US: Security Credentials - Secure Internet (ITS)

Description

This solution is used within the U.S.. It combines standards associated with US: Security Credentials with those for I–I: Secure Internet (ITS). The US: Security Credentials standards include upper–layer standards required to provide and revoke security credentials, define security policy, and handle enrollment coordination. The I–I: Secure Internet (ITS) standards include lower–layer standards that support secure communications between ITS equipment using X.509 or IEEE 1609.2 security certificates.

Includes Standards

LevelDocNumFullNameDescription
MgmtIETF RFC 3411An Architecture for Describing Simple Network Management Protocol (SNMP) Management FrameworksThis standard (RFC) defines the basic architecture for SNMPv3 and includes the definition of information objects for managing the SNMP entity's architecture.
MgmtIETF RFC 3412Message Processing and Dispatching for the Simple Network Management Protocol (SNMP)This standard (RFC) contains a MIB that assists in managing the message processing and dispatching subsystem of an SNMP entity.
MgmtIETF RFC 3413Simple Network Management Protocol (SNMP) ApplicationsThis standard (RFC) includes MIBs that allow for the configuration and management of remote Targets, Notifications, and Proxys.
MgmtIETF RFC 3414User–based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3)This standard (RFC) contains a MIB that assists in configuring and managing the user–based security model.
MgmtIETF RFC 3415View–based Access Control Model (VACM) for the Simple Network Management Protocol (SNMP)This standard (RFC) contains a MIB that supports the configuration and management of the View–based access control model of SNMP.
MgmtIETF RFC 3416Version 2 of the Protocol Operations for the Simple Network Management Protocol (SNMP)This standard (RFC) defines the message structure and protocol operations used by SNMPv3.
MgmtIETF RFC 3418Management Information Base (MIB) for the Simple Network Management Protocol (SNMP)This standard (RFC) defines the MIB to configure and manage an SNMP entity.
MgmtIETF RFC 4293Management Information Base for the Internet Protocol (IP)This standard (RFC) defines the MIB that manages an IP entity.
SecurityIETF RFC 5280Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) ProfileThis standard (RFC) defines how to use X.509 certificates for secure communications over the Internet.
SecurityIETF RFC 6749The OAuth 2.0 Authorization FrameworkThe OAuth 2.0 authorization framework enables a third–party application to obtain limited access to an HTTP service, either on behalf of a resource owner by orchestrating an approval interaction between the resource owner and the HTTP service, or by allowing the third–party application to obtain access on its own behalf. This specification replaces and obsoletes the OAuth 1.0 protocol described in RFC 5849.
SecurityIETF RFC 7230Hypertext Transfer Protocol (HTTP/1.1): Message Syntax and RoutingThis standard (RFC) defines the main Application Layer protocol used for the world–wide web.
SecurityIETF RFC 8446The Transport Layer Security (TLS) ProtocolThis standard (RFC) specifies Version 1.3 of the Transport Layer Security (TLS) protocol. The TLS protocol provides communications security over the Internet. The protocol allows client/server applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery.
SecurityISO 21177Intelligent transport systems –– Secure vehicle interface –– ITS–station security services for secure session establishment and authenticationISO 21177 defines a set of functional components that locally connect a vehicle ITS station (V–ITS–S) to a vehicle in a secure manner with minimum latency. It contains specifications for a set of security services required to ensure the authenticity and integrity of information exchanged between a vehicle and a V–ITS–S. These services include authentication and secure session establishment which are required to exchange information between a vehicle and a V–ITS–S in a trusted and secure manner.
SecurityISO/IEC 8825–7Information technology –– ASN.1 encoding rules –– Part 7: Specification of Octet Encoding Rules (OER)ISO/IEC 8825–7 specifies how to encode structures specified using ASN.1 using a byte–level encoding format. This standard is also available as ITU–T X.696.
ITS Application EntityNo Standard NeededNo Standard NeededThe services related to this portion of the stack are not critical within the scope of this solution.
FacilitiesIETF RFC 6749The OAuth 2.0 Authorization FrameworkThe OAuth 2.0 authorization framework enables a third–party application to obtain limited access to an HTTP service, either on behalf of a resource owner by orchestrating an approval interaction between the resource owner and the HTTP service, or by allowing the third–party application to obtain access on its own behalf. This specification replaces and obsoletes the OAuth 1.0 protocol described in RFC 5849.
FacilitiesIETF RFC 7230Hypertext Transfer Protocol (HTTP/1.1): Message Syntax and RoutingThis standard (RFC) defines the main Application Layer protocol used for the world–wide web.
FacilitiesISO 21177Intelligent transport systems –– Secure vehicle interface –– ITS–station security services for secure session establishment and authenticationISO 21177 defines a set of functional components that locally connect a vehicle ITS station (V–ITS–S) to a vehicle in a secure manner with minimum latency. It contains specifications for a set of security services required to ensure the authenticity and integrity of information exchanged between a vehicle and a V–ITS–S. These services include authentication and secure session establishment which are required to exchange information between a vehicle and a V–ITS–S in a trusted and secure manner.
FacilitiesISO/IEC 8825–7Information technology –– ASN.1 encoding rules –– Part 7: Specification of Octet Encoding Rules (OER)ISO/IEC 8825–7 specifies how to encode structures specified using ASN.1 using a byte–level encoding format. This standard is also available as ITU–T X.696.
TransNetIETF RFC 2460Internet Protocol, Version 6 (IPv6) SpecificationThis standard (RFC) specifies version 6 of the Internet Protocol (IPv6), also sometimes referred to as IP Next Generation or IPng.
TransNetIETF RFC 4291IP Version 6 Addressing ArchitectureThis standard (RFC) defines the addressing architecture of the IP Version 6 (IPv6) protocol. It includes the IPv6 addressing model, text representations of IPv6 addresses, definition of IPv6 unicast addresses, anycast addresses, and multicast addresses, and an IPv6 node's required addresses.
TransNetIETF RFC 4443Internet Control Message Protocol (ICMPv6) for the Internet Protocol Version 6 (IPv6) SpecificationThis standard (RFC) defines the control messages to manage IPv6.
TransNetIETF RFC 793Transmission Control ProtocolThis standard (RFC) defines the main connection–oriented Transport Layer protocol used on Internet–based networks.
Access Internet Subnet AlternativesA set of alternative standards that includes any Subnet Layer method of connecting to the Internet.

