Lightweight certificateless signcryption method capable of proving security in Internet of Vehicles

By building a vehicle network system consisting of KGC, roadside units and blockchain, and adopting a pseudonym mechanism and offline preloading, the computing and communication overheads are reduced, the problems of certificate management and high computing complexity in the vehicle network are solved, and efficient and secure vehicle-to-vehicle communication is achieved.

CN120751368APending Publication Date: 2025-10-03CHONGQING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510923083.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

In existing vehicle-to-vehicle communication, certificate-based signcryption schemes have problems such as high certificate management costs and high computational complexity of certificateless signcryption schemes, resulting in high system overhead and insufficient security, making it difficult to achieve efficient and secure communication between vehicles.

Method used

A system consisting of a key generation center (KGC), roadside units (ROUs), vehicles, and blockchain is constructed. A pseudonym mechanism and an offline preloading mechanism are adopted to reduce the computational complexity of the signcryption and decryption processes. The communication overhead is reduced by an aggregated signcryption and decryption method. At the same time, vehicle information is stored on the blockchain to achieve anonymous communication and privacy protection.

Benefits of technology

It achieves safe and reliable communication between vehicles, reduces computing and communication overhead, ensures information security and privacy protection, and is suitable for the Internet of Vehicles environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751368A_ABST
    Figure CN120751368A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of secure communication in the Internet of Vehicles, and particularly relates to a lightweight certificateless signcryption method capable of proving security in the Internet of Vehicles, which comprises the following steps: constructing an Internet of Vehicles system consisting of a key generation center KGC, a roadside unit, a vehicle and a block chain, and initializing system parameters; the vehicle-mounted unit in the vehicle and the roadside unit outside the vehicle respectively register in the key generation center, and system parameters and pseudonyms are returned after KGC verification is passed; the KGC generates a part of keys for the pseudonym and returns the keys to the vehicle, and the vehicle calculates and generates a key and a public key according to the returned part of keys and the pseudonym, and uploads the public key and the pseudonym to the block chain; the vehicle signcrypts the message according to the key, obtains the public key of the receiver from the block chain according to the pseudonym of the opposite side, and then sends the signcryption message to the receiver; and the target vehicle or the roadside unit receives the message and performs message de-signcryption, and uploads a transaction record to the block chain for storage. According to the invention, while anonymous and secure communication of each entity in the Internet of Vehicles system is ensured, the communication efficiency is improved by reducing the vehicle calculation pressure and the communication overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of secure communications in the Internet of Vehicles, and in particular relates to a provably secure lightweight certificateless signcryption method in the Internet of Vehicles. Background Art

[0002] With the development of Intelligent Transportation Systems (ITS), Internet of Vehicles (IoV) technology has revolutionized transportation systems. Modern vehicles are equipped with multiple wireless communication modules and sensors. On-Broadband Units (OBUs) within vehicles are capable of sharing real-time traffic and vehicle information. This is particularly true in vehicle-to-vehicle (V2V) communication, which involves direct data exchange between vehicles, increasing transmission speeds and addressing the limitations of vehicle-to-infrastructure (V2I) communication. However, the sensitive nature of traffic data transmitted in V2V communication makes it vulnerable to eavesdropping and malicious attacks. Any tampering or falsification of this data can negatively impact traffic efficiency, safety, and personal security. In addition to ensuring the availability of accurate traffic data, protecting vehicle privacy is equally important. Unauthorized disclosure of vehicle identity information could lead to illegal tracking or surveillance. Clearly, ensuring secure and reliable V2V communication is a key issue that needs to be addressed in the IoV.

[0003] To ensure the security and reliability of transmitted information, the Internet of Vehicles uses digital signcryption to encrypt and verify key information. This ensures that transmitted information cannot be decrypted or tampered with after malicious interception, ensuring non-repudiation of the information sent. Existing signcryption technologies are divided into certificate-based signcryption schemes and certificateless signcryption schemes.

[0004] The core concept of certificate-based signcryption schemes is to leverage public key infrastructure (PKI) to manage users' public keys. Specifically, a public key certificate issued by an authority associates the user's public key with their real identity. The certificate is also signed by the authority, allowing other users to verify the authenticity of the signer's public key by verifying the authority's signature. However, the development of certificate-based signcryption schemes is limited by the costs associated with issuing, storing, verifying, and revoking certificates.

[0005] In certificateless signcryption schemes, a key generation center (KGC) participates in generating a portion of a user's key, while the user generates the remaining portion. Therefore, the KGC cannot access the user's complete key, thus avoiding the security issues associated with centralized PKI management of user private keys. However, many existing certificateless signcryption schemes utilize bilinear pairings. These complex mathematical operations, while providing a certain degree of security, also significantly increase the scheme's overhead, placing a heavy computational burden on the system.

[0006] In summary, existing signcryption schemes have played a vital role in protecting users from external malicious node attacks and improving system efficiency. However, they still have limitations such as excessive system overhead and insufficient security. Therefore, it is of great significance to study an efficient and secure certificateless signcryption scheme adapted to the Internet of Vehicles. Summary of the Invention

[0007] To solve the above problems, the present invention proposes a provably secure, lightweight, certificateless signcryption method in the Internet of Vehicles, comprising the following steps:

[0008] S1. Build a connected vehicle system consisting of a key generation center (KGC), roadside units (RSUs), vehicles, and blockchain, and initialize system parameters.

