US: NTCIP Message Sign - SNMPv3/TLS

Description

This solution is used within the U.S.. It combines standards associated with US: NTCIP Message Sign with those for I–F: SNMPv3/TLS. The US: NTCIP Message Sign standards include upper–layer standards required to implement center–to–field message sign communications. The I–F: SNMPv3/TLS standards include lower–layer standards that support secure center–to–field and field–to–field communications using simple network management protocol (SNMPv3); implementations are strongly encouraged to use the TLS for SNMP security option for this solution to ensure adequate security.

Includes Standards

LevelDocNumFullNameDescription
MgmtNTCIP 1201NTCIP Global Object (GO) DefinitionsThis standard defines SNMP objects (data elements) used by a wide range of field devices like time and versioning information.
MgmtIETF RFC 3411An Architecture for Describing Simple Network Management Protocol (SNMP) Management FrameworksThis standard (RFC) defines the basic architecture for SNMPv3 and includes the definition of information objects for managing the SNMP entity's architecture.
MgmtIETF RFC 3412Message Processing and Dispatching for the Simple Network Management Protocol (SNMP)This standard (RFC) contains a MIB that assists in managing the message processing and dispatching subsystem of an SNMP entity.
MgmtIETF RFC 3413Simple Network Management Protocol (SNMP) ApplicationsThis standard (RFC) includes MIBs that allow for the configuration and management of remote Targets, Notifications, and Proxys.
MgmtIETF RFC 3414User–based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3)This standard (RFC) contains a MIB that assists in configuring and managing the user–based security model.
MgmtIETF RFC 3415View–based Access Control Model (VACM) for the Simple Network Management Protocol (SNMP)This standard (RFC) contains a MIB that supports the configuration and management of the View–based access control model of SNMP.
MgmtIETF RFC 3416Version 2 of the Protocol Operations for the Simple Network Management Protocol (SNMP)This standard (RFC) defines the message structure and protocol operations used by SNMPv3.
MgmtIETF RFC 3418Management Information Base (MIB) for the Simple Network Management Protocol (SNMP)This standard (RFC) defines the MIB to configure and manage an SNMP entity.
MgmtIETF RFC 4293Management Information Base for the Internet Protocol (IP)This standard (RFC) defines the MIB that manages an IP entity.
SecurityIETF RFC 6353Transport Layer Security (TLS) Transport Model for the Simple Network Management Protocol (SNMP)This standard (RFC) defines how to use the TLS authentication service to provide authentication within the access control mechanism of SNMP.
ITS Application EntityNTCIP 1203NTCIP Object Definitions for Dynamic Message Signs (DMS)This standard defines SNMP objects (data elements) for monitoring and controlling dynamic message signs (such as variable message signs).
FacilitiesIETF RFC 3411An Architecture for Describing Simple Network Management Protocol (SNMP) Management FrameworksThis standard (RFC) defines the basic architecture for SNMPv3 and includes the definition of information objects for managing the SNMP entity's architecture.
FacilitiesIETF RFC 3412Message Processing and Dispatching for the Simple Network Management Protocol (SNMP)This standard (RFC) contains a MIB that assists in managing the message processing and dispatching subsystem of an SNMP entity.
FacilitiesIETF RFC 3413Simple Network Management Protocol (SNMP) ApplicationsThis standard (RFC) includes MIBs that allow for the configuration and management of remote Targets, Notifications, and Proxys.
FacilitiesIETF RFC 3414User–based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3)This standard (RFC) contains a MIB that assists in configuring and managing the user–based security model.
FacilitiesIETF RFC 3415View–based Access Control Model (VACM) for the Simple Network Management Protocol (SNMP)This standard (RFC) contains a MIB that supports the configuration and management of the View–based access control model of SNMP.
FacilitiesIETF RFC 3416Version 2 of the Protocol Operations for the Simple Network Management Protocol (SNMP)This standard (RFC) defines the message structure and protocol operations used by SNMPv3.
FacilitiesNTCIP 1203NTCIP Object Definitions for Dynamic Message Signs (DMS)This standard defines SNMP objects (data elements) for monitoring and controlling dynamic message signs (such as variable message signs).
TransNetIETF RFC 2460Internet Protocol, Version 6 (IPv6) SpecificationThis standard (RFC) specifies version 6 of the Internet Protocol (IPv6), also sometimes referred to as IP Next Generation or IPng.
TransNetIETF RFC 4291IP Version 6 Addressing ArchitectureThis standard (RFC) defines the addressing architecture of the IP Version 6 (IPv6) protocol. It includes the IPv6 addressing model, text representations of IPv6 addresses, definition of IPv6 unicast addresses, anycast addresses, and multicast addresses, and an IPv6 node's required addresses.
TransNetIETF RFC 4443Internet Control Message Protocol (ICMPv6) for the Internet Protocol Version 6 (IPv6) SpecificationThis standard (RFC) defines the control messages to manage IPv6.
TransNetIETF RFC 793Transmission Control ProtocolThis standard (RFC) defines the main connection–oriented Transport Layer protocol used on Internet–based networks.
AccessNTCIP 2104NTCIP SP–EthernetThis standard defines the Access Layer for center–to–field communications where the local connection is some variant of Ethernet.

