
Motivation & challenges
Connected and software-defined vehicles depend on public-key cryptography to authenticate devices, protect V2X messages, manage certificates and secure software updates. Vehicles may remain operational for more than a decade, so the security mechanisms selected today must also withstand threats that may emerge during their service life. Future quantum computers could compromise widely deployed RSA- and elliptic-curve-based mechanisms, weakening both vehicle communications and the public key infrastructures that support them.
The transition is not a simple algorithm replacement. Post-quantum keys and signatures are generally larger, cryptographic operations can be more demanding for embedded hardware, and automotive applications impose strict timing and availability constraints. A viable migration path must therefore address performance, certificate lifecycle management, interoperability between different cryptographic implementations, and coexistence with existing deployment models.
Current landscape
Current C-ITS security architectures rely on a vehicular Public Key Infrastructure (vPKI), pseudonym certificates and classical signatures to provide authentication, integrity and privacy. The On-Board Unit (OBU) acts as the gateway between the in-vehicle domain and external services, while Roadside Units (RSUs) support traffic management and V2I applications. Cooperative Awareness Messages (CAMs) and Decentralized Environmental Notification Messages (DENMs) are broadcast so that nearby participants can receive them, with digital signatures used to establish authenticity and integrity.
The PiQASO use case deliberately focuses on communications that cross the vehicle trust boundary. Internal ECU-to-ECU communications and safety-critical control functions remain outside the PQC integration scope. This keeps the work aligned with realistic deployment conditions and concentrates the validation on the OBU, RSU, backend services and the managed vPKI.
Use Case description, goals and objectives
The PiQASO Automotive Use Case introduces a service-oriented post-quantum security layer for V2X communications and supporting trust services. Linux-based OBU and RSU platforms host the PiQASO SDK, which allows automotive and roadside applications to request cryptographic operations without directly managing the underlying algorithm implementations. The SDK can use local FPGA-based acceleration for computationally intensive operations or interact with PiQASO PQC-as-a-Service components, depending on the selected execution path.
A managed PQC-enabled vPKI, operated by the PKI provider, supports certificate issuance, validation, renewal and revocation.
The managed, PQC-enabled PKI (Public Key Infrastructure) supporting this use case is provided by Aruba, who is working alongside the team to integrate new quantum-resistant algorithms (ML-DSA and ML-KEM) into both on-board and network trust architectures.
Private keys are generated and retained by the requesting client, while the trust infrastructure authenticates requests, applies certificate policies and issues certificates based on the selected algorithm family. This enables the project to assess pure post-quantum and transitional approaches while retaining an operational model compatible with established PKI practices.
The primary reference scenario is emergency vehicle priority management. An emergency vehicle approaching a signalised intersection authenticates towards the RSU using credentials issued by the managed vPKI. The OBU then transmits signed CAM messages containing position, speed, direction and priority information. The RSU verifies the signature and certificate status before triggering traffic-light prioritisation. The scenario is intended to prevent vehicle impersonation and fraudulent priority requests while preserving the responsiveness required by a real-time traffic service.
The communication workflow combines ML-DSA-based authentication and message signatures with ML-KEM-based key establishment for protected unicast communications. CAM and DENM messages remain broadcast in plaintext, as required for cooperative awareness, but are accompanied by post-quantum signatures. Confidential exchanges use symmetric session keys derived after quantum-resistant key establishment.
A second scenario extends the same trust model to quantum-secure OTA software updates. The vehicle authenticates to the OTA infrastructure, establishes a protected session using ML-KEM and validates signed firmware metadata and packages before installation. ML-DSA is the baseline signature mechanism, while alternative post-quantum signature schemes may be evaluated to compare signature size and verification latency.
Validation will cover functional correctness, interoperability and performance. The project will measure signature generation and verification latency, ML-KEM key-establishment latency, certificate provisioning time, communication overhead and the benefit of hardware acceleration. It will also assess whether authenticated CAM and DENM processing, certificate rotation, secure session establishment and OTA verification can be performed without disrupting the operational requirements of the automotive scenarios.
Expected contribution: a practical architectural and experimental basis for migrating connected-vehicle communications and software lifecycle services towards quantum-resistant security, without redesigning the internal vehicle control domain.
About Abinsula
Founded in 2012, Abinsula is an Italian technology company specialising in embedded software, IoT, digital solutions, cybersecurity and cloud services. Automotive is a core business area, supported by experience in embedded platforms, infotainment, vehicle connectivity and secure software engineering. The company also develops ABILITY, a Linux distribution for embedded systems, and carries out continuous research and development to transfer emerging technologies into practical industrial solutions.
Within PiQASO, Abinsula leads the technical implementation of the automotive use case. Its role includes the integration of the PiQASO software stack on vehicle and roadside platforms, the development of representative V2X and OTA workflows, and the assessment of the performance and interoperability implications of introducing post-quantum cryptography into embedded automotive environments.
The project funded under Grant Agreement No. 101190366 is supported by the European Cybersecurity Competence CentreFunded by the European Union.
Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Cybersecurity Competence Centre.
Neither the European Union nor the granting authority can be held responsible for them.