Delivery with obligations: Production of ticket system security modules will be created for the Moscow Metro
Customers: Moscow Metro Project date: 2025/03
|
The Moscow Department for Competition Policy in mid-March published a tender[1] for[2] Moscow metro for the supply of security modules for secure storage and use of encryption keys on devices passenger automation of the ticket system used in the city of Moscow. In addition to the supply of goods, the project also provides not only the supply of security modules itself, but also counter investment obligations to create, modernize, master their production in the city of Moscow. The maximum initial contract price is set at 826.6 million rubles.
The competition is the implementation of the order of the Moscow government dated October 31, 2024 No. 889-RP "On holding an electronic tender for the conclusion of a contract for the supply of security modules for the secure storage and use of encryption keys on passenger automation devices of the ticket system...." It defines both the main conditions for holding an electronic competition, and the list of security modules for secure storage and use of encryption keys on passenger automation devices of the ticket system.
The section on the purpose of the goods in the terms of reference for the competition states that security modules are necessary in the metro ticket system to ensure reading/writing of travel tickets and checking the special code (SCB) of the ticket. The subway is introducing a new ticket system that uses NXP SAM AV3 security modules, and it is necessary to ensure compatibility with this device in terms of the actual functions performed.
The security module must support Mifare Plus and NE501CD + cards in SL3 mode (RB3) - using the AES cryptographic algorithm. Mifare Classic (SL1/RB1) compatibility mode is provided by the validator without the use of a security module.
And the published draft contract states that no later than three years from the date of conclusion of the contract, the supplier undertakes to create, modernize, master production in the city of Moscow, investing at least 700 million rubles, including VAT, security modules for secure storage and use of encryption keys on passenger automation devices of the ticket system used in Moscow.
It is important to understand: the city does not invest this money directly, but transfers investment obligations to the contractor, - Sergey Matusevich, director of AI and web technologies development at Artezio, explained for TAdviser the terms of this tender. - Moscow, for its part, guarantees the purchase of a certain volume of products within 9 years. This is the incentive for the company to invest such a large amount. The contract is designed for 9 years, and this is a significant period for such technologically complex equipment. During this time, it is planned to release more than 170 thousand security modules, which indicates the scale of the project. The first batch must be delivered no later than 48 months after the conclusion of the contract - this is a rather long time, which shows that the city understands the complexity of the task of creating such production from scratch. |
In accordance with the tender documentation, the delivery is divided into four stages:
- Stage 1 - from the 1st to 548th calendar day - delivery of 100 test modules with documentation and test methods;
- Stage 2 - from 1250th to 1,350th calendar day - delivery of the first 57.3 thousand. SIM cards;
- Stage 3 - from 2350 to 2 450th calendar day - delivery of the second batch of 57.4 thousand SIM cards;
- Stage 4 - from 3100 to 3 200th calendar day - the third batch of 57.4 thousand security modules.
The requirements are partially tied to the existing solution, since the new modules must be compatible with the already operating equipment, - Sergey Matusevich explained the situation. - Now the system uses foreign SAM AV3 modules from NXP, and the city wants to replace them with domestic analogues. As part of this tender, it is planned to create Russian security modules for ticket terminals of Moscow transport. This is logical: you can't just take and replace the entire system at once. But at the same time, the tender does not limit competition, since the technical characteristics of the security modules are quite standard. |
In particular, safety modules shall comply with international GOST R ISO/IEC 7816 for Micro-SIM identification cards. The technical documentation says that the card microprocessor should support both international standards for encryption and hashing of AES-128, AES-256, SHA-1, SHA-256 and RSA, and Russian GOST R34.11-2012, R34.12-2015 and R34.13-2015. It is also supposed to support the MIFARE Plus contactless interaction standard, the implementation of which is present in Troika cards. During their manufacture, the draft contract provides for the development by the manufacturer of the following technological redistributions:
- Automated grinding and polishing of plates used in the production of microcontrollers;
- Automated mounting of plates on the carrier/frame;
- Separation of the plate into crystals with laser ablation cutting;
- Personalization of contact and contactless smart cards.
In understandable terms, the production of such security modules is actually a miniature microelectronics plant, "Sergei Matusevich said for TAdviser. - The terms of reference indicate quite complex operations. For example, it will be necessary to create a line for automated grinding and polishing of plates, on which microcircuits are then created. And the documentation also requires that the new production can perform the separation of the plate into separate crystals using laser ablation. To the uninitiated, it may sound like something out of science fiction, but in fact, it's just the high-precision laser cutting method used in modern microelectronics. |
It should be noted that until recently, the supplier of maps for the Moscow metro was the Mikron Zelenograd plant. Moreover, in June last year, the first five thousand Troika cards with the NE501CD + transport chip produced at this plant have already been delivered to the Moscow Metro. It is possible that the new tender will also be won by this manufacturer, since the NE501CD + crystal is also mentioned in the tender documentation.
Mastering production within the framework of state tenders is a rather rare phenomenon, especially when it comes to such complex products as security modules for ticket systems, - Sergey Matusevich shared his thoughts. - In most cases, customers prefer to work with existing plants and finished products. In this tender, we see a completely different approach: the Moscow Metro requires not only to supply ready-made security modules, but to create from scratch a full-fledged production in Moscow with a technological cycle that includes automated grinding of plates, mounting them on carriers and dividing them into crystals using a laser. |