NOTSA: Novel OBU With Three-Level Security Architecture for Internet of Vehicles

NOTSA: Novel OBU With Three-Level Security Architecture for Internet of Vehicles
复制标题

NOTSA:车联网三级安全架构的新型OBU

DOI:
10.1109/jiot.2018.2800281
复制
发表时间:
2018-10-01
影响因子:
10.6
通讯作者:
Liu, Xiaolong
Liu, Xiaolong
中科院分区:
计算机科学1区
文献类型:
--
作者:
Wang, Liangmin;Liu, Xiaolong

文献摘要

被引文献

相似文献

车联网已经成为一个大规模的网络,其实现了多网络融合,包括车载网络、无线局域网、专用短程通信、设备到设备通信和蜂窝网络(例如,5G)。众所周知,车载网络被认为是一个封闭的网络,因此绝对安全。然而,多个网络接入和融合可能会引入不同的威胁。当前车载单元(OBU)无法保护车载网络。因此,攻击者很容易进行非法的车辆控制。在本文中,考虑到当前OBU和车载控制器局域网的漏洞,我们显示了实际车辆的主要攻击模型,并使用基于ISO 13335指南的IT安全管理方法评估引入的威胁。在此基础上,设计了具有三级安全体系结构的OBU,并提出了多级安全协议。它不仅可以提高外部网络的安全性,而且还可以通过与现有的车载安全方案合作来保护车载网络。在此基础上,我们分析了该方案的安全性,并在硬件平台上对其进行了评估。NOTSA和车载自组网的可靠性,然后使用可靠性框图进行了讨论。此外,我们还验证了所提出的协议的正确性。最后,通过仿真和比较,表明该方案是可行的,在时间开销、安全性和可靠性方面都优于现有方案。
Internet of Vehicles has become a massive network, which enables multinetwork fusion, including in-vehicle network, wireless local area network, dedicated short range communication, device-to-device communication, and cellular network (e.g., 5G). Proverbially, in-vehicle network is considered as a closed network and thus absolutely secure. However, multiple networks access and fusion can introduce different threats. Current on board units (OBUs) fail to protect in-vehicle network. Therefore, illegal vehicle control can be easily performed for attackers. In this paper, in consideration of vulnerabilities of current OBUs and in-vehicle controller area network, we show main attack model for actual vehicles, and assess introduced threats using the approach based on ISO 13335 guidelines for the management of IT security. Then, we design the novel OBU with three-level security architecture (NOTSA) and propose multilevel security protocols. It cannot only improve the security of external networks, but also protect the in-vehicle network by collaborating with current in-vehicle security schemes. Thereafter, we analyze security of proposed scheme, and evaluate it on hardware platform. The reliability of NOTSA and vehicular ad-hoc networks are then discussed using reliability block diagrams. In addition, we also verify the correctness of proposed protocols. Finally, the simulation results and comparison show that our scheme is feasible and more efficient than existing schemes in term of time overhead, security and reliability.