All You Need to Know About V2X PKI Certificates: Butterfly Key Expansion and Implicit Certificates

AutoCrypt SCMS now supports Butterfly Key Expansion for both implicit and explicit certificates of the V2X PKI ecosystem. This article explains why Butterfly Key Expansion is necessary for the SCMS and why implicit certificates might be a useful alternative to conventional certificates.

Vehicle-to-everything (V2X) communication allows vehicles to communicate with other vehicles and road entities for safety warnings, traffic coordination, and eventually vehicle-infrastructure cooperated autonomous driving (VICAD). Given that these V2X messages are critical to road safety, a vehicular public key infrastructure (PKI) known as the Security Credential Management System (SCMS) has been adopted worldwide to protect the integrity of V2X messages and the privacy of road users. V2X PKI certificates, or SCMS certificates, are therefore a crucial enabler of secure V2X communications.

What Is Unique About V2X PKI Certificates?

What makes V2X PKI certificates unique? The most significant difference between IT and V2X authentication is that IT authentication is centralized and hierarchical. Users use their digital signature to reveal their identity to the server, after which the server verifies the identity and grants the user access. There is apparently no need for users to prove their identity to other users. On the other hand, V2X authentication is decentralized, where users (vehicles) need to verify each other’s identity without revealing it. Sounds contradictory? This is made possible by using pseudonym certificates.

In the SCMS, pseudonym certificates are issued by authorization certification authorities (CA) to every road user (vehicle). As suggested by its name, these certificates are pseudonymous and thus do not contain the vehicle’s identity, but instead contain proof that the vehicle’s identity had been verified by the CA and that it is a legitimate entity.

Furthermore, to prevent a stalker from spying on the same pseudonym certificate over an extended period to trace its travel routes and behaviours, pseudonym certificates have very short validity periods. For an average private vehicle, up to 20 pseudonym certificates are issued weekly, rotating every few hours to prevent tracing. These numbers can vary depending on local regulations and the importance of the passenger. For instance, the vehicle for a head of state might require non-rotating, one-time pseudonym certificates issued every five minutes.

What Is Butterfly Key Expansion?

Every time a vehicle requests a pseudonym certificate, the responsible CA needs to sign a new certificate and return it to the vehicle. Given that a typical vehicle needs up to 20 certificates per week, the CA needs to sign over a thousand certificates to a single vehicle over a year. This is a scale never seen before in the IT or financial industry. As more and more vehicles join the V2X environment, it can soon become difficult for CAs to cope with the growing number of requests.

With advancements in cryptographic construction technology, a novel approach known as Butterfly Key Expansion now overcomes this disadvantage. Butterfly Keys allow a vehicle to request an arbitrary number of certificates all at once; each certificate with a different signing key and each encrypted with a different encryption key. A request using Butterfly Key Expansion contains only one signing public key seed, one encryption public key seed, and two expansion functions that enable expansion. Therefore, Butterfly Keys are very useful for requesting pseudonym certificates as they can drastically decrease the number of requests needed.

Note that Butterfly Keys are not needed for issuing application certificates* to roadside units (RSU). Since privacy is not a concern to roadside infrastructures, application certificates are issued once at a time and have very long validity periods, meaning that application CAs are fully capable of dealing with the volume of requests.

(*Pseudonym certificates are used by vehicles for self-identification in V2V communications, whereas application certificates are used by roadside infrastructures for self-identification in V2I applications.)

Explicit vs. Implicit Certificates

Pseudonym certificates can be constructed in two different forms: conventional (explicit) certificates and implicit certificates. Conventional certificates consist of three distinct pieces of data: 1) a public key, 2) the digital signature of the CA, binding the public key to the vehicle’s identification data, and 3) the vehicle’s identification data. During V2V message transmission, the sender signs the certificate with the private key, after which the receiver uses the public key in the certificate to verify and view the message. In this process, the sender’s identity is “explicitly verified” because by opening the message, the receiver knows that the sender is the only entity holding the private key. As such, these certificates are also known as explicit certificates.

However, a disadvantage of explicit certificates is that, since they contain three distinct pieces of data, their size can range between 2,000 bits to 30,000 bits, depending on the level of security needed. Such a size isn’t a concern in and of itself. But in the V2X environment, where traffic volume is high and transmission speeds are pivotal, smaller sizes can be more advantageous.

