Apparatus and method for managing pseudonymous certificates

By generating a pseudonymous certificate based on root value locking and activating it with an unlocking key, combined with a tree structure and a link seed value management method with preset periodic grouping, the problems of low efficiency and privacy protection in the pseudonymous certificate management system are solved, and effective pseudonymous certificate management and vehicle location tracking protection are achieved.

CN114428976BActive Publication Date: 2025-09-16PENTA SECURITY SYST INC +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202110512472.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-10-29
Filing Date
2021-05-11
Publication Date
2025-09-16
Estimated Expiration
2041-05-11

AI Technical Summary

Technical Problem

In the existing pseudonym certificate management system, the frequent revocation and reissuance of pseudonym certificates leads to inefficiency. Even by activating the pseudonym certificate, the privacy of the vehicle cannot be effectively protected, and attackers can still track the vehicle location by linking the seed value.

Method used

By generating a pseudonymous certificate in a state locked based on a root value, using an external server to periodically provide an unlocking key to activate the pseudonymous certificate, and deactivating the pseudonymous certificate under abnormal circumstances, a tree structure is used to connect link seed values ​​and group them in preset periods, and a link chain identifier is used to identify and stop receiving the unlocking key, thereby reducing the size of the certificate revocation list.

Benefits of technology

Effectively manage pseudonymous certificates, prevent vehicle location tracking, reduce the size of certificate revocation lists, protect vehicle privacy, and avoid the inefficiency caused by frequent revocation and reissue in traditional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114428976B_ABST
    Figure CN114428976B_ABST
Patent Text Reader

Abstract

The present disclosure relates to an apparatus and method for managing pseudonym certificates. A pseudonym certificate management method, performed by a pseudonym certificate management apparatus interoperating with an external server, may include: receiving from the external server a pseudonym certificate locked based on a root value recognizable only by the external server; periodically receiving an unlocking key for the pseudonym certificate from the external server; activating the pseudonym certificate using the unlocking key; and deactivating the pseudonym certificate when the activated pseudonym certificate is abnormal.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority from Korean Patent Application No. 10-2020-0141873, filed on October 29, 2020, which is hereby incorporated by reference herein in its entirety. Technical Field

[0003] The present disclosure relates to a method and apparatus for managing pseudonym certificates, and more particularly, to a method and apparatus for managing pseudonym certificates for secure vehicle-to-vehicle (V2V) communication. Background Art

[0004] The Secure Credential Management System (SCMS) is a system for secure vehicle-to-everything (V2X) communication developed by the Collision Avoidance Metrics Partnership (CAMP) and is a system that protects privacy by issuing multiple pseudonymous certificates.

[0005] The Link Value (LV) is used in SCMS for privacy protection and efficient certificate revocation. The Link Value is the identifier (ID) of the pseudonymous certificate and can also be used as the pseudonymous ID of the vehicle. Therefore, the location of the vehicle can also be tracked through the Link Value.

[0006] At the same time, the Link Authority (LA) can assign a Link Seed (LS) value to each vehicle, extract a Pre-Link Value (PLV) from the Link Seed value, and extract a Link Value representing the ID of the pseudonym certificate from the Pre-Link Value. Furthermore, the Link Value can be periodically revoked to prevent tracking of the vehicle through the tracking of the pseudonym certificate. In this case, the Link Seed value of the Link Value is included in the Certificate Revocation List (CRL).

[0007] Based on the link seed value contained in the certificate revocation list, certificate tracking can be performed. For example, if a pseudonymous certificate is revoked at a specific time, the certificate revocation list can be used to track pseudonymous certificates that are revoked after the specific time.

[0008] At the same time, due to the limited nature of vehicle resources, pseudonym certificates can be distributed in advance. If the linkage authority issues 20 pseudonym certificates per week for 3 years in advance, 3120 pseudonym certificates are required. In addition, if a pseudonym certificate is revoked at a specific time, all pseudonym certificates after the specific time should be revoked. Therefore, inefficiency occurs because the registration authority (RA) that registers the pseudonym certificates in the SCMS should reissue 3120 pseudonym certificates again. Summary of the Invention

[0009] In order to solve the above-mentioned problem, an exemplary embodiment of the present disclosure is directed to preventing vehicle location tracking by preventing tracking of a pseudonymous name certificate.

