A blockchain-based vehicle fog service secure communication system, method and terminal

CN116743387BActive Publication Date: 2026-08-18HUAZHONG NORMAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310494367.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-26
Publication Date
2026-08-18
Estimated Expiration
2043-04-26

AI Technical Summary

Technical Problem

这些方案通常要么忽略用户隐私,要么忽略驾驶车辆所需的时间,无法满足用户对高服务质量和车联网对低时延和高可靠性的要求

Benefits of technology

[0038] First, this invention enables secure communication between the RSU and OBU in vehicle fog service. When a vehicle connects to the system and registers with the TA (Task Agent), both parties need to authenticate each other. After successful authentication, they negotiate a session key for secure communication. After successful registration, the vehicle stores its registration information in its local memory. When using the service, the user logs in using a password and fingerprint. After successful login, the user sends a request to communicate with the RSU, and then both parties verify each other's authenticity. After successful verification, a session key is generated to ensure secure communication between the OBU and RSU.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116743387B_ABST
    Figure CN116743387B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of vehicle communication, and discloses a vehicle fog service security communication system and method based on a blockchain and a terminal, which comprises the following steps: a trusted authority (TA) verifies the original id of a vehicle, allocates a pseudo id to the vehicle, and uses an elliptic curve digital signature algorithm to sign the registration information of the vehicle; a roadside unit (RSU) performs identity authentication and data transmission with a vehicle-mounted unit that sends a communication request; a vehicle-mounted unit (OBU) performs identity authentication and data transmission with a nearby RSU; a blockchain uses a consortium blockchain as a decentralized underlying architecture to be instantiated; the application ensures the ultra-low delay and ultra-high reliability of vehicle fog service when negotiating a security communication key, uses a fog node at the network edge, improves the reliability of the network, and ensures low delay of the network. The communication scheme of the application is lightweight and can resist various known attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of vehicle communication technology, and in particular relates to a blockchain-based vehicle fog service secure communication system, method and terminal. Background Technology

[0002] Currently, Vehicle Fog Service (VFS), as a geographically distributed paradigm, addresses the limitations of traditional vehicular networks (VANETs) in real-time response and location awareness, and supports a wide range of traffic information services. VFS moves some storage and computing resources closer to the data source by moving them from the data center. It can collect and process the collected data in real time, then transmit it to a central server for management and storage, improving communication efficiency and proving highly beneficial for latency-sensitive applications. It can provide various conveniences for people's travel, such as road warnings, congestion control, and autonomous driving. VFS is considered one of the most promising technologies, especially for high-speed moving vehicles, ensuring ultra-low latency, ultra-high reliability, and high security of the communication system. Like the internet, VFS is an open network, vulnerable to various attacks such as impersonation, man-in-the-middle attacks, denial-of-service attacks, replay attacks, and desynchronization attacks. Unlike ordinary IoT systems, VFS should provide conditional anonymity, meaning that vehicle private information (such as physical serial numbers) should only be visible to trusted authorities, and no third-party observer can infringe on the driver's privacy. This feature emphasizes data immutability and accountability mechanisms. Therefore, in order to ensure secure communication in vehicle fog services, a lightweight authentication and key negotiation scheme that can resist various known attacks needs to be designed to guarantee the privacy and property security of trustworthy users.

[0003] Currently, there are few secure communication solutions designed for vehicle fog services, and most authentication schemes are still based on trusted third parties (such as the cloud). These schemes often either ignore user privacy or the time required for driving the vehicle, failing to meet users' requirements for high service quality and the low latency and high reliability of connected vehicles. In addition, a single centralized trusted third party may lead to a single point of failure.

[0004] Based on the above analysis, the problems and defects of the existing technology are as follows: the existing technology cannot meet users' requirements for high service quality and the requirements of vehicle networking for low latency and high reliability, and is susceptible to interference, has low security, and is prone to single point of failure. Summary of the Invention

[0005] To address the problems existing in the prior art, this invention provides a blockchain-based vehicle fog service secure communication system, method, and terminal.

[0006] This invention is implemented as follows: a blockchain-based vehicle fog service secure communication system, the blockchain-based vehicle fog service secure communication system comprising:

[0007] The cloud server, the core of the entire IOV system, possesses ample computing and storage resources and is maintained by authoritative institutions and stakeholders (such as government traffic management departments and vehicle manufacturers). The cloud server serves as both a Trusted Authorization Authority (TA) and a remote database. The TA is considered valid and trustworthy at all times. It is responsible for verifying the vehicle's original ID, assigning it a pseudo-ID, and then signing the vehicle's registration information using an elliptic curve digital signature algorithm.

