A lightweight fog computing-based internet of vehicles data sharing method
By employing lightweight fog computing and multi-authority access control methods, the computational overhead and security issues of data sharing in vehicular ad hoc networks are resolved, enabling fast and secure data interaction and decryption, thereby improving the system's stability and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ANHUI UNIV
- Filing Date
- 2023-05-24
- Publication Date
- 2026-04-24
AI Technical Summary
In existing technologies, data sharing in vehicle ad hoc networks faces challenges such as network bandwidth bottlenecks, data security risks, and high computational overhead. Traditional cloud computing models and encryption mechanisms cannot meet the requirements for real-time performance and security, and fog computing nodes have excessively high complexity and computational resource requirements.
A lightweight fog computing-based data sharing method is adopted, which uses multi-authority access control and outsourced computing to partially decrypt data using fog cars, reducing the computational load on vehicles. A lightweight CP-ABE scheme is designed to achieve rapid data interaction and secure transmission.
It effectively reduces the vehicle's computational overhead, improves data interaction speed, enhances system stability and security, reduces the risk of single points of failure, and achieves faster data decryption and higher security.
Smart Images

Figure CN116506849B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to vehicle-to-everything (V2X) data sharing technology, specifically to a V2X data sharing method based on lightweight fog computing. Background Technology
[0002] Vehicular Ad Hoc Networks (VANETs) refer to onboard devices in vehicles that utilize wireless communication technology to effectively leverage dynamic information from all vehicles within an information network platform, providing various functional services during vehicle operation. With the rapid growth in the number of vehicles and the continuous development of communication technology, the demand for vehicle safety and privacy protection is becoming increasingly urgent, making VANETs a research hotspot of common interest to governments, research institutions, and vehicle manufacturers. VANETs mainly consist of the following components: Trusted Authority (TA), Roadside Units (RSUs), vehicles, and Traffic Management Centers (TMCs). In VANETs, the two main communication types are vehicle-to-vehicle (V2V) communication and vehicle-to-roadside unit (V2I) communication. In V2V communication, vehicles periodically broadcast traffic-related information such as their speed, location, and route, which can be used to improve driving safety and reduce traffic accidents. In V2I communication, infrastructure such as RSUs is required to provide traffic-related services to nearby vehicles.
[0003] However, in vehicular ad hoc networks, the need for real-time processing and analysis of massive amounts of traffic data presents numerous challenges to traditional cloud computing models, including network bandwidth bottlenecks and data security risks. The widespread deployment of vehicular ad hoc networks largely depends on establishing secure and reliable mechanisms to provide effective data services. Furthermore, traditional encryption mechanisms may not be suitable for ensuring the security of information transmission in vehicle communications. This is because traditional Public Key Infrastructure (PKI) requires the receiving vehicle's public key to encrypt each message. In other words, if multiple vehicles share an encrypted message, the message will be encrypted multiple times, generating different versions of ciphertext, which cannot meet the real-time requirements of message transmission. Therefore, for communication between vehicles in ad hoc networks, using symmetric encryption methods increases the communication cost and security risks associated with exchanging session keys between message senders and receivers. In conclusion, achieving real-time access control and privacy protection for message transmission is a significant challenge in vehicular communication.
[0004] CP-ABE is an encryption technique for one-to-many data sharing. Each ciphertext has an access control policy defined by the data owner. Each user's private key is associated with their own attributes, and a user can decrypt the ciphertext if and only if their attributes satisfy the access control policy. However, traditional CP-ABE uses a single central authority to generate keys associated with each user's attributes, which can easily create a single point of failure in large-scale systems like vehicular networks (VANETs), leading to system congestion. Furthermore, vehicles have limited computing power, and CP-ABE, based on bilinear pairing, incurs significant computational overhead, making current CP-ABE schemes unsuitable for direct application in VANETs. Therefore, CP-ABE-based VANET data sharing has been extensively researched. However, in vehicular networks, a vehicle may hold attributes granted by multiple permissions, and the vehicle may share data with users managed by different permissions. To address the situation where user attributes originate from multiple permissions, several multi-permission schemes have been proposed.
