Dual authentication key negotiation method for vehicle networking commuting

By introducing a dual-factor authentication key negotiation method in the Internet of Vehicles system, combining physical non-cloneable functions and TPM chips, the behavioral authentication and identity authentication of vehicles are realized, and the problem of large computing and communication overhead in the Internet of Vehicles commuting scenario is solved, and security and performance are improved.

CN120499654APending Publication Date: 2025-08-15CHONGQING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510923483.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the existing Internet of Vehicle commuting scenarios, the calculation and communication overhead of authentication and key negotiation protocols is relatively high, and the existing solutions have great pressure on certificate management, which cannot effectively improve protocol performance, and poses security risks.

Method used

The dual-factor authentication key negotiation method is adopted, through the collaborative work of trusted centers, roadside units and vehicles, combined with physical non-clone functions and TPM chips, behavior authentication and identity authentication are realized, and the spatio-temporal behavior trust model and dynamic pseudonym mechanism are used to calculate the vehicle's behavior score and control the information release authority, and two-way identity verification and temporary session key negotiation without trusted institutions are supported.

Benefits of technology

In the commuting scenario of Internet of Vehicles, it improves security and performance, reduces computing and communication overhead, ensures information security, and supports the balance between anonymity and traceability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120499654A_ABST
    Figure CN120499654A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of identity authentication in the Internet of Vehicles, and particularly relates to an Internet of Vehicles commuting-oriented dual authentication key negotiation method, which specifically comprises the following steps of: constructing an Internet of Vehicles system which comprises a trusted center, a roadside unit and a vehicle, and publishing initial system parameters by the trusted center; a vehicle, a user and a roadside unit respectively complete identity registration and verification to a credible center, the credible center respectively distributes corresponding identity verification key parameters to the vehicle and the roadside unit, and a driver logs in through a biological key; the credible platform module integrity evaluation report of the vehicle is verified, the behavior score of the vehicle is calculated according to the historical behavior information of the vehicle, and the behavior score is composed of a travel score and an interaction score; after the session key negotiation process between the roadside unit and the vehicles is completed, the roadside unit acts as a main authentication node to realize authentication between the vehicles by using the key information generated by the vehicles, and only after the authentication is completed, an authentication result is uploaded to a trusted center for recording. According to the invention, each entity in the Internet of Vehicles system can be ensured to communicate safely, and the calculation overhead and the communication overhead are reduced, so that the authentication efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of identity authentication in vehicle networking, and specifically relates to a dual authentication key negotiation method for vehicle networking commuting. Background Art

[0002] The average commuting time in major Chinese cities reaches 36 minutes, and the average commuting distance per capita in Type II megacities with populations between 1 million and 3 million is 7.6 kilometers. Intelligent vehicle networking, as a key technological tool for improving urban mobility efficiency, can provide a better driving experience and safer, more convenient travel options. However, communication between vehicles and the infrastructure providing these services occurs over public channels, making them vulnerable to various attacks and security threats. Therefore, ensuring secure communication between vehicles and the infrastructure providing these services is a core issue in the field of vehicle networking.

[0003] Authentication and key agreement between vehicles and the infrastructure providing connected vehicle services are considered key solutions to these problems. Current authentication and key agreement schemes, depending on the authentication node, are categorized into two types: cloud server or trusted authority (TA)-based authentication schemes and proxy-based authentication schemes.

[0004] Authentication schemes based on cloud servers or trusted centers do not require the vehicle's authentication parameters to be sent in advance to agents such as roadside units (RSUs). This means that the vehicle's authentication parameters are not easily leaked, and even if the information stored in the roadside unit (RSU) is stolen, it will not affect the vehicle's identity security. Furthermore, the mutual authentication key negotiation process involving the vehicle, roadside unit (RSU), and trusted center (TA) is more trustworthy and secure than the mutual authentication key negotiation process involving only the roadside unit (RSU) and the vehicle. However, due to the complexity and uncertainty of the Internet, schemes involving trusted centers (TAs) or cloud servers in authentication can introduce uncertain fluctuations in network communication delays, making it impossible for delay-sensitive applications to provide immediate services.

[0005] Proxy-based authentication schemes, by eliminating the need for a trusted center, effectively overcome the problem of fluctuating network latency. These schemes address the single point of failure issue where mutual authentication between a single trusted center (TA) and all roadside units (RSUs) and vehicles in the system can easily lead to insufficient computing resources at the trusted center, excessive system storage load, and ultimately malfunction of the trusted center. However, while proxy-based authentication schemes reduce the burden on the central node to authenticate all vehicles, they require that certain secrets of the entity to be authenticated be sent to the proxy in advance, posing certain security risks.

[0006] In summary, existing authentication and key agreement protocols lack research tailored to the specific characteristics of commuting scenarios to further improve their performance, resulting in high computational and communication overhead for each entity in the connected vehicle network. Furthermore, existing solutions' reliance on certificates places significant pressure on TAs to manage certificates. Summary of the Invention

[0007] To solve the above technical problems, the present invention proposes a dual authentication key negotiation method for vehicle-to-vehicle commuting, comprising the following steps:

[0008] S1. Build a connected vehicle system, including a trusted center (TA), roadside units (RSU), and vehicles. The trusted center publishes its initialization system parameters.

[0009] S2. The vehicle, user, and roadside unit complete identity registration and verification with the TA in advance. The TA assigns corresponding authentication key parameters to the vehicle and roadside unit respectively, and the driver logs in using a biometric key.

