Skip to content
Control platform

PSA — site traffic system

The brain of the whole solution. PSA integrates kiosks, cameras, IP inputs and outputs, LED panels and access controllers, and decides who gets through. It's the presence of PSA that turns a kiosk into an e-Vrátnice.

Entry lane with a licence plate camera and an automatic barrier
Software · developed and engineered in-house
Architecture

One application server, a dedicated network

The PSA application server runs the entire solution layer: web administration, an MQTT broker as the bus for kiosks and peripherals, a local database and a reservation server for pre-registrations.

The components communicate over a dedicated network. The database runs locally and is not exposed externally, MQTT traffic must not leave the dedicated segment, and service access runs exclusively through a secured VPN. No PSA component is directly reachable from the public internet.

For security staff, a dedicated operator workstation can be deployed, physically and logically separated from your office network.

Integrated components

  • Indoor and outdoor kiosks
  • Licence plate cameras (RTSP)
  • IP input/output modules for barriers
  • LED panels and traffic lights
  • Access controllers for turnstiles and doors
  • Security operator workstation
How licence plate reading works

The camera receives no command — it only supplies the image

A detail that determines where you look for a fault — and therefore worth explaining.

A vehicle drives onto the induction loop

The loop embedded in the roadway detects the vehicle's metal mass and sends a pulse. Two are installed per lane.

The IP input/output module processes the pulse

The module monitors states and switches the barriers. It's the module that tells the system someone is waiting at the gate.

PSA reads the plate from the video stream

Only after the pulse does the software take a frame from the camera and recognise the licence plate. The camera itself triggers nothing.

The system decides and opens

It matches the plate against the records, verifies the authorisation and time window, opens the barrier, shows green and logs the passage with photo documentation.

For the IT department

Network requirements

An overview of the ports the system uses. We deliver the complete segmentation scheme during the project phase.

Web administrationHTTP 80 / HTTPS 443
Bus for kiosks and peripheralsMQTT, TCP 1883
Licence plate camerasRTSP, TCP 554
Access controllersTCP 4701
LED panelsTCP 10001
IP input/output modulesTCP 55555
Outgoing mailSMTP 25
Remote managementVPN, RDP 3389 / HTTPS 443
Reservation portal → PSASite-to-Site IPsec
Databaselocal, no network access
Two deployment topologies

Depending on who holds the perimeter

On-premise in the DMZ

All PSA components in a dedicated, isolated network inside your infrastructure. Your firewall controls the perimeter, remote management goes through your VPN. Reservation data from the public portal flows in through an encrypted tunnel.

Separate supplier network

PSA components in a physically separate network independent of your IT. Our router holds the perimeter, the reservation server is part of the application server. Suitable where you don't want to, or can't, provide space in your own network.

What it looks like

What the system leaves behind

Every passage has a time, a plate, an image and a record of whether the system or an operator authorised it. In an incident or a dispute, that's the only thing you can actually prove.

A chart of entries and exits by day above a table of individual passages
You can scroll the image sideways.
Passages A chart of entries and exits by day, with individual passages below it. Manual authorisation by an operator is highlighted and always shows the name of who opened the barrier. The period can be filtered and exported.
It's about schematic interface preview with sample data. Actual screens carry the licence plates of our customers' vehicles.
Security

Principles aligned with NIS2

The system controls physical access to the site, so it's a security element — and it's treated accordingly. Segmentation into a dedicated network, no component reachable from the internet, service access only through a VPN, MQTT traffic restricted to the dedicated segment to prevent an attacker from moving laterally across the network.

Voice authorisation of site access has its own protection: the kiosk's GSM module can only make outgoing calls, so it can't be called into from outside. The host authorises access by DTMF tones, the kiosk turns it into a secured message and the system creates an audit record. The voice channel is physically separated from the data network, so it can't be used as a route into your LAN.

The audit trail contains

  • The time and direction of each passage
  • The recognised licence plate and image
  • Whether the authorisation was automatic or manual
  • Which operator performed the action
  • Proof of a completed safety briefing
What your IT will say

Designed for strict IT environments and NIS2 principles

The site traffic system connects into your network — and the IT department rightly asks what that does to security. The answer is built into the design: no PSA component is directly reachable from the internet, the database runs locally and is not exposed externally, and the system's components sit in a dedicated, separate network (DMZ / VLAN), so a potential attack doesn't spread across the site. Service access runs only through a VPN, not through an open port.

It can be deployed in two ways, depending on your policy: on-premise in your DMZ behind a firewall you manage, or as a standalone unit with its own mobile connection where you don't want to let the system into the corporate network at all. Reservation data from the public portal flows in through an encrypted tunnel, not by direct access.

It's a design aligned with NIS2 principles, not a certificate — the operator is the one who meets the directive, and we supply technology that makes that easier, not harder.

Security principles

  • No part is directly exposed to the internet
  • Local, non-exposed database
  • Separate network — an attack doesn't spread further
  • Service access only through a VPN
  • On-premise DMZ, or a standalone unit
Frequently asked questions

What people ask most often

Can the system open the barrier automatically based on the licence plate?

Yes, that's the core of PSA. The camera reads the licence plate, the system matches it against the permissions and opens the barrier without any operator involvement. An unknown plate is handled at the kiosk or by phone — you set the rules.

What happens if the network or server fails?

Site access is designed so that a failure doesn't mean a closed gate: we define the barrier-opening modes according to your rules, including a fire scenario linked to the fire alarm system. Failure behaviour is part of the process design, not an afterthought.

How reliable is plate recognition?

On operational data from our installations, over 99 % of passages are handled automatically. The rest — damaged or foreign plates — is covered by a fallback procedure: the kiosk, a QR code or phone verification.

Does the system keep a history of passages?

Yes, every passage is stored with a time, direction, licence plate and photo. The history can be filtered and exported — for audits, the insurer and resolving disputes.

Interested in the PSA site traffic system for your operation?

Describe how things work at your site today. We'll come back with a proposed scope and a price — or start by building your specification in the configurator.