Message Encryption Transmission Method and Transmission Device

By using the key generated by the home signing user server and the pseudonym generated by the vehicle in vehicle identity authentication, the problems of low security of identity authentication and complex certificate management in the prior art are solved, and efficient and secure identity authentication and message transmission are achieved.

CN117979284BActive Publication Date: 2025-06-27CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410213576.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-27
Publication Date
2025-06-27
Estimated Expiration
2044-02-27

AI Technical Summary

Technical Problem

In the prior art, vehicle identity authentication is not safe and certificate management is complex, and there are problems such as complex certificate management, large communication overhead, and strong dependence on certificate authorities.

Method used

The message is signed by the first key generated by the home signing user server, the second key generated by the trusted unit, and the pseudonym generated by the vehicle, and the digital certificate signature algorithm and encryption algorithm are combined to realize identity authentication.

Benefits of technology

It improves the security of identity information, significantly reduces the computing overhead and communication overhead of messages, and realizes privacy protection on the basis of ensuring message integrity and real-timeness, and ensures the undeniability and unlinkability of messages.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117979284B_ABST
    Figure CN117979284B_ABST
Patent Text Reader

Abstract

The present application relates to the field of information security technology, and provides a message encryption transmission method and a transmission device. When the vehicle transmits a message to the verification unit, the method performs a digital certificate signature on the message by using a first key generated by a home subscriber server, a second key generated by a trusted unit, and a pseudonym generated by the vehicle, realizing the combined application of the digital certificate signature algorithm and the encryption algorithm in identity authentication. It can not only ensure the security of identity information, but also significantly reduce the computational overhead and communication overhead of the message. On the basis of ensuring the integrity and real-time nature of the message, it can achieve privacy protection, and ensure the non-repudiation and non-linkability of the message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular, to a message encryption transmission method and a transmission device. Background Art

[0002] In the field of the Internet of Vehicles (IoV), existing identity authentication methods usually rely on digital certificates provided by a Certificate Authority (CA). These certificates are managed through a Public Key Infrastructure (PKI), and there are problems such as complex certificate management, large communication overhead, and strong dependence on the CA. Summary of the Invention

[0003] In view of this, embodiments of this application provide a message encryption transmission method and a transmission device to solve the problems of low security of vehicle identity authentication and complex certificate management in the prior art.

[0004] In a first aspect of the embodiments of this application, a message encryption transmission method is provided, including:

[0005] Receiving a first Pre-Shared Key (PSK) sent by a Home Subscriber Server; i The first PSK i is generated by the Home Subscriber Server based on public parameters sent by a trusted unit;

[0006] Obtaining a Unique Identifier (UID) of a vehicle, i and generating a vehicle pseudonym (RID) based on the UID i , public parameters, and digest information sent by the Home Subscriber Server; i ;

[0007] Obtaining a message to be sent, and performing digital certificate signing on the message to be sent based on the first PSK i and the vehicle RID i to obtain a message data packet containing the digital certificate signature;

[0008] Sending the message data packet to a verification unit to enable the verification unit to verify the identity of the vehicle.

[0009] In a second aspect of the embodiments of this application, a message encryption transmission device is provided, including:

[0010] A receiving module, configured to receive a first PSK sent by a Home Subscriber Server i , the first PSK i is generated by the Home Subscriber Server based on public parameters sent by a trusted unit;

[0011] An acquisition module, configured to acquire the unique identifier UID of a vehicle i , and generate a vehicle pseudonym RID based on the UID i , public parameters, and the digest information sent by a home subscriber server i ;

[0012] The acquisition module is further configured to acquire a message to be sent, and perform a digital certificate signature on the message to be sent based on a first pre-shared key PSK i and the vehicle pseudonym RID i to obtain a message data packet containing the digital certificate signature;

[0013] A sending module, configured to send the message data packet to a verification unit, so that the verification unit verifies the identity of the vehicle.

[0014] The beneficial effects of the embodiments of the present application compared with the prior art are as follows: When the vehicle transmits a message to the verification unit in the embodiments of the present application, the message is digitally signed with a digital certificate by using a first key generated by a home subscriber server, a second key generated by a trusted unit, and a pseudonym generated by the vehicle, realizing the combined application of a digital certificate signature algorithm and an encryption algorithm in identity authentication. This not only ensures the security of identity information, but also significantly reduces the computational overhead and communication overhead of the message. On the basis of ensuring the integrity and real-time nature of the message, it can achieve privacy protection and ensure the non-repudiation and non-linkability of the message. Description of the Drawings

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0016] Figure 1 is a schematic structural diagram of an LTE-V network model provided by an embodiment of the present application.

[0017] Figure 2 is a model diagram of a replay attack in the process of vehicle-to-everything communication.

[0018] Figure 3 is a model diagram of a man-in-the-middle attack in the process of vehicle-to-everything communication.

[0019] Figure 4 is a schematic flow diagram of the process of a man-in-the-middle attack.

[0020] Figure 5 is a schematic flow diagram of a message encryption transmission method provided by an embodiment of the present application.

[0021] Figure 6 It is a schematic flowchart of another message encryption and transmission method provided by an embodiment of the present application.

[0022] Figure 7 It is a schematic flowchart of a method for the verification unit provided by an embodiment of the present application to verify the identity of a vehicle.

[0023] Figure 8 It is a schematic flowchart of an algorithm for adding a random number to defend against replay attacks provided by an embodiment of the present application.

[0024] Figure 9 It is a schematic flowchart of yet another message encryption and transmission method provided by an embodiment of the present application.

[0025] Figure 10 It is a signal interaction diagram of the message encryption and transmission method provided by an embodiment of the present application.

[0026] Figure 11 It is a schematic diagram of a message encryption and transmission device provided by an embodiment of the present application.

[0027] Figure 12 It is a schematic diagram of a message encryption and transmission system provided by an embodiment of the present application.

[0028] Figure 13 It is a schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0029] In the following description, specific details such as specific system architectures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0030] A message encryption and transmission method and device according to an embodiment of the present application will be described in detail below with reference to the accompanying drawings.

