A location privacy security-oriented vehicle networking access control method
By combining Handle identification, linear integer key sharing, and SDN in the vehicle-to-everything (V2X) environment, and utilizing a trusted center to generate an access control policy matrix and dynamic access control algorithm, the problem of vehicle location privacy data leakage is solved, and effective protection of identity verification and secure data sharing is achieved.
Patent Information
- Application Number
- CN202111153460.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-29
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2041-09-29
AI Technical Summary
In vehicle ad hoc networks, existing technologies struggle to effectively protect vehicle location privacy data, especially during information access between vehicles, where there is a risk of user location information leakage. Furthermore, traditional access control methods are susceptible to identity theft and revocation issues.
This approach combines Handle identification, linear integer key sharing, and software-defined networking (SDN). It generates an access control policy matrix through a trusted center, uses the uniqueness of Handle identification to determine vehicle identity, and employs a dynamic access control algorithm based on attributes and information flow models to filter out authorized users who meet the access policies, thus protecting the privacy of location service data.
It effectively reduces the risk of user location privacy data leakage, ensures vehicle identity security, reduces resource consumption for accessing user terminals, enables fine-grained data operations, and ensures secure sharing of location data.
Smart Images

Figure CN115914354B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the cross-technology field of privacy protection, access control and identity authentication, and specifically designs an access control method for supporting secure sharing of vehicle location privacy protection services in a vehicular network environment. BACKGROUND
[0002] In the past decade, the rapid development of vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communication technology has attracted extensive attention to vehicular ad hoc networks (VANETs). Modern vehicles are equipped with on-board units (OBUs) and roadside units (RSUs). Vehicle ad hoc networks (VANETs) are a key technology for intelligent transportation systems (ITS) and have the advantages of improving safety and convenience. However, one of the biggest challenges to its success is location privacy. With the rapid development of wireless communication, positioning technology and smart mobile terminals, location-based services (LBS) based on GIS platforms enable vehicles to obtain various information related to spatial location at any time. The geographical location of the vehicle is used to provide information and entertainment services, as the location of the vehicle usually represents its context information. Vehicles can easily obtain information such as nearby restaurants, gas stations, rest areas, etc. The user's location may reveal the user's sensitive privacy information such as interests, habits and health conditions, which will pose a threat to the user's privacy and security when these privacy information is obtained by an adversary. When VANETs and location-based services are integrated, LBS service providers can provide many location-based sharing services such as friend location query, friend travel trajectory query, and real-time sharing of current location. However, while enjoying the convenience of LBS services, there are also some challenges to be addressed. Location information is one of the most sensitive privacy information of users, and therefore has important value. For example, an attacker who steals the identity of a user's legitimate friend and requests the user's location service information can infer a lot of sensitive information from the location information. For example, an attacker can infer the user's physical condition from hospital data. In addition, an attacker can easily obtain the user's life behavior privacy according to the user's travel plan. These all pose a great security risk to the user, and it is very important to prevent malicious attackers from obtaining sensitive location information.
[0003] Currently, researchers at home and abroad have data sharing schemes based on attribute encryption (ABE) and identity-based access control. Among them, attribute-based encryption allows people to encrypt each data item according to the access control policy applicable to the data. However, in addition to the key escrow problem, ABE also has revocation problems, because once a user is revoked, the private key provided to existing users should be updated. We hope to achieve dynamic protection of each user's private data, and when an unauthorized user becomes an authorized user, we require dynamic detection of changes in user access permissions and reject unauthorized user access requests. At the same time, once the ABE encrypted file is decrypted by a user, this user can do anything with the file, but we want some data to be unable to be copied or downloaded. Identity-based access control has role-based access control (RBAC) or identity-based access control (IBAC) in VANET, which is vulnerable to identity theft, that is, if a legitimate user's identity (private key) is cracked by an attacker, the attacker will accordingly gain all legitimate authorization to the user's private data, posing a great threat to the user's privacy.
