A cloud-assisted authentication key agreement method for internet of vehicles

By using a cloud-assisted vehicle-to-everything (V2X) authentication method, which utilizes roadside unit broadcasting and cloud server verification, efficient and secure one-to-many key negotiation is achieved. This solves the problems of high computational overhead and security risks in existing technologies, and improves the security and efficiency of V2X communication.

CN116546493BActive Publication Date: 2026-04-24SHAANXI NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHAANXI NORMAL UNIV
Filing Date
2023-05-05
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing identity-based vehicle network authentication and key negotiation protocols have high computational overhead and security vulnerabilities in high-density and high-traffic environments, making it difficult to meet the complex communication needs of vehicle networks.

Method used

A cloud-assisted vehicle network authentication method is adopted, which broadcasts vehicle authentication requests through roadside units, uses cloud servers for identity verification and key negotiation, reduces the computational overhead of vehicles, and achieves a one-to-many authentication mode by fuzzing identities and reconstructing parameters.

Benefits of technology

Without increasing system storage burden and user computing overhead, it improves the security and efficiency of vehicle-to-vehicle communication, resists common attacks, and reduces the computing burden on vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116546493B_ABST
    Figure CN116546493B_ABST
Patent Text Reader

Abstract

The application discloses a cloud-assisted vehicle networking authentication key negotiation method, and a network architecture is constructed based on a vehicle-mounted unit, a roadside unit, a key generation center and a cloud server; in an authentication stage, the roadside unit broadcasts a vehicle authentication request message, and attributes of the vehicle are taken as identities to realize one-to-many mutual authentication and key negotiation. In the authentication stage, the vehicle does not need to explicitly specify an authentication object, only needs to send an authentication request message of the vehicle to roadside facilities, and the roadside facilities can broadcast the authentication request message, so that other vehicles meeting a condition can directly interact with the vehicle after receiving the message, and the calculation cost of the vehicle can be greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle networking technology, and in particular to a cloud-assisted vehicle networking authentication key negotiation method. Background Technology

[0002] As an emerging technology, the Internet of Vehicles (IoV) holds great promise for building intelligent transportation systems, offering convenient, richer, and more intelligent services to enhance people's travel experience. However, the sheer scale of IoV makes it inherently complex and vulnerable to various security threats. IoV authentication and key negotiation protocols are crucial for ensuring the security of IoV communication. In recent years, with the rapid development and deepening application of IoV technology, IoV authentication and key negotiation protocols have also been continuously evolving and improving.

[0003] Current vehicle-to-everything (V2X) authentication and key negotiation protocols mainly fall into two categories: public-key cryptography-based protocols and identity-based protocols. Among these, identity-based protocols have attracted significant attention due to their efficiency and security. Identity-based protocols are a relatively new type of protocol that has emerged in recent years. These protocols utilize the vehicle's own attributes as an identifier, enabling efficient identity authentication and key negotiation. Identity-based protocols primarily include attribute-based encryption, bilinear pairing-based protocols, and identity-based cryptography protocols. These protocols offer high efficiency and security and have been widely applied and researched in V2X applications.

[0004] Several identity-based key negotiation protocols have been proposed, including one-to-one and one-to-many authentication modes. One-to-one authentication is inefficient and unsuitable for high-density, high-traffic vehicle-to-everything (V2X) environments. Furthermore, this scheme has security vulnerabilities and is susceptible to various attacks. One-to-many authentication is limited to specific scenarios and imposes additional storage burden on the system. As the number of users increases, the storage overhead associated with the tree structure becomes increasingly significant. The most critical issue is that all the above schemes require the user to specify an authentication negotiator for communication, which introduces additional computational overhead from the very beginning of the authentication process.