[0010] S3. Verify the vehicle's Trusted Platform Module (TPM) integrity assessment report and calculate the vehicle's behavior score based on the vehicle's historical behavior information. The behavior score consists of a travel score and an interaction score.

[0011] S4. After the session key negotiation process between the RSU and the vehicle is completed, the RSU acts as the primary authentication node using the key information generated by the vehicle to authenticate the vehicle to the vehicle. Only after the authentication is completed, the authentication result is uploaded to the TA for record.

[0012] Preferably, step S3 specifically includes:

[0013] S31. Verify the vehicle's TPM integrity assessment report i , if r i If it is 0, it means that the vehicle's TPM integrity assessment report has failed. Matching parameter conf i The value of is determined by the degree of match between the current vehicle TPM configuration and the preset vehicle TPM configuration. If there is any mismatch, conf i The value of is set to 0, otherwise conf i The value of is set to 1.

[0014] S32. Calculate the vehicle's behavior score based on the vehicle's historical behavior information. The vehicle's behavior score is H. i =T i +C i , where T i is the travel score, C i Score the interaction.

[0015] The beneficial effects of the present invention are as follows: at the physical layer, the unique hardware fingerprint of the vehicle terminal is extracted through the Physical Unclonable Function (PUF), and the key storage and secure calculation are realized in combination with the TPM chip, thereby resisting the risks of hardware cloning and key leakage from the physical level; at the authentication layer, a dual verification architecture of behavior authentication and identity authentication is designed. The behavior authentication stage introduces a spatiotemporal behavior trust model. By analyzing the periodic characteristics of the vehicle's commuting route (such as fixed departure time, high-frequency traffic sections), historical interaction behavior (such as message category, message quality) and the continuity of the real-time driving trajectory, a dynamic behavior scoring function is constructed to comprehensively calculate the vehicle's behavior score. Based on this, information release authority control is implemented (for example, vehicles with high behavior scores can release security messages); the identity authentication stage adopts a dynamic pseudonym mechanism to support vehicles to complete two-way identity verification and temporary session key negotiation without the participation of trusted institutions; in addition, the protocol has a pseudonym update and anonymous traceability mechanism. While protecting the privacy of vehicle identities, it supports trusted institutions to restore the true identity of malicious vehicles through the vehicle identity database, effectively balancing anonymity and traceability; the security of the protocol is proved by using the BAN logical model; the vehicle's information release rights are restricted to ensure information security within the Internet of Vehicles. Compared with existing vehicle-to-vehicle (V2V) communication solutions, the protocol proposed in this invention has higher security and performance in commuting scenarios and has good economic benefits. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 This is a vehicle networking system model for a vehicle commuting scenario in an embodiment of the present invention;

[0017] Figure 2 is a flowchart of steps in an embodiment of the present invention;

[0018] Figure 3 This is a flowchart of step S3 in an embodiment of the present invention;

[0019] Figure 4 This is a flow chart of travel score calculation in an embodiment of the present invention;

[0020] Figure 5 This is a flowchart of the interactive scoring in an embodiment of the present invention;

[0021] Figure 6 This is a flowchart of dual authentication in an embodiment of the present invention. DETAILED DESCRIPTION

[0022] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0023] The present invention provides an embodiment of a dual authentication key negotiation method for vehicle-to-vehicle commuting. The vehicle-to-vehicle system constructed in this method involves three entities: a trusted center (TA), a roadside unit (RSU), and a vehicle. During the system initialization phase, the TA generates key parameters such as a system key. During the registration phase, the commuting vehicle and the RSU submit private parameters to the TA and obtain identity information parameters returned by the TA. During the login phase, the commuter's biometric information is verified to complete the login. During the behavior authentication phase, the vehicle's computational integrity report is detected and the commuting vehicle behavior score is calculated based on the vehicle's travel signature and historical interaction behavior records. During the identity authentication phase, session key negotiation is completed between vehicles. During the behavior score update phase, the behavior score is updated based on the vehicle's travel route and information interaction quality. During the pseudonym update phase, the TA updates the pseudonym for the vehicle. During the anonymous tracing phase, the TA traces the corresponding vehicle and RSU based on the pseudonym and changes the relevant information of their real identity.

[0024] In the embodiment provided by the present invention, considering the communication efficiency and security requirements in the context of the Internet of Vehicles system, a model of the Internet of Vehicles system for vehicle commuting scenarios is constructed, such as Figure 1 As shown, where:

[0025] The Trust Center (TA) is a fully trusted entity with powerful computing and storage capabilities, and can be considered a district or county-level traffic management department. It is responsible for the registration of all vehicles and roadside units (RSUs), as well as the identification and revocation of malicious vehicles (vehicles in the IoV system that publish false information).

[0026] A roadside unit (RSU) is an honest but curious entity with limited computing and storage capabilities, potentially stealing sensitive user information. It communicates with the trusted center via wired communication and with vehicles via wireless communication. It also authenticates the vehicle and provides services.

[0027] Vehicle V is an entity equipped with an on-board unit (OBU) and has certain computing and storage capabilities, and has subscribed to the corresponding Internet of Vehicles services on the commuting route.