[0004] After searching, it was found that the Chinese patent with publication number CN107968774B disclosed an information security protection method for a vehicle Internet terminal device on October 9, 2020, which includes: S1, respectively setting the communication processor of the communication unit and the gateway processor of the gateway in the vehicle Internet terminal device; S2, performing security measures on the APN data channel of the vehicle Internet terminal device; S3, performing data encryption on the T-BOX system communication of the vehicle Internet terminal device; S4, performing real-time processing on the key for information transmission in the vehicle Internet terminal device; S5, performing identity authentication on the login user in the vehicle Internet terminal device. The invention uses a five-dimensional information security protection scheme to ensure the integrity of network communication and the security of access channels, and to strengthen the confidentiality of customer information data.
[0005] However, this method can only protect the confidentiality of customer information, and does not consider information access between vehicles and communication devices or between vehicles in a vehicle Internet environment. Therefore, combining Handle identification, linear integer key sharing, and software-defined networks (SDN) in a vehicular ad hoc network to protect user location service private data is still a technical problem that needs to be solved by those skilled in the art. SUMMARY
[0006] In order to overcome the above-mentioned deficiencies of the prior art, the application provides a location privacy security-oriented vehicle networking access control method, which screens authorized vehicle users meeting attribute requirements according to vehicle user-defined access control strategies, stipulates which services and access time each authorized vehicle user can access, and prevents access of unauthorized users, so as to effectively reduce the risk of user location privacy data leakage in a vehicle networking environment.
[0007] The application is implemented by the following technical solutions:
[0008] The location privacy security-oriented vehicle networking access control method comprises the following steps:
[0009] The Handle identifier is sent to the trusted center for registration and registration, and the secret value returned by the trusted center is received; the own location information is sent, and the location service based on the location information is acquired; the own access control strategy is sent to the trusted center, and the access control strategy matrix generated by the trusted center according to the access rule is received, wherein the access control strategy matrix represents a plurality of attribute vectors of the current vehicle; the request flow of the request access is sent, the attribute vector carried by the access vehicle is reconstructed to obtain the reconstructed secret value, and it is judged whether the reconstructed secret value matches the expected secret value, and if the two match, the access is executed.
[0010] In the above technical solution, the vehicle user formulates the own access control strategy according to the own privacy demand, and sends the access control strategy to the trusted center; the trusted center generates the access control matrix according to the access control strategy of the user, obtains a plurality of attribute vectors of the current vehicle user, judges whether the attribute vector carried by the access vehicle meets the access control strategy defined by the vehicle to be accessed when the access vehicle requests, sends the reconstructed secret value to the vehicle to be accessed, and compares the secret value of the vehicle to be accessed, and if the two meet, the access request of the access vehicle is allowed, and the access is executed.
[0011] Specifically, the vehicle user stores the own location service in the virtual machine of the third-party service provider, and the purpose of the vehicle sending the own location information to the server is to acquire the service, for example, when the vehicle wants to obtain the real-time positioning service, the vehicle sends the own location information to the third-party service provider, the third-party service provider returns the service based on the location information of the vehicle, and the location service is stored in the virtual machine at this time.
[0012] Preferably, the trusted center determines whether it is the only real vehicle existing in the system according to the Handle identifier and the vehicle information table, and if yes, the registration is successful.
[0013] In particular, each vehicle to be registered in the system needs to send its unique Handle identity and access control policy to the trusted center for registration. Only the registered vehicle is considered as a trusted secure vehicle. If the vehicle registration is successful, it means that the Handle identity of the vehicle is unique and really exists in the system. The vehicle information table is maintained in the trusted center system to manage the registration information of all vehicles.
[0014] Preferably, the access rules specifically include three rules, and the generated access control policy matrix needs to meet the three rules at the same time.
[0015] In particular, the access control policy is converted into a distribution matrix M, which can be represented by the following three rules. Define M u ∈Z 1×1 is a single entry matrix, i.e. M u = [1], there is a matrix representing the access control policy P v , H v ∈Z e represents the first column of M v , and represents the remaining columns of the matrix except the first column.
[0016] Rule 1:
[0017] Each variable S i in the access control policy can be represented by the matrix M u .
[0018] Rule 2:
[0019] For any OR structure (OR), i.e. P = P1 V P2, the matrices corresponding to the access control policies P1 and P2 are and Therefore, the matrix M OR of the access control policy P can be constructed as follows.
