Identity authentication method and system for resisting identity forgery attack
Through the identity authentication method combining elliptic curve and AI model, the identity forgery attack problem of IoT vehicles is solved, the computing resources of RSU are optimized, and low-latency and efficient cross-domain authentication is achieved.
Patent Information
- Application Number
- CN202510964427.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-07-14
AI Technical Summary
Existing technologies cannot effectively defend against identity forgery attacks on IoT vehicles, and roadside units (RSUs) lack computing resources in high-density user scenarios and cannot meet low latency requirements.
The elliptic curve is used to generate key pairs, combined with AI models to schedule resources in real time, by preloading factors to RSU, using base stations to calculate pseudonym generation parameters, realizing cross-chain query and digital signature verification, and dynamically allocating computing tasks.
Effectively identify and prevent identity forgery attacks, optimize RSU computing resources, meet low latency requirements, and improve the credibility and efficiency of cross-domain authentication.
Smart Images

Figure CN120750593A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to an identity authentication method and system for resisting identity forgery attacks. Background Art
[0002] To ensure the identity security of IoT vehicles during cross-domain communication, existing technologies have proposed anonymous authentication schemes that conceal their true identities. Only trusted authorization can retrieve the true identity from the pseudonym. Furthermore, existing technologies have introduced pseudonym assignment mechanisms assisted by roadside unit (RSU) agents. However, these existing anonymity mechanisms fail to account for identity forgery attacks. By forging pseudonyms and corresponding keys, malicious vehicles can launch various attacks on the Internet of Vehicles. Existing anonymity mechanisms are unable to identify and locate these malicious vehicles.
[0003] Furthermore, existing roadside units (RSUs) require increasing computing resources. When a particular RSU is crowded with users, it will be unable to meet their low-latency requirements. Therefore, it is necessary to consider integrating large AI models with real-time dynamic strategy formulation.
[0004] Therefore, there is an urgent need for an identity authentication method and system that can resist identity forgery attacks. Summary of the Invention
[0005] The purpose of the present invention is to provide an identity authentication method and system for resisting identity forgery attacks, thereby overcoming the inability of the prior art to resist identity forgery attacks and meeting the demand for real-time dynamic scheduling of resources.
[0006] In a first aspect, the present application provides an identity authentication method for resisting identity forgery attacks, the method comprising:
[0007] System initialization, including generating key pairs for each entity via elliptic curves;
[0008] The user registers their identity in the domain, and the authentication center generates the corresponding key pair, encryption parameters, and identity certificate for the user, and uploads them to the on-chain storage;
[0009] Return address information from the chain;
[0010] The preloaded factors containing the private key are generated in the key generation center KGC. The batch of factors are preloaded to the roadside unit RSU for subsequent calculation of the pseudonym generation parameters.
[0011] When a user initiates a pseudonym generation request to a nearby RSU, the RSU verifies the legitimacy of the request and forwards it to a nearby base station. The base station uses an AI model to predict the resource usage status of the serving base station and neighboring stations, formulates a strategy, and assigns the serving base station to calculate the pseudonym generation parameters in real time.
[0012] After receiving the pseudonym generation parameters, the user generates his or her own pseudonym, verification parameters, and corresponding key pair;
[0013] The user uses a pseudonym and a key pair to calculate a unique signature and encrypts the message using the signature;
[0014] When a user requests communication, a message packet is sent to the recipient, wherein the message packet carries address information;
[0015] After receiving the message packet and verifying its validity, the receiver sends the message packet to the nearby RSU, which forwards it to the nearby base station. The service base station is assigned in real time according to the policy to verify the legitimacy of the user's pseudonym.
[0016] The receiver submits a pseudonymous request to a nearby RSU, which carries the address information, and queries whether the slave chain contains the address information, performing a cross-domain query for data verification;
[0017] If the slave chain contains the address information, the identity certificate is returned; otherwise, the address information is sent to the main chain, which assists in completing the query;
[0018] Return the identity certificate from the chain to the recipient;
[0019] The recipient verifies the signature of the user's identity. If the user does not use a pseudonym to generate parameters, the verification fails.
[0020] In a second aspect, the present application provides an identity authentication system for resisting identity forgery attacks, the system comprising:
[0021] Initialization module, used for system initialization, including generating key pairs for each entity through elliptic curve;
[0022] The authentication center is used for users to register their identities in the domain, generate corresponding key pairs, encryption parameters and identity certificates for users, and upload them to the slave chain for storage; and receive address information returned from the slave chain;
[0023] The key generation center (KGC) is used to generate preloaded factors containing private keys. Batches of factors are preloaded onto the roadside unit (RSU) for subsequent calculation of pseudonym generation parameters.