To enable speedier message transmission and more efficient certificate issuance, a new form of V2X PKI certificate is gaining popularity. Known as implicit certificates, or Elliptic Curve Qu-Vanstone (ECQV), these certificates contain the same three pieces of data as explicit certificates do, but do not carry them as three distinct elements. Instead, the public key and the digital signature are superimposed, leaving a single reconstruction value that is similar in size as the public key. The receiver of the message uses this reconstruction value to reconstruct the public key and verify the message. The way in which the public key and the digital signature are superimposed means that by verifying the public key, the digital signature and the legitimacy of the sender get “implicitly verified”.

Since implicit certificates contain a single reconstruction value, they are much lighter and thus require much less bandwidth to transmit. The typical size of an implicit certificate is only 200 to 500 bits, which is ideal for the SCMS, where a large volume of certificates needs to be transmitted within a constrained timeframe.

The concept of implicit certificates is developed and patented by Blackberry Certicom. Nevertheless, CAs are free to issue implicit certificates for applications in the SCMS in accordance with IEEE 1609.2.

V2X PKI Regional Requirements and Preferences

As mentioned earlier, Butterfly Key Expansion is only beneficial for issuing pseudonym certificates and is not used for generating application certificates. The same is true for implicit certificates. The lightweight advantage of implicit certificates is best seen when applied to pseudonym certificates, but less significant when applied to application certificates. Given that the mechanism behind implicit certificates is more complex, some parts of the world prefer to stay with explicit certificates.

As a result, a mix of different mechanisms is used in the real world. In fact, different transport authorities have established different requirements for the certificates used in their SCMS. In North America, implicit certificates have become the standard for all V2X PKI certificates, whereas, in China, explicit certificates are required. Europe has been establishing two different standards, one for explicit certificates and one for implicit certificates.

In general, V2X PKI certificates can be constructed using four different combinations.

AutoCrypt SCMS Ready to Support All Certificate Types

In late 2022, AUTOCRYPT completed its development on the issuance of both explicit and implicit certificates with Butterfly Key Expansion, gaining the full capability to issue and provision all types of V2X PKI certificates in the SCMS.

To learn more about AUTOCRYPT’s V2X security solutions and AutoCrypt SCMS, contact global@autocrypt.io.

To stay informed and updated on the latest news about AUTOCRYPT and mobility tech, subscribe to AUTOCRYPT’s newsletter.

AUTOCRYPT Accredited by WebTrust for CAs as V2X Root Certificate Authority

SEOUL, KOREA, December 7, 2022 — AUTOCRYPT, an industry-leading provider of automotive cybersecurity and connected mobility solutions, announced that it has been officially accredited by the AICPA/CICA WebTrust Program for CAs (Certification Authorities) as a root certificate authority for the V2X-PKI ecosystem, making it Asia’s first, and the world’s third V2X root certificate authority to receive the WebTrust seal.

The WebTrust Program accredits CAs after having licensed auditors conduct extensive audits to verify that the CA has adequate management capabilities and strictly follows its Certificate Practice Statement (CPS) by properly verifying organizations and protecting its certificate keys. The WebTrust seal is an internationally recognized symbol for safe practice in PKI and cryptography, to which many organizations demand WebTrust accreditation for all CAs involved in their supply chains.

AUTOCRYPT’s V2X-PKI CA (Certificate Authorization) Service acts as a root CA that registers, issues, manages, and revokes V2X certificates to subordinate CAs, supporting SCMS standards across North America, Europe, and China. Independently operated by its self-established security certification center, the service has undergone months of external audits and monitoring prior to receiving the accreditation.

“Aligning with our vision of enabling reliable and autonomous mobility for all road users, we developed our own root CA service to help establish trust within the V2X ecosystem,” said Daniel ES Kim, CEO of AUTOCRYPT. “By providing WebTrust-accredited certificate lifecycle management for V2X CAs, we look forward to enabling a streamlined V2X deployment process for our clients and partners, as well as encouraging more V2X implementations across a wider variety of use cases.”

Apart from serving as a V2X root CA, AUTOCRYPT offers a complete security solution for the V2X ecosystem, including a security module for OBU/RSUs, an SCMS backend, and an Integrated Management System (IMS) for SCMS that enables automotive OEMs to oversee all the SCMS certificates for their fleets via a graphical user interface.

