A blockchain-based completely anonymous authentication and key agreement method in a vehicle networking environment
By using blockchain technology to generate pseudonyms and temporary private keys for vehicles in the Internet of Vehicles (IoV), and combining them with homomorphic encryption algorithms, the single point of failure and certificate revocation list bloat issues of centralized architectures are resolved. This enables anonymous vehicle authentication and efficient key negotiation, while reducing memory requirements and computational costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-07
- Publication Date
- 2026-04-10
AI Technical Summary
In existing vehicle-to-everything (V2X) communication, the centralized architecture leads to single points of failure and low authentication efficiency, and cannot guarantee the complete anonymity and verifiability of vehicle pseudonyms. Furthermore, the expansion of the certificate revocation list causes excessive memory burden on vehicles.
By employing blockchain technology and collaborating with certification authorities, pseudonym generators, and accountability agencies, pseudonyms and temporary private keys for vehicles are generated. Homomorphic encryption algorithms are used to achieve complete anonymity and verifiability of vehicles, and time-limited certificate management enables automatic revocation of expired pseudonyms, reducing memory requirements.
It achieves fully anonymous and verifiable vehicle authentication in the Internet of Vehicles, reduces the memory requirements of the certificate revocation list, improves authentication efficiency, resists various types of attacks, and has low computational cost and low communication overhead.
Smart Images

Figure CN117041943B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of blockchain and vehicle network, and particularly relates to a completely anonymous authentication and key agreement method based on blockchain in a vehicle network environment. BACKGROUND
[0002] With the rapid development of information technology and the rise of intelligent transportation systems, Internet of Vehicles (IoV) as an important part of intelligent transportation systems has shown broad application prospects in road safety, traffic management, and assisted driving systems. However, the widespread application of Internet of Vehicles has also brought a series of technical and security challenges, especially in ensuring the reliability, security, and privacy of Internet of Vehicles communication. In order to meet the security requirements of communication in Internet of Vehicles, a key encryption method is usually used for interaction, and the key problem is the negotiation of session keys.
[0003] Pseudonym-based authentication and key agreement technology can achieve anonymous authentication of vehicle identity and mutual verification of session keys while establishing session keys, which is an effective way to ensure the reliability and privacy of Internet of Vehicles communication. However, most existing schemes use a single authority centralized architecture, which is prone to single point failure and low authentication efficiency, and cannot balance the complete anonymity and verifiability of vehicle pseudonyms. In addition, the ever-expanding certificate revocation list also puts a heavy burden on the vehicle memory.
[0004] Blockchain technology, as a publicly traceable and tamper-proof distributed ledger, can provide technical support for the anonymity, public verifiability, and distributed storage of Internet of Vehicles, and has great application potential in the security of Internet of Vehicles communication and the protection of vehicle identity privacy. Combining blockchain technology with Internet of Vehicles can effectively improve the security and communication efficiency of Internet of Vehicles environment. SUMMARY
[0005] In view of the above problems existing in authentication and key agreement in Internet of Vehicles, the application combines blockchain technology and proposes a completely anonymous authentication and key agreement method based on blockchain in Internet of Vehicles environment, which realizes the complete anonymity and verifiability of vehicle pseudonyms, avoids the continuous expansion of the certificate revocation list, and reduces the memory requirements of Internet of Vehicles for connected vehicles.
