网络出版日期: 2026-05-28
基金资助
国家自然科学基金(62272002;62472003;62202008);国家自然科学基金联合基金重点项目(U23A20308)
版权
Research on revocable attribute-based encryption access control mechanism for in-vehicle networks
Online published: 2026-05-28
Copyright
随着车内网(in-vehicle network,IVN)对数据安全性和灵活访问控制的需求日益提升,传统车载以太网及其应用层协议因缺乏内置身份验证与细粒度权限管控机制,已难以满足IVN的精细化安全访问控制需求。同时,IVN环境下车载设备计算资源受限的特性,进一步提升了细粒度访问控制方案的落地实现难度。针对IVN环境资源受限、通信实时性要求高,细粒度访问控制难以高效实现的难题,本文面向高级驾驶辅助系统(advanced driver assistance systems,ADAS)场景,开展动态数据访问控制机制研究。该方案引入轻量级椭圆曲线密码学,有效降低计算开销、提升系统执行效率;设计动态属性撤销机制,可在不影响其他网络实体的基础上,实现单一属性的精准撤销。实验结果表明,该方案在保障系统安全性的基础上,可为资源受限的车内网络提供高效、可扩展的访问控制解决方案,能够有效适配ADAS场景的车载通信安全与性能需求。
张静 , 张佳轩 , 沈韵 , 崔杰 , 魏璐 . 车内网中基于属性加密的可撤销访问控制机制研究[J]. 网络空间安全科学学报, 2026 , 4(3) : 105 -116 . DOI: 10.20172/j.issn.2097-3136.260526
With the growing demand for data security and flexible access control in in-vehicle network (IVN), traditional automotive Ethernet and its application-layer protocols lack built-in authentication and fine-grained permission control mechanisms, which cannot meet the refined security access control requirements of IVN. Furthermore, the limited computing resources of in-vehicle devices in IVN further increase the difficulty of implementing fine-grained access control. Aiming at the difficulties in implementing fine-grained access control under the conditions of limited resources and high real-time communication requirements in IVN, this paper investigates a dynamic data access control strategy applicable to advanced driver assistance systems (ADAS). The proposed scheme adopts lightweight elliptic curve cryptography to reduce computational overhead and improve system execution efficiency, and designs a dynamic attribute revocation mechanism to realize the precise revocation of a single attribute without interfering with other network entities. Experimental results show that the proposed scheme can ensure system security while providing an efficient and scalable access control solution for resource-constrained IVN. It can well balance the performance and security requirements of in-vehicle communication systems and adapt to the data access security needs of ADAS scenarios.
表 1 各密码操作的平均执行时间Table 1 Average execution time of each cryptographic operations |
| 描述 | 符号 | 开发板执行时间/ms | 树莓派执行时间/ms |
| AES-256 | 0.437 | 0.012 | |
| RSA-512加密 | 2.855 | 0.049 | |
| RSA-512解密 | 37.129 | 0.926 | |
| SHA256 | 0.069 | 0.008 | |
| HMAC(SHA256) | 0.194 | 0.011 | |
| 椭圆曲线点加 | 0.182 | 0.004 | |
| 椭圆曲线标量乘 | 26.274 | 0.476 | |
| 算术乘法 | 0.004 | 0.001 | |
| 模逆运算 | 5.935 | 0.006 | |
| RSA-512签名 | 38.214 | 0.946 | |
| RSA-512验签 | 2.553 | 0.063 |
表 2 各方案计算开销对比Table 2 Comparison of computation overhead for each scheme |
| 方案 | CCU计算开销/ms | 安全代理计算 开销/ms | 数据发布者计算 开销/ms | 数据接收者计算 开销/ms | 总计算开销/ms |
| 文献[6] | | | | | |
| 文献[7] | | | | | |
| 文献[8] | | - | | | |
| 本文 | | - | | | |
表 3 控制信令阶段通信开销对比Table 3 Communication overhead comparison in control signaling phase |
| 方案 | CCU通信开销/byte | SWC通信开销/byte | 总通信开销/byte |
| 文献[6] | | | 96 |
| 文献[7] | | | 112 |
| 文献[8] | | | 96 |
| 本文 | | | 84 |
| 1 |
Lobello L, Patti G, Leonardi L. A perspective on ethernet in automotive communications: current status and future trends[J]. Applied Sciences, 2023, 13 (3): 1278.