[0028] like Figure 2As shown, the present invention provides an embodiment of a dual authentication key negotiation method for vehicle-to-vehicle commuting, which specifically includes the following steps:

[0029] S1. Build a connected vehicle system, including a trusted center (TA), roadside units (RSU), and vehicles. The trusted center publishes its initialization system parameters.

[0030] S2. The vehicle, user, and roadside unit complete identity registration and verification with the TA in advance. The TA assigns corresponding authentication key parameters to the vehicle and the roadside unit respectively, and the driver logs in using a biometric key.

[0031] S3. Verify the vehicle's TPM integrity assessment report. After the vehicle's TPM integrity assessment report passes, calculate the vehicle's behavior score based on the vehicle's historical behavior information. The behavior score consists of a travel score and an interaction score.

[0032] S4. After the session key negotiation process between the RSU and the vehicle is completed, the RSU acts as the primary authentication node using the key information generated by the vehicle to authenticate the vehicle to the vehicle. Only after the authentication is completed, the authentication result is uploaded to the TA for record.

[0033] Preferably, in step S1, the initialization system parameters of the Internet of Vehicles system specifically include:

[0034] The trusted center TA selects elliptic curve parameters a and b, a prime number q representing the order of the elliptic curve finite field, and a generator G of the elliptic curve cyclic subgroup.

[0035] The trusted center TA selects a collision-resistant one-way hash function H:{0,1} * →{0,1} l , where l is the bit width of the hash function, which means that this hash function can map binary input of any length to an output of length l bits.

[0036] The trusted center TA selects a random number As the system private key and calculate P pub =s TA P is the system public key, where P is the key negotiation parameter. is the multiplicative group modulo q.

[0037] The trusted center TA publishes system parameters except the system private key.

[0038] Preferably, step S2 specifically includes:

[0039] Since a vehicle may correspond to multiple users, the vehicle and the user should register with the TA separately. The vehicle submits its vehicle information to the TA for registration in order to obtain the private parameters issued by the TA. The user submits his or her biometric information and ID card information to the TA to complete the registration. The specific process is as follows:

[0040] S201. The user takes the fingerprint information as the input of PUF in the car, and then calls the TPM module in the car to input the response of PUF f By hashing H p =H(IN f ) Get the corresponding user's identity H p , then H p It is sent together with the ID card and other information to initiate a user registration request.

[0041] S202. After receiving the user registration request, TA will send the user related information and identity H p The information is saved locally, and the verification parameters are generated using the user-related information during subsequent vehicle registration and sent to the corresponding vehicle.

[0042] In the connected vehicle system, a vehicle submits an identity registration request to the TA offline through a reliable channel. The TA verifies the identity registration request. If the verification is successful, the vehicle obtains the key authentication parameters. The specific process is as follows:

[0043] S211. The vehicle submits information such as license plate number, vehicle make and model, frame number, and in-vehicle TPM device number to TA to initiate a registration request.

[0044] After receiving the vehicle registration request, S212.TA generates a real IDV for the vehicle i And calculate the pseudonym FV i =H1(IDV i ||T i ) , Where T i The time when the vehicle initiates the registration request. Then, TA registers according to the identity H provided by the user. p Calculate the verification parameter H required for the user login stage ver =H(H p ||K p ), where K p Is the login password generated by TA for the user. Finally, the vehicle's real identity IDV i 、Kana FV i , login verification information H ver and login password K p Send to the vehicle and send IDV i 、FV i and save locally.

[0045] S213. The vehicle receives the information {IDV i ,FV i ,H ver}, the received information is stored in the local TPM.

[0046] The roadside unit in the connected vehicle system submits an identity registration request to the TA offline through a reliable channel. The TA verifies the identity registration request. If the verification is successful, the roadside unit obtains the key authentication parameters. The specific process is as follows:

[0047] S221. The RSU submits the device-related information to the TA to initiate a registration request.

[0048] S222. After receiving the RSU registration request, TA generates a real identity IDR for the RSU, and then sends the IDR to the RSU and saves it locally.

[0049] S223. After receiving the message containing the IDR from the TA, the RSU saves the IDR to the local TPM.

[0050] Since the communication behavior of the vehicle is actually controlled by the driver, it is necessary to verify the identity of the driver to prevent illegal persons from stealing the vehicle for malicious communication. Specifically, the driver's biometric information is used as a biometric key to log in, which can initially verify the driver's identity, and then the login password K p It can be used as a supplement to prevent users from being forced to log in. The login process is as follows:

[0051] S231. The vehicle user verifies the fingerprint and gets a response IN f , the user enters the login key K p .

[0052] S232.OBU first calculates H' p =H(IN f ), then calculate H' ver =H(H' p ||K p ), and finally verify H' ver =H ver Is it true? If so, the user has successfully logged in and becomes a legal user of the vehicle. Otherwise, the user cannot legally use the vehicle and obtain Internet of Vehicles services with his or her identity.

[0053] Since the vehicle is equipped with PUF, malicious attackers cannot pass the verification of the biometric key by tampering with the hardware. p The number of attempts is also limited to prevent key guessing.

[0054] Preferably, Figure 3 As shown, step S3 specifically includes:

[0055] S31. Verify the vehicle's TPM integrity assessment report i , its report score is calculated as follows:

[0056]

[0057] Among them, r i is the vehicle's TPM integrity assessment report score, if r i If it is 0, it means that the vehicle's TPM integrity assessment report has failed. Matching parameter conf i The value of is determined by the degree of match between the current vehicle TPM configuration and the preset vehicle TPM configuration. If there is any mismatch, conf i The value of is set to 0, otherwise conf i The value of is set to 1. The above design determines that devices with tampered TPM cannot enter the next authentication process, ensuring that the vehicle's computing and communication behaviors are supervised by the TPM. Then, if the vehicle's TPM integrity assessment report passes.

