ETSI TR 103 971-1 V2.1.1 (2026-05)
Intelligent Transport Systems (ITS); Security; Feature specific Threat, Vulnerability and Risk Analysis (TVRA); Part 1: Infield Test mode, Quantum safety; Release 2
Intelligent Transport Systems (ITS); Security; Feature specific Threat, Vulnerability and Risk Analysis (TVRA); Part 1: Infield Test mode, Quantum safety; Release 2
DTR/ITS-00546
General Information
- Status
- Not Published
- Technical Committee
- ITS WG5 - Security
- Current Stage
- 12 - Completion
- Due Date
- 07-May-2026
- Completion Date
- 06-May-2026
Frequently Asked Questions
ETSI TR 103 971-1 V2.1.1 (2026-05) is a standard published by the European Telecommunications Standards Institute (ETSI). Its full title is "Intelligent Transport Systems (ITS); Security; Feature specific Threat, Vulnerability and Risk Analysis (TVRA); Part 1: Infield Test mode, Quantum safety; Release 2". This standard covers: DTR/ITS-00546
DTR/ITS-00546
ETSI TR 103 971-1 V2.1.1 (2026-05) is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
TECHNICAL REPORT
Intelligent Transport Systems (ITS);
Security;
Feature specific Threat, Vulnerability and
Risk Analysis (TVRA);
Part 1: Infield Test mode, Quantum safety;
Release 2
2 ETSI TR 103 971-1 V2.1.1 (2026-05)
Reference
DTR/ITS-00546
Keywords
authentication, authorization, confidentiality,
security
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871
Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
No representation or warranty is made that this deliverable is technically accurate or sufficient or conforms to any law
and/or governmental rule and/or regulation and further, no representation or warranty is made of merchantability or fitness
for any particular purpose or against infringement of intellectual property rights.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.
Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part may be reproduced in any form or by any means except for the purpose of implementation of standards.
The content of the PDF version shall not be modified without the written authorization of ETSI.
The copyright and the foregoing restriction extend to reproduction in all media.
© ETSI 2026.
All rights reserved.
ETSI
3 ETSI TR 103 971-1 V2.1.1 (2026-05)
Contents
Intellectual Property Rights . 4
Foreword . 4
Modal verbs terminology . 4
1 Scope . 5
2 References . 5
2.1 Normative references . 5
2.2 Informative references . 5
3 Definition of terms, symbols and abbreviations . 6
3.1 Terms . 6
3.2 Symbols . 6
3.3 Abbreviations . 6
4 The TVRA Method . 7
Annex A: Application Note - Quantum Computing attack on cryptographic protections of
ITS . 8
A.1 Overview of threat and form of attack . 8
A.2 Scope of a quantum computing attack in ITS . 8
A.3 Impact of the quantum computing attack in ITS . 9
A.4 Risk assessment of quantum computing attack in ITS . 9
A.5 Countermeasure considerations for quantum computing attack on ITS . 9
A.6 Specific considerations for QSC in C-ITS . 10
A.7 QSC support by modification of the C-ITS security model . 12
Annex B: Application Note - Impact of in-field testing mode on ITS operation . 14
B.1 Overview of threat and form of attack . 14
B.2 Identification of delta Target Of Evaluation (TOE) . 15
B.3 Identification of security objectives . 16
B.3.1 Purpose . 16
B.3.2 Confidentiality . 16
B.3.3 Integrity . 16
B.3.4 Authenticity . 17
B.3.5 Availability . 17
B.4 Quantitative risk analysis for ITM . 17
B.5 Security countermeasure identification . 17
History . 19
ETSI
4 ETSI TR 103 971-1 V2.1.1 (2026-05)
Intellectual Property Rights
Essential patents
IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The declarations
pertaining to these essential IPRs, if any, are publicly available for ETSI members and non-members, and can be
found in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to
ETSI in respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the
ETSI IPR online database.
Pursuant to the ETSI Directives including the ETSI IPR Policy, no investigation regarding the essentiality of IPRs,
including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not
referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become,
essential to the present document.
Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners.
ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no
right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does
not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
DECT™, PLUGTESTS™, UMTS™ and the ETSI logo are trademarks of ETSI registered for the benefit of its
Members. 3GPP™, LTE™ and 5G™ logo are trademarks of ETSI registered for the benefit of its Members and of the
3GPP Organizational Partners. oneM2M™ logo is a trademark of ETSI registered for the benefit of its Members and of ®
the oneM2M Partners. GSM and the GSM logo are trademarks registered and owned by the GSM Association.