For more information regarding AUTOCRYPT’s V2X security solutions and offerings, contact global@autocrypt.io.

From Safety to Sustainability: A Look at the Short-Term Benefits of V2X

There are two major approaches to achieving autonomous driving. The first is ADAS (advanced driver-assistance systems). And the other is V2X (vehicle-to-everything). Although the public is now quite familiar with ADAS, V2X remains a relatively unknown field. Even among industry stakeholders, a common misconception about V2X is that it must be deployed on a mass scale to provide meaningful benefits. In this blog, we explain why V2X deployment might not be as big an investment as it might seem, by looking at some of the short-term benefits of V2X.

Why It Doesn’t Need to Be Mass Deployment

Indeed, the ultimate objective of V2X is to create a fully connected mobility ecosystem that enables a state of full driving automation (Level 5), where vehicles seamlessly communicate with their surrounding vehicles and infrastructure through exchanging messages in real-time, overcoming the shortcomings (e.g., blind spots, failed object recognition) of cameras and sensors. This approach towards autonomous driving is also referred to as Vehicle-Infrastructure Cooperated Autonomous Driving (VICAD).

However, establishing an entire V2X ecosystem is a long process, as it can take many years to transform an entire city’s transport infrastructure into V2X-enabled systems. Therefore, industry players shouldn’t solely focus on the final objective of VICAD, but instead, work towards deploying V2X for its immediate benefits. This way, consumers can start benefiting from V2X sooner, which helps generate momentum to accelerate further investment and deployment.

Imaging planning and building a subway network from scratch. Of course, the final goal is to create an interconnected network that covers the entire city. However, if the public must wait until an entire network to be completed before benefiting from it, there would be very little interest in moving the project forward. Instead, cities start by building and operating a single line to allow at least some consumers to benefit from it in the short term.

The same is true for V2X. It doesn’t need to be mass deployment before we can start to see benefits. Some case-specific applications, including Signal Phase and Timing (SPaT) and emergency vehicle preemption (EVP), have already generated some promising short-term benefits in terms of road safety and efficiency.

The Short-Term Benefits of V2X

1. Road safety

Even with selective, small-scale deployments over the short term, V2X opens the opportunity for many creative approaches to enhance road safety. For instance, V2X roadside units (RSU) can be installed onto traffic signals at selected intersections where car accidents frequently occur, enabling Signal Phase and Timing (SPaT). SPaT is a V2X application where the traffic signal informs incoming vehicles of the remaining time of the signal. When vehicles receive that information, they can automatically determine whether to continue to cruise through the intersection, slightly accelerate to pass through prior to the signal change, or gently decelerate to a full stop. Having machines do the timing and calculation can help reduce human misjudgments at intersections.

It might be tempting to think that SPaT is only beneficial when all vehicles are equipped with V2X onboard units (OBU). Of course, the more V2X-enabled vehicles there are, the more effective the use case becomes. Still, if only a quarter of vehicles were to be equipped with V2X OBUs, SPaT would make a significant difference by improving the safety record of the intersection. This is because drivers have a natural tendency to move with the flow. The behaviour of V2X-enabled vehicles will influence the behaviours of surrounding drivers, encouraging them to comply with the coordination as well, hence reducing the likelihood of dangerous acceleration and braking during yellow lights.

Installing RSUs at intersections enables another common use case known as emergency vehicle preemption (EVP), which is currently deployed in many major cities across the globe. This is where OBUs installed in ambulances and fire trucks communicate with RSUs at intersections, prompting the traffic signal to change in favour of their direction, making it a very useful application in dense city streets where emergency vehicles can easily get stuck in gridlocks.

As such, localized V2X applications like SPaT and EVP do not require mass deployment. Hence, infrastructure operators and automotive OEMs can focus primarily on these short-term benefits.

2. Traffic efficiency

Besides safety, traffic efficiency is one of the other short-term benefits of V2X. A promising V2X-enabled solution that helps increase traffic efficiency is truck platooning. This is when a fleet of trucks cruise in a row at the same speed in the formation of a train. Given that trucks take up a significant percentage of the highway, having trucks travel individually at different speeds across different lanes can slow the overall traffic and lead to potential safety hazards. By lining them up in a lane at a consistent speed, a significant amount of space can be freed up, enabling faster travel speeds, and reducing the level of congestion during peak times. Furthermore, truck drivers in the follower trucks will be able to rest during the trip, reducing the likelihood of driver fatigue, hence enhancing road safety as well.