[0008] Roadside Units (RSUs) are distributed facilities set at fixed intervals along both sides of a road. Their effective range should cover the entire road segment. However, RSUs located at the edge of the network are vulnerable to damage or disabling.

[0009] Each vehicle is equipped with an Onboard Unit (OBU), which enables authentication and data transfer with nearby Rear Units (RSUs) in a mobile environment. Due to resource constraints, the OBU does not support complex computations or massive data storage.

[0010] The blockchain is instantiated using a consortium blockchain as its decentralized underlying architecture. The TA (Task Provider) is responsible for initializing smart contracts and deploying them on the blockchain. Multiple RSUs (Resource Units) and the TA together form a fog zone, responsible for maintaining the blockchain and providing VFS (Virtual Server Provider) to legitimate vehicles. In this invention, RUSs are allowed to access the blockchain but do not participate in the consensus process.

[0011] Another objective of this invention is to provide a blockchain-based vehicle fog service secure communication method applied to the aforementioned blockchain-based vehicle fog service secure communication system, the blockchain-based vehicle fog service secure communication method comprising:

[0012] The system uses an authoritative registration authority to register the on-board units of vehicles connected to the system; users log in using their successfully registered password and fingerprint, and send communication requests to the roadside units.

[0013] The vehicle-mounted unit that sends the communication request and the roadside unit that receives the communication request perform bidirectional authentication, and after successful authentication, a session key is generated to enable secure communication between the vehicle-mounted unit and the roadside unit.

[0014] Furthermore, the blockchain-based secure communication method for vehicle fog services includes the following steps:

[0015] Step 1: The user logs in to the vehicle's On-Board Unit (OBU) using the ID and sends an injection request to a trusted authorized agency through a secure channel to register. The trusted authorized agency receives the registration request, assigns a pseudo ID to the vehicle, and then signs the vehicle's registration information using an elliptic curve digital signature algorithm.

[0016] Step 2: The user logs in using a password and fingerprint. The vehicle unit performs preliminary verification of the password and fingerprint. After successful verification, the vehicle unit encrypts the authentication request and broadcasts the encrypted authentication request to the network through a public channel.

[0017] Step 3: The roadside unit receives the authentication request. At the same time, the roadside unit and the vehicle-mounted unit perform bidirectional authentication by verifying the freshness of the authentication messages between the two parties and whether they are synchronized with the key. After successful authentication, a session key is generated for secure communication between the vehicle-mounted unit and the roadside unit.

[0018] Step four: Update the blockchain data.

[0019] Furthermore, step one includes:

[0020] (1) User inputs ID i and PW i OBU i Choose a random number r1 and calculate the HID. i =h(ID) i ||r1), HPW i =h(PW i ‖r1), and then send a registration request Reqi={HID} to TA1 via the secure channel. i HPW i};

[0021] (2) After receiving the registration request, TA1 selects a random number r2 and generates a random challenge C. i And calculate A1 = h(HID) i ||HPW i ||r2), B1=r2⊕h(HID) i ||HP W i And sign it for OBU using the private key. i Generate fake identity PID i =Sig SKTA1 (h(HID i ‖r2)), and then A1, B1, C through a secure channel i ,P ID i , and the symmetric key K are sent to the OBU i ;

[0022] (3) User input fingerprint BIO i OBU i Calculate Gen(BIO) i )=(σ i ,τ i ), R i =PUF(C i ), B1′=B1⊕r1, C1=h(ID i PW i ||σ i )⊕r1, PID i ' = PID i ⊕HP W i Auth i =h(A1‖HID) i HP W i ‖r1‖σ i Then, R is transmitted via a secure channel. i Send to TA1;

[0023] (4)TA1 is OBU i Choose a temporary identity (TID) i and transmit the temporary identity TID through a secure channel i Send to OBU i Then SCE i ={PID i ,TID i old =null,TID i new =TID i C i ,h(R i Store the data in the cloud database, calculate Hi = h(SCEi), and store PIDi and TID. i H i and pointing to TID i A pointer to the memory address of POINTER_TID i Package and generate a complete transaction set and upload it to the blockchain via a smart contract; finally, OBU i Set {K,PID i ′,B1′,C1,Auth i ,τ i ,TID i old =null,TID i new =TID i Stored in memory.

