By proceeding through this intersection, you agree that signals emitted by your property may be captured, associated with other observations, processed by government contractors and retained under policies you have never seen.
No road sign says that. No driver is handed a contract. Yet that sentence is a more honest description of the questions raised by the small computers appearing beside American roads than the language most agencies use to describe them.
They are called roadside units, or RSUs. An RSU is a rugged computer and radio installed near a road so that transportation infrastructure can exchange information with compatible equipment nearby. It might be mounted on a signal pole, attached to a gantry, placed inside a traffic cabinet, or connected to an antenna that is several feet away. It does not have one universal shape. The box a driver can see may be only one part of the installation.
The public safety story behind these units did not begin with a sudden discovery that every intersection needed a wireless computer. It grew out of the Federal Intelligent Transportation Systems program. During the 1990s, Congress and transportation agencies began treating electronics, communications, and computerized traffic management as another category of highway infrastructure. The stated goals were broad: reduce crashes, manage congestion, improve transit and commercial vehicle operations, and move information more quickly during emergencies. The Federal Highway Administration’s summary of the 1998 transportation law expressly made federal transportation money available for infrastructure based intelligent transportation improvements.
That policy changed what could be called a road project. A road was no longer only pavement, drainage, markings, bridges, and signals. It could also be a communications network. Once communications became infrastructure, roadside computers became eligible for the same public planning and funding machinery used for physical transportation projects.
In 1999, the Federal Communications Commission reserved spectrum around 5.9 gigahertz for dedicated short range communications used by intelligent transportation systems. The FCC later described that decision as an allocation of 75 megahertz intended for transportation and vehicle safety applications. The theory was that a traffic signal, emergency vehicle, work zone, or hazardous intersection could send a warning directly to an approaching vehicle without waiting for a distant cellular server. A local radio could communicate rapidly without depending on the vehicle’s public cellular service. Public agencies promoted possible uses including red light warnings, emergency vehicle alerts, work zone notices, transit priority, collision avoidance, and incident response. The RSU became the roadside endpoint for that plan.
That history does not prove that every modern deployment is necessary, proportionate, or harmless. It explains how the unit obtained its institutional legitimacy. It entered government budgets under the language of safety and traffic operations, then gained more processing power, more connectivity, and more dependence on outside services as the industry developed around it.
Inside the enclosure, an RSU generally contains a processor, memory, one or more radios, networking hardware, timing and location capability, security software, and a power connection. Some models receive power and data through one Ethernet cable. Others connect to fiber, a government network, or a cellular modem. The unit can communicate with the traffic signal controller in the roadside cabinet and with a remote traffic management system. Federal deployment guidance describes the complete environment as including advanced signal controllers, back-haul communications, data management, monitoring, and security credential systems. USDOT’s connected vehicle deployment guidance makes clear that an RSU does not operate as an isolated box.

At a signalized intersection, the traffic controller knows which lights are red, yellow, or green and when the phase is expected to change. The RSU can receive that information, format it as a standardized signal phase and timing message, and broadcast it to compatible vehicles nearby. It can also broadcast a digital map describing the lanes and permitted movements at that intersection. Together, those messages allow receiving equipment to understand both the geometry of the intersection and the state of the signal.
Communication also moves in the other direction. A compatible unit inside a vehicle can broadcast a basic safety message containing information such as position, speed, direction, acceleration, and braking status. The RSU can receive those messages, use them for a local safety application, summarize them, or forward information through its backhaul connection. Some processing happens at the roadside because sending every message to a central system would create enormous traffic and delay. USDOT has documented deployments in which RSUs perform this edge processing and turn incoming message streams into operational information such as queue lengths before sharing results with a traffic management center. That approach appears in the agency’s lessons from connected vehicle pilot programs.
V2X is the family of standards that makes those exchanges possible among vehicles, roadside equipment, and other compatible participants. The RSU is the roadside gateway in that system. It sits between the public roadway, nearby vehicles, the agency network, and whatever remote platform the agency has chosen.
The most important part of the system may be the part a driver never sees. It is the backhaul, the connection that carries information between the roadside location and another destination. That destination might be an agency server, a regional traffic center, or a commercial cloud platform. The RSU may transmit equipment status, security logs, message counts, diagnostic information, processed traffic data, or selected records received over the air. Exactly what leaves the intersection depends on the application, configuration, contract, and retention policy.
The RSU also creates a new cybersecurity boundary at the side of the road. It is a remotely managed computer connected to radios, signal equipment, agency networks, cloud platforms, credential systems, and vendor update services. Compromising an RSU does not automatically give a threat actor command of every traffic light. It can, however, create a path toward falsified roadside messages, interrupted safety broadcasts, stolen movement data, abused signal priority requests, disabled equipment, or a deeper foothold inside the transportation network. Whether an attacker can reach the traffic controller depends on the system architecture, permissions, network segmentation, and connections the agency allowed.
The government already knows these systems are difficult to secure. A 2024 Federal Highway Administration cybersecurity presentation identifies cybersecurity vulnerabilities as a risk of transportation technology and recounts attacks involving center to field networks, sensors, controllers, and agency systems. The same presentation states that USDOT does not impose transportation cybersecurity regulations on state, local, tribal, and territorial agencies. Actual traffic control software has also carried serious weaknesses. Federal vulnerability records for Econolite’s EOS traffic controller software describe versions that used weak protection for privileged credentials while leaving a configuration file accessible without authentication. Government is funding increasingly connected roads faster than it is establishing the staffing, oversight, segmentation, patching requirements, and public accountability needed to defend them.

