TUF - Secure Internet (ITS)

Description:

This solution is used within Australia, Canada, the E.U. and the U.S.. It combines standards associated with TUF with those for I-I: Secure Internet (ITS). The TUF standards include upper-layer standards required to install and update application software. The I-I: Secure Internet (ITS) standards include lower-layer standards that support secure communications between ITS equipment using X.509 or IEEE 1609.2 security certificates.

Relevant Regions:

Comm Profile: I-I: Secure Internet (ITS)

Comm Class: WAN - Wide Area Network

Standards in Profile:
LevelStandard
AccessInternet Subnet Alternatives
MgmtBundle: SNMPv3 MIB
SecuritySecure Session Alternatives
TransNetInternet Transport Alternatives
TransNetIP Alternatives

Data Profile: TUF

Standards in Profile:
LevelStandard
FacilitiesThe Update Framework
ITS Application EntityNot Needed
SecurityThe Update Framework

Solution Issues Severity: 7

The severity issue score calculation only includes issues associated with standards that are included by default.

Solution Issues:

DefaultSeverityNameTypeDescription
FalseMediumUncertainty about trust revocation mechanismSecurity GapThe mechanisms used to prevent bad actors from sending authorized messages is unproven.
FalseMediumUnvetted by communityStandardization GapThe proposed solution uses a suite of standards that is accepted within some communities, but has not necessarily been accepted for use within the context of this information triple.
TrueLowNot a standard (minor)Standardization GapThe document is publicly available and widely used but it is not currently a formal standard.
TrueMediumSecurity facilitated but not providedSecurity GapThe solution includes tools sufficient to facilitate security, but is dependent on out-of-scope components to implement.
TrueMediumUnvetted by communityStandardization GapThe proposed solution uses a suite of standards that is accepted within some communities, but has not necessarily been accepted for use within the context of this information triple.

Solution to Triples

This solution is used on the following information flow triples:
SourceFlowDestination
Center RSE application install/upgrade Connected Vehicle Roadside Equipment
Center field equipment software install/upgrade Field