X.1373 - Secure Wireless Internet (ITS)

Description:

This solution is used within Canada and the U.S.. It combines standards associated with X.1373 with those for I-M: Secure Wireless Internet (ITS). The X.1373 standards include upper-layer standards required to update software according to ITU-T approach. The I-M: Secure Wireless Internet (ITS) standards include lower-layer standards that support secure communications between two entities, either or both of which may be mobile devices, but they must be stationary or only moving within wireless range of a single wireless access point (e.g., a parked car). Security is based on X.509 or IEEE 1609.2 certificates. A non-mobile (if any) endpoint may connect to the service provider using any Internet connection method.

Relevant Regions:

Comm Profile: I-M: Secure Wireless Internet (ITS)

Comm Class: WAN - Wide Area Network

Standards in Profile:
LevelStandard
AccessWireless Internet Alternatives (NA)
MgmtBundle: SNMPv3 MIB
SecuritySecure Session Alternatives
TransNetInternet Transport Alternatives
TransNetIP Alternatives

Data Profile: X.1373

Standards in Profile:
LevelStandard
FacilitiesITU-T ITS Secure Software Update
ITS Application EntityITU-T ITS Secure Software Update

Solution Issues Severity: 24

The severity issue score calculation only includes issues associated with standards that are included by default.

Solution Issues:

DefaultSeverityNameTypeDescription
FalseMediumOption not standardizedStandardization GapThe option set includes at least one option that is not (yet) defined in a standard.
FalseMediumOverlap of standardsOverlapMultiple standards have been developed to address this information and it is unclear which standard should be used to address this specific information flow.
FalseMediumRegulatory Permission NeededStandardization GapDeployment of this standard requires regulatory approval, which is currently subject to significant delays.
FalseMediumUncertainty about trust revocation mechanismSecurity GapThe mechanisms used to prevent bad actors from sending authorized messages is unproven.
FalseHighRegulatory IssueStandardization GapDeployment of this standard is subject to regulatory approval, which is not currently expected to be granted for deployments in the near-term.
TrueLowData may not be fully defined (low)ITS Info GapThe information flow is unclear as to what precisely is needed; the standard may not fully support the needs of the information flow, depending on how it is interpreted.
TrueLowRelatively new technologyStandardization GapThe standard is finalized but has not been widely deployed. Deployment experience may result in further revisions in the technology, although it is expected that the standards group will make reasonable efforts to make any changes backwards compatible.
TrueMediumOutdated security referenceSecurity GapThe standard solution includes an outdated security reference.
TrueMediumStill under developmentStandardization GapA draft of the standard has been developed by the working group, but it was still under development at the time this analysis was performed.
TrueHighData/comm profile pairingStandardization GapThere are ambiguities as to how to (or if one should) couple the upper-layer standards defined in this solution with the indicated lower-layer standards.
TrueHighDraft not available (Critical)Standardization GapThe standards development organization has established a work item for the subject standard but a draft is not available for this critical feature to enable the interface. The draft may be missing due to the work item being new or simply a lack of activity on the work item.

Solution to Triples

SourceFlowDestination
Vehicle Service Center vehicle software install/upgrade Vehicle