Traffic data security sharing method based on blockchain and traceable ring signature

By using blockchain and traceable ring signature technology, the problems of centralization and high cost in VANETs are solved, realizing decentralized secure sharing and privacy protection of traffic data, and improving the security and efficiency of information sharing.

CN116437350BActive Publication Date: 2026-07-21JIANGXI UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JIANGXI UNIV OF SCI & TECH
Filing Date
2023-03-08
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing VANETs solutions suffer from centralization issues in privacy protection, identity authentication, and secure transmission. They are unable to effectively track the source of false information, and have high computational and storage costs, as well as complex key management.

Method used

Decentralized storage is achieved using blockchain technology, illegal vehicles are tracked using smart contracts, computational tasks are offloaded through edge computing, traceable ring signatures are used to ensure secure information sharing, authoritative institutions generate pseudonyms and store privacy information, and edge nodes process data to improve efficiency.

Benefits of technology

It enables decentralized and secure sharing of traffic data, reduces computing and storage costs, improves the security and efficiency of information sharing, can trace the source of false information and punish it, and protects driver privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116437350B_ABST
    Figure CN116437350B_ABST
Patent Text Reader

Abstract

A traffic data security sharing method based on blockchain and traceable ring signature, comprising an authority, a roadside unit, a traffic management department and a user, a vehicle is provided with a vehicle-mounted unit and an anti-tampering device. When the vehicle is driving, if an emergency occurs, the driver describes the event through the vehicle-mounted unit, signs the message using a traceable ring signature, and broadcasts the signed message to surrounding vehicles and roadside units using short-range wireless communication. After receiving the message, the roadside unit verifies the information, and if the information is correct, stores the message in the blockchain, facilitates other vehicles to obtain the message, and broadcasts the message to the coverage area. The blockchain records the message sharing, which is used for subsequent tracing and accountability of false information senders. The application meets the requirements of data sharing service for security and privacy, can resist existing network attacks, and provides a decentralized traffic data sharing scheme, which reduces the cost of data sharing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention pertains to the secure sharing of traffic data in vehicular ad hoc networks (VANETs), and involves blockchain technology and traceable ring signature technology in the field of information security. Background Technology

[0002] Intelligent Transportation Systems (ITS) integrate electronics, communications, and computer technologies to construct a real-time, accurate, and efficient traffic operation framework. Vehicular ad hoc networks (VANETs) describe the fluidity and coexistence of communication architectures between vehicles and between vehicles and roadside units, providing self-organized data transmission, safety precautions, navigation, and other roadside services. Vehicles exchange data via short-range wireless communication. This real-time information interaction (such as traffic information, weather conditions, and road conditions) can help vehicles or traffic control centers take proactive measures to reduce traffic accidents or road congestion. Therefore, an increasing number of scholars are dedicated to the research of VANETs to improve quality of life and work efficiency.

[0003] To protect sensitive information transmission and authentication in VANETs, ​​M Raya et al. embedded a suitable public key infrastructure (PKI) in "Securing vehicular ad hoc networks" in the Journal of Computer Security 2007, 15(1), and used an anonymous certificate issued by a Certificate Authority (CA) to hide the true identity of the vehicle during communication. Since PKI cannot provide location privacy and implement a fair distributed revocation mechanism, A Wasef et al. introduced a random encryption period to protect the location privacy of vehicles in IEEE Wireless Communications 2010, 17(5), "Complementing public key infrastructure to secure vehicular ad hoc networks [security and privacy in emerging wireless networks]", and proposed an efficient decentralized revocation protocol that allows a group of adjacent vehicles to revoke the revocation of a malicious vehicle in its vicinity. In their paper "Blockchain-based privacy-aware pseudonym management framework for vehicular networks" published in the *Arabian Journal for Science and Engineering*, 2020, 45(8), L Benarous et al. pointed out that existing PKI infrastructures are centralized and then proposed a blockchain-based pseudonym management framework for VANETs. These schemes prevent malicious vehicles from entering VANETs, ​​minimize the cost of certificate and signature verification, and design a tracking mechanism to revoke vehicles that persist in VANETs. However, PKI-based authentication schemes all have similar drawbacks: 1) a trusted CA is required to issue certificates; 2) the computational cost of certificate and signature verification is high; and 3) certificate storage and key management are difficult.

[0004] Some researchers have proposed ID-based privacy-preserving authentication schemes to address the problems encountered by PKI-based schemes in VANET applications, effectively reducing communication costs. L Deng et al., in *Peer-to-Peer Networking and Applications* 2021, 14(4), “Identity based two-party authenticated key agreement scheme for vehicular ad hoc networks,” pointed out that current identity-based two-party authentication key protocol schemes are not necessarily secure in real-world applications. To achieve energy-efficient privacy and communication security for communicators, Wakram et al., in *Computer Networks* 2022, “An energy-efficient and secure identity-based RFID authentication scheme for vehicular cloud computing,” designed an identity-based authentication system for vehicular cloud computing, which also utilizes radio frequency identification (RFID). Since identity-based authentication schemes rely on the CA to generate private keys based on user information, key management is considered the cornerstone of the VANET security framework and has become a key research focus. Given the respective advantages of PKI-based and identity-based schemes, SWang et al., in "Hybrid conditional privacy-preserving authentication scheme for VANETs" published in Peer-to-Peer Networking and Applications 2020, 13(5), combined the advantages of both schemes and proposed a hybrid conditional privacy-preserving authentication protocol for VANETs. This protocol achieves user authentication based on PKI certificates and identity-based signatures.

