Issuing offline PKI certificates in distributed V2X networks

By introducing a distributed certificate authority into a peer-to-peer wireless communication network and using a public generation matrix to generate PKI certificates, the problem of certificate issuance when vehicles cannot access the centralized certificate issuance entity is solved, and the information security and integrity of the V2X network is achieved.

CN114503510BActive Publication Date: 2025-05-09HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080067747.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-10-18
Filing Date
2020-04-26
Publication Date
2025-05-09
Estimated Expiration
2040-04-26

Smart Images

  • Figure CN114503510B_ABST
    Figure CN114503510B_ABST
Patent Text Reader

Abstract

A method and system for issuing public key infrastructure (PKI) certificates in a peer-to-peer wireless communication network, comprising: generating a PKI certificate at a first certificate authority (CA) node in the peer-to-peer communication network based on public key information received from an application node in the peer-to-peer wireless communication network; and sending the PKI certificate generated by the first CA node to the application node using the peer-to-peer wireless communication network.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to and the benefit of U.S. Application No. 16 / 657,433, filed on October 18, 2019, entitled “Issuing Offline PKI Certificates in Distributed V2X Network,” which is incorporated herein by reference. Technical Field

[0002] The present invention relates to a system and method for issuing public key infrastructure (PKI) certificates in a distributed vehicle-to-everything (V2X) network. Background Art

[0003] Vehicle-to-everything (V2X) communications enable vehicles to communicate with surrounding entities such as other vehicles, cellular towers, access points, road infrastructure elements, smart grid elements, and pedestrians. For example, V2X communications can include: device-to-device communications, such as vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), vehicle-to-grid (V2G), and vehicle-to-pedestrian (V2P); and device-to-network (V2N) communications, such as cellular network-based C-V2X communications and wireless local area network (WLAN)-based communications. Different protocols have been or are being developed to support V2X communications, for example, the WLAN-based IEEE 802.11p protocol released in 2012, the 3rd Generation Partnership Project (3GPP)-based IEEE 802.11a protocol, the 3rd Generation Partnership Project (3GPP)-based IEEE 802.11b protocol ...a protocol, the 3rd Generation Partnership rd The V2X protocol defined as long-term evolution (LTE) V2X in 3GPP (3rd Generation Partnership Project) Release 14 and 15, and the V2X protocol developed under Release 15.

[0004] In some applications, the information provided and received by entities in the V2X network may affect the operation of traffic control systems and individual vehicle control systems, and entities such as insurance companies and governments may also rely on the information. Given the potential security, financial, legal and regulatory impact of the information exchanged in V2X networks, it is critical to maintain the integrity of the information. In this regard, V2X communications may include traditional data integrity safeguards, such as the use of public key infrastructure (PKI) certificates.

[0005] Typically, PKI certificates are issued by a centralized certificate issuing entity. In situations where the vehicle can access such a centralized certificate issuing entity online, such as through a cellular network connection, such certificates can be issued and updated using traditional protocols. However, in some cases, the vehicle may not be able to connect to the centralized certificate issuing entity, meaning that the centralized certificate issuing entity is not accessible to the vehicle when the vehicle needs a PKI certificate. This may occur, for example, if the vehicle is out of range of the cellular network, the cellular network denies vehicle access due to network capacity issues or other reasons, there is a communication interruption between the cellular network and the certificate issuing entity, or the certificate issuing entity has experienced a temporary failure or is currently unavailable for other reasons.

[0006] Therefore, a need exists for a method and system to facilitate issuing PKI certificates to entities, such as vehicles, that do not have access to a centralized certificate issuing entity when the vehicle requires one or more PKI certificates. Summary of the invention

[0007] According to a first exemplary aspect of the present invention, a method for issuing a public key infrastructure (PKI) certificate in a peer-to-peer wireless communication network is disclosed. The method comprises: generating a PKI certificate at a first certificate authority (CA) node in the peer-to-peer communication network according to public key information received from an application node in the peer-to-peer wireless communication network; and sending the PKI certificate generated by the first CA node to the application node using the peer-to-peer wireless communication network.

[0008] According to an exemplary embodiment provided in the first aspect, the application node and the first CA node are each pre-configured with a public generation matrix, the public key information includes a public signature key generated by the application node using the generation matrix, and generating the PKI certificate at the first CA node includes: generating an intermediate certificate based on a first key, wherein the first key is based on: (i) the public signature key generated by the application node; (ii) the product of the generation matrix and the random value received from the application node; signing the intermediate certificate; encrypting the signed intermediate certificate to generate the PKI certificate. In some examples, the public key information includes a public encryption key calculated by the application node using the generation matrix, and encrypting the signed intermediate certificate to generate the PKI certificate is performed using a second key, wherein the second key is based on: (i) the public encryption key; (ii) the product of the generation matrix and the random value received from the application node.

[0009] In any of the above examples of the first aspect, the method includes: receiving, at the first CA node, the first key and the second key from a registration authority (RA) node in the peer wireless communication network. In some examples, the method includes: receiving, at the first CA node, a first random value calculated at the RA node; calculating a first intermediate value based on the product of the generation matrix and the first random value; receiving a second intermediate value from a second CA node in the peer wireless communication network, the second intermediate value being calculated by the second CA node based on the product of the generation matrix and the second random value calculated at the RA node; wherein the intermediate certificate generated by the first CA node is also based on the first intermediate value and the second intermediate value.

[0010] In any of the above examples of the first aspect, the CA node calculates the first key and the second key.

[0011] In any of the above examples of the first aspect, the peer wireless communication network is a sidelink (SL) vehicle-to-anything (V2X) communication network, and the application node and the CA node are each implemented by a processor-enabled control unit located on the corresponding vehicle.