[0024] Furthermore, step two includes:

[0025] User input ID i PW i and BIO i OBU i Calculate Rep(BIOi, τ) i )=σ i r1 = h(ID) i PW i ||σ i )⊕C1, HID i =h(ID) i ||r i HPW i =h(PW i ||r i ), PID i =PID i ′⊕HPW i r2=B1′⊕r1⊕h(HID) i ||HPW i ), A1 = h(HID) i ||HPW i ||r2), Auth i * =h(A1‖HID) i HPW i ‖r1‖σ i ), and with OBU i Auth stored in i The two are compared; if they are equal, the user login is successful; OBU i The authentication process generates a temporary interaction number n1 and a current timestamp T1, and encrypts the authentication request Req = E using a symmetric key. K {PID i ,TID i ,n1,T1}, and then broadcast {Req} to the network through a public channel.

[0026] Furthermore, step three includes:

[0027] 1) RSU j After receiving the message, check |T1 * Does -T1|≤ΔT hold true, where T1 * This indicates the time when the message was received, where ΔT represents the maximum allowable transmission delay of the network; if this condition is met, the contract algorithm is triggered to query the PID. i Does it exist on the blockchain? If the query is successful, RSU j Get {PID i ,TID i old =null,TIDi new =TID i ,Ci,h(Ri)};Then RSU j Generate n², T², and the new challenge C. i new Further calculate M1 = n2⊕h(TID) i ‖h(R i )‖n1‖T1‖T2), M2=C i new ⊕h(TID i ‖h(R i )‖n1‖n2), M3=h(C i ||C i new (‖n1‖n2‖T1‖T2), and finally, Msg1={M1,M2,M3,C) is transmitted through a public channel. i T1} is sent to the OBU i ;

[0028] 2) OBU i After receiving the message, check |T2 * Does -T2|≤ΔT hold true? If the message freshness condition holds true, then OBU... i Calculate R i =PUF(C i ), n2=M1⊕h(TID) i ‖h(R i )‖n1‖T1‖T2), C i new =M2⊕h(T 1D i ‖h(R i )‖n1‖n2), M3 * =h(C i ||C i new (||n1||n2||T1||T2) and compare it with the received M3. If they are equal, OBU i According to the new challenge C i new Calculate the new response R i new =PUF(C i new Then generate n3 and T3, and further calculate M4 = n3 ⊕ h(TID); i ‖h(R i )‖n2‖T2‖T3), M5=R i new ⊕h(TID i ‖h(R i )‖n2‖n3), M6=h(h(Ri )‖h(R i new Finally, Msg2 = {M4, M5, M6, T3} is sent to RSU via a public channel. j ;

[0029] 3) RSU j After receiving the message, check |T3 * Does -T3|≤ΔT hold true? If the message freshness condition holds true, then RSU... j Calculate n3 = M4⊕h(TID) i ‖h(R i )‖n2‖T2‖T3), R i new =M5⊕h(TID) i ‖h(R i )‖n2‖n3), M6 * =h(h(R) i )‖h(R i new )‖n2‖n3‖T2‖T3), and compare it with the received M6. If they are equal, it means RSU j OBU successfully certified i At this time, RSU j Generate a new temporary identity TID i new Given the temporary interaction number n4 and the current timestamp T4, calculate M7 = n4 ⊕ h(C i new ‖h(R i new )‖n3‖n4‖T4), M8=TID i new ⊕h(TID i ‖h(R i )‖n3‖T3‖T4), SK=h(P ID i ||TID i new ‖h(R i )‖R i new ‖n3‖n4‖T4), M9=h(h(SK)‖TID i new ‖h(R i new Finally, Msg3 = {M7, M8, M9, T4} is sent to the OBU via a public channel. i ;

[0030] 4) After receiving the message, OBUi checks |T4* Does -T4|≤ΔT hold true? If the message freshness condition holds true, calculate n4=M7⊕h(C i new ‖h(R i new )‖n3‖n4‖T4), TID i new =M8⊕h(T ID) i ‖h(R i )‖n3‖T3‖T4), SK=h(PID i ||TID i new ‖h(R i )‖R i new ||n3||n4||T4), M9 * =h(h(SK)‖TID i new ‖h(R i new )‖n3‖n4‖T3‖T4) and compare it with the received M9. If they are equal, it indicates that the OBU i Successfully certified RSU j And obtain the session key SK; OBU i Update Temporary Identity (TID) i old =TID i ,TID i new =TID i new Generate the current timestamp T5, calculate the key verifier SKV = h(h(SK)‖T5), and then send Msg4 = {SKV,T5} to RSU via the public channel. j ;

[0031] 5) RSU j After receiving the message, check |T5 * Does -T5|≤ΔT hold true? If the message freshness condition holds true, then RSU... j Calculate SKV * =h(h(SK)‖T5), and compare it with the received SKV. If they are equal, it means that mutual authentication is completed, and the whole authentication process is synchronous.