[0006] The completely anonymous authentication and key agreement method based on blockchain in Internet of Vehicles environment according to the application has the following characteristics:
[0007] (1) The method includes five types of entities, namely an authentication authority , a pseudonym generation authority , a liability authority , a vehicle, and a roadside unit ;
[0008] (2) The method comprises the following seven steps:
[0009] S1: System initialization;
[0010] authentication authority , pseudonym generation authority and accountability authority perform system initialization, generate public parameters and upload to the blockchain;
[0011] S2: Vehicle registration;
[0012] The vehicle generates its own registration key pair and applies for registration to the authentication authority , which verifies the legality of the vehicle identity, and if the verification is passed, stores the vehicle registration information; S3: Roadside unit
[0013] registration;
[0014] The roadside unit generates its own registration key pair and applies for registration to the authentication authority , which verifies the legality of the identity; if the verification is passed, calculates the pseudonym and partial private key in the Internet of Vehicles and sends it to the roadside unit through a secure channel; stores the registration information;
[0015] S4: Vehicle pseudonym application;
[0016] The vehicle sends a pseudonym application to the authentication authority , which generates a pseudonym and a temporary private key for the vehicle based on a homomorphic encryption algorithm together with the pseudonym generation authority ; the vehicle uses its own registration private key to decrypt the pseudonym and temporary private key generated by the authentication authority and the pseudonym generation authority for it; the vehicle generates its own certificate based on the corresponding pseudonym and temporary private key of the vehicle and uploads the certificate to the blockchain;
[0017] S5: Mutual authentication and key agreement between vehicles;
[0018] The vehicle and other vehicles in the network perform mutual authentication and key agreement, and communicate with the corresponding vehicles using the negotiated session key;
[0019] S6: The vehicle and the roadside unit perform mutual authentication and key agreement between them;
[0020] The vehicle and the roadside unit perform mutual authentication and key agreement between them;
[0021] S7: Malicious vehicle tracking;
[0022] The pseudonym generation mechanism After receiving the report of the malicious behavior of the vehicle, generates a tracking parameter according to the pseudonym information of the malicious vehicle and sends it to the tracking mechanism Based on the tracking parameter, the real identity of the malicious vehicle is tracked;
[0023] Further, the five types of entities are specifically described as:
[0024] (1) Authentication mechanism : The authentication mechanism is responsible for initializing the system, issuing public parameters and registering all vehicles and roadside units in the Internet of Vehicles; In addition, the authentication mechanism cooperates with the pseudonym generation mechanism to generate the pseudonym and temporary private key of the vehicle;
[0025] (2) Pseudonym generation mechanism : The work of the pseudonym generation mechanism includes two parts: cooperation with the authentication mechanism to generate the pseudonym and private key of the vehicle, and receiving the report of the malicious behavior of the vehicle and assisting the tracking mechanism to track the real identity of the malicious vehicle;
[0026] (3) Tracking mechanism : The tracking mechanism is responsible for tracking the real identity of the malicious vehicle;
[0027] (4) Vehicle: The vehicle has a certain computing power, and can communicate with other vehicles ) and ( ); Through or communication, the vehicle can transmit and obtain traffic information such as traffic congestion, accident warning and road information;
[0028] (5) Roadside unit : The roadside unit is a fixed road infrastructure deployed on the roadside, responsible for collecting and publishing real-time traffic information, and providing communication services for vehicles;
[0029] Further, the authentication agency , pseudonym generation agency and accountability agency in step S1 initialize the system as follows:
[0030] S11: The authentication agency selects an elliptic curve and an infinite point in a finite field ; The authentication agency generates a order cyclic group according to the elliptic curve , and the generator of the group is denoted as ;
[0031] S12: The authentication agency selects two random numbers and calculates its public key and public parameters , where is the master secret of , and is the private key of ;
[0032] S13: The authentication agency selects a one-way hash function , and uploads the parameter tuple to the blockchain;
[0033] S14: The pseudonym generation agency selects a random number , calculates its public key and uploads to the blockchain, where is the private key of ; The accountability agency selects a random number , calculates its public key and uploads the public key to the blockchain, where is the private key of ;
[0034] S15: the pseudonym generation mechanism dividing time evenly into time periods ; selecting a random number and calculating a public parameter , , and wherein and are system secret values for a time period ; uploading a parameter tuple to a blockchain; calculating , from the parameter tuple; at a time period , and a new secret value will be generated for a time period ;
[0035] Further, the process of generating secret values for a time period and in the step S15 is as follows:
[0036] at a time period , the pseudonym generation mechanism selects a secret value and calculates , , and wherein and are system secret values for a time period ; uploads a parameter tuple to a blockchain; calculates and from the parameter tuple;
[0037] Further, the registration process of a vehicle in the step S2 is as follows, taking a vehicle as an example:
[0038] S21: the vehicle generates its own private key and public key according to an encryption algorithm;
[0039] S22: the vehicle generates its own unique real identity and uses to encrypt Encryption yields ciphertext ;vehicle Registration Request Send to certification authority ,in This is the current timestamp;
[0040] S23: Received vehicle Registration request Then decrypt and verify the legitimacy of the vehicle's identity. If the vehicle... Legal identity tuple Store in a local database;
[0041] Furthermore, in step S3, the roadside unit The registration process, based on roadside units For example, the details are as follows:
[0042] S31: Roadside Unit via secure channel to certification authority Send registration request ,in roadside unit His true identity This is the current timestamp;
