Source-linked AI summary

Securing Vehicle-to-Everything (V2X) Communication Platforms

Monowar Hasan, Sibin Mohan, Takayuki Shimizu, Hongsheng Lu

arXiv:2003.07191v1cs.NIcs.CR

TL;DR

V2X platforms create security and privacy challenges as vehicles exchange information across connected entities. This survey synthesizes threats, standards, and defense mechanisms from over 150 papers, identifying gaps and open issues; falsified location information can reduce message delivery efficiency by up to approximately 90%.

  • Problem

    V2X lacks a comprehensive summary of its security challenges, standardization activities, and existing solutions despite increasing exposure to attacks.

  • Method

    The survey analyzes over 150 vehicular-security papers published from 1994–2019 and reviews standards, threats, detection approaches, and security solutions.

  • Results

    Falsified location information can decrease message delivery efficiency by up to approximately 90%.

  • Takeaways & Limitations

    The survey identifies semantic gaps in existing V2X security solutions and outlines possible open issues for securing V2X communications.

Abstract

from arXiv · show

Modern vehicular wireless technology enables vehicles to exchange information at any time, from any place, to any network -- forms the vehicle-to-everything (V2X) communication platforms. Despite benefits, V2X applications also face great challenges to security and privacy -- a very valid concern since breaches are not uncommon in automotive communication networks and applications. In this survey, we provide an extensive overview of V2X ecosystem. We also review main security/privacy issues, current standardization activities and existing defense mechanisms proposed within the V2X domain. We then identified semantic gaps of existing security solutions and outline possible open issues.

I. INTRODUCTION

V2X connects vehicles with pedestrians, infrastructure, roads, cloud platforms, and other networked entities, but expanded connectivity introduces security and privacy risks. This survey addresses the need for comprehensive coverage by reviewing threats, standards, defenses, and open issues.

  • V2X communications support vehicle-to-vehicle, vehicle-to-infrastructure, vehicle-to-pedestrian, and vehicle-to-cloud connections.
  • Additional computing and connectivity increase vehicles’ exposure to vulnerabilities, including attacks that can induce incorrect driving responses.A malicious vehicle may broadcast false traffic or accident observations, causing others to slow down or reroute.
  • Attacks on vehicular communication systems can cause data loss, component failure, and damage to the environment or infrastructure.
  • Methodology and Contributions: The survey studies over 150 papers published from 1994–2019 and excludes work not directly related to vehicular communication security.It focuses on malicious abnormal behavior and primarily examines V2X communication security.
  • Methodology and Contributions: The paper reviews V2X security and privacy standardization activities, classifies threats, develops a misbehavior-detection taxonomy, and analyzes existing security solutions.
  • Methodology and Contributions: The survey also discusses open issues, summarizes securing initiatives, and compares its coverage with related surveys.

II. V2X PLATFORM : AN OVERVIEW

V2X platforms connect vehicles through multiple communication modes and standards, using external interfaces linked to vehicle control systems. IEEE 802.11p-based systems support standardized safety messaging, while common BSM, CAM, and DENM messages are transmitted without encryption.

  • Communication Interfaces: Vehicle external interfaces connect through the telematics control unit, or OBU, while the vehicle control unit collects and disseminates vehicular data.The architecture includes interconnected ECUs coupled with sensors and actuators.
  • Communication Interfaces: Current regional V2X standards include DSRC in the United States, C-ITS in Europe, and ITS Connect in Japan.DSRC and C-ITS operate in the 5.9 GHz ITS band, whereas ITS Connect operates in the 760 MHz band.
  • Communication Interfaces: V2X includes V2V, V2P, V2I, V2C, V2N, and V2I2V communications using IEEE 802.11p-based or LTE-based technologies.Entities may communicate directly or through infrastructure.
  • IEEE 802.11p-based V2X Communications: IEEE 802.11p-based V2X technology is mature and deployed in several countries.
  • Communication Models: V2X messages use broadcast, unicast, or multicast patterns for applications including traffic optimization, cooperative cruise control, and lane-change warnings.
  • IEEE 802.11p-based V2X Communications: BSM, CAM, and DENM convey periodic or event-driven safety information, but these messages are transmitted unencrypted.BSM periodic messages can be sent at a maximum rate of 10 Hz; DENMs can target specific geographical areas through multiple-hop geocast.

