote maintenance through a recorded jump server; OT monitoring reports unknown devices in the control network for the first time.

What you get

  • Zone model with risk analysis under IEC 62443-3-2
  • Remote maintenance concept with jump server and session logs
  • Monitoring and reporting concept for KRITIS and NIS2
Discuss this topic
05Integrating dispatch, maintenance and billingSAP S/4HANA · API gateway · Apache Kafka

Our approach

Dispatch, maintenance, billing and partner systems in transportation and logistics companies have grown over years and are mostly linked through file exports and overnight batch runs. We place an integration layer with versioned interfaces and event processing between these systems, so that vehicle status, orders and maintenance events arrive within minutes instead of the next day. Every interface gets a data contract, automated tests and permissions, and changes to one system do not force a rebuild of the others.

Full scope
  • Interface catalog with data contracts, owners and dependencies across dispatch, ERP, workshop and telematics
  • API gateway and event processing with Apache Kafka for vehicle status, orders and maintenance events
  • Connection of SAP S/4HANA or other ERP and maintenance systems via standardized interfaces
  • Identity and authorization model for drivers, dispatchers, workshop and partners via OpenID Connect
  • Automated tests, versioning and release process per interface, monitoring in regular operations

A logistics provider connects telematics, order management and workshop system through an event platform; dispatch sees delays and maintenance needs in real time instead of in the daily report.

What you get

  • Integration architecture with interface catalog and data contracts
  • Tested, versioned interfaces with release process
  • Authorization model and operating model with monitoring
Discuss this topic
06Post-quantum readiness for vehicle PKI and backendsML-KEM (FIPS 203) · ML-DSA (FIPS 204) · Hybrid certificates

Our approach

Vehicles stay on the road longer than today's algorithms such as RSA and elliptic curves will remain secure against quantum computers, and control units can be upgraded in the field only to a limited extent. We inventory cryptographic algorithms, keys and certificates across vehicle PKI, V2X, backends and ticketing, assess protection lifetime and upgradability and plan the migration to ML-KEM and ML-DSA in stages. Crypto-agility in backend and enrollment ensures that algorithms can be replaced later without a recall.

Full scope
  • Crypto inventory across vehicle PKI, V2X certificates, update signatures, TLS and ticketing with rating by protection lifetime
  • Review of HSM firmware and control units for ML-KEM, ML-DSA and hybrid schemes
  • Crypto-agility in backend, enrollment and update service so that algorithms can be replaced without rebuilding applications
  • Hybrid certificates and migration plan for root CA, issuing CAs and signing services
  • Staged roadmap tied to vehicle generations, device replacement and BSI guidance

A vehicle manufacturer inventories the cryptography of its fleet PKI and update signing; the new vehicle generation receives hybrid certificates, while the existing fleet keeps today's algorithms until the model change.

What you get

  • Crypto inventory with risk rating
  • Migration roadmap for PKI, HSM and update service
  • Crypto-agility concept for backend and enrollment
Discuss this topic
containers vans — illustrative image
Transportation

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Transportation

Vehicle PKI at a commercial vehicle manufacturer

Signing keys for control unit updates on a build server, certificates issued by script, type approval under UNECE R155 requires a cybersecurity management system.

Solution

Vehicle PKI with root CA and issuing CAs, keys in the HSM with recorded ceremonies, signing service with four-eyes approval, threat analysis under ISO/SAE 21434.

Certificate per control unit with revocation, signed updates from the HSM, CSMS documents for the approval authority.

Discuss this topic

02 / Transportation

Ticketing platform at a transit association

Card data in its own database, every change within PCI scope, ticket sales outages at the timetable change.

Solution

Cloud-native ticketing platform on Kubernetes, card payment via payment provider with tokenization, load tests before every timetable change, operation as an application service.

Platform outside the PCI scope, stable sales at peak times, deletion and authorization concept under the GDPR.

Discuss this topic

03 / Transportation

Control systems at a rail infrastructure operator

Interlocking systems on the administrative network, vendor remote maintenance via permanently open access, KRITIS audit with findings.

Solution

Zone model under IEC 62443 with security gateways in front of legacy systems, jump server with session recording, passive OT monitoring connected to the SIEM.