[0010] In order to solve the above-mentioned problems, exemplary embodiments of the present disclosure are directed to providing a method for efficiently managing pseudonymous certificates.

[0011] According to an exemplary embodiment of the present disclosure for achieving the above-mentioned purpose, a pseudonym certificate management method performed by a pseudonym certificate management device that interacts with an external server may include: receiving a pseudonym certificate in a locked state based on a root value that can only be recognized by the external server from the external server; periodically receiving an unlocking key for the pseudonym certificate from the external server; activating the pseudonym certificate with the unlocking key; and deactivating the pseudonym certificate when the activated pseudonym certificate is abnormal.

[0012] The external server may include a plurality of linking mechanisms designated by the pseudonym certificate management apparatus.

[0013] A pseudonym certificate in a state locked based on a root value can be generated in the following manner: generating multiple link seed values ​​for generating an identifier (ID) of the pseudonym certificate based on root values ​​identifiable by multiple linking agencies; generating a pre-link value (PLV) encrypted based on the link seed value according to the Advanced Encryption Standard (AES); and generating multiple link values ​​representing the ID of the pseudonym certificate based on the pre-link value.

[0014] The link seed values ​​may be encrypted based on the root value and connected into a tree structure.

[0015] Link seed values ​​connected in a tree structure may be generated by being grouped according to a preset period.

[0016] The link seed values ​​within each group may be encrypted and concatenated, and the initial link seed value of each group may be represented by a link anchor seed (LAS) value generated based on the root value.

[0017] Deactivating the pseudonym certificate includes: identifying a link value of the pseudonym certificate through a link chain identifier (LCI); and stopping receiving an unlocking key based on the identified link value.

[0018] The pseudonym certificate management method may further include checking whether the pseudonym certificate has been deactivated through a certificate revocation list (CRL) issued by an external server.

[0019] According to another exemplary embodiment of the present disclosure for achieving the above-mentioned purpose, a pseudonym certificate management device that interacts with an external server may include: a processor; and a memory storing at least one instruction executable by the processor, wherein when the at least one instruction is executed by the processor, the processor performs the following operations: receiving a pseudonym certificate in a locked state based on a root value that can only be recognized by the external server from the external server; periodically receiving an unlocking key for the pseudonym certificate from the external server; activating the pseudonym certificate with the unlocking key; and deactivating the pseudonym certificate when the activated pseudonym certificate is abnormal.

[0020] The external server may include a plurality of linking mechanisms designated by the pseudonym certificate management apparatus.

[0021] A pseudonym certificate in a state locked based on a root value can be generated in the following manner: generating multiple link seed values ​​for generating an identifier (ID) of the pseudonym certificate based on root values ​​identifiable by multiple linking agencies; generating a pre-link value (PLV) encrypted based on the link seed value according to the Advanced Encryption Standard (AES); and generating multiple link values ​​representing the ID of the pseudonym certificate based on the pre-link value.

[0022] The link seed values ​​may be encrypted based on the root value and connected into a tree structure.

[0023] Link seed values ​​connected in a tree structure may be generated by being grouped according to a preset period.

[0024] The link seed values ​​within each group may be encrypted and concatenated, and the initial link seed value of each group may be represented by a link anchor seed (LAS) value generated based on the root value.

[0025] When deactivating the pseudonym certificate, the at least one instruction may further cause the processor to: identify a link value of the pseudonym certificate through a link chain identifier (LCI); and stop receiving the unlocking key according to the identified link value.

[0026] At least one instruction may further cause the processor to check whether the pseudonym certificate has been deactivated through a certificate revocation list (CRL) issued by an external server.

[0027] According to an exemplary embodiment of the present disclosure, the size of a pseudonym certificate revocation list can be reduced. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1A is a first exemplary diagram for describing a typical pseudonym certificate.

[0029] Figure 1B is a second exemplary diagram for describing a typical pseudonym certificate.

[0030] Figure 2A is a first exemplary diagram for describing a conventional method of tracking a pseudonymous certificate.

[0031] Figure 2B is a second exemplary diagram for describing a conventional method of tracking a pseudonymous certificate.

[0032] Figure 3 is an exemplary diagram for describing a conventional method of revoking a pseudonym certificate.

[0033] Figure 4 is an exemplary diagram for describing a method of activating a pseudonym certificate.

[0034] Figure 5A is a first exemplary diagram for describing the privacy issues caused by activating a pseudonym certificate.