Readiness: High–Moderate

Readiness Description

One significant or possibly a couple minor issues. For existing deployments, the chosen solution likely has identified security or management issues not addressed by the communications solution. Deployers should consider additional security measures, such as communications link and physical security as part of these solutions. They should also review the management issues to see if they are relevant to their deployment and would require mitigation. For new deployments, the deployment efforts should consider a path to addressing these issues as a part of their design activities. The solution does not by itself provide a fully secure implementation without additional work.

Issues

IssueSeverityDescriptionAssociated StandardAssociated Triple
Still under developmentMediumA draft of the standard has been developed by the working group, but it was still under development at the time this analysis was performed.IEEE 1609.2.1 WAVE – Certificate Management(All)

Supports Interfaces

SourceDestinationFlow
ODOT Cooperative ITS Credentials Management SystemCity of Niles Emergency Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Niles Emergency Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Niles Emergency Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Niles Maintenance Dispatchsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Niles Maintenance Dispatchsecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Niles Maintenance Dispatchsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Niles Maintenance Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Niles Maintenance Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Niles Maintenance Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Niles Traffic Signal Systemsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Niles Traffic Signal Systemsecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Niles Traffic Signal Systemsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Warren Emergency Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Warren Emergency Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Warren Emergency Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Warren Maintenance Dispatchsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Warren Maintenance Dispatchsecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Warren Maintenance Dispatchsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Warren Maintenance Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Warren Maintenance Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Warren Maintenance Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Warren Traffic Signal Systemsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Warren Traffic Signal Systemsecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Warren Traffic Signal Systemsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Emergency Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Emergency Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Emergency Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Maintenance Dispatchsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Maintenance Dispatchsecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Maintenance Dispatchsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Maintenance Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Maintenance Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Maintenance Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Traffic Signal Systemsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Traffic Signal Systemsecurity credentials
ODOT Cooperative ITS Credentials Management SystemCity of Youngstown Traffic Signal Systemsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCommercial Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCommercial Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemCommercial Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemConnected/Automated Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemConnected/Automated Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemConnected/Automated Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCounty and City Connected Vehicle Roadside Equipmentsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCounty and City Connected Vehicle Roadside Equipmentsecurity credentials
ODOT Cooperative ITS Credentials Management SystemCounty and City Connected Vehicle Roadside Equipmentsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemCounty Emergency Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemCounty Emergency Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemCounty Emergency Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemMahoning County Maintenance Dispatchsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemMahoning County Maintenance Dispatchsecurity credentials
ODOT Cooperative ITS Credentials Management SystemMahoning County Maintenance Dispatchsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemMahoning County Maintenance Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemMahoning County Maintenance Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemMahoning County Maintenance Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemMahoning County Signal Control Systemsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemMahoning County Signal Control Systemsecurity credentials
ODOT Cooperative ITS Credentials Management SystemMahoning County Signal Control Systemsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemODOT ATMSsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemODOT ATMSsecurity credentials
ODOT Cooperative ITS Credentials Management SystemODOT ATMSsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemODOT Connected Vehicle Roadside Equipmentsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemODOT Connected Vehicle Roadside Equipmentsecurity credentials
ODOT Cooperative ITS Credentials Management SystemODOT Connected Vehicle Roadside Equipmentsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemODOT District 4 Maintenance Garagessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemODOT District 4 Maintenance Garagessecurity credentials
