Research on revocable attribute-based encryption access control mechanism for in-vehicle networks
Online published: 2026-05-28
Copyright
With the growing demand for data security and flexible access control in in-vehicle network (IVN), traditional automotive Ethernet and its application-layer protocols lack built-in authentication and fine-grained permission control mechanisms, which cannot meet the refined security access control requirements of IVN. Furthermore, the limited computing resources of in-vehicle devices in IVN further increase the difficulty of implementing fine-grained access control. Aiming at the difficulties in implementing fine-grained access control under the conditions of limited resources and high real-time communication requirements in IVN, this paper investigates a dynamic data access control strategy applicable to advanced driver assistance systems (ADAS). The proposed scheme adopts lightweight elliptic curve cryptography to reduce computational overhead and improve system execution efficiency, and designs a dynamic attribute revocation mechanism to realize the precise revocation of a single attribute without interfering with other network entities. Experimental results show that the proposed scheme can ensure system security while providing an efficient and scalable access control solution for resource-constrained IVN. It can well balance the performance and security requirements of in-vehicle communication systems and adapt to the data access security needs of ADAS scenarios.
Zhang Jing , Zhang Jiaxuan , Shen Yun , Cui Jie , Wei Lu . Research on revocable attribute-based encryption access control mechanism for in-vehicle networks[J]. Journal of Cybersecurity, 2026 , 4(3) : 105 -116 . DOI: 10.20172/j.issn.2097-3136.260526
表 1 各密码操作的平均执行时间Table 1 Average execution time of each cryptographic operations |
| 描述 | 符号 | 开发板执行时间/ms | 树莓派执行时间/ms |
| AES-256 | 0.437 | 0.012 | |
| RSA-512加密 | 2.855 | 0.049 | |
| RSA-512解密 | 37.129 | 0.926 | |
| SHA256 | 0.069 | 0.008 | |
| HMAC(SHA256) | 0.194 | 0.011 | |
| 椭圆曲线点加 | 0.182 | 0.004 | |
| 椭圆曲线标量乘 | 26.274 | 0.476 | |
| 算术乘法 | 0.004 | 0.001 | |
| 模逆运算 | 5.935 | 0.006 | |
| RSA-512签名 | 38.214 | 0.946 | |
| RSA-512验签 | 2.553 | 0.063 |
表 2 各方案计算开销对比Table 2 Comparison of computation overhead for each scheme |
| 方案 | CCU计算开销/ms | 安全代理计算 开销/ms | 数据发布者计算 开销/ms | 数据接收者计算 开销/ms | 总计算开销/ms |
| 文献[6] | | | | | |
| 文献[7] | | | | | |
| 文献[8] | | - | | | |
| 本文 | | - | | | |
表 3 控制信令阶段通信开销对比Table 3 Communication overhead comparison in control signaling phase |
| 方案 | CCU通信开销/byte | SWC通信开销/byte | 总通信开销/byte |
| 文献[6] | | | 96 |
| 文献[7] | | | 112 |
| 文献[8] | | | 96 |
| 本文 | | | 84 |
| 1 |
Lobello L, Patti G, Leonardi L. A perspective on ethernet in automotive communications: current status and future trends[J]. Applied Sciences, 2023, 13 (3): 1278.
|
| 2 |
Rodríguez M J, Bilbao S, Martínez B, et al. An optimized, data distribution service-based solution for reliable data exchange among autonomous underwater vehicles[J]. Sensors, 2017, 17 (8): 1802.
|
| 3 |
Frank F, Püllen D, Kampmann A, et al. Towards deterministic DDS communication for secure service-oriented software-defined vehicles[M]//Availability, Reliability and Security. Cham Springer Nature Switzerland, 2025: 186-208.
|
| 4 |
Püllen D, Frank F, Christl M, et al. A security process for the automotive service-oriented software architecture[J]. IEEE Transactions on Vehicular Technology, 2024, 73 (4): 5036- 5053.
|
| 5 |
施文征, 王成野. 用于资源有限设备的DDS通信中间件开发[J]. 汽车实用技术, 2024, 49 (11): 40- 46.
Shi W Z, Wang C Y. Development of DDS communication middleware for resource-limited devices[J]. Automobile Technology, 2024, 49 (11): 40- 46.
|
| 6 |
Yu D, Hsu R H, Lee J, et al. EC-SVC: secure CAN bus in-vehicle communications with fine-grained access control based on edge computing[J]. IEEE Transactions on Information Forensics and Security, 2022, 17, 1388- 1403.
|
| 7 |
Yu D, Lee S, Hsu R H, et al. Ensuring end-to-end security with fine-grained access control for connected and autonomous vehicles[J]. IEEE Transactions on Information Forensics and Security, 2024, 19, 6962- 6977.
|
| 8 |
Shang C, Cao J, Liu J J, et al. CEAMP: a cross-domain entity authentication and message protection framework for intra-vehicle network[J]. IEEE Transactions on Intelligent Transportation Systems, 2024, 25 (7): 6780- 6795.
|
| 9 |
Rajkumar R R, Lee I, Sha L, et al. Cyber-physical systems: the next computing revolution[C]//Proceedings of the 47th Design Automation Conference. New York: ACM, 2010: 731-736.
|
| 10 |
Bandur V, Selim G, Pantelic V, et al. Making the case for centralized automotive E/E architectures[J]. IEEE Transactions on Vehicular Technology, 2021, 70 (2): 1230- 1245.