[0012] In any of the above examples of the first aspect, the first CA node is one of multiple CA nodes that jointly implement distributed CA in the peer-to-peer wireless communication network, and the method includes: generating a corresponding PKI certificate based on the public key information at the multiple CA nodes; and sending the PKI certificate to the application node using the peer-to-peer wireless communication network.

[0013] According to a second exemplary aspect of the present invention, an electronic device is disclosed, comprising: a processor system; a wireless transceiver system, the wireless transceiver system being coupled to the processor system for exchanging information with a peer-to-peer wireless communication network; a memory, the memory being coupled to the processor system. The memory stores executable instructions, which, when executed by the processor system, cause the electronic device to perform the following operations: generate a public key infrastructure (PKI) certificate based on public key information received from an application node in the peer-to-peer wireless communication network; and send the PKI certificate to the application node using the peer-to-peer wireless communication network.

[0014] In some examples of the second aspect, the public key information includes a public signature key calculated by the application node using a generation matrix, and the electronic device is used to generate the PKI certificate in the following manner: generating an intermediate certificate based on a first key, wherein the first key is based on: (i) the public signature key; (ii) the product of the generation matrix and a random value received from the application node; signing the intermediate certificate; and encrypting the signed intermediate certificate to generate the PKI certificate.

[0015] In any of the above examples of the second aspect, the public key information includes a public encryption key calculated by the application node using the generator matrix, and the electronic device encrypts the signed intermediate certificate using a second key to generate the PKI certificate, wherein the second key is based on: (i) the public encryption key; (ii) the product of the generator matrix and the random value received from the application node. In some examples, the electronic device is used to receive the first key and the second key from a registration authority (RA) node in the peer-to-peer wireless communication network.

[0016] In any of the above examples of the second aspect, the electronic device is used to: receive a first random value calculated at the RA node; calculate a first intermediate value according to the product of the generation matrix and the first random value; receive a second intermediate value from a second electronic device in the peer-to-peer wireless communication network, the second intermediate value being calculated by the second CA node according to the product of the generation matrix and the second random value calculated at the RA node. The intermediate certificate generated by the electronic device is also based on the first intermediate value and the second intermediate value.

[0017] In any of the above examples of the second aspect, the electronic device is used to calculate the first key and the second key.

[0018] In any of the above examples of the second aspect, the peer-to-peer wireless communication network is a sidelink (SL) vehicle-to-anything (V2X) communication network, and the electronic device is located on the vehicle.

[0019] According to a third exemplary aspect of the present invention, a method for obtaining a public key infrastructure (PKI) certificate is disclosed, comprising: at an application node in a peer-to-peer wireless communication network, calculating a public signature key; calculating a public encryption key; generating multiple random values; sending a request for a PKI certificate to each of a plurality of corresponding nodes in the peer-to-peer wireless communication network, wherein each request includes a copy of the public signature key, a copy of the public encryption key, and a corresponding random value among the plurality of random values; receiving and storing a plurality of certificates based on the public signature key and the private signature key and sent to the application node using the peer-to-peer wireless communication network.

[0020] In some examples of the third aspect, each node is a registration authority (RA) node in a distributed RA, and the method includes: at each RA node, calculating a first key, wherein the first key is based on: (i) the public signature key; (ii) the product of a generation matrix for generating the public signature key and the corresponding random value sent for the corresponding node; calculating a second key, wherein the second key is based on: (i) the public encryption key; (ii) the product of the generation matrix and the corresponding random value sent for the corresponding node; generating a first random value and a second random value; sending the first key, the second key and the first random value to a first associated certificate authority (CA) node in the peer wireless communication network; sending the first key, the second key and the second random value to a second associated certificate authority (CA) node in the peer wireless communication network.

[0021] In any of the above examples of the third aspect, the method includes: at each first CA node associated with the corresponding RA node, calculating a first intermediate value according to the product of the generation matrix and the first random value received from the corresponding RA node; receiving a second intermediate value from the second CA node associated with the same corresponding RA node according to the product of the generation matrix and the second random value received from the corresponding RA node; generating a PKI certificate using the first key, the second key, the first intermediate value, and the second intermediate value; and sending the PKI certificate generated by the first CA node to the application node using the peer wireless communication network. In some examples, generating the PKI certificate at each first CA node associated with the corresponding RA node includes: generating an intermediate certificate according to a combination of the first key, the first intermediate value, and the second intermediate value; signing the intermediate certificate; and encrypting the signed intermediate certificate using the second key to generate the PKI certificate.

[0022] In any of the above examples of the third aspect, the peer wireless communication network is a sidelink (SL) vehicle-to-anything (V2X) communication network, and the application node and at least some of the corresponding nodes are each implemented by a processor-enabled control unit located on the corresponding vehicle. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 is a schematic diagram of an offline PKI certificate issuance system related to an exemplary embodiment of the present invention.

[0024] Figure 2 The exemplary embodiment of the present invention provides Figure 1 A graphical representation of the offline PKI certificate issuance process for a system application.

[0025] Figure 3 yes Figure 2 Block diagram of the offline PKI certificate issuance process.

[0026] Figure 4 is a schematic diagram of an offline PKI certificate issuing system related to another exemplary embodiment of the present invention.

[0027] Figure 5 The exemplary embodiment of the present invention provides Figure 4 A graphical representation of the offline PKI certificate issuance process for a system application.

[0028] Figure 6 yes Figure 4 Block diagram of the offline PKI certificate issuance process.

