A Secure Communication Method for Anonymity and Resistance to Key Leakage in the Internet of Vehicles

By introducing authentication vectors and self-verified public and private key pairs into the Internet of Vehicles, the problems of vehicle identity anonymity, unlinkability and traceability in the Internet of Vehicles are solved, and safe and efficient inter-vehicle communication is achieved.

CN116321139BActive Publication Date: 2025-05-27XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310085829.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-06
Publication Date
2025-05-27
Estimated Expiration
2043-02-06

AI Technical Summary

Technical Problem

In the Internet of Vehicles, the prior art is difficult to achieve the identity anonymity, unlinkability and traceability of vehicles at the same time, thus unable to effectively ensure safe communication between vehicles.

Method used

By setting up an index library of vehicle identity, shared key and pseudonym in the trusted authorization center TA, the authentication vector is calculated based on the identity, shared key and unique timestamp when the vehicle enters the RSU jurisdiction, and two-way authentication between the vehicle, RSU and TA is realized. At the same time, the vehicle calculates the shared keys of both parties based on pseudonyms and self-verified public and private key pairs, and ensures secure communication within the group through the group key negotiation step.

Benefits of technology

The identity anonymity, unlinkability and traceability of the vehicle are realized, safe communication between vehicles is ensured, all requirements in conditional anonymity are met, and computing and communication efficiency is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116321139B_ABST
    Figure CN116321139B_ABST
Patent Text Reader

Abstract

The present invention discloses a secure communication method for anonymous anti-key leakage in a vehicle networking, which includes: a vehicle calculates an authentication vector based on an identity, a shared key and a unique timestamp, so that the vehicle, the RSU and the TA perform interactions based on the authentication vector and the unique timestamp to achieve mutual authentication; when the TA authenticates the vehicle successfully, it generates a pseudonym for the vehicle, and when the RSU authenticates the vehicle successfully, it generates a self-verifying public-private key pair and sends it to the vehicle; the vehicle calculates a shared key with other vehicles based on the self-verifying public-private key pair and the self-verifying public keys of other vehicles, encrypts a first random number and broadcasts the encryption result, and at the same time decrypts the encryption results of other vehicles to obtain the first random numbers of other vehicles, and calculates a group key according to the first random numbers of each vehicle in the vehicle group; the vehicle group performs secure communication based on the group key. The present invention simultaneously realizes identity anonymity, unlinkability and traceability in the vehicle networking, and realizes secure communication in the vehicle networking.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of vehicle networking, and particularly relates to a secure communication method for anonymous anti-key leakage in vehicle networking. Background Art

[0002] When communicating in vehicle networking, providing anonymity for vehicles is an important security requirement. Among them, conditional anonymity is the strongest form of anonymity, which includes three aspects: (1) Anonymity, the identity of the vehicle is only known to the vehicle itself and the authorized entity TA (Trusted Authorization Center), and any third party other than this cannot obtain the true identity of the vehicle; (2) Unlinkability, the attacker cannot determine the message sender by analyzing multiple intercepted messages; (3) Traceability, TA can determine the true identity of the vehicle by analyzing the messages sent by anonymous vehicles.

[0003] In the prior art, Han Mou et al. from Jiangsu University proposed a design method for an in-vehicle group negotiation communication protocol, which mainly includes the following content:

[0004] (i) System initialization:

[0005] TA randomly selects parameters to define its own public and private key pairs, and defines a hash function and a secure symmetric cryptographic algorithm, and then publishes the system parameters to the RSU and vehicles.

[0006] (ii) Two-way authentication between vehicle and roadside unit RSU:

[0007] The roadside unit regularly broadcasts message Meg1, and Meg1 contains signature information, which includes the public key and location information of the RSU; the vehicle receives Meg1 broadcast by the RSU, and verifies the signature and location information of the RSU; after the vehicle completes the authentication of the RSU, it sends message Meg2, which contains the public key of the vehicle, symmetric key parameters, timestamp, vehicle pseudonym, and an authentication code generated by the symmetric key; after the RSU receives Meg2, it verifies the timestamp and authentication code to complete the authentication of the vehicle. If the authentication fails, it sends Meg3 to the vehicle; the vehicle receives Meg3, generates a message authentication code HMAC(·), and sends it to the RSU through Meg4; the RSU receives Meg4 and verifies the message authentication code to complete the authentication of the vehicle.

[0008] (iii) Group key negotiation and update:

[0009] The vehicle selects a random number, calculates the corresponding value, and sends Pag1 to the RSU; the RSU receives Pag1, calculates the group key GK, sends Pag2 to the vehicle, and broadcasts Pag3 to other vehicles in the group at the same time; subsequently, the RSU executes the group key transfer mechanism, that is, the RSU signs and encrypts GK and sends the encrypted message to the nearby RSU in a wired manner; the vehicle receives Pag2 and obtains the group key; when a vehicle exits the group, it is necessary to prevent communication between the exiting vehicle and the vehicles in the group, so the group key needs to be updated; specifically, when the RSU detects through hardware that a certain user has left the group, it randomly selects parameters and sends Bm1 to the group members; the group members use the old group key to decrypt Bm1 to obtain the new group key.

[0010] (iv) Vehicle-to-vehicle communication:

[0011] The vehicle sends the message Wod1 to the RSU to request vehicle-to-vehicle communication; the RSU decrypts the message Wod1 using the group key, calculates the message authentication code, and broadcasts the message Wod2; the vehicle calculates the shared key, calculates the message wod3, and sends it to another vehicle; the vehicle obtains the messages Wod2 and Wod3, authenticates the vehicle, and obtains the communication key, so as to perform vehicle-to-vehicle one-to-one communication based on the communication key.

[0012] However, in the scheme of Jiangsu University, the vehicle anonymity depends on the pseudonyms used by the vehicles, and the TA cannot learn the real identities of the vehicles. Therefore, this scheme does not meet the requirements of anonymity and traceability in conditional anonymity.

