Privacy protection and traceable anonymous bidirectional authentication method for heterogeneous Internet of Vehicles
By building a heterogeneous network cryptographic system, vehicles and roadside units register and verify the legitimacy of their keys respectively, solving the problems of low computing efficiency and security risks in heterogeneous vehicle networks, achieving efficient and secure two-way authentication and key negotiation, and enhancing the security and practicality of the vehicle network.
Patent Information
- Application Number
- CN202510927021.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-09-30
AI Technical Summary
In a heterogeneous Internet of Vehicles (IoV) environment, two-way authentication and key negotiation between vehicles and roadside units (ROUs) suffer from computational inefficiency and security risks, especially the problem of vehicle privacy leakage.
A heterogeneous network cryptographic system is constructed based on a key generation center, a trusted registration authority and a private key generator. Vehicles and roadside units register their keys through certificateless public keys and identity public key systems respectively, and verify the legitimacy of each other through hash functions and temporary values, and finally negotiate session keys.
It realizes efficient and secure two-way authentication and key negotiation in heterogeneous environments, prevents the leakage of vehicle identity information, consumes less computing resources, has high computing efficiency and multiple high-security attributes, adapts to dynamic changes, and enhances the security and practicality of vehicle network data communication.
Smart Images

Figure CN120730299A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of key agreement technology, and in particular to a privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks. Background Art
[0002] With the rapid development of artificial intelligence (AI) and the Internet of Things (IoT), vehicles are increasingly being used across multiple industries, particularly in areas such as environmental monitoring, disaster response, and smart cities. AI enhances vehicles' autonomous decision-making capabilities, while the IoT enables seamless connectivity with a wide range of devices. However, despite their enormous potential, vehicles face limitations in computing and communication capabilities, as well as growing security challenges.
[0003] With the increasing application of the Internet of Vehicles (IoV) in intelligent transportation systems, data exchange and communication between vehicles and roadside units (ROUs) are becoming increasingly important. However, IoV authentication and key agreement face multiple security challenges, especially in the heterogeneous environment between vehicles and RSUs. Current methods mostly focus on authentication and key agreement under a single public key cryptosystem, but for bidirectional authentication and key agreement in heterogeneous environments, there are still problems such as insufficient computational efficiency and significant security risks. For example, vehicles typically communicate based on certificateless public key cryptosystems, while RSUs mostly use identity-based public key cryptosystems. In such a heterogeneous environment, bidirectional authentication and session key agreement between vehicles and RSUs usually require a third party to perform authentication and transfer, resulting in low computational and communication efficiency and security issues such as vehicle privacy leakage. Therefore, there is an urgent need for an efficient and secure bidirectional authentication and key agreement method to ensure rapid identity verification and secure data transmission between vehicles and RSUs in heterogeneous environments. Summary of the Invention
[0004] The purpose of the present invention is to provide a privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks.
[0005] To achieve the above object, the present invention is implemented according to the following technical solutions:
[0006] The present invention comprises the following steps:
[0007] Based on the key generation center, private key generator and trusted registration authority, public and private keys are generated to build a heterogeneous network cryptographic system;
[0008] Vehicles complete key registration by integrating a certificateless public key system, and roadside units complete key registration based on an identity public key system;
[0009] The vehicle and the roadside unit verify the legitimacy of each other through a hash function and a temporary value during the two-way authentication phase, and ultimately negotiate a session key.
[0010] Furthermore, the key generation center selects an additive cyclic group, a multiplicative cyclic group and a generator, selects a hash function, and generates the system public and private keys;
[0011] The trusted registration authority selects its own private key, calculates the public key, and sends it to the key generation center through a secure channel;
[0012] The key generation center generates system public parameters and sends them to all vehicles in the vehicle network through public channels;
[0013] The hash function includes: H1:G×{0,1} * →{0,1} * ,
[0014]
[0015] H5:G×G→{0,1} * ,
[0016]
[0017] Where n represents the length in bits of the negotiated key.
