Overview
EN ISO 21177:2024 (ISO 21177:2024) defines ITS station security services for secure session establishment and authentication between trusted devices. It specifies the services required to ensure authenticity of the source and integrity of information exchanged between ITS station communication units (ITS‑SCU), ITS station units (ITS‑SU), and external trusted entities such as sensor and control networks. The standard covers session lifecycle, cryptomaterial handling, access control state, and interfaces needed so ITS applications can exchange information in a trusted, auditable way.
Keywords: ITS station security services, secure session establishment, authentication, ISO 21177:2024, ITS‑SCU, ITS‑SU, ITS security.
Key Topics and Technical Requirements
- Session establishment and authentication: Procedures and primitives for initiating, extending and terminating secure sessions between trusted ITS entities.
- Architecture and functional entities: Roles and relationships for ITS‑SCU and ITS‑SU components and external trusted devices.
- Cryptomaterial handles and session state: Management of keys, certificates and session identifiers to protect confidentiality, integrity and authenticity.
- Access control and authorization: Policy models and access-control PDUs to enforce role-based access and authorization state.
- Enhanced and extended authentication: Support for stronger authentication methods (document references include SPAKE2 as an option) and mechanisms for owner/accessor roles.
- Interoperability with TLS and application specs: Guidance on relationship to Transport Layer Security (TLS) and higher-level ITS application requirements.
- Process flows and sequence diagrams: Detailed flows (configure, start session, send/receive PDUs, extend/force end sessions) to support implementation and testing.
- Security subsystem interfaces and data types: Defined primitives, PDUs and data models for implementers and vendors.
Practical Applications and Who Uses It
This standard is essential for ITS deployments that require trusted, time-sensitive communications, including:
- Automated driving systems requiring secure vehicle-to-infrastructure/vehicle-to-vehicle exchanges.
- Time-critical safety applications (collision avoidance, emergency braking coordination).
- Roadside infrastructure and traffic management for secure telemetry and control of sensors, signals and controllers.
- Remote management of ITS stations (referenced ISO 24102-2) for secure maintenance and diagnostics.
- Vehicle OEMs, tier‑1 suppliers, ITS integrators, cybersecurity engineers, and infrastructure operators implementing interoperable, standards-based security services.
Keywords: automated driving security, ITS cybersecurity, secure ITS sessions, remote management ITS.
Related Standards (if applicable)
- ISO 21217 - ITS station architecture (defines ITS‑SCU and ITS‑SU terms referenced by ISO 21177).
- ISO 24102‑2 - Remote management of ITS stations (related application use case).
- Relationship and guidance regarding TLS are discussed to align session-layer security with ITS application needs.
Use ISO 21177:2024 to design, evaluate and implement secure session and authentication services that meet regulatory and operational requirements across ITS ecosystems.