[0005] Recently, the inherent characteristics of blockchain, such as decentralization, immutability, and traceability, have attracted the interest of researchers, and many are using blockchain to solve privacy protection, identity authentication, and secure transmission issues in VANETs. Based on the current technical challenges of VANETs, ​​H Li et al., in "Blockchain meets VANET: An architecture for identity and location privacy protection in VANET" (Peer-to-Peer Networking and Applications, 2019, 6(2)), designed a novel decentralized VANETs architecture that leverages the inherent advantages of blockchain, thus avoiding centralization and mutual distrust among entities in VANETs. Regarding transmission security and the collection of private driver information in VANETs, ​​according to R Shrestha et al., in "A new type of blockchain for secure message exchange in VANET" (Digital communications and networks, 2020, 6(2)), a new blockchain can solve the problem of secure information exchange by creating a local blockchain with national borders. However, existing solutions lack a tracking mechanism; if a vehicle in a VANET sends false information, the authoritative TA cannot identify the specific source through the signature on the information. Therefore, using blockchain technology for tracking can achieve data security protection and trusted resource sharing. Summary of the Invention

[0006] The purpose of this invention is to propose a secure sharing method for traffic data based on blockchain and traceable ring signatures, so as to realize the secure and reliable sharing of traffic information in vehicle-mounted self-organizing networks using blockchain technology.

[0007] This invention utilizes the decentralized storage of road traffic information on the Ethereum blockchain. Leveraging the traceability feature of blockchain, smart contracts are used to track illegal vehicles and return the results to the authoritative entity (TA), enabling the traceability of malicious vehicles. The TA retains control over the source of signature information and determines penalties, which helps protect driver privacy and improves the security of VANETs' shared information. The authoritative entity generates pseudonyms for vehicles that successfully join the system. Vehicles use these pseudonyms for communication during information exchange. User registration information is stored in the TA's secure database, ensuring user privacy. Edge computing is used to address the low computing power issue of VANETs. Vehicle registration and signer tracking can be offloaded to cloud servers with greater computing storage capacity via edge nodes, which also improves the efficiency of VANETs.

[0008] The present invention discloses a secure traffic data sharing method based on blockchain and traceable ring signatures, comprising an authoritative agency (TA), a roadside unit (RSU), traffic management departments, and users, wherein the users are primarily vehicles (V). i Composed of the vehicle driver, in vehicle V i It is equipped with an on-board unit (OBU) and a tamper-proof device (TPD). When the vehicle V i In the event of an emergency during driving, the driver can describe the event using the On-Board Unit (OBU) installed in the vehicle and sign the message using a traceable ring signature. The signed message is then broadcast wirelessly to surrounding vehicles and Roadside Units (RSUs). Upon receiving the message, the RSUs verify it. If the verification is successful, the message is stored in the blockchain for other vehicles in the system to access, and it is immediately broadcast to the coverage area to alert other vehicles. After the message sharing service is completed, the blockchain records the message sharing, which can be used to trace and hold accountable those who send false information. This invention meets the security and privacy requirements of data sharing services, can resist existing network attacks, and proposes a decentralized traffic data sharing scheme that reduces the cost of data sharing.

[0009] Specifically, the present invention is achieved through the following technical solutions.

[0010] The present invention discloses a secure traffic data sharing method based on blockchain and traceable ring signatures, comprising the following steps:

[0011] (S01): During system initialization, the authoritative organization TA generates the system master public key MPK, master private key MSK, and system hash function H0…H5; all roadside unit RSU nodes jointly form a traffic event storage public chain, and the authoritative organization initializes an Ethereum in the node during system initialization; according to the draft of the malicious user tracking smart contract agreed upon by all parties, the authoritative organization TA writes the smart contract and deploys the smart contract on the blockchain;

[0012] (S02): Vehicle V i Before joining a vehicle-mounted self-organizing network, users need to register by submitting their real identity information to an authoritative organization (TA). After verifying the application information provided by the vehicle, the TA will then process the application based on the vehicle information. i Driver ID i Generate vehicle pseudonym PID iThe data is stored in the On-Board Unit (OBU). In addition, the authoritative organization generates a tracking public-private key pair for successfully registered vehicles, used for tracing malicious vehicles. This tracking key pair has a time limit and needs to be regenerated by the authoritative organization periodically. Vehicles in the system use the OBU to retrieve the pseudonym PID output by the authoritative organization (TA). i Generate your own public key PK i Private key sk i ;

[0013] (S03): When a sudden traffic incident occurs in the system, the event signer s uses the on-board unit (OBU) to describe the event; for the processed message m, the signer s uses a traceable ring signature to sign the message, and the signer s will then transfer the signed message {m, T} to the system. σ} Towards surrounding vehicles V i Broadcast to the roadside unit (RSU);

[0014] (S04): The roadside unit RSU receives the broadcast message {m, T} from the signer S. σ After that, the traceable ring signature T on message m is... σ The correctness of the message is verified. Once the verification is successful, the Roadside Unit (RSU) stores the message in the blockchain and broadcasts it to the entire system.