Foreword
This Technical Report (TR) has been produced by ETSI Technical Committee Intelligent Transport Systems (ITS).
The present document is part 1 of a multi-part deliverable, each part containing one of more specific application notes
documenting the TVRA results for a specific application.
Modal verbs terminology
In the present document "should", "should not", "may", "need not", "will", "will not", "can" and "cannot" are to be
interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions).
"must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation.
ETSI
5 ETSI TR 103 971-1 V2.1.1 (2026-05)
1 Scope
The present document summarizes the results of a Threat, Vulnerability and Risk Analysis (TVRA) of a number of
aspects of an Intelligent Transport System (ITS) by means of application notes. Each application note is addressed in a
distinct sub-part and considers the threat to existing and planned vehicle-to-vehicle and vehicle-to-roadside network
infrastructure communications services in the ITS Basic Set of Applications (BSA) [i.2] operating in a fully deployed
ITS.
The present document extends but does not replace previous publications addressing TVRA in ITS, e.g. in ETSI
TR 102 893 [i.16].
NOTE: Whilst the present document is a technical report it identifies requirements for future work. In all cases
these requirements are considered indicative pending their ratification in formal ETSI Technical
Specifications within the ETSI ITS Work Programme.
2 References
2.1 Normative references
Normative references are not applicable in the present document.
2.2 Informative references
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
referenced document (including any amendments) applies.
NOTE: While any hyperlinks included in this clause were valid at the time of publication ETSI cannot guarantee
their long-term validity.
The following referenced documents may be useful in implementing an ETSI deliverable or add to the reader's
understanding, but are not required for conformance to the present document.
[i.1] ETSI TS 102 165-1: "Cyber Security (CYBER); Methods and protocols; Part 1: Method and pro
forma for Threat, Vulnerability, Risk Analysis (TVRA)".
[i.2] ETSI TR 102 638: "Intelligent Transport Systems (ITS); Vehicular Communications; Basic Set of
Applications; Release 2".
[i.3] ETSI EG 203 310: "CYBER; Quantum Computing Impact on security of ICT Systems;
Recommendations on Business Continuity and Algorithm Selection".
[i.4] ETSI TR 103 619: "CYBER; Migration strategies and recommendations to Quantum Safe
schemes".
[i.5] ETSI TR 103 949: "Quantum-Safe Cryptography (QSC) Migration; ITS and C-ITS migration
study".
[i.6] ETSI TS 104 102: "Cyber Security (CYBER); Encrypted Traffic Integration (ETI); ZT-Kipling
methodology".
[i.7] ETSI TS 103 300-2: "Intelligent Transport Systems (ITS); Vulnerable Road Users (VRU)
awareness; Part 2: Functional Architecture and Requirements definition; Release 2".
[i.8] CCMB-2022-11-001: "Common Criteria for Information Technology Security Evaluation; Part 1:
Introduction and general model", November 2022, Revision 1.
[i.9] CCMB-2022-11-002: "Common Criteria for Information Technology Security Evaluation; Part 2:
Security functional components", November 2022, Revision 1.
ETSI
6 ETSI TR 103 971-1 V2.1.1 (2026-05)
[i.10] CCMB-2022-11-003: "Common Criteria for Information Technology Security Evaluation; Part 3:
Security assurance components", November 2022, Revision 1.
[i.11] FIPS 204: "Module-Lattice-Based Digital Signature Standard" (ML-DSA).
[i.12] FIPS 205: "Stateless Hash-Based Digital Signature Standard" (SLH-DSA).
[i.13] ETSI EN 303 645: "CYBER; Cyber Security for Consumer Internet of Things: Baseline
Requirements".
[i.14] ETSI TS 102 942: "Intelligent Transport Systems (ITS); Security; Access Control; Release 2".
[i.15] European Commission: "C-ITS Security - EU C-ITS security credential management system (EU
CCMS)".
[i.16] ETSI TR 102 893: "Intelligent Transport Systems (ITS); Security; Threat, Vulnerability and Risk
Analysis (TVRA)".
3 Definition of terms, symbols and abbreviations
3.1 Terms
For the purposes of the present document, the following terms apply:
ITS application: entity that defines and implements an ITS use case or a set of ITS use cases
ITS use case: specific scenario in which ITS messages are exchanged
ITS user: any ITS application or functional agent sending, receiving or accessing ITS-related information
3.2 Symbols
Void.