[0031] As mentioned above, in the field of IoV, existing identity authentication methods usually rely on digital certificates provided by CAs. Specifically, existing vehicle identity authentication methods mainly include the following:

[0032] 1) Certificate authentication method based on PKI. This method has the following disadvantages: The PKI system requires a trusted CA, which may become a single point of failure of the system. In addition, the issuance and management of certificates involve complex processes, increasing the overhead of the system.

[0033] 2) Traditional symmetric key exchange method. This method has the following disadvantages: There are problems in key distribution and management in the traditional symmetric key exchange method. In a large-scale vehicle-to-everything (V2X) network, key management can become very complex and may lead to system insecurity.

[0034] 3) Identity authentication method based on asymmetric keys. This method has the following disadvantages: Although the asymmetric key method provides certain security, in large-scale applications in the V2X network, traditional asymmetric key management may become inefficient and costly.

[0035] 4) Method using pre-shared keys. This method has the following disadvantages: Using pre-shared keys may involve security issues because the pre-sharing and management of keys may be threatened.

[0036] In view of this, embodiments of this application are based on the Elliptic Curve Cryptography (ECC) algorithm and provide an efficient and reliable certificate-less identity authentication method for the V2X network based on ECC. This method first improves the conventional V2X network model and proposes a new V2X network model, the LTE-V network model.

[0037] Figure 1 It is a schematic structural diagram of the LTE-V network model provided by embodiments of this application. As Figure 1 shown, the LTE-V network model includes a Trusted Authority (TA), a Road Side Unit (RSU), an On Board Unit (OBU), and a Home Subscriber Server (HSS). Solid double-headed arrows represent wired connections, the lightning symbol represents direct communication between two objects without passing through an intermediate base station, and dashed double-headed arrows represent communication between two objects through an intermediate base station. Through the LTE-V network, each OBU periodically (about 100 ms to 300 ms) sends traffic-related messages to the RSU. Therefore, the messages are transmitted to the traffic management center or the transportation application server through a secure wired channel for analysis and decision-making.

[0038] Among them, the TA is assumed to be a trusted entity and has sufficient computing power and storage capacity. It is responsible for system setup and trust management, can associate the real identity of the vehicle with information, and revoke malicious information.

[0039] The HSS is assumed to be trusted and has sufficient computing power and storage space. It is responsible for the registration of vehicle OBUs and RSUs. To prevent non-repudiation, both the TA and the HSS can perform conditional tracking.

[0040] RSUs are assumed to be semi-trusted, with insufficient computing power and storage space. RSUs located along roads or at intersections use LTE-V cells (LTE-V-Cells) to communicate with OBUs within their network coverage and communicate with the TA and HSS via a wired connection.

[0041] Due to the limited computing power and storage space of the OBU, it is assumed to be untrusted. It is allowed to directly communicate with other OBUs and pedestrians through the LTE-V network and communicate with the RSU through LTE-V-Cell technology.

[0042] In the LTE-V network model proposed in the embodiments of this application, if a convenient identity authentication scheme is to be proposed, the scheme must meet privacy protection, authentication and integrity, autonomy, non-repudiation, and anti-attack capabilities.

[0043] Among them, privacy protection means that the privacy of the OBU must be protected, including identity privacy, unlinkability, and conditional traceability. Identity privacy means that the true identity and location information of the OBU must be protected to prevent illegal access. Attackers and other OBUs must not be able to extract the true identity and location information of the OBU from traffic-related messages transmitted. Conditional traceability means that trusted entities should be able to extract the identity of misbehaving vehicles from disputed messages and impose corresponding legal penalties. Unlinkability means that except for the TA and HSS, no other party can trace a large number of signed messages to their source.

[0044] Authentication and integrity mean that the verifier must be able to check the authenticity of traffic-related messages to determine that the messages come from the expected sender. In addition, the integrity of the received messages must be investigated to detect any unauthorized modifications.

[0045] Autonomy means that frequent or permanent contact with the registration center must be avoided. The OBU must only request registration parameters from the HSS once, and subsequently it should be able to communicate using a pseudo-identity and key without interacting with the HSS.

[0046] Non-repudiation means that after successful authentication and conditional traceability, the OBU must not refuse to send disputed messages.

[0047] Anti-attack capability means that the proposed scheme must be able to resist common underlying communication attacks, such as replay and man-in-the-middle (MITM) attacks, etc.

[0048] A replay attack, also known as a replay, playback, or freshness attack, refers to an attacker sending a packet that the destination host has already received to deceive the system, mainly used in the identity authentication process to undermine the correctness of authentication.Figure 2 It is a model diagram of replay attack in the vehicle networking communication process. As Figure 2 shown, the vehicle transmits its identity information to the RSU for authentication. However, other malicious vehicles may obtain its identity information. Although the identity message is encrypted and the attacker cannot obtain the original information of the encrypted message, the attacker can resend this message to the RSU at the next time point, causing the RSU to repeatedly receive the same message, resulting in incorrect judgment and causing traffic accidents.

[0049] To make the vehicle networking system more secure, replay attacks need to be resisted. Common methods to resist replay attacks include:

[0050] 1) Adding a secret order value. The secret order value needs to be different each time in a replay attack. Its advantage is that the two parties do not need to keep time synchronization. Its disadvantage is that it is necessary to save the used random secret order values additionally, which requires storage and query overhead.

[0051] 2) Adding a timestamp. The timestamp represents the number of the current moment, while the timestamp of the replay will be relatively far from the current moment. Its advantage is that it does not require memory overhead. Its disadvantage is that the computer clocks of all communication parties must be synchronized (the better the synchronization, the less likely to be attacked).

[0052] 3) Adding a sequence number. The two parties add a gradually increasing integer to the message. As long as a discontinuous sequence number message (too large or too small) is received, a replay threat is considered. Its advantage is that it does not require time synchronization and the amount of information saved is small. Its disadvantage is that if the attacker successfully decrypts the message, the sequence number will be obtained and then data can be forged.