[0043] S32: Certification Body Received from roadside unit Registration request Afterwards, verification freshness and The legitimacy of the certification; after verification, the certification body Select random number And calculate , and Certification bodies tuples via secure channel Send to roadside unit ,in roadside unit The pseudonym in the Internet of Vehicles roadside unit Part of the private key;
[0044] S33: Roadside Unit Received tuple Afterwards, verification Is it valid? If so, roadside unit. Select random number ,calculate and and published wherein is a private key, is a public key;
[0045] Further, in the step S4, the vehicle applies a pseudonym, and the vehicle For example, the specific process is as follows:
[0046] S41: The vehicle generates a pseudonym request message in a time period and signs the message to obtain wherein is a current timestamp; the vehicle sends to the certification authority ;
[0047] S42: After the certification authority receives , the certification authority verifies the freshness of and the legality of ; after the verification, the certification authority selects a random number and calculates the partial pseudonym and the partial private key of the vehicle using the secret value in the time period ; the certification authority encrypts and respectively to obtain the ciphertext and sends to the pseudonym generation authority ; the certification authority encrypts the ciphertext and using an elliptic curve encryption algorithm and sends to the accountability authority ; ;
[0048] S43: After the pseudonym generation authority receives , the pseudonym generation authority selects a random number and calculates and using the secret value in the time period ; the pseudonym generation authority encrypts and respectively to obtain The ciphertext is obtained by encryption ; pseudonym generation mechanism The and are homomorphic operation to obtain , wherein ; pseudonym generation mechanism Send to the vehicle , and send to the accountability mechanism , wherein ;
[0049] S44: the vehicle After receiving , it is decrypted to obtain the pseudonym of the vehicle And the temporary private key :
[0050]
[0051]
[0052] The certification authority And the pseudonym generation mechanism Use Homomorphic encryption algorithm to generate temporary private key and pseudonym for the vehicle, while ensuring the verifiability of the vehicle pseudonym, realizing the complete anonymity of the vehicle, and any entity in the Internet of vehicles cannot track the real identity of the vehicle through the pseudonym or public key of the vehicle alone
[0053] The vehicle Generate a certificate , and publish it to the blockchain node; the blockchain node verifies the legitimacy of the certificate According to the following formula, if the verification is passed, the blockchain node stores the certificate using the storage structure of the Tree and uploads it to the blockchain
[0054] PID V i F i =[a+H( RID V i || r i )] f i P
[0055]
[0056] =[a f i + f i H( RID V i || r i )]P
[0057] =[ sk V i - sk PGA - sk CA ]P
[0058]
[0059] Vehicle after certificate uploading is completed Query the verification path of the certificate And publish the temporary public key of the vehicle in the time period And pseudonym ; ;
[0060] S45: accountability agency Decrypt And And save the tuple To the accountability list , wherein ;
[0061] Further, the mutual authentication and key negotiation of the vehicle and other vehicles in step S5 are as follows: And vehicle For example, as follows:
[0062] S51: vehicle Calculate And ; After the calculation is completed, vehicle Generate an authentication request message And send To vehicle , wherein Is the current timestamp;
[0063] S52: After vehicle Receive authentication request message Verify Freshness; if Is fresh, then
[0064] Verify Legality and use vehicle Temporary public key of the verification path Verify Certificate on the blockchain; if the verification is passed, vehicle calculate and After the calculation is completed, the vehicle Generate feedback message and will Send to vehicle ,in This is the current timestamp;
[0065] S53: Vehicles Received feedback message Afterwards, verification The freshness; if It's fresh, the vehicle. Using vehicles Verification path in temporary public key verify Is the certificate on the blockchain? If the verification is successful, the vehicle... calculate And verify The legality of the vehicle; if the verification is successful, the vehicle... Calculate confirmation information and to the vehicle Send confirmation message ,in This is the current timestamp;
[0066] S54: Vehicles Received feedback message Afterwards, verification The freshness; if It's fresh, the vehicle. verify Is it true? If true, the vehicle... and vehicles Use session key To conduct subsequent communication;
[0067] Furthermore, in step S6, the vehicle and Mutual authentication and key negotiation for vehicles and roadside units For example, the details are as follows:
[0068] S61: Vehicles calculate and After the calculation is completed, the vehicle Generate authentication request message And Send to roadside unit ,in This is the current timestamp;
[0069] S62: Roadside Unit receiving the authentication request message then verifying the freshness of ; if is fresh, the roadside unit verifies the legitimacy of ; if the verification passes, the roadside unit uses the vehicle public key to verify the path ; if the verification passes, the roadside unit computes and ; upon completion of the computation, the roadside unit generates a feedback message and sends to the vehicle , where is the current timestamp;
[0070] S63: upon receiving the feedback message , the vehicle verifies the freshness of ; if is fresh, the vehicle computes and verifies the legitimacy of ; if the verification passes, the vehicle computes confirmation information and sends a confirmation message to the vehicle
[0071] , where is the current timestamp; S64: upon receiving the feedback message , the roadside unit verifies whether holds; if so, the vehicle and the roadside unit use the session key for subsequent communication;
[0072] Further, the step S7 of malicious vehicle tracking, taking the vehicle as an example, is as follows:
[0073] S71: when an entity in the network detects malicious behavior of the vehicle in a time period , the entity will pseudonymize Time period The vehicle's malicious behavior was sent to a pseudonym generation agency. ;
[0074] S72: Kana generation agency Upon receiving the report, verify whether the malicious behavior is true; if true, Calculate accountability parameters and will Send to the accountability agency ;
[0075] S73: Accountability Agencies From the list of accountability Search and The true identity of the corresponding vehicle .