[0020]
[0021] Rule 3:
[0022] For any AND structure (AND), i.e. P = P1 A P2, the matrices corresponding to the access control policies P0 and P1 are and Therefore, the matrix M AND of the access control policy P can be constructed as follows.
[0023]
[0024] Preferably, the system initializes to select a secure encryption hash function Hash, and the hash function value of the Handle identifier is XORed with the attribute vector of the vehicle to obtain the attribute set of the vehicle itself.
[0025] Specifically, since each vehicle user applies for a Handle identifier, the real identity of the vehicle in the system is determined by the uniqueness of the Handle identifier.
[0026] Preferably, the trusted center performs a first XOR operation on the attribute vector of the vehicle and the hash function value of the Handle identifier, and returns the result of the first XOR operation to the vehicle; the vehicle performs a second XOR operation on the Handle identifier and the result of the first XOR operation to obtain the attribute set of the vehicle itself.
[0027] Specifically, even if the attribute set is stolen by a vehicle in the system, since the Handle identifier of the vehicle is unique and the Handle identifier cannot be stolen by an attacker, the attacker cannot obtain the attribute information of the vehicle even if the information sent by the trusted center to the vehicle is obtained.
[0028] Preferably, the trusted center performs a first XOR operation on the attribute vector of the vehicle and the hash function value of the Handle identifier, and returns the result of the first XOR operation to the vehicle; the vehicle performs a second XOR operation on the Handle identifier and the result of the first XOR operation to obtain the attribute set of the vehicle itself.
[0029] Specifically, the request flow is successfully matched in the OVS switch flow table, which indicates that the access request of the access vehicle has been processed and is still in the period of the last processing result, so the OVS switch determines how to process this flow according to the action specified in the flow table. If the specified action is forward, it means that the access vehicle satisfies the access strategy defined by the vehicle to be accessed; if the specified action is block, it means that the access vehicle is a malicious user defined by the vehicle to be accessed.
[0030] Preferably, if the reconstructed secret value does not satisfy the secret value of the vehicle to be accessed, the information flow is discarded, and the access request is rejected.
[0031] Specifically, for any attribute of an access vehicle satisfying the access strategy defined by the service provider for the vehicle to be accessed, there exists a reconstruction vector λ∈Z d such that M A T ·λ=ε. Therefore, the reconstruction vector λ can be obtained according to the following equation v :
[0032] M yT ·λ y = ε;
[0033] where M v is the service user attribute vector matrix, λ v is the reconstruction vector, ε = (1, 0, 0, …, 0) T is the target vector. The controller reconstructs the secret value s according to the calculated λ v , that is
[0034] S T λ v = (M v · ρ) T · λ v = ρ T · (M v T · λ v ) = ρ T · ε = s.
[0035] Preferably, the access control policy defined according to the accessed vehicle stipulates the time for the accessed vehicle to access this time.
[0036] Specifically, the accessed vehicle accesses which services within the stipulated time according to the information flow rule. When the access time exceeds the stipulated time, the accessed vehicle needs to perform re-identity authentication and check whether the access policy of the accessed vehicle is met. If the access policy of the accessed vehicle is met, the access can continue, otherwise the access request is rejected.
[0037] Preferably, the vehicle sends its own location information to the virtual machine to obtain a location service based on the location information; and the MAC address of the accessed vehicle and the IP address of the virtual machine corresponding to the accessed vehicle are used as the source MAC address, the destination IP address and the destination MAC address, and the source IP address of the flow table item.
[0038] Specifically, the virtual machine has isolation and can guarantee a certain security. Since the virtual machine is a closed system, only the user exclusive to each virtual machine can access the data stored in the virtual machine, and others cannot access.
[0039] Preferably, it further includes implementing fine-grained data operation based on the information flow model: converting the location service distribution policy into an information flow model, and the accessed vehicle accesses the stipulated services within the stipulated time according to the information flow rule in the information flow model.