[0029] Figure 7The exemplary embodiments provide a method for implementing Figure 1 or Figure 4 A block diagram of a control unit of a node in an offline PKI certificate issuance system. DETAILED DESCRIPTION

[0030] For convenience, the present invention describes exemplary embodiments of methods and systems with respect to a motor vehicle, such as an automobile, truck, bus, boat or ship, submarine, airplane, warehouse equipment, construction equipment, tractor or other farm equipment. The teachings of the present invention are not limited to any particular type of vehicle and can be applied to vehicles that do not carry passengers as well as vehicles that carry passengers. The methods and systems described in the present invention can be implemented in non-autonomous, semi-autonomous, and autonomous robotic vehicles, among others.

[0031] Figure 1 is a schematic diagram of an environment in which an offline public key infrastructure (PKI) certificate can be issued, provided by an exemplary embodiment. Figure 1 A plurality of entities are shown, including a subject vehicle 102, a plurality of other vehicles 104, and an infrastructure element 106 (e.g., a fixed pole mounted traffic camera). Each of the subject vehicle 102, the other vehicles 104, and the infrastructure element 106 includes a corresponding onboard processor enabled electronic device in the form of a control unit 115 capable of wireless communication. In an exemplary embodiment, the control unit 115 of the subject vehicle 102, the other vehicles 104, and the infrastructure element 106 is used to communicate with a remote registration and authentication system 130 via a wireless wide area network (WAN) 136 (e.g., a cellular network). For example, the control unit 115 may enable communication via the WAN 136 using one or more cellular vehicle-to-network (C-V2N) protocols. In addition, the control units 115 may also be capable of peer-to-peer communication with each other using a wireless local area network. In this regard, the control unit 115 may enable a peer-to-peer sidelink (SL) V2X communication network 140 using one or more vehicle-to-everything (V2X) protocols.

[0032] In an exemplary embodiment, in addition to the processor-enabled control unit 115, the subject vehicle 102 also includes a plurality of additional on-board processor-enabled electronic devices 110(1) to 110(n). The electronic devices 110(1) to 110(n) may include, among other things, devices or units capable of sensing, collecting, and processing information about the environment of the subject vehicle 102. For example, the on-board electronic devices 110(1) to 110(n) associated with the subject vehicle 102 may include one or more devices that sense and process information about the physical environment surrounding the vehicle, such as a light detection and ranging (LIDAR) unit, a radio detecting and ranging (RADAR) unit, and / or a camera unit. The electronic devices 110(1) to 110(n) may also include devices that collect and process information about the motion dynamics operating environment of the subject vehicle 102, such as an inertial measurement unit (IMU), a speedometer unit, and other vehicle motion dynamics measurement units. The electronic devices 110 ( 1 )- 110 ( n ) may also include devices that collect and process information regarding the geographic location of the subject vehicle 102 , such as a global positioning satellite unit.

[0033] In an exemplary embodiment, the control unit 115 of the subject vehicle 102 acts as an application node 112 that can apply a PKI certificate. When the application node 112 is online, it can communicate with one or more centralized remote systems (including the PKI system 130) via the WAN 136. In an exemplary embodiment, the PKI system 130 includes one or more computer systems (such as servers) for implementing a registration authority 132 and a PKI certificate authority 134. When the application node 112 is online, it can communicate with the registration authority 132 via the WAN 136 to perform a registration process to verify the identity of the application node 112. In an exemplary embodiment, a conventional PKI registration process can be used for this purpose. In addition, in an exemplary embodiment, each of the application nodes 112 can also perform a corresponding registration process with the registration authority 132 via the WAN 136 on behalf of the subject vehicle electronic devices 110 (1) to 110 (n).

[0034] Similarly, when application node 112 is online, it may request a digital PKI certificate for itself and electronic devices 110(1) to 110(n) from certificate authority 134. In an exemplary embodiment, a conventional PKI certificate issuance process may be used for this purpose.

[0035] However, when the application node 112 is offline relative to the PKI system 130 (e.g., when the subject vehicle 102 is located in an area not served by the WAN 136, or the application node 112 is otherwise denied access to the WAN 136 or the PKI system 130), it cannot communicate with the PKI system 130 via the WAN 136. This scheme has problems when the application node 112 is offline but needs a new PKI certificate. In this case, one or more of the control units 115 may need to ignore or suspend communications to avoid man-in-the-middle (MITM) attacks or imposter attacks.

[0036] Thus, an exemplary embodiment is described that enables a group of control units 115 of other vehicles 104 and / or infrastructure elements 106 to function together as an offline certificate issue (OCI) system 150. In the exemplary embodiment, the control unit 115 of the subject vehicle 102, the other vehicles 104, and the infrastructure elements 106 are configured by OCI software to implement respective nodes in the OCI system 150, as described below.

[0037] like Figure 1 As shown, at least some of the control units 115 in the SL V2X communication network 140 are configured by their corresponding OCI software to implement a virtual distributed registration authority (RA) 118 and a virtual distributed certificate authority (CA) 120. Specifically, a group of n+1 control units 115 are used to implement RA nodes 114(0) to 114(n), and a group of m+1 control units are used to implement CA nodes 116(0) to 116(m). In an exemplary embodiment, m≥n, and n+1 corresponds to the number of PKI certificates requested by the subject vehicle 102 (e.g., the subject vehicle 102 requires one PKI certificate for the control unit 115 and n PKI certificates for the electronic devices 110(1)-110(n) (one PKI certificate for each device). The n+1 RA nodes 114(0)-114(n) collectively implement a virtual distributed RA 118, and the m+1 CA nodes 116(0)-116(m) collectively implement a virtual distributed CA 120. In some exemplary embodiments, membership of the RA 118 and the CA 120 is randomly determined from the control unit 115 communicating with the SL V2X communication network 140. In some examples, membership of the RA 118 and the CA 120 is selected based on predetermined criteria.