[0058] S32. Calculate the vehicle's behavior score based on the vehicle's historical behavior information. The vehicle's behavior score is H. i =T i +C i , where H i Score the behavior, T i is the travel score, C i Score the interaction.

[0059] T i The vehicle's travel route within a certain period of time is determined. For commuting vehicles in particular, driving along the commuting route within a certain period of time can improve the vehicle's travel score. However, considering the nature of commuting and the cost of malicious vehicles committing malicious acts, the accumulation period of travel scores has been adjusted to 24 hours. This means that within 24 hours, only one complete round-trip commuting process of the vehicle will be accumulated as travel score, and the remaining commuting processes will not be accumulated as travel score. This prevents malicious vehicles from attempting to accumulate a high travel score in a short period of time and then committing malicious acts. i It is determined by the direct evaluation obtained by the vehicle after each interaction. Whether it is the traffic information reported to the RSU or the various messages provided in the interaction with other vehicles, they will be evaluated by the corresponding entity receiving the message afterwards.

[0060] Preferably, Figure 4 , Figure 5 As shown, the travel score and interaction score are updated in step S32 as follows:

[0061] S321. Within the 24-hour working day timeframe, based on the vehicle travel schedule stored by the TA, when the visit records cover all RSUs in the commuting route and each RSU generates two vehicle visit certificates, the vehicle is determined to have completed a complete round-trip commute.

[0062] S322. It is stipulated that after a vehicle completes a complete round trip, the number of RSUs actually passed by the vehicle on the commuting route is used as the basis for measuring the travel cost, wherein the travel cost is positively correlated with the number of RSUs passed.

[0063] S323. The calculated travel cost is used to update the vehicle's travel score. The higher the travel cost, the more difficult and costly it is for a malicious vehicle to accumulate behavior scores. The update method is as follows:

[0064]

[0065] in, For vehicle V i The travel score after this update, is the travel score up to the last time, d is the vehicle V i The number of days of continuous commuting on weekdays, Cost is the travel cost, N r is the average number of RSUs that all vehicles in the system pass through during their commutes. i The travel score increases nonlinearly, and the cumulative difficulty of the behavior score decreases significantly with the increase of consecutive commuting days.

[0066] S324. When the conversation with the vehicle ends, the vehicle uploads the message of this conversation to the RSU.

[0067] S325. After receiving the message uploaded by the vehicle, the roadside unit (RSU) evaluates the message based on its timeliness and authenticity. The evaluation results include three types: positive evaluation, negative evaluation, and general evaluation. The final interaction score is determined by the proportion of the above three types of evaluation, and its update method is as follows:

[0068]

[0069] in, is the updated interaction score, and E g 、E b and E n are the number of positive reviews, negative reviews, and normal reviews, respectively. is the historical interaction score. It can be seen that when there is a negative evaluation E b When the negative evaluation Eb , then the updated interaction score The ratio of positive reviews to all reviews except negative reviews and the historical interaction score Therefore, frequent information interaction does not quickly accumulate interaction scores, but maintaining high-quality information interaction can quickly accumulate interaction scores. Given this, malicious vehicles need to ensure the quality of their interactions if they want to achieve higher interaction scores, which greatly increases the cost of malicious behavior.

[0070] Preferably, after the vehicle passes the behavior authentication, it will enter the identity authentication phase. Since the session key negotiation process between the RSU and the vehicle is assumed to have been completed, the RSU will serve as the main authentication node in the V2V authentication process at this stage, and will only upload the authentication results to the TA for record after the authentication is completed. The specific authentication process is as follows: Figure 6 As shown, step S4 specifically includes:

[0071] S41. Vehicle V i and V j Generate key parameters P respectively i and P j Calculation method P i =i·G、P j =j·G. Where i and j are vehicle V i and V j The random number selected. Then, the vehicle V i and V j Select the current timestamp T svi and T svj , and send the message M containing the key parameters, pseudonym and timestamp i ={P i ,FV i ,T svi} and M j ={P j ,FV j ,T svj}Sent to RSU.

[0072] S42.RSU receives message M i ={P i ,FV i ,T svi} and M j ={P j ,FV j ,T svj}, first pass T rri -T svi <Δt、T rrj -T svj <Δt check timestamp T svi and T svjThe effectiveness of T rri and T rrj RSU receives message M i ={P i ,FV i ,T svi} and M j ={P j ,FV j ,T svj}, Δt is the maximum tolerance time threshold for message freshness check set by the system. If the above formula is established, the message M i ={P i ,FV i ,T svi} and M j ={P j ,FV j ,T svj} is fresh and valid, otherwise the corresponding message is discarded. Then RSU selects the timestamp T srt , and then the message M rt ={FV i ,FV j ,T srt}Send to TA, initiate vehicle V i and V j Behavioral score inquiry.

[0073] S43.TA receives message M rt ={FV i ,FV j ,T srt}, first check the timestamp T srt Whether to use T rrt -T srt <Δt holds true. Where T rrt TA receives message M rt ={FV i ,FV j ,T srt If the test passes, then find the vehicle V from the commuting vehicle behavior score database. i and V j Behavior score H i and H j . Then, TA selects the timestamp T str And the message M tr ={H i ,H j ,T str}Sent to RSU.