[0032] Furthermore, the updated data in the blockchain includes:

[0033] Update data in cloud database SCE i new ={PID i ,TID iold =TID i ,TID i new =TID i new C i ,h(R i )}, calculate H i new =h(SCE) i new ) will {PID i ,TID i new H i new ,POINTER_TID i new Package it into a new block and upload it to the blockchain.

[0034] Another object of the present invention is to provide a computer device including a memory and a processor, the memory storing a computer program, which, when executed by the processor, causes the processor to perform the steps of the blockchain-based vehicle fog service secure communication method.

[0035] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the blockchain-based vehicle fog service secure communication method.

[0036] Another objective of this invention is to provide an information data processing terminal for implementing the blockchain-based vehicle fog service secure communication system.

[0037] Based on the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solution to be protected by this invention are as follows:

[0038] First, this invention enables secure communication between the RSU and OBU in vehicle fog service. When a vehicle connects to the system and registers with the TA (Task Agent), both parties need to authenticate each other. After successful authentication, they negotiate a session key for secure communication. After successful registration, the vehicle stores its registration information in its local memory. When using the service, the user logs in using a password and fingerprint. After successful login, the user sends a request to communicate with the RSU, and then both parties verify each other's authenticity. After successful verification, a session key is generated to ensure secure communication between the OBU and RSU.

[0039] Secondly, this invention ensures ultra-low latency and ultra-high reliability of the vehicle fog service during the negotiation of secure communication keys. The authentication and key negotiation processes do not involve remote trusted parties (such as the cloud), and fog nodes are used at the network edge, improving network reliability and guaranteeing low latency. The communication scheme of this invention is lightweight and resistant to various known attacks. This invention guarantees conditional anonymity and untraceability of the communication protocol under strict ultra-low latency constraints.

[0040] Third, complex communication and processing technologies such as 5G networks and cloud computing are increasingly being used in heterogeneous IoT environments, including vehicle-to-everything (V2X) networks, accelerating the development of vehicle intelligence. VFS is considered the next stage in V2X development, as it can guarantee sufficient computing and storage resources to overcome the challenges of efficient communication and computing brought about by advanced vehicle applications, providing more intelligent traffic information services and improving road quality. However, as an open network, VFS inevitably faces various attacks. This invention primarily aims to protect secure communication within VFS, which is crucial for ensuring VFS provides secure and reliable services. Therefore, the technical solution of this invention, once commercialized, will generate significant expected benefits and commercial value. Attached Figure Description

[0041] Figure 1 This is a schematic diagram of the structure of a blockchain-based vehicle fog service secure communication system provided in an embodiment of the present invention;

[0042] Figure 2 This is a schematic diagram of a blockchain-based secure communication method for vehicle fog services provided in an embodiment of the present invention.

[0043] Figure 3 This is a flowchart of a blockchain-based vehicle fog service secure communication method provided in an embodiment of the present invention;

[0044] Figure 2 In the process: 1. User login: The onboard unit (OBUi) sends a broadcast authentication request (Req); 2. Road test unit (RSU) j 1. Upon receiving the request (Req), send authentication information Msg1; 2. Upon receiving message Msg1, OBUi verifies message freshness and returns message Msg2; 3. RSU j Receive Msg2, verify message freshness, and authenticate OBU. i After successful authentication, send message Msg3; 5. OBU i Received message Msg3, verified message freshness, and authenticated RSU. j After successful authentication, calculate the key verifier SKV and send message Msg4; 6. RSU j Upon receiving Msg4, verify the message freshness and key synchronization. If they are equal, mutual authentication is complete, and update the data in the blockchain. Detailed Implementation

[0045] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0046] like Figure 1 As shown, the blockchain-based vehicle fog service secure communication system provided in this embodiment of the invention includes:

[0047] Trusted Authorities (TAs): A TA is a trusted authority responsible for verifying the vehicle's original ID, assigning it a pseudo-ID, and then signing the vehicle's registration information using the Elliptic Curve Digital Signature Algorithm (ECDSA).