[0018] Furthermore, when a vehicle user registers, the vehicle receives the system’s public parameters, selects a secret value, calculates a partial public key, and initiates a pseudonym request to the trusted registration authority;
[0019] After receiving the pseudonym request, the trusted registration authority checks whether the vehicle is legal. If it is legal, it calculates a temporary value, sets a temporary pseudonym, generates a partial private key request, and sends it to the key generation center.
[0020] The key generation center receives the request, selects a random number, calculates the partial public key and digest value, generates a partial private key and sends it back to the vehicle;
[0021] The vehicle receives a partial private key reply and verifies it through a hash function. If the verification is successful, the complete public and private key pair is generated. Otherwise, a new pseudonym is applied for.
[0022] Furthermore, when the roadside unit registers, the roadside unit sends its own unique identity identifier to the private key generator through a secure channel to apply for a private key. After the private key generator generates the private key, it sends it to the roadside unit through a secure channel; after receiving the private key, the roadside unit uses a hash function to verify the private key. If the verification is successful, a public-private key pair is generated. Otherwise, the unique identity identifier is resent to the private key generator to apply for a private key.
[0023] Furthermore, the vehicle and roadside unit bidirectional authentication method for verifying the legitimacy of each other through a hash function and a temporary value includes:
[0024] The vehicle hides its true identity through a temporary value and ciphertext, while carrying a digest for verification by the roadside unit;
[0025] After verifying the legitimacy of the vehicle, the roadside unit generates a session key and returns a verification code;
[0026] The vehicle verifies the response from the roadside unit using the private key and generates a shared session key.
[0027] Furthermore, the shared session key is generated synchronously through a hash function and a temporary value.
[0028] A privacy-preserving and traceable anonymous bidirectional authentication method for heterogeneous vehicle networks, used to implement the method, includes a vehicle, a roadside unit, a trusted registration authority, a key generation center, and a private key generator:
[0029] The key generation center is used to generate system public parameters and distribute them to all roadside units and all vehicles in the system. It can also be used to generate partial private keys for vehicles and send them to target vehicles through secure channels.
[0030] A trusted registration authority that generates pseudonyms for all vehicles and can trace the vehicle's true identity back to its pseudonym;
[0031] The private key generator generates a private key of the roadside unit according to the identity identifier of the roadside unit, and sends the private key to the roadside unit through a secure channel;
[0032] The roadside unit, which belongs to the identity-based public key cryptography system, sends its own unique identity identifier to the private key generator to obtain a private key, and after receiving the private key, generates its own public key and private key. It can be used to accept authentication requests sent by vehicles, verify the legitimacy of the authentication request through a hash function and a temporary value, and then generate an authentication response and a session key. After sensing road condition information, it can use the session key to encrypt and securely send the road condition information to the target vehicle.
[0033] Vehicles belong to the certificateless public key cryptography system and generate the private key of their own public key through secure interaction with the key generation center. They can generate an authentication request and send it to the roadside unit. After receiving the authentication reply, they verify the legitimacy of the other party through hash functions and temporary values, and generate a session key known only to the vehicle and the roadside unit. Through on-board sensors and wireless devices, they can perceive road conditions and their own driving status in real time, and encrypt them with the session key and send them to the roadside unit.
