{"id":2319,"date":"2026-09-07T06:17:48","date_gmt":"2026-09-07T06:17:48","guid":{"rendered":"https:\/\/lillyneir.com\/?p=2319"},"modified":"2026-09-16T09:00:32","modified_gmt":"2026-09-16T09:00:32","slug":"post-quantum-risk-in-vehicle-to-infrastructure-communication","status":"publish","type":"post","link":"https:\/\/lillyneir.com\/zh\/post-quantum-risk-in-vehicle-to-infrastructure-communication\/","title":{"rendered":"Post-quantum risk in vehicle to infrastructure communication"},"content":{"rendered":"<h2>The roadside unit you install today may still be signing messages in 2040<\/h2>\n<p>Ask most people what quantum computing does to cryptography, and you get a story about stolen data sitting in an archive until someone can decrypt it. Harvest now, decrypt later. For a bank or a defence ministry, that is the first thing to worry about, and their migration plans follow sensibly from it.<\/p>\n<p>For the broadcast safety services at the heart of cooperative intelligent transport systems, the priority is different. Confidentiality is not the primary property at risk, which changes what you should be asking suppliers about vehicle-to-infrastructure communication this year.<\/p>\n<h2>Authenticity is the property that matters<\/h2>\n<p>For broadcast safety messages, confidentiality is not the primary concern. The <a href=\"https:\/\/www.etsi.org\/deliver\/etsi_tr\/103900_103999\/103949\/01.01.01_60\/tr_103949v010101p.pdf\" target=\"_blank\" rel=\"noopener\">ETSI C-ITS quantum-safe migration study<\/a> describes the model for Cooperative Awareness Messages and Decentralised Environmental Notification Messages as an all-informed broadcast, with data transmitted en clair accompanied by a signed attestation of authority.<\/p>\n<p>So the data is open by design. What carries the operational weight is authenticity, the proof that a message came from an authorised station and arrived unaltered.<\/p>\n<p>Break the signature scheme, and you don&#8217;t get to read traffic messages. You get to write them. A fabricated emergency brake warning, correctly signed, injected into a corridor at rush hour.<\/p>\n<h2>What actually signs the message<\/h2>\n<p>Worth naming the European trust structure, because migration has to happen inside it rather than around it.<\/p>\n<p>The EU C-ITS Security Credential Management System rests on the ETSI ITS security standards. <a href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/102900_102999\/102940\/02.01.01_60\/ts_102940v020101p.pdfv\" target=\"_blank\" rel=\"noopener\">ETSI TS 102 940<\/a> defines the communications security architecture, <a href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/102900_102999\/102941\/02.02.01_60\/ts_102941v020201p.pdf\" target=\"_blank\" rel=\"noopener\">ETSI TS 102 941<\/a> covers trust and privacy management, and the current <a href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/103000_103099\/103097\/02.02.01_60\/ts_103097v020201p.pdf\" target=\"_blank\" rel=\"noopener\">ETSI TS 103 097<\/a> defines security header and certificate formats.<\/p>\n<p>A Root CA sits at the top of the credential hierarchy. Below it, an Enrolment Authority issues credentials that establish station identity, while an Authorisation Authority issues authorisation tickets that define what a station is permitted to send. The station signs with the corresponding private key. Receivers validate the credential chain back to trusted roots distributed through the European Certificate Trust List.<\/p>\n<p>Security in vehicle to infrastructure communication therefore lives in the hierarchy rather than in the box on the pole: a certificate chain, a trust list, an issuance process and a revocation path. These elements have to migrate as a system. If you treat the roadside unit as the only unit of work in V2I migration planning, you have already missed most of the problem.<\/p>\n<h2>The lifecycle arithmetic<\/h2>\n<p>NIST <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2024\/08\/nist-releases-first-3-finalized-post-quantum-encryption-standards\" target=\"_blank\" rel=\"noopener\">finalised its first three post-quantum cryptography standards<\/a> in August 2024. FIPS 204 covers ML-DSA for digital signatures, published alongside ML-KEM and SLH-DSA. Those three standards are final. The wider algorithm portfolio is still evolving.