Certificateless aggregation signature authentication method for vehicle-mounted ad hoc network
By adopting a key generation center and a trust authority to generate public parameters in the vehicle-mounted self-organizing network and combining it with the elliptic cryptographic curve algorithm, a new certificateless aggregate signature authentication method is designed. This solves the problems of low computing and communication efficiency and insufficient security in the existing technology, and achieves efficient signature authentication and privacy protection.
Patent Information
- Application Number
- CN202510948831.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-10
- Publication Date
- 2025-10-03
AI Technical Summary
In existing vehicular ad hoc networks, certificateless signature authentication schemes cannot effectively resist attacks, have low computing and communication efficiency, cannot meet the needs of resource-constrained environments, and have insufficient privacy protection.
A key generation center and a trust authority are used to generate public parameters. Partial private and public keys of the vehicle are generated based on the public parameters. Signatures are generated and verified using pseudonyms. Combined with the elliptic cryptographic curve algorithm, a new aggregate signature authentication method is designed to defend against Type III attacks.
It improves computing efficiency, reduces communication overhead, and significantly improves security, effectively resisting attacks and protecting user privacy.
Smart Images

Figure CN120751380A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless network security technology, and in particular to a certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network. Background Art
[0002] In recent years, with the continuous increase in the number of cars worldwide, traffic accidents, road congestion, and fuel waste have become increasingly serious. Effectively reducing traffic accidents and achieving efficient traffic management have become urgent issues. As a key component of intelligent transportation systems, vehicular ad-hoc networks (VANETs) can collect and share traffic information, prevent accidents, improve transportation system efficiency, and provide information and entertainment services to users. Therefore, VANETs have become a research hotspot in intelligent transportation systems and have experienced rapid development.
[0003] Communication modes in VANETs include vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I). However, both V2V and V2I transmit information over public channels. In this open network environment, any node in the VANET can receive traffic information. Therefore, attackers, whether authorized or not, can easily intercept and tamper with this information, disrupting the normal operation of the entire VANET and seriously threatening the safety of users and property. Furthermore, attackers can impersonate legitimate users in the VANET and send false information to other vehicles, seriously compromising road safety. Therefore, ensuring the integrity and authenticity of vehicle communication data and protecting user privacy have become unavoidable issues.
[0004] To address the above issues, researchers have proposed various signature-based authentication schemes, including public key infrastructure-based schemes, identity-based schemes, and certificateless schemes. In systems based on public key infrastructure, there are challenges with certificate management, communication overhead, and computational overhead. Identity-based schemes rely on a centralized private key generation center to generate users' private keys, which leads to serious privacy deficiencies and key management issues. To this end, researchers have proposed many certificateless aggregate signature authentication schemes. However, existing schemes are either unable to resist threats from different adversaries, or have extremely low computational and communication efficiency, which cannot meet the needs of resource-constrained VANETs environments, and even fall into a vicious cycle of attack and defense iteration. Therefore, there is an urgent need to design an efficient and secure certificateless aggregate signature authentication scheme. Summary of the Invention
[0005] The present invention provides a certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network, which is used to overcome at least one technical problem existing in the prior art.
[0006] The present invention provides a certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network, comprising:
[0007] Generate public parameters using a key generation center and a trust institution, and publish the public parameters;
[0008] Generate a secret value x based on the public parameter i ;
[0009] Generate a pseudonymous PID for the vehicle using the Trust Center i ;
[0010] Based on the public parameters and the pseudonym, a key generation center generates a partial private key of the vehicle;
[0011] Based on the public parameters, the vehicle's partial private key and the pseudonym, a key pair for the vehicle is generated, the key pair for the vehicle including the vehicle's private key sk i and the vehicle's public key pk i ;
[0012] Based on the vehicle's key pair and pseudonym, the message m i Generate signature σ i =u i +h 3,i (x i +y i ), and send the signature to the roadside unit; where u i A random number chosen for the vehicle, h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ), where H3 is part of the public parameters, U i is a random value, t i is the current timestamp; y i Part of a partial private key;
[0013] Check whether the signature is valid. If not, reject the signature and the process ends; otherwise, accept the signature.