[0076] Compared with the prior art, the present invention has the following beneficial effects:
[0077] This invention generates vehicle pseudonyms through homomorphic negotiation between certification authorities and pseudonym generation organizations, achieving complete anonymity and verifiability of vehicle pseudonyms. It divides time into multiple time periods and embeds corresponding authentication parameters into pseudonyms generated within different time periods, enabling automatic revocation of expired pseudonyms and reducing the memory requirements of the certificate revocation list on the vehicle. It uses decentralized blockchain technology to verify and store vehicle certificates, improving authentication efficiency. This invention effectively resists various attacks such as replay attacks, man-in-the-middle attacks, and privileged insider attacks, while maintaining low computational cost and minimal communication overhead. Attached Figure Description
[0078] Figure 1 This is a network architecture diagram according to an embodiment of the present invention;
[0079] Figure 2 This is an overall flowchart of an embodiment of the present invention;
[0080] Figure 3 This is a flowchart illustrating the vehicle pseudonym application process according to an embodiment of the present invention. Detailed Implementation
[0081] The present invention will be further described below with reference to the accompanying drawings and embodiments:
[0082] like Figure 1 As shown, the fully anonymous authentication and key negotiation method based on blockchain in a vehicle-to-everything (V2X) environment described in this invention is based on a certification authority. Kana generation agencies Accountability agencies Vehicles and roadside units The constructed network framework, certification authorities and kana generation agencies Publish system parameters to all nodes in the network architecture.
[0083] Figure 2 This is an overall flowchart of a blockchain-based fully anonymous authentication and key negotiation method in a vehicle-to-everything (V2X) environment, provided by an embodiment of the present invention. Figure 2 As shown, the fully anonymous authentication and key negotiation method based on blockchain in the vehicle network environment provided by this invention mainly includes the following steps:
[0084] S1: System initialization;
[0085] Certification bodies Kana generation agencies and accountability agencies Perform system initialization, generate public parameters, and upload them to the blockchain;
[0086] Furthermore, S1 includes S11 to S15, as detailed below:
[0087] S11: The certification body In a finite field Select an elliptic curve and an infinity ,in and Need to meet The certification body According to the elliptic curve Generate a Cyclic group , for A generator;
[0088] S12: The certification body Select two random numbers And calculate its own public key and common parameters ,in for The Lord's secret, for The private key;
[0089] S13: The certification body Choose a one-way hash function and parameter tuple Uploaded to the blockchain;
[0090] S14: The pseudonym generation mechanism Select random number And calculate its own public key And upload to the blockchain, wherein is the private key of the pseudonym generation authority ; the accountability authority selects a private random number and computes its own public key and uploads to the blockchain, wherein is the private key of the pseudonym generation authority ;
[0091] S15: the pseudonym generation authority divides the system time evenly into multiple time periods ; selects a random number and computes public parameters , , and ; wherein and are the system secret values of the time period ; uploads the parameter tuple to the blockchain; the authentication authority computes , according to the parameter tuple; at the time period , and , the pseudonym generation authority will generate a new secret value for the time period ;
[0092] Further, in S15 and generate the secret value of the time period as follows:
[0093] At the time period , the pseudonym generation authority selects a secret value and computes , , and , wherein and are the system secret values of the time period ; uploads the parameter tuple to the blockchain; computes and according to the parameter tuple;
[0094] Since the verification of the vehicle certificate needs to use the certificate verification parameters of the current time period When the time period is replaced, and The system secret value of the corresponding time period is updated, and the certificate verification parameter is updated, so that the expired certificate cannot pass the verification; through the above mechanism, the automatic revocation of the expired pseudonym in the Internet of Vehicles can be realized, and the rapid expansion of the revocation list is relieved;
[0095] S2: vehicle registration;
[0096] The vehicle generates its own registration key pair and applies for registration to the certification authority The certification authority verifies the legality of the vehicle identity, if the verification is passed, stores the registration information of the vehicle;
[0097] Further, S2 includes S21-S24, taking the vehicle as an example, as follows:
[0098] S21: the vehicle selects a random number and calculates and ;
[0099] S22: the vehicle selects a random number and calculates , wherein ; the private key , the public key of the vehicle ;
[0100] S23: the vehicle generates its own unique real identity , and uses to encrypt to obtain ciphertext ; then the vehicle sends the registration request to , wherein is the current timestamp;
[0101] S24: the certification authority decrypts and verifies the legality of the vehicle identity after receiving the registration request of the vehicle , if the vehicle identity is legal, the certification authority stores the tuple to the local database.
