Ir arriba
Información del artículo

Highway to Hack - Security gaps in ETSI ITS standards

R. Gesteira-Miñarro, T. Yoshizawa, R. Palacios, G. López

Computer Standards & Interfaces Vol. 97, pp. 104133

Resumen:

Vehicle-to-Everything (V2X) communication technologies are revolutionizing transportation by enabling real-time information exchange among vehicles, infrastructure, pedestrians, and networks. While these technologies offer significant benefits in terms of road safety, traffic efficiency, and support for autonomous driving, they also introduce critical security and privacy risks due to their decentralized and dynamic nature. In this paper, we perform an analysis of the ETSI Intelligent Transport System (ITS) standards, specifications and reports to identify vulnerabilities that could be exploited to cause cyber–physical damages. We focus particularly on Cooperative Awareness Messages (CAM) and Decentralized Environmental Notification Messages (DENM) in the ETSI ITS standard, and pseudonym ID mechanisms. We identified several security issues, including vulnerabilities that lead to replay attacks, identity-based attacks such as spoofing and Sybil attacks, as well as grayhole attacks. We present attack scenarios where the issues found can be leveraged to compromise road safety, and quantify their potential impact through simulations using Eclipse SUMO. These scenarios might be relevant during a transition period where V2X-enabled vehicles coexist with legacy vehicles. Furthermore, we propose mitigations to address the identified issues. Our findings highlight the need for stronger security measures in V2X systems to ensure both safety and security in future intelligent transportation systems.


Resumen divulgativo:

En este artículo se analizan los estándares ETSI ITS de V2X para identificar vulnerabilidades de seguridad y privacidad en CAM, DENM y los mecanismos de pseudónimos. Mostramos cómo los ataques de replay, spoofing, Sybil y grayhole pueden afectar la seguridad vial, los evaluamos mediante simulaciones con SUMO y proponemos mitigaciones.


Palabras Clave: Cooperative awareness; Vehicle-to-everything; Replay attack; Pseudonym; Simulation; Cybersecurity


Índice de impacto JCR-JIF y cuartil WoS: 4,600 - Q1 (2025)

Referencia DOI: DOI icon https://doi.org/10.1016/j.csi.2026.104133

Publicado en papel: Abril 2026.

Publicado on-line: Enero 2026.



Cita:
R. Gesteira-Miñarro, T. Yoshizawa, R. Palacios, G. López, "Highway to Hack - Security gaps in ETSI ITS standards", Computer Standards & Interfaces, Vol. 97, pp. 104133, Abril 2026. [Online: Enero 2026] doi: 10.1016/j.csi.2026.104133

    Líneas de investigación:
  • IA segura, confiable, justa e interpretable
    Grupos de investigación:
  • Instituto de Investigación Tecnológica (IIT)
    ODS:
  • Objetivo 9: Industria, innovación e infraestructuras
  • Objetivo 11: Ciudades y comunidades sostenibles

pdf Previsualizar
pdf Solicitar el artículo completo a los autores