[0040] Specifically, the location service distribution policy (SRM) is converted into an information flow model
[0041] IFM = IFR0∪IFR1∪…∪IFR i ;
[0042] IFR = <Creator, Hd, Time, Role>. i IFR = <Creator, Hd, Time, Role>. i
[0043] Wherein Creator is the creator of the information flow rule, Hd is the Handle identity of the vehicle in the system, Time represents the time that the service user can access, Role = {A, U}, A represents that the administrator created this information flow rule, U represents that the ordinary user created this information flow rule, and the priority of the administrator role is greater than that of the ordinary user when there are two conflicting rules, that is, the information flow rule created by the administrator is executed.
[0044] Compared with the prior art, the present application has the beneficial effects that:
[0045] (1) In the present application, the vehicle user exists the position service of the vehicle user in the virtual machine of the third-party service provider, the vehicle user formulates the access control strategy according to the privacy demand of the vehicle user, and sends the access control strategy to the trusted center, the trusted center generates the access control matrix according to the access control strategy of the user, obtains a plurality of attribute vectors of the current vehicle user, the controller judges whether the attribute vector carried when accessing the vehicle satisfies the access control strategy defined by the vehicle to be accessed, and sends the secret value reconstructed to the vehicle to be accessed, and compares the secret value of the vehicle to be accessed, and if it is satisfied, the access request of the vehicle is allowed, and the technical problem of the risk of leakage of the position privacy data of the user in the vehicle network environment is solved.
[0046] (2) The present application uses the Handle technology to uniquely determine the real identity of the vehicle in the system, and uses the Handle identity to replace the traditional MAC or IP address to prevent the user identity from being tampered with; on the other hand, even if the attribute set is stolen by a vehicle in the system, the attacker will not get the attribute information of the vehicle even if he gets the information sent by the trusted center to the vehicle, and the information security of the vehicle user is ensured.
[0047] (3) The present application uses the trusted center to uniformly distribute the attribute information of the access user, and reduces the resource consumption of the access user terminal.
[0048] (4) The present application ensures that only the user satisfying the access control strategy can access the services in the corresponding virtual machine through the dynamic access control algorithm based on the attribute and information flow model, and ensures the safe sharing of the position data. BRIEF DESCRIPTION OF DRAWINGS
[0049] Figure 1 is a method flowchart according to an embodiment of the present application.
[0050] Figure 2 This is a diagram illustrating an application scenario according to an embodiment of the present invention;
[0051] Figure 3 The specific access process for accessing a vehicle according to an embodiment of the present invention. Detailed Implementation
[0052] The technical solutions of various embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0053] Example
[0054] like Figure 1 As shown in the figure, this embodiment discloses a vehicle-to-everything (V2X) access control method for location privacy and security, including the following steps: Vehicle registration: The vehicle to be registered sends its Handle identifier to a trusted center for registration. The trusted center selects a secret value and returns the secret value to the successfully registered vehicle; Vehicle identity authentication: The trusted center generates an access control policy matrix based on the access control policy and access rules sent by the successfully registered vehicle. The access control policy matrix represents multiple attribute vectors of the currently successfully registered vehicle; Attribute-based access control: The accessing vehicle sends a request flow to the OVS switch. The OVS switch sends the request flow to the controller. The controller reconstructs the secret value based on the attribute vectors carried by the accessing vehicle, and determines whether the reconstructed secret value satisfies the secret value of the accessed vehicle. If it does, the controller sends a flow table entry to the OVS switch, allowing the accessing vehicle to make this access request. This solves the problems of identity security and location privacy leakage in the V2X environment.
[0055] First, a location service shared privacy protection model is constructed using the isolation features of virtual machines. Based on the mapping relationship between virtual machines and users, the access policies and service distribution policies of virtual machines are modeled. Second, Handle identifiers replace traditional MAC or IP addresses to prevent user identities from being tampered with. Third, an SDN gateway extended based on attribute access control policies and information flow models is used to protect the privacy data of users stored in LBS service virtual machines and to achieve fine-grained data operations.
[0056] This embodiment provides a vehicle network access control method for location privacy and security, including the following steps:
[0057] Step 1) System initialization: The entire system is managed and guided by a third-party trusted center (TC).