[0014] Generate an aggregate signature based on the n signatures received And send it to the application server; Among them, H4 is part of the public parameters, A pub Indicates the public key of the application server;
[0015] Verify the aggregate signature σagg Is it valid? If not, the aggregate signature is rejected and the program ends; otherwise, the aggregate signature is accepted.
[0016] Optionally, a key generation center and a trust authority are used to generate public parameters, specifically:
[0017] Given a security parameter λ, generate a q-order additive group P is the group A generator of , q is a large prime number;
[0018] The key generation center selects a random value As the private key, and calculate the public key K pub =αP;
[0019] The trusted authority selects a random value As the private key, and calculate the public key T pub =βP;
[0020] Choose four different hash functions H1, H2, H3, H4:
[0021] Generate public parameters
[0022] Optionally, a secret value is generated based on the public parameter, specifically:
[0023] The vehicle selects a random value As its secret value, and calculate X i =x i P.
[0024] Optionally, a trust center is used to generate a pseudonym for the vehicle, specifically:
[0025] Get the vehicle's real identity (RID) i ;
[0026] The vehicle selects a random number Calculate U i =u i P, and through the secure channel {X i ,U i ,RID i}Send to trusted authority;
[0027] The trust agency sets the vehicle's pseudonym as PID i ={AID i ,T i},in, T i Indicates that the trusted authority is PID i Selected validity period;
[0028] {PID i ,X i}Sent to the key generation center.
[0029] Optionally, generate a partial private key for the vehicle, specifically:
[0030] The key generation center selects a random number And calculate R i =r i P;
[0031] The key generation center calculates y i =(r i +αh 2,i ), where h 2,i =H2(PID i ,X i ,R i ,K pub ), change psk i =(y i ,R i ) as part of the vehicle's private key, and {PID i ,psk i ,R i}Sent to the vehicle.
[0032] Optionally, generate a key pair for the vehicle, specifically:
[0033] Vehicle calculation h 2,i =H2(PID i ,X i ,R i ,K pub );
[0034] Vehicle Verification Is it true? If not, it means psk i and PID i If it is illegal, the program ends; if it is established, it means psk i and PID i legitimate;
[0035] Calculate Y i =y i P, and set the vehicle's public key to pk i =X i +Y i , the vehicle private key is set to sk i =(x i ,y i ).
[0036] Optionally, for message m i Generate a signature, specifically:
[0037] The vehicle obtains the current timestamp t i , and according to the received message m i Calculate h 3,i =H3(PID i ,pk i ,U i ,m i ,t i );
[0038] Vehicle calculation signature σ i =u i +h 3,i (x i +y i ), and the signed message {PID i ,pk i ,U i ,m i ,t i ,σ i}Sent to the roadside unit.
[0039] Optionally, the roadside unit is used to check whether the signature is valid, specifically:
[0040] Roadside unit inspection timestamp T i and t i Is it valid? If not, the RSU rejects the signature σ i ; If so, calculate h 3,i =H3(PID i ,pk i ,U i ,m i ,t i );
[0041] Roadside unit verification formula σ i P=U i +h 3,i pk i Is it true? If so, the signature is valid; otherwise, the signature is invalid.
[0042] Optionally, it also includes:
[0043] Roadside units will and σ agg Sent to the application server.
[0044] Optionally, verify the aggregate signature σ agg Whether it is effective, specifically:
[0045] Application Server Verification T i and t i Is the signature valid? If not, the application server rejects the aggregate signature σagg ; If valid, the application server calculates h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ),Ω i =U i +h 3,i pk i , where i = 1,…,n;
[0046] Verify the equation Is it true? If so, it means the aggregate signature σ agg Valid; if not, it means the aggregate signature σ agg invalid.
