ISO 21177:2023
Intelligent transport systems — ITS station security services for secure session establishment and authentication between trusted devices
Intelligent transport systems — ITS station security services for secure session establishment and authentication between trusted devices
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 100
- Дата публикации:
- 7 апреля 2023 г.
- Издание:
- ISO IS 21177 edition 1 version 1
- ICS:
- 03.220.01
This document contains specifications for a set of ITS station security services required to ensure the authenticity of the source and integrity of information exchanged between trusted entities, i.e.: — between devices operated as bounded secured managed entities, i.e. "ITS Station Communication Units" (ITS-SCU) and "ITS station units" (ITS-SU) as specified in ISO 21217; and — between ITS-SUs (composed of one or several ITS-SCUs) and external trusted entities such as sensor and control networks. These services include the authentication and secure session establishment which are required to exchange information in a trusted and secure manner. These services are essential for many intelligent transport system (ITS) applications and services including time-critical safety applications, automated driving, remote management of ITS stations (ISO 24102-2), and roadside/infrastructure-related services.
Abstract
Overview
ISO 21177:2023 - Intelligent transport systems - ITS station security services for secure session establishment and authentication between trusted devices - specifies a set of security services for ITS stations to ensure authenticity and integrity of information exchanged between trusted entities. The standard covers secure session establishment and authentication between bounded secured managed entities (ITS Station Communication Units - ITS‑SCU) and ITS station units (ITS‑SU), as well as between ITS‑SUs and external trusted entities such as sensor and control networks.
Key topics and technical requirements
- Secure session establishment and authentication: Services and procedures to negotiate trusted sessions that protect source authenticity and message integrity. The standard clarifies how these services relate to Transport Layer Security (TLS) and to application-level specifications.
- Architecture and functional entities: Definitions of roles and components (ITS‑SCU, ITS‑SU), cryptomaterial handles, session identifiers and session state management.
- Access control and authorization state: Mechanisms and PDUs for access control (e.g., AccessControlPdu, AccessControlResult) and how access policy is enforced during sessions.
- Authentication enhancements: Support for enhanced and extended authentication workflows, including a referenced method using SPAKE2 for password-authenticated key exchange.
- Service primitives and interfaces: Application–security (App‑Sec) interface primitives such as App‑Sec‑Configure, App‑Sec‑StartSession, App‑Sec‑Data, App‑Sec‑EndSession and related confirm/indication primitives to integrate security services with ITS applications.
- Process flows and sequence diagrams: Detailed flows for Configure, Start session, Send/Receive data, Extend session, Secure connection brokering and session termination.
- Security management information: PDUs and messages for certificate/CRL requests and security management information exchange.
Applications and who uses this standard
ISO 21177:2023 is essential for implementers and stakeholders building secure ITS ecosystems:
- Vehicle OEMs and automotive cybersecurity teams implementing secure V2X/ITS stations
- Roadside infrastructure and traffic management operators deploying trusted roadside units
- Suppliers of ITS‑SCU and ITS‑SU hardware/software modules
- System integrators and security architects designing time‑critical safety systems and automated driving features
- Remote management and maintenance platforms for ITS stations (linked to ISO 24102‑2)
Practical applications include time‑critical safety messaging, automated driving communications, roadside/infrastructure services, and secure remote management of ITS devices.
Related standards
- ISO 21217 - ITS station and communication unit definitions (ITS‑SCU, ITS‑SU)
- ISO 24102‑2 - Remote management of ITS stations
- Transport Layer Security (TLS) - referenced for relationship to session security
Keywords: ISO 21177:2023, ITS station security services, secure session establishment, authentication between trusted devices, ITS‑SCU, ITS‑SU, ITS security, automated driving security, access control PDU, SPAKE2, cryptomaterial handles.
Технические детали
- Технический комитет
- ISO/TC 204 - Intelligent transport systems
- SKU
- ISO 21177:2023
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 24102-2:2018
ДействующийIntelligent transport systems — ITS station management — Part 2: Remote management of ITS-SCUs
Overview ISO 24102-2:2018 defines the remote management component of Intelligent Transport Systems (ITS) station management. It specifies the Remote ITS Station Management Protocol (RSMP) - the proto…
BS ISO 21217:2020
ДействующийIntelligent transport systems. Station and communication architecture.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…