[0053] A man-in-the-middle attack means that the attacker creates independent connections with both ends of the communication and exchanges the data it receives, making both ends of the communication think that they are directly communicating with each other through a private connection. In fact, the entire session is completely controlled by the attacker. In a man-in-the-middle attack, the attacker can intercept the calls of both communication parties and insert new content. A man-in-the-middle attack is an attack lacking mutual authentication. Most encryption protocols specifically add some special authentication methods to prevent man-in-the-middle attacks. For example, the SSL protocol can verify whether the certificates used by one or both parties participating in the communication are issued by an authoritative and trusted digital certificate authentication agency and can perform two-way identity authentication.

[0054] Figure 3 It is a model diagram of man-in-the-middle attack in the vehicle networking communication process. As Figure 3 shown, there is a malicious third party between the sender and the receiver stealing the requested information, so that the sender and the receiver do not communicate directly. The specific process of the man-in-the-middle attack is as Figure 4 shown. A complete man-in-the-middle attack process:

[0055] 1) A requests B for the public key, but it is intercepted by C.

[0056] 2) C sends a public key request to B.

[0057] 3) B sends the public key to C.

[0058] 4) C intercepts B's public key and then replaces it with its own public key and sends it to A.

[0059] 5) A regards C's public key as B's public key, encrypts the information with it and sends it to B.

[0060] 6) C intercepts the encrypted information, decrypts it with its own private key to obtain the plaintext. At the same time, forges new information, encrypts it with B's public key and sends it to B.

[0061] 7) B obtains the encrypted information and decrypts it with its own private key, thus obtaining A's information.

[0062] Common methods to resist man-in-the-middle attacks include:

[0063] 1) Use encryption technology. Encrypting the communication content can effectively prevent man-in-the-middle from stealing the communication content.

[0064] 2) Use digital certificates. Digital certificates are electronic files issued by a trusted third party and can be used to verify the identities of communication parties. Using digital certificates can effectively prevent man-in-the-middle from disguising their identities.

[0065] 3) Use Secure Socket Layer (SSL) or Transport Layer Security (TLS) protocols. SSL and TLS are two commonly used network security protocols and can be used to protect the security of network communication.

[0066] 4) Use Virtual Private Network (VPN) technology. VPN can provide a secure communication channel for users and can effectively prevent man-in-the-middle attacks.

[0067] On this basis, the embodiment of the present application provides a method for encrypted message transmission. When the vehicle transmits a message to the verification unit, the message is digitally signed with the first key generated by the home subscriber server, the second key generated by the trusted unit, and the pseudonym generated by the vehicle, realizing the application of the digital certificate signature algorithm in combination with the encryption algorithm to identity authentication. It can not only ensure the security of identity information, but also significantly reduce the computational overhead and communication overhead of the message. On the basis of ensuring the integrity and real-time nature of the message, it can achieve privacy protection and ensure the non-repudiation and non-linkability of the message.

[0068] Figure 5 It is a schematic flow chart of a message encryption transmission method provided by an embodiment of the present application. Figure 5 The message encryption transmission method can be executed by Figure 1 the vehicle. As Figure 5 shown, the message encryption transmission method includes the following steps:

[0069] In step S501, receive the first key PSK sent by the home subscriber server i .

[0070] Among them, the first key PSK i is generated by the home subscriber server based on the public parameters sent by the trusted unit.

[0071] In step S502, obtain the unique identifier UID of the vehicle i , and generate the vehicle pseudonym RID based on the UID i , public parameters and the digest information sent by the home subscriber server i .

[0072] In step S503, obtain the message to be sent, and perform digital certificate signature on the message to be sent based on the first key PSK i and the vehicle pseudonym RID i to obtain a message data packet containing the digital certificate signature.

[0073] In step S504, send the message data packet to the verification unit so that the verification unit verifies the identity of the vehicle.

[0074] In the embodiment of the present application, the vehicle can first receive the first key PSK sent by the home subscriber server i . Among them, the vehicle can receive the first key PSK sent by the HSS through its OBU via the vehicle network i . The first key PSK i is generated by the HSS based on the public parameters sent by the TA. Further, the OBU can also receive the digest information from the HSS.

[0075] In the embodiment of the present application, the vehicle can also obtain the unique identifier UID of the vehicle i , and generate the vehicle pseudonym RID based on the UID i , public parameters and the received digest information i . Further, the vehicle can use the first key PSK i and the vehicle pseudonym RID iThe message to be sent is digitally signed with a digital certificate to obtain a message data packet containing the digital certificate signature. In this message data packet, the message encrypted with the vehicle key and the digital certificate signature after the digital certificate signature calculation of the message are included. In this way, the combination of the digital certificate signature algorithm and the encryption algorithm is used to encrypt the message, ensuring the security of the identity information.

[0076] In the embodiment of the present application, the vehicle can send the message data packet of the generated message to be sent to the verification unit, so that the verification unit verifies the message and receives the message after the verification passes. Among them, the verification unit can be an RSU.

[0077] According to the technical solution provided by the embodiment of the present application, when the vehicle transmits a message to the verification unit, the message is digitally signed with the first key generated by the home subscriber server, the second key generated by the trusted unit, and the pseudonym generated by the vehicle, realizing the application of the digital certificate signature algorithm and the encryption algorithm in combination for identity authentication. It can not only ensure the security of the identity information, but also significantly reduce the computational overhead and communication overhead of the message. On the basis of ensuring the integrity and real-time nature of the message, it can achieve privacy protection and ensure the non-repudiation and non-linkability of the message.

[0078] In the embodiment of the present application, the public parameters may include the base point P on the elliptic curve y 2 =x 3 +ax + b mod p, the large prime numbers p and q, the system public key P pub generated by the trusted unit, the hash functions h0, h1, h2, and h3 selected by the trusted unit, and the time difference function f(t c ). Among them, the base point P ∈ G, G is the additive group of order q generated by the point P on the elliptic curve, a, b ∈ F q , F q is the finite field of the large prime number q; h0: {0, 1} * → Z q , h1: h2: h3: {0, 1} * represents the set of all possible binary strings, including the empty string, → is the mapping symbol, Z q is the set of integers modulo q, is the multiplicative group modulo q, and this multiplicative group set contains all integers relatively prime to q.