[0074] S44.RSU receives message M tr ={H i ,Hj ,T str}, first check T rtr -T str <Δt, where T rtr RSU receives message M tr ={H i ,H j ,T str If the timestamp check passes, the behavior score H i and H j Marked into two levels: Good and Bad. Among them, the behavior score higher than the system threshold is marked as Good, and the behavior score lower than the system threshold is marked as Bad. Here, Good and Bad are fixed values of a hash length agreed in advance by the system and are only used for marking. Then, RSU selects the timestamp T sri And the message M ri ={P j ,FV j ,H j ,T sri}Sent to vehicle V i , RSU selects timestamp T srj And the message M rj ={P i ,FV i ,H i ,T srj}Sent to vehicle V j .

[0075] S45.VehicleV i and V j Received message M ri ={P j ,FV j ,H j ,T sri} and M rj ={P i ,FV i ,H i ,T srj}, first check the timestamp T sri and T srj The validity of the timestamp is determined if the timestamp check satisfies T rvi -T sri <Δt and T rvj -T srj <Δt, then accept the corresponding message, otherwise discard the stale message M ri ={P j ,FV j ,H j ,T sri} or M rj ={Pi ,FV i ,H i ,T srj}, where T rvi and T rvj The vehicle V i and V j Receive message M ri ={P j ,FV j ,H j ,T sri} and M rj ={P i ,FV i ,H i ,T srj} timestamp. Then the vehicle V i and V j According to SK ij =i·P j SK ji =j·P i Calculate the session key.

[0076] After the session key is negotiated, the message trust level is further set according to the value of the level parameter GB. For example, if the vehicle V i Received message M ri ={P j ,FV j ,H j ,T sri}H j is marked as Bad, then the vehicle V i Will not trust vehicles V j Security and privacy messages, and will not respond to vehicle V j The privacy request initiated by the vehicle V j The ability to exchange information about life and entertainment that does not involve security and privacy. i Received message M ri ={P j ,FV j ,H j ,T sri}H j is marked as Good, then vehicle V i Can trust the vehicle V j The security and privacy messages sent will also actively respond to the vehicle V j Various service requests initiated.

[0077] Preferably, in the Internet of Vehicles system, when a vehicle is found to have published false information, the identity of the vehicle is traced and revoked, including:

[0078] The trusted center TA uses the pseudonym VID of the vehicle j Find the service identification code SID when it was registered and other real information related to the vehicle and the owner.

[0079] The trusted center TA revokes the pseudonym VID in the identity database j The corresponding real vehicle legal identity is obtained and the identity database is updated. At this point, the vehicle no longer has a legal identity, and the trusted center has completed the identity tracing and revocation of the vehicle.

[0080] Preferably, the pseudonym mechanism makes it difficult for malicious parties to track the vehicle's true identity, thus ensuring the vehicle's privacy and security. However, if a vehicle uses the same pseudonym to communicate with other entities for a long time, its identity can be easily associated with the pseudonym by malicious trackers, thereby launching targeted attacks based on the historical information that may be exposed by the associated vehicle. Updating the pseudonym of the vehicle includes:

[0081] The trusted center TA receives the request based on the timestamp T f with the vehicle's real IDV i Calculate vehicle V i The pseudonym after the nth update is

[0082] The trusted center TA sends the pseudonym to the vehicle V i , vehicle V i save to the local TPM.

[0083] The BAN logical model is used to prove the semantic security of the embodiment of the present invention. The specific proof process is as follows:

[0084] (1) Idealization of the protocol

[0085] According to the rules of BAN logic, the first step is to idealize the identity verification process. The idealized form is listed below.

[0086] ①: V i →RSU:M i ={P i ,FV i ,T vsi}

[0087] ②:V j →RSU:M j ={P j ,FV j ,T vsj}

[0088] ③: RSU→V i :M ri ={P j ,FVj ,GB j ,T sri}

[0089] ④: RSU→V j :M rj ={P i ,FV i ,GB i ,T srj}

[0090] (2) Initial assumptions of the protocol

[0091] This agreement involves 4 entities: TA, RSU, V i and V j , each entity has its own capabilities and initial assumptions, where V i and V j They are peer entities, and their capabilities and initial assumptions are exactly the same. The capabilities and initial assumptions of each entity are as follows.

[0092] For TA:

[0093] A1: TA holds its public key P pub .

[0094] A2:TA|≡#H i :TA thinks the behavior score is H i It's fresh.

[0095] A3: TA has full control TA .

[0096] A4: TA believes that RSU has full control (FV i ,FV j ,T srt ).

[0097] A5: TA trusts the key pre-shared between it and RSU before the authentication phase.

[0098] For RSUs:

[0099] A6: RSU knows the existence of TA and TA's public key P pub .

[0100] A7: RSU believes that TA has full control (H i ,H j ,T str ).

[0101] A8: RSU believes that it is related to V i A temporary session key negotiated between the two parties.

[0102] A9: RSU believes that it is related to V j A temporary session key negotiated between the two parties.

[0103] A10: RSU believes V i Full Control (P i ,FV i ,T vsi ).

[0104] A11: RSU believes V j Full Control (P j ,FV j ,T vsj ).