[0038] Figure 2 and Figure 3Each illustrates the operation of the OCI system 150 implemented by the application node 112, the RA nodes 114(0) to 114(n), and the CA nodes 116(0) to 116(m) provided by an exemplary embodiment. Figure 2 Dashed boxes and lines are used to represent Figure 3 The operations corresponding to the process boxes identified by the same reference numerals in the flowchart of . As a prerequisite for the operation of the OCI system 150, the application node 112, the RA nodes 114(0) to 114(n) and the CA nodes 116(0) to 116(m) are each pre-configured with a public generation matrix G. As shown in box 310, the certificate issuance process begins with the application node 112 calculating key information including two pairs of public keys and private keys (U,u) and (V,v), where: U=u*G and V=v*G; U,u is a public-private encryption key pair, and V,v is a public-private signature key pair. In some examples, the private keys u,v can be based on a unique identifier associated with the controller 115, for example, the vehicle identification number of the vehicle in which the controller 115 is located. As shown in box 312, the application node 112 also generates an array of n+1 random values, r={r0,r1,…,r i ,…,r n As described above, n+1 is the number of PKI certificates that the application node 112 is requesting. In an exemplary embodiment, the random value r={r0, r1, ..., r i ,…,r n} is used to prevent fraud at RA nodes 114 ( 0 ) to 114 ( n ) and reduce man-in-the-middle (MITM) attacks in the OCI system 150 .

[0039] Then, the application node 112 sends its public key information (e.g., public encryption and signing keys U, V) and a random value array r = {r0, r1, ..., r i ,…,r n} to request n+1 PKI certificates. Specifically, Figure 3 As shown in block 314 and in Figure 2 As shown graphically in FIG. 1 , the application node 112 sends a corresponding tuple (U, V, r) to each of the n+1 RA nodes 114 (0) to 114 (n). i ) (e.g., a copy of the public encryption key and public signature key of the application node 112, and n+1 random values ​​{r0, r1, ..., r i ,…,r n In an exemplary embodiment, the application node 112 converts the array r={r0, r1, . . . , r i,…,r n} is randomly assigned to the corresponding tuples (U, V, r) sent to RA nodes 114(0) to 114(n). i ). In some examples, a gossip protocol may be used to send tuples to RA nodes 114(0) to 114(n).

[0040] As described in the following paragraphs, the distributed RA 118 is configured by its member RA nodes 114(0) to 114(n) to compute a set of n+1 certificate encryption keys {E0, E1, . . . , E i ,…,E n}, a set of n+1 public signature keys {S0,S1,…,S i ,…,S n} and a set of n+1 random value pairs {(r 00 ,r 01 ),(r 10 ,r 11 ),…,(r i0 ,r i1 ),…,(r n0 ,r n1 )} and then send them to the distributed CA 118 using the SLV2X communication network 140.

[0041] In this regard, as shown in block 316, upon receiving its corresponding tuple (U, V, r i ), each RA node 114(i) calculates the first key and the second key, namely the public signature key S i =V+r i *G and public encryption key E i =U+r i *G. As will be explained below, the first key S i The public signature key V of the application node 112, the generation matrix G and the application node source random value r i The sum of the products of and is provided to CA node 114 (k) for the intermediate certificate C' generated by OCI system 150 i Sign. Second key E i The public encryption key U of the application node 112 and the generation matrix G and the application node source random value r i and is used by CA node 114(k) to encrypt the signed intermediate certificate C" generated by OCI system 150. i .

[0042] As indicated at block 318, each RA node 114(i) also generates a corresponding random value pair (r i0 ,r i1), then, as shown in block 320, each RA node 114(i) sends the first tuple (E i ,S i ,r i0 ) is sent to the first associated CA node 116(j), and the second tuple (E i ,S i ,r i1 ) is sent to the second associated CA node 116(k), where j≠k, 0≤j≤m and 0≤k≤m. As will be explained in more detail below, the first CA node 116(j) and the second CA node 116(k) associated with the RA node 114(i) form a CA node cooperation pair for generating a unique PKI-based certificate C i Therefore, each RA node 114 (i) generates a first key S i and the second key E i The corresponding cooperating pair of CA nodes 116(j), 116(k) is sent, and a unique random value is sent to each CA node 116(j), 116(k) in the pair (e.g., r is sent to CA node 116(j)). i0 , sends r to CA node 116(k) i1 ). Random value pair (r i0 ,r i1 ) is used to mitigate fraud and man-in-the-middle (MITM) attacks in the OCI system 150. Figure 2 As shown, multiple RA nodes 114(1) to 114(n) may send tuples to the same CA node 116(i). Thus, the same CA node 116(i) may be a member of more than one CA node cooperating pair. Figure 2 In the illustration, CA node 116 (m) receives tuple (E) from RA node 114 (n). n ,S n ,r n1 ), receives the tuple (E1, S1, r ) from RA node 114 (1) 10 ). CA node 116(m) is part of a CA node cooperation pair that is associated with RA node 114(n) and includes CA node 116(m) and CA node 116(0), and CA node 116(m) is also part of another CA node cooperation pair that is associated with RA node 114(1) and includes CA nodes 116(m) and 116(1). In an exemplary embodiment, the association of the cooperation pairs of CA nodes 116(1) to 116(m) with the respective RA nodes 114(1) to 114(n) may be determined according to predetermined criteria during formation and ongoing operation of OCI system 150.

[0043] As explained in the following paragraphs, distributed CA 120 is configured by its member CA nodes 116(0) to 116(m) to generate a set of n+1 PKI certificates C = {C0, C1, ..., C i ,…,C n}, and then send them to the application node 112 using the SL V2X communication network 140.