[0079] That is to say, TA can define an elliptic curve y 2 =x 3 +ax + b mod p and select the base point P. On the other hand, TA randomly generates such that Ppub = sP, where s is the system private key and P pub is the system public key. TA can also select 4 hash functions (h0, h1, h2, h3). The hash functions are used to map information of different lengths into a fixed-length digest. h0: {0, 1} * → Z q represents a mapping or hash function from the set of binary strings {0, 1}* to the set of integers Zq modulo q. Here, h0 represents the name of the hash function, usually the symbol used to represent this mapping; {0, 1}* represents the set of all possible binary strings, including the empty string, which is the input domain, that is, the input accepted by the hash function; → represents the arrow of the mapping or function, indicating the mapping relationship from the input to the output; Zq represents the set of integers modulo q, which is the output domain of the hash function, meaning that the hash function maps a binary string to an element in the set of integers modulo q.

[0080] TA selects the function f(t c ) to determine the time interval on the network, where tc is the current time, which allows TA to manage the generation of vehicle pseudonyms. It also selects a random variable TA can save in TA's database, send to HSS, and publish the public parameters params = {P, p, q, P pub , h0, h1, h2, h3, f(t c )}.

[0081] In the embodiment of the present application, the first key PSK i is calculated by the home subscriber server using the following formula: where A i = α i P i , x is an integer randomly generated by the home subscriber server, and

[0082] Furthermore, α i = h1(x, UID i , P pub ), β i = h1(ID i , UID i , params, T pub ), where params are the public parameters, params = {P, p, q, P pub , h0, h1, h2, h3, f(t c )}, ID i is the vehicle identifier, and Tpub = xP.

[0083] Furthermore, the digest information sent by the home subscriber server includes first digest information, and the first digest message includes K i and Λ i ; where K i = β i A i , represents a set of hash functions with ID i information.

[0084] That is to say, different from the traditional solution, in the embodiment of the present application, the secret keys of the vehicle are not all generated by the TA, but part of them are generated by the TA and the other part is generated by the vehicle itself. Among them, the process of the vehicle generating part of the secret keys by itself is as follows:

[0085] The vehicle OBU selects a unique identifier UID i of the vehicle, and the UID i can be, for example, the registration information of the vehicle, including the identity information of the vehicle user and the vehicle identification number (VIN), etc., and submits the vehicle identification ID i and UID i to the HSS. The HSS randomly generates and calculates T pub = xP, (x, T pub ) is the key pair of the HSS.

[0086] The HSS calculates the first secret key α i of the vehicle OBU through the following formula i = h1(x, UID pub ), P i ), β i = h1(ID i , UID pub , params, T i ), K i = β i A where A i = α i P i , The HSS sends to the vehicle, sends (ID i , UID i , K i ) to the TA through a secure channel, and saves (x, ID i , UID i , Ki ) in its database and publish its public key T pub .

[0087] Figure 6 FIG. is a schematic flow chart of another message encryption and transmission method provided by an embodiment of the present application. Among them, Figure 6 Steps S605 to S607 in the illustrated embodiment are substantially the same as Figure 5 Steps S502 to S504 in the illustrated embodiment, and will not be described herein again. As Figure 6 shown, the message encryption and transmission method further includes the following steps:

[0088] In step S601, receive the first key PSK i and the first digest information sent by the home subscriber server.

[0089] In step S602, the vehicle generates second digest information.

[0090] In step S603, in response to verifying and confirming that the identity of the vehicle is valid based on the first digest information, the second digest information, the first key, and the public parameters, obtain a time period through a time difference function.

[0091] In step S604, in response to determining that the time period is a valid time period, determine that the condition for generating a pseudonym is satisfied.

[0092] In an embodiment of the present application, the vehicle can first receive the first key PSK i and the first digest information sent by the home subscriber server. As described above, the first digest message may include K i and Λ i . Further, the vehicle can also generate second digest information i and i UID pub based on information such as its own acquired ID and wherein, Then, the vehicle verifies and whether it holds. If so, continue to verify whether the equation holds. If it holds, it means that the identity of the vehicle is valid. At this time, the vehicle can receive the parameter set sent by the HSS and obtain the time period T c through the time difference function f(t s ). Finally, if it is determined that the time period T s is a valid time period, it can be determined that the current condition for generating a pseudonym is satisfied.

[0093] When the above conditions for generating kana are met, the vehicle can use the formula to generate a vehicle kana, where ⊕ is the exclusive OR operator.

[0094] As mentioned above, in the embodiments of the present application, part of the vehicle's key is generated by the TA, and the other part is generated by the vehicle itself. In the embodiments of the present application, the TA can generate the second key of the vehicle in the following manner: Obtain a random number Determine PK i = y i P is the public key in the second key of the vehicle, is the private key in the second key of the vehicle. Subsequently, the vehicle can receive the second key from the TA.

[0095] In the embodiments of the present application, the vehicle can perform a digital certificate signature on the message to be sent based on the received first key PSK i , the second key, and the vehicle kana RID i to obtain a message data packet containing the digital certificate signature. Specifically, the following method can be used to perform a digital certificate signature on the message to be sent:

[0096] First, obtain random numbers r i 1 and r i 2 , where Then calculate h 2i = h2(m i , ID i , UID i , SK i , T pub ), where m i is the message to be sent, and h 2i represents performing a hash calculation on the message. Next, calculate θ i = r i 1 + h 2i r i 2 , D i = θ i P, and calculate R i = D i + K i , where h 3i = h3(m i . R i , RID i , PK i , t i ), θ i , D i , R i and δ iAll are intermediate calculation parameters, h 3i Indicates performing a hash calculation on the message. Finally, determine σ i =(R i , δ i ) to sign the digital certificate, and determine (m i , σ i , RID i , PK i , t i ) as the message data packet, where t i is the current timestamp.

[0097] In the embodiment of the present application, the verification unit can verify the identity of the vehicle. Figure 7 It is a schematic flowchart of the method for the verification unit provided by the embodiment of the present application to verify the identity of the vehicle. Figure 7 The verification method of Figure 1 can be executed by the RSU of Figure 7 As shown in

[0098] In step S701, receive the message data packet sent by the vehicle.

[0099] Among them, the message data packet includes at least a timestamp.

[0100] In step S702, in response to verifying that the timestamp is valid, verify the digital certificate signature of the message data packet.

