A Fine-Grained Access Control Method for Vehicular Ad Hoc Networks Based on Multi-Strategy Access Trees

Through the multi-policy access tree and the Lagrangian polynomial secret value recovery mechanism, the problem that traditional access control models in the Internet of Vehicles cannot meet the fine-grainedness and security is solved, and efficient and secure resource access control is achieved.

CN116390092BActive Publication Date: 2025-07-11ZHIYU ZHILIAN (WUXI) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310067935.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-01
Publication Date
2025-07-11
Estimated Expiration
2043-02-01

AI Technical Summary

Technical Problem

Traditional access control models cannot effectively solve the resource access control problems caused by the distributed, open channel and dynamic networking characteristics of the Internet of Vehicles, especially in terms of fine-grainedness and security.

Method used

The multi-strategy access tree method is adopted, and the secret value is combined with the authorization token through the Lagrangian polynomial secret value recovery mechanism to achieve fine-grained access control of resources, and the multi-strategy access tree structure is used to improve policy access efficiency.

Benefits of technology

It realizes fine-grained access control in the Internet of Vehicles environment, improves the efficiency and security of access control, protects the policy security in the multi-policy access tree, and ensures the fine-grained resource access through the multi-policy tree matching algorithm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116390092B_ABST
    Figure CN116390092B_ABST
Patent Text Reader

Abstract

The present invention provides a fine-grained access control method for the Internet of Vehicles based on a multi-policy access tree, belonging to the technical field of Internet of Vehicles security. It solves the problems of large communication delay, large computational amount, low efficiency, and inability to achieve fine-grained resource access control in the resource security access control algorithm in the Internet of Vehicles environment. The technical solution is as follows: It includes the following steps: S1. Perform identity registration on vehicles and RSU; S2. The vehicle generates a multi-policy access tree and uploads it to the PES; S3. Inform the RSU of the resources it opens; S4. The RSU forwards the request to the PES, and the PES executes the MTRM algorithm; S5. The RSU conveys the access control status calculated by the PES to the vehicle. The beneficial effects of the present invention are: achieving fine-grained access to Internet of Vehicles resources through the formulation of multi-level access policies; greatly improving the access control efficiency; and combining the secret value with the authorization token by introducing the Lagrange polynomial secret value recovery mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle networking security, and particularly to a fine-grained access control method for vehicle networking based on a multi-policy access tree. Background Art

[0002] As an important branch of the Internet of Things in the field of intelligent transportation, vehicle networking is based on in-vehicle networks and vehicle-to-vehicle networks, and performs wireless information transmission and interaction between vehicles, between vehicles and roadside infrastructure, and between vehicles and external networks according to agreed communication protocols and data interaction standards, so as to achieve intelligent traffic management, intelligent dynamic information services, and intelligent vehicle control. As a large-scale distributed system, the massive resources of interconnected vehicles, including basic information, storage resources, redundant computing power, etc., can be fully shared to achieve coordinated vehicle communication, intelligent decision-making, and effectively improve the utilization rate of idle resources. However, due to the high dynamicity and self-organization of the vehicle networking communication topology, a multi-domain and open network environment is formed between roadside units and dynamic vehicles, resulting in the sensitive information of vehicle system resources being easily leaked or tampered with, threatening the property and personal safety of vehicle owners. Therefore, appropriate access control means must be taken to control the resource dissemination in vehicle networking to ensure the secure sharing of resources.

[0003] Traditional access control models mainly include the discretionary access control model, the mandatory access control model, and the role-based access control model, etc., which are mainly applicable to centralized security control systems. However, vehicle networking has new characteristics such as being distributed, having an open channel, dynamic networking, and being highly sensitive to communication latency. The traditional access control model cannot effectively solve its resource access control problem.

[0004] Attribute-based Access Control (ABAC) has been developed to address access control issues in distributed environments. The core idea of the ABAC method is that access between subjects and resources is authorized based on attributes, and the attributes of access control entities are the smallest granularity for access control decisions. Simply put, the access control system grants users the permission to access corresponding data based on their attributes. Due to the advantages of ABAC model such as being distributed, resource scalable, and having fine-grained access control authorization, in the Internet of Vehicles (IoV) environment, it can reduce the complexity of authorization logic and improve the flexibility of access control authorization. Therefore, domestic and foreign scholars have done a lot of work on the research of IoV access control algorithms based on the ABAC model. For example, scholars such as Huang first introduced the CPABE encryption method into the IoV in the paper "attribute-based secure policy enforcement in vehicular ad hocnetworks", and used an attribute-based security access policy framework to achieve fine-grained access control during the resource sharing process, putting forward new ideas for the research of IoV access control technology; scholars such as Liu in the paper "secure and efficient message dissemination with policy enforcement in VANET" solved the problem of large time consumption of attribute-based encryption by outsourcing some complex calculations to a third party; however, the requirements for the credibility and stability conditions of the outsourced third party are very strict, and data leakage or single point of failure problems are likely to occur; Pang Lijun et al. proposed a secure access control scheme for IoV cloud data based on CP-ABE in the paper "A Secure Access Control Scheme for IoV Cloud Data Based on CP-ABE", which solved the problem of large time consumption of attribute-based encryption and decryption algorithms and achieved the characteristics of high encryption and decryption efficiency, but the calculation cost of the vehicle-cloud service provider is relatively large and large delays are likely to occur. Liu Xuejiao et al. introduced the decentralized data storage of blockchain in the paper "A Secure Data Sharing Scheme for IoV Based on Blockchain" to solve the problems of easy tampering and leakage of data under traditional storage conditions, and introduced attribute encryption to solve flexible IoV access control, but the decentralized blockchain data upload will affect the data sharing efficiency and result in large delays; Hou Huiying et al. proposed an efficient and traceable anonymous communication scheme for IoV for autonomous driving in the paper "An Efficient and Traceable Anonymous Communication Scheme for IoV for Autonomous Driving", which demonstrated anonymity through the one-to-many relationship between the attribute set and the vehicle; however, while achieving anonymity, the fine-grainedness of the access control scheme is lost, making it difficult to meet the high requirements for fine-grainedness in the IoV environment.

[0005] How to solve the above technical problems is the problem faced by the present invention. Summary of the Invention

[0006] The present invention proposes a fine-grained access control method for the vehicle networking based on a multi-policy access tree, which mainly improves the traditional single-policy access tree into a multi-policy access tree. Through multi-level policy formulation, fine-grained access to resources is realized, and the policy access efficiency is greatly improved. In the multi-policy access control model, the scheme introduces a Lagrange polynomial secret value recovery mechanism, combines the secret value with the authorization token. As long as the attribute set of the resource-requesting vehicle matches any node of the corresponding tree, the secret value in the node can be calculated, thereby obtaining the access control permission, and solving the security problem of vehicle networking access control authorization.

[0007] The present invention is implemented by the following measures: A fine-grained access control method for the vehicle networking based on a multi-policy access tree, comprising the following steps:

[0008] S1. The trusted authentication center TA initializes the system parameters, and its PKI mechanism uses the Elgamal algorithm to generate public and private keys and certificates for vehicles and RSUs; the policy execution system PES defines a standard attribute set and generates a fixed attribute set for registered vehicles.

[0009] S2. The vehicle defines the access policy for its resources, generates an access policy table, and converts the access policy table into a corresponding multi-policy access tree structure, assigns a secret value to the non-leaf nodes of the access tree, and binds the secret value to the corresponding access policy; the vehicle submits the multi-policy access tree to the policy execution system for storage.

[0010] S3. During the process of the vehicle accessing the vehicle networking, it first conducts two-way identity authentication with the regional RSU to obtain a session key and a temporary pseudonym, and declares its openable resources to the regional RSU.

[0011] S4. The vehicle uses the pseudonym to send a resource request to the RSU; the RSU forwards the attribute set and the open resource object set of the vehicle to the policy execution system; the policy execution system obtains its multi-policy access tree according to the pseudonym of the open resource object, and executes the MTRM matching algorithm: match the attribute set of the applying vehicle with the multi-policy access tree to obtain the authorized node and the corresponding secret value, and according to the secret value, obtain the corresponding access policy, thereby obtaining the corresponding open resource.

[0012] S5. The policy execution system PES sends the accessible resource set to the RSU; the RSU respectively informs the vehicle of the access control status of the corresponding resources of the subject and object according to the vehicle pseudonym.

[0013] Further, the step S1 includes:

[0014] S11. Initialize the system parameters, and the TA randomly selects a prime number q and s, Calculate β = α s(mod q), and use s as the system master key S MK , and use β as the system public key P pub ; TA selects three one-way collision-resistant hash functions: TA publishes the system parameters Param = {q, α, β, H0, H1}, and retains the system master key S MK .