[0024] Roadside Unit (RSU), which receives pseudonym generation requests initiated by users, verifies the legitimacy of the requests, and forwards them to nearby base stations;
[0025] Base stations are used to predict the resource usage status of the serving base station and neighboring base stations through AI models, formulate strategies, and assign the serving base station to calculate pseudonym generation parameters in real time;
[0026] The user initiates a pseudonym generation request and sends it to a nearby RSU. After receiving the pseudonym generation parameters, the user generates its own pseudonym, verification parameters, and corresponding key pair. The pseudonym and key pair are used to calculate a unique signature, and the signature is used to encrypt the message. When the user requests communication, a message packet carrying address information is sent to the recipient.
[0027] The receiver receives the message packet, verifies its validity, and then sends it to a nearby RSU. The RSU forwards the message packet to a nearby base station, which assigns a serving base station in real time to verify the legitimacy of the user's pseudonym based on the policy. The receiver submits a pseudonym request to a nearby RSU, which carries address information, and queries whether the slave chain contains the address information, performing a cross-domain query for data verification. The receiver also verifies the user's identity signature. If the user does not use the pseudonym to generate parameters, the verification fails.
[0028] The slave chain is used to determine whether the address information is contained. If so, the identity certificate is returned. Otherwise, the address information is sent to the main chain, and the main chain assists in completing the query; the slave chain returns the identity certificate to the recipient.
[0029] In a third aspect, the present application provides an identity authentication system for resisting identity forgery attacks, the system comprising a processor and a memory:
[0030] The memory is used to store program code and transmit the program code to the processor;
[0031] The processor is configured to execute any one of the possible methods of the first aspect according to instructions in the program code.
[0032] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium is used to store program code, and the program code is used to be executed by a processor to implement any one of the methods described in the first aspect.
[0033] Beneficial effects
[0034] The present invention provides an identity authentication method and system for resisting identity forgery attacks. First, the system is initialized and a key pair is generated for the entity based on an elliptic curve. When a user registers in the domain, the authentication center generates a key pair, encryption parameters and identity certificate and stores them in the slave chain. The key generation center (KGC) pre-generates factors containing private keys and pre-loads them into the roadside unit (RSU). When a user initiates a pseudonym generation request, the RSU forwards the request to a nearby base station after verification; the base station uses an AI model to predict resource usage status and dynamically assigns a service base station in real time to calculate the pseudonym generation parameters. After obtaining the parameters, the user generates his own pseudonym, verification parameters and key pair, and uses the pseudonym key to generate a unique signature to encrypt the message and send it. After the recipient verifies the validity of the message, the verification request is forwarded to the base station through the RSU, which also dynamically assigns a service base station based on the AI strategy to verify the legitimacy of the pseudonym, and queries and verifies the user's identity certificate across chains (slave chain / main chain collaboration) by carrying address information.
[0035] The method and system of the present invention have the following advantages and effects:
[0036] 1. Effectively protect against identity forgery attacks: This invention employs a calculation mechanism based on preloaded factors and pseudonym generation parameters, requiring users to construct pseudonyms and keys using legitimate system-generated parameters. When verifying identity, the recipient can effectively identify pseudonyms and keys that were not generated using legitimate parameters (i.e., forged) by cross-chain certificate query and signature verification. This allows the recipient to accurately locate and protect against identity forgery attacks by malicious vehicles, resolving the key flaw of existing technologies that prevents forged identities from being detected.
[0037] 2. Achieve efficient and reliable cross-domain authentication: Utilize the master chain-slave chain collaborative architecture to store and query user identity certificates (slave chain storage, master chain assists cross-domain query), and combine it with digital signature verification to ensure the verifiability and non-repudiation of identity authentication data in cross-domain communication.
[0038] 3. Significantly optimizes the RSU computing resource burden and improves efficiency: High-computation tasks, such as pseudonym generation parameter calculation and pseudonym legitimacy verification, originally undertaken by the RSU, are dynamically assigned to base stations with greater computing power. In particular, AI models predict and schedule the optimal serving base station (in the local area or neighboring areas) in real time, significantly alleviating the resource bottleneck problem faced by a single RSU in densely populated user scenarios.
[0039] 4. AI-driven dynamic resource scheduling ensures low latency: A large AI model is introduced to predict the resource usage status of base station clusters (serving base stations and neighboring stations) in real time, and strategies are formulated based on this to dynamically assign computing tasks, achieving global optimization and real-time resource allocation. This enables the system to meet the stringent low-latency requirements of IoT vehicle communications even with high concurrency requests.