2) LTE-based V2X Communications:

LTE-V2X supports direct vehicle communication over PC5 sidelinks, with resource scheduling either assisted by base stations or selected autonomously. The survey focuses mainly on direct V2X security and discusses PKI-based credential management and LTE-V2X scope boundaries.

  • LTE-V2X communication modes: LTE-V2X extends 3GPP device-to-device functionality to support direct vehicle communication over the PC5 sidelink interface.Release 12 introduced ProSe-based sidelink communication, while Release 14 extended it for LTE-V2X.
  • LTE-V2X communication modes: PC5 mode 3 uses base-station scheduling through Uu links, whereas mode 4 autonomously selects sidelink resources without base-station assistance.Both modes use PC5 for communication among vehicles.
  • Scope and comparison: LTE-V2X is described as offering larger coverage than DSRC/C-ITS, but the technology remains under development and lacks real-environment safety-application trials.The survey therefore primarily examines DSRC/C-ITS security while also discussing LTE-V2X challenges and solutions.
  • Security and PKI: The survey mainly addresses direct V2X communication scenarios and reviews asymmetric-cryptography solutions using PKI to manage vehicle security credentials.PKI associates each vehicle with an asymmetric key pair and certificate, supporting secure message exchange.
  • Security and PKI: A generic V2X PKI includes communication nodes, a root of trust, authorization entities, a distribution center, and an operator.The root certification authority provides certificates to authorization entities, which issue certificates to communication nodes.

B. Standardization Efforts for V2X Security

V2X security standardization spans IEEE and SAE in the United States and ETSI and CEN in Europe. The surveyed frameworks address architecture, cryptography, certificates, privacy, and misbehavior detection through complementary standards and authorities.

  • Standardization organizations: IEEE and SAE are the principal United States organizations, while ETSI and CEN are the relevant European standardization organizations for V2X.Dedicated working groups address V2X security and privacy issues.
  • Misbehavior detection: CAMP-VSC defines misbehavior as willful or inadvertent transmission of incorrect data and proposes local and threshold-based global detection methods.Misbehavior reports can include BSM metadata, detection method, and suspected misbehavior timing and location before submission to SCMS.
  • Core standards: WAVE/DSRC and ETSI-ITS are major V2X standardization frameworks reviewed by the survey.SAE specifies performance requirements such as SAE J2945/1, while ETSI-ITS includes architecture, protocol-stack, security requirements, and mechanisms.
  • Cryptographic services: IEEE 1609.2 provides message authenticity and integrity through digital signatures, including ECDSA, and uses ECIES for transporting symmetric encryption keys.Receivers verify signatures with the sender’s associated certificate.
  • Certificates and privacy: ETSI architectures use an enrolment authority and an authorisation authority, with pseudonymous certificates intended to preserve vehicle identity privacy.Vehicles authenticate to the enrolment authority and use pseudonymous certificates when requesting service access.
  • Security scope: ETSI-ITS security standardization covers security management, trust and privacy models, threat and risk analysis, message and certificate formats, and PKI mapping with IEEE 1609.2.The ITS Forum in Japan additionally recommends encryption, key-leak countermeasures, and protection of stored vehicle and RSU information.

2) Harmonization Efforts:

United States–Europe harmonization efforts targeted interoperable security standards and communications protocols while identifying policy and regulatory needs. The surrounding survey framework categorizes attacker models and major V2X threats across communication scenarios.