[0009] S2. The vehicle's onboard unit and roadside unit register with KGC. KGC reviews and returns system parameters and a pseudonym.

[0010] S3. KGC generates a partial key for the pseudonym and returns it to the vehicle. The vehicle calculates a secret key and public key based on the returned partial key and pseudonym, and uploads the public key and pseudonym to the blockchain.

[0011] S4. The vehicle signifies the message using the key, obtains the recipient's public key from the blockchain based on the recipient's pseudonym, and then sends the signified message to the recipient.

[0012] S5. The target vehicle or roadside unit receives the message, decrypts the message, and uploads the transaction record to the blockchain for storage;

[0013] Preferably, step S3 specifically includes:

[0014] S31. The key generation center KGC selects a random number k i ∈Z q * and calculate PSK i,1 =k i P, then calculate h 1,i =H1(PID i ,PSK i,1,P pub ), encryption parameter psk i,2 =k i +sh 1,i , and finally the partial key (PSK i,1 ,psk i,2 ) is sent to vehicle V through a secure channel i ;

[0015] S32. The vehicle V i After receiving the partial key, first verify the psk i,2 P=PSK i,1 +h 1,i P pub If the key is valid, the key is accepted; otherwise, the key is discarded and re-applied.

[0016] S33. The vehicle V i After obtaining the verified partial private key, the vehicle V i Select y i ∈Z q * Calculate the private key sk i =y i +psk i,2 , the public key is PK i =sk i P pub , and then use its own pseudonym PID i And the corresponding public key PK i Upload to the blockchain (PID i ,PK i ).

[0017] The beneficial effects of the present invention are as follows: First, the transmission information is signed and encrypted through the certificateless signcryption technology, thereby ensuring the security of the information. Then, the scheme introduces a pseudonym mechanism, which, on the one hand, enables anonymous communication between the two parties, and on the other hand, can reveal the true identity of the vehicle when necessary, thereby achieving conditional privacy protection. At the same time, in order to improve the performance of the scheme and reduce communication overhead, the scheme minimizes the number of scalar multiplication and addition operations in the signcryption and decryption processes while ensuring security. Secondly, the scheme adds an offline preloading mechanism to the signcryption process, utilizing the computing resources of the vehicle when it is idle to calculate some signcryption parameters in advance, thereby reducing the real-time computing pressure of the vehicle. Next, the method of aggregated signcryption and aggregated decryption is adopted, which can realize the simultaneous verification of multiple signcrypted information, further reduce the communication overhead, and trace invalid signatures. Finally, the unforgeability and confidentiality of the proposed scheme are proved under the random oracle model. The simulation comparison results show that the proposed scheme has good performance and is suitable for the communication environment of the Internet of Vehicles. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 This is a vehicle networking system model for a vehicle commuting scenario in an embodiment of the present invention;

[0019] Figure 2 is a flowchart of steps of an embodiment of the present invention;

[0020] Figure 3 This is a flowchart of step S4 in an embodiment of the present invention; DETAILED DESCRIPTION

[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0022] This invention proposes a provably secure, lightweight, certificateless signcryption method for the Internet of Vehicles (IoV). The IoV system constructed in this method involves four entities: a key generation center (KGC), roadside units (RSUs), vehicles, and a blockchain. RSUs and vehicles must register their identities with the KGC before participating in IoV communications. The KGC sends corresponding identity parameters to each registered vehicle and RSU and stores them in the KGC's local memory for backup. If a registered vehicle initiates malicious activity for its own benefit, the KGC can track it and revoke its legitimate identity. Since the registered vehicle's identity information is stored in the KGC, the KGC can use this information to recover the vehicle's true identity. Furthermore, the KGC can revoke the malicious vehicle's public key from the blockchain. Once a vehicle's public key is revoked from the blockchain, other vehicles will no longer be able to communicate with it. Potential attackers cannot calculate the vehicle's identity information. Even if they obtain the identity information from the database, they cannot infer the vehicle's true identity through hash signatures because they lack access to the system master key. This achieves conditional privacy protection. At the same time, blockchain technology is used to store vehicle pseudonyms and public key information, avoiding key custody issues.

[0023] In the embodiment provided by the present invention, considering the communication efficiency and security requirements in the context of the Internet of Vehicles (IoV), a model for vehicle information interaction is constructed, such as Figure 1 As shown, where:

[0024] (1) Key Generation Center (KGC): The KGC is responsible for generating and managing system parameters, as well as generating pseudonyms and partial keys for other entities in the IoV. It has high computing, storage, and power resources.

[0025] (2) Blockchain: Blockchain is a distributed network for managing public keys, which stores pairs of vehicle identities and their corresponding public keys. At the same time, blockchain provides a query service for retrieving vehicle public keys based on the mapping between pseudonym information and keys, thereby ensuring secure communication between registered vehicles. In addition, each encrypted information transmitted by the vehicle will be uploaded to the blockchain for storage in the form of a transaction bill.

[0026] (3) Roadside Unit (RSU): The RSU located on the roadside is responsible for coordinating the information transmission between various entities. It also acts as a blockchain node responsible for uploading and downloading information, and can also aggregate signcryption and decryption information.

[0027] (4) Vehicles: Each vehicle in the Internet of Vehicles is equipped with an OBU module, which can perceive information and sign and decrypt the transmitted information.

[0028] like Figure 2 As shown, the present invention provides an embodiment of a provably secure lightweight certificateless signcryption method in an Internet of Vehicles, which specifically includes the following steps:

[0029] S1. Build a connected vehicle system consisting of a key generation center (KGC), roadside units (RSUs), vehicles, and blockchain, and initialize system parameters.