[0015] (S05): When false information sent by a malicious vehicle is detected, the smart contract deployed in the blockchain will verify the traceable ring signature T in the message. σ The system identifies the signer of the false message; the authoritative agency submits the information of the malicious vehicle to the traffic management department for punishment or revocation of its registration information, and then records the punishment result on the blockchain.

[0016] Further, the system generation described in step (S01) of the present invention is performed according to the following steps:

[0017] (1) System initialization

[0018] Inputting the security parameter λ, the authoritative body TA selects two cyclic multiplicative groups G1 and G2 with the same order q. T Let q be a large prime number, and suppose P is a generator of the multiplicative group G1. There exists a bilinear pair e: G1 × G1 → G T ;

[0019] The authoritative organization TA selects a random number. Use this as the master private key, calculate the master public key MPK = aP, and define a hash function. H1: {0, 1} * ×Z P * →G1,H2:{0,1} *×{0, 1} * →Z p * H3:Z p * ×G1→Z p * H4: {{0, 1} * ×Z p * →Z p * H5: {0, 1} * ×Z p * ×…×Z p * →Z P * Then the system parameters are params = {q, P, e, G1, G} T ,MPK,H0,H1,H2,H3,H4,H5};

[0020] (2) Smart Contract Deployment

[0021] The authoritative institution TA accepts the input of the smart contract draft, compiles it, and deploys it on the blockchain. After being verified by the blockchain, the smart contract obtains its unique address. When false messages are detected in the system, the smart contract will automatically trace the sender of the information and submit the identity of the false message sender to TA.

[0022] Furthermore, the user information encryption described in step (S02) of this invention is performed according to the following steps:

[0023] (1) Vehicle registration

[0024] Vehicle V i Randomly select a constant l i ∈Z P * Calculate M i =l i P, N i =l i MPK Then the vehicle will {M i OID i Send it to the authoritative organization TA, and the authoritative organization TA will then process it. After calculating the vehicle's real information and verifying the legality of the information submitted by the user, the authoritative agency TA generates a pseudonym for the vehicle. The pseudonym will be transmitted to vehicle V through a secure channel. i The pseudonym is stored in the on-board unit (OBU).

[0025] (2) Tracking key generation

[0026] The authoritative organization TA randomly selects a constant r i ∈Z P * Calculate x i =H2(r i ||t i ), where t i It is the tracking key x i The validity period is calculated to track the public key Y. i =x i (P+PID) i Then, the authoritative organization TA will {x i Y i The data is transmitted to the vehicle via a secure channel and stored in the tamper-proof device of the on-board unit (OBU). i Y i PID i Stored in the secure database of the authoritative organization, TA;

[0027] (3) Vehicle key generation

[0028] Vehicle V i A more authoritative organization, TA, generates a public / private key pair using pseudonyms, and then randomly selects a number n. i ∈Z P * Calculate its private key sk i =H3(n i ||PID i ), public key pk i =sk i P.

[0029] Furthermore, the traceable ring signature in step (S03) of the present invention signs the message according to the following steps:

[0030] (1) Attribute value generation

[0031] The signer s selects a public key set R1 = {pk1, pk2, ..., pkn} from n users in a roadside unit. n The corresponding tracking public key set Y′={Y1, Y2, …, Y} is: n} and the corresponding set of pseudonyms M = {PID1, PID2, ..., PID} n}, randomly select different numbers u i v i ∈Z P * Calculate L i K i , where I s =sk s H0(pk s) is the signature image of message m, used to prevent double-spending attacks;

[0032]

[0033]

[0034] (2) Partial signature generation

[0035] The signer s calculates h = H4(m||R1) and calculates the partial signature c of the generated message m. i d i ;

[0036]

[0037]

[0038] (3) Identity tracking signature generation

[0039] The signer s selects a random number w i ∈Z P * Used to generate a partial signature that tracks the signer's identity, and to calculate T. i =w i (P+PID i (i = 1, 2, ..., n), TK i =w i Y i (i = 1, 2, ..., n),

[0040] (4) Signature output

[0041] The traceable expiration signature of the output is T σ =(I s c1, c2, ..., c n d1, d2, ..., d n TK1, TK2, ..., TK n T).

[0042] Furthermore, the traceable ring signature verification described in step (S04) of the present invention is performed according to the following steps:

[0043] (1) Obtaining member public key

[0044] Since the verification of traceable ring signatures is primarily performed by Roadside Units (RSUs), which collect vehicle information within their coverage area, and the signer (s) obtains the information for generating the traceable ring signature from the RSU, the RSU can easily obtain the public key set R1 = {pk1, pk2, ..., pk...} required for verifying the ring signature. n};

[0045] (2) Traceable ring signature verification

[0046] The validity of the ring signature is determined by verifying the correctness of the following formula. If the formula is verified, message m is received and recorded in the newly generated block; otherwise, message m is rejected.