|
| 2 |
Rodríguez M J, Bilbao S, Martínez B, et al. An optimized, data distribution service-based solution for reliable data exchange among autonomous underwater vehicles[J]. Sensors, 2017, 17 (8): 1802.
|
| 3 |
Frank F, Püllen D, Kampmann A, et al. Towards deterministic DDS communication for secure service-oriented software-defined vehicles[M]//Availability, Reliability and Security. Cham Springer Nature Switzerland, 2025: 186-208.
|
| 4 |
Püllen D, Frank F, Christl M, et al. A security process for the automotive service-oriented software architecture[J]. IEEE Transactions on Vehicular Technology, 2024, 73 (4): 5036- 5053.
|
| 5 |
施文征, 王成野. 用于资源有限设备的DDS通信中间件开发[J]. 汽车实用技术, 2024, 49 (11): 40- 46.
Shi W Z, Wang C Y. Development of DDS communication middleware for resource-limited devices[J]. Automobile Technology, 2024, 49 (11): 40- 46.
|
| 6 |
Yu D, Hsu R H, Lee J, et al. EC-SVC: secure CAN bus in-vehicle communications with fine-grained access control based on edge computing[J]. IEEE Transactions on Information Forensics and Security, 2022, 17, 1388- 1403.
|
| 7 |
Yu D, Lee S, Hsu R H, et al. Ensuring end-to-end security with fine-grained access control for connected and autonomous vehicles[J]. IEEE Transactions on Information Forensics and Security, 2024, 19, 6962- 6977.
|
| 8 |
Shang C, Cao J, Liu J J, et al. CEAMP: a cross-domain entity authentication and message protection framework for intra-vehicle network[J]. IEEE Transactions on Intelligent Transportation Systems, 2024, 25 (7): 6780- 6795.
|
| 9 |
Rajkumar R R, Lee I, Sha L, et al. Cyber-physical systems: the next computing revolution[C]//Proceedings of the 47th Design Automation Conference. New York: ACM, 2010: 731-736.
|
| 10 |
Bandur V, Selim G, Pantelic V, et al. Making the case for centralized automotive E/E architectures[J]. IEEE Transactions on Vehicular Technology, 2021, 70 (2): 1230- 1245.
|
| 11 |
Hazem A, Fahmy H. LCAP-a lightweight CAN authentication protocol for securing in-vehicle networks[C]//10th Escar Embedded Security in Cars Conference, Berlin, Germany: Vol. 6. 2012: 172.
|
| 12 |
Groza B, Popa L, Murvay P S. Highly efficient authentication for CAN by identifier reallocation with ordered CMACs[J]. IEEE Transactions on Vehicular Technology, 2020, 69 (6): 6129- 6140.
|
| 13 |
Xiao L, Lu X Z, Xu T W, et al. Reinforcement learning-based physical-layer authentication for controller area networks[J]. IEEE Transactions on Information Forensics and Security, 2021, 16, 2535- 2547.
|
| 14 |
Ueda H, Kurachi R, Takada H, et al. Security authentication system for in-vehicle network[J]. SEI Technical Review, 2015, 81, 5- 9.
|
| 15 |
Hu S T, Zhang Q Z, Weimerskirch A, et al. Gatekeeper: a gateway-based broadcast authentication protocol for the in-vehicle Ethernet[C]//Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security. New York: ACM, 2022: 494-507.
|
| 16 |
Fassak S, El H Y, Zahid N, et al. A secure protocol for session keys establishment between ECUs in the CAN bus[C]//Proceedings of the 2017 International Conference on Wireless Networks and Mobile Communications (WINCOM). Piscataway: IEEE Press, 2017: 1-6.
|
| 17 |
Lodge N, Tambe N, Saqib F. Addressing vulnerabilities in CAN-FD: an exploration and security enhancement approach[J]. IoT, 2024, 5 (2): 290- 310.