  • Harmonization efforts: HTG1 sought to harmonize security standards from CEN, ETSI, and IEEE and promote cooperative V2X interoperability.HTG3 addressed harmonization of communications protocols.
  • Harmonization efforts: The harmonization task groups provided feedback to standardization organizations and identified areas where policy or regulatory action could improve V2X security.The harmonization efforts were completed in 2013.
  • Threat models: V2X security threats vary with attacker capabilities and access to vehicles, roadside units, or communication channels.Motivations include physical damage, financial gain, and non-monetary benefits such as improved traffic conditions or reputation.
  • Threat models: Attackers may be active, interacting with or disrupting the system, or passive, eavesdropping on sensitive data without direct interaction.Examples include false-data injection, denial of service, data alteration, and theft of private keys or certificates.
  • Attacker access: Internal attackers can follow the protocol while sending false or tampered information, whereas external attackers may lack valid access and passively eavesdrop on communications.The cited classification does not require external attackers to have physical system access.
  • Attack coverage: The survey focuses on attacks executable within existing V2X security mechanisms, emphasizing DoS, Sybil, and false-data-injection attacks.These attacks are summarized across communication scenarios and major threat categories.

1) DoS Attacks:

Denial-of-service attacks disrupt V2X availability through overload, jamming, or packet manipulation across network layers. Their effects can be geographically bounded or safety-critical, while related attack variants can exploit identities and injected information.

  • DoS mechanisms: DoS attacks overload a system with more requests than it can handle and can target different network layers.Distributed DoS attacks launch from multiple locations, making detection harder.
  • Physical-layer DoS: Jamming disrupts physical-layer communication through electromagnetic interference and can filter or limit incoming messages.Jamming generally requires no knowledge of exchanged-message semantics.
  • Physical-layer DoS: Physical-layer jamming around IEEE 802.11p or the 5.9 GHz bands is restricted by attackers’ wireless range and does not affect V2X communications everywhere.The cited limitation is geographic rather than semantic.
  • Network-layer DoS: Routing-based DoS such as JellyFish delays or periodically drops packets by exploiting congestion-control vulnerabilities.Packet dropping can prevent accident-warning messages from reaching other vehicles.
  • Related attack variants: Sybil attackers use multiple certified key pairs or pseudonyms to appear as multiple vehicles and can thereby support DoS or false road-condition reports.They may also manipulate reputation or trust scores assigned to vehicles.
  • False-data injection: False-data injection can broadcast incorrect traffic or safety information, and falsified location information can decrease message-delivery efficiency by up to approximately 90%.CACC is specifically reported as vulnerable to false-data-injection attacks.
  • False-data injection: Replay attacks retransmit previously authenticated messages after their original event conditions are no longer valid.The survey describes location-based replay as moving an authenticated message from location L_i to location L_j before rebroadcasting it.

V. MISBEHAVIOR IN V2X COMMUNICATIONS

In V2X security literature, misbehavior generally concerns malicious entities transmitting erroneous data, while this paper uses misbehavior detection for uncovering malicious entities. The section organizes detection and prevention approaches, including proactive credential-based mechanisms and reactive entity- or data-centric mechanisms.

  • Misbehavior commonly denotes malicious entities transmitting erroneous data, unlike faulty nodes that produce inaccurate data without malicious intent.The literature does not use these definitions consistently.
  • This paper uses “misbehavior detection” to mean uncovering malicious entities.
  • The section describes adversarial capabilities and summarizes diverse misbehavior detection mechanisms.
  • The assumed attacker possesses communication credentials and can distribute bogus information, including false, concealed, or tampered message content.
  • Proactive mechanisms use policies such as PKI, digital signatures, certificates, and tamper-proof hardware, but legitimate insiders can still generate false information.These mechanisms also face scalability and management challenges involving keys, revocation, and trust establishment.
  • Entity-centric detection includes behavioral and trust-based approaches, whereas data-centric mechanisms correlate received information with historical information or behavior.