This is where the public description often becomes dangerously vague. Saying that an RSU communicates with vehicles does not explain whether incoming messages are immediately discarded, reduced to anonymous counts, stored as individual observations, or linked across locations and time. Saying that the data is used for traffic management does not identify everyone with access to it. Saying that a message uses rotating credentials does not answer whether location and movement records can be associated with other sources after they enter a remote system.
The RSU itself is therefore only the visible edge of a longer chain. One company may manufacture the unit. Another may install and configure it. A telecommunications carrier may provide the cellular connection. A credential provider may authenticate messages. A systems integrator may connect the device to the signal controller. A software vendor may provide the dashboard, updates, analytics, and storage. Each additional participant creates another account, another contract, another set of access privileges, and another place where public information can become commercial dependence.
The commercial architecture is not hypothetical. Applied Information describes an installation in which roadside equipment connects to the traffic cabinet and sends information to the company’s Glance cloud platform. Its connected vehicle product description presents cloud management as part of the operating system. That can give a transportation agency remote monitoring, software updates, and useful analytics. It also means that understanding the device requires reading the contract behind it.
Who controls the data inside that platform? Can the vendor use it to improve another product? Can subcontractors access it? Is the agency entitled to obtain all raw records in a usable format? Does the vendor delete its copies when the contract ends? Can the information be shared with law enforcement, another government agency, a university, or a commercial partner? Are those decisions established by law, negotiated in procurement, or buried in a service agreement that most residents will never know exists?
The Federal Highway Administration has already documented the risks of vendor dependence. Its guidance warns that agencies can become tied to a cloud provider because extracting data and rebuilding the capability elsewhere may become prohibitively expensive or time consuming. It also notes that agencies have sometimes paid a high price to access data generated by their own infrastructure. Those warnings appear in FHWA’s own policy discussion of transportation management data.
The agency has also described business arrangements in which private companies sell transportation data directly to government, resell it through intermediaries, host it in the cloud, or install and maintain roadside equipment while the agency uses the resulting service. FHWA’s review of private sector transportation data models is broader than RSUs and does not establish that every RSU vendor sells raw vehicle records. It does establish that transportation data moves through commercial arrangements with additional markup, access rights, and incentives. That is why an agency should have to prove that reuse, aggregation, sharing, and sale are prohibited rather than expecting the public to assume they are.
The public did not merely supply the information moving through this system. It financed the system that collects and processes it.

The public pays for the road. The public pays for the signal pole, cabinet, electricity, network connection, installation, software, cybersecurity, support, and eventual replacement. Federal estimates place RSU hardware and integration alone in the thousands of dollars per location, before controller upgrades, back-haul, management systems, training, and continuing operations. USDOT’s cost review estimates three thousand to five thousand dollars for RSU hardware and integration and identifies additional costs for cellular service and signal equipment. A broader USDOT briefing on deployment costs lists fiber, cloud platforms, analytics, security credentials, workforce, management, and maintenance among the expenses that follow the purchase.
That is the contradiction drivers can see even if they never notice the RSU. They already pay taxes for public roads and for the governments responsible for maintaining them. They drive over broken pavement, faded markings, failing drainage, and repairs that remain unfinished. Traffic remains unmanageable. Then they are told that infrastructure requires another budget increase, another modernization plan, another connected corridor, another equipment contract, and another monthly service attached to the roadside.
The meaning of infrastructure has expanded. It now includes communications equipment, cloud platforms, data analytics, security subscriptions, software support, and vendor management. That expansion allows an agency to increase an infrastructure budget without necessarily delivering smoother pavement, safer physical road conditions, or less congestion. Taxpayers can be charged more for infrastructure while receiving less of what they reasonably believed infrastructure meant.
Transportation officials may correctly say that public money is divided into programs and that a technology grant cannot always be transferred directly into a pothole repair account. That is an accounting explanation, not an answer to the public’s objection. Legislatures and agencies decide what programs exist, how infrastructure is defined, what federal grants they pursue, which budget increases they request, and which continuing costs taxpayers will inherit. Earmarks do not appear by nature. They are policy choices. When a road is upgraded as a communications and data platform before it is maintained as a road, the people who funded it have every right to challenge that choice.
They also have the right to reject the suggestion that paying for the system amounts to consenting to its practices. Taxation authorizes government to provide public infrastructure. It does not give a transportation agency or its contractor an unlimited claim over information produced when residents use that infrastructure. If an RSU receives, processes, forwards, or retains observations about movement on a public road, the limits should be established publicly before collection begins.
A defensible RSU program would disclose each deployment’s location, manufacturer, model, communications method, message types received, information transmitted off site, retention period, vendor access, permitted secondary uses, security audits, sharing rules, and deletion procedure. Its contracts would prohibit sale and unrelated reuse unless the public had affirmatively authorized them. It would minimize information at the roadside instead of collecting first and inventing a purpose later. It would allow independent audits. It would make the answers available without forcing residents to identify a mystery box and fight through months of records requests.
An RSU may serve a legitimate safety function. That does not give an agency unlimited authority to collect information, conceal the data path, or let a vendor determine what happens after the information leaves the intersection. Public safety cannot become a blank check for an expanding technical system whose data flows are invisible and whose private participants may understand the system better than the people who paid for it.
We already paid for the road. We should not have to surrender an undisclosed stream of information simply to use it. When systems are connected, even indirectly, they become bridges. And once a bridge exists, information can be moved across environments…and out of them.
Discover more from Solide Info | The Engineer’s Authority on Cyber Defense
Subscribe to get the latest posts sent to your email.