[0005] Therefore, how to provide a cloud-assisted one-to-many key negotiation method for vehicle networking that effectively reduces computational overhead is a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0006] This invention addresses the aforementioned research status and existing problems by providing a more efficient and secure one-to-many key negotiation protocol. During the authentication phase, the roadside unit broadcasts the authentication request message from a vehicle, allowing any other vehicle that meets the requirements to perform mutual authentication and key negotiation.

[0007] This invention provides a cloud-assisted vehicle-to-everything (V2X) authentication key negotiation method. Based on a network architecture constructed from an on-board unit (OB), roadside units, a key generation center, and a cloud server, each vehicle is equipped with a unique OB, and the wireless communication range of several roadside units covers the vehicle's driving range. The key generation center publishes public parameters to all OB and roadside units in the network architecture through the roadside units. The method includes the following steps:

[0008] Vehicle registration steps:

[0009] The vehicle unit sends a key generation request message to the key generation center. The key generation center generates vehicle identity information and registration key information based on the key generation request message, and sends the registration key information to the corresponding vehicle unit.

[0010] Authentication and key negotiation steps:

[0011] Vehicle ID A The vehicle-mounted unit extracts its own vehicle identity information and registration key information, calculates and generates authentication request information using publicly available parameters, and sends it to roadside units within its wireless communication range for broadcast.

[0012] Vehicle ID B The onboard unit receives the authentication request message broadcast by the roadside unit, and sends the message along with the vehicle ID. B The vehicle's identity information is sent to the cloud server;

[0013] The cloud server is based on the vehicle ID. A Vehicle identity information and vehicle ID B Determine vehicle ID based on vehicle identity information B Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... B Output successful verification ID A The result information of identity, vehicle ID B Based on its own vehicle identity information and registration key information, the system calculates and generates an authentication response message using publicly available parameters, and then sends it to the vehicle ID. A The vehicle-mounted unit, and also based on the vehicle ID A Vehicle identity information and vehicle ID B Vehicle identity information settings and vehicle ID A Session key

[0014] Vehicle ID A The onboard unit receives the authentication response message and sends the message along with the vehicle ID. A The vehicle's identity information is sent to the cloud server;

[0015] The cloud server is based on the vehicle ID. A Vehicle identity information and vehicle ID B Determine vehicle ID based on vehicle identity information A Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... A Output successful verification ID B The result information of identity, vehicle ID A Based on vehicle ID A Vehicle identity information and vehicle ID B Vehicle identity information settings and vehicle ID B Session key

[0016] Preferably, the key generation center is also used to generate master public-private key pairs (msk, T). pub The key generation center then publishes the master public key and public parameters; the vehicle registration steps include:

[0017] The on-board unit generates a key generation request message based on its own vehicle's biometric features τ and sends it to the key generation center. The key generation center generates the corresponding vehicle's identity information and registration key information based on the key generation request message, the master private key msk, and the public parameters using a key generation algorithm. The registration key information is then sent to the on-board unit of the corresponding vehicle through the roadside unit, and the vehicle saves the registration key information.

[0018] Vehicle identification information includes: the vehicle's ambiguous identity;

[0019] The registration key information includes: the key and the reconstruction parameters.

[0020] Preferably, in the vehicle registration step, the vehicle unit uses a fuzzy extractor to input its own vehicle's biometric template τ; the fuzzy extractor generates a fuzzy identity ω and a reconstruction parameter ρ; in the authentication and key negotiation step, the fuzzy extractor is also used to verify the biometrics input by the vehicle unit to the fuzzy extractor in real time based on the fuzzy identity ω and the reconstruction parameter ρ.

[0021] Preferably, in the vehicle registration step, the key generation algorithm includes:

[0022] The key generation center randomly selects a polynomial q(x) of order d-1, whose constant term q(0) = y. For all i ∈ ω, r is selected. i ∈Z p ,calculate and Key

[0023] Where d∈(1,n), n represents the number of attributes in the fuzzy identity, with a value ≤100; g is the generator of group G, g2 is a random element in the cyclic group G, and G is a cyclic group of order p disclosed in the public parameters; Z p It is a finite field from 0 to p-1, where p is a large prime number chosen during the initialization phase; N = {1, ..., n+1}; t1,...,t n+1 ∈G, r i For each attribute in the finite field, a random value is chosen, where i represents the index of the attribute. Let Δ be the set of numbers coprime to p from 0 to p-1; i,N (x) is the Lagrange interpolation.