[0005] Multi-authorization schemes allow multiple independent authorizing agencies to monitor attributes and distribute corresponding keys, but this involves a central authorizing agency managing all attributes across different attribute agencies, which can be inefficient. Later, outsourced decryption of ABE ciphertexts was introduced, suggesting that some encryption and decryption computations be outsourced to the cloud. Outsourced computation methods can effectively solve the efficiency problem, but also introduce security issues that urgently need to be addressed. In data outsourcing, fog computing is considered a promising paradigm for improving the performance of critical latency applications, maximizing the utilization of vehicle communication and computing resources. Therefore, using fog computing to provide data-sharing computation for vehicles is one of the promising technologies.
[0006] While some existing vehicle-to-everything (V2X) technologies based on fog computing utilize fog computing to reduce communication overhead, the cryptographic schemes designed for specific encryption and decryption operations still require considerable computational overhead.
[0007] For example, patent CN_108718334_B proposes a method for securely uploading network sensing data based on vehicle-to-everything (V2X) group perception. However, in the system initialization phase, each private vehicle and each public bus fog unit within the system needs to be simultaneously authenticated to obtain the tamper-proof device password (PSW). This significantly increases costs and management complexity, hindering the registration of new vehicles and the deregistration of old ones. Furthermore, the method selects public buses as the public fog unit, but in areas such as elevated roads and rural areas where there are almost no public buses, its applicability is limited. Regarding the complexity of the fog computing nodes, public bus fog units need to collect, verify, and encrypt the uploaded sensing data, requiring substantial computing resources and storage space. The scalability and maintainability of the system must be considered; otherwise, it may impact system performance. This solution has several potential drawbacks, such as the need to deploy a V2X group perception system, select suitable public bus fog units, low data transmission efficiency, security issues, and complex fog computing nodes. These drawbacks need to be considered and optimized as much as possible to improve the system's stability and reliability.
[0008] For example, patent CN_111343273_B proposes an attribute-based strategy-hidden outsourced signature method in a vehicle-to-everything (V2X) environment. This method introduces multiple attribute authorities into the V2X environment, solving problems such as excessive system load and potential key escrow attacks caused by a central trusted authorization center managing and publishing all users and their keys in traditional single-authority V2X environments. However, the design of the first key pair corresponding to each attribute authority is overly complex, resulting in significant computational overhead. This overly complex key design also requires additional computational overhead in subsequent encryption and decryption. While enhancing confidentiality, the excessive computational overhead may lead to data loss due to delayed decryption. Summary of the Invention
[0009] Purpose of the invention: The purpose of this invention is to address the shortcomings of existing technologies and provide a vehicle-to-everything (V2X) data sharing method based on lightweight fog computing. By outsourcing computation to fog vehicles with computing resources, the computational overhead of vehicle data acquisition is greatly reduced. Furthermore, a multi-authority access control scheme is adopted to prevent single-point performance bottlenecks that may occur in individual attribute institutions, thereby preventing system inefficiency.
[0010] Technical solution: The present invention provides a vehicle-to-everything (V2X) data sharing method based on lightweight fog computing, comprising the following steps:
[0011] Step (1) System Initialization
[0012] System initialization is completed by storing the system public key PK and system master key MK in the public cloud through a single trusted authority TA;
[0013] Step (2) Vehicle Registration
[0014] The vehicle applies for legitimate identity registration with a trusted authority (TA); the trusted authority (TA) assigns a unique identifier (uid) to the vehicle and generates the vehicle's public key (UPK). uid Private key USK uid and Certificate uid In addition, vehicles on traffic facilities that are within the communication range of the Roadside Unit (RSU) and equipped with computing and storage resources can voluntarily apply to become FVs.