Another localized application of V2X is smart parking. This is when RSUs equipped in parking lots communicate with OBUs in nearby vehicles to inform them about parking space availability. In busy urban centers, a great amount of aggregated time is spent on searching for parking space. Not only is it a frustrating experience to circle around a busy block looking for the nearest available parking space that doesn’t cost a fortune, but those in search of parking can add up to the existing traffic and cause further congestion. With V2X-enabled smart parking, there will be no need to roam around urban streets for parking.

3. Cost saving

Road transportation comes with a cost. Apart from fuel and maintenance costs, every minute spent sitting in traffic is an opportunity cost that can be measured in the form of lost productivity. According to the 2021 INRIX Global Traffic Scoreboard, traffic congestion in the United States costs the average driver $564 in lost productivity throughout the year, and an aggregated $53 billion to the country.

When RSUs are deployed in critical areas such as frequently congested intersections and highway merges, V2X-enabled traffic coordination like SPaT and lane merge assists can reduce congestion remarkably, thus cutting unnecessary fuel consumption and productivity loss.

4. Environmental sustainability

When it comes to sustainable transport, electric vehicles (EV) are the most effective solution that contributes directly to a reduction in carbon emissions. However, many do not realize that V2X is another promising technology that can make a positive impact on environmental sustainability.

This is because V2X is an effective energy saver. As aforementioned, since V2X applications can help coordinate traffic and reduce congestion, the average vehicle spends less time on the road, with less unnecessary acceleration and braking. This results in not just less emission, but also less electricity consumption for EVs. Although this might seem like a subtle difference for a single vehicle, the accumulated energy savings and emission cuts can make a meaningful impact on the environment.

Additionally, just like emergency vehicle preemption, OBUs can also be installed on buses and street cars so that traffic signals can give priority to public transit, making traveling by public transit more efficient and convenient, thus encouraging greater usage.

5. Convenience

Regardless of its application, a common benefit that V2X brings across all use cases is convenience. Through real-time communications, road users will be able to benefit from a smart and connected mobility environment.

Start Small, Think Big

Back to the point — V2X connectivity isn’t all about the big picture of full autonomous driving. Through vehicle-infrastructure cooperation, V2X can be utilized for a wide range of localized use cases that do not require much time and effort to deploy. Eventually, these local deployments will naturally accumulate to shape an interconnected V2X ecosystem, enabling a complete VICAD experience. Therefore, policymakers, infrastructure operators, OEMs, and investors should push forward V2X deployment by focusing primarily on its immediate benefits.

Securing V2X Communications

An integral component of V2X deployment is cybersecurity. Encryption and PKI-based authentication measures must be preestablished within the communication end-entities (OBU/RSUs) to ensure that the messages communicated via V2X are securely protected from unauthorized access and tampering. Conversely, with more and more localized V2X deployments, cybersecurity capability will continuously improve with enhanced regional security policies.

AUTOCRYPT’s secure V2X communications solution strengthens both privacy and safety for V2X applications, including a security module installable onto OBU/RSUs, a Security Credential Management System (SCMS) that issues, revokes, and manages digital certificates for end-entities, as well as an Integrated Management System (IMS) for SCMS that allows automotive OEMs to easily manage all their V2X certificates across all vehicle fleets via a graphical user interface.


To learn more about AUTOCRYPT’s V2X security solutions and offerings, contact global@autocrypt.io.

To stay informed and updated on the latest news about AUTOCRYPT and mobility tech, subscribe to AUTOCRYPT’s quarterly newsletter.

Spotlight: V2X Interoperability Testing at OmniAir Costa del Sol Plugfest

In this blog, Vice President of Autocrypt North America, Martin Totev, takes us to OmniAir Consortium’s Costa del Sol Plugfest in Malaga, Spain, held between October 24 and 28, where AUTOCRYPT provided its SCMS certificates for the testing environment.

Interoperability Across the V2X Ecosystem

Cooperative Intelligent Transport Systems (C-ITS) are making road mobility increasingly connected and adaptive, linking vehicles with road infrastructures and pedestrians, and enabling them to cooperate with one another in real-time through V2X (vehicle-to-everything) communications. Yet, although the idea might seem straightforward, industry players and regulators have been putting tremendous effort into establishing V2X interoperability, ensuring that vehicles, smart devices, and infrastructures built by different manufacturers across various domains can seamlessly communicate with each other.