[0030] S2. The vehicle's onboard unit and roadside unit register with KGC. KGC reviews and returns system parameters and a pseudonym.

[0031] S3. KGC generates a partial key for the pseudonym and returns it to the vehicle. The vehicle calculates a secret key and public key based on the returned partial key and pseudonym, and uploads the public key and pseudonym to the blockchain.

[0032] S4. The vehicle signifies the message using the key, obtains the recipient's public key from the blockchain based on the recipient's pseudonym, and then sends the signified message to the recipient.

[0033] S5. The target vehicle or roadside unit receives the message, decrypts the message, and uploads the transaction record to the blockchain for storage;

[0034] Preferably, in step S1, the initialization system parameters of the Internet of Vehicles system specifically include:

[0035] The key generation center KGC selects elliptic curve parameters a and b, where a,b∈F p , 4a 3 +27b 2 ≠0(modp), F p Representing a finite field over large prime numbers, as well as a prime number q representing the order of the finite field of an elliptic curve and a generator G of the cyclic subgroup of the elliptic curve;

[0036] The key generation center KGC selects a random number As the system master key, then keep it secret and calculate its public key P pub =sP, P is its generator;

[0037] The key generation center KGC selects four one-way hash functions: Finally, upload the system parameters to the blockchain for storage: params = {G, q, P pub ,P,H1,H2,H3,H p}.

[0038] Preferably, step S2 specifically includes:

[0039] The process of registering the identity of the on-board unit in the vehicle in the Internet of Vehicles system and uploading its own identity information is as follows:

[0040] S201. The vehicle's onboard unit is registered with the key generation center KGC before joining the Internet of Vehicles. When the key generation center KGC passes the review, the system parameters will be sent to the vehicle through a secure channel. The vehicle will save the security parameters on the onboard unit OBU.

[0041] S202. The vehicle V i Select a random number based on the system parameters published by the system To obtain X i =x i P, then (ID i ,X i ), sent to the key generation center KGC through a secure channel for registration, where ID i Is the vehicle's true identity, X i is the public key;

[0042] S203. The key generation center KGC will review it and after the review is passed, KGC will (ID i ,X i ) is added to its own entity information mapping table;

[0043] S204. The key generation center KGC sets a pseudonym for the vehicle Where Δt represents the validity period of the anonymous identity, then PID i Sent to vehicle V via secure channel i , then, (PID i ,X i ,Δt) is stored by KGC;

[0044] S205. The pseudonym identity set by the key generation center KGC, when PIDi When the validity period of Δt is exceeded, the vehicle V i Need to obtain a new anonymous identity from KGC;

[0045] The process of registering the identity of the roadside unit (RSU) in the Internet of Vehicles system and uploading its own identity information is as follows:

[0046] S211. The roadside unit is registered at the key generation center KGC. When the key generation center KGC passes the review, the system parameters and part of the private key will be sent to the roadside unit through a secure channel. The roadside unit will save the parameters locally.

[0047] S212. The roadside unit selects a random number based on the parameters returned by the system to calculate its own public and private key pair, and uploads it to the blockchain for storage.

[0048] Preferably, step S3 specifically includes:

[0049] S31. The key generation center KGC selects a random number and calculate PSK i,1 =k i P, then calculate h 1,i =H1(PID i ,PSK i,1 ,P pub ), encryption parameter psk i,2 =k i +sh 1,i , and finally the partial key (PSK i,1 ,psk i,2 ) is sent to vehicle V through a secure channel i ;

[0050] S32. The vehicle V i After receiving the partial key, first verify the psk i,2 P=PSK i,1 +h 1,i P pub If the key is valid, the key is accepted; otherwise, the key is discarded and re-applied.

[0051] S33. The vehicle V i After obtaining the verified partial private key, the vehicle V i Select Calculate the private key sk i =y i +psk i,2 , the public key is PK i =sk i P pub , and then use its own pseudonym PIDi And the corresponding public key PK i Upload to the blockchain (PID i ,PK i ).

[0052] Preferably, Figure 3 As shown, step S4 specifically includes:

[0053] S41. If the vehicle has no other computing tasks, the vehicle will consider using the remaining computing resources to generate parameters for the signcryption process. At this time, the vehicle will use a pre-designed algorithm to generate the offline part of the signcryption: select a random selection And calculate the public key R i =r i P pub ;

[0054] S41. If the vehicle has no other computing tasks, the vehicle will consider using the remaining computing resources to generate parameters for the signcryption process. At this time, the vehicle will use a pre-designed algorithm to generate the offline part of the signcryption: select a random selection And calculate the public key R i =r i P pub ;

[0055] S42. The vehicle will {r i ,R i} List stored in vehicle OBU It is used to quickly assemble the signcrypted ciphertext and clear the list after each parameter is used, waiting for the next offline calculation to regenerate the required parameters;

[0056] S43. The vehicle now needs to send a message m to the target vehicle. i , the vehicle needs to do the following: If There are elements {r i ,R i}, then use {r i ,R i} as the signcryption parameter, otherwise, the vehicle is randomly selected Calculate R i =r i P pub , then calculate h 2,i =H2(R i ,m i ) and pass the recipient's pseudonymous PID j Get the recipient's public key PK from the blockchain j Then, the vehicle calculates W i =r i PK j , and sig i =r i +h 2,i sk i Finally, the message signcryption tuple σ i ={R i ,C i ,sig i} and timestamp t i Forward to the target vehicle;

