School of Transportation Science and Engineering, Beihang University, Beijing 102206, China.
China Software Testing Center, Beijing 100038, China.
Sensors (Basel). 2022 Jan 14;22(2):647. doi: 10.3390/s22020647.
The rapid development of intelligent networked vehicles (ICVs) has brought many positive effects. Unfortunately, connecting to the outside exposes ICVs to security threats. Using secure protocols is an important approach to protect ICVs from hacker attacks and has become a hot research area for vehicle security. However, most of the previous studies were carried out on V2X networks, while those on in-vehicle networks (IVNs) did not involve Ethernet. To this end, oriented to the new IVNs based on Ethernet, we designed an efficient secure scheme, including an authentication scheme using the Scalable Service-Oriented Middleware over IP (SOME/IP) protocol and a secure communication scheme modifying the payload field of the original SOME/IP data frame. The security analysis shows that the designed authentication scheme can provide mutual identity authentication for communicating parties and ensure the confidentiality of the issued temporary session key; the designed authentication and secure communication scheme can resist the common malicious attacks conjointly. The performance experiments based on embedded devices show that the additional overhead introduced by the secure scheme is very limited. The secure scheme proposed in this article can promote the popularization of the SOME/IP protocol in IVNs and contribute to the secure communication of IVNs.
智能网联汽车(ICV)的快速发展带来了许多积极的影响。然而,将车辆连接到外部网络也使其面临安全威胁。使用安全协议是保护 ICV 免受黑客攻击的重要手段,已成为车辆安全的热门研究领域。但是,以前的大多数研究都集中在 V2X 网络上,而针对车内网络(IVN)的研究则没有涉及以太网。为此,我们针对基于以太网的新型 IVN,设计了一种高效的安全方案,包括使用可扩展服务导向中间件 over IP(SOME/IP)协议的认证方案和修改原始 SOME/IP 数据帧有效负载字段的安全通信方案。安全分析表明,所设计的认证方案可以为通信双方提供相互身份认证,并确保临时会话密钥的机密性;所设计的认证和安全通信方案可以共同抵御常见的恶意攻击。基于嵌入式设备的性能实验表明,安全方案引入的额外开销非常有限。本文提出的安全方案可以促进 SOME/IP 协议在 IVN 中的推广,并有助于 IVN 的安全通信。