How is interoperability established? At the baseline, all manufacturers must follow a set of standards and protocols for each relevant use case. These protocols are often established by regulators and industry associations. For instance, the two major technical protocols for V2X communications include WAVE (Wireless Access in Vehicular Environments) by IEEE and C-V2X (cellular V2X) by 5GAA. As such, manufacturers of onboard units (OBU) and roadside units (RSU) need to ensure that all their end-entities within a V2X environment comply with the same protocol to enable reliable message transmission.

Similarly, the technical standard for electric vehicle charging is outlined in ISO 15118, which defines the architecture for Plug&Charge (PnC) and V2G (vehicle-to-grid) bidirectional charging, providing a set of consistent specifications and guidelines for OEMs, charger manufacturers, and charge point operators (CPO) to promote a seamless EV charging ecosystem.

Why Protocols Aren’t Enough: The Need for V2X Interoperability Testing

Simply because two manufacturers follow the same standard or protocol, it doesn’t necessarily guarantee that their devices will be perfectly compatible with each other under actual implementation. As a simplified example, the standard for a universal plug may specify the width but lacks specification on the length, resulting in plugs with different lengths being incompatible despite adhering to the same standard. In practice, incompatibility issues can be much more complex, arising from a variety of underlying factors that can be difficult to pinpoint.

Given that the V2X ecosystem involves a wide range of end-entities across different domains, interoperability testing is necessary prior to mass deployment. These tests are usually conducted at a plugtest (or plugfest), which invites all relevant manufacturers to deploy their vehicles and devices in combined scenarios.

OmniAir Plugfest

OmniAir Consortium is one of the most influential associations in the C-ITS industry. It specializes in promoting interoperability between different connected entities within the V2X ecosystem, including the vehicle itself, onboard units (OBU) and roadside units (RSU), embedded communication modules, and security modules and SCMS backends.

OmniAir Consortium regularly organizes interoperability testing events—known as OmniAir Plugfests—to provide a platform for industry participants to test the cross-domain interoperability of their connected mobility technologies and devices. The most recent Costa del Sol Plugfest was held between October 24 and 28 in Malaga, Spain.

Opening ceremony of the Costa del Sol Plugfest

A wide range of bench tests were performed at the Costa del Sol Plugfest, including those involving V2X modules, message encryption, V2X-PKI certificates, SPaT message transmissions, and MAP message transmissions. Specific use cases like red light violation warning, emergency vehicle preemption, lane closure warning, curve speed warning, and many more, were tested on the field. One of the industry’s major testing and inspection firms, DEKRA, provided its testbed for the event.

As one of the more than 60 associate members of the OmniAir Consortium, and a C-ITS cybersecurity provider specialized in securing V2X connections, the AUTOCRYPT team headed to Malaga to participate in the plugfest by providing AUTOCRYPT’s SCMS certificates to the devices tested at the event.

The AUTOCRYPT team testing our SCMS certificates at Dekra’s testbed

Is C-V2X Ready?

Vice President of Autocrypt North America, Martin Totev, presented at a panel session discussing whether C-V2X is ready to be deployed for commercial use. Martin expressed his optimism on C-V2X commercialization and stressed a step-by-step deployment approach. “It doesn’t need to be mass deployment and autonomous driving straight away,” said Martin. “We can begin by deploying them in vehicles first, then intersections with frequent accidents, gradually enhancing road safety and saving lives in the long run.”

Martin also pointed out the importance of cybersecurity in V2X. “Although interoperability testing is crucial, it only marks the beginning of a continuous improvement process. In fact, more commercial deployments are needed so that security and SCMS providers like AUTOCRYPT can continuously enhance its regional security policies and strengthen its definitions for misbehaviours.”

VP of Autocrypt North America, Martin Totev, speaking about C-V2X deployment

AUTOCRYPT’s Pivotal Role in the V2X Ecosystem

AUTOCRYPT specializes in securing V2X communications. Given that vehicles rely on V2X messages for judgment and decision-making, the validity of these messages is critical to the safety and functionality of cooperative autonomous driving.

