A User Authentication and Key Agreement Method Applicable to Vehicular Ad Hoc Networks
By adopting a PKI-based public key cryptography system for user authentication and key negotiation in the Internet of Vehicles environment, security issues and computing complexity in Internet of Vehicles communication in the prior art are solved, and efficient and secure key negotiation is achieved.
Patent Information
- Application Number
- CN202211609464.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-14
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-12-14
AI Technical Summary
The existing user authentication and key negotiation protocols have security problems and computing complexity in the Internet of Vehicles communication environment, making it difficult to achieve efficient and secure communication.
The PKI-based cryptographic system is adopted to perform user authentication and key negotiation through public keys, and the key is constructed using the signature method to reduce the calculation overhead of bilinear operations and point multiplication operations.
It realizes efficient and secure user authentication and key negotiation in the Internet of Vehicles environment, reduces computing overhead, enhances the confidentiality and non-forgery of keys, and resists witch attacks, disguised attacks and data authentication attacks.
Smart Images

Figure BDA0003997944540000027 
Figure FDA0003997944530000019
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information security, and particularly relates to a user authentication and key negotiation method applicable to the vehicle networking. Background Art
[0002] With the rapid development of communication systems, in order to ensure communication security, we have proposed the concept of key negotiation. It can provide identity authentication for participants and establish a shared session key between communication nodes, which can ensure the confidentiality and integrity of the communication process.
[0003] PKI is the abbreviation of Public Key Infrastructure in English. It is a security system based on public key technology. Its application covers most of the knowledge and technologies in cryptography, and it is an open structure. There is no end to the improvement based on security and efficiency. In the cryptographic system based on PKI, there is a trusted third-party authority CA to issue public key certificates for public key holders. This certificate is the result of the CA signing the public key and the identity information of the public key holder. The user of the public key can authenticate the public key by verifying the legality of the certificate. The key protocol based on PKI can effectively solve the problems of man-in-the-middle attacks using pre-shared keys to participate in encryption / decryption in the cross-domain key protocol based on passwords, and the problem that attackers can implement password guessing attacks due to weak passwords in Kerberos. In 2017, Mingping Qi and Jianhua Chen proposed a two-factor authentication key protocol for the client-server architecture, which used a secret hash value to shield the original identity of the user and the three-way handshake technology to solve the user anonymity problem and the clock synchronization problem, but it was pointed out by Alavalapati Goutham Reddy et al. that it is prone to server simulation attacks, user simulation attacks or internal attacks, etc. In 2018, Jiaqing Mo et al. proposed a new remote user authentication and key negotiation for the mobile client-server environment. This scheme relies on the elliptic curve discrete logarithm problem and the computational Diffie-Hellman problem. In 2019, Mohammad Wazid et al. published a security key management and user authentication scheme for fog computing services, but it has complex processes and large communication overhead.
[0004] In the vehicle networking communication environment, the communication process is more complex than in other fields. The above user authentication and key negotiation protocols all have more or less security problems or computational complexity problems. Therefore, it is necessary to design an efficient and secure user authentication and key negotiation method applicable to the vehicle networking. Summary of the Invention
[0005] Object of the Invention: The object of the present invention is to provide a user authentication and key negotiation method applicable to the vehicle networking, which can ensure the security and efficiency of communication.
[0006] Technical Solution: The present invention provides a user authentication and key negotiation method applicable to the vehicle networking, including the following steps:
[0007] S1: System establishment. Given a security parameter λ, a large prime number p is taken such that |p| = λ, q is a large prime factor of p - 1, and g is an element of order q in Z P such that where lq: N → N is a function that determines the length of q, and two secure hash functions are defined where l 1 、l 2 、l 3 、l 4 is the length of the bit string, and the system parameters are {l 1 ,l 2 ,l 3 ,l 4 ,p, q, g, H 1 ,H 2};
[0008] S2: Registration phase. Determine the private key x s 、public key y s of the sender, the private key x r 、public key y r of the receiver, and send the public keys to the trusted authority CA, and the CA issues certificates to the public key holders;
[0009] S3: User authentication and key negotiation phase. According to the private key x s 、public key y s of the sender and the public key y r of the receiver given in S2, the specific steps are as follows:
[0010] S3.1: Randomly select and
[0011] S3.2: The sender calculates for encrypting the key;
[0012] S3.3: The sender calculates the XOR value is the XOR operation, and H 1 is a hash operation;
[0013] S3.4: The sender calculates the verification value h = H 2 (k||y s ||yr ||ω), H 2 is a hashing operation, where the length of k is l 2 , y s has a length of l 3 , y r has a length of l 4 , and the length of ω is l 1 ;
[0014] S3.5: The sender calculates the signature v = hx s + x mod q;
[0015] S3.6: Finally, generate the ciphertext σ = (c, h, v). Where h is a verification value;
[0016] S4: Given the ciphertext σ, the sender's public key y s , the receiver's private key x r and the public key y r , the working principle of this algorithm is as follows:
[0017] S4.1: After the receiver receives the ciphertext σ, calculate ω through its own private key x r and the sender's public key y s ;
[0018] S4.2: The receiver calculates and recovers the key k of the key agreement through the known information
[0019] S4.3: The receiver calculates the verification value h' according to the key k, h' = H 2 (k||y s ||y r ||ω);
[0020] S4.4: If h' = h, the sender's identity is verified and the session key is established. Otherwise, return the error symbol ⊥.