[0015] Step (3), AA certification of multiple attribute authorization agencies
[0016] If an attribute authorization organization (AA) wants to authenticate the attributes of a vehicle, it needs to apply to a trusted authority (TA) first. After authentication, the TA assigns a unique identifier (Aid) to the legitimate AA and randomly selects a private key (k). Aid ∈Z p Simultaneously, the system master key MK is sent to the certified attribute authority AA; vehicles requiring attribute authentication will send a certificate Cert to the attribute authority AA. uid AA will execute the Keygen algorithm to generate a partial attribute key (PSK) for the vehicle. uid.aid ;
[0017] Step (4), Information Encryption and Outsourcing Request
[0018] Roadside Units (RSUs) use the Enc algorithm with encrypted CT. AES Information m is propagated in a specific form. Upon receiving information m, the source vehicle SV determines whether its current computing power is sufficient to decrypt the information in time. If the source vehicle SV cannot decrypt the ciphertext CT in time, it submits a computation outsourcing request to the Roadside Unit (RSU). Based on the received request, the Roadside Unit (RSU) first verifies whether the source vehicle SV meets the decryption conditions, and then allocates a suitable fog vehicle FV to the source vehicle SV according to the current environment (e.g., the number and computing power of fog vehicles FVs). The specific method for decrypting the ciphertext is as follows:
[0019] To restrict decryption to only users with a specific set of attributes, the attribute set needs to be associated with an access policy. Using a monotonically increasing Boolean formula, which is easy to express, the attributes are transformed into an LSSS access structure represented as (M, ρ), where M is an n×1 matrix related to the specific set of attributes associated with the unique access policy, and n is a variable depending on the LSSS flipping method and the definition of the monotonically increasing Boolean formula. The function ρ maps each row of M to a specific attribute, defined as I = {i, ρ(i) ∈ S}, where... And define {ω i ∈Zp}, i∈I is a set of constants; a secret parameter s∈Zp is randomly selected to encrypt the symmetric key key; a vector υ=(s,y2,y3,...,yn)T∈Z is defined. p n y2, y3, ..., yn are randomly selected to share parameter s; for each i = 1 to l, λ is calculated. i =M i υ, where M i It is a vector associated with the i-th row of M; based on the access structure of M, {λ i} is an effective sharing of secret s, only if ∑ i ∈I, ω i λ i =s; randomly select values r1, r2, ..., rl∈Zp;
[0020] Use the public key PK generated by TA to compute the ciphertext CT;
[0021] CT = (C0, C1, C′1, C 3,i D 3,i )
[0022] C0 = ENC key (m)
[0023]
[0024]
[0025]
[0026]
[0027] Where C0 refers to the ciphertext, and C1, C'1, C 3,i and D 3,i These are all intermediate calculation parameters;
[0028] Step (5): Execute the outsourced task of partially decrypting information.
[0029] The trusted fog vehicle (FV) executes the Partdec algorithm to perform a partially complex decryption calculation, obtaining a partially decrypted ciphertext TCT; then, the fog vehicle (FV) sends the TCT to the source vehicle (SV).
[0030] Step (6): Decrypt all information
[0031] The source vehicle SV uses the AES algorithm to finally decrypt the received partially decrypted TCT and obtain the plaintext.
[0032] Furthermore, the detailed process of step (1) is as follows:
[0033] Step (1-1): Use the input security parameter λ and system attribute set U to output the system's public key PK and master key MK;
[0034] Step (1-2): Select a large prime number p, and then select a group G and its generators g and h, where group G is a prime group of order p;
[0035] Steps (1-3): Define a bilinear mapping e: G×G→G T ;
[0036] Steps (1-4): Randomly select group elements h1, ..., h U ∈G is associated with the attributes in U;
[0037] Steps (1-5): The system randomly selects two exponents α and a∈Zp, and finally outputs the public key PK and the master key MK:
[0038] PK:
[0039] MK(α, a).
