Overview
SIST-TP CEN ISO/TR 21186-3:2021 - “Cooperative intelligent transport systems (C-ITS) - Guidelines on the usage of standards - Part 3: Security” - provides practical guidance on security for Intelligent Transport Systems (ITS) communications and data access. Published February 2021 and adopted by CEN, the technical report analyses security requirements, threat scenarios and best practices to achieve secure C-ITS connectivity, with specific integration guidance for ISO/TS 21177.
This guide targets the security aspects of cooperative transport ecosystems and supports design, implementation and operational decisions needed to protect communications, devices and credential infrastructure.
Key topics and technical content
- Security design process for C-ITS applications - methodology for embedding security into ITS services.
- Communications security mechanisms - recommended approaches for securing in-vehicle and infrastructure communication channels.
- Source authentication & access control - roles, policies and mechanisms for authenticating participants and controlling resource access.
- PKI, certificate authorities and certification processes - analysis of certificate lifecycle, trust models and gaps relevant to C-ITS deployments.
- IDX device security analysis - device-level threat modelling, asset identification, security objectives and Security Functional Requirements (SFR) mapping.
- ISO/TS 21177 implementation guidance - detailed architecture, protocol integration strategies, access policy structure and sequence diagrams for TLS-based access control.
- Gaps and needs for C-ITS certificate policy (CP) - analysis of PKI threats, mitigation measures and proposals for CP updates.
- Informative annexes with scenario threats, SFR mappings and proposals for improving TS 21177 (CRL requests, ownership/access policy, errata and session persistence).
Practical applications - who uses this standard
This report is practical for:
- C-ITS system architects and integrators designing secure services and communications.
- OEMs and device manufacturers implementing secure device architectures and hardening.
- PKI operators, certificate authorities and security engineers establishing trust frameworks and CP revisions.
- Transport authorities and ITS service providers assessing compliance, risk and deployment readiness.
- Security assessors and auditors performing threat modelling, SFR mapping and certification gap analysis.
Use cases include secure service onboarding, access-controlled data exchange, device provisioning, certificate lifecycle handling and threat-driven security requirement definition.
Related standards and references
- ISO/TS 21177 - access control and session management guidance referenced throughout the report.
- European C-ITS Certificate Policy (CP) - analysed for gaps and suggested changes.
- Common Criteria Protection Profiles (PPs) - used for comparative gap analysis in device security.
This technical report is a practical resource for implementing robust ITS security, including PKI, access control and device protection, helping stakeholders deploy resilient cooperative transport systems.