OSS-SO_Integration_en
OSS-SO_Integration_en
2
Integrating OSS‑SO offline locking systems
en User manual
Access Management System V5.2 Table of contents | en 3
Table of contents
1 Security 4
2 Introduction 5
3 System overview 6
4 Configuring a reader as an OSS-SO updater 8
5 Defining an OSS-SO site in a third-party configuration tool 10
6 Importing and configuring an OSS-SO-site in the Bosch OSS-SO configurator 11
6.1 Basic adding, modifying and deleting 12
6.2 Starting the OSS-SO configurator 12
6.3 Setting the card technology 13
6.4 Importing an XML configuration file 14
6.5 Completing the configuration of the OSS-SO system 14
6.6 Configuring the updater 14
6.7 Editing locks in the locking system 15
6.8 Editing lock groups in the locking system 16
6.9 Adding time models to the locking system 17
6.10 Adding authorizations to the locking system 18
6.11 Supervisory dialogs and printed reports 19
7 Assigning OSS-SO authorizations in the ACS 20
Glossary 22
1 Security
Use latest software
Before operating the device for the first time, make sure that you install the latest applicable
release of your software version. For consistent functionality, compatibility, performance, and
security, regularly update the software throughout the operational life of the device. Follow
the instructions in the product documentation regarding software updates.
The following links provide more information:
– General information: https://www.boschsecurity.com/xc/en/support/product-security/
– Security advisories, that is a list of identified vulnerabilities and proposed solutions:
https://www.boschsecurity.com/xc/en/support/product-security/security-advisories.html
Bosch assumes no liability whatsoever for any damage caused by operating its products with
outdated software components.
2 Introduction
OSS-SO is an industrial standard defined by the OSS Association to improve the
interoperability of offline locking systems from different manufacturers. If an offline locking
system is implemented to the OSS-SO standard, then locks from different manufacturers can
interpret identically the access rights on the same smart card.
Intended audience
Installers, configurators and system administrators involved in the implementation of OSS-SO
offline locking systems within access control systems from Bosch.
3 System overview
Prerequisites
– Originally implemented for AMS 4.0 and BIS ACE 4.9.1.
Later implementations have additional OSS-SO manufacturers and features.
– License for the OSS-SO feature in your ACS (access control system).
– OSS-SO-standard door locks
Configuration tasks overview
In order to configure an OSS-SO locking system within an access control system (ACS) from
Bosch, the following tasks are required. The tasks are described in detail in the rest of this
document.
– Configuring a reader as an OSS-SO update reader
– Creating an XML definition of a site using software and hardware from an OSS-SO
manufacturer
– Importing the manufacturer's XML definition and configuring an OSS-SO locking system in
the Bosch OSO Configurator too
– Assigning the necessary OSS-SO authorizations in the ACS.
Description
Notice!
Data security
i Bosch urgently recommends that you select converter hardware according to current data-
security standards. Our use of the WUT 58661 converter in this example is in no way an
endorsement of the device from a data-security perspective.
For example, to set 2-wire mode for RS-485 on a WUT 58661 device:
– Set the DIL switches SW1 and SW2 to ON
– Set the DIL switches SW3 through SW8 to OFF
–
Reader firmware
The firmware on the LECTUS select reader must be version 1.20 or later.
Notice!
Recommissioning an updater
i If you remove an updater from an OSS-SO configuration in order to use it elsewhere, reset
the reader to its factory defaults according to the manufacturer's instructions. Failure to do
this will prevent the reader from reconnecting to the same system or to a different system.
Prerequisites
– Originally implemented for AMS 4.0 and BIS ACE 4.9.1.
Later implementations have additional OSS-SO manufacturers and features.
– License for the OSS-SO feature in your ACS (access control system).
– OSS-SO-standard door locks
– The supported browsers: Google Chrome, Mozilla Firefox, Microsoft Edge (Chromium
based)
Top-level procedure
1. Start the OSS-SO configurator
2. Set the card technology to be used, and the parameters that it requires
3. Import an XML configuration file
4. Complete the configuration of the overall locking system
5. Configure one or more updaters
6. Edit locks and lock groups within the locking system, if required
7. Define OSS-SO-specific time models. These determine the time-periods in which the
cards can operate the offline locks.