[0035] Figure 5B is a second exemplary diagram for describing privacy issues caused by activating a pseudonym certificate.

[0036] Figure 6 is a flowchart illustrating a pseudonym certificate management method according to an exemplary embodiment of the present disclosure.

[0037] Figure 7 FIG. 1 is a first exemplary diagram of a pseudonym certificate management method according to an exemplary embodiment of the present disclosure.

[0038] Figure 8 FIG. 2 is a second exemplary diagram of a pseudonym certificate management method according to an exemplary embodiment of the present disclosure.

[0039] Figure 9 is a first exemplary diagram for describing privacy issues that may occur by restoring a revoked certificate according to the present disclosure.

[0040] Figure 10 is a second exemplary diagram for describing privacy issues that may occur by restoring a revoked certificate according to the present disclosure.

[0041] Figure 11 is a third exemplary diagram for describing privacy issues that may occur by restoring a revoked certificate according to the present disclosure.

[0042] Figure 12 is a block diagram of a pseudonym certificate management apparatus according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION

[0043] Embodiments of the present disclosure are disclosed herein. However, for the purpose of describing the embodiments of the present disclosure, the specific structural and functional details disclosed herein are merely representative. Therefore, the embodiments of the present disclosure can be embodied in many alternative forms and should not be construed as being limited to the embodiments of the present disclosure set forth herein.

[0044] Therefore, although the present disclosure is susceptible to various modifications and alternative forms, specific embodiments of the present disclosure are shown by way of example in the drawings and will be described in detail herein. However, it should be understood that there is no intention to limit the present disclosure to the particular forms disclosed, but on the contrary, the present disclosure is intended to cover all modifications, equivalents, and alternative forms that fall within the spirit and scope of the present disclosure. Throughout the description of the drawings, like reference numerals refer to like elements.

[0045] It will be understood that, although the terms first, second, etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element without departing from the scope of this disclosure. As used herein, the term "and / or" includes any and all combinations of one or more associated listed items.

[0046] It will be understood that when an element is referred to as being "connected" or "coupled" to another element, it can be directly connected or coupled to the other element, or intervening elements may be present. In contrast, when an element is referred to as being "directly connected" or "directly coupled" to another element, there are no intervening elements. Other words used to describe the relationship between elements (i.e., "between" versus "directly between," "adjacent" versus "directly adjacent," etc.) should be interpreted in a similar manner.

[0047] The terms used herein are for the purpose of describing specific embodiments only and are not intended to limit the present disclosure. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used herein, specify the presence of the stated features, integers, steps, operations, elements, and / or parts, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, parts, and / or groups thereof.

[0048] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present disclosure belongs. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art, and should not be interpreted in an idealized or overly formal sense unless expressly defined herein.

[0049] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings.

[0050] Figure 1A is a first exemplary diagram for describing a typical pseudonym certificate, and Figure 1B is a second exemplary diagram for describing a typical pseudonym certificate.

[0051] like Figure 1A and Figure 1B As shown, a typical pseudonym certificate may have an ID, which may be represented as a link value as described below. That is, a typical pseudonym certificate may be represented by ID(i, j), where i is the validity period of the pseudonym certificate and j is the serial number of the pseudonym certificate.

[0052] For example, if Figure 1A Certificate set 1 is a set of pseudonym certificates for a specific vehicle in the first week of June 2020. The first week of June is the validity period of the pseudonym certificates, and 1 to 19 are the serial numbers of the pseudonym certificates reissued after being revoked in the first week of June 2020. Therefore, the pseudonym certificates in certificate set 1 can be represented as ID (1, 1) and ID (1, 19).

[0053] In addition, referring to 1B, an attacker who wants to track the location of a specific vehicle through a pseudonym certificate can collect the pseudonym certificates of the specific vehicle. However, since the identifiers of the pseudonym certificates are different, the relationship between the pseudonym certificates cannot be identified. Therefore, the vehicles can be identified as different vehicles, and thus the vehicles cannot be tracked. For example, a specific vehicle may move in the order of positions 1 to 4, and an attacker can collect the pseudonym certificates of the specific vehicle (i.e., ID(3,1), ID(3,18), ID(3,4), and ID(3,12)). In this case, since the individual pseudonym certificate IDs are different, the specific vehicle can be identified as a different vehicle and cannot be tracked.