[0024] It should be noted that the public parameters do not include the master private key msk=y. y is selected during the initialization phase, and the key generation phase does not involve the selection of y.

[0025] Preferably, the authentication and key negotiation steps include:

[0026] Vehicle ID A The vehicle-mounted unit verifies the input biometric features, and extracts the fuzzy identity ω based on the biometric features and reconstructed parameters using publicly available parameters. A Based on fuzzy identity ω A The key is used to calculate authentication request information based on public parameters and then broadcast to roadside units within its wireless communication range.

[0027] Vehicle ID B The vehicle-mounted unit receives the authentication request message broadcast by the roadside unit, and sends the message along with the fuzzy identity ω B Send to the cloud server;

[0028] Cloud servers based on fuzzy identity ω A With ambiguous identity ω B The relationship between the intersection and threshold values ​​is used to determine fuzzy identity ω B Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... B Output successful verification ID A The result information of identity, vehicle ID B Based on fuzzy identity ω B The key is used to calculate authentication response information based on the public parameters and then sent to the vehicle ID. A The vehicle-mounted unit, while based on fuzzy identity ω A With ambiguous identity ω B Settings and vehicle ID A Session key

[0029] Vehicle ID A The vehicle-mounted unit receives the authentication response message and sends the message along with the fuzzy identity ω A Send to the cloud server;

[0030] Cloud servers based on fuzzy identity ω A With ambiguous identity ω B The relationship between the intersection and threshold values ​​is used to determine fuzzy identity ω A Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... A Output successful verification ID B The result information of identity, vehicle ID A Based on fuzzy identity ω A With ambiguous identity ω B Settings and vehicle ID B Session key

[0031] Preferably, in the vehicle ID A Fuzzy identity ω is extracted based on biometric features and reconstructed parameters calculated using publicly available parameters. A Previously, it also included vehicle ID. A The steps for the onboard unit to verify the correctness of the input biometric features are as follows:

[0032] The vehicle-mounted unit receives the new biometric feature τ' and the reconstructed parameter ρ. If the statistical distance between the new biometric feature τ' and the biometric template τ is within a set error range, it outputs the fuzzy identity ω. A .

[0033] This invention designs a more secure and efficient key negotiation protocol to ensure communication security between vehicles in the Internet of Vehicles (IoV) without imposing additional storage burden on the system or additional computational overhead on the user end. Compared with existing technologies, it has the following advantages:

[0034] 1. A one-to-many authentication mode is proposed, which is more in line with the application environment of the Internet of Vehicles;

[0035] 2. We will use security proofs and the formal analysis tool AVISPA to demonstrate that our solution has more security properties and can resist common attacks;

[0036] 3. During the authentication phase, vehicles do not need to explicitly specify the authentication target. They only need to send their authentication request message to the roadside facility, which will then broadcast it. Other vehicles that meet the requirements can then interact directly with the vehicle that receives the message, which can greatly reduce the vehicle's computational overhead. Attached Figure Description

[0037] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely embodiments of the present invention, and those skilled in the art can obtain other drawings based on the provided drawings without creative effort.

[0038] Figure 1 This is a network architecture diagram based on vehicle-mounted units, roadside units, key generation centers, and cloud servers provided in an embodiment of the present invention;

[0039] Figure 2 This is a flowchart of a cloud-assisted vehicle network authentication key negotiation method provided in an embodiment of the present invention. Detailed Implementation

[0040] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0041] The application principle of the present invention will be described in detail below with reference to the accompanying drawings.