[0058] wherein the step 1) is specifically as follows:
[0059] Step 11) first select a secret value s for authentication and e-1 random integers ρ i , i.e. ρ = (s, ρ2, … ρ e ), wherein k is a security parameter and l0 is a constant.
[0060] Step 12) select a secure encryption hash function Hash: Random number as the master key.
[0061] Step 2) device registration, before access control, each vehicle to be registered in the system needs to register its unique Handle identity and access control strategy in the trusted center TC, and the vehicle VT i registered successfully can obtain its own attribute vector and secret value s i . Only registered vehicles are considered as trusted secure vehicles. If the vehicle is registered successfully, it means that the Handle identity of the vehicle is unique and truly exists in the system. The vehicle information table is maintained in the trusted center TC system to manage the registration information of all vehicles. Based on the attribute and information flow model scheme, three rules need to be met at the same time to generate the attribute vector of each registered vehicle VT i .
[0062] wherein the step 2) is specifically as follows:
[0063] Step 21) first, each vehicle to be registered in the system sends its Handle identity to the trusted center TC, and the trusted center TC determines whether the vehicle to be registered is a unique and real vehicle in the system according to the Handle identity of each vehicle to be registered and the vehicle information table. At the same time, the registered vehicles include access vehicles and accessed vehicles, wherein the accessed vehicles are service providers, and each service provider sends its access control strategy P i to the trusted center TC.
[0064] Step 22) the trusted center TC generates the access strategy matrix M i according to the access control strategy P i of the registered service provider SP i in the system and the rules defined in this paper, and the specific rules are as follows:
[0065] In our access control scheme, we need to convert the access policy into a distribution matrix M, which can be represented by the following three rules. We define M u ∈Z 1×1 is a single-entry matrix, i.e. M u = [1]. There exists a matrix which represents the access policy P v . Let H v ∈Z e denote the first column of M v , and let denote the remaining columns of M except the first column.
[0066] Rule 1:
[0067] Each variable S i in the access policy P can be represented by a matrix M u .
[0068] Rule 2:
[0069] For any OR structure (OR), i.e. P = P1 V P2, the matrices corresponding to the access policies P1 and P2 are and respectively. Therefore, the matrix M OR of the access policy P can be constructed as follows.
[0070]
[0071] Rule 3:
[0072] For any AND structure (AND), i.e. P = P1 A P2, the matrices corresponding to the access policies P0 and P1 are and respectively. Therefore, the matrix M AND of the access policy P can be constructed as follows.
[0073]
[0074] According to the secret value s selected by the trusted center TC and e-1 random integers ρ i i.e. ρ = (s, ρ2,... ρ e ). The trusted center TC calculates S d = M · ρ = (s1, s2,... s d ) T and returns the secret value to the service provider in the system Meanwhile, it calculates and returns it to the corresponding vehicle VT i registered successfully, where v iA certain attribute possessed by a vehicle. For the XOR operation, h(hdi) performs a hash operation on the vehicle's Handle identifier.
[0075] Step 3) Vehicle identification, because each vehicle All vehicles have applied for a Handle identifier. The uniqueness of the Handle identifier can be used to determine the vehicle's true identity within the system. During the registration phase, the Trusted Center (TC) will verify the vehicle's VT (Virtual Vehicle Detection). i Attribute vectors The hash value h(hd) of the vehicle's Handle identifier i Performing an XOR operation is... The result r obtained by the XOR operation i Return to vehicle VT i Vehicle VT i The result can be XORed based on its own Handle identifier. Vehicle VT i It obtains its own attribute set. Even if the attribute set is stolen by a vehicle in the system, because the vehicle's Handle identifier is unique and we believe that the Handle identifier cannot be stolen by an attacker in our system, an attacker, even if they obtain the information sent to the vehicle by the Trusted Center (TC), will not obtain the vehicle's attribute information.
[0076] Step 4) Attribute-based access control: To protect user location privacy and security, after authenticating each vehicle in the system, we need to request access to the vehicle (SUM = {SU0, SU1, SU2, ..., SU...}). n}) to filter out service providers that meet the requirements Access policy vehicles. Only vehicles that meet the service provider's access policy are allowed to access the corresponding virtual machines (VMs). i VT vehicles i To the corresponding virtual machine VM i When an access request is issued, the vehicle carries an attribute vector assigned by the Trust Center. The SND controller analyzes and processes this data to determine whether the service user meets the access policy specified by the service provider and makes a decision to allow or deny access.