[0102] S3: roadside unit registration;
[0103] Roadside unit Generate its own registration key pair and send to the certification authority Apply for registration, the certification authority Verify The legitimacy of the identity; if the verification is passed, Calculate Pseudonym and partial private key in the Internet of vehicles, and send to the roadside unit through a secure channel ; Store The registration information;
[0104] Further, S3 includes S31-S33, to the roadside unit For example, as follows:
[0105] S31: Roadside unit Send a registration request to the certification authority Through a secure channel , wherein Is the real identity of the roadside unit , wherein Is the current timestamp;
[0106] S32: Certification authority After receiving the registration request of the roadside unit , verify The freshness of And the legitimacy of ; after verification, the certification authority Select a random number And calculate , And ; the certification authority Send the tuple To the roadside unit Through a secure channel, wherein Is the pseudonym of the roadside unit In the Internet of vehicles, Is the partial key of the roadside unit ;
[0107] S33: Roadside unit After receiving the tuple , verify Whether it is true; if it is true, the roadside unit Select a random number , calculate And And publish , wherein Is a private key of the vehicle, for a public key of the vehicle;
[0108] S4: vehicle pseudonym application;
[0109] The vehicle sends a pseudonym application to the certification authority, The certification authority, with the pseudonym generation authority, based on a homomorphic encryption algorithm generates a pseudonym and a temporary private key for the vehicle; the vehicle uses its own registered private key to decrypt the pseudonym and the temporary private key generated by the certification authority and the pseudonym generation authority for it; the vehicle generates its own certificate based on the pseudonym and the temporary private key corresponding to the vehicle and uploads the certificate to the blockchain;
[0110] Further, S4 includes S41-S45, taking the vehicle as an example, as follows:
[0111] S41: the vehicle generates a pseudonym request message for a time period and signs it to obtain , wherein is the current timestamp; the vehicle sends to , as shown in steps ①-② in Figure 3 ;
[0112] S42: After receiving , verify the freshness of and the validity of ; after verification, the certification authority selects a random number and calculates the partial pseudonym and the partial private key of the vehicle using the secret value for the time period ; respectively encrypt and to obtain ciphertext and send to , wherein:
[0113]
[0114]
[0115] In addition, Also will calculate And Send As shown in steps ③ ~ ⑥ in Figure 3 ;
[0116] S43: After receiving , select a random number , and use the time period Secret value Calculate And ; Respectively on And Encrypted to get ciphertext , wherein:
[0117]
[0118]
[0119] Will And Homomorphic operation to get , wherein ; Send Vehicle And send To , wherein , as shown in steps ⑦ ~ ⑩ in Figure 3 ;
[0120] The certification authority And pseudonym generation mechanism Use Homomorphic encryption algorithm for vehicle to generate temporary private key and pseudonym, while ensuring the vehicle pseudonym verifiable, the realization of the vehicle's complete anonymity, the mechanism makes any entity of Internet of vehicles can not be tracked by the vehicle's real identity alone through the vehicle's pseudonym or public key;
[0121] S44: vehicle Receive After decryption to get the vehicle's pseudonym And temporary private key :
[0122]
[0123]
[0124] Vehicle Generate certificate and publishes it to the blockchain nodes; the blockchain nodes verify the certificate and upload it to the blockchain; after the certificate is uploaded, the vehicle queries the verification path of the certificate and publishes the temporary public key and pseudonym of the vehicle in the time period as shown in ⑪-⑬ in FIG. 8; Figure 3
[0125] S45: decrypts and saves the tuple to the accountability list , wherein as shown in ⑭ in FIG. 9. Figure 3
[0126] The accountability authority does not directly store the real identity of the vehicle in the accountability list , but stores the real identity of the vehicle after encryption, which can effectively resist privileged insider attacks; even if the enemy obtains the vehicle information stored in the accountability authority as an insider, it is impossible to infer the real identity and other private information of the vehicle;
[0127] S5: mutual authentication and key negotiation between vehicles;
[0128] The vehicle and other vehicles in the network perform mutual authentication and key negotiation, and communicate with the corresponding vehicles using the negotiated session key;
[0129] Further, step S5 includes S51-S54, which are exemplified by mutual authentication and key negotiation between vehicle and vehicle as follows:
