This solution is used within the U.S.. It combines standards associated with US: NTCIP Message Sign with those for I-F: SNMPv3/TLS. The US: NTCIP Message Sign standards include upper-layer standards required to implement center-to-field message sign communications. The I-F: SNMPv3/TLS standards include lower-layer standards that support secure center-to-field and field-to-field communications using simple network management protocol (SNMPv3); implementations are strongly encouraged to use the TLS for SNMP security option for this solution to ensure adequate security.
Level | DocNum | FullName | Description |
---|---|---|---|
Mgmt | NTCIP 1201 | NTCIP Global Object (GO) Definitions | This standard defines SNMP objects (data elements) used by a wide range of field devices like time and versioning information. |
Mgmt | IETF RFC 3411 | An Architecture for Describing Simple Network Management Protocol (SNMP) Management Frameworks | This standard (RFC) defines the basic architecture for SNMPv3 and includes the definition of information objects for managing the SNMP entity's architecture. |
Mgmt | IETF RFC 3412 | Message Processing and Dispatching for the Simple Network Management Protocol (SNMP) | This standard (RFC) contains a MIB that assists in managing the message processing and dispatching subsystem of an SNMP entity. |
Mgmt | IETF RFC 3413 | Simple Network Management Protocol (SNMP) Applications | This standard (RFC) includes MIBs that allow for the configuration and management of remote Targets, Notifications, and Proxys. |
Mgmt | IETF RFC 3414 | User-based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3) | This standard (RFC) contains a MIB that assists in configuring and managing the user-based security model. |
Mgmt | IETF RFC 3415 | View-based Access Control Model (VACM) for the Simple Network Management Protocol (SNMP) | This standard (RFC) contains a MIB that supports the configuration and management of the View-based access control model of SNMP. |
Mgmt | IETF RFC 3416 | Version 2 of the Protocol Operations for the Simple Network Management Protocol (SNMP) | This standard (RFC) defines the message structure and protocol operations used by SNMPv3. |
Mgmt | IETF RFC 3418 | Management Information Base (MIB) for the Simple Network Management Protocol (SNMP) | This standard (RFC) defines the MIB to configure and manage an SNMP entity. |
Mgmt | IETF RFC 4293 | Management Information Base for the Internet Protocol (IP) | This standard (RFC) defines the MIB that manages an IP entity. |
Security | IETF RFC 6353 | Transport Layer Security (TLS) Transport Model for the Simple Network Management Protocol (SNMP) | This standard (RFC) defines how to use the TLS authentication service to provide authentication within the access control mechanism of SNMP. |
ITS Application Entity | NTCIP 1203 | NTCIP Object Definitions for Dynamic Message Signs (DMS) | This standard defines SNMP objects (data elements) for monitoring and controlling dynamic message signs (such as variable message signs). |
Facilities | IETF RFC 3411 | An Architecture for Describing Simple Network Management Protocol (SNMP) Management Frameworks | This standard (RFC) defines the basic architecture for SNMPv3 and includes the definition of information objects for managing the SNMP entity's architecture. |
Facilities | IETF RFC 3412 | Message Processing and Dispatching for the Simple Network Management Protocol (SNMP) | This standard (RFC) contains a MIB that assists in managing the message processing and dispatching subsystem of an SNMP entity. |
Facilities | IETF RFC 3413 | Simple Network Management Protocol (SNMP) Applications | This standard (RFC) includes MIBs that allow for the configuration and management of remote Targets, Notifications, and Proxys. |
Facilities | IETF RFC 3414 | User-based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3) | This standard (RFC) contains a MIB that assists in configuring and managing the user-based security model. |
Facilities | IETF RFC 3415 | View-based Access Control Model (VACM) for the Simple Network Management Protocol (SNMP) | This standard (RFC) contains a MIB that supports the configuration and management of the View-based access control model of SNMP. |
Facilities | IETF RFC 3416 | Version 2 of the Protocol Operations for the Simple Network Management Protocol (SNMP) | This standard (RFC) defines the message structure and protocol operations used by SNMPv3. |
Facilities | NTCIP 1203 | NTCIP Object Definitions for Dynamic Message Signs (DMS) | This standard defines SNMP objects (data elements) for monitoring and controlling dynamic message signs (such as variable message signs). |
TransNet | IETF RFC 2460 | Internet Protocol, Version 6 (IPv6) Specification | This standard (RFC) specifies version 6 of the Internet Protocol (IPv6), also sometimes referred to as IP Next Generation or IPng. |
TransNet | IETF RFC 4291 | IP Version 6 Addressing Architecture | This standard (RFC) defines the addressing architecture of the IP Version 6 (IPv6) protocol. It includes the IPv6 addressing model, text representations of IPv6 addresses, definition of IPv6 unicast addresses, anycast addresses, and multicast addresses, and an IPv6 node's required addresses. |
TransNet | IETF RFC 4443 | Internet Control Message Protocol (ICMPv6) for the Internet Protocol Version 6 (IPv6) Specification | This standard (RFC) defines the control messages to manage IPv6. |
TransNet | IETF RFC 793 | Transmission Control Protocol | This standard (RFC) defines the main connection-oriented Transport Layer protocol used on Internet-based networks. |
Access | NTCIP 2104 | NTCIP SP-Ethernet | This standard defines the Access Layer for center-to-field communications where the local connection is some variant of Ethernet. |
One significant or possibly a couple minor issues. For existing deployments, the chosen solution likely has identified security or management issues not addressed by the communications solution. Deployers should consider additional security measures, such as communications link and physical security as part of these solutions. They should also review the management issues to see if they are relevant to their deployment and would require mitigation. For new deployments, the deployment efforts should consider a path to addressing these issues as a part of their design activities. The solution does not by itself provide a fully secure implementation without additional work.