[0021] Furthermore, in S2, determining the sender's private key x s , public key y s , the receiver's private key x r , public key y r specifically includes the following steps:
[0022] The sender selects a random number as its private key, y s is the corresponding public key Similarly, the receiver selects a random number y r is the corresponding public key
[0023] Furthermore, the represents the group of integers excluding 0.
[0024] Furthermore, the sender's public key y s , and the receiver's public key y r requires CA authentication to be used
[0025] Beneficial effects:
[0026] 1. Compared with previous methods, the present invention adopts a PKI-based cryptographic system, without time-consuming bilinear pairing operations and point multiplication operations, with relatively small computational overhead, and can be widely applied in the actual scenarios of PKI-based vehicle networking.
[0027] 2. In the user authentication and key negotiation phase, most previous schemes used the Diffie-Hellman key negotiation method to construct keys, while we use the public key method to construct keys. Specifically, we use the signcryption method to construct the user authentication and key negotiation scheme. In addition to the confidentiality, authenticity, integrity, and non-forgeability inherent in the signcryption scheme itself, the scheme can also achieve key negotiation and resist attacks such as Sybil attacks, impersonation attacks, and data authentication attacks. The present invention is proven to be secure in the random oracle model, and this method has simple operations and high transmission efficiency, making it an ideal key negotiation method. Specific implementation manner
[0028] The present invention provides a method for user authentication and key negotiation applicable to vehicle networking. This method has simple operations and less computational complexity compared to other methods, so it is suitable for use in in-vehicle networks. Because the computing power of in-vehicle network nodes (On-Board Unit, abbreviated as OBU) is often limited, during the OBU communication process, the Road-Side Unit (RSU) of highway infrastructure is required as a transfer station to send communication data to the cloud server, and the computing power of the RSU is also often limited and mostly under different cryptographic systems from in-vehicle network nodes. Therefore, on the premise of ensuring the confidentiality and authenticity of data during the communication process, and also making the transmission efficient, the method proposed by the present invention can be perfectly applied to this scenario. The specific implementation of this method includes the following steps:
[0029] S1: System establishment. Given a security parameter λ, a large prime number p is taken such that |p| = λ, q is a large prime factor of p - 1, and g is an element of order q in Z P , such that where l q : N → N is a function that determines the length of q, and two secure hash functions are defined where l 1 , l2 , l 3 , l 4 , l 5 , l 6 is the length of the message, and the system parameters are {l 1 , l 2 , l 3 , l 4 , l 5 , l 6 , p, q, g, H 1 , H 2}.
[0030] S2: Registration phase: The OBU selects a random number as its private key, y s is the corresponding public key, Similarly, the RSU selects a random number y r as the corresponding public key, The OBU and the RSU send the generated public keys to a third-party trusted institution CA, and the CA issues certificates to the public key holders.
[0031] S3: User authentication and key establishment phase: The OBU establishes a user authentication and key negotiation process with the RSU, and this process includes the following steps:
[0032] S3.1: The OBU randomly selects and
[0033] S3.2: The OBU calculates for encrypting the key.
[0034] S3.3: The OBU calculates the XOR value is the XOR operation, H 1 is a hash operation, TS (Time Stamp) is the time stamp to prevent the reuse of ciphertext, and ED (Expiration Date) is the automatic revocation date.
[0035] S3.4: The OBU calculates the verification value h = H 2 (k||TS||ED||y s ||y r ||ω), H 2 is a hash operation, the length of k is l 2 , the length of TS is l 3 , the length of ED is l 4 , y s has a length of l 5 , y rhas a length of l 6 , ω has a length of l 1 .