[0044] In this regard, as shown at block 322, each CA node 116(j) is operable to calculate an intermediate value W for each random value that the CA node 116(j) receives from an associated RA node 114(i). ij =r ij *G. For illustration, Figure 2 In the example of FIG. 1 , CA node 116 ( 0 ) calculates a random value r sent by RA node 114 ( 0 ) to CA node 116 ( 0 ) 01 The median value W 01 =r 01 *G, CA node 116(0) also calculates the random value r sent by RA node 114(0) to CA node 116(0) n0 The median value W n0 =r n0 *G.

[0045] like Figure 3 As shown in blocks 324, 326 and 328 and in Figure 2 As shown graphically in FIG. 1 , each CA node 116 (j), 116 (k) associated with a public RA node 114 (i) is used to collaborate to generate an intermediate certificate C′. i , sign the intermediate certificate and sign the signature certificate C" i Encryption is performed to output a PKI-based certificate C i In some examples, collaboration between the CA nodes 116(j), 116(k) of the collaborating pair involves one of the CA nodes (eg, CA node 116(j)) calculating the intermediate value W ij The intermediate certificate C′ is sent to another CA node in the cooperative pair (eg, CA node 116(k)). Then, the receiving node (eg, CA node 116(k)) independently generates the intermediate certificate C′. i , for the intermediate certificate C' i Sign and sign the intermediate certificate C" i Perform the subsequent operations required for encryption and send the resulting signed encrypted PKI-based certificate C i In some examples, for each CA node collaboration pair, the selected CA node 116(j) or 116(k) is used to generate the intermediate certificate C' i , Signing intermediate certificate C"i CA node 116(j) or 116(k), encrypted PKI-based certificate C i The nodes selected for each CA node cooperation pair may be determined according to predetermined criteria during the formation and ongoing operation of the OCI system 150. In at least some examples, the nodes selected for each CA node cooperation pair are selected such that within the distributed CA 120, n+1 nodes of the CA nodes 116(0) to 116(m) are selected, and any one particular CA node 116(0) to 116(m) only needs to be in Figure 2 and Figure 3 A set of intermediate certificates C' is generated during an iteration of the certificate issuance process i , signed intermediate certificate C" i and PKI-based certificate C i .

[0046] In this regard, as shown in block 324, each cooperating pair of CA nodes 116(j), 116(k) associated with a common RA node 114(i) is used to jointly generate a corresponding intermediate certificate C′. i =(S i +∑W ij ,∑meta). As shown in the figure, the intermediate certificate C' i It includes two values, namely: (1) S i +∑W ij , which is the sum of: (a) the public signature key S calculated by the public associated RA node 114 (i) i (b) based on the random value r received from the public RA node 114 (i) i0 and r i1 , the intermediate values ​​W calculated by the two CA nodes 116(j) and 116(k) respectively ij and (2) ∑meta, which is the sum of a predetermined set of metadata items. In an exemplary embodiment, the metadata items include a unique identification value and a timestamp for each of the CA nodes 116(j), 116(k) of the CA node pair. As an illustration, in Figure 2 In the exemplary embodiment shown, CA node 116(j) converts the intermediate value W i0 (Based on the random value r i0 Calculated) is sent to the selected cooperating node 116 (k), which in turn calculates the first intermediate certificate C' i =(S i +∑W ij ,∑meta), where ∑W ij =W i0 +W i1 .

[0047] As shown in block 326, the selected CA node 116(k) of each cooperating pair of CA nodes 116(j), 116(k) uses its own private key h i For intermediate certificate C' i Sign to generate a signing intermediate certificate C" i =ECDSA(h i ,C' i ), ECDSA refers to the Elliptic Curve Digital Signature Algorithm, such as the ECDSA specified by the National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) publication FIPS PUB 186-4.

[0048] As indicated at block 328, the selected CA node 116(k) of each cooperating pair of CA nodes 116(j), 116(k) is then used to encrypt the data using the public encryption key E i Signing intermediate certificate C" i Encryption is performed to output an encrypted PKI-based certificate C i =AES(E i ,C” i ), wherein AES refers to the advanced encryption standard (AES) algorithm. In an exemplary embodiment, the PKI-based certificate C i It is an x.509PKI certificate. Then, based on the PKI certificate C i The CA node 116 (k) sends the certificate to the application node 112 via the SL V2X communication network 140 (block 330). Therefore, the n+1 selected CA nodes of the CA 120 jointly issue a set C of n+1 PKI-based certificates, C={C0, C1, ..., C i ,…,C n}, each selected CA node sends a corresponding certificate to the application node 112 using the SL V2X communication network 140. The application node 112 receives and stores n+1 certificates C = {C0, C1, ..., C i ,…,C n}(box 331).

[0049] When the PKI certificate issuance process is completed, n+1 certificates C = {C0, C1, ..., C i ,…,C n}, respectively for use by the application node 112 of the subject vehicle 102 and the n electronic devices 110(1) to 110(n). In an exemplary embodiment, the application node 112 may use the corresponding private key (u+r i ) For each issued certificate C i Decrypt it to recover the signing intermediate certificate C" i (Block 332). The application node uses the corresponding to the CA 120 for generating C' i The private key h i The public key H i From the signing intermediate certificate C" i Restore intermediate certificate C' i The application node 112 can calculate S i =V+r i *G determines the public signing key S for each certificate i , then from the intermediate certificate C' i Extract the middle value ∑W of the sum ij Then, the application node 112 can calculate each certificate C i Private signing key of i , as shown below: i =v+r i +∑W ij (Frame 334).