[0130] S51: when vehicle needs to communicate with vehicle , vehicle selects a random number and calculates , and ; after the calculation is completed, vehicle generates an authentication request message and sends to vehicle ;
[0131] S52: vehicle receiving the authentication request message then verifying the freshness of ; if is fresh, the vehicle verifies whether is valid; if valid, the vehicle uses the vehicle public key to verify the path verifies whether the certificate of is on the blockchain; if verified, the vehicle selects a random number and computes , , and ; upon completion of the computation, the vehicle generates a feedback message and sends to the vehicle ;
[0132] S53: upon receiving the feedback message , the vehicle verifies the freshness of ; if is fresh, the vehicle uses the vehicle public key to verify the path verifies whether the certificate of is on the blockchain; if verified, the vehicle computes and verifies whether is valid; if valid, the vehicle computes and sends a confirmation message to the vehicle , where is the current timestamp;
[0133] S54: upon receiving the feedback message , the vehicle verifies the freshness of ; if is fresh, the vehicle verifies whether is valid; if valid, the vehicle and the vehicle use the session key for subsequent communications;
[0134] By embedding timestamps into the authentication parameters during the authentication process, the message freshness verification will fail if an adversary performs a replay attack, and the identity authentication will fail if the adversary replaces the timestamp. Furthermore, the authentication process utilizes a verification path. The authenticity of certificates in the tree reduces the computational overhead of the authentication process;
[0135] S6: Vehicles and Mutual authentication and key negotiation between them;
[0136] Vehicles and roadside units Perform mutual authentication and key negotiation, and use the negotiated session key with the corresponding roadside unit. To communicate;
[0137] Furthermore, step S6 includes S61~S64, with the vehicle with roadside units Taking mutual authentication and key negotiation as an example, the details are as follows:
[0138] S61: When the vehicle Need to be connected with roadside units During communication, the vehicle Select random number And calculate , and After the calculation is completed, the vehicle Generate authentication request message And Send to roadside unit ;
[0139] S62: Roadside Unit Received authentication request message Afterwards, verification The freshness; if It's fresh, a roadside unit. verify Is it valid? If so, roadside unit. Using vehicles Verification path in public key verify Is the certificate on the blockchain? If the verification passes, the roadside unit... Select random number And calculate , , and After the calculation is completed, the roadside unit Generate feedback message And Send to vehicle ;
[0140] S63: vehicle after receiving the feedback message , verifies the freshness of ; if is fresh, the vehicle calculates , and verifies whether is true; if true, calculates and sends a confirmation message to the vehicle ;
[0141] S64: roadside unit after receiving the feedback message , verifies the freshness of ; if is fresh, the roadside unit verifies whether is true; if true, the vehicle and the roadside unit use the session key for subsequent communication;
[0142] S7: malicious vehicle tracking;
[0143] pseudonym generation mechanism after receiving the malicious behavior report of the vehicle, generates a liability parameter according to the pseudonym information of the malicious vehicle and sends it to the liability mechanism ; tracks the real identity of the malicious vehicle based on the liability parameter;
[0144] Further, S7 includes S71-S73, which are specific to the vehicle as follows:
[0145] S71: when an entity in the network detects the malicious behavior of the vehicle in a time period , the entity sends the pseudonym of the vehicle , the time period and the malicious behavior of the vehicle to the pseudonym generation mechanism ;
[0146] S72: pseudonym generation mechanism after receiving the report message, confirms whether the malicious behavior is true; if true, calculates the liability parameter , and sends it to the liability mechanism ;
[0147] S73: liability mechanism from the accountability list searching for a real identity corresponding vehicle .
[0148] The authentication key negotiation method based on the blockchain in the Internet of Vehicles environment described above with reference to the accompanying drawings can realize the complete anonymous authentication of the vehicle in the Internet of Vehicles and the automatic revocation of the expired pseudonym. However, the present application is not limited to the described embodiments, and any changes, modifications, replacements and variations made to the embodiments without departing from the principles and spirits of the present application still fall within the protection scope of the present application.