[0057] S44. The vehicle or roadside unit RSU is from different vehicles V1, V2, ... V n Receive multiple valid ciphertexts {R1,C1,sig1},{R2,C2,sig2},…,{R n ,C n ,sig n} and the corresponding timestamp t i When it is used as an intermediary, it can forward the aggregated signcryption to the intended recipient and aggregate these signcrypted multiple ciphertexts to first calculate R={R1,R2,…,R n}, C={C1,C2,…,C n}, T={t1,t2,…,t n} to compress these ciphertexts into a short signcryption σ = {R, C, Ω} and a timestamp T; then the aggregated signcryption σ = {R, C, Ω} and T are sent to nearby intended recipients.

[0058] Preferably, step S5 specifically includes:

[0059] S51. The vehicle sends an encrypted message to the recipient, and the recipient receives the sent signcrypted tuple σ i After that, you need to confirm the message freshness. If t j -t i >Δt max , at this time V j Reject σ i , where t j and Δt max Represents σ i Arrival time and maximum transmission delay;

[0060] S52. The vehicle sends an encrypted message to the recipient. After the recipient determines that the message is passed, calculate W i ′=R i sk j And restore the plaintext message Calculate h' 2,i =H2(R i ,m′ i );

[0061] S53. The vehicle sends an encrypted message to the receiver, and the receiver calculates and recovers the plaintext message and verifies the equation sig. i P pub =R i +h' 2,i PK i , if established, then V j Receive message m′ i Otherwise, V j Reject message m′ i ,After the message transmission is completed, a transaction record is generated and uploaded to the blockchain for storage;

[0062] S54. The vehicle V j Or roadside unit RSU from different vehicles V1, V2, ... V n When receiving the aggregated signcrypted ciphertext, it first decompresses the signcrypted ciphertext and then checks t i The effectiveness of i Freshness beyond the effective time, V j These ciphertexts are rejected, otherwise, V j Perform the following steps: (1) Decrypt each individual ciphertext to obtain the recovered message m′ i ,in (2) Calculate h' 2,i =H2(R i ,m′ i ). (3) Finally, through the formula Check the validity of the signature. If the formula is established, the integrity and reliability of the message are proved. At this time, V j Accept the recovered message, otherwise refuse to receive the recovered ciphertext;

[0063] Preferably, the vehicle or roadside unit (RSU) can identify invalid signcryptions that cause aggregate verification failures through a signature verification algorithm, and send the signcrypted pseudonyms to the key generation center (KGC), and then reveal the true identities of these pseudonyms to enable subsequent tracking and identity revocation, including:

[0064] The vehicle found that the aggregated signcryption verification failed, i.e. When the invalid aggregated signcrypted ciphertext is sent to the roadside unit RSU through a secure channel. After the roadside unit RSU receives the invalid aggregated signcrypted ciphertext, it first sorts all the ciphertexts participating in the aggregation in a certain order, then divides all the ciphertexts into two parts from the middle, and aggregates all the ciphertexts in the left half to obtain the re-aggregated signcrypted ciphertext σ left ;

[0065] The roadside unit RSU aggregates the signcrypted ciphertext σ left After that, the aggregate decryption signcryption algorithm is first used for verification. Where k is the number of ciphertexts in this part. This indicates that there is no invalid signature in the signature of the left half, so RSU repeats the steps for the right half of all signatures;

[0066] The roadside unit RSU verification in For the last verification result, all invalid signatures are found. Where e is the number of invalid signatures, then RSU will pseudonymize all invalid signatures. The data is sent to KGC, which starts tracking the behavior of the corresponding vehicle. If the vehicle is continuously observed to release invalid signcrypted ciphertexts, its true identity will be announced and its legal identity in the Internet of Vehicles will be revoked.

[0067] The random oracle model is used to prove the communication security of the embodiment of the present invention. The specific proof process is as follows:

[0068] If the certificateless signcryption scheme is secure, it must satisfy the unforgeability and confidentiality properties. Therefore, the unforgeability and confidentiality properties of the scheme are proved in the random oracle:

[0069] There are usually two types of attackers in certificateless signcryption schemes, as described below: (1) A I The attacker simulates a malicious vehicle node in the Internet of Vehicles. I They can replace any user's public key with a chosen value, but cannot access the system master key. This type of attacker includes two types of adversaries: I-1 and A I-2 , the unforgeability and confidentiality of the attack scheme. (2)A II The attacker simulates the dishonest KGC in the Internet of Vehicles. II They can access the system master key but cannot replace any user’s public key. Similarly, this type of attacker includes two types of adversaries: II-1 and A II-2 The attack scheme's unforgeability and confidentiality properties. To fully illustrate the security model of the proposed scheme, four interactive games are proposed. These games effectively simulate adversarial attacks against the aforementioned security aspects, accurately replicating the interaction between the challenger and the adversary. In the proposed scheme, the attack on unforgeability is described as follows: the attacker cannot successfully forge a valid signcrypted ciphertext of a legitimate user in polynomial time. The attack on confidentiality is described as follows: although the attacker can select a ciphertext and request decryption, he or she cannot distinguish the corresponding plaintext content.