[0013] Zhou Yousheng et al. from Chongqing University of Posts and Telecommunications proposed an anonymous authentication scheme against key leakage for the Internet of Vehicles, including the following:

[0014] (i) System initialization:

[0015] The TA publishes system parameters, including bilinear pairing, generator, hash function group, etc.

[0016] (ii) Public and private key generation

[0017] The TA, service provider, and vehicle each generate their own public and private keys.

[0018] (iii) Vehicle registration:

[0019] The vehicle calculates π = g c using the random number c, and then sends (ID obu , π) to the TA, where ID obu is the identity of the vehicle; the TA calculates and then saves (v obu , ID obu ); where SK msk is the private key of the TA.

[0020] (iv) Real - time key update:

[0021] In each time period \(i\), the vehicle calculates and calculates where \(T\) i is the timestamp, \(SK\) obu is the private key of the vehicle, \(PK\) pub is the public key of the TA, \(PK\) obu is the public key of the vehicle, \(H\) 1 (), \(H\) 2 () are the hash functions published by the TA; in each time period \(i\), the vehicle generates a random number \(r\) i , calculates and the private key \(\theta\) i at this time, where \(\theta\) i =\(\beta\) i + \(r\) i , \(H\) 3 () is the hash function published by the TA; then the vehicle calculates the pseudo - random identity parameter \(Q\) id =\(H\) 4 (ID obu ), parameter \(S\) i =\(g\) ρ , parameter \(J\) i =\(H\) 5 (PID obu , \(S\) i , \(i\)) and parameter and saves \(PID\) obu and \(TSK=(S\) i , \(I\) i ); where \(g\) is the preset base number, \(\rho\) is an arbitrary random number, \(H()\), \(H\) 4 (), \(H\) 5 () are the hash functions published by the TA, and \(e()\) represents the encryption algorithm.

[0022] (v) Vehicle requests service:

[0023] The vehicle uses the random number \(k\) i to calculate \(F = H\) 6 (ID obu , \(M\) i , \(U\)), \(W = H\) 7 (\(\varepsilon\), \(S\) i ) \(\oplus M\) i , \(Dpse = ID\) obu \(\oplus H\) 8 (\(\varepsilon\), \(S\) i ). Then the vehicle sends the message Send a request for service M to the service provider i ; where PK sp is the public key of the service provider, and H 6 (), H 7 (), H 8 () are hash functions announced by the TA

[0024] (vi) Verification request:

[0025] After receiving the service request sent by the vehicle, the service provider calculates and F' = H 6 (ID' obu , M' i , U), where SK sp is the private key of the service provider. Finally, the service provider verifies the equation whether it holds, where is the intermediate ciphertext. If the equation holds, the verification passes, and M' i is the service requested by the vehicle. If the equation does not hold, the verification fails, and the service for this request is refused

[0026] However, in the solution of Chongqing University of Posts and Telecommunications, the service provider must obtain the real identity of the user in order to pass the authentication of the user, that is, in addition to the TA, the service provider can also reveal the real identity of the user. Therefore, this solution does not meet the requirements of anonymity in conditional anonymity. In addition, although this solution realizes the mutual authentication between the service provider and the vehicle, it does not solve the problem of secure communication. The vehicle can only request services from the service provider and obtain feedback. No session key is established between the vehicle and the service provider, and the communication content between the two is public

[0027] In summary, how to simultaneously achieve identity anonymity, unlinkability, and traceability in the vehicle network, so as to achieve secure communication in the vehicle network, is an urgent technical problem in the field of vehicle network Summary of the Invention

[0028] In order to solve the above problems existing in the prior art, the present invention provides a secure communication method for anonymous anti-key leakage in a vehicle network

[0029] The technical problems to be solved by the present invention are realized through the following technical solutions

[0030] A secure communication method for anonymous anti-key leakage in a vehicle network, the vehicle network includes a trusted authorization center TA, a roadside unit RSU, and a vehicle; the TA has an index library of the identity, shared key, and pseudonym of the vehicle locally; the secure communication method includes

[0031] Authentication steps: When a vehicle enters the jurisdiction area of an RSU, the vehicle calculates an authentication vector through a hashing operation based on its identity, a shared secret key, and a unique timestamp, enabling the vehicle, the RSU, and the TA to interact based on the authentication vector and the unique timestamp to achieve mutual authentication; among them, when the TA authenticates the vehicle successfully, the TA generates a pseudonym for the vehicle and forwards it to the vehicle through the RSU, and when the RSU authenticates the vehicle successfully, the RSU generates a self-verifying public-private key pair corresponding to the vehicle's pseudonym and sends it to the vehicle;

[0032] Group key negotiation steps: Vehicles within the jurisdiction area calculate a shared key based on the self-verifying public-private key pair corresponding to their pseudonyms and the self-verifying public keys corresponding to the pseudonyms of other vehicles, encrypt a first random number using this key, and broadcast the encrypted result; the vehicle decrypts the encrypted result sent by each other vehicle using the key shared with that other vehicle to obtain the first random number used by that other vehicle; the vehicle calculates the group key based on the first random numbers of the vehicle group within the jurisdiction area;

[0033] Intra-group communication steps: The vehicle group within the jurisdiction area conducts secure communication based on the group key.

[0034] Optionally, the TA grants the RSU that accesses the network a symmetric key and a public-private key pair, and grants the vehicle that accesses the network a symmetric key as the vehicle's shared key;

[0035] The interaction among the vehicle, the RSU, and the TA based on the authentication vector and the unique timestamp to achieve mutual authentication includes:

[0036] The vehicle generates a first random parameter, and then sends the first random parameter, the authentication vector, and the unique timestamp to the RSU, so that the RSU forwards the authentication vector and the unique timestamp to the TA and saves the first random parameter for future use;

[0037] When the TA receives the authentication vector and the unique timestamp forwarded by the RSU, the TA searches the index library for the identity and symmetric key of the vehicle that can reconstruct the authentication vector; when found, the TA authenticates the vehicle successfully, generates a pseudonym for the vehicle, and then encrypts the generated pseudonym, the reconstructed authentication vector, and the unique timestamp using the RSU's symmetric key to form an encrypted message and sends it to the RSU;

[0038] After the RSU receives the encrypted information, the RSU decrypts the encrypted information using its own symmetric key. If the decryption is successful, the TA authentication passes, and at the same time, the vehicle to which the unique timestamp obtained by decryption belongs passes the authentication; moreover, the RSU generates a self-verifying public-private key pair corresponding to the pseudonym of the vehicle that passes the authentication, and sends the pseudonym of the vehicle, the self-verifying public-private key pair corresponding to the pseudonym, the unique timestamp obtained by decryption, the authentication vector, and the public key of the RSU itself to the vehicle through a message.