Claims
1.A method for completely anonymous authentication and key agreement based on blockchain in a vehicle Internet of Things environment, characterized in that: (1) The method includes five types of entities, which are authentication authority , pseudonym generation authority , accountability authority , vehicle and roadside unit ; (2) The method comprises the following seven steps: S1: System initialization; authentication authority , pseudonym generation authority , and accountability authority perform system initialization, generate public parameters and upload to the blockchain; S2: Vehicle registration; The vehicle generates its own registration key pair and sends it to the certification authority The application is registered, the certification authority The legality of the vehicle identity is verified, if the verification is passed, The registration information of the vehicle is stored; S3: Roadside unit Registration; Roadside unit Generating a registration key pair for itself and sending it to the certification authority Applying for registration, the certification authority Verification The legitimacy of the identity; if the verification is passed, Calculation Pseudonym and partial private key in the Internet of vehicles, and send to the roadside unit through a secure channel ; Storage Registration information; S4: Vehicle pseudonym application; The vehicle transmits the pseudonym application to the authentication authority The authentication authority transmits the pseudonym application to the pseudonym generation authority The pseudonym generation authority generates a pseudonym for the vehicle based on the pseudonym application The authentication authority transmits the pseudonym application to the pseudonym generation authority The homomorphic encryption algorithm generates a pseudonym and a temporary private key for the vehicle The vehicle decrypts the certificate using its registered private key The pseudonym generation authority The pseudonym and temporary private key generated therefor; the vehicle generates its own certificate based on the pseudonym and temporary private key corresponding to the vehicle and uploads the certificate to the blockchain; S5: Mutual authentication and key agreement between vehicles; Mutual authentication and key agreement between vehicles and other vehicles in the network, and communication with the corresponding vehicles using the negotiated session key; S6: mutual authentication and key agreement between the vehicle and the server; Vehicle and road side unit performing mutual authentication and key agreement, and communicating with the corresponding road side unit using the agreed session key performing communication; S7: Malicious vehicle tracking; Pseudonym generation mechanism Upon receiving a malicious behavior report of a vehicle, generating a liability parameter according to the pseudonym information of the malicious vehicle and sending it to a liability mechanism ; Tracking the real identity of the malicious vehicle based on the liability parameter. 2.The method of claim 1, wherein: The five types of entities are described in detail as follows: (1) Certification Body The certification body Responsible for initializing the system, publishing public parameters, and managing all vehicles and roadside units in the vehicle-to-everything (V2X) network. Registration is required; furthermore, the certification body... With pseudonym generation agencies Collaborate to generate a pseudonym and temporary private key for the vehicle; (2) pseudonym generation authority : the pseudonym generation authority works in two parts: generating a pseudonym and a private key for a vehicle in cooperation with the certification authority , receiving a report of malicious behavior of the vehicle and assisting the accountability authority in tracking the real identity of the malicious vehicle; (3) a liability agency : the liability agency is responsible for tracking the true identity of a malicious vehicle; (4) Vehicle: the vehicle has certain computing power, can communicate with other vehicles , and can also communicate with ; through or communication, the vehicle can transmit and obtain traffic information, including: traffic congestion, accident warning and road information; (5) Roadside unit : The roadside unit is a fixed road infrastructure deployed at the roadside, responsible for collecting and publishing real-time traffic information, and providing communication services for vehicles. 3.The method of claim 1, wherein: The authentication authority in the step S1 , the pseudonym generation authority , and the accountability authority The specific method of system initialization is: S11: The certification body In a finite field Select an elliptic curve and an infinity The certification body According to the elliptic curve Generate a Cyclic group ,group The generator is denoted as ; S12: the certification authority select two random numbers and compute its own public key and public parameters where is the master secret, is the private key; S13: the certification authority selecting a one-way hash function and uploading the parameter tuple to the blockchain; S14: the pseudonym generation mechanism selects a random number , calculates its own public key and uploads it to the blockchain, where is the private key of ; the accountability mechanism selects a random number , , calculates its own public key and uploads the public key to the blockchain, where is the private key of ; S15: The pseudonym generation mechanism Divide time evenly into multiple time periods ; Select random number And calculate common parameters , , and ,in and Time period The system secret value; tuple of parameters Uploaded to the blockchain; Calculate based on the parameter tuple , ; within a time period , and Will be a time period Generate a new secret value. 4.The method of claim 3, wherein: In the step S15 and is a time period The process of generating the secret value is as follows: at a time period , the pseudonym generation mechanism selects a secret value and calculates , , and wherein and are system secret values for a time period ; uploading a parameter tuple to a blockchain; calculating and from the parameter tuple. 5.The method of claim 4, wherein: The registration process of the vehicle in the step S2 is to register the vehicle For example, the specific implementation is as follows: S21: vehicle According to The encryption algorithm generates its own private key And public key ; S22: vehicle generate a real identity unique to itself , and use to encrypt the plaintext to obtain ciphertext ; vehicle send the registration request to the certification authority , wherein is the current timestamp; S23: Received vehicle Registration request Then decrypt and verify the legitimacy of the vehicle's identity. If the vehicle... Legal identity tuple Store in the local database. 