Abstract
Many CAN-based session key sharing approaches are based on the group key scheme, which can easily lead advanced adversaries to infiltrate all ECUs (electronic control units) in the network if the sharing key is leaked. To address the above problem, we propose a provable secure session key distribution protocol based on the improved NSSK (Needham–Schroeder shared key) protocol for the in-vehicle CAN network. We applied the mechanisms of message authentication and digital signature to fix the defects of the original NSSK regarding its lack of resistance to the Denning–Sacco attack. Then, we analyzed the provable security of the proposed protocol on the random oracle model and verified the security goals of the protocol by using the simulation tools AVISPA and Tamarin Prover; the results reflect that the protocol met the security requirements for key distribution such as session key secrecy, injective agreement, and known key secrecy. Finally, we compared our new protocol with other key distribution protocols in CAN bus communication to evaluate the performance of the new protocol in actual scenarios. The result shows that the protocol is secure against many payload-based attacks and is practical for in-vehicle CAN networks.
Funder
National Natural Science Foundation of China
Fundamental Research Funds for the Central Universities
Subject
General Mathematics,Engineering (miscellaneous),Computer Science (miscellaneous)
Reference27 articles.
1. A Practical Security Architecture for In-Vehicle CAN-FD
2. VeCure: A practical security framework to protect the CAN bus of vehicles;Wang;Proceedings of the 2014 International Conference on the Internet of Things (IoT),2014
3. vatiCAN–vetted, authenticated CAN bus;Nürnberger;Proceedings of the International Conference on Cryptographic Hardware and Embedded Systems,2016
4. LeiA: A lightweight authentication protocol for CAN;Radu;Proceedings of the European Symposium on Research in Computer Security,2016
5. An Attack-Resilient Source Authentication Protocol in Controller Area Network;Kang;Proceedings of the 2017 ACM/IEEE Symposium on Architectures for Networking and Communications Systems (ANCS),2017
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献