3.3 Abbreviations
For the purposes of the present document, the following abbreviations apply:
AA Attribute Authority
ABAC Attribute Based Access Control
CAM Cooperative Awareness Message
CRQC Cryptographically Relevant Quantum Computer
DENM Decentralized Environmental Notification Message
DTS Dedicated Test System
ECDLP Elliptic Curve Discrete Logarithm Problem
ECDSA Elliptic Curve Digital Signature Algorithm
ExVe External to Vehicle
FALCON Fast Fourier Lattice-based Compact Signatures over NTRU
FEC Forward Error Correction
IFI In-Field Inspection
ITM Infield Test Mode
ITS Intelligent Transport System
ITS-S ITS Station
MER Message Error Rate
ML-DSA Module-Lattice-based Digital Signature Algorithm
PKI Public Keying Infrastructure
PP Protection Profile
PTI Periodic Technical Inspection
QoS Quality of Service
ETSI
7 ETSI TR 103 971-1 V2.1.1 (2026-05)
RF Radio Frequency
SLH-DSA StateLess Hash-based Digital Signature Algorithm
SSP Service Specific Permissions
SUT System Under Test
SVI Secure Vehicle Interface
ToE Target of Evaluation
TVRA Threat, Vulnerability and Risk Analysis
ZT Zero Trust
4 The TVRA Method
The ETSI Threat, Vulnerability and Risk Analysis (TVRA) [i.1] is used to identify risks to a system by isolating the
vulnerabilities of the system, assessing the likelihood of a malicious attack on that vulnerability and determining the
impact that such an attack will have on the system.
In addition the present document applies parts of the ZT-Kipling Method described in ETSI TS 104 102 [i.6] in order to
assist in identifying the role and purpose of assets in the system under evaluation.
For ease of use in translating the recommendations of the present document into a Protection Profile (PP) as may be
required for certification purposes certain elements of the text are written in a Common Criteria [i.8], [i.9] and [i.10]
relevant format.
The application of the TVRA method to specific applications is addressed in the present document in Annex A,
addressing the threat of a Quantum Computing attack on cryptographic protections of ITS, and in Annex B, addressing
the threat and impact of in-field testing mode on ITS operation.
ETSI
8 ETSI TR 103 971-1 V2.1.1 (2026-05)
Annex A:
Application Note - Quantum Computing attack on
cryptographic protections of ITS
A.1 Overview of threat and form of attack
As outlined in ETSI EG 203 310 [i.3] all cryptographic algorithms should be considered to have a finite lifetime, where
that lifetime is determined in part by advances in cryptanalysis, by advances in computing, and by advances in the
underlying mathematical knowledge that underpins cryptology. In the domain of quantum computing there is a step
change in the way that computing attacks on cryptographic algorithms will occur. With the advent of realizable
Quantum Computers everything that has been transmitted or stored and that has been protected by one of the known to
be vulnerable algorithms, or that will ever be stored or transmitted, will become unprotected and thus vulnerable to
public disclosure. As the known to be vulnerable algorithms include those used in C-ITS/ITS the threat to C-ITS/ITS is
considered in the present document.
The function of a quantum computer is summarized in Annex A of ETSI EG 203 310 [i.3] and a summary of each of
Shor's and Grover's algorithms can be found in Annexes B and C respectively of the same document. For the purposes
of the present document the threat or attack can be simplified to a statement that the existence of a viable quantum
computer invalidates any security assertion made by existing asymmetric cryptographic technology, and specifically the
primary quantum threat to Elliptic Curve Digital Signature Algorithm (ECDSA) as used in C-ITS is that a sufficiently
powerful quantum computer could use Shor's algorithm to solve the Elliptic Curve Discrete Logarithm Problem
(ECDLP) in polynomial time, allowing an attacker to calculate a private key from a public key. This would enable an
attacker to forge the signatures that are used to build trust in the attribute attestations of C-ITS.
The threat can be written in a Common Criteria [i.8], [i.9] and [i.10] format as follows where the primary threat is
masquerade as shown:
T.Masquerade: An attacker with a quantum computer and access to any public key certificate can determine the
associated private key and masquerade as the private key holder
T.UnauthorizedOperation: An attacker with a compromised identity can perform operations with the privilege of the
masqueraded identity.