[0054] Figure 2A is a first exemplary diagram for describing a conventional method of tracking a pseudonymous certificate, and Figure 2B is a second exemplary diagram for describing a conventional method of tracking a pseudonymous certificate.

[0055] As mentioned above, a typical pseudonym certificate can be revoked and reissued. A pseudonym certificate revocation list (CRL) exists to check whether a specific pseudonym certificate has been revoked to prevent vehicle location tracking. At the same time, the certificate revocation list may include a link seed (LS) for identifying the ID of the revoked pseudonym certificate.

[0056] For example, refer to Figure 2B , a typical pseudonym certificate may include a link seed (LS) value, a pre-link value (PLV), and a link value (LV), and an identifier ID(i, j) of the pseudonym certificate may be expressed as a link value LV(i, j).

[0057] In this case, the link value LV(i,j) can be extracted by Equations 1 to 3.

[0058] [Formula 1]

[0059] LV(i,j)=PLV1(i,j)XOR PLV2(i,j)

[0060] [Formula 2]

[0061] PLV(i,j)=GeneratePLV(LS(i),j)

[0062] [Formula 3]

[0063] LS(i+1)=hash(LS(i))

[0064] The initial value LS(0) of the link seed can have any value.

[0065] Meanwhile, as described above, the pseudonym certificate revocation list may include a link seed value. Since the link value corresponding to the ID of the revoked pseudonym certificate can be obtained through the link seed value, the revoked pseudonym certificate can be tracked through the pseudonym certificate revocation list. For example, referring to Figure 2A and 2B , when the pseudonym certificate is revoked at i=5, the certificate revocation list may include LS(5), and since all pseudonym certificates have a connected structure, the pseudonym certificate from LS(5) may be traced.

[0066] Figure 3 is an exemplary diagram for describing a conventional method of revoking a pseudonym certificate.

[0067] Reference Figure 3Traditionally, pseudonym certificates have been repeatedly revoked and reissued. For example, if a linking authority issues 20 pseudonym certificates per week for three years in advance, 3,120 pseudonym certificates are required. In addition, if a pseudonym certificate is revoked at a specific time, all pseudonym certificates after that time should also be revoked. Consequently, there is an inefficiency problem because the registration authority (RA) that registers pseudonym certificates in the SCMS should reissue 3,120 pseudonym certificates again.

[0068] Figure 4 is an exemplary diagram for describing a method of activating a pseudonym certificate.

[0069] Reference Figure 4 As described above, a method for solving the problem caused by reissuing a pseudonym certificate in a registration authority can be seen. For example, there is a method that assigns a pseudonym certificate to a vehicle that is locked by a locking key, and distributes an unlocking key to the vehicle to activate the pseudonym certificate. In this case, the pseudonym certificate can be reused in the following manner: by stopping the provision of the unlocking key distributed to the vehicle instead of revoking the pseudonym certificate, and by redistributing the unlocking key to the vehicle instead of reissuing the pseudonym certificate to activate the pseudonym certificate. Therefore, the problem caused by the revocation or reissuance of the pseudonym certificate does not occur.

[0070] Figure 5A is a first exemplary diagram for describing the privacy issues caused by activating a pseudonymous certificate, and Figure 5B is a second exemplary diagram for describing privacy issues caused by activating a pseudonym certificate.

[0071] As described above, using lock and unlock keys instead of revoking or reissuing pseudonym certificates can resolve the problem of unnecessary revocation or reissuance of pseudonym certificates at the linking authority and the registration authority that registered the pseudonym certificates. However, even if the distribution of the pseudonym certificate unlock key is stopped, the location of a specific vehicle can still be tracked using the link seed value included in the pseudonym certificate revocation list. This problem occurs because all link seed values ​​of the pseudonym certificates are linked.

[0072] For example, refer to Figure 5A and Figure 5B , when the distribution of the unlocking key of the pseudonym certificate stops at i=5, the attacker can extract LS(8) from LS(5) included in the pseudonym certificate revocation list, can extract PLV(8,j) from LS(8), and can extract LV(8,j) through PLV(8,j). Therefore, the attacker can track the location of a specific vehicle through the link value LV(8,j).

[0073] Since the location of the pseudonym certificate can be tracked within a specific time in the above manner, there is a problem in that the privacy of a specific vehicle cannot be protected even if the pseudonym certificate is activated in a conventional manner.