[0034] The beneficial effects of the present invention are:
[0035] The present invention can achieve secure and efficient two-way authentication and key negotiation between certificateless public key cryptography systems and identity-based public key cryptography systems. By providing pseudonyms and anonymous authentication for vehicles, the invention can effectively prevent the leakage of identity information of vehicles and roadside units, and prevent attackers from tracking the vehicle's route and location through public keys or identity information. In addition, the calculation process of the invention does not rely on pairing operations, consumes less computing resources, has a short running time, and has high computing efficiency. In terms of security, the invention meets multiple high-security properties such as two-way authentication, key negotiation, unforgeability, perfect forward security, perfect backward security, and unlinkability, thereby enhancing the security strength of Internet of Vehicles data communications. In addition, the invention has good scalability and can adapt to dynamic changes in the Internet of Vehicles environment, ensuring the practicality of the system and user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 Schematic diagram of the system model of the privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks of the present invention;
[0037] Figure 2 A flow chart of two-way authentication and key agreement for the privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks of the present invention;
[0038] Figure 3 This is a comparison chart of the running time of 80 security models for the privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks of the present invention;
[0039] Figure 4 This is a comparison chart of the running time of the 112 security model of the privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks of the present invention;
[0040] Figure 5 This is a comparison chart of the running time of the 128 security models for the privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks of the present invention;
[0041] Figure 6 A bar chart comparing the average running time of various methods of the privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks of the present invention;
[0042] Figure 7 This is a comparison chart of the communication lengths of different methods in the authentication process for the privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks of the present invention. DETAILED DESCRIPTION
[0043] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. The exemplary embodiments of the present invention are used to illustrate the present invention but are not intended to limit the present invention.
[0044] like Figure 1-2 As shown, the present invention includes the following steps:
[0045] This method can be divided into three main parts: system initialization, user registration and two-way authentication. The general process is as follows Figure 2 shown.
[0046] System initialization
[0047] Based on the given system security parameter γ, the trusted third party TA first selects an additive cyclic group G and a generator P of G, where the order of G is q (q<2 γ ). Secondly, for the three trusted third-party components, the key generation center selects a random number As the private key of the key generation center, calculate P pub-1 =s1P is the public key of the key generation center; the private key generator also selects a random number As the private key of the private key generator, calculate P pub-2 =s2P as the public key of the private key generator; the trusted registration authority selects a random number As the private key of the trusted registration authority, calculate T pub =tP as the public key of the trusted registration authority. Then, to achieve two-way security authentication between the vehicle and the roadside unit, the key generation center selects a message check code function MAC(·) and 6 secure one-way hash functions: H1:G×{0,1} * →{0,1} * , H5:G×G→{0,1} * , Among them, n represents the bit length of the negotiated key. Finally, TA generates public system parameters params = {G, P, q, P pub-1 ,P pub-2 ,T pub ,MAC(·),H1,H2,H3,H4,H5,H6}, and sent to all vehicles and roadside units under the system through public channels.
[0048] Registration stage
[0049] Considering the vehicle V i The privacy protection requirements of the vehicle and the certificateless public key cryptography system are as follows during the vehicle registration phase:
[0050] Secret value generation
[0051] Assume that the vehicle V i The unique identifier is RID i, can realize the unique identification of the vehicle, such as license plate number and other information, then the vehicle V i The following calculations can be performed.
[0052] Vehicle V i Select random value As its own secret value, calculate P i =x i P as a partial public key;
[0053] Generate pseudonym and partial private key request {P i ,RID i} and sent to the trusted registration authority through a secure channel.
[0054] Pseudonym generation
[0055] Upon receiving the pseudonym and partial private key request {P i ,RID i}After that, perform the following calculation:
[0056] Check vehicle RID i Is it in the legal registration unit directory? If not, it will be discarded directly; otherwise, proceed to the next step of calculation;
[0057] Calculating PID i =H1(tP i ,ΔT)⊕RID i As a vehicle V i Pseudonym, where H1 represents the hash function and ΔT represents the pseudonym PID i validity period;
[0058] Generate partial private key request {P i ,PID i} and sent to the key generation center through a secure channel.
[0059] Partial private key generation
[0060] The key generation center receives the partial private key request {P i ,PID j}, perform the following calculations.
[0061] Pick a random number Calculate R i =r i P as vehicle V i Part of the public key;
[0062] Calculate the summary value h i =H2(PID i ,P i ,R i ,P pub-1) and the vehicle's partial private key d i =r i +s1h i , where H2 is a hash function;
[0063] Generate partial private key reply {R i ,d i ,PID i} and sent to the vehicle V through a secure channel i ;
[0064] Complete key generation
[0065] Vehicle V i After receiving the partial private key reply {R i ,d i ,PID i}, perform the following calculations.
