US: GTFS real-time - Secure Wireless Internet (ITS)

Description:

This solution is used within Canada and the U.S.. It combines standards associated with US: GTFS real-time with those for I-M: Secure Wireless Internet (ITS). The US: GTFS real-time standards include upper-layer standards required to implement real-time, public, transit-related communications. The I-M: Secure Wireless Internet (ITS) standards include lower-layer standards that support secure communications between two entities, either or both of which may be mobile devices, but they must be stationary or only moving within wireless range of a single wireless access point (e.g., a parked car). Security is based on X.509 or IEEE 1609.2 certificates. A non-mobile (if any) endpoint may connect to the service provider using any Internet connection method.

Relevant Regions:

Comm Profile: I-M: Secure Wireless Internet (ITS)

Comm Class: WAN - Wide Area Network

Standards in Profile:
LevelStandard
AccessWireless Internet Alternatives (NA)
MgmtBundle: SNMPv3 MIB
SecuritySecure Session Alternatives
TransNetInternet Transport Alternatives
TransNetIP Alternatives

Data Profile: US: GTFS real-time

Standards in Profile:
LevelStandard
FacilitiesIETF RFC 4180 CSV Files
FacilitiesIETF RFC 7159 JSON
FacilitiesIETF RFC 9110 HTTP Semantics
FacilitiesIETF RFC 9112 HTTP/1.1
FacilitiesISO 21320-1 ZIP
ITS Application EntityGTFS Realtime

Solution Issues Severity: 10

The severity issue score calculation only includes issues associated with standards that are included by default.

Solution Issues:

DefaultSeverityNameTypeDescription
FalseMediumOption not standardizedStandardization GapThe option set includes at least one option that is not (yet) defined in a standard.
FalseMediumOverlap of standardsOverlapMultiple standards have been developed to address this information and it is unclear which standard should be used to address this specific information flow.
FalseMediumRegulatory Permission NeededStandardization GapDeployment of this standard requires regulatory approval, which is currently subject to significant delays.
FalseMediumUncertainty about trust revocation mechanismSecurity GapThe mechanisms used to prevent bad actors from sending authorized messages is unproven.
FalseHighRegulatory IssueStandardization GapDeployment of this standard is subject to regulatory approval, which is not currently expected to be granted for deployments in the near-term.
TrueLowNot a standard (minor)Standardization GapThe document is publicly available and widely used but it is not currently a formal standard.
TrueMediumOutdated security referenceSecurity GapThe standard solution includes an outdated security reference.
TrueMediumPerformance not fully defined (medium)ITS Info GapThe performance rules are not fully defined for this information flow.
TrueMediumSecure data access not providedSecurity GapThe solution does not define rules on how the application entity authenticates requests to accept or provide data.

Solution to Triples

SourceFlowDestination
Transit Vehicle OBE transit vehicle location data Transit Management Center
Transit Vehicle OBE transit vehicle schedule performance Transit Management Center