[0040] 5. Enhanced data verification credibility: The cross-chain query mechanism (slave chain -> main chain -> slave chain) ensures that the user's original identity certificate can be obtained and verified efficiently and reliably even across domains, improving the data credibility and integrity of the entire identity authentication process. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0042] Figure 1 is a flow chart of the present invention;
[0043] Figure 2 This is a system architecture diagram of the present invention. DETAILED DESCRIPTION
[0044] The preferred embodiments of the present invention are described in detail below with reference to the accompanying drawings so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby making a clearer and more precise definition of the protection scope of the present invention.
[0045] Existing technologies forge pseudonyms in two ways: First, after a malicious vehicle registers in a domain, it doesn't send a pseudonym request to the system, but instead forges an illegal pseudonym to communicate with surrounding entities. This illegal pseudonym is not verified or authorized by the system's pseudonym mechanism.
[0046] Second, the malicious vehicle has already initiated a pseudonym generation request to the system. It obtains the authorization parameters for pseudonym generation and generates a valid pseudonym according to the system's rules. However, during actual communication, it does not use the valid pseudonym. Instead, it forges another pseudonym using the authorization parameters, packages this pseudonym with the authorization parameters, and launches an attack, making it impossible for the system to locate its true identity.
[0047] However, the traditional single-chain blockchain architecture cannot meet the cross-domain requirements of the Internet of Vehicles. Data in the vehicle domain needs to be frequently read and written in the blockchain, and each authentication transaction must be verified by consensus before being written.
[0048] Furthermore, existing roadside units (RSUs) require increasing computing resources. When a particular RSU is crowded with users, it will be unable to meet their low-latency requirements. Therefore, it is necessary to consider integrating large AI models with real-time dynamic strategy formulation.
[0049] The present application provides an identity authentication method for resisting identity forgery attacks, the method comprising:
[0050] System initialization, including generating key pairs for each entity via elliptic curves;
[0051] The user registers their identity in the domain, and the authentication center generates the corresponding key pair, encryption parameters, and identity certificate for the user, and uploads them to the on-chain storage;
[0052] Return address information from the chain;
[0053] The preloaded factors containing the private key are generated in the key generation center KGC. The batch of factors are preloaded to the roadside unit RSU for subsequent calculation of the pseudonym generation parameters.
[0054] When a user initiates a pseudonym generation request to a nearby RSU, the RSU verifies the legitimacy of the request and forwards it to a nearby base station. The base station uses an AI model to predict the resource usage status of the serving base station and neighboring stations, formulates a strategy, and assigns the serving base station to calculate the pseudonym generation parameters in real time.
[0055] After receiving the pseudonym generation parameters, the user generates his or her own pseudonym, verification parameters, and corresponding key pair;
[0056] The user uses a pseudonym and a key pair to calculate a unique signature and encrypts the message using the signature;
[0057] When a user requests communication, a message packet is sent to the recipient, wherein the message packet carries address information;
[0058] After receiving the message packet and verifying its validity, the receiver sends the message packet to the nearby RSU, which forwards it to the nearby base station. The service base station is assigned in real time according to the policy to verify the legitimacy of the user's pseudonym.
[0059] The receiver submits a pseudonymous request to a nearby RSU, which carries the address information, and queries whether the slave chain contains the address information, performing a cross-domain query for data verification;
[0060] If the slave chain contains the address information, the identity certificate is returned; otherwise, the address information is sent to the main chain, which assists in completing the query;
[0061] Return the identity certificate from the chain to the recipient;
[0062] The recipient verifies the signature of the user's identity. If the user does not use a pseudonym to generate parameters, the verification fails.
[0063] In the above process, malicious users cannot pass signature verification because they do not use valid pseudonym generation parameters. The calculation of pseudonym generation parameters increases the workload of the RSU. However, using distributed base stations and serving base stations can reduce the computational burden on the RSU, lower costs, and fully utilize the computing power of base stations. It also allows the deployment of AI models in base stations for real-time prediction and strategy development, making more efficient use of resources.
[0064] In some preferred embodiments, the users include a first user and a second user, the first user and the second user are each registered in a different domain, and their respective identity certificates are stored in two independent slave chains, namely the first slave chain and the second slave chain, to obtain two different certificate storage account addresses.