[0048] Roadside Unit (RSU): An RSU is defined as a distributed facility set at fixed intervals along both sides of a road. Multiple RSUs together with TAs constitute a fog zone, which is responsible for maintaining the blockchain and providing VFS to legitimate vehicles.

[0049] On-board Unit (OBU): Each vehicle is equipped with an OBU, which enables authentication and data transfer with nearby RSUs in a mobile environment. Due to resource constraints, the OBU does not support complex calculations and massive data storage.

[0050] Blockchain: Instantiated using a consortium blockchain as a decentralized underlying architecture.

[0051] like Figures 2-3 As shown, the blockchain-based vehicle fog service secure communication method provided in this embodiment of the invention includes the following steps:

[0052] S101, the user logs in to the vehicle's on-board unit (OBU) using the ID and sends an injection request to a trusted authorized agency through a secure channel for registration; the trusted authorized agency receives the registration request, assigns a pseudo ID to the vehicle, and then uses an elliptic curve digital signature algorithm to sign the vehicle's registration information.

[0053] S102, the user logs in using a password and fingerprint. The vehicle unit performs preliminary verification of the password and fingerprint. After successful verification, the vehicle unit encrypts the authentication request and broadcasts the encrypted authentication request to the network through a public channel.

[0054] S103, the roadside unit receives the authentication request, and at the same time, the roadside unit and the vehicle-mounted unit perform bidirectional authentication by verifying the freshness of the authentication messages between the two parties and whether they are synchronized with the key; and after successful authentication, a session key is generated for secure communication between the vehicle-mounted unit and the roadside unit; and blockchain data is updated.

[0055] The secure communication method for vehicle fog services based on blockchain provided in this invention includes a registration phase and an authentication phase. The registration phase involves a registration authority registering the vehicle-mounted unit (V2V); the authentication phase involves bidirectional authentication between the V2V and roadside units (LSUs), and the generation of a session key to enable secure communication between the V2V and LSUs.

[0056] Registration phase:

[0057] User registration: Users register through a trusted authority. The registration process is as follows:

[0058] Step 1. User enters ID i and PW i Subsequently, OBU i Choose a random number r1 and calculate the HID. i =h(ID) i ||r1), HPW i =h(PW i ‖r1), and then send a registration request Reqi={HID} to TA1 via a secure channel. i HPW i}

[0059] Step 2. After receiving the registration request, TA1 selects a random number r2 and generates a random challenge C. i Then calculate A1 = h(HID) i ||HPW i ||r2), B1=r2⊕h(HID) i ||HP W i And sign it for OBU using the private key. i Generate fake identity PID i =Sig SKTA1 (h(HID i ‖r2)), and then A1, B1, C through a secure channel i ,P ID i , and the symmetric key K are sent to the OBU i .

[0060] Step 3. User inputs fingerprint BIO i OBU i Calculate Gen(BIO) i )=(σ i,τ i ), R i =PUF(C i ), B1′=B1⊕r1, C1=h(ID i PW i ||σ i )⊕r1, PID i ' = PID i ⊕HP W i Auth i =h(A1‖HID) i HP W i ‖r1‖σ i Then, R is transmitted via a secure channel. i Send to TA1.

[0061] Step 4. TA1 is the OBU i Choose a temporary identity (TID) i And send it to the OBU via a secure channel. i Then SCE i ={P ID i ,TID i old =null,TID i new =TID i C i ,h(R i Store the data in the cloud database, calculate Hi = h(SCEi), and store PIDi and TID. i H i and pointing to TID i A pointer to the memory address, i.e., POINTER_TID i A complete transaction set is packaged and uploaded to the blockchain via a smart contract. Finally, OBU... i Set {K,PID i ′,B1′,C1,Auth i ,τ i ,TID i old =null,TID i new =TID i} Stored in its memory.

[0062] Certification phase:

[0063] (1) Login: User enters ID i PW i and BIO i OBU i Calculate Rep(BIOi, τ) i)=σ i r1 = h(ID) i PW i ||σ i )⊕C1, HID i =h(ID) i ||r i HPW i =h(PW i ||r i ), PID i =PID i ′⊕HPW i r2=B1′⊕r1⊕h(HID) i ||HPW i ), A1 = h(HID) i ||HPW i ||r2), Auth i * =h(A1‖HID) i HPW i ‖r1‖σ i ), and with OBU i Auth stored in i The two are compared; if they are equal, the user has successfully logged in. Then the OBU... i The authentication process generates a temporary interaction number n1 and a current timestamp T1, and encrypts the authentication request Req = E using a symmetric key. K {PID i ,TID i ,n1,T1}, and then broadcast {Req} to the network through a public channel.