[0070] The game between challenger Q and adversary is as follows:

[0071] 1. Unforgeability

[0072] Game 1 (Challenger Q and Adversary A I-1)

[0073] Phase 1: System initialization phase: Challenger Q simulates the system to execute the initialization algorithm, generates system parameters params and sends them to adversary A I-1 , and then keep the system master key secret.

[0074] Phase 2: Query Phase:

[0075] Hash query. Adversary A I-1 Send data to challenger Q to execute this query and obtain the result of the corresponding hash function calculation.

[0076] Partial private key query. Adversary A I-1 Send the pseudonymous identity of the specified user to the challenger Q to execute this query and obtain the partial private key of the corresponding user.

[0077] Private key query. Adversary A I-1 Send the pseudonymous identity of the specified user to the challenger Q to execute this query and obtain the private key of the corresponding user.

[0078] Public key query. Adversary A I-1 Send the pseudonymous identity of the specified user to the challenger Q to execute this query and obtain the public key of the corresponding user.

[0079] Replace the public key query. Adversary A I-1 Send the pseudonymous identity of the specified user and the public key to be replaced to the challenger Q to execute this query, and the challenger Q replaces the public key of the corresponding user.

[0080] Signcryption query. Adversary A I-1 Send the pseudonymous information and message of the simulated information sender and receiver to the challenger Q to perform this query. At this time, the challenger Q executes the signcryption algorithm, and the adversary A I-1 Obtain the signed ciphertext.

[0081] Phase 3: Forgery Phase: Adversary A I-1 Output a forged signcrypted ciphertext based on the information obtained from the previous query. If the signcrypted ciphertext is verified to be valid, then the adversary A I-1 Win the game.

[0082] Game 2: (Challenger Q and Adversary A II-1 )

[0083] Phase 1: System initialization phase: Same as Game 1.

[0084] Phase 2: Query phase: All queries related to Game 1 can be executed except for the replacement public key query.

[0085] Phase 3: Forgery Phase: Same as Game 1, Adversary A II-1Output a forged signcryption information based on the information obtained from the previous query. If the signcryption information is verified to be valid, then the adversary A II-1 Win the game.

[0086] 2. Confidentiality

[0087] Game 3: (Challenger Q and Adversary A I-2 )

[0088] Phase 1: System initialization phase: Same as Game 1.

[0089] Phase 2: Query phase: All queries and decryption queries as in Game 1 can be performed.

[0090] Decryption query. Adversary A I-2 Send the pseudonymous information of the simulated message sender and receiver, the encrypted message and the decryption request to the challenger Q to perform this query. Q executes the decryption algorithm, restores the original plaintext message and sends it to A I-2 .

[0091] Phase 3: Challenge Phase: When Phase 2 ends, A I-2 Enter the challenge phase. I-2 Pick two different messages m0 and m1 with the same length. Q selects a random value b∈{0,1} and calculates the ciphertext σ corresponding to the selected message m0 * , and feedback to A I-2 , A I-2 A is allowed to perform polynomial queries and finally output the result b'. If b'=b, then A I-2 Win the game.

[0092] Game 4: (Challenger Q and Adversary A II-2 )

[0093] Phase 1: System initialization phase: Same as Game 1.

[0094] Phase 2: Query phase: All queries in game 3 except public key replacement query can be executed.

[0095] Stage 3: Challenge stage: Same as game 3.

[0096] Theorem 1 (About adversary A I-1 Unforgeability under attack) If there is A I Type A I-1 In probabilistic polynomial time, by executing at most Second H i Query (i=1,2,3), q psk Second part private key query, q sk Private key query, q pktimes the public key query and q sc The second sign-cryptographic query, and wins the game 1 with a non-negligible advantage ε, then Q can be no less than The advantages of are used to solve the elliptic curve discrete logarithm ECDLP problem.

[0097] Proof: Challenger Q uses a random input {P pub ,aP pub}∈G1, where The task is to calculate a. In addition, Q is calculated by comparing it with A I-1 The interaction records the query response into a list and randomly selects the index PID as the identity that needs to be challenged l . In addition, all query lists ( L psk 、L sk 、L pk and L pkr ) is initialized to empty.

[0098] Phase 1: System initialization phase

[0099] Challenger Q executes the system initialization algorithm, generates system parameters params, and sends the system parameters to A I-1 .

[0100] Phase 2: Query Phase H1 Query: When A I-1 When an H1 query is initiated, Q first searches To see if the element (PID i ,PSK i,1 ,P pub ,h 1,i ), if it exists, Q sends the elements to A I-1 Otherwise, Q is randomly selected Setting up PSK i,1 =k i P and calculate h 1,i =H1(PID i ,PSK i,1 ,P pub ), and finally Q will h 1,i Send to A I-1 And (PID i ,PSK i,1 ,P pub ,h 1,i ) added to

[0101] H2 query: When A I-1 When an H2 query is issued, Q first retrieves To see if there is an element {m i,R i ,h 2,i}. If it exists, Q will h 2,i Send to A I-1 Otherwise, Q is randomly selected Then {m i ,R i ,h 2,i}Add to Finally, Q will h 2,i Send to A I-1 .

[0102] H3 query: When A I-1 When an H3 query is initiated, Q first searches To see if there is an element {W i ,h 3,i If it exists, Q will h 3,i Return to A I-1 Otherwise, Q selects a random number Then the element {W i ,h 3,i}Add to In the end, Q will h 3,i Send to A I-1 .