[0047] The innovative features of the embodiments of the present invention include:
[0048] (1) In this embodiment, an elliptic encryption curve is used. Compared with the bilinear pairing scheme, the computational efficiency is higher and the communication overhead can be significantly reduced. This is one of the innovations of the embodiment of the present invention.
[0049] (2) In this embodiment, in order to resist Type III attacks, the present invention proposes a new aggregation algorithm. In this aggregation algorithm, an aggregate signature can be generated only when all signatures are valid. That is, as long as there is an invalid signature, it cannot be aggregated into a valid aggregate signature. Therefore, this scheme can significantly improve security and is one of the innovations of the embodiment of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0051] Figure 1 This is the framework diagram of the vehicle-mounted self-organizing network system;
[0052] Figure 2 A flow chart of a certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network provided by an embodiment of the present invention;
[0053] Figure 3 A flow chart for generating common parameters provided by an embodiment of the present invention;
[0054] Figure 4 A flow chart for generating pseudonyms according to an embodiment of the present invention;
[0055] Figure 5 A flow chart of generating a vehicle key pair provided by an embodiment of the present invention;
[0056] Figure 6 A flow chart for checking whether a signature is valid provided by an embodiment of the present invention;
[0057] Figure 7 A flowchart of checking whether a signature is valid is provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0058] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without creative work are within the scope of protection of the present invention.
[0059] It should be noted that the terms "including," "having," and any variations thereof in the embodiments of the present invention and the accompanying drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to the process, method, product, or apparatus.
[0060] The embodiments of the present invention disclose a certificateless aggregate signature authentication method and system for a vehicle-mounted ad hoc network, which are described in detail below.
[0061] Figure 1 This is the framework diagram of the vehicle-mounted self-organizing network system. Figure 2 For a flow chart of a certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network provided by an embodiment of the present invention, please refer to Figure 1 and Figure 2 The embodiment of the present invention provides a certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network, including:
[0062] Step 1: Generate public parameters using the key generation center and the trust institution, and publish the public parameters;
[0063] Step 2: Generate a secret value x based on the public parameter i ;
[0064] Step 3: Generate a pseudonymous PID for the vehicle using the Trust Center i ;
[0065] Step 4: Based on the public parameters and pseudonym, the key generation center generates the vehicle's partial private key;
[0066] Step 5: Generate the vehicle's key pair based on the public parameters, the vehicle's partial private key and the pseudonym. The vehicle's key pair includes the vehicle's private key sk i and the vehicle's public key pk i ;
[0067] Step 6: Based on the vehicle’s key pair and pseudonym, i Generate signature σ i =u i +h 3,i (x i +y i ), and send the signature to the roadside unit; where u i A random number chosen for the vehicle, h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ), where H3 is part of the public parameters, U i is a random value, t i is the current timestamp; y i Part of a partial private key;
[0068] Step 7: Check whether the signature is valid. If not, reject the signature and the process ends; otherwise, accept the signature.
[0069] Step 8: Generate an aggregate signature based on the n signatures received And send it to the application server; Among them, H4 is part of the public parameters, A pub Indicates the public key of the application server;
[0070] Step 9: Verify the aggregate signature σ agg Is it valid? If not, the aggregate signature is rejected and the program ends; otherwise, the aggregate signature is accepted.
[0071] Specifically, please refer to Figure 1 ,VANETs system generally consists of five entities, namely, the key generation center KGC, the trust authority TA, the application server AS, the roadside unit RSU and the vehicle equipped with the on-board unit.