[0105] A12: The RSU trusts the key pre-shared between it and the TA before the authentication phase.

[0106] For V i :

[0107] A13: V i Have your own real identity IDV i .

[0108] A14: V i |≡(TA,RSU,P pub ): V i Trust TA, RSU and TA's public key P pub .

[0109] A15: V i Believe that RSU has full control (P j ,FV j ,H j ,T sri ).

[0110] A16: V i Trust the temporary session key negotiated between it and the RSU.

[0111] (3) Security Proof Objectives of the Protocol

[0112] Due to TA, RSU and V i The security of communication between has been proven. Therefore, the protocol proposed in this invention is mainly based on V i and Vj Mutual trust between the two parties is the security goal. The following are two security goals proposed.

[0113] G1:V i |≡(P j ,FV j ,H j ,T sri ): V i Trust the temporary session key negotiation message sent by the RSU.

[0114] G2: V j |≡(P i ,FV i ,H i ,T srj ): V j Trust the temporary session key negotiation message sent by the RSU.

[0115] (4) Security Proof of the Protocol

[0116] V i and V j G1 and G2 are verified by mutual trust through the negotiated session key. The verification process is as follows.

[0117] V1: Because before this stage, RSU and V i and V j The key negotiation process has been completed and the temporary session key has been obtained. Now the timestamp verification is performed first. If the timestamp T svi and T svj If the test is passed, then RSU|≡#(T svi ) and RSU|≡#(T svj ), then according to Available RSU|≡#(P i ,FV i ,T svi ) and RSU|≡#(P j ,FV j ,T svj ). Then by and A8: And A9: It can be seen that RSU|≡V i |~(P i ,FV i ,T svi ) and RSU|≡V j |~(P j ,FV j ,T svj ), then according to and RSU|≡#(P i ,FVi ,T svi ) and RSU|≡#(P j ,FV j ,T svj ) can get RSU|≡V i |≡(P i ,FV i ,T svi ) and RSU|≡V j |≡(P j ,FV j ,T svj ). And according to and A10: And A11: Then we can get RSU|≡(P i ,FV i ,T svi ) and RSU|≡(P j ,FV j ,T svj ), so far RSU has completed V i and V j Then, RSU initiates V i and V j Behavioral score inquiry request.

[0118] V2: TA first checks the timestamp T srt , if T srt Fresh is TA|≡#(T srt ), then according to We can get TA|≡#(FV i ,FV j ,T srt ). Then, according to and A5: It can be seen that TA|≡RSU|~(FV i ,FV j ,T srt ). Then, according to and TA|≡#(FV i ,FV j ,T srt ) can be deduced that TA|≡RSU|≡(FV i ,FV j ,T srt ). Then according to and We can get TA|≡(FV i ,FV j ,T srt), so far TA has completed the inspection of RSU. Finally, TA sends the message M tr ={H i ,H j ,T str}Sent to RSU.

[0119] V3: RSU checks timestamp T str , if it is fresh, then RSU|≡#(T str ), then according to Available RSU|≡#(H i ,H j ,T str ).Depend on and A12: We can get RSU|≡TA|~(H i ,H j ,T str ). Then by and RSU|≡#(H i ,H j ,T str ) can be deduced that RSU|≡TA|≡(H i ,H j ,T str ). Then according to and The available RSU|≡(H i ,H j ,T str ), so far RSU has completed the inspection of TA. Finally, RSU sends the message M ri ={P j ,FV j ,H j ,T sri} and M rj ={P i ,FV i ,H i ,T srj} are sent to V i and V j .

[0120] V4: First, by V i and V j For timestamp T rvi and T rvj Perform the test, if the test passes, there will be V i |≡#(T rvi ) and V j |≡#(T rvj ), then according to Vi |≡#(P j ,FV j ,H j ,T sri ) and V j |≡#(P i ,FV i ,H i ,T srj ). Because V i and V j is a peer entity, V j Assuming the same capability of A16, then and A16: V i |≡RSU|~(P j ,FV j ,H j ,T sri ) and V j |≡RSU|~(P i ,FV i ,H i ,T srj ).according to and V i |≡#(P j ,FV j ,H j ,T sri ) and V j |≡#(P i ,FV i ,H i ,T srj ) can be obtained V i |≡RSU|≡(P j ,FV j ,H j ,T sri ) and V j |≡RSU|≡(P i ,FV i ,H i ,T srj ). Then due to V j Possess V i Regarding the equivalence assumption of A15, according to and A15: V i |≡(P j ,FV j ,H j ,T sri ) and V j |≡(P i ,FV i ,H i ,Tsrj ). At this point, V i and V j The verification of RSU is completed, which means that the security proof goals G1 and G2 are achieved.

[0121] In the proof process of BAN logic, all messages involved in the protocol were simulated, reasonable pre-assumptions were made, and rigorous proof rules were formulated. The realization of security proof goals G1 and G2 means that the protocol has completed the verification of the authenticity, freshness and credibility of the messages involved in the protocol, ensuring V i and V j Negotiation of temporary session keys can be performed securely.

