Workshop Description
For traffic engineers and urban mobility security teams. Covers PQC migration for SCOOT/SCATS adaptive signal control, tunnel and bridge SCADA (Modbus TCP, DNP3), ANPR data protection, and V2X communication security (IEEE 1609.2, ETSI ITS-G5). Includes C-ITS PKI quantum readiness and ML-DSA latency analysis for roadside units.
Urban mobility infrastructure combines several systems with distinct quantum exposure profiles. SCOOT and SCATS adaptive signal control systems use UTMC protocols with RSA/ECDSA authentication between controllers and traffic management centres. Tunnel and bridge SCADA systems run Modbus TCP, DNP3, and IEC 60870-5-104 for ventilation, lighting, and fire suppression control. These are safety-critical loops where a cryptographic compromise has physical consequences. ANPR camera networks transmit vehicle images over TLS and store RSA-signed movement records for 2-7 years, creating a concrete harvest-now-decrypt-later window. V2X communication (IEEE 1609.2, ETSI ITS-G5) uses ECDSA P-256 for certificate-based authentication of safety messages between vehicles and roadside infrastructure, with sub-100ms latency requirements that constrain PQC algorithm choice. The European C-ITS PKI trust model adds another layer: root certificate authorities must plan quantum readiness while maintaining cross-certification during transition. This workshop audits each system, measures ML-DSA verification latency on reference roadside unit processors, and builds a phased migration plan that starts with highest-risk systems (ANPR data stores, tunnel SCADA) and sequences controller firmware upgrades around existing replacement cycles.
What participants cover
- SCOOT/SCATS signal control security: UTMC protocol cryptographic dependencies, controller-to-centre authentication, and PQC firmware upgrade constraints
- Tunnel and bridge SCADA: Modbus TCP, DNP3, and IEC 60870-5-104 quantum exposure in safety-critical ventilation, lighting, and fire suppression control loops
- ANPR data protection: re-encrypting stored vehicle movement records with ML-KEM before quantum computers reach 2-7 year retention windows
- V2X communication: IEEE 1609.2 and ETSI ITS-G5 certificate authentication, ML-DSA latency constraints, and C-ITS PKI quantum readiness
- Controller replacement cycles: sequencing PQC firmware upgrades around 15-20 year traffic signal controller lifecycles and OTA capability
- Cryptographic inventory and prioritisation: mapping every TLS certificate, signing key, and authentication token across the urban mobility system