[0039] After the vehicle receives the message, it authenticates the TA and the RSU according to the authentication vector and the unique timestamp therein.

[0040] Optionally, the vehicle calculates the shared key between both parties based on the self-verifying public-private key pair corresponding to its pseudonym and the self-verifying public keys corresponding to the pseudonyms of other vehicles, including:

[0041] The vehicle broadcasts its negotiation message and receives the negotiation messages broadcast by other vehicles; the negotiation message includes the pseudonym of the vehicle, the self-verifying public key, and the second random parameter generated by the vehicle.

[0042] The vehicle calculates the shared key between both parties based on the self-verifying public-private key pair corresponding to its pseudonym and the self-verifying public keys corresponding to the pseudonyms of other vehicles, using the formula to calculate the shared key between both parties.

[0043] where h 1 = H 1 (PVID i ||PVID j ||PK i ||PK j ||A i ||A j ), h 0 = H 1 (PVID j ||PK j ), h 2 = H 1 (PVID j ||PVID i ||PK j ||PK i ||A j ||A i ), || represents character concatenation, sk i is the self-verifying private key corresponding to the pseudonym of vehicle i, PVID i is the pseudonym of vehicle i, PVID j is the pseudonym of other vehicle j, PK i is the self-verifying public key corresponding to the pseudonym of vehicle i, PK j is the self-verifying public key corresponding to the pseudonym of other vehicle j. is the public key of roadside unit k, A i = a i P is the second random parameter broadcast by vehicle i, A j = a j P is the second random parameter broadcast by vehicle j, a i is the second random number selected by vehicle i, a j is the second random number selected by other vehicle j, P is the elliptic curve group <g>generator of, <g>Consists of all points on the elliptic curve E / F defined over the finite field F p and an infinite point O; H and H P are different hash functions; E / F 1 , H, H P , the finite field F 1 , the characteristic p of the finite field F p and the public key of TA are all included in the system parameters broadcast by TA; k ij is the shared key calculated by vehicle i for both itself and vehicle j.

[0044] Optionally, the RSU generates a self - verifying public - private key pair corresponding to the pseudonym for the authenticated vehicle, and sends the vehicle's pseudonym, the self - verifying public - private key pair corresponding to the pseudonym, the decrypted authentication vector and the unique timestamp, as well as the RSU's own public key to the vehicle through a message, including:

[0045] The RSU selects a third random number k i to calculate K i = k i P, and calculates PK i = R i + K i as the self - verifying public key corresponding to the pseudonym of vehicle i; where R i = r i P is the first random parameter of vehicle i, and r i is the fourth random number selected by vehicle i;

[0046] The RSU calculates as the partial private key of the self - verifying private key corresponding to the pseudonym of vehicle i; is the private key of the roadside unit k;

[0047] The RSU sends the vehicle's pseudonym, self - verifying public key, partial private key, decrypted authentication vector and unique timestamp, as well as the RSU's own public key to the vehicle in the form of a message through a public channel, so that vehicle i calculates sk = sk′ i + r i as its own complete self - verifying private key after the verification equation i holds.

[0048] Optionally, when the vehicle calculates the shared key between both parties based on the self - verifying public - private key pair corresponding to its pseudonym and the self - verifying public keys corresponding to the pseudonyms of other vehicles, the two parties authenticate each other.

[0049] Optionally, the method further includes:

[0050] When a new vehicle joins the vehicle group via the authentication step, trigger the re - execution of the group key negotiation step.

[0051] Optionally, the method further includes:

[0052] When a vehicle leaves the jurisdiction area, the remaining vehicles re - select the first random number, and recalculate the group key according to the sub - step of encrypting the first random number with the key and broadcasting the encrypted result and subsequent sub - steps in the group key negotiation step.

[0053] Optionally, the method further includes:

[0054] When a vehicle is revoked by the TA, the remaining vehicles re - select the first random number, and recalculate the group key according to the sub - step of encrypting the first random number with the key and broadcasting the encrypted result and subsequent sub - steps in the group key negotiation step.

[0055] Optionally, calculating the group key according to the first random numbers of each vehicle group in the jurisdiction area includes:

[0056] gk = H(b 1 + b 2 +…b i +…+ b N );

[0057] Wherein, H is the hash function included in the system parameters broadcast by the TA, b 1 ~b N are respectively the first random numbers of each vehicle in the vehicle group, and gk is the calculated group key.

[0058] Optionally, when a vehicle receives the message, authenticating the TA and the RSU according to the authentication vector and the unique timestamp therein includes:

[0059] When a vehicle receives the message, verify the correctness of the authentication vector therein and whether the unique timestamp therein is consistent with the timestamp sent by itself to the RSU; when the verification result of the authentication vector is correct, pass the authentication of the TA; when the unique timestamp in the message is consistent with the timestamp sent by itself to the RSU, pass the authentication of the RSU.

[0060] The secure communication method for anonymous anti - key leakage in the vehicle - to - everything network provided by the present invention has the following beneficial effects:

[0061] (1) Only the TA knows the identity of the vehicle, and the RSU cannot obtain the real identity of the vehicle; moreover, the vehicle uses the pseudonym assigned by the TA during the communication with other vehicles, and other vehicles cannot obtain its identity either, achieving perfect anonymous protection. Therefore, the present invention meets the requirements regarding anonymity in conditional anonymity.

