诊断主体授权问题是车辆远程故障诊断中的关键问题。针对当前车辆远程诊断授权协议(PVAUDS)中存在的问题,提出了新的车辆远程诊断授权协议(PVAUDS+)。在保证原协议安全目标的前提下,为诊断主体提供双向认证和票据新鲜性验证,并保证发送票据的可信第三方能够有效抵御拒绝服务攻击。使用安全协议证明工具ProVerif对PVAUDS+协议的安全属性进行自动化证明,通过增加发起代价的机制解决对可信第三方的拒绝服务攻击问题,从而说明PVAUSD+协议能够满足提出的安全目标。定量分析结果说明本协议具有较好的可行性。
The authorization of diagnosis principals is a critical problem in the remote fault diagnosis of vehicles. Con- sidering the defects of the previous authorization protocol for the remote diagnosis, i.e. PVAUDS, a novel authorization protocol is proposed, named PVAUDS+. In addition to the enforcement on the security properties of PVAUDS, the bidi- rectional authentication and the freshness of authorization tickets for the diagnosis principals are provided. The resistance of Denial-of-Service (DOS) attack for the trusted third party is also provided. The proposed security targets are achieved through the cost increasing of requests for the resistance of DoS attack, the automatic proof of security properties with the ProVerif tool. The results of quantitative analysis show proposed protocol is practical for use.