V2X security and the C-ITS ecosystem
How vehicles trust messages from other vehicles and infrastructure — and the PKI that makes it possible
Trusting a message from a stranger
V2X — vehicle-to-everything — lets a vehicle receive and act on wireless messages from other vehicles, roadside units and networks: a warning that the car ahead has braked hard, that an emergency vehicle is approaching, that a signal is about to change. The safety benefit only exists if the receiver can trust those messages. And the sender is, by definition, a stranger: two vehicles that have never met must be able to authenticate each other's traffic in milliseconds, at highway speed, with no prior relationship.
That is the whole security problem of V2X in one sentence. It is not confidentiality — most V2X safety messages are broadcast in the clear. It is authenticity and integrity: proving a message genuinely came from a legitimate station and was not forged, altered or replayed. If an attacker could inject a credible "hard braking ahead" message into traffic, the consequences are physical, not informational.
C-ITS: the ecosystem the messages live in
C-ITS — Cooperative Intelligent Transport Systems — is the wider ecosystem: the vehicles, the roadside infrastructure, the message sets they exchange, and the trust infrastructure that underpins them. C-ITS covers vehicle-to-vehicle (V2V) cooperation, vehicle-to-infrastructure (V2I) links to traffic signals and roadside units, and the back-end services behind them. Security is not a feature bolted onto C-ITS; it is a precondition for the system doing anything useful, because every cooperative decision rests on believing a message from a party you cannot see.
The PKI that makes it work
V2X trust is built on a public-key infrastructure. Every station holds credentials issued by a trusted authority; every safety message it broadcasts is digitally signed; every receiver verifies that signature before acting. Because the receiver trusts the issuing authority, it can trust a message from a sender it has never encountered.
The twist that makes vehicle PKI distinctive is privacy. A single fixed certificate per vehicle would let anyone with a receiver track that vehicle everywhere. So V2X uses pseudonym certificates: short-lived credentials, held in pools and rotated frequently, that authenticate the message without exposing a stable identity. A misbehaving station can still be revoked, but ordinary drivers are not trivially trackable. This is a demanding infrastructure to run — issuing, distributing, rotating and revoking certificates across a large fleet — and it sits on the same key-management foundations described in automotive PKI and key management.
Where V2X sits against other authenticated links
V2X is one of several places where a vehicle must authenticate an external party using certificates. They share the PKI backbone but differ in what they protect.
| Link | What is authenticated | Privacy mechanism | Primary risk |
|---|---|---|---|
| V2X / C-ITS | Broadcast safety messages between vehicles and infrastructure | Rotating pseudonym certificates | Forged or replayed safety messages |
| EV charging (ISO 15118) | The vehicle and the charger to each other | Contract and vehicle certificates | Fraud and abuse at the charging inlet |
| OTA update | The update source to the vehicle | Signing keys held in the back end | Unsigned or tampered software |
The EV-charging case is a close cousin worth reading alongside this — see EV charging security: ISO 15118 and Plug & Charge. In all three, the vehicle is deciding whether to trust something from outside itself, and in all three the answer comes down to certificates, keys and the discipline that manages them.
The attack surface
V2X widens the vehicle's external attack surface, which is exactly the concern UN R155 Annex 5 raises under external connectivity and communication channels. The threats a V2X design must treat include:
- Message forgery and spoofing — injecting fabricated safety messages. Mitigated by mandatory signature verification and rejecting anything unsigned or invalid.
- Replay — re-broadcasting a genuine past message out of context. Mitigated by timestamps, freshness checks and geographic plausibility.
- Sybil attacks — one station forging many identities to manufacture false consensus. Mitigated by certificate issuance controls and misbehaviour detection.
- Key and certificate compromise — theft of credentials from a station. Mitigated by secure hardware storage, short certificate lifetimes and prompt revocation.
- Privacy attacks — tracking a vehicle across time. Mitigated by the pseudonym scheme itself.
None of these are edge cases. They are the working content of the Annex 5 categories a CSMS is assessed against, which is why V2X design has to feed the vehicle's threat analysis rather than sit beside it. The method for that analysis — asset, threat scenario, attack path, feasibility, risk, treatment — is the ISO/SAE 21434 TARA.
The regulatory frame
V2X does not have a single regulation of its own; it inherits obligations from several. Under UN R155, V2X interfaces are part of the vehicle's cyber security management system and its threat analysis, and the vehicle carrying them needs a CSMS certificate of compliance (valid three years) plus per-type approval. In the EU, the Cyber Resilience Act — Regulation (EU) 2024/2847 — adds horizontal obligations for products with digital elements, including secure-by-design, an SBOM and vulnerability handling, with vulnerability and incident reporting applying from 11 September 2026 and the main body of obligations from 11 December 2027. For an exporter, V2X connectivity is one more surface where both the type-approval regime and the horizontal product law apply at once.
The practical takeaway
The engineering lesson of V2X is that authentication is not optional and cannot be retrofitted cheaply. A vehicle that acts on cooperative messages must verify every one, must manage a large pseudonym-certificate estate, and must protect its keys in hardware. Those requirements land during concept and architecture, not after. Designed in, they are routine; bolted on, they are the reason a first assessment stalls.
The AutoSifu view
AutoSifu treats V2X as part of the vehicle's overall cybersecurity case, not a standalone module. We take the PKI, message-authentication and key-management design into the TARA and the CSMS, and carry it through to the evidence an assessor reads — working one route from compliance to solutioning to CoC/VTA support under R155/R156 and AIS-189/AIS-190, with our strategic partner CIRT, the approval body, in the room. Our partnership with AUTOCRYPT gives that V2X and PKI work real depth rather than a checklist.
Questions
- What is V2X security?
- V2X (vehicle-to-everything) security is the set of controls that let a vehicle trust wireless messages from other vehicles, roadside infrastructure and networks. Its core problem is authentication: a receiver must know a safety message genuinely came from a legitimate sender and was not forged or replayed. It is built primarily on a public-key infrastructure that signs every message, so a receiver can verify the sender without ever having met it.
- How are V2X messages trusted?
- Each V2X message is digitally signed by the sending station, and the receiver verifies that signature against a certificate issued by a trusted authority in a V2X PKI. To protect drivers from being tracked, senders use short-lived pseudonym certificates that rotate rather than a single fixed identity. A receiver therefore trusts the message's authenticity and validity without learning who the sender actually is.
- What is C-ITS?
- C-ITS stands for Cooperative Intelligent Transport Systems — the ecosystem in which vehicles and infrastructure exchange information to improve safety and traffic flow. It covers vehicle-to-vehicle and vehicle-to-infrastructure communication, the message sets they use, and the trust infrastructure that authenticates them. Security is foundational to C-ITS because acting on an unauthenticated safety message could be dangerous.