[0047]

[0048] Furthermore, the malicious vehicle tracking and punishment mechanism described in step (S05) of the present invention is implemented according to the following steps:

[0049] (1) Malicious vehicle tracking

[0050] Once a malicious user's false message is detected, the smart contract accesses the secure database of the authoritative institution TA via an interface to obtain the traceable key pairs {x} of all ring members. i Y i}, calculate T i =TK i ·x -1 Then through bilinear pairing e(TK) i P+PID i )=e(T i Y i ) Verify T i After verifying the correctness, calculate... The sender of the fake message can use bilinear pairing e(T, P+PID) i ) = e(E, Y i )Sure;

[0051] (2) Penalties and revocation of malicious vehicle licenses

[0052] After identifying a malicious vehicle, the authoritative agency TA will determine the punishment based on the number of times the vehicle sent false messages. If the number of malicious acts by a vehicle is between 0 and 3, TA will lower the vehicle's reputation value and record the punishment in the blockchain. TA will also strictly review messages sent by vehicles that have sent false information; sending genuine information will increase the reputation value. For users who have sent false messages more than 3 times or have excessively low reputation values, TA will revoke their registration information and will not allow them to re-register for a certain period. Re-registration of malicious vehicles will be subject to strict review by TA, and re-registration is only permitted after the review is passed.

[0053] The traceable ring signature algorithm proposed in this invention not only possesses strong security and anonymity but also resists network attacks. By introducing vehicle edge computing, it reduces latency and cost during information sharing. Utilizing the Ethereum blockchain as the underlying architecture of this system, a secure traffic data sharing model is constructed. Unlike existing centralized traffic network databases, when false information is detected in the system, the data stored in the blockchain can be used to trace users who disrupt traffic. Attached Figure Description

[0054] Figure 1 A system model diagram for secure sharing of traffic data.

[0055] Figure 2 A diagram illustrating vehicle registration and key generation for secure sharing of traffic data.

[0056] Figure 3 Map for tracking and punishing malicious vehicles in order to ensure the secure sharing of traffic data.

[0057] Figure 4 A flowchart illustrating the specific implementation of secure sharing of traffic data.

[0058] Figure 5 The computational overhead for each step of the secure sharing of traffic data in this invention.

[0059] Figure 6 This is a comparison chart showing the computational overhead of the traffic data security shared key generation process of this invention.

[0060] Figure 7 This is a comparison chart showing the computational overhead of the traffic data secure sharing signature generation process of this invention.

[0061] Figure 8 This is a comparison chart showing the computational overhead of the traffic data secure sharing signature verification process of this invention.

[0062] Figure 9 This is a comparison chart showing the computational overhead of the malicious vehicle tracking process in the secure sharing of traffic data according to the present invention.

[0063] Figure 10 This invention addresses the communication overhead for each step of secure traffic data sharing.

[0064] Figure 11 This is a comparison chart showing the communication overhead of the signature generated for secure sharing of traffic data according to the present invention. Detailed Implementation

[0065] The present invention will be further described below with reference to the accompanying drawings and specific embodiments.

[0066] 1. The model design of this invention.

[0067] like Figure 1 The specific parameters for the overall structure of this invention are defined as follows:

[0068] Trusted Authority (TA): The TA possesses powerful computing and storage capabilities and is responsible for the daily maintenance of VANETs. To other entities within VANETs, ​​the TA is considered completely trustworthy and uncompromising towards any adversary. The TA is also responsible for VANET initialization, generating system parameters, and providing vehicle registration. When vehicles wish to join a VANET, they must first submit a registration application to the TA; only vehicles whose applications are approved can join. When a vehicle sends false information to disrupt normal traffic, the TA will track the vehicle based on the digital signature in the message and transfer the vehicle information to traffic management authorities for punishment. When a vehicle repeatedly engages in misconduct, the TA will revoke its registration information.

[0069] Vehicles: Vehicles in VANETs are equipped with On-Board Units (OBUs) and Tamper-Proof Devices (TPDs). Vehicles are considered data collection devices within VANETs, ​​and can communicate with other vehicles and RSUs via the OBU to share road information. When a vehicle applies for registration with the TA (Task Manager), the TA pre-installs initialization parameters in the OBU. The TPDs in the OBU ensure that these parameters are secure and cannot be arbitrarily tampered with by attackers.

[0070] Roadside Units (RSUs): Roadside units are installed on both sides of the road and support the Dedicated Short-Range Communication (DSRC) protocol, allowing communication with vehicles within a specific range. Specifically, RSUs can receive information from vehicles, verify it, forward the verified information to other vehicles, and store it in a blockchain. RSUs are interconnected, exchanging information through a secure wired network.

[0071] Traffic Management Department: The traffic management department manages the vehicles in VANETs. It receives driver information from TA, imposes corresponding penalties on vehicles with misconduct, and records the penalty results on the blockchain through node consensus. The data recorded on the blockchain cannot be tampered with.

[0072] Edge computing: Leveraging powerful computing and storage capabilities, edge computing processes data at the network edge, reducing network latency while improving data security and privacy. Edge computing accesses RSUs, TAs, and other entities within VANETs through edge nodes, and offloads most data computation to cloud servers, thereby improving the efficiency of VANETs.