[0064] (2) Mutual authentication: After successful user login, the on-board unit and the roadside unit perform mutual authentication. The authentication steps are as follows:

[0065] Step 1. RSU j After receiving the message, check |T1 * Does -T1|≤ΔT hold true, where T1 * This indicates the time the message was received, and ΔT represents the maximum allowable transmission delay by the network. If this condition is met, the contract algorithm is triggered to query the PID. i Does it exist on the blockchain? If the query is successful, RSU j Get {PID i ,TID i old =null,TID i new =TID i ,Ci,h(Ri)}. Then RSU jGenerate n², T², and the new challenge C. i new Further calculate M1 = n2⊕h(TID) i ‖h(R i )‖n1‖T1‖T2), M2=C i new ⊕h(TID i ‖h(R i )‖n1‖n2), M3=h(C i ||C i new (‖n1‖n2‖T1‖T2), and finally, Msg1={M1,M2,M3,C) is transmitted through a public channel. i T1} is sent to the OBU i .

[0066] Step 2. OBU i After receiving the message, check |T2 * Does -T2|≤ΔT hold true? If the message freshness condition holds true, then OBU... i Calculate R i =PUF(C i ), n2=M1⊕h(TID) i ‖h(R i )‖n1‖T1‖T2), C i new =M2⊕h(T 1D i ‖h(R i )‖n1‖n2), M3 * =h(C i ||C i new (||n1||n2||T1||T2) and compare it with the received M3. If they are equal, OBU i According to the new challenge C i new Calculate the new response R i new =PUF(C i new Then n3 and T3 are generated, and M4 = n3 ⊕ h(TID) is further calculated. i ‖h(R i )‖n2‖T2‖T3), M5=R i new ⊕h(TID i ‖h(R i )‖n2‖n3), M6=h(h(R i )‖h(R i newFinally, Msg2 = {M4, M5, M6, T3} is sent to RSU via a public channel. j .

[0067] Step 3. RSU j After receiving the message, check |T3 * Does -T3|≤ΔT hold true? If the message freshness condition holds true, then RSU... j Calculate n3 = M4⊕h(TID) i ‖h(R i )‖n2‖T2‖T3), R i new =M5⊕h(TID) i ‖h(R i )‖n2‖n3), M6 * =h(h(R) i )‖h(R i new The result is )‖n2‖n3‖T2‖T3), which is compared with the received M6. If they are equal, it indicates that RSU j OBU successfully certified i At this time, RSU j Generate a new temporary identity TID i new Given the temporary interaction number n4 and the current timestamp T4, calculate M7 = n4 ⊕ h(C i new ‖h(R i new )‖n3‖n4‖T4), M8=TID i new ⊕h(TID i ‖h(R i )‖n3‖T3‖T4), SK=h(P ID i ||TID i new ‖h(R i )‖R i new ‖n3‖n4‖T4), M9=h(h(SK)‖TID i new ‖h(R i new Finally, Msg3 = {M7, M8, M9, T4} is sent to the OBU via a public channel. i .

[0068] Step 4. After receiving the message, OBUi checks |T4 *Does -T4|≤ΔT hold true? If the message freshness condition holds true, calculate n4=M7⊕h(C i new ‖h(R i new )‖n3‖n4‖T4), TID i new =M8⊕h(T ID) i ‖h(R i )‖n3‖T3‖T4), SK=h(PID i ||TID i new ‖h(R i )‖R i new ||n3||n4||T4), M9 * =h(h(SK)‖TID i new ‖h(R i new ()‖n3‖n4‖T3‖T4) and compare it with the received M9. If they are equal, it means that the OBU i Successfully certified RSU j And obtain the session key SK. OBU i Update Temporary Identity (TID) i old =TID i ,TID i new =TID i new Generate the current timestamp T5, calculate the key verifier SKV = h(h(SK)‖T5), and then send Msg4 = {SKV,T5} to RSU via the public channel. j .

[0069] Step 5. RSU j After receiving the message, check |T5 * Does -T5|≤ΔT hold true? If the message freshness condition holds true, then RSU... j Calculate SKV * =h(h(SK)‖T5), and compare it with the received SKV. If they are equal, it means that mutual authentication is complete and the entire authentication process is synchronous. Then update the data SCE in the cloud database. i new ={PID i ,TID i old =TID i ,TID i new =TID inew C i ,h(R i )}, calculate H i new =h(SCE) i new ) will {PID i ,TID i new H i new ,POINTER_TID i new Package it into a new block and upload it to the blockchain.