[0015] S12. Attribute normalization definition. Attribute-based access control controls the permissions of entities with attributes as the basic unit. Among them, attributes include the access subject, the accessed resource, the access operation, and the environment. The environmental attributes include the vehicle's network status, road environment, historical information, etc.; the characteristics of the vehicle are described by a series of specific attributes, which can be specifically divided into fixed attributes and variable attributes; fixed attributes are attributes that do not change or remain unchanged for a long time during the vehicle's life cycle, such as vehicle manufacturers, years, and system security levels, etc.; variable attributes are attributes that change periodically, such as the vehicle's current position and driving direction, etc.; in the initialization stage of the policy enforcement system, define the standard attribute set A = {a1, a2,..., a n} of vehicle entities in the vehicle networking system.

[0016] S13. Entity registration. In this stage, mainly realize the offline initialization registration of entity RSU and vehicle V i , and RSU and vehicle V i respectively submit their basic information (public and private keys, identity information) to TA. TA issues certificates for the public keys provided by RSU and vehicles, and PES generates a fixed attribute subset for the vehicle:

[0017] S131. Before deploying the RSU, the vehicle management office uniformly purchases RSU devices and initializes them. The RSU selects a random number as its private key S R , and calculates the public key of the RSU where τ is a primitive element;

[0018] S132. TA issues a certificate Cert R for the RSU. The certificate includes: the public key of the RSU, the certificate validity period, the private key signature of TA, the location information of the RSU, etc. The RSU stores the certificate Cert R and the public key locally;

[0019] S133. The registration of vehicle V i is completed by the trusted certification center TA. Vehicle V i submits basic information (license plate number, vehicle owner identity information, vehicle registration information, vehicle violation information, etc.) to TA. After TA verifies its authenticity, it sets ID i as the unique identity identifier of vehicle V i .

[0020] S134, Vehicle V i Select random number Calculate vehicle V i The public key And put x i Set to Vehicle V i Private key Stored in the tamper-proof device of the OBU, where It is a primitive element;

[0021] S135, TA is vehicle V i Certificate issuance The certificate includes: Vehicle V i The public key ID i , the validity period of the certificate, the TA's private key signature, etc., the vehicle V i Store the certificate in a tamper-proof device at the OBU;

[0022] S136, TA selects a random number n as vehicle V i Calculate pseudo-identity: And the vehicle V i Pseudo ID i ', Identity ID i Make associations;

[0023] S137, the strategy execution system PES according to the vehicle V i The submitted basic information is mapped to the standard attribute set A = {a1, a2, ..., a n}, generate the vehicle V i A subset of the attributes in, For vehicle V i A fixed set of attributes that are authorized in an access control system.

[0024] Furthermore, the S2 step includes:

[0025] S21, generate access strategy table, vehicle V i You can define different access policies for different open resources to achieve fine-grained access. Specifically, by defining multiple access policies, different attribute sets can be mapped to different resources. k , forming a triple access strategy <P i , A i , R i >.

[0026] S22. The purpose of generating the multi-policy tree is to convert the access policy table defined by the vehicle in step S21 into a corresponding multi-policy access tree structure; the algorithm improves the traditional single-policy spanning tree into a multi-policy spanning tree, maps the secret values of different nodes of the spanning tree to different policies, and binds them to the authorization token, so as to achieve efficient and flexible access control. The method of converting the access policy table into the corresponding access tree structure is as follows: Assume that the vehicle attributes are (A, B, C, D, E), and the non-leaf nodes are gate nodes that store secret values. The process of converting the policy table defined by the vehicle into an access tree structure is that if, according to the policy table defined by the vehicle, the vehicle needs to meet one of the following 5 attribute sets to open relevant resources, which is expressed as:

[0027] Attribute set 1: {Attribute A, Attribute B}

[0028] Attribute set 2: {Attribute C}

[0029] Attribute set 3: {Attribute D}

[0030] Attribute set 4: {Attribute E}

[0031] Attribute set 5: {Attribute B}

[0032] And the logical expression corresponding to the generated multi-policy tree structure is:

[0033] (Attribute A && Attribute B) || (Attribute C || Attribute D) || Attribute E

[0034] The multi-policy spanning tree adopts the in-order traversal method in breadth-first traversal. The value of the leaf node is the attribute value, and the non-leaf node contains the threshold value, the node index value index k , k ∈ {1, 2, 3,...}, the secret value secret k and the token H1(index k , secret k ). Only when the threshold value limit is met can the non-leaf node be decrypted to obtain the secret value of the non-leaf node, and then obtain the authorization token for the corresponding resource; generate a multi-policy access tree.

[0035] S23. Storage of the multi-policy access tree. Vehicle V i submits the multi-authorization access tree to the policy execution system of the trusted certification center, including the access tree Tree i , the pseudonym F i and the token policy mapping table T-P-map[][]. Among them, the access tree Tree i is stored using the child representation method, that is, the child nodes of each node are connected by a single linked list to form a linear structure. The policy execution system PES establishes a mapping relationship between the address of the root node of the multi-policy access tree and the corresponding vehicle pseudo-identity ID i '.

[0036] Furthermore, the generation process of the multi-policy access tree is as follows:

[0037] S221. Define the access tree nodes, including the attribute value attr, threshold value gate, index value index, secret value secret, the list of child nodes children[] of non-leaf nodes, and the Lagrange polynomial f(x) of non-leaf nodes.

[0038] S222. Initialize the data. To establish the access tree, it is necessary to define the nodes of the tree. The nodes are divided into two categories: leaf nodes and non-leaf nodes. The Node data structure defines both types of nodes. Use the Node data structure to initialize the array N, and store the attribute values, policies, threshold values, and index numbers of child nodes of the n nodes of the access tree into N.atts, N.Policy, N.gates, and N.children respectively.

[0039] S223. Establish the spanning tree. Use the data in the array N to assign values to each node in the spanning tree. If the node is a leaf node, use the attribute set atts in the initialized array N to assign attribute values to the leaf node. If it is a non-leaf node, assign the threshold value (k x , num) and child nodes to the node according to the threshold value set gates and child node set children in the initialized array N.

[0040] S224. Execute the token policy binding algorithm, mainly to realize the permission mapping between the secret value of non-leaf nodes of the access tree and the access policy table, so as to define the access tree as a multi-policy access tree. The specific execution process is as follows:

[0041] S2241. The vehicle selects a random number as the secret value of the root node n of the multi-authorization access tree, calculates the hash value of the secret value and the index value of the root node, and uses the result as the authorization token of the root node. At the same time, establish a mapping relationship between the authorization token and the policy corresponding to this node in the access policy table.

[0042] S2242. Use the number one less than the threshold value of the root node as the degree of the polynomial f(x), the random number array coef[] as the coefficients of the polynomial f(x), the secret value (secret) of the root node as the constant term of the polynomial f(x), and x as the variable to generate the polynomial f(x). And use this polynomial as the node polynomial of the root node.

[0043] S2243. The vehicle substitutes the index value index of the child node of the root node as the independent variable into the polynomial f(x) of the root node to calculate the secret value of its child node.

[0044] S2244. The vehicle performs a hash operation on the secret value and index value of the child node and uses the hash value as the authorization token for its child node.

[0045] S2245. The vehicle maps the access policy Policy corresponding to node n in the access policy table to the authorization token token of node n and stores this mapping in the T-A-map[][] table.

[0046] S2246. Execute a recursive loop. In the recursive loop, use the child node of this node as the new root node, but there is no need to initialize the secret value and token of the root node anymore; until this root node is a leaf node of the access tree.

[0047] S2247. Use the token policy mapping table T-P-map[][] as the return result for the authorization credential when other vehicles access.

[0048] Further, the S3 step includes:

[0049] S31. Two-way authentication. The RSU periodically broadcasts the certificate and signature. When vehicle V i drives into the communication area of the RSU, it obtains the certificate Cert R and the public key of the RSU, and uses this public key to verify the validity of the RSU signature, thereby determining the legality of the RSU identity. Similarly, vehicle V i sends its certificate, timestamp, and signature, etc. to the RSU. The timestamp is used to prevent replay attacks; after the RSU obtains the certificate of vehicle V i , it uses the public key of V i to verify the validity of the signature of vehicle V i , thereby verifying the legality of the identity of vehicle V i .

[0050] S32. Session key generation. After both parties verify the legality of their identities, perform the session key generation operation. The process is as follows: The RSU and vehicle V i respectively select a random number a, b. The RSU selects a large prime number p and an integer g and makes them public. The RSU calculates K1 = g a mod p and sends to vehicle V i , vehicle V i uses its private key S Vi to decrypt , and calculates the session key key = (K1) b mod p. Then, vehicle V i calculates K2 = g b mod p and sends to the RSU. The RSU decrypts , and calculates the session key key = (K2)a modp; After the session key is calculated, the RSU generates a temporary pseudonym F for vehicle V i by calculating F i = H3(ID i '||Nonce), where Nonce is a random number, and sends it to vehicle V i . In the area of this RSU, the vehicle communicates using the temporary pseudonym

[0051] S33. Declare available resources. The target vehicle V j generates a ciphertext message using the session key and sends it to the RSU. The message includes: the pseudonym F j , the resource set R k , the location of vehicle V j and the timestamp TS. After decrypting the message using the session key, the RSU first verifies the timeliness based on the timestamp TS. If it times out, it verifies again. Then it compares the value with ΔL. If it is greater, it means that vehicle V has left the jurisdiction of the current RSU and rejects this declaration. Otherwise, it stores the relevant field values of vehicle V i in the available resource table of the vehicle, indicating that the resource is open for application by the vehicles in the area of this RSU j .