[0062] (2) Whenever a vehicle enters the jurisdiction area of an RSU, it will obtain a new pseudonym and the corresponding self-verifying public-private key pair. That is, the vehicle uses different identity information in the jurisdiction areas of different RSUs. Therefore, an attacker cannot determine the message sender by analyzing multiple intercepted messages. Thus, the present invention meets the requirements of unlinkability in conditional anonymity.

[0063] (3) The TA has an index library of the vehicle identities and shared keys locally, that is, the TA has the ability to reveal the true identity of the vehicle. Therefore, the present invention meets the requirements of traceability in conditional anonymity.

[0064] (4) The vehicle, RSU, and TA interact based on the authentication vector and the unique timestamp to achieve mutual authentication among them, so that each party can ensure that the communication partner is secure and trustworthy.

[0065] (5) The vehicles within the jurisdiction area calculate the shared keys between each other based on the pseudonyms and the self-verifying public-private keys corresponding to the pseudonyms, and further calculate the group key based on the pairwise shared keys. Thus, secure communication is carried out based on the group key, ensuring pairwise secure communication within the group and secure communication within the entire group.

[0066] (6) The present invention uses a self-verifying public key system to implement a self-verifying cryptographic scheme on the elliptic curve group, improving the computing and communication efficiency, and being more suitable for the vehicle networking with rapid vehicle handovers.

[0067] In summary, the present invention simultaneously realizes identity anonymity, unlinkability, and traceability in the vehicle networking, and realizes secure communication in the vehicle networking.

[0068] The following will further elaborate on the present invention in conjunction with the accompanying drawings. Description of the Drawings

[0069] Figure 1 is a schematic diagram of the vehicle networking;

[0070] Figure 2 is a schematic diagram of the TA processing the network access applications of vehicles and RSUs in an embodiment of the present invention;

[0071] Figure 3 is a schematic diagram of the TA broadcasting system parameters in an embodiment of the present invention;

[0072] Figure 4 is a flowchart of a secure communication method for anonymous anti-key leakage in a vehicle networking provided by an embodiment of the present invention;

[0073] Figure 5 is an interactive schematic diagram when the vehicle, RSU, and TA authenticate each other in an embodiment of the present invention;

[0074] Figure 6 It is another form of interaction schematic diagram when the vehicle, RSU, and TA authenticate each other in the embodiments of the present invention;

[0075] Figure 7 It is a schematic diagram of the group key negotiation step in the embodiments of the present invention. Detailed implementation manners

[0076] The present invention will be further described in detail below in conjunction with specific embodiments, but the implementation manners of the present invention are not limited thereto.

[0077] In order to simultaneously achieve identity anonymity, unlinkability, and traceability in the vehicle network, and thus realize secure communication in the vehicle network, the embodiments of the present invention provide a secure communication method for anonymous anti-key leakage in the vehicle network.

[0078] See Figure 1 As shown, the vehicle network includes a trusted authorization center (TA), roadside units (RSUs), and vehicles. Among them, see Figure 2 As shown, the TA processes the network access applications of vehicles and RSUs, and grants the vehicles that access the network a shared key VK i , and grants the RSUs that access the network (with the identity RID k ) a symmetric key RK k and a public-private key pair i is the number of the vehicle, and k is the number of the RSU. The TA has an index library of the vehicle's identity VID i , shared key VK i and pseudonym PVID i locally, so as to reveal the true identity of the vehicle. In addition, as Figure 3 shown, the TA also broadcasts the system parameters paras to the entire network, and specific examples of which parameters are included will be given later.

[0079] See Figure 4 As shown, the secure communication method for anonymous anti-key leakage in the vehicle network provided by the embodiments of the present invention includes the following steps:

[0080] Authentication step S10: When a vehicle enters the jurisdiction area of a certain RSU, the vehicle calculates an authentication vector through a hash operation based on its identity, shared key, and unique timestamp, so that the vehicle, the RSU, and the TA interact based on the authentication vector and the unique timestamp to achieve mutual authentication; among them, when the TA authenticates the vehicle successfully, the TA generates a pseudonym for the vehicle and forwards it to the vehicle through the RSU, and when the RSU authenticates the vehicle successfully, the RSU generates a self-verifying public-private key pair corresponding to the vehicle's pseudonym and sends it to the vehicle.

[0081] It is understandable that when a vehicle enters the jurisdiction area of a certain RSU, it needs to register for network access at this RSU to join the network under the jurisdiction of this RSU.

[0082] In this authentication step, the formula for the vehicle to calculate the authentication vector through hash operation based on the identity, shared key, and unique timestamp is: AV i = H(VID i ||VK i ||TS 1 ); where VK i is the shared key of vehicle i, TS 1 is the unique timestamp, VID i is the identity of vehicle i, || represents character concatenation, H is the hash function included in the system parameters broadcast by TA, and AV i is the authentication vector calculated by vehicle i.

[0083] See Figure 5 and Figure 6 As shown, in this authentication step, the vehicle, RSU, and TA interact based on the authentication vector and unique timestamp to achieve mutual authentication, including the following sub-steps:

[0084] (1) The vehicle generates the first random parameter R i , and then sends the first random parameter R i , authentication vector AV i and unique timestamp TS 1 to the RSU, so that the RSU forwards the authentication vector AV i and unique timestamp TS 1 to the TA and saves the first random parameter R i for future use.

[0085] (2) When the TA receives the authentication vector AV i and unique timestamp TS 1 forwarded by the RSU, the TA searches the index library for the identity and symmetric key of the vehicle that can reconstruct the authentication vector AV i ; when found, the TA passes the vehicle authentication, generates a pseudonym PVID i for the vehicle, and then uses the symmetric key RK k of the RSU to encrypt the generated pseudonym, reconstructed authentication vector AV i ' = H(VID i ||PVID i ||VK i ||TS 1 ) and unique timestamp TS 1 to form the encrypted information Send it to the RSU. Among them, TA generates a pseudonym PVID for the vehicle i After that, the pseudonym can be stored in the index library, and it is associated with the vehicle's identity VID i and the shared key VK i Stored together.