[0070] The technical solution of this invention can be applied to VFS to ensure communication security and provide secure and reliable vehicle information services. Vehicle privacy information (such as physical serial numbers) should only be visible to trusted authorities, and no third-party observer should infringe on the driver's privacy. This solution provides conditional anonymity, emphasizing data immutability and accountability mechanisms in cases where malicious vehicles release false information leading to accidents or crimes.

[0071] This invention applies the vehicle fog service secure communication method to a computer device, which includes a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the processor executes the vehicle fog service secure communication method.

[0072] The present invention applies the vehicle fog service secure communication method to a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor executes the vehicle fog service secure communication method.

[0073] This invention applies the vehicle fog service secure communication method to an information data processing terminal.

[0074] It should be noted that embodiments of the present invention can be implemented in hardware, software, or a combination of both. The hardware portion can be implemented using dedicated logic; the software portion can be stored in memory and executed by a suitable instruction execution system, such as a microprocessor or dedicated-design hardware. Those skilled in the art will understand that the above-described devices and methods can be implemented using computer-executable instructions and / or included in processor control code, for example, such code provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and modules of the present invention can be implemented by hardware circuitry such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field-programmable gate arrays, programmable logic devices, etc., or by software executed by various types of processors, or by a combination of the above-described hardware circuitry and software, such as firmware.

[0075] In terms of security, this invention provides a variety of functional features that can resist various known attacks, mainly including:

[0076] Privacy and anonymity, privileged insider attacks, desynchronization attacks, impersonation attacks, physical attacks, forward / backward key confidentiality, replay attacks, traceability and non-repudiation, key update attacks, offline password guessing, transient key leakage, man-in-the-middle attacks, etc.

[0077] In terms of communication cost, this invention has a significant advantage. To facilitate comparison of the communication costs of different systems, we assume the hash value (using the SHA-1 algorithm) is 160 bits long, the temporary interaction number and identity information are 128 bits long, symmetric encryption / decryption is 128 bits, and the timestamp is 32 bits. This invention requires the transmission of 5 messages, totaling 2944 bits.

[0078] In terms of computational cost, this invention requires less computational cost. To facilitate comparison of the computational costs of different systems, let T... h T represents the computation time required for a hash operation. eym T represents the computation time required for symmetric encryption / decryption operations. fe T represents the computation time required for the fuzz extractor to generate or copy the function. puf This represents the computation time for the physically non-clonable function. The experimental measurement used is: T. h ≈0.00032s, T sym ≈0.0056s, T fe ≈0.0171s, T puf ≈0.023s. The computational cost required for this invention is 27T. h +2Tsym +T fe +2T puf ≈0.05994s.