ODOT Cooperative ITS Credentials Management SystemODOT District 4 Maintenance Garagessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemODOT District 4 Maintenance Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemODOT District 4 Maintenance Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemODOT District 4 Maintenance Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemODOT District 4 Officesecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemODOT District 4 Officesecurity credentials
ODOT Cooperative ITS Credentials Management SystemODOT District 4 Officesecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemODOT Freeway Safety Patrol Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemODOT Freeway Safety Patrol Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemODOT Freeway Safety Patrol Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemODOT Traffic Signal Control Systemsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemODOT Traffic Signal Control Systemsecurity credentials
ODOT Cooperative ITS Credentials Management SystemODOT Traffic Signal Control Systemsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOSHP Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOSHP Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemOSHP Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Emergency Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Emergency Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Emergency Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Maintenance Garagessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Maintenance Garagessecurity credentials
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Maintenance Garagessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Maintenance Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Maintenance Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Maintenance Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Traffic Signal Systemssecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Traffic Signal Systemssecurity credentials
ODOT Cooperative ITS Credentials Management SystemOther Municipality or Township Traffic Signal Systemssecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOTIC Central Dispatchsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOTIC Central Dispatchsecurity credentials
ODOT Cooperative ITS Credentials Management SystemOTIC Central Dispatchsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOTIC Connected Vehicles Roadside Equipmentsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOTIC Connected Vehicles Roadside Equipmentsecurity credentials
ODOT Cooperative ITS Credentials Management SystemOTIC Connected Vehicles Roadside Equipmentsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOTIC Maintenance and Construction Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOTIC Maintenance and Construction Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemOTIC Maintenance and Construction Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOTIC Maintenance Dispatch Officessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOTIC Maintenance Dispatch Officessecurity credentials
ODOT Cooperative ITS Credentials Management SystemOTIC Maintenance Dispatch Officessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemOTIC Public Service Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemOTIC Public Service Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemOTIC Public Service Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemTraveler Information Devicessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemTraveler Information Devicessecurity credentials
ODOT Cooperative ITS Credentials Management SystemTraveler Information Devicessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemTrumbull County Maintenance Dispatchsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemTrumbull County Maintenance Dispatchsecurity credentials
ODOT Cooperative ITS Credentials Management SystemTrumbull County Maintenance Dispatchsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemTrumbull County Maintenance Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemTrumbull County Maintenance Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemTrumbull County Maintenance Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemTrumbull County Signal Control Systemsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemTrumbull County Signal Control Systemsecurity credentials
ODOT Cooperative ITS Credentials Management SystemTrumbull County Signal Control Systemsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemWestern Reserve Port Authoritysecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemWestern Reserve Port Authoritysecurity credentials
ODOT Cooperative ITS Credentials Management SystemWestern Reserve Port Authoritysecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemWestern Reserve Port Authority Connected Vehicle Roadside Equipmentsecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemWestern Reserve Port Authority Connected Vehicle Roadside Equipmentsecurity credentials
ODOT Cooperative ITS Credentials Management SystemWestern Reserve Port Authority Connected Vehicle Roadside Equipmentsecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemWRTA ADA All–Access Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemWRTA ADA All–Access Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemWRTA ADA All–Access Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemWRTA Countywide Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemWRTA Countywide Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemWRTA Countywide Vehiclessecurity policy and networking information
ODOT Cooperative ITS Credentials Management SystemWRTA Fixed Route Vehiclessecurity credential revocations
ODOT Cooperative ITS Credentials Management SystemWRTA Fixed Route Vehiclessecurity credentials
ODOT Cooperative ITS Credentials Management SystemWRTA Fixed Route Vehiclessecurity policy and networking information