VI. DOS AND SYBIL ATTACK DETECTION

The survey groups DoS and Sybil detection mechanisms by attack type and infrastructure support. Proposed defenses span radio, traffic, routing, trust, threshold, identity, model-based, and physical-layer techniques, with application-specific limitations.

  • DoS Attack Detection/Mitigation: DoS defenses address attacks at varying layers, including jamming, flooding, packet dropping, and distributed denial-of-service scenarios.
  • DoS Attack Detection/Mitigation: Jamming-based DoS can be detected through radio-interference patterns, statistical network-traffic analysis, and data-mining methods.
  • DoS Attack Detection/Mitigation: Watchdog mechanisms detect repeated packet dropping by estimating neighbor trust from sent-versus-forwarded packet ratios.Collisions can also prevent forwarding, so packet loss is not uniquely attributable to attacks.
  • DoS Attack Detection/Mitigation: Adaptive message-rate thresholds can detect flooding-based DoS, but the cited scheme is designed for vehicles communicating with a single RSU and may not scale generically.
  • Sybil Attack Detection: Sybil detection approaches operate either without infrastructure or with RSU, PKI, or trusted-authority assistance.
  • Sybil Attack Detection: One infrastructure-free approach compares neighboring vehicles’ tables over time, but short attacks evade it and traffic jams can increase false positives or detection latency.The approach also incurs high communication overhead and detection latency.
  • Sybil Attack Detection: Other Sybil defenses use witness signatures, local network models and sensors, or signal-strength and RSSI measurements to identify inconsistent identities or positions.

2) RSU-assisted Sybil Detection:

RSU-assisted Sybil detection uses centralized infrastructure to verify claimed positions and identify suspicious nodes. The broader section frames V2X integrity checking across events, messages, locations, and reputation.

  • Centralized Sybil-detection mechanisms use authorities such as RSUs to identify Sybil nodes.
  • One approach assigns vehicles claimer, witness, and verifier roles, using witness-measured signal strength to verify claimed positions.
  • V2X communication integrity can be checked through event validation, message-integrity checks, location verification, and reputation analysis.

A. Event Validation

Event-validation mechanisms assess message correctness by combining evidence from sensors, infrastructure, witnesses, subsequent behavior, and vehicle trajectories. These approaches trade validation coverage against communication, authentication, privacy, or accuracy constraints.

  • The certainty-of-event curve combines local-sensor, RSU, and vehicle-message evidence to assign confidence to received events using a threshold curve.
  • Voting-based event validation collects witness signatures, but insufficient signatures can cause events to be missed completely.
  • Post-event detection uses subsequent driver behavior and root-cause analysis to assess whether a post-crash notification or part of its content was false.
  • VEBAS analyzes neighboring vehicles’ messages with behavioral and trust-based mechanisms, then broadcasts trust scores within the single-hop neighborhood.
  • MisDis records each vehicle peer’s sent and received messages in secure logs so vehicles can independently assess deviations from expected behavior.It requires strong identification and authentication, does not discuss privacy preservation, and lacks performance evaluation.
  • Position and behavior validation compares radar information, received GPS data, CAM trajectories, and physical-layer measurements to isolate malicious or inconsistent nodes.Proposed measurements include signal angle of arrival, Doppler speed, and extended Kalman filter estimation.
  • Dead reckoning can detect spoofed GPS information, but its calculated position is only an approximation.

D. Reputation Analysis and Revocation

V2X reputation and revocation research uses statistical, Bayesian, clustering, and voting-based mechanisms to identify malicious vehicles, but practical response, trust assumptions, scalability, and deployment remain open concerns.