Issue | Severity | Description | Associated Standard | Associated Triple |
---|---|---|---|---|
Out of date (medium) | Medium | The standard includes normative references to other standards that have been subject to significant changes that can impact interoperability or security of systems and the industry has not specified if and how these updates should be implemented for deployments of this standard. | IETF RFC 6353 TLS for SNMP | (All) |
Update data to SNMPv3 | Low | Data has been defined for SNMPv1, but needs to be updated to SNMPv3 format. | (None) | (All) |
Use case not considered in design (minor) | Low | While the indicated standards nominally address the information flow, the design may not meet practical constraints because this particular use case was not the focus of the design effort. | (None) | NYSDOT Region 8 HVTMC Transportation Management=>lane management control=>LHTL ITS Field Equipment |
Use case not considered in design (minor) | Low | While the indicated standards nominally address the information flow, the design may not meet practical constraints because this particular use case was not the focus of the design effort. | (None) | NYSTA Bridge Maintenance Facility=>lane management control=>NYSTA ITS Field Equipment |
Use case not considered in design (minor) | Low | While the indicated standards nominally address the information flow, the design may not meet practical constraints because this particular use case was not the focus of the design effort. | (None) | NYSBA Command Center=>lane management control=>NYSBA ITS Field Equipment |
Use case not considered in design (minor) | Low | While the indicated standards nominally address the information flow, the design may not meet practical constraints because this particular use case was not the focus of the design effort. | (None) | NYSBA Command Center=>lane management control=>NYSBA Reversible Lanes |
Use case not considered in design (minor) | Low | While the indicated standards nominally address the information flow, the design may not meet practical constraints because this particular use case was not the focus of the design effort. | (None) | NYSTA Statewide Operations Center (TSOC)=>lane management control=>NYSTA ITS Field Equipment |
Use TLS for SNMP Option | Low | The standard allows for multiple security mechanisms. The only defined mechanism that meets the requirements for C-ITS is the one based on TLS. | (None) | (All) |
Source | Destination | Flow |
---|---|---|
CCHD Facility | CCHD ITS Field Equipment | roadway dynamic signage data |
CCHD ITS Field Equipment | CCHD Facility | roadway dynamic signage status |
CCHD ITS Field Equipment | NYSDOT Region 8 HVTMC Transportation Management | roadway dynamic signage status |
City of New Rochelle DPW Headquarters | Westchester County Police Department ITS Field Equipment | roadway dynamic signage data |
City of New Rochelle DPW Maintenance Facility | Private Road Maintenance Contractor ITS Field Equipment | roadway dynamic signage data |
City of White Plains TDP ITS Field Equipment | City of White Plains TDP Traffic Management | roadway dynamic signage status |
City of White Plains TDP Traffic Management | City of White Plains TDP ITS Field Equipment | roadway dynamic signage data |
NYSBA Command Center | NYSBA ITS Field Equipment | lane management control |
NYSBA Command Center | NYSBA ITS Field Equipment | roadway dynamic signage data |
NYSBA Command Center | NYSBA Reversible Lanes | lane management control |
NYSBA ITS Field Equipment | NYSBA Command Center | roadway dynamic signage status |
NYSBA ITS Field Equipment | NYSBA Maintenance and Construction Management | roadway dynamic signage status |
NYSBA Maintenance and Construction Management | NYSBA ITS Field Equipment | roadway dynamic signage data |
NYSDOT 8-1 Maintenance ITS Field Equipment | NYSDOT 8-1 Maintenance Management System | roadway dynamic signage status |
NYSDOT 8-1 Maintenance ITS Field Equipment | NYSDOT Region 8 HVTMC Transportation Management | roadway dynamic signage status |
NYSDOT 8-1 Maintenance Management System | NYSDOT 8-1 Maintenance ITS Field Equipment | roadway dynamic signage data |
NYSDOT Access Gates | NYSDOT Region 8 ITS Field Equipment | dynamic sign coordination |
NYSDOT Access Gates | NYSDOT Region 8 ITS Field Equipment | variable speed limit coordination |
