Uptane - Secure Wireless Internet (ITS)

Description

This solution is used within Canada and the U.S.. It combines standards associated with Uptane with those for I–M: Secure Wireless Internet (ITS). The Uptane standards include upper–layer standards required to update software in a vehicle according to the Uptane standards. The I–M: Secure Wireless Internet (ITS) standards include lower–layer standards that support secure communications between two entities, either or both of which may be mobile devices, but they must be stationary or only moving within wireless range of a single wireless access point (e.g., a parked car). Security is based on X.509 or IEEE 1609.2 certificates. A non–mobile (if any) endpoint may connect to the service provider using any Internet connection method.

Includes Standards

LevelDocNumFullNameDescription
MgmtIETF RFC 3411An Architecture for Describing Simple Network Management Protocol (SNMP) Management FrameworksThis standard (RFC) defines the basic architecture for SNMPv3 and includes the definition of information objects for managing the SNMP entity's architecture.
MgmtIETF RFC 3412Message Processing and Dispatching for the Simple Network Management Protocol (SNMP)This standard (RFC) contains a MIB that assists in managing the message processing and dispatching subsystem of an SNMP entity.
MgmtIETF RFC 3413Simple Network Management Protocol (SNMP) ApplicationsThis standard (RFC) includes MIBs that allow for the configuration and management of remote Targets, Notifications, and Proxys.
MgmtIETF RFC 3414User–based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3)This standard (RFC) contains a MIB that assists in configuring and managing the user–based security model.
MgmtIETF RFC 3415View–based Access Control Model (VACM) for the Simple Network Management Protocol (SNMP)This standard (RFC) contains a MIB that supports the configuration and management of the View–based access control model of SNMP.
MgmtIETF RFC 3416Version 2 of the Protocol Operations for the Simple Network Management Protocol (SNMP)This standard (RFC) defines the message structure and protocol operations used by SNMPv3.
MgmtIETF RFC 3418Management Information Base (MIB) for the Simple Network Management Protocol (SNMP)This standard (RFC) defines the MIB to configure and manage an SNMP entity.
MgmtIETF RFC 4293Management Information Base for the Internet Protocol (IP)This standard (RFC) defines the MIB that manages an IP entity.
SecurityIETF RFC 5280Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) ProfileThis standard (RFC) defines how to use X.509 certificates for secure communications over the Internet.
SecurityIETF RFC 8446The Transport Layer Security (TLS) ProtocolThis standard (RFC) specifies Version 1.3 of the Transport Layer Security (TLS) protocol. The TLS protocol provides communications security over the Internet. The protocol allows client/server applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery.
ITS Application EntityUptaneUptaneThis dosucment describes an open and secure software update system design which protects software delivered over–the–air to the computerized units of automobiles. The framework can thwart attacks from malicious actors who can compromise servers and networks used to sign and deliver updates. Hence, it is designed to be resilient even to the best efforts of nation state attackers. There are multiple different free open source and closed source implementations available. Uptane is integrated into Automotive Grade Linux, an open source system currently used by many large OEMs and has also been adopted by a number of U.S. and international manufacturers.
FacilitiesUptaneUptaneThis dosucment describes an open and secure software update system design which protects software delivered over–the–air to the computerized units of automobiles. The framework can thwart attacks from malicious actors who can compromise servers and networks used to sign and deliver updates. Hence, it is designed to be resilient even to the best efforts of nation state attackers. There are multiple different free open source and closed source implementations available. Uptane is integrated into Automotive Grade Linux, an open source system currently used by many large OEMs and has also been adopted by a number of U.S. and international manufacturers.
TransNetIETF RFC 2460Internet Protocol, Version 6 (IPv6) SpecificationThis standard (RFC) specifies version 6 of the Internet Protocol (IPv6), also sometimes referred to as IP Next Generation or IPng.
TransNetIETF RFC 4291IP Version 6 Addressing ArchitectureThis standard (RFC) defines the addressing architecture of the IP Version 6 (IPv6) protocol. It includes the IPv6 addressing model, text representations of IPv6 addresses, definition of IPv6 unicast addresses, anycast addresses, and multicast addresses, and an IPv6 node's required addresses.
TransNetIETF RFC 4443Internet Control Message Protocol (ICMPv6) for the Internet Protocol Version 6 (IPv6) SpecificationThis standard (RFC) defines the control messages to manage IPv6.
TransNetIETF RFC 793Transmission Control ProtocolThis standard (RFC) defines the main connection–oriented Transport Layer protocol used on Internet–based networks.
Access3GPP Network3GPP Cellular Communications NetworkThis proxy standard represents a variety of 3GPP releases and underlying standards and technologies that rely upon cellular base stations for connectivity, including 3G, 4G, and the emerging 5G technologies.

Readiness: High

Readiness Description

A small number of minor issues. For existing deployments, consider addressing issues as needed as part of maintenance or upgrade activities. For new deployments, the solution is likely suitable for wide–scale deployment when applied to the triples it supports, though the noted issues should be considered and a path to addressing them developed, if needed, either as part of design or subsequent maintenance or upgrade activities.

Issues

IssueSeverityDescriptionAssociated StandardAssociated Triple
Use case not considered in design (minor)LowWhile the indicated standards nominally address the information flow, the design may not meet practical constraints because this particular use case was not the focus of the design effort.Uptane(All)

Supports Interfaces

SourceDestinationFlow
City of Akron Equipment and Fleet Service GaragesCity of Akron Emergency Vehiclesvehicle software install/upgrade
City of Akron Equipment and Fleet Service GaragesCity of Akron Maintenance Vehiclesvehicle software install/upgrade
City of Green Fleet Service GaragesCity of Green Emergency Vehiclesvehicle software install/upgrade
City of Green Fleet Service GaragesCity of Green Maintenance Vehiclesvehicle software install/upgrade
City of Hudson Equipment and Fleet Service GarageCity of Hudson Emergency Vehiclesvehicle software install/upgrade
City of Hudson Equipment and Fleet Service GarageCity of Hudson Maintenance Vehiclesvehicle software install/upgrade
City of Kent Equipment and Fleet Service GarageCity of Kent Emergency Vehiclesvehicle software install/upgrade
City of Kent Equipment and Fleet Service GarageCity of Kent Maintenance Vehiclesvehicle software install/upgrade
METRO RTA Equipment and Fleet Service FacilitiesConnected/Automated Vehiclesvehicle software install/upgrade
METRO RTA Equipment and Fleet Service FacilitiesMETRO RTA Fixed–Route Vehiclesvehicle software install/upgrade
METRO RTA Equipment and Fleet Service FacilitiesMETRO RTA Paratransit Vehiclesvehicle software install/upgrade
METRO RTA Equipment and Fleet Service FacilitiesPARTA Fixed–Route Vehiclesvehicle software install/upgrade
ODOT District Maintenance Repair FacilitiesODOT District 4 Maintenance Vehiclesvehicle software install/upgrade
ODOT District Maintenance Repair FacilitiesODOT Freeway Safety Patrol Vehiclesvehicle software install/upgrade
OTIC Equipment and Fleet Service FacilitiesOTIC Maintenance and Construction Vehiclesvehicle software install/upgrade
OTIC Equipment and Fleet Service FacilitiesOTIC Public Service Vehiclesvehicle software install/upgrade
PARTA Equipment and Fleet Service FacilitiesConnected/Automated Vehiclesvehicle software install/upgrade
PARTA Equipment and Fleet Service FacilitiesPARTA Fixed–Route Vehiclesvehicle software install/upgrade
PARTA Equipment and Fleet Service FacilitiesPARTA Paratransit Vehiclesvehicle software install/upgrade