AUTOCRYPT secures V2X communications using both encryption and authentication technologies. On the frontend, a security module is embedded into each end-entity to encrypt and decrypt messages by referring to a list of SCMS certificates stored in a Local Certificate Manager (LCM). At the backend, its SCMS architecture enables the proper issuance, revocation, and verification of certificates, ensuring message validity and privacy.

To learn more about AUTOCRYPT’s V2X security solutions, contact global@autocrypt.io.

To stay informed and updated on the latest news about AUTOCRYPT and mobility tech, subscribe to AUTOCRYPT’s quarterly newsletter.

Pedestrian Safety Month: How to Achieve Zero Road Fatality with V2X?

In 2020, the US Department of Transportation (DOT)’s National Highway Traffic Safety Administration (NHTSA) designated October as National Pedestrian Safety Month, celebrating the right to safety for every user of the road. The goal is to raise public awareness and strengthen efforts on improving road safety, with an emphasis on protecting vulnerable road users (VRU). VRUs include any road user that is not protected by a metal frame, such as pedestrians, cyclists, and motorcyclists.

The Current Stance of Road Safety

According to the latest statistics published by the World Health Organization (WHO), an estimated 1.3 million people across the globe die every year from road traffic incidents, with another 20 to 50 million people suffering non-fatal injuries, many of which lead to permanent disabilities.

The good news is that in most of the developed world, the number of road fatalities has seen a steady decrease over time. This pattern is especially salient in Europe; the road fatality figure of the European Union has more than halved from 51,400 deaths recorded in 2001 to 19,800 deaths in 2021. Based on the trajectory, the EU is targeting less than 11,400 annual deaths by 2030.

Beyond Europe, a similar downward trend can be seen in other developed countries like Japan, Canada, Korea, and Australia. In fact, the United States is the only country among advanced economies where road fatality saw an increase over the past decade.

This leads us to the bad news. Unfortunately—just like the United States—many parts of the world are not seeing a decrease in road fatality, meaning that the world is becoming increasingly polarized in terms of road safety. Today, 93% of the world’s road fatalities happen in less developed countries. By working with the above figures, it can be derived that road fatality in the EU only accounts for 1.5% of the global figure, despite its population representing 5.6% of world population.

Reasons for Road Traffic Accidents

To improve road safety, the best measure is to tackle the causes of traffic accidents and prevent them in the first place. To most daily drivers, operating a vehicle can feel like a subconscious task. Despite so, driving requires an intensive amount of data processing in the subconscious mind, with countless perception-judgment cycles happening every minute. One error in any of the two processes can lead to dangerous situations and potential accidents.

As expected, most errors leading to accidents are human mistakes or flaws. For instance, errors in perception can occur under low visibility, often a result of poor weather conditions or complicated terrain. Perception errors can also be caused by a lack of attention on the road due to smartphone distraction or mental stress. Similarly, judgment errors can be caused by sleep deprivation or alcohol consumption.

Oftentimes, a fatal crash isn’t the result of a driver’s error, but an error made by a vulnerable road user. For instance, a lot of road fatalities are the result of pedestrians and cyclists disobeying signals. Hence, improving road safety requires collective efforts from all road users.

Efforts to Reduce Road Traffic Accidents

By studying the potential reasons and scenarios that could result in traffic accidents, the transportation sector and the automotive industry have made a lot of preventative and protective efforts. Thanks to these efforts, many countries have managed to reduce road fatality at a steady rate.

The most significant effort is the adoption of Advanced Driver Assistance Systems (ADAS) in newer vehicles. Features like blind spot detection, lane keep assist, collision alert, and emergency braking have contributed to a great reduction in crashes. In recent years, OEMs and ADAS suppliers have further strengthened the capability of sensor and AI-based object recognition technologies to achieve a driving automation level of L2 and up to L3. Tesla’s Autopilot is one of the most marketed examples.

Other preventative measures have also been made, such as enforcing lower speed limits, increasing penalties for traffic law violations, and more spending on educating road safety to the public. Conventional protective measures have also seen great improvements, with safer airbags and vehicle structures that are better capable of absorbing crash energy.

Why Are These Efforts Not Enough?

Although ADAS adoption has demonstrated great results in reducing traffic accidents, its influence is limited to more advanced economies. Since the cost of ADAS is mostly distributed to end consumers, most consumers in low- and mid-income economies may find it too expensive to purchase a new vehicle with all the ADAS features. This explains why most of the reduction in road fatality was observed in high-income economies.