[0052] Further, the step S4 includes:

[0053] S41. V i applies for resources. The source vehicle V i sends a resource request message to the RSU where the set represents the resource request set required by vehicle V i , and TS represents the timestamp, which is used to prevent replay attacks

[0054]

[0055] Locate the target vehicle. The RSU receives the application message. After decrypting and verifying the timeliness, it locates the target vehicle V j that meets the resource requirements. The process is as follows: The RSU generates a request resource attribute set i for the source vehicle V retrieves the vehicle available resource table according to the resource request set of vehicle V i and returns the pseudonyms of the target vehicles V j that meet the conditions. If there are multiple matches, it returns the set of pseudonyms of the target vehicles that meet the conditions {F1,..., F k}

[0056] S42. The RSU forwards the resource access request of the subject vehicle V i to the PES The request message contains the following fields: the attribute set of the subject vehicle V i ; the pseudonym set {F1,..., F } of the object vehicles that meet the conditions; and the timestamp TS. Use the system public key P k to encrypt this request message: pub

[0057]

[0058] The policy enforcement system PES decrypts this request message using the master key S MK and, with the vehicle pseudonym set {F1,..., F k} in the request message fields as the index conditions of the multi-policy access tree, determines the multi-policy access trees corresponding to multiple pseudonyms F j and, for each multi-policy access tree, performs an authorization matching check one by one according to the following steps; PES determines multiple access trees tree j using the resource request information sent by the RSU, and then executes the multi-policy tree resource matching (MTRM) algorithm to check the authorization of the subject vehicle resources and generate the highest-privilege resource set;

[0059] PES retrieves the triple access policy table in S2 according to the PolicyList[] obtained by the MTRM algorithm. If the policies obtained by PolicyList[] are {P1, P2,..., P k}, the corresponding resource sets in the access policy table should be {R1, R2,..., R k}, then the maximum policy resource set R max = R1 ∪ R2 ∪... ∪ R k can be generated; PES uses R max as the resource set accessible by the subject vehicle V i .

[0060] Furthermore, the process of PES executing the multi-policy tree resource matching algorithm is as follows:

[0061] S421. PES traverses forward from the last node of the tree in turn until the root node is reached.

[0062] S422. PES determines whether each node is a leaf node according to each node. If it is a leaf node, it determines whether the attribute value of the subject vehicle meets the attribute value of the node; if it is a non-leaf node, it determines whether each child node of the non-leaf node is a valid node. If it is a valid node, it inserts the node into the available child array.

[0063] ​S423. PES determines whether the number of nodes in the available child array of node n reaches the threshold value, and determines whether the secret value of node n can be restored.

[0064] S424. PES traverses the available child array of the recoverable non-leaf node n, calculates the Lagrange interpolation factors of the effective child nodes, and uses the Lagrange interpolation factors of the effective child nodes and the secret value to recover the secret value of the non-leaf node n.

[0065] S425. PES performs a hash operation on the secret value of the non-leaf node n and the node index value, and uses the calculation result as the token of the node n.

[0066] S426. PES matches the token of the node with the elements in the token attribute column in T_P_map[][] generated by the resource owner of the multi-policy access tree, and inserts the results that meet the token matching conditions into the policy list.

[0067] S427. PES returns the policy list PolicyList[], which contains all the access control policies corresponding to the secret values of the non-leaf nodes that meet the attribute matching in the multi-policy access control tree, realizing fine-grained and efficient access control of a multi-policy access control tree.

[0068] Further, the step S5 includes:

[0069] S51. PES encrypts the authorization notification message with the RSU public key and sends it to the RSU:

[0070]

[0071] Including the following fields: the subject vehicle pseudonym F i 、the object vehicle pseudonym F j 、the set of accessible resources R i of V max and the timestamp TS.

[0072] S52. The RSU generates an authorization notification message 1 for the subject vehicle V i ,and this message contains the status of the vehicle V i 's resource request and the timestamp TS, and encrypts it using the session key key i :

[0073]

[0074] If vehicle V i receives this message, it indicates that the resource request authorization is successful.

[0075] S53. The RSU generates an authorization notification message 2 for the object vehicle Vj :

[0076]

[0077] This message contains the set of accessible resources R j of V max and the timestamp TS. V j opens the resources waiting for access by the host vehicle V i Compared with the prior art, the beneficial effects of the present invention are as follows:

[0078] (1) A fine-grained access control method for vehicle networking based on a multi-strategy access tree of the present invention innovatively designs a multi-strategy access tree formulated by multiple levels of strategies. In the multi-strategy access tree, all non-leaf nodes can be defined as an access strategy. By using the Lagrange interpolation formula to determine whether the child nodes of the non-leaf node meet the threshold value, the permission level granted to the resource requester is determined. Finally, the highest permission level in the non-leaf node is obtained. The design of the multi-strategy access tree effectively improves the access efficiency of the strategy.

[0079] (2) A fine-grained access control method for vehicle networking based on a multi-strategy access tree of the present invention innovatively designs a token strategy binding algorithm for calculating the secret value of non-leaf nodes of the multi-strategy access tree and the permission mapping of the access policy table: The calculation of the secret value of non-leaf nodes of the multi-strategy access tree is generated according to the basic principle of the Lagrange interpolation formula by the root node and the access policy defined by the resource owner (the threshold value of each node). The permission mapping of the access policy table mainly maps the secret value of the non-leaf node to a token and binds the token to the strategy corresponding to the node, effectively protecting the security of the strategies defined in the multi-strategy access tree.

[0080] (3) A fine-grained access control method for vehicle networking based on a multi-strategy access tree of the present invention innovatively designs a multi-strategy tree matching algorithm (MTRM) for resource authorization check of resource requesters: The multi-strategy access tree determines whether it meets the threshold value of the non-leaf node corresponding to the leaf node by matching the leaf node corresponding to the attribute set of the resource requester. According to the basic principle of the Lagrange interpolation formula, the token of the non-leaf node can be obtained, and then the strategy corresponding to the non-leaf node can be obtained. Finally, the one with the highest permission level is used as the final return result. The multi-strategy tree matching algorithm is the core of the multi-strategy of the access tree, achieving the effect of fine-grained resource access control in vehicle networking. BRIEF DESCRIPTION OF THE DRAWINGS

[0081] The drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation to the present invention.

[0082] Figure 1 Flow chart of the vehicle networking fine-grained access control based on multi-policy access tree according to an embodiment of the present invention;

[0083] Figure 2 Schematic diagram of the vehicle networking architecture according to an embodiment of the present invention;

[0084] Figure 3 System logic architecture diagram according to an embodiment of the present invention;

[0085] Figure 4 Scheme framework diagram of the vehicle networking fine-grained access control based on multi-policy access tree according to an embodiment of the present invention;

[0086] Figure 5 Schematic diagram of the system initialization process according to an embodiment of the present invention;

[0087] Figure 6 Schematic diagram of the multi-policy access tree generation process according to an embodiment of the present invention;

[0088] Figure 7 Schematic framework of the multi-authorization access tree structure according to an embodiment of the present invention;

[0089] Figure 8 Flow chart of the vehicle network access verification according to an embodiment of the present invention;

[0090] Figure 9 Flow chart of the resource access control according to an embodiment of the present invention;

[0091] Figure 10 Flow chart of the resource authorization process according to an embodiment of the present invention;

[0092] Figure 11 Comparison of the policy matching calculation overhead according to an embodiment of the present invention Figure 1 ;

[0093] Figure 12 Comparison of the policy matching calculation overhead according to an embodiment of the present invention Figure 2 ; Detailed implementation manners

[0094] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Of course, the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0095] Embodiment

[0096] Refer to Figures 1 to 12 , the technical solution provided by the present invention is that this embodiment provides a vehicle networking fine-grained access control method based on a multi-policy access tree. As Figure 1 shown, the method includes the following steps:

[0097] S1. The trusted authority initializes the system parameters and the standard attribute set, and registers the identities of the vehicles and RSU.

[0098] S2. The vehicle generates a multi-policy access tree and uploads it to the PES.

[0099] S3. After the vehicle accesses the Internet of Vehicles, it notifies the RSU of the resources it opens.

[0100] S4. The vehicle requests resources, the RSU forwards the request to the PES, and the PES executes the MTRM algorithm.

[0101] S5. The RSU conveys the access control status calculated by the PES to the vehicle.