[0072] KGC, as a trusted third party, is responsible for generating some of the vehicle's private keys and possesses sufficient computing and storage capabilities. TA, like KGC, is also a trusted third-party organization responsible for system initialization, RSU, and vehicle registration. To achieve conditional privacy protection, TA generates pseudonyms for vehicles and only discloses the vehicle's true identity when necessary. AS connects to RSUs via a secure channel, receives and verifies traffic-related information from them, and also provides services such as traffic rescue, navigation, and entertainment. RSUs are distributed on both sides of the road and communicate with surrounding vehicles and verify traffic information received from them. Vehicles equipped with OBUs collect traffic data, including speed, location, and traffic conditions, process this information, and then broadcast it.
[0073] The certificateless aggregate signature authentication scheme usually consists of an underlying certificateless signature scheme and an aggregation algorithm. Please refer to Figure 2 The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network provided by an embodiment of the present invention first generates public parameters using a key generation center and a trust institution in step 1, and publishes the public parameters.
[0074] Figure 3 For a flow chart of generating common parameters provided by an embodiment of the present invention, please refer to Figure 3 When generating public parameters, first, through step 11, the security parameter λ is given and a q-order additive group is generated. P is the group A generator of , q is a large prime number. In step 12, a random value is selected by the key generation center As the private key, and use the selected private key to calculate the public key K pub =αP. In step 13, a random value is selected by the trusted authority As the private key, and use the selected private key to calculate the public key T pub =βP. In step 14, four different hash functions H1, H2, H3, H4 are selected: In step 15, the public parameters are generated based on the above group, the public key of the key generation center, the public key of the trust institution and the hash function.
[0075] After obtaining the public parameters, in step 2, the vehicle will select a random value based on the public parameters. As its secret value, and based on the secret value, calculate X i =x i P.
[0076] To achieve conditional privacy protection, in step 3, the trust center generates a pseudonymous PID for the vehicle. i . Figure 4For a flowchart of generating pseudonyms according to an embodiment of the present invention, please refer to Figure 4 In this embodiment, when generating a pseudonym, it is necessary to first obtain the vehicle's real identity RID through step 31 i After obtaining the vehicle's true identity, in step 32, the vehicle will select a random number And calculate the random number U by the selected random number i =u i P, and then {X i ,U i ,RID i} is sent to the trust institution. In step 33, the trust institution sends the pseudonym PID i Select a valid time period T i , and according to U i 、T i etc., calculate At the same time, set the vehicle's pseudonym as PID i ={AID i ,T i After obtaining the pseudonym of the vehicle, go to step 34 and convert {PID i ,X i}Sent to the key generation center.
[0077] In step 4, the key generation center generates a partial private key for the vehicle based on the received public parameters and pseudonym. When generating the private key, the key generation center first selects a random number And according to the random number r i Calculate R i =r i P. The key generation center also uses the random number r i and α to calculate y i =(r i +αh 2,i ), where h 2,i =H2(PID i ,X i ,R i ,K pub ), set the vehicle's partial private key to psk i =(y i ,R i ). At the same time, in order for the vehicle to generate a key pair, {PID i ,psk i ,R i}Sent to the vehicle.
[0078] After the vehicle receives the above message, it can generate the vehicle key pair in step 5 based on the received public parameters, part of the vehicle's private key and pseudonym, where the vehicle key pair includes the vehicle's private key ski and the vehicle's public key pk i .
[0079] Figure 5 For a flow chart of generating a vehicle key pair provided by an embodiment of the present invention, please refer to Figure 5 In this embodiment, when generating a key pair for a vehicle, the vehicle first calculates h according to the received data in step 51. 2,i =H2(PID i ,X i ,R i ,K pub ). Get h 2,i Then, in step 52, the equation y is verified by the vehicle i P=R i +K pub h 2,i and Is it true? If not, it means psk i and PID i If it is illegal, the program ends; otherwise, if it is established, it means psk i and PID i Legal. When psk i and PID i If it is legal, then Y can be calculated through step 53. i =y i P, and set the vehicle's public key to pk i =X i +Y i , the vehicle private key is set to sk i =(x i ,y i ).