Besides being expensive, sensors have their limitations. Regardless of the amount of machine learning fed into the algorithm, in the end, sensors are just like the human eye, which must see and identify an object before making judgments. This makes sensors prone to distortion and blind spots.

Then what else can we do to achieve zero road fatality? Perhaps we can take a look at the commercial aviation industry, which has achieved zero fatality almost every year throughout the past decade. Of course, comparing road traffic with air traffic is comparing apples to oranges. Still, one thing we can learn from air traffic coordination is that it does not rely on visibility. Decisions and flight paths are determined through wireless communication.

Why Is V2X the Ultimate Answer to Achieving Zero Road Fatality?

Wireless communication for road traffic is called V2X (Vehicle-to-Everything) communication. This allows vehicles to seamlessly communicate with surrounding vehicles, road infrastructures, and even the handheld devices of vulnerable road users, to ensure that every participant on the road can receive real-time warnings and seamlessly cooperate through what is referred to as cooperative autonomous driving.

To enable V2X connectivity, a vehicle needs to be equipped with an onboard unit (OBU), while a roadside unit (RSU) needs to be installed into every relevant road infrastructure. Smartphones are also readily available V2X connectivity units, allowing vulnerable road users carrying smartphones to enroll in the V2X ecosystem. In general, V2X connectivity units are cheaper to install and deploy than ADAS, and their long-term maintenance costs are also lower.

In the short run, V2X is a great complementary measure to ADAS. Although equipping all road users and infrastructures with V2X may take decades, municipalities can begin by installing RSUs in areas with frequent accidents and areas dangerous to pedestrian safety.

By seeing the invisible and communicating information based on facts, V2X will be the ultimate answer to zero road fatality.


As an automotive cybersecurity and mobility solutions provider, AUTOCRYPT plays a crucial role in securing V2X communications. Its V2X solution is readily installable onto OBU/RSUs, consisting of a secure communication module, a PKI backend, an Integrated Management System for SCMS, along with a root CA service for the V2X-PKI ecosystem.

To learn more about AUTOCRYPT’s V2X security offerings, contact global@autocrypt.io.

To stay informed and updated on the latest news about AUTOCRYPT and mobility tech, subscribe to AUTOCRYPT’s quarterly newsletter.

AUTOCRYPT Unveils Integrated Management System for SCMS at ITS World Congress 2022

LOS ANGELES, September 29, 2022 — AUTOCRYPT, an industry-leading C-ITS cybersecurity and smart mobility solutions provider, demonstrated its newly launched Integrated Management System (IMS) for SCMS at ITS World Congress 2022 in Los Angeles. As the sole V2X security provider for all C-ITS projects in Korea, AUTOCRYPT specializes in securing V2X, in-vehicle systems, and Plug&Charge, as well as PKI systems and certificate authorization services.

AUTOCRYPT’s IMS for SCMS is an integrated certificate management tool for the Security Credential Management System (SCMS), a PKI-based security verification system for V2X communications. IMS for SCMS enables automotive OEMs to supervise and manage all issued and revoked certificates for their vehicle fleets in real-time – across all regions – on one centralized UI.

AUTOCRYPT’s IMS for SCMS dashboard showing an overview of SCMS data in a selected region

IMS for SCMS not only provides a detailed view of all certificates and related resources, but is also equipped with automated features and services that assist with certificate management, such as system inspection and diagnostics, as well as 24/7 response for operational and technical issues. Custom-built based on the user’s needs, it is compatible with the North American SCMS, the European C-ITS CMS (CCMS), and the Chinese C-SCMS.

“At AUTOCRYPT we believe that V2X is the ultimate solution to safer transport and fully autonomous driving. One of our primary goals is to make the V2X ecosystem both secure and convenient for every party involved,” said Daniel ES Kim, CEO of AUTOCRYPT. “With the benefits of IMS for SCMS, we look forward to seeing more OEMs and infrastructure operators upscaling their V2X-enabled fleets and devices.”

Besides IMS for SCMS, AUTOCRYT’s V2X security solution includes a security module for OBUs/RSUs, V2X-PKI for road user authentication, and a root CA service that authorizes subordinate certification authorities.

To find out more about AUTOCRYPT’s V2X and automotive cybersecurity solutions, contact global@autocrypt.io.