[0102] As Figure 2 shown, in the fine-grained access control method for the Internet of Vehicles based on the multi-policy access tree, the Internet of Vehicles architecture includes:

[0103] 1. Trusted Authentication Center (TA): The trusted authentication center is an authoritative institution that establishes a connection with the Road Side Unit (RSU) through a wired network, and is mainly used for initializing the system parameters of the Internet of Vehicles system, issuing certificates, and entity authentication, etc.

[0104] 2. Road Side Unit (RSU): The road side unit is usually fixed on both sides of the road and at intersections, has strong computing power and storage capacity, provides services for in-vehicle units to access the network, and at the same time, cooperates with the trusted authentication center TA to process system data.

[0105] 3. On-Board Unit (OBU): The on-board unit of the vehicle has certain computing and storage capabilities. It uses the DSRC vehicle-to-vehicle short-range communication protocol or other wireless communication protocols to communicate with other OBUs and RSUs to form a network. At the same time, the on-board unit is also the resource owner and resource visitor in the system.

[0106] As Figure 3 shown, the Internet of Vehicles access control model of the fine-grained access control method for the Internet of Vehicles based on the multi-policy access tree has three layers. The bottom layer is the network composed of OBUs, the middle layer is the RSU access network, and the top layer is the trusted authentication institution (trusted authentication center, policy enforcement system).

[0107] 1. The trusted authentication institution includes two parts: the trusted authentication center TA and the policy enforcement system PES (Policy Enforcement System). In this solution, the trusted authentication center is mainly responsible for initializing the system parameters, providing PKI authentication services for vehicles and RSUs, and assisting the RSU to achieve reliable access of mobile vehicle nodes; the policy enforcement system (i.e., the access control server) is responsible for policy initialization definition and authorization control work.

[0108] 2. The RSU communicates wirelessly with the vehicles within its jurisdiction through the DSRC protocol or other wireless communication protocols. In this solution, due to its strong computing power and storage capacity, it is mainly responsible for applying for the permissions of resource owners for resource requesters.

[0109] 3. Each vehicle is equipped with an OBU module. In this solution, it mainly serves as the object (resource owner) and the subject (resource requester) in the access control system. At the same time, the object vehicle as the resource owner needs to initialize its access policy for the open resources according to the standard attribute set.

[0110] As Figure 4 shown, it includes the following steps:

[0111] S1. The trusted authentication center TA initializes the system parameters. Its PKI mechanism uses the Elgamal algorithm to generate public and private keys and certificates for vehicles and RSU; the policy execution system PES defines the standard attribute set and generates a fixed attribute set for the registered vehicles.

[0112] S2. The vehicle defines the access policy for its resources, generates an access policy table, and converts the access policy table into a corresponding multi-policy access tree structure. Assigns a secret value to the non-leaf nodes of the access tree, binds the secret value to the corresponding access policy; the vehicle submits the multi-policy access tree to the policy execution system for storage.

[0113] S3. During the process of accessing the Internet of Vehicles, the vehicle first conducts a two-way identity authentication with the regional RSU, obtains the session key and the temporary pseudonym, and declares its openable resources to the regional RSU.

[0114] S4. The vehicle uses the pseudonym to send a resource request to the RSU; the RSU forwards the attribute set and the open resource object set of the vehicle to the policy execution system; the policy execution system obtains its multi-policy access tree according to the pseudonym of the open resource object, and executes the MTRM matching algorithm: match the attribute set of the applying vehicle with the multi-policy access tree to obtain the authorized nodes and the corresponding secret values, and according to the secret values, obtain the corresponding access policy, so as to obtain the corresponding open resources.

[0115] S5. The policy execution system PES sends the accessible resource set to the RSU; the RSU respectively informs the subject and object vehicles of the access control status of the corresponding resources according to the vehicle pseudonym.

[0116] As Figure 5 , the S1 step includes:

[0117] S11. System parameter initialization, TA randomly selects prime numbers q and s, calculate β = α s (mod q), and take s as the system master key SMK , β serves as the system public key P pub ; TA selects three one-way collision-resistant hash functions: TA publishes the system parameters Param = {q, α, β, H0, H1} and retains the system master key S MK .

[0118] S12. Attribute normalization definition. Attribute-based access control controls the permissions of entities based on attributes as the basic unit. Among them, attributes include the access subject, the accessed resource, the access operation, and the environment. Environmental attributes include the network status of the vehicle, the road environment, historical information, etc.; the characteristics of the vehicle are described by a series of specific attributes, which can be specifically divided into fixed attributes and variable attributes; fixed attributes are attributes that do not change or remain unchanged for a long time during the vehicle life cycle, such as vehicle manufacturers, years, and system security levels, etc.; variable attributes are attributes that change periodically, such as the current position and driving direction of the vehicle, as shown in Table 1 below:

[0119] Table 1

[0120]

[0121]

[0122] In the initialization stage of the policy enforcement system, the standard attribute set A = {a1, a2,..., a n} of vehicle entities in the vehicle networking system is defined.

[0123] S13. Entity registration. In this stage, the offline initialization registration of entities RSU and vehicle V i is mainly realized. RSU and vehicle V i submit their basic information (public and private keys, identity information) to TA respectively. TA issues certificates for the public keys provided by RSU and the vehicle. PES generates a fixed attribute subset for the vehicle:

[0124] S131. Before deploying the RSU, the vehicle management office uniformly purchases RSU devices and initializes them. The RSU selects a random number as its private key S R and calculates the public key of the RSU where τ is a primitive element;

[0125] S132. TA issues a certificate Cert R for the RSU. The certificate contains: the public key of the RSU, the certificate validity period, the private key signature of TA, the location information of the RSU, etc. The RSU stores the certificate Cert R and the public key locally;

[0126] S133. Vehicle V iRegistration is completed by the trusted certification authority TA, and the vehicle V i submits basic information (license plate number, vehicle owner's identity information, vehicle registration information, vehicle violation information, etc.) to the TA. After the TA verifies its authenticity, it sets the ID i as the unique identity identifier of the vehicle V i ;

[0127] S134. The vehicle V i selects a random number and calculates the public key of the vehicle V i and sets x as the private key of the vehicle V i and stores it in the non-tamperable device of the OBU, where i is a primitive element;

[0128] S135. The TA issues a certificate for the vehicle V i The certificate includes: the public key of the vehicle V identity identifier ID i the validity period of the certificate, the private key signature of the TA, etc. The vehicle V stores the certificate in the non-tamperable device of the OBU; i i

[0129] S136. The TA selects a random number n for the vehicle V i and calculates the pseudo-identity: and associates the pseudo-identity ID' of the vehicle V i with the identity identifier ID i ; i

[0130] S137. The policy enforcement system PES maps according to the basic information submitted by the vehicle V i to the standard attribute set A = {a1, a2,..., a n} and generates the attribute subset of this vehicle V i where, is the fixed attribute set authorized for the vehicle V i in the access control system.

[0131] For example Figure 6 , the S2 step includes:

[0132] S21. Generate an access policy table. The vehicle V i can define different access policies for its own different open resources to achieve fine-grained access. Specifically, by defining multiple access policies, map the attribute sets that meet different conditions to different resources R k ​​​​​​, to form a triple access policy <P i , A i , R i >: as shown in Table 2 below

[0133] Table 2

[0134]

[0135] S22. The purpose of generating a multi-policy tree is to convert the access policy table defined by the vehicle in step S21 into a corresponding multi-policy access tree structure; the algorithm improves the traditional single-policy generation tree into a multi-policy generation tree, maps the secret values of different nodes of the generation tree to different policies, and binds them to the authorization token, so as to achieve efficient and flexible access control. The method of converting the access policy table into the corresponding access tree structure is as follows: assume that the vehicle attributes are (A, B, C, D, E), the non-leaf nodes are gate nodes, and store the secret values. The process of converting the policy table defined by the vehicle into the access tree structure is that if, according to the policy table defined by the vehicle, the vehicle needs to meet one of the following 5 attribute sets to open the relevant resources, which is expressed as:

[0136] Attribute set 1: {Attribute A, Attribute B}

[0137] Attribute set 2: {Attribute C}

[0138] Attribute set 3: {Attribute D}

[0139] Attribute set 4: {Attribute E}

[0140] Attribute set 5: {Attribute B}

[0141] And the logical expression corresponding to the generated multi-policy tree structure is:

[0142] (Attribute A && Attribute B) || (Attribute C || Attribute D) || Attribute E. The formed multi-policy tree structure is as Figure 7 shown;

[0143] The multi-policy generation tree adopts the in-order traversal method in breadth-first traversal. The value of the leaf node is the attribute value, and the non-leaf node contains the threshold value, the node index value index k , (k ∈ {1, 2, 3,...}), the secret value secret k and the token H1(index k , secret k ). Only when the threshold value is satisfied can the non-leaf node be decrypted to obtain the secret value of the non-leaf node, and then obtain the authorization token for the corresponding resource; further generate a multi-policy access tree:

[0144] S221. Define the access tree nodes, including the attribute value attr, threshold value gate, index value index, secret value secret, the list of child nodes children[] of non-leaf nodes, and the Lagrange polynomial f(x) of non-leaf nodes. The specific content is shown in Table 3 below:

[0145] Table 3

[0146]

[0147] S222. Initialize the data. To build the access tree, it is necessary to define the nodes of the tree. The nodes are divided into two categories: leaf and non-leaf. The Node data structure defines both types of nodes. Use the Node data structure to initialize the array N, and store the attribute values, policies, threshold values, and index numbers of child nodes of the n nodes of the access tree into N.atts, N.Policy, N.gates, and N.children respectively. The specific content is shown in Table 4 below:

[0148] Table 4

[0149]

[0150]

[0151] S223. Build the spanning tree. Use the data in the array N to assign values to each node in the spanning tree. If the node is a leaf node, use the attribute set atts in the initialized array N to assign attribute values to the leaf node. If it is a non-leaf node, assign the threshold value (k x , num) and child nodes to the node according to the threshold value set gates and child node set children in the initialized array N. The specific content is shown in Table 5 below:

[0152] Table 5

[0153]

[0154] S224. Execute the token policy binding algorithm, which mainly realizes the permission mapping between the secret value of non-leaf nodes of the access tree and the access policy table, so as to define the access tree as a multi-policy access tree. The specific execution process is shown in Table 6 below:

[0155] Table 6

[0156]

[0157]

[0158] S2241. The vehicle selects a random number as the secret value of the root node n of the multi-authorization access tree, calculates the hash value of the secret value and the index value of the root node, and uses the result as the authorization token of the root node. At the same time, a mapping relationship is established between the authorization token and the policy corresponding to the node in the access policy table.

[0159] S2242. Using the threshold value of the root node minus 1 as the degree of the polynomial f(x), the random number array coef[] as the coefficients of the polynomial f(x), the secret value (secret) of the root node as the constant term of the polynomial f(x), and x as the variable, generate the polynomial f(x); and use this polynomial as the node polynomial of the root node.

[0160] S2243. The vehicle substitutes the index value index of the child node of the root node as the independent variable into the polynomial f(x) of the root node to calculate the secret value of its child node.

[0161] S2244. The vehicle performs a hash operation on the secret value and the index value of the child node, and uses the hash value as the authorization token of its child node.

[0162] S2245. The vehicle maps the access policy Policy corresponding to node n in the access policy table to the authorization token token of node n, and stores this mapping in the T-A-map[][] table.

[0163] S2246. Execute a recursive loop. In the recursive loop, use the child node of this node as the new root node, but there is no need to initialize the secret value and token of the root node; until this root node is the leaf node of the access tree.

[0164] S2247. Use the token-policy mapping table T-P-map[][] as the return result for the authorization credential when other vehicles access.

[0165] S23. Multi-policy access tree storage. Vehicle V i submits the multi-authorization access tree to the policy execution system of the trusted certification center, including the access tree Tree i , the pseudonym F i and the token-policy mapping table T-P-map[][]. Among them, the access tree Tree i is stored using the child representation method, that is, the child nodes of each node are connected by a single linked list to form a linear structure. The policy execution system PES establishes a mapping relationship between the address of the root node of this multi-policy access tree and the corresponding vehicle pseudo-identity ID i '.

[0166] Such as Figure 8 , the S3 step includes:

[0167] S31. Mutual authentication. The RSU periodically broadcasts its certificate and signature. When vehicle V enters the communication area of the RSU, it obtains the certificate Cert and the public key of the RSU, and uses this public key to verify the validity of the RSU's signature, thereby determining the legitimacy of the RSU's identity. Similarly, vehicle V sends its certificate, timestamp, and signature, etc. to the RSU. The timestamp is used to prevent replay attacks. After obtaining the certificate of vehicle V, the RSU uses the public key of V to verify the validity of the signature of vehicle V, thereby verifying the legitimacy of the identity of vehicle V. i When driving into the communication area of the RSU, obtain the certificate Cert R and the public key of the RSU, and use this public key to verify the validity of the RSU's signature, thereby determining the legitimacy of the RSU's identity. Similarly, vehicle V i sends its certificate, timestamp, and signature, etc. to the RSU. The timestamp is used to prevent replay attacks. After the RSU obtains the certificate of vehicle V, it uses the public key of V i to verify the validity of the signature of vehicle V i and thereby verify the legitimacy of the identity of vehicle V i ; i

[0168] S32. Session key generation. After both parties verify the legitimacy of their identities, perform the session key generation operation. The process is as follows: The RSU and vehicle V respectively select a random number a, b. The RSU selects a large prime number p and an integer g and makes them public. The RSU calculates K1 = g^a mod p and sends it i to vehicle V. Vehicle V decrypts it using its private key a and calculates the session key key = (K1)^b mod p. Then, vehicle V calculates K2 = g^b mod p and sends it i to the RSU. The RSU decrypts it i and calculates the session key key = (K2)^a mod p. After the session key is calculated, the RSU calculates a temporary pseudonym F for vehicle V = H3(ID'||Nonce), where Nonce is a random number, and sends it b to vehicle V. In the area of this RSU, the vehicle uses the temporary pseudonym for communication. i b a i i i i

[0169] S33. Declare available resources. The target vehicle V uses the session key to generate a ciphertext message j and sends it to the RSU. The message includes: the pseudonym F , the resource set R j , the location of vehicle V k and the timestamp TS. After the RSU decrypts this message using the session key, it first verifies the timeliness according to the timestamp TS. If it times out, verify again. Then compare the values j ​​​​​​​​​​​​​ Whether it is greater than ΔL. If so, it indicates that vehicle V i has left the jurisdiction area of the current RSU, and this declaration is rejected. Otherwise, the relevant field values of this vehicle V j are stored in the vehicle available resource table, indicating that this resource is open for application by vehicles in the RSU area; as shown in Table 7 below:

[0170] Table 7

[0171]

[0172] For example Figure 9 , step S4 includes:

[0173] S41. Vehicle V i applies for resources. The main vehicle V i sends a resource request message to the RSU where the set represents the resource request set required by vehicle V i , and TS represents the time stamp, which is used to prevent replay attacks:

[0174]

[0175] Locate the target vehicle. After receiving the application message, decrypting and verifying the timeliness, the RSU locates the target vehicle V that meets the resource requirements j , and the process is as follows: The RSU generates a request resource attribute set for the main vehicle V i According to the resource request set of vehicle V , the vehicle available resource table is retrieved, and the target vehicle V that meets the conditions is returned i pseudonym. If there are multiple matches, the set of pseudonyms of the target vehicles that meet the conditions {F1,..., F j} is returned. k}

[0176] S42. The RSU forwards the resource access request of the main vehicle V i to the PES. The request message contains the following fields: the attribute set of the main vehicle V , the set of pseudonyms of the target vehicles that meet the conditions {F1,..., F i} and the time stamp TS. This request message is encrypted using the system public key P k pub} and the time stamp TS. This request message is encrypted using the system public key P pub :

[0177]

[0178] The policy execution system PES decrypts this request message using the master key S MK and uses the set of vehicle pseudonyms {F1,..., F in the request message fields k} Determine multiple pseudonyms F as the index conditions of the multi-policy access tree j Corresponding multi-policy access trees, and for each multi-policy access tree, perform authorization matching checks one by one according to the following algorithm; PES determines multiple access trees tree using the resource request information sent by the RSU j After that, execute the multi-policy tree resource matching (MTRM) algorithm for the main vehicle resource authorization check to generate the highest-privilege resource set; the specific process is shown in Table 8 below:

[0179] Table 8

[0180]

[0181] S421. PES traverses from the last node of the tree in sequence until the root node is reached.

[0182] S422. PES determines whether each node is a leaf node according to each node. If it is a leaf node, it determines whether the attribute value of the main vehicle satisfies the attribute value of the node; if it is a non-leaf node, it determines whether each child node of the non-leaf node is a valid node. If it is a valid node, insert it into the available child array of the node.

[0183] S423. PES determines whether the number of nodes in the available child array of the node n reaches the threshold value to determine whether the secret value of the node n can be restored.

[0184] S424. PES traverses the available child array of the recoverable non-leaf node n, calculates the Lagrange interpolation factor of the valid child nodes, and uses the Lagrange interpolation factor of the valid child nodes and the secret value to restore the secret value of the non-leaf node n.

[0185] S425. PES performs a hash operation on the secret value of the non-leaf node n and the node index value, and uses the calculation result as the token of the node n.

[0186] S426. PES matches the token of the node with the elements in the token attribute column in T_P_map[][] generated by the resource owner of the multi-policy access tree, and inserts the results that meet the token matching conditions into the policy list.

[0187] S427. PES returns the policy list PolicyList[], and PolicyList[] contains all the access control policies corresponding to the secret values of the non-leaf nodes that meet the attribute matching in the multi-policy access control tree, realizing a fine-grained and efficient access control that supports multiple policies for an access control tree.