[0080] After obtaining the vehicle's key pair, in step 6, the vehicle first obtains the current timestamp t i , and according to the received message m i Calculate h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ). Get h 3,i After that, the signature σ can be calculated based on the received vehicle public and private keys i =u i +h 3,i (x i +y i ), and the signed message {PID i ,pk i ,U i ,m i,t i ,σ i} is sent to the roadside unit. i A random number chosen for the vehicle, H3 is the hash function in the public parameters, U i is a random value.
[0081] To ensure the validity of the signature, the roadside unit needs to verify whether the signature is valid through step 7 after receiving the above message. Figure 6 For a flow chart of checking whether a signature is valid provided by an embodiment of the present invention, please refer to Figure 6 When checking whether the signature is valid, first in step 71, the roadside unit checks the timestamp T i and t i Is it valid? If the timestamp is invalid, the RSU rejects the signature σ i , the program ends; otherwise, if the timestamp is valid, calculate h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ). And verify the formula σ through step 72 i P=U i +h 3,i pk i Is it true? If so, it means the signature is valid and the signature is accepted; otherwise, it means the signature is invalid and the signature is rejected, and the program ends.
[0082] When the roadside unit receives n signatures, it can generate an aggregate signature based on the received n signatures in step 8. And send it to the application server. Among them, H4 is the hash function in the public parameter, A pub Indicates the public key of the application server, A pub =γP, γ is a random value selected by the application server as its own private key,
[0083] It should be noted that, in addition to sending the aggregate signature σ agg In addition, you also need to send This facilitates the application server to verify the aggregate signature in step 9.
[0084] Figure 7 For a flow chart of checking whether a signature is valid provided by an embodiment of the present invention, please refer to Figure 7 , verify the aggregate signature σ agg If it is valid, first go through step 91 to check T i and ti Is the signature valid? If not, the application server rejects the aggregate signature σ agg , the program ends; if valid, calculate h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ),Ω i =U i +h 3,i pk i , where i = 1, ..., n. And verify the equation through step 92. Is it true? If so, it means the aggregate signature σ agg If it is valid, the application server accepts the aggregate signature; if it is not valid, it means that the aggregate signature σ agg Invalid. The application server rejects the aggregate signature.
[0085] The certificateless aggregate signature authentication method for vehicular ad hoc networks, provided by this invention, utilizes elliptic cryptographic curves, offering higher computational efficiency and significantly reduced communication overhead compared to bilinear pairing schemes. Furthermore, to defend against Type III attacks, this invention proposes a new aggregation algorithm that generates an aggregate signature only when all signatures are valid. In other words, if even one invalid signature exists, a valid aggregate signature cannot be generated. This significantly improves security.
[0086] Those skilled in the art will appreciate that the accompanying drawings are merely schematic diagrams of an embodiment, and the modules or processes in the accompanying drawings are not necessarily required to implement the present invention.
[0087] Those skilled in the art will appreciate that the modules in the apparatuses of the embodiments may be distributed in the apparatuses of the embodiments as described in the embodiments, or may be located in one or more apparatuses different from the embodiments with corresponding changes. The modules in the above embodiments may be combined into one module or further divided into multiple sub-modules.
[0088] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network, characterized in that: include: Generate public parameters using a key generation center and a trust institution, and publish the public parameters; Generate a secret value x based on the public parameter i ; Generate a pseudonymous PID for the vehicle using the Trust Center i ; Based on the public parameters and the pseudonym, a key generation center generates a partial private key of the vehicle; Based on the public parameters, the vehicle's partial private key and the pseudonym, a key pair for the vehicle is generated, the key pair for the vehicle including the vehicle's private key sk i and the vehicle's public key pk i ; Based on the vehicle's key pair and pseudonym, the message m i Generate signature σ i =u i +h 3,i (x i +y i ), and send the signature to the roadside unit; where u i A random number chosen for the vehicle, h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ), where H3 is part of the public parameters, U i is a random value, t i is the current timestamp; y i is part of a partial private key; Check whether the signature is valid. If not, reject the signature and the process ends; otherwise, accept the signature. Generate an aggregate signature based on the n signatures received And send it to the application server; Among them, H4 is part of the public parameters, A pub Indicates the public key of the application server; Verify the aggregate signature σ agg Is it valid? If not, the aggregate signature is rejected and the program ends; otherwise, the aggregate signature is accepted.