[0042] like Figure 1 As shown in the figure, an embodiment of the present invention provides a cloud-assisted vehicle network authentication key negotiation method. Based on a network architecture constructed from an on-board unit, a roadside unit, a key generation center, and a cloud server, a unique on-board unit is set on the vehicle, and the wireless communication range of several roadside units covers the vehicle's driving range. The key generation center publishes public parameters to all on-board units and roadside units in the network architecture through the roadside units.

[0043] Understandably, vehicle-mounted units can use vehicle-mounted terminals such as OBU-200R, MK5-OBU, 5G-V2X, and TITAN-OBU; roadside units can use wireless communication base stations or gateways, including QF-VX1000 from Qianfang Technology, RSU5201 from Huawei, Y2000 from ZTE, and so on.

[0044] The method in this embodiment specifically includes the following steps:

[0045] Vehicle registration steps:

[0046] The on-board unit sends a key generation request message to the key generation center. The key generation center generates vehicle identity information and registration key information based on the key generation request message and sends them to the corresponding on-board unit.

[0047] Authentication and key negotiation steps:

[0048] Vehicle ID A The vehicle-mounted unit extracts its own vehicle identity information and registration key information, calculates and generates authentication request information using publicly available parameters, and sends it to roadside units within its wireless communication range for broadcast.

[0049] Vehicle ID B The onboard unit receives the authentication request message broadcast by the roadside unit, and sends the message along with the vehicle ID. B The vehicle's identity information is sent to the cloud server;

[0050] The cloud server is based on the vehicle ID. A Vehicle identity information and vehicle ID B Determine vehicle ID based on vehicle identity information B Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... B Output successful verification ID A The result information of identity, vehicle ID B Based on its own vehicle identity information and registration key information, the system calculates and generates an authentication response message using publicly available parameters, and then sends it to the vehicle ID. A The vehicle-mounted unit, and also based on the vehicle ID A Vehicle identity information and vehicle ID B Vehicle identity information settings and vehicle ID A Session key

[0051] Vehicle ID A The on-board unit receives the authentication reply message and sends the message along with the vehicle ID. A The vehicle's identity information is sent to the cloud server;

[0052] The cloud server is based on the vehicle ID. A Vehicle identity information and vehicle ID B Determine vehicle ID based on vehicle identity information A Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... A Output successful verification ID B The result information of identity, vehicle ID A Based on vehicle ID A Vehicle identity information and vehicle ID B Vehicle identity information settings and vehicle ID B Session key

[0053] The execution of the method in this embodiment involves a fuzz extractor and three algorithms: Setup, KeyGen, and AttrCheck, which are described in detail below:

[0054] 1. Fuzzy Extractor

[0055] The fuzz extractor consists of two algorithms:

[0056] (ω,ρ)←FE.Gen(τ): This algorithm takes a biometric template τ as input and outputs a fuzzy identity ω and reconstruction parameters ρ.

[0057] ω←FE.Rep(τ',ρ): This algorithm takes a new biometric feature τ' and a reconstruction parameter ρ as input. If the statistical distance between the real-time input biometric feature τ' and the original template τ is sufficiently close, it outputs a fuzzy identity ω.

[0058] This embodiment utilizes a fuzzy extractor to generate a fuzzy identity ω while simultaneously processing the vehicle ID. A Fuzzy identity ω is extracted based on biometric features and reconstructed parameters calculated using publicly available parameters. A Previously, it also included vehicle ID. A The steps of the onboard unit to verify the correctness of the input biometric features using a fuzz extractor are as follows:

[0059] The vehicle-mounted unit receives the new biometric feature τ' and the reconstructed parameter ρ. If the statistical distance between the new biometric feature τ' and the biometric template τ is within a set error range, it outputs the fuzzy identity ω. A Based on the assessment of the statistical error between the real-time biometric feature τ' and the original template τ, the fuzzy identity ω of the current vehicle is recovered.