[0188] PES retrieves the triple access policy table in S2 according to the PolicyList[] obtained by the MTRM algorithm. If the policies obtained by PolicyList[] are {P1, P2,..., P k}, the corresponding resource sets in the access policy table should be {R1, R2,..., R k}, then the maximum policy resource set R max = R1 ∪ R2 ∪... ∪ R k can be generated; PES uses R max as the resource set accessible to the host vehicle V i .

[0189] For example Figure 10 , the step S5 includes:

[0190] S51. PES encrypts the authorization notification message with the RSU public key and sends it to the RSU:

[0191]

[0192] It includes the following fields: the host vehicle pseudonym F i , the target vehicle pseudonym F j , the accessible resource set R i of V max and the timestamp TS.

[0193] S52. The RSU generates an authorization notification message 1 for the host vehicle V i . This message contains the status of the vehicle V i 's resource request and the timestamp TS, and encrypts it using the session key key i :

[0194]

[0195] If the vehicle V i receives this message, it indicates that the resource request authorization is successful.

[0196] S53. The RSU generates an authorization notification message 2 for the target vehicle V j :

[0197]

[0198] This message contains the accessible resource set R j of V max and the timestamp TS. V j opens the resources and waits for access by the host vehicle V i .

[0199] To verify the feasibility of this embodiment, the correctness and method feasibility of the present invention are analyzed.

[0200] 1. Proof of Security

[0201] Theorem Given a1, a2,..., a n+1 are distinct numbers in the number field F, and b1, b2,..., b n+1 are arbitrary numbers in the number field F that are not all zero. If there exists a unique polynomial f(x) of degree not exceeding n in the number field F such that

[0202]

[0203] And the polynomial f(x) can be expressed as

[0204]

[0205] Formula (2) is called the Lagrange interpolation formula. Then the generation and recovery of the secret values in the above multi-strategy access tree access control scheme are secure.

[0206] Proof Let the polynomial f(x) = c0 + c1x + c2x 2 +... + c n x n .

[0207] 1) Proof of the Existence and Uniqueness of the Polynomial

[0208] From equation (1), we have:

[0209]

[0210] Take the secret values of the leaf nodes that match the multi-strategy access tree attribute A i of the resource requester and the resource owner as the constant terms {b1, b2,..., b n+1} of equation (3). The index value of the current leaf node in its parent node (non-leaf node) is the coefficient a i (i = 1, 2,... n + 1) in equation (3). The number of valid attribute values of the resource requester is the highest degree n in the linear equations of equation (3). Also, equation (3) is a system of linear equations of n + 1 linear equations with c0, c1,..., c n as unknowns. Then its coefficient determinant (denoted as D) is an (n + 1)-order Vandermonde determinant, and

[0211]

[0212] Also, when i ≠ j, the index values a i , a j of the leaf nodes are not equal (a i ≠ a j), so \(D\neq0\), that is, the linear equation system (3) has a unique solution \(c_0, c_1, \cdots, c\) n . Therefore, in the number field \(F\), there exists only a unique polynomial \(f(x)=c_0 + c_1x + c_2x\) 2 +\cdots + c n x n such that \(f(a i ) = b i (i = 1, 2, \cdots, n + 1)\) holds. Thus, it can be concluded that the polynomial function \(f(x)\) of each non - leaf node can be uniquely determined by the attribute set \(A\) i ' of its corresponding leaf nodes.

[0213] However, if the number of valid attributes of the resource requester is less than the threshold value of the corresponding non - leaf node (\(n\lt k\) x ), then the highest degree of the unique polynomial \(f(x)=c_0 + c_1x + c_2x\) 2 +\cdots + c n x n existing in the number field \(F\) will be less than \((k x - 1)\).

[0214] 2) Proof of polynomial correctness

[0215] According to Cramer's rule, we can get where \(D j+1 is the determinant obtained by replacing the \((j + 1)\) - th column of \(D\) with the constant column \(b_1, b_2, \cdots, b\) n+1 in equation (3).

[0216]

[0217] Substituting into the polynomial \(f(x)\) gives equation (4)

[0218]

[0219] where \(A ij is the algebraic cofactor of \(a ij in \(D\). By exchanging the double - summation signs in equation (4), we get

[0220]

[0221] And This is also a Vandermode determinant, so we have equation (6)

[0222]

[0223] Substituting equation (6) into equation (5) gives Furthermore, the Lagrange interpolation formula is obtained.

[0224] Since the degree of the polynomial defined for each non - leaf node in the multi - policy access tree of the resource owner is determined by the threshold value k of this node x of this node, and the secret value secret and the index value index of the child nodes of each non - leaf node satisfy secret = f(index). Therefore, by substituting the attribute values of k x resource requesters into the leaf nodes of the multi - policy access tree of the resource owner, determining their corresponding secret values, and combining with the index value of this leaf node under the current non - leaf node, a unique known polynomial function f(x) of the non - leaf node can be determined.

[0225] Conversely, if n < k x , then the (k x -1) - order polynomial f(x) predefined for the current non - leaf node cannot be generated. At this time, the polynomial f(x) constructed by n leaf nodes * ≠ f(x).

[0226] 3) Proof of security for secret recovery

[0227] Since when the independent variable of the polynomial function of the non - leaf node is 0, the calculation result f(0) of f(x) is the secret value of the current non - leaf node. Therefore, only when the attribute values of the resource requester are included in the attribute set of the current non - leaf node and satisfy the threshold value k x can the secret value of the current non - leaf node be recovered.

[0228] Conversely, if f(x) * ≠ f(x), then f(0) * ≠ f(0). Therefore, if the attributes of the resource requester do not meet the threshold value of the non - leaf node of the multi - policy access tree of the resource owner (n < k x ), the secret value of this node cannot be obtained through the Lagrange interpolation polynomial, and the access right corresponding to this node cannot be obtained either.

[0229] To sum up, if the attribute set of the resource requester does not meet the predefined attribute set and threshold value of the multi - policy access tree, the resources of the resource owner cannot be obtained. Therefore, the resource matching of this scheme on the multi - policy access tree is secure.

[0230] 2. Identity privacy

[0231] When the vehicle communicates with other entities in the vehicle - to - everything system using a temporary pseudonym during the message transmission process, the anonymity of the vehicle identity can be guaranteed. In this scheme, only the TA can restore the true identity of the vehicle according to its pseudo - identity. Given that the pseudo - identity of vehicle V i is the true identity ID iThe TA generates the vehicle ID when the vehicle is registered offline. Therefore, based on the anti-collision property of the secure hash function, the attacker cannot restore the real identity of the vehicle based on the pseudo-identity. Therefore, this solution meets the anonymity requirements of the vehicle identity.

[0232] 3. Message non-repudiation

[0233] During the process of declaring open resources and resource requests, the TA should be able to trace the real identity of the vehicle. The TA can reveal the real identity of the vehicle through XOR operation based on the pseudo identity of the vehicle. The specific process is as follows:

[0234] Known temporary pseudonym F i is determined by the RSU according to the vehicle V i Pseudo ID' i Generate, when the vehicle V i When driving illegally, RSU will inform TA vehicle V i The pseudo-identity of TA is calculated by For vehicle V i The real identity of the person is traced and the trace results are reported to the relevant judicial department. Therefore, this solution meets the requirement of non-repudiation of the message.

[0235] 4. Performance Analysis

[0236] The performance of this scheme is compared with that of the "Efficient and Verifiable Multi-Authorization Attribute-Based Encryption Scheme" proposed by Zhong Hong et al. (Scheme 1), the "Traceable and Revocable Multi-Authorization Center Attribute-Based Encryption Scheme in Vehicle Ad Hoc Networks" proposed by Wu Jingwen et al. (Scheme 2), the "Multi-Authorization Attribute Encryption Scheme with Verifiable Outsourcing Supporting Attribute Revocation" proposed by Ming Yang et al. (Scheme 3), and the "Multi-Authorization Access Control Scheme Supporting Policy Hiding in Satellite Networks" proposed by Wang Yaqiong et al. (Scheme 4).

[0237] Refer to Table 9 below. This study is a simulation experiment. The simulation development kit uses the JPBC cryptographic library. The simulation hardware platform CPU is AMD Ryzen 5 5600H, and the memory is 16GB. Scheme [1-4] encrypts and decrypts the attribute value of the entity by performing bilinear operations on group G. Let l be the number of attributes of the entity. According to the experimental results of Scheme 2, the execution time of bilinear cryptographic operations is:

[0238] Table 9

[0239]

[0240] The comparison results of the four solutions in terms of strategy matching calculation overhead are shown in Table 10:

[0241] Table 10

[0242]

[0243] During the performance simulation test of this experiment, since the time value required for single - access policy matching calculation is small, the relative error of different sample data is large. Therefore, the experiment reduces the relative error by taking the average value of 100 times. When the multi - policy access tree of the simulation experiment contains only 1 policy, let the number of attributes be 5, 10, 15, 20 respectively for performance testing. Then, when the number of attributes is fixed at 20, let the number of policies of the multi - policy access tree be 4, 8, 12, 16 respectively for performance testing. In all the above cases, the method of running multiple times and calculating the average value is used to eliminate the data error caused by environmental differences.