[0073] Blockchain: This invention uses a public blockchain as the decentralized underlying architecture of our solution to instantiate VANETs. It is verified by the RSU according to the consensus algorithm of the message. Registered vehicles can access the blockchain through the RSU to obtain the required traffic data.

[0074] Smart Contracts: A smart contract is a computer protocol developed by TA and deployed on a blockchain. It accesses TA's secure database, obtains the driver's tracking private key, and calculates T. i Then, a two-line matching process is used to identify the true signatory. When an event triggers a clause in the contract, the contract is automatically executed to trace the true signatory and return the result to them.

[0075] 2. The method for secure sharing of traffic data of the present invention

[0076] The vehicle registration and key generation method for secure sharing of traffic data based on blockchain and traceable ring signatures proposed in this invention is as follows: Figure 2 As shown, malicious vehicles and penalties are as follows Figure 3 As shown, the specific implementation process of the method is as follows: Figure 4 As shown, the specific implementation process of the traceable ring signature algorithm is as follows:

[0077] (1) System initialization

[0078] 1) Input the security parameter λ, and the authoritative body TA selects two cyclic multiplication groups G1 and G2 with the same order q. T Let q be a large prime number, and suppose P is a generator of the multiplicative group G1. There exists a bilinear pair e: G1 × G1 → G T .

[0079] 2) The authoritative organization TA selects a random number. Use this as the master private key and calculate the master public key MPK = aP.

[0080] 3) Define the hash function H1: {0, 1} * ×Z P * →G1,H2:{0,1} * ×{0, 1} * →Z p *H3:Z p * ×G1→Z p * H4: {{0, 1} * ×Z p * →Z p * H5: {0, 1} * ×Z p * ×...×Z p * →Z P * .

[0081] 4) The output system parameters are params = {q, P, e, G1, G} T , MPK, H0, H1, H2, H3, H4, H5}.

[0082] (2) Smart Contract Deployment

[0083] The authoritative institution TA accepts the input of the smart contract draft, compiles it, and deploys it on the blockchain. After being verified by the blockchain, the smart contract obtains its unique address. When false messages are detected in the system, the smart contract will automatically trace the sender of the information and submit the identity of the false message sender to TA.

[0084] (3) Vehicle registration

[0085] 1) Vehicle V i Randomly select a constant l i ∈Z P * Calculate M i =l i P, N i =l i MPK Then the vehicle will {M i OID i Send it to the authoritative organization TA.

[0086] 2) Authoritative institution TA through After calculating the vehicle's real information and verifying the legality of the information submitted by the user, the authoritative agency TA generates a pseudonym for the vehicle.

[0087] 3) Transmit the pseudonym to vehicle V through a secure channel. i Then it is stored in the on-board unit (OBU).

[0088] (4) Tracking key generation

[0089] 1) The authoritative organization TA randomly selects a constant r. i ∈Z P * Calculate x i =H2(r i ||t i ), where t i It is the tracking key x i The validity period is calculated to track the public key Y. i =x i (P+PID i ).

[0090] 2) The authoritative organization TA will {x i Y i The data is transmitted to the vehicle via a secure channel and stored in the tamper-proof device of the on-board unit (OBU). i Y i PID i It is stored in the secure database of the authoritative organization, TA.

[0091] (5) Vehicle key generation

[0092] Vehicle V i A more authoritative organization, TA, generates a public / private key pair using pseudonyms, and then randomly selects a number n. i ∈Z P * Calculate its private key sk i =H3(n i ||PID i ), public key pk i =sk i P.

[0093] (6) Signature generation

[0094] 1) Attribute value generation

[0095] The signer s selects a public key set R1 = {pk1, pk2, ..., pkn} from n users in a roadside unit. n The corresponding tracking public key set Y′={Y1, Y2, …, Y} is: n} and the corresponding set of pseudonyms M = {PID1, PID2, ..., PID} n}, randomly select different numbers u i v i ∈Z P * Calculate L i K i , where I s =sk s H0(pk s ) is the signature image of message m, used to prevent double-spending attacks.

[0096]

[0097]

[0098] 2) Partial signature generation

[0099] The signer s calculates h = H4(m||R1) and calculates the partial signature c of the generated message m. i d i .

[0100]

[0101]

[0102] 3) Identity tracking signature generation

[0103] The signer s selects a random number w i ∈Z P * Used to generate a partial signature that tracks the signer's identity, and to calculate T. i =w i (P+PID i (i = 1, 2, ..., n), TK i =w i Y i (i = 1, 2, ..., n),

[0104] 4) Signature output

[0105] The traceable expiration signature of the output is T σ =(I s c1, c2, ..., c n d1, d2, ..., d n TK1, TK2, ..., TK n T).

[0106] (7) Signature verification

[0107] 1) Obtaining member public keys

[0108] Since the verification of traceable ring signatures is primarily performed by Roadside Units (RSUs), which collect vehicle information within their coverage area, and the signer (s) obtains the information for generating the traceable ring signature from the RSU, the RSU can easily obtain the public key set R1 = {pk1, pk2, ..., pk...} required for verifying the ring signature. n};

[0109] 2) Traceable ring signature verification

[0110] The validity of the ring signature is determined by verifying the correctness of the following formula. If the formula is verified, message m is received and recorded in the newly generated block; otherwise, message m is rejected.