Readiness: High–Moderate

Readiness Description

One significant or possibly a couple minor issues. For existing deployments, the chosen solution likely has identified security or management issues not addressed by the communications solution. Deployers should consider additional security measures, such as communications link and physical security as part of these solutions. They should also review the management issues to see if they are relevant to their deployment and would require mitigation. For new deployments, the deployment efforts should consider a path to addressing these issues as a part of their design activities. The solution does not by itself provide a fully secure implementation without additional work.

Issues

IssueSeverityDescriptionAssociated StandardAssociated Triple
Out of date (medium)MediumThe standard includes normative references to other standards that have been subject to significant changes that can impact interoperability or security of systems and the industry has not specified if and how these updates should be implemented for deployments of this standard.IETF RFC 6353 TLS for SNMP(All)
Update data to SNMPv3LowData has been defined for SNMPv1, but needs to be updated to SNMPv3 format.(None)(All)
Use case not considered in design (minor)LowWhile the indicated standards nominally address the information flow, the design may not meet practical constraints because this particular use case was not the focus of the design effort.(None)ODOT ATMS=>lane management control=>ODOT District 4 Lane Control Devices
Use case not considered in design (minor)LowWhile the indicated standards nominally address the information flow, the design may not meet practical constraints because this particular use case was not the focus of the design effort.(None)ODOT ATMS=>lane management control=>ODOT District 4 DMS
Use TLS for SNMP OptionLowThe standard allows for multiple security mechanisms. The only defined mechanism that meets the requirements for C–ITS is the one based on TLS.(None)(All)