8. Define authorizations that can be assigned to cardholders in the ACS.
The individual steps of this top-level procedure are described in detail in the following
sections, beginning with generic editing procedures:
Editing procedures
The basic procedures are the same on each dialog:
Refer to
– Assigning OSS-SO authorizations in the ACS, page 20
MIFARE DESFire
– For MIFARE DESFire, enter the following parameters. The parameters marked with an
asterisk (*) are mandatory:
File size Integer: The size of files on the card. Default This information is available
(byte) 288. This information available from the from the manufacturer of
manufacturer of your access cards. your access cards.
LEGIC advant
– For LEGIC advant, enter the following parameters. The parameters marked with an
asterisk (*) are mandatory:
NOTE: In order to use LEGIC advent card technology you will need to order from the PHG
company:
– An OSS-SO updater
– A SAM63 card with your company's unique LEGIC stamp. The SAM63 card initializes the
updater so that it can write to LEGIC cards.
– LEGIC user cards with your company's LEGIC stamp
– Click Save to save the data or Cancel to discard your changes.
Manufacturer
Dialog path: OSS-SO Configurator tool > Manufacturers
4 Select the manufacturer of the OSS-SO locking system from the list.
– Click Save to save the data or Cancel to discard your changes.
Reader name String: a name for the updater device Free text
Port The network port for OSS-SO communication. Consult the manufacturer's
instructions.
Locking system* The name of the offline locking system Drop-down list
Lock ID* Unique integer within the locking system Unique integer within the
locking system.
Locking system* The name of the offline locking system Drop-down list
Assigned locks A list of the names of the locks in this Move locks from one list
group. to the other to assign and
unassign.
Click to do an
Available locks A list of the names of the locks that are
incremental search on
eligible for this group.
long lists.
Dialog path
OSS-SO Configurator tool > Time models
Procedure
Time interval 1.1* Starting time and finishing time (From/ Use the time picker
To) widget to select times.
(Optional) Time
The time format depends
intervals 1.2, 2.1, 2.2
on the settings of your
operating system.
Assigned locks and A list of the names of the locks in this Move locks from one list
lock groups group. to the other to assign and
See the additional parameters in the unassign.
following table.
Click to do an
Available locks A list of the names of the locks that are
incremental search on
eligible for this authorization.
long lists.
Available lock A list of the names of the locks groups
groups that are eligible for this authorization
Click to select all
members of a list.
For each assigned lock or lock group, two optional parameters are provided:
Office mode / toggle If enabled, this option allows the holder On/Off toggle
door of the authorization to unlock or lock a
door for a prolonged period, for example
during office hours.
Time model The days and periods in which the holder Drop-down list
of the authorization can operate the
respective assigned lock or lock group.
Basic procedure
1. Use the search and filter functions to filter out elements of interest.
2. Click the (print) icon on to send the filtered list to a printer or PDF file.
Dialog path
– In the ACE client menu select Personnel data > Cards
– In the AMS main client menu select Personnel data > Cards
Procedure
1. In the Cards dialog, select the person to receive OSS-SO authorizations.
2. Select the OSS-SO tab.
3. Make the assignments:
– All OSS-SO authorizations that are already assigned to the person appear in the list on
the left.
– All OSS-SO authorizations that are available for assignment appear in the list on the right.
Select items and then click the buttons between the lists to move items from one list to the
other.
1. Save the person record now, or first configure a time window, as described below.
Valid from The earliest date and time when the updater may transfer the assigned
authorizations to the card.
Valid until The latest date and time when the updater may transfer the assigned
(optional) authorizations to the card.
Validity time The duration of the authorizations from the moment they are transferred to
the card.
The default value for this duration is set as a property of the locking
system, but you can override that value here.
Refer to
– Configuring a reader as an OSS-SO updater, page 8
Glossary
ACS
generic term for a Bosch Access Control System,
for example, AMS (Access Management System)
or ACE (BIS Access Engine).
offline locking
access control where the locks are not in constant
electronic contact with the main system. Instead
the locks receive their settings from smart cards
that a human operator programs at a separate
computer.
OSS Association
The Open Security Standards Association. https://
www.oss-association.com
OSS-SO
the SO (Standard Offline) standard of the OSS
Association. An industry standard to improve the
interoperability of offline locking systems from
different manufacturers.
OSS-SO updater
an electronic device which writes, deletes and
modifies authorization data on an OSO credential.
UART
Universal asynchronous receiver-transmitter
(UART) - a hardware device for asynchronous
serial communication. Data format and
transmission speeds are configurable.