[0040] Furthermore, the specific process of vehicle registration in step (2) is as follows:
[0041] Step (2-1): The Trusted Authority (TA) verifies the vehicle's OBU module to determine if it is a valid device and its UID. i This refers to the identity, ID of the i-th user. i This refers to the identity of the i-th vehicle;
[0042] Step (2-2): The TA obtains the vehicle's attribute information, including location, direction, speed, and registration time;
[0043] Step (2-3): TA applies for a unique identifier uid for the vehicle and randomly selects the vehicle's private key k. uid Generate a CP-ABE public key UPK for the source vehicle SV. uid Private key USK uid and Certificate uid ;
[0044]
[0045] USK uid =(k uid )
[0046] Cert uid Includes UPK uid And user attribute set S.
[0047] Furthermore, in step (3), the attribute authorization agency AA executes the Keygen algorithm to generate a partial attribute key PSK for the vehicle. uid.aid The specific formula is:
[0048]
[0049] k uid For vehicle private keys; L1, K x , These are all intermediate calculation parameters.
[0050] Furthermore, the specific process of the outsourced task of performing partial information decryption in step (5) is as follows:
[0051] Step (5-1): After receiving the encrypted text broadcast by the RSU, the vehicle determines whether it has sufficient computing power and whether its current position and speed can download the information completely from the current RSU in time.
[0052] Step (5-2): If there is insufficient computing power, the vehicle will be considered the source vehicle SV. The source vehicle SV requests the RSU to outsource the complex decryption operation to a nearby vehicle with the necessary capabilities. The request message includes a portion of the attribute key PSK. uid.aid ;
[0053] Step (5-3): After receiving the outsourced computing task, the trusted FV uses PSK. uid.aid The Partdec algorithm is executed to convert the original ciphertext CT into TCT for partial decryption;
[0054] Step (5-4): Determine whether the attribute set of the fog vehicle FV satisfies the access structure embedded in the ciphertext. If not, the data cannot be decrypted.
[0055] Step (5-5): When executing the Partdec algorithm, the input is a partial attribute key (PSK). uid.aid And a ciphertext CT represented as access structure (M, ρ), then the fog vehicle FV converts the ciphertext CT into a partially decrypted ciphertext TCT: TCT = (C0, C2, C1', C... 3,i D 3,i ).
[0056] Furthermore, the specific process of decrypting all information in step (6) is as follows:
[0057] Step (6-1): The trusted fog vehicle FV will send the partially decrypted TCT obtained from Partdec to the source vehicle SV;
[0058] Step (6-2): Execute the Fulldec algorithm to decrypt the AES key, then you can use the Dec decryption algorithm for AES. AES (CT AES → key to retrieve plaintext information;
[0059]
[0060] Beneficial effects: The lightweight fog computing-based vehicle-to-everything (V2X) data sharing method of the present invention can reduce computational overhead and achieve faster data interaction in V2X; compared with the prior art, the present invention has the following advantages:
[0061] (1) This invention adopts multi-authorization attribute authentication to solve the single point of failure problem that is easy to occur in single authorization scheme. It includes a single trusted authority (TA) for public cloud storage and multiple attribute authorities (AA). The heavy work of verifying the legality of user attributes is shared by multiple AA, which can independently complete the legality verification of some user attributes.
[0062] (2) The present invention realizes the reconstruction of the CP-ABE scheme and designs a lightweight CP-ABE scheme that reduces the computational load of the vehicle unit while maintaining the fine granularity, flexibility and safety of CP-ABE.
[0063] (3) The security of the cryptographic protocol of the present invention is evaluated through formal security analysis and it can resist a variety of attacks. Compared with other related schemes, it has stronger security. Attached Figure Description
[0064] Figure 1 This is a system model diagram of the present invention;
[0065] Figure 2 This is a line graph comparing the computational overhead of the system initialization process of this invention.
[0066] Figure 3 A line graph showing the computational overhead of the key generation process in this invention;
[0067] Figure 4 A line graph comparing the computational overhead of the encryption process in this invention;
[0068] Figure 5 This is a line graph comparing the computational overhead of the decryption process of this invention.