[0103] Partial private key query: A I-1 Send PID i To Q to perform this query. Q first checks PID i =PID l If so, Q stops the query. Otherwise, Q does the following: It first retrieves L psk To see if the element (PID i ,PSK i,1 ,psk i,2 ). If it exists, Q will {PSK i,1 ,psk i,2}Send to A I-1 Otherwise, Q obtains h by executing H1 query 1,i Then select a random number Calculate PSK at the same time i,1 =psk i,2 Ph 1,i P pub , and finally Q will {PSK i,1 ,psk i,2}Add to L psk and send A I-1 .

[0104] Private key query: A I-1 Send PID iTo Q to perform this query. Q first checks PID i =PID l If yes, Q stops the query. Otherwise, Q does the following: It first retrieves L sk To see if the element (PID i ,sk i ). If it exists, Q will sk i Send to A I-1 , otherwise, Q selects a random number Calculate sk i =y i +psk i,2 , and finally Q will sk i Send to A I-1 And (PID i ,sk i ) added to L sk middle.

[0105] Public key query: A I-1 Send PID i Go to Q to execute this query. Q first retrieves L pk To see if there is an element {PID i ,PK i If it exists, Q will use the public key PK i Provided to A I-1 Otherwise, Q checks PID i =PID l Is it true? If not, Q uses the private key query to obtain sk i , and further calculate PK i =sk i P pub , otherwise, Q selects two random numbers and calculate Finally, Q will PK i Send to A I-1 , and {PID i ,PK i}Add to L pk middle.

[0106] Public key replacement query: A I-1 Send PID i and the new public key Replace the original public key PK i , and then sent to Q to execute the query. Q uses Update and replace L pkr The corresponding elements in .

[0107] Signcryption query: A I-1 The sender PIDi , Receiver PID j and the information m that needs to be signed i Send to Q to execute the query. Q first determines the PID i =PID l If not, Q executes the actual signcryption algorithm normally because Q knows sk i , then Q uses the signcryption algorithm to generate σ i ={R i ,C i ,sig i} and send it to A I-1 If so, Q selects a random number To calculate R i =r i * P pub , W i =r i * PK j , And set h 2,i =H2(m i ,R i ), then add {m i ,R i ,h 2,i}arrive And calculate sig i =r i * +h 2,i sk i , and finally the ciphertext σ i ={R i ,C i ,sig i}Send to A I-1 .

[0108] Stage 3: Forgery

[0109] A I-1 Provide signcryption σ′ i ={R i ,C i ,sig′ i} and the ciphertext satisfies sig′ i P pub =R i +h' 2,i pk i , according to the bifurcation lemma, A I-1 You can find different To satisfy At this time R i =aP pub, therefore, the following formula holds:

[0110]

[0111] Finally, A I-1 Output This output value is a non-negligible advantage Solution to the ECDLP problem.

[0112] Theorem 2 (About adversary A II-1 Unforgeability under attack) If there is A II Type A II-1 In probabilistic polynomial time, by executing at most Second H i Query (i=1,2,3), q sk Private key query, q pk Public key query and q sc The second signatory query, and wins the game 2 with a non-negligible advantage ε, then Q can be no less than to solve the ECDLP problem.

[0113] The proof is similar to Theorem 1, so it will not be elaborated here.

[0114] Theorem 3 (About Adversary A I-2 Confidentiality under attack) If there is A I Type A I-2 In probabilistic polynomial time, by executing at most Second H i Query (i=1,2,3), q psk Second part private key query, q sk Private key query, q pk times the public key query and q unsc decryption query, and wins game 3 with a non-negligible advantage ε, then Q can be calculated with a value no less than to solve the ECDLP problem.

[0115] Proof: Challenger Q uses a random input {P pub ,aP pub}∈G, where The task is to calculate a. In addition, Q is calculated by comparing it with A I-2 The interaction records the query response into a list and randomly selects the index PID as a challenge identifier l . In addition, all query lists are initialized to empty.

[0116] Phase 1: System initialization phase

[0117] The system initialization method is the same as Game 1.

[0118] Phase 2: Query Phase

[0119] Attacker A I-2 All the same queries as Lemma 1 can be done adaptively.

[0120] Decryption query: A I-2 PID of the sender i and the receiver PID j Execute decryption σ i ={R i ,C i ,sig i}. Q first checks the PID j ≠PID l Is it true? If so, Q obtains the recipient's private key sk j To execute the decryption algorithm normally, otherwise, Q is from the list L sk Select an element as sk j , then by Restore messages and search for L H2 To obtain {m′ i ,R i ,h 2,i}h 2,i Then, Q calculates sig i P pub =R i +h 2,i PK i Is it true? If sig i P pub =R i +h 2,i PK i If it holds, then Q will m′ i Forward to A I-2 , otherwise, Q is selected from the list L sk Select another element as sk j , and repeat this step, when the list L sk There is no element in sig that makes this equation i P pub =R i +h 2,i PK i When it is established, Q outputs the error symbol ⊥ to A I-2 .

[0121] Phase 3: Challenge Phase

[0122] Opponent A I-2 for Choose two different messages m0 and m1 with the same length. If Then Q stops the operation, otherwise, Q selects two random values and Then calculate Finally to A I-2 Provide signcryption

[0123] Output guess: A I-2 Output predicted If A I-2 Can solve the ECDLP problem, then A I-2 Can be obtained from Get r i Therefore, according to A I-2 You can request W i * H3 query and perform XOR operation to recover the plaintext message This is because

[0124] In the above interaction, the probability of rejecting a valid ciphertext during the decryption phase is less than q unsc / 2 k , and the probability of terminating the game in partial private key query and private key query is Therefore A I-2 Able to be no less than The advantages of solving ECDLP problems.