[0060] 2. Setup Algorithm

[0061] This algorithm is a system initialization algorithm, and its main steps are as follows:

[0062] The system selects two cyclic groups G and G' of order p. T Let g be a generator of group G, and e: G × G → G T This represents a bilinear mapping.

[0063] System randomly selects g2,t1,...,t n+1 ∈G, calculate g1=g y , N = {1, ..., n+1}. Choose two safe hash functions. Set the fuzz extractor FE = (FE.Gen(), FE.Rep()). Set the private key msk = y and the public key T. pub =e(g,g2) y , set param = (G, GT ,p,g,e,g1,g2,T pub ,T(·),FE,H1,H2) are the publicly disclosed parameters of the system; Let Δ be the set of numbers coprime to p from 0 to p-1; i,N (x) represents the Lagrange interpolation.

[0064] 3. KeyGen Algorithm

[0065] This algorithm is a key generation algorithm. The key generation center generates a public-private key pair for the vehicle ID. The main steps are as follows:

[0066] The fuzzy vehicle identity ω=(δ1,...,δ)←FE.Gen(τ) algorithm is used to extract the vehicle's identity ω=(δ1,...,δ k ),δ k ∈Z p (k∈1,...,n) and reconstruction parameter ρ. Z p It is a finite field from 0 to p-1, where p is a large prime number chosen during the initialization phase.

[0067] Randomly select a polynomial q(x) of order d⁻¹, whose constant term q(0) = y. For all i ∈ ω, choose r. i ∈Z p ,calculate and Then ρ, and Send to the vehicle. Vehicle setup key. And store ρ. d∈(1,n), where n represents the number of attributes in the fuzzy identity, with a value ≤100; r i A random value is chosen for each attribute in the finite field, where i represents the index of the attribute.

[0068] 4. AttrCheck Algorithm

[0069] The algorithm is executed by a cloud server, taking the sender's message (ω) as input. A ,A1,M A N A C A Z A ,T A ) and the ambiguous identity of the recipient ω B First check |ω A ∩ω B If the value is less than the threshold value d, output 1; otherwise, randomly select d elements to form a set S and verify the result. Is it equal to T? pub If they are equal, output 1; otherwise, output 0.

[0070] In one embodiment, a system initialization phase is included before performing the vehicle registration step, as well as the authentication and key negotiation steps:

[0071] The key generation center system runs the Setup algorithm to generate a master public-private key pair (msk, T). pub The system then sends the public parameter param to all on-board units and roadside units in the vehicle network via the roadside unit.

[0072] In one embodiment, the key generation center is used to generate the master public-private key pair (msk, T). pub And save; the vehicle registration steps include:

[0073] The on-board unit generates a key generation request message based on its own vehicle's biometric features τ and sends it to the key generation center. The key generation center generates the corresponding vehicle's extraction vehicle identity information and registration key information based on the key generation request message, the master private key msk, and the public parameters using a key generation algorithm. This information is then sent to the corresponding vehicle's on-board unit via the roadside unit. The vehicle stores the vehicle identity information ω and the registration key information.

[0074] Vehicle identification information includes: the vehicle's ambiguous identity;

[0075] The registration key information includes: the key and the reconstruction parameters.

[0076] The specific execution process is as follows:

[0077] Upon receiving the vehicle's key generation request message, the key generation center runs the KeyGen algorithm. Based on the vehicle's biometric template τ, it uses the (ω,ρ)←FE.Gen(τ) algorithm to extract the vehicle's fuzzy identity and reconstruct parameters, and then uses the vehicle's master public private key pair (msk,T) to further refine the key generation. pub The system outputs the key SK for the corresponding vehicle and the public parameter param. Then, it sends the key SK and the reconstruction parameter ρ to the corresponding vehicle through the roadside unit. The vehicle stores the key and reconstruction parameter in the anti-tampering device.