[0074] Figure 6 is a flowchart illustrating a pseudonym certificate management method according to an exemplary embodiment of the present disclosure.

[0075] Reference Figure 6 The pseudonym certificate management method according to an exemplary embodiment of the present disclosure is a pseudonym certificate management method performed by a pseudonym certificate management device that interacts with an external server, and may include a step S110 of receiving, from the external server, a pseudonym certificate in a locked state based on a root value recognizable only by the external server.

[0076] Here, the external server may include a plurality of link authorities (LAs) designated by the pseudonym certificate management apparatus.

[0077] At the same time, a pseudonym certificate in a state locked based on a root value recognizable only by an external server can be generated in the following manner: multiple link seed values ​​for generating the ID of the pseudonym certificate are generated based on the root value recognizable only by multiple link agencies, a pre-link value (PLV) encrypted based on the link seed value is generated according to the Advanced Encryption Standard (AES), and multiple link values ​​representing the pseudonym certificate ID are generated based on the pre-link value.

[0078] Here, the link seed values ​​may be encrypted based on the root value and connected in a tree structure. In addition, the link seed values ​​connected in the tree structure may be generated by being grouped according to a preset period. At the same time, the link seed values ​​generated and grouped in each group may be encrypted and connected.

[0079] In addition, the present disclosure may include step S120 of periodically receiving an unlocking key for the pseudonym certificate from an external server. Furthermore, the present disclosure may include step S130 of activating the pseudonym certificate using the unlocking key. Furthermore, the present disclosure may also include step S140 of deactivating the activated pseudonym certificate if the pseudonym certificate is abnormal.

[0080] Here, if the pseudonym certificate is abnormal, the step S140 of deactivating the activated pseudonym certificate may include the steps of identifying a link value of the pseudonym certificate through a link chain identifier (LCI); and stopping receiving an unlocking key based on the identified link value.

[0081] Meanwhile, the pseudonym certificate management method according to the exemplary embodiment of the present disclosure may further include the step of checking whether the pseudonym certificate has been deactivated through a certificate revocation list (CRL) issued by an external server.

[0082] Figure 7 is a first exemplary diagram of a pseudonym certificate management method according to an exemplary embodiment of the present disclosure, and Figure 8 FIG. 2 is a second exemplary diagram of a pseudonym certificate management method according to an exemplary embodiment of the present disclosure.

[0083] As described above, the conventional method of revoking and reissuing a pseudonym certificate or the conventional method of activating a pseudonym certificate has the following problem: the link seed values ​​are linked, so the pseudonym certificate can still be traced even when the pseudonym certificate is revoked or the distribution of the unlocking key is stopped.

[0084] According to an exemplary embodiment of the present disclosure, a link seed value can be generated based on a root value received from a linking mechanism so that the connection between pseudonym certificates can be released, unlike conventional pseudonym certificates. Figure 7 In the present disclosure, each link seed value can be generated by encrypting a root value that can only be identified by a link mechanism, and the link seed value can be generated in a tree structure based on the root value. Here, the root value can only be identified by multiple link mechanisms specified by the pseudonym certificate management device described later.

[0085] At the same time, multiple linking mechanisms can extract link seed values ​​from the root value, extract pre-link values ​​based on the link seed value, and extract each link value based on the pre-link value. That is, in order to prevent attackers from tracking vehicles through pseudonymous certificates, multiple linking mechanisms can independently extract link values ​​from the link seed value.

[0086] In addition, since the link seed value is generated from the root value and is not connected to each other, even if the pseudonym certificate is revoked, the attacker cannot track the location of the specific pseudonym certificate through the link seed value. Here, the link seed value can be calculated using Equation 4.

[0087] [Formula 4]

[0088] LS(i)=hash(Root LA ||ID LA ||i)

[0089] Here, ID LA The ID of the linking organization specified by the pseudonym certificate management apparatus to be described later may be indicated.

[0090] In addition, refer to Figure 8 In the present disclosure, link seed values ​​connected in a tree structure can be generated by being grouped according to a preset period. In this case, the preset period can be set by the pseudonym certificate management device. For example, link seed values ​​i = 0, 1, and 2 corresponding to t = 0 can be connected and grouped, and link seed values ​​i = 3, 4, and 5 corresponding to t = 1 can be connected and grouped.