[0050] exist Figures 1 to 3 In the illustrated exemplary OCI system 150, n+1 control units 115 are used within the SL V2X communication network 140 to implement the RA nodes 114(0) to 114(n) of the distributed RA 118, and m+1 (where m≥n) other control units 115 are used within the SL V2X communication network 140 to implement the CA nodes 114(0) to 114(m) of the distributed CA 120. In some cases, it may be necessary or beneficial to implement an OCI system with fewer control units 115. In this regard, Figures 4 to 6 The architecture and operation of another OCI system 400 according to other exemplary embodiments are shown. Compared to the above-described OCI system 150, the OCI system 400 requires fewer control units 115.

[0051] exist Figure 4 In the example shown, at least some of the control units 115 in the SL V2X communication network 140 are configured by their respective OCI software to implement a set of n+1 dual-function registration authority / certificate (RA) nodes 414(0) to 414(n) within the SL communication network 140, which form a virtual distributed RA / CA. In addition, in the exemplary embodiment, n+1 corresponds to the number of PKI certificates requested by the subject vehicle 102.

[0052] Figure 5 and Figure 6 Each shows the operation of the OCI system 400 implemented by the application node 112 and the RA / CA nodes 414(0) to 114(n) according to an exemplary embodiment. As a prerequisite for the operation of the OCI system 150, the application node 112 and the RA / CA nodes 414(0) to 414(n) are each pre-configured with a public generation matrix G. As shown in box 610, the certificate issuance process begins with the application node 112 calculating key information including two pairs of public and private keys (U,u) and (V,v), where: U=u*G and V=v*G; U,u is a public-private encryption key pair, and V,v is a public-private signature key pair. As shown in box 612, the application node 112 also generates an array of n+1 random values, r={r0,r1,…,r i ,…,r n In an exemplary embodiment, the random value r={r0, r1, . . . , r i ,…,r n}Used to prevent fraud and reduce man-in-the-middle (MITM) attacks in the OCI system 400.

[0053] The application node 112 then sends its public encryption and signing keys U, V and a random value array r = {r0, r1, ..., r i ,…,r n} to request n+1 PKI certificates. Specifically, Figure 6 As shown in block 614 and in Figure 5 As shown graphically in FIG. 1 , the application node 112 sends a corresponding tuple (U, V, r) to each of the n+1 RA / CA nodes 414 (0) to 414 (n). i ) (e.g., a copy of the public encryption key and public signature key of the application node 112, and n+1 random values ​​{r0, r1, ..., r i ,…,r n In an exemplary embodiment, the application node 112 converts the array r={r0, r1, . . . , r i ,…,r n The value of} is randomly assigned to each tuple (U, V, r) sent to RA / CA nodes 414(0) to 414(n). i ). In some examples, the gossip protocol may be used to send tuples to the RA / CA nodes 414(0) to 414(n).

[0054] As shown in block 616, when the corresponding tuple (U, V, r) is received from the application node 112, i ), each RA / CA node 414(i) calculates the first key and the second key, namely the public signature key S i =V+r i *G and encryption key E i =U+r i *G, in the same manner as described above with respect to RA node 114(i).

[0055] like Figure 6 As shown in blocks 624, 626 and 628 and in Figure 5 As shown graphically in FIG. 1 , each RA / CA node 414 (i) is used to generate an intermediate certificate C′ i , sign the intermediate certificate and sign the signature certificate C" i Encryption is performed to output a PKI-based certificate C i .

[0056] Referring to block 624, each RA / CA node 414(i) is used to generate an intermediate certificate C' i =(S i ,∑meta). As shown in the figure, the intermediate certificate C' i It includes two values, namely: (1) the public signature key S calculated by RA / CA node 414(i) i ; (2) ∑meta, which is the sum of a predetermined set of metadata items. In an exemplary embodiment, the metadata items include a unique identification value and a timestamp of the RA / CA node 414 (i).

[0057] As shown in block 626, each RA / CA node 414(i) uses its own private key h i For intermediate certificate C' i Sign to generate a signing intermediate certificate C" i =ECDSA(h i ,C' i ), as described above, ECDSA refers to the Elliptic Curve Digital Signature Algorithm, such as the ECDSA specified by the National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) publication FIPS PUB 186-4.

[0058] Then, as indicated at block 628, each RA / CA node 414(i) uses the public encryption key E i Signing intermediate certificate C"i Encryption is performed to output an encrypted PKI-based certificate C i =AES(E i ,C” i ), wherein AES refers to the advanced encryption standard (AES) algorithm. In an exemplary embodiment, the PKI-based certificate C i It is an x.509PKI certificate. Then, based on the PKI certificate C i The RA / CA node 414(i) is sent to the application node 112 via the SL V2X communication network 140 (block 628). Therefore, the n+1 RA / CA nodes 414(0) to 414(n) of the RA / CA 418 jointly issue a set C of n+1 PKI-based certificates, C={C0, C1, ..., C i ,…,C n}, each RA / CA 414(0) to 414(n) sends a corresponding certificate to the application node 112 using the SL V2X communication network 140. The application node 112 receives and stores n+1 certificates C = {C0, C1, ..., C i ,…,C n}(box 631).

[0059] exist Figure 5 and 6 When the PKI certificate issuance process shown is completed, n+1 certificates C = {C0, C1, ..., C i ,…,C n}, respectively for use by the application node 112 of the subject vehicle 102 and the n electronic devices 110(1) to 110(n). In an exemplary embodiment, the application node 112 may use the corresponding private key (u+r i ) For each issued certificate C i Decrypt it to recover the signing intermediate certificate C" i (Block 632). The application node 112 can calculate S i =V+r i *G determines the public signing key S for each certificate i Then, the application node 112 can calculate each certificate C i Private signing key of i , as shown below: i =v+r i (Frame 634).