[0078] In one embodiment, in the Internet of Vehicles (IoV), the vehicle ID A Desiring to obtain information related to their own vehicle, they then selected vehicles with similar identities for authentication and communication, using these vehicles as the basis for their vehicle IDs. A Vehicle ID for authentication negotiation B The authentication and key negotiation steps include:

[0079] Vehicle ID A The vehicle-mounted unit verifies the input biometric features, and extracts the fuzzy identity ω based on the biometric features and reconstructed parameters using publicly available parameters. A Based on fuzzy identity ωA The key is used to calculate authentication request information based on public parameters and then broadcast to roadside units within its wireless communication range.

[0080] Vehicle ID B The vehicle-mounted unit receives the authentication request message broadcast by the roadside unit, and sends the message along with the fuzzy identity ω B Send to the cloud server;

[0081] Cloud servers based on fuzzy identity ω A With ambiguous identity ω B The relationship between the intersection and threshold values ​​is used to determine fuzzy identity ω B Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... B Output successful verification ID A The result information of identity, vehicle ID B Based on fuzzy identity ω B The key is used to calculate authentication response information based on the public parameters and then sent to the vehicle ID. A The vehicle-mounted unit, while based on fuzzy identity ω A With ambiguous identity ω B Settings and vehicle ID A Session key

[0082] Vehicle ID A The vehicle-mounted unit receives the authentication response message and sends the message along with the fuzzy identity ω A Send to the cloud server;

[0083] Cloud servers based on fuzzy identity ω A With ambiguous identity ω B The relationship between the intersection and threshold values ​​is used to determine fuzzy identity ω A Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... A Output successful verification ID B The result information of identity, vehicle ID A Based on fuzzy identity ω A With ambiguous identity ω B Settings and vehicle ID B Session key

[0084] The specific execution process is as follows:

[0085] S1: Vehicle ID A The onboard unit receives the input biometric features τ' and reconstruction parameters ρ, and then the onboard unit runs ω A The FE.Rep(τ',ρ) algorithm outputs a fuzzy identity ω. A . id ARandomly select α A ,β A , and the current timestamp T A , where i∈ω A And calculate:

[0086] A0=H1(ω A ,T A ),

[0087] A1=α A +β A ·A0,

[0088]

[0089]

[0090]

[0091]

[0092] Finally, the vehicle will (ω) A ,A1,M A N A C A Z A ,T A It is sent to nearby roadside units for broadcasting.

[0093] It should be noted that biometric characteristics include: the vehicle's region, model, color, brand, type, whether it is an official vehicle, and driver identity information. The key generation center stores the fuzzy identity ω, the key SK, and the vehicle's unique identifier id, facilitating the tracing of the true identity of any malicious vehicle present in the vehicle network.

[0094] S2: Vehicle ID B After receiving the authentication request message broadcast by the roadside unit, send the message along with your fuzzy identity ω B Send to the cloud server. Obscure identity. B The extraction process is also based on the vehicle ID. B The process of inputting biometric features τ', determining whether they are within the error range, and then extracting them (i.e., the same as vehicle ID) A Extracting fuzzy identities ω A (the process).

[0095] After receiving the message, the cloud server executes the AttrCheck algorithm and then returns the output to id. B . id B If the result is 1 after receiving the result, then the ID has been successfully verified. AIf the vehicle's identity is verified, the authentication request message will be discarded; otherwise, it will be automatically sent. Upon successful verification, the vehicle ID will be entered into the system. B Random selection and the current timestamp T B , where i′∈ω B And calculate:

[0096] B0=H1(ω B ,T B ),

[0097] B1=α B +β B ·B0,

[0098]

[0099]

[0100]

[0101]

[0102] Finally, the vehicle will (ω) B ,B1,M B N B C B Z B ,T B Send to vehicle ID A and set the session key. in, Session key Stored in vehicle ID B middle.