[0122] The present invention is aimed at the vehicle network commuting scenario and designs a dual authentication key negotiation method for vehicle network commuting. First, the three-party mutual trust identity authentication key negotiation is completed in the first identity authentication stage. Then, in the behavior authentication stage, the travel signature collected during the vehicle commuting is used as an important component of the behavior authentication. Combined with the vehicle's current driving route and the information quality rating in the previous V2V session, the current vehicle's behavior score is obtained through the behavior score calculation formula. In the identity authentication stage, for vehicles whose behavior scores are equal to or exceed the established threshold, higher information interaction permissions are granted after the identity authentication is completed. For vehicles whose behavior scores are lower than the established threshold, lower information interaction permissions are granted after the authentication is completed. In addition, this article also uses BAN logic to prove the security of the technical solution of the present invention. After computer software simulation, the results show that the method of the present invention is more secure in the vehicle network commuting scenario and has lower computational overhead and communication overhead than the existing solutions.

[0123] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware through a program, and the program can be stored in a computer-readable storage medium, which may include: ROM, RAM, disk or CD, etc.

[0124] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A dual authentication key negotiation method for vehicle-to-vehicle commuting, characterized in that: The method comprises: S1. Build a connected vehicle system, including a trusted center (TA), roadside units (RSUs), and vehicles. The trusted center publishes its initialization system parameters. S2. The vehicle, user, and roadside unit (RSU) complete identity registration and verification with the TA in advance. The TA assigns corresponding authentication key parameters to the vehicle and roadside unit respectively, and the driver logs in using a biometric key. S3. Verify the vehicle's Trusted Platform Module (TPM) integrity assessment report and calculate a vehicle behavior score based on the vehicle's historical behavior information. The behavior score consists of a travel score and an interaction score. S4. After the session key negotiation process between the RSU and the vehicle is completed, the RSU acts as the primary authentication node using the key information generated by the vehicle to authenticate the vehicle to the vehicle. Only after the authentication is completed, the authentication result is uploaded to the TA for record.

2. The dual authentication key negotiation method for vehicle-to-vehicle commuting according to claim 1 is characterized in that: The initialization system parameters of the Internet of Vehicles system specifically include: The trusted center TA selects elliptic curve parameters a and b, a prime number q representing the order of the elliptic curve finite field, and a generator G of the elliptic curve cyclic subgroup; The trusted center TA selects a collision-resistant one-way hash function H:{0,1} * →{0,1} l , where l is the bit width of the hash function; The trusted center TA selects a random number As the system private key and calculate P pub =s TA P is the system public key, where P is the key negotiation parameter. is the multiplicative group modulo q.

3. The dual authentication key negotiation method for vehicle-to-vehicle commuting according to claim 1 is characterized in that: The step S2 specifically includes: The process of user identity registration and obtaining key authentication parameters in the Internet of Vehicles system is as follows: S201. The user takes the fingerprint information as the input of the physical unclonable function PUF in the car, and then calls the TPM module in the car to input the response of PUF f By hashing H p =H(IN f ) Get the corresponding user's identity H p , then H p Send it together with ID card and other information to TA to initiate user registration request; S202. After receiving the user registration request, TA will send the user related information and identity H p Save it locally, and use the user-related information to generate verification parameters during subsequent vehicle registration and send them to the corresponding vehicle; The process of registering a vehicle in the Internet of Vehicles system and obtaining key authentication parameters is as follows: S211. The vehicle submits the license plate number, vehicle make and model, frame number, in-vehicle TPM device number and other information to the TA to initiate a registration request; After receiving the vehicle registration request, S212.TA generates a real IDV for the vehicle i And calculate the pseudonym FV i =H1(IDV i ||T i ), where T i The time when the vehicle initiates the registration request. Then, TA registers according to the identity H provided by the user. p Calculate the verification parameter H required for the user login stage ver =H(H p ||K p ), where K p Is the login password generated by TA for the user. Finally, the vehicle's real identity IDV i 、Kana FV i , login verification information H ver and login password K p Send to the vehicle and send IDV i 、FV i and H ver Save locally; S213. The vehicle receives the information {IDV i ,FV i ,H ver }, the received information is stored in the local TPM. The process of registering the identity of the roadside unit in the Internet of Vehicles system and obtaining key authentication parameters is as follows: S221. The RSU submits the device's relevant information to the TA to initiate a registration request; S222. After receiving the RSU registration request, the TA generates a real identity ID for the RSU, and then sends the IDR to the RSU and saves it locally; S223. After receiving the message containing the IDR from the TA, the RSU saves the IDR to the local TPM. The driver login process in the Internet of Vehicles system is as follows: S231. The vehicle user verifies the fingerprint and gets a response IN f , the user enters the login key K p ; S232. The onboard unit OBU first calculates H' p =H(IN f ), then calculate H' ver =H(H' p ||K p ), and finally verify H' ver =H ver Is it true? If so, the user has successfully logged in and becomes a legal user of the vehicle. Otherwise, the user cannot legally use the vehicle and obtain Internet of Vehicles services with his or her identity.

4. The dual authentication key negotiation method for vehicle-to-vehicle commuting according to claim 1, characterized in that: The step S3 specifically includes: S31. Verify the vehicle's TPM integrity assessment report i ; S32. Calculate the vehicle's behavior score based on the vehicle's historical behavior information. The vehicle's behavior score is H. i =T i +C i , where H i Score the behavior, T i is the travel score, C i Score the interaction.