[0065] In some preferred embodiments, the first user establishes a connection with a trusted entity in the local domain in the domain where the first user is located, namely, the first slave chain. The first user queries whether the identity certificate of the corresponding user exists through the account address of the second user. If it exists, it is directly returned to the trusted entity for identity authentication. If there is no identity certificate of the second user in the first slave chain, the first slave chain submits a request to the corresponding node in the main chain, and queries the data information of the account address in the second slave chain in the main chain.
[0066] In some preferred embodiments, when an account address is queried from the second slave chain, the main chain will send the received data response from the second slave chain to the first slave chain. The trusted entity of the first slave chain uses the identity certificate in the data to perform relevant authentication. If the authentication is successful, the first user and the second user in different domains are allowed to communicate.
[0067] The user may be a vehicle, the so-called trusted entity may be a corresponding node from the chain, and the first user or the second user may be a sender or a receiver.
[0068] Figure 2 This is an architecture diagram of the identity authentication system provided by this application to resist identity forgery attacks. The system includes:
[0069] Initialization module, used for system initialization, including generating key pairs for each entity through elliptic curve;
[0070] The authentication center is used for users to register their identities in the domain, generate corresponding key pairs, encryption parameters and identity certificates for users, and upload them to the slave chain for storage; and receive address information returned from the slave chain;
[0071] The key generation center (KGC) is used to generate preloaded factors containing private keys. Batches of factors are preloaded onto the roadside unit (RSU) for subsequent calculation of pseudonym generation parameters.
[0072] Roadside Unit (RSU), which receives pseudonym generation requests initiated by users, verifies the legitimacy of the requests, and forwards them to nearby base stations;
[0073] Base stations are used to predict the resource usage status of the serving base station and neighboring base stations through AI models, formulate strategies, and assign the serving base station to calculate pseudonym generation parameters in real time;
[0074] The user initiates a pseudonym generation request and sends it to a nearby RSU. After receiving the pseudonym generation parameters, the user generates its own pseudonym, verification parameters, and corresponding key pair. The pseudonym and key pair are used to calculate a unique signature, and the signature is used to encrypt the message. When the user requests communication, a message packet carrying address information is sent to the recipient.
[0075] The receiver receives the message packet, verifies its validity, and then sends it to a nearby RSU. The RSU forwards the message packet to a nearby base station, which assigns a serving base station in real time to verify the legitimacy of the user's pseudonym based on the policy. The receiver submits a pseudonym request to a nearby RSU, which carries address information, and queries whether the slave chain contains the address information, performing a cross-domain query for data verification. The receiver also verifies the user's identity signature. If the user does not use the pseudonym to generate parameters, the verification fails.
[0076] The slave chain is used to determine whether the address information is contained. If so, the identity certificate is returned. Otherwise, the address information is sent to the main chain, and the main chain assists in completing the query; the slave chain returns the identity certificate to the recipient.
[0077] The present application provides an identity authentication system for resisting identity forgery attacks, the system comprising: the system comprising a processor and a memory:
[0078] The memory is used to store program code and transmit the program code to the processor;
[0079] The processor is configured to execute the method described in any one of all embodiments of the first aspect according to instructions in the program code.
[0080] The present application provides a computer-readable storage medium, which is used to store program code, and the program code is used to be executed by a processor to implement any one of the methods in all embodiments of the first aspect.
[0081] In a specific implementation, the present invention further provides a computer storage medium, wherein the computer storage medium may store a program that, when executed, may include some or all of the steps of various embodiments of the present invention. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0082] Those skilled in the art will clearly understand that the technology in the embodiments of the present invention can be implemented by means of software plus the necessary general-purpose hardware platform. Based on this understanding, the technical solutions in the embodiments of the present invention, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention or certain portions of the embodiments.
[0083] In particular, for the embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description in the method embodiments.
[0084] The above-described embodiments of the present invention do not limit the protection scope of the present invention.