[0125] Theorem 4 (About adversary A II-2 Confidentiality under attack) If there is A II Type A II-2 In probabilistic polynomial time, by executing at most Second H i Query (i=1,2,3), q sk Private key query, q pk times the public key query and q unsc decryption query, and wins game 4 with a non-negligible advantage ε, then Q can be The advantages of solving ECDLP problems.

[0126] The proof is similar to Theorem 3.3, so we will not elaborate on it here.

[0127] Aiming at the inefficient and vulnerable Internet of Vehicles (IoV) communication environment, the present invention designs a provably secure, lightweight, certificateless signcryption method for the IoV. First, a pseudonymous identity is set during the initial registration phase. Then, the number of scalar multiplication and addition operations in the signcryption and decryption processes is reduced. Secondly, an offline preloading mechanism is added to the signcryption process. Next, aggregated signcryption and decryption methods are used to further reduce communication overhead and enable the tracing of invalid signatures. Finally, the unforgeability and confidentiality of the proposed method are demonstrated under a random oracle model. Simulation comparison results show that the proposed scheme has good performance and is suitable for the IoV communication environment.

[0128] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware through a program, and the program can be stored in a computer-readable storage medium, which may include: ROM, RAM, disk or CD, etc.

[0129] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A provably secure, lightweight, certificateless signcryption method for Internet of Vehicles, characterized by: The following steps are involved: S1. Build a connected vehicle system consisting of a key generation center (KGC), roadside units (RSUs), vehicles, and blockchain, and initialize system parameters. S2. The vehicle's onboard unit and roadside unit register with KGC. KGC reviews and returns system parameters and a pseudonym. S3. KGC generates a partial key for the pseudonym and returns it to the vehicle. The vehicle calculates a secret key and public key based on the returned partial key and pseudonym, and uploads the public key and pseudonym to the blockchain. S4. The vehicle signifies the message using the key, obtains the recipient's public key from the blockchain based on the recipient's pseudonym, and then sends the signified message to the recipient. S5. The target vehicle or roadside unit receives the message, decrypts the message, and uploads the transaction record to the blockchain for storage.

2. A provably secure lightweight certificateless signcryption method in the Internet of Vehicles according to claim 1, characterized in that: The initial system parameters of the Internet of Vehicles system specifically include: The key generation center KGC selects elliptic curve parameters a and b, where a,b∈F p , 4a 3 +27b 2 ≠0(modp), F p Representing a finite field over large prime numbers, as well as a prime number q representing the order of the finite field of an elliptic curve and a generator G of the cyclic subgroup of the elliptic curve; The key generation center KGC selects a random number As the system master key, It is the multiplication group of the module q, which is then kept secret and its public key P is calculated. pub =sP, P is its generator; The key generation center KGC selects four one-way hash functions: H1, Finally, upload the system parameters to the blockchain for storage: params = {G, q, P pub ,P,H1,H2,H3,H p }.

3. The method for a provably secure, lightweight certificateless signcryption method in an Internet of Vehicles according to claim 1, wherein: The step S2 specifically includes: The process of registering the identity of the on-board unit in the vehicle in the Internet of Vehicles system and uploading its own identity information is as follows: S201. The vehicle's onboard unit is registered with the key generation center KGC before joining the Internet of Vehicles. When the key generation center KGC passes the review, the system parameters will be sent to the vehicle through a secure channel. The vehicle will save the security parameters on the onboard unit OBU. S202. The vehicle V i Select a random number based on the system parameters published by the system To obtain X i =x i P, then (ID i ,X i ), sent to the key generation center KGC through a secure channel for registration, where ID i Is the vehicle's true identity, X i is the public key; S203. The key generation center KGC will review it and after the review is passed, KGC will (ID i ,X i ) is added to its own entity information mapping table; S204. The key generation center KGC sets a pseudonym for the vehicle Where Δt represents the validity period of the anonymous identity, then PID i Sent to vehicle V via secure channel i , then, (PID i ,X i ,Δt) is stored by KGC; S205. The pseudonym identity set by the key generation center KGC, when PID i When the validity period of Δt is exceeded, the vehicle V i Need to obtain a new anonymous identity from KGC; The process of registering the identity of the roadside unit (RSU) in the Internet of Vehicles system and uploading its own identity information is as follows: S211. The roadside unit is registered at the key generation center KGC. When the key generation center KGC passes the review, the system parameters and part of the private key will be sent to the roadside unit through a secure channel. The roadside unit will save the parameters locally. S212. The roadside unit selects a random number based on the parameters returned by the system to calculate its own public and private key pair, and uploads it to the blockchain for storage.

4. The method for a provably secure lightweight certificateless signcryption method in an Internet of Vehicles according to claim 1, characterized in that: The step S3 specifically includes: S31. The key generation center KGC selects a random number And calculate the encryption parameter PSK i,1 =k i P, then calculate h 1,i =H1(PID i ,PSK i,1 ,P pub ), encryption parameter psk i,2 =k i +sh 1,i , and finally the partial key (PSK i,1 ,psk i,2 ) is sent to vehicle V through a secure channel i ; S32. The vehicle V i After receiving the partial key, first verify the psk i,2 P=PSK i,1 +h 1,i P pub If the key is valid, the key is accepted; otherwise, the key is discarded and re-applied. S33. The vehicle V i After obtaining the verified partial private key, the vehicle V i Select Calculate the private key sk i =y i +psk i,2 , the public key is PK i =sk i P pub , and then use its own pseudonym PID i And the corresponding public key PK i Upload to the blockchain (PID i ,PK i ).