NYSDOT Region 8 HVTMC Transportation Management | CCHD ITS Field Equipment | roadway dynamic signage data |
NYSDOT Region 8 HVTMC Transportation Management | LHTL ITS Field Equipment | lane management control |
NYSDOT Region 8 HVTMC Transportation Management | NYSDOT 8-1 Maintenance ITS Field Equipment | roadway dynamic signage data |
NYSDOT Region 8 HVTMC Transportation Management | NYSDOT Region 8 ITS Field Equipment | roadway dynamic signage data |
NYSDOT Region 8 HVTMC Transportation Management | NYSDOT Region 8 ITS Field Equipment | variable speed limit control |
NYSDOT Region 8 HVTMC Transportation Management | NYSTA ITS Field Equipment | roadway dynamic signage data |
NYSDOT Region 8 HVTMC Transportation Management | WCDPWT ITS Field Equipment | roadway dynamic signage data |
NYSDOT Region 8 ITS Field Equipment | NYSDOT Access Gates | dynamic sign coordination |
NYSDOT Region 8 ITS Field Equipment | NYSDOT Access Gates | variable speed limit coordination |
NYSDOT Region 8 ITS Field Equipment | NYSDOT Region 8 HVTMC Transportation Management | roadway dynamic signage status |
NYSDOT Region 8 ITS Field Equipment | NYSDOT Region 8 HVTMC Transportation Management | variable speed limit status |
NYSTA Bridge Maintenance Facility | NYSTA ITS Field Equipment | lane management control |
NYSTA Bridge Maintenance Facility | NYSTA ITS Field Equipment | roadway dynamic signage data |
NYSTA Bridge Maintenance Facility | NYSTA ITS Field Equipment | variable speed limit control |
NYSTA ITS Field Equipment | NYSDOT Region 8 HVTMC Transportation Management | roadway dynamic signage status |
NYSTA ITS Field Equipment | NYSTA Bridge Maintenance Facility | roadway dynamic signage status |
NYSTA ITS Field Equipment | NYSTA Bridge Maintenance Facility | variable speed limit status |
NYSTA ITS Field Equipment | NYSTA Statewide Operations Center (TSOC) | roadway dynamic signage status |
NYSTA ITS Field Equipment | NYSTA Statewide Operations Center (TSOC) | variable speed limit status |
NYSTA Statewide Operations Center (TSOC) | NYSTA ITS Field Equipment | lane management control |
NYSTA Statewide Operations Center (TSOC) | NYSTA ITS Field Equipment | roadway dynamic signage data |
NYSTA Statewide Operations Center (TSOC) | NYSTA ITS Field Equipment | variable speed limit control |
OCDPW Headquarters | Orange County Emergency Services ITS Field Equipment | roadway dynamic signage data |
PANYNJ Port Authority Agency Operations Center (PAAOC) | Private Road Maintenance Contractor ITS Field Equipment | roadway dynamic signage data |
PANYNJ Stewart Airport Operations Center | Private Road Maintenance Contractor ITS Field Equipment | roadway dynamic signage data |
Private Road Maintenance Contractor | Private Road Maintenance Contractor ITS Field Equipment | roadway dynamic signage data |
Private Road Maintenance Contractor ITS Field Equipment | City of New Rochelle DPW Maintenance Facility | roadway dynamic signage status |
Private Road Maintenance Contractor ITS Field Equipment | PANYNJ Port Authority Agency Operations Center (PAAOC) | roadway dynamic signage status |
Private Road Maintenance Contractor ITS Field Equipment | PANYNJ Stewart Airport Operations Center | roadway dynamic signage status |
Private Road Maintenance Contractor ITS Field Equipment | Private Road Maintenance Contractor | roadway dynamic signage status |
RCOFES Emergency Management | RCOFES ITS Field Equipment | roadway dynamic signage data |
RCOFES ITS Field Equipment | RCOFES Emergency Management | roadway dynamic signage status |
WCDPWT ITS Field Equipment | NYSDOT Region 8 HVTMC Transportation Management | roadway dynamic signage status |
WCDPWT ITS Field Equipment | WCDPWT Maintenance and Construction Management | roadway dynamic signage status |
WCDPWT ITS Field Equipment | WCDPWT Maintenance Facility | roadway dynamic signage status |
WCDPWT ITS Field Equipment | WCDPWT Traffic Management | roadway dynamic signage status |
WCDPWT Maintenance and Construction Management | WCDPWT ITS Field Equipment | roadway dynamic signage data |
WCDPWT Maintenance Facility | WCDPWT ITS Field Equipment | roadway dynamic signage data |
WCDPWT Traffic Management | WCDPWT ITS Field Equipment | roadway dynamic signage data |
Westchester County Police Department ITS Field Equipment | City of New Rochelle DPW Headquarters | roadway dynamic signage status |