[0069] Figure 6 This is a line graph comparing the computational costs of the entire process of this invention. Detailed Implementation
[0070] The technical solution of the present invention will be described in detail below, but the scope of protection of the present invention is not limited to the embodiments described.
[0071] like Figure 1 As shown, the vehicle-to-everything (V2X) data sharing method based on lightweight fog computing of the present invention involves the following participating entities: a Trusted Authority (TA) with overall authorization, multiple Attribute Authorization Agencies (AAs), Roadside Units (RSUs) along the road, Source Vehicles (SVs) receiving data, and Fog Vehicles (FVs) that outsource decryption. The Trusted Authority (TA) possesses sufficient computing, storage, and communication capabilities; and is responsible for the initialization of the entire system, providing registration services for vehicles and Attribute Authorization Agencies, setting system parameters for each attribute of the general attribute set, and generating public keys. During the system initialization phase, it assigns a unique UID to each user and a unique hi attribute permission to each attribute privilege. For key requests from users, the TA is responsible for generating public-private key pairs and issuing certificates to users based on their UIDs. The TA is also responsible for authenticating Attribute Authorization Agencies (AAs) and assigning a unique Aid to each AA to generate partial attribute keys for users.
[0072] The Attribute Authorization Authority (AA) is responsible for verifying the legitimacy of user attributes and generating partial attribute keys for users who pass the verification. Each AA manages a disjoint set of attributes, and each AA can independently perform this process for any user. When an AA is selected, it will verify the user's legitimate attributes through manual verification or authentication protocols and generate a partial attribute key associated with that attribute.
[0073] Roadside Units (RSUs) communicate directly with and transmit information to vehicles via Dedicated Short Range Communication (DSRC). Specifically, the RSU manages all outsourced tasks within its communication range. Each vehicle is equipped with an Onboard Unit (OBU), and this invention relates to two types of vehicles: source vehicles (SVs) requiring real-time services and fog vehicles (FVs) with abundant surplus computing power. Fog vehicles may include parked vehicles, public transportation vehicles, or transportation facilities equipped with computing resources. These vehicles or facilities with sufficient computing resources proactively apply to become vehicles in exchange for certain rewards, and the operating unit allocates resources to suitable vehicles to ensure timely and effective information services.
[0074] The vehicle-to-everything (V2X) data sharing method of this embodiment includes the following steps:
[0075] Step (1) System Initialization
[0076] System initialization is completed by storing the system public key PK and system master key MK in the public cloud through a single trusted authority TA;
[0077] Step (1-1): Use the input security parameter λ and system attribute set U to output the system's public key PK and master key MK;
[0078] Step (1-2): Select a large prime number p, and then select a group G and its generators g and h, where group G is a prime group of order p;
[0079] Steps (1-3): Define a bilinear mapping e: G×G→G T ;
[0080] Steps (1-4): Randomly select group elements h1, ..., h U ∈G is associated with the attributes in U;
[0081] Steps (1-5): The system randomly selects two exponents α and a∈Zp, and finally outputs the public key PK and the master key MK:
[0082] PK:
[0083] MK(α, a);
[0084] Step (2) Vehicle Registration
[0085] Step (2-1): The Trusted Authority (TA) verifies the vehicle's OBU module to determine if it is a valid device and its UID. i This refers to the identity, ID of the i-th user. i This refers to the identity of the i-th vehicle;
