
C-ITS Pilot Security Credential Management System

The Department of Transport and Main Roads is already conducting a 500-vehicle, on-road field operational test (FOT) of a number of Cooperative Intelligent Transport Systems (C-ITS) safety applications.
In order that this FOT be reflective of the ‘real world’ the Queensland pilot requires the use of a security system known as a C-ITS Security Credential Management System (SCMS). The use of this system, its readiness, safety role, governance, placement and its administrative overhead on government and private industry will be studied through this project.
This iMOVE project is being monitored and relied upon by Australian State and Federal Transport jurisdictions to give guidance and direction on C-ITS compliance, cybersecurity, and resource impact for State and Federal governments, and private industries.
Participants
- Queensland Dept of Transport and Main Roads
- Department of Infrastructure, Regional Development and Cities
- Integrity Security Services (ISS)
Project background
Fundamental to C-ITS is the delivery of reliable and accurate messages between vehicles themselves, and between vehicles and traffic management infrastructure – failure could result in a collision, and at worst, a fatality. Security controls for C-ITS, including those offered by a SCMS also ensure that the system produces reliable and accurate information on which safety decisions can be made.
In this instance, the system’s security controls directly support the system’s safety objectives. By extension, a failure, or lack of these controls, results in a failure, lack of, or reduced level of safety. Looking further forward, the information from a cooperative vehicle may even be used by automated vehicles to make road safety decisions and potentially make those decisions without the occupant’s input.
The Commonwealth Government has called for delivery of priority trials and research of transformative transport technologies including smart infrastructure, C-ITS, and the development of a nationally agreed deployment plan for the security management of connected and automated vehicles (National Policy Framework for Land Transport Technology, Action Plan: 2016-2019). Other relevant national activities include:
- NTC’s Cooperative Intelligent Transport Systems Final Policy Paper (NTC 2013) considers security and privacy issues within the Australian regulatory context.
- Harmonisation Task Group (HTG) 6 for C-ITS security was a cooperative effort between EU, Australian and US policy and technical experts to develop an end-to-end security policy framework (ITS Security Policy, 2014), and is co-chaired by Transport Certification Australia. HTG 7 builds on the work to develop SCMS standards.
The emerging ETSI TS standards require a C-ITS Security Credential Management System (SCMS) for vehicles and transport infrastructure – based on PKI (public key infrastructure) – that issues digital certificates to a variety of ITS stations and associated manufacturers. The primary function of the SCMS is to create a common point of trust for interconnected devices through the use of digital certificates in connected vehicles.
In plain English, the goals of a SCMS are to:
- enable vehicles and ITS infrastructure to communicate in a secure manner
- enable rogue (for example, compromised or “hacked”) vehicles and ITS infrastructure to be removed from the C-ITS ecosystem
- allow specialised vehicles (such as emergency or military vehicles) to conduct specialised operations (such as traffic signal pre-emption) on the traffic system
There are a number of existing international PKI-based SCMS’s that have been developed specifically for C-ITS. These SCMS are built on the basis of regional policy, regulatory and operational requirements and constraints that may not align with the Australian security environment. There is also little practical information available on the organisational changes that may impact transport authorities with the introduction of this system, or how the system can be best deployed or managed to meet the expected safety benefits, or the role government must, should or could play in this new C-ITS security environment.
Further, an SCMS includes functions for identifying and removing security threats (misbehaviour management), however, little research has been conducted on how to identify a security threat in a connected vehicle environment or how to counter the threat.
This iMOVE project will be delivered by TMR, the international SCMS provider and the national cooperation/government technical reference group for cyber security for C-ITS in Australia. At this time, other states (including NSW, Victoria and South Australia) are supporting Queensland in piloting an SCMS, rather than planning separate initiatives for their own C-ITS projects.
In the connected vehicle space, this iMOVE project is therefore intended to:
1. Analyse the impact that the introduction of an SCMS has to:
- Australian transport authorities (organisational, operational and governance implications)
- Vehicle safety and security
- Australian and state privacy legislation, and the implications and protections required thereof
- C-ITS system performance
2. Prepare a research platform in order to inform future standards development for connected vehicle security threat detection and prevention (being performed in a separate though related iMOVE project)
Project wrap-up
In 2019, the Queensland Department of Transport and Main Roads (TMR) Ipswich Connected Vehicle Pilot was the largest C-ITS pilot in Australia and the first ETSI-compliant, WebTrust-certified, cellular-capable implementation of a Security Credential Management System (SCMS) internationally. That project, C-ITS Pilot Security Credential Management System, has been completed and an overview is provided below.
This product was jointly selected from a range of international suppliers by an Australian Transport cross jurisdictional selection panel from Queensland, New South Wales and Victorian State Governments.
Background
This project would implement an ETSI standards compliant security system for C-ITS capable of supporting up to 500 vehicles, 50 roadside stations and the central station. Practical Key Performance Indicators for the product were difficult to set at the outset of the project as many variables remained unknown.
As such, the project set a small number of high-level requirements and adopted an agile-like process involving workshops, discovery and joint progress.
Findings
The project had the following findings –
- The C-ITS standards do not cover the security of the security system. Related standards such as WebTrust (used to secure eCommerce transactions) were able to be adapted.
- The standards do not dictate which vehicles can perform which actions across the system – an element of traffic management knowledge is required manage the security system.
- Standards still need a common interpretation between participants; these are best resolved through technical workshops and testing procedures.
Technical findings
- Without hardware acceleration of digital signature validation, use case performance is impacted on low power devices.
- Digital certificate validation failures are common and part of normal operations for example, when stations meet for the first time.
- Close proximity cell towers can interfere with GPS reception. This is particularly important when C-ITS stations are fixed (such as roadside stations connected to intersections).
- Without GPS reception and without a secondary time source, even stations with fixed locations can lose time sync causing security verification failures.
- All processes on vehicle stations should be resilient to power failures – including the certificate “top-up” process.
- Hardware Security Module (HSM) load spreading schedules should be considered to make best use of resources. Butterfly keys may also reduce Public Key Infrastructure (PKI) load peaks.
- Permitted certificate durations are reduced, that automated certificate renewal and certificate exception notifications are critical.
- The central C-ITS station message signing function should complete within 20 milliseconds per message for the 95th percentile at maximum message throughput to minimise message propagation delays.
Governance findings
- System can be governed much like a standard PKI ensuring any changes to standards or security are significant as all stations are impacted. It involves multiple vehicle manufacturers, government transport jurisdictions, and SCMS providers. This should be considered when setting up governance groups for a country/jurisdiction.
- Governance over the C-ITS security system requires a convergence of government and private, and ICT and transport engineering disciplines.
Conclusion
Overall, the project was deemed successful in investigating the operational and governance aspects of running an SCMS in a C-ITS environment. Based on this project, all participants were able to make practical improvements to their products, knowledge and understanding of the SCMS.
Discover more from iMOVE Australia Cooperative Research Centre | Transport R&D
Subscribe to get the latest posts sent to your email.