5. The dual authentication key negotiation method for vehicle-to-vehicle commuting according to claim 4 is characterized in that: The step S32 specifically includes: The steps for updating the travel score in the behavior score update phase are as follows: S321. Within a 24-hour working day, based on the vehicle travel schedule stored by the TA, a vehicle is considered to have completed a complete round-trip commute when the visit records cover all RSUs in the commuting route and each RSU generates two vehicle visit certificates. S322. After a vehicle completes a full round trip, the number of RSUs actually passed by the vehicle on the commuting route is used as a measure of the travel cost, wherein the travel cost is positively correlated with the number of RSUs passed; S323. The calculated travel cost is used to update the vehicle's travel score. The higher the travel cost, the higher the difficulty and cost of malicious vehicle behavior score accumulation. The steps for updating the interaction score in the behavior score update phase are as follows: S324. When the conversation with the vehicle ends, the vehicle uploads the message of this conversation to the RSU; S325. After receiving the message uploaded by the vehicle, the roadside unit RSU evaluates the message based on the timeliness and authenticity of the message. The evaluation results include three types: positive evaluation, negative evaluation and general evaluation.

6. The dual authentication key negotiation method for vehicle-to-vehicle commuting according to claim 4, characterized in that: The step S4 specifically includes: S41. Vehicle V i and V j Generate key parameters P respectively i and P j The calculation method is: P i =i·G、P j =j·G. Where i and j are vehicle V i and V j The random number selected. Then, the vehicle V i and V j Select the current timestamp T svi and T svj , and send the message M containing the key parameters, pseudonym and timestamp i ={P i ,FV i ,T svi } and M j ={P j ,FV j ,T svj }Send to RSU; S42.RSU receives message M i ={P i ,FV i ,T svi } and M j ={P j ,FV j ,T svj }, first pass T rri -T svi <Δt、T rrj -T svj <Δt check timestamp T svi and T svj The effectiveness of T rri and T rrj RSU receives message M i ={P i ,FV i ,T svi } and M j ={P j ,FV j ,T svj }, Δt is the maximum tolerance time threshold for message freshness check set by the system. If the above formula is established, the message M i ={P i ,FV i ,T svi } and M j ={P j ,FV j ,T svj } is fresh and valid, otherwise the corresponding message is discarded. Then RSU selects the timestamp T srt , and then the message M rt ={FV i ,FV j ,T srt }Send to TA, initiate vehicle V i and V j Behavioral score inquiry; S43.TA receives message M rt ={FV i ,FV j ,T srt }, first check the timestamp T srt Whether to use T rrt -T srt <Δt holds true. Where T rrt TA receives message M rt ={FV i ,FV j ,T srt If the test passes, then find the vehicle V from the commuting vehicle behavior score database. i and V j Behavior score H i and H j . Then, TA selects the timestamp T str And the message M tr ={H i ,H j ,T str }Send to RSU; S44.RSU receives message M tr ={H i ,H j ,T str }, first check T rtr -T str <Δt, where T rtr RSU receives message M tr ={H i ,H j ,T str If the timestamp check passes, the behavior score H i and H j Marked into two levels: Good and Bad. Among them, the behavior score higher than the system threshold is marked as Good, and the behavior score lower than the system threshold is marked as Bad. Here, Good and Bad are fixed values of a hash length agreed in advance by the system and are only used for marking. Then, RSU selects the timestamp T sri And the message M ri ={P j ,FV j ,H j ,T sri }Sent to vehicle V i , RSU selects timestamp T srj And the message M rj ={P i ,FV i ,H i ,T srj }Sent to vehicle V j ; S45.VehicleV i and V j Received message M ri ={P j ,FV j ,H j ,T sri } and M rj ={P i ,FV i ,H i ,T srj }, first check the timestamp T sri and T srj The validity of the timestamp is determined if the timestamp check satisfies T rvi -T sri <Δt and T rvj -T srj <Δt, then accept the corresponding message, otherwise discard the stale message M ri ={P j ,FV j ,H j ,T sri } or M rj ={P i ,FV i ,H i ,T srj }, where T rvi and T rvj The vehicle V i and V j Receive message M ri ={P j ,FV j ,H j ,T sri } and M rj ={P i ,FV i ,H i ,T srj } timestamp. Then the vehicle V i and V j According to SK ij =i·P j SK ji =j·P i Calculate the session key.

7. The dual authentication key negotiation method for vehicle-to-vehicle commuting according to claim 1, characterized in that: When a vehicle is found to have published false information in the Internet of Vehicles system, the vehicle's identity is traced and revoked, including: The trusted center TA uses the pseudonym VID of the vehicle j Find the service identification code (SID) and other real information related to the vehicle and its owner when it was registered; The trusted center TA revokes the pseudonym VID in the identity database j The corresponding real vehicle legal identity is updated in the identity database. The vehicle no longer has a legal identity, and the trusted center TA completes the identity tracing and revocation of the vehicle.

8. The dual authentication key negotiation method for vehicle-to-vehicle commuting according to claim 1, characterized in that: In order to protect the privacy and security of the vehicle in the Internet of Vehicles system, the vehicle pseudonym is updated, including: The trusted center TA receives the request based on the timestamp T f with the vehicle's real IDV i Calculate vehicle V i The pseudonym FV after the nth update i n =H1(IDV i ||T f ); The trusted center TA sends the pseudonym to the vehicle V i , vehicle V i Save FV i n to the local TPM.

Citation Information

Cited By

  • Vehicle networking system communication method and vehicle networking system

    CN121692111A

  • A vehicle networking system communication method and a vehicle networking system

    CN121692111B