ISO 21177:2024
Intelligent transport systems — ITS station security services for secure session establishment and authentication between trusted devices
Intelligent transport systems — ITS station security services for secure session establishment and authentication between trusted devices
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 99
- Дата публикации:
- 19 марта 2024 г.
- Издание:
- ISO IS 21177 edition 2 version 1
- ICS:
- 03.220.01
This document contains specifications for a set of ITS station security services required to ensure the authenticity of the source and integrity of information exchanged between trusted entities, i.e.: — between devices operated as bounded secured managed entities, i.e. "ITS Station Communication Units" (ITS-SCU) and "ITS station units" (ITS-SU) as specified in ISO 21217; and — between ITS-SUs (composed of one or several ITS-SCUs) and external trusted entities such as sensor and control networks. These services include the authentication and secure session establishment which are required to exchange information in a trusted and secure manner. These services are essential for many intelligent transport system (ITS) applications and services, including time-critical safety applications, automated driving, remote management of ITS stations (ISO 24102-2), and roadside/infrastructure-related services.
Abstract
Overview
ISO 21177:2024 - Intelligent transport systems - ITS station security services for secure session establishment and authentication between trusted devices - specifies a standardized set of security services to ensure authenticity of the source and integrity of information exchanged between trusted ITS entities. It covers secure session establishment and authentication between bounded, managed ITS entities (ITS Station Communication Units - ITS‑SCU and ITS Station Units - ITS‑SU) and between ITS‑SUs and external trusted networks (for example sensor or control networks). These services support time‑critical safety, automated driving, remote ITS station management and roadside/infrastructure services.
Key topics and technical requirements
- Secure session establishment and authentication: mechanisms to authenticate peers and create trusted session contexts for data exchange. The document describes relationships to Transport Layer Security (TLS) and application‑layer specifications.
- Authenticity and integrity guarantees: procedures and message formats to ensure source authenticity and data integrity between trusted devices.
- Architecture and functional entities: definitions for ITS‑SCU/ITS‑SU roles, cryptomaterial handles, session IDs and session state management.
- Access control and authorization state: policy models and state handling for access decisions and authorization.
- Enhanced and extended authentication: support for enhanced authentication methods (including SPAKE2 as an example of a supported enhanced authentication method) and extended authentication PDUs.
- Process flows and sequence diagrams: detailed flows (Configure, Start session, Send/Receive PDU, Extend session, Force end session, Secure connection brokering) and state transition diagrams for implementers.
- Interfaces and data types: App‑Sec interface primitives (App‑Sec‑Configure, StartSession, Data, EndSession, Deactivate, etc.), security subsystem internal interfaces, and management PDUs (security management info, CRL and certificate chain requests/responses).
- Secure connection brokering and session extension: brokered connections, prerequisites and detailed processing to enable multi‑entity secured interactions.
Applications and who uses it
- Automotive OEMs and Tier‑1 suppliers implementing ITS stations and in‑vehicle communication units.
- ITS system architects and security engineers designing end‑to‑end secure V2X, roadside infrastructure and sensor integrations.
- Road operators and infrastructure vendors deploying secure roadside units, remote management systems and automated driving support services.
- Standards organizations and integrators mapping ITS security to TLS and application specifications.
Related standards
- ISO 21217 (ITS station architecture) - defines ITS‑SU/ITS‑SCU concept used by ISO 21177.
- ISO 24102‑2 (remote management of ITS stations) - use case referenced in scope.
- TLS and other application‑level security profiles - ISO 21177 describes relationships to these protocols.
Keywords: ISO 21177:2024, ITS station security services, secure session establishment, authentication, ITS‑SCU, ITS‑SU, intelligent transport systems, SPAKE2, access control, TLS, automated driving.
Технические детали
- Технический комитет
- ISO/TC 204 - Intelligent transport systems
- SKU
- ISO 21177:2024
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO 21217:2020
ДействующийIntelligent transport systems. Station and communication architecture.
BS EN ISO 21177:2024
ДействующийIntelligent transport systems. ITS station security services for secure session establishment and authenticat…
ISO 24102-2:2018
ДействующийIntelligent transport systems — ITS station management — Part 2: Remote management of ITS-SCUs
Overview ISO 24102-2:2018 defines the remote management component of Intelligent Transport Systems (ITS) station management. It specifies the Remote ITS Station Management Protocol (RSMP) - the proto…