[0086] (3) When the RSU receives the encrypted information, the RSU decrypts the encrypted information using its own symmetric key. If the decryption is successful, the TA authentication passes, and at the same time, the vehicle to which the unique timestamp TS 1 belongs passes the authentication; moreover, the RSU generates the pseudonym PVID i corresponding self-verifying public-private key pair KEY for the vehicle that passes the authentication, and sends the vehicle's pseudonym PVID i , the self-verifying public-private key pair KEY corresponding to the pseudonym, the unique timestamp TS 1 decrypted, and the authentication vector AV i ', as well as the RSU's own public key PK RSUk to the vehicle.

[0087] (4) When the vehicle receives the message, it authenticates the TA and the RSU according to the authentication vector AV i ' and the unique timestamp TS 1 in it.

[0088] Specifically, when the vehicle receives the message, it verifies the correctness of the authentication vector in it and whether the unique timestamp in it is consistent with the timestamp it sent to the RSU; when the verification result of the authentication vector is correct, the TA authentication passes; when the unique timestamp in the message is consistent with the timestamp it sent to the RSU, the RSU authentication passes.

[0089] Among them, in step (3), the RSU generates the pseudonym of the vehicle that passes the authentication and the self-verifying public-private key pair corresponding to the pseudonym, and sends the vehicle's pseudonym, the self-verifying public-private key pair corresponding to the pseudonym, the decrypted authentication vector and unique timestamp, as well as the RSU's own public key to the vehicle, including:

[0090] (a) The RSU selects a third random number k i Calculate K i =k i P, and calculate PK i =R i +K i as the self-verifying public key corresponding to the vehicle's pseudonym; where R i =r i P is the first random parameter sent by the vehicle to the RSU and saved by the RSU during the authentication step, and r i generates R i The fourth random number selected at that time; P is an elliptic curve group <g>generator of <g>Consists of all the points on the elliptic curve E / F defined over the finite field F p and an infinite point O; P

[0091] (b) RSU calculation Calculate the partial private key corresponding to the pseudonym of the vehicle as the self-verifying private key; where is the private key of the roadside unit (RSU) k; H is the hash function included in the system parameters broadcast by the TA;

[0092] (c) The RSU sends the pseudonym of the vehicle, the self-verifying public key, the partial private key, the decrypted authentication vector and the unique timestamp, as well as its own public key to the vehicle through a common channel in the form of a message, so that the vehicle calculates sk after the verification equation i = sk′ i + r i as its complete self-verifying private key.

[0093] Then, the vehicle securely stores (PVID i , sk i , PK i ), and takes (sk i , PK i ) as the self-verifying public-private key pair corresponding to its pseudonym PVID i . Figure 5 In KEY = (sk′ i , PK i ) of

[0094] The inventors have tried to use the identity-based public key system / certificateless public key system to implement the method of the embodiments of the present invention, and found that in the certificateless public key system, a secure channel must be shared between the RSU and the vehicle to establish a certificateless public / private key pair for the vehicle, and the form of the certificateless public / private key pair is complex, resulting in a relatively high computational complexity of the group key. In the identity-based public key system, in order to securely transfer the identity-based private key of the vehicle to the vehicle, the roadside unit must establish a secure channel with the vehicle. Therefore, the vehicle needs to register a public-private key pair at the TA, that is, the vehicle needs to inform the TA of its private key; during the two-way authentication process between the RSU and the vehicle, the TA needs to transfer the public key of the vehicle to the RSU, and the RSU uses this public key to encrypt the identity-based private key of the vehicle, so as to send the identity-based private key of the vehicle to the vehicle. The security overhead of the solutions under these two public key systems is relatively high, which does not meet the requirements of high efficiency.

[0095] ​In the embodiments of the present invention, a self - verifying public - key system is used. The self - verifying public - key system does not require a public - key certificate, reducing the additional overhead brought by the transmission, verification, and management of public - key certificates in the public - key system based on certificates. Therefore, the embodiments of the present invention have lower computational complexity, lower computational rate, and higher communication efficiency. Moreover, the self - verifying private key of the vehicle is only known to the user of the vehicle itself, eliminating the problem of key escrow inherent in the identity - based public - key system. When transmitting keys between the RSU and the vehicle, there is no need to establish a secure channel between the roadside unit and the vehicle, and a public channel can be used.

[0096] In this authentication step, a two - way authentication between the vehicle and the RSU is achieved with the help of the TA, ensuring that all parties communicate in a trusted network. Since the roadside unit trusts the TA, when the TA authenticates the vehicle, the roadside unit also authenticates the vehicle. The TA encrypts the reconstructed authentication vector and the unique timestamp with the symmetric key of the RSU; after receiving the encrypted information, the RSU decrypts the encrypted information successfully with its own symmetric key to complete the authentication of the TA. The RSU further sends the unique timestamp and the authentication vector to the vehicle, which is equivalent to informing the vehicle of the authentication result of the TA for the RSU and the authentication result of the RSU for the TA; correspondingly, the vehicle can also authenticate the TA according to the received unique timestamp and authentication vector. Thus, the embodiments of the present invention solve the problem in the prior art that the method for establishing a secure association between the RSU and the vehicle is not clear, resulting in doubts about the authentication between the vehicle and the RSU based on this authentication step.

[0097] Group key negotiation step S20: Vehicles within the jurisdiction calculate the shared key between each other based on the self - verifying public - private key pair corresponding to their pseudonyms and the self - verifying public keys corresponding to the pseudonyms of other vehicles, encrypt the first random number with this key and broadcast the encryption result; use the key shared with each other vehicle to decrypt the encryption result sent by this other vehicle to obtain the first random number used by this other vehicle; calculate the group key according to the first random numbers of the vehicle group within the jurisdiction.

[0098] Among them, the embodiments of the present invention implement a scheme for calculating keys based on self - verifying public - private key pairs on an elliptic - curve group. Compared with the prior art where bilinear pairs are widely used to implement cryptographic schemes, the computational and communication efficiency in the embodiments of the present invention is relatively low, and it is more suitable for the vehicle - to - everything network with rapid vehicle handover.