|
| 18 |
Feng Y, Qin G H, Zhang Z Z, et al. In-vehicle CAN bus security communication protocol based on identity encryption[C]//Proceedings of SPIE Conference on International Conference on Computer Network Security and Software Engineering (CNSSE 2024), 2024: 150.
|
| 19 |
Iorio M, Buttiglieri A, Reineri M, et al. Protecting in-vehicle services: security-enabled SOME/IP middleware[J]. IEEE Vehicular Technology Magazine, 2020, 15 (3): 77- 85.
|
| 20 |
Ghosal A, Halder S, Conti M. Secure over-the-air software update for connected vehicles[J/OL]. Computer Networks, 2022. https://doi.org/10.1016/j.comnet.2022.109394.
|
| 21 |
Lamanna M, Treccozzi L, Perazzo P, et al. Performance evaluation of attribute-based encryption in automotive embedded platform for secure software over-the-air update[J]. Sensors, 2021, 21 (2): 515.
|
| 22 |
Saidi A, Amira A, Nouali O. A secure multi-authority attribute based encryption approach for robust smart grids[J]. Concurrency and Computation: Practice and Experience, 2024, 36 (7): e7972.
|
| 23 |
Yu S X, Cao Q, Wang C Y, et al. Efficient ECC-based conditional privacy-preserving aggregation signature scheme in V2V[J]. IEEE Transactions on Vehicular Technology, 2023, 72 (11): 15028- 15039.
|
| 24 |
Chen Y X, Zhang J, Wei X Y, et al. Cross-domain authentication scheme for vehicles based on given virtual identities[J]. IEEE Internet of Things Journal, 2024, 11 (9): 15869- 15879.
|
| 25 |
Benyahya M, Lenard T, Collen A, et al. A systematic review of threat analysis and risk assessment methodologies for connected and automated vehicles[C]//Proceedings of the 18th International Conference on Availability, Reliability and Security. New York: ACM, 2023: 1-10.
|
| 26 |
Luo F, Wang J J, Zhang X, et al. In-vehicle network intrusion detection systems: a systematic survey of deep learning-based approaches[J]. PeerJ Computer Science, 2023, 9, e1648.
|
| 27 |
Devincenzi M, Pesé M, Bodei C, et al. Contextualizing security and privacy of software-defined vehicles: a literature review and industry perspectives[J/OL]. ACM Computing Surveys, 2026, https://doi.org/10.1145/3814955. https://dl.acm.org/doi/10.1145/3814955.
|
| 28 |
Giraldo J, Sarkar E, Cardenas A A, et al. Security and privacy in cyber-physical systems: a survey of surveys[J]. IEEE Design & Test, 2017, 34 (4): 7- 17.
|
| 29 |
Bhaskar S, Parmar K, Jinwala D C. Comparative evaluation of pairing-free and pairing-based CP-ABE schemes for resource constrained environments[J]. Cluster Computing, 2025, 28 (7): 431.
|
| 30 |
Boneh D. The decision Diffie-Hellman problem[M]//Algorithmic Number Theory. Berlin, Heidelberg Springer, 1998: 48-63.
|
| 31 |
Shamir A. How to share a secret[J]. Communications of the ACM, 1979, 22 (11): 612- 613.
|
| 32 |
Waters B. Ciphertext-policy attribute-based encryption: an expressive, efficient, and provably secure realization[M]//Public Key Cryptography – PKC 2011. Berlin, Heidelberg Springer, 2011: 53-70.
|
| 33 |
Bethencourt J, Sahai A, Waters B. Ciphertext-policy attribute-based encryption[C]//Proceedings of the 2007 IEEE Symposium on Security and Privacy (SP '07). Piscataway: IEEE Press, 2007: 321-334.
|
| 34 |
Zhang X Y, Thakur N, Ogundepo O, et al. MIRACL: a multilingual retrieval dataset covering 18 diverse languages[J]. Transactions of the Association for Computational Linguistics, 2023, 11: 1114-1131.
|
/
| 〈 |
|
〉 |