  • Reputation Analysis: Statistical and Bayesian approaches estimate traffic consistency or a vehicle’s probability of maliciousness from observations.Bayesian schemes require prior message-reception probabilities, whose derivation for generic V2X use cases is unspecified.
  • Reputation Analysis: LEAVE uses entropy-based measurement, k-means clustering, neighbor accusations, and majority comparison to detect misbehaving vehicles.Contradictory high-velocity information can identify a vehicle whose messages differ from neighboring vehicles’ majority reports.
  • Revocation: Voting-based schemes may require pseudonym mechanisms to prevent vehicles from using multiple pseudonyms in parallel.Parallel pseudonyms can affect the interpretation of accusations and voting outcomes.
  • Design Considerations: Existing V2X security solutions often impose high computation and delay overheads and have been evaluated only under limited operating conditions.The paper also identifies trade-offs involving false positives, CRL size, complexity, and RSU availability, alongside limited comparison and feasibility studies.
  • Revocation: Efficient response mechanisms remain an open issue, particularly for DoS/DDoS attacks where responding is described as almost impossible.The literature focuses more on detecting misbehavior than on designing effective responses.
  • Deployment: Full V2X deployment faces infrastructure and fleet implementation costs, including the costs of RSUs and PKI.Installation and maintenance are identified as practical obstacles to widespread implementation.

B. Security Issues for LTE-V2X

LTE-V2X security spans authentication, privacy, base-station control, and in-vehicle attack surfaces, while associated projects and standards address architecture, testing, and protection mechanisms.

  • LTE-V2X Security Requirements: 3GPP requires authenticated message origins and protection against long-term vehicle identification from transmissions.Suggested measures include protecting permanent identities and minimizing their exposure through pseudonyms.
  • Privacy: LTE-V2X privacy remains exposed because subscriber-ID associations can compromise vehicle privacy, while PC5 specifications do not impose additional privacy mechanisms.3GPP Release 14 leaves PC5 privacy mechanisms to regional regulators and operators, despite recommending identifier changes and randomization.
  • Base-Station Security: Centralized LTE-V2X modes create risks if attackers control base stations, including scheduling manipulation, resource collisions, and incorrect network configuration.The passage also identifies potential location-information exposure from compromised base stations.
  • In-Vehicle Security: Vehicle attack surfaces include sensors, localization modules, and in-vehicle user devices, while intra-vehicle attacks can threaten cryptographic secrets and safety-critical functions.Examples include side-channel key inference and denial-of-service attacks affecting steering, braking, LiDAR, or camera systems.
  • Defense Mechanisms: Proposed ECU and CAN protections include hardware security modules, isolation, secure OTA updates, message encryption, authentication, and intrusion detection.Replacing CAN does not eliminate the applicability of security measures built above the bus.
  • Security Projects: V2X security projects in Europe and the United States address secure onboard architecture, protocols, privacy, legal requirements, mobility, and real-world testing.EVITA focuses on onboard protection, while simTD investigated secure V2X systems through field tests.

B. Related Surveys

Existing surveys cover many vehicular security and privacy topics, but often concentrate on selected attack classes, cryptographic countermeasures, or broad overviews without sufficient detection detail.

  • Prior Coverage: Earlier surveys address functional requirements, protocols, vulnerabilities, misbehavior detection, anonymous authentication, routing attacks, and false-information detection.Their scopes differ substantially across conventional vehicular networks and specific attack or countermeasure classes.
  • Scope Gaps: Some prior work focuses narrowly on false-data injection, routing-oriented attacks, or cryptographic countermeasures rather than the broader modern V2X security landscape.The paper contrasts these narrower emphases with its coverage of DSRC/C-ITS and C-V2X platforms and applications.
  • Scope Gaps: Recent broad surveys cover communication technologies, standardization, attack techniques, and security requirements but provide insufficient detail on detection mechanisms.The stated limitation follows from their broad scope.
  • This Survey: This survey aims to complement prior work by providing a holistic overview of V2X security issues and possible countermeasures.Its stated coverage includes security and privacy aspects across modern V2X platforms and applications.
  • Conclusion: The survey reviews current standards, potential threats, and detection approaches and identifies a need for layered defense to improve system resiliency.The conclusion also states that V2X security mechanisms may inform broader safety-critical cyber-physical domains.
Loading 2003.07191v1…