[0101] In step S703, in response to verifying that the digital certificate signature is valid, receive the message.

[0102] In the embodiment of the present application, the RSU can first receive the message data packet (m i , σ i , RID i , PK i , t i ) sent by the vehicle, where m i is the message sent by the vehicle, σ i is the digital certificate signature of the vehicle, RID i is the vehicle pseudonym, PK i is the public key of the vehicle, and t i is the current timestamp when the vehicle sends the message data packet. Next, the RSU can verify the timestamp in the message data packet. When it is verified that the timestamp is valid, the digital certificate signature of the message data packet can be further verified. If it is verified that the digital certificate signature is valid, then receive the message m i .

[0103] In the embodiment of the present application, verify that the timestamp ti Valid, it can be: determining the arrival time T of the message data packet; in response to the difference between the arrival time T and the timestamp t i being less than a preset time difference threshold, determining the timestamp t i is valid.

[0104] In the embodiments of the present application, the message data packet can be a single message data packet or include n message data packets, where n is a positive integer greater than 1. When the message data packet is a single message data packet, verifying the digital certificate signature of the message data packet can be implemented in the following manner:

[0105] Obtain h 3i = h3(m i , R i , RID i , PK i , t i ), where h 3i represents performing a hash calculation on the message, h3 is a hash function, h3: {0,1} * represents the set of all possible binary strings, including the empty string, → is a mapping symbol, Z q is the set of integers modulo q, is the multiplicative group modulo q, and this multiplicative group set contains all integers relatively prime to q. q is a large prime number in the elliptic curve y 2 = x 3 + ax + b mod p, and R i is an intermediate parameter when the vehicle calculates the digital certificate signature of the message. R i is included in σ i ;

[0106] In response to the verification, determining that δ i P = R i + h 3i (PK i ) + T pub , determining that the digital certificate signature is valid, where δ i is an intermediate parameter when the vehicle calculates the digital certificate signature of the message. δ i is also included in σ i , P is the base point on the elliptic curve y 2 = x 3 + ax + b mod p, P ∈ G, G is the additive group of order q generated by the point P on the elliptic curve, T pub = xP, x is an integer randomly generated by the home subscriber server, and

[0107] When the message data packet includes n message data packets, the digital certificate signature of the message data packet can be verified in the following manner:

[0108] Obtain a random vector {ξ i} 1≤i≤n , where {ξ i} ∈ [1, 2 l , and l is the word length;

[0109] Calculate h 3i = h3(m i , R i , RID i , PK i , t i ) 1≤i≤n ;

[0110] In response to the verification determination Determine that the digital certificate signature is valid.

[0111] In this way, due to the complexity of the elliptic curve algorithm, the verifier needs to use the equations δ i P = R i + h 3i (PK i ) + T pub and to verify the integrity and validity of the identity message (m i , σ i , RID i , PK i , t i ). Since the identity information has been hashed to obtain a digest, according to the properties of the hash function, if the message changes even slightly, the above two equations will not hold, and if the message is retransmitted or the delay is too high, the authentication will also fail. Therefore, the technical solution of the embodiment of the present application can meet the message integrity and real-time requirements.

[0112] On the other hand, the vehicle OBU transmits a group of messages (m i , σ i , RID i , PK i , t i ), and generates a pseudonym through this message Therefore, in order to obtain the true identity information from the pseudonym, the attacker must know UID i and K i , because the hash function is irreversible and these messages are protected, the attacker cannot obtain the true ID of the vehicle OBU, thus achieving privacy protection.

[0113] Furthermore, in the technical solution provided by the embodiments of the present application, the TA and HSS can trace the true identity of the OBU through messages. Therefore, no OBU can refuse to sign messages, thus realizing non-repudiation.

[0114] Furthermore, since each communication session uses a dynamically changing pseudonym, no attacker can track the vehicle's location information from the transmitted messages. Additionally, because there are different random values r i 1 、r i 2 、y i and h 2i , these random values are all used to generate the vehicle's signature, and this signature cannot be used for two different communications. Therefore, no attacker can track the vehicle's messages, thus realizing unlinkability.

[0115] Still further, in the message signature operation , a timestamp t i is added to the message and a hash operation is performed. At this time, the receiver will first check whether the timestamp has expired. If it has expired, this message will be discarded, thereby being able to resist replay attacks. However, the timestamp has relatively high requirements for the time synchronization of different machines. Therefore, the embodiments of the present application also combine the generation of random numbers to resist replay attacks.

[0116] Based on digital signatures, the embodiments of the present application further propose an algorithm for adding random numbers to defend against replay attacks. Figure 8 is a schematic flow diagram of the algorithm for adding random numbers to defend against replay attacks provided by the embodiments of the present application. As Figure 8 shown, the method includes the following steps:

[0117] 1) Set a random number. A random number can be generated by using the random function random so that the message contains the random number to ensure the uniqueness and freshness of the message.

[0118] 2) When the sender transmits data, the generated random number is transmitted to the receiver together.

[0119] 3) After receiving the message and the random number, the receiver detects in its own database whether the random number requested by the message has appeared before. If it is detected that this random number is repeated with the data carried in a previous data transmission, it can be considered that a replay attack has occurred.

[0120] 4) The receiver establishes a corresponding index for each received random number and stores it in the database.

[0121] In the technical solution provided by the embodiment of the present application, when using a random number to resist replay attacks, first use the hash function encryption algorithm to extract the digital digest of the transmitted plaintext data, and then send it to the receiving party together with the generated random number. After receiving the information, the receiving party first decrypts it with the public key of the sending party to obtain the plaintext data, compares the decrypted data with the original plaintext data, and then detects whether the random number appears for the first time, so as to ensure the integrity of the data and effectively resist replay attacks.

[0122] At the same time, since a man-in-the-middle can use the obtained public key of the sending party to impersonate the sending party. If a signature certificate is added to the public key of the sending party, then this public key cannot be used by others. Therefore, using digital signatures can effectively prevent man-in-the-middle attacks. Thus, the technical solution provided by the embodiment of the present application can resist man-in-the-middle attacks.