[0111]

[0112] 3. The method for tracking and punishing malicious vehicles of the present invention

[0113] (1) Malicious vehicle tracking

[0114] 1) Once a malicious user's false message is detected, the smart contract accesses the secure database of the authoritative institution TA via an interface to obtain the traceable key pairs {x} of all ring members. i Y i}, calculate T i =TK i ·x -1 .

[0115] 2) Then through bilinear pairing e(TK) i P+PID i )=e(T i Y i ) Verify T i After verifying the correctness, calculate...

[0116] 3) The sender of the fake message can use bilinear pairing e(T, P+PID) i ) = e(E, Y i )Sure.

[0117] (2) Penalties and revocation of malicious vehicle licenses

[0118] After identifying a malicious vehicle, the authoritative agency TA will determine the punishment based on the number of times the vehicle sent false messages. If the number of malicious acts by a vehicle is between 0 and 3, TA will lower the vehicle's reputation value and record the punishment in the blockchain. TA will also strictly review messages sent by vehicles that have sent false information; sending genuine information will increase the reputation value. For users who have sent false messages more than 3 times or have excessively low reputation values, TA will revoke their registration information and will not allow them to re-register for a certain period. Re-registration of malicious vehicles will be subject to strict review by TA, and re-registration is only permitted after the review is passed.

[0119] If a false message is detected in the system, it will trigger a smart contract deployed in the system to track the sender of the false message. Algorithm 1 provides the overall process of the malicious vehicle tracking mechanism.

[0120]

[0121] 4. Security Guarantee of the Invention

[0122] In the random oracle model, the attacker It can adaptively select information for attack. He is a challenger who can utilize The ability to solve ECDLP. Assuming the attacker... Attack the scheme with a non-negligible probability and challenge the opponent. A series of queries are posed, given P, Q = aP, The goal is to achieve this through cooperation with The challenger's private key is output in the interactive output ECDLP scheme, for which... Select PID i * As the anonymous challenger, Challenger S and the attacker Conduct multiple rounds of interaction.

[0123] attacker For the signer's PID i * Output another message m * The signature, constructed in a similar way, The same result can be obtained; two valid ring signatures are output as T. σ and T σ * . The result of a = MSK is used as a scheme output of ECDLP. However, ECDLP is difficult to implement, so the two are contradictory. That is to say, the scheme of this invention satisfies the unforgeability requirement. Through a similar challenger game, with multiple rounds of interaction between the challenger and the attacker, this invention satisfies anonymity and traceability. Since Ethereum is used as the underlying architecture when building the system, this invention also inherits the security of blockchain technology and can resist network attacks.

[0124] 5. Computational overhead of the present invention

[0125] The computational overhead generated during the secure sharing of traffic data mainly consists of key generation, signature generation, and malicious vehicle tracking. Table 1 shows the comparison results between the computational overhead of this invention for secure sharing of traffic data and existing schemes (Fujisaki E et al. in "IEICE transactions on fundamental electronics, communications and computer sciences" 2008, 91(1) "Traceable ring signature"; Bouakaz S et al. in "Journal of Information Security and Applications" 2020, "A certificateless ring signature scheme with batch verification for applications in VANET"; MaoX et al. in "Security and Communication Networks" 2021, "Linkable Ring Signature Scheme Using Biometric Cryptosystem and NIZK and Its Application"; Lai C et al. in "Peer-to-Peer Networking and Applications" 2022, 15(3) "Secure medical datasharing scheme based on traceable ring signature and blockchain"). p T represents a bilinear pairing operation event. m T represents the time of the dot product operation. e T represents the exponential operation time. h This represents the hash-to-block operation time. The experimental setup was: i7-10870H CPU @ 2.20GHz, 16GB RAM, using an HP laptop. The software environment was based on Ubuntu 18.04, implemented using Python 3.6 and PYPBC 0.2, and constructed using type A curves from the PBC library to create a symmetric prime-order bilinear group. T p T m T e and T h The execution times were 1.4481ms, 0.3526ms, 1.1518ms, and 2.4538ms, respectively.

[0126] Table 1 Comparison of computational costs

[0127]

[0128]

[0129] Based on the time consumption of each operation in Table 1 and the specific steps in our plan, we calculated the time consumption of the five steps in the plan, with the number of ring members n ranging from 20 to 100. The results are as follows. Figure 5 As shown.

[0130] In our experiments, with the number of ring members n = 100, compared to the schemes of Fujisaki et al., Bouakaz et al., and Lai et al., our scheme reduced key generation costs by approximately 31.65%, 61.84%, and 70.34%, respectively. Although the key generation process of our scheme is longer than that of Mao et al., the tracking key and vehicle key in our scheme are pre-generated by the TA and the vehicle during vehicle registration and stored in the vehicle's OBU, thus not affecting the communication efficiency of VANETs. We set the number of ring members n from 20 to 100, and the computational costs of our scheme and other ring signature schemes are as follows: Figure 6 As shown.