6.The method of claim 5, wherein: The step S3 of registering the roadside unit The registration process of the roadside unit For example, as follows: S31: Roadside unit to an authentication authority sending a registration request wherein for a roadside unit a true identity, a current timestamp; S32: Certification Body Received from roadside unit Registration request Afterwards, verification freshness and The legitimacy of the certification; after verification, the certification body Select random number And calculate , and Certification bodies tuples via secure channel Send to roadside unit ,in roadside unit The pseudonym in the Internet of Vehicles roadside unit Part of the private key; S33: Roadside Unit Received tuple Afterwards, verification Is it valid? If so, roadside unit. Select random number ,calculate and And announce ,in for private key, for The public key. 7.The method of claim 6, wherein: In the step S4, the vehicle applies for a pseudonym, and the vehicle For example, the specific implementation is as follows: S41 : vehicle generation time period pseudonym request message and signs it to obtain wherein is a current timestamp; vehicle sends ; S42: The certification body Received Afterwards, verification freshness and The legitimacy of the certification body; after verification. Select random number and use time period Secret Value Calculate vehicles Partial kana and part of the private key Certification bodies To each and conduct Encryption yields ciphertext and to pseudonym generation agencies send Certification bodies The ciphertext is obtained by encrypting using the elliptic curve cryptography algorithm. and and to the accountability agency send ; S43: Kana generation agency Received Then, select a random number. and use time period Secret Value calculate and ; Pseudonym generation organization To each and conduct Encryption yields ciphertext ; Pseudonym generation organization Will and Perform homomorphic operations to obtain ,in ; Pseudonym generation organization Will Send to vehicle and will Send to the accountability agency ,in ; S44: vehicle receiving decrypting it to obtain a pseudonym of the vehicle and a temporary private key : vehicle Generate Certificate And publish it to the blockchain nodes; the blockchain nodes verify the certificate. The certificate is verified for legality and uploaded to the blockchain; after the certificate is uploaded, the vehicle... Query the verification path of the certificate And publish the time period of the vehicle mentioned. Temporary public key and kana ; S45: accountability agency decrypt and and save the tuple to the accountability list where . 8.The method of claim 7, wherein: The mutual authentication and key agreement between the vehicles in the step S5 is to make the vehicles and the vehicles For example, the specific implementation is as follows: S51: Vehicles calculate and After the calculation is completed, the vehicle Generate authentication request message and will Send to vehicle ,in This is the current timestamp; S52: vehicle receiving the authentication request message after, verifying the freshness of the nonce; if the nonce is fresh, then verifying the legitimacy of the certificate and utilizing the vehicle verification path in the temporary public key verifying whether the certificate is on the blockchain; if the verification is passed, the vehicle computes and ; after the computation is completed, the vehicle generates a feedback message , and sends to the vehicle , where is the current timestamp; S53: vehicle receiving the feedback message afterwards, verifying the freshness of the certificate; if the certificate is fresh, the vehicle computes a verification path in the temporary public key verifies the certificate on the blockchain; if the verification is successful, the vehicle computes and verifies the legality of the certificate; if the verification is successful, the vehicle computes confirmation information and sends a confirmation message to the vehicle wherein is the current timestamp; S54: vehicle receiving the feedback message , verifying the freshness of the message; if the message is fresh, the vehicle verifying whether the message is valid; if valid, the vehicle and the vehicle using the session key for subsequent communication. 9.The method of claim 8, wherein: In step S6, the vehicle and Mutual authentication and key negotiation between vehicles and roadside units For example, the details are as follows: S61: Vehicles calculate and After the calculation is completed, the vehicle Generate authentication request message And Send to roadside unit ,in This is the current timestamp; S62: Roadside Unit Received authentication request message Afterwards, verification The freshness; if It's fresh, a roadside unit. verify The legality of the roadside unit; if the verification passes, the roadside unit Using vehicles Verification path in public key verify Is the certificate on the blockchain? If the verification passes, the roadside unit... calculate and ; After the calculation is completed, the roadside unit Generate feedback message And Send to vehicle ,in This is the current timestamp; S63: vehicle receiving the feedback message afterwards, verifying the freshness of the signature; if the signature is fresh, the vehicle computes and verifies the validity of the signature; if the verification is successful, the vehicle computes confirmation information and sends a confirmation message to the vehicle wherein is the current timestamp; S64: Roadside unit Receiving the feedback message After, verifying The freshness of the message; if The message is fresh, the roadside unit Verifies If the message is valid; if valid, the vehicle And the roadside unit Use the session key For subsequent communication. 10.The method of claim 9, wherein: The step S7 malicious vehicle tracking, with the vehicle For example, as follows: S71: When an entity in the network detects a vehicle In time period The entity will engage in malicious behavior, and the vehicle kana Time period The vehicle's malicious behavior was sent to a pseudonym generation agency. ; S72: Kana generation agency Upon receiving the report, verify whether the malicious behavior is true; if true, Calculate accountability parameters and will Send to the accountability agency ; S73: accountability agency from the accountability list searches for the real identity of the corresponding vehicle .
Citation Information
Patent Citations
Internet of vehicles node anonymous authentication method based on block chain
CN113596778A
Internet of vehicles pseudonym management method based on homomorphic encryption mechanism
CN114599028A