2. The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network according to claim 1, characterized in that: Use the key generation center and the trust authority to generate public parameters, specifically: Given a security parameter λ, generate a q-order additive group P is the group A generator of , q is a large prime number; The key generation center selects a random value As the private key, and calculate the public key K pub =αP; The trusted authority chooses a random value As the private key, and calculate the public key T pub =βP; Choose four different hash functions H1, H2, H3, H4: Generate public parameters 3. The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network according to claim 2, characterized in that: Generate a secret value based on the public parameters, specifically: The vehicle selects a random value As its secret value, and calculate X i =x i P.
4. The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network according to claim 3, characterized in that: Use the trust center to generate a pseudonym for the vehicle, specifically: Get the vehicle's real identity (RID) i ; The vehicle selects a random number Calculate U i =u i P, and through the secure channel {X i ,U i ,RID i }Send to trusted authority; The trust agency sets the vehicle's pseudonym as PID i ={AID i ,T i }, where AID i =RID i ⊕H1(βU i ,T i ), T i Indicates that the trusted authority is PID i Selected validity period; {PID i ,X i }Sent to the key generation center.
5. The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network according to claim 4, characterized in that: Generate a partial private key for the vehicle, specifically: The key generation center selects a random number and calculate R i =r i P; The key generation center calculates y i =(r i +αh 2,i ), where h 2,i =H2(PID i ,X i ,R i ,K pub ), change psk i =(y i ,R i ) as the vehicle's partial private key, and {PID i ,psk i ,R i }Sent to the vehicle.
6. The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network according to claim 5, characterized in that: Generate the vehicle's key pair, specifically: Vehicle calculation h 2,i =H2(PID i ,X i ,R i ,K pub ); Vehicle Verification i P=R i +K pub h 2,i and RID i =AID i ⊕H1(u i T pub ,T i ) is established, if not, it means psk i and PID i If it is illegal, the procedure ends; If true, it means psk i and PID i legitimate; Calculate Y i =y i P, and set the vehicle's public key to pk i =X i +Y i , the vehicle private key is set to sk i =(x i ,y i ).
7. The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network according to claim 6, characterized in that: For message m i Generate a signature, specifically: The vehicle obtains the current timestamp t i , and according to the received message m i Calculate h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ); Vehicle calculation signature σ i =u i +h 3,i (x i +y i ), and the signed message {PID i ,pk i ,U i ,m i ,t i ,σ i }Sent to the roadside unit.
8. The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network according to claim 7, characterized in that: Use the roadside unit to check whether the signature is valid, specifically: Roadside unit inspection timestamp T i and t i Is it valid? If not, the RSU rejects the signature σ i ; If so, calculate h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ); Roadside unit verification formula σ i P=U i +h 3,i pk i Is it true? If so, the signature is valid; otherwise, the signature is invalid.
9. The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network according to claim 8, characterized in that: Also includes: Roadside units will and σ agg Sent to the application server.
10. The certificateless aggregate signature authentication method for a vehicle-mounted ad hoc network according to claim 9, characterized in that: Verify the aggregate signature σ agg Whether it is effective, specifically: Application Server Verification i and t i Is the signature valid? If not, the application server rejects the aggregate signature σ agg ; If valid, the application server calculates h 3,i =H3(PID i ,pk i ,U i ,m i ,t i ),Ω i =U i +h 3,i pk i , where i = 1,…,n; Verify the equation Is it true? If so, it means the aggregate signature σ agg Valid; if not, it means the aggregate signature σ agg invalid.