[0099] Specifically, as shown in Figure 7 In this group key negotiation step, when a vehicle calculates the shared key between each other based on the self - verifying public - private key pair corresponding to its pseudonym and the self - verifying public keys corresponding to the pseudonyms of other vehicles, it includes:

[0100] (1) The vehicle broadcasts its negotiation message and receives the negotiation messages broadcast by other vehicles; the negotiation message includes the vehicle's pseudonym PVID i Self-verifying public key PK i and the second random parameter A generated by the vehicle i ;

[0101] (2) The vehicle calculates the shared key between the two parties based on the self-verifying public and private key pair corresponding to its pseudonym and the self-verifying public keys corresponding to the pseudonyms of other vehicles, using the formula to calculate the shared key between the two parties.

[0102] where h 1 = H 1 (PVID i ||PVID j ||PK i ||PK j ||A i ||A j ), h 0 = H 1 (PVID j ||PK j ), h 2 = H 1 (PVID j ||PVID i ||PK j ||PK i ||A j ||A i ), || represents character concatenation, sk i is the self-verifying private key corresponding to the pseudonym of vehicle i, PVID i is the pseudonym of vehicle i, PVID j is the pseudonym of other vehicle j, PK i is the self-verifying public key corresponding to the pseudonym of vehicle i, PK j is the self-verifying public key corresponding to the pseudonym of other vehicle j, is the public key of roadside unit k, A i = a i P is the second random parameter broadcast by vehicle i, A j = a j P is the second random parameter broadcast by vehicle j, a i is the second random number selected by vehicle i, a j is the second random number selected by other vehicle j, P is the elliptic curve group <g>generator of, <g>Consists of all points on the elliptic curve \(E / F\) defined over the finite field \(F\) p and an infinite point \(O\); \(H\) and \(H'\) P are different hash functions; \(E / F\), \(H\), \(H'\), 1 the characteristic \(p\) of the finite field \(F\) and the public key of TA are all included in the system parameters broadcast by TA; \(k\) P is the shared key calculated by vehicle \(i\) for both itself and vehicle \(j\). 1 The characteristic \(p\) of the finite field \(F\) p and the public key of TA are all included in the system parameters broadcast by TA; \(k\) ij is the shared key calculated by vehicle \(i\) for both itself and vehicle \(j\).

[0103] Continuing to refer to Figure 7 as shown, after vehicle \(i\) calculates the shared key with other vehicle \(j\), vehicle \(i\) selects a random number \(b\) i , encrypts the first random number using the calculated key to obtain the encryption result Broadcasts to all vehicles in the group. At the same time, vehicle \(i\) will receive the encryption results broadcast by other vehicles. Vehicle \(i\) decrypts the encryption results broadcast by these vehicles using the keys shared with these vehicles respectively, so as to obtain the first random numbers \(b\) j selected by other vehicles, and then calculates the group key \(gk = H(b\) 1 + \(b\) 2 + … + \(b\) i + … + \(b\) N + … + \(b\) 1 ~ \(b\) N ij

[0104] It should be noted that when a vehicle calculates the shared key between itself and other vehicles based on its self-verifying public and private key pairs corresponding to its pseudonym and the self-verifying public keys corresponding to the pseudonyms of other vehicles, the two parties authenticate each other. This is because only the vehicle with the correct self-verifying private key can calculate the key \(k\) ij , so in this group key negotiation step, implicit authentication between vehicles in the group is also achieved.

[0105] It is worth mentioning that most of the existing technologies rely on RSU to distribute the group key, which is called an incomplete key distribution scheme, with low efficiency and unable to meet the secure communication requirements between vehicles. For example, in the scheme of Jiangsu University mentioned in the background technology, the distribution of the session key is carried out through the roadside unit, the security overhead of the roadside unit is large, and there are problems with the authentication between the roadside unit and the vehicle.

[0106] Group communication step S30: The vehicle group within the jurisdiction conducts secure communication based on the group key.

[0107] In addition, when a new vehicle joins the vehicle group via the authentication step, the above-mentioned group key negotiation step is triggered to execute again.

[0108] Specifically, assume that the newly added vehicle is the (N + 1)-th user. The newly added vehicle broadcasts (PVID N+1 , PK N+1 , A N+1 ) to the group, and other vehicles send (PVID i , PK i , A i ) to this vehicle. This vehicle calculates the shared key k N+1,i with other vehicles, (1 ≤ i ≤ N). All vehicles reselect the first random number b i , encrypt the first random number using the key shared with other vehicles and broadcast the encryption result. At the same time, decrypt the first random numbers of other vehicles, and then calculate the new group key gk = H(b 1 + b 2 + … b N + b N+1 ).

[0109] Thus, it can be ensured that the vehicle newly joining the group cannot obtain the group key before its joining.

[0110] When a vehicle leaves the jurisdiction area of the current RSU, the remaining vehicles reselect the first random number and recalculate the group key according to the sub-step of "encrypting the first random number using this key and broadcasting the encryption result" and subsequent sub-steps in the group key negotiation step. Thus, it can prevent the vehicle that exits the group from continuing to decrypt the messages in the original group.

[0111] It can be understood that when multiple vehicles exit the jurisdiction area of the RSU simultaneously, it is also the remaining vehicles that reselect the first random number and then recalculate the group key.

[0112] Similarly, when a vehicle is revoked by the TA, the remaining vehicles reselect the first random number and recalculate the group key according to the sub-step of "encrypting the first random number using this key and broadcasting the encryption result" and subsequent sub-steps in the group key negotiation step.

[0113] Specifically, when a vehicle within the jurisdiction of the RSU publishes illegal information, it is necessary to revoke the legal user identity of this vehicle. At this time, the RSU requests the TA to revoke the user identity. The TA revokes the user identity and notifies all RSUs in the network. Each RSU conveys the revocation of this vehicle to the remaining vehicles within its jurisdiction area. These vehicles delete the key shared with the revoked vehicle and reselect the first random number and then recalculate the group key. Thus, it can prevent the revoked vehicle from continuing to decrypt the messages in the original group.