[0103] It's important to note that in vehicle-to-everything (V2X) communication, the communication protocols of the on-board units are consistent, allowing any two on-board units to communicate directly. IEEE 802.11p extends traditional short-range wireless network technology, enabling features highly useful for automobiles, including: more advanced handoff schemes, mobile operation, enhanced security, identification, and peer-to-peer authentication. Most importantly, it allows communication on designated on-board frequencies. This will serve as the foundation for DSRC (Dedicated Short Range Communication) or vehicle-to-vehicle communication. Vehicle-to-vehicle communication can occur between vehicles or between vehicles and roadside infrastructure networks.

[0104] S3: Vehicle ID A Received from vehicle ID B After receiving the authentication reply message, send this message along with your vague identity ω AThe data is sent to the cloud server. The cloud server then wirelessly returns the AttrCheck algorithm result to the vehicle ID via the roadside unit. A If the result is 1, then id A ID successfully verified B If the user's identity is confirmed, the authentication response message will be discarded. A Settings and ID B The session key is in, Session key Stored in vehicle ID A In this embodiment, the calculation of the session keys for the two vehicles is equivalent.

[0105] The vehicle ID is completed after the above steps. A and vehicle ID B After authentication and key negotiation, communication between the two parties will be based on the generated session key to achieve symmetric encryption.

[0106] This invention proposes an authentication and key negotiation protocol method that uses vehicle attributes as identities to achieve one-to-many authentication. We prove the security of our protocol using security proofs and AVISPA. Furthermore, we evaluate the performance of our protocol in terms of computational and communication overhead, demonstrating more efficient, secure, and feasible results.

[0107] The above provides a detailed description of a cloud-assisted vehicle network authentication key negotiation method provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

[0108] In this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, without necessarily requiring or implying any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A cloud-assisted method for vehicular network authentication key negotiation, characterized in that: The network architecture is based on an on-board unit, roadside units, a key generation center, and a cloud server. Each vehicle is equipped with a unique on-board unit, and the wireless communication range of several roadside units covers the vehicle's driving range. The key generation center publishes public parameters to all on-board and roadside units in the network architecture through the roadside units. The process includes the following steps: Vehicle registration steps: The vehicle unit sends a key generation request message to the key generation center. The key generation center generates vehicle identity information and registration key information based on the key generation request message, and sends the registration key information to the corresponding vehicle unit. Authentication and key negotiation steps: Vehicle ID A The vehicle-mounted unit extracts its own vehicle identity information and registration key information, calculates and generates authentication request information using publicly available parameters, and sends it to roadside units within its wireless communication range for broadcast. Vehicle ID B The onboard unit receives the authentication request message broadcast by the roadside unit, and sends the message along with the vehicle ID. B The vehicle's identity information is sent to the cloud server; The cloud server is based on the vehicle ID. A Vehicle identity information and vehicle ID B Determine vehicle ID based on vehicle identity information B Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... B Output successful verification ID A The result information of identity, vehicle ID B Based on its own vehicle identity information and registration key information, the system calculates and generates an authentication response message using publicly available parameters, and then sends it to the vehicle ID. A The vehicle-mounted unit, and also based on the vehicle ID A Vehicle identity information and vehicle ID B Vehicle identity information settings and vehicle ID A Session key Vehicle ID A The onboard unit receives the authentication response message and sends the message along with the vehicle ID. A The vehicle's identity information is sent to the cloud server; The cloud server is based on the vehicle ID. A Vehicle identity information and vehicle ID B Determine vehicle ID based on vehicle identity information A Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... A Output successful verification ID B The result information of identity, vehicle ID A Based on vehicle ID A Vehicle identity information and vehicle ID B Vehicle identity information settings and vehicle ID B Session key 2. The cloud-assisted vehicle network authentication key negotiation method according to claim 1, characterized in that, The key generation center is also used to generate master public-private key pairs (MSK, T). pub And save; the vehicle registration steps include: The on-board unit generates a key generation request message based on its own vehicle's biometric features τ and sends it to the key generation center. The key generation center generates the corresponding vehicle's identity information and registration key information based on the key generation request message, the master private key msk, and the public parameters using a key generation algorithm. The registration key information is then sent to the on-board unit of the corresponding vehicle through the roadside unit, and the vehicle saves the registration key information. Vehicle identification information includes: the vehicle's ambiguous identity; The registration key information includes: the key and the reconstruction parameters.