[0131] Figure 7 This section compares the computational cost of signature generation for our proposed method with those of Fujisaki et al., Bouakaz et al., and Lai et al. The computational cost of signature generation is linearly related to the number of ring members. Our method has the lowest computational cost compared to other ring signature schemes. With 100 ring members, our scheme generates a ring signature in just 256.22 milliseconds, saving time on signature exchange generation and improving the efficiency of VANETs. In Fujisaki et al.'s scheme, more dot multiplication, exponentiation, and two additional hash-to-block operations are required, resulting in a high computational cost; generating a ring signature takes (5n+1)T. e +(3n-2)T m +3T h Compared to our previous approach, by setting the number of ring members n=100, we reduced our computational cost by 62.84%.

[0132] Figure 8 A comparison of the computational costs of signature verification is shown. It demonstrates that the computational cost increases with the number of ring members. The computational time required for signature verification in this invention is less than that in the schemes of Fujisaki et al., Bouakaz et al., and Lai et al.

[0133] Comparison of computational costs in the tracing process (see) Figure 9 As the number of members in the circle increases, the time consumed in the tracking process also increases. In our scheme, with 100 circle members, it takes 324.88 milliseconds to track the true signer of message m. Compared with the schemes of Bouakaz et al. and Lai et al., our scheme has lower computational overhead. According to the scheme of Fujisaki et al., when the number of circle members n≤42, our scheme is able to track the true signer in a shorter time; when the number of circle members n>42, our scheme has a larger computational overhead during the tracking process.

[0134] 6. Communication overhead of the present invention

[0135] Table 2 compares the communication overhead of the traceable ring signature generated by this invention during data sharing with the schemes of Bouakaz et al., Mao et al., and Lai et al. According to Chen et al.'s description in "CPP-CLAS: efficient and conditional privacy-preserving certificateless aggregate signature scheme for VANETs" in IEEE Internet of Things Journal 2021, 9(12), Z P * The sizes of the elements in G1 are 20×2=40 bytes and 64×2=128 bytes, respectively.

[0136] Table 2 Comparison of Communication Overhead

[0137]

[0138]

[0139] In this invention, the transmission parameters during vehicle registration, key generation, and signature generation mainly include: vehicle pseudonym (PID). i ∈G1, Tracking private key x i ∈Z p * Vehicle public key Y i ∈G1, Message signature T σ And so on. We set the ring member n to between 20 and 100, and the communication overhead of our scheme is as follows: Figure 10 As shown.

[0140] Figure 11The communication overhead during signature transmission was compared with that of Bouakáz et al., Mao et al., and Lai et al. The communication overhead increases with the increase of the number of ring members. The method proposed in this invention consumes less communication overhead for signature transmission than the aforementioned schemes. When the number of ring members n is set to 100, the communication overhead of our scheme is only 20968 bytes, which is a 29.86% reduction compared to Lai et al.'s scheme.

[0141] 7. Performance evaluation of the present invention

[0142] Table 3 evaluates the performance of the traffic data secure sharing method proposed in this invention. Compared with the schemes of Fujisaki et al., Bouakaz et al., Mao et al., and Lai et al., this invention uses blockchain as the underlying architecture to achieve distributed storage of traffic data. It inherits the characteristics of blockchain such as anonymity, traceability, and distributed architecture. Smart contracts are deployed in the blockchain to track malicious users who disrupt normal traffic order. Using a traceable ring signature algorithm, it not only achieves conditional privacy protection but also reduces computational and communication overhead, thereby improving the efficiency of VANETs.

[0143] Table 3 Performance Evaluation

[0144] Unforgeability × √ √ √ √ Anonymity √ √ √ √ √ Traceability √ √ × √ √ Distributed architecture × × × √ √ Privacy protection × √ √ × √ Using smart contracts × × × × √

[0145] Table 3 compares and analyzes the proposed secure traffic data sharing method based on blockchain and traceable ring signatures with the other solutions mentioned above from six aspects: unforgeability, anonymity, traceability, distributed framework, privacy protection, and use of smart contracts. The comparison results show that our solution has better performance and feasibility.

Claims

1. A secure data sharing method for traffic systems based on blockchain and traceable ring signatures, characterized by: Follow these steps: (S01): The authoritative institution TA generates the system master public key MPK, master private key MSK, and system hash function during system initialization. All Roadside Unit (RSU) nodes together form a public blockchain for storing traffic incidents. During system initialization, the authoritative body initializes an Ethereum blockchain within the nodes. Based on the draft smart contract for tracking malicious users agreed upon by all parties, the authoritative body (TA) writes the smart contract and deploys it on the blockchain. (S02): Vehicle V i Before joining a vehicle-mounted self-organizing network, users need to register by submitting their real identity information to an authoritative organization (TA). After verifying the application information provided by the vehicle, the TA will then process the application based on the vehicle information. i Driver ID i Generate vehicle pseudonym PID i It is stored in the on-board unit (OBU); In addition, the authoritative organization will generate a tracking public-private key pair for successfully registered vehicles for tracing malicious vehicles. These tracking key pairs have time limits and need to be regenerated by the authoritative organization periodically. Vehicles in the system use their onboard units (OBUs) based on the pseudonym PID output by the authoritative organization's TA (Technical Expertise) system. i Generate your own public key PK i Private key sk i ; (S03): When a sudden traffic incident occurs in the system, the event signer... The event is described using the on-board unit (OBU); For the processed message m, the signer s uses a traceable ring signature to sign the message, and the signer s then sends the signed message... V towards surrounding vehicles i Broadcast to the roadside unit (RSU); (S04): Roadside Unit RSU receives signatory broadcast message Next, a traceable ring signature is created on message m. The correctness of the message is verified. Once the verification is successful, the Roadside Unit (RSU) stores the message in the blockchain and broadcasts it to the entire system. (S05): When false information sent by a malicious vehicle is detected, the smart contract deployed in the blockchain will verify the traceable ring signature in the message. The system identifies the signer of the false message; the authoritative agency submits the information of the malicious vehicle to the traffic management department for punishment or revocation of its registration information, and then records the punishment result on the blockchain.

