Overview
ISO 21177:2024 - Intelligent transport systems - ITS station security services for secure session establishment and authentication between trusted devices - specifies a standardized set of security services to ensure authenticity of the source and integrity of information exchanged between trusted ITS entities. It covers secure session establishment and authentication between bounded, managed ITS entities (ITS Station Communication Units - ITS‑SCU and ITS Station Units - ITS‑SU) and between ITS‑SUs and external trusted networks (for example sensor or control networks). These services support time‑critical safety, automated driving, remote ITS station management and roadside/infrastructure services.
Key topics and technical requirements
- Secure session establishment and authentication: mechanisms to authenticate peers and create trusted session contexts for data exchange. The document describes relationships to Transport Layer Security (TLS) and application‑layer specifications.
- Authenticity and integrity guarantees: procedures and message formats to ensure source authenticity and data integrity between trusted devices.
- Architecture and functional entities: definitions for ITS‑SCU/ITS‑SU roles, cryptomaterial handles, session IDs and session state management.
- Access control and authorization state: policy models and state handling for access decisions and authorization.
- Enhanced and extended authentication: support for enhanced authentication methods (including SPAKE2 as an example of a supported enhanced authentication method) and extended authentication PDUs.
- Process flows and sequence diagrams: detailed flows (Configure, Start session, Send/Receive PDU, Extend session, Force end session, Secure connection brokering) and state transition diagrams for implementers.
- Interfaces and data types: App‑Sec interface primitives (App‑Sec‑Configure, StartSession, Data, EndSession, Deactivate, etc.), security subsystem internal interfaces, and management PDUs (security management info, CRL and certificate chain requests/responses).
- Secure connection brokering and session extension: brokered connections, prerequisites and detailed processing to enable multi‑entity secured interactions.
Applications and who uses it
- Automotive OEMs and Tier‑1 suppliers implementing ITS stations and in‑vehicle communication units.
- ITS system architects and security engineers designing end‑to‑end secure V2X, roadside infrastructure and sensor integrations.
- Road operators and infrastructure vendors deploying secure roadside units, remote management systems and automated driving support services.
- Standards organizations and integrators mapping ITS security to TLS and application specifications.
Related standards
- ISO 21217 (ITS station architecture) - defines ITS‑SU/ITS‑SCU concept used by ISO 21177.
- ISO 24102‑2 (remote management of ITS stations) - use case referenced in scope.
- TLS and other application‑level security profiles - ISO 21177 describes relationships to these protocols.
Keywords: ISO 21177:2024, ITS station security services, secure session establishment, authentication, ITS‑SCU, ITS‑SU, intelligent transport systems, SPAKE2, access control, TLS, automated driving.