Supports Interfaces

SourceDestinationFlow
City of Niles ITS Field DevicesCity of Niles Maintenance Dispatchroadway dynamic signage status
City of Niles ITS Field DevicesCity of Niles Traffic Signal Systemroadway dynamic signage status
City of Niles ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentroadway dynamic signage status
City of Niles ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentvehicle signage local data
City of Niles Maintenance DispatchCity of Niles ITS Field Devicesroadway dynamic signage data
City of Niles Maintenance DispatchTrumbull County ITS Field Devicesroadway dynamic signage data
City of Niles Traffic Signal SystemCity of Niles ITS Field Devicesroadway dynamic signage data
City of Warren ITS Field DevicesCity of Warren Maintenance Dispatchroadway dynamic signage status
City of Warren ITS Field DevicesCity of Warren Traffic Signal Systemroadway dynamic signage status
City of Warren ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentroadway dynamic signage status
City of Warren ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentvehicle signage local data
City of Warren Maintenance DispatchCity of Warren ITS Field Devicesroadway dynamic signage data
City of Warren Traffic Signal SystemCity of Warren ITS Field Devicesroadway dynamic signage data
City of Youngstown ITS Field DevicesCity of Youngstown Maintenance Dispatchroadway dynamic signage status
City of Youngstown ITS Field DevicesCity of Youngstown Traffic Signal Systemroadway dynamic signage status
City of Youngstown ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentroadway dynamic signage status
City of Youngstown ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentvehicle signage local data
City of Youngstown Maintenance DispatchCity of Youngstown ITS Field Devicesroadway dynamic signage data
City of Youngstown Traffic Signal SystemCity of Youngstown ITS Field Devicesroadway dynamic signage data
County and City Connected Vehicle Roadside EquipmentCity of Niles ITS Field Devicesroadway dynamic signage data
County and City Connected Vehicle Roadside EquipmentCity of Warren ITS Field Devicesroadway dynamic signage data
County and City Connected Vehicle Roadside EquipmentCity of Youngstown ITS Field Devicesroadway dynamic signage data
County and City Connected Vehicle Roadside EquipmentMahoning County ITS Field Devicesroadway dynamic signage data
County and City Connected Vehicle Roadside EquipmentOther Municipality or Township ITS Field Devicesroadway dynamic signage data
County and City Connected Vehicle Roadside EquipmentTrumbull County ITS Field Devicesroadway dynamic signage data
County and City Parking Management SystemsCounty and City Connected Vehicle Roadside Equipmentvehicle signage local data
Mahoning County ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentroadway dynamic signage status
Mahoning County ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentvehicle signage local data
Mahoning County ITS Field DevicesMahoning County Maintenance Dispatchroadway dynamic signage status
Mahoning County ITS Field DevicesMahoning County Signal Control Systemroadway dynamic signage status
Mahoning County Maintenance DispatchMahoning County ITS Field Devicesroadway dynamic signage data
Mahoning County Signal Control SystemMahoning County ITS Field Devicesroadway dynamic signage data
ODOT ATMSODOT District 4 DMSlane management control
ODOT ATMSODOT District 4 DMSroadway dynamic signage data
ODOT ATMSODOT District 4 DMSvariable speed limit control
ODOT ATMSODOT District 4 Lane Control Deviceslane management control
ODOT ATMSODOT District 4 Lane Control Devicesroadway dynamic signage data
ODOT ATMSODOT District 4 Speed Monitoring Roadside Equipmentroadway dynamic signage data
ODOT ATMSODOT District 4 Variable Speed Limit Signsroadway dynamic signage data
ODOT ATMSODOT District 4 Variable Speed Limit Signsvariable speed limit control
ODOT Connected Vehicle Roadside EquipmentODOT District 4 DMSroadway dynamic signage data
ODOT District 4 DMSODOT ATMSroadway dynamic signage status
ODOT District 4 DMSODOT ATMSvariable speed limit status
ODOT District 4 DMSODOT Connected Vehicle Roadside Equipmentroadway dynamic signage status
ODOT District 4 DMSODOT Connected Vehicle Roadside Equipmentvehicle signage local data
ODOT District 4 DMSODOT District 4 Maintenance Garagesroadway dynamic signage status
ODOT District 4 DMSODOT District 4 Officeroadway dynamic signage status
ODOT District 4 Lane Control DevicesODOT ATMSroadway dynamic signage status
ODOT District 4 Lane Control DevicesODOT Connected Vehicle Roadside Equipmentvehicle signage local data
ODOT District 4 Maintenance GaragesODOT District 4 DMSroadway dynamic signage data
ODOT District 4 Maintenance GaragesODOT District 4 Speed Monitoring Roadside Equipmentroadway dynamic signage data
ODOT District 4 OfficeODOT District 4 DMSroadway dynamic signage data
ODOT District 4 OfficeODOT District 4 Speed Monitoring Roadside Equipmentroadway dynamic signage data
ODOT District 4 RWIS StationsODOT District 4 Variable Speed Limit Signsdynamic sign coordination
ODOT District 4 RWIS StationsODOT District 4 Variable Speed Limit Signslane management coordination
ODOT District 4 RWIS StationsODOT District 4 Variable Speed Limit Signsvariable speed limit coordination
ODOT District 4 Speed Monitoring Roadside EquipmentODOT ATMSroadway dynamic signage status
ODOT District 4 Speed Monitoring Roadside EquipmentODOT District 4 Maintenance Garagesroadway dynamic signage status
ODOT District 4 Speed Monitoring Roadside EquipmentODOT District 4 Officeroadway dynamic signage status
ODOT District 4 Variable Speed Limit SignsODOT ATMSroadway dynamic signage status
ODOT District 4 Variable Speed Limit SignsODOT ATMSvariable speed limit status
ODOT District 4 Variable Speed Limit SignsODOT Connected Vehicle Roadside Equipmentvehicle signage local data
ODOT District 4 Variable Speed Limit SignsODOT District 4 RWIS Stationsdynamic sign coordination
ODOT District 4 Variable Speed Limit SignsODOT District 4 RWIS Stationslane management coordination
ODOT District 4 Variable Speed Limit SignsODOT District 4 RWIS Stationsvariable speed limit coordination
ODOT Rest Area Truck Parking Availability SystemODOT Connected Vehicle Roadside Equipmentvehicle signage local data
Other Municipality or Township ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentroadway dynamic signage status
Other Municipality or Township ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentvehicle signage local data
Other Municipality or Township ITS Field DevicesOther Municipality or Township Maintenance Garagesroadway dynamic signage status
Other Municipality or Township ITS Field DevicesOther Municipality or Township Traffic Signal Systemsroadway dynamic signage status
Other Municipality or Township Maintenance GaragesOther Municipality or Township ITS Field Devicesroadway dynamic signage data
Other Municipality or Township Traffic Signal SystemsOther Municipality or Township ITS Field Devicesroadway dynamic signage data
OTIC Service Plaza Truck Parking Management SystemOTIC Connected Vehicles Roadside Equipmentvehicle signage local data
Trumbull County ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentroadway dynamic signage status
Trumbull County ITS Field DevicesCounty and City Connected Vehicle Roadside Equipmentvehicle signage local data
Trumbull County ITS Field DevicesTrumbull County Maintenance Dispatchroadway dynamic signage status
Trumbull County ITS Field DevicesTrumbull County Signal Control Systemroadway dynamic signage status
Trumbull County Maintenance DispatchTrumbull County ITS Field Devicesroadway dynamic signage data
Trumbull County Signal Control SystemTrumbull County ITS Field Devicesroadway dynamic signage data
Western Reserve Port Authority Parking Management SystemsWestern Reserve Port Authority Connected Vehicle Roadside Equipmentvehicle signage local data