Abstract
Connected vehicle (CV) technologies are emerging as a crucial technology for improving safety on future roadways. Wireless vehicle-to-everything (V2X) communication allows CVs to exchange information that provides enhanced awareness and supports better driving decisions, especially in high-risk or non-line-of-sight scenarios. However, V2X also exposes new surfaces to physical layer attacks and increasingly sophisticated, potentially quantum-capable threat actors. As human or autonomous CV drivers will make split-second safety-critical decisions based on the contents of V2X messages, ensuring their authenticity, as well as their reliable and timely delivery, is crucial. Otherwise, malicious attackers may interfere with safety services or spoof messages to manipulate regional traffic flows and potentially even induce crashes. In this dissertation, we challenge the readiness of CVs to withstand these and other threats from increasingly capable attackers, and we accordingly take steps to harden V2X by designing cross-layer security protocols and developing physically grounded evaluation architectures to evaluate them under realistic conditions. In the first part of this dissertation, we systematically analyze the current threat environment to identify gaps in CV security foundations. We begin by exposing vulnerabilities in 5G Cellular Vehicle-to-Everything (C-V2X) by developing two debilitating and stealthy denial-of-service (DoS) attacks that target the resource allocation and scheduling algorithms of C-V2X. We subsequently propose machine learning-based defenses to rapidly and accurately detect each attack. Our DoS attacks demonstrate that availability requires greater attention from system architects and standardization bodies, which until now have developed security requirements that focus primarily on authentication and integrity rather than reliable message delivery. We then shift from wireless to a cryptographic perspective by analyzing the threat of variational cryptanalysis—hybrid quantum-classical attacks designed to run on near-term quantum hardware that have been put forward as a viable method of breaking modern cryptography even before the advent of a cryptographically relevant quantum computer. Through extensive simulations of noisy intermediate-scale quantum (NISQ) circuits, we demonstrate that NISQ hardware noise and the inherent properties of symmetric cryptography are very effective at neutralizing known variational attacks. We further develop formal bounds on variational cryptanalysis that establish the limitations of known techniques more generally, concluding that such attacks currently pose no credible threat to widely used cryptographic primitives such as the Advanced Encryption Standard (AES). In the second part of this dissertation, we focus on hardening CVs against quantum threats. We begin by laying out the fundamental problem: the high overhead of standardized algorithms for quantum-resistant cryptography (QRC), including NIST’s preferred Module Lattice-based Digital Signature Algorithm (ML-DSA), is incompatible with the physical (PHY) layer design and severe wireless constraints of both legacy IEEE and future 3GPP protocols for V2X communication. Based on this incompatibility, we establish that simply substituting QRC for the elliptic-curve cryptography of current security standards (e.g., IEEE 1609.2) is a non-starter, and that more tailored solutions are required. We then delineate the expected evolution of V2X technology, CV deployment requirements, and quantum threats over the coming years. We accordingly develop new authentication protocols tailored for each distinct combination thereof. For legacy systems based on IEEE 802.11p/bd Dedicated Short Range Communications (DSRC), we develop a cross-layer authentication protocol that uses carefully designed QRC-signed certificates and makes their usage practical via a machine learning-based technique for optimizing certificate distribution intervals based on PHY and MAC layer observations. For current and near-future 5G C-V2X we take an even more explicitly cross-layer approach that combines safety-aware adaptive modulation at the PHY layer with provably secure hybrid message authentication at the application layer to reduce safety violations by more than 92% compared with current systems, even on dense urban roadways. Finally, for high CV density in future 6G C-V2X, we quantify scalability limits on vehicular public-key infrastructure (VPKI) and propose a new, scalable architecture that retains critical trust management benefits of VPKI while alleviating bottlenecks in fast-path (real-time) message authentication to enable practical quantum resistance, even in ultra-high-density environments with up to 800 vehicles per km$^2$. The third part of this dissertation tackles the challenge of testing CV safety and security under realistic conditions. Simulations are scalable and inexpensive, but their abstractions (e.g., stochastic modeling of wireless channels) mean their results do not always align closely with reality. At the other extreme, field testing on real roads is the gold standard, but it is often impractical (if not impossible) due to severe costs, safety risks and legal constraints. Digital twins have emerged as one way to fill the gap, and in the first chapter of this part we develop a new digital twinning framework for CV testing. Our Digital Twin for Connected Vehicle Safety and Security (DT-CoVeSS) provides a basis for physically grounded CV evaluation that combines (1) automated digital twinning of arbitrary environments using open-source geospatial data; (2) a hardware-in-the-loop testbed, with software-defined radios and commercial C-V2X devices supplying actual wireless signals; and (3) an extension of commercial ray-tracing software to the PHY structure of 5G C-V2X signals. In the second chapter, we address crucial limitations of digital twinning—non-responsiveness to internal interactions and difficulty handling out-of-sequence and noisy measurements—by developing our Responsive and Causal Shadowing for Testing (RECAST) digital shadowing framework. Built around our novel Conflict- and Time-Corrected Kalman Filtering Framework (CTC-KFF), which supports causally aware state reconstruction to handle out-of-sequence measurements, RECAST concretely connects communication-layer failures and security attacks to measurable roadway safety outcomes. These contributions facilitate evaluating whether future CV protocols are not only secure, but also practical for safety-critical deployment.
Publication Date
8-2026
Document Type
Dissertation
Student Type
Graduate
Degree Name
Electrical and Computer Engineering (Ph.D)
College
Kate Gleason College of Engineering
Advisor
Hanif Rahbari
Advisor/Committee Member
Sonia Lopez Alarcon
Advisor/Committee Member
Fawad Ahmad
Recommended Citation
Twardokus, Geoff, "Cross-Layer Security and Responsive Evaluation Architectures for Quantum Resistance in Connected Vehicles" (2026). Thesis. Rochester Institute of Technology. Accessed from
https://repository.rit.edu/theses/12750
Campus
RIT – Main Campus