Separated networks without operational interruption, traceable remote maintenance, evidence for the BSI without open findings.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Data sources, vehicle interfaces, control systems, platforms and regulatory gaps

    Prioritized list of measures, crypto inventory, gap analysis for UNECE R155, PCI DSS, KRITIS and NIS2
  2. 02

    Concept

    Target architecture, zone model, PKI design, operating model

    Target architecture, PKI and HSM concept, zone model, interface catalog, operating model, test concept
  3. 03

    Implementation

    PKI, data platform, ticketing and segmentation in stages

    Integrated systems, recorded key ceremonies, tests, documentation, approval per stage
  4. 04

    Operations

    Monitoring, certificate renewal, audits, knowledge transfer

    Monitoring, certificate and key rotation, audit support, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What are IT solutions for transportation and logistics?

Six modules from the fleet data platform to post-quantum readiness for vehicle fleets, planned, integrated and operated by OTOKO®. Vehicle keys and certificates are held in hardware security modules, and the evidence for KRITIS, NIS2 and UNECE R155 is produced during the project. The entire solution runs in German data centers.

IT solutions for transportation and logistics bring fleet and traffic data together, give connected vehicles a cryptographic identity and keep ticketing, dispatch and control systems available under load and under attack. OTOKO® covers six modules: a fleet and traffic data platform, connected vehicles and V2X certificates with HSM-backed PKI, ticketing and payment under PCI DSS, control and signaling systems under IEC 62443, integration of dispatch, maintenance and billing, and post-quantum readiness for vehicle PKI and backends.

The difference from a pure consulting project lies in operations and evidence. Every certificate issuance, every interface and every zone model comes with logs, version history and the documents that UNECE R155, PCI DSS and the BSI require. Cryptography and hardware security modules are our core competence. Signing keys for software updates and the keys of the vehicle PKI are therefore held in certified devices rather than in software.

Why OTOKO® for transportation and logistics

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. We place vehicle PKI, update signing keys and V2X certificates in certified hardware security modules, as UNECE R155 and the approval authorities expect.

  • German data centers

    The entire solution runs in German data centers, from the vehicle PKI and the ticketing platform to the data platform for fleet and traffic data.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what the BSI, approval authorities, PCI assessors and information security teams expect in the transportation sector.

  • One team through to operations

    One team accompanies you from consulting to operations. Security architects, PKI specialists, data engineers and application developers stay on without handover to third parties.

Delivery and details

Most transportation and logistics companies do not fail on missing technology but on data silos, unprotected interfaces and gaps in the evidence auditors ask for.

Data without a common time reference

Telematics, control system, workshop and billing keep their own data sets, dispatch plans with yesterday's exports and nobody can explain downtime across the fleet.

Vehicle keys in software

Signing keys for software updates sit on a build server, certificates are issued by script and revocation is not provided for.

Ticketing in PCI scope

The ticketing platform stores card data in its own database, every change brings in the PCI assessor and morning peak loads bring sales to a halt.

Control systems on the office network

Interlocking and traffic control systems are connected to the administrative network without segmentation, vendors maintain them over permanently open remote access and incidents would only be noticed when something fails.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour data center, your HSMs and control systemsData centers in Germany, operated under ISO 27001Azure, AWS or Google Cloud, region selectable
OperationYour team or OTOKO® as managed serviceOTOKO®, with audit rights for your companyShared, platform services by the provider
ToolsHSMs on site, Kafka, Kubernetes, OT monitoring in the control networkHosted PKI, HSM as a service, data and ticketing platformCloud HSM services, managed data and streaming services
Suited forControl systems, interlockings, signing keys, KRITIS facilitiesVehicle PKI, ticketing and data platform with a need for sovereigntyPassenger apps, analytics, peak loads in ticket sales
ComplianceFull control, evidence from your ISMS and CSMSProcessing agreement under GDPR, location Germany, KRITIS evidenceProcessing agreement, standard contractual clauses, exit plan per service

Collaboration

Project

Clearly scoped undertaking such as a vehicle PKI, a ticketing modernization or a zone model with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for type approvals, timetable changes and audit preparation

Team reinforcement

Security architects, PKI specialists, data engineers or application developers work in your teams, tools and release processes.

  • Onboarding into your processes, systems and security requirements
  • Scalable as the project progresses
  • Suited for companies with their own team and capacity gaps

Managed service

OTOKO® operates PKI, HSMs, data platform or ticketing application with agreed service levels, reports and the contract terms that KRITIS and NIS2 require for service providers.

  • Monitoring, certificate renewal, updates and on-call duty
  • Audit rights, service levels and exit plans in the contract
  • Suited for operators without their own team for PKI, HSM or platform operations

What each regulation requires in transportation and logistics and what OTOKO® delivers for it.