[0066] Calculating RID i '=H1(x i T pub ,ΔT)⊕PID i , and determine the RID i '=RID i Is it true, where H1 is the hash function and ΔT is the validity period of the pseudonym;
[0067] If true, it means the pseudonym PID i If it is legal, proceed to the next step of verification; otherwise, discard it directly;
[0068] With the help of hash function H2 and the public key P of the key generation center pub-1 , calculate the summary value h i =H2(RID i ,P i ,R i ,P pub-1 ), judge and verify equation d i P=R i +h i P pub-1 whether it is established;
[0069] If established, vehicle V i Completed pseudonym setting and key initialization, and set PID i As his pseudonym, PK i ={P i ,R i} and SK i ={x i ,d i} as your own public key and private key; otherwise, directly abandon it and re-execute the pseudonym application.
[0070] Roadside Unit (RSU) j The public key cryptography system belonging to the identity, and its specific process of interacting with the private key generator to complete the registration is as follows.
[0071] Roadside Unit (RSU) j Send your own unique identifier RID j To the private key generator for applying for a private key, where the unique identifier RID j Can represent RSU j Unique identification information, such as installation location;
[0072] The private key generator receives the roadside unit RSU j Unique Identifier RID j Then, perform the following calculation to generate the corresponding private key.
[0073] Query roadside unit RSU j RID j Is it a legally registered unit. If not, the private key generator will give up registering the roadside unit RSU j Otherwise, the private key generator performs the following calculation process;
[0074] Pick a random number Calculate R j =r j P is the public key of the roadside unit and the digest value h j =H3(RID j ,R j ,P pub-2 ), where H3 is a hash function;
[0075] Calculate d j =r j +s2h j As the private key of the roadside unit, and the private key information {d j ,R j}Sent to the roadside unit RSU through a secure channel j ;
[0076] Roadside Unit (RSU) j Received private key information {d j ,R j}, perform the following calculations.
[0077] Execute judgment equation d j P=R j +H3(RID j ,R j ,P pub-2 )P pub-2 Is it true, where H3 is a hash function, P pub-2is the public key of the private key generator.
[0078] If established, RSU j Set your own private key to SK j =d j , the public key is PK j =R j If not, RSU j The public-private key pair is considered illegal, discarded directly and the unique identity identifier RID is resent j Used by the private key generator to apply for a private key.
[0079] Two-way authentication
[0080] The mutual authentication phase can be divided into three main stages: authentication request, authentication response, and key agreement, as detailed below. Furthermore, to better illustrate the method, this method assumes the existence of a vehicle, Alice, and a roadside unit, Bob. Once both have generated public and private keys, the proposed method is based on mutual authentication between them.
[0081] Authentication request phase
[0082] Assume that vehicle Alice enters the area under the jurisdiction of roadside unit Bob and obtains Bob's unique identity information RID through Bob's broadcast signal. B and public key information PK B =R B After that, Alice performs the following calculation to generate the authentication request Rep.
[0083] Pick a random number Calculate the temporary value T1 = a(d A +x A )P;
[0084] Based on the hash function H3, the vehicle's entire private key SK A ={x A ,d A} and the public key P of the private key generator pub-2 , calculate the summary value h B =H3(RID B ,R B ,P pub-2 ) and temporary value T2 = a(d A +x A )(R B +h B P pub-2 );
[0085] Calculate the summary value h=H4(PID A ,P A ,RA ,P pub-1 ,RID B ,R B ,P pub-2 ,T1,T2), where P pub-1 It is the system public key of the key generation center;
[0086] Calculate the temporary value C=H5(T1,T2)⊕(PID A ||P A ||R A ||h), where || represents bit string concatenation and H5 is a hash function;
[0087] Generate an authentication request message Rep={T1, C} and send Rep to the roadside unit Bob through a public channel.
