The current standards for Intelligent Transport Systems (ITSs) by the European Telecommunications Standards Institute (ETSI) rely heavily on Public Key Infrastructures (PKIs) and pseudonym-based digital certificates to provide message authenticity and user privacy in vehicular communications. Although effective, this approach introduces substantial complexity due to heavy certificate management and network overhead, particularly in cases of dense traffic. To simplify certificate management without sacrificing interoperability, this paper proposes a standard-compatible redesign of (part of) ETSI’s authentication and authorization lifecycle that replaces pseudonym-based certificates with Group Signatures (GSs). Our redesign preserves the separation of duties between Enrollment Authorities (EAs) and Authorization Authorities (AAs), balancing authenticity, unlinkability, non-repudiation, and limited anonymity. Also, we implement a proof-of-concept within the opensource C2C-Common platform using IBM’s libgroupsig library. Our benchmarks show that our redesign introduces substantial yet improvable signing and verification overheads — 3.7× and 10×, respectively — while maintaining comparable message sizes. Finally, we discuss a further ETSI-compatible extension with Attribute-Based Encryption (ABE) to introduce fine-grained access control aligned with ETSI’s permission codes and C-Roads use cases.

Revisiting the ETSI ITS Lifecycle with Certificateless Authorization Based on Group Signatures

Gennaro, Riccardo;Berlato, Stefano
;
Tomasi, Alessandro;Ranise, Silvio;
2026-01-01

Abstract

The current standards for Intelligent Transport Systems (ITSs) by the European Telecommunications Standards Institute (ETSI) rely heavily on Public Key Infrastructures (PKIs) and pseudonym-based digital certificates to provide message authenticity and user privacy in vehicular communications. Although effective, this approach introduces substantial complexity due to heavy certificate management and network overhead, particularly in cases of dense traffic. To simplify certificate management without sacrificing interoperability, this paper proposes a standard-compatible redesign of (part of) ETSI’s authentication and authorization lifecycle that replaces pseudonym-based certificates with Group Signatures (GSs). Our redesign preserves the separation of duties between Enrollment Authorities (EAs) and Authorization Authorities (AAs), balancing authenticity, unlinkability, non-repudiation, and limited anonymity. Also, we implement a proof-of-concept within the opensource C2C-Common platform using IBM’s libgroupsig library. Our benchmarks show that our redesign introduces substantial yet improvable signing and verification overheads — 3.7× and 10×, respectively — while maintaining comparable message sizes. Finally, we discuss a further ETSI-compatible extension with Attribute-Based Encryption (ABE) to introduce fine-grained access control aligned with ETSI’s permission codes and C-Roads use cases.
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11582/373007
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
social impact