2. The method for secure sharing of traffic data based on blockchain and traceable ring signatures according to claim 1, characterized in that: The system generation described in step (S01) is performed as follows: (1) System initialization Inputting the security parameter λ, the authoritative body TA selects two cyclic multiplicative groups G1 and G2 with the same order q. T Where q is a large prime number, and P is a generator of the multiplicative group G1, there exists a bilinear pairing. ; The authoritative organization TA selects a random number. Used as the master private key, and used to calculate the master public key. Define a hash function , , , , , Then the system parameters are ; (2) Deployment of smart contracts The authoritative institution TA accepts the input of the smart contract draft, compiles it, and deploys it on the blockchain. After being verified by the blockchain, the smart contract obtains its unique address. When false messages are detected in the system, the smart contract will automatically trace the sender of the information and submit the identity of the false message sender to TA.

3. The method for secure sharing of traffic data based on blockchain and traceable ring signatures according to claim 1, characterized in that: The step (S02) of generating the tracking public-private key pair is performed as follows: (1) Vehicle registration Vehicle V i Randomly select a constant ,calculate , , Then the vehicle will Send to the authoritative organization TA, the authoritative organization TA will then process it. After calculating the vehicle's real information and verifying the legality of the information submitted by the user, the authoritative agency TA generates a pseudonym for the vehicle. And transmit the pseudonym to vehicle V through a secure channel. i Then it is stored in the on-board unit (OBU); (2) Tracking key generation The authoritative organization TA randomly selects a constant. ,calculate , where t i It is the tracking key x i The validity period is used to calculate and track the public key. Then, the authoritative agency TA will It is sent to the vehicle through a secure channel and stored in the tamper-proof device of the on-board unit (OBU). Stored in the secure database of the authoritative organization, TA; (3) Vehicle key generation Vehicle V i Generate a public / private key pair based on the pseudonym generated by the authoritative organization TA, and randomly select a number. Calculate its private key Public key .

4. A method for secure sharing of traffic data based on blockchain and traceable ring signatures as described in claim 1, characterized in that: The traceable ring signature described in step (S03) signs the message as follows: (1) Attribute value generation The signer s selects a set of public keys from n users in the roadside unit. The corresponding public key set for tracking and the corresponding kana set Randomly select different numbers calculate ,in It is the signature image of message m, used to prevent double-spending attacks; (1) (2) (2) Partial signature generation Signer's calculation And calculate the partial signature c of the generated message m. i d i ; (3) (4) (3) Identity tracking signature generation The signer s selects a random number Used to generate a partial signature that tracks the signer's identity, and calculate , , ; (4) Signature output The output traceable ring signature is .

5. A method for secure sharing of traffic data based on blockchain and traceable ring signatures according to claim 1, characterized in that: The traceable ring signature verification described in step (S04) is performed as follows: (1) Obtaining member public key Since the verification of traceable ring signatures is primarily performed by Roadside Units (RSUs), which collect information about vehicles entering their coverage area, and the signer (s) obtains the information for generating the traceable ring signature from the RSU, the RSU can easily obtain the set of ring member public keys required for verifying the ring signature. ; (2) Traceable ring signature verification The validity of the ring signature is determined by verifying the correctness of the following formula. If the formula is verified, message m is received and recorded in the newly generated block; otherwise, message m is rejected. (5)。 6. A method for secure sharing of traffic data based on blockchain and traceable ring signatures as described in claim 1, characterized in that: The malicious vehicle tracking and punishment mechanism described in step (S05) is implemented as follows: (1) Malicious vehicle tracking Once a malicious user's false message is detected, the smart contract accesses the secure database of the authoritative institution TA via an interface to obtain traceable key pairs for all ring members. ,calculate Then through bilinear pairing Verify T i After verifying the correctness, calculate... Senders of fake news can use bilinear pairing. Sure; (2) Penalties and revocation of penalties for malicious vehicles After identifying the malicious vehicle, the authoritative agency TA will determine the punishment based on the number of times the malicious vehicle sends false messages. If the number of times the malicious vehicle commits malicious acts... At that time, the authoritative agency TA will lower the vehicle's reputation value and record the penalty in the blockchain. It will also strictly review the messages sent by vehicles that have sent false information, while sending true information can increase the reputation value. The number of times false messages were sent For users with excessively low credit scores, the authoritative agency will revoke their registration information and will not allow them to re-register for a certain period of time; the re-registration of malicious vehicles will be subject to strict review by the authoritative agency TA, and can only be re-registered after the review is passed.