100 likes | 119 Views
Overview. Standardization for IoT / ITS security in ITU-T SG17 X.iotsec-1 X.iotsec-2 X.itssec-1 X.itssec-2 Introduction of SG20 (IoT and Smart Cities) Brief introduction of the standardization for ITS security (X.itssec-1). Ongoing Recommendations on IoT related issues in SG 17.
E N D
Overview • Standardization for IoT / ITS security in ITU-T SG17 • X.iotsec-1 • X.iotsec-2 • X.itssec-1 • X.itssec-2 • Introduction of SG20 (IoT and Smart Cities) • Brief introduction of the standardization for ITS security (X.itssec-1)
Ongoing Recommendations of IoT Security • X.iotsec-1: Simple encryption procedure for Internet of Things (IoT) environments • Timing: 2016-09/ Determination • Purpose: Provides specification of encryption with associated mask data (EAMD) for the Internet of things (IoT) devices • Includes what EAMD does and how to provide a set of security services for traffic using it • X.iotsec-2: Security framework for Internet of Things • Timing: 2018-02/ Determination • Purpose: Analyses security threats and challenges in the Internet of Things environment, and describes security capabilities that could mitigate these threats and address security challenges • Framework methodology is provided for determining which of these security capabilities are required for mitigating security threats and addressing security challenges for Internet of Things.
Ongoing Recommendations of ITS Security • X.itssec-2: Security guidelines for V2X communication systems • Timing: 2017-03 / Determination • Purpose: Provides security guidelines for V2X communication systems. V2X means Vehicle-to-Vehicle (V2V), V2I (Vehicle-to-Infrastructure) and/or V2N (Vehicle-to-Nomadic Devices) • X.itssec-1: Secure software update capability for intelligent transportation system communications devices • Timing: 2016-09/ Determination • Purpose: Provides a procedure of secure software updating for ITS communication devices for the application layer in order to prevent threats such as tampering of and malicious intrusion to communication devices on vehicles * ThisDraftRecommendationwillbeexplainedindetaillater.
Structure of a new SG 20 (IoT and Smart Cities) * Roles in SG 20 and SG 17 for IoT security and privacy should work jointly and the result of roles demarcation should be reported to TSAG (Parents SG of SG17/20 in ITU-T)
Brief introduction of X.itssec-1 • Title of Recommendation • “Secure software update capability for ITS communications devices” (X.itssec-1) • Purpose • to provide common methods to update the software by a secure procedure including security controls and protocol definition • The Recommendation would be a guideline of the baseline security for networked vehicle. • Editors • Masashi Eto (NICT) • Koji Nakao (KDDI/NICT) • Determination • Sep. 2016
Protocol Definition Upd Server at OEM Vehicle Mobile Gateway (VMG) User Interface Supplier ECU
Example of a message: diagnose (submit) Upd Server at OEM Vehicle Mobile Gateway (VMG) User Interface Supplier ECU 4. diagnose (submit)
Collaboration with industry and SDOs • This activity is highly required to collaborate with automotive industries and other standardization organizations (SDOs).