[0123] Figure 9 It is a schematic flow diagram of another message encryption and transmission method provided by the embodiment of the present application. Figure 9 The message encryption and transmission method can be jointly executed by Figure 1 the TA, HSS, RSU, and OBU of Figure 9 As shown, the message encryption and transmission method includes the following steps:

[0124] In step S901, the trusted unit generates public parameters and sends the public parameters to the home subscriber server, the verification unit, and the vehicle.

[0125] In step S902, the home subscriber server generates the first key PSK i and the digest information, and sends the first key PSK i and the digest information to the vehicle.

[0126] In step S903, the vehicle generates a vehicle pseudonym RID i based on the unique identifier UID i of the vehicle, the public parameters, and the digest information.

[0127] In step S904, the vehicle obtains the second key from the trusted unit and performs a digital certificate signature on the message to be sent based on the first key PSK i , the second key, and the vehicle pseudonym RID i to obtain a message data packet containing the digital certificate signature.

[0128] In step S905, the verification unit receives the message data packet and, after passing the verification of the timestamp and the digital certificate signature in the message data packet, receives the message.

[0129] In the embodiment of the present application, the trusted unit first generates public parameters and sends the public parameters to the home subscriber server, the verification unit, and the vehicle. The home subscriber server generates the first key PSK based on the public parameters i and the digest information, and sends the first key PSK i and the digest information to the vehicle. The vehicle generates the vehicle pseudonym RID based on the unique identifier UID of the vehicle i , the public parameters, and the digest information i . Meanwhile, the vehicle obtains the second key from the trusted unit, and based on the first key PSK i , the second key, and the vehicle pseudonym RID i performs digital certificate signature on the message to be sent, and obtains the message data packet containing the digital certificate signature. The verification unit receives the message data packet, and after verifying the timestamp and the digital certificate signature in the message data packet, receives the message.

[0130] Figure 10 is the signal interaction diagram of the message encryption and transmission method provided by the embodiment of the present application. As Figure 10 shown, the TA first generates and distributes the public parameters to the HSS, RSU, and OBU; the HSS generates the first key based on the public parameters and distributes the first key to the OBU; the TA also generates the second key and distributes it to the OBU; the OBU receives the first key and the second key after the identity verification is passed, and generates the pseudonym; the OBU performs digital authentication signature on the message based on the first key, the second key, and the pseudonym, and obtains the message data packet; the OBU sends the message data packet to the RSU, and the RSU receives the message after successfully authenticating the timestamp and the digital authentication signature in the message data packet.

[0131] Adopting the technical solution of the embodiment of the present application, there is no need to rely on the traditional certificate issuing authority, reducing the complex certificate management process and the communication and computing overhead. By using the ECC key negotiation algorithm, a fast and efficient key negotiation process is realized, accelerating the establishment of communication, facilitating the timely communication between vehicle networking devices, and improving the communication efficiency. Utilizing the high security of ECC, the strength of identity verification is improved, and some attacks and security risks existing in traditional identity authentication methods are prevented. The certificate-free design reduces the dependence on centralized certificate management, making this method more suitable for the scenario of large-scale deployment of vehicle networking, and maintaining the flexibility and scalability of the system. At the same time, this method does not require prior distribution and management of certificates, simplifies the vehicle deployment process, reduces the complexity of maintenance and management, and makes the system easier to implement and maintain.

[0132] All the above optional technical solutions can be combined arbitrarily to form the optional embodiments of the present application, which will not be elaborated one by one here.

[0133] The following is an embodiment of the apparatus of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the apparatus embodiment of the present application, please refer to the method embodiment of the present application.

[0134] Figure 11 It is a schematic diagram of a message encryption and transmission device provided by an embodiment of the present application. As Figure 11 shown, the device includes:

[0135] A receiving module 1101, configured to receive a first pre-shared key PSK sent by a home subscriber server i , and the first pre-shared key PSK i is generated by the home subscriber server based on the public parameters sent by the trusted unit.

[0136] An obtaining module 1102, configured to obtain a unique identifier UID of a vehicle i , and generate a vehicle pseudonym RID based on the UID i , the public parameters, and the digest information sent by the home subscriber server i .

[0137] The obtaining module 1102 is further configured to obtain a message to be sent, and perform a digital certificate signature on the message to be sent based on the first pre-shared key PSK i and the vehicle pseudonym RID i to obtain a message data packet containing the digital certificate signature.

[0138] A sending module 1103, configured to send the message data packet to a verification unit, so that the verification unit verifies the identity of the vehicle.

[0139] According to the technical solution provided by the embodiment of the present application, when the vehicle transmits a message to the verification unit, the digital certificate signature of the message is performed by using the first key generated by the home subscriber server, the second key generated by the trusted unit, and the pseudonym generated by the vehicle, so that the digital certificate signature algorithm and the encryption algorithm are combined and applied to identity authentication, which can not only ensure the security of identity information, but also significantly reduce the computational overhead and communication overhead of the message. On the basis of ensuring the integrity and real-time nature of the message, privacy protection can be achieved, and the non-repudiation and non-linkability of the message can be ensured.

[0140] In the embodiment of the present application, the public parameters include the base point P, the large prime numbers p and q in the elliptic curve y 2 =x 3 +ax+bmodp, the system public key P pub generated by the trusted unit, the hash functions h0, h1, h2, and h3 selected by the trusted unit, and the time difference function f(t c); where the base point P ∈ G, G is an additive group of order q generated by the point P on the elliptic curve, and a, b ∈ F q , F q is a finite field of large prime number q; h0: {0, 1} * → Z q , h1: h2: h3: {0, 1} * represents the set of all possible binary strings, including the empty string, → is the mapping symbol, and Z q is the set of integers modulo q, is the multiplicative group modulo q, and this multiplicative group set contains all integers relatively prime to q.

[0141] In the embodiment of the present application, the first key PSK i is calculated by the home subscriber server using the following formula: where A i = α i P i , x is an integer randomly generated by the home subscriber server, and α i = h1(x, UID i , P pub ); β i = h1(ID i , UID i , params, T pub ), where IDi is the vehicle identifier, params are the public parameters, params = {P, p, q, P pub , h0, h1, h2, h3, f(t c )}, and T pub = xP.