[0088] Authentication response phase
[0089] After receiving the authentication request message Rep={T1,C}, the roadside unit Bob generates an authentication reply Rep according to the following calculation process.
[0090] Calculate temporary value T2'=d B T1 and PID A ||P A ||R A ||h=C⊕H5(T1,T2);
[0091] Based on the hash function H4, the summary value h'=H4(PID A ,P A ,R A ,P pub-1 ,RID B ,R B ,P pub-2 ,T1,T2'), and determine whether the equation h=h' holds. If not, it means that the authentication request is illegal and is directly discarded; otherwise, Bob continues to perform the next step;
[0092] Select random number Calculate temporary value T3 = bT2';
[0093] System public key P based on hash function H2 and key generation center pub-1 , calculate h A =H2(PID A ,P A ,R A ,P pub-1 ) and T4=bd B (R A +h A P pub-1 );
[0094] Calculate the session key based on the hash function H6 and the message check code function MAC BA =H6(h',T3), generate message check code
[0095] Generate an authentication reply Rep = {mac, T4} and send Rep to vehicle Alice through a public channel.
[0096] Key negotiation phase
[0097] After receiving the authentication reply Rep, vehicle Alice performs the following calculation to complete key negotiation.
[0098] Based on all of its own private keys SK A ={x A ,d A}, calculate the temporary value
[0099] Calculate the session key based on the hash function H6 and the message authentication code function MAC AB =H6(h,T3') and message verification code Where h is the digest value generated during the authentication request phase;
[0100] Determine whether the verification equation mac'=mac is established. If not, Alice considers the message illegal and directly abandons the authentication and replies to Rep; otherwise, Alice considers Bob to have passed the authentication and uses the session key key AB Serves as the key for symmetric encryption in subsequent communications with the roadside unit.
[0101] Correctness Proof The present invention will explain the main calculation process involved in this method, which is as follows.
[0102] The calculation process of T2 in the authentication request phase and T2' in the authentication response phase is as follows:
[0103] T2=d B T1=(r B +s2h B )T1
[0104] =a(r B +s2H3(RID B ,R B ,P pub-2 ))(r A +s1H2(PID A ,P A ,R A ,P pub-1 )+x A )P
[0105] =a(r A +s1H2(PID A ,P A ,R A ,P pub-1 )+x A )(r B +s2H3(RID B ,R B ,P pub-2 ))P
[0106] =a(d A +x A )(R B +H3(RID B ,R B ,P pub-2 )P pub-2 )
[0107] =T2.
[0108] The calculation process of T3 and T3' in the authentication response phase is as follows:
[0109]
[0110] =ba(d A +x A )(R B +H3(RID B ,R B ,P pub-2 )P pub-2 )
[0111] =bT2'
[0112] =T3.
[0113] For the session password key generated by Alice during the key negotiation phase AB and the session key generated by Bob BA The equation for calculation:
[0114] key BA =H6(h',T3)
[0115] =H6(H4(PID A ,P A ,R A ,P pub-1 ,RID B ,R B ,P pub-2 ,T1,T2'),T3)
[0116] =H6(H4(PIDA ,P A ,R A ,P pub-1 ,RID B ,R B ,P pub-2 ,T1,T2),T3')
[0117] =H6(h,T3')
[0118] =key AB .
[0119] Therefore, it can be seen from the above equation that the method proposed in the present invention is computationally feasible.
[0120] In the performance analysis, the present invention compares and analyzes the security strength, computational efficiency and communication efficiency of the proposed method.
[0121] To verify the security strength of authentication and key agreement mechanisms, numerous security properties have been proposed. These security properties can verify whether the proposed mechanisms can resist specific security attacks. Therefore, this paper analyzes different methods from the perspectives of mutual authentication, key agreement, perfect forward security, security of known session-specific temporary information, privacy protection, anonymity, traceability, and scalability, as shown in Table 1. Among them, for the two methods proposed by Jin, they meet the same security properties [1].