NOTE: As the primary threat is that no presented identity is trustable given that a quantum computer can be used
to recover the private key of any key pair then any subsequent use of the compromised identity is
secondary and only by removal of the masquerade threat can the system be restored to normal operation.
A.2 Scope of a quantum computing attack in ITS
Following the practice of ETSI TS 102 165-1 [i.1] to identify the assets in the system and their interactions that are
impacted by a particular attack the present document asserts the following:
• All cryptographic assets, technical operations, stores and management operations of the ITS system are
impacted.
The assessment made in ETSI TR 103 949 [i.5] is that where C-ITS/ITS uses elliptical curve cryptography there is a
substantial risk of masquerade (impersonation attack) and that can lead to collapse of the required trust model. ETSI
TR 103 949 [i.5] only explicitly analysed the keying infrastructure and then implicitly the application of cryptographic
operations that are dependent on that infrastructure. The attack considered is the application of a quantum computer in
such a way that any public key certificate can be processed to recover the matching private key. Once a private key is
recovered there is no way to determine the authenticity of anything protected by that private key.
ETSI
9 ETSI TR 103 971-1 V2.1.1 (2026-05)
A.3 Impact of the quantum computing attack in ITS
The assessment of the impact to ITS and C-ITS as a whole by the existence of a Cryptographically Relevant Quantum
Computer (CRQC) is that it is High. In using current elliptical curve cryptography there is a substantial risk of
masquerade (impersonation attack) and that can lead to collapse of the required trust model.
A.4 Risk assessment of quantum computing attack in ITS
Applying the risk model from ETSI TS 102 165-1 [i.1] there is some uncertainty on the timetable for when a QC will
exist but once it exists the impact will be High, and the likelihood of an attack similarly considered as Likely, leading to
critical risk (see Table A.1).
Table A.1: Risk assessment for the application of a CRQC to ITS/C-ITS keying infrastructure
NOTE: The assessment of factors for the attack makes an assumption that Quantum Computing resources will be
widely available using web-services with most development environments also making APIs available to
access such resources hence the rating of "Standard" for equipment. In addition the time taken to develop
and launch an attack is assessed to be very low as there is a lot of already published knowledge of how to
use QCs in attacks to recover private keys.
The analysis is independent of the specific nature of any ITS/C-ITS solution as the loss of trust in the entire suite of ITS
models is what is critical.
A.5 Countermeasure considerations for quantum
computing attack on ITS
The risk to ITS of a Quantum Computer applied to the keying infrastructure is critical and the mitigation is non-trivial.
Whilst quantum safe cryptographic algorithms exist they require substantially more bandwidth than any current
algorithm. This addresses not just signature and key sizes for transmission but also the processing required to create and
verify signatures.
Whilst C-ITS/ITS systems generally have been designed with crypto-agility in mind the scale of ITS systems, having
very large numbers of stakeholders and a considerably larger number of impacted devices, requires that migration to a
post quantum environment (i.e. one that is fully quantum safe) is considered as a critical task. The process of migration
is described in ETSI TR 103 619 [i.4] and for ITS in ETSI TR 103 949 [i.5].
All ITS-Ss will be required to be Quantum Safe.
ETSI
10 ETSI TR 103 971-1 V2.1.1 (2026-05)
A.6 Specific considerations for QSC in C-ITS
A standard ECDSA signature size is approximately twice the length of the underlying elliptic curve's key size, or
approximately 64 bytes (512 bits) for a 32 byte (256-bit) curve. The performance requirement identified in ETSI
TS 103 300-2 [i.7] and stated in clause 5.3.3 of [i.7] as OSEC01 "The security processes shall support generating
messages at a rate of 10 Hz, receiving messages at a rate of 2 KHz, latency of 300 ms end-to-end and an average sent
packet size over 1 s of 300 bytes". Each message is assumed to be signed and the verification key available, this means
2 000 signature verifications per second, and 10 signature creations per second. The channel capacity at 5,9 GHz for
C-ITS is not particularly impacted (the 10 MHz channels can comfortably cope with several 10 s of Mb/s of data traffic)
although with normal radio conditions the more data that is contained in a packet the greater the chance of packet loss
even with reasonably robust Forward Error Correction (FEC) added at lower layers. C-ITS is predicated on a datagram
transmission protocol with no linkage between transmitted packets and the QoS is defined as best effort all informed,
particularly for CAM (i.e. all me
...