[0079] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications, equivalent substitutions, and improvements made by those skilled in the art within the scope of the technology disclosed in the present invention, and within the spirit and principles of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A blockchain-based vehicle fog service secure communication system, characterized in that, include: Cloud servers are used for computing and storage resources and are maintained by authoritative organizations and stakeholders. The cloud server assumes the responsibilities of both a trusted authorization authority and a remote database. A trusted authorization authority is responsible for verifying the vehicle's original ID, assigning it a pseudo ID, and then using the elliptic curve digital signature algorithm to sign the vehicle's registration information. Roadside units are distributed facilities set at fixed intervals along both sides of the road, with an effective range covering the entire road segment. Roadside units located at the edge of the network are easily damaged or disabled. Each vehicle is equipped with an onboard unit that performs authentication and data transmission with nearby roadside units in a mobile environment; however, due to resource constraints, the onboard unit does not support complex calculations and massive data storage. The blockchain uses a consortium blockchain as its decentralized underlying architecture for instantiation. A trusted authorization authority is responsible for initializing smart contracts and deploying them on the blockchain. Multiple roadside units and the trusted authorization authority together constitute a fog zone, responsible for maintaining the blockchain and providing vehicle fog services to legitimate vehicles. Roadside units are allowed to access the blockchain but do not participate in the consensus process. A blockchain-based vehicle fog service secure communication method applied to the aforementioned blockchain-based vehicle fog service secure communication system, the blockchain-based vehicle fog service secure communication method comprising: The system uses an authoritative registration authority to register the on-board units of vehicles connected to the system; users log in using their successfully registered password and fingerprint, and send communication requests to the roadside units. The vehicle-mounted unit sending the communication request and the roadside unit receiving the communication request perform bidirectional authentication, and generate a session key after successful authentication to enable secure communication between the vehicle-mounted unit and the roadside unit; The blockchain-based secure communication method for vehicle fog services includes the following steps: Step 1: The user uses the ID to access the vehicle's onboard unit. Log in and send an injection request to a trusted authorization agency through a secure channel to register; the trusted authorization agency receives the registration request, assigns a pseudo ID to the vehicle, and then uses the elliptic curve digital signature algorithm to sign the vehicle's registration information; Step 2: The user logs in using a password and fingerprint. The vehicle unit performs preliminary verification of the password and fingerprint. After successful verification, the vehicle unit encrypts the authentication request and broadcasts the encrypted authentication request to the network through a public channel. Step 3: The roadside unit receives the authentication request. At the same time, the roadside unit and the vehicle-mounted unit perform bidirectional authentication by verifying the freshness of the authentication messages between the two parties and whether they are synchronized with the key. After successful authentication, a session key is generated for secure communication between the vehicle-mounted unit and the roadside unit. Step four: Update the blockchain data; Step one includes: (1) User input and , Choose a random number and calculate , Then through a secure channel to Send registration request ; (2) After receiving the registration request, select a random number. Generate random challenges and calculate , And signed with private key Generate fake identities Then through a secure channel , and symmetric key Send together ; (3) User inputs fingerprint , calculate , , , , , Then through a secure channel Send to ; (4) for Choose a temporary identity and transmit temporary identity through a secure channel Send to Then Stored in a cloud database, computation ,Will , , and pointing pointer to memory address Package and generate a complete transaction set and upload it to the blockchain via a smart contract; finally Will Stored in memory; Step two includes: User input , and , calculate , , , , , , , and with Stored in The two values ​​are compared; if they are equal, the user has successfully logged in. Initiating the authentication process generates a temporary interaction number. and current timestamp And encrypt the authentication request with a symmetric key. Then broadcast to the network via public channels. .

2. The blockchain-based vehicle fog service secure communication system as described in claim 1, characterized in that, Step three includes: 1) After receiving the message, check. Whether it is valid, among which Indicates the time when the message was received. This indicates the maximum allowable transmission delay on the network; if this condition is met, the contract algorithm is triggered to query. Does it exist on the blockchain? If the query is successful, get ; then generate , and new challenges Further calculations , , Finally, through public channels Send to ; 2) After receiving the message, check. Whether this condition holds true depends on whether the information is fresh. calculate , , , and with the received Compare them; if they are equal, According to the new challenges Calculate the new response Then it produces , Further calculations , , Finally Sent via public channel ; 3) After receiving the message, check. Whether this condition holds true depends on whether the information is fresh. calculate , , and with the received Compare them; if they are equal, it means... Successful authentication ,at this time Generate a new temporary identity Temporary Interaction Number and current timestamp and calculate , , , Finally Sent via public channel ; 4) After receiving the message, check. Whether it holds true, if the message freshness condition is met, calculate. , , , and the received Compare them; if they are equal, it means... Successful authentication and obtain the session key. ; Update temporary identity , Generate the current timestamp And calculate the key verifier Then through public channels Send to ; 5) After receiving the message, check. Whether this condition holds true depends on whether the information is fresh. calculate and with the received The comparison is performed, and if they are equal, it indicates that mutual authentication is complete, and the entire authentication process is synchronous.

3. The blockchain-based vehicle fog service secure communication system as described in claim 1, characterized in that, The updated blockchain data includes: Update data in cloud database ,calculate Will Package it into a new block and upload it to the blockchain.

4. A computer device, characterized in that, The computer device includes a memory and a processor. The memory stores a computer program that, when executed by the processor, causes the processor to perform the steps of the blockchain-based vehicle fog service secure communication system as described in any one of claims 1-3.

5. A computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the blockchain-based vehicle fog service secure communication system as described in any one of claims 1-3.

6. An information data processing terminal, characterized in that, The information data processing terminal is used to implement the blockchain-based vehicle fog service secure communication system as described in claim 1.

Citation Information

Patent Citations

  • Vehicle fog data light-weight anonymous access authentication method based on blockchain assistance

    CN109194610A

  • Lightweight fog-assisted V2G network anonymous identity authentication system, method and device

    CN115834070A