[0122] Table 1 Comparison of security attributes of different methods
[0123]
[0124]
[0125] As can be seen from Table 1, existing methods can all achieve mutual authentication and key agreement. However, they all have certain security weaknesses in terms of high-level security properties. The method proposed in this paper does not require pairing operations, offering certain computational advantages in terms of known session-specific temporary information security, privacy protection, and traceability. Therefore, compared with existing methods, this paper not only meets basic security properties such as mutual authentication and key agreement, but also meets multiple strong security properties including perfect forward secrecy, known session-specific temporary information security, privacy protection, anonymity, and traceability, demonstrating higher security strength.
[0126] To evaluate the computational efficiency of the proposed method, we used the Pypbc0.2 library and a Raspberry Pi 4 Model B to simulate and test real-world authentication scenarios involving vehicles and roadside units. First, we implemented the specific authentication processes for different methods, ignoring the communication process. Second, we measured the runtime of each authentication method under the 80, 112, and 128 security models and different authentication times n = [2, 4, 6, 8, 10], creating a runtime comparison chart. Finally, for quantitative analysis, we measured the average runtime of different methods after 100 iterations under the 80, 112, and 128 security models.
[0127] pass Figure 3-5 It can be found that as the security model strength increases, the computation time required by the proposed method is significantly shorter than any existing method. This advantage becomes more pronounced as the number of authentications increases. For security models with 80, 112, and 128 authentications, the proposed method only requires 31.64us, 120.4us, and 271.85us, respectively. Compared to the fastest existing method, the proposed method improves runtime by 0.13%, 15.92%, and 23.97%, respectively, resulting in an average improvement in computational efficiency of 13.34%.
[0128] To verify the communication efficiency of the proposed method, the present invention quantitatively compares and analyzes the message lengths sent by different methods during the two-way authentication and key negotiation process. In the scenario where neither party in the communication knows the public key information of the other party, the present invention counts the data lengths sent by the different methods at the receiving and sending sides, and sets the bit length of the receiver or sender identity |ID| to 128 and the bit length of the element |G| in the cyclic group to 1024. The bit length of the element |q| is 160, the bit length of the message authentication code |MAC| is 128, the bit length of the timestamp |time| is 64, and the bit length of the session key |SK| is 256. A comparison chart of the message lengths of different methods in the authentication process is generated, as shown in Figure 6 shown.
[0129] from Figure 7 It can be seen that compared to existing methods, the data sent during the communication process in this invention includes the public key information of both parties authenticating and the vehicle's pseudonym, occupying a total of 4016 bits. However, the transmission of public key information and the generation of vehicle pseudonyms are necessary to ensure the anonymity of authentication messages and protect the privacy of the vehicle, which is essential for improving the security of vehicle-to-vehicle authentication and key agreement. Therefore, in the method proposed in this invention, the additional communication overhead is necessary and acceptable to meet strong security properties such as anonymity and traceability.
[0130] The embodiments of the present invention are described in detail above. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the core idea of the present invention. At the same time, for those skilled in the art, according to the idea of the present invention, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. Privacy protection and traceability anonymous two-way authentication method for heterogeneous vehicle networks, characterized by: include: The key generation center, private key generator and trusted registration authority generate public and private keys respectively, and jointly build a heterogeneous cryptographic system; Vehicles complete key registration by integrating a certificateless public key system, and roadside units complete key registration based on an identity public key system; The vehicle and the roadside unit bidirectionally authenticate each other through hash functions and temporary values, and finally negotiate a shared session key.
2. The privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks according to claim 1 is characterized in that: The key generation center selects the additive cyclic group, multiplicative cyclic group and generator, selects the hash function, and generates the system public and private keys; The trusted registration authority selects its own private key, calculates its own public key, and sends it to the key generation center through a secure channel; The key generation center selects its own private key, calculates its own public key, generates system public parameters, and sends them to all vehicles in the vehicle network through public channels; The hash function includes: H1:G×{0,1} * →{0,1} * , H5:G×G→{0,1} * , Where n represents the length in bits of the negotiated key.