[0060] Figure 71 is a block diagram of an example of an electronic device that may be used as an onboard control unit 115 in a vehicle 102, 104 or an infrastructure element 106. As described above, according to an exemplary embodiment, the control unit 115 is used to implement an application node 112, an RA node 114(i), a CA node 116(k), and an RA / CA node 414(i). The control unit 115 may be connected to a plurality of onboard electronic devices 110(1) to 110(n), which may include devices or units capable of sensing, collecting, and processing information about the vehicle and its environment. In some examples, the control unit 115 may be connected to vehicle systems, such as a drive control system and an electromechanical system.

[0061] The control unit 115 includes a processor system 101, which is coupled to multiple components via a communication bus, and the communication bus provides a communication path between the components and the processor system 101. The processor system 101 is coupled to a memory 126, and the memory 126 may include random access memory (RAM), read only memory (ROM), and persistent (non-volatile) memory, such as flash erasable programmable read only memory (EPROM) (flash memory). The control unit 115 includes one or more wireless transceivers 131, which enable the control unit 115 to exchange data with the WAN 136 and the peer SL V2X communication network. The control unit 115 may also include a satellite receiver for receiving satellite signals from a positioning satellite network. The control unit 115 may also include one or more I / O interfaces 136, such as a touch screen and an audio input / output interface. The processor system 101 may include one or more processing units, for example, one or more central processing units (CPUs), one or more graphical processing units (GPUs), and other processing units.

[0062] The memory 126 of the control unit 115 stores software instruction sets executable by the processor system 101, which enable the control unit 115 to implement multiple systems 161. The system 161 includes an operating system 160 and an OCI communication system 172. The OCI communication system 172 enables the control unit 115 to implement one or more of the above-mentioned application node 112, RA node 114 (i), CA node 116 (k) and RA / CA node 414 (i). The system 161 may also include other modules 174, for example, a mapping module, a navigation module, an automatic and assisted driving module, a climate control module, a media player module, a telephone module and a message module.

[0063] The memory 126 also stores various data 180. For example, in the case of the application node 112, the data 180 may include a key pair U,u and V,v; a certificate C; a generator matrix G; and an array of random values ​​r.

[0064] In an exemplary embodiment, the in-vehicle electronic devices 110 ( 1 ) to 110 ( n ) may be implemented using an arrangement of electronic components similar to the control unit 115 .

[0065] The present invention is carried out with reference to the accompanying drawings, in which embodiments are shown. However, many different embodiments may be used, and therefore the description should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to make the present invention thorough and complete. The separate boxes or the separation of the functional elements of the illustrated systems, modules, and devices do not necessarily require the physical separation of these functions, because the communication between these elements can occur by means of message passing, function calls, shared memory spaces, etc. without any such physical separation. Therefore, although these functions are described separately herein for ease of explanation, these functions do not need to be implemented in physically or logically separated platforms. Different devices may have different designs, so that although some devices implement some functions in fixed-function hardware, other devices may implement these functions in a programmable processor, which has a code obtained from a machine-readable medium.

[0066] In addition, all values ​​and subranges within the disclosed range are also disclosed. In addition, although the disclosed and illustrated systems, equipment and processes herein may include a specific number of elements / components, these systems, equipment and components may be modified to include more or less such elements / components. For example, although any disclosed element / component may be a single quantity, the embodiments disclosed herein may be modified to include a plurality of such elements / components. The subject matter described herein is intended to encompass and include all suitable technical changes.

[0067] Although the present invention is at least partially described in terms of methods, it will be understood by those skilled in the art that the present invention also relates to various components for performing at least some aspects and features of the described methods, whether by hardware (DSP, GPU, ASIC or FPGA), software or a combination thereof. Therefore, the technical solution of the present invention can be embodied in a non-volatile or non-transitory machine-readable medium (e.g., an optical disk, flash memory, etc.), in which executable instructions are tangibly stored, which enable a processing device (e.g., a vehicle control system) to perform an example of the method disclosed herein.

[0068] The present invention may be embodied in other specific forms without departing from the subject matter of the claims. The exemplary embodiments described are to be considered in all respects as merely illustrative and not restrictive. The present invention is intended to encompass and include all appropriate changes in the technology. Therefore, the scope of the present invention is described by the appended claims rather than by the subject description. The scope of the claims should not be limited by the embodiments set forth in the examples, but should be given the broadest interpretation consistent with the entire description.

Claims

1. An electronic device, characterized in that: include: Processor system; a wireless transceiver system coupled to the processor system for exchanging information with a peer-to-peer wireless communication network; A memory coupled to the processor system and storing executable instructions that, when executed by the processor system, cause the electronic device to perform the following operations: generating a public key infrastructure (PKI) certificate based on public key information received from an application node in the peer-to-peer wireless communication network; sending the PKI certificate to the application node using the peer-to-peer wireless communication network; The public key information includes a public signature key calculated by the application node using a generation matrix, and the electronic device is used to generate the PKI certificate in the following manner: generating an intermediate certificate based on a first key, wherein the first key is based on: (i) the public signature key; (ii) the product of the generator matrix and a random value received from the application node; Signing the intermediate certificate; The signed intermediate certificate is encrypted to generate the PKI certificate.

2. The electronic device according to claim 1, characterized in that: The public key information includes a public encryption key calculated by the application node using the generation matrix, and the electronic device encrypts the signed intermediate certificate using a second key to generate the PKI certificate, wherein the second key is based on: (i) the public encryption key; (ii) the product of the generation matrix and the random value received from the application node.

3. The electronic device according to claim 2, characterized in that: The electronic device is used to receive the first key and the second key from a registration authority (RA) node in the peer-to-peer wireless communication network.

