Journal of Information Security Research ›› 2019, Vol. 5 ›› Issue (12): 1076-1088.

Previous Articles     Next Articles

An Adaptive Security Mechanism of CAN Bus in Vehicle

  

  • Received:2019-12-10 Online:2019-12-15 Published:2019-12-10

自适应的车内CAN总线安全机制

陈颖1,钟成2,3,李兴华2,3,姜奇2,3,张会林2,3,景誉文2,3   

  1. 1. 西安电子科技大学
    2. 西安电子科技大学网络与信息安全学院
    3. 西安电子科技大学网络与信息安全学院
  • 通讯作者: 陈颖
  • 作者简介:陈颖 硕士研究生,主要研究方向为网络与信息安全、车联网安全. chenglume@163.com 钟成 硕士研究生,主要研究方向为网络与信息安全、入侵检测. czhongcs@126.com 李兴华 博士,教授,博士生导师,主要研究方向为网络与信息安全、隐私保护、云计算、安全协议形式化方法. xhli1@mail.xidian.edu.cn 姜奇 博士,副教授,博士生导师,主要研究方向为移动互联网、物联网安全与隐私. jiangqixdu@gmail.com 西安电子科技大学网络与信息安全学院 张会林 硕士研究生,主要研究方向为网络与信息安全、车联网安全. huilin_zhang@qq.com 景誉文 硕士研究生,主要研究方向为网络与信息安全. 247546414@qq.com

Abstract: While the connected vehicles are promoting the development of important technologies such as intelligent transportation and smart cities, its security problems are increasingly severe at the same time. As the core bus network of connected vehicles, CAN bus is responsible for the transmission of sensor information and control instructions, therefore, the issue of its security protection attracts more and more attention. However,the existing security mechanism failed to consider the differentiated needs of messages and dynamic invehicle network environment. It is hard to balance security and network performance at the same time. Therefore, an adaptive security mechanism for CAN bus is proposed. Firstly, a factor set is established, and a differentiated security strategy and corresponding communication protocol are designed according to the requirement of message security and invehicle network environment. Then, the adaptive selection of security strategy is proposed based on the fuzzy decisionmaking idea and the consideration of the message requirements as well as the invehicle network factors. Finally, the feasibility and security of the proposed scheme are verified through theoretical analysis, Moreover, the experimental results indicated that the proposed scheme had limited computing cost, which made it suitable for ECU nodes with limited computing capacity and CAN bus networks with high realtime requirements.

Key words: in-vehicle network, CAN bus, security mechanism, fuzzy decision, key management

摘要: 网联汽车在推动智能交通、智慧城市等重要技术发展的同时,其存在的安全问题日益突出.作为网联汽车的核心总线网络,CAN总线主要负责传感器信息以及控制指令的传输,对其安全防护成为了研究重点.然而现有的CAN总线安全方案未考虑到报文安全需求的差异性以及车内网络环境的动态性,难以兼顾安全性和网络性能.因此,提出了一种自适应的车内CAN总线安全机制,首先根据报文安全需求和车内网络环境等因素建立因素集,并设计了差异化的安全策略及相应的通信协议.随后基于模糊决策的思想,根据报文安全需求和车内网络环境自适应地选取安全策略.最后通过理论分析验证了所提方案的可行性和安全性,同时,实验结果表明该方案所需计算开销有限,适用于计算能力受限的ECU节点和高实时性需求的CAN总线网络.

关键词: 车内网, CAN总线, 安全机制, 模糊决策, 密钥管理