Deploying digital certificates on terminal devices safely is a prerequisite for PKI based C-V2X direct communication security mechanism to play a role. To overcome the shortcoming of high cost of traditional out-band injection method
a novel initial security configuration solution based on GBA security capability exposed by 4G/5G cellular network is proposed for C-V2X devices in this paper. By taking USIM’s inherent advantages in user identity
root key
GBA capability and hardware security environment
V2X devices at very beginning stage can mutually authenticate and establish secure connection with certificate authorization center through 4G/5G network
then apply for certificates online and implement security self-initialization. It helps to avoid security environment upgrade in production lines and reduce C-V2X technology introduction cost for enterprise greatly. Besides
it also has the characteristics of simple and effective