[0086] Step (2-2): The TA obtains the vehicle's attribute information, including location, direction, speed, and registration time;
[0087] Step (2-3): TA applies for a unique identifier uid for the vehicle and randomly selects the vehicle's private key k. uid Generate a CP-ABE public key UPK for the source vehicle SV. uid Private key USK uid and Certificate uid ;
[0088]
[0089] USK uid =(k uid )
[0090] Cert uid Includes UPK uid And user attribute S; Step (3), multiple attribute authorization agency AA certification
[0091] If an attribute authorization organization (AA) wants to authenticate the attributes of a vehicle, it needs to apply to a trusted authority (TA) first. After authentication, the TA assigns a unique identifier (Aid) to the legitimate AA and randomly selects a private key (k). Aid ∈Z pSimultaneously, the master key MK is sent to the certified attribute authority AA; vehicles requiring attribute authentication will send the certificate Cert to the attribute authority AA. uid AA will execute the Keygen algorithm to generate a partial attribute key (PSK) for the vehicle. uid.aid ;
[0092]
[0093] Step (4), Information Encryption and Outsourcing Request
[0094] Roadside Units (RSUs) use the Enc algorithm with encrypted CT. AES If the source vehicle SV cannot decrypt the ciphertext CT in time, it submits a computation outsourcing request to the Roadside Unit (RSU). Upon receiving the request, the RSU first verifies whether the source vehicle SV meets the decryption conditions, and then allocates a suitable fog vehicle FV to the source vehicle SV based on the current environment (e.g., the number and computing power of fog vehicles FVs). The specific method for decrypting the ciphertext is as follows:
[0095] Using a monotonically increasing Boolean formula, attributes are easily expressed as an LSSS access structure represented as (M, ρ), where M is an n×l matrix related to a specific set of attributes associated with a unique access strategy, and n is a variable depending on the LSSS flip method and the definition of the monotonically increasing Boolean formula; the function ρ maps each row of M to a specific attribute, defined as I = {i, ρ(i) ∈ S}, where And define {ω i ∈Zp}, i∈I is a set of constants; a secret parameter s∈Zp is randomly selected to encrypt the symmetric key key; a vector υ=(s,y2,y3,...,yn)T∈Z is defined. p n y2, y3, ..., yn are randomly selected to share parameter s; for each i = 1 to l, λ is calculated. i =M i υ, where M i It is a vector associated with the i-th row of M; based on the access structure of M, {λ i} is an effective sharing of secret s, only if ∑ i ∈I, ω i λ i =s; randomly select values r1, r2, ..., rl∈Zp;
[0096] Use the public key PK generated by TA to compute the ciphertext CT;
[0097] CT = (C0, C1, C′1, C 3,i D a,i )
[0098] C0 = ENC key (m)
[0099]
[0100]
[0101]
[0102]
[0103] Step (5): Execute the outsourced task of partially decrypting information.
[0104] The trusted fog vehicle (FV) executes the Partdec algorithm to perform a partially complex decryption calculation, obtaining a partially decrypted ciphertext TCT; then, the fog vehicle (FV) sends the TCT to the source vehicle (SV).
[0105] Step (5-1): After receiving the encrypted message broadcast by the RSU, the vehicle determines whether it has sufficient computing power, location and speed to completely download the information from the current RSU.
[0106] Step (5-2): If there is insufficient computing power, the vehicle will be considered the source vehicle SV. The source vehicle SV requests the RSU to outsource the complex decryption operation to a nearby vehicle with the necessary capabilities. The request message includes a portion of the attribute key PSK. uid.aid ;
[0107] Step (5-3): After receiving the outsourced computing task, the trusted FV uses PSK. uid.aid The Partdec algorithm is executed to convert the original ciphertext CT into TCT for partial decryption;
[0108] Step (5-4): Determine whether the attribute set of the fog vehicle FV satisfies the access structure embedded in the ciphertext. If not, the data cannot be decrypted.