[0091] Meanwhile, the initial link seed value at time t may be referred to as LAS(t), which is the Link Anchor Seed (LAS) value. Figure 8 , LAS(0) can mean LS(0,0), and can mean hash(Root LA ||ID LA ||0). In addition, LAS(10) can mean LS(1,1), and can mean hash(Root LA ||ID LA ||1).

[0092] In addition, when the link seed values ​​connected in the tree structure are grouped according to a preset period, the link seed value may be defined as in Equation 5, and the pre-link value PLV may be defined as in Equation 6.

[0093] [Formula 5]

[0094] LS(t,i+1)=hash(ID LA ‖LS(t,i))

[0095] [Formula 6]

[0096] PLV(t,i,j)=E(LS(t,i),ID LA ‖j)

[0097] Here, E may mean encryption, and in Equation 6, it may mean encrypting ID using LS(t,i) LA .

[0098] Figure 9 is a first exemplary diagram for describing privacy issues that may occur by restoring a revoked certificate according to the present disclosure, Figure 10 is a second exemplary diagram for describing privacy issues that may occur by restoring a revoked certificate according to the present disclosure, and Figure 11 is a third exemplary diagram for describing privacy issues that may occur by restoring a revoked certificate according to the present disclosure.

[0099] Reference Figure 9 , it can be seen that, compared to the case of the conventional pseudonym certificate management method, the location of a specific vehicle cannot be tracked in the exemplary embodiment of the present disclosure. For example, if the certificate is revoked at i=6, then according to the present disclosure, the specific vehicle does not receive the unlocking key corresponding to t=2, thereby making it possible to keep the pseudonym certificate corresponding to t=2 locked.

[0100] At the same time, unlike the conventional certificate management method, in the present disclosure, the connection of all linked seed values ​​included in the pseudonym certificate is released, so that all information about the time when the pseudonym certificate was revoked and restored can be included in the pseudonym certificate revocation list. For example, the certificate revocation list (CRL) can only include information about i=6,7 (including the time when the certificate was revoked) corresponding to t=1. That is, the certificate revocation list can include LS(6) and LS(7).

[0101] On the other hand, if the certificate is restored at i = 7 (i.e., if the unlocking key is distributed), the attacker can track the pseudonymous certificate from LS(6) and LS(7) included in the certificate revocation list for a period of time after i = 8. However, since LS(8) cannot be extracted unless the path value is known, the privacy of a specific vehicle can be protected.

[0102] Reference Figure 10 , when the pseudonym certificate is revoked at i=7 (the distribution of the unlocking key is stopped) and the pseudonym certificate is restored at i=10 (i.e., when the unlocking key is distributed), since the time points corresponding to them are different, the certificate revocation list may include all information corresponding to the corresponding time points. That is, the certificate revocation list may include LS(7), LS(8), LS(9), LS(10), and LS(11). In this case, the certificate revocation list may have a problem that the size of the certificate revocation list becomes larger than that of the conventional certificate management method.

[0103] However, as described above, in the present disclosure, since link seed values ​​connected in a tree structure are generated by being grouped according to a preset period, and the link seed values ​​within each group are encrypted and connected, the certificate revocation list may not include all information about the time of revoking and restoring the pseudonym certificate.

[0104] For example, refer to Figure 11 , when the pseudonym certificate is revoked at i=7 (the distribution of the unlocking key is stopped), and the pseudonym certificate is restored at i=10 (i.e., when the unlocking key is distributed), since the time points corresponding to them are different, the certificate revocation list can include all information corresponding to the corresponding time points. However, Figure 10 Unlike the case of t=2, the certificate revocation list may include only LS(7) and LS(8). That is, since the link seed values ​​in the group corresponding to t=2 are encrypted and all concatenated, and LS(11) can be calculated from LS(8), the certificate revocation list may not include LS(9), LS(10), and LS(11). Therefore, the size of the certificate revocation list can be reduced.

[0105] Meanwhile, the present disclosure may include the following steps: if the pseudonym certificate is abnormal, deactivating the activated pseudonym certificate. In this case, the step of deactivating the pseudonym certificate may include the step of identifying the link value of the pseudonym certificate through a link chain identifier (LCI) and the step of stopping receiving the unlocking key based on the identified link value.

[0106] Meanwhile, LCI can be as shown in Equation 7.