<\/p>\n<p>Timing is where the sector repeats things carelessly. <a href=\"https:\/\/csrc.nist.gov\/pubs\/ir\/8547\/ipd\" target=\"_blank\" rel=\"noopener\">NIST IR 8547<\/a> remains an initial public draft. Its proposed transition plan would deprecate 112-bit public-key schemes after 2030 and disallow quantum-vulnerable public-key signature schemes, including ECDSA over P-256, after 2035.<\/p>\n<p>Read that as transition guidance, not a binding deadline. For EU and Gulf road authorities, the dates are a useful signal about where the cryptographic ecosystem is heading, not a local legal requirement.<\/p>\n<p>Now set a procurement horizon beside them. The <a href=\"https:\/\/www.etsi.org\/deliver\/etsi_tr\/103900_103999\/103949\/01.01.01_60\/tr_103949v010101p.pdf\" target=\"_blank\" rel=\"noopener\">ETSI migration study<\/a> works from field lifetimes for onboard units and some roadside units on the order of twenty years. A roadside unit tendered this year gets installed next year. Whatever signs messages in 2040 is being specified in a document someone is drafting right now.<\/p>\n<h2>Why the usual migration recipe does not fit<\/h2>\n<p>Conventional migration guidance assumes you can update systems on a schedule, in waves, with the estate converging inside a few years. <a href=\"https:\/\/www.etsi.org\/deliver\/etsi_tr\/103900_103999\/103949\/01.01.01_60\/tr_103949v010101p.pdf\" target=\"_blank\" rel=\"noopener\">ETSI&#8217;s analysis of C-ITS migration<\/a> identifies a harder constraint: vehicles may remain isolated from the trust infrastructure for long periods and move freely across national and trust boundaries.<\/p>\n<p>The migration plan therefore has to sequence interdependent assets while preserving trust continuity. That is a design requirement, and specifying it now costs less than retrofitting it later.<\/p>\n<h2>Signature size is a hard constraint here<\/h2>\n<p>Here, direct V2X radio communication parts company with a web server, and this is the part most migration commentary skips.<\/p>\n<p>In the ETSI model, an <a href=\"https:\/\/www.etsi.org\/deliver\/etsi_tr\/103900_103999\/103949\/01.01.01_60\/tr_103949v010101p.pdf\" target=\"_blank\" rel=\"noopener\">ECDSA P-256 signature<\/a> has a minimum size of 64 bytes, with the actual transmitted size depending on the encoding. For comparison, under the finalised FIPS 204 the smallest ML-DSA parameter set, ML-DSA-44, produces a <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/fips\/nist.fips.204.pdf\" target=\"_blank\" rel=\"noopener\">2,420-byte signature with a 1,312-byte public key<\/a>.<\/p>\n<p>The ETSI study works from a Cooperative Awareness Message that can reach up <a href=\"https:\/\/www.etsi.org\/deliver\/etsi_tr\/103900_103999\/103949\/01.01.01_60\/tr_103949v010101p.pdf\" target=\"_blank\" rel=\"noopener\">to 500 bytes and may be transmitted at up to 10 Hz<\/a>, on a radio channel shared with other stations in range. An ML-DSA-44 signature alone is almost five times the size of a 500-byte CAM.<\/p>\n<p>The consequence is not a tuning problem. ETSI states the mechanism plainly: G5 and CAM messages use basic link control with <a href=\"https:\/\/www.etsi.org\/deliver\/etsi_tr\/103900_103999\/103949\/01.01.01_60\/tr_103949v010101p.pdf\" target=\"_blank\" rel=\"noopener\">no windowing or retransmission capability, and message error rate degrades as message size increases<\/a>. A larger signature produces a larger message, and the radio design has to absorb the consequence.<\/p>\n<p>Falcon offers substantially smaller signatures, and NIST is developing a Falcon-derived FN-DSA standard as FIPS 206. NIST still described <a href=\"https:\/\/csrc.nist.gov\/csrc\/media\/presentations\/2026\/mpts2026-3b1\/images-media\/mpts2026-3b1-slides-nist-pqc-moody.pdf\" target=\"_blank\" rel=\"noopener\">Draft FIPS 206<\/a> as under development in 2026. Whichever way the algorithm question settles, the roadside unit needs a migration path that does not depend on today&#8217;s scheme remaining unchanged for the life of the hardware.