4. The electronic device according to claim 1 or 2, characterized in that: The electronic device is used for: receiving a first random value calculated by an RA node in the peer-to-peer wireless communication network; Calculate a first intermediate value according to the product of the generator matrix and the first random value; receiving a second intermediate value from a second electronic device within the peer-to-peer wireless communication network, the second intermediate value being calculated by the second electronic device based on a product of the generator matrix and a second random value calculated at the RA node; The intermediate certificate generated by the electronic device is also based on the first intermediate value and the second intermediate value.

5. The electronic device according to claim 2, characterized in that: The electronic device is used to calculate the first key and the second key.

6. The electronic device according to claim 1, characterized in that: The peer-to-peer wireless communication network is a sidelink (SL) vehicle-to-anything (V2X) communication network, and the electronic device is located on the vehicle.

7. A method for issuing a public key infrastructure (PKI) certificate in a peer-to-peer wireless communication network, characterized in that: include: generating a PKI certificate at a first certificate authority (CA) node in the peer-to-peer wireless communication network based on public key information received from an application node in the peer-to-peer wireless communication network; Sending the PKI certificate generated by the first CA node to the application node using the peer-to-peer wireless communication network; The application node and the first CA node are each pre-configured with a generation matrix, the public key information includes a public signature key generated by the application node using the generation matrix, and generating the PKI certificate at the first CA node includes: generating an intermediate certificate according to a first key, wherein the first key is based on: (i) the public signature key generated by the application node; (ii) the product of the generator matrix and a random value received from the application node; Signing the intermediate certificate; The signed intermediate certificate is encrypted to generate the PKI certificate.

8. The method according to claim 7, characterized in that The public key information includes a public encryption key calculated by the application node using the generation matrix, and encryption of the signed intermediate certificate to generate the PKI certificate is performed using a second key, wherein the second key is based on: (i) the public encryption key; (ii) the product of the generation matrix and the random value received from the application node.

9. The method according to claim 8, characterized in that include: The first CA node receives the first key and the second key from a registration authority (RA) node in the peer-to-peer wireless communication network.

10. The method according to claim 7 or 8, characterized in that: include: At the first CA node, Receiving a first random value calculated at the RA node; Calculate a first intermediate value according to the product of the generator matrix and the first random value; receiving a second intermediate value from a second CA node within the peer-to-peer wireless communication network, the second intermediate value being calculated by the second CA node based on a product of the generator matrix and a second random value calculated at the RA node; The intermediate certificate generated by the first CA node is also based on the first intermediate value and the second intermediate value.

11. The method according to claim 8, characterized in that The first CA node calculates the first key and the second key.

12. The method according to claim 7, characterized in that: The peer-to-peer wireless communication network is a sidelink (SL) vehicle-to-anything (V2X) communication network; The application node and the CA node are each implemented by a processor-enabled control unit located on a corresponding vehicle.

13. The method according to claim 7, characterized in that The first CA node is one of a plurality of CA nodes that jointly implement distributed CA in the peer-to-peer wireless communication network, and the method includes: Generate corresponding PKI certificates according to the public key information at the multiple CA nodes; The PKI certificate is sent to the application node using the peer-to-peer wireless communication network.

14. A method for obtaining a public key infrastructure (PKI) certificate, characterized in that: The method comprises: An application node in a peer-to-peer wireless communication network, Calculate the public signature key; Calculate a public encryption key; Generate multiple random values; sending a request for a PKI certificate for each of a plurality of corresponding nodes in the peer-to-peer wireless communication network, wherein each request includes a copy of the public signing key, a copy of the public encryption key, and a corresponding random value of the plurality of random values; A plurality of certificates based on the public signing key and the private signing key and transmitted to the application node using the peer-to-peer wireless communication network are received and stored.

15. The method according to claim 14, characterized in that The corresponding node is a distributed registration authority (RA) node, and the method comprises: At each RA node, Calculating a first key, wherein the first key is based on: (i) the public signature key; (ii) a product of a generator matrix used to generate the public signature key and the corresponding random value sent for the corresponding node; Calculating a second key, wherein the second key is based on: (i) the public encryption key; (ii) the product of the generator matrix and the corresponding random value sent for the corresponding node; generating a first random value and a second random value; sending the first key, the second key, and the first random value to a first associated certificate authority (CA) node in the peer-to-peer wireless communication network; The first key, the second key, and the second random value are sent to a second associated certificate authority (CA) node in the peer-to-peer wireless communication network.

16. The method according to claim 15, characterized in that include: At each first CA node associated with a corresponding RA node, calculating a first intermediate value based on a product of the generator matrix and the first random value received from the corresponding RA node; receiving a second intermediate value from the second CA node associated with the same corresponding RA node based on a product of the generator matrix and the second random value received from the corresponding RA node; generating a PKI certificate using the first key, the second key, the first intermediate value, and the second intermediate value; The PKI certificate generated by the first CA node is sent to the application node using the peer-to-peer wireless communication network.

17. The method according to claim 16, characterized in that Generating the PKI certificate at each first CA node associated with the corresponding RA node includes: generating an intermediate certificate based on a combination of the first key, the first intermediate value, and the second intermediate value; Signing the intermediate certificate; The signed intermediate certificate is encrypted using the second key to generate the PKI certificate.

18. The method according to claim 14, characterized in that The peer-to-peer wireless communication network is a sidelink (SL) vehicle-to-anything (V2X) communication network, and the application nodes and at least some of the corresponding nodes are each implemented by a processor-enabled control unit located on a corresponding vehicle.

Citation Information

Patent Citations

  • Cryptographic methods and systems using blinded activation codes for digital certificate revocation

    US20190245703A1