[0244] Take the number of attributes of the resource requester as the abscissa and the time overhead as the ordinate. The number of policies of the scheme is set to 1. According to the experimental data in Scheme 2 and the simulation results in this simulation, determine the comparison of the execution policy matching calculation overhead of each scheme as Figure 11 shown.

[0245] Since this scheme needs to calculate the secret value for each node of the multi - policy access tree and complete the policy matching for the valid attribute values that match the multi - policy access tree, and during the process of restoring the secret value and completing the policy matching, the increase in the number of leaf nodes corresponding to the valid attribute values will lead to an increase in the Lagrange factors of the non - leaf node polynomials. Therefore, as the number of attributes increases, the calculation overhead of policy matching will also increase. However, when the access control policy is unique and the number of attributes gradually increases, the calculation overhead of this scheme for 100 - time policy matching is significantly less than that of other schemes.

[0246] Take the number of policies as the abscissa and the time overhead as the ordinate, and set the number of attributes of each scheme to 20. According to the experimental data in Scheme 2 and the simulation results in this simulation, determine the comparison of the execution policy matching calculation overhead of each scheme, as Figure 12 shown.

[0247] Since when this scheme performs policy matching on the multi - policy access tree and takes all its non - leaf nodes as policies, if the number of valid attribute values that match the multi - policy access tree is the same, the number of Lagrange interpolation factors of the non - leaf node polynomials to be calculated is also approximately the same. Therefore, when the number of attributes is the same, the increase in the access control policy has a negligible impact on the calculation overhead of policy matching. The calculation overhead of this scheme is almost close to a straight line. And when the number of attributes is the same and the access control policy increases, the calculation overhead of this scheme for 10 - time policy matching is significantly less than that of other schemes.

[0248] In summary, since complex bilinear operations are not used in constructing the multi-policy access tree and policy matching in this solution, the computational overhead of policy matching in this solution is significantly less than that of other solutions under the conditions of the same number of attribute values or the same number of policies. At the same time, the multi-policy access tree realizes fine-grained access control. Therefore, it is suitable for use in the vehicle networking environment with a large number of resource visitors and small communication delay.

[0249] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A fine-grained access control method for vehicle networking based on a multi-strategy access tree, characterized in that, It includes the following steps: S1. The trusted authentication center TA initializes the system parameters. Its PKI mechanism uses the Elgamal algorithm to generate public-private keys and certificates for vehicles and RSUs; the policy enforcement system PES defines a standard attribute set and generates a fixed attribute set for registered vehicles; S2. The vehicle defines the access policies for its resources, generates an access policy table, and converts the access policy table into a corresponding multi-policy access tree structure. Secret values are assigned to the non-leaf nodes of the access tree, and the secret values are bound to the corresponding access policies; the vehicle submits the multi-policy access tree to the policy enforcement system for storage; S3. During the process of accessing the vehicle network, the vehicle first conducts a two-way identity authentication with the regional RSU, obtains a session key and a temporary pseudonym, and declares its openable resources to the regional RSU; S4. The vehicle sends a resource request to the RSU using the pseudonym; the RSU forwards the vehicle's attribute set and the open resource object set to the policy enforcement system; the policy enforcement system obtains its multi-policy access tree according to the pseudonym of the open resource object and executes the MTRM matching algorithm: matching the attribute set of the applying vehicle with the multi-policy access tree to obtain the authorized nodes and the corresponding secret values, and according to the secret values, obtaining the corresponding access policies, so as to obtain the corresponding open resources; S5. The policy enforcement system PES sends the accessible resource set to the RSU; the RSU, according to the vehicle pseudonym, respectively informs the vehicle of the access control status of the corresponding resources of the subject and object.

2. The fine-grained access control method for vehicle networking based on a multi-policy access tree according to claim 1, wherein The S1 step includes: S11. System parameter initialization. TA randomly selects prime numbers q and s, calculates β = α s (mod q), and takes s as the system master key S MK , and β as the system public key P pub ; TA selects three one-way collision-resistant hash functions: H0, H1, H2: TA publishes the system parameters Param = {q, α, β, H0, H1}, and retains the system master key S MK ; S12. Attribute standardization definition. In attribute-based access control, the permissions of entities are controlled with attributes as the basic unit, where attributes include the access subject, the accessed resource, the access operation, and the environment. The environmental attributes include the vehicle's network status, road environment, and historical information. The characteristics of a vehicle are described by a series of specific attributes, which are specifically divided into fixed attributes and variable attributes. Fixed attributes are those that do not change or remain unchanged for a long time during the vehicle's life cycle. Variable attributes are those that change periodically. In the initialization phase, the policy execution system defines the standard attribute set A = {a1, a2,..., a n} for vehicle entities in the vehicle networking system; S13. Entity registration. In this stage, the offline initialization registration of the entity RSU and the vehicle V is realized. i The RSU and the vehicle V i submit their basic information, public-private keys, and identity information to the TA respectively. The TA issues certificates for the public keys provided to the RSU and the vehicle, and the PES generates a fixed attribute subset for the vehicle. S131. Before deploying the RSU, the vehicle management office uniformly purchases the RSU devices and initializes them. The RSU selects a random number as its private key S R , and calculates the public key of the RSU where τ is a primitive element; S132. TA issues certificate Cert to the RSU R , and the certificate contains: the public key of the RSU, the certificate validity period, the private key signature of the TA, and the location information of the RSU. The RSU stores the certificate Cert R and the public key locally; S133, Vehicle V i Registration is completed by the trusted certification authority TA. Vehicle V i submits basic information, including license plate number, vehicle owner's identity information, vehicle registration information, and vehicle violation information, to TA. After TA verifies its authenticity, it sets the ID i as the unique identity identifier of Vehicle V i ; S134, Vehicle V i Select random number Calculate vehicle V i The public key And put x i Set to Vehicle V i Private key Stored in the tamper-proof device of the OBU, where It is a primitive element; S135 and TA are for vehicle V i Issuing a certificate The certificate includes: vehicle V i 's public key Identity identifier ID i , the validity period of the certificate, the private key signature of TA, vehicle V i Stores the certificate in the non-tamperable device of the OBU; S136. TA selects a random number n as vehicle V i Calculate the pseudo - identity: And for vehicle V i The pseudo - identity ID i ', and the identity identifier ID i Perform an association; S137. The Policy Execution System PES maps according to the basic information submitted by vehicle V i to the standard attribute set A = {a1, a2,..., a n}, generating the attribute subset of this vehicle V i wherein, is the fixed attribute set authorized by vehicle V in the access control system. i ​ 3. The fine-grained access control method for vehicle networking based on a multi-policy access tree according to claim 2, wherein The S2 step includes: S21. Generate an access policy table. Vehicle V i Defines different access policies for its different open resources to achieve fine-grained access. Specifically, by defining multiple access policies, map different sets of attributes to different resources R k , forming a triple access policy <P i , A i , R i >; S22. The purpose of generating the multi-policy tree is to convert the access policy table defined by the vehicle in the S21 step into a corresponding multi-policy access tree structure; the algorithm improves the traditional single-policy spanning tree to a multi-policy spanning tree, maps the secret values of different nodes of the spanning tree to different policies, and binds them to the authorization tokens. The method of converting the access policy table into a corresponding access tree structure is as follows: assume that the vehicle attributes are (A, B, C, D, E), and the non-leaf nodes are gate nodes, storing secret values. The process of converting the policy table defined by the vehicle into an access tree structure is that if, according to the policy table defined by the vehicle, the vehicle needs to meet one of the following 5 attribute sets to open relevant resources, which is expressed as: Attribute set 1: {Attribute A, Attribute B} Attribute set 2: {Attribute C} Attribute set 3: {Attribute D} Attribute set 4: {Attribute E} Attribute set 5: {Attribute B} And the logical expression corresponding to the generated multi-policy tree structure is: (Attribute A && Attribute B) || (Attribute C || Attribute D) || Attribute E The multi-policy spanning tree adopts the inorder traversal method in breadth-first traversal. The value of the leaf node is the attribute value, and the non-leaf node contains the threshold value and the node index value index k , k ∈ {1, 2, 3,...}, the secret value secret k and the token H1(index k , secret k ). Only when the threshold value limit is met can the non-leaf node be decrypted to obtain the secret value of the non-leaf node, and then the authorization token for the corresponding resource can be obtained; generate a multi-policy access tree; S23. Multi-policy access tree storage, vehicle V i Submit a multi-authorization access tree to the policy execution system of the trusted certification center, including access tree Tree i , pseudonym F i and token policy mapping table T-P-map[][]. Among them, access tree Tree i is stored using the child representation method, that is, the child nodes of each node are connected by a single linked list to form a linear structure. The policy execution system PES establishes a mapping relationship between the address of the root node of the multi-policy access tree and the corresponding vehicle pseudo-identity ID i '.