3. The privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks according to claim 1 is characterized in that: When a vehicle user registers, the vehicle receives the system’s public parameters, selects a secret value, calculates a partial public key, and sends a pseudonym request to the trusted registration authority; The trusted registration authority receives the request, checks whether the vehicle is legal, and if so, calculates a temporary value, sets a temporary pseudonym, generates a partial private key request, and sends it to the key generation center. After receiving the request, the key generation center selects a random number, calculates the partial public key and digest value, generates the partial private key, and sends it back to the vehicle through a secure channel; After the vehicle receives the partial private key, it verifies it through a hash function. If the verification is successful, the complete public and private key pair is generated. Otherwise, a new pseudonym is applied for.
4. The privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks according to claim 1 is characterized in that: When a roadside unit registers, the roadside unit sends its own unique identity identifier to the private key generator for completing the application for a private key by interacting with the private key generator, and is verified by a hash function. If the verification is passed, a public-private key pair is generated. Otherwise, the unique identity identifier is resent to apply for a private key.
5. The privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks according to claim 1 is characterized in that: The method for bidirectional authentication between a vehicle and a roadside unit to verify the legitimacy of the other party by using a hash function and a temporary value includes: The vehicle hides its true identity through a temporary value and ciphertext, while carrying a digest for verification by the roadside unit; After verifying the legitimacy of the vehicle, the roadside unit generates a session key and returns a verification code; The vehicle verifies the response from the roadside unit using the private key and generates a shared session key.
6. The privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks according to claim 1 is characterized in that: During the mutual authentication phase, the calculation process avoids using bilinear pairing operations.
7. A privacy protection and traceable anonymous two-way authentication method for heterogeneous vehicle networks, used to execute the method according to any one of claims 1 to 6, characterized in that: Includes vehicles, roadside units, trusted registration authorities, key generation centers, and private key generators; The key generation center is used to generate system public parameters and distribute them to all roadside units and all vehicles in the system. It can also be used to generate partial private keys for vehicles and send them to target vehicles through secure channels. A trusted registration authority that generates pseudonyms for all vehicles and can trace the vehicle's true identity back to its pseudonym; A private key generator, generating a private key of the roadside unit according to the identity identifier of the roadside unit, and sending the private key to the roadside unit through a secure channel; The roadside unit, which belongs to the identity-based public key cryptography system, sends its own unique identity identifier to the private key generator to obtain a private key, and generates its own public key and private key after receiving the private key. It can be used to accept authentication requests sent by vehicles, verify the legitimacy of the authentication request through a hash function and a temporary value, and then generate an authentication response and a session key. After sensing road condition information, it can use the session key to encrypt and securely send the road condition information to the target vehicle. Vehicles belong to the certificateless public key cryptography system and generate the private key of their own public key through secure interaction with the key generation center. They can generate an authentication request and send it to the roadside unit. After receiving the authentication reply, they verify the legitimacy of the other party through hash functions and temporary values, and generate a session key known only to the vehicle and the roadside unit. Through on-board sensors and wireless devices, they can perceive road conditions and their own driving status in real time, and encrypt them with the session key and send them to the roadside unit.
Citation Information
Patent Citations
Internet of vehicles efficient batch authentication key negotiation method based on signature
CN117098128A
Novel signcryption scheme based on privacy protection of intelligent Internet of Vehicles
CN117336713A
Message authentication method based on certificateless strong anonymity in Internet of Vehicles environment
CN118612718A
Privacy protection and traceable certificateless anonymous bidirectional authentication method suitable for Internet of Things
CN118784229A
Lightweight and safe multi-receiver heterogeneous signcryption method suitable for Internet of Vehicles
CN119967409A