[0114] It is understandable that when there are changes in group members, the practice of group members recalculating the group key ensures the forward / backward security of the group key. Therefore, the embodiments of the present invention not only provide a secure key negotiation method, but also provide an update method thereof, realizing secure communication between vehicles.

[0115] In summary, the secure communication method for anonymous anti-key leakage in the vehicle networking provided by the embodiments of the present invention has the following beneficial effects:

[0116] (1) Only the TA knows the identity of the vehicle, and the RSU cannot obtain the true identity of the vehicle; moreover, the vehicle uses the pseudonym assigned by the TA during the communication with other vehicles, and other vehicles cannot obtain its identity either, realizing perfect anonymous protection. Therefore, the embodiments of the present invention meet the requirements regarding anonymity in conditional anonymity.

[0117] (2) When the vehicle enters the jurisdiction area of each RSU, it will obtain a new pseudonym and the corresponding self-verifying public-private key pair, that is, the vehicle uses different identity information in the jurisdiction areas of different RUSs, and the attacker cannot determine the message sender by analyzing multiple intercepted messages. Therefore, the embodiments of the present invention meet the requirements regarding unlinkability in conditional anonymity.

[0118] (3) The TA has an index library of the vehicle's identity and shared keys locally, that is, the TA has the ability to reveal the true identity of the vehicle. Therefore, the embodiments of the present invention meet the requirements regarding traceability in conditional anonymity.

[0119] (4) The vehicle, RSU, and TA interact based on the authentication vector and the unique timestamp to achieve mutual authentication among them. Thus, each party in the embodiments of the present invention can ensure that the communication counterpart is secure and trustworthy.

[0120] (5) The vehicles within the jurisdiction area calculate the shared keys between both parties pairwise based on the pseudonym and the self-verifying public-private key corresponding to the pseudonym, and further calculate the group key based on the pairwise shared keys, thereby performing secure communication based on the group key, ensuring pairwise secure communication within the group and secure communication within the entire group.

[0121] (6) The embodiments of the present invention use the self-verifying public key system, realizing the self-verifying cryptoscheme on the elliptic curve group, improving the calculation and communication efficiency, and being more suitable for the vehicle networking with rapid vehicle handover.

[0122] In summary, the embodiments of the present invention simultaneously achieve identity anonymity, unlinkability, and traceability in the vehicle networking, realizing secure communication in the vehicle networking. Moreover, the present invention solves the problem of secure communication between vehicles, realizing many functions such as key negotiation between multiple vehicles, mutual authentication between vehicles, group key update, and accountability for illegal vehicles.

[0123] It should be noted that the terms "first", "second", etc. are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure.

[0124] In the description of this specification, the description with reference to the terms "an embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.

[0125] Although the present application has been described in connection with various embodiments herein, however, in the process of implementing the claimed present application, those skilled in the art can understand and achieve other variations of the disclosed embodiments by viewing the accompanying drawings and the disclosure. In the description of the present invention, the term "including" does not exclude other components or steps, the term "a" or "an" does not exclude a plurality of cases, and the meaning of "a plurality" is two or more unless otherwise specifically defined. In addition, certain measures are described in different embodiments, but this does not mean that these measures cannot be combined to produce good results.

[0126] In the present invention, unless otherwise clearly specified and limited, the first feature being "on" or "under" the second feature may include direct contact between the first and second features, or may include the first and second features not being in direct contact but being in contact through additional features therebetween. Moreover, the first feature being "above", "over" and "on" the second feature includes the first feature being directly above and obliquely above the second feature, or merely indicating that the first feature has a higher horizontal height than the second feature. The first feature being "under", "beneath" and "under" the second feature includes the first feature being directly below and obliquely below the second feature, or merely indicating that the first feature has a lower horizontal height than the second feature.

[0127] The above content is a further detailed description of the present invention in combination with specific preferred embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can be made, and all should be regarded as belonging to the protection scope of the present invention.< / g> < / g> < / g> < / g> < / g> < / g>

Claims

1. A secure communication method for anonymous anti-key leakage in a vehicle networking system, characterized in that, the vehicle networking system includes a Trusted Authority (TA), Road Side Units (RSUs) and vehicles; TA has an index database of vehicle identities, shared keys and pseudonyms locally; the secure communication method includes: Authentication step: When a vehicle enters the jurisdiction area of a certain RSU, the vehicle calculates an authentication vector through hash operation based on its identity, shared key and a unique timestamp, so that the vehicle, the RSU and TA interact based on the authentication vector and the unique timestamp to achieve authentication among them; wherein, when TA authenticates the vehicle successfully, TA generates a pseudonym for the vehicle and forwards it to the vehicle through the RSU, and when the RSU authenticates the vehicle successfully, the RSU generates a self-verifying public-private key pair corresponding to the vehicle's pseudonym and sends it to the vehicle; Group key negotiation step: Vehicles within the jurisdiction area calculate the shared key between each other based on the self-verifying public-private key pair corresponding to their pseudonyms and the self-verifying public keys corresponding to the pseudonyms of other vehicles, encrypt the first random number with this key and broadcast the encrypted result; the vehicle decrypts the encrypted result sent by the other vehicle using the key shared with each other vehicle to obtain the first random number used by the other vehicle; the vehicle calculates the group key based on the first random numbers of the vehicle group within the jurisdiction area; Intra-group communication step: The vehicle group within the jurisdiction area conducts secure communication based on the group key.

