US: Security Credentials - Guaranteed Secure Internet (ITS)

Description:

This solution is used within Canada and the U.S.. It combines standards associated with US: Security Credentials with those for I-I: Guaranteed Secure Internet (ITS). The US: Security Credentials standards include upper-layer standards required to provide and revoke security credentials, define security policy, and handle enrollment coordination. The I-I: Guaranteed Secure Internet (ITS) standards include lower-layer standards that support secure communications with guaranteed delivery between ITS equipment using X.509 or IEEE 1609.2 security certificates.

Relevant Regions:

Comm Profile: I-I: Guaranteed Secure Internet (ITS)

Comm Class: WAN - Wide Area Network

Standards in Profile:
LevelStandard
AccessInternet Subnet Alternatives
MgmtBundle: SNMPv3 MIB
SecuritySecure Session Alternatives
TransNetIETF RFC 9293 TCP
TransNetIP Alternatives

Data Profile: US: Security Credentials

Standards in Profile:
LevelStandard
FacilitiesIEEE 1609.2.1 WAVE - Certificate Management
ITS Application EntityNot Needed
SecurityIEEE 1609.2.1 WAVE - Certificate Management

Solution Issues Severity: 3

The severity issue score calculation only includes issues associated with standards that are included by default.

Solution Issues:

DefaultSeverityNameTypeDescription
FalseMediumOption not standardizedStandardization GapThe option set includes at least one option that is not (yet) defined in a standard.
FalseMediumUncertainty about trust revocation mechanismSecurity GapThe mechanisms used to prevent bad actors from sending authorized messages is unproven.
TrueMediumOutdated security referenceSecurity GapThe standard solution includes an outdated security reference.

Solution to Triples

SourceFlowDestination
CCMS Manager System signed CTL Root CA
Cooperative ITS Credentials Management System enrollment coordination Other Credentials Management Systems
Distribution Center certificate chain file Location Obscurer Proxy
Distribution Center signed CTL Location Obscurer Proxy
Elector signed CTL CCMS Manager System
Enrollment CA enrollment cert Device Configuration Manager
Enrollment CA enrollment cert Registration Authority
Misbehavior Authority certificate revocations Authorization CA
Misbehavior Authority certificate revocations Distribution Center
Misbehavior Authority certificate revocations Intermediate CA
Misbehavior Authority certificate revocations Root CA
Other Credentials Management Systems enrollment coordination Cooperative ITS Credentials Management System
Registration Authority certificate chain file Location Obscurer Proxy
Registration Authority certificate revocations Location Obscurer Proxy
Registration Authority enrollment cert Location Obscurer Proxy
Registration Authority RA cert Location Obscurer Proxy
Registration Authority signed CTL Location Obscurer Proxy
Root CA signed CTL Intermediate CA