[0107] [Formula 7]

[0108] LCI=Enc(Pubkey LA ,Root LA )

[0109] Here, Pubkey LA Can refer to the public key of the linking organization, and Root LA This can refer to a root value that can be identified by the linking mechanism. Specifically, LCI can be encrypted using the public key and the root value, and the link value of a pseudonym certificate revoked by the LCI can be identified. Furthermore, the reception of the unlocking key can be stopped based on the link value identified by the LCI.

[0110] Figure 12 is a block diagram of a pseudonym certificate management apparatus according to an exemplary embodiment of the present disclosure.

[0111] like Figure 12 As shown, the pseudonym certificate management device 100 according to an exemplary embodiment of the present disclosure may include a processor 110, a memory 120 for storing at least one instruction executable by the processor and an execution result of the at least one instruction, and a transceiver 130 connected to a network for performing communication.

[0112] The pseudonym certificate management apparatus 100 may further include an input interface device 140, an output interface device 150, a storage device 160, and the like. Each component included in the pseudonym certificate management apparatus 100 may be connected to communicate with each other, such as by being connected via a bus 170. However, each component included in the pseudonym certificate management apparatus 100 may be connected to the processor 110 via a separate interface or a separate bus rather than via the common bus 170. For example, the processor 110 may be connected to at least one of the memory 120, the transceiver 130, the input interface device 140, the output interface device 150, and the storage device 160 via a dedicated interface.

[0113] The processor 110 may execute a program stored in at least one of the memory 120 and the storage device 160. The processor 110 may refer to a central processing unit (CPU), a graphics processing unit (GPU), or a dedicated processor on which the method according to the embodiment of the present disclosure is executed. Each of the memory 120 and the storage device 160 may be composed of at least one of a volatile storage medium and a non-volatile storage medium. For example, the memory 120 may include at least one of a read-only memory (ROM) and a random access memory (RAM).

[0114] The storage device 160 may also store a root value that is identifiable only by the link mechanism, an initial link seed value based on the root value, a link seed value generated based on the root value, a pre-link value, and a link value. Furthermore, the storage device 160 may store a preset period for revoking a link value and a preset period for grouping link seed values ​​connected in a tree structure.

[0115] Here, at least one instruction may cause the processor to: receive a pseudonym certificate from an external server that is in a locked state based on a root value recognizable only by the external server; and periodically receive an unlocking key for the pseudonym certificate from the external server; activate the pseudonym certificate with the unlocking key; and deactivate the pseudonym certificate when the activated pseudonym certificate is abnormal.

[0116] At the same time, a pseudonym certificate in a state locked based on a root value can be generated in the following manner: generating multiple link seed values ​​for generating an identifier (ID) of the pseudonym certificate based on root values ​​identifiable by multiple linking agencies; generating a pre-link value (PLV) encrypted based on the link seed value according to the Advanced Encryption Standard (AES); and generating multiple link values ​​representing the ID of the pseudonym certificate based on the pre-link value.

[0117] Furthermore, when deactivating the pseudonym certificate, the at least one instruction may further cause the processor to: identify a link value of the pseudonym certificate through a link chain identifier (LCI); and stop receiving the unlocking key according to the identified link value.

[0118] At the same time, the at least one instruction may further cause the processor to check whether the pseudonym certificate has been deactivated through a certificate revocation list (CRL) issued by an external server.

[0119] The operation of the method according to the exemplary embodiment of the present disclosure can be implemented as a computer-readable program or code in a computer-readable recording medium. The computer-readable recording medium may include various recording devices for storing data that can be read by a computer system. In addition, the computer-readable recording medium can store and execute a program or code, which can be distributed in a computer system connected via a network and can be read by a computer in a distributed manner.

[0120] The computer readable recording medium may include a hardware device that is specifically configured to store and execute program commands, such as ROM, RAM, or flash memory. The program commands may include not only machine language codes created by a compiler, but also high-level language codes that can be executed by a computer using an interpreter.

[0121] Although some aspects of the present disclosure have been described in the context of an apparatus, these aspects may be described in terms of a method, and a module or apparatus may correspond to a step or feature of a step of the method. Similarly, aspects described in the context of a method may be represented as corresponding modules or items or features of a corresponding apparatus. Some or all of the steps of the method may be performed by (or using) a hardware device such as a microprocessor, a programmable computer, or an electronic circuit. In some embodiments, the device may perform one or more of the most important steps of the method.