Standards and evidence
RequirementDemandsOTOKO® delivers
UNECE R155Cybersecurity management system of the vehicle manufacturer across the entire lifecycle, risk assessment per vehicle type, secured software updates under UNECE R156 and evidence for type approvalThreat analysis under ISO/SAE 21434, vehicle PKI and signing service with HSM protection, update process with logs and CSMS documents for the approval authority
PCI DSSProtection of cardholder data through scope definition, encryption, access control, logging and regular assessmentTokenization via payment providers, removal of ticketing from the scope, logging and documents for the QSA assessment or SAQ
IEC 62443Zones and conduits with security levels, risk assessment, hardened components, controlled remote access and incident detection in automation and control systemsZone model under IEC 62443-3-2, segmentation and security gateways, remote maintenance via jump servers, passive OT monitoring, supplemented by CLC/TS 50701 for railway systems
NIS2Risk management, supply chain security, staged reporting of significant incidents and management accountability; for KRITIS operators additionally attack detection and evidence under the BSI ActRisk register with dependency map, reporting processes, attack detection in control network and backend, service provider contracts with audit rights, evidence documentation for the BSI
GDPRLegal basis, data minimization, data subject rights, processing agreements and data protection impact assessment for location and passenger dataData protection concept for telematics and ticketing, pseudonymization of location data, deletion concept, processing agreement, support for the impact assessment

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which IT solutions for transportation and logistics does OTOKO® offer?

The portfolio covers data platforms for fleet and traffic data, vehicle PKI and V2X certificates with HSM protection, ticketing and payment under PCI DSS, security for control and signaling systems under IEC 62443, integration of dispatch, maintenance and billing, and post-quantum readiness. Each module can be commissioned on its own or as a complete package, with operation in German data centers.

How are software updates and V2X messages for vehicles secured?

Every update is signed with a private key that sits in a hardware security module and never leaves the device; the vehicle verifies the signature before installation and rejects manipulated packages. V2X messages carry signatures with short-lived certificates under IEEE 1609.2 or ETSI TS 103 097, which authenticate vehicle and infrastructure without making the driver traceable. Issuance, renewal and revocation run through the vehicle PKI and are logged.

What does NIS2 mean for transportation and logistics companies?

NIS2 lists transport among the sectors of high criticality and obliges affected companies to manage risks, report significant incidents in stages and secure their supply chain, with management accountable for implementation. Operators above the KRITIS thresholds additionally demonstrate their measures under the BSI Act. We work with operators of critical infrastructure and regulated industries. A comparison of your measures with the obligations shows where action is needed.

How does the ticketing platform stay outside the PCI scope?

Card data is not stored in your own system but handed over directly to a certified payment provider during payment, which returns a token in exchange. The ticketing platform works only with this token, so changes to fares, app or sales channels no longer touch the scope. We document the remaining requirements for the assessment or the self-assessment questionnaire.

Do we have to replace control or interlocking systems to become secure?

Usually not. Segmentation, security gateways, data diodes and monitored remote maintenance can be placed in front of existing components without changing their approval or operation. Replacement is planned only where components no longer allow a secure connection, and then as part of renewals that are due anyway.

When should vehicle fleets switch to post-quantum cryptography?

Now, with the inventory. Vehicles stay on the road for many years and control units can be upgraded in the field only to a limited extent, so the next vehicle generation determines the cryptography for decades to come. The inventory shows which PKI components, HSMs and update services must be migrated first, and the roadmap ties the switch to model changes and device replacements.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

Security architect: Target architecture, zone model, evidence for KRITIS and NIS2. Cryptography specialist: Vehicle PKI, HSM integration, signing service, PQC roadmap. OT security engineer: Segmentation, remote maintenance, OT monitoring under IEC 62443. Data engineer: Data platform, models, monitoring. Application developer: Ticketing, interfaces, application service. Project lead: Milestones, acceptance, reporting.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Data sources, vehicle interfaces, control systems, platforms and regulatory gaps Prioritized list of measures, crypto inventory, gap analysis for UNECE R155, PCI DSS, KRITIS and NIS2

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as a vehicle PKI, a ticketing modernization or a zone model with a defined result, milestones and acceptance. Team reinforcement: Security architects, PKI specialists, data engineers or application developers work in your teams, tools and release processes. Managed service: OTOKO® operates PKI, HSMs, data platform or ticketing application with agreed service levels, reports and the contract terms that KRITIS and NIS2 require for service providers.

What happens at handover to operations?

Monitoring, certificate renewal, audits, knowledge transfer Monitoring, certificate and key rotation, audit support, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Transportation

Let's discuss your next step.

Let us discuss how your fleet data, vehicles, and booking systems can work together securely.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.