[0077] Step 4) is as follows:
[0078] In step 41), if the request flow is successfully matched in the OVS switch flow table, it indicates that the vehicle SU iThe access request has already been processed and is still within the cycle of the last processing result. Therefore, the OVS switch determines how to process this flow according to the action specified in the flow table. If the specified action is "forward," it means that this access vehicle satisfies the service provider's requirements. Defined access policy P i If the specified action is "block", it means that the user accessing the vehicle is a malicious user as defined by the service provider.
[0079] Step 42) The request flow failed to match in the OVS switch flow table. The switch sent this information flow to the controller as a suspicious flow. The controller then determines the suspicious flow based on the access vehicle SU. i Attribute vector carried with the request Determine if the service provider's requirements are met. Defined access policies. After receiving a suspicious flow from the OVS switch, the SDN controller retrieves the access vehicle SU from the flow. i The attribute vector v = (v1, v2, ... v) n For any accessing user whose attributes satisfy the access policy defined by the service provider, there exists a reconstruction vector λ∈Z. d This makes M A T ·λ=ε. Therefore, we can obtain the reconstructed vector λ according to the following equation. v :
[0080] M v T ·λ v =ε
[0081] Where M v For the service user attribute vector matrix, λ v For the reconstructed vector, ε = (1, 0, 0, ..., 0) T The target vector is λ. The controller uses the calculated λ... v The secret value s is reconstructed, that is
[0082] S T λ v =(M v ·ρ) T ·λ v =ρ T ·(M v T ·λ v ) = p T ·ε=s
[0083] Step 43) SDN sends the calculated secret value s to the service provider SP k The comparison is performed. If the verification is successful, it indicates that the accessed vehicle SU... iSatisfy the current user-defined access policy, SDN controller in accordance with the service provider-defined privacy policy provisions access vehicle this time authorized access time, according to the access vehicle SU i MAC address and virtual machine VM i IP address as the source MAC address, destination IP address and destination MAC address, source IP address of the flow table entry. Flow table entry to the OVS switch allows this vehicle access request. If the verification fails, indicating that the access vehicle attributes do not meet the user-defined access policy (illegal user), the controller will discard the information flow to reject its access request.
[0084] Step 5) based on the information flow model to achieve fine-grained data operations, after the above-mentioned based on the attribute-based access control, we can determine the real identity of each vehicle in the system, and allow the vehicle to access the corresponding virtual machine to meet the service provider access policy, reject the access of illegal users or malicious users. We will convert the location service distribution policy into an information flow model to specify which services each authorized vehicle can access and the access time, implement fine-grained data operations, and protect the security of privacy data.
[0085] Wherein, the step 5) is specifically as follows:
[0086] Step 51) we need to convert the location service distribution policy (SRM) into an information flow model
[0087] IFM = IFR0 U IFR1 U … U IFR i
[0088] Where IFR i represents an information flow rule IFR i = <Creator, Hd, Time, Role>.
[0089] Where Creator is the creator of the information flow rule, Hd is the Handle identifier of the vehicle in the system, Time indicates the time when the service user can access, Role = {A, U}, A indicates that the administrator created this information flow rule, U indicates that the ordinary user created this information flow rule, we default When there are two rules conflict, the priority of the administrator role is greater than that of the ordinary user, that is, according to the information flow rule created by the administrator to execute.
[0090] Step 52) access user according to the information flow rule in the specified time to access which services. When the access time exceeds the specified time, the access user needs to perform re-identity authentication and check whether the access policy of the data owner is met. If the access user-defined access policy is met, the access can continue, otherwise the access request is rejected.