Claims
1. An identity authentication method for resisting identity forgery attacks, characterized in that: The method comprises: System initialization, including generating key pairs for each entity via elliptic curves; The user registers their identity in the domain, and the authentication center generates the corresponding key pair, encryption parameters, and identity certificate for the user, and uploads them to the on-chain storage; Return address information from the chain; The preloaded factors containing the private key are generated in the key generation center KGC. The batch of factors are preloaded to the roadside unit RSU for subsequent calculation of the pseudonym generation parameters. When a user initiates a pseudonym generation request to a nearby RSU, the RSU verifies the legitimacy of the request and forwards it to a nearby base station. The base station uses an AI model to predict the resource usage status of the serving base station and neighboring stations, formulates a strategy, and assigns the serving base station to calculate the pseudonym generation parameters in real time. After receiving the pseudonym generation parameters, the user generates his or her own pseudonym, verification parameters, and corresponding key pair; The user uses a pseudonym and a key pair to calculate a unique signature and encrypts the message using the signature; When a user requests communication, a message packet is sent to the recipient, wherein the message packet carries address information; After receiving the message packet and verifying its validity, the receiver sends the message packet to the nearby RSU, which forwards it to the nearby base station. The service base station is assigned in real time according to the policy to verify the legitimacy of the user's pseudonym. The receiver submits a pseudonymous request to a nearby RSU, which carries the address information, and queries whether the slave chain contains the address information, performing a cross-domain query for data verification; If the slave chain contains the address information, the identity certificate is returned; otherwise, the address information is sent to the main chain, which assists in completing the query; Return the identity certificate from the chain to the recipient; The recipient verifies the signature of the user's identity. If the user does not use a pseudonym to generate parameters, the verification fails.
2. The method according to claim 1, wherein: The users include a first user and a second user. The first user and the second user are each registered in a different domain. Their respective identity certificates are stored in two independent slave chains, namely the first slave chain and the second slave chain, to obtain two different certificate storage account addresses.
3. The method according to claim 2, wherein: The first user establishes a connection with a trusted entity in the local domain in the domain where he is located, namely the first slave chain. The first user queries whether the identity certificate of the corresponding user exists through the account address of the second user. If it exists, it is directly returned to the trusted entity for identity authentication. If the identity certificate of the second user does not exist in the first slave chain, the first slave chain submits a request to the corresponding node in the main chain to query the data information of the account address in the second slave chain in the main chain.
4. The method according to claim 2, wherein: When the account address is queried from the second slave chain, the main chain will send the received data response from the second slave chain to the first slave chain. The trusted entity of the first slave chain will use the identity certificate in the data to perform relevant authentication. If the authentication is successful, the first user and the second user in different domains are allowed to communicate.
5. An identity authentication system for resisting identity forgery attacks, characterized in that: The system comprises: Initialization module, used for system initialization, including generating key pairs for each entity through elliptic curve; The authentication center is used for users to register their identities in the domain, generate corresponding key pairs, encryption parameters and identity certificates for users, and upload them to the slave chain for storage; and receive address information returned from the slave chain; The key generation center (KGC) is used to generate preloaded factors containing private keys. Batches of factors are preloaded onto the roadside unit (RSU) for subsequent calculation of pseudonym generation parameters. Roadside Unit (RSU), which receives pseudonym generation requests initiated by users, verifies the legitimacy of the requests, and forwards them to nearby base stations; Base stations are used to predict the resource usage status of the serving base station and neighboring base stations through AI models, formulate strategies, and assign the serving base station to calculate pseudonym generation parameters in real time; The user initiates a pseudonym generation request and sends it to a nearby RSU. After receiving the pseudonym generation parameters, the user generates its own pseudonym, verification parameters, and corresponding key pair. The pseudonym and key pair are used to calculate a unique signature, and the signature is used to encrypt the message. When the user requests communication, a message packet carrying address information is sent to the recipient. The receiver receives the message packet, verifies its validity, and then sends it to a nearby RSU. The RSU forwards the message packet to a nearby base station, which assigns a serving base station in real time to verify the legitimacy of the user's pseudonym based on the policy. The receiver submits a pseudonym request to a nearby RSU, which carries address information, and queries whether the slave chain contains the address information, performing a cross-domain query for data verification. The receiver also verifies the user's identity signature. If the user does not use the pseudonym to generate parameters, the verification fails. The slave chain is used to determine whether the address information is contained. If so, the identity certificate is returned. Otherwise, the address information is sent to the main chain, and the main chain assists in completing the query; the slave chain returns the identity certificate to the recipient.
6. An identity authentication system for resisting identity forgery attacks, characterized in that: The system includes a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is configured to implement the method according to any one of claims 1 to 4 according to the instructions in the program code.
7. A computer-readable storage medium, characterized in that The computer-readable storage medium is used to store program code, and the program code is used to be executed by a processor to implement the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Alliance chain cross-chain-oriented identity authentication method
CN117335958A
Certificateless identity authentication method based on block chain and related device
CN119766448A
Certificateless strong anonymous aggregation signcryption method in Internet of Vehicles
CN119814323A
Vehicle-mounted network identity authentication method, device, equipment and storage medium
CN120301601A
Cited By
Method and system for intelligently and cooperatively defending identity forgery attack
CN120835296A
A method and system for intelligent collaborative defense against identity spoofing attacks
CN120835296B