[0036] S3.5: The OBU calculates the signature v = hx s + x mod q.
[0037] S3.6: Finally, generate the ciphertext σ = (c, h, v). Where h is a verification value.
[0038] S4: After receiving the ciphertext σ from the OBU, the RSU decrypts it and performs authentication. The working principle of this algorithm is as follows:
[0039] S4.1: After receiving the ciphertext σ, the RSU calculates ω through its own private key x r and the public key y of the sender s to calculate ω,
[0040] S4.2: The RSU calculates and recovers the key k for key negotiation through known information,
[0041] S4.3: The RSU calculates the verification value h' according to the key k, h' = H 2 (k||TS||ED||y s ||y r ||ω).
[0042] S4.4: If h' = h, the authentication of the OBU passes and the session key is established. Otherwise, return an error symbol
[0043] This method ensures the confidentiality and unforgeability of the key during the communication between the OBU and the RSU in the vehicle network. Because if the equation h' = h does not hold, it proves that the verification fails, the ciphertext may be tampered with or it means that the ciphertext is not sent by the OBU, and the RSU rejects the ciphertext and does not make corresponding judgment instructions.
[0044] Through the present invention, a user authentication and key negotiation method applicable to the vehicle network is constructed. This method can be well applied to the vehicle network environment and solves the key negotiation problem in vehicle network communication based on the PKI technology.
[0045] The above embodiments are only for illustrating the technical concept and characteristics of the present invention, and their purpose is to enable those who are familiar with this technology to understand the content of the present invention and implement it accordingly, and cannot be used to limit the protection scope of the present invention. All equivalent transformations or modifications made according to the spirit of the present invention should be covered within the protection scope of the present invention.
Claims
1. A user authentication and key negotiation method applicable to the vehicle networking, characterized in that: It includes the following steps: S1: System establishment. Given a security parameter λ, take a large prime number p such that |p| = λ, q is a large prime factor of p - 1, and g is an element of order q in Z P such that where lq: N → N is a function that determines the length of q, and define two secure hash functions where l 1 、l 2 、l 3 、l 4 are the lengths of bit strings. The system parameters are {l 1 , l 2 , l 3 , l 4 , p, q, g, H 1 , H 2}; S2: Registration phase, determine the sender's private key x s , public key y s , the recipient's private key x r , public key y r , and send the public key to the trusted institution CA, and the CA issues a certificate to the public key holder; S3: User authentication and key negotiation phase. According to the private key x of the sender given in S2 s , the public key y of the sender s and the public key y of the receiver r , the specific process of user authentication and key negotiation for the sender to establish communication with the receiver is as follows: S3.1: Randomly select and S3.2: The sender calculates for encrypting the key; S3.3: The sender calculates the XOR value is an XOR operation, H 1 is a hashing operation; S3.4: The sender calculates the verification value h = H 2 (k || y s || y r || ω), where H 2 is a hashing operation. Here, the length of k is l 2 , the length of y s is l 3 , the length of y r is l 4 , and the length of ω is l 1 ; S3.5: The sender calculates the signature \(v = hx s +x\bmod q; S3.6: Finally, generate the ciphertext σ = (c, h, v), where h is a verification value; S4: Given the ciphertext σ, the sender's public key y s , the receiver's private key x r and the public key y r , decrypt and authenticate, which specifically includes the following steps: S4.1: After the receiver receives the ciphertext σ, it calculates ω through its own private key x r and the sender's public key y s S4.2: The receiver calculates and recovers the key k for key negotiation through known information. S4.3: The receiver calculates the verification value h' according to the key k, h' = H 2 (k||y s ||y r ||ω); S4.4: If h' = h, the authentication of the sender passes and the session key is established; otherwise, return the error symbol ⊥.
2. The user authentication and key negotiation method applicable to the vehicle networking according to claim 1, characterized in that: in S2, the private key x of the sender is determined s , the public key y s , the private key x of the recipient r , the public key y r Specifically, it includes the following steps: The sender selects a random number as its private key, y s and the corresponding public key is Similarly, the receiver selects a random number y r and the corresponding public key is 3. The user authentication and key negotiation method applicable to the vehicle networking according to claim 1, characterized in that: The said represents the group of integers excluding 0.
4. The user authentication and key negotiation method applicable to the vehicle networking according to claim 1, characterized in that: The sender's public key y s , and the recipient's public key y r requires CA authentication to be used.
Citation Information
Patent Citations
Heterogeneous user authentication and key negotiation method
CN113572603A
Efficient certificateless authenticated key agreement method and system without bilinear pairing operation
CN114024668A