<\/p>\n<h2>What to require in this year&#8217;s tender<\/h2>\n<p>Three things, none of them an algorithm choice.<\/p>\n<p>Crypto agility comes first, and it means more than a configurable setting. NIST defines <a href=\"https:\/\/csrc.nist.gov\/pubs\/cswp\/39\/upd1\/considerations-for-achieving-crypto-agility\/final\" target=\"_blank\" rel=\"noopener\">crypto agility<\/a> as the capability to replace and adapt cryptographic algorithms across protocols, applications, software, hardware, firmware and infrastructure while preserving security and ongoing operations.<\/p>\n<p>For the roadside estate, require a documented path for replacing cryptographic algorithms, certificate profiles and implementations without replacing the roadside hardware, with enough compute, memory and update capability to accommodate substantially larger schemes.<\/p>\n<p>Second, a certificate lifecycle you can operate at scale. Issuing, renewing and revoking credentials across thousands of stations is an operational process long before it becomes a cryptographic one, and it is the part that fails quietly.<\/p>\n<p>Third, a written migration path for the public key infrastructure, agreed before anything goes into the ground. <a href=\"https:\/\/portal.etsi.org\/webapp\/WorkProgram\/Report_WorkItem.asp?WKI_ID=78788\" target=\"_blank\" rel=\"noopener\">ETSI TR 103 949<\/a> works through what is required to identify the standards changes needed to support PQC signatures on certificate authorities and other top-level keys and to help root CAs plan the transition.<\/p>\n<p>What you are asking for today is therefore the migration path: how this estate moves from one algorithm family to the next while preserving interoperability and trust continuity.<\/p>\n<h2>The part that hardens<\/h2>\n<p>Keep deploying C-ITS where the operational case supports it. Waiting for complete cryptographic certainty would freeze infrastructure decisions for years.<\/p>\n<p>Stop deploying cryptography that cannot be changed. Put roadside units in the ground this year without crypto agility, and you are casting a 2035 problem into concrete, which happens to be the one part of a roadside installation that is genuinely hard to update.<\/p>\n<p><em>Lillyneir designs and integrates roadside infrastructure and <a href=\"https:\/\/lillyneir.com\/zh\/v2x-communication\/\">cooperative ITS systems<\/a> for road authorities and motorway operators. If you are specifying roadside equipment this year, the cryptographic lifecycle is worth an hour of the conversation. <a href=\"https:\/\/lillyneir.com\/zh\/contact\/\">\u8054\u7cfb\u6211\u4eec<\/a> our team.<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>A roadside unit signs what vehicles act on. Break the scheme and you get to write those messages, not read them. Discover what post-quantum migration asks of an estate installed today and still signing in 2040.<\/p>","protected":false},"author":4,"featured_media":2320,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"Post-quantum risk in vehicle to infrastructure communication","_seopress_titles_desc":"In cooperative ITS the property at risk is authenticity. What post-quantum migration means for vehicle to infrastructure communication and the roadside estate.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"footnotes":""},"categories":[8],"tags":[],"class_list":["post-2319","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-article"],"_links":{"self":[{"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/posts\/2319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/comments?post=2319"}],"version-history":[{"count":1,"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/posts\/2319\/revisions"}],"predecessor-version":[{"id":2321,"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/posts\/2319\/revisions\/2321"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/media\/2320"}],"wp:attachment":[{"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/media?parent=2319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/categories?post=2319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lillyneir.com\/zh\/wp-json\/wp\/v2\/tags?post=2319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}