3. The cloud-assisted vehicle network authentication key negotiation method according to claim 1, characterized in that, During the vehicle registration process, the on-board unit uses a fuzz extractor to input its own vehicle's biometric template τ. The fuzzy extractor generates a fuzzy identity ω and a reconstruction parameter ρ. In the authentication and key negotiation steps, the fuzzy extractor is also used to verify the biometric features input to the fuzzy extractor by the vehicle unit in real time based on the fuzzy identity ω and the reconstruction parameter ρ.

4. The cloud-assisted vehicle network authentication key negotiation method according to claim 2, characterized in that, In the vehicle registration step, the key generation algorithm includes: The key generation center randomly selects a polynomial q(x) of order d-1, whose constant term q(0) = y. For all i ∈ ω, r is selected. i ∈Z p ,calculate and Key Where d∈(1,n), n represents the number of attributes in the fuzzy identity, with a value ≤100; g is the generator of group G, g2 is a random element in the cyclic group G, and G is a cyclic group of order p disclosed in the public parameters; Z p It is a finite field from 0 to p-1, where p is a large prime number chosen during the initialization phase; N = {1, ..., n+1}; t1,...,t n+1 ∈G, r i For each attribute in the finite field, a random value is chosen, where i represents the index of the attribute. Let be the set of numbers coprime to p from 0 to p-1; Δi,N(x) is the Lagrange interpolation.

5. The cloud-assisted vehicle network authentication key negotiation method according to claim 2, characterized in that, The authentication and key negotiation steps include: Vehicle ID A The vehicle-mounted unit verifies the input biometric features, and extracts the fuzzy identity ω based on the biometric features and reconstructed parameters using publicly available parameters. A Based on fuzzy identity ω A The key is used to calculate authentication request information based on public parameters and then broadcast to roadside units within its wireless communication range. Vehicle ID B The vehicle-mounted unit receives the authentication request message broadcast by the roadside unit, and sends the message along with the fuzzy identity ω B Send to the cloud server; Cloud servers based on fuzzy identity ω A With ambiguous identity ω B The relationship between the intersection and threshold values ​​is used to determine fuzzy identity ω B Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... B Output successful verification ID A The result information of identity, vehicle ID B Based on fuzzy identity ω B The key is used to calculate authentication response information based on the public parameters and then sent to the vehicle ID. A The vehicle-mounted unit, while based on fuzzy identity ω A With ambiguous identity ω B Settings and vehicle ID A Session key Vehicle ID A The vehicle-mounted unit receives the authentication response message and sends the message along with the fuzzy identity ω A Send to the cloud server; Cloud servers based on fuzzy identity ω A With ambiguous identity ω B The relationship between the intersection and threshold values ​​is used to determine fuzzy identity ω A Does it meet the verification requirements? If so, the cloud server sends the vehicle ID... A Output successful verification ID B The result information of identity, vehicle ID A Based on fuzzy identity ω A With ambiguous identity ω B Settings and vehicle ID B Session key 6. The cloud-assisted vehicle network authentication key negotiation method according to claim 5, characterized in that, In vehicle ID A Fuzzy identity ω is extracted based on biometric features and reconstructed parameters calculated using publicly available parameters. A Previously, it also included vehicle ID. A The steps for the onboard unit to verify the correctness of the input biometric features are as follows: The vehicle-mounted unit receives the new biometric feature τ' and the reconstructed parameter ρ. If the statistical distance between the new biometric feature τ' and the biometric template τ is within a set error range, it outputs the fuzzy identity ω. A .