[0091] Figure 2 This is the actual scenario used in this embodiment. In the field of connected vehicles, when users request services from third-party service providers, they also store their location privacy data with these providers. LBS service providers can offer many location-based sharing services, such as friend location lookup, friend travel trajectory lookup, and real-time location sharing. However, if a user's privacy data is maliciously obtained, it could pose a significant security risk to the data owner. In this case, each user must pass a gateway screening process before accessing the data. Only users who meet the access policies defined by the data owner can access the corresponding virtual machine through the gateway. Users who do not meet the access policies are denied access, ensuring data privacy and security. Simultaneously, an information flow model is used to ensure which users can access which services, enabling fine-grained data manipulation. Therefore, users need to use a dynamic access control algorithm based on attributes and an information flow model to access data in the corresponding virtual machine, ensuring data privacy and security.
[0092] Figure 3 This is the access flowchart for this embodiment. Assume vehicle V0 stores its location service in a third-party service provider's virtual machine VM0. Vehicle V0 formulates its own access control policy P based on its privacy requirements and sends access policy P to the Trusted Center TC. The Trusted Center TC generates an access control matrix based on the user's access control policy and a random number, and simultaneously sends a secret value to vehicle V0. During the identity verification phase, since each vehicle... All vehicles have applied for a Handle identifier. The uniqueness of the Handle identifier can be used to determine the vehicle's true identity within the system. In our system, during the registration phase, the Trusted Center (TC) will check the vehicle's VT (Virtual Vehicle Detection). i The attributes it has The hash value h(hd) of the vehicle's Handle identifier i Performing an XOR operation is... The result r obtained by the XOR operation i Return to vehicle VT i Vehicle VT i The result can be XORed based on its own Handle identifier. Vehicle VT i Obtain its own attribute set. During the access control phase, if the request flow successfully matches in the OVS switch flow table, it indicates that the vehicle SU... i The access request has already been processed and is still within the cycle of the last processing result. Therefore, the OVS switch determines how to process this flow according to the action specified in the flow table. If the specified action is "forward," it means that this access vehicle satisfies the service provider's requirements. Defined access policy P iIf the specified action is "block", it means that the user accessing the vehicle is a malicious user as defined by the service provider.
[0093] The request flow failed to match in the OVS switch flow table. The switch sent this flow as a suspicious flow to the controller, which then determined the flow based on the attribute vector carried when requesting access to the vehicle SUi. Determine if the service provider's requirements are met. Defined access policies. After receiving a suspicious flow from the OVS switch, the SDN controller retrieves the access vehicle SU from the flow. i The attribute vector v = (v1, v2, ... v) n Therefore, we can use equation M A T ·λ=ε, thus obtaining the reconstructed vector λ v M v For the service user attribute vector matrix, λ v For the reconstructed vector, ε = (1, 0, 0, ..., 0) T The target vector is λ. The controller uses the calculated λ... v and equation S T λ v =(M v ·ρ) T ·λ v =ρ T ·(M v T ·λ v )=ρ T ·ε = s reconstructs the secret value s. SDN sends the calculated secret value s to the service provider SP. k The comparison is performed. If the verification is successful, it indicates that the accessed vehicle SU... i To satisfy the current user-defined access policy, the SDN controller, based on the privacy policy defined by the service provider, specifies the authorized access time for this vehicle and determines the access time based on the access vehicle's SU (User Unit). i MAC address and virtual machine VM i The IP address is used as the source MAC address, destination IP address, and destination MAC address, source IP address in the flow table entry. The flow table entry is sent to the OVS switch to allow the vehicle's access request. If verification fails, it indicates that the attributes of the accessing vehicle do not meet the user-defined access policy (illegal user), and the controller will discard the information flow and refuse its access request. Finally, based on the information flow model, the specific services in the virtual machine that are accessed are determined within the specified access time.
[0094] The embodiment adopts a method different from the previous method, combines Handle identification, linear integer key sharing and software defined network (SDN) in vehicle self-organizing network to protect user location service privacy data. In the method, each vehicle user has a dedicated virtual machine in LBS service provider to save own location service privacy data. Each virtual machine provides a set of services which can only be accessed by legal users meeting own defined access control strategy and service distribution strategy, and each user can define own access control strategy to specify which users can access own services and refuse access of other unauthorized users. Since the virtual machine is a closed system, only the user dedicated to each virtual machine can access data stored in the virtual machine. In order to verify the real identity of each user, Handle identification is introduced to uniquely determine the real identity of each user, and an SDN gateway is designed to protect data of each user stored in the virtual machine of the LBS service provider. A dynamic access control algorithm based on attribute and information flow model is embedded in the SDN gateway to meet the protection of privacy data of each user in a dynamic environment. The SDN gateway screens out authorized users meeting attribute requirements according to the access control strategy defined by the user, and specifies services accessible by each authorized user and access time according to the service distribution strategy defined by the user. The gateway prevents access of unauthorized users.