5. The method for a provably secure lightweight certificateless signcryption method in an Internet of Vehicles according to claim 1, characterized in that: The step S4 specifically includes: S41. If the vehicle has no other computing tasks, the vehicle will consider using the remaining computing resources to generate parameters for the signcryption process. At this time, the vehicle will use a pre-designed algorithm to generate the offline part of the signcryption: select a random selection And calculate the public key R i =r i P pub ; S42. The vehicle will {r i ,R i } List stored in vehicle OBU It is used to quickly assemble the signcrypted ciphertext and clear the list after each parameter is used, waiting for the next offline calculation to regenerate the required parameters; S43. The vehicle V i At this time, it is necessary to j Send message m i , the vehicle needs to do the following: If There are elements {r i ,R i }, then use {r i ,R i } as the signcryption parameter, otherwise, the vehicle V i Random selection Calculate R i =r i P pub , then calculate h 2,i =H2(R i ,m i ) and pass the recipient's pseudonymous PID j Get the recipient's public key PK from the blockchain j , then, the vehicle calculates W i =r i PK j , encrypted information and message signature sig i =r i +h 2, i sk i , finally, the message signcryption tuple σ i ={R i ,C i ,sig i } and timestamp t i Forwarded to target vehicle V j ; S44. The vehicle or roadside unit RSU is from different vehicles V1, V2, ... V n Receive multiple valid ciphertexts {R1,C1,sig1},{R2,C2,sig2},…,{R n ,C n ,sig n } and the corresponding timestamp t i When it is used as an intermediary, it can forward the aggregated signcryption to the intended recipient and aggregate these signcrypted multiple ciphertexts to first calculate R={R1,R2,…,R n }, C={C1,C2,…,C n }, T={t1,t2,…,t n } to compress these ciphertexts into a short signcryption σ = {R, C, Ω} and a timestamp T; then the aggregated signcryption σ = {R, C, Ω} and T are sent to nearby intended recipients.

6. The method for a provably secure lightweight certificateless signcryption method in an Internet of Vehicles according to claim 1, characterized in that: The step S5 specifically includes: S51. The vehicle sends an encrypted message to the recipient, and the recipient receives the sent signcrypted tuple σ i After that, you need to confirm the message freshness. If t j -t i >Δt max , at this time V j Reject σ i , where t j and Δt max Represents σ i Arrival time and maximum transmission delay; S52. The vehicle sends an encrypted message to the recipient. After the recipient determines that the message is passed, calculate W i '=R i sk j And restore the plaintext message Calculate h' 2,i =H2(R i ,m i '); S53. The vehicle sends an encrypted message to the receiver, and the receiver calculates and recovers the plaintext message and verifies the equation sig. i P pub =R i +h' 2,i PK i , if established, then V j Receive message m i ', otherwise, V j Reject message m i ', after the message transmission is completed, the transaction record is generated and uploaded to the blockchain for storage; S54. The vehicle V j Or roadside unit RSU from different vehicles V1, V2, ... V n When receiving the aggregated signcrypted ciphertext, first decompress the signcrypted ciphertext and then check t i The effectiveness of i Freshness beyond the effective time, V j These ciphertexts are rejected, otherwise, V j Perform the following steps: (1) Decrypt each individual ciphertext to obtain the recovered message m i ',in (2) Calculate h' 2,i =H2(R i ,m i '); (3) Finally, through the formula Check the validity of the signature. If the formula is established, the integrity and reliability of the message are proved. At this time, V j Accept the recovered message, otherwise refuse to receive the recovered ciphertext.

7. The method for a provably secure lightweight certificateless signcryption method in an Internet of Vehicles according to claim 1, characterized in that: The vehicle or roadside unit (RSU) can identify invalid signcryptions that cause aggregate verification failures through a signature verification algorithm, and send the signcrypted pseudonyms to the key generation center (KGC). The true identities of these pseudonyms are then revealed to enable subsequent tracking and identity revocation, including: The vehicle found that the aggregated signcryption verification failed, i.e. When the invalid aggregated signcrypted ciphertext is sent to the roadside unit RSU through a secure channel, the roadside unit RSU first sorts all the ciphertexts participating in the aggregation in a certain order, then divides all the ciphertexts into two parts from the middle, and aggregates all the ciphertexts in the left half to obtain the re-aggregated signcrypted ciphertext σ left ; The roadside unit RSU aggregates the signcrypted ciphertext σ left After that, the aggregate decryption signcryption algorithm is first used for verification. If Where k is the number of ciphertexts in this part, it means that there is no invalid signature in the signature of the left half, then RSU repeats the steps for the right half of all signatures; The roadside unit RSU verification in For the last verification result, all invalid signatures are found. Where e is the number of invalid signatures, then RSU will pseudonymize all invalid signatures. The data is sent to KGC, which starts tracking the behavior of the corresponding vehicle. If the vehicle is continuously observed to release invalid signcrypted ciphertexts, its true identity will be announced and its legal identity in the Internet of Vehicles will be revoked.

Citation Information

Cited By

  • Anonymous dynamic authentication and key agreement method based on certificateless signature

    CN122093076A