[0109] Step (5-5): When executing the Partdec algorithm, the input is a partial attribute key (PSK). uid.aid And a ciphertext CT represented as access structure (M, ρ), then the fog vehicle FV converts the ciphertext CT into a partially decrypted ciphertext TCT: TCT = (C0, C2, C1', C... 3,i D 3,i )
[0110] Step (6): Decrypt all information, that is, the source vehicle SV uses the AES algorithm to finally decrypt the received partially decrypted TCT and finally obtain the plaintext;
[0111] Step (6-1): The trusted fog vehicle FV will send the partially decrypted TCT obtained from Partdec to the source vehicle SV;
[0112] Step (6-2): Execute the Fulldec algorithm to decrypt the AES key, then you can use the Dec decryption algorithm for AES. AES (CT AES → key to retrieve plaintext information;
[0113]
[0114] Example:
[0115] The execution times of different cryptographic operations in this invention are shown in Table 1. Bilinear operations were performed using a pairwise cryptographic library (V2.0.0) in the Java programming language. Simulations were conducted on a Win10 PC with an Intel Core i7-12700K CPU at 2.1.00 GHz and 8 GB of RAM. For each cryptographic operation, the experiment was repeated 1000 times, and the average value was calculated as the final result.
[0116] Table 1. Execution time of different cryptographic encryption operations in this invention;
[0117]
[0118] The computational overhead of the technical solution of this invention in actual application and the computational overhead of other solutions are compared in Table 2.
[0119] Table 2 shows the calculation results of the overhead of this invention and other solutions.
[0120] The computational cost of the technical solution of this invention in practical application, and a comparison of the computational cost of each part and the total computational cost with other existing solutions, are as follows: Figures 2 to 6 As shown, compared to the total overhead, the present invention (located at the bottom of the figure) has a clear advantage as the number of attributes gradually increases.
Claims
1. A vehicle-to-everything (V2X) data sharing method based on lightweight fog computing, characterized in that, Includes the following steps: Step (1) System Initialization System initialization is completed by storing the system public key PK and system master key MK in the public cloud through a single trusted authority TA; Step (2) Vehicle Registration Vehicles apply for legal identity registration with a trusted agency (TA); The trusted authority (TA) assigns a unique identifier (uid) to each vehicle and simultaneously generates the vehicle's public key. Private key and certificates In addition, vehicles on traffic facilities within the communication range of roadside units (RSUs) and equipped with computing and storage resources can voluntarily apply to become fog vehicles (FVs). Step (3), AA certification of multiple attribute authorization agencies If an attribute authorization organization (AA) wants to authenticate the attributes of a vehicle, it must first apply to a trusted authority (TA). After authentication, the TA assigns a unique identifier (Aid) to the legitimate AA and randomly selects a private key. Simultaneously, the system master key MK is sent to the certified attribute authority AA; vehicles requiring attribute authentication will send certificates to the attribute authority AA. AA will execute the Keygen algorithm to generate partial attribute keys for the vehicle. ; Step (4), Information Encryption and Outsourcing Request Roadside Units (RSUs) use the Enc algorithm with encrypted CT. AES The information m is transmitted in a form. After receiving the information m, the source vehicle SV will determine whether its current computing power is sufficient to decrypt the information in time. If the source vehicle SV cannot decrypt the ciphertext CT in time, it will submit a computing outsourcing request to the RSU. Upon receiving a request, the Roadside Unit (RSU) first verifies whether the source vehicle (SV) meets the decryption conditions, and then assigns a suitable fog vehicle (FV) to the source vehicle (SV) based on the current environment. The specific method for decrypting the ciphertext is as follows: The attributes are transformed into an LSSS access structure represented as (M, ρ) using a monotonically increasing Boolean formula, where M is an n×l matrix related to a specific set of attributes associated with a unique access strategy, and n is a variable depending on the definition of the LSSS flip method and the monotonically increasing Boolean formula; the function ρ maps each row of M to a specific attribute, and I = {i, ρ(i) ∈ S} is defined, where S is the set of user attributes, where I ⊂ 1, 2, ..., l, and { ∈Zp}, i∈I is a set of constants; the secret parameter s∈ is randomly selected. To encrypt the symmetric key; define a vector υ=(s,y2,y3,...,yn)T∈Z p n y2, y3, ..., yn are randomly selected to share parameter s; for each i = 1 to l, calculate = ,in It is a vector associated with the i-th row of M; based on the access structure of M, { } is a valid sharing of secret s, only if ∈I, =s; randomly select values r1, r2, ..., rl∈Zp; Use the public key PK generated by TA to compute the ciphertext CT; ; ; in, It refers to ciphertext. , , and All are components of encrypted CT scans; Step (5): Execute the outsourced task of partially decrypting the information, that is, the trusted fog vehicle FV executes the Partdec algorithm to complete part of the complex decryption calculation and obtains the partially decrypted ciphertext. Then, the fog vehicle FV will Send to the source vehicle SV; the specific process is as follows: Step (5-1): After receiving the encrypted text broadcast by the RSU, the vehicle determines whether it has sufficient computing power and whether its current position and speed can be fully downloaded from the current RSU in time. Step (5-2): If there is insufficient computing power, the vehicle will be considered the source vehicle SV. The source vehicle SV requests the RSU to outsource the complex decryption operation to a nearby vehicle with the necessary capabilities. The request message includes part of the attribute key. ; Step (5-3): After receiving the outsourced computing task, the trusted FV uses... The Partdec algorithm is executed to convert the original ciphertext CT into TCT for partial decryption; Step (5-4): Determine whether the attribute set of the fog vehicle FV satisfies the access structure embedded in the ciphertext. If not, the data cannot be decrypted. Step (5-5): When executing the Partdec algorithm, the input is a partial attribute key. And a ciphertext CT represented as access structure (M,ρ), then the fog vehicle FV converts the ciphertext CT into a partially decrypted ciphertext TCT: TCT=(C0,C2,C1′,C... 3,i D 3,i ); Step (6): Decrypt all information. The source vehicle SV uses the AES algorithm to finally decrypt the received partially decrypted TCT and obtain the plaintext. The specific process is as follows: Step (6-1): The trusted fog vehicle FV will send the partially decrypted TCT obtained from Partdec to the source vehicle SV. Step (6-2): Execute the Fulldec algorithm to decrypt the AES key, then you can use the Dec decryption algorithm for AES. AES (CT AES → key to retrieve plaintext information; 。 2. The vehicle-to-everything (V2X) data sharing method based on lightweight fog computing according to claim 1, characterized in that, The detailed process of step (1) is as follows: Step (1-1): Use the input security parameter λ and system attribute set U to output the system's public key PK and master key MK; Step (1-2): Select a large prime number p, and then select a group G and its generators g and h, where group G is a prime group of order p; Steps (1-3): Define a bilinear mapping ; Steps (1-4): Randomly select group elements h1,...,h U ∈G is associated with the attributes in U; Steps (1-5): The system randomly selects two exponents α and a∈Zp, and finally outputs the public key PK and the master key MK: ; 。 3. The vehicle-to-everything (V2X) data sharing method based on lightweight fog computing according to claim 1, characterized in that, The specific process for vehicle registration in step (2) is as follows: Step (2-1): The trusted authority (TA) verifies the vehicle's OBU module to determine if it is a valid device. This refers to the identity of the i-th user. This refers to the identity of the i-th vehicle; Step (2-2): The TA obtains the vehicle's attribute information, including location, direction, speed, and registration time; Steps (2-3): The TA applies for a unique identifier (uid) for the vehicle and randomly selects the vehicle's private key. Generate CP-ABE public key for the source vehicle SV Private key and certificates ; ; Certificate Include And user attribute set S.
4. The vehicle-to-everything (V2X) data sharing method based on lightweight fog computing according to claim 1, characterized in that, In step (3), the attribute authorization agency AA executes the Keygen algorithm to generate partial attribute keys for the vehicle. The specific formula is: ; For vehicle private key; , , Both are key components, and α and a are random exponents belonging to Zp.
Citation Information
Patent Citations
Attribute-based strategy hiding outsourcing signcryption method in Internet of Vehicles environment
CN111343273A
Enabling a fog service layer with application to smart transport systems
US20210208946A1