[0122] While the present disclosure has been described with reference to preferred embodiments, it will be apparent to those skilled in the art that various changes and modifications can be made therein without departing from the spirit and scope of the invention as defined in the following claims.

Claims

1. A pseudonym certificate management method, executed by a pseudonym certificate management device interacting with an external server, the pseudonym certificate management method comprising: receiving, from the external server, a pseudonym certificate in a state locked based on a root value recognizable only by the external server; periodically receiving an unlocking key for the pseudonym certificate in the locked state from the external server; activating the pseudonym certificate in the locked state using the unlocking key; as well as When the activated pseudonym certificate is abnormal, the activated pseudonym certificate will be revoked. wherein the external server includes a plurality of linking mechanisms designated by the pseudonym certificate management device, wherein the pseudonym certificate in a locked state based on the root value is generated by generating a plurality of link seed values ​​for generating an identifier ID of the pseudonym certificate based on the root values ​​identifiable by the plurality of linking mechanisms, wherein the plurality of link seed values ​​are encrypted based on the root value and connected into a tree structure, and The link seed values ​​connected in a tree structure have at least two groups grouped according to a preset period.

2. The pseudonym certificate management method according to claim 1, wherein: The pseudonym certificate in a locked state based on the root value is further configured to be generated by: Generate a pre-link value PLV encrypted based on the link seed value according to the Advanced Encryption Standard AES; and A plurality of link values ​​representing the ID of the pseudonym certificate are generated based on the pre-link value.

3. The pseudonym certificate management method according to claim 1, wherein: The link seed values ​​within each group are encrypted and concatenated, and the initial link seed value of each group is represented by a link anchor seed LAS value generated based on the root value.

4. The pseudonym certificate management method according to claim 1, wherein: Deactivating the pseudonym certificate includes: Identifying the link value of the pseudonym certificate by a link chain identifier LCI; and Receipt of the unlocking key is stopped based on the identified link value.

5. The pseudonym certificate management method according to claim 1, further comprising: Whether the pseudonym certificate has been deactivated is checked through a certificate revocation list CRL issued by the external server.

6. A pseudonym certificate management device, the pseudonym certificate management device interacting with an external server, comprising: processor; as well as a memory storing at least one instruction executable by the processor, Wherein, when the at least one instruction is executed by the processor, the processor is caused to perform the following operations: receiving, from an external server, a pseudonym certificate in a state locked based on a root value recognizable only by the external server; periodically receiving an unlocking key for the pseudonym certificate in the locked state from the external server; activating the pseudonym certificate in the locked state using the unlocking key; and When the activated pseudonym certificate is abnormal, the activated pseudonym certificate will be revoked. wherein the external server includes a plurality of linking mechanisms designated by the pseudonym certificate management device, wherein the pseudonym certificate in a locked state based on the root value is generated by generating a plurality of link seed values ​​for generating an identifier ID of the pseudonym certificate based on the root values ​​identifiable by the plurality of linking mechanisms, wherein the plurality of link seed values ​​are encrypted based on the root value and connected into a tree structure, and The link seed values ​​connected in a tree structure have at least two groups grouped according to a preset period.

7. The pseudonym certificate management device according to claim 6, wherein: The pseudonym certificate in a locked state based on the root value is further configured to be generated by: Generate a pre-link value PLV encrypted based on the link seed value according to the Advanced Encryption Standard AES; and A plurality of link values ​​representing the ID of the pseudonym certificate are generated based on the pre-link value.

8. The pseudonym certificate management device according to claim 6, wherein: The link seed values ​​within each group are encrypted and concatenated, and the initial link seed value of each group is represented by a link anchor seed LAS value generated based on the root value.

9. The pseudonym certificate management device according to claim 6, wherein: Upon deactivating the pseudonym certificate, the at least one instruction further causes the processor to: Identifying the link value of the pseudonym certificate by a link chain identifier LCI; and Receipt of the unlocking key is stopped based on the identified link value.

10. The pseudonym certificate management device according to claim 6, wherein: The at least one instruction further causes the processor to check whether the pseudonym certificate has been deactivated through a certificate revocation list (CRL) issued by the external server.

Citation Information

Patent Citations

  • Open type superfluous drying apparatus for getting high quality fruit and vegetables

    KR1020200141873A

  • Cryptographic methods and systems using blinded activation codes for digital certificate revocation

    CN111684764A

  • Device update transmission using a bloom filter

    US10666427B1