4. The fine-grained access control method for vehicle networking based on a multi-policy access tree according to claim 3, wherein In the S22 step, the process of generating the multi-policy access tree includes the following steps: S221. Define the access tree nodes, including attribute value attr, threshold gate, index value index, secret value secret, the list of child nodes children[] of the non-leaf node, and the Lagrangian polynomial f(x) of the non-leaf node; S222. Initialize the data. To build an access tree, it is necessary to define the nodes of the tree. The nodes are divided into two categories: leaves and non-leaves. The Node data structure defines both types of nodes. Initialize the array N using the Node data structure, and store the attribute values, policies, threshold values, and index numbers of the child nodes of the n nodes of the access tree into N.atts, N.Policy, N.gates, and N.children respectively. S223. Establish a spanning tree, assign values to each node in the spanning tree using the data in array N. If the node is a leaf node, assign attribute values to the leaf node using the attribute set atts in the initialized array N. If it is a non-leaf node, assign the threshold value (k x , num) and child nodes of the node according to the threshold value set gates and child node set children in the initialized array N; S224. Execute the token policy binding algorithm to realize the permission mapping between the secret values of the non-leaf nodes of the access tree and the access policy table, so as to define the access tree as a multi-policy access tree. The specific execution process is as follows: S2241. The vehicle selects a random number as the secret value of the root node n of the multi-authorization access tree, calculates the hash value of the secret value and the index value of the root node, and uses the result as the authorization token of the root node. Establish a mapping relationship between the authorization token and the policy corresponding to the node in the access policy table. S2242. Take the threshold value of the root node minus 1 as the degree of the polynomial f(x), the random number array coef[] as the coefficients of the polynomial f(x), the secret value (secret) of the root node as the constant term of the polynomial f(x), and x as the variable to generate the polynomial f(x); and use this polynomial as the node polynomial of the root node. S2243. The vehicle substitutes the index value index of the child node of the root node as the independent variable into the polynomial f(x) of the root node to calculate the secret value of its child node. S2244. The vehicle performs a hash operation on the secret value and index value of the child node, and uses the hash value as the authorization token of its child node. S2245. The vehicle maps the access policy Policy corresponding to the node n in the access policy table to the authorization token token of the node n, and stores this mapping in the T-A-map[][] table. S2246. Execute a recursive loop. In the recursive loop, use the child nodes of this node as the new root node, and there is no need to initialize the secret value and token of the root node; until this root node is a leaf node of the access tree. S2247. Use the token policy mapping table T-P-map[][] as the return result for the authorization certificate when other vehicles access.

5. The fine-grained access control method for vehicle networking based on a multi-policy access tree according to claim 4, wherein The specific steps of step S3 are as follows: S31. Mutual authentication. The RSU periodically broadcasts its certificate and signature. When the vehicle V i enters the communication area of the RSU, it obtains the certificate Cert R and the public key of the RSU, and uses the public key to verify the validity of the signature signed by the RSU, so as to determine the legitimacy of the RSU's identity. The vehicle V i sends its certificate, timestamp and signature to the RSU. The timestamp is used to prevent replay attacks. After the RSU obtains the certificate of the vehicle V i , it uses the public key of V i to verify the validity of the signature of the vehicle V i , so as to verify the legitimacy of the identity of the vehicle V i ; S32. Session key generation. After both parties verify the legitimacy of their identities, the session key generation operation is performed. The specific process is as follows: The RSU and vehicle V i respectively select a random number a and b. The RSU selects a large prime number p and an integer g and makes them public. The RSU calculates K1 = g a mod p and sends it to vehicle V i . Vehicle V i uses its private key to decrypt and calculates the session key key = (K1) b mod p. Then, vehicle V i calculates K2 = g b mod p and sends it to the RSU. The RSU decrypts and calculates the session key key = (K2) a mod p. After the session key calculation is completed, the RSU calculates a temporary pseudonym F i for vehicle V i = H3(ID i '||Nonce), where Nonce is a random number, and sends it to vehicle V i . In the area of this RSU, the vehicle communicates using the temporary pseudonym; S33. Declare openable resources, object vehicle V j Generate a ciphertext message using the session key Send it to the RSU. The message contains: pseudonym F j resource set R k vehicle V j position and timestamp TS. After the RSU decrypts the message using the session key, it first verifies the timeliness according to the timestamp TS. If it times out, verify again. Then compare the value whether it is greater than ΔL. If so, it means that vehicle V i has left the jurisdiction area of the current RSU and rejects this declaration. Otherwise, store the relevant field values of the vehicle V j into the available resource table of the vehicle, indicating that the resource is open for application by the vehicles in the RSU area.

6. The fine-grained access control method for vehicle networking based on a multi-policy access tree according to claim 5, wherein The specific content of step S4 includes the following steps: S41, V i Apply for resources, the host vehicle V i Send a resource request message to the RSU Among them, the set Indicates vehicle V i The required resource request set, TS represents the timestamp, which is used to prevent replay attacks: V i → RSU: Locate the target vehicle. After the RSU receives the application message and decrypts and verifies its timeliness, locate the target vehicle V that meets the resource requirements j , and the specific process is as follows: The RSU is the host vehicle V i to generate a set of requested resource attributes According to the resource request set of vehicle V i , retrieve the vehicle available resource table and return the target vehicle V that meets the conditions j pseudonyms. If there are multiple matches, return the set of target vehicle pseudonyms that meet the conditions {F1,..., F k}; S42. The RSU forwards the resource access request of the subject vehicle V i to the PES The request message contains the following fields: the attribute set of the subject vehicle V i , the pseudonym set {F1,..., F } of the object vehicles that meet the conditions, and the timestamp TS. The system public key P k is used to encrypt this request message: pub ​ RSU→PES: The Policy Execution System PES utilizes the master key S MK to decrypt the request message, and uses the set of vehicle pseudonyms {F1,..., F k} in the request message fields as the index condition of the multi-policy access tree to determine multiple pseudonyms F j corresponding multi-policy access trees, and for each multi-policy access tree, perform authorization matching checks one by one according to the following steps; PES uses the resource request information sent by the RSU to determine multiple access trees tree j After that, execute the multi-policy tree resource matching MTRM algorithm for the main vehicle resource authorization check to generate the highest-privilege resource set; PES retrieves the triple access policy table in step S2 according to the PolicyList[] obtained by the MTRM algorithm. If the policies obtained by PolicyList[] are {P1, P2,..., P k}, the corresponding resource sets in the access policy table should be {R1, R2,..., R k}, then the maximum policy resource set R max = R1 ∪ R2 ∪... ∪ R k is generated; PES uses R max as the resource set accessible by the host vehicle V i .

7. The fine-grained access control method for vehicle networking based on a multi-policy access tree according to claim 6, wherein In step S42, the multi-policy tree resource matching algorithm includes: S421. PES traverses forward from the last node of the tree until it reaches the root node. S422. PES judges whether each node is a leaf node according to each node. If it is a leaf node, judge whether the attribute value of the subject vehicle satisfies the attribute value of this node; if it is a non-leaf node, judge whether each child node of this non-leaf node is a valid node. If it is a valid node, insert it into the available child array of this node. S423. PES judges whether the number of nodes in the available child array of this node n reaches the threshold value to determine whether the secret value of node n can be restored. S424. For the recoverable non - leaf node n in the PES traversal, use the child array to calculate the Lagrange interpolation factors of the valid child nodes, and use the Lagrange interpolation factors of the valid child nodes and the secret value to recover the secret value of the non - leaf node n; S425. PES performs a hash operation on the secret value of the non - leaf node n and the node index value, and uses the calculation result as the token of the node n; S426. PES uses the token of the node to match the elements in the token attribute column in T_P_map[][] generated by the resource owner of the multi - policy access tree, and inserts the results that meet the token matching conditions into the policy list; S427. PES returns the policy list PolicyList[], and PolicyList[] contains the access control policies corresponding to the secret values of all non - leaf nodes that meet the attribute matching in the multi - policy access control tree.

8. The fine-grained access control method for vehicle networking based on a multi-policy access tree according to claim 7, wherein The step S5 includes the following steps: S51. PES encrypts the authorization notification message with the RSU public key and sends it to the RSU: PES → RSU: including the following fields: the pseudo name F of the host vehicle i , the pseudo name F of the object vehicle j , the set R of accessible resources of V i and the time stamp TS; max ​ S52. The RSU generates an authorization notification message 1 for the host vehicle V i , and this message contains the vehicle V i status of the resource request and the timestamp TS, and encrypts it using the session key key i : RSU→V i : Vehicle V i If this message is received, it indicates that the resource request authorization is successful; S53. The RSU generates the authorization notice message 2 for the target vehicle V j : RSU→V j : The message contains the access resource set R j and the timestamp TS, where V max opens the resource waiting for the access of the host vehicle V j i .​