[0142] In the embodiment of the present application, the digest information sent by the home subscriber server includes the first digest information; before generating the vehicle pseudonym, it further includes: the vehicle generates the second digest information; in response to verifying and confirming that the identity of the vehicle is valid based on the first digest information, the second digest information, the first key, and the public parameters, a time period is obtained through a time difference function; in response to determining that the time period is a valid time period, a vehicle pseudonym is generated.

[0143] In the embodiment of the present application, before obtaining the message to be sent, it further includes: obtaining the second key sent by the trusted institution; where the second key is generated by the trusted unit in the following manner: obtaining a random number Determine PK i = y i P is the public key in the second key of the vehicle, It is the private key in the second key of the vehicle.

[0144] In the embodiments of the present application, based on the first key PSK i and the vehicle pseudonym RID i perform a digital certificate signature on the message to be sent to obtain a message data packet containing the digital certificate signature, including: obtaining a random number r i 1 and r i 2 , where calculate h 2i =h2(m i , ID i , UID i , SK i , T pub ), where m i is the message to be sent, and h 2i represents performing a hash calculation on the message; calculate θ i =r i 1 +h 2i r i 2 , D i =θ i P; calculate R i =D i +K i , where h 3i =h3(m i .R i , RID i , PK i , t i ), θ i , D i , R i and δ i are all intermediate calculation parameters, and h 3i represents performing a hash calculation on the message; determine σ i =(R i , δ i ) as the digital certificate signature; determine (m i , σ i , RID i , PK i , t i ) as the message data packet, where t i is the current timestamp.

[0145] In the embodiments of the present application, the verification unit verifies the identity of the vehicle, including: receiving the message data packet (m i , σ i , RID i, PK i , t i ), where m i is the message sent by the vehicle, σ i is the digital certificate signature of the vehicle, RID i is the vehicle pseudonym, PK i is the public key of the vehicle, t i is the current timestamp when the vehicle sends the message data packet; in response to the verification determining that the timestamp t i is valid, verify the digital certificate signature of the message data packet; in response to the verification determining that the digital certificate signature is valid, receive the message m i .

[0146] In the embodiments of the present application, in response to the message data packet being a single message data packet, verifying the digital certificate signature of the message data packet includes: obtaining h 3i = h3(m i , R i , RID i , PK i , t i ), where h 3i represents performing a hash calculation on the message, h3 is a hash function, h3: {0,1} * represents the set of all possible binary strings, including the empty string, → is the mapping symbol, Z q is the set of integers modulo q, is the multiplicative group modulo q, and this multiplicative group set contains all integers relatively prime to q. q is the large prime number in the elliptic curve y 2 = x 3 + ax + b mod p, R i is the intermediate parameter when the vehicle calculates the digital certificate signature of the message, and R i is included in σ i ; in response to the verification determining that δ i P = R i + h 3i (PK i ) + T pub , determine that the digital certificate signature is valid, where δ i is the intermediate parameter when the vehicle calculates the digital certificate signature of the message, and δ i is also included in σ i , P is the base point on the elliptic curve y 2 = x 3 + ax + b mod p, P ∈ G, G is the additive group of order q generated by the point P on the elliptic curve, T pub = xP, x is an integer randomly generated by the home subscription user server, and

[0147] In the embodiments of the present application, in response to the message data packet including n message data packets, where n is a positive integer greater than 1, verifying the digital certificate signature of the message data packet includes: obtaining a random vector {ξ i} 1≤i≤n , where {ξ i} ∈ [1, 2 l , and l is the word length; calculating h 3i = h3(m i , R i , RID i , PK i , t i ) 1≤i≤n ; in response to the verification determining the digital certificate signature is valid.

[0148] Figure 12 is a schematic diagram of a message encryption and transmission system provided by an embodiment of the present application. As Figure 12 shown, the system includes:

[0149] A trusted unit, configured to generate public parameters and send the public parameters to a home subscriber server, a verification unit, and a vehicle.

[0150] A home subscriber server, configured to generate a first key PSK i and digest information based on the public parameters, and send the first key PSK i and the digest information to the vehicle.

[0151] A vehicle, configured to generate a vehicle pseudonym RID i based on the unique identifier UID i of the vehicle, the public parameters, and the digest information.

[0152] The vehicle is further configured to obtain a second key from the trusted unit, and perform a digital certificate signature on the message to be sent based on the first key PSK i , the second key, and the vehicle pseudonym RID i to obtain a message data packet including the digital certificate signature.

[0153] A verification unit, configured to receive the message data packet and receive the message after passing the verification of the timestamp and the digital certificate signature in the message data packet.

[0154] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0155] Figure 13It is a schematic diagram of the electronic device provided by the embodiment of the present application. As Figure 13 shown, the electronic device 13 of this embodiment includes: a processor 1301, a memory 1302, and a computer program 1303 stored in the memory 1302 and executable on the processor 1301. When the processor 1301 executes the computer program 1303, it implements the steps in each of the above method embodiments. Alternatively, when the processor 1301 executes the computer program 1303, it implements the functions of each module / unit in each of the above device embodiments.

[0156] The electronic device 13 may be a desktop computer, a notebook, a palm computer, a cloud server, or other electronic devices. The electronic device 13 may include, but is not limited to, the processor 1301 and the memory 1302. Those skilled in the art can understand that Figure 13 merely examples of the electronic device 13, which do not constitute a limitation on the electronic device 13, and may include more or fewer components than shown in the figure, or different components.

[0157] The processor 1301 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0158] The memory 1302 may be an internal storage unit of the electronic device 13, for example, the hard disk or memory of the electronic device 13. The memory 1302 may also be an external storage device of the electronic device 13, for example, a plug-in hard disk equipped on the electronic device 13, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. The memory 1302 may also include both the internal storage unit and the external storage device of the electronic device 13. The memory 1302 is used to store the computer program and other programs and data required by the electronic device.

[0159] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiments can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0160] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of this application, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be implemented. The computer program can include computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device that can carry computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0161] The above embodiments are only used to illustrate the technical solutions of this application, rather than to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of this application, and should all be included in the protection scope of this application.