[0095] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the technical solutions of the embodiments of the present application.
Claims
1. A vehicle network access control method for location privacy and security, characterized in that, Includes the following steps: Send the Handle identifier to the Trusted Center for registration, and receive the secret value returned by the Trusted Center; Send its own location information to obtain location services based on that location information; The system sends its own access control policy to the trusted center and receives the access control policy matrix generated by the trusted center based on the access rules. The access control policy matrix represents multiple attribute vectors of the current vehicle. Specifically, the access rules include three rules, and the generated access control policy matrix must simultaneously satisfy all three rules. These three rules include: Rule 1: Each variable in the access control policy Use matrices express; Rule 2, for any OR structure, i.e. Access control policy and The corresponding matrices are respectively and Therefore, the matrix of access control policy P Constructed in the following manner: , Rule 3: For any AND structure, i.e. Access control policy and The corresponding matrices are respectively and Therefore, the matrix of access control policy P Constructed in the following manner: , The request stream that sends the request is reconstructed based on the attribute vector carried by the accessing vehicle to obtain the reconstructed secret value. It is then determined whether the reconstructed secret value matches the expected secret value. If they match, the access is executed.
2. The vehicle network access control method for location privacy and security according to claim 1, characterized in that, The Trust Center uses the Handle identifier and vehicle information table to determine whether it is the only real vehicle existing in the system; if so, the registration is successful.
3. The vehicle network access control method for location privacy and security according to claim 1, characterized in that, The system initializes by selecting a secure cryptographic hash function Hash, and performs an XOR operation between the vehicle's multiple attribute vectors and the hash function value identified by the Handle to obtain the vehicle's own attribute set.
4. The vehicle network access control method for location privacy and security according to claim 3, characterized in that, The Trust Center performs a first XOR operation on the vehicle's attribute vector and the hash function value of the Handle identifier, and returns the result of the first XOR operation to the vehicle; the vehicle then performs a second XOR operation on its own Handle identifier and the result of the first XOR operation to obtain the vehicle's own attribute set.
5. The vehicle network access control method for location privacy and security according to claim 1, characterized in that, When a vehicle requests a flow from the OVS switch, if the request flow matches successfully in the OVS switch's flow table, the OVS switch will process the request flow according to the action specified in the flow table. If the request flow fails to match, the OVS switch will send the request flow to the controller and reconstruct the secret value for the vehicle.
6. The vehicle network access control method for location privacy and security according to claim 1, characterized in that, If the reconstructed secret value does not match the secret value of the accessed vehicle, the information stream is discarded and the access request is rejected.
7. The vehicle network access control method for location privacy and security according to claim 1, characterized in that, The access control policy defined for the accessed vehicle specifies the authorized access time for this visit.
8. The vehicle network access control method for location privacy and security according to claim 1, characterized in that, The vehicle sends its own location information to the virtual machine to obtain location services based on the location information; the source MAC address and destination IP address and the destination MAC address and source IP address of the virtual machine corresponding to the accessed vehicle are used as flow table entries.
9. A vehicle network access control method for location privacy and security according to claim 1, characterized in that, It also includes fine-grained data operations based on information flow models: the location service distribution strategy is transformed into an information flow model, and the accessing vehicles access the specified services within a specified time according to the information flow rules in the information flow model.
Citation Information
Patent Citations
Information security protection method for vehicle networking terminal equipment
CN107968774B
Strong privacy protection dual authentication method based on node identities and reputations in Internet of vehicles
CN106330910A
Internet of things (IoT) privacy protection method and system for preventing ciphertext from being tampered based on CP-ABE
CN107070652A
Data access control method suitable for interior of automatic driving vehicle
CN112115494A