2. The secure communication method according to claim 1, characterized in that, TA grants the symmetric key and public-private key pair of the RSU to the RSU that accesses the network, and grants the symmetric key of the vehicle as the vehicle's shared key to the vehicle that accesses the network; The interaction among the vehicle, the RSU and TA based on the authentication vector and the unique timestamp to achieve authentication among them includes: The vehicle generates a first random parameter, and then sends the first random parameter, the authentication vector and the unique timestamp to the RSU, so that the RSU forwards the authentication vector and the unique timestamp to TA and saves the first random parameter for future use; When TA receives the authentication vector and the unique timestamp forwarded by the RSU, TA searches the index database for the identity of the vehicle and the vehicle's symmetric key that can reconstruct the authentication vector; when found, TA authenticates the vehicle successfully, generates a pseudonym for the vehicle, and then encrypts the generated pseudonym, the reconstructed authentication vector and the unique timestamp using the symmetric key of the RSU to form an encrypted message and send it to the RSU; When the RSU receives the encrypted message, the RSU decrypts the encrypted message using its own symmetric key. If the decryption is successful, the RSU authenticates TA successfully and authenticates the vehicle corresponding to the decrypted unique timestamp successfully; and the RSU generates a self-verifying public-private key pair corresponding to the vehicle's pseudonym for the authenticated vehicle, and sends the vehicle's pseudonym, the self-verifying public-private key pair corresponding to the pseudonym, the decrypted unique timestamp and authentication vector, and the RSU's own public key to the vehicle through a message. After the vehicle receives the message, it authenticates the TA and the RSU based on the authentication vector and the unique timestamp therein.

3. The secure communication method according to claim 2, wherein, the vehicle calculates the shared key between the two parties based on the self-verifying public and private key pair corresponding to its pseudonym and the self-verifying public key corresponding to the pseudonyms of other vehicles, including: the vehicle broadcasts its negotiation message and receives the negotiation messages broadcast by other vehicles; the negotiation message includes the pseudonym of the vehicle, the self-verifying public key, and the second random parameter generated by the vehicle; The vehicle calculates the shared key between the two parties by using the formula k ij = H((h 1 a i + sk i )(h 2 A j + h 0 PK RSUk + PK j )); where h 1 = H 1 (PVID i || PVID j || PK i || PK j || A i || A j ), h 0 = H 1 (PVID j || PK j ), h 2 = H 1 (PVID j || PVID i || PK j || PK i || A j || A i ), || represents character concatenation, sk i is the self-verifying private key corresponding to the pseudonym of vehicle i, PVID i is the pseudonym of vehicle i, PVID j is the pseudonym of other vehicle j, PK i is the self-verifying public key corresponding to the pseudonym of vehicle i, PK j is the self-verifying public key corresponding to the pseudonym of other vehicle j, is the public key of roadside unit k, A i = a i P is the second random parameter broadcast by vehicle i, A j = a j P is the second random parameter broadcast by vehicle j, a i is the second random number selected by vehicle i, a j is the second random number selected by other vehicle j, P is the elliptic curve group <g>generator of, <g>Consists of all points on the elliptic curve E / F defined over the finite field F p and an infinite point O; H and H P are different hash functions; E / F 1 , H, H P , the finite field F 1 , the characteristic p of the finite field F p and the public key of TA are all included in the system parameters broadcast by TA; k ij is the shared key calculated by vehicle i for both itself and vehicle j.< / g> < / g> 4. The secure communication method according to claim 3, wherein, the RSU generates a self-verifying public and private key pair corresponding to the pseudonym for the vehicle that has passed the authentication, and sends the pseudonym of the vehicle, the self-verifying public and private key pair corresponding to the pseudonym, the decrypted authentication vector and the unique timestamp, and the public key of the RSU itself to the vehicle through a message, including: The RSU selects the third random number k i Calculate K i = k i P, and calculate PK i = R i + K i as the self-verifying public key corresponding to the pseudonym of vehicle i; where R i = r i P is the first random parameter of vehicle i, and r i is the fourth random number selected for vehicle i; RSU calculation The partial private key corresponding to the pseudonym of vehicle i as the self-verifying private key; Is the private key of roadside unit k; The RSU sends the vehicle's pseudonym, self-certifying public key, partial private key, decrypted authentication vector, unique timestamp, and its own public key to the vehicle in the form of a message via a common channel, so that vehicle i calculates sk after verifying the equation holds. i = sk i ' + r i as its complete self-certifying private key.

5. The secure communication method according to claim 3, wherein, when the vehicle calculates the shared key between the two parties based on the self-verifying public and private key pair corresponding to its pseudonym and the self-verifying public key corresponding to the pseudonyms of other vehicles, the two parties authenticate each other.

6. The secure communication method according to claim 1, wherein, it further includes: when a new vehicle joins the vehicle group via the authentication step, triggering the re-execution of the group key negotiation step.

7. The secure communication method according to claim 1, wherein, it further includes: when a vehicle leaves the jurisdiction area, the remaining vehicles re-select the first random number, and recalculate the group key according to the sub-step of encrypting the first random number with the key and broadcasting the encrypted result and the subsequent sub-steps in the group key negotiation step.

8. The secure communication method according to claim 1, wherein, it further includes: when a vehicle is revoked by the TA, the remaining vehicles re-select the first random number, and recalculate the group key according to the sub-step of encrypting the first random number with the key and broadcasting the encrypted result and the subsequent sub-steps in the group key negotiation step.

9. The secure communication method according to claim 1, wherein, calculating the group key according to the first random numbers of the vehicle groups in the jurisdiction area includes: gk = H(b 1 + b 2 + … b i + … + b N ); Among them, H is the hash function included in the system parameters broadcast by TA, and b 1 ~b N are respectively the first random numbers of each vehicle in the vehicle group, and gk is the calculated group key.

10. The secure communication method according to claim 2, wherein, when the vehicle receives the message, authenticating the TA and the RSU based on the authentication vector and the unique timestamp therein, including: when the vehicle receives the message, verifying the correctness of the authentication vector therein and whether the unique timestamp therein is consistent with the timestamp sent by itself to the RSU; when the verification result of the authentication vector is correct, passing the authentication of the TA; when the unique timestamp in the message is consistent with the timestamp sent by itself to the RSU, passing the authentication of the RSU.

Citation Information

Patent Citations

  • Vehicle-vehicle security communication method based on RSU assisted authentication

    CN104683112A

  • Method for designing vehicle network group negotiation communication protocol

    CN106027233A