Claims

1. A message encryption transmission method, characterized in that: The method is performed by a vehicle, and comprises: Receive the first key PSK sent by the home subscriber server i , the first key PSK i Generated by the home subscriber server based on public parameters sent by the trusted unit; Get the vehicle's unique identifier UID i , based on the UID i , the public parameters and the summary information sent by the home subscriber server to generate a vehicle pseudonym RID i ,in, , For ID i Hash function set of information, ID i For vehicle identification, , , , params is the common parameters, T pub = xP, where x is an integer randomly generated by the home subscriber server, and , P is an elliptic curve The base point in the s is the time period determined by the time difference function during which the vehicle receives the first key and summary information sent by the home subscription server, is the XOR operator, h0 and h1 are the hash functions selected by the trusted unit, is the multiplication group modulo q, which contains all integers coprime to q, and both p and q are elliptic curves. The large prime numbers in , F q is a finite field of q; The first key PSK i The home subscriber server calculates it using the following formula: ,in, ; , P pub System public key generated for the trusted unit; Obtaining a second key sent by the trusted unit; The second key is generated by the trusted unit in the following manner: Get random numbers ; Sure is a public key in the second key of the vehicle, A private key in a second key of the vehicle; Get the message to be sent based on the first key PSK i , second key and vehicle pseudonym RID i Signing the message to be sent with a digital certificate to obtain a message data packet containing the digital certificate signature; The message data packet is sent to a verification unit so that the verification unit verifies the identity of the vehicle.

2. The method according to claim 1, characterized in that The public parameters include elliptic curve The base point P, large prime numbers p and q, and the system public key P generated by the trusted unit pub , the hash functions h0, h1, h2 and h3 selected by the trusted unit and the time difference function f(t c ), t c is the current time; Among them, the base point , G is the additive group of order q generated by the base point P on the elliptic curve; , , , , represents the set of all possible binary strings, including the empty string, is the mapping symbol, Z q is the set of integers modulo q.

3. The method according to claim 1, characterized in that The summary information sent by the home subscriber server includes first summary information; Before generating the vehicle pseudonym, the method further includes: The vehicle generates second summary information; In response to verifying that the identity of the vehicle is valid based on the first summary information, the second summary information, the first key and the public parameter, obtaining a time period through a time difference function; In response to determining that the time period is a valid time period, it is determined that a pseudonym generation condition is satisfied.

4. The method according to claim 1, characterized in that based on the first key PSK i , second key and vehicle pseudonym RID i The message to be sent is digitally signed with a certificate to obtain a message data packet containing the digital certificate signature, including: Get random numbers and ,in, ; calculate , where m i is the message to be sent, h 2i Indicates hash calculation for the message; calculate , ; calculate , ,in, , , D i , R i and These are all intermediate calculation parameters, h 3i Indicates hash calculation for the message; Sure signing the digital certificate; Sure is the message data packet, where t i is the current timestamp; Among them, h2 and h3 are hash functions selected by the trusted unit.

5. The method according to claim 1, characterized in that The verification unit verifies the identity of the vehicle, including: Receive message packets sent by vehicles , where m i Messages sent to vehicles, Sign the vehicle's digital certificate, RID i is the vehicle pseudonym, t i The current timestamp when the vehicle sends the message data packet; In response to verifying the time stamp t i If valid, the digital certificate signature of the message data packet is verified; In response to verifying that the digital certificate signature is valid, receiving the message m i .

6. The method according to claim 5, characterized in that In response to the message data packet being a single message data packet, verifying the digital certificate signature of the message data packet includes: Get , where h 3i Indicates hash calculation of the message, h3 is the hash function selected by the trusted unit, , represents the set of all possible binary strings, including the empty string, is the mapping symbol, R i is the intermediate parameter when the vehicle calculates the digital certificate signature of the message, R i Included in middle; In response to the verification determination , determine that the digital certificate signature is valid, where, It is the intermediate parameter when the vehicle calculates the digital certificate signature of the message. Also included in middle, , G is the additive group of order q generated by the base point P on the elliptic curve.

7. The method according to claim 5, characterized in that In response to the message data packet including n message data packets, where n is a positive integer greater than 1, the verifying the digital certificate signature of the message data packet includes: Get a random vector ,in, , l is the word length; calculate ,h 3i Indicates hash calculation of the message, h3 is the hash function selected by the trusted unit, R i It is an intermediate parameter when the vehicle calculates the digital certificate signature of the message; In response to the verification determination , determine that the digital certificate signature is valid, It is an intermediate parameter used by the vehicle to calculate the digital certificate signature of the message.

8. A message encryption transmission device, characterized in that: include: A receiving module configured to receive a first key PSK sent by a home subscriber server i , the first key PSK i Generated by the home subscriber server based on public parameters sent by the trusted unit; An acquisition module configured to acquire a unique identifier UID of the vehicle i , based on the UID i , the public parameters and the summary information sent by the home subscriber server to generate a vehicle pseudonym RID i ,in, , For ID i Hash function set of information, ID i For vehicle identification, , , , params is the common parameters, T pub = xP, where x is an integer randomly generated by the home subscriber server, and , P is an elliptic curve The base point in the s is the time period determined by the time difference function during which the vehicle receives the first key and summary information sent by the home subscription server, is the XOR operator, h0 and h1 are the hash functions selected by the trusted unit, is the multiplication group modulo q, which contains all integers coprime to q, and both p and q are elliptic curves. The large prime numbers in , F q is a finite field of q; The first key PSK i The home subscriber server calculates it using the following formula: ,in, ; , P pub System public key generated for the trusted unit; The receiving module is further configured to obtain a second key sent by the trusted unit; The second key is generated by the trusted unit in the following manner: Get random numbers ; Sure is a public key in the second key of the vehicle, A private key in a second key of the vehicle; The acquisition module is further configured to acquire a message to be sent based on the first key PSK i , second key and vehicle pseudonym RID i Signing the message to be sent with a digital certificate to obtain a message data packet containing the digital certificate signature; The sending module is configured to send the message data packet to the verification unit so that the verification unit verifies the identity of the vehicle.

Citation Information

Patent Citations

  • Method and system for protecting condition privacy of internet of vehicles based on certificateless batch verification

    CN106059766A