汽车工程 ›› 2023, Vol. 45 ›› Issue (9): 1626-1636.doi: 10.19562/j.chinasae.qcgc.2023.09.011

所属专题: 智能网联汽车技术专题-控制2023年

• • 上一篇    下一篇



  1. 1.同济大学汽车学院,上海 201804
    2.普华基础软件股份有限公司,上海 200125
  • 收稿日期:2023-05-06 出版日期:2023-09-25 发布日期:2023-09-23
  • 通讯作者: 罗峰 E-mail:luo_feng@tongji.edu.cn
  • 基金资助:

Security Access Control for Service-Oriented Multi-domain Electrical and Electronic Architecture

Zhenyu Yang1,Feng Luo1(),Zitong Wang1,Yi Ren1,Xiaoxian Zhang2   

  1. 1.School of Automotive Studies,Tongji University,Shanghai 201804
    2.ISOFT Infrastructure Software Co. ,Ltd. ,Shanghai 200125
  • Received:2023-05-06 Online:2023-09-25 Published:2023-09-23
  • Contact: Feng Luo E-mail:luo_feng@tongji.edu.cn



关键词: 访问控制, SOME/IP, 多域电子电气架构, 安全协议


Under the service-oriented multi-domain electrical and electronic architecture, a large number of heterogeneous services are deployed in the vehicle for purposes such as autonomous driving, safety, comfort, and remote diagnosis. With the increasing interaction with the outside world, there are incremental security risks in the in-vehicle network. In this paper, a secure access control mechanism is proposed to prevent unauthenticated and unauthorized access requests to the in-vehicle domain controllers. Firstly, an access control architecture for attribute-based access control is proposed based on the analysis of security requirements of intelligent connected vehicle, which supports not only fine-grained and flexible authorization but also online permission detection based on per-stream filtering and policing. Secondly, a formal access control model is given in terms of a five-tuple, which mathematically describes the subject, object, policy and request, and proposes a hash-based policy evaluation engine. Finally, the secure access sequence guarantees confidentiality, integrity and availability of the access control process through session establishment and secure communication.

Key words: access control, SOME/IP, multi-domain EEA, security protocol