|
| 11 |
Hazem A, Fahmy H. LCAP-a lightweight CAN authentication protocol for securing in-vehicle networks[C]//10th Escar Embedded Security in Cars Conference, Berlin, Germany: Vol. 6. 2012: 172.
|
| 12 |
Groza B, Popa L, Murvay P S. Highly efficient authentication for CAN by identifier reallocation with ordered CMACs[J]. IEEE Transactions on Vehicular Technology, 2020, 69 (6): 6129- 6140.
|
| 13 |
Xiao L, Lu X Z, Xu T W, et al. Reinforcement learning-based physical-layer authentication for controller area networks[J]. IEEE Transactions on Information Forensics and Security, 2021, 16, 2535- 2547.
|
| 14 |
Ueda H, Kurachi R, Takada H, et al. Security authentication system for in-vehicle network[J]. SEI Technical Review, 2015, 81, 5- 9.
|
| 15 |
Hu S T, Zhang Q Z, Weimerskirch A, et al. Gatekeeper: a gateway-based broadcast authentication protocol for the in-vehicle Ethernet[C]//Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security. New York: ACM, 2022: 494-507.
|
| 16 |
Fassak S, El H Y, Zahid N, et al. A secure protocol for session keys establishment between ECUs in the CAN bus[C]//Proceedings of the 2017 International Conference on Wireless Networks and Mobile Communications (WINCOM). Piscataway: IEEE Press, 2017: 1-6.
|
| 17 |
Lodge N, Tambe N, Saqib F. Addressing vulnerabilities in CAN-FD: an exploration and security enhancement approach[J]. IoT, 2024, 5 (2): 290- 310.
|
| 18 |
Feng Y, Qin G H, Zhang Z Z, et al. In-vehicle CAN bus security communication protocol based on identity encryption[C]//Proceedings of SPIE Conference on International Conference on Computer Network Security and Software Engineering (CNSSE 2024), 2024: 150.
|
| 19 |
Iorio M, Buttiglieri A, Reineri M, et al. Protecting in-vehicle services: security-enabled SOME/IP middleware[J]. IEEE Vehicular Technology Magazine, 2020, 15 (3): 77- 85.
|
| 20 |
Ghosal A, Halder S, Conti M. Secure over-the-air software update for connected vehicles[J/OL]. Computer Networks, 2022. https://doi.org/10.1016/j.comnet.2022.109394.
|
| 21 |
Lamanna M, Treccozzi L, Perazzo P, et al. Performance evaluation of attribute-based encryption in automotive embedded platform for secure software over-the-air update[J]. Sensors, 2021, 21 (2): 515.
|
| 22 |
Saidi A, Amira A, Nouali O. A secure multi-authority attribute based encryption approach for robust smart grids[J]. Concurrency and Computation: Practice and Experience, 2024, 36 (7): e7972.
|
| 23 |
Yu S X, Cao Q, Wang C Y, et al. Efficient ECC-based conditional privacy-preserving aggregation signature scheme in V2V[J]. IEEE Transactions on Vehicular Technology, 2023, 72 (11): 15028- 15039.
|
| 24 |
Chen Y X, Zhang J, Wei X Y, et al. Cross-domain authentication scheme for vehicles based on given virtual identities[J]. IEEE Internet of Things Journal, 2024, 11 (9): 15869- 15879.
|
| 25 |
Benyahya M, Lenard T, Collen A, et al. A systematic review of threat analysis and risk assessment methodologies for connected and automated vehicles[C]//Proceedings of the 18th International Conference on Availability, Reliability and Security. New York: ACM, 2023: 1-10.
|
| 26 |
Luo F, Wang J J, Zhang X, et al. In-vehicle network intrusion detection systems: a systematic survey of deep learning-based approaches[J]. PeerJ Computer Science, 2023, 9, e1648.
|
| 27 |
Devincenzi M, Pesé M, Bodei C, et al. Contextualizing security and privacy of software-defined vehicles: a literature review and industry perspectives[J/OL]. ACM Computing Surveys, 2026, https://doi.org/10.1145/3814955. https://dl.acm.org/doi/10.1145/3814955.
|
| 28 |
Giraldo J, Sarkar E, Cardenas A A, et al. Security and privacy in cyber-physical systems: a survey of surveys[J]. IEEE Design & Test, 2017, 34 (4): 7- 17.
|
| 29 |
Bhaskar S, Parmar K, Jinwala D C. Comparative evaluation of pairing-free and pairing-based CP-ABE schemes for resource constrained environments[J]. Cluster Computing, 2025, 28 (7): 431.
|
| 30 |
Boneh D. The decision Diffie-Hellman problem[M]//Algorithmic Number Theory. Berlin, Heidelberg Springer, 1998: 48-63.
|
| 31 |
Shamir A. How to share a secret[J]. Communications of the ACM, 1979, 22 (11): 612- 613.
|
| 32 |
Waters B. Ciphertext-policy attribute-based encryption: an expressive, efficient, and provably secure realization[M]//Public Key Cryptography – PKC 2011. Berlin, Heidelberg Springer, 2011: 53-70.
|
| 33 |
Bethencourt J, Sahai A, Waters B. Ciphertext-policy attribute-based encryption[C]//Proceedings of the 2007 IEEE Symposium on Security and Privacy (SP '07). Piscataway: IEEE Press, 2007: 321-334.
|
| 34 |
Zhang X Y, Thakur N, Ogundepo O, et al. MIRACL: a multilingual retrieval dataset covering 18 diverse languages[J]. Transactions of the Association for Computational Linguistics, 2023, 11: 1114-1131.
|
/
| 〈 |
|
〉 |